12.07.2015 Views

SOW Annex D - Ministerio de Defensa

SOW Annex D - Ministerio de Defensa

SOW Annex D - Ministerio de Defensa

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NATO UNCLASSIFIEDAMD-7 TO IFB-CO-12546-POL GAG - <strong>SOW</strong> <strong>Annex</strong> DSupport package may be composed of several sub-sections or Appendices, addressingrespectively the individual sites. The Contractor is invited to <strong>de</strong>scribe his intent in theSAP.d. As a minimum, the SAP shall address in <strong>de</strong>tail all elements as <strong>de</strong>scribed in the templateof the NATO Security Accreditation Plan which is attached as Appendix 1 to <strong>Annex</strong> Dof the SoW.e. A Final Draft and Final version of the SAP shall be <strong>de</strong>livered as a standalone documentby the Contractor according to section 13 of the <strong>SOW</strong>.1.5.2 Security Risk Assessment (SRA)a. The Contractor shall produce a Security Risk Assessment (SRA), i<strong>de</strong>ntifying the threatsand vulnerabilities to the system, <strong>de</strong>termining their magnitu<strong>de</strong> and i<strong>de</strong>ntifying areasneeding safeguards or countermeasures.b. Objective of the SRA is to <strong>de</strong>fine the security objectives of confi<strong>de</strong>ntiality, availabilityand integrity/authenticity of the <strong>de</strong>signed GAG system according to the particularservices to be provi<strong>de</strong>d by the resulting GAG system, the values of the traffic andinformation stored and transported over the GAG system, and the nature and levels ofthe particular threats being i<strong>de</strong>ntified.c. The SRA may be composed as a standalone document, but may instead be inclu<strong>de</strong>d inthe SSRS and SISRS documents (ref. 1.5.3 and 1.5.4 below). If composed as astandalone document, the Contractor shall insert appropriate cross references from theSSRS and SISRS documents to the applicable sections in the SRA.d. This Risk assessment shall be <strong>de</strong>veloped in accordance with the gui<strong>de</strong>lines contained inabove Reference B.1.5.3 System Specific Security Requirement Statement (SSRS)a. The Contractor shall <strong>de</strong>velop a System Specific Security Requirement Statement(SSRS) <strong>de</strong>scribing the entire GAG system architecture, including all its assets and therelated security requirements, the security environment, security measures and securityadministration that have to be implemented in support of the system.b. This SSRS shall be <strong>de</strong>veloped in accordance with the gui<strong>de</strong>lines contained in aboveReference C.1.5.4 System Interconnection Security Requirement Statement (SISRS)a. The Contractor shall <strong>de</strong>velop a separate SISRS for each CE site and GAG site.b. In terms of interconnections between various networks or systems, for elements of theGAG system connected to or providing connectivity via the NDN or any other HostNation’s network or system, the particular National security requirements of the HostNation shall be taken into account.NATO UNCLASSIFIEDPage 5 of 14

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!