Attachment_No._SOO-4.pdf
PDF 631 KB Posted
- Attached to
- National Vehicle Maintenance Federal contract opportunity
- Solicitation number
- 15M10319RA4100013
About this file
Attachment SOO-4
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| QnAs.pdf | ||
| Attachment_No._SOO-1.pdf | ||
| Attachment_No._SOO-3.pdf | ||
| 15M10319RA4100013_1.pdf | ||
| FAR_52.212-2_Attachment.pdf | ||
| NVM_Ordering_Procedures.pdf | ||
| 20191002_NVM_SOO.pdf | ||
| Attachment_No._SOO-2.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT No. SOO-4 Proposal Information Technology Requirements (Sub-Factor 6)
The contractor must provide an online portal (website) for evaluation with trial log-on info and/or sufficient information to articulate whether or not the proposed online portal meets the needs of the
Government as communicated below. Examples of technical specifications are included in the SOO in
Objective 1. The proposal should include IT performance requirements (examples: latency, browser specific, JCOTS inspected). An operational support element (examples: patching, security incident resolution, & upgrades) should be provided in the proposal. Contractor should specify Data at Rest/Data in Transit protections. The Contractor shall disclose known issues with DOJ or OCIO. The Contractor should provide information on how they control access to data by users/systems/service; this should also include how they log & control access by their contracted & subcontracted support. The Contractor should disclose their methodology to protect Data/PII and how it is accomplished. Finally, how will the Contractor track, export, and manage the Data individually and/or in bulk to meet federal record management and litigation hold requirements?
Specific Requirements Related to Information Technology Service Solutions
The contractor must provide an “Enterprise” Vehicle Fleet Maintenance Services (VFMS) solution.
Enterprise is defined as supporting 5-500 office locations; offering up to three (3) secured user names/passwords per location to eliminate sharing passwords; complimentary accounts with
Administrative Oversight allowing centralized management capabilities; and IT administrative assistance and/or access option for USMS testing, cyber security monitoring, Tier 1 break fix resolution, optimization of web performance, and logging information.
The Enterprise VFMS Services must provide a centralized management service with a master Enterprise
Reporting Account capability to allow program management by the Administrator to track all vehicle fleet related information and vehicle related maintenance associated with transactions by site, account, vehicle and executive summary view options. The VFMS solution must offer Program Administrator Controls that allow the Administrator to set user spending limits, change user profile controls and permissions. The
VFMS solution must also provide named user site and local management services with site and local level tracking.
The Enterprise VFMS Services solution is considered a managed service solution in a shared commercial cloud where USMS IT compliance controls outlined, apply to the portion of the systems, services, content and support related to USMS specific information.
USMS information shared through a Web Application and/or Application Portal that must be protected and accessible only by authorized Government and authorized Contractor support. USMS information must be maintained and protected inclusive of logical container protection elements, especially if maintained in a shared Contractor VFMS SaaS solution. The Contractor must provide a summary document summarizing the protection measures, sensitive information data map; and must address the information assurance compliance requirements measures that will be leveraged to provide the managed services. USMS follows a Systems Development Lifecycle (SDLC) program/project management strategy that requires change control approval and an Authority to Operate for production services enablement.
All solution electronic communications between the Government users and the Contractor for Enterprise
VFMS Services must be encrypted in transit, using compliant web and portal access controls. All web based data information transferred to and from an USMS user device shall processed through an authorized browser portal; and Department of Justice, Justice Cloud Optimized TIC Services (JCOTS), (DOJ) Trusted
Internet Connection (TIC) access point. Electronic communications information, if stored externally, must meet the federal compliance standards. USMS will retain data and electronic information in accordance with Department of Justice retention policy requirements, unless information handling compliance allows for sufficient disposition prior to release. Privileged data specific to USMS used for automation, analytics and reporting is considered the property of USMS.
In accordance with FAR 39.105, this section is included in this SOO. This section applies to solution, support, and IT resources, including awardees, contractors, subcontractors, lessors, suppliers, and manufacturers that may have access to USMS sensitive data. Data is considered Sensitive Data that contains USMS IT interconnection configuration settings, USMS user’s account identities and identity management configuration settings; and content containing Personally Identifiable Information that includes accident details, credit card information, sensitive user information, and USMS site locations.
Non-Sensitive data shall follow standard industry information controls including information related to vehicles, service stations, or other general publically accessible information or IT services. The Enterprise VFMS Service Solution must present no security vulnerabilities to the Government’s sensitive but unclassified networks and meet all current security parameters outlined in Attachment A: PGD 15-03, Security and Information Systems. The Enterprise VFMS Services solution must provide a method to prevent unauthorized usage and unauthorized access to Governments information. The contractor must maintain all services and must comply with all security and regulatory compliance requirements, see Attachment B: Referenced Standards and Compliance Requirements.
Services delivered, configured, operated, maintained and optimized must align to the strategic plan and enterprise architecture. Contractor staff who may have access to USMS information containing Personally
Identifiable Information (PII) must safeguard sensitive data and information technology resources; must have a completed background investigation; and must have a signed a Rules Of Behavior (ROB) and NDA in place. All performance outcomes will be delivered in accordance with DOJ information assurance policies and requirements.
The contractor must meet the Procurement Guidance Documents DOJ IT Security Standards. If the contractor acts on behalf of, or provides advice with respect to any phase of an agency procurement, as defined in FAR 3.104-4, then the contractor must execute and submit a IT Non-Disclosure Agreement
(NDA) Form; and ensure that all its personnel (to include subcontractors, teaming partners, and consultants) who will be personally and substantially involved in the performance of the SOO submit an
NDA if they have access to sensitive data.
SECURITY OF INFORMATION AND INFORMATION SYSTEMS DOJ PGD 15-03 Guidance I. Applicability to
Contractors and Subcontractors
This guidance applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of contractors, subcontractors, and CSPs (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ
Information. It establishes and implements specific DOJ requirements applicable to this Contract. The requirements established herein are in addition to those required by the Federal Acquisition Regulation
(“FAR”), including FAR 11.002(g) and 52.239-1, the Privacy Act of 1974, and any other applicable laws, mandates, Procurement Guidance Documents, and Executive Orders pertaining to the development and operation of Information Systems and the protection of Government Information. This guidance does not alter or diminish any existing rights, obligation or liability under any other civil and/or criminal law, rule, regulation or mandate.
II. General Definitions
The following general definitions apply to this guidance. Specific definitions also apply as set forth in other paragraphs.
A. Information means any communication or representation of knowledge such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. Information includes information in an electronic format that allows it be stored, retrieved or transmitted, also referred to as “data,” and “personally identifiable information” (“PII”), regardless of form.
B. Personally Identifiable Information (or PII) means any information about an individual maintained by an agency, including, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and information, which can be used to distinguish or trace an individual's identity, such as his or her name, social security number, date and place of birth, mother's maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual.
C. DOJ Information means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, Information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired in order to perform the contract.
D. Information System means any resources, or set of resources organized for accessing, collecting, storing, processing, maintaining, using, sharing, retrieving, disseminating, transmitting, or disposing of
(hereinafter collectively, “processing, storing, or transmitting”) Information.
E. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information.
III. Confidentiality and Non-disclosure of DOJ Information
A. Preliminary and final deliverables and all associated working papers and material generated by Contractor containing DOJ Information are the property of the U.S. Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Representative (“COR”) at the conclusion of the contract.
The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14.
B. All documents produced in the performance of this contract containing DOJ Information are the property of the U.S. Government and Contractor must neither reproduce nor release to any third-party at any time, including during or at expiration or termination of the contract without the prior written permission of the CO.
C. Any DOJ information made available to Contractor under this contract must be used only for the purpose of performance of this contract and must not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, Contractor assumes responsibility for the protection of the confidentiality of any and all DOJ Information processed, stored, or transmitted by the Contractor. When requested by the CO (typically no more than annually), Contractor must provide a report to the CO identifying, to the best of Contractor’s knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed, stored, or transmitted under the Contract, including an estimate of the number of individuals for whom PII has been processed, stored or transmitted under the Contract and whether such information includes social security numbers (in whole or in part).
IV. Compliance with Information Technology Security Policies, Procedures and Requirements
A. For all Covered Information Systems, Contractor must comply with all security requirements, including but not limited to the regulations and guidance found in the Federal Information Security Management
Act of 2014 (“FISMA”), Privacy Act of 1974, E-Government Act of 2002, National Institute of Standards and
Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, PGD 15-03, 199, and 200, OMB Memoranda, Federal Risk and Authorization Management Program (“FedRAMP”), DOJ IT Security
Standards, including DOJ Order 0904, as amended. These requirements include but are not limited to:
1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise;
2. Providing security awareness training including, but not limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information
Systems;
3. Creating, protecting, and retaining Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information;
4. Maintaining authorizations to operate any Covered Information System;
5. Performing continuous monitoring on all Covered Information Systems;
6. Establishing and maintaining baseline configurations and inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System
Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Information Systems;
7. Ensuring appropriate contingency planning has been performed, including DOJ Information and
Covered Information System backups;
8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication methods where required;
9. Establishing an operational incident handling capability for Covered Information Systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and reporting incidents to appropriate officials and authorities within
Contractor’s organization and the DOJ;
10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms, and personnel used to conduct such maintenance;
12. Protecting Covered Information System media containing DOJ Information, including paper, digital and electronic media; limiting access to DOJ Information to authorized users; and sanitizing or destroying Covered Information System media containing DOJ Information before disposal, release or reuse of such media;
13. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Information Systems to authorized U.S. citizens unless a waiver has been granted by the Contracting Officer (“CO”), and protecting the physical facilities and support infrastructure for such
Information Systems;
14. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with DOJ Security standards;
15. Assessing the risk to DOJ Information in Covered Information Systems periodically, including scanning for vulnerabilities and remediating such vulnerabilities in accordance with DOJ policy and ensuring the timely removal of assets no longer supported by the Contractor;
16. Assessing the security controls of Covered Information Systems periodically to determine if the controls are effective in their application, developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in such Information Systems, and monitoring security controls on an ongoing basis to ensure the continued effectiveness of the controls;
17. Monitoring, controlling, and protecting information transmitted or received by Covered
Information Systems at the external boundaries and key internal boundaries of such Information Systems, and employing architectural designs, software development techniques, and systems engineering principles that promote effective security; and
18. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection from malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate action in response.
B. Contractor must not process, store, or transmit DOJ Information using a Covered Information
System without first obtaining an Authority to Operate (“ATO”) for each Covered Information System. The
ATO must be signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under this contract. The DOJ standards and requirements for obtaining an ATO may be found at DOJ Order 2640.2, as amended. (For
Cloud Computing Systems, see Section V, below.)
C. Contractor must ensure that no Non-U.S. citizen accesses or assists in the configuration, operation, management, or maintenance of any DOJ Information System, unless a waiver has been granted by the by the DOJ Component Head (or his or her designee) responsible for the DOJ Information
System, the DOJ Chief Information Officer, and the DOJ Security Officer.
D. When requested by the DOJ CO or COR, or other DOJ official as described below, in connection with DOJ’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of DOJ Information, Contractor must provide DOJ, including the Office of Inspector General (“OIG”) and Federal law enforcement components, (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Contractor’s facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by DOJ or agents acting on behalf of DOJ, and such access must be provided within 72 hours of the request.
Additionally, Contractor must cooperate with DOJ’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of DOJ Information.
E. The use of Contractor-owned laptops or other portable digital or electronic media to process or store DOJ Information covered by this guidance is prohibited until Contractor provides a letter to the DOJ
CO, and obtains the CO’s approval, certifying compliance with the following requirements:
1. Media and data must be encrypted using a NIST FIPS 140-2 approved product or method;
2. Contractor must implement a process to ensure that security and other applications software is kept up-to-date;
3. Where applicable, media must utilize antivirus software and a host-based firewall mechanism;
4. Contractor must log all computer-readable data extracts from databases holding DOJ Information and verify that each extract including PGD 15-03, Security of Information and Information Systems. Any such data which has been erased within 90 days of extraction or that its use is still required. All DOJ
Information is sensitive information unless specifically designated as non-sensitive by the DOJ; and,
5. A Rules of Behavior (“ROB”) form must be signed by users. These rules must address, at a minimum, authorized and official use, prohibition against unauthorized users and use, and the protection of DOJ Information. The form also must notify the user that he or she has no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contractor-owned laptops or other portable digital or electronic media.
F. Contractor-owned removable media containing DOJ Information must not be removed from DOJ facilities without prior approval of the DOJ CO or COR.
G. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with DOJ security requirements.
H. Contractor must keep an accurate inventory of digital or electronic media used in the performance of DOJ contracts.
I. Contractor must remove all DOJ Information from Contractor media and return all such information to the DOJ within 15 days of the expiration or termination of the contract, unless otherwise extended by the CO, or waived (in part or whole) by the CO, and all such information must be returned to the DOJ in a format and form acceptable to the DOJ. The removal and return of all DOJ Information must be accomplished in accordance with DOJ IT Security Standard requirements, and an official of the
Contractor must provide a written certification certifying the removal and return of all such information to the CO within 15 days of the removal and return of all DOJ Information.
J. DOJ, at its discretion, may suspend Contractor’s access to any DOJ Information, or terminate the contract, when DOJ suspects that Contractor has failed to comply with any security requirement, or in the event of an Information System Security Incident (see Section V.E. below), where the Department determines that either event gives cause for such action. The suspension of access to DOJ Information may last until such time as DOJ, in its sole discretion, determines that the situation giving rise to such action has been corrected or no longer exists. Contractor understands that any suspension or termination in accordance with this provision shall be at no cost to the DOJ, and that upon request by the CO, Contractor must immediately return all DOJ Information to DOJ, as well as any media upon which DOJ
Information resides, at Contractor’s expense.
V. Cloud Computing
A. Cloud Computing means an Information System having the essential characteristics described in NIST
SP 800-145, The NIST Definition of Cloud Computing. For the sake of this guidance, Cloud Computing includes Software as a Service, Platform as a Service, and Infrastructure as a Service, and deployment in a Private Cloud, Community Cloud, Public Cloud, or Hybrid Cloud.
B. Contractor may not utilize the Cloud system of any CSP unless:
1. The Cloud system and CSP have been evaluated and approved by a 3PAO certified under FedRAMP and Contractor has provided the most current Security Assessment Report (“SAR”) to the DOJ CO for consideration as part of Contractor’s overall System Security Plan, and any subsequent SARs within 30 days of issuance, and has received an ATO from the Authorizing Official for the DOJ component responsible for maintaining the security confidentiality, integrity, and availability of the DOJ Information under contract; or,
2. If not certified under FedRAMP, the Cloud System and CSP have received an ATO signed by the
Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under the contract.
C. Contractor must ensure that the CSP allows DOJ to access and retrieve any DOJ Information processed, stored or transmitted in a Cloud system under this Contract within a reasonable time of any such request, but in no event less than 48 hours from the request. To ensure that the DOJ can fully and appropriately search and retrieve DOJ Information from the Cloud system, access must include any schemas, meta-data, and other associated data artifacts.
VI. Information System Security Breach or Incident
A. Definitions
1. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any DOJ Information accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system.
2. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed, Covered Information System Security Breach.
3. Security Incident means any Confirmed or Potential Covered Information System Security Breach.
B. Confirmed Breach. Contractor must immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the DOJ CO and the CO's Representative (“COR”). If the Confirmed
Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call DOJ-CERT at 1-866-US4-CERT (1-866-874-2378) immediately (and in no event later than within 1 hour of discovery of the Confirmed Breach), and must notify the CO and COR as soon as practicable.
C. Potential Breach.
1. Contractor must report any Potential Breach within 72 hours of detection to the DOJ CO and the
COR, unless Contractor has (a) completed its investigation of the Potential Breach in accordance with its own internal policies and procedures for identification, investigation and mitigation of Security Incidents and (b) determined that there has been no Confirmed Breach.
2. If Contractor has not made a determination within 72 hours of detection of the Potential Breach whether an Confirmed Breach has occurred, Contractor must report the Potential Breach to the DOJ CO and COR within one-hour (i.e., 73 hours from detection of the Potential Breach). If the time by which to report the Potential Breach occurs outside of regular business hours and/or neither the DOJ CO nor the
COR can be reached, Contractor must call the DOJ Computer Emergency Readiness Team (DOJ-CERT) at
1-866-US4-CERT (1-866-874-2378) within one-hour (i.e., 73 hours from detection of the Potential Breach) and contact the DOJ CO and COR as soon as practicable.
D. Any report submitted in accordance with paragraphs (B) and (C), above, shall identify (1) both the
Information Systems and DOJ Information involved or at risk, including the type, amount, and level of sensitivity of the DOJ Information and, if the DOJ Information contains PII, the estimated number of unique instances of PII, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the US-CERT
Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by the DOJ. Contractor must continue to provide written updates to the DOJ CO regarding the status of the Security Incident at least every three (3) calendar days until informed otherwise by the DOJ CO.
E. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident will be made by DOJ senior officials or the DOJ Core
Management Team at DOJ’s discretion.
F. Upon notification of a Security Incident in accordance with this section, Contractor must provide to DOJ full access to any affected or potentially affected facility and/or Information System, including access by the DOJ OIG and Federal law enforcement organizations, and undertake any and all response actions DOJ determines are required to ensure the protection of DOJ Information, including providing all requested images, log files, and event information to facilitate rapid resolution of any Security Incident.
G. DOJ, at its sole discretion, may obtain, and Contractor will permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any Security
Incident. Additionally, DOJ, at its sole discretion, may require Contractor to retain, at Contractor’s expense, a Third Party Assessing Organization (3PAO), acceptable to DOJ, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.
H. Response activities related to any Security Incident undertaken by DOJ, including activities undertaken by Contractor, other federal agencies, and any third-party contractors or firms at the request or direction of DOJ, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Security Incident and/or liability for any additional response activities. Contractor must be responsible for all costs and related resource allocations required for all such response activities related to any Security Incident, including the cost of any penetration testing.
VII. Personally Identifiable Information Notification Requirement
Contractor certifies that it has a security policy in place that contains procedures to promptly notify any individual who’s Personally Identifiable Information (“PII”) was, or is reasonably determined by DOJ to have been, compromised. Any notification must be coordinated with the DOJ CO and must not proceed until the DOJ has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by Contractor must be coordinated with, and subject to the approval of, DOJ. Contractor must be responsible for taking corrective action consistent with DOJ Data Breach Notification Procedures and as directed by the DOJ CO, including all costs and expenses associated with such corrective action, which may include providing credit monitoring to any individuals whose PII was actually or potentially compromised.
VIII. Pass-through of Security Requirements to Subcontractors and CSPs
The requirements set forth in the preceding paragraphs of this guidance apply to all subcontractors and
CSPs who perform work in connection with this Contract, including any CSP providing services for any other CSP under this Contract, and Contractor shall flow down this guidance to all subcontractors and
CSPs performing under this contract. Any breach by any subcontractor or CSP of any of the provisions set forth in this guidance will be attributed to Contractor.
REFERENCED STANDARDS AND COMPLIANCE REQUIREMENTS
The Government recognizes that some of the standards and their associated data items identified below, may change. Throughout this effort, the Contractor or the Government may propose following newer standards and their associated data items that replace or supersede those below. To substitute newer standards and their associated data items the Contractor must: 1) identify existing standards and data items to be replaced; 2) identify new standards and associated data items proposed for use; 3) provide a rationale for using the new items including cost, schedule, performance, and supportability impact; and 4) receive government approval. In the event of conflict between any of the requirements comprised in the sections below, said conflict must be brought to the attention of the Government and resolved with the Government.
These standards apply to services delivered by the Contractor, Services maintained by the Contractor and Service Designs proposed by the Contractor.
1. Overarching
a. E-Government Act of 2002 at https://www.gpo.gov/fdsys/pkg/PLAW-
107publ347/pdf/PLAW-107publ347.pdf.
b. Federal Information Security Management Act of 2014 (FISMA) at https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf.
c. Privacy Act of 1974, 5 U.S.C. § 552a at https://www.gpo.gov/fdsys/pkg/USCODE- 2012title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf and Overview of the Privacy Act of 1974, 2015 Edition at https://www.justice.gov/opcl/overview-privacy-act1974- 2015-edition.
d. Homeland Security Act of 2002 (Public Law 107-296, 116
Stat. 2135) at:
https://www.dhs.gov/sites/default/files/publications/hr_5005_enr.pdf
e. NIST SP 800-37 Rev 1 Guide for Applying the Risk Management Framework to Federal
Information Systems: a Security Life Cycle Approach at https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final.
f. Federal Risk and Authorization Management Program (FedRAMP) at https://www.fedramp.gov/
g. NIST SP 800-53 Revision 4 at (https://nvd.nist.gov/800-53/) with DOJ specific security controls for unclassified information and information technology systems.
h. NIST SP 800-60 Vol I Rev 1 Guide for Mapping Types of Information and Information Systems to Security Categories at https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final and NIST SP 800-60 Vol 2 Rev 1 Guide for Mapping Types of Information and Information
Systems to Security Categories: Appendices at https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final
i. NIST SP 800-88, Revision 1 Guidelines for Media
Sanitization at https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelinesmedia-sanitization
j. FIPS 199 Standards for Security Categorization of Federal Information and Information
Systems at http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
k. Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules at https://csrc.nist.gov/publications/detail/fips/140/2/final.
l. FIPS 200 Minimum Security Requirements for Federal Information and Information Systems at https://csrc.nist.gov/publications/detail/fips/200/final https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.gpo.gov/fdsys/pkg/USCODE-2012-title5/pdf/USCODE-2012-title5-partI-chap5-subchapII-sec552a.pdf https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.justice.gov/opcl/overview-privacy-act-1974-2015-edition https://www.dhs.gov/sites/default/files/publications/hr_5005_enr.pdf https://www.dhs.gov/sites/default/files/publications/hr_5005_enr.pdf https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final https://www.fedramp.gov/ https://www.fedramp.gov/ https://nvd.nist.gov/800-53/ https://nvd.nist.gov/800-53/ https://nvd.nist.gov/800-53/ https://nvd.nist.gov/800-53/ https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization https://www.nist.gov/publications/nist-special-publication-800-88-revision-1-guidelines-media-sanitization http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf https://csrc.nist.gov/publications/detail/fips/140/2/final https://csrc.nist.gov/publications/detail/fips/140/2/final https://csrc.nist.gov/publications/detail/fips/200/final https://csrc.nist.gov/publications/detail/fips/200/final
m. Public Law 107-56 (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept an Obstruct Terrorism (USA PATRIOT ACT) Act of 2001) at https://www.gpo.gov/fdsys/pkg/PLAW-107publ56/content-detail.html
n. NIST Special publication 800-63, Electronic Authentication
Guideline at https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013- 08-29.
o. DOJ Procurement Guidance Documents (PGD) 15-03, Security of Information and Information
System, DOJ Order 0904 for DOJ’s Cybersecurity Program at https://www.justice.gov/jmd/page/file/964941/download, DOJ Order 0903, Information
Technology Management at https://www.justice.gov/jmd/file/877186/download.
p. Homeland Security Presidential Directive (HSPD)-7, Critical Infrastructure Identification, Prioritization, and Protection, dated December 17, 2003 at https://www.dhs.gov/homelandsecurity-presidential-directive-7
q. HSPD-12, Policies for a Common Identification Standard for Federal Employees and
Contractors, dated August 27, 2004 at https://www.dhs.gov/homeland-security-presidentialdirective-12.
r. DOJ Procurement Guidance Document (PGD) 14-03, Acquisition of High- or Moderate-Impact Information Technology Systems at https://dojnet.doj.gov/jmd/cao/pgd/pgd-14-03.pdf. Any solution component shall follow NIST SP 800-161 Supply Chain Risk Management Practices for
Federal Information Systems with supply chain protections as defined in the NIST 800-53 SA-
12 control.
s. Guidelines on Securing Public Web Servers, Special Publication 800-44, Version 2, dated
September 2007, at https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final
t. NIST Special Publication 800-63B, Digital Identity Guidelines, dated June 2017, at https://pages.nist.gov/800-63-3/sp800-63b.html
u. NIST Special Publication 1800-16, Securing Web Transactions, https://csrc.nist.gov/publications/detail/sp/1800-16/draft
v. Section 508 Electronic and Information Technology Accessibility at https://www.section508.gov/
i. The Contractor must provide a statement indicating its capability to comply with
Section 508 requirements. Unless the Government invokes an exemption, all
Electronic and Information Technology (EIT) services must fully comply with Section
508 of the Rehabilitation Act of 1973, per the 1998 Amendments, 29 United States
Code (U.S.C.) 794d, and the Architectural and Transportation Barriers Compliance
Board’s Electronic and Information Technology Accessibility Standards at 36 Code of
Federal Regulations (CFR) 1194. The contractor must identify all EIT services provided, identify the technical standards applicable to all products and services provided, and state the degree of compliance with the applicable standards upon request.
ii. Contractors must use 508 best practices to ensure that information and services are accessible to persons with disabilities and during development to create accessible digital products (https://www.section508.gov/create). Federal agencies are responsible for ensuring their information and services are accessible to persons with disabilities. The Revised 508 Standards include not just IT tools and systems, but https://www.gpo.gov/fdsys/pkg/PLAW-107publ56/content-detail.html https://www.gpo.gov/fdsys/pkg/PLAW-107publ56/content-detail.html https://www.gpo.gov/fdsys/pkg/PLAW-107publ56/content-detail.html https://www.gpo.gov/fdsys/pkg/PLAW-107publ56/content-detail.html https://www.gpo.gov/fdsys/pkg/PLAW-107publ56/content-detail.html https://www.gpo.gov/fdsys/pkg/PLAW-107publ56/content-detail.html https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29 https://www.justice.gov/jmd/file/877186/download https://www.justice.gov/jmd/file/877186/download https://www.justice.gov/jmd/file/877186/download https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-7 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://dojnet.doj.gov/jmd/cao/pgd/pgd-14-03.pdf https://dojnet.doj.gov/jmd/cao/pgd/pgd-14-03.pdf https://dojnet.doj.gov/jmd/cao/pgd/pgd-14-03.pdf https://dojnet.doj.gov/jmd/cao/pgd/pgd-14-03.pdf https://dojnet.doj.gov/jmd/cao/pgd/pgd-14-03.pdf https://dojnet.doj.gov/jmd/cao/pgd/pgd-14-03.pdf https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html https://csrc.nist.gov/publications/detail/sp/1800-16/draft https://csrc.nist.gov/publications/detail/sp/1800-16/draft https://csrc.nist.gov/publications/detail/sp/1800-16/draft https://csrc.nist.gov/publications/detail/sp/1800-16/draft https://www.section508.gov/ https://www.section508.gov/ https://www.section508.gov/create https://www.section508.gov/create electronic content such as documents, web pages, presentations, social media content, blogs, and certain emails. The Contractor must comply with the technical standards at 36 CFR 1194.21 in performing this delivery order marked
_§1194.21 Software applications and operating systems
_§1194.22 Web-based intranet and internet information and applications
The standards do not require the installation of specific accessibility-related software or the attachment of an assistive technology device, but merely require that the offered services be compatible with such software and devices so that it can be made accessible if so required by the agency in the future.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.