ATU Vendor Attestation.pdf

PDF 431 KB Posted

Attached to
SU/MH/SOT in Dallas, TX Federal contract opportunity
Solicitation number
15BCTS26Q00000001
Issued by
Department of Justice Bureau of Prisons Central Office

About this file

This document is an Acquisition Plan from the Federal Bureau of Prisons (FBOP), Department of Justice, that establishes security and compliance requirements for vendors handling DOJ information.

The plan requires vendors to affirm implementation of security controls including certifications such as SOC 2, ISO 27001, state licensure requirements, Payment Card Industry compliance, HIPAA, and other applicable environment certifications, with documented evidence attached. Vendors must maintain DOJ data exclusively within United States boundaries with access limited to U.S. citizens only, use data solely for contract performance, and prohibit reproduction or third-party release without written authorization from the Contracting Officer (CO) or Contracting Officer's Representative (COR). Vendors must report actual breaches within one hour and suspected breaches within 24 hours to the CO, COR, DOJ Security Operations Center (jsoc@usdoj.gov, 202-357-7000), FBOP's Information Security Program Office, and the Contracting Officer. The vendor bears all costs for breach response activities and must cooperate fully with DOJ investigations, providing facility access and system information including images, log files, and event data.

The plan includes a comprehensive questionnaire requiring vendors to identify data types being transmitted (sensitive data, PII, Federal Tax Information, Protected Health Information, and other Limited Official Use Information) and document security implementations. Vendors must attest to specific security controls including Multi-Factor Authentication, least privilege access management, encryption of sensitive data at rest and in transit, mobile device management, formal cybersecurity programs, routine vulnerability scanning, penetration testing, vulnerability remediation timelines (30 days for critical/high risk, 90 days for medium risk), 24/7/365 monitoring services, and subcontractor security requirements. Section D requires the vendor representative to sign attesting to the accuracy of information provided and acceptance of responsibility for protecting DOJ data confidentiality, integrity, and availability on vendor networks.

View the file

Other files for this federal contract opportunity

Other files attached to SU/MH/SOT in Dallas, TX, newest first.
File Type Posted
Questions for 15BCTS26Q00000001 (CTS in Dallas TX) 2 3-5-26.pdf PDF
Questions for 15BCTS26Q00000001 (CTS in Dallas TX) 1.pdf PDF
Cover Letter Dallas Texas.pdf PDF
SF-1449 Dallas TX 15BCTS26Q00000001.pdf PDF
Technical Quotation Information Packet Dallas TX.docx DOCX document
Business Quotation Information Packet.pdf PDF
2022 STATEMENT OF WORK (SOW).pdf PDF
APN 22-03 Whistleblower Information.pdf PDF
Attachment Quotation Form.xlsx XLSX spreadsheet
Pricing Chart.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Acquisition Plan FBOP | Department of Justice

The vendor affirms that they have security controls in place to protect DOJ information when that data is being stored, transmitted, processed, or displayed on the vendor’s information technologies. Applicable security controls include certifications indicating compliance with: state licensure requirements, SOC 2, ISO 27001, Payment Card Industry, HIPAA as applicable or other environment certifications that would be applicable (to be specified by the vendor). Vendor has attached documentation of said certifications as part of this affirmation.

The vendor affirms that internal controls are in place to identify and remediate vulnerabilities within any IT system in which DOJ information is stored and that DOJ data will be stored exclusively within the boundaries of the United States and that only US citizens have access to DOJ’s data. The vendor affirms that any DOJ information made available to vendor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. The vendor shall neither reproduce nor release such information to any third-party at any time, including during or after performance of the contract, without prior written permission of the CO or COR.

The vendor agrees to report any actual or suspected breach of DOJ Information within one hour of discovery of an actual breach, and within 24 hours of a suspected breach if vendor has not yet been able to determine whether a breach has occurred. A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses DOJ Information or (2) an authorized user accesses or potentially accesses DOJ Information for an other than authorized purpose. The report of a breach must be made to the CO or COR; if neither can be reached, the vendor must report the breach to the DOJ Security Operations Center (jsoc@usdoj.gov, 202-357-7000) and FBOP’s Information Security Program Office; the COR; and the Contracting Officer within one (1) hour of the initial discovery. The vendor should not disclose any details of the potential or confirmed breach to any individual not involved in responding to the breach. The vendor agrees to cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals. Such cooperation includes, but is not limited to, providing to DOJ full access to any facility and/or Information System affected or potentially affected the breah or potential breach, and to undertake any and all response actions DOJ determines are required to ensure the protection of DOJ Information, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. The vendor further agrees that it shall be responsible for all costs and related resource allocations that DOJ deems required for all such response activities related to any breach.

[FBOP Proposed Attestation] [BOP RRC, CMS & Credit Reporting Contracts: To Address ATU concerns]

A. Vendor Information Types Questions Yes No N/A Description ☐ ☐ ☐ Is the data sensitive (as defined by NIST)?

☐ ☐ ☐ Does the data contain Personally Identifiable Information (PII)?

☐ ☐ ☐ Does the data contain Federal Tax Information (FTI)?

☐ ☐ ☐ Does the data contain Protected Health Information (PHI)?

Does the data contain other Limited Official Use Information:

☐ Legal Privilege ☐ Legal Strategy ☐ Grand Jury ☐ Title III Information ☐ Protected Materials ☐ Privacy Act ☐ Procurement Sensitive ☐ Intellectual Property ☐ Law Enforcement Sensitive ☐ Infrastructure Sensitive

Approximately how many records will be transmitted to the vendor during the contract period?

B. Vendor Information Security Questions Yes No N/A Description

☐ ☐ ☐ Is Multi Factor Authentication (MFA) used to access DOJ data?

Describe implementation:

Explain N/A:

☐ ☐ ☐ Is the principle of least privilege employed for access management?

Describe implementation:

Explain N/A:

Is sensitive data encrypted at rest and/or in transit (e.g., sensitive Personally Identifiable Information (PII), Federal Tax Information (FTI), health information (HIPAA))?

Describe implementation:

Explain N/A:

Do portable devices require mobile device management tools before allowing access to corporate data, including email?

Describe implementation:

Explain N/A:

☐ ☐ ☐ Is there a formal cyber security program which includes policy enforcement?

Describe implementation:

Explain N/A:

☐ ☐ ☐ Are routine vulnerability scans of all system assets and endpoints performed?

Yes No N/A Description Describe implementation:

Explain N/A:

Are internal and external penetration tests conducted?

Describe implementation:

Explain N/A:

Are known vulnerabilities mitigated or remediated within 30 for critical and high risk, and 90 days for medium risks?

Describe implementation:

Explain N/A:

o Critical Patch - to be installed within 30 days or sooner if possible o High Risk Patch - to be installed within 60 days or sooner if possible o Medium Risk Patch - to be installed within 90 days or sooner if possible o Low Risk Patch - to be installed within the normal patching rotation, but within at least a year.

Are monitoring services employed which will notify resources as needed 24x7x365 to support incident response?

Describe implementation:

Explain N/A:

If sub-contractors are used, describe questionnaire and other requirements of sub-contractors:

Describe implementation:

Explain N/A:

C. Data Owners Role Responsible Party Responsibilities

Data Steward Entity who is responsible for the categorization, protection, usage, and quality of the data.

Data Steward Entity who is responsible for the confidentiality, integrity, and availability of the data on a day-to-day basis.

Data Steward Entity who is responsible for the confidentiality, integrity, and availability of data on a day-to-day basis.

D. Vendor Signature As the vendor representative, I attest that the information in sections A and B are accurate, and I accept the responsibility of protecting and ensuring the confidentiality, integrity, and availability of DOJ data on a day-to-day basis when it is on the vendor or subcontracted vendor networks.

A. Vendor Information Types Questions
B. Vendor Information Security Questions
C. Data Owners
D. Vendor Signature
Check Box1: Off
Check Box2: Off
Check Box3: Off
Check Box4: Off
Check Box5: Off
Check Box6: Off
Check Box7: Off
Check Box8: Off
Check Box9: Off
Check Box10: Off
Check Box11: Off
Check Box12: Off
Check Box13: Off
Check Box14: Off
Check Box15: Off
Check Box16: Off
Check Box17: Off
Check Box18: Off
Check Box19: Off
Check Box20: Off
Check Box21: Off
Check Box22: Off
Check Box23: Off
Check Box24: Off
Check Box25: Off
Check Box26: Off
Check Box27: Off
Check Box28: Off
Check Box29: Off
Check Box30: Off
Check Box31: Off
Check Box32: Off
Check Box33: Off
Check Box34: Off
Check Box35: Off
Check Box36: Off
Check Box37: Off
Check Box38: Off
Check Box39: Off
Check Box40: Off
Check Box41: Off
Check Box42: Off
Check Box43: Off
Check Box44: Off
Check Box45: Off
Check Box46: Off
Check Box47: Off
Check Box48: Off
Check Box49: Off
Check Box50: Off
Check Box51: Off
Check Box52: Off
Check Box53: Off
Check Box54: Off
Check Box55: Off
Check Box56: Off
Check Box57: Off
Check Box58: Off
undefined:
Insert description for implementation:
Insert explanation:
Insert Responsible Party:

File details come from the government source that posted it. Updated .