Orange County NC Website
<br /> <br />P a g e 32 <br /> <br /> <br />Orange County <br />Facilities Security Assessment <br />RFP#: 367-OC 5403 <br />CTCH Security Business Consulting – www.ctchconsulting.com <br /> <br />out-brief. The ‘read ahead’ (draft documents) would be provided 10 days prior to the <br />official out-brief. <br />_________________________________ <br /> <br />Phase II – Draft Security Plan Development: Once Phase I is completed the team <br />can then begin to identify which form of security plans would be most advantageous to <br />OC security goals. The team would develop the plan(s) using the following two tiers: <br />Tier I: Artifacts Evaluations | Tier II: Deliverable Creation <br />_________________________________ <br /> <br />Tier I – Artifacts Evaluation: The <br />team will take into account existing <br />security plans that may be in place, how <br />effective these existing plans are, what <br />plan context needs to be added (based <br />on industry best practices and <br />guidelines), which existing plan context <br />needs to be omitted and will identify <br />which security plan recommendations were accepted, rejected or tabled by OC based on <br />the Phase I Observations and Recommendations. The team will focus on developing <br />security plans that address existing threats associated with OC sites and plans that <br />address the normal hazards associated public owned assets and plans that address <br />security system management guidelines. <br /> <br />Tier II – Final Deliverables: The team would draft the plan in a way that outlines <br />the hierarchy of OC, publishes security roles and responsibilities, outlines everyday <br />security policy/procedures, identifies how security information is communicated <br />between staff members and that publishes incident response guides. Elements of the <br />plan will be based on security industry best practices that have help other public <br />organizations create security plans that improve security oversight efforts. <br /> <br />Official Out-Brief: The official Out-Brief for the Draft Security Plan would be <br />hosted at the completion of Phase II - Tier II. The out-brief would be used to officially <br /> <br /> <br />DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB