03 - Security Technical Requirements.xlsx
XLSX spreadsheet 27 KB Posted
- Attached to
- Request for Information: Award Eligibility Determination Federal contract opportunity
- Solicitation number
- Not on record
- Issued by
- Department of Education
About this file
This document outlines technical security requirements for a federal student loan servicing system. It specifies controls from the NIST SP 800-53 series that a vendor must meet to receive an Authorization to Operate, including developing system security plans, boundary documents, privacy impact assessments, and continuous monitoring capabilities. It mandates encryption, access restrictions, training, auditing, vulnerability scanning, patching, change management, and incident response according to federal guidelines. The vendor must maintain segregation of education data, support technology refreshment, and ensure secure destruction of records. Overall, the document provides an extensive list of cybersecurity controls a vendor must fulfill to handle federal student information within this system.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 10 - AED Draft SLAs.xlsx | XLSX spreadsheet | |
| 12 - CPS 101 with FA impacts 09102020.pdf | ||
| 11 - ED CSF Risk Scorecard Overview_July 2020.pdf | ||
| 09 - FSA Current State.pdf | ||
| AED RFI Final.pdf | ||
| 08 - FSA Identity Access Mgt Solution Overview.docx | DOCX document | |
| 01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf | ||
| 02 - Pricing Template.xlsx | XLSX spreadsheet | |
| 07 - Hosting Environments w Approved ATOs.pdf | ||
| 06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx | XLSX spreadsheet | |
| 05 - Hosting Environments with Approved Agency ATOs.pdf | ||
| 04 - Additional Current State Technical Constraints.xlsx | XLSX spreadsheet |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1 U.S. Department of Education Office of Federal Student Aid Next Generation Financial Services Environment
Attachment 03 – Security Technical Requirements
| Number | Requirements | Meets | Explanation of How the Requirement is Met | Does Not Meet | Explanation and Mitigation Strategy (if does not meet) |
| 1000.0000 | The vendor shall provide all information and take all actions requested by Federal Student Aid to support the process for the vendor to receive an Authorization to Operate. | ||||
| 1000.0100 | The vendor shall complete a self-assessment of its system and facilities based on NIST SP 800-53 controls, and additional controls directed by FSA, identify security deficiencies/gaps, and create a remediation plan for the identified deficiencies. | ||||
| 1000.0110 | Prior to implementation, the vendor shall support and must pass a NIST SP 800-53 controls assessment conducted by FSA. | ||||
| 1000.0210 | The vendor shall develop and maintain the System Security Plan (SSP) in compliance with NIST SP 800-18 and NIST SP-800-53 and any other applicable Federal Statutes, Standards, and Guidelines, and enter all SSP information into the Department's FISMA management tool, CSAM. | ||||
| 1000.0220 | The vendor shall review and update the SSP at any time when significant changes are made to the servicing system/solution, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO). | ||||
| 1000.0310 | The vendor shall develop and keep current a System Boundary document using the templates provided by FSA. | ||||
| 1000.0410 | The vendor shall conduct a periodic review of System Boundary Document and update as needed, but no less than annually, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO). | ||||
| 1000.0500 | The vendor shall develop a Privacy Threshold Analysis (PTA), and a Privacy Impact Assessment (PIA) in accordance with federal regulations and update them as needed, but no less than annually, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO). | ||||
| 1000.0600 | The vendor shall comply with 100% of the applicable NIST 800-53 security controls, and any FSA modifications, in accordance with the FIPS 199 category for the proposed solution. | ||||
| 1000.0800 | The vendor shall provide previous security information from the past three years if available to include a discussion of security incidents; and audits like the Statement on Standards for Attestation Engagements (SSAE) No. 18, Sarbanes Oxley reviews, independent security assessments, risk assessments, and/or internal reviews along with the applicable remediation plans. | ||||
| 1000.1000 | In accordance with FSA's Lifecycle Management Methodology, Enterprise Change Management Plan, and Business Change Management Plan, the vendor shall develop a configuration management plan, for all systems in development and production, and shall update the plan as needed, but no less than annually, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO). | ||||
| 1000.1100 | The vendor shall bundle the requested security information as attachments to a discussion document that explains the artifact submitted. The vendor's senior security official and program manager shall sign the document to certify the system's security posture and overall security risk. The vendor shall ensure all information is entered into the Department's FISMA management tool and kept current. | ||||
| 1001.0000 | The vendor shall ensure that all Personally Identifiable Information (PII), including Sensitive Personally Identifiable Information (SPII), is kept secure and provided only to properly authorized individuals and organizations. | ||||
| 1001.0100 | The vendor shall restrict access to personnel who have obtained proper U.S. Department of Education (ED) final or preliminary clearance / background investigation adjudication and who are specifically authorized to view or perform transactions and services on loans held by FSA or the Department. | ||||
| 1001.0200 | The vendor shall ensure proper control and handling of PII, including any SPII, residing on their computer, on removable media, and on paper documents. | ||||
| 1001.0400 | The vendor shall ensure data at rest that contains PII and/or SPII is encrypted using validated FIPS 140-2 encryption in any and all vendor and government Cloud computing environments. where PII and/or SPII is housed, and/or stored. | ||||
| 1001.0410 | The vendor shall consider data at rest to include data that reside in databases, file systems, information technology systems, applications, personal computers (desktops and laptops and portable electronic devices [PEDs] and mobile electronic devices and personal data assistants [PDAs]) and other structured storage devices (USB flash drives, memory cards, external hard drives, writeable CDs and DVDs) that are not in transit. | ||||
| 1001.0420 | Proposed cloud solutions shall meet the appropriate requirements of NIST SP 800-145, FIPS 199, FIPS 200 and/or FedRAMP. If a private cloud1 solution, as defined by NIST SP 800-145, is proposed it shall meet either a FIPS-199 High level or Moderate level, depending on the proposed architecture and corresponding FIPS-199 category of the system. If the solution proposes a FedRAMP cloud solution it must be FedRAMP "Ready"2 at either a FIPS-199 High level or Moderate level, depending on the proposed architecture and corresponding FIPS-199 category of the system. See solicitation documentation for additional clarification. | ||||
| 1001.0500 | The vendor shall present evidence (e.g., NIST certificate for the specific product and module) that the products it utilizes provide cryptographic protections using modules that comply with FIPS PUB 140-2 standards. |
| 1001.0510 | The vendor shall ensure the proper marking, control, and storage of all printouts and other paper documents containing PII and/or SPII in their possession. |
| 1001.0600 | The vendor shall ensure PII and/or SPII is not sent in the subject line, or body of an email, or included in an unencrypted attachment. Attachments containing PII and/or SPII must be encrypted using an approved FIPS 140-2 encryption method. |
| 1001.0610 | The vendor shall ensure communications in which PII and/or SPII is transferred include a secure encrypted channel using an FIPS 140-2 encryption method. |
| 1001.0620 | The vendor shall ensure passwords for encrypted attachments are not communicated in the same email as the attachment. |
| 1002.0000 | Immediately following successful completion of a security authorization, the vendor shall implement continuous security monitoring in accordance with NIST SP 800-137 capable of satisfying an ongoing security authorization. The vendor's Continuous Monitoring must feed into the Department and FSA continuous monitoring programs via machine to machine near-real-time updates and static frequency based updates. The vendor shall ensure all information is entered into the Department's FISMA management tool and kept current with all changes. |
| 1002.0100 | The vendor shall provide POA&M updates in accordance with requirements and the any schedules set forth in the U.S. Department of Education's Handbook for Information Assurance Cybersecurity, and in any U.S. Department of Education Instructions on Information Assurance and/or Cybersecurity, Security Policy Handbook and with the FSA Plan of Action & Milestones (POA&M) Guide - see 01002B_POAM_SOP. Reference: NIST 800-53 control CA-5. |
| 1002.0500 | The vendor shall provide an annual update to the contingency plan completed in accordance with NIST 800-34, and with the U.S. Department of Education's OCIO-10 Handbook for Information Technology Security Contingency Planning Guidance Procedures. See 01002C_ITCPG Reference: NIST 800-53 control CP-2 |
| 1002.0700 | The vendor shall conduct and provide the results of the monthly review and validation of system users’ accounts to ensure the continued need for system access. The user certification and authorization documents will illustrate the organization establishes, activates, modifies, reviews, disables, and removes information system accounts in accordance with documented account management procedures. Reference: NIST 800-53 control AC-2. Ad Hoc reports of personnel, positions, access and suitability shall be provided upon request. |
| 1002.0800 | The vendor shall provide and maintain a well-defined, documented, and up-to-date System(s) Baseline Configuration Standard Document specification to which the information system is built or changed. Reference: NIST 800-53 |
| 1002.0910 | Changes to the baseline configuration shall be reflected within the System(s) Baseline Configuration Standard Documentation on a regular schedule based on FSA Hardening Standards and guidelines. |
| 1002.1100 | The vendor shall provide the external IP space used to support FSA and enter into an agreement with the Department and DHS to allow them to conduct ongoing Health and Hygiene uncredentialled scanning. |
| 1002.1200 | The vendor shall provide monthly, not later than the 2nd day of the month, CyberScope reports for all systems that support FSA. The report will be in National Institute of Standards and Technology (NIST) Security Content Automation Protocol (SCAP) format. See also: the U.S. Department of Education's Handbook for Information Assurance Cybersecurity, and any U.S. Department of Education Instructions on Information Assurance and/or Cybersecurity. |
| 1004.0000 | The vendor shall ensure all internet traffic is routed via trusted internet connections (TIC) or MTIPS. |
| 1005.0000 | The vendor shall display an FSA approved (as amended) system use notification message (banner) before users access the servicing system. |
| 1006.0100 | The vendor shall work with FSA to develop appropriate session lock/termination procedures and practices that conform with FSA's requirements, and to the requirements in the U.S. Department of Education's Logical Access Control Guidance post award. |
| 1008.0000 | The vendor shall complete personnel background screening requirements in compliance with all Federal, Education and Federal Student Aid guidelines. |
| 1008.0100 | All personnel are required to complete a federal background investigation based on their position risk level. Vendor employees who have undergone appropriate personnel security screening for another federal agency may submit proof of personal security screening for validation. (Attached Security 1008_vendor Employee Personnel Security Screenings.) Reciprocity may or may not be granted by ED and/or FSA Personnel Security. |
| 1008.0200 | All individuals must receive ED suitability and FSA authorization prior to accessing FSA data or information systems. Favorable preliminary suitability designations must be obtained for all positions prior to working on ED or FSA systems or data (This process can take 2-6 weeks). |
| 1008.0300 | Only US citizens may be assigned to a High Risk IT (Tier 4, Federal Investigative Standards) level positions. All system administrator, engineer, security and other similar users with privileged access must meet Tier 4 requirements including US citizenship. |
| 1008.0400 | All vendor employees with access to ED or FSA data who are not determined to be "high risk" shall be designated "Moderate Risk IT" Tier 2 Federal Investigative Standard level positions. |
| 1010.0000 | The vendor shall require all personnel to complete mandatory and specialized security training as defined in coordination with FSA. |
| 1010.0200 | The vendor shall require all personnel to successfully complete initial security awareness training prior to granting access to FSA data or information systems and conduct Department identified mandatory annual training. |
| 1010.0310 | The vendor shall ensure minimum information security training hours required for these positions is as follows: |
-IT Executives, Managers and System Owners (1 hr) -Information Security Specialist or Information System Security Officer (ISSO) - 20 hrs -Privacy Officer and staff - 5 hrs -System Administrator, Network Administrator, Database Administrator, Service Desk Personnel/Helpdesk, System Programmers, Programmer with access to production environment - 10 hrs -Other IT Personnel with security responsibilities - 1 hr
| 1010.0400 | The vendor shall maintain records of security training completion and provide those records to ED or FSA on demand. |
| 1011.0000 | The vendor shall identify primary and alternate telecommunications sites sufficient to meet Tier 4 data center resilience and uptime. |
| 1013.0000 | The vendor shall not use wireless communication containing Federal Student Aid information within the data center. |
| 1015.0000 | The vendor shall provide, to the FSA Information System Security Officer (ISSO), focused and timely support, including complete evidence, in responding to all oversight and agency audits. |
| 1015.0200 | The vendor shall provide Plans of Action and Milestones to FSA's ISSO for system audits, and shall remediate audit findings specified in those plans according to agreed upon deadlines. |
| 1016.0000 | The vendor shall audit security relevant events as defined by NIST, ED, and FSA guidance and create policies, procedures, guidelines to ensure compliance. |
| 1016.0100 | Auditable events shall be machine readable and made available in near real time to the ED and FSA SOC through automated APIs or equivalent. |
| 1017.0000 | The vendor shall perform internal and external routine network, database, and web applications scans for all devices, networks, and enclaves that support or contain FSA information or information systems, on a monthly basis. |
| 1017.0100 | The vendor shall provide the scan results to the FSA ISSO (and/or designated personnel). |
| 1017.0200 | The vendor shall analyze results and identify any vulnerabilities in coordination with FSA or ED resources. |
| 1018.0000 | The vendor shall enter security vulnerabilities identified through scans into an FSA approved template without false positives or duplicate findings. |
| 1019.0000 | The vendor shall train personnel on how to identify suspicious activity. |
| 1019.0100 | The vendor shall document all suspicious activity and report the activity to ED and FSA. |
| 1020.0000 | The vendor shall comply with federal requirements regarding audit storage. |
| 1021.0000 | The vendor shall provide appropriate responses to audit processing failures in accordance with federal regulations. |
| 1021.0200 | The vendor shall protect audit information in accordance with federal requirements. |
| 1022.0000 | The vendor shall implement remediation to correct deficiencies. |
| 1022.0200 | The vendor shall track deficiencies identified by any source. |
| 1022.0300 | The vendor shall create a mitigation strategy that fully remediates the deficiency and provide all other required information within 10 business days for deficiencies identified in formal FISMA, FISCAM, Financial, FSA (e.g., A-123, SSAE18, OIG) audits and within 30 business days for deficiencies identify by other sources. |
| 1022.0500 | The vendor shall complete the latest and correct form of the Department's POA&M deficiency tracking system’s injection template and submit to the correct Agencies’ recipient within the time frame required by the source of the deficiency or the Agencies’ recipient. |
| 1022.0600 | The vendor shall make any changes or updates required by the Department's POA&M deficiency tracking system IV&V team and/or the Agencies’ recipient of the Departments POA&M other deficiency tracking system’s injection template within 2 business days. |
| 1022.0700 | Once the Departments POA&M Agencies’ POAM/CSAM/other deficiency tracking system’s IV&V team and the Agencies’ recipient accept the mitigation strategy and the required items for the deficiency, it is an active corrective action that shall be worked by the vendor through completion. |
| 1022.0800 | The vendor shall submit the evidence to be used to demonstrate that the deficiency has been corrected no later than 10 business days prior to the estimated completion date |
| 1022.0900 | If after the deficiency has been entered and accepted into the Departments POA&M deficiency tracking system and the vendor cannot close the deficiency by the estimated completion date, the vendor shall submit for Agency consideration a justification for extending/changing the date and submit it to the Agencies’ recipient no later than 1 month prior to the current estimated completion date. |
| 1022.1000 | To close the deficiency in the Department's POA&M deficiency tracking system, the vendor shall input acceptable evidence of closure in the Department's POA&M deficiency tracking system’s and notify the Agencies’ recipient for review. |
| 1022.1100 | Issues causing or threatening milestones to be missed and potentially the estimated completion date shall be reported by the vendor to the Agencies’ Contracting Officer, the Agencies’ Contracting Officer’s representative, the Agencies’ recipient, the Agencies’ Business Owner and System Owner and the FSA and ED CISO no later than 1 week prior to the milestone date being threatened. |
| 1022.1200 | If the vendor disputes the ownership of the deficiency, they shall raise the issue in writing to the Agencies’ Contracting Officer, the Agencies’ Contracting Officer’s Representative, the Agencies’ recipient, the Agencies’ Business Owner and System Owner and the FSA CISO prior to the finding being injected/entered into the Department's POA&M deficiency tracking system and attend and participate meetings to discuss and make a decision on the ownership. Once ownership is decided, if needed, milestones and party identification shall be utilized to address issues raised in the ownership decision process. |
| 1023.0000 | The vendor shall capture all identified vulnerabilities and security weaknesses and corrective actions tracked through the Department's POA&M tool. |
| 1024.0000 | To the extent required to carry out a program of inspection to safeguard against threats to federal data, security audits, and control assessments, the Contractor shall afford ED/FSA access to the Contractor’s (and/or any subcontractor’s) facilities, installations, technical capabilities, operations, documentation, records, and databases within 48 hours of notification. The program of inspection shall include, but is not limited to vulnerability scans of authenticated and unauthenticated operating system/network, application, web applications, and database applications. |
| 1034.0100 | In the event of a security incident, the vendor shall preserve evidence and allow external forensic analysis either on-site or through shipment of components, and shall provide requested evidence within 24 hours. |
| 1034.0200 | The vendor shall report the status of their actions taken in relation to security alerts/warnings as requested. |
| 1036.0000 | The vendor shall comply with NIST 800-53 for physical and environmental controls. |
| 1036.0100 | The vendor shall log and escort visitors at all times. |
| 1036.0200 | The vendor shall keep facility access control lists current. The access and approved access lists shall be provided to the COR, CO or ISSO upon request and no later than 24 hours from request. |
| 1036.0300 | Alternate worksites shall be required to have the same protections as the primary site. |
| 1038.0000 | The vendor shall meet Federal Student Aid’s password standards, and the Department's Password requirements, as stated in the Department's Logical Access Control Guidance. (See Attachment - 1038_FSAPasswordParametersPolicyandProcedure). |
| 1039.0000 | The vendor shall maintain server and device security configurations in accordance with NIST security configuration standards (See: http://checklists.nist.gov/) and certify that applications are fully functional. The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved ED/FSA configuration baseline. |
| 1039.0100 | The vendor shall keep security patches current, within 30 days of vendor release, and appropriately tested prior to moving into production. Patching timing, based on severity, will adhere to OCIO 3-112 (Handbook for Information Assurance Security Policy Cybersecurity, and to any U.S. Department of Education Instructions on Information Assurance and/or Cybersecurity. |
| 1040.0000 | The vendor shall document all interconnections and have an Interconnection Security Agreement and a Trading Partners Agreement in place. (See NIST SP 800-47.) |
| 1041.0000 | The vendor shall document and follow change control management procedures, obtaining FSA approval as needed. (See Chapter 40000 for detailed Change Management requirements.) The vendor shall participate in in the ED and FSA change management, configuration management and enterprise architecture boards as required. |
| 1043.0000 | The vendor shall monitor and review user logs and produce monthly analysis reports of the reviews. The reviews shall determine if user behavior is indicative of insider threats. |
| 1044.0000 | The vendor shall comply with the controls for access management. |
| 1044.0100 | The vendor shall comply with the controls for access management contained in the current versions and revisions of: National Institute of Standards and Technology (NIST), SP-800-53, Recommended Security Controls for Federal Information Systems and Organizations; and NIST-SP-800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans. |
| 1044.0200 | The vendor shall comply with federal regulations regarding remote access. All remote access solutions, if provided, must support PIV authentication. |
| 1044.0300 | The vendor shall comply with federal regulations regarding access controls for portable and mobile devices. All access controls for portable and mobile devices, if applicable, must be capable of leveraging PIV or PIV derived credentials. |
| 1044.0400 | NOTE: The Government, at its discretion, may suspend or terminate the access and/or use of any or all Government access and systems for conducting business with any/or all vendors when a security or other electronic access, use or misuse issue gives cause for such action. The suspension or termination may last until such time as the Government determines that the situation has been corrected or no longer exists. |
| 1045.0000 | The vendor shall send application access reports monthly to Federal Student Aid for certification of access. |
| 1046.0000 | The vendor shall track and retain records of everyone who has approved access (user ID) to the servicing system, including clearances, training, and signed security documents; ensure that necessary clearances do not lapse; and suspend FSA access for anyone not in compliance. |
| 1047.0000 | The vendor shall restrict user access to only functions specific to the user's job duties. |
| 1048.0000 | The vendor shall send an email to all FSA System Security Officers at any time one of the vendor's users is no longer employed or no longer requires access to FSA systems, advising the FSA System Security Officers that the status of the person(s) identified is "no longer employed" or "no longer required access to FSA systems." This email shall be sent at least 5 days prior to an employee's removal from a contract or immediate in cases that require immediate removal of an individual for security or suitability reasons. |
| 1050.0100 | The vendor shall meet the NIST Special Publication 800-63-3, Digital Identity Guidelines for information on the level of assurance at Identity Assurance Level (IAL) 3, Authenticator Assurance Level (AAL) 3, and Federation Assurance Level (FAL) 3 (previously referred to as Level of Assurance 4 (LOA4)) and OMB Memorandum M-04-04. |
| 1050.0200 | If vendor proposes use of its corporate tokens to meet FSA’s requirements, vendor shall demonstrate to FSA that without exception it can achieve Identity Assurance Level (IAL) 3, Authenticator Assurance Level (AAL) 3, and Federation Assurance Level (FAL) 3 authentication and meet all FSA requirements. All privileged, administrative, Tier 4 suitability and those users with access to ED or FSA data must be issued ED approved PIV authenticators. All other users performing functions on behalf of ED or FSA (Tier 2 suitability) must meet IAL 2, AAL 2, and FAL 2. If applicable, end users of the vendors solution shall be provided IAL 2, AAL 2, and FAL 2 standard capabilities with the ability to issue up to IAL 3, AAL 3, and FAL 3 authenticators. |
| 1051.0300 | The vendor shall comply with instructions on how to register the tokens using the Federal Student Aid Two Factor Authentication Token For FSA User Handout distributed with the tokens. |
| 1054.0200 | In the event of any reported security breach, the Government may immediately disable or deactivate vendor access to its network without prior notice. |
| 1056.0100 | The vendor shall ensure compliance with FISMA by authoring FISMA artifacts and responding to FISMA-related data calls. |
| 1056.0110 | The vendor shall provide technical strategy, guidance, and consultative advice to ED and FSA regarding facility, network, and operating system security. |
| 1056.0120 | The vendor shall ensure that the website is in compliance with OMB Memoranda M-17-06, M-15-13, M-08-23, and M-10-23; DHS Binding Operational Directives (BOD); and NIST SP 800-52 and NIST SP 800-44. |
| 1056.0130 | The vendor shall implement and renew TLS 1.2 certificates with HTTP Strict Transport Security (HSTS) enabled, host federal websites on a .gov location, and not have any DNS records with the www prefix. |
| 1056.0140 | The vendor shall ensure that email applications have SMTP enabled. |
| 1056.0150 | The vendor shall support security testing and evaluation of FSA's applications that are impacted by the vendor's scope and deliverables. |
| 1056.0160 | The vendor shall support remediation of security-related issues in FSA's applications that are impacted by the vendor's scope and deliverables. |
| 1056.0170 | The vendor shall support handling security incidents related to FSA's applications that are impacted by the vendor's scope and deliverables. |
| 1056.0180 | The vendor shall ensure the website requires two factor authentication where necessary and meets other requirements of the ED Cyber Security Job Aid (https://share.ed.gov/teams/sow/SitePages/Reviewer.aspx). |
| 1057.0000 | The vendor shall report incidents in accordance with FSA and Department security policy. |
| 1057.0100 | The vendor shall be liable for breaches of security resulting from failure to follow Federal, NIST, DHS, ED or FSA security processes and the federal law, guidance documents, and security standards. |
| 1057.0200 | The vendor shall develop and implement processes and technology to ensure compliance with the ED and FSA cybersecurity incident response and breach activities within OCIO-14 Handbook for Cybersecurity Incident Response and Reporting. |
| 1057.0300 | The vendor shall report all suspected and confirmed cybersecurity incident and breaches, using Department approved reporting requirements, the within 45 minutes of discovery of the incident. The following organizations will be the recipients of the report: EDCIRC (edcirc@ed.gov), FSASOC (fsasoc@ed.gov), and EDSOC (edsoc@ed.gov). The vendor shall integrate their SOC ticketing or incident reporting system with the ED and FSA SOC services to enable near real time reporting and query capabilities. |
| 1061.0000 | The vendor shall maintain a logical and physical segregation of ED and FSA data from all non-ED/FSA data within their infrastructure, whether cloud (see FedRAMP for additional guidance) or non-cloud, both in storage and during the transmission of the data, and report the segregated configuration via the FISMA management system. |
| 1062.0400 | The vendor shall use the change management process to identify potential security gaps in segregation maintenance, and shall report status and findings quarterly. |
| 1065.0000 | The vendor shall designate a Security Administrator and ISSO, who shall serve as a primary contact point regarding security related issues. |
| 1066.0000 | The vendor shall support ED and FSA's Technology Refreshment and Evergreening activities. |
| 1066.0100 | The vendor performing integration services for FSA in connection with FISMA-approved (FedRAMP ready or authorized) cloud computing services (SaaS, PaaS, IaaS) shall ensure the infrastructure, support software, and enabling components and frameworks are maintained to (at minimum) N-1 supported versions as part of a standard technology refreshment program (evergreening). |
| 1070.0100 | The vendor shall follow FSA's Information Technology Infrastructure Library (ITIL) processes supporting the data center including the Incident and Problem Management process and the Security Incident management process including the Breach Notification Policy and Response Plan. Also see attachment 1070_FSA_Incident_Response_SOP_V3.0_FINAL. |
| 1070.0200 | The vendor shall be required to provide information that will assist in determining the problem, root cause and resolution within 24 hours from request. |
| 1071.0000 | The vendor performing integration services for FSA in connection with FISMA-approved cloud computing services (SaaS, PaaS, IaaS) shall acquire for FSA any and all licenses necessary to meet FSA’s requirements for the use of such cloud services as specified in the contract. |
| 1081.0000 | The vendor shall allow FSA access to FSA information including data schemas, meta data, and other associated data artifacts that are required to ensure FSA can fully and appropriately retrieve FSA information that can be stored, read, and processed; including but not limited to data stored on recovery media, tape backups, images etc. |
| 1082.0000 | The vendor shall not publish, permit to be published, or distribute for public consumption, any information, oral or written, concerning the results or conclusions made pursuant to the performance of this contract, without the prior written consent of the FSA CISO and Contracting Officer. |
| 1082.0100 | Two copies of any material proposed to be published or distributed must be submitted to the FSA Contracting Officer for approval. |
| 1085.0000 | The vendor shall, upon end/suspension/termination of contract, execute secure destruction of all existing active and archived originals and/or copies of all FSA and FSA-activity-related files and information, including both electronic and hardcopy data. All destruction must be in adherence to NIST SP 800-88 as amended, and ED and FSA Security Policy Requirements. |
| 1085.0100 | The vendor shall complete the destruction within an agreed upon timeframe with FSA, but no later than sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by FSA or by the vendor for any reason. |
| 1085.0300 | The vendor must provide FSA with Certification of Secure Destruction of all existing active and archived originals and/or copies of all FSA and FSA-activity-related files and information. The Certification shall be provided by a Third Party Firm approved in advance by FSA. All costs associated with Certification shall be the sole responsibility of the vendor. |
| 1085.0400 | After system disposal/decommissioning, the vendor must track and monitor FSA PII and/or SPII data on backup and other secondary media sources that cannot be immediately destroyed and report security incidents and breaches to Federal Student Aid within one hour of becoming aware of the incident/breach until such media is taken out of production and destroyed. |
| 1086.0000 | The vendor shall, upon end/suspension/termination of contract, return all FSA-Owned and Leased Computing and Information Storage Equipment. |
| 1086.0100 | The vendor shall return the items within an agreed upon timeframe with FSA, but no later than sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by FSA or by the vendor for any reason; |
| 1086.0200 | The vendor must provide FSA with Certification of Verified Return of all FSA-Owned and Leased Computing and Information Storage Equipment. |
| 1088.0000 | The vendor must use FedRamp approved assessors (3PAO) to perform and document independent assessments of security controls for the systems. Assessment results and associated POAMs and RAFs shall be kept current in the ED FISMA management system. |
| 1089.0000 | The vendor shall develop a Business Impact Assessment (BIA) and Appendix Document in accordance with federal regulations and Federal Student Aid guidance and update as needed but no less than annually, and provide the documents to FSA on demand. |
| 1090.0000 | The vendor shall maintain a living list of all information assets, mapped to systems and applications, and prioritized by risk. |
| 1092.0000 | The vendor shall integrate risk management into governance and oversight of the cybersecurity function and program outcomes. |
| 1093.0000 | The vendor shall plan for whole-of-business incident response, with codified decision matrices, event-specific playbooks, and scenario-driven simulation. |
| 1094.0000 | The vendor shall make security a driving design feature of technology architecture and resource for it appropriately. |
| 1095.0000 | The vendor shall apply elevated levels of protection for higher-risk systems and assets. |
| 1096.0000 | Embed anti-fraud practices deeply with security operations and response. |
| 20008.0200 | The vendor will update FSA with their list of Suspicious email and physical addresses at FSA's request. |
| 20008.0300 | The vendor shall receive and store the indicators of suspicious application for additional analysis and review from ED and FSA through manual and automated means. |
| Footnotes | |
| 1. NIST 800-145 The NIST Definition of Cloud Computing. Private cloud. The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off premises. | |
| 2. FedRAMP Ready means the cloud service provider (CSP) has completed a Readiness Assessment Report (RAR) that has been approved by the FedRAMP PMO. This indicates that a CSP is likely to attain a JAB P-ATO an Agency ATO. While not a guarantee that the CSP will become authorized, the government has a clearer understanding of a provider’s technical capabilities before the assessment process begins so there is a greater likelihood of success in the authorization process. https://www.fedramp.gov/make-the-most-of-the-fedramp-marketplace/ |
Page &P of &N
File details come from the government source that posted it. Updated .