Notice ID: SS-2023-2022 Description The National Renewable Energy Laboratory (NREL) is a national laboratory of the U.S. Department of Energy (DOE), Office of Energy Efficiency and Renewable Energy (EERE), operated and managed by the Alliance for Sustainable Energy, LLC. NREL advances the science and engineering of energy efficiency, sustainable transportation, and renewable power technologies and provides the knowledge to integrate and optimize energy systems. Subcontractor shall perform security control assessor functions including: Develop assessment criteria (which controls to assess/what frequency) (subj. to review/agreement by CSPM/CISO) Create and manage assessment schedule (subj. to review/agreement by CSPM/CISO) - Continuous Assessment Plan (CAP) Request data from implementation teams (using Servicenow tickets) Enter data into tracking tool(s) Evaluate data from implementation teams and adjudicate on control performance Communicate assessment results, including changes in technical implementation and deficiencies, to ISSO and System Owners during assessment process Subcontractor shall support the Vulnerability Management program, including: Tracking the status of known exploitable vulnerabilities based on Binding Operational Directive 22-01, Cyber security and Infrastructure Security Agency (CISA) guidance, and Golden Field Office (GFO) requirements and additionally external systems with critical and high vulnerabilities. The scope of work shall include, but not be limited to, Project Manager duties: Security Project Coordination Vulnerability Management Coordination Creation of tickets, making patching assignments to responsible parties Status reporting, tracking, and addressing compliance discrepancies. Subcontractor shall support other Information System Security Officer tasks as directed. Provide Project Manager level support for cyber security operations and status reporting on compliance discrepancies... Read more here.
Opportunities
DOE NREL Sources Sought: Cybersecurity Department and Program Support ServicesBy Jackie Gilbert
Notice ID: SS-2023-2022
Description
The National Renewable Energy Laboratory (NRELFebruary 2, 2023