Extracted text (via pymupdf)
15727 characters
2021 State Homeland Security Grant Application Submitted by Seema Sewell on February 16, 2021 - 3:07pm PROJECT ADMINISTRATION PROJECT DESCRIPTION Subrecipient Agreement #: 210206-01 Project Title: Cyber Security Protection for Local and Tribal Governments Project Summary: Maricopa County, on behalf of the Central region, is applying for the Arizona Department of Homeland Security grant to provide important cyber security products to local and tribal governments in Arizona. Maricopa County, on behalf of the Central region, will MOU the award to the State of Arizona, Department of Administration (ADOA) to continue the existing cyber grant program. For the previous two years 40+ local governments have participated in the cyber grant program awarded to the ADOA to leverage the buying power of the ADOA Enterprise Security team, and the expertise of ADOA and the multi-jurisdictional team created for the current grant program. Many local and tribal governments have cyber gaps because they do not have the resources, knowledge or the budget to purchase and install best practice cyber security tools to protect their data and their networks from compromise. Since local, tribal, and state government systems interconnect to each other we are all at significant risk of attack or compromise. The State and ADOA have successfully implemented an enterprise cyber security controls program across more than 86 state agencies and are using the success of that program and economies of scale to provide some of those products to local and tribal governments who are unable to budget or do not have the knowledge resources to implement those cyber products. These products can fit into three categories: 1) visibility of threats or gaps, 2) hunting for compromises, or 3) education of users. For FFY 2020, ADOA was awarded Arizona Department of Homeland Security SHSGP grant for Security Awareness and Anti-Phishing Training (SAT), Multi Factor Authentication (MFA), and Web Application Firewall (WAF). They were also awarded a UASI grant for Advanced Endpoint Protection (AEP). This is an increase over the FFY 2019 award and successful program for SAT. For more information visit: https://aset.az.gov/local-tribal-cyberprogram A multi-jurisdictional team was developed to notify local and tribal governments statewide of the products and licenses available and to assist the organizations with on-boarding and deploying these cybersecurity products to their organizations. As of February 2020, more than 43,000 combined licenses (SAT, AEP, MFA, & WAF) have been requested by more than 70 local or tribal governments through the online request forms and additional local and tribal organizations have shown interest in participating. Our primary objective and priority is the continuity and sustainment of the current grant program at FFY 2020 award levels. To sustain the current grant program Maricopa County, on behalf of the Central region, and four other local governments in each of the 5 AZ Homeland Security regions are each applying for a portion of the total program. Reduction or elimination of this grant would require some or all program participants to discontinue use of these cyber products increasing risk to systems and data and negating the efforts of the applicants to onboard and operationalize these products. This grant application will identify the primary priority (Priority 1) in the Funding Priorities section of this application for sustainment of current program. We will also identify expansion Priorities 2, 3, and 4 if there are opportunities to expand this grant program. Organization Name: Maricopa County Printed on 09/22/2021 COMMENTS / REVIEW Funding Year: 2021 Performance Period: October 1, 2021 to September 30, 2022 Award Letter Date: September 20, 2021 Award Docs Return by Date: Monday, Jan. 31, 2022 Award Exp Start Date: Friday, Oct. 1, 2021 EHP: A APPLICANT CONTACT Applicant Title: Cyber Security Senior Manager Applicant Name: Seema Sewell Applicant Email: seema.sewell@maricopa.gov Applicant Office Phone: (602) 506-0548 Address: 301 S. 4th Ave Phoenix AZ 85003-2445 Printed on 09/22/2021 HEAD OF AGENCY CONTACT Head of Agency Title: CIO Head of Agency Name: Ed Winfield Head of Agency Email: ed.winfield@maricopa.gov Head of Agency Office Phone: (602) 372-1333 PROGRAM CONTACT Program Contact Title: Cyber Security Senior Manager Program Contact Name: Seema Sewell Program Contact Email: seema.sewell@maricopa.gov Program Contact Office Phone: (602) 506-0548 Printed on 09/22/2021 FISCAL CONTACT Fiscal Contact Title: Director Fiscal Contact Name: Cindy Goelz Fiscal Contact Email: cindy.goelz@maricopa.gov Fiscal Contact Office Phone: (602) 506-4010 Address: 301 W Jefferson St Phoenix AZ 85003-2102 AGENCY DEMOGRAPHICS Number of sworn personnel: 0 Specialized Team Project Supports: None INITIATIVES Initiatives: Strengthen Cybersecurity Capabilities Is this project a Law Enforcement Terrorism Prevention Activity (LETPA)?: No Project Type: Establish/enhance cyber security program THREAT PROFILE 1. What is the terrorism threat your area faces that will be addressed by this project?: Cyber Attack 2. Explain how this project will assist your agency in preventing/protecting against/mitigating/responding to/recovering from all hazards events and threats including your chosen Printed on 09/22/2021 terrorism threat in question 1.: To increase visibility and protection of threats or fills cyber gaps, assist the hunting and detection of compromises, and provide security awareness education to end users. 3. Mission Area > Core Capability: Protect › Cybersecurity 3a. Capability Target > POETE > Gap: Every 1 year, appropriate authorities review and update cyber incident plans/annexes based on evolving threats covering 25 publicly managed and/or regulated critical infrastructure facilities. › Equipment › Controlling electronic access Every 1 year, appropriate authorities review and update cyber incident plans/annexes based on evolving threats covering 25 publicly managed and/or regulated critical infrastructure facilities. › Equipment › Detecting malicious activity Every 1 year, appropriate authorities review and update cyber incident plans/annexes based on evolving threats covering 25 publicly managed and/or regulated critical infrastructure facilities. › Equipment › Protective measures Every 1 year, appropriate authorities review and update cyber incident plans/annexes based on evolving threats covering 25 publicly managed and/or regulated critical infrastructure facilities. › Equipment › Technical countermeasures Every 1 year, appropriate authorities review and update cyber incident plans/annexes based on evolving threats covering 25 publicly managed and/or regulated critical infrastructure facilities. › Training › End-user awareness 4. What resources does your agency have to support the capability target selected above?: The State of Arizona has implemented the recommended cyber controls/products across more than 86 state agencies, and we can manage the addition of other local and tribal agencies using the same products and processes. We have also established a multi-jurisdictional team (state and local representation) to manage the current grant award. 5. How will this project help your agency to achieve the capability target selected above?: This helps to protect local, tribal, and state networks and data because local, tribal, and state networks are interconnected. We’re only as strong as our weakest link. This project will provide training to local and tribal government users on cyber security awareness teaching them to identify security risks and events in order to avoid and report threats from email attacks and other threats (SAT). This project will also provide cyber security products that will protect systems and data: with PC and system based software protecting against advanced persistent threat over and above traditional anti- virus (AEP), protect web domains and web servers from Internet based attacks (WAF), and provide credential protection with an additional layer of protection in addition to logins and passwords (MFA). 6. Will your agency continue to maintain, support and sustain this capability with other funding sources if Homeland Security grant funds were no longer available?: No 6a. Describe the reasons your agency will not continue to maintain this capability.: No, our agency does not have the budget and is unable to spend our organization’s budget to support other governments. To maintain controls, each participating local and tribal government would need to fund their own licenses. 7. Does this project support a NIMS typed resource?: No 8. Has your agency previously been awarded Homeland Security Grant Program (SHSGP, UASI and/or OPSG) funding to support this project/capability?: No 9. Is your agency prepared to provide up to 25% cash (hard) or in-kind (soft) match and ensure it is tracked and documented should matching funds be a requirement in FFY 2021?: No 10. Describe which agencies will directly benefit from this project aside from your own and how they will benefit.: Local and Tribal governments without proper knowledge, resources and funding to implement sophisticated cyber controls will benefit through the standards and best practices-based approach proven successful at the State of Arizona government. The state, local and tribal governments will also benefit from economies of scale by purchasing bulk licenses through competitive state contracts. The current multi-jurisdictional team deploying four cyber security products currently also demonstrates the ability and benefit to build and sustain government partnerships. Printed on 09/22/2021 PLANNED PROJECT ACTIVITIES PLANNED ACTIVITIES FOR QUARTER #1 Activity #1 (October 1 – December 31): MOU the award to ADOA. ADOA will begin purchase of product(s). ADOA will re-engage with Liaison and Planning teams. PLANNED ACTIVITIES FOR QUARTER #2 Activity #2 (January 1 – March 31): ADOA and Liaison team will re-engage participating organizations to continue deployment and use of the product(s). Communicate to local and tribal organizations if additional licenses are available. PLANNED ACTIVITIES FOR QUARTER #3 Activity #3 (April 1 – June 30): ADOA and Liaison team will on-board additional organizations if additional license are made available. PLANNED ACTIVITIES FOR QUARTER #4 Activity #4 (July 1 – September 30): ADOA and Liaison team will continue and conclude deployment and report on KPIs and metrics. Printed on 09/22/2021 EQUIPMENT REQUEST Equipment Item Age/Condition of Equipment Qty Requested Cost Per Unit Total Requested Qty Awarded Total Awarded Item Name: Advanced Endpoint Protection (AEP) licensing Description: Advanced Endpoint Protection (AEP) software to be deployed on local and tribal government personal computers (PC's) and other systems to provide enhanced malware and advanced persistent threat (APT) endpoint protection above traditional anti-virus. NA 7,529 $12 $90,348 7,529 $90,348 Item Name: Web Application Firewall (WAF) licensing Description: WAF protects web domains and web servers of local and tribal government from Internet and internal threat actors. NA 17 $1,030 $17,510 17 $17,510 Item Name: Multi Factor Authentication (MFA) licensing Description: MFA provides credential protection for systems in addition to login and password. As passwords may be easily cracked or reused, MFA provides an additional layer of protection to ensure only authorized account owners can access their computer accounts. 2,259 $13 $29,367 2,259 $29,367 $137,225 $137,225 Equipment Requested Total: $137,225 Equipment Awarded Total: $137,225 Printed on 09/22/2021 TRAINING REQUEST Training Item Backfill / Overtime Workshops / Conferences Trainers / Contractors / Consultants Supplies Travel Total Requested Total Awarded Training Name: Security Awareness and Anti-Phishing Training (SAT) Training Description: Security Awareness and Anti-Phishing Training Software as a Service licenses for one year to train local and tribal government users on cyber security awareness and to be vigilant by identifying and avoiding email scams and attacks. Multiple on-demand, online, courses available including recommended (and required by State of Arizona policy) basic, organization wide, cyber security awareness training. Supplies Details: Software as a Service licenses for security awareness and anti-phishing training including the Learning Management System (LMS) to record user completion and anti-phishing campaign metrics. $0 $0 $0 $75,288 Award - $75,288 $0 $75,288 $75,288 $75,288 $75,288 Training Request Total: $75,288 Training Award Total: $75,288 Does your agency have a MYTEP?: No Printed on 09/22/2021 EXERCISE REQUEST Description Exercise Type Backfill / Overtime Workshops / Conference Contractors / Consultants Supplies Travel Total Requested Total Awarded $0 $0 $0 $0 $0 $0 $0 $0 $0 Exercise Requested Total: $0 Exercise Awarded Total: $0 Does your agency have a MYTEP?: No PLANNING REQUEST Description Backfill and Overtime Workshops / Conference Staff / Contractors / Consultants Materials Travel Total Requested Total Awarded $0 $0 $0 $0 $0 $0 $0 $0 $0 Planning Request Total: $0 Planning Award Total: $0 Printed on 09/22/2021 ORGANIZATION ACTIVITY REQUEST Description Overtime Operational Expenses Staff / Contractors / Consultants Total Requested Total Awarded $0 $0 $0 $0 $0 $0 $0 Organizational Activity Request Total: $0 Organizational Activity Award Total: $0 MANAGEMENT AND ADMINISTRATION REQUEST Description Backfill / Overtime Personnel / Contractor / Consultant Travel Materials Total Requested $0 $0 $0 $0 $0 $0 M&A Total Requested: $0 M&A Awarded Total: $0 Printed on 09/22/2021 PROJECT REQUEST TOTAL Cost Category Total Requested Total Awarded Equipment Total $137,225 $137,225 Exercise Total $0 $0 Training Total $75,288 $75,288 Planning Total $0 $0 Organization Total $0 $0 Project Total $212,513 $212,513 M&A Amount Requested M&A Amount Awarded Management and Administration $0 $0 Indirect Costs Requested Indirect Costs Approved Indirect Costs No No INDIRECT COSTS Is your agency seeking indirect costs?: No Indirect Costs Approved: No Printed on 09/22/2021 FUNDING PRIORITIES Can partial funding be accepted in support of this project?: Yes Funding Details: Funding Priorities / Partial Funding Details Priority 1: Equipment, Advanced Endpoint Protection (continuation of 2020 grant funded recipients), minimum funding priority total $67,759.24. Priority 1: Equipment, Web Application Firewall licensing, (continuation of 2020 grant funded recipients), minimum funding priority total $6,233.85. Priority 1: Equipment, Multi Factor Authentication (continuation of 2020 grant funded recipients), minimum funding priority total $9,791.21. Priority 1: Training, Security Awareness and Anti-Phishing Training (continuation of 2020 grant funded recipients), minimum funding priority total $37,644.02. -- Additional priorities for program expansion: Priority 2: Equipment, Web Application Firewall (expand licensing to Qty 17 due to demand) cost per unit $1,030, total $17,510.00 Priority 2: Training, Security Awareness and Anti-Phishing (expand training library due to demand) $60,230.44 Priority 3: Equipment, Multi Factor Authentication (expand license to Qty 2259 due to demand) cost per unit $13, total $29,367.00 Priority 3: Training, Security Awareness and Anti-Phishing (expand training library and licenses due to demand) $75,288.05 Priority 4: Equipment, Advanced Endpoint Protection (expand licensing to Qty 7529 due to demand) cost per unit $12, total $90,348.00 MOU Award Type: cyber Printed on 09/22/2021