Loading...
The URL can be used to link to this page
Your browser does not support the video tag.
Home
My WebLink
About
Professional Services Proposal - Criminal Justice Information Security Compliance Gap Assessment – Crowe LLP
1316 COUNTY -CITY BUILDING 227 W.JEFFERSON BOULEVARD Sol iTH BEND. INDIANA 46601-1830 CITY OF SOUTH BEND PETE BUTTIGIEG, MAYOR BOARDU LIC WORKS December 19, 2019 Mr. Mike Del Giudice Crowe LLP 330 E. Jefferson Blvd. PO BOX 7 South Bend, IN 46624-0007 RE: Professional Services Proposal Dear Mr. Del Giudice: PHONE 574/235-9251 FAx 574/235-9171 The Board of Public Works, at its meeting held on December 19, 2019, approved the above referenced professional services proposal for the criminal justice information security compliance gap assessment in the amount of $22,000. Enclosed please find the original of the contract for your signature. Please sign and return the original agreement to our office and retain a copy for your records. If you have any further questions regarding this matter, please call this office at (574) 235-9251. Sincerely, Linda M. Martin, Clerk Enclosure GARY A. GILOT GENEVIEVE E. MILLER ELIZABETH A. MARADIK LAURA L. O'SULLIVAN THERESE J. DORAU Crowe LLP Independent Member Crowe Global 330 East Jefferson Boulevard Post Office Box 7 South Bend, Indiana 46624-0007 Tel +1 574 232 3992 Fax +1 574 236 B692 www.crowe,com October 24, 2019 Dan O'Connor City of South Bend 227 W. Jefferson Blvd South Bend, IN 46601 Dear Mr. O'Connor Crowe LLP appreciates the opportunity to assist City of South Bend (South Bend) in assessing its Cybersecurity Risk by providing you this proposal for a Criminal Justice Information Security (CJIS) Gap Assessment. Crowe is an experienced, stable and well -respected consulting and accounting firm with a strong commitment to information Cybersecurity services. We have delivered high value to our clients for decades and we feel that we are the best firm to serve South Bend. Our goal is to work with you to deliver a unique solution that exactly meets your needs and value expectations. We wish to thank South Bend for taking the time to discuss and respond to our questions. Our proposed project scope and approach was customized based on your feedback. Based upon the requirements and desired outcome of this project, we feel that the Crowe Team has the unique capabilities to make this project a success. Crowe's Cybersecurity team performs over 200 assessments annually for our clients. We have worked with some of the state and local government organizations helping them with their information security needs, including: Gap analysis against industry regulatory requirements (e.g. CJIS) and industry frameworks (e.g. ISO 27000) Design and implementation of organization wide Information Risk Management programs Performing Enterprise IT Risk Assessments Data inventory, data classification, and data protection initiatives Risk, and controls review of third party vendors Internal and External Penetration Assessments, including social engineering Application Security and Penetration Assessments We look forward to the opportunity to assist South Bend in this project and will provide you our closest attention. If needed, we would be happy to work with you to further customize this proposal relative to scope and fees. Should there be any questions with regard to our proposal, please contact me at 630.575.4359 or via email at mike.delgiudice@crowe.com. We welcome further discussion with you and other representatives from South Bend regarding our proposal. Sincerely, Mike Del Giudice Principal Proposal to Provide CJ I S Gap Assessment October 24, 2019 Submitted to: Dan O'Connor City of South Bend 227 W. Jefferson Blvd, South Bend, IN 46601 Submitted by: Mike Del Giudice Crowe LLP 330 East Jefferson Boulevard South Bend, Indiana 46624-0007 Tel 630.575.4359 Mike.delgiudice@crowe.com Proposal to Provide WIS GapAssessment City of South Bend Table of Contents Crowe's Cybersecurity Team................................................................................................................1 Industry Presentation and Publications...............................................................................................2 Collegiate Cyber Defense Competition...............................................................................................3 ToolDevelopment................................................................................................................................3 IndustryExperience ................ ..................... ......... ........... ........ .... — —.. ......... .......— .............._4 Government Practice ........................ ......... ........... .......... --....... ---.. , ........... ,. ,...,..—, --,. 4 Government Advisory Experience .... ......... ... ..... . ......... ......... .................. . „ ,,,... ,,,,.,.. ,-4 CJISGap Assessment...........................................................................................................................6 Crowe Integrated Cybersecurity Framework, ...................................................................................... 6 ProjectScope... ... .................... .. ...... ............ . ........... Deliverables.. „ .......... .. .... . ................. . ....... .. ..........---- ....... ...... ..... .. .... ..... 8 Feesand Assumptions........................................................................................................................12 Fees...................................................................................................................................................12 Assumptions......................................................................................................................................12 DeliveryTeam.......................................................................................................................................13 ProjectRoles......................................................................................................................................13 Appendix A — Delivery Team Resumes..............................................................................................15 © 2019 Crowe LLP www.Crowe corn Crowe LLP and its subsidiaries are independent members of Crowe Global, a Swiss organization. "Crowe' is the brand used by the Crowe Global network and its member firms, but it is not a worldwide partnership. Crowe Global and each of its members are separate and independent legal entities and do not obligate each other Crowe LLP and its subsidiaries are not responsible or liable for any acts or omissions of Crowe Global or any other Crowe Global members, and Crowe LLP and its subsidiaries specifically disclaim any and all responsibility or liability for acts or omissions of Crowe Global or any other Crowe Global member, Crowe Global does not render any professional services and does not have an ownership or partnership interest in Crowe LLP or any other member, Crowe Global and its other members are not responsible or liable for any acts or omissions of Crowe LLP and its subsidiaries and specifically disclaim any and all responsibility or liability for acts or omissions of Crowe LLP and its subsidiaries. Visit www crowe.com/disclosure for more information about Crowe LLP, its subsidiaries, and Crowe Global, Proposal to Provide CJIS Gap Assessment City of South Bend Crowe's Cybersecurity Team Crowe has worked with hundreds of companies across the United States and internationally to improve the quality of their Cybersecurity posture through risk assessments, penetration testing, Cybersecurity assessments, and the implementation of security/technology solutions. Crowe's Cybersecurity team consists of nearly 60 professionals in seven office locations who deliver the following services: Cyl:w raec uctt A.mm s=:rmxit InQ astrll::1we ,eciudy Assevsrrannt Penc.,trahon i ushng (Eatlrenal, Inlernzad Wirckss) Apaprloa.arion Reviews (Wat, ERP) CaraoigAance A: mnsnw=rxit, $H[PAA, PU F'FI C. GLDA) F3nnyRurvde f SecurOyRoadmafr T Se m. y System Desiypn IT Sacndly Vemkii- Selec4fon y'eagiry lnformMion and E,40M Management Advanced Erylpmnl Pvolectian Clow) Sec:unty Caavernarrce Risk and Conrownce Data Discovery and Data Ckrsiiicahoa Seckmiity i� i Olt Oi r {ill'isne"v, CoofinuRy Rw9 DmewK Recovwy Man Irwident FSe%xnw: Flan E'easswer9TandMudVWar Vulrwwalmlity Marrageaesa:nP F'roa. carat ,Security Awareners Pmiram VF;`dWr IlMnargeMP.rrt Data I...enkaW P" otecliun (V7LF. I T &-. u* Delaarbr nl Outsowun; Fturd Fixty Firogao a Aanaxgenw.nt l T Seck%Ry StO NfOlwns (lS0, Mauer, An;40) Can -De and Aprp kation Secufgy Der*tcpxi Fxcardses (80:1 R, IR) SecudN Irvellipixe IncrdeM Resgmnse and f onam;rs The team that would be constructed to assist you includes professionals who have functioned as CISOs, served as security administrators, and managed internal risk assessment functions. A large majority of our professionals, including all of our Managers and above, are certified and regularly speak on information security issues at national security conferences such. Crowe maintains multiple consultants that hold the following certifications: • Certified Information System Security Professional (CISSP) • Offensive Security Certified Professional (OSCP) • Offensive Security Certified Expert (OSCE) • Certified Ethical Hacker (CEH) • GIAC Penetration Tester (GPEN) • DIAC Web Application Penetration Tester (GWAPT) • Certified in Risk and Information Systems Control (CRISC) • CompTIA Security+ © 2019 Crowe LI_I I www,MOM corn Proposal to Provide CJIS Gap Assessment City of South Bend Industry Presentation and Publications A sample of Crowe's presentations and contributions to the Information Security community include: Blackhat - US 2017: During Blackhat 2017 Piotr Marszalik and Michael Wrzesniak, at Crowe, spoke about exploiting physical access gained during a penetration assessment to access to quickly and automatically extract hashes and plant backdoors on Windows systems. The creation of tool called "SmuggleBus" Iblackhed was the outcome of their research and is used by penetration testers today. Blackhat - US 2015: At the prestigious Blackhat Security Conference, Cybersecurity Consultants Mike McAtee and Lucas Morris unveiled "Cracklord", a new distributed �f password cracking system. This tool was built as a management platform '44'?, that load balances CPU/GPU resources from multiple hardware systems into a single queuing system DerbyCon 7: Crowe continues its security community contributions at Derbycon 7, where Jim Shaver and Mitch Hennigan spoke about the underlying architecture and security of Kerberos in an Active Directory environment. This research led to the discovery of optional weak encryption being available to be used by Kerberos. Additionally, several undocumented functions of Kerberos in Active Directory were discovered. DerbyCon 4: At DerbyCon 4 Ryan Reynolds spoke on the topic of advanced traffic manipulation techniques such as NetBIOS-NS/LLMNR, ARP -Spoofing, and IPv6 Stack precedence. These techniques are used by hackers to manipulate network traffic with the goal of gathering unauthorized access to sensitive data traversing the network during Internal Penetration Assessments. Also at DerbyCon 4, Lucas Morris showcased "RavenHlD". RavenHlD is a combination Arduino board/IOS application that ��j �r� can be used to collect badge information for cloning. This method is used to advance Crowe's social engineering testing for corporate client environments. DEFCON 22 & DEFCON 20: At Deacon 22 as well as Defcon 20; Lucas Morris and Mike McAtee rwk,� � . contributed to the Windows security world with a panel on their tool "Shareenum". It is a tool that can be used to enumerate Windows SMB shares, fingerprint systems, as well as test password re -use. "Shareenum" is made with �- r speed and scalability in mind for bulk system testing. BSides DFW 2013, 2016 and 2017: At BSides DFW; Ryan Reynolds, Chris Wilkinson, Brad Hannah, Mitch Hennigan and John Alves have presented throughout the years on the latest tools and techniques used by consultants and attackers in the Cybersecurity community. Crowe continues to speak at local events on a regular basis on a variety of Information Security topics. C9 2019 Crow: LLP www. Crowe. cony Proposal to Provide CJIS Gap Assessment City of South Bend Crowe has been involved a number of other presentations, some examples include: • "Anatomy of a Breach" at the University of Texas at Dallas Fraud Conference in 2016 • "The Three Lines of Defense" at North American CACS in 2016 • "Forensics Investigations" at the University of Texas at Dallas Fraud Conference in 2015 • "Network Security Trends" at the AICPA National Conference in 2014 • "Anatomy of a Breach" at the San Francisco ISACA Fall Conference in 2014 • "Penetration Testing: Lessons Learned" for the Texas Bankers Association in 2014 • "CyberSecurity Trends" at the 2013 American Bankers Association National Convention • Presentations on Penetration Testing and Business Continuity at ISACA's Geek Week Collegiate Cyber Defense Competition The Collegiate Cyber Defense Competition is an event held annually to assess an institutions student's depth of understanding and operational°�r rti. competency in managing the challenges inherent in protecting a 01011 E adr, ITT corporate network infrastructure and business information systems. The C,YHEPit SE competition is structured to score University's "Blue Team" Defense ('011 �'yll p Y (Defense) � ��,��rr�-� a ui IHm+S ability to defend their environment against a simulated hack coordinated by the "Red Team" Professional Penetration Testers. Crowe Cybersecurity Consultants have been invited to participate on the Red Team for the following contests: • Nationals (2018, 2017) • Mid -West Region (2013 - 2017) • Northeast Region (2017, 2013, 2011, 2010) • Southwest Region (2017) Crowe has invested a significant amount of research and development time into becoming a forefront industry leader in Information Security. Our technology risk professionals have in-depth knowledge not only of the industry standards for Information Security, but also the practical implementation of these standards in accordance with business processes and drivers. Tool Development A continuous development and review process is facilitated to ensure that clients are receiving the best of breed tool suites; whether commercial, in-house developed, or publicly available. A sample of the tools that Crowe has contributed to the Information Security community include: • cm-directory-enum (2018) • echidna (2017) — Presented at DerbyCon • SmuggleBus (2017) — Presented at Blackhat & DerbyCon • ad-Idap-enum (2016) • Go-SSHscan (2016) • Cracklord (2015) — Presented at Blackhat • RavenHID (2014) - Presented at DerbyCon • Share-Enum (2013) — Presented at DEFCON Crowe recognizes that highly technical engagements such as Penetration Testing and IT Forensic Assessments require significant investments of both key personnel and resources. In identifying this requirement, Crowe has not only created a dedicated Cybersecurity team, but also focused that team to establish the Crowe Center for Cyber Security. This Center serves as a foundation in technology assessment services, ensuring that our team stays on the cutting edge of the security field. &> I019 Crowe LLP ewww.rrow¢:,com Proposal to Provide CJIS Gap Assessment Industry Experience Government Practice City of South Bend Crowe has been serving the needs of many different types of government organizations for more than 40 years. We help governments better serve their communities by providing professional, objective solutions that meet their needs and the needs of their key stakeholders. Crowe solutions help address the financial and operational issues most critical to governments. Crowe serves more than 600 governmental entities nationally. Government Advisory Experience Government ,19y Get the right support to overcome challenges and deliver superior service We serve hundreds of state and local governments nationwide and work on thousands of engagements Our team of governmental specialists — many of whom are former elected or appointed officials — can provide you the thought leadership and technical expertise you need. Today's government leaders are charged with delivering superior service in the midst of declining revenues and funding, greater public demand, and increasingly complex regulations. At Crowe, we strive to help governments better serve their constituents by providing solutions that improve performance, optimize revenue, and manage risk. Crowe's innovative solutions help address the financial and operational issues most critical to governments in challenging economic times. Our extensive scope of competencies — business process, technology, finance, accounting, fraud investigation, risk consulting, economic development, and performance - allows us to deliver effective, cost-efficient services. We believe quality work, based upon strong competency and directed towards our clients' needs, are the core elements of creating value for our clients. We have delivered high value to our clients for decades, and we feel we are well -suited to help the City with its needs. Crowe has extensive experience serving State and Local Government clients in a variety of project roles. We deliver successful projects in the governmental arena due to a number of factors, including initial relationship -building to understand each client's distinct risks, resource constraints, political environment, stakeholder groups, and jurisdictional focus. Regardless of the type of project undertaken, these issues are inherently part of Crowe's approach in working with public sector clients. Listed below are select government clients for whom we have provided a range of IT security, management consulting, advisory, and audit services over the past five years. We have provided references for bolded clients. In addition, we have include applicable references for Private Sector BIA clients to further demonstrate our subject matter expertise. 2019 Crowe I...ILP wvvvw coarrnre.. corn Proposal to Provide CJIS Gap Assessment City of South Bend 5 Marion County Information Services Agency ' IT Strategic Planning and (IN) Chargeback Model Development Franklin County Children Services (OH) IT Strategic Planning, Business Process Reengineering Counties Cook County Clerk of the Circuit Court (IL) Case Management System Needs Assessment DuPage County (IL) Financial Audit Services Penetration Testing, Lake County (IL) Cybersecurity Gap Assessment City of Aurora (IL) Penetration Testing Town of Zionsville (IN) IT Roadmap Development City of Chicago (IL) Web Development and Planning Services Municipalities City of Des Plaines (IL) Financial Audit Services City of Fort Worth (TX) CAFR Preparation Village of Northbrook Cybersecurity Gap Assessment and Roadmap Minnesota State Retirement Systems IT Risk Management Indiana Economic Development Commission IT Roadmap Development State Agencies Arkansas Department of Information Services OMB Circular A-87 Compliance Illinois Department of Corrections GAAP Package Preparation Indiana Public Retirement System Gap Assessment, Business Impact Analysis College of Lake County (IL) Financial Audit Services City Colleges of Chicago (IL) Internal Audit Services Chicago Retail Transit Authority Penetration Testing, Cybersecurity Assessment Special Districts Illinois Municipal Retirement Fund Penetration Testing, Cybersecurity Assessment and Colleges Berea College Cybersecurity Gap Assessment Joliet Junior College Penetration Testing, Cybersecurity Assessment Alice Lloyd College Cybersecurity Gap Assessment (-) 2019 Crowe I...I.. P 'Annm crovve. corn Proposal to Provide CJIS Gap Assessment City of South Bend CJIS Gap Assessment Crowe Integrated Cybersecurity Framework Determining an appropriate control framework for cybersecurity is challenging for even mature organizations. The complexities and nuances with existing regulatory requirements (e.g. HIPAA) combined with industry standards (e.g. NIST Cybersecurity Framework) make managing control expectations nearly impossible. To help address this challenge, Crowe has established the Crowe Integrated Cybersecurity Framework (CICF). Defining a comprehensive cybersecurity risk and control framework that seamlessly integrates with existing regulatory and industry guidance is integral for organizations looking to efficiently evaluate and manage their cybersecurity risk. The framework was established by mapping controls across common regulatory standards and industry frameworks to correlate controls. Controls could be categorized based on like themes, and these themes were utilized to create an integrated control requirement. By correlating the controls, this integrated control can be defined in a way that includes a single test procedure that allows the organization to understand compliance with all common control requirements across the different standards. For example, password policies are addressed within the majority of cybersecurity regulatory standards and industry frameworks. Leveraging the CICF, Crowe will test this control one time, but be able to conclude on organizational compliance across the different standards, allowing for an efficient, but comprehensive evaluation process. Crowe's framework includes: • Regulatory requirements, such as the Criminal Justice Information Security Policy (CJIS), FFIEC Cybersecurity Assessment Tool (FFIEC CAT), and the Health Insurance Portability and Accountability Act (HIPAA) • Industry frameworks, such as NIST 800-53 r4 and the NIST Cybersecurity Framework (NIST CSF) The CICF is a dynamic framework, continually being modified to accommodate changes in standards and to incorporate additional standards as necessary. Currently, Crowe's CICF consists of fourteen unique control domains defining a comprehensive cybersecurity risk and control universe. (02019 Crowe LA F' www,crowre. cam Proposal to Provide CJIS Gap Assessment City of South Bend 7 ' Data Pratectian Pl W aX socuannyr Ihreat & Vtulneralsility IAardoglarr u„.:.esrintrltia sarm^;ua Secure Sl Security Dt ange Management ,,all soc;euuti¢y Lagging and IMonitouing I I Ol�aerahorv; Ilhusirross Goinilllr uilly II'Wan,,:u¢ oruucint ' Secorty Condiguratsan Management ' -third Party Fisk Managernent Uerprl hNrar'tt;r{Ia' ollf"rrlt These domains are divided into unique control categories that contain a series of controls and test procedures. _..--'IIllfl PFI',MND ,.._.. L.&l PefYSll'; I�'#h,IF%Nf,f':: t(I fl Ifll PiFkf^III Vl...^G 11' • <f ll ��n r�rJl fl "pi r.r ,; lbhrrrlAGf ININ"I rf 1�%3iH I ` J' .n 1'r II�"wit "' ` 'wl" `1 I,I III V Irtl�t'I -P_i lJ I ' I AIr, 411WYII CItUNI 11tr tit l`71 r I v 1..5,:9r DING AIIJI) n'.e I Il ICNI. r CU 0Y ' fj mllml INRf INI YfdIdIlWr!! ., n.,i,F ei. r.l f�i, "�NF JFrrc;ilc_'A ukum "I'I ,; on If.a1 I I` fYl I 01114;}NS rl ' r ,, lly I+ „,I'14,I lI II'r f,I 1GtIvIf'IC'. l+flAIQA('P lAll:lNII. - r�..�a n. 1 f•.inl ;, liu=Rrrh '-1 I^.� i,f re Organizations can identify those regulatory requirements and industry standards they wish to include, and the CICF allows Crowe to dynamically create a custom risk and control universe specific to each organization. Project Scope Based on our understanding of your needs, Crowe will utilize the CICF to complete a CJIS Gap Assessment for South Bend. CJIS consists of thirteen policy areas, each of which will be evaluated as part of this engagement: • Policy Area 1—Information Exchange Agreements • Policy Area 2—Security Awareness Training • Policy Area 3—Incident Response • Policy Area 4—Auditing and Accountability • Policy Area 5—Access Control • Policy Area 6—Identification and Authentication • Policy Area 7—Configuration Management • Policy Area 8—Media Protection • Policy Area 9—Physical Protection 02019 Crowe I..I...I' vwuw, crowe.. cam Proposal to Provide WIS Gap Assessment City of South Bend 8 • Policy Area 10—Systems and Communications Protection and Information Integrity • Policy Area 11—Formal Audits • Policy Area 12—Personnel Security • Policy Area 13 — Mobile Devices Deliverables Crowe will provide the following deliverables as part of this engagement: Deliverable Brief Description Exit Meeting Document Document presented at the end of the fieldwork to facilitate a discussion on the •m.,o,.� results of the engagement prior to formal reporting. R)"OV"w,, CJIS Gap Assessment Report PowerPoint summarizing the current state of the Summary of Compliance Status organization against the CICF. SAW on f& mwmmm,nncmwnm. Goon oMavW tN W,tea: RROHoowu N, no wPM9 f,mt avmw'd m f."NWwo mn'm mm'a,," 4alw'imBEwftm n, wN w4 mass ,�""• RiuAIa�YMkns[riadimMr� me r �u Ewa wank e,ewim�ramm armrn,� mRaarw?ma �"'"'�'" _-. mow mwmrcaaznm,mw nay b* mimmum nvaam6�wrewAw ku!Onw o�mmm00 on o- @�OUA; Ur IA!WY-4�1V IPu irwsuNn'lmu �mwwmrcaroAmnNAsuBaUmiM,µ m"aromauw.k V�.wnfa'r• imimuuumro _.... � w,mrcmnamram. 49rw �n avhnmru rk ,x N, nun rawn,wn mWwauwawa+.� wwmwmwmu .. ky ONA y4lw w0 o rftaa¢rckra, RN@ml mm rrv; atl Ow UM ma'wuat mwo R% + tmmt+fto ,,aarmw'rmmOnmum,uu Won nMftd un uuem meummmorOK at Rho Appi' Y a,10VO GWfwVN4Pvwq On Rv ^uamm4A %ma d{YRN oo,%%wdgu we w 111111111111111110111 WABk,xdo,tl d RO Om mlA"O hmvvvd tl; ym Vky„pnd iv,,O*v mt ON 0e44W;,,.uA�m4l94; QOUVOI areb" w MA be Wrow Am wk Pw b w iraa WROP 1raamu w ARM k@umr mFWf4,0011 !mrNMmn�x.avreauum. w 6,uJA49 maawniuw (rri N aaa Ak"Vj, ➢rpwlVutik' mmA mu,m w a, uuuuuum mm��� mmm���uwuw�wuw�w u�urnrroa Amonmrcdra ra:iavwwrRu. � re�nwiammrmmommprom�iwum= .. 0) 20 9 9 Ormov we: a I ..I I W%1W. marmmnrt, maO M Proposal to Provide CJIS Gap Assessment City of South Bend .W II-. . . . . . . . . . . . . . . . . I'll, . ...... ..... . ........ . C 2019 Crowe LLP VVww. crowe.cOM Proposal to Provide CJIS Gap Assessment City of South Bend Project Approach Crowe anticipates each project will consist of three phases. / //%ORMYi r r // ii i %� /�OG �i/ R 0 c. d V All key planning activities may include internal stakeholders or (if applicable) third parties. • Confirm scope and approach for the engagement • Define Communications Plan • Identify Key Stakeholders • Finalize project timeline, target dates, and execution strategy • Discuss testing approach, sampling method, and determine sample • Develop and delivery requested items • Finalize a Project Plan • Conduct Kick-off Meeting • Plan logistics for fieldwork • Finalize format for final deliverables • Requested Items • Initial Interview Schedule • 3 weeks (includes time to respond to requested item) • 4 hours: Client will need to spend approximately 4 total hours for kick-off meeting and to gather requested materials. All key fieldwork activities may include internal stakeholders or (if applicable) third parties. • Review requested items • Conduct interviews with Key Stakeholders in order to assess the design of the control environment • Document design control gaps • Coordinate with Key Stakeholders to conduct testing • Conduct testing to evaluate control effectiveness (see potential testing approaches below) • Assess results of control testing and document gaps • Evaluate gaps against CJIS requirements • Completed work programs • Scan results from automated testing • 2 - 3 weeks • 4 — 6 hours per week: Key stakeholders will need to commit approximately 4 - 6 hours a week to participate in interviews and so support testing procedures. 10 • Create Exit Document • Conduct Exit Meeting with Key Stakeholders • Create and deliver technical document summarizing the engagement results in a spreadsheet (if applicable) • Document the Security Assessment Report with Gap Analysis, including: • Executive Summary • Dashboard of CJIS Compliance • Discussion of the Procedures Performed • Prioritized List of Gaps • Remediation Plan of Action with Milestones • Exit Meeting Document • Technical Document, spreadsheet summarizing any technical results of the engagement • Security Assessment Report, including Remediation Plan of Action • 3 weeks • 2 — 4 hours: Client will spend 2 — 4 hours participating in exit meetings, reviewing deliverables, and responding (if necessary) to the report. Providing a comprehensive solution is critical to the success of this project. Providing a combination of testing approaches will provide maximum value to validate the effectiveness of the control environment. The specific procedures to be performed will be determined during scoping and the initial interviews with Key Stakeholders. Some of the test procedures that could be included as part of the testing are: 0 Penetration Testing. Testing designed to mimic an attacker in an attempt to validate information Proposal to Provide CJIS Gap Assessment City of South Bend 11 security controls Internal Security Assessment. Authorized internal testing designed to discover and analyze systems for misconfigurations, vulnerabilities, and security controls weaknesses Proposal to Provide CJIS Gap Assessment City of South Bend 12 Fees and Assumptions Fees The following table lists proposed cost for each deliverable and the total fixed price based on Crowe's understanding of the project. �j/o:i %� j f ! /r/rrrrii . ,�% % /// rr� �/ii���% CJIS Gap Assessment Thirteen CJIS Policy Areas $22,000 Total $22,000 This engagement will be billed on a fixed fee basis in accordance with our proposed fee structure and audit project estimates. Travel and out-of-pocket expenses will be billed to South Bend at actual cost. Any other expenses will be discussed and approved in advance by you. The pricing in this proposal will remain valid for a period of 30 days from the date of this proposal. Assumptions Crowe assumes the following sample sizes and assumptions as relates to the security reviews described above: j%j/% 'iiir %% ,,,,,,v v,,, i • South Bend accepts all statements made within this document regarding scope. Information requested through a separate resource request letter will be gathered and available for our consultants upon arrival. • Your resources and subject matter experts will be available to participate in interview sessions, individual meetings, and conference calls as necessary to provide input about the technology, organization, and processes that are currently in place at the South Bend. General Project 0 Crowe consultants will have access to all necessary systems, Assumptions resources, and personnel for the duration of the engagement. • The Gap Assessment will focus on the South Bend Police Department, including tests of a sample of up to: • 225 mobile devices • 100 desktops • 25 servers • One Active Directory Environment • 2 unique applications Ali.) 2019 Crowe ILLP mfwvycruwre,co m Proposal to Provide CJIS Gap Assessment City of South Bend 13 Delivery Team The following sections describe the project roles and associated responsibilities. As with projects similar in size and structure, multiple project roles may be held by one or more individuals. Crowe may leverage the following key resources in order to staff the engagement: Mike Del Giudice Project Executive, Principal Trevor Krause Project Manager, Technical Lead Garrett Pieratt Project Consultant Mr. Del Giudice is a security and privacy thought leader, leading Crowe's Cybersecurity team in the Public Sector, while providing security services to a broad range of Fortune 500 organizations across industries Certifications include CISSP, CRISC, Mr. Krause has been performing Cybersecurity Assessments and Penetration Testing for clients in multiple service industries, including the Public Sector. Certifications include: CISSP Mr. Pierratt has been performing Internal, External, and Web Penetration Assessments for clients in multiple service industries, including the Public Sector. Mr. Jacoway has been performing Internal, External, Ian Jacoway Project Consultant and Web Penetration Assessments, as well as Cybersecurity Assessments, for clients in multiple service industries, including the Public Sector. Mr. Cockshott has been performing Internal, External, Peter Cockshott Project Consultant and Web Penetration Assessments, as well as Cybersecurity Assessments, for clients in multiple service industries, including the Public Sector, Mr. Bridges has been performing Internal, External, Obadiah Bridges Project Consultant and Web Penetration Assessments, as well as Cybersecurity Assessments, for clients in multiple service industries, including the Public Sector. Project Roles Project Executive The Project Executive's primary responsibilities include: • Assuring client satisfaction • Project Billing and Contracts • Making available the appropriate Crowe resources to accomplish the project objectives and address other needs and requests of the project team. • Assuring quality and direction of Crowe work in addressing the project objectives • Soliciting feedback regarding the project and Crowe's performance • Reviewing the overall progress of the project and assist with setting revised project direction (if required) • Provide project 'dash -board' review K32019 Cvowe h..IS, vvWW.. rrowe'GINm Proposal to Provide CJIS Gap Assessment City of South Bend 14 Project Manager The Project Manager oversees the day-to-day activities of the project (in conjunction with client Project Executive). They will share joint responsibility for the planning and execution of all Project activities. The Crowe Project Manager is primarily responsible for: • Assuring client satisfaction • Directing, making available and managing Crowe resources to accomplish the engagement objectives • Maintaining necessary communications with the entire Project Team • Performing detail planning, scheduling and execution of project activities within the overall plan • Assigning tasks to project personnel • Monitoring staff and Project progress • Managing risks and escalated issues from Project Team • Monitoring budgets, preparing reports and scheduling resources • Measuring project success against budget, original scope, business objectives • Assuming responsibility for planning resource requirements and coordinating the daily tasks of all Project Team members • Ensuring that all resources and their respective skills are optimally utilized • Providing quality assurance of work undertaken by staff assigned to the Project Project Specialists The Crowe Project Specialists are primarily responsible for the following: • Understanding the Project approach, targeted objectives and making informed decisions and recommendations throughout • Completing tasks and deliverables assigned by the Project Manager • Transferring the appropriate skills to your Project Team Members © 2019 Crowe LLP www. Crowe com Proposal to Provide CJIS Gap Assessment City of South Bend 15 Appendix A — Delivery Team Resumes We have provided resumes for the proposed engagement team on the pages below. Michaels J. Del Giudice Profile Mr. Del Giudice is a Principal in the Consulting Practice with 19 years of experience in the areas of information security and data privacy. He is a security and privacy thought leader, leading Crowe's cybersecurity practice for the Public Sector, while providing security services to a broad range of Fortune 500 organizations across industries. Professional and Industry Experience Mr. Del Giudice evaluates and developes solutions to improve IT capability, maturity, and governance. He is experienced in critical infrastructure environments, including insurance, financial institutions, energy, transportation, healthcare, and government sectors. Mr. Del Giudice assists management in the execution of security strategies, including the solution design, requirements gathering, and vendor selection. He also designs and implements customized cybersecurity frameworks addressing confidentiality, integrity, and availability requirements. Mr. Del Giudice has experience with data security, including data classification and inventory, control framework design and implementation, and data strategies. He designs and implements Business Impact Assessments, Business Continuity Plans, and Disaster Recovery Programs. Mr. Del Giudice understands Intellectual Property (IP) protection procedures addressing logical, physical, and business controls; and he has experience with multiple regulatory requirements, such as GLBA, HIPAA, NERC CIP, CJIS, and FTC Safeguards Rule, as well as security frameworks such as NIST 800-53, NIST Cybersecurity, and ISO. Education & Certifications • Bachelor of Science, Computer Engineering o University of Illinois I Champaign, Illinois • Certified Information Systems Security Professional (CISSP) • Certified in Risk and Information System Control (CRISC) 225 West Wacker Drive, Suite 2600 Chicago, Illinois 60606-1224 Direct 630.575.4359 Fax 312.899.5300 mike.deigiudice@crowe.com www.crowe.com Client Focus Services: • IT Risk Management • Data Security and Privacy • Security and Maturity Assessments • Security Consulting Publications and Speaking Engagements • FSA Times, "Have You Conducted a Data Protection Audit Lately?" • EUCI NERC Fundamentals course, "NERC CIP Compliance" and "NERC CIP Compliance" • Trained the Office of the Comptroller of the Currency (OCC) on IT security • IIA Chicago's annual seminar • NADA national conference, "Manage your IT Risk and Improve your Bottom Line,." • IIA, "Mobile Device Risk in an Increasingly Connected World." • NADA national conference, "Technical Security — Protecting your Dealerships Information Assets." • WI Automobile & Truck Association, the VT Automobile Dealers Association, and the Chicago Automobile Trade Association • Dealer Magazine and Digital Dealer, FTC's Safeguards Rule. • IIA IT Fraud seminar • OH Information Security Conference, "Security Strategy: Planning the Next 3 to 5 Years." Professional Affiliations • Institute of Internal Auditors • Chicago Chapter of ISACA (D 2019 Crowe L.1...P w p w.crowe, oxn Proposal to Provide CJIS Gap Assessment City of South Bend 16 Client Listing • Performed a maturity assessment of a large insurance provider's vulnerability management program and developed a roadmap to improve capabilities. • Assisted a large, multi -state insurance provider in designing and establishing an IT Risk Management Program, aligning the program with existing Enterprise Risk Management initiatives, executing an Enterprise IT Risk Assessment, assessing controls to mitigate risks, and designing strategies to treat risks. • Assisted a large government agency in addressing an executive order due to a data breach, which included performing a data inventory, classifying and stratifying data repositories, defining a cybersecurity framework, assessing controls, and defining a long term security roadmap. • Assisted a State agency in designing and implementing an Enterprise Risk Management Program, developed tools to support execution of the assessment, and trained personnel to manage the program on an ongoing basis. • Assisted an international hospitality company in designing and establishing an IT Risk Management Program, defined IT risk, risk appetite and risk tolerance, developed tools to support the risk management processes, assist with the integration of the process into the existing GRC platform, and helped with the integration of supporting risk management programs into the overall program. • Assisted a large insurance provider in assessing information security across the organization, including through application specific assessments of critical portals leveraged for claims management with members. • Assisted a large, multi -state insurance provider in developing a physical security strategy, including security guards, cameras, and ingress/egress doors to more effectively and efficiently manage physical security risks. • Assisted a large municipal utility by performing a mock audit against NERC's Critical Infrastructure Protection standards. • Assisted an electric and natural gas provider by conducting a mock audit against NERC's Critical Infrastructure Protection standards and performing penetration testing to identify organizational gaps, with follow-up procedures to help design and implement controls. • Assisted an Independent System Operator (ISO) deploying smart grid technology by designing a cybersecurity framework allowing them to oversee providers implementing the technology. • Assisted a large financial institution in developing a Business Continuity Program, including the performance of a business impact analysis, documentation of Business Continuity procedures, and development of test plans. • Assisted a university healthcare provider in evaluating existing disaster recovery procedures of key organizational applications and providing recommendations to address existing gaps. • Assisted an international manufacturing organization protect their intellectual property, particularly within new facilities and third party vendors located overseas, by helping define an information security framework and roadmap to address security gaps within the organization. • Assisted a large insurance provider by evaluating the maturity of the IT Security function, identified the organizations desired future state based on industry benchmark and organizational tolerances, and developed a roadmap to achieve desired organizational capability and maturity levels. • Assisted a large automotive retailer by assessing the maturity of the IT organization, provided recommendations to address identified organizational gaps, and providing ongoing support and guidance on strategic IT initiatives. • Assisted an automotive retailer in responding to an inquiry from the Federal Trade Commission, including a review ensuring they appropriately addressed the FTC Safeguards Rule. • Assisted an automotive retailer by evaluating physical and logical security controls in place to protect customer information and to satisfy regulatory requirements. • Assisted a large transportation organization in assessing security within their critical infrastructure technologies, including an analysis of the security controls and practices within their primary data center and signaling environments. Proposal to Provide CJIS Gap Assessment City of South Bend 17 488 Madison Avenue, Floor 3 New York, New York 10022-5702 u' I�' Krause Direct 212.750.2803 yrl , G.;q��SP - Senior Manager Fax 212.572.5572 trevor.krause@crowe.com www.crowe.com rt< Profile Client Focus Mr. Krause has been with Crowe LLP for nine years, providing Services: Cybersecurity services to clients in multiple service industries. . IT Risk Assessments • Cybersecurity Assessments (NYDFS, FFIEC CAT, NISI, Professional and Industry Experience NERcrcIP, PCI, FFIEC, GLBA, sax and HIPAA) Mr. Krause's is a member of the Cybersecurity public sector division, . Penetration Testing, Including Social a subdivision of Risk, which includes services such as security Engineering assessments, internal and external penetration testing, and Industries: supporting clients with compliance to various regulations and Public Sector security standards. Cybersecurity assessments include all elements Financial Services of an organization's Information Technology infrastructure which include, but not limited to: Community Involvement • IT Management and Governance, Junior Achievement • Application Infrastructure, • Server Infrastructure, • Network Infrastructure; and • Endpoint Management. Mr. Krause has provided Cybersecurity services assisting various industries to develop a Cybersecurity Maturity Assessment based on NIST Cybersecurity Frameworks (NIST PRISMA, NIST Cybersecurity, NIST 800-53, NIST 800-171) requirements by: • Perform monitoring procedures of internal controls and identify compliance and control effectiveness with the NIST Frameworks; • Proactively identifying the threats that present the greatest risks; and, • Documenting overall risk values and recommendations. Professional Affiliations • Information Systems Security Association (ISSA) Education & Certifications • Bachelor of Science, Information Technology o Drexel University I Philadelphia, Pennsylvania • Certified Information Systems Security Professional (CISSP) u' 2019 Crowe IJ._r' www urrawe, aNn Proposal to Provide CJIS Gap Assessment City of South Bend 18 541 Darby Creek Road, Suite #270 Lexington, Kentucky 40509 Gaut" 'tt Pier tt Cell: 859.445.4522 1iechncdr)gy Risk Consultant Office: 859.263.7344 garrett.pieraft@crowe.com www.crowe.com Profile Client Focus Garrett Pieratt is a staff consultant in Crowe's Technology Risk Services: Consulting Practice with experience in Cybersecurity Cybersecurity Assessments Assessments and SIEM monitoring and analysis. Security Information and Event Management (STEM) Industries: Professional and Industry Experience Healthcare Garrett interned at SDGblue with the Security team, preforming Public Sector information security assessments as well as working on development projects, before becoming a full time employee in Septermber 2016. He became a Crowe employee when SDGblue was aquired by Crowe. He has worked with teams responsible for providing various IT security services, including: • Internal and External security assessments • Network, Host, and Physical assessments • SIEM monitoring and analysis Education & Certifications • Bachelor of Science, Information Communication Technology, Minor in Computer Science o University of Kentucky i Lexington, KY (W 2019 Crowe L.A 1:1 Mm cro;Ne COO Proposal to Provide CJIS Gap Assessment City of South Bend 19 3815 River Crossing Parkway, Suite 300 Peter E . Cockshott hott Indianapolis, Indiana 46240-0977 ..t"echir ology Risk, Consultant Direct (317) 208-2524 Peter.Cockshoft@crowe.com www.crowe.com Profile Client Focus Mr. Cockshott is a consultant in Crowe's Cybersecurity Risk Services: Consulting Practice with experience in Cybsersecurity Penetration Testing Governance Assessments, Network Security Assessments, Cybersecurity Assessments External/Internal Penetration assessments and Third Party Risk Third Party Risk Assessments Assessments. Industries: • Financial Services Professional and Industry Experience Public Sector • Healthcare Mr. Cockshott interned at Crowe with the Techology Risk — Security and Privacy group, before becoming a full time Technology Risk Consultant in the Indianapolis office in September 2017. He has worked with teams responsible for providing various IT security services, including: 0 Internal penetration tests External penetration tests • Network and System Security assessments • Social Engineering and Physical Security reviews • Third Party Risk Assessments • Information Security Governance Assessments Education & Certifications • Bachelors of Science, Informatics & Computer Science w/ Cognate in Cybersecurity o Indiana University I Bloomington, Indiana Qo K 19 Crawre: LJ....p WWW crcaWO aaOM Proposal to Provide CJIS Gap Assessment City of South Bend 20 225 West Wacker Drive, Suite 2600 lain Jacoway Chicago, Illinois 60606-1224 Direct 312.606.7156 'rechnohogy R sk ConSLIulllsint ian.jacoway@crowe.com www.crowe.com Profile Client Focus Mr.Jacoway leverages 5 years of experience in computer services: science, privacy, and security. He joined the Cybersecurity team • Penetration Testing as a staff member leveraging his prior network development • Cybersecurity Assessments projects, dedicated interest in the field, and involvement on • Wireless Security Testing multiple subversive security assessments. Ian has also • Social Engineering evaluated a Fortune 500 organization's security assessment • Health Checks solution as well as numerous finniancial intitutions. Industries: • Financial Services Professional and Industry Experience Healthcare Ian has worked on teams responsible for providing various • Higher Education Public Sector Cybersecurity services and IT Audit services, including: Retail Dealer • Internal and External Penetration Tests • Network and System Security Assessments • Cybersecurity Health Checks • Security Maturity Assessments Education & Certifications • Bachelors of Science, Computer Science • Minor in Applied Mathematics o Worcester Polytechnic Institute I Worcester, MA (,) ) 119 Crowe 1.6 P wwwr.Gu'r„ WC, COO BOARD OF PUBLIC WORKS AGENDA ITEM REVIEW REQUEST FORM Date Name 12/09/19 Daniel O'Connor Department Innovation & Tech BPW Date 12/19/19 Phone Extension 6201 �iamwiNNNNNNummmumr�woium... m�uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuumuuuwiwowwmmuwimmuw�ire �rw,mr�mwm�orvmmmmomomom�mmarm�ummurur�wimm Required Prior to Submittal to Board Legal Attorney Name Sandra Kennedy Controller review is required for all Contracts $5,000.00 or more Controller and greater than one year in length per the City Purchasing Policy Purchasing Z Check the p L J' Agreement Professional Services Bid Opening ❑ Quote Opening F] Chg Order No. Ease./Encroach. IN Other: Company or Vendor Name New Vendor MBE/WBE Contractor Project Name Project Number Funding Source Account No. iropriate Item T e — Re u�red fore 11 Submissions Contract Z Pro osalI Addendum �❑ Amendment ❑ Bid Award ❑ Req. to Advertise ❑ Title Sheet Quote Award CAI C/O & PCA No.. PCA Traffic Control ❑ Resolution Claim Reeuired Information ❑ Yes.L.L..P............._❑......If Yes, Approved by....Purchasi_ng.............. "�' No ❑ MBE Completed E-Verify Form Attached ❑ Yes �J WBE 0 No Proposal for Crowe LLP Professional Services to perform a CJIS compliance aap analysis for our public safety team IT Professional Serices 279-0672-415.31-06 Amount $22,000 One-time expensew Terms of Contract Proposal for a one-time professional services Expense ... Purpose/Description This is a ro osal for Crowe LLP to erform a one-time rofdssional services e a ement to do a CJIS Com liance Ca Assessment. For Char q d rs Qp! �] Increase $ Amount of �.�.�w .-�-�-� F Decrease $ Previous Amount Current Percent of Change New Amount Total Percent of Change: Time Extension: Dispersal After Approval Copy Original ® ❑ Mic_haelSniadecki ® ❑ Dan O'Connor ® ❑ Shawn.....DW w.w. elahanty Information Technologies Department 227 W Jefferson Blvd (574) 245-6000 TO: Board of Public Works, Linda Martin CC: Dan O'Connor, Michael Schmidt, Sandra Kennedy, Daniel Parker, Ben Dougherty, Clara McDaniels FROM: Daniel O'Connor SUBJECT: Proposal for Crowe LLP Professional Services to perform a CJIS compliance gap analysis for our public safety team DATE: 12/09/19 Linda, Sandra, Dan and Michael, Please see the attached proposal to for a professional services agreement with Crowe LLP. This proposal for a 2020 professional services engagement would be for Crowe LLP to perform a Criminal Justice Information Systems (CJIS) gap analysis for the South Bend Police Department. The dollar amount for this proposal request is a one-time cost of $22,000, Thank you Daniel O'Connor