Modification to a Previous Presolicitation Notice - Primary Paying Agent Services
22.05.12
(E.g. 800-37, 800-60, 800-53, 800-53A, 800-137, 800-34 and other applicable NIST standards), and evolving PBGC Enterprise Information Security Office (EISO) policies and procedures including Information Security Requirements for Externally Hosted Systems. Safeguarding sensitive PBGC data (protecting its availability, confidentiality and integrity in accordance with FIPS 199/200 requirements), access controls, configuration management, contingency planning (including continuity of operations) and a rigorous continuous monitoring plan are of especially critical importance. Most of PBGC data, including data loaded into the PA's pension payment system, requires NIST 800-53 controls required of moderate risk systems. The required high-level process is as follows. It is expected that after contract award, items 1 - 6 will be completed before the PA's pension payment system can go live with PBGC data: 1. Define the control environment of the PA's pension payment system 2. Assess the adequacy of
Source: Insurance News Net (press release)