4.1 SLCGP Objective – Governance and Planning – Project A – Cybersecurity Plan 4.1.1 Cybersecurity Posture Assessment 4.1.1.1 Review M1W’s current cybersecurity plan 4.1.1.2 Assess M1W’s current cybersecurity posture utilizing an industry standard framework such as CIS or NIST 4.1.1.3 Develop a 5-year cybersecurity plan based on interviews, documentation reviews, and assessment 4.1.2 Incident Response Plan Development 4.1.2.1 Review M1W’s current incident response plan 4.1.2.2 Assess the incident response plan in accordance with industry best practices for critical infrastructure 4.1.2.3 Update/replace incident response plan based on interviews, documentation reviews, and assessment 4.1.3 Corporate and OT Network Audit 4.1.3.1 Review M1W’s current corporate and OT network architecture 4.1.3.2 Assess M1W’s network architecture based on best practices and accepted architecture models for industrial control systems (ie – Purdue model) 4.1.3.3 Recommend changes to M1W’s network architecture to enhance security 4.1.3.4 Implement agreed upon changes to M1W’s network architecture 4.2 SLCGP Objective – Mitigation – Project B – TOTP Fobs & MFA Develop a user login procedure that utilizes hardware (ie – TOTP tokens, FIDO keys, etc.) and built in Microsoft Windows functions (ie – Hello for Business, etc.) to ensure multi-factor authentication is enforced for every login. The procedure must be easy to follow and seamless for users to use. The procedure must also not rely on any bring your own device (BYOD). Procurement or 200 TOTP Fobs or other MFA hardware should be included in the proposal and listed as a separate line item. 4.3 SLCGP Objective – Workforce Development – Project C - Trainings Develop customized training for M1W employees according to their day-to-day functions. There should be a minimum of training developed for employees that work with finances, executive training, and operations training. If the proposer determines that additional training would be appropriate for this project, please include those options in the proposal. The proposer must also provide the initial training for each functional area.