RFQ STRATUS Pool 2 Attch B Security Requirements_Amd 001.pdf

PDF 833 KB Posted

Attached to
USDA STRATUS Cloud Basic Ordering Agreement (BOA) Pool 2: Integration and Development Support Services On-Ramp Federal contract opportunity
Solicitation number
12314425Q0065
Issued by
Department of Agriculture Assistant Secretary for Departmental Management

About this file

This document is Attachment B to a Request for Quote (RFQ) for the USDA STRATUS Cloud Basic Ordering Agreement (BOA), specifically detailing security requirements for Pool 2: Integration and Development Support Services. The security requirements outline comprehensive protocols for cloud service providers, including compliance with Federal Risk Authorization Management Program (FedRAMP), National Institute of Standards and Technology (NIST) standards, and USDA-specific cloud computing regulations. Key requirements include maintaining continuous security monitoring, protecting controlled unclassified information, implementing fortified security measures, and obtaining and maintaining a valid Authority to Operate (ATO) from USDA.

The document specifies responsibilities for multiple entities, including authorized assessment and evaluation entities (such as CISA, GAO, NSA), USDA ordering entities, and authorized vendors. Vendors must comply with stringent security controls, including rapid remediation of security findings (15 days for critical issues, 30 days for others), maintaining FedRAMP and Department of Defense Cloud Authorization Services (DCAS) authorizations, and timely reporting of cybersecurity incidents. The security requirements are designed to protect information systems from recurring security threats and ensure robust cyber defenses across system levels, from root infrastructure to application and data layers.

View the file

Other files for this federal contract opportunity

Other files attached to USDA STRATUS Cloud Basic Ordering Agreement (BOA) Pool 2: Integration and Development Support Services On-Ramp, newest first.
File Type Posted
1. Instructions RFQ 12314425Q0065 STRATUS Pool 2 On-Ramp_Amd 002.pdf PDF
1. Instructions RFQ 12314425Q0065 STRATUS Pool 2 On-Ramp_Amd 002.pdf PDF
Contracting Officer Updates RFQ12314425Q0065 07.21.25.pdf PDF
STRATUS Pool 2 BOA Holders 07.11.25.xlsx XLSX spreadsheet
RFQ STRATUS Pool 2 Attch E Questions and Answers_Amd 001.xlsx XLSX spreadsheet
Contracting Officer Updates RFQ12314425Q0065 07.11.25.pdf PDF
RFQ STRATUS Pool 2 Attch D Provisions and Clauses_Amd 001.pdf PDF
RFQ STRATUS Pool 2 Attch G Prior Experience Cover Sheet_Amd 001.docx DOCX document
1. Instructions RFQ 12314425Q0065 STRATUS Pool 2 On-Ramp_Amd 001.pdf PDF
Contracting Officer Updates RFQ12314425Q0065 07.09.25.pdf PDF
Contracting Officer Updates RFQ12314425Q0065.pdf PDF
RFQ STRATUS Pool 2 Attch A SOO.pdf PDF
RFQ STRATUS Pool 2 Attch C Billing_Automation_Data Reporting.pdf PDF
RFQ STRATUS Pool 2 - Cover Letter.pdf PDF
RFQ STRATUS Pool 2 Attch I Projected Task Order Opportunities.xlsx XLSX spreadsheet
RFQ STRATUS Pool 2 Attch D Provisions and Clauses.pdf PDF
RFQ STRATUS Pool 2 Attch G Prior Experience Cover Sheet.docx DOCX document
1. Instructions RFQ 12314425Q0065 STRATUS Pool 2 On-Ramp.pdf PDF
RFQ STRATUS Pool 2 Attch F Labor Categories.pdf PDF
RFQ STRATUS Pool 2 Attch B Security Requirements.pdf PDF
RFQ STRATUS Pool 2 Attch E Questions and Answers Template.xlsx XLSX spreadsheet
RFQ STRATUS Pool 2 Attch H Invoice Format.xlsx XLSX spreadsheet
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOLICITATION NO. 12314425Q0065

STRATUS CLOUD BASIC ORDERING AGREEMENT

POOL 2: INTEGRATION AND DEVELOPMENT SUPPORT SERVICES

ATTACHMENT B

SECURITY REQUIREMENTS

Attachment B: Security Requirements – RFQ 12314425Q0065 Page 2 of 6

Attachment B: Security Requirements

B.1. USDA STRATUS Blanket Ordering Agreement (BOA) Security Requirements – Pool 2

The Contractor shall establish and maintain a security program and security controls per Federal Risk Authorization Management Program (FedRAMP) and Cloud Security and Privacy Requirements as specified as well as compliance with current Federal and United States Department of Agriculture (USDA) policies and directives.

B.1.1 Definitions

B.1.1.1 Authorization and Evaluation Entity - An authorized assessment and evaluation entity is an explicitly identified government entity under this BOA, that is authorized to conduct and perform independent assessments and evaluations leveraging best practices and guidelines established by NIST and commercial standards.

a) United States Federal Government - The following US Federal Government agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:

Cybersecurity and Infrastructure Security Agency (CISA)

Government Accounting Office (GAO)

National Security Agency (NSA) / Central Security Service (CSS)

Office of the Director of National Intelligence (ODNI)

b) United States Department of Defense - The following DoD agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:

Director Operational Test & Evaluation (DOT&E)

Marine Corps Forces Cyberspace Command Sixteenth Air Force (AFCYBER)

US Army Cyber Command (ARCYBER)

US Cyber Command (USCC) 157

US Fleet Cyber Command

Department of Defense Cloud Authorization Services (DCAS)

c) United States Department of Agriculture (USDA) – The following USDA agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:

Office of the Chief Information Officer (OCIO)

Digital Infrastructure Service Center (DISC)

B.1.1.2 Authorized Vendor - An authorized vendor is an entity that has been awarded a USDA BOA award by the BOA Administering function. An authorized vendor can be a Pool 1 – Cloud Service Provider (CSP); Pool 2 – Application Developer (AppDev), Operations & Maintenance (O&M), and/or System Integrator (SI); and/or Pool 3 – Software as a Service (SaaS) provider.

Attachment B: Security Requirements – RFQ 12314425Q0065 Page 3 of 6

Cloud Service Provider (CSP) - A CSP is an entity that directly operates and manages the cloud services (i.e., IaaS, PaaS, SaaS, etc.) technology (e.g., facility, hardware, software).

B.1.2 Responsibilities

B.1.2.1 Authorized Assessment and Evaluation Entity Responsibilities – Authorization and Evaluation Entities as defined in Section B.1.1 have the following responsibilities as related to all USDA Stratus Pool 2 Task Orders:

a) Cybersecurity Assessments and Evaluations - Authorized assessment and evaluation entities are responsible for conducting and performing announced and unannounced independent cybersecurity (e.g., OCIO, DISC, etc.) and operational (e.g., performance, SLAs) assessments and evaluations (e.g., OT&E) of the cloud services (i.e., IaaS, PaaS, SaaS, etc.)

architectures (e.g., compute, networking, storage) and security domains involved in the processing, transporting, and / or storing authorized ordering entities data.

b) Coordination - Authorized assessment and evaluation entities are responsible for coordinating assessment and evaluation activities with the authorized vendors.

Coordination responsibilities shall include planning, execution, and post assessment and evaluation activities (e.g., remediations, Plan of Actions and Milestones (POA&Ms).

c) Cost - Authorized assessment and evaluation entities are responsible for their assessment and evaluation costs.

d) Findings and Recommendations - Authorized assessment and evaluation entities are responsible for documenting the assessment and evaluation findings and recommendations (e.g., reports).

e) Communication and Distribution - Authorized assessment and evaluation entities are responsible for communicating and distributing the assessment and evaluation findings and recommendations to the following:

BOA Contracting Officer (CO)

Task Order Contracting Officer Representative (TO COR)

Authorized assessment and evaluation entities (e.g., OCIO, DISC, etc.)

Assessed and evaluated authorized vendor(s)

B.1.2.2. USDA Authorized Ordering Entity (Mission Owners) – Authorized Ordering Entities have the following responsibilities as related to all USDA Stratus Pool 2 Task Orders:

a) Cybersecurity Assessments and Evaluations

Findings and Recommendations - Authorized ordering entities are responsible for receiving and reviewing authorized assessment and evaluation entities' assessment and evaluation findings and recommendations (e.g., reports).

Suspension and Termination of Task Order(s) - Authorized ordering entities are responsible for evaluating and determining if the findings and recommendations of an assessment and evaluation warrants the suspension or termination (i.e., termination for cause, termination for convenience) of a TO(s) awarded under this BOA.

USDA Authorization Management Program Reporting - Authorized USDA ordering entities are responsible for reporting and submitting issued ATO(s) to USDA OCIO and FedRAMP.

Attachment B: Security Requirements – RFQ 12314425Q0065 Page 4 of 6

Authorized USDA ordering entities are responsible for reporting and submitting any ATO Assessment & Authorization (A&A) identified inconsistencies (i.e., with FedRAMP authorization, with USDA OCIO authorization), concerns, or issues to OCIO and FedRAMP.

Cybersecurity Incident Reporting - Authorized USDA ordering entities are responsible for reporting of cybersecurity incidents to the BOA Contracting Officer and to their TO(s) authorized vendors to ensure the authorized vendor can take appropriate mitigation actions.

B.1.2.3 Authorized Vendor – Pool 2 Vendors

a) Coordination - Authorized vendors shall be responsible for coordinating assessment and evaluation activities with the authorized assessment and evaluation entities. Coordination responsibilities shall include planning, execution, and post assessment and evaluation activities (e.g., remediations, POA&Ms).

b) Findings and Recommendations - Authorized vendors shall be responsible for receiving and reviewing authorized assessment and evaluation entities' assessment and evaluation findings and recommendations (e.g., reports).

c) Mitigation and Remediation - Authorized vendors shall be responsible for evaluating, determining, and executing the appropriate mitigation and remediation activities (e.g., fixes, patches, updates) in response to the findings and recommendations of an assessment and evaluation. Findings shall be remediated within established USDA timeframes; 15 days for Critical, and 30 days for all others.

d) Public Disclosure and Release - Authorized vendors shall be responsible for reviewing the written notifications from authorized assessment and evaluation entities including the provided unclassified versions of the assessment and evaluation findings and recommendations and timely reply, within 30 calendar days, to the authorized assessment and evaluation entities of any concerns or objections to the public disclosure or release.

B.1.2.4 Cybersecurity Authorization to Operate (ATO)

a) Notification of Terms and Conditions Discrepancies - Authorized vendors shall be responsible for immediately notifying the BOA Contracting Officer when a conflict, discrepancy, or issue is identified between the applicable laws, regulations, policies, and Terms & Conditions of the US, USDA STRATUS BOA, or their TO(s).

b) Performance Conflict Elevation - Authorized vendors shall be responsible for elevating unresolvable performance conflicts with authorized ordering entities to the BOA Contracting Officer for arbitration and resolution.

c) Department of Defense Cloud Authorization Services Authorization(s) - Vendors shall be responsible for obtaining and maintaining DCAS authorization(s) for their CSO(s) (i.e., IaaS, PaaS, SaaS, etc.) in accordance with DCAS regulations and policies.

d) Federal Risk and Authorization Management Program Authorization(s) - Vendors shall be responsible for obtaining and maintaining FedRAMP authorization(s) for their CSO(s) (i.e., IaaS, PaaS, SaaS, etc.) in accordance with FedRAMP regulations and policies.

e) Cybersecurity Incident Reporting - Authorized vendors are responsible for timely reporting cybersecurity incidents to the TO(s) Contracting Authority to ensure awareness of the incident and mitigating actions the authorized vendor is performing.

Attachment B: Security Requirements – RFQ 12314425Q0065 Page 5 of 6

B.1.3 Applicable Security Controls, Compliance, and Policies

Authorized Vendors under the USDA STRATUS BOA for ordering Pool 2 Providers shall comply with USDA high level security policy/guidelines, to include:

B.1.3.1 Ensure ongoing Assessment and Authorization (A&A) of the cloud service tenant according to the appropriate level and conform with the Federal Information Security Modernization Act (FISMA), the Federal Information Processing Standards (FIPS) 199 Categorization (Low, Moderate, High), and Office of Management and Budget (OMB) Circular A-130, and Federal Risk Management Program (FedRAMP) standards.

B.1.3.2 Comply and meet thresholds set in the National Institute of Standards and Technology (NIST) SP 800-53 Risk Management Framework “Security and Privacy Controls for Federal Information Systems and Organizations.”

a) CA-1 Security Assessment and Authorization Policies and Procedures - Formal, documented security assessment and authorization policies that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Formal, documented procedures to facilitate the implementation of the security assessment and authorization policies and associated security assessment and authorization controls.

b) CA-7 Continuous Monitoring – The organization establishes a continuous monitoring strategy and implements a continuous monitoring program that includes: a configuration management process for the information system and its constituent components; a determination of the security impact of changes to the information system and environment of operation; Ongoing security control assessments in accordance with the organizational continuous monitoring strategy; and Reporting the security state of the information system to the Authorizing Official at least quarterly.

B.1.3.3 Information and data management shall comply with Executive Order 13556 regarding Controlled Unclassified Information (CUI), Personally Identifiable Information (PII) a subset of CUI, and Sensitive PII a subset of PII that requires additional controls and safeguards.

B.1.3.4 Maintain strong physical security controls, managed access to the virtual environment, and maintain strong separation between virtual workloads and environments. Provide clear segregation of data unless otherwise specified, at the application level, and storage level.

B.1.3.5 Fortified Security – Security that enables cyber defenses from the “root” level of systems through the application layer and down to the data layer with improved capabilities including continuous monitoring and auditing; automated threat detection; resiliency against persistent adversarial threat;

encryption at rest and in transits; and an operating environment that meets or exceeds USDA information security requirements.

B.1.3.6 Cybersecurity and Infrastructure Security Agency (CISA) Cybersecurity Division Trusted Internet Connections (TIC) Reference Architecture Document (current and subsequent versions) 2.0 - TIC is a federal cybersecurity initiative intended to enhance network and boundary security across the Federal Government. The Office of Management and Budget (OMB), the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), and the General Services Administration (GSA) oversee the TIC initiative through a robust program that sets guidance and an execution framework for agencies to implement a baseline boundary security standard.

Attachment B: Security Requirements – RFQ 12314425Q0065 Page 6 of 6

B.1.3.7 USDA Specific Guidance - The Contractor shall comply with cloud security and privacy requirements specified below including with directed mandates to protect and defend information systems from recurring security threats or in response to real-time vulnerabilities.

a) USDA Department Regulation DR-3650-001 Cloud Computing - This Departmental Regulation (DR) updates the United States Department of Agriculture (USDA) policy for implementing the Office of Management and Budget’s (OMB) Federal Cloud Computing Strategy (Cloud Smart) across the USDA’s information technology (IT) portfolio of information and information systems. Link - https://www.usda.gov/directives/dr-3650-001

b) FedRAMP compliant as assessed by a third-party assessment organization (as defined in Section 1.1.1 “Authorization and Evaluation Entity”) authorized and accredited for this purpose by the USDA and FedRAMP.

c) Compliant with all FedRAMP controls required for the FISMA Low and Moderate Level of Risk Categorization.

d) At all times be operating under a valid Authority to Operate (ATO) granted by USDA for at least the FISMA Low Level of Risk Categorization.

e) Determined by USDA to effectively meet the controls required by FedRAMP after a pre-award review of the security control test results used to authorize the service. USDA will conduct the pre-award review of the security control test results used to authorize the service within a 2-week window after the technical evaluation is completed but before the award executed. USDA will be responsible for conducting the pre-award review and is solely responsible for making the decision as it pertains to issuance of the ATO.

File details come from the government source that posted it. Updated .