Health & Human Services (HHS) - a Shared Service Provider

Organizationally, the U.S. Department of Health and Human Services (HHS) Enterprise Security Services (ESS) sits within the HHS Office of the Chief Information Officer and the Office of the Chief Information Security Officer. ESS provides information security services offerings across the HHS Enterprise including its Operating Divisions (i.e., National Institute of Health, Center for Medicare & Medicaid Services, Administration for Children and Families, Food & Drug Administration).

 Please see the list of Services and Service Providers below for a list of initial cybersecurity services offered on the Cyber Marketplace. Validated service offerings are indicated with a green checkmark Validated Service

Services

Account Management Validated Service

Analysis & Detection Validated Service

Business Impact Analysis (BIA) System Security Validated Service

Enterprise Performance Life Cycle (EPLC) Compliance Validated Service

Federal Information Processing Standards (FIPS) 199 Categorization Validated Service

Information System Security Manager and Information System Security Officer (ISSO) Oversight and Coordination Validated Service

Information System Security Officer (ISSO) Assessment & Authorization (A&A) Support  Validated Service

Information System Security Officer (ISSO) Configuration Management Planning Validated Service

Information System Security Officer (ISSO) Contingency Planning Validated Service

Information System Security Officer (ISSO) Continuous Monitoring Validated Service

Information System Security Officer (ISSO) Incident Management Planning & Response Validated Service

Information System Security Officer (ISSO) Plan of Action and Milestones (POA&M) Management Validated Service

Information System Security Officer (ISSO) Risk Management Framework (RMF) Practices Support Validated Service

Information System Security Officer (ISSO) Security Guidance & Analysis Validated Service

Information System Security Officer (ISSO) Systems Re-Authorization Validated Service

Risk Management Framework (RMF) Lifecycle Services Validated Service

Security Assessment Reporting Validated Service

Security Consultation Services (SCS) Assessment & Authorization (A&A) Support Validated Service

Security Consultation Services (SCS) Configuration Management Planning Validated Service

Security Consultation Services (SCS) Contingency Planning Validated Service

Security Consultation Services (SCS) Continuous Monitoring Validated Service

Security Consultation Services (SCS) Incident Management Planning & Response Validated Service

Security Consultation Services (SCS) Plan of Action and Milestones (POA&M) Management Validated Service

Security Consultation Services (SCS) Risk Management Framework (RMF) Practices Support Validated Service

Security Consultation Services (SCS) Security Guidance & Analysis Validated Service

Security Consultation Services (SCS) Systems Re-Authorization Validated Service

Security Controls Assessment Validated Service

Security Monitoring Validated Service

System Security Management Validated Service

Technical Vulnerabilities Assessment Validated Service

Vulnerability & Specialized Vulnerability Scanning Validated Service

Contact

For additional information, please visit our website: https://www.hhs.gov/about/agencies/asa/ocio/cybersecurity/enterprise-security-services-line-of-business/index.html.

For inquiries about ESS offered services or if interested in purchasing services, please contact us at esslob@hhs.gov.