FISMA_Requirements.pdf
PDF 224 KB Posted
- Attached to
- Airborne ElectroMagnetic (AEM) Data Processing Software License Federal contract opportunity
- Solicitation number
- 0040397695
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Clauses_and_Provisions_Not_SBSA.rtf | RTF text file | |
| BRAND_NAME_SALIENT_CHARACTERISTICS_v2.docx | DOCX document | |
| Section_508_Compliance.pdf | ||
| Brand_Name_Salient_Characteristics.docx | DOCX document | |
| Clauses_and_Provisions_SBSA.rtf | RTF text file |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FISMA
If any of these statements are inaccurate, request the non-template version from your AOA. They will be able to provide you with one that includes more options for each section.
Work Statement Attachment – Information Technology Security Requirements Summary
1. Background Investigation
Contractor employees who will have access to Federal information technology (IT) systems are subject to background investigations by the Federal Office of Personnel Management. Procedures for investigations and obtaining identity credentials are described in clause GS 1414 (or GS 1419 if working on the Denver
Federal Center). The level of investigation required will be the same as would be required for Federal employees holding positions involving similar duties.
Based on the risk and sensitivity of duties performed and system access authorities to be granted, the following type of background investigations will be required, as described in DOI Departmental Manual
Part 441, Chapter 3, Attachment 5 (available at:
http://elips.doi.gov/app_dm/act_getfiles.cfm?relnum=3631).
Duties – The student will work mostly in the field. Will use USGS computer for necessary training courses and completion of assignments.
Investigation Level – 1
2. Non-disclosure Agreement
Prior to receiving access to USGS computers, contractor employees shall be required to sign non-disclosure or other system security agreements, depending on the systems to be used and level of access granted. The required non-disclosure agreement will be similar to the attached but may be customized, as needed, to reflect the data involved. Restrictions on use, duplication, and disclosure of sensitive and proprietary data are covered in clause GS 1406.
3. Training
Contractor employees shall complete USGS-defined Federal Information Systems Security Awareness computer security training before being granted system access and must renew the training annually.
Failure to complete training within the required timeframe may result in loss of system access for that user. Contractor employees with significant IT security responsibilities shall also complete specialized role-based training.
4. Personnel Changes
Not applicable
5. Contractor Location http://elips.doi.gov/app_dm/act_getfiles.cfm?relnum=3631
6. Applicable Standards
Not Applicable
7. Asset Valuation
Asset valuation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.
8. Property Rights
9. Independent Verification and Validation (IV & V)
10. Certification & Accreditation
Certification and Accreditation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.
11. Internet Logon Banner
Not applicable. Contractor will not be required to develop or maintain any public Internet pages under this contract.
12. Incident Reporting
Contractor employees must report any computer security incidents (viruses, intrusion attempts, system compromises, offensive e-mail, etc.) which may affect Government data or systems in accordance with the DOI Computer Incident Response Guide. Report computer security incidents to USGS help desk or
Security Point Of Contact (SPOC). In many cases, your local system administrator is your Security Point
Of Contact. The help desk or SPOC will investigate and coordinate with the Computer Security Incident
Response Team (CSIRT).
13. Quality Control (Malicious Code)
All software and hardware shall be free of malicious code.
14. Self-Assessment
Not applicable – not a Major Application or GSS.
15. Vulnerability Analysis
Vulnerability Analysis on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.
16. Logon Banner
When presented with the USGS logon banner, contractor employees shall read and acknowledge a
Government approved logon warning.
17. Security Controls
18. Contingency Plan
File details come from the government source that posted it.