| CONTRACT
SUMMARY: |
|
| Provides
information security program support to the Veterans Benefit
Administration (VBA). The VBA information security program
support includes system lifecycle security support and
Certification and Accreditation (C&A) support. The system
lifecycle security support encompasses Independent Verification
and Validation (IV&V) of newly developed systems to ensure
system/application designs contain the appropriate security
controls (Federal Information Processing Standards (FIPS)
200, National Institute of Standards and Technology (NIST),
Defense Information Assurance Certification and Accreditation
Program (DIACAP), Federal Information Systems Controls
Audit Manual (FISCAM)) and met minimum Federal standards
for encryption (FIPS 140-2) In accordance with the Federal
Information Security Management Act (FISMA). |
|
| The
C&A consists 97 Major Applications, 52 Regional Offices,
and 3 Information Technology Centers (ITC) and included
the following system configurations: |
|
 |
Stand-alone
applications/systems (Microsoft/Solaris/Linux/Unix) |
 |
Web-based
applications (IIS/Apache) |
 |
Mainframe/transaction
applications/systems (IBM/Honeywell/Bull) |
 |
Stand-alone/distributed
databases/data warehouses (MS Access/SQL/My SQL/Oracle) |
 |
Client/Sever
applications (fat/thin clients/middleware) |
 |
Legacy
system/applications |
 |
Telecommunication/Wireless/Wide-Area
Networks (WAN)/ Local Area Networks (LAN)/switching
networks |
|
|
| Each
Major Application, Regional Office, and ITC includes the
design, development, preparation, and maintenance of Certification
and Accreditation (C&A) documentation to include: |
|
 |
Security
Requirement Traceability Matrix (SRTM) |
 |
System
Security Plans (SSP) |
 |
Risk/Vulnerability/Threat
Assessments |
 |
Business
Impact Assessments (BIA) |
 |
Contingency
Plans |
 |
Continuity
Of Operations Plans (COOP) |
 |
Information
Security Program Resource Guide |
 |
Plans
Of Action and Milestones (POA&M) |
 |
Corrective
Action Plans |
 |
Privacy
Impact Assessments |
 |
Configuration
Management Plans |
 |
Physical
Security Guides |
 |
Security
Policies, Procedures, and Guidelines |
|