CCRI Services Question Set 3.pdf

PDF 85 KB Posted

Attached to
Command Cyber Readiness Inspection Services Federal contract opportunity
Solicitation number
W911YN20Q0007
Issued by
Department of the Army Florida Army National Guard

View the file

Other files for this federal contract opportunity

Other files attached to Command Cyber Readiness Inspection Services, newest first.
File Type Posted
W911YN20Q000702 CCRI Amend 02.pdf PDF
CCRI Services Question Set 2.pdf PDF
W911YN20Q000701 CCRI Amend 01.pdf PDF
CCRI Services Question Set 1.pdf PDF
W911YN20Q0007 CCRI Prep.pdf PDF
PWS CCRI 10Jan20.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

W911YN-20-Q-0007

Command Cyber Readiness Inspection Services

Question Set 3

Certification Questions:

Q.1) Which category should we follow (i.e., IAT Level II, IAM Level II or IASAEII..Etc.?) . In other words, a team member who has CCNA Security or a CISSP certification is qualified based on IAT Level II, IAM Level II, and IASA II certification listed above table? (Provided that they have experience with tools such as NESSUS, SCAP, ACAS, and SCC.)

A.1): IAW DoD 8140 and 8570.01M, each category of Information Assurance Workforce is separate and distinct and have their own levels and certification requirements, this is the Baseline Certification requirement. Level II is different in each of the categories (IAM, IAT, IASE, CND-T, Etc.). For an IAM (Information Assurance Management) Level II, CISSP is one of the appropriate Baseline Certifications.

The IAM categories is for those who manage networks and environments, thus CISSP-which is at its heart a management centric security certification.

IAT (Information Assurance Technology) Level II is the technical "doer" or 'knob turner". Thus, they should have CCNA Security or SEC+ to demonstrate their ability to operate with a basic understanding of Cybersecurity. IAT Level II does not correlate to an IAM Level II nor to the other categories.

For this contract, those with CISSP should suffice since it meets the Baseline Certification for IATIII, IAMII and IASEII. CCNA Security would also be appropriate.

Q.2) Regarding the tools, can a team member qualify if they meet some of the scanning tools listed:

NESSUS, SCAP, ACAS, and SCC, say if they have experience with NESSUS, SCAP and other scanning tools such as nmap, OWASP, HBASS, STIG, Kali Linux, metasploit,.etc.

A.2) The Baseline Certification basically demonstrates a person can operate as a manager or technician in a secure manner. Most Statements of Work that I have seen do require some basic Baseline Certification from the contractors. Further training or certifications (outside the Baseline Certification) is needed to show proficiency with an application, environment, system, etc. Army usually terms these Computing Environment Certifications/Training or Specialized Training. Training/Certifications such as Splunk Engineer, Kali Linux, OCSP, Tanium Engineer, HBSS, etc..., would meet this requirement based on the scope of work required (which I have not seen).

Hours questions:

Q.3) Can the team lead just work on site for one week and try to put as many hours and get as much done as possible during the one week process? I understand 72 hours have been allocated to the team lead and if all work can't be done during the one week, can he finish the rest remotely?

A.3) 72 hrs was historical data, We think whole process to do the CCRI should not take any longer than a week, Two weeks at the most. The team needs to be onsite just like a real CCRI inspection is conducted.

Q.4) Can the Team Lead provide the audit for 40 hours on site and the rest (32 hours) remote? I understand 72 hours were used by the team lead previously and the remote work might be mainly to run and put together reports. All the other team members will be on site.

A.4) They need to be looking over the shoulder of the Technician to review the configuration files.

Remote connectivity is not an option. If the team needs additional hours to put together reports, they can do that remotely or onsite.

Also See Question set 2 number 2B & 4A.

Clarification on PWS:

Section 1.1 Scope paragraph 4 mentions “Historical level of effort of 72 hours.

This is not the mandatory time to complete, and you must propose your best solution.

Section 1.3 period of performance of 8-10 working days:

This should have also stated the Florida Army Guard work an alternate work schedule of 5/4/9 with every other Monday Flex day off.

End of Question Set 3

File details come from the government source that posted it. Updated .