19-FDA-SOL-1215586_Attachment_A_-_SOW.pdf
PDF 529 KB Posted
- Attached to
- Computational Whole Heart Modeling Federal contract opportunity
- Solicitation number
- 19-FDA-SOL-1211586
About this file
Attachment A - Statement of Work
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| JOFOC_Computational_Whole_Heart_r.pdf | ||
| 19-FDA-SOL-1215586_Attachment_B_-_Schedule.xlsx | XLSX spreadsheet | |
| 19-FDA-SOL-1215586.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work (SOW)
Title: Computational whole heart modeling, web-based computing and remote data viewing and access services
1. Background
CDRH/OSEL/DAM has received intramural funding from Critical Path to support a project to demonstrate to FDA Staff and Industry how to more fully harness computational modeling to reduce the size of prospective clinical trials for medical devices. This will include extending methodologies developed by CDRH in conjunction with stakeholders to employ the “virtual patient model”. See this link for additional background: https://mdic.org/project/virtual-patient-vp-model/
2. Objective
The objective is to obtain (1) a 1-year service agreement (with the option for an additional year) for the contractor to perform whole human heart computations with a virtually implanted generic medical device that shall be created as part of the project plan using high-performance cloud computing in accordance to the Critical Path Project Plan, (2) online access to the data, simulation and the database for registered users, and
(3) web-based capabilities for viewing data and simulations.
3. Scope
The FDA requires a contractor to perform whole heart computations with a virtually implanted generic medical device using high-performance cloud computing to support the requirements of the Critical Path project.
The current details of the project are provided in the Appendix A – Project Plan. The Critical Path Project Plan was developed under a Research Collaboration Agreement (RCA) in conjunction with Dassault Systemes Solidworks Corp.
The “in silico clinical trial” that shall be completed as a part of the project shall be tested on a generic heart failure medical device. To accomplish our goals in the Project Plan, the FDA requires a physics-based computational model of a whole human heart; one that includes all critical functionality of the heart: electrophysiology, solid mechanics, and fluid dynamics, including all relevant anatomical features (such as ventricles, atria and vessels), and one that is available to stakeholders in the community to employ. The FDA intend to develop a generic medical device that will be virtually implanted in the whole human heart computational model. The whole human heart computational model will need to be adaptable to represent the relevant disease states to create https://mdic.org/project/virtual-patient-vp-model/
“virtual patients” and a “virtual population” such that we can conduct an in silico clinical trial with data that can be used support a proposal for a real clinical trial.
4. Tasks
The ability to perform these complex computations and host the massive amount of potential anatomical and simulation data and making the data remotely available on-demand to registers users, is required to complete the FDA research Project Plan. The project plan will be provided after award.
More specifically, the contractor shall perform the following in accordance with the Project Plan:
(i) establish a relevant, physics-based computational human heart model that allows for electrophysiology, electromechanics and fluid dynamics pumping of the heart;
(ii) develop preliminary features and designs of a computational models of a potential generic heart failure medical device (as part of the Project
Plan)
(iii) perform test simulations of the preliminary generic medical device virtually implanted in the computational human heart model;
(iv) perform the clinically-relevant preliminary computational simulations of the human heart and preliminary generic medical device to simulate a
“mock” in silico clinical trial;
(v) store and manage the imaging, computational, test and clinical data from all aspects of this phase of the project; and
(vi) provide cloud access to FDA registered users to these data in order to complete project objectives laid out in Project Plan.
Task # Task Name Task Description T001 Grant access to computational human heart modeling platform
The vendor shall provide the FDA project team access to the computational human heart modeling platform in which simulations are conducted, along with access to relevant data and simulations performed by the vendor.
12 remote registered users should have access for a year to the web-based platform and hosted data through a standard internet connection and web browser for at least 12 remote users. Customer support shall be included.
T002 Training of platform Train FDA staff on platform usage relevant to the project. This shall include in-person hands-on training for all FDA team members (max 12) along with web tutorials to revisit after training.
T003 Computational model of the generic medical device
The contractor shall provide a subject matter expert to establish a preliminary design of a generic heart failure medical device. The contractor shall develop and manufacture sample preliminary devices
The contractor shall establish a computational model of the preliminary generic medical device, and associated data to perform simulations (i.e., geometry CAD models, material constitutive model, mesh, boundary conditions, and executables) using the web-based platform.
T004 Computational simulations of the virtually implanted medical device in the human heart model
The contractor shall perform preliminary simulations of the generic medical device virtually implanted in the relevant human heart geometries under relevant clinical conditions, as established as by the research team.
T005 Phase 1: In silico clinical trial simulations
The contractor shall perform the clinically-relevant computational simulations of the human heart and generic medical device to simulate relevant aspects of Phase 1 of in silico clinical trial, as determined by the research team.
T006 Final generic device design
The contractor shall provide a subject matter expert and project team to finalize the generic medical device design.
T007 Preliminary computational simulations of the final device and heart model
To ensure that the final design meets the project requirements, the contractor shall perform preliminary simulations of the final device design with the relevant heart geometries, in preparation for Phase 2 of the in silico clinical trial
T008 Phase 2: In silico clinical trial simulations
The contractor shall perform the clinically-relevant computational simulations of the human heart and final generic medical device to perform Phase 2 of the in silico clinical trial, as determined by the research team.
5. Deliverables
Item Item Name Item Description Frequency
Projected Delivery
Date T001 User accounts for platform access Provide 12 user names and passwords for access to the platform
12 Within 30 days after award
T002 Training Schedule and deliver a training session
1 Within 90 days after award
T003 Computational model of the generic medical device the design and the computational model of the preliminary generic medical device and associated data to perform simulations (i.e., geometry CAD models, material constitutive model, mesh, relevant boundary conditions, and executables for Simulia).
contact details subject matter expert for inclusion in project plan.
one sample of the generic medical device
120 days after award
90 days after contract initiation
180 days after initiation
T004 Computational simulations of the virtually implanted medical device in the human heart model preliminary data from the initial computational model, simulations and data of the virtually implanted preliminary generic medical device in the relevant geometries on the web-based platform. The number of initial simulations will be determined by the research team, as appropriate for future directions of the project.
1 270 days after initiation
T005 Phase 1: In silico clinical trial simulations access to the preliminary data the Phase 1 of the in silico clinical trial, which shall include the computational model, simulations and data of the virtually implanted preliminary generic medical device in the relevant geometries on the web-based platform. The number of simulations in Phase 1 will be determined by the research team, as appropriate for Phase 2 of the project.
1 360 days after contract initiation
Option Year Deliverables T006 Final generic device design final design of the generic medical device and associated data to perform simulations (i.e., geometry CAD models, material constitutive model, mesh, relevant boundary conditions, and executables for Simulia)
1 420 days after initiation
T007 Preliminary computational simulations of the final device and heart model preliminary data from the initial computational model, simulations and data of the virtually implanted final generic medical device in the relevant geometries on the web-based platform. The number of simulations will be determined by the research team.
1 report 520 days after initiation
T008 Phase 2: In silico clinical trial simulations access to the data from Phase 2 of the in silico clinical trial, which will include the computational model, simulations and data of the virtually implanted final generic medical device in the relevant geometries on the web-based platform. The number of simulations in Phase 2 will be determined by the research team, as appropriate for the mock IDE Submission.
1 720 days after initiation
6. Inspection and Acceptance
The FDA COR will perform inspection and acceptance of materials and services to be provided under this order. The COR will perform inspection and acceptance of materials and services provided by the Contractor within 10 business days of submission. The Contractor shall implement necessary changes within 10 business days from the day of rejection or change notification.
7. Contract Type
This is a firm fixed price purchase order.
8. Place of Performance
The work shall be performed at the contractor’s location.
9. Period of Performance
The period of performance is for a base period of one (1) year and one (1) option period for one (1) year. Additionally, there is an option to extend services for up to six (6) months in accordance with FAR 52.217-8 Option to Extend Services. If the optional services are required, the Government has the option to exercise any amount of hours for the labor categories within the line item ceiling for a duration of up to 6 months.
10. Government Furnished Equipment (GFE)/ Government Furnished
Information (GFI)
The server and viewer should be available through remote access. FDA will provide two laptops for the FDA scientific network to host the portal and download any necessary data and simulations for the FDA project.
The furnished equipment is only authorized for transaction of official
Government business and shall not be used for personal business. Personal long-distance calls are not authorized and the cost of all personal long-distance calls made shall be deducted from the contractor's invoice. Telephones, facsimile machines and computer equipment are subject to communications security monitoring at all times. The cost of replacement Government furnished equipment (GFE) as a result of contractor negligence may be deducted from the contractor’s invoice. The contractor may be issued keys (physical and/or electronic). The contractor shall safeguard the keys from loss, theft or destruction, and must display all keys signed for at scheduled or unscheduled key control inspections. The contractor shall be required to reimburse the
Government for lost keys, or lockset (if locksets are required to be replaced) as a result of lost keys. The cost of replacement of keys/locksets may be deducted from payments to the contractor.
Contractor Negligence
Any loss, damage, or mishandling of FDA IT equipment or assets that is directly attributed to contractor negligence shall be the responsibility of the contractor.
The contractor shall be required to reimburse the Government at the full retail cost of the asset(s). This reimbursement shall be deducted against the contractor’s monthly payment.
11. Contract Administration
Contracting Officer’s Authority
The Contracting Officer (CO) identified above has responsibility for ensuring the performance of all necessary actions for effective contracting; ensuring compliance with the terms of the contract and safeguarding the interests of the United States in its contractual relationships. The CO is the only individual who has the authority to enter into, administer, or terminate this contract and is the only person authorized to approve changes to any of the requirements under this contract, and notwithstanding any provision contained elsewhere in this contract, this authority remains solely with the CO.
No statement, whether oral or written, by anyone other than the Contracting
Officer, will be interpreted as modifying the terms and conditions of this BPA. It is the Contractor’s responsibility to contact the CO immediately if there is even the appearance of any technical direction that is or may be outside the scope of the contract. The Government will not reimburse the Contractor for any work not authorized by the CO, including work outside the scope of the contract.
Contracting Officer’s Representative (COR)
The Contracting Officer’s Representative (COR) is responsible for: (1) monitoring the contractor's technical progress, including the surveillance and assessment of performance and recommending to the Contracting Officer changes in requirements; (2) interpreting the statement of work and any other technical performance requirements; (3) performing technical evaluation as required; (4) performing technical inspections and acceptances required by this contract;
and (5) assisting in the resolution of technical problems encountered during performance.
The Contracting Officer is the only person with authority to act as agent of the Government under this contract. Only the Contracting Officer has authority to:
(1) direct or negotiate any changes in the statement of work; (2) modify or extend the period of performance; (3) change the delivery schedule; (4) authorize reimbursement to the contractor for any costs incurred during the performance of this contract; or (5) otherwise change any terms and conditions of this contract.
The Government may unilaterally change its COR designation
12. Rights in Data
Please see terms and conditions for applicable clauses , specifically FAR clause 52.227-14 and Alt. IV (Dec 2007) Rights in Data – General and 52.227-17 --
Rights in Data -- Special Works
13. Government Points of Contact
Contract Specialist Contracting Officer Michelle Dacanay Phillip Frame
4041 Powder Mill Road 4041 Powder Mill Road Room 41025B Room 42053
Beltsville, MD 20705 Beltsville, MD 20705 Phone: 301-796-0447 Phone: 240-402-7578 Email: Michelle.Dacanay@fda.hhs.gov Email: Phillip.Frame@fda.hhs.gov
Contracting Officer’s Representative Technical Point of Contact Provided at award Provided at award
14. Appendix
Appendix A – Project Plan (provided after award)
15. Security Constraints
Procurements Requiring Information Security and/or Physical Access Security
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A
Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor
(and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2) Safeguarding Information and Information Systems. In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
mailto:Michelle.Dacanay@fda.hhs.gov mailto:Phillip.Frame@fda.hhs.gov
a. Protect government information and information systems in order to ensure:
Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an FDA network or operated by the
Contractor on behalf of FDA regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party. This includes notifying the FDA Systems Management Center (SMC) within one (1) hour of discovery/detection in the event of an information security incident.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS/FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the FDA Information Security Program security requirements, outlined in the FDA Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing your
ISSO.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
3) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special
Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality: [X] Low [ ] Moderate [ ] High http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf
Integrity: [X] Low [ ] Moderate [ ] High Availability: [X] Low [ ] Moderate [ ] High Overall Risk Level: [X] Low [ ] Moderate [ ] High
Based on information provided by the Privacy Office, system/data owner, or other privacy representative, it has been determined that this solicitation/contract involves:
[X ] No PII [ ] Yes PII
Personally Identifiable Information (PII). Per the OMB Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.”
Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother’s maiden name, biometric records, etc.
PII Confidentiality Impact Level has been determined to be: [ ] Low [ ] Moderate [ ] High
4) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa). As implemented the term “handling” refers to
“…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re- using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
b. disclosed to authorized personnel on a Need-To-Know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
d. returned to FDA control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization and the FDA IS2P Appendix T: Sanitization of Computer-Related Storage Media.
5) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The
Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of FDA shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and FDA policies.
Unauthorized disclosure of information will be subject to the HHS/FDA sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential
Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
6) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
7) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable
HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
8) Contract Documentation. The Contractor shall use FDA-provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
9) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.)
in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. All devices (i.e.: desktops, laptops, mobile devices, etc.) that store, transmit, or process non-public FDA information should utilize FDA-provided or FDA information security authorized devices that meet HHS and FDA-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
d. Verify that the encryption solutions in use are compliant with FIPS
140-2. The Contractor shall provide a written copy of the validation documentation to the COR.
e. Use the Key Management system on the HHS Personal
Identification Verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys.
Encryption keys (PIV card) shall be provided to the COR upon request and at the conclusion of the contract. Upon completion of contract, contractor ensures that COR is able to access and read any encrypted data.
10) Contractor Non-Disclosure Agreement (NDA). Each Contractor
(and/or any subcontractor) employee having access to non-public government information under this contract shall complete the FDA non-disclosure agreement (3398 Form), as applicable. A copy of each signed and witnessed NDA shall be submitted to the CO and/or COR prior to performing any work under this acquisition.
11) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) –
The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a full PIA needs to be completed.
http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf http://inside.fda.gov:9003/downloads/administrative/forms/fda/ucm013733.pdf
a. If the results of the PTA show that a full PIA is needed, the
Contractor shall assist procuring activity representative, program office and the FDA SOP or designee with completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002. The PTA/PIA must be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).
b. The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee in reviewing and updating the PIA at least every three years throughout the Enterprise Performance Life Cycle (EPLC) /information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable FDA Contractor Information Security
Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete FDA Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS and FDA training policies.
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy and FDA Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Standard Operating Procedures (SOP).
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS
Information Technology General Rules of Behavior.
2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior (ROB) before accessing HHS and FDA data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines.
D. Incident Response
The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/FDA SMC /Incident Response Team
(IRT) teams within 24 hours, whether the response is positive or negative.
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.” The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by FISMA as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII.”
In the event of a suspected or confirmed incident or breach, the Contractor
(and/or any subcontractor) shall:
1) Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
2) NOT notify affected individuals unless so instructed by the
Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send FDA approved notifications to affected individuals as directed by
FDA’s SOP.
3) Report all suspected and confirmed information security and privacy incidents and breaches to the FDA Systems Management Center, COR, CO, and other stakeholders, (Recommend adding the FDA Senior Official for Privacy with contact information and either defining or deleting “other stakeholders.”) including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour of discovery/detection, and consistent with the applicable FDA and HHS policy and procedures, NIST standards and guidelines, as well as US-
CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised.
In addition, the Contractor shall:
a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
b. not include any sensitive information in the subject or body of any reporting e-mail; and
c. encrypt sensitive information in attachments to email, media, etc.
4) Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information and HHS and FDA incident response policies when handling PII breaches.
5) Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation demand.
E. Position Sensitivity Designations
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal
Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract: [See the FDA Security Article, entitled Contractor Personnel Security Clearance Standards and Residency Requirements for the Position Risk Designation Tier(s) (i.e., 1, 2, and/or 4) that apply to this award.]
F. Homeland Security Presidential Directive (HSPD)-12
The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a
Common Identification Standard for Federal Employees and Contractors;
OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster and any revisions to the roster as a result of staffing changes shall be submitted to the COR and/or CO per the COR or CO’s direction. Any revisions to the roster as a result of staffing changes shall be submitted within a timeline as directed by the COR and/or CO. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
G. Contract Initiation and Expiration
1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract.
All information systems development or enhancement tasks supported by the contractor shall follow the FDA EPLC framework and methodology in accordance with the FDA EPLC Project documentation, located here:
http://sharepoint.fda.gov/orgs/DelMgmtSupport/IntakeProc/EPLCv 2/SitePages/v2/EPLCHome.aspx HHS EA requirements may be located here:
https://www.hhs.gov/about/agencies/asa/ocio/index.html
2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
3) Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation in accordance with FDA OAGS SMGs to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media
Sanitization and FDA IS2P Appendix T: Sanitization of Computer- Related Storage Media
4) Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR as soon as it is known that an employee will stop working under this contract.
5) Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the
CO and/or COR. Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or FDA policies.
6) The Contractor (and/or any subcontractor) shall coordinate with the
COR via email, copying the Contract Specialist, to ensure that the appropriate person performs and documents the actions identified in the FDA eDepart system http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepa rtDepartureSystem/default.htm as soon as it is known that an employee will terminate work under this contract within days of the employee’s exit from the contract. All documentation shall be made available to the CO and/or COR upon request.
H. Records Management and Retention
The Contractor (and/or any subcontractor) shall maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified
Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS/FDA policies and shall not dispose of any records unless authorized by HHS/FDA.
In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS/FDA policies.
Contracts Involving Cloud Services
A. FDA FedRAMP Privacy and Security Requirements
The Contractor (and/or any subcontractor) shall be responsible for the following privacy and security requirements:
1) FedRAMP Compliant ATO. Comply with FedRAMP Security http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/default.htm http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/default.htm
Assessment and Authorization (SA&A) requirements and ensure the information system/service under this contract has a valid FedRAMP compliant (approved) ATO in accordance with Federal Information
Processing Standard (FIPS) Publication 199 defined security categorization. If a FedRAMP compliant ATO has not been granted, the Contractor shall submit a plan to obtain a FedRAMP compliant ATO prior to production implementation.
a. Implement applicable FedRAMP baseline controls commensurate with the agency-defined security categorization and the applicable FedRAMP security control baseline (www.FedRAMP.gov). The FDA Information Security and Privacy Policy (IS2P) and HHS Cloud Computing and Federal Risk and Authorization Management Program (FedRAMP) Guidance further define the baseline policies as well as roles and responsibilities. The Contractor shall also implement a set of additional controls identified by the agency when applicable.
b. A security control assessment must be conducted by a FedRAMP third-party assessment organization (3PAO) for the initial ATO and annually thereafter or whenever there is a significant change to the system’s security posture in accordance with the FedRAMP Continuous Monitoring Plan.
2) Data Jurisdiction. The contractor shall store all information within the security authorization boundary, data at rest or data backup, within the continental United States (CONUS).
3) Service Level Agreements. Add when applicable. The Contractor shall understand the terms of the service agreements that define the legal relationships between cloud customers and cloud providers and work with FDA to develop and maintain an SLA.
4) Interconnection Agreements/Memorandum of Agreements. Add when applicable. The Contractor shall establish and maintain Interconnection Agreements and or Memorandum of Agreements/Understanding in accordance with HHS/FDA policies.
B. Protection of Information in a Cloud Environment
1) If contractor (and/or any subcontractor) personnel must remove any information from the primary work area, they shall protect it to the same extent they would the proprietary data and/or company trade secrets and in accordance with HHS/FDA policies.
2) FDA will retain unrestricted rights to federal data handled under this contract. Specifically, FDA retains ownership of any user created/loaded data and applications collected, maintained, used, or operated on behalf of FDA and hosted on contractor’s infrastructure, as well as maintains the right to request full copies of these at any time. If requested, data must be available to FDA within one (1) http://www.fedramp.gov/ business day from request date or within the timeframe specified otherwise. All data shall be accompanied by the relevant encryption key and/or access codes, or otherwise received in a useable format leveraging existing FDA systems, software, or other IT resources. In addition, the data shall be provided at no additional cost to FDA.
3) The Contractor (and/or any subcontractor) shall ensure that the facilities that house the network infrastructure are physically and logically secure in accordance with FedRAMP requirements and HHS policies.
4) The contractor shall support a system of records in accordance with
NARA-approved records schedule(s) and protection requirements for federal agencies to manage their electronic records in accordance with 36 CFR § 1236.20 & 1236.22 (ref. a), including but not limited to the following:
a. Maintenance of links between records and metadata, and
b. Categorization of records to manage retention and disposal, either through transfer of permanent records to NARA or deletion of temporary records in accordance with NARA-approved retention schedules.
5) The disposition of all FDA data shall be at the written direction of
HHS/FDA. This may include documents returned to FDA control;
destroyed; or held as specified until otherwise directed. Items returned to the Government shall be hand carried or sent by certified mail to the COR.
6) If the system involves the design, development, or operation of a system of records on individuals, the Contractor shall comply with the Privacy Act requirements from Section 3, as follows:
It has been determined that this contract is subject to the Privacy Act of 1974, because this contract provides for the design, development, or operation of a system of records about individuals.
The System of Records Notice (SORN) that is applicable to this contract is: [FDA requiring activity insert SORN number if one exists. If there is no SORN, indicate that a SORN will be developed].
The design, development, or operation work the Contractor is to perform is: [FDA requiring activity insert description of design, development, and/or operation work; see definitions in the FAR at
24.101 - Definitions].
The disposition to be made of the Privacy Act records upon completion of contract performance is: [FDA requiring activity insert records disposition instructions the contractor and any subcontractor must follow upon completion of contract performance].
C. Security Assessment and Authorization Process
1) The Contractor (and/or any subcontractor) shall comply with HHS/FDA and FedRAMP requirements as mandated by federal laws, regulations, and HHS/FDA policies, including making available any documentation, physical access, and logical access needed to support the SA&A requirement. The level of effort for the SA&A is based on the system’s FIPS 199 security categorization and HHS/FDA security policies.
a. In addition to the FedRAMP compliant ATO, the contractor shall complete and maintain an agency SA&A package to obtain agency ATO prior to system deployment/service implementation. The agency ATO must be approved by the FDA authorizing official (AO) prior to implementation of system.
b. CSP systems categorized as Federal Information Processing
Standards (FIPS) 199 high must leverage a FedRAMP accredited third-party assessment organization (3PAO); moderate impact CSP systems must make a best effort to use a FedRAMP accredited 3PAO. CSP systems categorized as FIPS 199 low impact may leverage a non-accredited, independent assessor.
c. For all acquired cloud services, the SA&A package must contain the following Documentation. See the SA&A package deliverables from Section 4 and/or deliverables mentioned in the FedRAMP Standard Contract Language available on the FedRAMP site.
Following the initial ATO, the Contractor must review and maintain the ATO in accordance with HHS/FDA policies.
2) DHS/HHS/FDA reserves the right to perform penetration testing (pen testing) on all systems operated on behalf of the agency. If DHS/HHS/FDA exercises this right, the Contractor (and/or any subcontractor) shall allow DHS/HHS/FDA employees (and/or designated third parties) to conduct Security Assessment activities to include control reviews in accordance with DHS/HHS/FDA requirements. Review activities include, but are not limited to, scanning operating systems, web applications, wireless scanning;
network device scanning to include routers, switches, and firewall, and IDS/IPS; databases and other applicable systems, including general support structure, that support the processing, transportation, storage, or security of Government information for vulnerabilities.
3) The Contractor must identify any gaps between required FedRAMP
Security Control Baseline/Continuous Monitoring controls and the contractor’s implementation status as documented in the Security
Assessment Report and related Continuous Monitoring artifacts. In addition, all gaps shall be documented and tracked by the contractor for mitigation in a Plan of Action and Milestones (POA&M) document. Depending on the severity of the risks, FDA may require remediation at the contractor’s expense, before FDA issues an ATO.
4) The Contractor (and/or any subcontractor) shall mitigate security risks for which they are responsible, including those identified during
SA&A and continuous monitoring activities. All vulnerabilities and other risk findings shall be remediated by the prescribed timelines from discovery: (1) critical and high vulnerabilities no later than thirty
(30) calendar days and (2) medium and low vulnerabilities no later than sixty (60) calendar days . In the event a vulnerability or other risk finding cannot be mitigated within the prescribed timelines above, they shall be added to the designated POA&M and mitigated within the newly designated timelines. FDA will determine the risk rating of vulnerabilities using FedRAMP baselines.
5) Revocation of a Cloud Service. HHS/FDA have the right to take action in response to the CSP’s lack of compliance and/or increased level of risk. In the event the CSP fails to meet HHS/FDA and FedRAMP security and privacy requirements and/or there is an incident involving sensitive information, HHS and/or FDA may suspend or revoke an existing agency ATO (either in part or in whole) and/or cease operations. If an ATO is suspended or revoked in accordance with this provision, the CO and/or COR may direct the CSP to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor information system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
D. Reporting and Continuous Monitoring
1) Following the initial ATOs, the Contractor (and/or any subcontractor) must perform the minimum ongoing continuous monitoring activities specified below, submit required deliverables by the specified due dates, and meet with the system/service owner and other relevant stakeholders to discuss the ongoing continuous monitoring activities, findings, and other relevant matters. The CSP will work with the agency to schedule ongoing continuous monitoring activities.
(i)
2) At a minimum, the Contractor must provide the following artifacts/deliverables on a monthly Basis:
a. Operating system, database, Web application, and network vulnerability scan results;
b. Updated POA&Ms;
c. Any updated authorization package documentation as required by the annual attestation/assessment/review or as requested by the FDA System Owner or AO; and
d. Any configuration changes to the system and/or system components or CSP’s…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.