Roles/Responsibilities:
The resources shall complete and submit the following deliverables:
1) Review Client cybersecurity policies procedures standards and risk assessments and identfy Gaps and assist in addressing those gaps as per NIST 2.0 by November 30 2025.
2) 2024 NIST Remediation Support to be completed by January 31 2026.
3) 2025 NIST CSF Annual Assessment/Audit-Q4 2025 to be completed by June 30 2026.
o Final NIST CSF Assessment Report (PDF and editable formats)
o Maturity Scorecard Dashboard o Risk and Gap Register
o Presentation Slides for Leadership Review
Mandatory Skills:
MINIMUM QUALIFICATIONS:
Proposers shall meet each of the minimum qualification requirements at the time of proposal submittal:
- Five years of experience performing assessments alignments and policy development with the NIST Cybersecurity Framework (CSF) across all departments systems and third-party interfaces.
- Five years of experience with conducting state assessment target profile development Gap analysis and Implementation roadmap with control mappings to various processes. Demonstrated expertise with Framework integration with Enterprise Risk Management (ERM) Identity and Access Management (IAM) and Cloud security controls. Ensure interoperability with compliance (HIPAA COPPA FERPA CIIPA GDPR etc.)
- Experience in establishing the Metrics and Continuous Monitoring providing dashboard for dashboards for executive visibility (CISO CIO board) planning regular maturity assessment and establishing metrics for each CSF function and subcategory.
- These requirements may be satisfied with both public sector and commercial experience.
- REQUIRED QUALIFICATIONS
- These requirements may be satisfied with both public sector and commercial experience
- Experience in governance and program design
- Experience in NIST CSF framework integration
- Experience in technology alignment with NIST CSF
- Experience in establishing metrics and executive dashboard creation.
- Experience with compliance and audit requirements
- Experience with understanding larger systems and their dependencies.
- Experience with developing governance framework documents SOPs and policies.
- These requirements apply to the proposer
Desirable Skills: N/A