Combine Solicitation – Financial Statement Audit & Federal Information Security Management Act of 2002 Evaluation
| Federal Information & News Dispatch, Inc. |
Notice Type: Combine Solicitation
Posted Date:
Office Address:
Subject: Financial Statement Audit & Federal Information Security Management Act of 2002 Evaluation
Classification Code: R - Professional, administrative, and management support services
Solicitation Number: CCR-14-0001
Contact:
Setaside: N/AN/A
Place of Performance (address):
Place of Performance (zipcode): 20425
Place of Performance Country: US
Description:
Due to space limitations, the complete Solicitation is not posted here. The complete Solicitation may be requested via email to mailto:[email protected]. Please reference the Solicitation Number, CCR-14-0001, in your email.
This is a combined synopsis/solicitation for commercial services prepared in accordance with the format in FAR Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested and a written solicitation will not be issued.
Solicitation CCR-14-0001 is issued by the
Scope of Work
Financial Statement Audit (FSA)
The Contractor shall conduct an audit of Commission's annual financial statements. The audit shall be performed in accordance with generally accepted government auditing standards (GAGAS), as specified in the most current version of the
With respect to Required Supplementary Information (RSI) and Required Supplementary Stewardship Information (RSSI), the Contractor shall assess whether the information and its presentation is materially consistent with the information in the basic statements. In performing this assessment the contractor shall perform procedures consistent with AU [Section] 558, Required Supplementary Information.
With respect to internal controls, the Contractor shall obtain an understanding of the components of internal control and assess the level of control risk relevant to the assertions embodied in the classes of transactions, account balances, and disclosure component of the financial statements. Such controls include relevant information technology (IT) general and application controls and controls relating to intra-entity and intra-governmental transactions and balances.
To assess the effectiveness of the IT control environment, the Contractor shall, at a minimum, perform procedures over the following GAO Federal Information System Controls Audit Manual (FISCAM) general control areas:
Security management
Access controls
Configuration management
Segregation of duties
Contingency planning
With respect to compliance with applicable laws and regulations, the Contractor shall perform tests of compliance with laws and regulations, including laws governing the use of budget authority laws, regulations, and government-wide policies identified by OMB, and any other laws and regulations that could have a direct and material effect on the basic statements.
Planning
The Contractor shall plan the audit work consistent with the FAM Section 200. The Contractor shall develop ways to obtain the evidence necessary to report on Commission's financial statements, internal controls, and compliance with laws and regulations. The Contractor shall receive approval from the Contracting Officer's Representative (COR) prior to the implementation of any changes to the scope of the audit. The Contractor shall conduct an entrance conference with key Commission officials for the financial statement audit. The entrance conference shall occur prior to the commencement of work. The Contractor shall coordinate with the COR to schedule these meetings.
Testing
The Contractor shall complete the following in accordance with FAM Sections 300 and 400:
determine the nature, timing, and extent of audit procedures
document the results of audit procedures performed
document conclusions reached
Audit procedures shall encompass tests of internal controls, tests of detail transactions and balances (substantive testing), and tests of compliance of laws and regulations. As necessary and based on testing performed, the Contractor shall develop findings and recommendations, as described in the FAM Section 580 and generally accepted government-auditing standards.
Reporting
The Contractor shall complete audit procedures, evaluate results and conclusions reached, and report results to the
Federal Information Security Management Act (FISMA) Evaluation
The Contractor shall develop an evaluation program that shall include the objectives of each program and steps that will be taken to accomplish the objectives, including the nature, timing and extent of evaluation procedures. The evaluation program shall conform to applicable OMB/DHS guidance. The evaluation program shall encompass the Program Areas referenced in SOW Section 2.2. The Contractor shall conduct an entrance conference with key Commission officials for the FISMA evaluation. The entrance conference shall occur prior to the commencement of work. The Contractor shall coordinate with the ACOR to schedule these meetings.
Evaluation of USCCR's Information Security Posture
The Contractor shall conduct an evaluation of Commission's compliance with FISMA and related OMB, DHS, and
Overall Security Management:
Development of Detailed IT Policies and Procedures
A Comprehensive Risk Management Process
A Comprehensive Certification and Accreditation Process
Effective Oversight of Contractors and Contractor Systems
An Agency-Wide Privacy Program
Effective Configuration Management Policies and Procedures
Program Areas:
Continuous monitoring management
Configuration management
Identity and access management
Incident response and reporting
Risk management
Security training
Plan of action and milestones
Remote access management
Contingency planning
Contractor systems
Security capital planning
Systems inventory
The FISMA evaluation shall be conducted in accordance with the
FISMA Evaluation Report
The Contractor shall perform evaluation procedures. The Contractor shall document results of testing and conclusions reached in accordance with FISMA, CIGIE Quality Standards on Inspection and Evaluation, and applicable annual instructions from OMB, DHS, and
OMB/DHS Reporting
The Contractor shall develop a draft FISMA evaluation report that includes the results of evaluation procedures and complies with applicable OMB/DHS guidance. This report is subject to ACOR approval prior to finalizing the form and content. The report shall include a section that describes findings identified during performance of FISMA evaluation procedures, including recommendations for management. The Contractor shall conduct an exit conference with key Commission officials for the FISMA evaluation. The exit conference shall occur upon completion of the evaluation. The Contractor shall coordinate with the ACOR to schedule these meetings. The Contractor shall conduct a lessons learned meeting with the appropriate Commission management representatives and ACOR to discuss and document the processes that were effective and those that could be improved during the subsequent year's contract performance.
The Commission is a micro-agency and must file reports via Cyberscope utilizing the metrics for micro-agencies. The draft reports for Cyberscope should consist of three separate reports: one utilizing the IG Metrics, one utilizing the CIO metrics and one utilizing the Privacy metrics..
Conduct Network Scan
The Contractor shall complete a Network Scan.
Deliverables
! No. ! Title ! Ref. !
! 001 ! Detailed Audit Planning Documents2 ! 2.1.1 !
! 002 ! Audit Programs ! 2.1.1 !
! 003 ! Internal Control Phase Documents ! 2.1.2 !
! 004 ! Interim Audit Documentation ! 2.1.2 !
! 005 ! Final Audit Documentation ! 2.1.2 !
! 006 ! Audit Reports (Draft and Final) ! 2.1.3 !
! 007 ! Management Letter Financial Statement Audit ! 2.1.3 !
! 008 ! FISMA Evaluation Program ! 2.2.1 !
! 009 ! FISMA Evaluation Documentation ! 2.2.2 !
! 010 ! FISMA Evaluation Final ! 2.2.3 !
! 011 ! Network Scan ! 2.2.4 !
! 012 ! Firm Memorandum for Independence and Quality Control, Peer Review Report and PCAOB Inspection Report ! 2.3.2.2 !
! 013 ! Statements of Independence and GAOCPE Compliance ! 2.3.2.2, 2.3.2.3 !
! 014 ! Non-Disclosure Agreements ! 2.3.2.4 !
! 015 ! Monthly Progress Reports ! 2.3.3 !
! 016 ! Technical Status Meeting Agendas ! 2.3.4 !
!
The period of performance for this task shall be from the date of award through
Offers will be evaluated in accordance with FAR 52-212.2 "Evaluation - Commercial Items, which is incorporated into this solicitation with addendum to paragraph (a) as follows: the following factors shall be used to evaluate offers: (1) Technical Proposal, (2) past performance, and (3) price. The Government will make award to the responsible offeror whose offer conforms to the requirements herein and represents the best value to the Government. Contractor qualifications are more important than price.
Technical Proposal: The quote shall include (1) the technical approach, (2) qualifications of key personnel and other proposed staff, and (3) contractor's qualifications. The quote must provide resumes of all key personnel and other proposed staff. The resumes should indicate the proposed staff's knowledge and experience with conducting Financial Statement and FISMA audits on small Federal agencies. The quote must include the contractor's experience with conducting Financial Statement and FISMA audits on small Federal agencies.
Past performance: The quote shall include a minimum of three (3) references with a brief description of previous projects of similar size and complexity. Each example of past performance shall include: contract number; contract description; contract amount and type of contract; period of performance; name, address, Email address, telephone number, fax number (if Govt contract, provide the name, telephone number of contracting officer and the COR or if commercial, provide the technical and contracting equivalent); size and complexity of the project; and whether all options were exercised.
Pricing: The quote shall include the following information: (1) a breakdown of labor categories, fully burdened hourly rates for all proposed personnel under each effort as outlined in the Statement of Work, (2) a breakdown of the number of proposed hours in sufficient detail to allow the Government a good understanding of your planned technical approach and the ability to review the consistency between the planned technical approach and the proposed pricing. Appendex B should be used to provide a breakdown and summary of the price proposal quote.
The proposal shall not exceed 25 pages - resumes excluded.
The following Federal Acquisition Regulation (FAR) provisions and clauses in effect through FAC 2005-03, dated
All RFQs received in mailto:[email protected] must be received by the deadline specified on http://www.usccr.gov/ [http://www.usccr.gov]. USCCR accepts no liability for the problems that are encountered by your email system. Please check for any viruses or security problems with your system before sending an email to this account. We will not accept any RFQs after the posted deadline.
Point of contact:
Place of Performance:
Link/URL: https://www.fbo.gov/spg/USCCR/USCCR/USCCR1/CCR-14-0001/listing.html
| Copyright: | (c) 2013 Federal Information & News Dispatch, Inc. |
| Wordcount: | 2192 |


Presolicitation Notice – Medical Claims Adjudication
Advisor News
- A new era of advisor support for caregiving
- Millennial Dilemma: Home ownership or retirement security?
- How OBBBA is a once-in-a-career window
- RICKETTS RECAPS 2025, A YEAR OF DELIVERING WINS FOR NEBRASKANS
- 5 things I wish I knew before leaving my broker-dealer
More Advisor NewsAnnuity News
- An Application for the Trademark “DYNAMIC RETIREMENT MANAGER” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
- Product understanding will drive the future of insurance
- Prudential launches FlexGuard 2.0 RILA
- Lincoln Financial Introduces First Capital Group ETF Strategy for Fixed Indexed Annuities
- Iowa defends Athene pension risk transfer deal in Lockheed Martin lawsuit
More Annuity NewsHealth/Employee Benefits News
Life Insurance News
- A new era of advisor support for caregiving
- An Application for the Trademark “HUMPBACK” Has Been Filed by Hanwha Life Insurance Co., Ltd.: Hanwha Life Insurance Co. Ltd.
- ROUNDS LEADS LEGISLATION TO INCREASE TRANSPARENCY AND ACCOUNTABILITY FOR FINANCIAL REGULATORS
- The 2025-2026 risk agenda for insurers
- Jackson Names Alison Reed Head of Distribution
More Life Insurance News