SECURITY SERVICES BPA

Size: px
Start display at page:

Download "SECURITY SERVICES BPA"

Transcription

1 PROGRAM SUPPORT CENTER SECURITY SERVICES BPA ORDERING GUIDE VOLUME 1

2

3 SECURITY SERVICES BPAORDERING GUIDE Overview The Program Support Center s (PSC s) Blanket Purchase Agreement (BPA) is intended for use by federal government agencies. This ordering guide provides helpful information for acquiring physical and logical security products and services and defines the roles and responsibilities of the parties involved in PSC s ordering process. Questions about the BPA and ordering procedures should be directed to: Contracting Officer Donald Hadrick Please visit for more information about contracting security consulting, program and project management, and other security-related services. FEES AS LOW AS 1.5% EXPEDITED TASK ORDERS OUTSTANDING CONTRACTORS POINTS OF CONTACT Donald Hadrick Contracting Officer Branch Chief, Division of Acquisition Management donald.hadrick@psc.hhs.gov Joseph Pirrone Contracting Officer Branch Chief, Division of Acquisition Management Joseph.pirrone@psc.hhs.gov Patrick A. Joy Interim Head of Contracting Activity Procurement Analyst/Customer Liaison Acquisition Management Services (AMS) Patrick.Joy@psc.hhs.gov PSC Security Services BPA PSC Security Services BPA Ordering Guide Volume 1 1

4 PSC Security Services Table of Contents Overview...1 How to Use This Guide General Information About the PSC Scope of Functional Categories (FCs) Contract Team PSC Best Practices Roles and Responsibilities Program Support Center (PSC) PSC s Program Manager Customer PSC Contracting Officer Task Order Contracting Officer Contractor s Program Manager PSC Ordering Procedures...6 Appendix A:...7 Appendix B:...8 Appendix C:...10 Appendix D:...12 Appendix E:...13 Appendix F:...14 Appendix G:...15 Appendix H: Ordering Guide Volume 1 PSC Security Services BPA

5 How to Use This Guide Chapters 1 through 3 provide general information, roles and responsibilities, and Program Support Center (PSC) ordering procedures. Appendices A through F provide PSC s contractor agency list, specific task order procedures, a task order request package consisting of a checklist and instructions, a sample format for a Statement of Work (SOW), a template for a memorandum to PSC, and information specific to the U.S. Department of Health and Human Services (HHS) Operating and Staff Divisions (OPDIVs-STAFFDIVs). The information will help customers develop task orders and Contracting Officers evaluate the material accompanying a task order request. Appendices G and H are a technical glossary and an acronym list. 1.2 Scope of Functional Categories (FCs) The following Functional Categories (FCs) identify the security products and services offered by PSC. An individual task order may relate to a single FC or may involve services from multiple FCs. FC1: Infrastructure Engineering, Systems Design, Development, Procurement, Implementation, Integration, and Sustainment Security systems design, installation, and sustainment services Physical Access Control Systems (PACS): Public Key Infrastructure integration HSPD-12, FIPS 201, OSIPS, and NIST Special Publication compliant PSC Security Services BPA 1. General Information 1.1 About the PSC PSC is a leading-edge customer-focused, shared services organization, with a reputation for providing quick and easy access to high-quality security solutions at an unbeatable price. PSC.GOV = SMARTContracting Streamlined procurement Multidisciplinary security solutions Accelerated awards Reduced GSA rates Team of security experts Managed by the PSC, the BPA provides best value, mission-critical security products and services by offering pre-negotiated discounted GSA pricing. The services offered through the BPA include endto-end security solutions compliant with Homeland Security Presidential Directive 12 (HSPD-12) and support for development, deployment, operations and maintenance, and sustainment of security solutions and requirements. Biometric, personal identification verification (PIV), and mobile application development Networked video surveillance systems Intrusion Detection Systems (IDS) SCADA systems SCIF solutions Fire and safety systems Mass Notification System (MNS)/ Emergency Notification Systems (ENS) HVAC systems UL2050 certificated services and security monitoring capabilities Security construction and facility hardening Critical System Monitoring Communication systems (wireless and land mobile radio) Systems repair, maintenance and technical support Command and Dispatch Centers RFID Tagging and Tracking Systems FC2: Independent Test, Validation, Verification, and Evaluation Product assessment and validation / new technology evaluation Information assurance Certification and Accreditation (C&A) PSC Security Services BPA Ordering Guide Volume 1 3

6 PSC Security Services FC3: Security Risk Assessment Planning Security requirements analysis Planning and implementation of DHS Interagency Security Committee (ISC) compliant enterprise security risk assessments FC4: Management Support Services Program and Project Management Security program performance metrics management Policy and procedures development 1.4 PSC Best Practices The ordering guidelines contained herein are in concert with federal procurement best practices and focus on the following: Establishing simplified ordering procedures and award documentation Managing multiple task order awards with highly skilled, responsible contractor teams of industry experts (large, small, woman owned, etc.) who possess a wide variety of expertise Enterprise transformation Counter-terrorism expertise and training Continuity of Operations Planning (COOP) 1.3 Contract Team This BPA was awarded on October 28, 2010, as a result of an open and competitive General Services Administration (GSA) solicitation. The contract (GS-07F-0029M HHSP XB) awarded to Securityhunter is supported by the following subcontractors: PricewaterhouseCoopers, LLP Northrop Grumman Stanley Convergent Security Solutions CertiPath, LLC Tetra Tech Chugach Federal Solutions, Inc. Securityhunter is a Multiple Award Schedule 84 GSA contractor. Additionally, subcontractors offer goods and services available on GSA Multiple Award Schedules 58i, 70, and 84. Using these contracts will help to reduce the overhead associated with multiple acquisitions. In addition, aggregation of demand provides the government with purchasing leverage encouraging vendors to offer the best possible prices because of economies of scale. For specific capabilities of each teaming partner, see Appendix A. Scheduling periodic meetings between the PSC, the prime contractor team, and the customer to discuss administrative matters, future requirements, and any adjustments to the ordering process Ensuring accurate application of Section 508 Electronic and IT Accessibility Standards during all phases of a task order life cycle, from establishment of requirements to closeout 2. Roles and Responsibilities The following subsections describe the roles and responsibilities of the primary contracting Points of Contact (POCs) for matters regarding BPA administration. 2.1 Program Support Center (PSC) PSC manages the BPA and works closely with both the Contracting Officers and the prime contractor to oversee the issuance of task orders. Specifically, PSC is responsible for: Ensuring customers are aware of their responsibilities and the scope of products and services under the BPA Ensuring all task orders comply with the terms, conditions, requirements, specifications, details, and/or delivery schedules set forth in the BPA Addressing and satisfying the needs of all participants in the process Maintaining a level of program integrity that prevents contractual or programmatic problems Soliciting feedback and providing continuous process improvement 4 Ordering Guide Volume 1 PSC Security Services BPA

7 2.2 PSC s Program Manager PSC s Program Manager is the government s senior representative responsible for oversight and administration of the EPACS BPA. The government Program Manager has oversight and final approval authority for all government-sponsored, in whole or in part, improvement initiatives planned or formulated by participating PSC Service organizations and the contractor. In addition, the Program Manager s responsibilities include, but are not limited to, coordination and facilitation of government business development initiatives, evaluation of resultant outcomes including customer satisfaction and retention, and development of ensuing marketing and customer support initiatives. Assist in expediting orders Ensure compliance with contract requirements Issue a final decision and handle all contract-level contractual disputes under the Contract Disputes Act Issue all modifications against the contracts 2.5 Task Order Contracting Officer Task order Contracting Officers within the Strategic Acquisition Service, Division of Acquisition Management, shall order services via task orders following the ordering procedures set forth below. Their specific responsibilities include: PSC Security Services BPA 2.3 Customer The customer prepares the task order request, along with all relevant information, including the following: Statement of Work (SOW) (see Appendices C, D, and E for further instructions, a sample format for a SOW, and a memorandum template) Independent Government Cost Estimate (IGCE) Customer name, title, organization, telephone number, fax number, and address Proposal instructions (including proposal due dates) Other pertinent statutory or regulatory requirements, including applicable Section 508 requirements or exceptions Note: In certain circumstances, the customer may requisition PSC to support SOW development. 2.4 PSC Contracting Officer The PSC Contracting Officer has the overall responsibility for BPA contract administration. The Contracting Officer is the only person authorized to act on behalf of the government to amend, modify, or deviate from the BPA terms, conditions, requirements, specifications, details, and/or delivery schedules. The Contracting Officer is responsible for the overall administration and final closeout of the BPA, and when necessary, shall: Provide scope oversight Serve as liaison between the contractor and PSC Ensuring task orders are within the scope of the contract Determining the appropriate functional category or categories based on the predominant work to be performed under the task order (see Appendix B for a detailed scope of functional categories) Approving or withholding payment, or authorizing partial payment, of invoices Ensuring task order administration and final closeout Notifying PSC at the end of each fiscal year about which task orders awarded in the preceding fiscal year are closed and complete, including release of claims letters (if applicable) Task order Contracting Officers may designate trained, certified Contracting Officer s Technical Representatives (COTRs) to be responsible for day-to-day oversight and management of individual task orders. This work includes inspecting and accepting deliverables and providing input for past performance reports. 2.6 Contractor s Program Manager The contractor s Program Manager shall act as the central POC with the government for all BPA matters and shall represent the contractor at all post-award status meetings. The Program Manager shall resolve all technical and programmatic disputes and provide full customer support. The Program Manager is responsible for overall contractor response to and performance of task order requests and shall not serve in any other capacity under this contract. PSC Security Services BPA Ordering Guide Volume 1 5

8 PSC Security Services 3. PSC Ordering Procedures This section describes the procedures for ordering services through the BPA. The Appendices to this guide provide the PSC contractor with specific task order procedures and a task order request package consisting of a checklist and instructions, as well as sample format for a SOW, a memorandum template, resources, and a technical glossary. The ordering process is depicted in figure 1 and described below: f) Enterprise Architecture Board (EAB) Approval (if required) g) Investment Review Board (IRB) Approval (if required) h) Form DD 254 (if applicable) i) Proposal instructions, including due dates 2) PSC reviews SOW to ensure it is in line with the scope of work outlined in the BPA. 3) PSC requests complete cost and technical proposals from the prime contractor (prime). 4) Prime prepares task order response proposal based on SOW and or may engage customer to obtain additional technical information to fulfill the request.** 5) PSC reviews prime s response and presents to customer for adjudication. 6) Upon approval, task order is awarded and work commences. *See Appendix E for a memorandum template with instructions, to assist with submission of task order requests. **The amount of time allowed for the response is typically 10 days, which may be adjusted based on the scope or complexity of the requirement and the customer s needs. Figure 1 - BPA Ordering Process 1) Customer submits task order request* checklist (Appendix C) to PSC Contracting Officer. Checklist is accompanied by the following: a) SOW (required) b) IGCE c) Funding Document(s)/IAA/MIPR (electronic copy) d) Acquisition Plan or copy of Advanced Acquisition Plan e) Customer Agency CIO Approval (if applicable) 6 Ordering Guide Volume 1 PSC Security Services BPA

9 Appendix A BPA Prime Contractor Capabilities Securityhunter Targeting Security Solutions PSC Security Services BPA Program management Physical Security Subject Matter Experts (SMEs) Electronic security systems design, installation, and sustainment Public Key Infrastructure integration with Physical Access Control Systems Product assessment and validation Security systems design and installation Biometric, PIV, and mobile application development Physical security solutions Design, installation, and sustainment Nationwide technical support Planning and implementation of security risk assessment Experienced Homeland Security Presidential Directive 12 (HSPD-12) program management Counter-terrorism expertise and training Design and engineering services HVAC design and installation SCADA implementation Facility hardening General construction and management PSC Security Services BPA Ordering Guide Volume 1 7

10 PSC Security Services Appendix B PSC Task Order Procedures for Security Support Services The functional categories and task order types are described below. Description of PSC s Security Support Services Functional Categories (FC) The task order Contracting Officer shall determine under which functional area a task order request belongs. The Contracting Officer shall base this determination on the predominant work to be performed under the task order. PSC offers five functional categories of support and services, as listed below: Functional Category 1: Infrastructure Engineering, Systems Design, Development, Procurement, Implementation, Integration, and Sustainment SOLUTIONS Security systems design, installation, and sustainment services; Physical Access Control Systems (PACS): Public Key Infrastructure integration - HSPD-12, FIPS 201, OSIPS, NIST Special Publication compliant - Biometric, Personal Identification Verification (PIV), and mobile application development; Networked video surveillance systems; Intrusion Detection Systems (IDS); SCADA systems; SCIF solutions; Fire and safety systems; Mass Notification System (MNS)/Emergency Notification Systems (EMS); HVAC systems; UL 2050 certificated services and security monitoring capabilities; Security construction and facility hardening; Critical systems monitoring; Communication systems (wireless and land mobile radio); Systems repair, maintenance, and technical support; Command and Dispatch Centers; RFID tagging and tracking systems As ordered, the contractor shall provide any and all phases of systems design and development through deployment to ensure its security solutions will enable customers to achieve their mission, goals, and objectives. As ordered, the contractor shall provide any and all operations and maintenance (O&M) solutions, processes, and procedures necessary to sustain systems ordering activity at the highest levels of service consistent with availability, cost, schedule, and performance objectives. These solutions may be required across the HHS infrastructure, including, but not limited to, the following: Data Center, Help Desk and Field Support Services, and Security Operations. This functional category includes the full range of O&M solutions. Functional Category 2: Independent Test, Validation, Verification, and Evaluation SOLUTIONS Product assessment and validation/new technology evaluation - Information assurance - Certification and Accreditation (C&A) As ordered, the contractor shall provide the full range of independent test, validation, verification, and evaluation solutions to ensure all IT products and services meet HHS standards and are performing to defined design, cost, schedule, and performance specifications and capabilities. The contractor shall provide best practices, technologies, tools, and support for operational assessments, integration testing, and systems test and evaluation, including security C&A, for IT systems. The contractor shall also provide independent verification and validation by monitoring and evaluating projects through activities such as, but not limited to, assessments, process and procedure audits, project and performance management, and systems analysis and design. 8 Ordering Guide Volume 1 PSC Security Services BPA

11 Functional Category 3: Security Risk Assessment Planning SOLUTIONS Security Requirements Analysis - Planning and implementation of enterprise security risk assessment with Interagency Security Committee (ISC) compliance As ordered, the contractor shall provide all planning and administration of enterprise security risk assessments. The contractor shall conduct assessments using the most recent federal guidelines, such as those published by the DHS Interagency Security Committee (ISC). Results of all assessments shall be documented and a corrective action plan developed. The contractor shall track and compile all data for reporting purposes. PSC Security Services BPA Functional Category 4: Management Support Services SOLUTIONS Program and project management - Security program performance metrics management - Policy and procedures development - Enterprise transformation - Counter-terrorism expertise and training - Continuity of Operations Planning (COOP) As ordered, the contractor shall provide the full range of business and technical management services that assist with the development, implementation, and continuous improvement of policies, procedures, guidelines, and directives. All documents and guidance shall comply with customer agency and HHS requirements (policy, legal, and legislative). Services encompass IT policy and planning including, but not limited to, enterprise architecture, IT security, training, enterprise resource management, business process reengineering, IT transformation and strategy, organizational change management, and enterprise and program management office support, for example, business case development and performance management. Types of Task Orders Under PSC, the task order Contracting Officers may negotiate several types of task orders that differ in the degree of risk associated with costs of performance assumed by the contractor. The types of tasks include: firm fixed price, and time and materials. PSC Security Services BPA Ordering Guide Volume 1 9

12 PSC Security Services Appendix C Checklist for Task Order Request Package PSC TASK ORDER REQUEST CHECKLIST AND INSTRUCTIONS: This form constitutes a request for contract support under the PSC Security BPA. The requiring activity shall complete this form, together with the associated attachments, and forward the entire package to the PSC Contracting Officer, Donald Hadrick: donald.hadrick@psc.hhs.gov for processing. Project Title Security Services - Functional Categories (Select all that apply.) Functional Category 1: Infrastructure Engineering, Systems Design, Development, Procurement, Implementation, Integration, and Sustainment Functional Category 2 Independent Test, Validation, Verification and Evaluation Functional Category 3: Security Risk Assessment Planning Functional Category 4: Management Support Services Requiring Activity or Point of Contact Name: Title: Organization: 1. Task Order (TO) Title: Telephone No.: Fax No.: Address: Designated Task Order Contracting Officer s Technical Representative (COTR) Name: Title: Organization: Telephone No.: Fax No.: Address: 10 Ordering Guide Volume 1 PSC Security Services BPA

13 The complete package must include all of the items listed in this block, as required or applicable. Send files electronically via or fax to the task order Contracting Officer, Donald Hadrick: gov. All files shall be completed using Microsoft Word 2003 or higher. Independent Government Cost Estimate (IGCE) Acquisition Plan or copy of Advanced Acquisition Plan Customer Agency CIO Approval (if applicable) PSC Security Services BPA Enterprise Architecture Board (EAB) Approval (if required) Investment Review Board (IRB) Approval (if required) Task Order-Unique Form DD 254 Use only if security requirements exceed the basic contract Form DD 254. Statement of Work (SOW) (See Appendix D for format) All SOWs must include pertinent statute or regulation requirements and applicable Section 508 requirements or exceptions. Funding Document(s) Scanned or other electronic version is preferable. Recommended Contract Type (check one): Firm Fixed Price (FFP) (no justification required) Time and Materials (T&M) (provide justification below) T&M contracts require justification in accordance with Federal Acquisition Regulations (FARs). PSC Security Services BPA Ordering Guide Volume 1 11

14 PSC Security Services Appendix D Sample Format for a Statement of Work (SOW) (1) PROJECT TITLE: Provide a short, descriptive title of the work to be performed. (2) BACKGROUND: Provide a brief description/summary of the goods or services sought, and describe the need for the goods or services, the current environment, and the customer s mission as it relates to this requirement. (3) SCOPE: Indicate which PSC contract functional categories apply to the work to be performed. Include a high-level overview of the procurement, its objectives, size, and projected outcomes. Do not include anything that will not contribute to the expected result. Include impacts or implications. (4) APPLICABLE DOCUMENTS: List relevant legal, regulatory, policy, and security documents. Include publication number, title, version, date, where the document can be obtained, etc. State which specific portions of the documents apply. (5) SPECIFIC TASKS: Provide a narrative of the specific tasks that make up the SOW. Number the tasks sequentially, for example, Task 1: title of task and description and Task 2: title of task and description, etc. Describe in clear terms, using active language, what work will be performed. The requirement must be defined sufficiently for the contractor to submit a realistic proposal and for the government to negotiate a meaningful price or estimated cost. SOWs must be outcome-based ; that is, they must include the development and delivery of actual products (e.g., assessment report, procurement, systems design and/or installation, sustainment services, etc.). (6) DELIVERABLES AND DELIVERY SCHEDULE: List all outputs or outcomes with specific due dates or timeframes. Include media type, quantity, and delivery point(s). State due dates in terms of calendar days after task order award. (7) GOVERNMENT-FURNISHED EQUIPMENT AND INFORMATION: Identify the government-furnished equipment and information, if any, to be provided to the contractor, and identify any limitations on use. Be as specific as possible. (8) PLACE OF PERFORMANCE: Specify whether the work will be performed at the contractor s site or at a government site. Provide exact address, if possible. Describe any local or long-distance travel the contractor will be required to perform. (9) PERIOD OF PERFORMANCE: State the period of performance in total calendar days after task order award (e.g., 365 calendar days after award), or in start and end dates, for example, October 1, 20XX, through September 30, 20XX. (10) SECURITY: State whether the work will be UNCLASSIFIED, CONFIDENTIAL, SECRET or TOP SECRET. 12 Ordering Guide Volume 1 PSC Security Services BPA

15 Appendix E Task Order Request: Template for a Memorandum to PSC Customers may use the following memorandum template to assist with submission of task order requests. Contracting Officer: Donald Hadrick Telephone No.: PSC Security Services BPA Donald.hadrick@psc.hhs.gov The subject line of your Security Support Services Task Order Request Copy and paste the following: TO: Don Hadrick The purpose of this memorandum is to request issuance of a task order under the HHS Program Support Center s security support services BPA. All required documentation is provided as specified on the attached task order checklist. The point(s) of contact for this request is [insert name], who can be reached at [insert address] and/or [insert telephone number]. Sincerely, PSC Security Services BPA Ordering Guide Volume 1 13

16 PSC Security Services Appendix F Information for HHS Customers The applicable PSC Service Areas, that is, the Administrative Operations Service (AOS) and the Information System Management Service (ISMS), are available to work directly with customers and PSC prime contractors, throughout the acquisition process. These Service Areas provide assistance, support, and overall contract management or administration. As such, AOS and ISMS, guided by directives from other organizations, develop, employ, and promulgate procedures and templates that support those directives. PSC Contracting Officers are authorized task order Contracting Officers for purposes of this BPA. All warranted PSC Contracting Officers are available to conduct acquisitions on behalf of customers, in particular for those who do not have a contracting office or capability. Such actions shall be coordinated with AOS and ISMS. Upon request of the task order Contracting Officer, AOS and ISMS shall assist in creating the task order. AOS and ISMS can offer advice regarding one or more of the following issues: Applicability of the SOW with respect to scope Realism of the IGCE Appropriateness of the selected contract type (FFP vs. T&M) Adequacy of the justification used for the exception to the requirements for fair opportunity to be considered 14 Ordering Guide Volume 1 PSC Security Services BPA

17 Appendix G PSC Glossary This glossary is not intended to be a comprehensive list of acquisition terminology. These terms are commonly found within this ordering guide and are included for clarification. Best Value The expected outcome of an acquisition that, in the Government s estimation, provides the greatest overall benefit in response to the requirement. It involves the analysis of technical and cost proposals to determine which proposal offers the best trade-off between price/cost and performance, where quality is considered an integral performance factor. See Federal Acquisition Regulation (FAR) Part PSC Security Services BPA Firm Fixed-Price Contract A contract suitable for acquiring commercial items or for acquiring supplies or services on the basis of reasonable definite functional or detailed specifications, when the contracting officer can establish fair and reasonable prices at the outset. Independent Government Cost Estimate (IGCE) Assists the task order contracting officer in determining the reasonableness of a contractor s cost and technical proposals. The customer prepares the IGCE and submits it as part of the procurement request. It is for GOVERNMENT USE ONLY and should not be made available to the PSC contractors. Original Equipment Manufacturer (OEM) A producer/manufacturer that provides a product to its customers, who then proceeds to modify or bundle the product before distributing it to their customers. Service Level Agreement (SLA) A formal written agreement established between two parties: the contractor and the Government customer. It defines the expected level of services, the metrics associated with these services, acceptable and unacceptable service levels, and incentive awards for service levels exceeded and/or penalty provisions for services not provided. Statement of Work (SOW) A type of work statement that describes the need for the goods or services, the scope of work to be performed, applicable documents, specific tasks, deliverables and delivery schedule, Government-furnished property and information, place and period of performance, and security requirements. Task Order (TO) An order for services placed against an established contract or with Government sources. In the case of the PSC acquisition, TOs are orders for services placed against contracts awarded under the BPA. Time-and-Materials Contract A contract that provides for acquiring supplies or services on the basis of direct labor hours at specified fixed hourly rates; include wages, overhead, general and administrative expenses, and profit; and materials at cost, including, if appropriate, material handling costs as part of material costs. A timeand-materials contract may be used only when it is not possible at the time the task order is executed to estimate accurately the extent or duration of the work, or to anticipate costs with any reasonable degree of confidence. PSC Security Services BPA Ordering Guide Volume 1 15

18 PSC Security Services Appendix H Acronym List AOS Administrative Operations Service BPA Blanket Purchase Agreement C&A Certification and Accreditation CIO Chief Information Officer COOP Continuity of Operations Planning COTR Contracting Officer s Technical Representative DHS U.S. Department of Homeland Security EAP Enterprise Architecture Board ENS Emergency Notification Systems EPACS Enterprise Program Access Control Systems FAR Federal Acquisition Regulation FC Functional category FFP Firm Fixed Price FIPS Federal Information Processing Standard GSA General Services Administration HHS U.S. Department of Health and Human Services HSPD-12 Homeland Security Presidential Directive 12 HVAC Heating Ventilation and Air Conditioning IAA Inter-Agency Agreement IDCE Independent Government Cost Estimate IDS Intrusion Detection System IGCE Independent Government Cost Estimate IRB Investment Review Board ISC Interagency Security Committee ISMS Information System Management Service IT Information Technology MIPR Military Interdepartmental Purchase Request MNS Mass Notification System NIST National Institute of Standards and Technology O&M Operations and maintenance OEM Original Equipment Manufacturer OPDIV Operations Division OSIPS Open Systems Integration and Performance Standards PACS Physical Access Control Systems PIV Personal Identification Verification POC Point of Contact PSC Program Support Center RFID Radio Frequency Identification SCADA Supervisory Control and Data Acquisition SCIF Sensitive Compartmented Information Facility SLA Service Level Agreement SOW Statement of Work STAFFDIV Staff Division T&M Time and Materials TO Task order 16 Ordering Guide Volume 1 PSC Security Services BPA

19

20 U.S. Department of Health & Human Services Office of the Assistant Secretary for Administration Program Support Center 5600 Fishers Lane Rockville, MD Use your smartphone to scan the QR Code for quick access to

ENCORE II REQUIREMENTS CHECKLIST AND CERTIFICATIONS

ENCORE II REQUIREMENTS CHECKLIST AND CERTIFICATIONS ENCORE II REQUIREMENTS CHECKLIST AND CERTIFICATIONS This form is completed by the Task Monitors and forwarded to DISA/DITCO-Scott with a complete ENCORE II Requirements Package. (electronic signatures

More information

FiXs - Federated and Secure Identity Management in Operation

FiXs - Federated and Secure Identity Management in Operation FiXs - Federated and Secure Identity Management in Operation Implementing federated identity management and assurance in operational scenarios The Federation for Identity and Cross-Credentialing Systems

More information

SECTION 10 CONTRACTING FOR PROFESSIONAL SERVICES CONSULTANT COMPETITIVE NEGOTIATION ACT (CCNA)

SECTION 10 CONTRACTING FOR PROFESSIONAL SERVICES CONSULTANT COMPETITIVE NEGOTIATION ACT (CCNA) SECTION 10 CONTRACTING FOR PROFESSIONAL SERVICES CONSULTANT COMPETITIVE NEGOTIATION ACT (CCNA) 10.0 INTRODUCTION The purpose of this procedure is to provide guidance for hiring professional firms for architectural,

More information

IT-CNP, Inc. Capability Statement

IT-CNP, Inc. Capability Statement Securing America s Infrastructure Security Compliant IT Operations Hosting Cyber Security Information FISMA Cloud Management Hosting Security Compliant IT Logistics Hosting 1 IT-CNP, Inc. is a Government

More information

existing customer base (commercial and guidance and directives and all Federal regulations as federal)

existing customer base (commercial and guidance and directives and all Federal regulations as federal) ATTACHMENT 7 BSS RISK MANAGEMENT FRAMEWORK PLAN [L.30.2.7, M.2.2.(7), G.5.6; F.2.1(41) THROUGH (76)] A7.1 BSS SECURITY REQUIREMENTS Our Business Support Systems (BSS) Risk MetTel ensures the security of

More information

CASA External Peer Review Program Guidelines. Table of Contents

CASA External Peer Review Program Guidelines. Table of Contents CASA External Peer Review Program Guidelines Table of Contents Introduction... I-1 Eligibility/Point System... I-1 How to Request a Peer Review... I-1 Peer Reviewer Qualifications... I-2 CASA Peer Review

More information

THE GSA IT SCHEDULE 70 ORDERING PROCESS

THE GSA IT SCHEDULE 70 ORDERING PROCESS HOW TO ORDER IT PROFESSIONAL SERVICES FROM IT NOBLE, INC. USING GSA IT SCHEDULE 70 THE GSA IT SCHEDULE 70 ORDERING PROCESS Step 1: Customer consults with IT Noble, Inc. professionals to develop the Statement

More information

Comprehensive Professional Energy Services Blanket Purchase Agreements Ordering Guide

Comprehensive Professional Energy Services Blanket Purchase Agreements Ordering Guide U.S. General Services Administration Comprehensive Professional Energy Services Blanket Purchase Agreements Ordering Guide www.gsa.gov/energyservicesbpa Pub Number: 5-10-00416 Date Posted: 3/02/2011 Version:

More information

INFORMATION ASSURANCE DIRECTORATE

INFORMATION ASSURANCE DIRECTORATE National Security Agency/Central Security Service INFORMATION ASSURANCE DIRECTORATE CGS Physical Enterprise Physical Enterprise Monitoring is the monitoring of the physical and environmental controls that

More information

DEPARTMENT OF HEALTH and HUMAN SERVICES. HANDBOOK for

DEPARTMENT OF HEALTH and HUMAN SERVICES. HANDBOOK for DEPARTMENT OF HEALTH and HUMAN SERVICES HANDBOOK for FEDERAL ACQUISITION CERTIFICATION PROGRAM/PROJECT MANAGERS Issuer Office of the Secretary Office of the Assistant Secretary for Financial Resources

More information

VMware vcloud Air Accelerator Service

VMware vcloud Air Accelerator Service DATASHEET AT A GLANCE The VMware vcloud Air Accelerator Service assists customers with extending their private VMware vsphere environment to a VMware vcloud Air public cloud. This Accelerator Service engagement

More information

DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY DEPARTMENT OF PROCUREMENT

DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY DEPARTMENT OF PROCUREMENT DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY DEPARTMENT OF PROCUREMENT REQUEST FOR PROPOSALS (RFP) for An Independent Review of Architectural and Engineering Consultant Overhead Rates RFP NUMBER: 17-PR-DETS-45

More information

Federal Acquisition Service Authorized Federal Supply Schedule Price List

Federal Acquisition Service Authorized Federal Supply Schedule Price List Federal Acquisition Service Authorized Federal Supply Schedule Price List On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic

More information

MNsure Privacy Program Strategic Plan FY

MNsure Privacy Program Strategic Plan FY MNsure Privacy Program Strategic Plan FY 2018-2019 July 2018 Table of Contents Introduction... 3 Privacy Program Mission... 4 Strategic Goals of the Privacy Office... 4 Short-Term Goals... 4 Long-Term

More information

Streamlined FISMA Compliance For Hosted Information Systems

Streamlined FISMA Compliance For Hosted Information Systems Streamlined FISMA Compliance For Hosted Information Systems Faster Certification and Accreditation at a Reduced Cost IT-CNP, INC. WWW.GOVDATAHOSTING.COM WHITEPAPER :: Executive Summary Federal, State and

More information

Hewlett Packard Enterprise Company Public Sector - Federal

Hewlett Packard Enterprise Company Public Sector - Federal Hewlett Packard Enterprise Company Public Sector - Federal Federal Partner Ready Agent Rules of Engagement FY18 Updated 1/1/18 1 The following document is provided as a guide for Hewlett Packard Enterprise

More information

IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive

IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive IT Governance ISO/IEC 27001:2013 ISMS Implementation Service description Protect Comply Thrive 100% guaranteed ISO 27001 certification with the global experts With the IT Governance ISO 27001 Implementation

More information

Virginia State University Policies Manual. Title: Information Security Program Policy: 6110

Virginia State University Policies Manual. Title: Information Security Program Policy: 6110 Purpose Virginia State University (VSU) uses information to perform the business services and functions necessary to fulfill its mission. VSU information is contained in many different mediums including

More information

Contents. Navigating your way to the cloud

Contents. Navigating your way to the cloud Contents Navigating your way to the cloud Moving to the digital economy 4 Four essential steps to a successful cloud adoption and deployment 5 Step 1: Full, informed stakeholder involvement 6 Step 2: Targeted

More information

Notification of Issuance of Binding Operational Directive and Establishment of. AGENCY: National Protection and Programs Directorate, DHS.

Notification of Issuance of Binding Operational Directive and Establishment of. AGENCY: National Protection and Programs Directorate, DHS. This document is scheduled to be published in the Federal Register on 09/19/2017 and available online at https://federalregister.gov/d/2017-19838, and on FDsys.gov 9110-9P-P DEPARTMENT OF HOMELAND SECURITY

More information

Request for Proposal for Technical Consulting Services

Request for Proposal for Technical Consulting Services Request for Proposal for Technical Consulting Services The Node.js Foundation is requesting proposals from highly qualified consultants with demonstrated expertise in providing Node.js technical consultation

More information

Isaca EXAM - CISM. Certified Information Security Manager. Buy Full Product.

Isaca EXAM - CISM. Certified Information Security Manager. Buy Full Product. Isaca EXAM - CISM Certified Information Security Manager Buy Full Product http://www.examskey.com/cism.html Examskey Isaca CISM exam demo product is here for you to test the quality of the product. This

More information

Appendix 12 Risk Assessment Plan

Appendix 12 Risk Assessment Plan Appendix 12 Risk Assessment Plan DRAFT December 13, 2006 Revision XX Qwest Government Services, Inc. 4250 North Fairfax Drive Arlington, VA 22203 A12-1 RFP: TQC-JTB-05-0001 December 13, 2006 REVISION HISTORY

More information

Will Federated Cross Credentialing Solutions Accelerate Adoption of Smart Card Based Identity Solutions?

Will Federated Cross Credentialing Solutions Accelerate Adoption of Smart Card Based Identity Solutions? Will Federated Cross Credentialing Solutions Accelerate Adoption of Smart Card Based Identity Solutions? Jack Radzikowski,, Northrop Grumman & FiXs Smart Card Alliance Annual Meeting La Jolla, California

More information

Appendix 12 Risk Assessment Plan

Appendix 12 Risk Assessment Plan Appendix 12 Risk Assessment Plan DRAFT March 5, 2007 Revision XX Qwest Government Services, Inc. 4250 North Fairfax Drive Arlington, VA 22203 A12-i RFP: TQC-JTB-05-0002 March 5, 2007 REVISION HISTORY Revision

More information

HPE DATA PRIVACY AND SECURITY

HPE DATA PRIVACY AND SECURITY ARUBA, a Hewlett Packard Enterprise company, product services ( Services ) This Data Privacy and Security Agreement ("DPSA") Schedule governs the privacy and security of Personal Data by HPE in connection

More information

RFQ OIT-1 Q&A. Questions and Answers, in the order received.

RFQ OIT-1 Q&A. Questions and Answers, in the order received. Question Does the system have an existing SSP? Do they use a system like Xacta or CSAM to generate the SSP. Will they provide us the current POAM list? Will they provide scanning tools or we have to bring

More information

Payment Card Industry (PCI) 3-D Secure (PCI 3DS) Qualification Requirements for 3DS Assessors

Payment Card Industry (PCI) 3-D Secure (PCI 3DS) Qualification Requirements for 3DS Assessors Payment Card Industry (PCI) 3-D Secure (PCI 3DS) Qualification Requirements for 3DS Assessors Version 1.0 November 2017 Document Changes Date Version Description November 2017 1.0 Initial Release of the

More information

ATTACHMENT A POLICES AND PROCEDURES REGARDING CELLULAR TELEPHONES AND MOBILE COMMUNICATION DEVICES

ATTACHMENT A POLICES AND PROCEDURES REGARDING CELLULAR TELEPHONES AND MOBILE COMMUNICATION DEVICES ATTACHMENT A POLICES AND PROCEDURES REGARDING CELLULAR TELEPHONES AND MOBILE COMMUNICATION DEVICES 1. INTRODUCTION 1.1 The Office of Information Technology Services ( OITS ) has the responsibility of managing

More information

INFORMATION ASSURANCE DIRECTORATE

INFORMATION ASSURANCE DIRECTORATE National Security Agency/Central Security Service INFORMATION ASSURANCE DIRECTORATE CGS Network Mapping The Network Mapping helps visualize the network and understand relationships and connectivity between

More information

Areas of impact for client consideration taken from the Rules for achieving and maintaining IATF recognition 4 th Edition for ISO/TS 16949

Areas of impact for client consideration taken from the Rules for achieving and maintaining IATF recognition 4 th Edition for ISO/TS 16949 Areas of for client consideration taken from the Rules for achieving and maintaining IATF recognition 4 th Edition for ISO/TS 16949 1 st February 2014 1 Foreword Introduction The IATF recognizes certification

More information

Information Technology General Control Review

Information Technology General Control Review Information Technology General Control Review David L. Shissler, Senior IT Auditor, CPA, CISA, CISSP Office of Internal Audit and Risk Assessment September 15, 2016 Background Presenter Senior IT Auditor

More information

IBM Resilient Incident Response Platform On Cloud

IBM Resilient Incident Response Platform On Cloud Service Description IBM Resilient Incident Response Platform On Cloud This Service Description describes the Cloud Service IBM provides to Client. Client means the contracting party and its authorized

More information

NETWORX PROGRAM INDIVIDUAL SMALL BUSINESS SUBCONTRACTING PLAN IDIQ TASK ORDER BASED

NETWORX PROGRAM INDIVIDUAL SMALL BUSINESS SUBCONTRACTING PLAN IDIQ TASK ORDER BASED NETWORX PROGRAM INDIVIDUAL SMALL BUSINESS SUBCONTRACTING PLAN IDIQ TASK ORDER BASED Company Name: Qwest Government Services, Inc. (QGSI) Address: 4250 N. Fairfax Drive Arlington, VA 22203 Date Submitted:

More information

Interagency Advisory Board HSPD-12 Insights: Past, Present and Future. Carol Bales Office of Management and Budget December 2, 2008

Interagency Advisory Board HSPD-12 Insights: Past, Present and Future. Carol Bales Office of Management and Budget December 2, 2008 Interagency Advisory Board HSPD-12 Insights: Past, Present and Future Carol Bales Office of Management and Budget December 2, 2008 Importance of Identity, Credential and Access Management within the Federal

More information

The U.S. Government s Role in Standards and Conformity Assessment

The U.S. Government s Role in Standards and Conformity Assessment The U.S. Government s Role in Standards and Conformity Assessment ASTM International-Russian Federation on Technical Regulating and Metrology Coordinated Program Mary Saunders Chief, Standards Services

More information

IAF Mandatory Document for the Transfer of Accredited Certification of Management Systems

IAF Mandatory Document for the Transfer of Accredited Certification of Management Systems IAF MD 2:2007. International Accreditation Forum, Inc. IAF Mandatory Document IAF Mandatory Document for the Transfer of Accredited Certification of Management Systems (IAF MD 2:2007) IAF MD2:2007 International

More information

Effective October 1, 2017 the Total Hourly Rates for the NYSTEC contract can be found below.

Effective October 1, 2017 the Total Hourly Rates for the NYSTEC contract can be found below. Effective October 1, 2017 the Total Hourly Rates for the NYSTEC contract can be found below. NYSTEC Labor Category Not to Exceed Rates exclusive of travel for NYSTEC FY 2017 Not to Exceed Rates exclusive

More information

DoD Internet Protocol Version 6 (IPv6) Contractual Language

DoD Internet Protocol Version 6 (IPv6) Contractual Language DoD Internet Protocol Version 6 (IPv6) Contractual Language 1. Purpose: Contents of this document shall be incorporated in Government Acquisition Programs, Procurements, Services, and Contracts (including

More information

VMware BCDR Accelerator Service

VMware BCDR Accelerator Service AT A GLANCE The rapidly deploys a business continuity and disaster recovery (BCDR) solution with a limited, pre-defined scope in a non-production environment. The goal of this service is to prove the solution

More information

Security and Privacy Governance Program Guidelines

Security and Privacy Governance Program Guidelines Security and Privacy Governance Program Guidelines Effective Security and Privacy Programs start with attention to Governance. Governance refers to the roles and responsibilities that are established by

More information

DFARS Cyber Rule Considerations For Contractors In 2018

DFARS Cyber Rule Considerations For Contractors In 2018 Portfolio Media. Inc. 111 West 19 th Street, 5th Floor New York, NY 10011 www.law360.com Phone: +1 646 783 7100 Fax: +1 646 783 7161 customerservice@law360.com DFARS Cyber Rule Considerations For Contractors

More information

IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION

IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION Briefing for OFPP Working Group 19 Feb 2015 Emile Monette GSA Office of Governmentwide Policy emile.monette@gsa.gov Cybersecurity Threats are

More information

American Association for Laboratory Accreditation

American Association for Laboratory Accreditation R311 - Specific Requirements: Federal Risk and Authorization Management Program Page 1 of 10 R311 - Specific Requirements: Federal Risk and Authorization Management Program 2017 by A2LA. All rights reserved.

More information

Scheme Document SD 003

Scheme Document SD 003 Scheme Document SD 003 Management Systems (ISO 9001, ISO 14001, BS OHSAS 18001 & PN111 Factory Production Control) SD 003 Rev 03.6 10 Oct 2013 Page 1 of 13 (blank) SD 003 Rev 03.6 10 Oct 2013 Page 2 of

More information

Exam4Tests. Latest exam questions & answers help you to pass IT exam test easily

Exam4Tests.   Latest exam questions & answers help you to pass IT exam test easily Exam4Tests http://www.exam4tests.com Latest exam questions & answers help you to pass IT exam test easily Exam : CISM Title : Certified Information Security Manager Vendor : ISACA Version : DEMO 1 / 10

More information

Section Qualifications of Audit teams Qualifications of Auditors Maintenance and Improvement of Competence...

Section Qualifications of Audit teams Qualifications of Auditors Maintenance and Improvement of Competence... Section 9. SFI 2010-2014 Audit Procedures and Auditor Qualifications and Accreditation Updated January 2011 Section 9 Introduction... 3 1. Scope... 3 2. Normative Reference... 3 3. Terms and Definitions...

More information

IBM Managed Security Services - Vulnerability Scanning

IBM Managed Security Services - Vulnerability Scanning Service Description IBM Managed Security Services - Vulnerability Scanning This Service Description describes the Service IBM provides to Client. 1.1 Service IBM Managed Security Services - Vulnerability

More information

Turning Risk into Advantage

Turning Risk into Advantage Turning Risk into Advantage How Enterprise Wide Risk Management is helping customers succeed in turbulent times and increase their competitiveness Glenn Tjon Partner KPMG Advisory Presentation Overview

More information

SLI Compliance ONC-ATL Testing Program Guide

SLI Compliance ONC-ATL Testing Program Guide SLI Compliance A Division of Gaming Laboratories International, LLC 4720 Independence St. Wheat Ridge, CO 80033 303-422-1566 www.slicompliance.com SLI Compliance ONC-ATL Testing Program Guide Document

More information

EUROPEAN ICT PROFESSIONAL ROLE PROFILES VERSION 2 CWA 16458:2018 LOGFILE

EUROPEAN ICT PROFESSIONAL ROLE PROFILES VERSION 2 CWA 16458:2018 LOGFILE EUROPEAN ICT PROFESSIONAL ROLE PROFILES VERSION 2 CWA 16458:2018 LOGFILE Overview all ICT Profile changes in title, summary, mission and from version 1 to version 2 Versions Version 1 Version 2 Role Profile

More information

REVIEW OF MANAGEMENT AND OVERSIGHT OF THE INTEGRATED BUSINESS MANAGEMENT SYSTEM (IBMS) January 16, 2009

REVIEW OF MANAGEMENT AND OVERSIGHT OF THE INTEGRATED BUSINESS MANAGEMENT SYSTEM (IBMS) January 16, 2009 APPENDIX 1 REVIEW OF MANAGEMENT AND OVERSIGHT OF THE INTEGRATED BUSINESS MANAGEMENT SYSTEM (IBMS) January 16, 2009 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto

More information

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors Page 1 of 6 Applies to: faculty staff students student employees visitors contractors Effective Date of This Revision: June 1, 2018 Contact for More Information: HIPAA Privacy Officer Board Policy Administrative

More information

Adobe Digital Media (Formerly Desktop) Products Enterprise Software Agreement Carahsoft Technology. Blanket Purchase Agreement (BPA) N A-ZF31

Adobe Digital Media (Formerly Desktop) Products Enterprise Software Agreement Carahsoft Technology. Blanket Purchase Agreement (BPA) N A-ZF31 Adobe Digital Media (Formerly Desktop) Products Enterprise Software Agreement Carahsoft Technology Blanket Purchase Agreement (BPA) N00104-12-A-ZF31 (Approved 4/21/14) 1 DOD ESI BPA ORDERING GUIDE This

More information

REPORT 2015/149 INTERNAL AUDIT DIVISION

REPORT 2015/149 INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2015/149 Audit of the information and communications technology operations in the Investment Management Division of the United Nations Joint Staff Pension Fund Overall results

More information

ROADMAP TO DFARS COMPLIANCE

ROADMAP TO DFARS COMPLIANCE ROADMAP TO DFARS COMPLIANCE ARE YOU READY FOR THE 12/31/17 DEADLINE? In our ebook, we have answered the most common questions we receive from companies preparing for DFARS compliance. Don t risk terminated

More information

COMMERCIAL FURNACES CERTIFICATION PROGRAM

COMMERCIAL FURNACES CERTIFICATION PROGRAM COMMERCIAL FURNACES CERTIFICATION PROGRAM AHRI OM CFRN JANUARY 2018 2111 Wilson Blvd, Suite 500 Arlington, Virginia 22201 (703) 524-8800 Sponsored and administered by: PREFACE The following manual outlines

More information

Blanket Purchase Agreement Attachment D Ordering Guide. SolarWinds DLT Solutions, LLC. Blanket Purchase Agreement (BPA) N A-ZF42

Blanket Purchase Agreement Attachment D Ordering Guide. SolarWinds DLT Solutions, LLC. Blanket Purchase Agreement (BPA) N A-ZF42 SolarWinds DLT Solutions, LLC Blanket Purchase Agreement (BPA) N00104-13-A-ZF42 1 Version Dated: 7 June 2018 DOD ESI BPA ORDERING GUIDE This Ordering Guide has been developed by the DoD ESI team to assist

More information

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

UNCLASSIFIED. FY 2016 Base FY 2016 OCO Exhibit R-2, RDT&E Budget Item Justification: PB 2016 Defense Security Service Date: February 2015 0400: Research, Development, Test & Evaluation, Defense-Wide / BA 7: Operational Systems Development COST

More information

CRITERIA FOR CERTIFICATION BODY ACCREDITATION IN THE FIELD OF RISK BASED INSPECTION MANAGEMENT SYSTEMS

CRITERIA FOR CERTIFICATION BODY ACCREDITATION IN THE FIELD OF RISK BASED INSPECTION MANAGEMENT SYSTEMS CRITERIA FOR CERTIFICATION BODY ACCREDITATION IN THE FIELD OF RISK BASED INSPECTION MANAGEMENT SYSTEMS Approved By: Executive: Accreditation: Mpho Phaloane Revised By: RBI STC Working Group Members Date

More information

Code of Ethics Certification 2018 CHECKLIST

Code of Ethics Certification 2018 CHECKLIST Code of Ethics Certification 2018 CHECKLIST Medical technology companies (both AdvaMed members and non-members) may participate in this certification program. The certification affirms that the company

More information

SUBJECT: PRESTO operating agreement renewal update. Committee of the Whole. Transit Department. Recommendation: Purpose: Page 1 of Report TR-01-17

SUBJECT: PRESTO operating agreement renewal update. Committee of the Whole. Transit Department. Recommendation: Purpose: Page 1 of Report TR-01-17 Page 1 of Report TR-01-17 SUBJECT: PRESTO operating agreement renewal update TO: FROM: Committee of the Whole Transit Department Report Number: TR-01-17 Wards Affected: All File Numbers: 465-12, 770-11

More information

Solutions Technology, Inc. (STI) Corporate Capability Brief

Solutions Technology, Inc. (STI) Corporate Capability Brief Solutions Technology, Inc. (STI) Corporate Capability Brief STI CORPORATE OVERVIEW Located in the metropolitan area of Washington, District of Columbia (D.C.), Solutions Technology Inc. (STI), women owned

More information

REQUEST FOR PROPOSALS ZONING ORDINANCE

REQUEST FOR PROPOSALS ZONING ORDINANCE REQUEST FOR PROPOSALS ZONING ORDINANCE City of Allegan Allegan County, Michigan A. Background. The City of Allegan is hereby requesting proposals from qualified, multidisciplinary professionals in the

More information

RFQ OIT-1 Q&A. Questions and Answers, in the order received.

RFQ OIT-1 Q&A. Questions and Answers, in the order received. Question Does the system have an existing SSP? Do they use a system like Xacta or CSAM to generate the SSP. Will they provide us the current POAM list? Will they provide scanning tools or we have to bring

More information

Green Star Volume Certification. Process Guide

Green Star Volume Certification. Process Guide Green Star Volume Certification Process Guide Contents Executive Summary... 3 Volume Certification... 3 The Volume Certification Process Guide... 3 Questions?... 4 Volume Certification Summary... 5 Stage

More information

CERTIFICATION BODY (CB) APPROVAL REQUIREMENTS FOR THE IFFO RESPONSIBLE SUPPLY (IFFO RS) AUDITS AND CERTIFICATION

CERTIFICATION BODY (CB) APPROVAL REQUIREMENTS FOR THE IFFO RESPONSIBLE SUPPLY (IFFO RS) AUDITS AND CERTIFICATION CERTIFICATION BODY (CB) APPROVAL REQUIREMENTS FOR THE IFFO RESPONSIBLE SUPPLY (IFFO RS) AUDITS AND CERTIFICATION Introduction The IFFO RS Certification Programme is a third party, independent and accredited

More information

IBM Resilient Incident Response Platform On Cloud

IBM Resilient Incident Response Platform On Cloud Service Description IBM Resilient Incident Response Platform On Cloud This Service Description describes the Cloud Service IBM provides to Client. Client means the contracting party and its authorized

More information

FDIC InTREx What Documentation Are You Expected to Have?

FDIC InTREx What Documentation Are You Expected to Have? FDIC InTREx What Documentation Are You Expected to Have? Written by: Jon Waldman, CISA, CRISC Co-founder and Executive Vice President, IS Consulting - SBS CyberSecurity, LLC Since the FDIC rolled-out the

More information

Green Squared Certification Manual

Green Squared Certification Manual SCS Global Services Manual Green Squared Certification Manual Environmental Certification Services Division 2000 Powell Street, Ste. 600, Emeryville, CA 94608 USA +1.510.452.8000 main +1.510.452.8001 fax

More information

I. PURPOSE III. PROCEDURE

I. PURPOSE III. PROCEDURE A.R. Number: 2.11 Effective Date: 2/1/2009 Page: 1 of 5 I. PURPOSE This policy outlines the procedures that third party organizations must follow when connecting to the City of Richmond (COR) networks

More information

Statement of Organization, Functions, and Delegations of Authority: Office of the

Statement of Organization, Functions, and Delegations of Authority: Office of the This document is scheduled to be published in the Federal Register on 07/27/2016 and available online at http://federalregister.gov/a/2016-17737, and on FDsys.gov 4184-40P DEPARTMENT OF HEALTH AND HUMAN

More information

ITU Asia-Pacific Centres of Excellence Training on Conformity and Interoperability. Session 2: Conformity Assessment Principles

ITU Asia-Pacific Centres of Excellence Training on Conformity and Interoperability. Session 2: Conformity Assessment Principles ITU Asia-Pacific Centres of Excellence Training on Conformity and Interoperability Session 2: Conformity Assessment Principles 12-16 October 2015 Beijing, China Keith Mainwaring ITU Expert Agenda 1. Context

More information

Request for Qualifications for Audit Services March 25, 2015

Request for Qualifications for Audit Services March 25, 2015 Request for Qualifications for Audit Services March 25, 2015 I. GENERAL INFORMATION A. Purpose This Request for Qualifications (RFQ) is to solicit a CPA firm with which to contract for a financial and

More information

REQUEST FOR INFORMATION STATE OF FLORIDA. Florida Statewide NG-911 Routing Services RFI NO.: DMS-12/13-002

REQUEST FOR INFORMATION STATE OF FLORIDA. Florida Statewide NG-911 Routing Services RFI NO.: DMS-12/13-002 REQUEST FOR INFORMATION STATE OF FLORIDA Florida Statewide NG-911 Routing Services RFI NO.: DMS-12/13-002 I. INTRODUCTION The State of Florida, Department of Management Services (the Department ), hereby

More information

OFFICE OF THE UNDER SECRETARY OF DEFENSE 3000DEFENSEPENTAGON WASHINGTON, DC

OFFICE OF THE UNDER SECRETARY OF DEFENSE 3000DEFENSEPENTAGON WASHINGTON, DC OFFICE OF THE UNDER SECRETARY OF DEFENSE 3000DEFENSEPENTAGON WASHINGTON, DC 20301-3000 ACQUISITION, TECHNO LOGY. A N D LOGISTICS SEP 2 1 2017 MEMORANDUM FOR COMMANDER, UNITED ST A TES SPECIAL OPERATIONS

More information

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT Mitigation Framework Leadership Group (MitFLG) Charter DRAFT October 28, 2013 1.0 Authorities and Oversight The Mitigation Framework Leadership Group (MitFLG) is hereby established in support of and consistent

More information

Timber Products Inspection, Inc.

Timber Products Inspection, Inc. Timber Products Inspection, Inc. Product Certification Public Document Timber Products Inspection, Inc. P.O. Box 919 Conyers, GA 30012 Phone: (770) 922-8000 Fax: (770) 922-1290 TP Product Certification

More information

Agenda. Bibliography

Agenda. Bibliography Humor 2 1 Agenda 3 Trusted Digital Repositories (TDR) definition Open Archival Information System (OAIS) its relevance to TDRs Requirements for a TDR Trustworthy Repositories Audit & Certification: Criteria

More information

IBM Case Manager on Cloud

IBM Case Manager on Cloud Service Description IBM Case Manager on Cloud This Service Description describes the Cloud Service IBM provides to Client. Client means and includes the company, its authorized users or recipients of the

More information

INFORMATION ASSURANCE DIRECTORATE

INFORMATION ASSURANCE DIRECTORATE National Security Agency/Central Security Service INFORMATION ASSURANCE DIRECTORATE CGS Risk Monitoring Risk Monitoring assesses the effectiveness of the risk decisions that are made by the Enterprise.

More information

DHS Overview of Sustainability and Environmental Programs. Dr. Teresa R. Pohlman Executive Director, Sustainability and Environmental Programs

DHS Overview of Sustainability and Environmental Programs. Dr. Teresa R. Pohlman Executive Director, Sustainability and Environmental Programs DHS Overview of Sustainability and Environmental Programs Dr. Teresa R. Pohlman Executive Director, Sustainability and Environmental Programs DHS Mission DHS Organization Getting to Know DHS Mission: Secure

More information

CYBER SECURITY BRIEF. Presented By: Curt Parkinson DCMA

CYBER SECURITY BRIEF. Presented By: Curt Parkinson DCMA CYBER SECURITY BRIEF Presented By: Curt Parkinson DCMA September 20, 2017 Agenda 2 DFARS 239.71 Updates Cybersecurity Contracting DFARS Clause 252.204-7001 DFARS Clause 252.239-7012 DFARS Clause 252.239-7010

More information

GENERAL SERVICES ADMINISTRATION

GENERAL SERVICES ADMINISTRATION GENERAL SERVICES ADMINISTRATION Federal Supply Service Authorized Federal Supply Schedule Price List On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option

More information

An Overview of ISO/IEC family of Information Security Management System Standards

An Overview of ISO/IEC family of Information Security Management System Standards What is ISO/IEC 27001? The ISO/IEC 27001 standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), is known as Information

More information

Metro Mot opo'"'" T""''"""~" '"'"""''

Metro Mot opo'' T''~ '''' '"''"'''''c.,.., Metro Mot opo'"'" T""''"""~" '"'"""'' One Gateway Plaza Los Angeles, CA 90012-2952 2 13.922.2000 Tel metro. net 40 SYSTEM SAFETY AND OPERATIONS COMMITTEE JUNE 19, 2014 SUBJECT: ACTION:

More information

Request for Proposal (RFP)

Request for Proposal (RFP) Request for Proposal (RFP) BOK PENETRATION TESTING Date of Issue Closing Date Place Enquiries Table of Contents 1. Project Introduction... 3 1.1 About The Bank of Khyber... 3 1.2 Critical Success Factors...

More information

Anna Independent School District

Anna Independent School District Anna Independent School District 501 S. Sherley Avenue Anna Texas 75409 www.annaisd.org Phone: 972-924-1000 Fax: 972-924-1001 Request for Proposals (RFP) Spring 2015 Computer Hardware Refresh The Technology

More information

Service Description: CNS Federal High Touch Technical Support

Service Description: CNS Federal High Touch Technical Support Page 1 of 1 Service Description: CNS Federal High Touch Technical Support This service description ( Service Description ) describes Cisco s Federal High Touch Technical support (CNS-HTTS), a tier 2 in

More information

SİGMACERT ULUSLARARASI BELGELENDİRME EĞİTİM TEST HİZMETLERİ LTD. ŞTİ.

SİGMACERT ULUSLARARASI BELGELENDİRME EĞİTİM TEST HİZMETLERİ LTD. ŞTİ. SİGMACERT ULUSLARARASI BELGELENDİRME EĞİTİM TEST HİZMETLERİ LTD. ŞTİ. YS.PR.01 Certification Procedure (Revision 01 03.05.2017) Written by Reviewed & Authorized by Date: Date: CONTENT PAGE NO. A. Objective

More information

Google Cloud & the General Data Protection Regulation (GDPR)

Google Cloud & the General Data Protection Regulation (GDPR) Google Cloud & the General Data Protection Regulation (GDPR) INTRODUCTION General Data Protection Regulation (GDPR) On 25 May 2018, the most significant piece of European data protection legislation to

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 27006 Second edition 2011-12-01 Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems

More information

SOC 3 for Security and Availability

SOC 3 for Security and Availability SOC 3 for Security and Availability Independent Practioner s Trust Services Report For the Period October 1, 2015 through September 30, 2016 Independent SOC 3 Report for the Security and Availability Trust

More information

REPORT 2015/186 INTERNAL AUDIT DIVISION

REPORT 2015/186 INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2015/186 Audit of information and communications technology operations in the Secretariat of the United Nations Joint Staff Pension Fund Overall results relating to the effective

More information

Request for Proposal HIPAA Security Risk and Vulnerability Assessment. May 1, First Choice Community Healthcare

Request for Proposal HIPAA Security Risk and Vulnerability Assessment. May 1, First Choice Community Healthcare Request for Proposal HIPAA Security Risk and Vulnerability Assessment May 1, 2016 First Choice Community Healthcare Timeline The following Timeline has been defined to efficiently solicit multiple competitive

More information

IBM Sterling B2B Services File Transfer Service

IBM Sterling B2B Services File Transfer Service Service Description IBM Sterling B2B Services File Transfer Service This Service Description describes the Cloud Service IBM provides to Client. Client means the company and its authorized users and recipients

More information

Appendix 6 Operational Support Systems Change Management Plan

Appendix 6 Operational Support Systems Change Management Plan Appendix 6 Operational Support Systems Change Management Plan DRAFT December 13, 2006 Revision XX Qwest Government Services, Inc. 4250 North Fairfax Drive Arlington, VA 22203 A6-1 RFP: TQC-JTB-05-0001

More information

Metropolitan Washington Airports Authority PROCUREMENT AND CONTRACTS DEPT. AMENDMENT OF SOLICITATION

Metropolitan Washington Airports Authority PROCUREMENT AND CONTRACTS DEPT. AMENDMENT OF SOLICITATION Metropolitan Washington Airports Authority PROCUREMENT AND CONTRACTS DEPT. AMENDMENT OF SOLICITATION Metropolitan Washington Airports Authority Procurement and Contracts Dept., MA-29 2733 Crystal Drive

More information

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC Auditing and Monitoring for HIPAA Compliance HCCA COMPLIANCE INSTITUTE 2003 April, 2003 Presented by: Suzie Draper Sheryl Vacca, CHC 1 The Elements of Corporate Compliance Program There are seven key elements

More information

Annual Report for the Utility Savings Initiative

Annual Report for the Utility Savings Initiative Report to the North Carolina General Assembly Annual Report for the Utility Savings Initiative July 1, 2016 June 30, 2017 NORTH CAROLINA DEPARTMENT OF ENVIRONMENTAL QUALITY http://portal.ncdenr.org Page

More information