About this file

Revised Specification

View the file

Other files for this federal contract opportunity

Other files attached to CLR039b Long Range Discrimination Radar Construction Package #2 ECF, Clear AFS, AK, newest first.
File Type Posted
01_19_30_02_29_Attachment_g.pdf PDF
01_19_30_02_29_Attachment_f.pdf PDF
01_50_00_02_00_Attachment_a.pdf PDF
01_19_30_02_29_Attachment_a.pdf PDF
23_05_93.02_00.pdf PDF
01_45_35.02_00.pdf PDF
W911KB18R0006_AM_3.pdf PDF
Schedule_of_Drawings_AM__3_Sheet_1.pdf PDF
05_40_00.02_00.pdf PDF
08_44_23.02_00.pdf PDF
G-100003E_Location_and_Vicinity_Map.pdf PDF
01_19_30.02_29.pdf PDF
01_11_00.02_00.pdf PDF
28_23_23.02_10.pdf PDF
09_29_00.02_00.pdf PDF
Revised_M_Drawings.pdf PDF
Revised_TY_Drawings.pdf PDF
EG100101E_SITE_PLAN_-_GROUNDING.pdf PDF
Schedule_of_Drawings_AM__3_Sheet_2.pdf PDF
01_50_00.02_00.pdf PDF
Final_Presentation--Pre-Proposal_Site_Visit--20180515_Slide_5_Date_Corrections.pdf PDF
01_33_29.02_00.pdf PDF
Revised_E-1_Drawings.pdf PDF
28_20_01.02_10.pdf PDF
Revised_Site_Plan_Drawings.pdf PDF
26_21_00.02_00.pdf PDF
Revised_T_Drawings.pdf PDF
Revised_Security_Drawings.pdf PDF
08_88_36.02_00.pdf PDF
G-100005E_Contractor_Laydown_Areas.pdf PDF
Site_Visit_Sign_In_Sheet.pdf PDF
W911KB18R0006_AM_2.pdf PDF
33_71_02.02_00.pdf PDF
EG100101E_-_SITE_PLAN_-_GROUNDING.pdf PDF
28_23_23.02_10.pdf PDF
Final_Presentation--Pre-Proposal_Site_Visit--20180515.pdf PDF
C_Drawing_revisions.pdf PDF
Revised_E_Drawings.pdf PDF
A_Drawing_Revisions.pdf PDF
28_20_00.02_00.pdf PDF
Revised_E-9_Drawings.pdf PDF
W911KB18R0006_AM_1.pdf PDF
JA_for_Vindictor_LRDR_ECF_Redacted.pdf PDF
JA_Edwards_EST3_fire_Panel_CP_2_ECF_Redacted.pdf PDF
CP2_RTA_SPECS_V2_CLR039_18-0410.pdf PDF
SPECS_V2-4_CLR039_18-0410.pdf PDF
CLR_LRDR_CP2_Rev2_RTA_Drawings_22x34.pdf PDF
CP2_RTA_SPECS_V3_CLR039_18-0410.pdf PDF
CP2_RTA_SPECS_V4_CLR039_18-0410.pdf PDF
W911KB18R0006.pdf PDF
Show all 50

CLR039b Long Range Discrimination Radar Construction Package #2 ECF, Clear AFS, AK has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CP#2 Long Range Discrimination Radar (LRDR) CLR039b LRDR Complex Security - Clear AFS, Alaska AM#2

SECTION 01 91 10.02 29

CYBERSECURITY/RISK MANAGEMENT FRAMEWORK REQUIREMENTS

08/16

PART 1 GENERAL

1.1 STATEMENT OF WORK (SOW) DISCUSSION

The Contractor shall extend the existing cyber-secure systems provided as part of Construction Package 1 (CP1) with all applicable security artifacts and security engineering to meet the requirements of receiving an Authority to Operate (ATO) accreditation decision via the application of Department of Defense (DoD) Risk Management Framework (RMF). The design and construction of the systems shall not favor functional requirements over security where possible. The expected duration for RMF Steps 1-5 including ATO stated below shall include period from notice to proceed to and Construction Completion Dates as defined in Section 01 11 00.02 00 SUMMARY OF WORK for work associated with ECF and perimeter which includes security. The Contractor shall conduct, participate and provide minutes of RMF related meetings as required.

The Risk Management Framework contractor currently working with the Government for preparations of Construction Package 1 will continue in that role to integrate this construction package as modifications to the existing FA/MNS and BMS system ATO processes. AM#2... ...AM#2 The Contractor (CP2) shall utilize and augment where necessary the security controls implemented under the previous and partially concurrent Construction Package 1 work.

Until the expanded systems are transferred to the Government, the Contractor shall maintain the expansions to the Construction Package 1 system as the Information System Owner (ISO) and provide the services of Information Systems Architect and Information Systems Security Engineers and related duties as defined in NIST SP 800-37 Rev 1 and similar responsibilities as defined in UFC 4-010-06 . The Government will function as Authorizing Official and other roles as defined in the same documents.

Implementation of each RMF is a major component of vendor development to attain secure control systems in an independent construction package.

There are five (5) required steps in the RMF approval process. The contractor shall direct and support the government as necessary and as defined in this Section to ensure the completion of the steps listed below related to the expansion of the systems and as outlined in Part 3 in the following tasks:

1. Categorize Information System

2. Select Security Controls

3. Implement Security Controls

4. Assess Security Controls

5. Authorize To Operate (ATO)

6. Monitor Security Controls (If necessary)

Guidance on RMF execution can be found in NIST SP 800-37 Rev 1 , UFC 4-010-06 . and at the following RMF Knowledge Service site:

https://rmfks.osd.mil/rmf/RMFImplementation/Pages/default.aspx

SECTION 01 91 10.02 29 Page 1

The Contractor shall refer to the above site for the most current guidance and information related to RMF execution. A valid CAC or External Certification Authority (ECA) for authentication to access the sites.

The site referenced above requires first time users to register at:

https://rmfks.osd.mil/login.htm and http://csrc.nist.gov/groups/SMA/fisma/framework.html

The cybersecurity accreditation requirements described in this specification shall apply to information systems identified in paragraph

RISK MANAGEMENT FRAMEWORK.

The RMF work will require entering information into the Enterprise Mission Assurance Support Service (eMASS) initiated by the Government as described in Step 1 after approval under 01 33 00.02 00 SUBMITTAL PROCEDURES. The Access to the eMASS site will be continue to be made available either at a secure workstation within Building 800 or at another MDA Facility to the existing CP1 RMF subcontractor. The existing RMF construction contractor's eMASS access will be continue to be sponsored through MDA.

Any changes of personnel will include passing all security clearances for working on the classified system will be requirement of the Contractor.

1.2 REFERENCES

The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.

RMF for the systems shall comply with the latest versions of the following documents, codes, standards and industry practices, as a minimum:

DEFENSE INFORMATION SYSTEMS AGENCY (DISA)

DISA STIG Applicable Security Technical Implementation Guides (STIGs)

U.S. DEPARTMENT OF DEFENSE (DOD)

DODI 8500.01 Cybersecurity

DODI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT)

DODI 8530.01 Cybersecurity Activities Support to DoD Information Network Operations

DODI 8581.01 Information Assurance (IA) Policy for Space Systems Used by the Department of Defense

UFC 4-010-06 Cybersecurity of Facility-Related Control Systems

U.S. DEPARTMENT OF DEFENSE MISSILE DEFENSE AGENCY (MDA)

MDA 8500.02-P Information Assurance Program Plan

SECTION 01 91 10.02 29 Page 2

COMMITTEE ON NATIONAL SECURITY SYSTEMS (CNSS)

CNSSI 1253 Security Categorization and Control Selection for National Security Systems

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)

NIST FIPS 199 Standards for Security Categorization of Federal Information and Information Systems

NIST SP 800-23 Guidelines to Federal Organizations on Security Assurance and Acquisition/Use of Tested/Evaluated Products

NIST SP 800-37 Rev 1 Guide for Applying the Risk Management Framework to Federal Information Systems:

A Security Life Cycle Approach

NIST SP 800-53 Rev 4 Security and Privacy Controls for Federal Information Systems and Organizations

NIST SP 800-82 Rev 2 Guide to Industrial Control Systems (ICS) Security

NIST SP 800-147 Basic Input/Output System (BIOS) Protection Guidelines

National Security Agency (NSA)

NSA SCG Security Configuration Guides (SCG)

1.3 SUBMITTALS

Government approval is required for submittals with a "G" designation;

submittals not having a "G" designation are for information only.

Submittals with an "S" designation following the “G” are for inclusion in the Sustainability Notebook, in conformance to Section 01 33 29.02 00 SUSTAINABILITY REPORTING. Other designations following the "G" designation identify the office that will review the submittal for the Government. Submit the following in accordance with Section 01 33 00.02 00

SUBMITTAL PROCEDURES:

SD-01 Preconstruction Submittals

ISSM and Lead Designer RMF Experience;

RMF Categorization Meeting Minutes;

Contractor Computer Cybersecurity Compliance Statements;

SD-03 Product Data

BMS Information Processing Equipment; G

AM#2... ...AM#2

FA/MNS Information Processing Equipment; G

SECTION 01 91 10.02 29 Page 3

Base product data is included with the respective sections.

SD-05 Design Data

Draft Modifications to CP1 Security Plan(s); G

Security Plan Update(s); G . This is an unclassified notification of the availability of the update being available on eMASS.

SD-06 Test Reports

Internal Security Control Assessment Plan(s); G

Internal Security Control Self-Assessment(s); G This is an unclassified notification of the completion of the Self-Assessment testing and availability on eMASS.

SD-11 Closeout Submittals

Security Authorization Package; . This is an unclassified notification of the availability of the update being available on eMASS.

AM#2... Submit Notice Of ATO ...AM#2

1.4 RISK MANAGEMENT FRAMEWORK (RMF)

Department of Defense Instructions DODI 8500.01 , and DODI 8510.01 , and UFC 4-010-06 incorporate Platform IT (PIT) into the RMF process. PIT is a category of both IT hardware and software that is physically part of, dedicated to, or essential in real time to the mission performance of special purpose systems. The systems listed below are considered PITs as designated by the Government and AO. The contractor shall be responsible for implementing each system PIT using products in accordance with NIST SP 800-23 or similar processes as described in UFC 4-010-06 Categorization of the systems will follow to identify the required controls IAW the RMF process.

1.4.1 SYSTEM BASED RMF

Each of the following systems shall be considered for inclusion as one or more PIT based Risk Management Frameworks within the Project:

AM#2... a. Building Management System (BMS) as specified in Section

23 09 23.02 29 DIRECT DIGITAL CONTROL FOR HVAC, BACNET, CEPOA SPECIFIC

...AM#2

c. Section 28 31 76.02 10 Interior Fire Alarm and Mass Notification

System (FA/MNS)

1.4.2 INITIAL CONFIDENTIALITY - INTEGRITY - AVAILABILITY ASSESSMENT

Existing NIST FIPS 199 Confidentiality- Integrity- Availability (CIA) impact ratings for the control systems (CS) to be modified under this work are as indicated in the table below.

SECTION 01 91 10.02 29 Page 4

EXISTING LRDR CS Confident-iality Integrity Availability

BMS MC Low Moderate High

AM#2... ...AM#2

FA/MNS Low Low Low

Initial determinination of NIST FIPS 199 Confidentiality- Integrity- Availability (CIA) impact ratings for the control systems (CS) for work added are as indicated in the table below. These will be refined with the Authorizing Official (AO) and supporting RMF team during Step 1 of the RMF process. Note systems with "MC" suffix are considered Mission Critical. Contractor is responsible for coordinating with the Government Authorizing Official and the Contracting Officer for obtaining the system authorizations as defined herein and operating the system(s) until government turnover following Construction Completion Date. Contractor shall group component(s) with protection/control into as few RMF packages as practical for each system; all component(s) with protection/control shall be included in a single RMF package. Lists of hardware and software shall be provided for each RMF package. Final values shall not be higher than those determined under the CP1 Security Planning as described above.

LRDR CS Confident-iality Integrity Availability

BMS MC Low Moderate Low

AM#2... ...AM#2

FA/MNS Low Low Low

Each of the above system's cabling, CS infrastructure and equipment shall include an integrated RMF solution in accordance with all applicable regulations and directives to obtain a favorable Authority to Operate (ATO), as well as an Authority to Connect (ATC) to any MDA or Air Force networks. The Contractor shall provide all documentation and information required to obtain a favorable Assess and Authorize (A&A) decision. To meet the RMF requirements the Contractor shall complete the Security Authorization Package (SAP), and receive a favorable A&A, an ATO, and an ATC for the system.

1.4.3 Cybersecurity

Risk Management Framework shall be developed, manufactured, delivered and maintained in accordance with DODI 8500.01 , DODI 8510.01 , DODI 8581.01 , DODI 8530.01 , NIST SP 800-53 Rev 4 , NIST SP 800-147 and MDA 8500.02-P requirements. The contractor shall integrate all applicable cybersecurity requirements into the systems engineering requirements process to ensure early identification of and integration of cybersecurity into the system, including verification methods. The Contractor shall configure system components in accordance with applicable DISA STIG and NSA SCG. The Contractor shall provide assessment of RMF Equipment submitted under the control systems and evidence of compliance in accordance with

SECTION 01 91 10.02 29 Page 5

NIST SP 800-23 and MDA RMF guidance. The Contractor shall stay aware of current/changing cybersecurity requirements to ensure the final system meets current requirements and thus capable of receiving an Authorization to Operate (ATO). Assessment and authorization recommendations will be based on the resolution or mitigation of all identified findings to an acceptable level of risk per the Authorization Official (AO).

1.4.3.1 Computer Network Defense

The Contractor shall extend the existing design and implementation of an MDA approved cybersecurity infrastructure to protect the confidentiality, integrity and availability of RMF and supporting systems and shall ensure the successful interconnection with a DoD-approved Computer Network Defense Service Provider (CNDSP) to meet mandatory Tier 2 CND monitoring and reporting requirements.

1.5 QUALIFICATIONS

Contractor shall employ an coordinate and integrate with the CP1 RMF system designer or team . The CP1 RMF Contractor's Information System Security Manager (ISSM) and Lead Designer shall have a minimum of seven

(7) years of documented experience (or IAT Level III certification) in the design and implementation of RMF and information assurance for DoD control, security and fire alarm systems. The existing RMF team member will continue to have External Certification Authority (ECA) for entry and access to information as noted in this specification. Provide confirmation of Construction Package 1's ISSM and Lead Designer RMF Experience is being used for approval.

1.5.1 Cybersecurity Training

All contractor personnel performing IA/Cybersecurity duties and responsibilities as either a primary or as an additional/embedded duty, to include system or network privileged users, shall meet the training, certification, and reporting requirements in accordance with DODM 8570.01-M Change 3 Information Assurance, Training, Certification and Workforce Management Instructions.

1.6 WARRANTY

Warranty does not start until Authority to Operate the CP2 additions is given by the AO.

1.7 DEFINITIONS

1.7.1 Computer

As used in this Section, a computer is one of the following:

a. a device running a non-embedded desktop or server version of Microsoft Windows

b. a device running a non-embedded version of MacOS

c. a device running a non-embedded version of Linux

d. a device running a version or derivative of the Android OS, where Android is considered separate from Linux

SECTION 01 91 10.02 29 Page 6

e. a device running a version of Apple iOS

1.7.2 Network Connected

A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).

Any device that supports wireless communication is network connected, regardless of whether the device is communicating using wireless .

1.7.3 User Account Support Levels

The support for user accounts is categorized in this Section as one of three levels:

1.7.3.1 FULLY Supported

Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.

1.7.3.2 MINIMALLY Supported

Device supports a small, fixed number of accounts (perhaps only one).

Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "user name and password" structure).

1.7.3.3 NOT Supported

Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.

1.7.4 User Interface

Generally, a user interface is hardware on a device allowing user interaction with that device via input (buttons, switches, sliders, keyboard, touch screen, etc.) and a screen. There are three types of user interfaces defined in this Section: Limited Local User Interface, Full Local User Interface and Remote User Interface. In this Section, when the term "User Interface" is used without specifying which type, it refers only to Full Local User Interface and Remote User Interface (NOT to Limited Local User Interface).

1.7.4.1 Limited Local User Interface

A Limited Local User Interface is a user interface where the interaction is limited, fixed at the factory, and cannot be modified in the field.

The user must be physically at the device to interact with it.

Examples of Limited Local User Interface include thermostats (Space Sensor Modules as defined in Section 23 09 13 INSTRUMENTATION AND CONTROL DEVICES

FOR HVAC).

SECTION 01 91 10.02 29 Page 7

1.7.4.2 Full Local User Interface

A Full Local User Interface is a user interface where the interaction and displays are field-configurable.

Examples of a Full Local User Interface include local applications on a computer and user interfaces to Variable Speed Drives .

1.7.4.3 Remote User Interface

A Remote User Interface is a user interface on a Client device allowing user interaction with a different Server device. The user need not be physically at the Server device to interact with it.

1.8 CYBERSECURITY DURING CONSTRUCTION

In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.

1.8.1 Contractor Computer Equipment

Contractor owned computers may be used for construction. When used, contractor computers must meet the following requirements:

1.8.1.1 Operating System

The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be current on security patches and operating system manufacturer required updates.

1.8.1.2 Anti-Malware Software

The computer must run anti-malware software from a reputable software manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. All computers used on this project must be scanned using the installed software at least once per day.

1.8.1.3 Passwords and Passphrases

The passwords and passphrases for all computers must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.8.2 Temporary IP Networks

Temporary contractor-installed IP networks may be used during construction. When used, temporary contractor-installed IP networks must meet the following requirements:

1.8.2.1 Network Boundaries and Connections

The network must not extend outside the project site and must not connect to any IP network other than IP networks provided under this project or

SECTION 01 91 10.02 29 Page 8

Government furnished IP networks provided for this purpose. Any and all network access from outside the project site is prohibited.

1.8.3 Government Access to Network

Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this specification

1.8.4 Temporary Wireless IP Networks

In addition to the other requirements on temporary IP networks, temporary wireless IP (WiFi) networks must not interfere with existing wireless network and must use WPA2 security. Network names (SSID) for wireless networks must be changed from their default values.

1.8.5 Passwords and Passphrases

The passwords and passphrases for all network devices and network access must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.8.6 Contractor Temporary Network Cybersecurity Compliance Statements

Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf . Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.

PART 2 PRODUCTS

2.1 CONTROL SYSTEM INFORMATION PROCESSING EQUIPMENT

Information processing equipment provided for each CS shall be suitable for selected security controls with products in accordance with guidelines of NIST SP 800-23 , NIST SP 800-147 matching CP1 installed equipment of similar functionality or otherwise approved through evaluation and testing as described in UFC 4-010-06 acceptable to the control system AO. Submit information processing equipment documentation for each RMF package as part of the Draft Modifications to CP1 Security Plan.

a. BMS Information Processing Equipment

AM#2... ...AM#2

c. FA/MNS Information Processing Equipment

PART 3 EXECUTION

3.1 RMF PROCESS REQUIREMENTS

The design requirements for items listed above under RISK MANAGEMENT FRAMEWORK shall follow the the procedure in NIST SP 800-37 Rev 1 and UFC 4-010-06 . as outlined in this Section.

The Contractor shall design and implement an MDA approved ICS

SECTION 01 91 10.02 29 Page 9 infrastructure in accordance with NIST SP 800-82 Rev 2 to protect the confidentiality, integrity and availability of RMF and supporting systems and shall ensure the successful interconnection with a DoD-approved Computer Network Defense Service Provider (CNDSP) to meet mandatory Tier 2 CND monitoring and reporting requirements.

3.1.1 Step 1 - Categorization of Control System Information Systems

The Contractor shall in coordination with the Construction Package 1 RMF contractor and Government's Information System Owner (ISO) and Authorizing Official (AO) support refinements in categorization IAW NIST FIPS 199, CNSSI 1253 and NIST SP 800-82 Rev 2 of the CS and document the results of the security categorization in the security plan. The Contractor may use the Department of Homeland Security Cyber Security Evaluation Tool or similar method to assist in the refinement process of the CP1 categorizations. The RMF contractor shall lead the categorization meetings with Contracting Officer, ISO and UR, and the Information System Security Manger (ISSM) as requested to support security categorization.

The Contractor shall distribute meeting minutes of each all meetings including final collection of RMF Categorization Meeting Minutes within a week of each meeting.

3.1.1.1 RMF Roles

Identification and assignment of RMF Team members is a collaborative process involving all relevant stakeholders, to include the Contractor, which may interact with the system throughout its lifecycle. The Contractor and Client will have similar roles as noted in the list below, where Contractor equivalent role for development of the RMF are noted.

The Contractor in coordination with Contracting Officer and ISO shall ensure that the RMF Team positions are properly identified and listed in the Security Plan. The RMF Team includes:

RMF Role Government Personnel Role

RMF Sub-Contractor Role

Component Chief Information Officer (CIO) X Supporting

Component Senior Information Security Officer

(SISO)

X Supporting

Authorizing Official (AO) X

Authorizing Official Designated Representative

(AODR)

X

Security Control Assessor (SCA) X Supporting

Information System Owner (ISO) X Initial representative until

Government Acceptance

Program Manager or System Manager (PM/SM) X Supporting

Information System Security Manager (ISSM) X

SECTION 01 91 10.02 29 Page 10

RMF Role Government Personnel Role

RMF Sub-Contractor Role

Information System Security Officer (ISSO) X

RMF Specialty Designer(s) X

CS Vendor/Integrator Subject Matter Expert X

User Representative (UR) X

3.1.1.2 NIST FIPS 199 / CNSSI 1253 Security Categorization

The Contractor shall ensure that a written subsection of the security plan covers NIST FIPS 199 / CNSSI 1253 Security Categorization and Threat Assessment documenting agreed final C-I-A impact values and identification of RMF packages covering one or more CS. The government will provide a C-I-A concurrence memorandum agreeing with the determination of impacts.

3.1.1.3 Initiate the Security Plan(s)

The Contractor shall in collaboration with the control system ISO(s) initiate and develop a comprehensive modification to the existing CP1 Security Plan(s). Each modified Security Plan provides an overview of the security requirements, description of each CS (including system boundary) and describes the security controls in place or planned for meeting those requirements for the expanded systems.

3.1.1.4 System Registrations

The ISO is responsible for registering each modification of RMF Package;

Initiating an Enterprise Mission Assurance Support Service (eMASS)entry and receiving a unique ID for each RMF Package for the project. The Contractor shall coordinate with Contracting Officer to obtain an eMASS account. The Contractor will be required to submit a completed DD Form 2875 and complete the eMASS Computer Based Training (CBT) (https://disa.deps.mil/ext/cop/iase/emass/Pages/training.aspx). Access to eMASS will require the Contractor to have a valid security clearance and access to SIPRnet through MDA facilities.

The RMF Contractor shall record the eMASS Identification ID in the System Identification field within the Security Plan.

3.1.2 Step 2 - Selection of CS Security Controls

3.1.2.1 RMF Control Selection

The Contractor in coordination with the RMF Team shall select the Security control baselines based upon impact levels for each control system from NIST SP 800-53 Rev 4 and NIST SP 800-82 Rev 2 . Conduct appropriate tailoring of the selected set of security controls to include;

Supplementing the tailored baseline security control set, identification of Inherited Common / Hybrid Security Controls, and documenting the Final Security Control Set to be approved in the Final Security Plan.

Select NIST SP 800-53 Rev 4 (note: NIST SP 800-82 Rev 2 Industrial Control Systems Security Guide, Appendix G ICS Overlay will be used to evaluate control systems and will be programmed into eMASS. Until that happens, the

SECTION 01 91 10.02 29 Page 11

EI&E NIST SP 800-82 Rev 2 ICS Overlay Security Controls and EI&E NIST SP 800-53 Rev 4 and 800-82 Rev 2 merge found at (https://rmfks.osd.mil/) shall be used manually to complete the security controls until the eMASS functionality is available.

The Contractor shall ensure that the CP1 and additional selected set of security controls, along with the supporting rationale for selection decisions and any system use restrictions, are included the security plan.

The security plan must also, identify all common controls inherited from external providers, and establish minimum assurance requirements for those controls.

The Contractor shall categorize and identify Control Correlation Items (CCIs) as one or more of the following categories as described in

UFC 4-010-06 :

a. DoD-Defined: Either the DoD has provided a value for the "organization selected" values, or the DoD implementation guidance states that the CCI is already met by existing policy or regulation. These values are defined in the CCI list obtained from the RMF Knowledge Service.

b. RMF Designer: The designer has a role to address for the CCI. Either the designer needs to provide design specifications to cover a requirement for the control system itself and/or the designer must provide input to others within the Contractor team regarding the implementation or lack of feasibility of the CCI.

c. Non-Designer: The CCI is beyond the responsibility of the designer, and is the responsibility of someone else, such as a standard operating procedure.

d. Platform Enclave: The CCI contains a requirement which is expected to be implemented at the Platform Enclave and inherited by the control system, or is mostly implemented at the Platform Enclave but also needed within the field control system.

e. Impractical: The CCI is impractical to fully implement in a control system, but may be applied in a limited manner to a least some part of the control system.

3.1.2.2 Continuous Monitoring Strategy

The Contractor with coordination through the ISO shall develop a system-level strategy for the continuous monitoring of the CS. The system-level continuous monitoring strategy is a mandatory requirement to be included in the Security Plan

3.1.2.3 Draft Modifications to CP1 Security Plan

Upon Contractor completion of adjustments to eMASS input sheets ready for security control selection within eMASS, the Security Plan can be generated. The Contractor shall provide a Draft Modifications to CP1 Security Plan(s) by providing eMASS input forms with sufficient information to understand the intended or actual implementation of each security control employed within or inherited by the CS from a common control provider. By approving the security plan, the AO agrees to the system categorization, the set of security controls proposed to meet the security requirements for the system, and the adequacy of the system-level continuous monitoring strategy.

SECTION 01 91 10.02 29 Page 12

The Security Plan shall also contain supporting appendices (or placeholders for further development) or as references to appropriate sources, other risk and security-related documents such as but limited to a(n):

a. Risk Assessment.

b. Privacy Impact Assessment.

c. System Interconnection Agreements (if applicable).

d. Security Controls including:

1. The final classification of each of the CCIs.

2. The changes to standard CCI requirements along with an explanation of the changes.

3. The Control Correlation Items CCIs which have been incorporated into the control system design. Document changes from standard requirements, or selections made when multiple options are available.

4. Information for others as required.

e. Continuous Monitoring Strategy.

3.1.3 RMF Step 3 - Implement CS Security Control(s)

3.1.3.1 Internal Security Control Self-Assessment Plan

The Contractor shall develop, review, and submit any revisions to internal security control assessment plan(s) using eMASS generated template to internally assess the selected system-level security controls.

The plan should include identification of assessment testing logistics, vulnerability scanning tools (i.e. ACAS, SCAP, SRG, etc…), roles and responsibilities, detailed test plans, etc. See paragraph TESTING for additional requirements.

The Contractor shall identify the specific section (using document section name) that satisfies each actionable item for each CCI. For example "…in the SystemName System Security Plan, section/paragraph (Account Control, Purpose & Scope)…" vice "…in the SSP…"

The Contractor shall address each actionable item in each CCI for the Selected Security Controls determined by the RMF Team in RMF Step 2- Select Security Controls.

3.1.3.2 Internal Security Control Self-Assessment (Scan/Fix/Scan testing and Analysis

The contractor shall assess (scan and perform checks) control system's components using approved cybersecurity scanning tools and applicable manual checks utilizing DISA Security Technical Implementation Guides (STIG) as described within the Internal Security Control Self-Assessment Plan. See paragraph TESTING for vulnerability testing requirements. If vulnerabilities are found (Category (CAT) 1, 2 or 3) as the result of automated scans and manual checks, the Contractor shall remediate, mitigate, and or provide technical rationale as to why the vulnerability cannot meet compliance requirements. Upon completion vulnerability resolution, the Contractor shall rescan the CS utilizing the same methods as previously stated to ensure all vulnerabilities have been properly remediated and/or properly and acceptably mitigated or documented as an open vulnerability. The Contractor shall strive to mitigate and or remediate all vulnerabilities associated with the CS to greatest extent possible. CAT 1 and High Risk CAT 2 vulnerability findings that cannot be

SECTION 01 91 10.02 29 Page 13 remediated or mitigated to a lower acceptable risk as determined by the AO, are to be reported to the government with supporting rationale, and properly identified on the Initial Plan of Actions and Milestones (POA&M).

The results of the Internal Security Control Self-Assessment shall be documented within eMASS by the SO with support from the Contractor.Submit the results as a non-classified summary of the eMASS Internal Security Control Self-Assessment(s) under FOUO requirements.

The Contractor shall support the ISO as necessary in associating a system-level artifact (in eMASS) with each CCI when the artifact is used to support test results from the Internal Security Control Self-Assessment. The contractor shall use the artifact name in the test results for example: "Documented in the SystemName System Security Plan…" vice "Documented in the SSP…"

The Contractor shall identify the specific section (using document section name) that satisfies each actionable item for each CCI. For example "…in the SystemName System Security Plan, section/paragraph (Account Control, Purpose & Scope)…" vice "…in the SSP…"

The Contractor shall address each actionable item in each CCI for the Selected Security Controls determined by the RMF Team in RMF Activity 2- Select Security Controls.

Upon completion of the Internal Security Control Self-Assessment the Contractor shall assist Contracting Officer and the ISO to support the scheduling of the Government's Assessment prior to Authorization to Operate and Connects.

3.1.3.3 Security Plan Update

Upon Contractor completion of RMF Step 3, the Contractor shall update the eMASS Security Plan and submit notification of update completionwith any updates to previous and new information to include, but not limited to, the following system-level documentary RMF artifacts within the deliverables as required:

a. Risk Assessment, updates

b. Privacy Impact Assessment, updates

c. System Interconnection Agreements, updates (if applicable)

d. Continuous Monitoring Strategy, updates

e. Configuration Management Plan

f. Contingency Planning

1. Disaster Recovery Plan

2. IT Contingency Plan

3. Continuity of Operations Plan

4. System Restoration Checklist

g. Security Configurations

1. System Architecture / Network Topology / Data Flow depicting CS

Authorization Boundary

2. Hardware Inventory List

3. Software Inventory List

4. Ports, Protocols, and Services (PPS) List in accordance with DoD

PPS Category Assurance List (CAL)

h. Physical Security Plan

i. Information Assurance Vulnerability(IAVM)/Patch Management Plan

SECTION 01 91 10.02 29 Page 14

3.1.3.4 Authority to Test

A successful Internal Security Control Self-Assessment shall be deemed necessary to allow the control system to be tested within the system's capability without interconnecting to remote resources or MDA/AF networks.

3.1.4 RMF Step 4 - Assess Security Control(s)

3.1.4.1 Government RMF Controls Validation Test (CVT)

The Contractor shall be available as needed to assist the combined MDA/Air Force's (Government's) RMF CVT Team for the duration of the assessment(s). The normal duration of an assessment is typically 3-5 working days (on-site) for the scans, document review, and manual checks.

It typically takes an additional 30 days (off-site) for the Government team to perform analysis and provide the requisite reports. The contractor shall plan its schedule accordingly to effectively capture these events and the associated timelines to complete.

3.1.4.2 Security Assessment Results & Remediation Actions

The Contractor shall upon receipt of the Security CVT Results conduct remediation actions based on the findings and recommendations of the Government's team. Receipt of the Corrected Final Security CVT Results should be delivered to the Contractor no later than 30 days after RMF CVT

3.1.5 RMF Step 5 - Authorize Control System(s)

3.1.5.1 Plan of Action and Milestones (POA&M)

The Contractor shall prepare and submit the POA&M based on the findings and recommendations of the Security Control Assessment Results. The Contractor shall create a vulnerability and one milestone for every non-complying control in the POA&M module of eMASS for Security Control Assessor-Representative (SCR-R) use in performing final residual risk analysis. The Contractor shall allot 45 days for POA&M development and 15 days for review and approval.

3.1.5.2 Security Authorization Package

Upon approval of the POA&M the Contractor shall assist the ISO in submission of the Security Authorization Package via eMASS into the Package Approval Chain (PAC) for review and approval. Unclassified notification of submission will be provided to the Government outside of eMASSS. The PAC is tiered approval process in which the Security Authorization Package goes through multiple levels of approval by the PAC.

The Security Authorization Packages will include:

a. System Security plan

b. Security Control Assessment Report

c. Plan of Action and Milestones

d. Continuous Monitoring Plan

The Security Authorization Package goes through multiple levels of approval. If during the Initial Review the SCA-R identifies there is insufficient information or missing data or artifacts, the package must be returned for rework. The Contractor shall support resolving any issues related to rework within scope as directed by the Contracting Officer. The Contractor shall allot for 25 days for the review prior to submission to

SECTION 01 91 10.02 29 Page 15 the AO for the final Security Authorization Determination.

3.1.5.3 Security Authorization Determination (ATO)

The AO makes the final approval decision in the 6th level of the PAC, the Contractor shall allot 45 days for the final AO Security Authorization Determination i.e. ATO. Submit notice of ATO by the AO shall be submitted to

3.1.5.4 Authority to Connect (ATC)

Upon receipt of the final Security Authorization Determination (ATO), the Contractor shall assist the ISO in obtaining ATC via MDA network service provider, if required.

3.1.6 RMF Step 6 - Monitor Security Controls

The Contractor shall maintain the CS's Security Controls in accordance with the Continuous Monitoring Plan between ATO and Construction Completion Date or Government Maintenance if it should occur before Construction Completion Date.

3.1.6.1 IAVM/CTO Activities

The Contractor shall assess Government IA Vulnerability Notices (IAVNs) and Command Tasking Orders (CTOs) to determine system applicability and shall develop plans and implement product vendor patches and other mitigations in support of IAVM as approved by MDA during this monitoring period. The Contractor shall report IAVM and CTO status to the Government ISSM on a weekly basis.

3.2 Coordination of RMF activities with Contract Completion

The Contractor shall include the following and other information on review durations in this specification in their Construction Schedule.

a. The Internal Security Control Self-Assessment documentation in eMASS and submittal should occur no later than 5 months prior to the scheduled completion of Step 3 for each CS. This submittal forms the basis for the Assessment and Authorization (ATO Approval Package) request.

b. Contractor shall coordinate on-site inspections no less 90 days before testing is required.

c. Interim ATO must be received prior to completion of Commissioning or similar Government Acceptance Testing such as required for Fire Alarm AM#2... ...AM#2 Systems.

3.3 TESTING

3.3.1 General Requirements for Testing

Provide personnel, equipment, instrumentation, and supplies necessary to perform site testing. The Government will witness all performance verification and certification testing. Written permission shall be obtained from the Government before proceeding with the next phase of testing. Original copies of all data produced during performance verification and endurance testing, shall be turned over to the Government at the conclusion of each phase of testing, prior to Government approval

SECTION 01 91 10.02 29 Page 16 of the test

3.3.2 Vulnerability Assessment and Asset Testing

Once the Contractor has started control systems and pre-ATO testing, the Contractor shall conduct monthly cybersecurity vulnerability assessment scans for the initial and all subsequent strings utilizing the Assured Compliance Assessment Solution (ACAS) DoD toolset current at the time the scan is performed. Download the ACAS DoD toolset from DISA.mil patch repository at: https://patches.csd.disa.mil/CollectionInfo.aspx?id=442 (DoD issued ECA or CAC is required). At the time the scan is performed, the Contractor shall request the MDA Sensors Information System Security Manager (ISSM) provide software and required licenses.

Resulting data shall be made available via secure methods for Government review and analysis. The Contractor shall provide technical, Systems Administrator (SA), and Network Administrator (NA) expertise for execution of Government-conducted Security Control Assessment (SCA), Penetration Testing, and Interface Boundary (IFB) Tests. The Contractor shall participate in pre-SCA coordination meetings, post-test analysis, Assessment and Authorization Technical Interchange and Risk Assessment Meetings, and Plan of Action & Milestone (POA&M) maintenance activities.

-- End of Section --

SECTION 01 91 10.02 29 Page 17

File details come from the government source that posted it.