B08_Atch_A_0002.pdf

PDF 367 KB Posted

Attached to
DIGITAL RADIOGRAPHY Federal contract opportunity
Solicitation number
140G0223Q0191
Issued by
Department of the Interior US Geological Survey Office of Acquisitions and Grants

About this file

This document outlines security requirements for a federal solicitation seeking digital radiography services. The solicitation is number 140G0223Q0191 issued by the Department of the Interior's US Geological Survey Office of Acquisitions and Grants. Respondents must address requirements for background investigations, non-disclosure agreements, training, personnel changes, contractor location, applicable standards, asset valuation and categorization, property rights, independent verification and validation, certification and accreditation, quality control, self-assessments, vulnerability analysis, security controls, and contingency planning. The document also includes instructions to offerors regarding providing accessibility conformance reports and describing their approach, plans, scenarios and acceptance criteria to ensure compliance with Section 508 accessibility standards.

View the file

Other files for this federal contract opportunity

Other files attached to DIGITAL RADIOGRAPHY, newest first.
File Type Posted
Sol_140G0223Q0191_Amd_0002.pdf PDF
Sol_140G0223Q0191_Amd_0001.pdf PDF
Sol_140G0223Q0191.pdf PDF
A06_Salient_Characteristics_-_Copy.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFQ 140G0223Q0191 – Digital Radiography

GS0335 FISMA DEC 2011

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

1 N/A ☐

Background Investigations. The Contractor shall perform in accordance with clause “Security Requirements:

Facility Access and Information Technology.”

2 N/A ☐

Contractor will have access to Privacy Act System of Records – Work under this contract will involve design, development or operation of (access to) system(s) of records containing personal information protected by the Privacy Act (5 U.S.C.

Section 552a).

Non-disclosure Agreement. Prior to receiving access to USGS computers, contractor employees shall be required to sign nondisclosure or other system security agreements, depending on the systems to be used and level of access granted.

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

User Access to USGS IT Systems known to contain sensitive or proprietary data

IT Support services (greater than user access) Development or Maintenance of Custom Applications On-site contractor support and management of IT system Off-site contractor Oversight and Management of IT

System IT Security Services

Privacy Act System: [Identify covered system(s) to which the contractor may have access] Click or tap here to enter text.

Work to be performed: [Summarize nature of the contractor's use of such records, such as]

User-level access to system containing protected records Operation or maintenance of Privacy Act System of records or computers hosting such system Design or modification of a Privacy Act system of records]

The contractor is not required or permitted to respond to requests for Privacy Act data or to make decisions about releases of data under the Act. Contractor shall ensure its employees are instructed to safeguard against improper use or release of such data and advise them that violation of the Act may involve criminal penalties. The contractor will comply with FAR clause 52.224-2, Privacy Act, incorporated herein by reference and with DOI Privacy Act regulations at 43 CFR 2, Subpart D

3 N/A ☐

Training. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology” - Contractor employees must successfully complete DOI’s end- user computer security

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

awareness training prior to being granted access to DOI data or being issued a user account. Training must be renewed annually. Additionally, the contract employees must sign a Statement of Responsibility (SOR) that states they have read the appropriate Rules of Behavior and other applicable Information security policies.

4 N/A ☐

Personnel Changes. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology” - The contractor must notify the COR immediately when an employee working on a DOI system is reassigned or leaves the contractor’s employ.

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

User Access to USGS IT Systems known to contain sensitive or proprietary data

IT Support services (greater than user access) Development or Maintenance of Custom Applications * On-site contractor support and management of IT system Off-site contractor Oversight and Management of IT

System IT Security Services *

*May not be applicable for off-site performance.

5 N/A ☐

Contractor Location. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

User Access to USGS IT Systems known to contain sensitive or proprietary data

IT Support services (greater than user access) Development or Maintenance of Custom Applications On-site contractor support and management of IT system Off-site contractor Oversight and Management of IT

System IT Security Services

No portion of the services to be performed hereunder may be performed outside the United States without the express written permission of the Contracting Officer.

Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

If services are proposed to be performed abroad, the Contractor shall provide an acceptable security plan that addresses mitigation of problems related to communication, control, and protecting the confidentiality, integrity, and availability of IT systems and information.

A Security Plan Template is available upon request from the Contracting Officer.

6 N/A ☐

N/A Applicable Standards. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology” - Contractor must follow the DOI System Development Life Cycle (SDLC), NIST SP 800-64 and the DOI SDLC Security Integration Guide.

7 N/A ☐

Asset Valuation-Security Categorization: The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

☐User Access to USGS IT Systems - The Government is responsible for security categorization on USGS systems to which the Contractor may have access under this contract.

☐IT Support Services greater than User-Level Services Choose One:

☐The Government is responsible for security categorization on USGS systems to which the Contractor may have access under this contract.

☐The Government has defined the [insert name of system to be developed, operated or maintained by the contractor] to be a [Major Application], [Minor Application] or [General support system] as defined in OMB Circular A-130, Appendix III and NIST SP800-

53. The following risk and sensitivity levels have been assigned based on the FIPS 199 and the NIST SP 800-60.

Mission impact: Click or tap here to enter text.

Data sensitivity:Click or tap here to enter text.

Risk Level:Click or tap here to enter text.

Bureau/departmental/national criticality:

Click or tap here to enter text.

☐Off-Site Oversight and Management of IT System- The Contractor shall use the FIPS 199 and the NIST SP 800-https://insight.usgs.gov/aei/offices/oa/oag/AOP/guidefordevelopingsecurityplans.pdf

Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.

☐IT Security Services - Applies only if the purpose of the contract includes obtaining asset valuation services. The Contractor shall use the FIPS 199 and the NIST SP 800- 60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.

8 ☒

The Government shall be granted unlimited rights in software or data produced hereunder as described in FAR clause 52.227-17, Rights in Data— Special Works, incorporated by reference herein.

Select either COTS or custom software language as applicable. If both apply, identify software/data deliverables governed by each clause.

Property Rights.

For Federal Supply Schedule orders or orders under an existing contract, rights to software acquired hereunder are set forth in the basic contract.

For open market contracts, the Government's rights in software delivered hereunder shall be as described in software developer's commercial software license agreement or the clause FAR 52.227-19, Commercial Computer Software- Restricted Rights, whichever is greater.

9 N/A ☐

Independent Verification and Validation (IV&V). The Government is responsible for independent software verification and validation prior to being moved into production.

On-Site Contractor Support and Management of IT System Choose One:

Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

☐Software will be independently verified and validated by the Government or another selected contractor prior to being moved into production.

☐Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide

☐Off-Site Contractor Operation and Management of IT System Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide

☐IT Security Service - Applies only if the purpose of the contract includes obtaining IV&V services.

10 N/A ☐ Applies if the purpose of the contract includes obtaining C&A services.

Certification & Accreditation.

☐User Access to USGS IT Systems or IT Supports Services (Greater than User Access) Certification and Accreditation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

☐Development or Maintenance of Custom Applications The contractor will perform Certification and Accreditation (C&A) services on the application developed or maintained hereunder prior to going into production. The application must be re-accredited every three years or whenever there is a major change that affects security. C&A documents will be provided to the COR in both hard copy and electronic forms. The contractor must follow NIST SP 800-37, 800-18, 800-30, 800-60, 800-53A, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment.

NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/ FIPS documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor may request copies of DOI documents by contacting the http://csrc.nist.gov/publications/nistpubs/ http://csrc.nist.gov/publications/nistpubs/

Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

Contracting Officer. The government reserves the right to conduct the ST&E using either Government personnel or an independent contractor. The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.

☐On-Site Contractor Support and Management of IT System or Off-Site Contractor Operation and Management of IT System The Contractor must maintain systems that are compliant with NIST SP 800-18, 800-30, 800-37, 800-53A, 800-60, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment. As required by the above, Major Applications and General Support Systems shall be certified and accredited (C&A) prior to going into production and re-accredited every three years or whenever there is a major change that affects security.

C&A documents will be provided to the COR in both hard copy and electronic forms. NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor may request copies of DOI documents by contacting the Contracting Officer. The government will reserve the right to conduct the ST&E, using either Government personnel or an independent contractor. The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.

11 N/A for COTS

HW & SW,

User Access to

USGS IT

Systems (other than IT services), IT Support Services (User Level or greater access)

N/A ☐

Internet Logon Banner. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

☐Develop or Maintenance of Custom Applications or Onsite Contractor Support and Management of IT System or Off-site Contractor Oversight and Management of IT System – Web based applications developed or maintained under this contract must contain a USGS approved logon Banner:

https://portal.doi.net/CIO/ITPMgmt/Documents/IT Standards/IT Security/DOI Security Control Standards (based on NIST SP 800-53 Revision 3)/Access Control v1.4.pdf

12 N/A ☐

Incident Reporting. The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information http://csrc.nist.gov/publications/nistpubs/ https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf

Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

Technology” - The contractor must report computer security incidents affecting DOI data or systems in accordance with the DOI Computer Incident Response Guide.

13 ☐

Quality Control. All software or hardware purchased must be free of malicious code such as viruses, Trojan horse programs, worms, spyware, etc. Validation of this must be written into the contract.

14 N/A N/A ☐

Self-Assessment. The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” - The contractor must conduct an annual self-assessment in accordance with annual DOI guidance on all information systems in production.

15 N/A ☐

Vulnerability Analysis. Vulnerability Analysis on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

16 N/A ☐

Logon Banner. Contractor employees who access DOI information systems must acknowledge a government-approved legal warning banner prior to logging on to the system. This includes contractor owned information systems hosting DOI data.

17 N/A ☐

Security Controls.

The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” – The Contractor shall ensure compliance with the security control requirements of the current version of NIST SP 800-53, Rev.1, which are applicable to the security categorization of the data or system. FIPS 199 and the NIST SP 800-60 will be used to determine information types and security categorizations.

18 N/A N/A ☐

Contingency Plan.

The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology.”

For IT Support Services: The Contractor shall submit a contingency plan in accordance with NIST SP 800-34 and DOI IT Systems Contingency Plan Guide.

ICT ACCESSIBILITY REQUIREMENTS STATEMENT PER SECTION 508 OF THE REHABILITATION ACT

Digital Radiography

E201.1 Scope ICT that is procured, developed, maintained, or used by agencies shall conform to the Revised 508 Standards.

E205.1 General Electronic content shall comply with E205.

E205.2 Public Facing Electronic content that is public facing shall conform to the accessibility requirements specified in E205.4.

E205.3 Agency Official Communication Electronic content that is not public facing shall conform to the accessibility requirements specified in E205.4 when such content constitutes official business and is communicated by an agency through one or more of the following:

● A. An emergency notification;

● B. An initial or final decision adjudicating an administrative claim or proceeding;

● C. An internal or external program or policy announcement;

● D. A notice of benefits, program eligibility, employment opportunity, or personnel action;

● E. A formal acknowledgement of receipt;

● F. A survey questionnaire;

● G. A template or form;

● H. Educational or training materials; or

● I. Intranet content designed as a Web page.

E205.4 Accessibility Standard (WCAG 2.0) - Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (Incorporated by reference, see 702.10.1).

E206.1 General. Where components of ICT are hardware and transmit information or have a user interface, such components shall conform to the requirements in Chapter 4.

E207.1 General Where components of ICT are software and transmit information or have a user interface, such components shall conform to E207 and the requirements in Chapter 5

Exception from E207.1 General: Software that is assistive technology and that supports the accessibility services of the platform shall not be required to conform to the requirements in Chapter 5.

E207.2 WCAG Conformance User interface components, as well as the content of platforms and applications, shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).

Exceptions from E207.2 WCAG Conformance:

● Software that is assistive technology and that supports the accessibility services of the platform shall not be required to conform to E207.2.

● Non-web software shall not be required to conform to the following four Success Criteria in WCAG 2.0: 2.4.1 Bypass Blocks; 2.4.5 Multiple Ways; 3.2.3 Consistent Navigation; and 3.2.4 Consistent Identification.

● Non-Web software shall not be required to conform to Conformance Requirement 3 Complete Processes in WCAG 2.0.

E208.1 General Where an agency provides support documentation or services for ICT, such documentation and services shall conform to the requirements in Chapter 6.

E301 General

E301.1 Scope. The requirements of Chapter 3 shall apply to ICT where required by 508 Chapter 2 (Scoping Requirements), 255 Chapter 2 (Scoping Requirements), and where otherwise referenced in any other chapter of the Revised 508 Standards or Revised 255 Guidelines.

E302 Functional Performance Criteria

302.1 Without Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that does not require user vision.

302.2 With Limited Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited vision.

302.3 Without Perception of Color. Where a visual mode of operation is provided, ICT shall provide at least one visual mode of operation that does not require user perception of color.

302.4 Without Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that does not require user hearing.

302.5 With Limited Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited hearing.

302.6 Without Speech. Where speech is used for input, control, or operation, ICT shall provide at least one mode of operation that does not require user speech.

302.7 With Limited Manipulation. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that does not require fine motor control or simultaneous manual operations.

302.8 With Limited Reach and Strength. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.

302.9 With Limited Language, Cognitive, and Learning Abilities. ICT shall provide features making its use by individuals with limited cognitive, language, and learning abilities simpler and easier.

501.1 Scope - The requirements of Chapter 5 shall apply to software where required by 508 Chapter 2 (Scoping Requirements), 255 Chapter 2 (Scoping Requirements), and where otherwise referenced in any other chapter of the Revised 508 Standards or Revised 255 Guidelines.

Exception from E501.1 Scope: Where Web applications do not have access to platform accessibility services and do not include components that have access to platform accessibility services, they shall not be required to conform to 502 or 503 provided that they conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).

502.1 General - Software shall interoperate with assistive technology and shall conform to 502.

Exception from E502.1 General: ICT conforming to 402 shall not be required to conform to 502.

503.1 General Applications shall conform to 503.

602.1 General.Documentation that supports the use of ICT shall conform to 602.

602.2 Accessibility and Compatibility Features. Documentation shall list and explain how to use the accessibility and compatibility features required by Chapters 4 and 5. Documentation shall include accessibility features that are built-in and accessibility features that provide compatibility with assistive technology.

602.3 Electronic Support Documentation. Documentation in electronic format, including Web-based self-service support, shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).

602.4 Alternate Formats for Non-Electronic Support Documentation. Where support documentation is only provided in non-electronic formats, alternate formats usable by individuals with disabilities shall be provided upon request.

603.1 General. ICT support services including, but not limited to, help desks, call centers, training services, and automated self-service technical support, shall conform to 603.

603.2 Information on Accessibility and Compatibility Features. ICT support services shall include information on the accessibility and compatibility features required by 602.2.

603.3 Accommodation of Communication Needs. Support services shall be provided directly to the user or through a referral to a point of contact. Such ICT support services shall accommodate the communication needs of individuals with disabilities.

Instructions to Offerors

1 Provide an Accessibility Conformance Report (ACR) for each commercially available Information and Communication Technology (ICT) item offered through this contract. Create the ACR using the Voluntary Product Accessibility Template Version 2.1 or later, located at https://www.itic.org/policy/accessibility/vpat. Complete each ACR in accordance with the instructions provided in the VPAT template. Each ACR must address the applicable Section 508 requirements referenced in the Work Statement. Each ACR shall state exactly how the ICT meets the applicable standards in the remarks/explanations column, or through additional narrative.

All "Not Applicable" (N/A) responses must be explained in the remarks/explanations column or through additional narrative. Address each standard individually and with specificity, and clarify whether conformance is achieved throughout the entire ICT Item (for example - user https://www.itic.org/policy/accessibility/vpat functionality, administrator functionality, and reporting), or only in limited areas of the ICT Item.

Provide a description of the evaluation methods used to support Section 508 conformance claims. The agency reserves the right, prior to making an award decision, to perform testing on some or all of the Offeror’s proposed ICT items to validate Section 508 conformance claims made in the ACR.

2 Describe your approach to incorporating universal design principles to ensure ICT products or services are designed to support disabled users.

3 Describe plans for features that do not fully conform to the Section 508 Standards.

4 Describe "typical" user scenarios and tasks, including individuals with disabilities, to ensure fair and accurate accessibility testing of the ICT product or service being offered.

Acceptance Criteria

1 Prior to acceptance, the government reserves the right to perform testing on required ICT items to validate the offeror’s Section 508 conformance claims. If the government determines that Section 508 conformance claims provided by the offeror represent an inaccurate level of conformance than what is actually delivered to the agency, the government shall, at its option, require the offeror to remediate the delivered item to align with the required Section 508 conformance claims prior to acceptance.

File details come from the government source that posted it. Updated .