J_TE09_Baseline Compliance Requirements_1.docx
DOCX document 119 KB Posted
- Attached to
- Minerals Revenue Management Support System Federal contract opportunity
- Solicitation number
- 140D0420R0005
About this file
This document provides a draft request for proposal for operations and maintenance support services for the Minerals Revenue Management Support System for the Office of Natural Resources Revenue. The draft RFP includes sections on technical requirements, contract terms, and evaluation criteria. Offerors are encouraged to review the draft documents and submit any questions by February 23rd to inform revisions to the formal RFP, which has yet to be released. The draft RFP outlines support needs for systems managing revenue collection from federal and American Indian mineral leases. Services include application hosting, help desk support, maintenance, and enhancements. The contract would have a one-year base period and four one-year options, with an anticipated award date in late 2020.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFI: DOIFBO190064 Operations and Maintenance Support Services for MRMSS.
Title: Minerals Revenue Management Support System (MRMSS) - Operations and Support / Development and Enhancement for the Office of Natural Resource Revenue (ONRR)
Section J Technical Exhibit (TE09)
IT SECURITY AND BASELINE COMPLIANCE REQUIREMENTS
Table of Contents
| Section 1.0 – Requirements for Protecting Sensitive Information | 4 |
| 1.1 Applicability | 4 |
| 1.2 Authorization to Use, Store, or Share Sensitive Information | 4 |
| 1.3 Contract Performance Information | 6 |
| 1.3.1 Dissemination of Contract Performance Information | 6 |
| 1.3.2 Contractor Testimony | 6 |
| 1.4 Mandatory Requirement for Contractor Return of all DOI and DOI-Activity-Related Information | 6 |
| 1.5 Mandatory Requirement for Verified Secure Destruction of All DOI and | 8 |
| DOI-Activity-Related Information | 8 |
| 1.6 Mandatory Requirement for Contractor Return of all DOI-Owned and Leased | 9 |
| Computing and Information Storage Equipment | 9 |
| 1.7 Information/Data Ownership and Access | 9 |
| Section 2 - Information Assurance Requirements | 11 |
| 2.1 Compliance with IT Security Policies | 11 |
| 2.2 Information Types | 11 |
| 2.2.1 Sensitive Information | 11 |
| 2.2.2 Personally Identifiable Information (PII) | 11 |
| 2.2.3 Sensitive PII | 12 |
| 2.3 Information Security Incidents | 12 |
| 2.3.1 Information Security Incident Reporting Requirements | 12 |
| 2.3.2 Information Security Incident Response Requirements | 13 |
| 2.4 Contractor Policy Document for Protection of Sensitive Information | 14 |
| 2.5 Design and Technical Architecture Requirements | 15 |
| 2.6 Federal Information Security Modernization Act (FISMA) Compliance | 16 |
| 2.6.1 Security Assessment and Authorization (A&A) | 16 |
| 2.6.1.1 Security Controls | 19 |
| 2.6.1.1.1 Secure Technical Implementation Guides | 23 |
| 2.6.1.1.2 FIPS 140 Encryption Requirements | 23 |
| 2.6.1.2 System Security Plan (SSP) | 24 |
| 2.6.1.3 Contingency Plan (CP) | 24 |
| 2.6.1.4 Security Assessment Plan and Report (SAP/SAR) | 24 |
| 2.6.1.5 Plan of Action and Milestones (POA&M) | 25 |
| 2.6.1.6 Continuous Monitoring Plan (CMP) | 25 |
| 2.6.1.6.1 Vulnerability Scanning | 27 |
| 2.6.1.6.2 Remediation of Vulnerabilities and Weaknesses | 27 |
| 2.6.1.6.3 Audit Logging | 28 |
| 2.6.1.6.4 Security Monitoring and Alerting Requirements | 28 |
| 2.6.1.6.5 System Management | 28 |
| 2.6.1.7 Contingency and Disaster Recovery Plans | 29 |
| 2.6.2 Cloud Security Requirements | 29 |
| 2.6.2.1 Infrastructure as a Service (IaaS) Requirements | 29 |
| 2.6.2.2 Platform as a Service (PaaS) Requirements | 31 |
| 2.6.2.3 Software as a Service (SaaS) Requirements | 31 |
| 2.6.2.4 FedRAMP Security Requirements Overview | 31 |
| 2.6.2.5 FedRAMP Security Compliance Requirements | 32 |
| 2.6.2.6 FedRAMP Requirements Related to Assessment and Authorization (A&A) | 32 |
| 2.6.2.7 Assessment and Authorization of the System | 34 |
| 2.6.2.8 System Security Plan (SSP) | 34 |
| 2.6.2.9 Security Assessment Plan and Report (SAP/SAR) | 36 |
| 2.6.2.10 Reporting and Continuous Monitoring | 36 |
| 2.6.2.11 Required FedRAMP Policies and Regulations | 36 |
| 2.7 Contractor Access to DOI IT Systems | 36 |
| 2.8 Contractor Personnel Security Clearance Requirements | 37 |
| 2.9 Homeland Security Presidential Directive-12 (HSPD-12) Compliance | 38 |
| 2.10 Federal Reporting Requirements | 41 |
| 2.11 IT Security and Privacy Education, Awareness and Training | 41 |
| 2.12 Requirements Related to Compliance Reviews, Audits, Evaluations, Inspections and E-Discovery | 42 |
| 2.13 Supply Chain Risk Management | 44 |
| 2.14 Copyright and Licensing Requirements | 46 |
| Section 3 - Privacy Requirements | 47 |
| 3.1 Privacy Act Requirements | 47 |
| 3.2 Privacy Clauses | 48 |
| 3.3 Privacy Controls | 51 |
| 3.4 Privacy Breach Reporting Requirements | 52 |
| 3.5 Privacy Breach Response Requirements | 54 |
| Section 4 - Section 508 Requirements | 56 |
| Section 5 - Records Management Requirements | 56 |
| Section 6 - Paperwork Reduction Act Requirements | 60 |
| Section 7 - Internet Protocol Version 6 (IPv6) Requirements | 60 |
| Section 8 - Secure Application Environments and Trusted Internet Connection (TIC) Requirements | 60 |
| Acronyms | 62 |
| Contractor Personnel Security Requirements | 64 |
| Glossary | 66 |
Section 1.0 – Requirements for Protecting Sensitive Information
1.1 Applicability
This document applies to the Contractor, its sub-Contractors, and Contractor personnel (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of the requirements contained in this document in all subcontracts. This document addresses specific Department of the Interior (DOI) requirements in addition to those included in the Federal Acquisition Regulation (FAR), Federal Information Security Modernization Act of 2014 (FISMA) (44 U.S.C. Chapter 35), Privacy Act of 1974 (5 U.S.C. 552a, as amended), Federal Records Act (44 U.S.C. Chapter 31), Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), Health Insurance Portability and Accountability Act of 1996 (HIPAA, Pub. L. 104-191, 110 Stat. 1936), Sarbanes-Oxley Act of 2002 (SOX, Pub. L. 107-204, 116 Stat 745), Office and Management and Budget (OMB) Circular A-130, Managing Information as a Strategic Resource, and other laws, mandates, or executive orders pertaining to the development and operations of information systems and the protection of sensitive information and data. The following should not be construed to alter or diminish civil and/or criminal liabilities provided under various laws or mandates.
1.2 Authorization to Use, Store, or Share Sensitive Information
(a) Information created, collected, used, processed, stored, maintained, disclosed, or otherwise disposed of by the Contractor in the performance of this contract shall be accessed, transferred, stored or processed only within the sole jurisdiction of the United States Federal Government. The Contractor shall not host any portion of the information, data, information system, infrastructure, or environment in facilities outside the contiguous United States, Alaska, Hawaii, and other U.S. Territories.
(b) The primary locations shall be the main and backup data centers located within the sole jurisdiction of the United States Federal Government.
(c) In addition, other sites include the location of the Contractor support teams who provide support to the Government in resolving issues involving the task order solution, locations where backup or archiving facilities may be agreed to by the Government, or sites where antivirus and other security scans are performed.
(d) The Contractor shall comply and agree to at all times to protect the Government’s information and data in accordance with the terms of this contract. The data that is processed, maintained, or stored by the Contractor shall be protected against unauthorized access, disclosure or modification, theft, or destruction.
(e) Information made available to the Contractor by the Government for the performance or administration of this effort shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer (CO).
(f) The preparation of the deliverables in this contract will be completed at a Controlled Unclassified Information (CUI) level and shall not be shared with any other organization without prior approval from the DOI CO.
(g) The Contractor, and any sub-Contractors, shall not use any DOI sensitive agency information, including Personally Identifiable Information (PII) or contract information, for any purpose other than those activities necessary for the performance of this contract.
(h) Written approval by the Chief Information Officer (CIO), Associate Chief Information Officer (ACIO), or their designee, is required prior to the use or storage of DOI Sensitive Information or sharing of DOI Sensitive Information by the Contractor with anyone that is not a party to this contract or with any sub-Contractor for which the Contractor has failed to insert the substance of the requirements contained in this document in all related subcontracts.
(i) The Contractor shall not remove Sensitive Information from approved DOI location(s), electronic device(s), or other container(s), without prior written approval of the DOI CIO, ACIO, or their designee.
(j) Any information made available to the Contractor by the Government shall be used only for the purpose of carrying out the terms and conditions of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of the contract. In performance of this contract, the Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its sub-Contractors shall be under the supervision of the Contractor or the Contractor’s responsible employees. The Contractor agrees to assume responsibility for protecting the confidentiality of Government records, which are not public information. Each Contractor or employee of the Contractor to whom information may be made available or disclosed shall be notified in writing by the Contractor that such information may be disclosed only for a purpose and to the extent authorized herein. Further disclosure of any such information, by any means, for a purpose or to an extent unauthorized herein, may subject the offender to criminal sanctions imposed by 18 U.S.C. §§ 1030.
The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The Service Provider (SP) shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this contract should be considered as CUI. It is anticipated that this information will be gathered, created, and stored within the primary work location. If SP personnel must remove any information from the primary work area they should protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act information.
CUI data and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The SP shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to Government control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following National Institute of Standards and Technology (NIST) Special Publication (SP) 800-88, Guidelines for Media Sanitization.
The disposition of all information will be at the written direction of the COR. The COR must consult with the POR who in turn must also consult with the appropriate cognizant Records Officer to help ensure appropriate measures have been taken by the SP to ensure that records are preserved and disposed of in accordance with Federal government-wide policy and DOI standards and requirements. Items returned to the Government shall be hand carried or sent by certified mail to the COR.
The data that is processed and stored by the various applications within the network infrastructure may contain financial data as well as personally identifiable information (PII). This data and PII, in addition to all other types of CUI and sensitive information, shall be protected against unauthorized access, disclosure or modification, theft, or destruction. The Contractor shall ensure that the facilities that house the network infrastructure are physically secure.
The data must be available to the Government upon request within one business day or within the timeframe specified otherwise, and shall not be used for any other purpose other than that specified herein. The SP shall provide requested data at no additional cost to the Government.
1.3 Contract Performance Information
1.3.1 Dissemination of Contract Performance Information
The Contractor must not publish, permit to be published or distributed for public consumption, any information, oral or written, concerning the results or conclusions made pursuant to the performance of this contract, without the prior written consent of the CO. Two copies of any material proposed to be published or distributed must be submitted to the CO for approval.
1.3.2 Contractor Testimony
All requests for the testimony of the Contractor or its employees, and any intention to testify as an expert witness relating to: (a) any work required by, and or performed under, this contract; or (b) any information provided by any party to assist the Contractor in the performance of this contract, must be immediately reported to the CO. Neither the Contractor nor its employees must testify on a matter related to work performed or information provided under this contract, either voluntarily or pursuant to a request, in any judicial or administrative proceeding unless approved by the CO or required by a judge in a final court order.
1.4 Mandatory Requirement for Contractor Return of all DOI and DOI-Activity-Related Information
The disposition of all information will be at the written direction of the COR. Items returned to the Government shall be hand carried or sent by certified mail to the COR.
(a) Within thirty (30) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or by the Contractor for any reason, the Contractor must return all original (and at least one duplicate copy of those information types specified by DOI) of all DOI-provided and DOI-Activity-Related Information, (including but not limited to all records, files, and metadata in electronic or hardcopy format); including but not limited to the following:
1. provided by DOI; or
2. obtained by the Contractor while conducting activities in accordance with the contract with DOI; or
3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or
4. received from the Contractor by any other related organization and/or any other component or separate business entity.
(b) Within forty-five (45) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or the Contractor for any reason, the Contractor must provide DOI with an associated Certification of Verified Return of all original (and at least one duplicate copy of those information types specified by DOI) of all DOI and DOI-Activity-Related Information, (including but not limited to all records, files, and metadata in electronic or hardcopy format); including but not limited to the following:
1. provided by DOI; or
2. obtained by the Contractor while conducting activities in accordance with the contract with DOI; or
3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or
4. or received from the Contractor by any other related organization and/or any other component or separate business entity.
(c) This certification must be provided by a third party firm approved by DOI in advance. All costs and resource allocations required for this third party service must be the sole responsibility of the Contractor.
1.5 Mandatory Requirement for Verified Secure Destruction of All DOI and DOI-Activity-Related Information
The disposition of all information will be at the written direction of the COR. Items returned to the Government shall be hand carried or sent by certified mail to the COR.
(a) Within sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or by the Contractor for any reason, BUT ONLY after DOI has accepted and approved the Contractor’s compliance with the Certified Verification of Return of Information Requirement, the Contractor must execute secure destruction (either by the Contractor or third party firm approved in advance by DOI) of all existing active and archived originals and/or copies of all DOI and DOI-Activity-Related files and information, including but not limited to all records, files, and metadata in electronic or hardcopy format, by procedures approved by DOI in advance and in accordance with applicable DOI information technology (IT) Security Policy Requirements, including but not limited to the following:
1. provided by DOI; or
2. obtained by the Contractor while conducting activities in accordance with the contract with DOI; or
3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or
4. received from the Contractor by any other related organization and/or any other component or separate business entity.
(b) Within seventy-five (75) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or the Contractor for any reason, BUT ONLY after DOI has accepted and approved the Contractor’s compliance with the Certified Verification of Return of Information Requirement, the Contractor must provide DOI with Certification of Secure Destruction of all existing active and archived originals and/or copies of all DOI -Activity-Related files and information, including but not limited to all records, files, and metadata in electronic or hardcopy format, by procedures approved by DOI in advance and in accordance with applicable DOI IT Security Policy Requirements, including but not limited to the following:
1. provided by DOI; or
2. obtained by the Contractor while conducting activities in accordance with the contract with DOI; or
3. distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity; or
4. received from the Contractor by any other related organization and/or any other component or separate business entity.
(c) This certification must be provided by a third party firm approved by DOI in advance. All costs and resource allocations required for this third party service must be the sole responsibility of the Contractor.
1.6 Mandatory Requirement for Contractor Return of all DOI-Owned and Leased Computing and Information Storage Equipment
The disposition of all computing and information storage equipment will be at the written direction of the COR. Items returned to the Government shall be hand carried or sent by certified mail to the COR.
(a) Within sixty (60) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or by the Contractor for any reason; or within a time period approved by DOI, the Contractor must return all DOI-owned and leased computing and information storage equipment.
(b) Within seventy-five (75) days after the end of the contract performance period or after the contract is suspended or terminated by DOI or the Contractor for any reason, the Contractor must provide DOI with Certification of Verified Return of all DOI-Owned and Leased Computing and Information Storage Equipment. This certification must be provided by a third party firm approved by DOI in advance. All costs and resource allocations required for this third party service must be the sole responsibility of the Contractor.
1.7 Information/Data Ownership and Access
(a) All documents produced under this contract are the property of the U.S. Government and cannot be reproduced, or retained by the Contractor, even if the contract is revoked by either party for any reason. All appropriate project documentation will be given to the agency during and at the end of this contract in an acceptable and usable format, which may include the original format, at no additional cost to DOI. The Contractor shall not release any information without the written consent of the CO.
(b) The Government retains unrestricted rights to all Government data. DOI retains ownership of any and all user created/loaded data and applications hosted on the Contractor’s infrastructure, as well as maintains the right to request full copies of these at any time.
(c) The preliminary and final deliverables and all associated working papers and other material deemed relevant by the agency that have been generated by the Contractor in the performance of this contract, are the property of the U.S. Government and must be submitted to the COR at the conclusion of the contract in an acceptable and usable format, which may include the original format, at no additional cost to DOI. The U.S. Government has unlimited data rights to all deliverables and associated working papers and materials in accordance with FAR 52.227-14.
(d) The Contractor acknowledges DOI’s exclusive right of ownership of the information and is required to transfer or return (or delete) all agency data collected, processed, stored or maintained by Contractor on behalf of DOI upon termination of services, and shall provide written certification and supporting documentation attesting to the return of agency data collected, processed, maintained, or stored by the Contractor. Contractor shall provide DOI logical and physical access to Contractor’s facilities, installations, technical capabilities, operations, records, and databases upon request to verify the Contractor’s certification for the return or removal of agency data.
(e) DOI information stored in the Contractor’s or Service Provider’s (SP) network and computing environments remain the property of DOI, not the Contractor or SP. DOI retains ownership of the information and any media type that stores Government information. The Contractor or SP do not have rights to the DOI information for any purposes other than those explicitly stated in the contract. The Contractor and SP must protect DOI information from unauthorized access by Contractor and SP personnel, other Contractors, or other SP subscribers. The Contractor and SP must allow DOI full access to DOI information including data schemas, metadata, and other associated data artifacts that are required to ensure DOI can fully and appropriately retrieve DOI information from all of the Contractor or Service Provider environments that have been utilized to store, read, or process DOI’s information.
(f) The Contractor shall treat all deliverables under the contract as the property of the U.S. Government for which DOI and any of its designated officials shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable without the express permission of the CO or COR.
(g) The Contractor is required to obtain the CO’s approval prior to engaging in any contractual relationship (sub-Contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, this contract. The Contractor (and any sub-Contractor) is required to abide by Government and DOI guidance for protecting sensitive and proprietary information.
(h) At the expiration of the contract, the Contractor shall return all sensitive DOI information and IT resources provided to the Contractor during the contract, and certify to the CO and COR that all DOI information has been sanitized or purged from any Contractor-owned system following the template provided in NIST Special Publication 800-88 Guidelines for Media Sanitization. DOI reserves the right, and the Contractor shall cooperate with DOI officials, to conduct reviews to ensure that the security and privacy requirements in the contract are implemented and enforced.
(i) The Contractor shall keep the information confidential, use appropriate safeguards to maintain its security in accordance with minimum Federal standards. Contractor must also explain and certify that its sub-Contractor(s) will adhere to the same minimum Federal standards when working with sensitive data.
(j) The Contractor’s invoicing, billing, and other financial, administrative records or databases may not store or include any sensitive Government information, such as PII, created, obtained, or provided during the performance of the contract. It is acceptable to list the names, titles and contact information for the CO, or other designated agency official associated with the administration of the contract in the invoices as needed.
Section 2 - Information Assurance Requirements
2.1 Compliance with IT Security Policies
(a) Information systems and system services provided to DOI by the Contractor must comply with current DOI IT Security and Privacy Control Standards, privacy policies and other related guidance.
(b) Contractors are also required to comply with current Federal regulations and guidance found in FISMA, the Privacy Act of 1974, Section 208 of the E-Government Act of 2002, NIST, FIPS and the NIST 800-Series Special Publications, OMB memorandum, and other relevant Federal laws and regulations that DOI must comply with.
2.2 Information Types
The term Information is synonymous with data, regardless of format or medium. Information shall be managed in accordance with applicable laws, regulations, executive orders, and policies regarding the safeguarding and dissemination of CUI. PII is a subset of information designated as CUI, and Sensitive PII is a subset of PII that requires additional controls and safeguards. All requirements for Sensitive Information apply to PII and Sensitive PII. All requirements for PII apply to Sensitive PII.
2.2.1 Sensitive Information
Sensitive Information is any information, which if lost, compromised, or disclosed, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual, the Government, or the Government’s interests. Sensitive Information is subject to stricter handling requirements because of the increased risk if the data is compromised. Some categories of Sensitive Information include financial, medical or health, legal, proprietary, strategic and business, human resources, PII, and Sensitive PII. These categories of information require appropriate protection as stand-alone information and may require additional protection in aggregate.
2.2.2 Personally Identifiable Information (PII)
PII, as defined in OMB Circular A-130, refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information that is publicly available — in any medium and from any source — is or can be combined to identify an individual. As an example, PII includes a name and an address because it uniquely identifies an individual, but alone may not constitute Sensitive PII.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
2.2.3 Sensitive PII
Sensitive PII is a subset of PII, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Sensitive PII can be used to target, harm, or coerce an individual or entity, assume or alter an individual’s or entity’s identity, or alter the outcome of an individual’s or entity’s activities. Sensitive PII requires stricter handling because of the increased risk to an individual or associates if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as SSNs, driver’s license number, financial account number, or biometric identifiers such as fingerprint. Additional information used in conjunction with the identity of an individual (directly or indirectly inferred) such as date of birth, citizenship status, criminal history, medical information, and system authentication information (account passwords, personal identification numbers (PINs) are also considered Sensitive PII. In addition, the context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or complaint.
2.3 Information Security Incidents
An Information Security Incident is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or Sensitive Information.
(a) The Service Provider shall not impose on DOI employees or Contractors any additional requirements other than those articulated in DOI policies (e.g., IT Security, Privacy, Human Resources acceptable use policy, etc.) nor impose any penalties or sanctions on, or against, DOI employees for resolution of policy violations and accept that DOI’s handbook on Charges and Penalty Selection for Disciplinary and Adverse Actions, and associated Table of Penalties, are acceptable and to be applied at the management discretion of the agency.
2.3.1 Information Security Incident Reporting Requirements
All Information Security Incidents must be reported in accordance with the requirements below even if it is believed the incident may be limited, small, or insignificant. DOI will determine when an incident requires additional focus and attention.
(a) Contractor employees must report all information security incidents to the DOI Computer Incident Response Center (DOI-CIRC) immediately, and no later than 1 hour after becoming aware of the incident, at: DOICIRC@ios.doi.gov, (703) 648-5655, regardless of day or time.
(b) When notifying the DOI-CIRC, copy the CO and COR if possible, or if reporting by phone or CO’s or COR email is not immediately available, contact the CO and the COR immediately after reporting the incident to DOI-CIRC. The Contractor is responsible for positively verifying that notification was received and acknowledged by the CO or the COR.
(c) If you have questions regarding these procedures, please contact the CO or the COR.
(d) Contractor shall NOT include any Sensitive Information in the subject or body of any e-mail. Contractor shall transmit Sensitive Information using NIST Federal Information Processing Standard (FIPS) 140-2, Security Requirements for Cryptographic Modules, compliant encryption methods to protect Sensitive Information in email attachments. Passwords must not be communicated in the same email as the attachment. Contractor should contact the CO or COR if encryption software is needed.
(e) Contractor employees must also provide any supplementary information or reports related to a previously reported incident directly to the DOI-CIRC with the following text in the subject line of the email: “Supplementary Information/Report related to previously reported incident # [insert number].”
2.3.2 Information Security Incident Response Requirements
(a) The Service Provider shall establish incident response and recovery procedures and practices that integrate DOI Computer Incident Response Center (DOI-CIRC) and DOI Advanced Security Operations Center (ASOC) incident and breach detection, reporting, notification, handling, response, containment, eradication and recovery processes and that adequately inform DOI senior agency officials, AO, Information System Owner, and Information System Security Officer (ISSO) of incidents, remediation and containment actions.
(b) The Service Provider shall immediately report all incidents, whether suspected or confirmed, involving potential risks to the confidentiality, integrity or availability of DOI’s information or to the function of provided systems operated on behalf of DOI, to the DOI-CIRC, DOI Contracting Officer and DOI System Owner. The Service Provider shall report computer security incidents and breaches affecting DOI data/information or to the function of provided systems in accordance with the DOI Enterprise Computer Security Incident Response Plan. The Service Provider shall promptly coordinate with the DOI System Owner and DOI-CIRC on all related incident handling, response, containment, eradication, and recovery efforts throughout the incident lifecycle until fully resolved to the satisfaction of the DOI System Owner.
(c) Upon becoming aware of any unlawful access to any DOI data/information stored on the Service Provider’s equipment or in the Service Provider’s facilities, or unauthorized access to such facilities or equipment resulting in loss, disclosure or alteration of any DOI data/information (a “Security Incident”), the Service Provider will:
(i) immediately notify the CO and COR’s via email with details of the Security Incident;
(ii) investigate the Security Incident and provide DOI with detailed information about the Security Incident; and
(iii) take reasonable steps to mitigate the effects and to minimize any damage resulting from the Security Incident.
(d) The Service Provider shall document a set of procedures for DOI approval and agreement for what DOI needs to perform to take an application offline (whether a software patch is going to be installed by the provider or subscriber), the testing that must be performed to ensure the application continues to perform as intended, and the procedures needed to bring the application back online. Plans for system maintenance should be expressed in a Service Level Agreement (SLA).
(e) All determinations related to information security incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services will be made by authorized DOI officials at DOI’s discretion.
(f) The Contractor and Contractor employees must provide full access and cooperation for all activities determined by DOI to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of information security incidents.
(g) Incident response activities determined to be required by DOI may include but are not limited to, inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the incident and/or liability for any additional response activities.
(h) DOI, at its sole discretion, may obtain the assistance of Federal agencies and/or third party firms to aid in incident response activities, as needed.
(i) The Contractor is responsible for all costs and related resource allocations required for all subsequent incident response activities determined to be required by DOI, whether incurred by DOI, agents under contract or on assignment to DOI, or by third party firms.
2.4 Contractor Policy Document for Protection of Sensitive Information
(a) The Contractor is responsible for the proper handling and protection of Sensitive Information to prevent unauthorized disclosure. All Contractor employees are required to complete and sign both 1) a Non-disclosure Agreement granting conditional access to CUI information to guarantee the protection and integrity of Government information and documents and 2) a certificate of no conflict of interest before starting work under the contract.
(b) The contract deliverables shall be labeled “CONTROLLED UNCLASSIFIED INFORMATION” (CUI). External transmission/dissemination of For Official Use Only (FOUO) and CUI to or from a Government computer must be encrypted. Certified encryption modules must be used in accordance with the most current version of FIPS PUB 140, “Security requirements for Cryptographic Modules.”
(c) The Contractor must produce an attestation document requiring approval by the CIO, or designate, providing details regarding how the Contractor is protecting and handling sensitive DOI information. The attestation must address the following, at a minimum:
1. Proper marking, control, storage and handling of Sensitive Information residing on electronic media, including computers and removable media, and on paper documents.
2. Proper control and storage of mobile technology, portable data storage devices, and communication devices.
3. Proper use of FIPS 140-2 compliant encryption methods to protect Sensitive Information while at rest and in transit throughout DOI, Contractor, and/or sub-Contractor networks, and on host and client platforms.
4. Proper use of FIPS 140-2 compliant encryption methods to protect Sensitive Information in email attachments, including policy that passwords must not be communicated in the same email as the attachment.
5. Information Security Incidents.
6. Contractor Access to DOI IT Systems.
7. IT Security Awareness Training.
8. Specialized IT Security Awareness Training for Security Staff.
9. Information Systems Policy Compliance requirements and procedures.
10. Contract Performance Information.
2.5 Design and Technical Architecture Requirements
(a) The Contractor provided solution shall integrate with DOI’s Identity, Authorization and Access Management (IdAAM) solution. This solution consists of the Microsoft Active Directory (AD) and Public Key Infrastructure (PKI) architecture and associated Certificate Authority and DOI HSPD-12 PIV Smart Card-based credentials. The Contractor provided solution must not require direct integration with, colocation of, or direct access to DOI’s AD environment or Domain Controllers. DOI’s AD architecture includes Active Directory Federated Services (ADFS) that provide reliable authentication services via Security Assertion Markup Language (SAML). The Contractor provided solution must support DOI’s SAML-based authentication services to meet all authentication needs and requirements of both DOI and the Contractor provided solution. Such Contractor provided solutions must enable logical authentication utilizing those credentials without requiring additional Contractor provided solution credentials. DOI uses Microsoft’s Active Directory to create a single DOI-wide directory of all users. This directory is known as the Enterprise Active Directory (EAD). The Contractor provided solution must recognize the EAD as the authoritative source for authentication. DOI authenticates users with username and password; however, the Department is transitioning to Entrust PKI for authentication. The system shall support authentication using DOI’s Entrust Public Key Infrastructure (PKI). In the future, all users shall be authenticated with the Entrust PKI and use the Homeland Security Presidential Directive (HSPD-12) Personal Identity Verification (PIV) Smart Card. At this time, some users will continue to be authenticated by username and password which must be supported by the Contractor provided solution.
(b) The Contractor shall support the enablement and use of strong authentication tokens in accordance with the Federal Identity, Credential, and Access Management (FICAM) implementation guidance, HSPD-12 Directive, and applicable National Institute of Standards and Technology (NIST) standards and guidelines regarding use of the PIV Smart Card logical authentication credentials for access to the Contractor provided environment, software, applications, services or infrastructure by either the Contractor, authorized system administrators and end-users in a manner that leverages DOI’s existing authentication infrastructure to mitigate the risk of account compromise or hijacking.
2.6 Federal Information Security Modernization Act (FISMA) Compliance
2.6.1 Security Assessment and Authorization (A&A)
The Government will provide timely review of the Service Provider’s Assessment and Authorization (A&A) documentation package and any changes submitted by the Service Provider that could require re-assessment in order to assist the Government in its compliance with FISMA and the NIST 800-53 security control requirements. If there are any errors, omissions or other issues with the Provider’s A&A documentation package or assessment results, the Government will timely notify the Service Provider and provide reasonable descriptions of specific errors, omissions or other issues. The Government will reasonably coordinate with the Service Provider in the A&A process and will not unreasonably withhold or delay any review of A&A package documentation, assessment result from the independent assessor, or authorization decisions.
All A&A documents will be provided to the COR, DOI System Owner, and DOI Authorizing Official (AO) in both hard copy and electronic forms.
DOI may choose to cancel the contract/award and terminate any outstanding orders if the Service Provider has its authorization revoked and the deficiencies are greater than agency risk tolerance thresholds.
(a) This contract may require the Contractor to develop, deploy, and/or use information systems to access and/or store Government information, including Sensitive Information. The Contractor must provide a detailed outline of its present and proposed information systems security program and demonstrate that it complies with the Federal Information Security Modernization Act of 2014 (44 U.S.C. Chapter 35) as well as applicable Department of the Interior (DOI) policies and security requirements based on the Federal Information Processing Standard (FIPS) 199 categorization provided by DOI. The Contractor facilities must also meet the security requirements for the same impact level or greater as defined by the FIPS 199 categorization provided by DOI.
(b) All new IT systems, including outsourced systems, Major Applications (MA) or General Support Systems (GSS) and significant upgrades to systems must be assessed and authorized in keeping with FISMA and National Institute of Standards and Technology (NIST) standards. These Assessment and Authorization (A&A) requirements also apply to systems that are already built and are utilized by DOI organizations under a contract with the Service Provider for the system (DOI data uploaded to the system). Such systems must meet the IT security and privacy requirements and ongoing requirements set forth within this document, including the eighteen DOI Security and Privacy Control Family Standards that correspond to the NIST Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, which identify additional required control enhancements and that specify DOI-defined control parameters and additional unique DOI-specific controls.
(c) All information systems that input, store, process, and/or output Government information must be provided an Authorization to Operate (ATO) signed by the the cognizant Authorizing Official (AO) designated by the Department’s Chief Information Officer (CIO). The Contractor must adhere to current DOI policies, procedures, and guidance for security Assessment and Authorization (A&A) activities.
(d) The Contractor will work with DOI to define a clearly demarcated security authorization boundary for the the information system (e.g., all associated networks, servers, applications, databases, storage, and other supporting systems and devices.
(e) All information systems must undergo FISMA-compliant security A&A prior to going into production and undergo Continuous Monitoring, as described herein.
(f) In accomplishing and maintaining A&A, the Contractor must follow the current version of the following:
· NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems
· NIST SP 800-30, Guide for Conducting Risk Assessments
· NIST SP 800-34, Contingency Planning Guide for Federal Information Systems
· NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach
· NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
· NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
· NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories
· NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
· NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
· NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations
· FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
· FIPS 200, Minimum Security Requirements for Federal Information and Information Systems
· DOI Security and Privacy Control Standards
· DOI Privacy Impact Assessment Guide
(g) Prior to Security A&A, a Privacy Impact Assessment (PIA) for all systems must be completed and provided to the DOI Privacy Officer, or designate, for a determination. PIAs must identify privacy controls implemented for systems and must be completed in accordance with the DOI Privacy Impact Assessment Guide.
(h) FIPS 199 must be utilized to determine the security categorization (High, Moderate, or Low) for Contractor information technology (IT) systems and security control baseline requirements. The cognizant AO must provide written and signed approval of the FIPS 199 security categorization. The DOI CIO or responsible AO have the authority to change the categorization rating based on additional knowledge of threats and vulnerabilities, as needed.
(i) Security A&A documentation must be developed with the use of 1) DOI security documentation templates, as adapted for Contractor IT systems for services and systems that are not cloud-based, or 2) the templates provided by the Federal Risk Authorization and Management Program (FedRAMP) provided at https://www.fedramp.gov/resources/templates-2016/. Templates are available for services and systems that are not cloud-based for all security documentation including System Security Plan (SSP), Security Assessment Report (SAR), Contingency Plan, Incident Response Plan, etc. The Security A&A process must be followed throughout the IT system lifecycle process to ensure proper oversight by DOI.
(j) The Contractor will provide supporting documentation to DOI as necessary in support of the A&A process.
(k) The Authorizing Official (AO) for the system will be the government official formally designated by the DOI authorized senior executive.
The Level of Effort for the A&A is based on the System’s NIST FIPS 199 categorization. The Contractor shall create, maintain and update the following documentation:
· Privacy Impact Assessment (PIA)
· Test Procedures and Results
· Security Assessment Report (SAR)
· System Security Plan (SSP)
· System Privacy Plan
· IT System Contingency Plan (CP)
· IT System Contingency Plan (CP) Test Results
· Plan of Action and Milestones (POA&M)
· Continuous Monitoring Plan (CMP)
· Control Tailoring Workbook
· Control Implementation Summary Table
· Results of Penetration Testing
· Software Code Review
· Interconnection Agreements/Service Level Agreements/Memorandum of Agreements
Identified gaps between required security and privacy controls and the Service Provider's implementation as documented in the SAR shall be tracked by the Service Provider for mitigation in a POA&M document and communicated to the DOI Authorizing Official, System Owner and Information Systems Security Officer (ISSO) immediately and remediation status routinely on a quarterly basis thereafter. Depending on the severity of the gaps, the Government may require them to be remediated before a provisional authorization is issued.
The Service Provider, using an independent assessor approved by the DOI Authorizing Official (AO), will perform the A&A of the provided information system developed or maintained hereunder prior to going into production.
Subsequent to the initial authorization to operate, required to be formally approved by the DOI AO, DOI requires that the provided information system follow the ongoing authorization process and associated continuous monitoring requirements as prescribed by OMB and NIST. The Service Provider shall maintain an Information Security Continuous Monitoring (ISCM) program that meets or exceeds the requirements specified in this Contract/Task Order and minimally meets the latest editions of the DOI Security and Privacy Control Family Standards and NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. All controls shall be assessed in accordance with the NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations. The Service Provider shall assess the effectiveness of required implemented controls on an ongoing basis and whenever there is a significant change to the system’s security posture in accordance with the system’s Continuous Monitoring Plan.
The Service Provider is responsible for mitigating all security risks found during A&A and continuous monitoring activities.
2.6.1.1 Security Controls
Where the security control requirements outlined herein cannot be met, at the discretion of and approval by the DOI Authorizing Official (AO), either:
· other alternative mitigating/compensating controls can be offered by the Service Provider for consideration and approval by the DOI AO;
· the DOI AO can formally document and accept the associated risk of not implementing a control or the residual risk level resulting from partial risk mitigation; or
· the DOI AO can reject risk acceptance and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .