| Location: | Oklahoma |
|---|---|
| Posted: | Jun 19, 2026 |
| Due: | Jul 6, 2026 |
| Agency: | Grand River Dam Authority |
| Type of Government: | State & Local |
| Category: |
|
| Solicitation No: | RFP 9461 – Audit Services – Information Technology |
| Publication URL: | To access bid details, please log in. |
Jun 18, 2026
RFP Number: 9461
Project Description: Audit Services – Information Technology
The bid is due by July 6, at 2:00 PM CST
Please send all questions and correspondence to: Melissa.Rickman@GRDA.com
Questions are due by June 29, 2026, at 2:00 PM CST
Click the link above to access the packet for all pertinent documentation.
Disclaimer
It is the responsibility of the prospective vendor to check the GRDA Website regularly for bidding opportunities and any amendments or announcements that may be issued to solicitations. GRDA is not responsible for a vendor’s failure to acknowledge any aforementioned information required to be obtained in a timely manner.
Some solicitations have documents, such as blueprints, that cannot be attached to the solicitations due to confidentiality issues. It is the responsibility of the prospective vendor to read instructions in the solicitation on how to obtain these documents required to complete the solicitation response and to submit the response in accordance with the instructions. Fax, E-mail or third party submitted copies of bids will not be accepted for the submission of sealed bids. Sealed bids must be submitted via bidexpress.com.
Solicitation means a request or invitation by GRDA for a vendor to submit a priced offer to sell acquisitions to GRDA. A solicitation (i.e. bid opportunities) may be a Request for Quote (RFQ), an Invitation to Bid (ITB), or a Request for Proposal (RFP).
An amendment to a solicitation means a written change, addition, correction, or revision to a solicitation.
An announcement includes, but not limited to, notice of award, cancellation of a solicitation, an update of a solicitation.
GRAND RIVER DAM AUTHORITY RFQ/RFP# 9461
Solicitation Cover Page
1. Solicitation #: 9461
2. Solicitation Issue Date: 6.16.26
3. Brief Description of Requirement:
The Grand River Dam Authority is seeking responses for Audit Services - Information Technology
4. Response Due Date: 7.6.26 Time: 2:00 P.M. CDT
5. Contracting Officer:
Name: Melissa Rickman
Phone: 918.370.6969
Email: melissa.rickman@grda.com
Grand River Dam Authority is an agency of the State of Oklahoma.
GRDA Engineering & Technology Center * 9933 E 16th Street * Tulsa, Oklahoma 74128 *918-256-5545
Request for Proposal
Audit Services - Information Technology
I. SCOPE OF WORK
The Grand River Dam Authority (the "Authority" or "GRDA"), a non-appropriated state
agency, was created by the State of Oklahoma in 1935 as a conservation and reclamation
district. The Authority has the power to control, store, preserve, and distribute the waters
of the Grand River and its tributaries for any useful purpose and to develop and generate
water power, electric power, and electric energy within the boundaries of the Authority
and to buy, sell, resell, interchange, and distribute electric power and energy.
GRDA's Information Technology (IT) team formally adopted and implemented 117 of
the safeguards from the CIS Critical Security Controls - version 8 framework (see
enclosed document identifying the safeguards). The Internal Audit Services (IAS) team is
seeking proposals from qualified firms to provide professional IT assurance services on
the effectiveness of this implementation. The engagement shall be performed in
accordance with the Global Internal Audit Standards, including all relevant elements of
the Cyber Security Topical Requirement, with work anticipated to begin October 1,
2026.
II. INSTRUCTIONS FOR SUBMITTING A PROPOSAL
Proposals must be emailed to Melissa Rickman (melissa.rickman@grda.com) by July 6,
2026 . All questions and correspondence should be directed to her no later than June 29,
2026. Contact with GRDA personnel other than Ms. Rickman regarding this RFP may be
grounds for elimination from the selection process.
III. DELVERABLES
The Respondent selected will be responsible for the following:
* Conducting an entrance conference with the key stakeholders from IT and Internal
Audit Services
* Developing a formal audit objective, audit plan and virtually discussing them with the
Director of Internal Audit Services prior to execution
* Providing written status updates biweekly via email to the Director of Internal Audit
Services
* Developing and discussing draft audit results with the Director of Internal Audit
Services, including:
Executive summary
Detailed observations with risk ratings
* Recommendations for improvement and an overall conclusion
* Presenting the audit results to IT senior management and the Director of Internal
Audit Services as well as addressing questions
* Seeking and incorporating management's responses to recommendations into the
final work product
* Providing an electronic version of the final work product to the Director of Internal
Audit Services.
IV. PROPOSAL REQUIREMENTS
There shall be six (6) parts to the proposal;
1. Qualifications - The Respondent should state the size of the Respondent firm, and nature
of the professional staff to be employed in this engagement. The principal supervisory
and management staff, including engagement partners, managers, and other supervisors
and specialists, who would be assigned to the engagement, should be identified. Describe
the IT auditing experience of each person. The engagement team must include certified
professionals holding one or more of the following credentials: Certified Internal Auditor
(CIA); Certified Information Systems Auditor (CISA); Certified Information Security
Manager (CISM); or Certified in Risk and Information Systems Control (CRISC).
2. Experience and References- The Respondent must have a minimum of five (5) years of
experience performing audits of a similar nature and have completed at least three (3)
information technology audits within the last three (3) years. Preference may be given to
Respondents with specific experience in evaluating the CIS Critical Security Controls
framework. These audits should be conducted in accordance with Global Internal Audit
Standards or the International Standards for the Professional Practice of Internal
Auditing.
Identify the scope of work, date, engagement partners, total hours, and the name and
contact information of the principal client contact.
3. Cost Proposal - Provide a total all-inclusive maximum price to complete the engagement
including all direct and indirect costs including all out-of-pocket expenses. Include a
schedule of professional fees and expenses that supports the total all-inclusive maximum
price. Out-of-pocket expenses for Respondent personnel (e.g., travel, lodging and per
diem) will be reimbursed for itemized actual and necessary expenses (with detailed
supporting receipts). All expense reimbursements will be charged against the total all-
inclusive maximum price submitted by the Respondent. The Authority will not be
responsible for expenses incurred in preparing and submitting responses to this proposal.
Such costs should not be included in the proposal.
4. Engagement Letter- Provide a sample format engagement letter that may be similar to
what would be used for this engagement along with any supplemental terms and
conditions. Please note that state law prohibits the Authority from entering into contracts
with indemnification and/or limitation of liability provisions. The agreement shall be
governed in accordance with the laws of the State of Oklahoma.
5. Certificate of Non-Collusion and Business Relationships - Submit the provided
Certificate of Non-Collusion and Business Relationships affidavit with the proposal.
6. Insurance Requirements - Commencing with the performance of the Services and
continuing until the earlier of acceptance of the Services or termination of this
Agreement, Respondent shall maintain the following types of insurance coverage with
limits as indicated below. All insurance required in this Agreement shall be obtained
from insurance companies that are duly licensed or authorized in the State of Oklahoma
and rated A- or better by A.M. Best Company or otherwise reasonably acceptable to
GRDA.
6.1.1 Workers' Compensation
Workers' compensation insurance sufficient to meet Respondent's obligations
under the laws of the State of Oklahoma and any other state where the Services
are being performed, including employer's liability coverage for injury, disease
and death with coverage limits of at least One Million Dollars ($1,000,000) per
accident and per employee/policy limit by disease.
6.1.2 Commercial General Liability
Commercial general liability insurance (including contractual liability coverage)
on an occurrence basis for bodily injury, death, "broad form" property damage,
and personal injury, with coverage limits of at least One Million Dollars
($1,000,000) per occurrence and Two Million Dollars ($2,000,000) in the
aggregate.
6.1.3 Professional Liability Insurance
Professional liability insurance with limits of at least One Million Dollars
($1,000,000) per claim and in the aggregate covering Respondent against sums
which Respondent may become legally obligated to pay on account of
professional liability caused by negligent acts, errors, and omissions during the
performance of this Agreement.
6.1.4 Excess Liability
Excess Liability or Umbrella Insurance coverage written over the underlying
employer's liability, commercial general liability, and professional liability
insurance described above on an occurrence form with a limit of at least Three
Million Dollars ($3,000,000) per occurrence and aggregate.
6.1.5 Certificates
Respondent agrees to provide GRDA with verification of insurance, acceptable to
GRDA evidencing the above-described coverage prior to the start of Services
hereunder and annually thereafter. The required insurance policies shall be
endorsed to provide a minimum of thirty (30) days advance notice to the GRDA
in the event of cancellation or non-renewal.
V. EVALUATION AND SELECTION OF PROPOSAL
GRDA will evaluate the proposals using a "best value" approach and may consider not
only the bid prices, but also other factors including, but not limited to, relevant
experience and qualifications of team, audit approach, and proposed timeline for
completion. After the initial evaluation, the GRDA may choose to enter into further
negotiations with selected respondent(s) and may elect to request that a best and final
offer be submitted after negotiations.
VI. PROJECT MANAGEMENT
The project manager on this engagement is:
Jeff Brown, Director of Internal Audit Services
Grand River Dam Authority
201 NW 63rd, Suite 305
Oklahoma City, OK 73115
913-430-6615
jeff.brown@grda.com
All invoices shall be emailed accounts.payable@grda.com or mailed to PO Box 669,
Chouteau, OK 74337. They should state ATTN: Jeff Brown and include but not be
limited to:
* Service period and hours billed
* Estimated percentage complete
* Total amount requested
VII. MISCELLANEOUS
The Authority assumes no responsibility or liability for any costs you may incur in responding to
this RFP, including attending meetings or contract negotiations.
Respondents will be bound to comply with the provisions set forth herein
All bids, both successful and unsuccessful, shall be maintained for a period of five (5) years from
the date of opening of bids or for a period of three (3) years from the date of completion of the
contract, whichever is longer, or as may be required by the Oklahoma Open Records Act and
such records shall be open to public inspection and shall be a matter of public record.
The Authority reserves the right to reject any or all proposals submitted.
| Control/Safeguard Number | Implementation Group | Library Control Name | Subprocess Name | |
|---|---|---|---|---|
| 1 | 1.1 | IG1 | CIS.IMEA.CIS1.1 Asset Inventory | Inventory and Control of Enterprise Assets |
| 2 | 1.3 | IG2 | CIS.IMEA.CIS1.3 Active Asset Discovery | Inventory and Control of Enterprise Assets |
| 3 | 2.1 | IG1 | CIS.IMSA.CIS2.1 Software Inventory | Inventory and Control of Software Assets |
| 4 | 2.2 | IG1 | CIS.IMSA.CIS2.2 Authorized Software | Inventory and Control of Software Assets |
| 5 | 2.3 | IG1 | CIS.IMSA.CIS2.3 Unauthorized Software | Inventory and Control of Software Assets |
| 6 | 2.4 | IG2 | CIS.IMSA.CIS2.4 Software Inventory Tools | Inventory and Control of Software Assets |
| 7 | 3.3 | IG1 | CIS.DAT.CIS3.3 Data Access Control Lists | Data Protection |
| 8 | 3.4 | IG1 | CIS.DAT.CIS3.4 Data Retention | Data Protection |
| 9 | 3.6 | IG1 | CIS.DAT.CIS3.6 End-User Device Data Encryption | Data Protection |
| 10 | 3.10 | IG2 | CIS.DAT.CIS3.10 Encryption of Data In Transit | Data Protection |
| 11 | 3.11 | IG2 | CIS.DAT.CIS3.11 Encryption of Data At Rest | Data Protection |
| 12 | 4.1 | IG1 | CIS.CFG.CIS4.1 Secure Configuration Process | Secure Configuration of Enterprise Assets and Software |
| 13 | 4.2 | IG1 | CIS.CFG.CIS4.2 Secure Configuration Process for Network Infrastructure | Secure Configuration of Enterprise Assets and Software |
| 14 | 4.3 | IG1 | CIS.CFG.CIS4.3 Automatic Session Locking | Secure Configuration of Enterprise Assets and Software |
| 15 | 4.4 | IG1 | CIS.CFG.CIS4.4 Servers Firewall | Secure Configuration of Enterprise Assets and Software |
| 16 | 4.5 | IG1 | CIS.CFG.CIS4.5 Firewall on End-User Devices | Secure Configuration of Enterprise Assets and Software |
| 17 | 4.6 | IG1 | CIS.CFG.CIS4.6 Secure Management of Assets and Software | Secure Configuration of Enterprise Assets and Software |
| 18 | 4.7 | IG1 | CIS.CFG.CIS4.7 Management of Default Accounts | Secure Configuration of Enterprise Assets and Software |
| 19 | 4.8 | IG2 | CIS.CFG.CIS4.8 Restriction of Unnecessary Services | Secure Configuration of Enterprise Assets and Software |
| 20 | 4.9 | IG2 | CIS.CFG.CIS4.9 DNS Servers Configuration | Secure Configuration of Enterprise Assets and Software |
CIS Critical Security Controls
Safeguards Implemented
Control/Safeguard Implementation
Number Group Library Control Name Subprocess Name
CIS.IMEA.CIS1.1 Asset
1 1.1 IG1 Inventory Inventory and Control of Enterprise Assets
CIS.IMEA.CIS1.3 Active
2 1.3 IG2 Asset Discovery Inventory and Control of Enterprise Assets
CIS.IMSA.CIS2.1 Software
3 2.1 IG1 Inventory Inventory and Control of Software Assets
CIS.IMSA.CIS2.2
4 2.2 IG1 Authorized Software Inventory and Control of Software Assets
CIS.IMSA.CIS2.3
5 2.3 IG1 Unauthorized Software Inventory and Control of Software Assets
CIS.IMSA.CIS2.4 Software
6 2.4 IG2 Inventory Tools Inventory and Control of Software Assets
CIS.DAT.CIS3.3 Data
7 3.3 IG1 Access Control Lists Data Protection
CIS.DAT.CIS3.4 Data
8 3.4 IG1 Retention Data Protection
CIS.DAT.CIS3.6 End-User
9 3.6 IG1 Device Data Encryption Data Protection
CIS.DAT.CIS3.10
Encryption of Data In
10 3.10 IG2 Transit Data Protection
CIS.DAT.CIS3.11
11 3.11 IG2 Encryption of Data At Rest Data Protection
CIS.CFG.CIS4.1 Secure Secure Configuration of Enterprise Assets and
12 4.1 IG1 Configuration Process Software
CIS.CFG.CIS4.2 Secure
Configuration Process for Secure Configuration of Enterprise Assets and
13 4.2 IG1 Network Infrastructure Software
CIS.CFG.CIS4.3 Automatic Secure Configuration of Enterprise Assets and
14 4.3 IG1 Session Locking Software
CIS.CFG.CIS4.4 Servers Secure Configuration of Enterprise Assets and
15 4.4 IG1 Firewall Software
CIS.CFG.CIS4.5 Firewall Secure Configuration of Enterprise Assets and
16 4.5 IG1 on End-User Devices Software
CIS.CFG.CIS4.6 Secure
Management of Assets and Secure Configuration of Enterprise Assets and
17 4.6 IG1 Software Software
CIS.CFG.CIS4.7
Management of Default Secure Configuration of Enterprise Assets and
18 4.7 IG1 Accounts Software
CIS.CFG.CIS4.8 Restriction Secure Configuration of Enterprise Assets and
19 4.8 IG2 of Unnecessary Services Software
CIS.CFG.CIS4.9 DNS Secure Configuration of Enterprise Assets and
20 4.9 IG2 Servers Configuration Software
| 21 | 4.10 | IG2 | CIS.CFG.CIS4.10 Automated Device Lockout | Secure Configuration of Enterprise Assets and Software |
|---|---|---|---|---|
| 22 | 4.11 | IG2 | CIS.CFG.CIS4.11 Remote Wipe Capability | Secure Configuration of Enterprise Assets and Software |
| 23 | 4.12 | IG3 | CIS.CFG.CIS4.12 Organization Workspace Separation | Secure Configuration of Enterprise Assets and Software |
| 24 | 5.1 | IG1 | CIS.ACCT.CIS5.1 Inventory of Accounts | Account Management |
| 25 | 5.2 | IG1 | CIS.ACCT.CIS5.2 Unique Passwords | Account Management |
| 26 | 5.3 | IG1 | CIS.ACCT.CIS5.3 Inactive Accounts | Account Management |
| 27 | 5.4 | IG1 | CIS.ACCT.CIS5.4 Administrator Privileges | Account Management |
| 28 | 5.5 | IG2 | CIS.ACCT.CIS5.5 Inventory of Service Accounts | Account Management |
| 29 | 5.6 | IG2 | CIS.ACCT.CIS5.6 Account Management | Account Management |
| 30 | 6.1 | IG1 | CIS.ACM.CIS6.1 Access Provisioning Process | Access Control Management |
| 31 | 6.2 | IG1 | CIS.ACM.CIS6.2 Access Deprovisioning Process | Access Control Management |
| 32 | 6.3 | IG1 | CIS.ACM.CIS6.3 MFA for Externally-Exposed Applications | Access Control Management |
| 33 | 6.4 | IG1 | CIS.ACM.CIS6.4 MFA for Remote Network Access | Access Control Management |
| 34 | 6.5 | IG1 | CIS.ACM.CIS6.5 MFA for Administrative Access | Access Control Management |
| 35 | 6.6 | IG2 | CIS.ACM.CIS6.6 Inventory of Authentication and Authorization Systems | Access Control Management |
| 36 | 6.7 | IG2 | CIS.ACM.CIS6.7 Centralized Access Control | Access Control Management |
| 37 | 6.8 | IG3 | CIS.ACM.CIS6.8 Role- Based Access Control | Access Control Management |
| 38 | 7.1 | IG1 | CIS.CVM.CIS7.1 Vulnerability Management Process | Continuous Vulnerability Management |
| 39 | 7.2 | IG1 | CIS.CVM.CIS7.2 Remediation Process | Continuous Vulnerability Management |
| 40 | 7.3 | IG1 | CIS.CVM.CIS7.3 Operating System Patch Management | Continuous Vulnerability Management |
| 41 | 7.4 | IG1 | CIS.CVM.CIS7.4 Application Patch Management | Continuous Vulnerability Management |
| 42 | 7.5 | IG2 | CIS.CVM.CIS7.5 Internal Asset Vulnerability Scans | Continuous Vulnerability Management |
CIS.CFG.CIS4.10 Secure Configuration of Enterprise Assets and
21 4.10 IG2 Automated Device Lockout Software
CIS.CFG.CIS4.11 Remote Secure Configuration of Enterprise Assets and
22 4.11 IG2 Wipe Capability Software
CIS.CFG.CIS4.12
Organization Workspace Secure Configuration of Enterprise Assets and
23 4.12 IG3 Separation Software
CIS.ACCT.CIS5.1
24 5.1 IG1 Inventory of Accounts Account Management
CIS.ACCT.CIS5.2 Unique
25 5.2 IG1 Passwords Account Management
CIS.ACCT.CIS5.3 Inactive
26 5.3 IG1 Accounts Account Management
CIS.ACCT.CIS5.4
27 5.4 IG1 Administrator Privileges Account Management
CIS.ACCT.CIS5.5
Inventory of Service
28 5.5 IG2 Accounts Account Management
CIS.ACCT.CIS5.6 Account
29 5.6 IG2 Management Account Management
CIS.ACM.CIS6.1 Access
30 6.1 IG1 Provisioning Process Access Control Management
CIS.ACM.CIS6.2 Access
31 6.2 IG1 Deprovisioning Process Access Control Management
CIS.ACM.CIS6.3 MFA for
Externally-Exposed
32 6.3 IG1 Applications Access Control Management
CIS.ACM.CIS6.4 MFA for
33 6.4 IG1 Remote Network Access Access Control Management
CIS.ACM.CIS6.5 MFA for
34 6.5 IG1 Administrative Access Access Control Management
CIS.ACM.CIS6.6 Inventory
of Authentication and
35 6.6 IG2 Authorization Systems Access Control Management
CIS.ACM.CIS6.7
36 6.7 IG2 Centralized Access Control Access Control Management
CIS.ACM.CIS6.8 Role-
37 6.8 IG3 Based Access Control Access Control Management
CIS.CVM.CIS7.1
Vulnerability Management
38 7.1 IG1 Process Continuous Vulnerability Management
CIS.CVM.CIS7.2
39 7.2 IG1 Remediation Process Continuous Vulnerability Management
CIS.CVM.CIS7.3 Operating
40 7.3 IG1 System Patch Management Continuous Vulnerability Management
CIS.CVM.CIS7.4
Application Patch
41 7.4 IG1 Management Continuous Vulnerability Management
CIS.CVM.CIS7.5 Internal
42 7.5 IG2 Asset Vulnerability Scans Continuous Vulnerability Management
| 43 | 7.6 | IG2 | CIS.CVM.CIS7.6 Externally Exposed Asset Vulnerability Scans | - Continuous Vulnerability Management |
|---|---|---|---|---|
| 44 | 7.7 | IG2 | CIS.CVM.CIS7.7 Vulnerability Remediation | Continuous Vulnerability Management |
| 45 | 8.1 | IG1 | CIS.LOG.CIS8.1 Audit Log Management Process | Audit Log Management |
| 46 | 8.2 | IG1 | CIS.LOG.CIS8.2 Audit Log Collection | Audit Log Management |
| 47 | 8.3 | IG1 | CIS.LOG.CIS8.3 Audit Log Storage | Audit Log Management |
| 48 | 8.4 | IG2 | CIS.LOG.CIS8.4 Standardized Time Synchronization | Audit Log Management |
| 49 | 8.5 | IG2 | CIS.LOG.CIS8.5 Detailed Audit Logs | Audit Log Management |
| 50 | 8.6 | IG2 | CIS.LOG.CIS8.6 DNS Query Audit Logs | Audit Log Management |
| 51 | 8.7 | IG2 | CIS.LOG.CIS8.7 URL Request Audit Logs | Audit Log Management |
| 52 | 8.9 | IG2 | CIS.LOG.CIS8.9 Centralized Audit Logs | Audit Log Management |
| 53 | 8.10 | IG2 | CIS.LOG.CIS8.10 Audit Log Retention | Audit Log Management |
| 54 | 8.11 | IG2 | CIS.LOG.CIS8.11 Audit Log Review | Audit Log Management |
| 55 | 9.1 | IG1 | CIS.EWP.CIS9.1 Browsers and Email Clients | Email and Web Browser Protections |
| 56 | 9.2 | IG1 | CIS.EWP.CIS9.2 DNS Filtering | Email and Web Browser Protections |
| 57 | 9.3 | IG2 | CIS.EWP.CIS9.3 Network- based URL Filters | Email and Web Browser Protections |
| 58 | 9.4 | IG2 | CIS.EWP.CIS9.4 Restriction of Browser and Email Extensions | Email and Web Browser Protections |
| 59 | 9.5 | IG2 | CIS.EWP.CIS9.5 DMARC Policy | Email and Web Browser Protections |
| 60 | 9.6 | IG2 | CIS.EWP.CIS9.6 Blocking of File Types | Email and Web Browser Protections |
| 61 | 9.7 | IG3 | CIS.EWP.CIS9.7 Email Server Anti-malware | Email and Web Browser Protections |
| 62 | 10.1 | IG1 | CIS.MAL.CIS10.1 Anti- malware Software | Malware Defenses |
| 63 | 10.2 | IG1 | CIS.MAL.CIS10.2 Update of Anti-malware Signatures | Malware Defenses |
| 64 | 10.3 | IG1 | CIS.MAL.CIS10.3 Restrictions on Removable Media | Malware Defenses |
CIS.CVM.CIS7.6 Externally-
Exposed Asset
43 7.6 IG2 Vulnerability Scans Continuous Vulnerability Management
CIS.CVM.CIS7.7
44 7.7 IG2 Vulnerability Remediation Continuous Vulnerability Management
CIS.LOG.CIS8.1 Audit Log
45 8.1 IG1 Management Process Audit Log Management
CIS.LOG.CIS8.2 Audit Log
46 8.2 IG1 Collection Audit Log Management
CIS.LOG.CIS8.3 Audit Log
47 8.3 IG1 Storage Audit Log Management
CIS.LOG.CIS8.4
Standardized Time
48 8.4 IG2 Synchronization Audit Log Management
CIS.LOG.CIS8.5 Detailed
49 8.5 IG2 Audit Logs Audit Log Management
CIS.LOG.CIS8.6 DNS
50 8.6 IG2 Query Audit Logs Audit Log Management
CIS.LOG.CIS8.7 URL
51 8.7 IG2 Request Audit Logs Audit Log Management
CIS.LOG.CIS8.9
52 8.9 IG2 Centralized Audit Logs Audit Log Management
CIS.LOG.CIS8.10 Audit
53 8.10 IG2 Log Retention Audit Log Management
CIS.LOG.CIS8.11 Audit
54 8.11 IG2 Log Review Audit Log Management
CIS.EWP.CIS9.1 Browsers
55 9.1 IG1 and Email Clients Email and Web Browser Protections
CIS.EWP.CIS9.2 DNS
56 9.2 IG1 Filtering Email and Web Browser Protections
CIS.EWP.CIS9.3 Network-
57 9.3 IG2 based URL Filters Email and Web Browser Protections
CIS.EWP.CIS9.4
Restriction of Browser and
58 9.4 IG2 Email Extensions Email and Web Browser Protections
CIS.EWP.CIS9.5 DMARC
59 9.5 IG2 Policy Email and Web Browser Protections
CIS.EWP.CIS9.6 Blocking
60 9.6 IG2 of File Types Email and Web Browser Protections
CIS.EWP.CIS9.7 Email
61 9.7 IG3 Server Anti-malware Email and Web Browser Protections
CIS.MAL.CIS10.1 Anti-
62 10.1 IG1 malware Software Malware Defenses
CIS.MAL.CIS10.2 Update
63 10.2 IG1 of Anti-malware Signatures Malware Defenses
CIS.MAL.CIS10.3
Restrictions on Removable
64 10.3 IG1 Media Malware Defenses

With GovernmentContracts, you can:
Follow KC-135 Center Console Refresh (CCR) Revision 2 Active Contract Opportunity Notice ID
DEPT OF DEFENSE
Bid Due: 9/15/2026
Bid Information Type Invitation For Bid Status Issued Number 10-2026 (Lake McMurtry Pump
City of Stillwater
Bid Due: 8/19/2026
Procurement #164796 Title Request for Sealed Bids -CNIT Fiber Distribution Relocation (Cherokee County)
Cherokee Nation
Bid Due: 8/19/2026
Follow Inventory Management and Material Support-Sole Source to Cherokee Nation Armored Solutions Active
DEPT OF DEFENSE
Bid Due: 8/11/2026