Appendix C-Baseline Compliance Contract Requirements_0001.pdf

PDF 1 MB Posted

Attached to
Computer Security Monitoring, Incident Response, a Federal contract opportunity
Solicitation number
140A1620R0018
Issued by
Department of the Interior Bureau of Indian Affairs Central Office

About this file

This federal solicitation seeks computer security monitoring, incident response, and security engineering support services for the Bureau of Indian Affairs Central Office. Required services include vulnerability scanning, security assessments, incident response, patch management, antivirus software, and malware detection. Offerors must demonstrate experience with Federal Information Security Management Act compliance, continuous monitoring, and assessment and authorization processes. The performance period is one base year with four optional one-year extensions. Proposals are due within 30 days and the agency intends to award a single firm-fixed-price contract.

View the file

Other files for this federal contract opportunity

Other files attached to Computer Security Monitoring, Incident Response, a, newest first.
File Type Posted
Attachment 2 SOW A0002_0002.pdf PDF
Attachment 2 SOW 5.13.2020_0001.pdf PDF
QA 5.13.2020_0001.pdf PDF
B09 SF30 140A1620R0018 A0001_0001.pdf PDF
B08 Attachment 1 - Pricing Schedule.xlsx XLSX spreadsheet
Sol_140A1620R0018.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix: Baseline Compliance Contract Requirements

This document provides the baseline compliance Requirements that must be included in all contracts that involve IT products or services in accordance with the DOI Information Management and Technology Compliance Acquisition Policy.

As with all Federal government agencies, DOI is subject to numerous requirements stemming from a variety of Laws, rules, regulations, directives, and standards aimed at ensuring the protection of sensitive agency information and information systems. These requirements include providing information security and privacy protections commensurate with the risk and magnitude of the potential harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of (i) information collected or maintained by or on behalf of the agency; and (ii) information systems used or operated by the agency or by a contractor on behalf of the agency.

Consequently, the Contractor shall also adhere to and comply with applicable Laws, Executive Orders and Executive Branch Policy regarding the design, build, testing, operations and maintenance of the information system and the security controls designed to safeguard agency information. This document establishes the information technology (IT) security and privacy requirements in which the service provider must comply. These requirements are applicable when DOI information is generated, accessed, stored, processed, or exchanged with DOI or on behalf of DOI by a service provider or subcontracted service provider, regardless of whether the information resides on a DOI information system or a service provider/subcontracted service provider’s information system. The service provider shall protect the confidentiality, integrity, and availability of DOI electronic information and IT resources and protect DOI electronic information from unauthorized disclosure.

DOI remains responsible and accountable for all risk incurred by use of services provided by external service providers. This risk is addressed by requiring a minimum set of security and privacy controls that must be implemented and monitored to provide assurance that DOI information remains accurate, secure and available. The requirements outlined herein are intended to provide DOI with an acceptable level of trust and controls that must be maintained throughout the lifecycle of the acquisition. This level of trust and controls are maintained by:

1. Meeting the IT security and privacy requirements as identified within this document, including satisfying the ongoing continuous monitoring requirements identified herein;

and

2. The Provider acquiring the services of an agreed upon independent third-party accredited assessor1 to test and evaluate the effectiveness of the applicable security controls.

Table of Contents

1 See https://www.fedramp.gov/marketplace/accredited-assessors/ https://www.fedramp.gov/marketplace/accredited-assessors/

Section 1.0 – Requirements for Protecting Sensitive Information 5

1.1 Applicability 5

1.2 Authorization to Use, Store, or Share Sensitive Information 5

1.3 Contract Performance Information 7

1.3.1 Dissemination of Contract Performance Information 7

1.3.2 Contractor Testimony 7

1.4 Mandatory Requirement for Contractor Return of all DOI and DOI-Activity-Related Information 7

1.5 Mandatory Requirement for Verified Secure Destruction of All DOI and 9 DOI-Activity-Related Information 9

1.6 Mandatory Requirement for Contractor Return of all DOI-Owned and Leased 10 Computing and Information Storage Equipment 10

1.7 Information/Data Ownership and Access 10

Section 2 - Information Assurance Requirements 12

2.1 Compliance with IT Security Policies 12

2.2 Information Types 12

2.2.1 Sensitive Information 12

2.2.2 Personally Identifiable Information (PII) 12

2.2.3 Sensitive PII 13

2.3 Information Security Incidents 13

2.3.1 Information Security Incident Reporting Requirements 13

2.3.2 Information Security Incident Response Requirements 14

2.4 Contractor Policy Document for Protection of Sensitive Information 15

2.5 Design and Technical Architecture Requirements 16

2.6 Federal Information Security Modernization Act (FISMA) Compliance 17

2.6.1 Security Assessment and Authorization (A&A) 17

2.6.1.1 Security Controls 20

2.6.1.1.1 Secure Technical Implementation Guides 24

2.6.1.1.2 FIPS 140 Encryption Requirements 24

2.6.1.2 System Security Plan (SSP) 25

2.6.1.3 Contingency Plan (CP) 26

2.6.1.4 Security Assessment Plan and Report (SAP/SAR) 26

2.6.1.5 Plan of Action and Milestones (POA&M) 26

2.6.1.6 Continuous Monitoring Plan (CMP) 27

2.6.1.6.1 Vulnerability Scanning 28

2.6.1.6.2 Remediation of Vulnerabilities and Weaknesses 29

2.6.1.6.3 Audit Logging 29

2.6.1.6.4 Security Monitoring and Alerting Requirements 30

2.6.1.6.5 System Management 30

2.6.1.7 Contingency and Disaster Recovery Plans 30

2.6.2 Cloud Security Requirements 31

2.6.2.1 Infrastructure as a Service (IaaS) Requirements 31

2.6.2.2 Platform as a Service (PaaS) Requirements 33

2.6.2.3 Software as a Service (SaaS) Requirements 33

2.6.2.4 FedRAMP Security Requirements Overview 33

2.6.2.5 FedRAMP Security Compliance Requirements 33

2.6.2.6 FedRAMP Requirements Related to Assessment and Authorization (A&A) 34

2.6.2.7 Assessment and Authorization of the System 35

2.6.2.8 System Security Plan (SSP) 36

2.6.2.9 Security Assessment Plan and Report (SAP/SAR) 37

2.6.2.10 Reporting and Continuous Monitoring 38

2.6.2.11 Required FedRAMP Policies and Regulations 38

2.7 Contractor Access to DOI IT Systems 38

2.8 Contractor Personnel Security Clearance Requirements 39

2.9 Homeland Security Presidential Directive-12 (HSPD-12) Compliance 40

2.10 Federal Reporting Requirements 43

2.11 IT Security and Privacy Education, Awareness and Training 43

2.12 Requirements Related to Compliance Reviews, Audits, Evaluations, Inspections and E- Discovery 44

2.13 Supply Chain Risk Management 46

2.14 Copyright and Licensing Requirements 48

Section 3 - Privacy Requirements 49

3.1 Privacy Act Requirements 49

3.2 Privacy Clauses 50

3.3 Privacy Controls 53

3.4 Privacy Breach Reporting Requirements 54

3.5 Breach Response Requirements 56

Section 4 - Section 508 Requirements 58

Section 5 - Records Management Requirements 59

Section 6 - Paperwork Reduction Act Requirements 62

Section 7 - Internet Protocol Version 6 (IPv6) Requirements 62

Section 8 - Secure Application Environments and Trusted Internet Connection (TIC) Requirements 62

Acronyms 64

Contractor Personnel Security Requirements 66

Glossary 68

Suggest insertion of a table instead of inserting the full text clauses.Error! Bookmark not defined.

Table of Deliverables and Reporting Requirements 74

Table of Authorities 76

Reference Documents (publicly available) 81

Section 1.0 – Requirements for Protecting Sensitive Information

1.1 Applicability

This document applies to the Contractor, its sub-Contractors, and Contractor personnel (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of the requirements contained in this document in all subcontracts. This document addresses specific Department of the Interior (DOI) requirements in addition to those included in the Federal Acquisition Regulation (FAR), Federal Information Security Modernization Act of 2014 (FISMA) (44 U.S.C. Chapter 35), Privacy Act of 1974 (5 U.S.C. 552a, as amended), Federal Records Act (44 U.S.C. Chapter 31), Section 508 of the Rehabilitation Act of 1973 (29 U.S.C.

794d), Health Insurance Portability and Accountability Act of 1996 (HIPAA, Pub. L. 104-191, 110 Stat. 1936), Sarbanes-Oxley Act of 2002 (SOX, Pub. L. 107-204, 116 Stat 745), Office and Management and Budget (OMB) Circular A-130, Managing Information as a Strategic Resource, and other laws, mandates, or executive orders pertaining to the development and operations of information systems and the protection of sensitive information and data. The following should not be construed to alter or diminish civil and/or criminal liabilities provided under various laws or mandates.

1.2 Authorization to Use, Store, or Share Sensitive Information

(a) Information created, collected, used, processed, stored, maintained, disclosed, or otherwise disposed of by the Contractor in the performance of this contract shall be accessed, transferred, stored or processed only within the sole jurisdiction of the United States Federal Government.

The Contractor shall not host any portion of the information, data, information system, infrastructure, or environment in facilities outside the contiguous United States, Alaska, Hawaii, and other U.S. Territories.

(b) The primary locations shall be the main and backup data centers located within the sole jurisdiction of the United States Federal Government.

(c) In addition, other sites include the location of the Contractor support teams who provide support to the Government in resolving issues involving the task order solution, locations where backup or archiving facilities may be agreed to by the Government, or sites where antivirus and other security scans are performed.

(d) The Contractor shall comply and agree to at all times to protect the Government’s information and data in accordance with the terms of this contract. The data that is processed, maintained, or stored by the Contractor shall be protected against unauthorized access, disclosure or modification, theft, or destruction.

(e) Information made available to the Contractor by the Government for the performance or administration of this effort shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer (CO).

(f) The preparation of the deliverables in this contract will be completed at a Controlled Unclassified Information (CUI) level and shall not be shared with any other organization without prior approval from the DOI CO.

(g) The Contractor, and any sub-Contractors, shall not use any DOI sensitive agency information, including Personally Identifiable Information (PII) or contract information, for any purpose other than those activities necessary for the performance of this contract.

(h) Written approval by the Chief Information Officer (CIO), Associate Chief Information Officer (ACIO), or their designee, is required prior to the use or storage of DOI Sensitive Information or sharing of DOI Sensitive Information by the Contractor with anyone that is not a party to this contract or with any sub-Contractor for which the Contractor has failed to insert the substance of the requirements contained in this document in all related subcontracts.

(i) The Contractor shall not remove Sensitive Information from approved DOI location(s), electronic device(s), or other container(s), without prior written approval of the DOI CIO, ACIO, or their designee.

(j) Any information made available to the Contractor by the Government shall be used only for the purpose of carrying out the terms and conditions of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of the contract. In performance of this contract, the Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its sub- Contractors shall be under the supervision of the Contractor or the Contractor’s responsible employees. The Contractor agrees to assume responsibility for protecting the confidentiality of Government records, which are not public information. Each Contractor or employee of the Contractor to whom information may be made available or disclosed shall be notified in writing by the Contractor that such information may be disclosed only for a purpose and to the extent authorized herein. Further disclosure of any such information, by any means, for a purpose or to an extent unauthorized herein, may subject the offender to criminal sanctions imposed by 18 U.S.C. §§ 1030.

The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The Service Provider (SP) shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this contract should be considered as CUI. It is anticipated that this information will be gathered, created, and stored within the primary work location. If SP personnel must remove any information from the primary work area they should protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act information.

CUI data and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The SP shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to Government control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following National Institute of Standards and Technology (NIST) Special Publication (SP) 800-88, Guidelines for Media Sanitization.

The disposition of all information will be at the written direction of the COR. The COR must consult with the POR who in turn must also consult with the appropriate cognizant Records Officer to help ensure appropriate measures have been taken by the SP to ensure that records are preserved and disposed of in accordance with Federal government-wide policy and DOI standards and requirements. Items returned to the Government shall be hand carried or sent by certified mail to the COR.

The data that is processed and stored by the various applications within the network infrastructure may contain financial data as well as personally identifiable information (PII).

This data and PII, in addition to all other types of CUI and sensitive information, shall be protected against unauthorized access, disclosure or modification, theft, or destruction. The Contractor shall ensure that the facilities that house the network infrastructure are physically secure.

The data must be available to the Government upon request within one business day or within the timeframe specified otherwise, and shall not be used for any other purpose other than that specified herein. The SP shall provide requested data at no additional cost to the Government.

1.3 Contract Performance Information

1.3.1 Dissemination of Contract Performance Information

The Contractor must not publish, permit to be published or distributed for public consumption, any information, oral or written, concerning the results or conclusions made pursuant to the performance of this contract, without the prior written consent of the CO. Two copies of any material proposed to be published or distributed must be submitted to the CO for approval.

1.3.2 Contractor Testimony

All requests for the testimony of the Contractor or its employees, and any intention to testify as an expert witness relating to: (a) any work required by, and or performed under, this contract; or

(b) any information provided by any party to assist the Contractor in the performance of this contract, must be immediately reported to the CO. Neither the Contractor nor its employees must testify on a matter related to work performed or information provided under this contract, either voluntarily or pursuant to a request, in any judicial or administrative proceeding unless approved by the CO or required by a judge in a final court order.

1.4 Mandatory Requirement for Contractor Return of all DOI and DOI-Activity-Related

Information

The disposition of all information will be at the written direction of the COR. Items returned to the Government shall be hand carried or sent by certified mail to the COR.

(a) Within thirty (30) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or by the Contractor for any reason, the Contractor must return all original (and at least one duplicate copy of those information types specified by DOI) of all DOI-provided and DOI-Activity-Related Information, (including but not limited to all records, files, and metadata in electronic or hardcopy format); including but not limited to the following:

1. provided by DOI; or

2. obtained by the Contractor while conducting activities in accordance with the contract with DOI; or

3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or

4. received from the Contractor by any other related organization and/or any other component or separate business entity.

(b) Within forty-five (45) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or the Contractor for any reason, the Contractor must provide DOI with an associated Certification of Verified Return of all original (and at least one duplicate copy of those information types specified by DOI) of all DOI and DOI-Activity- Related Information, (including but not limited to all records, files, and metadata in electronic or hardcopy format); including but not limited to the following:

contract with DOI; or

3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or

4. or received from the Contractor by any other related organization and/or any other component or separate business entity.

(c) This certification must be provided by a third party firm approved by DOI in advance. All costs and resource allocations required for this third party service must be the sole responsibility of the Contractor.

1.5 Mandatory Requirement for Verified Secure Destruction of All DOI and DOI-Activity-Related Information

The disposition of all information will be at the written direction of the COR. Items returned to the Government shall be hand carried or sent by certified mail to the COR.

(a) Within sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or by the Contractor for any reason, BUT ONLY after DOI has accepted and approved the Contractor’s compliance with the Certified Verification of Return of Information Requirement, the Contractor must execute secure destruction (either by the Contractor or third party firm approved in advance by DOI) of all existing active and archived originals and/or copies of all DOI and DOI-Activity-Related files and information, including but not limited to all records, files, and metadata in electronic or hardcopy format, by procedures approved by DOI in advance and in accordance with applicable DOI information technology (IT) Security Policy Requirements, including but not limited to the following:

contract with DOI; or

3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or

4. received from the Contractor by any other related organization and/or any other component or separate business entity.

(b) Within seventy-five (75) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or the Contractor for any reason, BUT ONLY after DOI has accepted and approved the Contractor’s compliance with the Certified Verification of Return of Information Requirement, the Contractor must provide DOI with Certification of Secure Destruction of all existing active and archived originals and/or copies of all DOI - Activity-Related files and information, including but not limited to all records, files, and metadata in electronic or hardcopy format, by procedures approved by DOI in advance and in accordance with applicable DOI IT Security Policy Requirements, including but not limited to the following:

contract with DOI; or

3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or

4. received from the Contractor by any other related organization and/or any other component or separate business entity.

(c) This certification must be provided by a third party firm approved by DOI in advance. All costs and resource allocations required for this third party service must be the sole responsibility of the Contractor.

1.6 Mandatory Requirement for Contractor Return of all DOI-Owned and Leased

Computing and Information Storage Equipment

The disposition of all computing and information storage equipment will be at the written direction of the COR. Items returned to the Government shall be hand carried or sent by certified mail to the COR.

(a) Within sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or by the Contractor for any reason; or within a time period approved by DOI, the Contractor must return all DOI-owned and leased computing and information storage equipment.

(b) Within seventy-five (75) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or the Contractor for any reason, the Contractor must provide DOI with Certification of Verified Return of all DOI-Owned and Leased Computing and Information Storage Equipment. This certification must be provided by a third party firm approved by DOI in advance. All costs and resource allocations required for this third party service must be the sole responsibility of the Contractor.

1.7 Information/Data Ownership and Access

(a) All documents produced under this contract are the property of the U.S. Government and cannot be reproduced, or retained by the Contractor, even if the contract is revoked by either party for any reason. All appropriate project documentation will be given to the agency during and at the end of this contract in an acceptable and usable format, which may include the original format, at no additional cost to DOI. The Contractor shall not release any information without the written consent of the CO.

(b) The Government retains unrestricted rights to all Government data. DOI retains ownership of any and all user created/loaded data and applications hosted on the Contractor’s infrastructure, as well as maintains the right to request full copies of these at any time.

(c) The preliminary and final deliverables and all associated working papers and other material deemed relevant by the agency that have been generated by the Contractor in the performance of this contract, are the property of the U.S. Government and must be submitted to the COR at the conclusion of the contract in an acceptable and usable format, which may include the original format, at no additional cost to DOI. The U.S. Government has unlimited data rights to all deliverables and associated working papers and materials in accordance with FAR 52.227-14.

(d) The Contractor acknowledges DOI’s exclusive right of ownership of the information and is required to transfer or return (or delete) all agency data collected, processed, stored or maintained by Contractor on behalf of DOI upon termination of services, and shall provide written certification and supporting documentation attesting to the return of agency data collected, processed, maintained, or stored by the Contractor. Contractor shall provide DOI logical and physical access to Contractor’s facilities, installations, technical capabilities, operations, records, and databases upon request to verify the Contractor’s certification for the return or removal of agency data.

(e) DOI information stored in the Contractor’s or Service Provider’s (SP) network and computing environments remain the property of DOI, not the Contractor or SP. DOI retains ownership of the information and any media type that stores Government information. The Contractor or SP do not have rights to the DOI information for any purposes other than those explicitly stated in the contract. The Contractor and SP must protect DOI information from unauthorized access by Contractor and SP personnel, other Contractors, or other SP subscribers.

The Contractor and SP must allow DOI full access to DOI information including data schemas, metadata, and other associated data artifacts that are required to ensure DOI can fully and appropriately retrieve DOI information from all of the Contractor or Service Provider environments that have been utilized to store, read, or process DOI’s information.

(f) The Contractor shall treat all deliverables under the contract as the property of the U.S.

Government for which DOI and any of its designated officials shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable without the express permission of the CO or COR.

(g) The Contractor is required to obtain the CO’s approval prior to engaging in any contractual relationship (sub-Contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, this contract. The Contractor (and any sub-Contractor) is required to abide by Government and DOI guidance for protecting sensitive and proprietary information.

(h) At the expiration of the contract, the Contractor shall return all sensitive DOI information and IT resources provided to the Contractor during the contract, and certify to the CO and COR that all DOI information has been sanitized or purged from any Contractor-owned system following the template provided in NIST Special Publication 800-88 Guidelines for Media Sanitization. DOI reserves the right, and the Contractor shall cooperate with DOI officials, to conduct reviews to ensure that the security and privacy requirements in the contract are implemented and enforced.

(i) The Contractor shall keep the information confidential, use appropriate safeguards to maintain its security in accordance with minimum Federal standards. Contractor must also explain and certify that its sub-Contractor(s) will adhere to the same minimum Federal standards when working with sensitive data.

(j) The Contractor’s invoicing, billing, and other financial, administrative records or databases may not store or include any sensitive Government information, such as PII, created, obtained, or provided during the performance of the contract. It is acceptable to list the names, titles and contact information for the CO, or other designated agency official associated with the administration of the contract in the invoices as needed.

Section 2 - Information Assurance Requirements

2.1 Compliance with IT Security Policies

(a) Information systems and system services provided to DOI by the Contractor must comply with current DOI IT Security and Privacy Control Standards, privacy policies and other related guidance.

(b) Contractors are also required to comply with current Federal regulations and guidance found in FISMA, the Privacy Act of 1974, Section 208 of the E-Government Act of 2002, NIST, FIPS and the NIST 800-Series Special Publications, OMB memorandum, and other relevant Federal laws and regulations that DOI must comply with.

2.2 Information Types

The term Information is synonymous with data, regardless of format or medium.

Information shall be managed in accordance with applicable laws, regulations, executive orders, and policies regarding the safeguarding and dissemination of CUI. PII is a subset of information designated as CUI, and Sensitive PII is a subset of PII that requires additional controls and safeguards. All requirements for Sensitive Information apply to PII and Sensitive PII. All requirements for PII apply to Sensitive PII.

2.2.1 Sensitive Information

Sensitive Information is any information, which if lost, compromised, or disclosed, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual, the Government, or the Government’s interests. Sensitive Information is subject to stricter handling requirements because of the increased risk if the data is compromised. Some categories of Sensitive Information include financial, medical or health, legal, proprietary, strategic and business, human resources, PII, and Sensitive PII. These categories of information require appropriate protection as stand-alone information and may require additional protection in aggregate.

2.2.2 Personally Identifiable Information (PII)

PII, as defined in OMB Circular A-130, refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information that is publicly available

— in any medium and from any source — is or can be combined to identify an individual. As an example, PII includes a name and an address because it uniquely identifies an individual, but alone may not constitute Sensitive PII.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

2.2.3 Sensitive PII

Sensitive PII is a subset of PII, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.

Sensitive PII can be used to target, harm, or coerce an individual or entity, assume or alter an individual’s or entity’s identity, or alter the outcome of an individual’s or entity’s activities.

Sensitive PII requires stricter handling because of the increased risk to an individual or associates if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as SSNs, driver’s license number, financial account number, or biometric identifiers such as fingerprint. Additional information used in conjunction with the identity of an individual (directly or indirectly inferred) such as date of birth, citizenship status, criminal history, medical information, and system authentication information (account passwords, personal identification numbers (PINs) are also considered Sensitive PII. In addition, the context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or complaint.

2.3 Information Security Incidents

An Information Security Incident is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or Sensitive Information.

(a) The Service Provider shall not impose on DOI employees or Contractors any additional requirements other than those articulated in DOI policies (e.g., IT Security, Privacy, Human Resources acceptable use policy, etc.) nor impose any penalties or sanctions on, or against, DOI employees for resolution of policy violations and accept that DOI’s handbook on Charges and Penalty Selection for Disciplinary and Adverse Actions, and associated Table of Penalties, are acceptable and to be applied at the management discretion of the agency.

2.3.1 Information Security Incident Reporting Requirements

All Information Security Incidents must be reported in accordance with the requirements below even if it is believed the incident may be limited, small, or insignificant. DOI will determine when an incident requires additional focus and attention.

(a) Contractor employees must report all information security incidents to the DOI Computer Incident Response Center (DOI-CIRC) immediately, and no later than 1 hour after becoming aware of the incident, at: DOICIRC@ios.doi.gov, (703) 648-5655, regardless of day or time.

(b) When notifying the DOI-CIRC, copy the CO and COR if possible, or if reporting by phone or CO’s or COR email is not immediately available, contact the CO and the COR immediately after reporting the incident to DOI-CIRC. The Contractor is responsible for positively verifying that notification was received and acknowledged by the CO or the COR.

(c) If you have questions regarding these procedures, please contact the CO or the COR.

(d) Contractor shall NOT include any Sensitive Information in the subject or body of any e-mail.

Contractor shall transmit Sensitive Information using NIST Federal Information Processing Standard (FIPS) 140-2, Security Requirements for Cryptographic Modules, compliant encryption methods to protect Sensitive Information in email attachments. Passwords must not be communicated in the same email as the attachment. Contractor should contact the CO or COR if encryption software is needed.

(e) Contractor employees must also provide any supplementary information or reports related to a previously reported incident directly to the DOI-CIRC with the following text in the subject line of the email: “Supplementary Information/Report related to previously reported incident # [insert number].”

2.3.2 Information Security Incident Response Requirements

(a) The Service Provider shall establish incident response and recovery procedures and practices that integrate DOI Computer Incident Response Center (DOI-CIRC) and DOI Advanced Security Operations Center (ASOC) incident and breach detection, reporting, notification, handling, response, containment, eradication and recovery processes and that adequately inform DOI senior agency officials, AO, Information System Owner, and Information System Security Officer (ISSO) of incidents, remediation and containment actions.

(b) The Service Provider shall immediately report all incidents, whether suspected or confirmed, involving potential risks to the confidentiality, integrity or availability of DOI’s information or to the function of provided systems operated on behalf of DOI, to the DOI-CIRC, DOI Contracting Officer and DOI System Owner. The Service Provider shall report computer security incidents and breaches affecting DOI data/information or to the function of provided systems in accordance with the DOI Enterprise Computer Security Incident Response Plan. The Service Provider shall promptly coordinate with the DOI System Owner and DOI-CIRC on all related incident handling, response, containment, eradication, and recovery efforts throughout the incident lifecycle until fully resolved to the satisfaction of the DOI System Owner.

(c) Upon becoming aware of any unlawful access to any DOI data/information stored on the Service Provider’s equipment or in the Service Provider’s facilities, or unauthorized access to such facilities or equipment resulting in loss, disclosure or alteration of any DOI data/information (a “Security Incident”), the Service Provider will:

(i) immediately notify the CO and COR’s via email with details of the Security Incident;

(ii) investigate the Security Incident and provide DOI with detailed information about the Security Incident; and

(iii) take reasonable steps to mitigate the effects and to minimize any damage resulting from the Security Incident.

(d) The Service Provider shall document a set of procedures for DOI approval and agreement for what DOI needs to perform to take an application offline (whether a software patch is going to be installed by the provider or subscriber), the testing that must be performed to ensure the application continues to perform as intended, and the procedures needed to bring the application back online. Plans for system maintenance should be expressed in a Service Level Agreement

(SLA).

(e) All determinations related to information security incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services will be made by authorized DOI officials at DOI’s discretion.

(f) The Contractor and Contractor employees must provide full access and cooperation for all activities determined by DOI to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of information security incidents.

(g) Incident response activities determined to be required by DOI may include but are not limited to, inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the incident and/or liability for any additional response activities.

(h) DOI, at its sole discretion, may obtain the assistance of Federal agencies and/or third party firms to aid in incident response activities, as needed.

(i) The Contractor is responsible for all costs and related resource allocations required for all subsequent incident response activities determined to be required by DOI, whether incurred by DOI, agents under contract or on assignment to DOI, or by third party firms.

2.4 Contractor Policy Document for Protection of Sensitive Information

(a) The Contractor is responsible for the proper handling and protection of Sensitive Information to prevent unauthorized disclosure. All Contractor employees are required to complete and sign both 1) a Non-disclosure Agreement granting conditional access to CUI information to guarantee the protection and integrity of Government information and documents and 2) a certificate of no conflict of interest before starting work under the contract.

(b) The contract deliverables shall be labeled “CONTROLLED UNCLASSIFIED INFORMATION” (CUI). External transmission/dissemination of For Official Use Only (FOUO) and CUI to or from a Government computer must be encrypted. Certified encryption modules must be used in accordance with the most current version of FIPS PUB 140, “Security requirements for Cryptographic Modules.”

(c) The Contractor must produce an attestation document requiring approval by the CIO, or designate, providing details regarding how the Contractor is protecting and handling sensitive DOI information. The attestation must address the following, at a minimum:

1. Proper marking, control, storage and handling of Sensitive Information residing on electronic media, including computers and removable media, and on paper documents.

2. Proper control and storage of mobile technology, portable data storage devices, and communication devices.

3. Proper use of FIPS 140-2 compliant encryption methods to protect Sensitive Information while at rest and in transit throughout DOI, Contractor, and/or sub-Contractor networks, and on host and client platforms.

4. Proper use of FIPS 140-2 compliant encryption methods to protect Sensitive Information in email attachments, including policy that passwords must not be communicated in the same email as the attachment.

5. Information Security Incidents.

6. Contractor Access to DOI IT Systems.

7. IT Security Awareness Training.

8. Specialized IT Security Awareness Training for Security Staff.

9. Information Systems Policy Compliance requirements and procedures.

10. Contract Performance Information.

2.5 Design and Technical Architecture Requirements

(a) The Contractor provided solution shall integrate with DOI’s Identity, Authorization and Access Management (IdAAM) solution. This solution consists of the Microsoft Active Directory (AD) and Public Key Infrastructure (PKI) architecture and associated Certificate Authority and DOI HSPD-12 PIV Smart Card-based credentials. The Contractor provided solution must not require direct integration with, colocation of, or direct access to DOI’s AD environment or Domain Controllers. DOI’s AD architecture includes Active Directory Federated Services (ADFS) that provide reliable authentication services via Security Assertion Markup Language (SAML). The Contractor provided solution must support DOI’s SAML-based authentication services to meet all authentication needs and requirements of both DOI and the Contractor provided solution. Such Contractor provided solutions must enable logical authentication utilizing those credentials without requiring additional Contractor provided solution credentials. DOI uses Microsoft’s Active Directory to create a single DOI-wide directory of all users. This directory is known as the Enterprise Active Directory (EAD). The Contractor provided solution must recognize the EAD as the authoritative source for authentication. DOI authenticates users with username and password; however, the Department is transitioning to Entrust PKI for authentication. The system shall support authentication using DOI’s Entrust Public Key Infrastructure (PKI). In the future, all users shall be authenticated with the Entrust PKI and use the Homeland Security Presidential Directive (HSPD-12) Personal Identity Verification (PIV) Smart Card. At this time, some users will continue to be authenticated by username and password which must be supported by the Contractor provided solution.

(b) The Contractor shall support the enablement and use of strong authentication tokens in accordance with the Federal Identity, Credential, and Access Management (FICAM) implementation guidance, HSPD-12 Directive, and applicable National Institute of Standards and Technology (NIST) standards and guidelines regarding use of the PIV Smart Card logical authentication credentials for access to the Contractor provided environment, software, applications, services or infrastructure by either the Contractor, authorized system administrators and end-users in a manner that leverages DOI’s existing authentication infrastructure to mitigate the risk of account compromise or hijacking.

2.6 Federal Information Security Modernization Act (FISMA) Compliance

2.6.1 Security Assessment and Authorization (A&A)

The Government will provide timely review of the Service Provider’s Assessment and Authorization (A&A) documentation package and any changes submitted by the Service Provider that could require re-assessment in order to assist the Government in its compliance with FISMA and the NIST 800-53 security control requirements. If there are any errors, omissions or other issues with the Provider’s A&A documentation package or assessment results, the Government will timely notify the Service Provider and provide reasonable descriptions of specific errors, omissions or other issues. The Government will reasonably cooperate with the Service Provider in the A&A process and will not unreasonably withhold or delay any review of A&A package documentation, assessment result from the independent assessor, or authorization decisions.

All A&A documents will be provided to the COR, DOI System Owner, and DOI Authorizing Official (AO) in both hard copy and electronic forms.

DOI may choose to cancel the contract/award and terminate any outstanding orders if the Service Provider has its authorization revoked and the deficiencies are greater than agency risk tolerance thresholds.

(a) This contract may require the Contractor to develop, deploy, and/or use information systems to access and/or store Government information, including Sensitive Information. The Contractor must provide a detailed outline of its present and proposed information systems security program and demonstrate that it complies with the Federal Information Security Modernization Act of 2014 (44 U.S.C. Chapter 35) as well as applicable Department of the Interior (DOI) policies and security requirements based on the Federal Information Processing Standard (FIPS) 199 categorization provided by DOI. The Contractor facilities must also meet the security requirements for the same impact level or greater as defined by the FIPS 199 categorization provided by DOI.

(b) All new IT systems, including outsourced systems, Major Applications (MA) or General Support Systems (GSS) and significant upgrades to systems must be assessed and authorized in keeping with FISMA and National Institute of Standards and Technology (NIST) standards.

These Assessment and Authorization (A&A) requirements also apply to systems that are already built and are utilized by DOI organizations under a contract with the Service Provider for the system (DOI data uploaded to the system). Such systems must meet the IT security and privacy requirements and ongoing requirements set forth within this document, including the eighteen DOI Security and Privacy Control Family Standards that correspond to the NIST Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, which identify additional required control enhancements and that specify DOI-defined control parameters and additional unique DOI-specific controls.

(c) All information systems that input, store, process, and/or output Government information must be provided an Authorization to Operate (ATO) signed by the the cognizant Authorizing Official (AO) designated by the Department’s Chief Information Officer (CIO). The Contractor must adhere to current DOI policies, procedures, and guidance for security Assessment and Authorization (A&A) activities.

(d) The Contractor will work with DOI to define a clearly demarcated security authorization boundary for the the information system (e.g., all associated networks, servers, applications, databases, storage, and other supporting systems and devices.

(e) All information systems must undergo FISMA-compliant security A&A prior to going into production and undergo Continuous Monitoring, as described herein.

(f) In accomplishing and maintaining A&A, the Contractor must follow the current version of the following:

● NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems

● NIST SP 800-30, Guide for Conducting Risk Assessments

● NIST SP 800-34, Contingency Planning Guide for Federal Information Systems

● NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal

Information Systems: a Security Life Cycle Approach

● NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and

Organizations

● NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information

Systems and Organizations: Building Effective Assessment Plans

● NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to

Security Categories

● NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable

Information (PII)

● NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

● NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations

● FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

● FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

● DOI Security and Privacy Control Family Standards

● DOI Privacy Impact Assessment Guide

(g) Prior to Security A&A, a Privacy Impact Assessment (PIA) for all systems must be completed and provided to the DOI Privacy Officer, or designate, for a determination. PIAs must identify privacy controls implemented for systems and must be completed in accordance with the DOI Privacy Impact Assessment Guide.

(h) FIPS 199 must be utilized to determine the security categorization (High, Moderate, or Low) for Contractor information technology (IT) systems and security control baseline requirements.

The cognizant AO must provide written and signed approval of the FIPS 199 security categorization. The DOI CIO or responsible AO have the authority to change the categorization rating based on additional knowledge of threats and vulnerabilities, as needed.

(i) Security A&A documentation must be developed with the use of 1) DOI security documentation templates, as adapted for Contractor IT systems for services and systems that are not cloud-based, or 2) the templates provided by the Federal Risk Authorization and Management Program (FedRAMP) provided at https://www.fedramp.gov/resources/templates- 2016/. Templates are available for services and systems that are not cloud-based for all security documentation including System Security Plan (SSP), Security Assessment Report (SAR), Contingency Plan, Incident Response Plan, etc. The Security A&A process must be followed throughout the IT system lifecycle process to ensure proper oversight by DOI.

(j) The Contractor will provide supporting documentation to DOI as necessary in support of the A&A process.

(k) The Authorizing Official (AO) for the system will be the government official formally designated by the DOI authorized senior executive.

The Level of Effort for the A&A is based on the System’s NIST FIPS 199 categorization. The Contractor shall create, maintain and update the following documentation:

● Privacy Impact Assessment (PIA)

● Test Procedures and Results

● Security Assessment Report (SAR)

● System Security Plan (SSP)

● System Privacy Plan https://www.fedramp.gov/resources/templates-2016/ https://www.fedramp.gov/resources/templates-2016/

● IT System Contingency Plan (CP)

● IT System Contingency Plan (CP) Test Results

● Plan of Action and Milestones (POA&M)

● Continuous Monitoring Plan (CMP)

● Control Tailoring Workbook

● Control…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .