W81K00-22-Q-0109_Exhibit 1_RMF Timelines (1).pdf

PDF 9 KB Posted

Attached to
Solicitation – Cost-Per-Test- Flow Cytometry Testing: Reagents and Instrumentation Federal contract opportunity
Solicitation number
22-Q-0109
Issued by
Department of the Army Medical Command

About this file

This exhibit outlines the assessment timeframes and requirements for a Risk Management Framework process. The vendor must submit initial documentation within 15 business days of award and final documentation within four months of award. Requirements include hardware, software and architecture documents; RMF documentation; Nessus scans; STIG checklists; and SCAP scans. The government will provide an initial security assessment plan within 20 business days, RMF templates within five business days of initial vendor contact, and applicable STIGs within 30 days. The government anticipates recommending an Authorization to Operate with Conditions within two weeks of receiving final documentation and scans, and will schedule Independent Verification and Validation within three weeks thereafter.

View the file

Other files for this federal contract opportunity

Other files attached to Solicitation – Cost-Per-Test- Flow Cytometry Testing: Reagents and Instrumentation, newest first.
File Type Posted
W81K00-22-Q-0109_Exhibit 3 _DHA Cybersecurity RMF Requirements (1).pdf PDF
W81K00-22-Q-0109_Exhibit 2_ Defense Health Agency (DHA) Cybersecurity Risk Management and Risk _.pdf PDF
Solicitation - W81K00-22-Q-0109.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

EXHIBIT 1

RMF Assessment Timeframes

Required Vendor Timeframes: The Government shall complete its required actions within the following referenced timeframes but no later than one year after order/contract issuance. If the vendor has completed all required actions in a timely manner and acceptable manner while the Government experiences delays, the vendor would be given additional time for future actions corresponding to the amount of Government delay.

Vendor Requirements: Initial Draft Date Due Final Date Due

Vendor to contact Gov POC:

dha.detrick.med-log.mbx.cyberlog@mail.mil

10 business days post award

Hardware/Software/Architecture Documents 15 business days post award

20 business days post

RMF Documentation Production

6 weeks post award

4 months post

Technical Nessus Scans

1 month post award

6 months post

Technical STIG Checklists

Technical SCAP

Required Vendor Timeframes: The Government shall complete its required actions within the following referenced timeframes but no later than one year after order/contract issuance. If the vendor has completed all required actions in a timely manner and acceptable manner while the Government experiences delays, the vendor would be given additional time for future actions corresponding to the amount of Government delay.

Government Requirements Initial Draft Date Due Final Date Due

Kickoff Meeting 15 business days post award -

Security Assessment Plan Generation 20 business days post award 30 days post award

RMF Templates sent to Vendor 5 business days post vendor initial contact

Copies of Applicable STIGs sent to Vendor 17 business days post award

30 days post award

Authorization to Operate with Conditions (ATO-C) Recommendation

ATO-C recommendation submitted to

3rd party validator 2 weeks after final documentation/technical scans received

Independent Verification and Validation (IV&V) Scheduling

Scheduling request to 3rd party validator 3 weeks after final documentation/technical scans received

File details come from the government source that posted it. Updated .