FISMA_Requirements.pdf

PDF 224 KB Posted

Attached to
Airborne ElectroMagnetic (AEM) Data Processing Software License Federal contract opportunity
Solicitation number
0040397695
Issued by
Department of the Interior US Geological Survey

View the file

Other files for this federal contract opportunity

Other files attached to Airborne ElectroMagnetic (AEM) Data Processing Software License, newest first.
File Type Posted
Clauses_and_Provisions_Not_SBSA.rtf RTF text file
BRAND_NAME_SALIENT_CHARACTERISTICS_v2.docx DOCX document
Section_508_Compliance.pdf PDF
Brand_Name_Salient_Characteristics.docx DOCX document
Clauses_and_Provisions_SBSA.rtf RTF text file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FISMA

If any of these statements are inaccurate, request the non-template version from your AOA. They will be able to provide you with one that includes more options for each section.

Work Statement Attachment – Information Technology Security Requirements Summary

1. Background Investigation

Contractor employees who will have access to Federal information technology (IT) systems are subject to background investigations by the Federal Office of Personnel Management. Procedures for investigations and obtaining identity credentials are described in clause GS 1414 (or GS 1419 if working on the Denver

Federal Center). The level of investigation required will be the same as would be required for Federal employees holding positions involving similar duties.

Based on the risk and sensitivity of duties performed and system access authorities to be granted, the following type of background investigations will be required, as described in DOI Departmental Manual

Part 441, Chapter 3, Attachment 5 (available at:

http://elips.doi.gov/app_dm/act_getfiles.cfm?relnum=3631).

Duties – The student will work mostly in the field. Will use USGS computer for necessary training courses and completion of assignments.

Investigation Level – 1

2. Non-disclosure Agreement

Prior to receiving access to USGS computers, contractor employees shall be required to sign non-disclosure or other system security agreements, depending on the systems to be used and level of access granted. The required non-disclosure agreement will be similar to the attached but may be customized, as needed, to reflect the data involved. Restrictions on use, duplication, and disclosure of sensitive and proprietary data are covered in clause GS 1406.

3. Training

Contractor employees shall complete USGS-defined Federal Information Systems Security Awareness computer security training before being granted system access and must renew the training annually.

Failure to complete training within the required timeframe may result in loss of system access for that user. Contractor employees with significant IT security responsibilities shall also complete specialized role-based training.

4. Personnel Changes

Not applicable

5. Contractor Location http://elips.doi.gov/app_dm/act_getfiles.cfm?relnum=3631

6. Applicable Standards

Not Applicable

7. Asset Valuation

Asset valuation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

8. Property Rights

9. Independent Verification and Validation (IV & V)

10. Certification & Accreditation

Certification and Accreditation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

11. Internet Logon Banner

Not applicable. Contractor will not be required to develop or maintain any public Internet pages under this contract.

12. Incident Reporting

Contractor employees must report any computer security incidents (viruses, intrusion attempts, system compromises, offensive e-mail, etc.) which may affect Government data or systems in accordance with the DOI Computer Incident Response Guide. Report computer security incidents to USGS help desk or

Security Point Of Contact (SPOC). In many cases, your local system administrator is your Security Point

Of Contact. The help desk or SPOC will investigate and coordinate with the Computer Security Incident

Response Team (CSIRT).

13. Quality Control (Malicious Code)

All software and hardware shall be free of malicious code.

14. Self-Assessment

Not applicable – not a Major Application or GSS.

15. Vulnerability Analysis

Vulnerability Analysis on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

16. Logon Banner

When presented with the USGS logon banner, contractor employees shall read and acknowledge a

Government approved logon warning.

17. Security Controls

18. Contingency Plan

File details come from the government source that posted it.