2_2_Attachment_J-1_Requirement_Certification.pdf
PDF 243 KB Posted
- Attached to
- Panic Button Device and Subscription Federal contract opportunity
- Solicitation number
- 9594CS25Q0050
About this file
Attachment J-1 is a Requirement Certification document for a wearable panic button system for Community Supervision Officers (CSOs). The document details comprehensive technical and functional requirements for a GPS-enabled panic button device and integrated iPhone application. Key specifications include: small, lightweight design attachable to belt/lanyard, ability to send location-based alerts to team members, automatic check-in tracking, emergency notification capabilities (including 911 alert if no response), and management tools for monitoring team locations.
The system must support discreet team communication, enable CSOs to schedule and confirm check-ins during field activities, and provide backup alert features. The panic button must have sufficient button resistance to prevent false alerts and integrate with agency-issued iPhones. Additional requirements cover security protocols, including compliance with Federal Information Security Modernization Act (FISMA), Fed RAMP guidelines, and specific security control implementations for cloud-based services. The contract opportunity seeks to purchase between 150-250 devices with an accompanying safety application for community supervision operations.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 2_2_9594CS25Q0050.pdf | ||
| 2_2_Attachment_J-2_Solicitation_Price_Sheet.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
9594CS25Q0050
Attachment J-1: Requirement Certification
Section Description of Requirements Compliance Yes/No Comment
C.2.2.1 The panic button and its integrated app should utilize Global Positioning System (GPS) and may use additional technologies to provide accurate location information.
C.2.2.2 The integrated application shall be functional on agency-issued iPhones.
C.2.2.3
The wearable panic button and integrated iPhone application will be assigned to individual Community Supervision Officers (CSO’s) to be used when conducting home visits or other field activities to meet with supervised offenders or collateral contacts. CSO’s may conduct this work individually or in pairs.
C.2.2.4
The wearable panic buttons should have management tools which enable management to monitor their team’s location or communicate with all team members at any given time. The wearable panic button should have the capability to broadcast to a specific team, if possible.
C.2.2.5 Alert notifications shall be scalable to discreet teams or a combination of teams across the agency.
C.2.2.6
Wearable panic button specifications and features:
a. Small, lightweight, able to fit in a pocket.
b. Attachable to a belt, lanyard or protective vest.
c. A pressable button, that when first pushed sends an alert message to team members, including the CSO’s location, SCSOs, and fellow team members.
d. The pressable button should have resistance sufficient to avoid false alerts if the button is bumped or brushed.
e. The alert and integrated application should have backup features:
i. Alerts resulting from a pressed panic button or from a non-response to a scheduled checkin shall issue an alert on the team’s and SCSO’s phone applications indicating the CSO’s location (via GPS)
ii. The phone application shall allow the supervisor or other team members to text, email, or call the CSO
iii. If no one responds to the alert within a fixed interval (such as 30 seconds) the system shall alert 911, providing the CSO’s name and location.
C.2.2.7
Check-ins, Notifications & Alarms:
a. The application shall allow a CSO to schedule an itinerary of check-ins recording the intended date, time, and location.
b. The application shall notify workers when they should check-in:
i. When a CSO arrives at an address on the itinerary, the application automatically starts the check-in, or the CSO can manually start it on the application.
ii. A manual confirmation by the CSO on the application will notify the SCSO that the CSO has “checked in,” confirming his or her safety at that moment on the visit.
iii. The application shall automatically alert the SCSO (or other manually added contacts) if a CSO does not check-in within a fixed amount of time upon starting a visit and at scheduled intervals during the visit.
iv. The application shall allow users to manually increase or decrease the interval for check-ins.
v. The application shall allow check-in alerts to occur by
SMS, email or phone call.
c. Location tracking and data storage shall only be active while a CSO is in an active check-in event, or when he/she hits a panic button on the wearable device or in the application.
C.2.2.8
Dashboard(s): The system should have an interface that provides users and supervisors with key data and features that are easy to access and to understand.
C.2.2.9
Report capabilities: the applications computer management system shall have:
a. A broad range of readily available reports useful on the team, branch, division or enterprise levels.
b. Customizable report capability.
C.2.2.10
Application Programming Interface (API). The Contractor shall provide a Representational State Transfer (REST) Application Programming Interface (API) affording CSOSA the opportunity to fetch records relevant to its use of the Contractor’s Case Management System (CMS) on demand over a secured Hypertext Transport Protocol (HTTPS) connection. The API shall:
a. Support changes (i.e., insert/update/delete operations) performed against the Contractor’s CMS.
b. Be accessible to authorized CSOSA staff within thirty days of task order award.
c. Accept JavaScript Object Notation (JSON) blocks as requests.
d. Return JSON blocks as responses.
e. Include endpoints for retrieving system user records identifying and characterizing CSOSA users and vendor agents who have inserted/updated/deleted records related to CSOSA personnel, team configurations, event check-ins or alerts, and event locations.
H.1 H.1 CSOSA Contractor Information Security Requirements.
H.1.1
The Contractor shall meet and comply with Federal laws, Executive Orders, directives, policies, regulations, standards, and guidance, as amended and extended, for the protection of the information system and information during processing, while in storage, and during transmission. The Contractor shall be required to comply with, at a minimum:
a. Federal Information Security Modernization Act of 2014
(FISMA)
b. Office of Management and Budget (OMB) Circular and
Memoranda (e.g. Circular A-130)
c. U.S. Department of Homeland Security Directives (e.g.
US-CERT and HSPD-12)
d. National Institute of Standards and Technology (NIST)
Federal Information Processing Standards (FIPS) and Special Publication (SP) 800 Series (e.g. FIPS 200, FIPS 199, FIPS 140-2, SP 800-18, SP 800-37, SP 800-53 Rev
4, SP 800-60)
H.1.2 The Federal Information Security Modernization Act of 2014 (FISMA) requires the head of each agency to provide information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information. It requires those measures to be in place for information collected or maintained by or on behalf of the agency; and information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.
H.1.2.1
The law defines the term "information security" to mean protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide:
a. Integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;
b. Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information;
and
c. Availability, which means ensuring timely and reliable access to and use of information.
H.1.2.2
The Contractor shall provide and implement security controls, as selected by CSOSA, to meet the security requirements for a Moderate impact level system as defined in NIST SP 800- 53 (as amended), Security and Privacy Controls for Federal Information Systems and Organizations.
H.1.2.3
Executive departments and agencies procuring commercial and non-commercial cloud services, or systems provided or managed by other departments or agencies, contractors, or other sources shall comply with FISMA requirements. The Federal Risk and Authorization Management Program (Fed RAMP) is a government-wide program that provides a standardized approach to FISMA compliance as it applies to cloud-based computing services. It oversees and standardizes how to do security assessments, authorizations, and continuous monitoring for cloud products and services.
Fed RAMP requirements apply to all cloud deployment models (e.g., Public Clouds, Community Clouds, Private Clouds, Hybrid Clouds); and all cloud service models (e.g., Infrastructure as a Service, Platform as a Service, Software as a Service) as defined by the National Institute of Standards and Technology (NIST).
H.2
Security Assessment and Authorization, and Continuous Monitoring. The Contractor shall apply the appropriate set of baseline security controls as required in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 (as amended), Security and Privacy Controls for Federal Information Systems and Organizations.
H.2.1
The Contractor shall be responsible for the cost of preparing the Security Authorization Package using NIST SP 800-37 (as amended) Guide for Applying the Risk Management Framework to Federal Information Systems (using Fed RAMP templates, where available) and maintaining compliance.
H.2.2
The Contractor shall be able to maintain a security management continuous monitoring environment that meets or exceeds the Continuous Monitoring requirements in SP 800-37, Appendix G.
H.3 Requirements for Externally Hosted Services and Applications. Since the Contractor's CMS is external to CSOSA the following requirements also apply:
H.3.1
CSOSA reserves the right to perform Penetration Testing. If CSOSA exercises this right, the Contractor shall allow Government employees (or designated third parties) to conduct Security Assessment activities to include control reviews in accordance with Fed RAMP requirements. Review activities include but are not limited to scanning operating systems , web applications, wireless scanning; network device scanning to include routers, switches, and firewall, and IDS/IPS; databases and other applicable systems, including general support structure, that support the processing, transportation, storage, or security of Government information for vulnerabilities.
H.3.2
Identified gaps between required Security Controls and the Contractor's implementation as documented in the System Security Plan (SSP) shall be tracked by the Contractor for mitigation in a Plan of Action and Milestones (POA&M) document.
H.3.3
The Contractor is responsible for mitigating all security risks found during security assessment and accreditation and continuous monitoring activities. All high-risk vulnerabilities shall be mitigated within 30 days and all moderate risk vulnerabilities shall be mitigated within 90 days from the date vulnerabilities are formally identified.
H.3.4
The Contractor shall provide access to the Federal Government, or their designee acting as their agent, when requested, in order to verify compliance. CSOSA reserves the right to conduct onsite inspections. The Contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review.
H.3.5
CSOSA has the right to perform manual or automated audits, scans, reviews, or other inspections of the Contractor's Information Technology (IT) environment being used to provide or facilitate services for CSOSA. In accordance with the Federal Acquisitions Regulations (FAR) clause 52.239-1, the Contractor shall be responsible for the following security safeguards:
H.3.6
The Contractor shall not publish or disclose in any manner, without the CO's written consent, the details of any safeguards either designed or developed by the Contractor under this purchase order or otherwise provided by CSOSA.
H.3.7
H.3.7 To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor shall afford CSOSA access to the Contractor's facilities, installations, technical capabilities, operations, documentation, records, and databases within 72 hours. The program of inspection shall include, but is not limited to:
a. Authenticated and unauthenticated operating system/network vulnerability scans;
b. Authenticated and unauthenticated web application vulnerability scans;
c. Authenticated and unauthenticated database application vulnerability scans; and
d. Automated scans can be performed by Government personnel, or agents acting on behalf of CSOSA, using
Government operated equipment, and Government specified tools.
H.3.8
If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.
H.3.9
If the Contractor chooses to run its own automated scans or audits, results from these scans may, at CSOSA's discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by CSOSA. In addition, the results of Contractor-conducted scans shall be provided, in full, to
CSOSA.
H.3.10
CSOSA may choose to cancel for convenience the (Contract/Award) if the Contractor has its authorization revoked and the deficiencies are greater than agency risk tolerance thresholds.
H.3.11
The Contractor shall comply with CSOSA security and privacy requirements (subject to change by the CSOSA Information Security Office) and as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.
H.3.12 The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this purchase order.
H.3.13
The Contractor shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this purchase order should be considered as Controlled Unclassified Information (CUI). It is anticipated that this information will be gathered, created, and stored within the primary work location. If Contractor personnel shall remove any information from the primary work area they should protect it to the same extent they would their proprietary data and/or company trade secrets.
H.3.14
CSOSA shall retain unrestricted rights to government data.
The ordering activity retains ownership of any user created/loaded data and applications hosted on Contractor's infrastructure, as well as maintains the right to request full copies of these at any time.
H.3.15
The Contractor shall ensure that the facilities that house the network infrastructure are physically secure. The data shall be available to CSOSA upon request within one business day or within the timeframe specified otherwise, and shall not be used for any other purpose other than that specified herein.
H.3.16
The Contractor shall provide requested data at no additional cost to CSOSA. No data shall be released by the Contractor without the consent of CSOSA in writing. All requests for release shall be submitted in writing to the CO.
H.3.17
The Contractor shall provide full access and cooperation for all activities determined by CSOSA to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of cyber incidents.
H.3.18 The Contractor shall be responsible for all costs and related resource allocations required for all subsequent incident response activities determined to be required by CSOSA, whether incurred by Government, agents under purchase order or on assignment to CSOSA, or by third party firms.
H.4
Additional Requirements for CSP hosted Services and Applications. If the Contractor's CMS is hosted in a commercial cloud service provider (CSP) environment like MS Azure, Amazon Web Services (AWS), IBM Cloud, Google Cloud, or similar the following requirements apply. The preferred level of Fed RAMP compliance status is moderate.
H.4.1
The Contractor shall implement the controls contained within the Fed RAMP Security Controls Baseline, and Fed RAMP Continuous Monitoring Strategy Guide available at the Fed RAMP website https://www.fedramp.gov/documents. These documents define requirements for compliance to meet minimum Federal information security requirements.
H.4.2
The Contractor shall follow Fed RAMP guidelines and security guidance. In situations where there are no procedural guides, the Contractor shall use generally accepted industry best practices for information security.
H.4.3
The Contractor shall be responsible for the cost of preparing the Security Authorization Package using the Fed RAMP Security Assessment Framework (SAF) process (using Fed RAMP templates, where available) and maintaining compliance.
H.4.4 The Contractor shall be responsible for preparing the Security Authorization Package using the Fed RAMP SAF Process and Fed RAMP Security Control Baseline Workbook.
H.4.5
The Contractor shall comply with Fed RAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.
H.4.6 The Contractor shall create, maintain and update the documentation using Fed RAMP requirements and templates, which are available at https://www.fedramp.gov/templates/.
H.4.7
The Contractor shall use an accredited Third-Party Assessment Organization (3PAO) whenever there is a significant change to the system's security posture in accordance with the Fed RAMP Continuous Monitoring Strategy Guide.
H.4.8
To the extent required to carry out the Fed RAMP Security Assessment and Authorization (SA&A) Process (also known as the Federal Risk and Authorization Management Program) and Fed RAMP Continuous Monitoring, to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public Government data collected and stored by the Contractor, the Contractor shall afford CSOSA access to the Contractor's facilities, installations, technical capabilities, operations, documentation, records, and databases.
H.4.9
If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.
https://www.fedramp.gov/documents https://www.fedramp.gov/templates/
Quoter’s name and title
Quoter’s signature
Date
| Compliance YesNoThe panic button and its integrated app should utilize Global Positioning System GPS and may use additional technologies to provide accurate location information: |
| CommentThe panic button and its integrated app should utilize Global Positioning System GPS and may use additional technologies to provide accurate location information: |
| Compliance YesNoThe integrated application shall be functional on agency issued iPhones: |
| CommentThe integrated application shall be functional on agency issued iPhones: |
| Compliance YesNoThe wearable panic button and integrated iPhone application will be assigned to individual Community Supervision Officers CSOs to be used when conducting home visits or other field activities to meet with supervised offenders or collateral contacts CSOs may conduct this work individually or in pairs: |
| CommentThe wearable panic button and integrated iPhone application will be assigned to individual Community Supervision Officers CSOs to be used when conducting home visits or other field activities to meet with supervised offenders or collateral contacts CSOs may conduct this work individually or in pairs: |
| Compliance YesNoThe wearable panic buttons should have management tools which enable management to monitor their teams location or communicate with all team members at any given time The wearable panic button should have the capability to broadcast to a specific team if possible: |
| CommentThe wearable panic buttons should have management tools which enable management to monitor their teams location or communicate with all team members at any given time The wearable panic button should have the capability to broadcast to a specific team if possible: |
| Compliance YesNoAlert notifications shall be scalable to discreet teams or a combination of teams across the agency: |
| CommentAlert notifications shall be scalable to discreet teams or a combination of teams across the agency: |
| Compliance YesNoWearable panic button specifications and features a Small lightweight able to fit in a pocket b Attachable to a belt lanyard or protective vest c A pressable button that when first pushed sends an alert message to team members including the CSOs location SCSOs and fellow team members d The pressable button should have resistance sufficient to avoid false alerts if the button is bumped or brushed e The alert and integrated application should have backup features i Alerts resulting from a pressed panic button or from a nonresponse to a scheduled checkin shall issue an alert on the teams and SCSOs phone applications indicating the CSOs location via GPS ii The phone application shall allow the supervisor or other team members to text email or call the CSO iii If no one responds to the alert within a fixed interval such as 30 seconds the system shall alert 911 providing the CSOs name and location: |
| CommentWearable panic button specifications and features a Small lightweight able to fit in a pocket b Attachable to a belt lanyard or protective vest c A pressable button that when first pushed sends an alert message to team members including the CSOs location SCSOs and fellow team members d The pressable button should have resistance sufficient to avoid false alerts if the button is bumped or brushed e The alert and integrated application should have backup features i Alerts resulting from a pressed panic button or from a nonresponse to a scheduled checkin shall issue an alert on the teams and SCSOs phone applications indicating the CSOs location via GPS ii The phone application shall allow the supervisor or other team members to text email or call the CSO iii If no one responds to the alert within a fixed interval such as 30 seconds the system shall alert 911 providing the CSOs name and location: |
| Compliance YesNoCheckins Notifications Alarms a The application shall allow a CSO to schedule an itinerary of checkins recording the intended date time and location b The application shall notify workers when they should checkin i When a CSO arrives at an address on the itinerary the application automatically starts the checkin or the CSO can manually start it on the application ii A manual confirmation by the CSO on the application will notify the SCSO that the CSO has checked in confirming his or her safety at that moment on the visit iii The application shall automatically alert the SCSO or other manually added contacts if a CSO does not check in within a fixed amount of time upon starting a visit and at scheduled intervals during the visit: |
| CommentCheckins Notifications Alarms a The application shall allow a CSO to schedule an itinerary of checkins recording the intended date time and location b The application shall notify workers when they should checkin i When a CSO arrives at an address on the itinerary the application automatically starts the checkin or the CSO can manually start it on the application ii A manual confirmation by the CSO on the application will notify the SCSO that the CSO has checked in confirming his or her safety at that moment on the visit iii The application shall automatically alert the SCSO or other manually added contacts if a CSO does not check in within a fixed amount of time upon starting a visit and at scheduled intervals during the visit: |
| iv The application shall allow users to manually increase or decrease the interval for checkins v The application shall allow checkin alerts to occur by SMS email or phone call c Location tracking and data storage shall only be active while a CSO is in an active checkin event or when heshe hits a panic button on the wearable device or in the application: |
| Dashboards The system should have an interface that provides users and supervisors with key data and features that are easy to access and to understand: |
| Report capabilities the applications computer management system shall have a A broad range of readily available reports useful on the team branch division or enterprise levels b Customizable report capability: |
| Application Programming Interface API The Contractor shall provide a Representational State Transfer REST Application Programming Interface API affording CSOSA the opportunity to fetch records relevant to its use of the Contractors Case Management System CMS on demand over a secured Hypertext Transport Protocol HTTPS connection The API shall a Support changes ie insertupdatedelete operations performed against the Contractors CMS b Be accessible to authorized CSOSA staff within thirty days of task order award c Accept JavaScript Object Notation JSON blocks as requests d Return JSON blocks as responses e Include endpoints for retrieving system user records identifying and characterizing CSOSA users and vendor agents who have insertedupdateddeleted records related to CSOSA personnel team configurations event checkins or alerts and event locations: |
| H1 CSOSA Contractor Information Security Requirements: |
| The Contractor shall meet and comply with Federal laws Executive Orders directives policies regulations standards and guidance as amended and extended for the protection of the information system and information during processing while in storage and during transmission The Contractor shall be required to comply with at a minimum a Federal Information Security Modernization Act of 2014 FISMA b Office of Management and Budget OMB Circular and Memoranda eg Circular A130 c US Department of Homeland Security Directives eg USCERT and HSPD12 d National Institute of Standards and Technology NIST Federal Information Processing Standards FIPS and Special Publication SP 800 Series eg FIPS 200 FIPS 199 FIPS 1402 SP 80018 SP 80037 SP 80053 Rev 4 SP 80060: |
| The Federal Information Security Modernization Act of 2014 FISMA requires the head of each agency to provide information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized: |
| access use disclosure disruption modification or destruction of information It requires those measures to be in place for information collected or maintained by or on behalf of the agency and information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency: |
| The law defines the term information security to mean protecting information and information systems from unauthorized access use disclosure disruption modification or destruction in order to provide a Integrity which means guarding against improper information modification or destruction and includes ensuring information nonrepudiation and authenticity b Confidentiality which means preserving authorized restrictions on access and disclosure including means for protecting personal privacy and proprietary information and c Availability which means ensuring timely and reliable access to and use of information: |
| The Contractor shall provide and implement security controls as selected by CSOSA to meet the security requirements for a Moderate impact level system as defined in NIST SP 800 53 as amended Security and Privacy Controls for Federal Information Systems and Organizations: |
| Executive departments and agencies procuring commercial and noncommercial cloud services or systems provided or managed by other departments or agencies contractors or other sources shall comply with FISMA requirements The Federal Risk and Authorization Management Program Fed RAMP is a governmentwide program that provides a standardized approach to FISMA compliance as it applies to cloudbased computing services It oversees and standardizes how to do security assessments authorizations and continuous monitoring for cloud products and services Fed RAMP requirements apply to all cloud deployment models eg Public Clouds Community Clouds Private Clouds Hybrid Clouds and all cloud service models eg Infrastructure as a Service Platform as a Service Software as a Service as defined by the National Institute of Standards and Technology NIST: |
| H2: |
| Security Assessment and Authorization and Continuous Monitoring The Contractor shall apply the appropriate set of baseline security controls as required in the National Institute of Standards and Technology NIST Special Publication SP 80053 as amended Security and Privacy Controls for Federal Information Systems and Organizations: |
| H21: |
| The Contractor shall be responsible for the cost of preparing the Security Authorization Package using NIST SP 80037 as amended Guide for Applying the Risk Management Framework to Federal Information Systems using Fed RAMP templates where available and maintaining compliance: |
| H22: |
| The Contractor shall be able to maintain a security management continuous monitoring environment that meets or exceeds the Continuous Monitoring requirements in SP 80037 Appendix G: |
| Requirements for Externally Hosted Services and Applications Since the Contractor s CMS is external to CSOSA the following requirements also apply: |
| CSOSA reserves the right to perform Penetration Testing If CSOSA exercises this right the Contractor shall allow Government employees or designated third parties to conduct Security Assessment activities to include control reviews in accordance with Fed RAMP requirements Review activities include but are not limited to scanning operating systems web applications wireless scanning network device scanning to include routers switches and firewall and IDSIPS databases and other applicable systems including general support structure that support the processing transportation storage or security of Government information for vulnerabilities: |
| Identified gaps between required Security Controls and the Contractor s implementation as documented in the System Security Plan SSP shall be tracked by the Contractor for mitigation in a Plan of Action and Milestones POAM document: |
| The Contractor is responsible for mitigating all security risks found during security assessment and accreditation and continuous monitoring activities All highrisk vulnerabilities shall be mitigated within 30 days and all moderate risk vulnerabilities shall be mitigated within 90 days from the date vulnerabilities are formally identified: |
| The Contractor shall provide access to the Federal Government or their designee acting as their agent when requested in order to verify compliance CSOSA reserves the right to conduct onsite inspections The Contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review: |
| CSOSA has the right to perform manual or automated audits scans reviews or other inspections of the Contractor s Information Technology IT environment being used to provide or facilitate services for CSOSA In accordance with the Federal Acquisitions Regulations FAR clause 522391 the Contractor shall be responsible for the following security safeguards: |
| The Contractor shall not publish or disclose in any manner without the COs written consent the details of any safeguards either designed or developed by the Contractor under this purchase order or otherwise provided by CSOSA: |
| H37 To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security integrity and confidentiality of Government data the Contractor shall afford CSOSA access to the Contractors facilities installations technical capabilities operations documentation records and databases within 72 hours The program of inspection shall include but is not limited to a Authenticated and unauthenticated operating systemnetwork vulnerability scans b Authenticated and unauthenticated web application vulnerability scans c Authenticated and unauthenticated database application vulnerability scans and d Automated scans can be performed by Government personnel or agents acting on behalf of CSOSA using: |
| Government operated equipment and Government specified tools: |
| If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor or if existing safeguards have ceased to function the discoverer shall immediately bring the situation to the attention of the other party: |
| If the Contractor chooses to run its own automated scans or audits results from these scans may at CSOSAs discretion be accepted in lieu of Government performed vulnerability scans In these cases scanning tools and their configuration shall be approved by CSOSA In addition the results of Contractorconducted scans shall be provided in full to CSOSA: |
| CSOSA may choose to cancel for convenience the ContractAward if the Contractor has its authorization revoked and the deficiencies are greater than agency risk tolerance thresholds: |
| The Contractor shall comply with CSOSA security and privacy requirements subject to change by the CSOSA Information Security Office and as mandated by Federal laws and policies including making available any documentation physical access and logical access needed to support this requirement: |
| The Contractor shall be responsible for properly protecting all information used gathered or developed as a result of work under this purchase order: |
| The Contractor shall also protect all Government data equipment etc by treating the information as sensitive All information about the systems gathered or created under this purchase order should be considered as Controlled Unclassified Information CUI It is anticipated that this information will be gathered created and stored within the primary work location If Contractor personnel shall remove any information from the primary work area they should protect it to the same extent they would their proprietary data andor company trade secrets: |
| CSOSA shall retain unrestricted rights to government data The ordering activity retains ownership of any user createdloaded data and applications hosted on Contractor s infrastructure as well as maintains the right to request full copies of these at any time: |
| The Contractor shall ensure that the facilities that house the network infrastructure are physically secure The data shall be available to CSOSA upon request within one business day or within the timeframe specified otherwise and shall not be used for any other purpose other than that specified herein: |
| The Contractor shall provide requested data at no additional cost to CSOSA No data shall be released by the Contractor without the consent of CSOSA in writing All requests for release shall be submitted in writing to the CO: |
| The Contractor shall provide full access and cooperation for all activities determined by CSOSA to be required to ensure an effective incident response including providing all requested images log files and event information to facilitate rapid resolution of cyber incidents: |
| The Contractor shall be responsible for all costs and related resource allocations required for all subsequent incident response activities determined to be required by CSOSA: |
| whether incurred by Government agents under purchase order or on assignment to CSOSA or by third party firms: |
| Additional Requirements for CSP hosted Services and Applications If the Contractors CMS is hosted in a commercial cloud service provider CSP environment like MS Azure Amazon Web Services AWS IBM Cloud Google Cloud or similar the following requirements apply The preferred level of Fed RAMP compliance status is moderate: |
| The Contractor shall implement the controls contained within the Fed RAMP Security Controls Baseline and Fed RAMP Continuous Monitoring Strategy Guide available at the Fed RAMP website httpswwwfedrampgovdocuments These documents define requirements for compliance to meet minimum Federal information security requirements: |
| The Contractor shall follow Fed RAMP guidelines and security guidance In situations where there are no procedural guides the Contractor shall use generally accepted industry best practices for information security: |
| The Contractor shall be responsible for the cost of preparing the Security Authorization Package using the Fed RAMP Security Assessment Framework SAF process using Fed RAMP templates where available and maintaining compliance: |
| The Contractor shall be responsible for preparing the Security Authorization Package using the Fed RAMP SAF Process and Fed RAMP Security Control Baseline Workbook: |
| The Contractor shall comply with Fed RAMP requirements as mandated by Federal laws and policies including making available any documentation physical access and logical access needed to support this requirement: |
| The Contractor shall create maintain and update the documentation using Fed RAMP requirements and templates which are available at httpswwwfedrampgovtemplates: |
| The Contractor shall use an accredited ThirdParty Assessment Organization 3PAO whenever there is a significant change to the systems security posture in accordance with the Fed RAMP Continuous Monitoring Strategy Guide: |
| To the extent required to carry out the Fed RAMP Security Assessment and Authorization SAA Process also known as the Federal Risk and Authorization Management Program and Fed RAMP Continuous Monitoring to safeguard against threats and hazards to the security integrity and confidentiality of any nonpublic Government data collected and stored by the Contractor the Contractor shall afford CSOSA access to the Contractor s facilities installations technical capabilities operations documentation records and databases: |
| If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor or if existing safeguards have ceased to function the discoverer shall immediately bring the situation to the attention of the other party_2: |
| Quoters name and title: |
| Date: |
| Text1: |
| Text2: |
| Text3: |
| Text4: |
| Text5: |
| Text6: |
| Text7: |
| Text8: |
| Text9: |
| Text10: |
| Text11: |
| Text12: |
| Text13: |
| Text14: |
| Text15: |
| Text16: |
| Text17: |
| Text18: |
| Text19: |
| Text20: |
| Text21: |
| Text22: |
| Text23: |
| Text24: |
| Text25: |
| Text26: |
| Text27: |
| Text28: |
| Text29: |
| Text30: |
| Text31: |
| Text32: |
| Text33: |
| Text34: |
| Text35: |
| Text36: |
| Text37: |
| Text38: |
| Text39: |
| Text40: |
| Text41: |
File details come from the government source that posted it. Updated .