B08_ATT_1_SCOPE_OF_WORK.doc

DOC document 101 KB Posted

Attached to
Payment Card Industry Data Security Standards Services Federal contract opportunity
Solicitation number
140P2119R0023
Issued by
Department of the Interior National Park Service National Office

About this file

Attachment 1 - Scope of Work

View the file

Other files for this federal contract opportunity

Other files attached to Payment Card Industry Data Security Standards Services, newest first.
File Type Posted
140P2119R0023_AMENDMENT_0001_SF_30.pdf PDF
QUESTIONS_&_ANSWERS_140P2119R0023_AM_0001.pdf PDF
B08_140P2119R0023_COMBINED_SYNOPSIS_SOLICITATION.doc DOC document
B08_ATT_2_PAST_PERFORMANCE_QUESTIONNAIRE.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 0001

Scope of Work Document No.

140P2119R0023 Document Title

Payment Card Industry Data Security Standards (PCI-DSS) Services

Scope of Work:

1.0 BACKGROUND

The National Park Service (NPS) is a U.S. Federal Agency under the auspices of the U.S. Department of the Interior (DOI). The NPS manages more than 400 national parks, monuments, and other conservation areas and historic properties. The Recreation Fee Program oversees all credit card processing inside the NPS, which includes approximately 1000 merchant accounts that are collectively processing approximately 6 million credit card transactions annually. Each year the NPS is required by Treasury and its processor, WorldPay, to validate compliance with the Payment Card Industry Data Security Standards (PCI-DSS) requirements for all processing “payment channels.” As a credit card merchant, the NPS must meet appropriate Payment Card Industry (PCI) standards to securely process, store and transmit cardholder data.

The Recreation Fee Program manages all credit card processing activities whose merchant account is registered to the NPS through WorldPay (this excludes concessioners and other groups that have contractual relationships with the NPS outside the scope of this contract). The Recreation Fee Program issues guidance for establishing credit card processing merchant accounts, implementing credit card acceptance programs, purchasing credit card processing equipment and consulting with parks on PCI DSS related issues including recommendations for connectivity and processing appropriate to the site’s environment. The Recreation Fee Program also issues service wide updates on payment card industry banking initiatives.

Card Processing Venues: Credit card processing is not limited to the Recreation Fee Program but includes a cross section of programs across all of the NPS, including but not limited to: Special Park Users, Commercial Use Authorization permits, Wilderness/Backcountry permit fees, emergency services, administration/budget, etc.. Note that the scope of this initiative does not include PCI compliance for Recreation.gov (interagency reservation system), concessionaires (food service and lodging providers) or NPS cooperating and “friends” associations (e.g., gift shops and or books stores located in the parks).

Card Processing Devices: The NPS owns and leases a variety of point of sale devices and application(s) which provide fee collection and management for NPS fee-collecting parks, sites, and divisions.

Card Processing Environments: The NPS Point-of-Sale architecture is comprised of a hybrid architecture made up of on premise and cloud based systems and processes. The government will provide to the successful vendor a list of common controls that are managed at a global level (Department or Agency).

2.0 SCOPE

PCI Security Standards Policy Guidance

Successful vendor will provide guidance to the NPS on overall strategy regarding compliance with PCI security standards, development and interpretation of policies, advice and guidance on changes to PCI Data Security Standards, and remediation of specific issues uncovered during the SAQ process

PCI DSS Scope Reduction Guidance

· Successful vendor will provide the NPS with guidance on reduction of PCI scope, including:

· Guidance on deployment of Point to Point Encryption (P2PE) solutions

· Assessment and authoring of white papers on P2PE solutions leading to a reduction of PCI scope

· Reduction of applicable controls to those required by the P2PE SAQ

· Segmentation guidance Cardholder Data Environment (CDE)

· Successful vendor will be required to document the National Park Service cardholder data environment (CDE) in a secure digital medium that the Recreation Fee Program can work with during the PCI-DSS compliance processes.

· The CDE will catalog Network Components, Point-of-Sale (POS) systems On, Servers, Applications, Virtual Components and Third-party IT systems.

· Successful vendor will develop a maintenance process to keep the CDE up to date. The process will need to be approved by the National Park Service Recreation Fee Program before implementing.

· Successful vendor will update the CDE in accordance with the CDE maintenance process described above.

Self-assessment Questionnaires (SAQ)

· Successful vendor will determine which self-assessment questionnaire is applicable for each merchant account.

· Successful vendor will facilitate, collect, and input all data for all merchant accounts to complete PCI-DSS related self-assessment questionnaires into a system of their own choosing at no additional cost to the government.

· Successful vendor will filter merchant account responses and determine how self-assessments are aggregated using a secure digital medium that the Recreation Fee program can interact with.

Attestation of Compliance (AOC) Successful Qualified Security Assessor (ASQ) vendor will provide a PCI Attestation of Compliance (AOC) to the NPS Recreation Fee program annually. The AOC will be delivered to the National Park Service no later then January 10 of the subsequent year following completion of the SAQ.

PCI SSC Level 1 Penetration Testing and Vulnerability Scans

With each test and scan, should a vulnerability be uncovered the successful vendor will re-test or scan to validate remediation efforts were successful.

· Successful vendor will be required to provide quarterly vulnerability scanning across the NPS CDE

· Each scan report needs to be stored after each scan is completed

· Vulnerabilities identified in each scan will be compared to an established baseline from the NPS CDE and then a detailed report will be presented to NPS Recreation Fee program staff with applicable guidance on risk and possible remediation techniques and or steps.

· Successful vendor will be required to provide Annual level 1 penetration testing across the NPS CDE

· A penetration test report should be produced after each test. The report should focus on what data was compromised and how. The report should detail the actual method of the attack and exploit, the value of the exploited data, and recommendations for improving the NPS’s security posture across the CDE.

· Each penetration test report should be stored after each test report has been delivered to the Recreation Fee program staff.

5.0 DELIVERABLES

Table 1 List of Deliverables

Task
Required

Deliverables/Reports Required Due

Date Description of Deliverable Content

1
PCI Security Standards Policy Guidance
Ongoing

At the request of the Federal Government, vendor will provide the NPS with guidance on reduction of PCI scope, including but not limited to:

· Guidance on deployment of Point to Point Encryption (P2PE) solutions

· Assessment and authoring of white papers on P2PE solutions leading to a reduction of PCI scope

· Segmentation guidance Guidance may be delivered to the National Park Service in any format in which the government requests including, but not limited, to white papers, email, technical bulletins, or phone conversations

2
Cardholder Data Environment and Self-Assessment Questionnaires
CDE, Within 90 days of contract award

SAQ, September 1 of each calendar year

CDE and summary report are required within 90 days of contract award.

CDE summary will be updated and summary report is required at a minimum following the schedule below:

· updated 15 days post each vulnerability scan and each penetration test

· pre-and post SAQ

SAQ elicitation, documentation and response entries will begin September 1st of each calendar year.

3
Attestation of Compliance
January 10th of each subsequent calendar year.
Attestation of Compliance will be delivered to the National Park Service by 10th calendar day of subsequent year.
4
Annual PCI SSC Level 1 Penetration Testing and Vulnerability Scans
6/30
Scans will commence within 60 days of contract award. Quarterly scan will then follow schedule included:

· January 1 – 10th

· April 1 – 10th

· July 1 – 10th

· October 1 – 10th

Scan reports shall be delivered to the government on or before the 10th day of the quarter identified in the pattern above.

6.0 DELIVERY INSTRUCTIONS

CDE access shall be made available to the government within 90 days of contract award.

One copy of each report will be submitted to the Contracting Officer’s Representative. The contractor shall deliver each report in a mutually agreed upon format. Deliverables are to be transmitted with a cover letter, on the prime contractor’s letterhead, describing the contents. Any subsequent reports made to the Government will be made in the mutually agreed format.

7.0 TRAVEL

Contractor employees will not be required to travel for the purposes of providing PCI-DSS compliance services.

8.0 GOVERNMENT FURNISHED INFORMATION

· There is no anticipated need for Government Furnished Equipment relevant to providing the deliverables.

· The government will share all currently known government information related to the merchant accounts as well as IP addresses upon successful contract award.

· Architectural diagrams and/or documentation will not be provided.

9.0 GOVERNMENT POINTS OF CONTACT

Contracting Officer (CO):

Paula Johnson

Contracting Officer, WASO-WCO

7333 West Jefferson Avenue, Suite 100

Lakewood, CO 80235

Phone: 303-969-2407

Email Address: paula_johnson@nps.gov

Contracting Officer’s Representative (COR):

Joshua Bernick

Data Manager

Recreation Fee Program

12795 W. Alameda Parkway

Lakewood, CO 80228

Phone: 720-739-1597

Email: Joshua_bernick@nps.gov

10.0 PERIOD OF PERFORMANCE

The contractor shall begin performance immediately upon award, and continue through until contact completion, cancelation or termination. The period of performance for this project shall include one (1) base period plus four (4) one (1) period options, and shall be from:

Base Period:

May 20th, 2019 to May 19th, 2020

Optional Period One (1):

May 20th, 2020 to May 19th, 2021

Optional Period Two (2):

May 20th, 2021 to May 19th, 2022

Optional Period Three (3):

May 20th, 2022 to May 19th, 2023 Optional Period Four (4):

May 20th, 2023 to May 19th, 2024 Please note: These dates are estimated, and the actual dates will be determined at the time of award.

11.0 NON-DISCLOSURE

The contractor recognizes that in the performance of this contract it may receive or be exposed to information covered under the Privacy Act of 1974, and shall comply with all applicable safeguarding and handling requirements associated with Privacy Act information, including data provided on a proprietary basis by other contractors, equipment manufacturers and other private or public entities. The contractor shall agree to use and examine this information exclusively in the performance of this contract and to take the necessary steps in accordance with Government regulations to prevent disclosure of such information to any party outside the Government or Government designated support contractors. The contractor and all contractor personnel shall be required to sign Non-disclosure statement at the time of award. If violated, the Government reserves the right to require dismissal of the contractor employee(s).

All contractor employees will be required to sign a non-disclosure statement prior to any performance on this contract.

12.0 INVOICING AND FIRM FIXED PRICE SCHEDULE

Invoices may be submitted more than once per year, but no more than once per month, based upon actual work completed and submission of required deliverables as specified in the awarded contract, subject to the approval of the Contracting Officer and/or the designated COR. Invoices shall be submitted to the Invoice Processing Platform per Block 18a and in accordance with the procedures detailed in local clause Electronic Invoicing and Payment Requirements – Invoice Processing Platform (IPP) (APR 2013).

The price schedule applicable to this contract is as follows:

CONTRACT LINE ITEM NUMBER (CLIN)
CONTRACT LINE ITEM TITLE
QUANTITY
UNIT
UNIT PRICE
TOTAL PRICE
1
BASE PERIOD (05/20/2019-05/19/2020)
1
LS
$
$
TOTAL BASE PRICE (CLIN 1) ------------------------------------
$
2
OPTION PERIOD ONE (05/20/2020-05/19/2021)
1
LS
$
$
3
OPTION PERIOD TWO (05/20/2021-05/19/2022)
1
LS
$
$
4
OPTION PERIOD THREE (05/20/2022-05/19/2023)
1
LS
$
$
5
OPTION PERIOD FOUR (05/01/2023-04/30/2024)
1
LS
$
$
TOTAL PRICE FOR ALL OPTIONS (CLINs 2 through 5)
$
TOTAL PROPOSED PRICE - BASE PLUS ALL OPTIONS (CLINs 1 through 5)
$

File details come from the government source that posted it.