W81K00-22-Q-0109_Exhibit 1_RMF Timelines (1).pdf
PDF 9 KB Posted
- Attached to
- Solicitation – Cost-Per-Test- Flow Cytometry Testing: Reagents and Instrumentation Federal contract opportunity
- Solicitation number
- 22-Q-0109
- Issued by
- Department of the Army Medical Command
About this file
This exhibit outlines the assessment timeframes and requirements for a Risk Management Framework process. The vendor must submit initial documentation within 15 business days of award and final documentation within four months of award. Requirements include hardware, software and architecture documents; RMF documentation; Nessus scans; STIG checklists; and SCAP scans. The government will provide an initial security assessment plan within 20 business days, RMF templates within five business days of initial vendor contact, and applicable STIGs within 30 days. The government anticipates recommending an Authorization to Operate with Conditions within two weeks of receiving final documentation and scans, and will schedule Independent Verification and Validation within three weeks thereafter.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| W81K00-22-Q-0109_Exhibit 3 _DHA Cybersecurity RMF Requirements (1).pdf | ||
| W81K00-22-Q-0109_Exhibit 2_ Defense Health Agency (DHA) Cybersecurity Risk Management and Risk _.pdf | ||
| Solicitation - W81K00-22-Q-0109.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
EXHIBIT 1
RMF Assessment Timeframes
Required Vendor Timeframes: The Government shall complete its required actions within the following referenced timeframes but no later than one year after order/contract issuance. If the vendor has completed all required actions in a timely manner and acceptable manner while the Government experiences delays, the vendor would be given additional time for future actions corresponding to the amount of Government delay.
Vendor Requirements: Initial Draft Date Due Final Date Due
Vendor to contact Gov POC:
dha.detrick.med-log.mbx.cyberlog@mail.mil
10 business days post award
Hardware/Software/Architecture Documents 15 business days post award
20 business days post
RMF Documentation Production
6 weeks post award
4 months post
Technical Nessus Scans
1 month post award
6 months post
Technical STIG Checklists
Technical SCAP
Required Vendor Timeframes: The Government shall complete its required actions within the following referenced timeframes but no later than one year after order/contract issuance. If the vendor has completed all required actions in a timely manner and acceptable manner while the Government experiences delays, the vendor would be given additional time for future actions corresponding to the amount of Government delay.
Government Requirements Initial Draft Date Due Final Date Due
Kickoff Meeting 15 business days post award -
Security Assessment Plan Generation 20 business days post award 30 days post award
RMF Templates sent to Vendor 5 business days post vendor initial contact
Copies of Applicable STIGs sent to Vendor 17 business days post award
30 days post award
Authorization to Operate with Conditions (ATO-C) Recommendation
ATO-C recommendation submitted to
3rd party validator 2 weeks after final documentation/technical scans received
Independent Verification and Validation (IV&V) Scheduling
Scheduling request to 3rd party validator 3 weeks after final documentation/technical scans received
File details come from the government source that posted it. Updated .