Attachment 4- IT Security Requirements_0002.pdf
PDF 122 KB Posted
- Attached to
- INSTALLATION OF FACILITY ACCESS CONTROL SECURITY S Federal contract opportunity
- Solicitation number
- 140G0121Q0054
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140G0121Q0054_Amd_0004.pdf | ||
| Attachment 5 - door schedule_0003.pdf | ||
| Sol_140G0121Q0054_Amd_0003.pdf | ||
| Attachment 3 - revisions_Appendix 1_0002.pdf | ||
| Sol_140G0121Q0054_Amd_0002.pdf | ||
| Sol_140G0121Q0054_Amd_0001.pdf | ||
| Attach 2 - Instructions for Site Visit.pdf | ||
| Attach - DOL Wage Determination.pdf | ||
| Sol_140G0121Q0054.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
140G0121Q0054 Amendment 2 ATTACHMENT 4
Section 508 Information Technology Security Requirements Summary
1. Background Investigation Contractor employees who will have access to federal Information Technology (IT) systems are subject to background investigations by the Federal Office of personnel Management. The level of investigation required will be the same as would be required for federal employees holding position involving similar duties. Work cannot begin on the DOI/USGS system until the background investigation has at least been initiated.
DOI Departmental Manual Part 441, Chapter 3, available at:
https://www.doi.gov/elips/search?doc_type=All&query=DOI+Departmental+Manual+Part+441%2C&archived=0 The manual provides level and procedural guidance for the appropriate background investigations based on types of access. The solicitation and contract should state the levels required for applicable labor categories or positions.
This position has been determined to be MODERATE RISK and requires a Minimum Background Investigation and credit check.
2. Non-disclosure Agreement Prior to receiving access to the USGS computers, contractor employees shall be required to sign non-disclosure or other system security agreements, depending on the systems to be used and level of access granted. The required non-disclosure agreement will be similar or may be customized as needed to reflect the data involved. Restrictions on use, duplication and disclosure of sensitive and proprietary data are covered in clause GS1406.
3. Training Contractor employees shall complete the USGS-defined Federal Information Systems Security Awareness computer security training before being granted system access and must renew the training annually.
Failure to complete training within the required timeframe may result in loss of system access for that user. Contractor employees with the significant IT security responsibilities shall also complete specialized role-based training as directed.
4. Personnel Changes The System Administrator will provide a list to the COR/Technical Liaison identifying contractor and subcontractor employees requiring access to the USGS systems for performance of work hereunder and will assign each person a unique user ID. The USGS Project Officer will be advised immediately when any of the personnel no longer require USGS computer access so that those IDs and access privileges can be cancelled. When possible, the COR must be notified in advance of any potential unfriendly termination of an employee or subcontractor.
5. Contractor Location The work will be performed on-site at USGS Wood Hole, MA.
6. Applicable Standards Not applicable.
7. Asset Valuation Not applicable.
8. Property Rights Not applicable.
140G0121Q0054 Amendment 2 ATTACHMENT 4
9. Independent Verification and Validation (IV & V) Not applicable.
10. Certification & Accreditation Not applicable.
11. Internet Logon Banner Not applicable.
12. Incident Reporting Contractor employees must report any computer security (viruses, intrusion attempts, system compromises, offensive e-mail, etc.) which may affect government data or systems in accordance with the DOI computer Security Incident Response Team Handbook (http://internet.usgus.gov/gio/security /doisirthandbook.doc) and as directed and described in (http://internal.usgs.gov/gio/security/irarticl.html).
Report computer security incidents to the USGS Help Desk or Security Point of Contact (SPOC). In many cases, your local system administrator is your Security Point of Contact. The Help Desk or SPOC will investigate and coordinate with the Computer Security Incident Response Team (CSIRT).
13. Quality Control (Malicious Code) All software and hardware shall be free of malicious code.
14. Self-Assessment Not applicable.
15. Vulnerability Analysis Vulnerability Analysis on USGS Systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.
16. Logon Banner When presented with the USGS logon banner, contractor employees shall read and acknowledge a Government approved logon warning.
17. Security Controls Not applicable.
18. Contingency Plan Not applicable – the Government is responsible for contingency planning.
File details come from the government source that posted it. Updated .