CCRI Services Question Set 2.pdf
PDF 103 KB Posted
- Attached to
- Command Cyber Readiness Inspection Services Federal contract opportunity
- Solicitation number
- W911YN20Q0007
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CCRI Services Question Set 3.pdf | ||
| W911YN20Q000702 CCRI Amend 02.pdf | ||
| W911YN20Q000701 CCRI Amend 01.pdf | ||
| CCRI Services Question Set 1.pdf | ||
| W911YN20Q0007 CCRI Prep.pdf | ||
| PWS CCRI 10Jan20.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
W911YN-20-Q-0007
Command Cyber Readiness Inspection Services
Question Set 2
Certification Question:
Q.1) Team Lead Requirements - CCRI DISA certified TL, Tenable TCNAcertified, and CISSP Can the above requirement be substituted with a person with a CISSP, Security+, Master Resiliency certifications who has done over dozens of these CCRI audits with experience in scanning tools such as Nessus, SCAP, ACAS, SCC?
A.1) Only personnel with DOD 8570 approved baseline certifications Level II or higher. Needs experience in scanning tools such as NESSUS, SCAP, ACAS, and SCC
Q.2) Traditional/PhysicalSecurity Inspector Requirements –ASIS Physical Security professional (PSP) and/or SAPPC certified
a) Can this requirement be met with a CISSP, Tripwire, NERC CIP who did Physical Security Assessment for PGE + 30K Devices?
A.a) No
b) If not, then can this person be remote only if he has the ASIS (PSP) certification and guide the person onsite? Below is the qualification of this person:
A.b) Absolutely no remote access. Must be on site
* ASIS Physical Security Professional (PSP) Cert. No. 18444
* National Institute for Certification in Engineering Technologies (NICET) Level IV -- Fire Alarm Systems (Highest level obtainable) Cert. No. 93111
c) Network Infrastructure Inspector Requirements - DISA CCRI Certified Network Security Reviewer.
Can this person be replaced with a CCIE/CCNA person with STIG experience and will follow Team Lead’s guidance in collecting the technical data needed for the CCRI audit?
A.c) This person can be onsite. Only personnel with DOD 8570 approved baseline certifications Level II or higher. Needs experience in scanning tools such as NESSUS, SCAP, ACAS, and SCC
Q.3) Web/Database Inspector Requirements - DISA CCRI Certified Senior WEB, Database, Windows AD and DNS Server Reviewer.
Can this person be replaced with a MCSE person with STIG experience and will follow Team Lead’s guidance in collecting the technical data needed for the CCRI audit?
A.3) MCSE NO. Someone with STIG experience and DOD 8570 Level II certification
Q.4) HBSS/ACAS Inspector Requirements - DISA CCRI Certified HBSS/Windows
Workstation Security Reviewer.
a) can this person be remote only and provide guidance to the onsite who can conduct this audit?
A.a) No this person must be on-site
b) or can this person be the Team Lead who’s profile summary has been provided in Question 1 above? If so, this will save on having an additional staff member.
A.b) No. Team Lead will be busy with the G6 and the ISSM. This person will be actively working with his counter-partner
c) If not any of the above, can this person be a MCSE/CCIE/CCNA with STIG experience to conduct the CCRI audit following the Team Lead’s guidance?
A.c) Only personnel with DOD 8570 approved baseline certifications Level II or higher.
need experience in scanning tools such as NESSUS, SCAP, ACAS, and SCC
Q.5) Wireless/VOIP Inspector Requirements – DISA CCRI Certified Wireless/VOIP Can this person be a CCIE/CCNP/CCNA with STIG experience to conduct the technical audit following the Team Lead’s guidance?
A.5) This person can be onsite. Only personnel with DOD 8570 approved baseline certifications Level II or higher. Needs experience in scanning tools such as NESSUS, SCAP, ACAS, and SCC.
END OF QUESTION SET 2.
File details come from the government source that posted it. Updated .