01_91_10.02_29.pdf
PDF 60 KB Posted
- Attached to
- CLR039b Long Range Discrimination Radar Construction Package #2 ECF, Clear AFS, AK Federal contract opportunity
- Solicitation number
- W911KB18R0006
About this file
Revised Specification
View the file
Other files for this federal contract opportunity
Show all 50
CLR039b Long Range Discrimination Radar Construction Package #2 ECF, Clear AFS, AK has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CP#2 Long Range Discrimination Radar (LRDR) CLR039b LRDR Complex Security - Clear AFS, Alaska AM#2
SECTION 01 91 10.02 29
CYBERSECURITY/RISK MANAGEMENT FRAMEWORK REQUIREMENTS
08/16
PART 1 GENERAL
1.1 STATEMENT OF WORK (SOW) DISCUSSION
The Contractor shall extend the existing cyber-secure systems provided as part of Construction Package 1 (CP1) with all applicable security artifacts and security engineering to meet the requirements of receiving an Authority to Operate (ATO) accreditation decision via the application of Department of Defense (DoD) Risk Management Framework (RMF). The design and construction of the systems shall not favor functional requirements over security where possible. The expected duration for RMF Steps 1-5 including ATO stated below shall include period from notice to proceed to and Construction Completion Dates as defined in Section 01 11 00.02 00 SUMMARY OF WORK for work associated with ECF and perimeter which includes security. The Contractor shall conduct, participate and provide minutes of RMF related meetings as required.
The Risk Management Framework contractor currently working with the Government for preparations of Construction Package 1 will continue in that role to integrate this construction package as modifications to the existing FA/MNS and BMS system ATO processes. AM#2... ...AM#2 The Contractor (CP2) shall utilize and augment where necessary the security controls implemented under the previous and partially concurrent Construction Package 1 work.
Until the expanded systems are transferred to the Government, the Contractor shall maintain the expansions to the Construction Package 1 system as the Information System Owner (ISO) and provide the services of Information Systems Architect and Information Systems Security Engineers and related duties as defined in NIST SP 800-37 Rev 1 and similar responsibilities as defined in UFC 4-010-06 . The Government will function as Authorizing Official and other roles as defined in the same documents.
Implementation of each RMF is a major component of vendor development to attain secure control systems in an independent construction package.
There are five (5) required steps in the RMF approval process. The contractor shall direct and support the government as necessary and as defined in this Section to ensure the completion of the steps listed below related to the expansion of the systems and as outlined in Part 3 in the following tasks:
1. Categorize Information System
2. Select Security Controls
3. Implement Security Controls
4. Assess Security Controls
5. Authorize To Operate (ATO)
6. Monitor Security Controls (If necessary)
Guidance on RMF execution can be found in NIST SP 800-37 Rev 1 , UFC 4-010-06 . and at the following RMF Knowledge Service site:
https://rmfks.osd.mil/rmf/RMFImplementation/Pages/default.aspx
SECTION 01 91 10.02 29 Page 1
The Contractor shall refer to the above site for the most current guidance and information related to RMF execution. A valid CAC or External Certification Authority (ECA) for authentication to access the sites.
The site referenced above requires first time users to register at:
https://rmfks.osd.mil/login.htm and http://csrc.nist.gov/groups/SMA/fisma/framework.html
The cybersecurity accreditation requirements described in this specification shall apply to information systems identified in paragraph
RISK MANAGEMENT FRAMEWORK.
The RMF work will require entering information into the Enterprise Mission Assurance Support Service (eMASS) initiated by the Government as described in Step 1 after approval under 01 33 00.02 00 SUBMITTAL PROCEDURES. The Access to the eMASS site will be continue to be made available either at a secure workstation within Building 800 or at another MDA Facility to the existing CP1 RMF subcontractor. The existing RMF construction contractor's eMASS access will be continue to be sponsored through MDA.
Any changes of personnel will include passing all security clearances for working on the classified system will be requirement of the Contractor.
1.2 REFERENCES
The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.
RMF for the systems shall comply with the latest versions of the following documents, codes, standards and industry practices, as a minimum:
DEFENSE INFORMATION SYSTEMS AGENCY (DISA)
DISA STIG Applicable Security Technical Implementation Guides (STIGs)
U.S. DEPARTMENT OF DEFENSE (DOD)
DODI 8500.01 Cybersecurity
DODI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT)
DODI 8530.01 Cybersecurity Activities Support to DoD Information Network Operations
DODI 8581.01 Information Assurance (IA) Policy for Space Systems Used by the Department of Defense
UFC 4-010-06 Cybersecurity of Facility-Related Control Systems
U.S. DEPARTMENT OF DEFENSE MISSILE DEFENSE AGENCY (MDA)
MDA 8500.02-P Information Assurance Program Plan
SECTION 01 91 10.02 29 Page 2
COMMITTEE ON NATIONAL SECURITY SYSTEMS (CNSS)
CNSSI 1253 Security Categorization and Control Selection for National Security Systems
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)
NIST FIPS 199 Standards for Security Categorization of Federal Information and Information Systems
NIST SP 800-23 Guidelines to Federal Organizations on Security Assurance and Acquisition/Use of Tested/Evaluated Products
NIST SP 800-37 Rev 1 Guide for Applying the Risk Management Framework to Federal Information Systems:
A Security Life Cycle Approach
NIST SP 800-53 Rev 4 Security and Privacy Controls for Federal Information Systems and Organizations
NIST SP 800-82 Rev 2 Guide to Industrial Control Systems (ICS) Security
NIST SP 800-147 Basic Input/Output System (BIOS) Protection Guidelines
National Security Agency (NSA)
NSA SCG Security Configuration Guides (SCG)
1.3 SUBMITTALS
Government approval is required for submittals with a "G" designation;
submittals not having a "G" designation are for information only.
Submittals with an "S" designation following the “G” are for inclusion in the Sustainability Notebook, in conformance to Section 01 33 29.02 00 SUSTAINABILITY REPORTING. Other designations following the "G" designation identify the office that will review the submittal for the Government. Submit the following in accordance with Section 01 33 00.02 00
SUBMITTAL PROCEDURES:
SD-01 Preconstruction Submittals
ISSM and Lead Designer RMF Experience;
RMF Categorization Meeting Minutes;
Contractor Computer Cybersecurity Compliance Statements;
SD-03 Product Data
BMS Information Processing Equipment; G
AM#2... ...AM#2
FA/MNS Information Processing Equipment; G
SECTION 01 91 10.02 29 Page 3
Base product data is included with the respective sections.
SD-05 Design Data
Draft Modifications to CP1 Security Plan(s); G
Security Plan Update(s); G . This is an unclassified notification of the availability of the update being available on eMASS.
SD-06 Test Reports
Internal Security Control Assessment Plan(s); G
Internal Security Control Self-Assessment(s); G This is an unclassified notification of the completion of the Self-Assessment testing and availability on eMASS.
SD-11 Closeout Submittals
Security Authorization Package; . This is an unclassified notification of the availability of the update being available on eMASS.
AM#2... Submit Notice Of ATO ...AM#2
1.4 RISK MANAGEMENT FRAMEWORK (RMF)
Department of Defense Instructions DODI 8500.01 , and DODI 8510.01 , and UFC 4-010-06 incorporate Platform IT (PIT) into the RMF process. PIT is a category of both IT hardware and software that is physically part of, dedicated to, or essential in real time to the mission performance of special purpose systems. The systems listed below are considered PITs as designated by the Government and AO. The contractor shall be responsible for implementing each system PIT using products in accordance with NIST SP 800-23 or similar processes as described in UFC 4-010-06 Categorization of the systems will follow to identify the required controls IAW the RMF process.
1.4.1 SYSTEM BASED RMF
Each of the following systems shall be considered for inclusion as one or more PIT based Risk Management Frameworks within the Project:
AM#2... a. Building Management System (BMS) as specified in Section
23 09 23.02 29 DIRECT DIGITAL CONTROL FOR HVAC, BACNET, CEPOA SPECIFIC
...AM#2
c. Section 28 31 76.02 10 Interior Fire Alarm and Mass Notification
System (FA/MNS)
1.4.2 INITIAL CONFIDENTIALITY - INTEGRITY - AVAILABILITY ASSESSMENT
Existing NIST FIPS 199 Confidentiality- Integrity- Availability (CIA) impact ratings for the control systems (CS) to be modified under this work are as indicated in the table below.
SECTION 01 91 10.02 29 Page 4
EXISTING LRDR CS Confident-iality Integrity Availability
BMS MC Low Moderate High
AM#2... ...AM#2
FA/MNS Low Low Low
Initial determinination of NIST FIPS 199 Confidentiality- Integrity- Availability (CIA) impact ratings for the control systems (CS) for work added are as indicated in the table below. These will be refined with the Authorizing Official (AO) and supporting RMF team during Step 1 of the RMF process. Note systems with "MC" suffix are considered Mission Critical. Contractor is responsible for coordinating with the Government Authorizing Official and the Contracting Officer for obtaining the system authorizations as defined herein and operating the system(s) until government turnover following Construction Completion Date. Contractor shall group component(s) with protection/control into as few RMF packages as practical for each system; all component(s) with protection/control shall be included in a single RMF package. Lists of hardware and software shall be provided for each RMF package. Final values shall not be higher than those determined under the CP1 Security Planning as described above.
LRDR CS Confident-iality Integrity Availability
BMS MC Low Moderate Low
AM#2... ...AM#2
FA/MNS Low Low Low
Each of the above system's cabling, CS infrastructure and equipment shall include an integrated RMF solution in accordance with all applicable regulations and directives to obtain a favorable Authority to Operate (ATO), as well as an Authority to Connect (ATC) to any MDA or Air Force networks. The Contractor shall provide all documentation and information required to obtain a favorable Assess and Authorize (A&A) decision. To meet the RMF requirements the Contractor shall complete the Security Authorization Package (SAP), and receive a favorable A&A, an ATO, and an ATC for the system.
1.4.3 Cybersecurity
Risk Management Framework shall be developed, manufactured, delivered and maintained in accordance with DODI 8500.01 , DODI 8510.01 , DODI 8581.01 , DODI 8530.01 , NIST SP 800-53 Rev 4 , NIST SP 800-147 and MDA 8500.02-P requirements. The contractor shall integrate all applicable cybersecurity requirements into the systems engineering requirements process to ensure early identification of and integration of cybersecurity into the system, including verification methods. The Contractor shall configure system components in accordance with applicable DISA STIG and NSA SCG. The Contractor shall provide assessment of RMF Equipment submitted under the control systems and evidence of compliance in accordance with
SECTION 01 91 10.02 29 Page 5
NIST SP 800-23 and MDA RMF guidance. The Contractor shall stay aware of current/changing cybersecurity requirements to ensure the final system meets current requirements and thus capable of receiving an Authorization to Operate (ATO). Assessment and authorization recommendations will be based on the resolution or mitigation of all identified findings to an acceptable level of risk per the Authorization Official (AO).
1.4.3.1 Computer Network Defense
The Contractor shall extend the existing design and implementation of an MDA approved cybersecurity infrastructure to protect the confidentiality, integrity and availability of RMF and supporting systems and shall ensure the successful interconnection with a DoD-approved Computer Network Defense Service Provider (CNDSP) to meet mandatory Tier 2 CND monitoring and reporting requirements.
1.5 QUALIFICATIONS
Contractor shall employ an coordinate and integrate with the CP1 RMF system designer or team . The CP1 RMF Contractor's Information System Security Manager (ISSM) and Lead Designer shall have a minimum of seven
(7) years of documented experience (or IAT Level III certification) in the design and implementation of RMF and information assurance for DoD control, security and fire alarm systems. The existing RMF team member will continue to have External Certification Authority (ECA) for entry and access to information as noted in this specification. Provide confirmation of Construction Package 1's ISSM and Lead Designer RMF Experience is being used for approval.
1.5.1 Cybersecurity Training
All contractor personnel performing IA/Cybersecurity duties and responsibilities as either a primary or as an additional/embedded duty, to include system or network privileged users, shall meet the training, certification, and reporting requirements in accordance with DODM 8570.01-M Change 3 Information Assurance, Training, Certification and Workforce Management Instructions.
1.6 WARRANTY
Warranty does not start until Authority to Operate the CP2 additions is given by the AO.
1.7 DEFINITIONS
1.7.1 Computer
As used in this Section, a computer is one of the following:
a. a device running a non-embedded desktop or server version of Microsoft Windows
b. a device running a non-embedded version of MacOS
c. a device running a non-embedded version of Linux
d. a device running a version or derivative of the Android OS, where Android is considered separate from Linux
SECTION 01 91 10.02 29 Page 6
e. a device running a version of Apple iOS
1.7.2 Network Connected
A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).
Any device that supports wireless communication is network connected, regardless of whether the device is communicating using wireless .
1.7.3 User Account Support Levels
The support for user accounts is categorized in this Section as one of three levels:
1.7.3.1 FULLY Supported
Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.
1.7.3.2 MINIMALLY Supported
Device supports a small, fixed number of accounts (perhaps only one).
Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "user name and password" structure).
1.7.3.3 NOT Supported
Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.
1.7.4 User Interface
Generally, a user interface is hardware on a device allowing user interaction with that device via input (buttons, switches, sliders, keyboard, touch screen, etc.) and a screen. There are three types of user interfaces defined in this Section: Limited Local User Interface, Full Local User Interface and Remote User Interface. In this Section, when the term "User Interface" is used without specifying which type, it refers only to Full Local User Interface and Remote User Interface (NOT to Limited Local User Interface).
1.7.4.1 Limited Local User Interface
A Limited Local User Interface is a user interface where the interaction is limited, fixed at the factory, and cannot be modified in the field.
The user must be physically at the device to interact with it.
Examples of Limited Local User Interface include thermostats (Space Sensor Modules as defined in Section 23 09 13 INSTRUMENTATION AND CONTROL DEVICES
FOR HVAC).
SECTION 01 91 10.02 29 Page 7
1.7.4.2 Full Local User Interface
A Full Local User Interface is a user interface where the interaction and displays are field-configurable.
Examples of a Full Local User Interface include local applications on a computer and user interfaces to Variable Speed Drives .
1.7.4.3 Remote User Interface
A Remote User Interface is a user interface on a Client device allowing user interaction with a different Server device. The user need not be physically at the Server device to interact with it.
1.8 CYBERSECURITY DURING CONSTRUCTION
In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.
1.8.1 Contractor Computer Equipment
Contractor owned computers may be used for construction. When used, contractor computers must meet the following requirements:
1.8.1.1 Operating System
The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be current on security patches and operating system manufacturer required updates.
1.8.1.2 Anti-Malware Software
The computer must run anti-malware software from a reputable software manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. All computers used on this project must be scanned using the installed software at least once per day.
1.8.1.3 Passwords and Passphrases
The passwords and passphrases for all computers must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.8.2 Temporary IP Networks
Temporary contractor-installed IP networks may be used during construction. When used, temporary contractor-installed IP networks must meet the following requirements:
1.8.2.1 Network Boundaries and Connections
The network must not extend outside the project site and must not connect to any IP network other than IP networks provided under this project or
SECTION 01 91 10.02 29 Page 8
Government furnished IP networks provided for this purpose. Any and all network access from outside the project site is prohibited.
1.8.3 Government Access to Network
Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this specification
1.8.4 Temporary Wireless IP Networks
In addition to the other requirements on temporary IP networks, temporary wireless IP (WiFi) networks must not interfere with existing wireless network and must use WPA2 security. Network names (SSID) for wireless networks must be changed from their default values.
1.8.5 Passwords and Passphrases
The passwords and passphrases for all network devices and network access must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.8.6 Contractor Temporary Network Cybersecurity Compliance Statements
Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf . Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.
PART 2 PRODUCTS
2.1 CONTROL SYSTEM INFORMATION PROCESSING EQUIPMENT
Information processing equipment provided for each CS shall be suitable for selected security controls with products in accordance with guidelines of NIST SP 800-23 , NIST SP 800-147 matching CP1 installed equipment of similar functionality or otherwise approved through evaluation and testing as described in UFC 4-010-06 acceptable to the control system AO. Submit information processing equipment documentation for each RMF package as part of the Draft Modifications to CP1 Security Plan.
a. BMS Information Processing Equipment
AM#2... ...AM#2
c. FA/MNS Information Processing Equipment
PART 3 EXECUTION
3.1 RMF PROCESS REQUIREMENTS
The design requirements for items listed above under RISK MANAGEMENT FRAMEWORK shall follow the the procedure in NIST SP 800-37 Rev 1 and UFC 4-010-06 . as outlined in this Section.
The Contractor shall design and implement an MDA approved ICS
SECTION 01 91 10.02 29 Page 9 infrastructure in accordance with NIST SP 800-82 Rev 2 to protect the confidentiality, integrity and availability of RMF and supporting systems and shall ensure the successful interconnection with a DoD-approved Computer Network Defense Service Provider (CNDSP) to meet mandatory Tier 2 CND monitoring and reporting requirements.
3.1.1 Step 1 - Categorization of Control System Information Systems
The Contractor shall in coordination with the Construction Package 1 RMF contractor and Government's Information System Owner (ISO) and Authorizing Official (AO) support refinements in categorization IAW NIST FIPS 199, CNSSI 1253 and NIST SP 800-82 Rev 2 of the CS and document the results of the security categorization in the security plan. The Contractor may use the Department of Homeland Security Cyber Security Evaluation Tool or similar method to assist in the refinement process of the CP1 categorizations. The RMF contractor shall lead the categorization meetings with Contracting Officer, ISO and UR, and the Information System Security Manger (ISSM) as requested to support security categorization.
The Contractor shall distribute meeting minutes of each all meetings including final collection of RMF Categorization Meeting Minutes within a week of each meeting.
3.1.1.1 RMF Roles
Identification and assignment of RMF Team members is a collaborative process involving all relevant stakeholders, to include the Contractor, which may interact with the system throughout its lifecycle. The Contractor and Client will have similar roles as noted in the list below, where Contractor equivalent role for development of the RMF are noted.
The Contractor in coordination with Contracting Officer and ISO shall ensure that the RMF Team positions are properly identified and listed in the Security Plan. The RMF Team includes:
RMF Role Government Personnel Role
RMF Sub-Contractor Role
Component Chief Information Officer (CIO) X Supporting
Component Senior Information Security Officer
(SISO)
X Supporting
Authorizing Official (AO) X
Authorizing Official Designated Representative
(AODR)
X
Security Control Assessor (SCA) X Supporting
Information System Owner (ISO) X Initial representative until
Government Acceptance
Program Manager or System Manager (PM/SM) X Supporting
Information System Security Manager (ISSM) X
SECTION 01 91 10.02 29 Page 10
RMF Role Government Personnel Role
RMF Sub-Contractor Role
Information System Security Officer (ISSO) X
RMF Specialty Designer(s) X
CS Vendor/Integrator Subject Matter Expert X
User Representative (UR) X
3.1.1.2 NIST FIPS 199 / CNSSI 1253 Security Categorization
The Contractor shall ensure that a written subsection of the security plan covers NIST FIPS 199 / CNSSI 1253 Security Categorization and Threat Assessment documenting agreed final C-I-A impact values and identification of RMF packages covering one or more CS. The government will provide a C-I-A concurrence memorandum agreeing with the determination of impacts.
3.1.1.3 Initiate the Security Plan(s)
The Contractor shall in collaboration with the control system ISO(s) initiate and develop a comprehensive modification to the existing CP1 Security Plan(s). Each modified Security Plan provides an overview of the security requirements, description of each CS (including system boundary) and describes the security controls in place or planned for meeting those requirements for the expanded systems.
3.1.1.4 System Registrations
The ISO is responsible for registering each modification of RMF Package;
Initiating an Enterprise Mission Assurance Support Service (eMASS)entry and receiving a unique ID for each RMF Package for the project. The Contractor shall coordinate with Contracting Officer to obtain an eMASS account. The Contractor will be required to submit a completed DD Form 2875 and complete the eMASS Computer Based Training (CBT) (https://disa.deps.mil/ext/cop/iase/emass/Pages/training.aspx). Access to eMASS will require the Contractor to have a valid security clearance and access to SIPRnet through MDA facilities.
The RMF Contractor shall record the eMASS Identification ID in the System Identification field within the Security Plan.
3.1.2 Step 2 - Selection of CS Security Controls
3.1.2.1 RMF Control Selection
The Contractor in coordination with the RMF Team shall select the Security control baselines based upon impact levels for each control system from NIST SP 800-53 Rev 4 and NIST SP 800-82 Rev 2 . Conduct appropriate tailoring of the selected set of security controls to include;
Supplementing the tailored baseline security control set, identification of Inherited Common / Hybrid Security Controls, and documenting the Final Security Control Set to be approved in the Final Security Plan.
Select NIST SP 800-53 Rev 4 (note: NIST SP 800-82 Rev 2 Industrial Control Systems Security Guide, Appendix G ICS Overlay will be used to evaluate control systems and will be programmed into eMASS. Until that happens, the
SECTION 01 91 10.02 29 Page 11
EI&E NIST SP 800-82 Rev 2 ICS Overlay Security Controls and EI&E NIST SP 800-53 Rev 4 and 800-82 Rev 2 merge found at (https://rmfks.osd.mil/) shall be used manually to complete the security controls until the eMASS functionality is available.
The Contractor shall ensure that the CP1 and additional selected set of security controls, along with the supporting rationale for selection decisions and any system use restrictions, are included the security plan.
The security plan must also, identify all common controls inherited from external providers, and establish minimum assurance requirements for those controls.
The Contractor shall categorize and identify Control Correlation Items (CCIs) as one or more of the following categories as described in
UFC 4-010-06 :
a. DoD-Defined: Either the DoD has provided a value for the "organization selected" values, or the DoD implementation guidance states that the CCI is already met by existing policy or regulation. These values are defined in the CCI list obtained from the RMF Knowledge Service.
b. RMF Designer: The designer has a role to address for the CCI. Either the designer needs to provide design specifications to cover a requirement for the control system itself and/or the designer must provide input to others within the Contractor team regarding the implementation or lack of feasibility of the CCI.
c. Non-Designer: The CCI is beyond the responsibility of the designer, and is the responsibility of someone else, such as a standard operating procedure.
d. Platform Enclave: The CCI contains a requirement which is expected to be implemented at the Platform Enclave and inherited by the control system, or is mostly implemented at the Platform Enclave but also needed within the field control system.
e. Impractical: The CCI is impractical to fully implement in a control system, but may be applied in a limited manner to a least some part of the control system.
3.1.2.2 Continuous Monitoring Strategy
The Contractor with coordination through the ISO shall develop a system-level strategy for the continuous monitoring of the CS. The system-level continuous monitoring strategy is a mandatory requirement to be included in the Security Plan
3.1.2.3 Draft Modifications to CP1 Security Plan
Upon Contractor completion of adjustments to eMASS input sheets ready for security control selection within eMASS, the Security Plan can be generated. The Contractor shall provide a Draft Modifications to CP1 Security Plan(s) by providing eMASS input forms with sufficient information to understand the intended or actual implementation of each security control employed within or inherited by the CS from a common control provider. By approving the security plan, the AO agrees to the system categorization, the set of security controls proposed to meet the security requirements for the system, and the adequacy of the system-level continuous monitoring strategy.
SECTION 01 91 10.02 29 Page 12
The Security Plan shall also contain supporting appendices (or placeholders for further development) or as references to appropriate sources, other risk and security-related documents such as but limited to a(n):
a. Risk Assessment.
b. Privacy Impact Assessment.
c. System Interconnection Agreements (if applicable).
d. Security Controls including:
1. The final classification of each of the CCIs.
2. The changes to standard CCI requirements along with an explanation of the changes.
3. The Control Correlation Items CCIs which have been incorporated into the control system design. Document changes from standard requirements, or selections made when multiple options are available.
4. Information for others as required.
e. Continuous Monitoring Strategy.
3.1.3 RMF Step 3 - Implement CS Security Control(s)
3.1.3.1 Internal Security Control Self-Assessment Plan
The Contractor shall develop, review, and submit any revisions to internal security control assessment plan(s) using eMASS generated template to internally assess the selected system-level security controls.
The plan should include identification of assessment testing logistics, vulnerability scanning tools (i.e. ACAS, SCAP, SRG, etc…), roles and responsibilities, detailed test plans, etc. See paragraph TESTING for additional requirements.
The Contractor shall identify the specific section (using document section name) that satisfies each actionable item for each CCI. For example "…in the SystemName System Security Plan, section/paragraph (Account Control, Purpose & Scope)…" vice "…in the SSP…"
The Contractor shall address each actionable item in each CCI for the Selected Security Controls determined by the RMF Team in RMF Step 2- Select Security Controls.
3.1.3.2 Internal Security Control Self-Assessment (Scan/Fix/Scan testing and Analysis
The contractor shall assess (scan and perform checks) control system's components using approved cybersecurity scanning tools and applicable manual checks utilizing DISA Security Technical Implementation Guides (STIG) as described within the Internal Security Control Self-Assessment Plan. See paragraph TESTING for vulnerability testing requirements. If vulnerabilities are found (Category (CAT) 1, 2 or 3) as the result of automated scans and manual checks, the Contractor shall remediate, mitigate, and or provide technical rationale as to why the vulnerability cannot meet compliance requirements. Upon completion vulnerability resolution, the Contractor shall rescan the CS utilizing the same methods as previously stated to ensure all vulnerabilities have been properly remediated and/or properly and acceptably mitigated or documented as an open vulnerability. The Contractor shall strive to mitigate and or remediate all vulnerabilities associated with the CS to greatest extent possible. CAT 1 and High Risk CAT 2 vulnerability findings that cannot be
SECTION 01 91 10.02 29 Page 13 remediated or mitigated to a lower acceptable risk as determined by the AO, are to be reported to the government with supporting rationale, and properly identified on the Initial Plan of Actions and Milestones (POA&M).
The results of the Internal Security Control Self-Assessment shall be documented within eMASS by the SO with support from the Contractor.Submit the results as a non-classified summary of the eMASS Internal Security Control Self-Assessment(s) under FOUO requirements.
The Contractor shall support the ISO as necessary in associating a system-level artifact (in eMASS) with each CCI when the artifact is used to support test results from the Internal Security Control Self-Assessment. The contractor shall use the artifact name in the test results for example: "Documented in the SystemName System Security Plan…" vice "Documented in the SSP…"
The Contractor shall identify the specific section (using document section name) that satisfies each actionable item for each CCI. For example "…in the SystemName System Security Plan, section/paragraph (Account Control, Purpose & Scope)…" vice "…in the SSP…"
The Contractor shall address each actionable item in each CCI for the Selected Security Controls determined by the RMF Team in RMF Activity 2- Select Security Controls.
Upon completion of the Internal Security Control Self-Assessment the Contractor shall assist Contracting Officer and the ISO to support the scheduling of the Government's Assessment prior to Authorization to Operate and Connects.
3.1.3.3 Security Plan Update
Upon Contractor completion of RMF Step 3, the Contractor shall update the eMASS Security Plan and submit notification of update completionwith any updates to previous and new information to include, but not limited to, the following system-level documentary RMF artifacts within the deliverables as required:
a. Risk Assessment, updates
b. Privacy Impact Assessment, updates
c. System Interconnection Agreements, updates (if applicable)
d. Continuous Monitoring Strategy, updates
e. Configuration Management Plan
f. Contingency Planning
1. Disaster Recovery Plan
2. IT Contingency Plan
3. Continuity of Operations Plan
4. System Restoration Checklist
g. Security Configurations
1. System Architecture / Network Topology / Data Flow depicting CS
Authorization Boundary
2. Hardware Inventory List
3. Software Inventory List
4. Ports, Protocols, and Services (PPS) List in accordance with DoD
PPS Category Assurance List (CAL)
h. Physical Security Plan
i. Information Assurance Vulnerability(IAVM)/Patch Management Plan
SECTION 01 91 10.02 29 Page 14
3.1.3.4 Authority to Test
A successful Internal Security Control Self-Assessment shall be deemed necessary to allow the control system to be tested within the system's capability without interconnecting to remote resources or MDA/AF networks.
3.1.4 RMF Step 4 - Assess Security Control(s)
3.1.4.1 Government RMF Controls Validation Test (CVT)
The Contractor shall be available as needed to assist the combined MDA/Air Force's (Government's) RMF CVT Team for the duration of the assessment(s). The normal duration of an assessment is typically 3-5 working days (on-site) for the scans, document review, and manual checks.
It typically takes an additional 30 days (off-site) for the Government team to perform analysis and provide the requisite reports. The contractor shall plan its schedule accordingly to effectively capture these events and the associated timelines to complete.
3.1.4.2 Security Assessment Results & Remediation Actions
The Contractor shall upon receipt of the Security CVT Results conduct remediation actions based on the findings and recommendations of the Government's team. Receipt of the Corrected Final Security CVT Results should be delivered to the Contractor no later than 30 days after RMF CVT
3.1.5 RMF Step 5 - Authorize Control System(s)
3.1.5.1 Plan of Action and Milestones (POA&M)
The Contractor shall prepare and submit the POA&M based on the findings and recommendations of the Security Control Assessment Results. The Contractor shall create a vulnerability and one milestone for every non-complying control in the POA&M module of eMASS for Security Control Assessor-Representative (SCR-R) use in performing final residual risk analysis. The Contractor shall allot 45 days for POA&M development and 15 days for review and approval.
3.1.5.2 Security Authorization Package
Upon approval of the POA&M the Contractor shall assist the ISO in submission of the Security Authorization Package via eMASS into the Package Approval Chain (PAC) for review and approval. Unclassified notification of submission will be provided to the Government outside of eMASSS. The PAC is tiered approval process in which the Security Authorization Package goes through multiple levels of approval by the PAC.
The Security Authorization Packages will include:
a. System Security plan
b. Security Control Assessment Report
c. Plan of Action and Milestones
d. Continuous Monitoring Plan
The Security Authorization Package goes through multiple levels of approval. If during the Initial Review the SCA-R identifies there is insufficient information or missing data or artifacts, the package must be returned for rework. The Contractor shall support resolving any issues related to rework within scope as directed by the Contracting Officer. The Contractor shall allot for 25 days for the review prior to submission to
SECTION 01 91 10.02 29 Page 15 the AO for the final Security Authorization Determination.
3.1.5.3 Security Authorization Determination (ATO)
The AO makes the final approval decision in the 6th level of the PAC, the Contractor shall allot 45 days for the final AO Security Authorization Determination i.e. ATO. Submit notice of ATO by the AO shall be submitted to
3.1.5.4 Authority to Connect (ATC)
Upon receipt of the final Security Authorization Determination (ATO), the Contractor shall assist the ISO in obtaining ATC via MDA network service provider, if required.
3.1.6 RMF Step 6 - Monitor Security Controls
The Contractor shall maintain the CS's Security Controls in accordance with the Continuous Monitoring Plan between ATO and Construction Completion Date or Government Maintenance if it should occur before Construction Completion Date.
3.1.6.1 IAVM/CTO Activities
The Contractor shall assess Government IA Vulnerability Notices (IAVNs) and Command Tasking Orders (CTOs) to determine system applicability and shall develop plans and implement product vendor patches and other mitigations in support of IAVM as approved by MDA during this monitoring period. The Contractor shall report IAVM and CTO status to the Government ISSM on a weekly basis.
3.2 Coordination of RMF activities with Contract Completion
The Contractor shall include the following and other information on review durations in this specification in their Construction Schedule.
a. The Internal Security Control Self-Assessment documentation in eMASS and submittal should occur no later than 5 months prior to the scheduled completion of Step 3 for each CS. This submittal forms the basis for the Assessment and Authorization (ATO Approval Package) request.
b. Contractor shall coordinate on-site inspections no less 90 days before testing is required.
c. Interim ATO must be received prior to completion of Commissioning or similar Government Acceptance Testing such as required for Fire Alarm AM#2... ...AM#2 Systems.
3.3 TESTING
3.3.1 General Requirements for Testing
Provide personnel, equipment, instrumentation, and supplies necessary to perform site testing. The Government will witness all performance verification and certification testing. Written permission shall be obtained from the Government before proceeding with the next phase of testing. Original copies of all data produced during performance verification and endurance testing, shall be turned over to the Government at the conclusion of each phase of testing, prior to Government approval
SECTION 01 91 10.02 29 Page 16 of the test
3.3.2 Vulnerability Assessment and Asset Testing
Once the Contractor has started control systems and pre-ATO testing, the Contractor shall conduct monthly cybersecurity vulnerability assessment scans for the initial and all subsequent strings utilizing the Assured Compliance Assessment Solution (ACAS) DoD toolset current at the time the scan is performed. Download the ACAS DoD toolset from DISA.mil patch repository at: https://patches.csd.disa.mil/CollectionInfo.aspx?id=442 (DoD issued ECA or CAC is required). At the time the scan is performed, the Contractor shall request the MDA Sensors Information System Security Manager (ISSM) provide software and required licenses.
Resulting data shall be made available via secure methods for Government review and analysis. The Contractor shall provide technical, Systems Administrator (SA), and Network Administrator (NA) expertise for execution of Government-conducted Security Control Assessment (SCA), Penetration Testing, and Interface Boundary (IFB) Tests. The Contractor shall participate in pre-SCA coordination meetings, post-test analysis, Assessment and Authorization Technical Interchange and Risk Assessment Meetings, and Plan of Action & Milestone (POA&M) maintenance activities.
-- End of Section --
SECTION 01 91 10.02 29 Page 17
File details come from the government source that posted it.