03 - Security Technical Requirements.xlsx

XLSX spreadsheet 27 KB Posted

Attached to
Request for Information: Award Eligibility Determination Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of Education

About this file

This document outlines technical security requirements for a federal student loan servicing system. It specifies controls from the NIST SP 800-53 series that a vendor must meet to receive an Authorization to Operate, including developing system security plans, boundary documents, privacy impact assessments, and continuous monitoring capabilities. It mandates encryption, access restrictions, training, auditing, vulnerability scanning, patching, change management, and incident response according to federal guidelines. The vendor must maintain segregation of education data, support technology refreshment, and ensure secure destruction of records. Overall, the document provides an extensive list of cybersecurity controls a vendor must fulfill to handle federal student information within this system.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information: Award Eligibility Determination, newest first.
File Type Posted
10 - AED Draft SLAs.xlsx XLSX spreadsheet
12 - CPS 101 with FA impacts 09102020.pdf PDF
11 - ED CSF Risk Scorecard Overview_July 2020.pdf PDF
09 - FSA Current State.pdf PDF
AED RFI Final.pdf PDF
08 - FSA Identity Access Mgt Solution Overview.docx DOCX document
01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf PDF
02 - Pricing Template.xlsx XLSX spreadsheet
07 - Hosting Environments w Approved ATOs.pdf PDF
06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx XLSX spreadsheet
05 - Hosting Environments with Approved Agency ATOs.pdf PDF
04 - Additional Current State Technical Constraints.xlsx XLSX spreadsheet
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sheet1 U.S. Department of Education Office of Federal Student Aid Next Generation Financial Services Environment

Attachment 03 – Security Technical Requirements

NumberRequirementsMeetsExplanation of How the Requirement is MetDoes Not MeetExplanation and Mitigation Strategy (if does not meet)
1000.0000The vendor shall provide all information and take all actions requested by Federal Student Aid to support the process for the vendor to receive an Authorization to Operate.
1000.0100The vendor shall complete a self-assessment of its system and facilities based on NIST SP 800-53 controls, and additional controls directed by FSA, identify security deficiencies/gaps, and create a remediation plan for the identified deficiencies.
1000.0110Prior to implementation, the vendor shall support and must pass a NIST SP 800-53 controls assessment conducted by FSA.
1000.0210The vendor shall develop and maintain the System Security Plan (SSP) in compliance with NIST SP 800-18 and NIST SP-800-53 and any other applicable Federal Statutes, Standards, and Guidelines, and enter all SSP information into the Department's FISMA management tool, CSAM.
1000.0220The vendor shall review and update the SSP at any time when significant changes are made to the servicing system/solution, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO).
1000.0310The vendor shall develop and keep current a System Boundary document using the templates provided by FSA.
1000.0410The vendor shall conduct a periodic review of System Boundary Document and update as needed, but no less than annually, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO).
1000.0500The vendor shall develop a Privacy Threshold Analysis (PTA), and a Privacy Impact Assessment (PIA) in accordance with federal regulations and update them as needed, but no less than annually, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO).
1000.0600The vendor shall comply with 100% of the applicable NIST 800-53 security controls, and any FSA modifications, in accordance with the FIPS 199 category for the proposed solution.
1000.0800The vendor shall provide previous security information from the past three years if available to include a discussion of security incidents; and audits like the Statement on Standards for Attestation Engagements (SSAE) No. 18, Sarbanes Oxley reviews, independent security assessments, risk assessments, and/or internal reviews along with the applicable remediation plans.
1000.1000In accordance with FSA's Lifecycle Management Methodology, Enterprise Change Management Plan, and Business Change Management Plan, the vendor shall develop a configuration management plan, for all systems in development and production, and shall update the plan as needed, but no less than annually, including, but not limited to, whenever any changes are made that necessitate the generation and procurement of a new Authorization to Operate (ATO).
1000.1100The vendor shall bundle the requested security information as attachments to a discussion document that explains the artifact submitted. The vendor's senior security official and program manager shall sign the document to certify the system's security posture and overall security risk. The vendor shall ensure all information is entered into the Department's FISMA management tool and kept current.
1001.0000The vendor shall ensure that all Personally Identifiable Information (PII), including Sensitive Personally Identifiable Information (SPII), is kept secure and provided only to properly authorized individuals and organizations.
1001.0100The vendor shall restrict access to personnel who have obtained proper U.S. Department of Education (ED) final or preliminary clearance / background investigation adjudication and who are specifically authorized to view or perform transactions and services on loans held by FSA or the Department.
1001.0200The vendor shall ensure proper control and handling of PII, including any SPII, residing on their computer, on removable media, and on paper documents.
1001.0400The vendor shall ensure data at rest that contains PII and/or SPII is encrypted using validated FIPS 140-2 encryption in any and all vendor and government Cloud computing environments. where PII and/or SPII is housed, and/or stored.
1001.0410The vendor shall consider data at rest to include data that reside in databases, file systems, information technology systems, applications, personal computers (desktops and laptops and portable electronic devices [PEDs] and mobile electronic devices and personal data assistants [PDAs]) and other structured storage devices (USB flash drives, memory cards, external hard drives, writeable CDs and DVDs) that are not in transit.
1001.0420Proposed cloud solutions shall meet the appropriate requirements of NIST SP 800-145, FIPS 199, FIPS 200 and/or FedRAMP. If a private cloud1 solution, as defined by NIST SP 800-145, is proposed it shall meet either a FIPS-199 High level or Moderate level, depending on the proposed architecture and corresponding FIPS-199 category of the system. If the solution proposes a FedRAMP cloud solution it must be FedRAMP "Ready"2 at either a FIPS-199 High level or Moderate level, depending on the proposed architecture and corresponding FIPS-199 category of the system. See solicitation documentation for additional clarification.
1001.0500The vendor shall present evidence (e.g., NIST certificate for the specific product and module) that the products it utilizes provide cryptographic protections using modules that comply with FIPS PUB 140-2 standards.
1001.0510The vendor shall ensure the proper marking, control, and storage of all printouts and other paper documents containing PII and/or SPII in their possession.
1001.0600The vendor shall ensure PII and/or SPII is not sent in the subject line, or body of an email, or included in an unencrypted attachment. Attachments containing PII and/or SPII must be encrypted using an approved FIPS 140-2 encryption method.
1001.0610The vendor shall ensure communications in which PII and/or SPII is transferred include a secure encrypted channel using an FIPS 140-2 encryption method.
1001.0620The vendor shall ensure passwords for encrypted attachments are not communicated in the same email as the attachment.
1002.0000Immediately following successful completion of a security authorization, the vendor shall implement continuous security monitoring in accordance with NIST SP 800-137 capable of satisfying an ongoing security authorization. The vendor's Continuous Monitoring must feed into the Department and FSA continuous monitoring programs via machine to machine near-real-time updates and static frequency based updates. The vendor shall ensure all information is entered into the Department's FISMA management tool and kept current with all changes.
1002.0100The vendor shall provide POA&M updates in accordance with requirements and the any schedules set forth in the U.S. Department of Education's Handbook for Information Assurance Cybersecurity, and in any U.S. Department of Education Instructions on Information Assurance and/or Cybersecurity, Security Policy Handbook and with the FSA Plan of Action & Milestones (POA&M) Guide - see 01002B_POAM_SOP. Reference: NIST 800-53 control CA-5.
1002.0500The vendor shall provide an annual update to the contingency plan completed in accordance with NIST 800-34, and with the U.S. Department of Education's OCIO-10 Handbook for Information Technology Security Contingency Planning Guidance Procedures. See 01002C_ITCPG Reference: NIST 800-53 control CP-2
1002.0700The vendor shall conduct and provide the results of the monthly review and validation of system users’ accounts to ensure the continued need for system access. The user certification and authorization documents will illustrate the organization establishes, activates, modifies, reviews, disables, and removes information system accounts in accordance with documented account management procedures. Reference: NIST 800-53 control AC-2. Ad Hoc reports of personnel, positions, access and suitability shall be provided upon request.
1002.0800The vendor shall provide and maintain a well-defined, documented, and up-to-date System(s) Baseline Configuration Standard Document specification to which the information system is built or changed. Reference: NIST 800-53
1002.0910Changes to the baseline configuration shall be reflected within the System(s) Baseline Configuration Standard Documentation on a regular schedule based on FSA Hardening Standards and guidelines.
1002.1100The vendor shall provide the external IP space used to support FSA and enter into an agreement with the Department and DHS to allow them to conduct ongoing Health and Hygiene uncredentialled scanning.
1002.1200The vendor shall provide monthly, not later than the 2nd day of the month, CyberScope reports for all systems that support FSA. The report will be in National Institute of Standards and Technology (NIST) Security Content Automation Protocol (SCAP) format. See also: the U.S. Department of Education's Handbook for Information Assurance Cybersecurity, and any U.S. Department of Education Instructions on Information Assurance and/or Cybersecurity.
1004.0000The vendor shall ensure all internet traffic is routed via trusted internet connections (TIC) or MTIPS.
1005.0000The vendor shall display an FSA approved (as amended) system use notification message (banner) before users access the servicing system.
1006.0100The vendor shall work with FSA to develop appropriate session lock/termination procedures and practices that conform with FSA's requirements, and to the requirements in the U.S. Department of Education's Logical Access Control Guidance post award.
1008.0000The vendor shall complete personnel background screening requirements in compliance with all Federal, Education and Federal Student Aid guidelines.
1008.0100All personnel are required to complete a federal background investigation based on their position risk level. Vendor employees who have undergone appropriate personnel security screening for another federal agency may submit proof of personal security screening for validation. (Attached Security 1008_vendor Employee Personnel Security Screenings.) Reciprocity may or may not be granted by ED and/or FSA Personnel Security.
1008.0200All individuals must receive ED suitability and FSA authorization prior to accessing FSA data or information systems. Favorable preliminary suitability designations must be obtained for all positions prior to working on ED or FSA systems or data (This process can take 2-6 weeks).
1008.0300Only US citizens may be assigned to a High Risk IT (Tier 4, Federal Investigative Standards) level positions. All system administrator, engineer, security and other similar users with privileged access must meet Tier 4 requirements including US citizenship.
1008.0400All vendor employees with access to ED or FSA data who are not determined to be "high risk" shall be designated "Moderate Risk IT" Tier 2 Federal Investigative Standard level positions.
1010.0000The vendor shall require all personnel to complete mandatory and specialized security training as defined in coordination with FSA.
1010.0200The vendor shall require all personnel to successfully complete initial security awareness training prior to granting access to FSA data or information systems and conduct Department identified mandatory annual training.
1010.0310The vendor shall ensure minimum information security training hours required for these positions is as follows:

-IT Executives, Managers and System Owners (1 hr) -Information Security Specialist or Information System Security Officer (ISSO) - 20 hrs -Privacy Officer and staff - 5 hrs -System Administrator, Network Administrator, Database Administrator, Service Desk Personnel/Helpdesk, System Programmers, Programmer with access to production environment - 10 hrs -Other IT Personnel with security responsibilities - 1 hr

1010.0400The vendor shall maintain records of security training completion and provide those records to ED or FSA on demand.
1011.0000The vendor shall identify primary and alternate telecommunications sites sufficient to meet Tier 4 data center resilience and uptime.
1013.0000The vendor shall not use wireless communication containing Federal Student Aid information within the data center.
1015.0000The vendor shall provide, to the FSA Information System Security Officer (ISSO), focused and timely support, including complete evidence, in responding to all oversight and agency audits.
1015.0200The vendor shall provide Plans of Action and Milestones to FSA's ISSO for system audits, and shall remediate audit findings specified in those plans according to agreed upon deadlines.
1016.0000The vendor shall audit security relevant events as defined by NIST, ED, and FSA guidance and create policies, procedures, guidelines to ensure compliance.
1016.0100Auditable events shall be machine readable and made available in near real time to the ED and FSA SOC through automated APIs or equivalent.
1017.0000The vendor shall perform internal and external routine network, database, and web applications scans for all devices, networks, and enclaves that support or contain FSA information or information systems, on a monthly basis.
1017.0100The vendor shall provide the scan results to the FSA ISSO (and/or designated personnel).
1017.0200The vendor shall analyze results and identify any vulnerabilities in coordination with FSA or ED resources.
1018.0000The vendor shall enter security vulnerabilities identified through scans into an FSA approved template without false positives or duplicate findings.
1019.0000The vendor shall train personnel on how to identify suspicious activity.
1019.0100The vendor shall document all suspicious activity and report the activity to ED and FSA.
1020.0000The vendor shall comply with federal requirements regarding audit storage.
1021.0000The vendor shall provide appropriate responses to audit processing failures in accordance with federal regulations.
1021.0200The vendor shall protect audit information in accordance with federal requirements.
1022.0000The vendor shall implement remediation to correct deficiencies.
1022.0200The vendor shall track deficiencies identified by any source.
1022.0300The vendor shall create a mitigation strategy that fully remediates the deficiency and provide all other required information within 10 business days for deficiencies identified in formal FISMA, FISCAM, Financial, FSA (e.g., A-123, SSAE18, OIG) audits and within 30 business days for deficiencies identify by other sources.
1022.0500The vendor shall complete the latest and correct form of the Department's POA&M deficiency tracking system’s injection template and submit to the correct Agencies’ recipient within the time frame required by the source of the deficiency or the Agencies’ recipient.
1022.0600The vendor shall make any changes or updates required by the Department's POA&M deficiency tracking system IV&V team and/or the Agencies’ recipient of the Departments POA&M other deficiency tracking system’s injection template within 2 business days.
1022.0700Once the Departments POA&M Agencies’ POAM/CSAM/other deficiency tracking system’s IV&V team and the Agencies’ recipient accept the mitigation strategy and the required items for the deficiency, it is an active corrective action that shall be worked by the vendor through completion.
1022.0800The vendor shall submit the evidence to be used to demonstrate that the deficiency has been corrected no later than 10 business days prior to the estimated completion date
1022.0900If after the deficiency has been entered and accepted into the Departments POA&M deficiency tracking system and the vendor cannot close the deficiency by the estimated completion date, the vendor shall submit for Agency consideration a justification for extending/changing the date and submit it to the Agencies’ recipient no later than 1 month prior to the current estimated completion date.
1022.1000To close the deficiency in the Department's POA&M deficiency tracking system, the vendor shall input acceptable evidence of closure in the Department's POA&M deficiency tracking system’s and notify the Agencies’ recipient for review.
1022.1100Issues causing or threatening milestones to be missed and potentially the estimated completion date shall be reported by the vendor to the Agencies’ Contracting Officer, the Agencies’ Contracting Officer’s representative, the Agencies’ recipient, the Agencies’ Business Owner and System Owner and the FSA and ED CISO no later than 1 week prior to the milestone date being threatened.
1022.1200If the vendor disputes the ownership of the deficiency, they shall raise the issue in writing to the Agencies’ Contracting Officer, the Agencies’ Contracting Officer’s Representative, the Agencies’ recipient, the Agencies’ Business Owner and System Owner and the FSA CISO prior to the finding being injected/entered into the Department's POA&M deficiency tracking system and attend and participate meetings to discuss and make a decision on the ownership. Once ownership is decided, if needed, milestones and party identification shall be utilized to address issues raised in the ownership decision process.
1023.0000The vendor shall capture all identified vulnerabilities and security weaknesses and corrective actions tracked through the Department's POA&M tool.
1024.0000To the extent required to carry out a program of inspection to safeguard against threats to federal data, security audits, and control assessments, the Contractor shall afford ED/FSA access to the Contractor’s (and/or any subcontractor’s) facilities, installations, technical capabilities, operations, documentation, records, and databases within 48 hours of notification. The program of inspection shall include, but is not limited to vulnerability scans of authenticated and unauthenticated operating system/network, application, web applications, and database applications.
1034.0100In the event of a security incident, the vendor shall preserve evidence and allow external forensic analysis either on-site or through shipment of components, and shall provide requested evidence within 24 hours.
1034.0200The vendor shall report the status of their actions taken in relation to security alerts/warnings as requested.
1036.0000The vendor shall comply with NIST 800-53 for physical and environmental controls.
1036.0100The vendor shall log and escort visitors at all times.
1036.0200The vendor shall keep facility access control lists current. The access and approved access lists shall be provided to the COR, CO or ISSO upon request and no later than 24 hours from request.
1036.0300Alternate worksites shall be required to have the same protections as the primary site.
1038.0000The vendor shall meet Federal Student Aid’s password standards, and the Department's Password requirements, as stated in the Department's Logical Access Control Guidance. (See Attachment - 1038_FSAPasswordParametersPolicyandProcedure).
1039.0000The vendor shall maintain server and device security configurations in accordance with NIST security configuration standards (See: http://checklists.nist.gov/) and certify that applications are fully functional. The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved ED/FSA configuration baseline.
1039.0100The vendor shall keep security patches current, within 30 days of vendor release, and appropriately tested prior to moving into production. Patching timing, based on severity, will adhere to OCIO 3-112 (Handbook for Information Assurance Security Policy Cybersecurity, and to any U.S. Department of Education Instructions on Information Assurance and/or Cybersecurity.
1040.0000The vendor shall document all interconnections and have an Interconnection Security Agreement and a Trading Partners Agreement in place. (See NIST SP 800-47.)
1041.0000The vendor shall document and follow change control management procedures, obtaining FSA approval as needed. (See Chapter 40000 for detailed Change Management requirements.) The vendor shall participate in in the ED and FSA change management, configuration management and enterprise architecture boards as required.
1043.0000The vendor shall monitor and review user logs and produce monthly analysis reports of the reviews. The reviews shall determine if user behavior is indicative of insider threats.
1044.0000The vendor shall comply with the controls for access management.
1044.0100The vendor shall comply with the controls for access management contained in the current versions and revisions of: National Institute of Standards and Technology (NIST), SP-800-53, Recommended Security Controls for Federal Information Systems and Organizations; and NIST-SP-800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans.
1044.0200The vendor shall comply with federal regulations regarding remote access. All remote access solutions, if provided, must support PIV authentication.
1044.0300The vendor shall comply with federal regulations regarding access controls for portable and mobile devices. All access controls for portable and mobile devices, if applicable, must be capable of leveraging PIV or PIV derived credentials.
1044.0400NOTE: The Government, at its discretion, may suspend or terminate the access and/or use of any or all Government access and systems for conducting business with any/or all vendors when a security or other electronic access, use or misuse issue gives cause for such action. The suspension or termination may last until such time as the Government determines that the situation has been corrected or no longer exists.
1045.0000The vendor shall send application access reports monthly to Federal Student Aid for certification of access.
1046.0000The vendor shall track and retain records of everyone who has approved access (user ID) to the servicing system, including clearances, training, and signed security documents; ensure that necessary clearances do not lapse; and suspend FSA access for anyone not in compliance.
1047.0000The vendor shall restrict user access to only functions specific to the user's job duties.
1048.0000The vendor shall send an email to all FSA System Security Officers at any time one of the vendor's users is no longer employed or no longer requires access to FSA systems, advising the FSA System Security Officers that the status of the person(s) identified is "no longer employed" or "no longer required access to FSA systems." This email shall be sent at least 5 days prior to an employee's removal from a contract or immediate in cases that require immediate removal of an individual for security or suitability reasons.
1050.0100The vendor shall meet the NIST Special Publication 800-63-3, Digital Identity Guidelines for information on the level of assurance at Identity Assurance Level (IAL) 3, Authenticator Assurance Level (AAL) 3, and Federation Assurance Level (FAL) 3 (previously referred to as Level of Assurance 4 (LOA4)) and OMB Memorandum M-04-04.
1050.0200If vendor proposes use of its corporate tokens to meet FSA’s requirements, vendor shall demonstrate to FSA that without exception it can achieve Identity Assurance Level (IAL) 3, Authenticator Assurance Level (AAL) 3, and Federation Assurance Level (FAL) 3 authentication and meet all FSA requirements. All privileged, administrative, Tier 4 suitability and those users with access to ED or FSA data must be issued ED approved PIV authenticators. All other users performing functions on behalf of ED or FSA (Tier 2 suitability) must meet IAL 2, AAL 2, and FAL 2. If applicable, end users of the vendors solution shall be provided IAL 2, AAL 2, and FAL 2 standard capabilities with the ability to issue up to IAL 3, AAL 3, and FAL 3 authenticators.
1051.0300The vendor shall comply with instructions on how to register the tokens using the Federal Student Aid Two Factor Authentication Token For FSA User Handout distributed with the tokens.
1054.0200In the event of any reported security breach, the Government may immediately disable or deactivate vendor access to its network without prior notice.
1056.0100The vendor shall ensure compliance with FISMA by authoring FISMA artifacts and responding to FISMA-related data calls.
1056.0110The vendor shall provide technical strategy, guidance, and consultative advice to ED and FSA regarding facility, network, and operating system security.
1056.0120The vendor shall ensure that the website is in compliance with OMB Memoranda M-17-06, M-15-13, M-08-23, and M-10-23; DHS Binding Operational Directives (BOD); and NIST SP 800-52 and NIST SP 800-44.
1056.0130The vendor shall implement and renew TLS 1.2 certificates with HTTP Strict Transport Security (HSTS) enabled, host federal websites on a .gov location, and not have any DNS records with the www prefix.
1056.0140The vendor shall ensure that email applications have SMTP enabled.
1056.0150The vendor shall support security testing and evaluation of FSA's applications that are impacted by the vendor's scope and deliverables.
1056.0160The vendor shall support remediation of security-related issues in FSA's applications that are impacted by the vendor's scope and deliverables.
1056.0170The vendor shall support handling security incidents related to FSA's applications that are impacted by the vendor's scope and deliverables.
1056.0180The vendor shall ensure the website requires two factor authentication where necessary and meets other requirements of the ED Cyber Security Job Aid (https://share.ed.gov/teams/sow/SitePages/Reviewer.aspx).
1057.0000The vendor shall report incidents in accordance with FSA and Department security policy.
1057.0100The vendor shall be liable for breaches of security resulting from failure to follow Federal, NIST, DHS, ED or FSA security processes and the federal law, guidance documents, and security standards.
1057.0200The vendor shall develop and implement processes and technology to ensure compliance with the ED and FSA cybersecurity incident response and breach activities within OCIO-14 Handbook for Cybersecurity Incident Response and Reporting.
1057.0300The vendor shall report all suspected and confirmed cybersecurity incident and breaches, using Department approved reporting requirements, the within 45 minutes of discovery of the incident. The following organizations will be the recipients of the report: EDCIRC (edcirc@ed.gov), FSASOC (fsasoc@ed.gov), and EDSOC (edsoc@ed.gov). The vendor shall integrate their SOC ticketing or incident reporting system with the ED and FSA SOC services to enable near real time reporting and query capabilities.
1061.0000The vendor shall maintain a logical and physical segregation of ED and FSA data from all non-ED/FSA data within their infrastructure, whether cloud (see FedRAMP for additional guidance) or non-cloud, both in storage and during the transmission of the data, and report the segregated configuration via the FISMA management system.
1062.0400The vendor shall use the change management process to identify potential security gaps in segregation maintenance, and shall report status and findings quarterly.
1065.0000The vendor shall designate a Security Administrator and ISSO, who shall serve as a primary contact point regarding security related issues.
1066.0000The vendor shall support ED and FSA's Technology Refreshment and Evergreening activities.
1066.0100The vendor performing integration services for FSA in connection with FISMA-approved (FedRAMP ready or authorized) cloud computing services (SaaS, PaaS, IaaS) shall ensure the infrastructure, support software, and enabling components and frameworks are maintained to (at minimum) N-1 supported versions as part of a standard technology refreshment program (evergreening).
1070.0100The vendor shall follow FSA's Information Technology Infrastructure Library (ITIL) processes supporting the data center including the Incident and Problem Management process and the Security Incident management process including the Breach Notification Policy and Response Plan. Also see attachment 1070_FSA_Incident_Response_SOP_V3.0_FINAL.
1070.0200The vendor shall be required to provide information that will assist in determining the problem, root cause and resolution within 24 hours from request.
1071.0000The vendor performing integration services for FSA in connection with FISMA-approved cloud computing services (SaaS, PaaS, IaaS) shall acquire for FSA any and all licenses necessary to meet FSA’s requirements for the use of such cloud services as specified in the contract.
1081.0000The vendor shall allow FSA access to FSA information including data schemas, meta data, and other associated data artifacts that are required to ensure FSA can fully and appropriately retrieve FSA information that can be stored, read, and processed; including but not limited to data stored on recovery media, tape backups, images etc.
1082.0000The vendor shall not publish, permit to be published, or distribute for public consumption, any information, oral or written, concerning the results or conclusions made pursuant to the performance of this contract, without the prior written consent of the FSA CISO and Contracting Officer.
1082.0100Two copies of any material proposed to be published or distributed must be submitted to the FSA Contracting Officer for approval.
1085.0000The vendor shall, upon end/suspension/termination of contract, execute secure destruction of all existing active and archived originals and/or copies of all FSA and FSA-activity-related files and information, including both electronic and hardcopy data. All destruction must be in adherence to NIST SP 800-88 as amended, and ED and FSA Security Policy Requirements.
1085.0100The vendor shall complete the destruction within an agreed upon timeframe with FSA, but no later than sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by FSA or by the vendor for any reason.
1085.0300The vendor must provide FSA with Certification of Secure Destruction of all existing active and archived originals and/or copies of all FSA and FSA-activity-related files and information. The Certification shall be provided by a Third Party Firm approved in advance by FSA. All costs associated with Certification shall be the sole responsibility of the vendor.
1085.0400After system disposal/decommissioning, the vendor must track and monitor FSA PII and/or SPII data on backup and other secondary media sources that cannot be immediately destroyed and report security incidents and breaches to Federal Student Aid within one hour of becoming aware of the incident/breach until such media is taken out of production and destroyed.
1086.0000The vendor shall, upon end/suspension/termination of contract, return all FSA-Owned and Leased Computing and Information Storage Equipment.
1086.0100The vendor shall return the items within an agreed upon timeframe with FSA, but no later than sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by FSA or by the vendor for any reason;
1086.0200The vendor must provide FSA with Certification of Verified Return of all FSA-Owned and Leased Computing and Information Storage Equipment.
1088.0000The vendor must use FedRamp approved assessors (3PAO) to perform and document independent assessments of security controls for the systems. Assessment results and associated POAMs and RAFs shall be kept current in the ED FISMA management system.
1089.0000The vendor shall develop a Business Impact Assessment (BIA) and Appendix Document in accordance with federal regulations and Federal Student Aid guidance and update as needed but no less than annually, and provide the documents to FSA on demand.
1090.0000The vendor shall maintain a living list of all information assets, mapped to systems and applications, and prioritized by risk.
1092.0000The vendor shall integrate risk management into governance and oversight of the cybersecurity function and program outcomes.
1093.0000The vendor shall plan for whole-of-business incident response, with codified decision matrices, event-specific playbooks, and scenario-driven simulation.
1094.0000The vendor shall make security a driving design feature of technology architecture and resource for it appropriately.
1095.0000The vendor shall apply elevated levels of protection for higher-risk systems and assets.
1096.0000Embed anti-fraud practices deeply with security operations and response.
20008.0200The vendor will update FSA with their list of Suspicious email and physical addresses at FSA's request.
20008.0300The vendor shall receive and store the indicators of suspicious application for additional analysis and review from ED and FSA through manual and automated means.
Footnotes
1. NIST 800-145 The NIST Definition of Cloud Computing. Private cloud. The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off premises.
2. FedRAMP Ready means the cloud service provider (CSP) has completed a Readiness Assessment Report (RAR) that has been approved by the FedRAMP PMO. This indicates that a CSP is likely to attain a JAB P-ATO an Agency ATO. While not a guarantee that the CSP will become authorized, the government has a clearer understanding of a provider’s technical capabilities before the assessment process begins so there is a greater likelihood of success in the authorization process. https://www.fedramp.gov/make-the-most-of-the-fedramp-marketplace/

Page &P of &N

File details come from the government source that posted it. Updated .