03 UUI Security Requirements-Mobile.pdf

PDF 324 KB Posted

Attached to
Unified User Interface (UUI) Federal contract opportunity
Solicitation number
47PM0024R0003
Issued by
General Services Administration Public Buildings Service

About this file

This document is a solicitation notice for the Unified User Interface (UUI) project. The General Services Administration (GSA) is requesting proposals to provide a unified user interface solution. Key details include:

  • A single award contract will be made for this requirement. The acquisition is not set aside for small businesses.

  • The pre-proposal conference will be held on February 6, 2024, with a maximum of three attendees allowed per offeror. Questions are due by February 5 and February 8, 2024.

  • Proposals are due by February 26, 2024 at 07:59 AM EST and must be submitted electronically as described in Section L. The offer acceptance period is 120 days from proposal due date.

  • The Service Contract Labor Standards wage rate decision DC 2015-4281 dated December 26, 2023 applies to the contract.

  • The government will make award to the responsible offeror with the best valued proposal. There are 16 attachments providing additional requirement details.

View the file

Other files for this federal contract opportunity

Other files attached to Unified User Interface (UUI), newest first.
File Type Posted
00 Solicitation Amendment 47PM0024R0003_0002 2024 02 28.pdf PDF
18 47PM0024R0003 Questions Answers_2024 02 13.pdf PDF
17 GSA Control Tailoring Workbook 2023 07 11.xlsx XLSX spreadsheet
00 Solicitation Amendment 47PM0024R0003_0001 2024 02 13.pdf PDF
Preproposal conference slides and notes 2024 02 06.pdf PDF
07 GSA Data Normalization for Building Automation Systems_v25.pdf PDF
06 GSA Smart Building Implementation Guide_v1_2_1-20220422.pdf PDF
13 Sec L Past Performance_Questionnaire v202312.pdf PDF
14 UUI User Stories Response.xlsx XLSX spreadsheet
15 Sec L Small Business Participation Commitment Document (SBPCD) Template .docx DOCX document
01 RFP CVR Ltr_Preproposal Invitation 2024 01 22.pdf PDF
10 ADM_21811_HSPD_1_PIV_and_Credentialing_and_Background_Investigations_for_Contractors_Posted_Version_3_18_2020.pdf PDF
05 GSA Smart Buildings Program Guide Link location.pdf PDF
08 Technology_Policy_for_PBS-Owned_Buildings_Monitoring_and_Control_Systems.pdf PDF
16 UUI Synopsis Questions and Answers_January 22 2024.pdf PDF
11 NDA UUI.pdf PDF
04 Building_Technologies_Technical_Reference_Guide_(BTTRG)_Final_Ver20_June2021.pdf PDF
02 UUI RFP 47PM0024R0003.pdf PDF
09 Personnel_security_contractor_fitness_fact_sheet.pdf PDF
12 SCL WD 15_4281 2023 12 26.pdf PDF
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Table of Contents

Table of Contents 1 Internal Information Systems - IT Security and Privacy Requirements 2

1.1 Required Policies and Regulations for GSA Contracts 2

1.2 GSA Security Compliance Requirements 4

1.3 Essential Security Controls 4

1.4 Assessment and Authorization (A&A) Activities 10

1.5 Reporting and Continuous Monitoring 13

1.6 GSA Privacy Requirements 17

1.7 Additional Stipulations 18

Mobile Application - IT Security and Privacy Requirements 21

1.1 General Mobile Application Guidelines 21

1.2 Mobile Device Security 21

1.3 Application Sources 22

1.4 Terms of Service (ToS) 23

1.5 GSA Privacy Requirements 23

1.6 GSA App Development, Assessment, Authorization and Deployment 24

1.7 Intellectual Property 26

1.8 Confidentiality and Nondisclosure 26

1.9 GSA Non-Disclosure Agreement 27

1.10 Personnel Security Requirements 28

1.11 Additional Stipulations 28

Appendix A: GSA Tailoring of NIST 800-53 Controls 31

Internal Information Systems - IT Security and Privacy Requirements

1.1 Required Policies and Regulations for GSA Contracts

Federal Laws, Regulations, and Guidance:

The contractor shall comply with all applicable Federal Laws and Regulations.

● 40 U.S.C. 11331, “Responsibilities for Federal Information Systems Standards”

● Cybersecurity & Infrastructure Security Agency (CISA) Cybersecurity Directives - Listing of

Emergency and Binding Operational Directives

● Executive Order (EO) 13556, “Controlled Unclassified Information”

● FISMA of 2014, “The Federal Information Security Modernization Act of 2014”

● HSPD 12, “Homeland Security Presidential Directive 12 – Policy for a Common

Identification Standard for Federal Employees and Contractors”

● OMB Circular A-130, “Managing Information as a Strategic Resource” https://www.gpo.gov/fdsys/pkg/USCODE-2009-title40/pdf/USCODE-2009-title40-subtitleIII-chap113-subchapIII-sec11331.pdf https://www.cisa.gov/directives https://www.federalregister.gov/documents/2010/11/09/2010-28360/controlled-unclassified-information https://www.congress.gov/113/plaws/publ283/PLAW-113publ283.pdf https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A130/a130revised.pdf

● OMB M-10-23, “Guidance for Agency Use of Third-Party Websites and Applications”

● OMB M-14-03, “Enhancing the Security of Federal Information and Information

Systems”

● OMB M-15-13, “Policy to Require Secure Connections across Federal Websites and Web

Services”

● OMB M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable

Information”

● OMB M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6)”

● Privacy Act of 1974, “5 USC, § 552a”

● National Archives and Records Administration (NARA) Controlled Unclassified

Information (CUI) Registry

● OMB Memoranda, location of current fiscal year guidance on Federal Information

Security and Privacy Management Requirements, including FISMA reporting

Federal Standards and Guidance:

The contractor shall comply with all applicable Federal Information Processing Standards (FIPS).

NIST Special Publications (800 Series) are guidance, unless required by a FIPS publication, in which case usage is mandatory.

● FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information Systems”

● FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information Systems”

● FIPS PUB 140-31, “Security Requirements for Cryptographic Modules”

● NIST SP 800-18, Revision 1, “Guide for Developing Security Plans for Federal Information

Systems”

● NIST SP 800-30, Revision 1, “Guide for Conducting Risk Assessments”

● NIST SP 800-34, Revision 1, “Contingency Planning Guide for Federal Information

Systems”

● NIST SP 800-37, Revision 2, “Risk Management Framework for Information Systems and

Organizations: A System Life Cycle Approach for Security and Privacy”

● NIST SP 800-47, Revision 1, “Managing the Security of Information Exchanges”

● NIST SP 800-53, Revision 5, “Security and Privacy Controls for Information Systems and

Organizations”

● NIST SP 800-53A, Revision 5, “Assessing Security and Privacy Controls in Information

Systems and Organizations”

● NIST SP 800-63-3, “Digital Identity Guidelines”

● NIST SP 800-81-2, “Secure Domain Name System (DNS) Deployment Guide”

● NIST SP 800-122, “Guide to Protecting the Confidentiality of Personally Identifiable

Information (PII)”

1 NIST has issued FIPS 140-3 and no longer accepts FIPS 140-2 modules for validation. However, previously validated 140-2 modules will be accepted through September 22, 2026. For additional information see the NIST Cryptographic Module Validation Program website.

https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2010/m10-23.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2014/m-14-03.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2015/m-15-13.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2017/m-17-12_0.pdf https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf https://www.justice.gov/opcl/privacy-act-1974 https://www.archives.gov/cui https://www.archives.gov/cui https://www.whitehouse.gov/omb/information-for-agencies/memoranda https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-47r1.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-3.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-81-2.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-122.pdf https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Validated-Modules/Search

● NIST SP 800-137, “Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations”

● NIST SP 800-161, Revision 1, “Supply Chain Risk Management Practices for Federal Information Systems and Organizations”

GSA Policies:

The contractor shall comply with the following GSA Directives/Policies.

● GSA Order CIO 1878.3, “Developing and Maintaining Privacy Threshold Assessments, Privacy Impact Assessments, Privacy Act Notices, and System of Records Notices”

● GSA Order CIO 2100.1, “GSA Information Technology (IT) Security Policy”

● GSA Order ADM 2181.1, “Homeland Security Presidential Directive-12 Personal Identity

Verification and Credentialing Policy, and Background Investigations for Contractor Employees”

● GSA Order CIO 2183.1, “Enterprise Identity, Credential, and Access Management (ICAM) Policy”

● GSA Order CIO 2200.1, “GSA Privacy Act Program”

● GSA Order CIO 9297.2, “GSA Information Breach Notification Policy”

The contractor shall comply with the following GSA policies listed below when inside a GSA building or inside a GSA firewall.

● GSA Order ADM 9732.1, “Personnel Security and Suitability Program Handbook”

The GSA policies listed in this paragraph must be followed, if applicable.

● GSA Order CIO 2103.2, “Controlled Unclassified Information (CUI) Policy”

● GSA Order CIO 2104.1, “GSA Information Technology (IT) General Rules of Behavior”

GSA Procedural Guides:

GSA IT Procedural Guides are guidance, unless required by a GSA Directive/Policy, in which case usage is mandatory.

Note: GSA’s Procedural Guides are updated frequently; to make sure you have the most recent version of publicly available procedural guides, visit GSA.gov. If a non-publicly available guide is needed, contact the contracting officer who will coordinate with the GSA Office of the Chief Information Security Officer to determine if it can be made available.

1.2 GSA Security Compliance Requirements

FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information Systems,” is a mandatory federal standard that defines the minimum security requirements for federal information and information systems in seventeen security-related areas. Information systems supporting GSA must meet the minimum security and privacy requirements through the use of the security controls in accordance with NIST Special Publication 800-53, Revision 5 (hereafter described as NIST 800-53), “Security and Privacy Controls for Information Systems and Organizations.”

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-137.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/about-us/organization/office-of-the-chief-information-officer/chief-information-security-officer-ciso/it-security-procedural-guides

To comply with the federal standard, GSA must determine the security category of the information and information system in accordance with FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information Systems,” and then the contractor shall apply the appropriately tailored set of Low, Moderate, or High impact baseline security controls in NIST 800-53, as determined by GSA. NIST 800-53 controls requiring organization-defined parameters (i.e., password settings) shall be consistent with GSA specifications. The GSA-specified control parameters and supplemental guidance defining more specifically the requirements per FIPS PUB 199 impact level are available in the GSA Control Tailoring Workbook referenced in Appendix A of this document.

The Contractor shall use GSA technical guidelines, NIST guidelines, Center for Internet Security (CIS) guidelines (Level 1), or industry best practice guidelines in hardening their systems. Where a GSA security hardening benchmark exists, it must be used. GSA security hardening benchmarks may be exceeded but not lowered. GSA benchmarks are available on the GSA Intranet and will be provided by GSA upon request.

1.3 Essential Security Controls

All NIST 800-53 controls must be implemented as per the applicable FIPS PUB 199 Low (L), Moderate (M), or High (H) baseline. Controls in the Privacy baseline are applicable if PII data is being collected, stored, or transmitted. The following table identifies essential security controls from the respective baselines to highlight their importance; ensure they are implemented; and identify integration requirements with GSA’s IT and IT Security environment. Systems shall have these essential security controls implemented. Further, the proposed system and security architecture of the information system shall be reviewed and approved by the Security Engineering Division, in the Office of the Chief Information Security Officer before commencement of system build (architecture, infrastructure, and code).

Control ID Control Title

GSA

Baseline GSA Implementation Guidance

AC-2

Account Management

L, M, H

Account management systems must leverage or integrate with existing GSA account management solutions or processes, as applicable and defined in the GSA IT ICAM Roadmap (see GSA Order CIO 2183.1, “Enterprise Identity, Credential, and Access Management (ICAM) Policy.”

AC-17 (3)

Remote Access | Managed Access Control Points

M, H

All remote accesses to the internal information system must be routed through GSA’s managed network access control points, subjecting them to security monitoring.

Control ID Control Title

GSA

Baseline GSA Implementation Guidance

AU-2 Event Logging L, M, H

Information systems shall implement audit configuration requirements as documented in applicable GSA IT Security Technical Hardening Guides (i.e., hardening and technology implementation guides); for web applications see GSA IT Security Procedural Guide 07-35, Section 2.8.10, What to Log.

For technologies where a Technical Guide and Standard does not exist, events from an industry source such as vendor guidance or Center for Internet Security (CIS) benchmark, recommended by the GSA S/SO or Contractor to be approved by the GSA AO shall be used.

Internal Information systems shall send all logs listed in CIO-IT Security-01-08: Auditing and Accountability (AU) to GSA’s central Enterprise Logging Platform (ELP) to support information system monitoring. possible. System audit logs not able to be transmitted to the ELP, system owners must coordinate with the ISSO to ensure AU-2 requirements are met.

AU-6 (1)

Audit Record Review, Analysis, and Reporting | Automated Process Integration

M, H

Internal systems must integrate with GSA’s Security Stack as specified in GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk, which supports review of audit log events via GSA’s Enterprise Logging Platform (ELP). Audit logs not able to be transmitted to the ELP and logs for web applications, databases, and other tools when PII is in scope must be reviewed by the system team.

CM-6

Configuration Settings

L, M, H

Information systems shall implement GSA benchmarks for system hardening. GSA benchmarks may be exceeded but not lowered. Where a GSA benchmark does NOT exist, GSA technical guidelines, NIST guidelines, Center for Internet Security guidelines (Level 1), or industry best practice guidelines, as reviewed and accepted by the GSA AO.

Further, all workstations and servers connected to the GSA network shall have BigFix agents installed and operating as expected.

CM-7 Least Functionality L, M, H

Internal systems must integrate with GSA’s Security Stack as specified in GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk, which supports least functionality via GSA’s implementation of CarbonBlack.

Baseline GSA Implementation Guidance

CP-7

Alternative Processing Site

M, H

FIPS PUB 199 Moderate and High impact systems must implement processing across geographically disparate locations to ensure fault tolerance. Cloud Infrastructure as a Service (IaaS) architectures shall implement a multi-region strategy (multiple availability zones in a single region are not sufficient).

CP-8

Telecommunications Services

M, H

FIPS PUB 199 Moderate and High impact information systems must implement alternate telecom services to support resumption when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.

IA-2 (1)

Identification and Authentication (Organizational Users) | Multifactor Authentication to Privileged Accounts

L, M, H

All information systems shall implement multi-factor authentication for privileged accounts.

Information systems shall technically integrate with a GSA privileged access and authentication solution, as applicable and defined in the GSA IT ICAM Roadmap (see GSA Order CIO 2183.1, “Enterprise Identity, Credential, and Access Management (ICAM) Policy”).

IA-2 (2)

Identification and Authentication (Organizational Users) | Multifactor Authentication to Non-Privileged Accounts

L, M, H

All information systems must implement multi-factor authentication for non-privileged accounts.

Information systems shall technically integrate with a GSA supported enterprise authentication solution (e.g., support SAML 2.0 or OIDC with an GSA enterprise SSO solution), , as applicable and defined in the GSA IT ICAM Roadmap (GSA Order CIO 2183.1, “Enterprise Identity, Credential, and Access Management (ICAM) Policy”).

IA-7

Cryptographic Module Authentication

L, M, H

The information system shall implement authentication to FIPS PUB 140-3/140-2 compliant encryption modules as specified in the respective standards. Reference:

Cryptographic Module Validation Program Validated Modules

MP-4 Media Storage M, H

Digital media including magnetic tapes, external/removable hard drives, flash/thumb drives, diskettes, compact disks, and digital video disks shall be encrypted using a FIPS PUB 140-3/140-2 validated encryption module.

MP-5 Media Transport M, H

Digital media including magnetic tapes, external/removable hard drives, flash/thumb drives and digital video disks shall be encrypted using a FIPS PUB 140-3/140-2 validated encryption module during transport outside of controlled areas.

https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://www.gsa.gov/directives-library/ https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Validated-Modules

Baseline GSA Implementation Guidance

PL-8

Security and Privacy Architectures

L, M, H

All information system security architectures must be formally reviewed and approved by the Office of the Chief Information Security Officer, Security Engineering Division during the system develop/design stages of the SDLC and prior to Security Assessment and Authorization.

RA-5

Vulnerability Monitoring and Scanning

L, M, H

All systems must integrate with the GSA vulnerability scanning tool set managed by the Security Operations Division in the Office of the Chief Information Security Officer. Information systems shall coordinate integration with the scanning program by contacting SecOps@gsa.gov.

RA-8

Privacy Impact Assessments

L, M, H RA-8 is included in all FIPS 199 Baselines to ensure all systems complete a Privacy Threshold Assessment (PTA) to determine if a Privacy Impact Assessment (PIA) is required.

SA-22

Unsupported System Components

L, M, H

All systems must be comprised of software and hardware components that are fully supported in terms of security patching for the anticipated life of the system; software must be on GSA’s Enterprise Architecture IT Standards List.

SC-8

SC-8(1)

Transmission Confidentiality and Integrity

Transmission Confidentiality and Integrity | Cryptographic Protection

M, H

L, M, H

Implemented encryption algorithms and cryptographic modules shall be FIPS-approved and FIPS PUB 140-3/140-2 validated, respectively.

o Digital signature encryption algorithms o Block cypher encryption algorithms o Secure hashing algorithms

For web services connections, implement end to end encryption terminating the connection at the web server;

connections terminated at a load balancer, Firewall, and/or WAF shall employ re-encryption techniques to ensure end to end encryption.

ALL associated URLs must have their second-level domain HTTP Strict Transport Security (HSTS) preloaded and have no weak ciphers, have no weak protocols, and preload .gov domains. (see Binding Operational Directive (BOD) 18-01, Enhance Email and Web Security).

SSL/TLS implementations shall align with GSA IT Security Procedural Guide 14-69: SSL/TLS Implementation.

SC-13

Cryptographic Protection

L, M, H

Implemented encryption algorithms and cryptographic modules shall be FIPS-approved and FIPS PUB 140-3/140-2 validated, respectively.

o Digital signature encryption algorithms o Block cypher encryption algorithms o Secure hashing algorithms mailto:SecOps@gsa.gov https://csrc.nist.gov/Projects/cryptographic-algorithm-validation-program/digital-signatures https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Block-Ciphers https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Secure-Hashing https://cyber.dhs.gov/bod/18-01/ https://csrc.nist.gov/Projects/cryptographic-algorithm-validation-program/digital-signatures https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Block-Ciphers https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Secure-Hashing

Baseline GSA Implementation Guidance

SC-17

Public Key Infrastructure Certificates

M, H

Implement appropriate creation, use, and signing of crypto certs in agreement with GSA IT Security Procedural Guide 14-69: SSL/TLS Implementation, and NIST Special Publications 800-52, Revision 2 and 1800-16.

SC-18 Mobile Code M, H

Systems must adhere to GSA's requirements regarding IT Standards and CIO-IT Security-07-35: Web Application Security and CIO-IT Security-17-81: Web Browser Technologies Hardening, as applicable, to ensure only approved code (including mobile code) is used.

SC-22

Architecture and Provisioning for Name / Address Resolution Service

L, M, H

Information systems shall be Domain Name System Security Extensions (DNSSEC) compliant. Reference NIST SP 800-81-2, which provides deployment guidelines for securing DNS within an enterprise

SC-28 (1)

Protection of Information at Rest | Cryptographic Protection

L, M, H

**Systems that process Personally Identifiable Information (PII), Payment Card Industry (PCI) data, Authenticators (e.g., passwords, tokens, keys, certificates, hashes, etc.), and other sensitive data as determined by the AO, shall encrypt that data everywhere (i.e., at file level, database level, at rest, and in transit). For databases, encryption of the whole database, table, column, or field levels is acceptable, as appropriate.

Other methods including, but not limited to, application encryption or tokenization are also acceptable.

For web services connections, implement end to end encryption terminating the connection at the web server;

connections terminated at a load balancer shall employ re-encryption techniques to ensure end to end encryption.

**Federal Policy requires implementation of FIPS PUB 140-3/140-2 validated encryption modules and FIPS-approved ciphers suites. Encryption of GSA sensitive data (e.g., PII, PCI, Authenticators, other business sensitive data) at rest and in transit shall be with FIPS validated encryption modules wherever possible; exceptions require Acceptance of Risk (AOR) to be signed by the GSA CISO and AO.

Baseline GSA Implementation Guidance

SI-2 Flaw Remediation L, M, H

All projects and systems must be adequately tested for flaws;

all Critical, High, and Moderate risk findings must be remediated prior to go-live. Post go-live vulnerability remediation timelines are as follows:

● BOD Timelines:

o Within 14 days for vulnerabilities added to the Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog with a CVE date post FY21.

o Per the CISA KEV catalog date or GSA Standard timelines below, whichever is earlier, for vulnerabilities in the CISA KEV catalog with a CVE date in FY21 or earlier.

o Within 15 days for Critical (Very High) vulnerabilities for Internet-accessible systems or services.

● GSA Standard Timelines:

o Within 30 days for Critical (Very High) and High vulnerabilities o Within 90 days for Moderate vulnerabilities o Within 120 days for Low vulnerabilities for

Internet-accessible systems/services

SI-3

Malicious Code Protection

L, M, H All internal information systems must incorporate CarbonBlack and FireEye HX agents on supported operating systems. These agents will be provided.

SI-4 System Monitoring L, M, H

All information systems must be monitored internally and across ingress/egress points for potentially malicious activity.

In addition, all internal information systems must incorporate CarbonBlack and FireEye HX agents on supported operating systems. These agents will be provided.

SI-10

Information Input Validation

M, H

All systems accepting input from end users must validate the input in accordance with industry best practices and published guidelines, including GSA IT Security Procedural Guide 07-35, “Web Application Security,” and OWASP Top 10 Web Application Security Vulnerabilities.

SR-2

Supply Chain Risk Management Plan

L, M, H Tier 3 (Information System) plans for each system should be developed consistent with the template in Appendix E of NIST

SP 800-161.

SR-6

Supplier Assessment and Reviews

M, H

PM-21

Accounting of Disclosures

See note below

Requires accounting of disclosures of PII.

Baseline GSA Implementation Guidance

PM-25

Minimization of Personally Identifiable Information Used in Testing, Training, and Research

See note below

Requires implementation of policies and procedures to minimize PII used in testing, training, and research.

PT-5 Privacy Notice See note below

Privacy notices help inform individuals about how their personally identifiable information is being processed by the system or organization

PT-5 (2)

Privacy Notice | Privacy Act Statements

See note below

Include Privacy Act statements on forms that collect information that will be maintained in a Privacy Act system of records or provide Privacy Act statements on separate forms that can be retained by individuals.

PT-6

System of Records Notice

See note below

Federal agencies must publish a system of records notice in the Federal Register upon the establishment and/or modification of a Privacy Act system of record

PT-7 (1)

Specific Categories of Personally Identifiable Information | Social Security Numbers

See note below

Federal law and policy establish specific requirements for organizations’ processing of Social Security numbers;

organizations take steps to eliminate unnecessary uses of Social Security numbers and other sensitive information and observe any particular requirements that apply.

SI-12 (1)

Information Management and Retention | Limit Personally Identifiable Information Elements

See note below

Limit personally identifiable information being processed in the information life cycle to specified elements.

Note: Privacy controls are not associated with a FIPS PUB 199 baseline. Controls are applicable if PII data is being collected, stored, or transmitted.

1.4 Assessment and Authorization (A&A) Activities

The implementation of a new Federal Government IT system requires a formal approval process known as Assessment and Authorization (A&A). NIST Special Publication 800-37, Revision 2 (hereafter described as NIST 800-37) and GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk provide guidelines for performing the A&A process. The system/application must have a valid assessment and authorization, known as an Authorization to Operate (ATO) (signed by the Federal government) before going into operation and processing GSA information. The failure to obtain and maintain a valid ATO will result in the termination of the contract. The system must have a new A&A conducted (signed by the Federal government) when significant changes are made to the system, and as specified in GSA IT

Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk, and the guides for GSA’s other A&A processes referenced therein.

Assessing the System

1. The Contractor shall comply with Assessment and Authorization (A&A) requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement. The Level of Effort for the A&A is based on the System’s NIST Federal Information Processing Standard (FIPS) Publication 199 categorization. Documents that contain CUI must be marked, handled, and transmitted as described in Additional Stipulations. The contractor shall create, maintain, and update the following A&A documentation:

● System Security and Privacy Plan (SSPP) completed in agreement with NIST Special Publication 800-18, Revision 1, “Guide for Developing Security Plans for Federal Information Systems,” and completed in accordance with GSA SSPP requirements and templates. The SSPP shall include as appendices required policies and procedures across 19 control families mandated per FIPS PUB 200, Rules of Behavior, and Interconnection Security Agreements (in agreement with NIST Special Publication 800-47, “Managing the Security of Information Exchanges”). The SSPP shall include; as an appendix, a completed GSA Control Tailoring Workbook (CTW) identified in Appendix A of this guide. The column in the CTW titled “Vendor/Contractor Defined Values” shall be used to document all contractor implemented parameter settings that differ from the GSA Defined Value and the Vendor/Contractor defined value when the value is deferred to the Vendor/Contractor. GSA’s approval will be documented in the CTW column titled “GSA Approval of Vendor/Contractor Defined Values.”

Note: A description of how the system will transition to IPv6, as required by OMB M-21-07, must be included as part of the system’s SSPP.

● Contingency Plan completed in agreement with NIST Special Publication 800-34 and GSA IT Security Procedural Guide 06-29: Contingency Planning.

● Business Impact Analysis completed in agreement with NIST Special Publication 800-34 and GSA IT Security Procedural Guide 06-29: Contingency Planning.

● Contingency Plan Test Report completed in agreement with GSA IT Security Procedural Guide 06-29: Contingency Planning.

● Incident Response Plan completed in agreement with NIST Special Publication 800-61, “Computer Security Incident Handling Guide” and GSA IT Security Procedural Guide 01-02: Incident Response.

● Incident Response Test Report completed in agreement with NIST Special Publication 800-61, “Computer Security Incident Handling Guide” and GSA IT Security Procedural Guide 01-02: Incident Response.

● Configuration Management Plan completed in agreement with GSA IT Security Procedural Guide 01-05: Configuration Management.

● Plan of Action & Milestones completed in agreement with GSA IT Security Procedural Guide 09-44: Plan of Action and Milestones (POA&M).

● Penetration Test Reports documenting the results of vulnerability analysis and exploitability of identified vulnerabilities. Note: Penetration testing is required for all Internet accessible, all FIPS 199 High, and all High Value Asset (HVA) information systems. These systems are required to complete an independent penetration test and provide an Independent Penetration Test Report documenting the results of the exercise as part of the A&A package. Reference GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk and GSA IT Security Procedural Guide 11-51: Conducting Penetration Test Exercises for penetration testing guidance.

2. Information systems must be assessed and authorized every three (3) years or whenever there is a significant change to the system’s security posture in accordance with NIST Special Publication 800-37 Revision 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” and GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk or via continuous monitoring based on GSA IT Security Procedural Guide 12-66: Information Security Continuous Monitoring (ISCM) Strategy & Ongoing Authorization (OA) Program that is reviewed and accepted by the GSA CISO.

3. At the Moderate impact level and higher, the Government is responsible for providing an independent Security Assessment/Risk Assessment in accordance with GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk.

4. If the Government is responsible for providing a Security Assessment/Risk Assessment and Penetration Test, the Contractor shall allow GSA employees (or GSA designated third party contractors) to conduct A&A activities to include control reviews in accordance with NIST 800-53/NIST 800-53A and GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk. Review activities include but are not limited to operating system vulnerability scanning, web application scanning, and database scanning of applicable systems that support the processing, transportation, storage, or security of GSA information. This includes the general support system infrastructure.

5. Identified gaps between required NIST 800-53 controls and the contractor’s implementation as documented in the Security Assessment/Risk Assessment report shall be tracked for mitigation in a Plan of Action and Milestones (POA&M) document completed in accordance with GSA IT Security Procedural Guide 09-44: Plan of Action and Milestones (POA&M). Depending on the severity of the gaps, the Government may require them to be remediated before an Authorization to Operate is issued.

6. The Contractor is responsible for mitigating all security risks found during the A&A and continuous monitoring activities. Vulnerabilities must be mitigated as follows:

(1) BOD Timelines:

(a) Within 14 days for vulnerabilities added to CISA’s KEV Catalog with a CVE date post FY21.

(b) Per the CISA KEV catalog date or GSA Standard timelines below, whichever is earlier, for vulnerabilities in the CISA KEV catalog with a CVE date in FY21 or earlier.

(c) Within 15 days for Critical (Very High) vulnerabilities for Internet-accessible systems or services.

(2) GSA Standard Timelines

(a) Within 30 days for Critical (Very High) and High vulnerabilities.

(b) Within 90 days for Moderate vulnerabilities.

(c) Within 120 days for Low vulnerabilities for Internet-accessible systems/services.

7. The Government will determine the risk rating of vulnerabilities.

8. The Contractor shall comply with all actions specified in DHS Cybersecurity Directives as specified in Additional Stipulations.

Authorization of the System

1. Upon receipt of the documentation (A&A Package) described in GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk. and NIST Special Publication 800-37 as documented above, the GSA Authorizing Official (AO) for the system (in coordination with the GSA Chief Information Security Officer (CISO), System Owner, Information System Security Manager (ISSM), and Information System Security Officer (ISSO) will render an authorization decision to:

● Authorize system operation w/out any restrictions or limitations on its operation;

● Authorize system operation w/ restriction or limitation on its operation, or

● Not authorize system operation.

2. The System Owner, AO, and supporting stakeholders including but not limited to System Custodians, supporting contractors, etc., shall make appropriate personnel available for interviews and provide documentation to the Federal Government, or their designee acting as their agent, in order to verify compliance with the requirements of GSA’s Information Technology security program.

1.5 Reporting and Continuous Monitoring

Maintenance of the security authorization to operate will be through continuous monitoring of security controls of the contractor’s system and its environment of operation to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to GSA per the schedules below. The submitted deliverables (or lack thereof) provide a current understanding of the security state and risk posture of the information systems. They allow GSA AOs to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur.

https://www.cisa.gov/directives

Deliverables to be provided Quarterly to the GSA ISSO, ISSM, and/or COR.

1. Plan of Action & Milestones (POA&M) Update (Due NLT the 1st day of the third month of each quarter) Reference: NIST 800-53 control CA-5 Provide POA&M updates in accordance with requirements and the schedule set forth in GSA CIO IT Security Procedural Guide 09-44: Plan of Action and Milestones (POA&M).

2. FISMA Quarterly Metrics data, as necessary (i.e., when a FISMA quarterly data call is issued that is applicable to the system). (Due per data call request deadline)

Deliverables to be provided Annually (or when there is a major change) to the GSA ISSO, ISSM, and/or COR (Due dates for annual deliverables are designated per deliverable in the following lists.)

Annual Deliverables due NLT February 25th.

1. Annual FISMA Self-Assessment Reference: NIST 800-53 control CA-2 Deliver the results of the annual FISMA self-assessment conducted per GSA IT Security Procedural Guide 04-26: Federal Information Security Modernization Act (FISMA) Implementation. Based on the controls selected for self-assessment, the GSA OCISO will provide the appropriate test cases for completion.

2. Updated A&A documentation including the SSPP, Contingency Plan, and Business Impact Analysis

a. SSPP Reference: NIST 800-53 control PL-2 Review and update the SSPP annually to ensure the plan is current and accurately describes implemented system controls and reflects changes to the contractor system and its environment of operation. The SSPP must be in accordance with NIST 800-18, Revision 1, “Guide for Developing Security Plans for Federal Information Systems.”

b. Contingency Plan Reference: NIST 800-53 control CP-2 Provide an annual update to the contingency plan completed in accordance with NIST 800-34, “Contingency Planning Guide for Federal Information Systems” and GSA IT Security Procedural Guide 06-29: Contingency Planning.

c. Business Impact Analysis Reference: NIST 800-53 control CP-2 Provide an annual update to the business impact analysis completed in accordance with NIST 800-34, “Contingency Planning Guide for Federal Information Systems”, and GSA IT Security Procedural Guide 06-29: Contingency Planning.

3. Contingency Plan Test Report Reference: NIST 800-53 control CP-4

Provide a contingency plan test report completed in accordance with GSA IT Security Procedural Guide 06-29: Contingency Planning. A continuity test shall be conducted annually prior to mid-July of each year. The continuity test can be a tabletop test while the system is at the FIPS PUB 199 Low Impact level. The tabletop test must include Federal and hosting Contractor representatives. Functional exercises must be completed once every three years for FIPS PUB 199 Moderate impact systems and annually for FIPS PUB 199 High impact systems.

4. Incident Response Test Report Reference: NIST 800-53 control IR-3 Provide an incident response plan test report documenting results of incident reporting process per GSA IT Security Procedural Guide 01-02, Incident Response.

5. User Certification/Authorization Review Documents Reference: NIST 800-53 control AC-2 Provide the results of the annual review and validation of system users’ accounts to ensure the continued need for system access. The user certification and authorization documents will illustrate the organization establishes, activates, modifies, reviews, disables, and removes information system accounts in accordance with documented account management procedures.

6. Separation of Duties Document/Matrix Reference: NIST 800-53 control AC-5 Develop and furnish a separation of duties matrix reflecting proper segregation of duties for IT system maintenance, management, and development processes. The separation of duties matrix will be updated or reviewed on an annual basis.

Annual Deliverables due NLT June 25th.

7. Penetration Testing Report Reference: NIST 800-53 control CA-8 All Internet accessible systems, and all FIPS PUB 199 High impact systems are required to complete an independent penetration test and provide a Penetration Test Report documenting the results of the exercise as part of their A&A package. Annual penetration tests are required for these same systems in accordance with GSA Order CIO

2100.1 and CIO-IT Security-11-51: Conducting Penetration Test Exercises.

8. Information Exchanges (if applicable) Reference: NIST 800-53 control CA-3 Provide Interconnection Security Agreements (ISA), Information Exchange Agreements and any supporting Memoranda of Agreement/Understanding (MOA/U), completed in accordance with NIST 800-47, “Managing the Security of Information Exchanges,” for existing and new interconnections. Per NIST 800-47, an interconnection is the direct connection of two or more IT systems for the purpose of sharing data and other information resources through a pipe, such as ISDN, T1, T3, DS3, VPN, etc. ISAs shall be submitted as appendices as part of the annual SSPP submission. ISAs shall include, if applicable, any changes since the last submission; updated ISAs are required at least every three years.

9. Configuration Management Plan Reference: NIST 800-53 control CM-9 Provide an annual update to the Configuration Management Plan for the information system.

10. Incident Response Plan Reference: NIST 800-53 control IR-8 Provide an annual update to the Incident Response Plan for the information system.

11. Personnel Screening and Security Reference: NIST 800-53 control PS-3, NIST 800-53 control PS-7 Furnish documentation reflecting favorable adjudication of background investigations for all personnel (including subcontractors) supporting the system. Contractors shall comply with GSA Order CIO 2100.1, “GSA Information Technology (IT) Security Policy” and GSA Order ADM 2181.1, “Homeland Security Presidential Directive-12, Personal Identity Verification and Credentialing, and Background Investigations for Contractors.”

GSA separates the risk levels for personnel working on Federal computer systems as follows:

● A favorable initial fitness/suitability determination must be granted, and a Tier 1 or higher background investigation initiated before access to the GSA network or any GSA IT system. There shall be no waivers to this requirement for GSA network and IT system access for GSA employees or contractors.

● A favorable initial fitness/suitability determination must be granted, and a Tier 2 or higher background investigation initiated before access to PII/CUI is granted.

The authority and access shall be determined by the appropriate GSA Supervisor (for GSA employees) or CO (for contract personnel), Data Owner, and the System's AO. Each System's AO, with the request of the GSA Supervisor, Data Owner, or CO, shall evaluate the risks associated with each such request.

● A favorable suitability determination must be completed at a Tier 2 or higher background investigation before privileged access to the GSA network or IT systems is granted. A waiver may be requested in order to maintain GSA business operations; however, such requests should be used judiciously and not incur unnecessary risks to GSA.

If final adjudication of a background investigation is unfavorable, GSA network and IT system access must be revoked, and any GFE, including the GSA PIV card must be retrieved and returned to OMA.

12. Supply Chain Risk Management Plan Reference: NIST 800-53 control SR-2 Systems must have their own system specific SCRM Plans that detail response activities and reporting requirements to GSA consistent with NIST SP 800-161.

Annual Deliverable due NLT August 30th.

13. HVA Data Call (if applicable) Reference: CISA HVA Program Management Office Respond to the annual HVA data call, if applicable (i.e., when an HVA Data call is issued that is applicable to the vendor/contractor system).

1.6 GSA Privacy Requirements

Personally identifiable information (PII) is not in the scope of the acquisition and PII is not expected to be stored, processed, or transmitted in the vendor's information system. The collection, maintenance, or dissemination of any PII that is subject to the Privacy Act and/or the E-Government Act will be handled in full accordance with all GSA rules of conduct and in accordance with GSA Privacy Program requirements.

The contractor shall work with GSA to prepare a Privacy Threshold Assessment (PTA) to confirm and document PII is not in scope, or to determine which categories of information will be stored, processed, or transmitted by the system. The PTA must be completed before development begins and whenever a change with a privacy impact (e.g., a new category of information is collected) is made to an existing system. PTAs are required as part of GSA’s process to determine whether a Privacy Impact Assessment (PIA) and/or a System of Records Notice (SORN) is required, and if any other privacy requirements apply to the information system. Information regarding PIAs can be found in GSA Order CIO 1878.3.

PII (should it come into scope) will require the following guidelines be adhered to.

● The vendor’s information system must be authorized at least at the FIPS PUB 199 Moderate level.

● For any system that collects, maintains, or disseminates PII, a PIA must be completed by the contractor and provided to the GSA Privacy Office for review along with the other authorization to operate (ATO) documents.

● If the system retrieves information using PII, the Privacy Act applies and it must have a system of records notice (SORN) published in the Federal Register.

● If PII is collected from individuals by the system, a Privacy Act Statement (i.e., Privacy Notice) must be provided to users prior to their use of the application on what data is being collected and why, as well as the authority for the collection and the impact of not providing some or all of it. The Privacy Act Statement must be available to the individual directly on the form used to collect the information. Providing a link back to the Statement from the form is acceptable.

Per OMB A-130 Privacy Act Statements must include:

(1) the authority (whether granted by statute or executive order) that authorizes the solicitation of the information and whether disclosure of such information is mandatory or voluntary;

(2) the principal purpose(s) for which the information is intended to be used;

https://www.gsa.gov/reference/gsa-privacy-program/rules-and-policies-protecting-pii-privacy-act https://www.gsa.gov/reference/gsa-privacy-program/privacy-impact-assessments-pia https://www.gsa.gov/reference/gsa-privacy-program/systems-of-records-privacy-act https://www.gsa.gov/reference/gsa-privacy-program/systems-of-records-privacy-act

(3) the published routine uses to which the information is subject;

(4) the effects on the individual, if any, of not providing all or any part of the requested information; and

(5) an appropriate citation (and, if practicable, a link) to the relevant SORN(s).

An example Privacy Act Statement is available at GSA’s Privacy Act Statement for Design Research.

Note: Systems that access data a user creates must assume a user may include privacy data/PII in the system unless the data creation is restricted to data controlled by the system.

All contractor staff who have significant privacy information responsibilities must complete GSA’s mandatory privacy awareness and role-based training courses. This includes contractors who work with PII as part of their work duties (e.g., Human Resource staff, Finance staff, and managers/supervisors).

1.7 Additional Stipulations

1. Security documentation will be marked as follows:

a. PTAs, and PIAs will not be marked.

b. CP, BIA, and CP Test Reports will be marked CUI//EMGT.

c. All other security documentation will be marked CUI//ISVI.

d. Documents will be marked in bold text on the top of all pages. Spelling out of acronyms is not required.

e. The cover page of each CUI document must contain the following statement on the lower left of the page.

Controlled by: General Services Administration OCISO ISP Division: ispcompliance@gsa.gov.

f. External transmission/dissemination of CUI to or from a Government system must be encrypted. A FIPS PUB 140-3/140-2 validated encryption module must be used to encrypt the CUI data.

2. The Contractor shall certify applications are fully functional and operate correctly as intended on systems using benchmarks from GSA technical guidelines, NIST guidelines, Center for Internet Security guidelines, or industry best practice guidelines, as reviewed and accepted by the GSA AO. The standard installation, operation, maintenance, update, and/or patching of software shall not alter the configuration settings from the approved benchmark configuration. Information technology for Windows systems should use the Windows Installer Service for installation to the default “program files” directory and should be able to silently install and uninstall. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges. The contractor shall use tools to verify their products operate correctly with the approved benchmark configurations and do not alter the benchmark settings.

https://www.gsa.gov/reference/gsa-privacy-program/privacy-act-statement-for-design-research

4. The Contractor shall cooperate in good faith in defining non-disclosure agreements (NDAs) that other third parties must sign when acting as the Federal government’s agent.

Note: GSA’s Office of the General Counsel (OGC) is available to coordinate on defining NDA requirements. Upon request, GSA OGC can advise on NDA development.

5. The Government has the right to perform manual or automated audits, scans, reviews, or other inspections of the IT environment being used to provide or facilitate services for the Government. The Contractor shall be responsible for the following privacy and security safeguards:

a. The Contractor shall not publish or disclose in any manner, without the Contracting Officer’s written consent, the details of any safeguards either designed or developed by the Contractor under this contract or otherwise provided by the Government. Exception - Disclosure to a Consumer Agency for purposes of A&A verification or to the MAX.Gov portal. To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor shall afford the Government access to facilities, installations, technical capabilities, operations, documentation, records, and databases used to provide or facilitate services for the Government within 72 hours of the request. Access to support incident investigations, shall be provided as soon as possible but not longer than 72 hours after request.

The program of inspection shall include, but is not limited to:

● Authenticated and unauthenticated operating system/network…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .