2_2_Attachment_J-1_Requirement_Certification.pdf

PDF 218 KB Posted

Attached to
Remote Monitoring Device Federal contract opportunity
Solicitation number
9594CS25Q0061
Issued by
Court Services and Offender Supervision Agency

About this file

Attachment J-1 is a Requirement Certification document for a remote offender monitoring solution that details comprehensive technical specifications for computer and internet activity tracking. The document outlines extensive requirements for a software solution that enables Community Supervision Case Officers (CSOs) to monitor offenders' digital activities 24/7 across Windows, Mac OS, Android, and iOS devices, including capabilities such as capturing computer use, internet browsing, communication activities, file transfers, screen captures, application blocking, and keystroke tracking.

The technical requirements include a dedicated web-based interface for CSOs with multiple access levels, remote installation and removal of monitoring software, on-call technical support, comprehensive training provisions, and stringent information security protocols. Additional requirements mandate compliance with Federal Risk and Authorization Management Program (FedRAMP) standards, continuous monitoring, vulnerability scanning, and robust data protection measures. The solution must facilitate detailed reporting, immediate alert notifications, and provide CSOs with extensive configuration options for monitoring individual offenders or groups, with the overarching goal of enabling remote supervision of offenders' digital interactions.

View the file

Other files for this federal contract opportunity

Other files attached to Remote Monitoring Device, newest first.
File Type Posted
2_2_Attachment_J-2_Solicitation_Price_Sheet.pdf PDF
2_2_9594CS25Q0061.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

9594CS25Q0061

Attachment J-1: Requirement Certification

Section Description of Requirements Compliance Yes/No Comment

C.2.1 & C.3.1

Data Capture. 24 hours a day, seven (7) days a week data capture of offender’s computer and internet usage and activities on Windows, Mac OS, Android, and iOS devices.

A. Computer Use – Collect all use of monitored computer/device, i.e. program/application uses, login/logout, file creation/access/modification.

B. Internet Browser Activity – Collect all internet browser activity captured by Uniform Resource Locator (URL) and designated by browser used with data and time accessed.

C. Communication Activity – Capture email, chat/IM, video communication. (Screen captures may satisfy the minimum requirement. Full text or HTML of all chat/IM, email, or any other web-based chat communications exceeds the minimum requirements).

D. Program and Application Activity – Capture use of programs and application by data and time accessed.

E. File Transfer Activity – Capture files sent/received by computer device.

F. File Activity - Capture files created/modified/accessed activity by the computer device.

G. External Media, Human Interface Device(s) and/or Peripheral(s) Device Activity – Capture external (non-resident) media device access such as USB flash drives, network-connected hard drives/storage, wireless hard drives, and any other media storage device not resident to the monitored device to include cloud storage.

H. Screen Capture – The solution shall permit for the ability to capture screen activity (screen shot) of the monitored devices, and shall be configurable based on identified keyword, application/program usage, or time intervals.

I. Application/Program/Website blocking – The solution shall permit for the ability to configure and block identified application(s), program(s), and website(s) from being used or accessed on the monitored device.

J. Data Review – The solution shall provide the review of all flagged data collected for validity based on case profile(s).

K. Image Analysis – The solution shall review all images, screenshots, and videos collected by the solution for validity based on case profile(s).

L. Alerts and Reports – The solution shall provide immediate alert notification(s), as well as time set interval reports, based on identified risk(s) such as keyword(s) or application(s) by email, text, or telephone contact.

M. Keystroke Activity – The solution shall capture user keystroke activity.

C.2.2 & C.2.3

Remote Access via Dedicated Interface. The contractor shall provide CSOs 24 hours a day, seven (7) days a week remote access to the dedicated interface through which the solution’s features and reports are accessible.

A. All access shall be web based and accessible by web browser by traditional and mobile computer devices, without the use of any third-party software interface.

B. The contractor shall maintain and provide login ID and temporary passwords for all CSOs upon request. The interface shall allow CSOs to create unique login and passwords upon creation of an account.

C. The interface shall provide the CSOs the ability to view, print, download, and enter/modify offender information.

D. The interface shall allow the CSO to enroll defendants/offenders with offender profile information, choose specific monitoring protocols, restrictions, exclusions from monitoring, and delineate key alerts, suspicious activity notifications, and innocuous activities;

and other tasks as noted in C.3.1 Task 1- Data Capture.

E. Upon CSO enrollment of a offender into the contractor's solution, the contractor's solution shall confirm enrollment with the CSO.

F. The interface shall provide multiple (hierarchical) levels of access, up to an enterprise level of access that enables the COR to view all users and connected devices, active and inactive, searchable by install and uninstall dates.

G. The interface shall provide for the management and configuration of persons under supervision “case” on an individual case level as well as group.

H. The contractor's solution shall possess the capability to capture each CSO's access and utilization of the solution;

provide offender enrollment, removal, and modification capability; key alert summary reports; and other customized reports as designated by the COR.

I. The interface shall provide the ability to create, customize, configure, and assign case type profile(s) to a case(s) and group(s).

J. The interface shall provide the ability to create, customize, configure, and assign individual and group keywords of interest to be noted in data collection to individual cases and groups.

K. The interface shall provide the ability to create, customize, configure, and assign individual and group application(s)/program(s) of interest to be noted in the data collection to individual cases and groups.

L. The interface shall provide the ability to create, customize, configure, and assign reports for individual cases and group.

M. The interface shall provide reports on:

1. The number of devices installed and active the present day or within a searchable date range.

2. The number of devices that failed to connect for three (3) days.

3. The number of devices that failed to connect for seven (7) days.

C.2.3 & C.3.3

Physical and/or Remote Installation and Removal of Hardware and/or Software - The solution shall be able to be installed and uninstalled by CSO or contractor.

A. The solution shall have the ability to be installed and uninstalled by a CSO as well as the contractor by scheduled appointment.

B. The offeror shall provide a solution for physical installation and removal of hardware and/or software to accomplish the following objectives for this task as follows:

1. The contractor shall provide all necessary equipment and software required to install and remove the monitoring solution software.

2. The monitoring solution shall be installable by both the contractor, by service appointment, and CSO without the aid of contractor.

3. The contractor shall provide all required training, notes, or other details for installation.

4. The solution shall notify the assigned CSO of installation completion.

5. The contactor’s solution shall facilitate the installation of monitoring software no more than three (3) business days after enrollment when a request for contractor installation is submitted.

C.2.4 & C.3.4

Technical Support. On-call 24 hours a day, seven (7) days a week technical support.

A. The contractor shall aid and inform CSOs regarding all functions of the contractor’s solution.

B. The contractor shall provide contact information for technical assistance to all CSOs, including after hours and on-call procedures.

C. The contractor shall provide CSOs with digital copies of captured and stored data documents and data retrieval and preparation, if needed.

D. The contractor shall address and provide detailed response for all assistance requests in a reasonable time frame.

C.2.5 & C.3.5

Training. The contractor shall provide training to the CSO staff on the installation, use, and maintenance of the monitoring solution. This should include training to ensure CSOs meet the minimum standard in usage of the solution.

A. Training shall be available and provided to all CSOs using the solution.

B. The contractor shall develop training for the installation and removal of the monitoring solution.

C. The contractor shall provide training for the overall use of the dedicated interface.

D. The contractor shall provide training on the overall functionality of the contractor’s solution.

E. Within thirty (30) calendar days contract award, the contractor shall provide to the COR a training program, to include content and materials, for training CSOs on the installation and implementation of the contractor's solution.

F. Training may be in the form of web-based modules, in-person presentations, video, or other formats as approved by the COR.

G. The contractor may provide up to six web-based training sessions per period of performance on technology refreshes, new features, or best practices for using the solution.

H. The Contractor shall provide a copy of any web-based training sessions to the COR in a SCROM file format, or a file convertible to a SCROM file format, that can be posted on the agency’s Learning Management System.

C.2.6 & C.3.6

Technology Refreshment. The contractor shall provide a technological refresh at any time during the period of performance, should a technological advancement occur that would enhance the contractor's ability to perform data capture and management.

A. The contractor shall provide a technological refresh on any identified services or abilities noted in this contract at any time during the period of performance, should a technological advancement occur that would enhance the contractor's ability to perform data capture and management.

B. The offeror shall provide a solution for technology refresh to accomplish the following objectives for this task as follows:

1. The contractor shall coordinate with the COR on scheduled releases because of implementation of new technology and associated training within 30 days of the release.

2. The Contractor shall provide written notification in writing via email, text, or alert via dedicated interface at least 24 hours in advance of any scheduled service outages.

3. CSOSA reserves the right to modify its stated requirements per platform to take advantage of emerging technologies and enhanced capabilities to allow for optimal monitoring.

4. The contractor shall only provide software that is the most recent generation and supported by the manufacturer. Any replacement, new or upgraded software specifications and delivery information shall be submitted, in writing, to the COR and approved by the

CO.

5. The contractor shall immediately (no greater than 24 hours) to take documented measures to correct all failures and deficiencies resulting from software or services acquired under contract. During this time, the contractor shall provide the COR documentation related to the timeframe for full resolution. The contractor shall provide replacement software and/or hardware as needed.

6. Throughout the life of the contract, the contractor shall provide the most recent generation of reliable software, hardware, and support services to mitigate the risk of obsolescence of existing technology.

7. The contractor shall provide up-to-date monitoring to include the ability to monitor new operating systems (OS) releases within a maximum of six (6) months from release of OS developer’s kit or a maximum of 90 days from market launch (whichever is sooner).

C.2.7 & C.3.7

Application Programming Interface (API). The Contractor shall provide a Representational State Transfer (REST) Application Programming Interface (API) affording CSOSA the opportunity to fetch records relevant to its use of the Contractor’s Case Management System (CMS) on demand over a secured Hypertext Transport Protocol (HTTPS) connection. The API shall:

A. Support changes (i.e., insert/update/delete operations) performed against the Contractor’s CMS.

B. Be accessible to authorized CSOSA staff within thirty days of task order award.

C. Accept JavaScript Object Notation (JSON) blocks as requests.

D. Return JSON blocks as responses.

E. Include endpoints for retrieving system user records identifying and characterizing CSOSA users and vendor agents who have inserted/updated/deleted records related to CSOSA personnel, CSOSA team configurations, offender records, device type, device installation and uninstallation dates, invoice periods, line items, unit costs, and billable unit counts sufficient to support invoicing and CSOSA audits.

H.1 H.1 CSOSA Contractor Information Security Requirements.

H.1.1

The Contractor shall meet and comply with Federal laws, Executive Orders, directives, policies, regulations, standards, and guidance, as amended and extended, for the protection of the information system and information during processing, while in storage, and during transmission. The Contractor shall be required to comply with, at a minimum:

a. Federal Information Security Modernization Act of 2014

(FISMA)

b. Office of Management and Budget (OMB) Circular and

Memoranda (e.g. Circular A-130)

c. U.S. Department of Homeland Security Directives (e.g.

US-CERT and HSPD-12)

d. National Institute of Standards and Technology (NIST)

Federal Information Processing Standards (FIPS) and Special Publication (SP) 800 Series (e.g. FIPS 200, FIPS 199, FIPS 140-2, SP 800-18, SP 800-37, SP 800-53 Rev

4, SP 800-60)

H.1.2

The Federal Information Security Modernization Act of 2014 (FISMA) requires the head of each agency to provide information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information. It requires those measures to be in place for information collected or maintained by or on behalf of the agency; and information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.

H.1.2.1

The law defines the term "information security" to mean protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide:

a. Integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;

b. Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information;

and

c. Availability, which means ensuring timely and reliable access to and use of information.

H.1.2.2 The Contractor shall provide and implement security controls, as selected by CSOSA, to meet the security requirements for a Moderate impact level system as defined in NIST SP 800-

53 (as amended), Security and Privacy Controls for Federal Information Systems and Organizations.

H.1.2.3

Executive departments and agencies procuring commercial and non-commercial cloud services, or systems provided or managed by other departments or agencies, contractors, or other sources shall comply with FISMA requirements. The Federal Risk and Authorization Management Program (Fed RAMP) is a government-wide program that provides a standardized approach to FISMA compliance as it applies to cloud-based computing services. It oversees and standardizes how to do security assessments, authorizations, and continuous monitoring for cloud products and services.

Fed RAMP requirements apply to all cloud deployment models (e.g., Public Clouds, Community Clouds, Private Clouds, Hybrid Clouds); and all cloud service models (e.g., Infrastructure as a Service, Platform as a Service, Software as a Service) as defined by the National Institute of Standards and Technology (NIST).

H.2

Security Assessment and Authorization, and Continuous Monitoring. The Contractor shall apply the appropriate set of baseline security controls as required in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 (as amended), Security and Privacy Controls for Federal Information Systems and Organizations.

H.2.1

The Contractor shall be responsible for the cost of preparing the Security Authorization Package using NIST SP 800-37 (as amended) Guide for Applying the Risk Management Framework to Federal Information Systems (using Fed RAMP templates, where available) and maintaining compliance.

H.2.2

The Contractor shall be able to maintain a security management continuous monitoring environment that meets or exceeds the Continuous Monitoring requirements in SP 800-37, Appendix G.

H.3 Requirements for Externally Hosted Services and Applications. Since the Contractor's CMS is external to CSOSA the following requirements also apply:

H.3.1

CSOSA reserves the right to perform Penetration Testing. If CSOSA exercises this right, the Contractor shall allow Government employees (or designated third parties) to conduct Security Assessment activities to include control reviews in accordance with Fed RAMP requirements. Review activities include but are not limited to scanning operating systems , web applications, wireless scanning; network device scanning to include routers, switches, and firewall, and IDS/IPS; databases and other applicable systems, including general support structure, that support the processing, transportation, storage, or security of Government information for vulnerabilities.

H.3.2

Identified gaps between required Security Controls and the Contractor's implementation as documented in the System Security Plan (SSP) shall be tracked by the Contractor for mitigation in a Plan of Action and Milestones (POA&M) document.

H.3.3

The Contractor is responsible for mitigating all security risks found during security assessment and accreditation and continuous monitoring activities. All high-risk vulnerabilities shall be mitigated within 30 days and all moderate risk vulnerabilities shall be mitigated within 90 days from the date vulnerabilities are formally identified.

H.3.4

The Contractor shall provide access to the Federal Government, or their designee acting as their agent, when requested, in order to verify compliance. CSOSA reserves the right to conduct onsite inspections. The Contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review.

H.3.5

CSOSA has the right to perform manual or automated audits, scans, reviews, or other inspections of the Contractor's Information Technology (IT) environment being used to provide or facilitate services for CSOSA. In accordance with the Federal Acquisitions Regulations (FAR) clause 52.239-1, the Contractor shall be responsible for the following security safeguards:

H.3.6

The Contractor shall not publish or disclose in any manner, without the CO's written consent, the details of any safeguards either designed or developed by the Contractor under this purchase order or otherwise provided by CSOSA.

H.3.7

H.3.7 To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor shall afford CSOSA access to the Contractor's facilities, installations, technical capabilities, operations, documentation, records, and databases within 72 hours. The program of inspection shall include, but is not limited to:

a. Authenticated and unauthenticated operating system/network vulnerability scans;

b. Authenticated and unauthenticated web application vulnerability scans;

c. Authenticated and unauthenticated database application vulnerability scans; and

d. Automated scans can be performed by Government personnel, or agents acting on behalf of CSOSA, using Government operated equipment, and Government specified tools.

H.3.8

If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

H.3.9

If the Contractor chooses to run its own automated scans or audits, results from these scans may, at CSOSA's discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by CSOSA. In addition, the results of Contractor-conducted scans shall be provided, in full, to

CSOSA.

H.3.10

CSOSA may choose to cancel for convenience the (Contract/Award) if the Contractor has its authorization revoked and the deficiencies are greater than agency risk tolerance thresholds.

H.3.11

The Contractor shall comply with CSOSA security and privacy requirements (subject to change by the CSOSA Information Security Office) and as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.

H.3.12 The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this purchase order.

H.3.13

The Contractor shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this purchase order should be considered as Controlled Unclassified Information (CUI). It is anticipated that this information will be gathered, created, and stored within the primary work location. If Contractor personnel shall remove any information from the primary work area they should protect it to the same extent they would their proprietary data and/or company trade secrets.

H.3.14

CSOSA shall retain unrestricted rights to government data.

The ordering activity retains ownership of any user created/loaded data and applications hosted on Contractor's infrastructure, as well as maintains the right to request full copies of these at any time.

H.3.15

The Contractor shall ensure that the facilities that house the network infrastructure are physically secure. The data shall be available to CSOSA upon request within one business day or within the timeframe specified otherwise, and shall not be used for any other purpose other than that specified herein.

H.3.16

The Contractor shall provide requested data at no additional cost to CSOSA. No data shall be released by the Contractor without the consent of CSOSA in writing. All requests for release shall be submitted in writing to the CO.

H.3.17

The Contractor shall provide full access and cooperation for all activities determined by CSOSA to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of cyber incidents.

H.3.18

The Contractor shall be responsible for all costs and related resource allocations required for all subsequent incident response activities determined to be required by CSOSA, whether incurred by Government, agents under purchase order or on assignment to CSOSA, or by third party firms.

H.4

Additional Requirements for CSP hosted Services and Applications. If the Contractor's CMS is hosted in a commercial cloud service provider (CSP) environment like MS Azure, Amazon Web Services (AWS), IBM Cloud, Google Cloud, or similar the following requirements apply. The preferred level of Fed RAMP compliance status is moderate.

H.4.1

The Contractor shall implement the controls contained within the Fed RAMP Security Controls Baseline, and Fed RAMP Continuous Monitoring Strategy Guide available at the Fed RAMP website https://www.fedramp.gov/documents. These documents define requirements for compliance to meet minimum Federal information security requirements.

H.4.2

The Contractor shall follow Fed RAMP guidelines and security guidance. In situations where there are no procedural guides, the Contractor shall use generally accepted industry best practices for information security.

H.4.3

The Contractor shall be responsible for the cost of preparing the Security Authorization Package using the Fed RAMP Security Assessment Framework (SAF) process (using Fed RAMP templates, where available) and maintaining compliance.

H.4.4 The Contractor shall be responsible for preparing the Security Authorization Package using the Fed RAMP SAF Process and Fed RAMP Security Control Baseline Workbook.

H.4.5

The Contractor shall comply with Fed RAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.

H.4.6 The Contractor shall create, maintain and update the documentation using Fed RAMP requirements and templates, which are available at https://www.fedramp.gov/templates/.

H.4.7

The Contractor shall use an accredited Third-Party Assessment Organization (3PAO) whenever there is a significant change to the system's security posture in accordance with the Fed RAMP Continuous Monitoring Strategy Guide.

H.4.8

To the extent required to carry out the Fed RAMP Security Assessment and Authorization (SA&A) Process (also known as the Federal Risk and Authorization Management Program) and Fed RAMP Continuous Monitoring, to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public Government data collected and stored by the Contractor, the Contractor shall afford CSOSA access to the Contractor's facilities, installations, technical capabilities, operations, documentation, records, and databases.

H.4.9

If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

Quoter’s name and title

Quoter’s signature

Date

A. The solution shall have the ability to be installed and uninstalled by a CSO as well as the contractor by scheduled appointment.
B. The offeror shall provide a solution for physical installation and removal of hardware and/or software to accomplish the following objectives for this task as follows:
1. The contractor shall provide all necessary equipment and software required to install and remove the monitoring solution software.
2. The monitoring solution shall be installable by both the contractor, by service appointment, and CSO without the aid of contractor.
3. The contractor shall provide all required training, notes, or other details for installation.
4. The solution shall notify the assigned CSO of installation completion.
5. The contactor’s solution shall facilitate the installation of monitoring software no more than three (3) business days after enrollment when a request for contractor installation is submitted.
Compliance YesNoData Capture 24 hours a day seven 7 days a week data capture of offenders computer and internet usage and activities on Windows Mac OS Android and iOS devices A Computer Use Collect all use of monitored computerdevice ie programapplication uses loginlogout file creationaccessmodification B Internet Browser Activity Collect all internet browser activity captured by Uniform Resource Locator URL and designated by browser used with data and time accessed C Communication Activity Capture email chatIM video communication Screen captures may satisfy the minimum requirement Full text or HTML of all chatIM email or any other webbased chat communications exceeds the minimum requirements D Program and Application Activity Capture use of programs and application by data and time accessed E File Transfer Activity Capture files sentreceived by computer device F File Activity Capture files createdmodifiedaccessed activity by the computer device G External Media Human Interface Devices andor Peripherals Device Activity Capture external non resident media device access such as USB flash drives networkconnected hard drivesstorage wireless hard drives and any other media storage device not resident to the monitored device to include cloud storage H Screen Capture The solution shall permit for the ability to capture screen activity screen shot of the monitored devices and shall be configurable based on identified keyword applicationprogram usage or time intervals I ApplicationProgramWebsite blocking The solution shall permit for the ability to configure and block identified applications programs and websites from being used or accessed on the monitored device J Data Review The solution shall provide the review of all flagged data collected for validity based on case profiles:
CommentData Capture 24 hours a day seven 7 days a week data capture of offenders computer and internet usage and activities on Windows Mac OS Android and iOS devices A Computer Use Collect all use of monitored computerdevice ie programapplication uses loginlogout file creationaccessmodification B Internet Browser Activity Collect all internet browser activity captured by Uniform Resource Locator URL and designated by browser used with data and time accessed C Communication Activity Capture email chatIM video communication Screen captures may satisfy the minimum requirement Full text or HTML of all chatIM email or any other webbased chat communications exceeds the minimum requirements D Program and Application Activity Capture use of programs and application by data and time accessed E File Transfer Activity Capture files sentreceived by computer device F File Activity Capture files createdmodifiedaccessed activity by the computer device G External Media Human Interface Devices andor Peripherals Device Activity Capture external non resident media device access such as USB flash drives networkconnected hard drivesstorage wireless hard drives and any other media storage device not resident to the monitored device to include cloud storage H Screen Capture The solution shall permit for the ability to capture screen activity screen shot of the monitored devices and shall be configurable based on identified keyword applicationprogram usage or time intervals I ApplicationProgramWebsite blocking The solution shall permit for the ability to configure and block identified applications programs and websites from being used or accessed on the monitored device J Data Review The solution shall provide the review of all flagged data collected for validity based on case profiles:
K Image Analysis The solution shall review all images screenshots and videos collected by the solution for validity based on case profiles L Alerts and Reports The solution shall provide immediate alert notifications as well as time set interval reports based on identified risks such as keywords or applications by email text or telephone contact M Keystroke Activity The solution shall capture user keystroke activity:
Remote Access via Dedicated Interface The contractor shall provide CSOs 24 hours a day seven 7 days a week remote access to the dedicated interface through which the solutions features and reports are accessible A All access shall be web based and accessible by web browser by traditional and mobile computer devices without the use of any thirdparty software interface B The contractor shall maintain and provide login ID and temporary passwords for all CSOs upon request The interface shall allow CSOs to create unique login and passwords upon creation of an account C The interface shall provide the CSOs the ability to view print download and entermodify offender information D The interface shall allow the CSO to enroll defendantsoffenders with offender profile information choose specific monitoring protocols restrictions exclusions from monitoring and delineate key alerts suspicious activity notifications and innocuous activities and other tasks as noted in C31 Task 1Data Capture E Upon CSO enrollment of a offender into the contractors solution the contractor s solution shall confirm enrollment with the CSO F The interface shall provide multiple hierarchical levels of access up to an enterprise level of access that enables the COR to view all users and connected devices active and inactive searchable by install and uninstall dates G The interface shall provide for the management and configuration of persons under supervision case on an individual case level as well as group H The contractors solution shall possess the capability to capture each CSO s access and utilization of the solution provide offender enrollment removal and modification:
capability key alert summary reports and other customized reports as designated by the COR I The interface shall provide the ability to create customize configure and assign case type profiles to a cases and groups J The interface shall provide the ability to create customize configure and assign individual and group keywords of interest to be noted in data collection to individual cases and groups K The interface shall provide the ability to create customize configure and assign individual and group applicationsprograms of interest to be noted in the data collection to individual cases and groups L The interface shall provide the ability to create customize configure and assign reports for individual cases and group M The interface shall provide reports on 1 The number of devices installed and active the present day or within a searchable date range 2 The number of devices that failed to connect for three 3 days 3 The number of devices that failed to connect for seven 7 days:
Physical andor Remote Installation and Removal of Hardware andor Software The solution shall be able to be installed and uninstalled by CSO or contractor:
A The solution shall have the ability to be installed and uninstalled by a CSO as well as the contractor by scheduled appointment B The offeror shall provide a solution for physical installation and removal of hardware andor software to accomplish the following objectives for this task as follows 1 The contractor shall provide all necessary equipment and software required to install and remove the monitoring solution software 2 The monitoring solution shall be installable by both the contractor by service appointment and CSO without the aid of contractor 3 The contractor shall provide all required training notes or other details for installation 4 The solution shall notify the assigned CSO of installation completion 5 The contactors solution shall facilitate the installation of monitoring software no more than three 3 business days after enrollment when a request for contractor installation is submitted:
Technical Support Oncall 24 hours a day seven 7 days a week technical support A The contractor shall aid and inform CSOs regarding all functions of the contractors solution B The contractor shall provide contact information for technical assistance to all CSOs including after hours and oncall procedures C The contractor shall provide CSOs with digital copies of captured and stored data documents and data retrieval and preparation if needed D The contractor shall address and provide detailed response for all assistance requests in a reasonable time frame:
Training The contractor shall provide training to the CSO staff on the installation use and maintenance of the monitoring solution This should include training to ensure CSOs meet the minimum standard in usage of the solution A Training shall be available and provided to all CSOs using the solution:
B The contractor shall develop training for the installation and removal of the monitoring solution C The contractor shall provide training for the overall use of the dedicated interface D The contractor shall provide training on the overall functionality of the contractors solution E Within thirty 30 calendar days contract award the contractor shall provide to the COR a training program to include content and materials for training CSOs on the installation and implementation of the contractor s solution F Training may be in the form of webbased modules in person presentations video or other formats as approved by the COR G The contractor may provide up to six webbased training sessions per period of performance on technology refreshes new features or best practices for using the solution H The Contractor shall provide a copy of any webbased training sessions to the COR in a SCROM file format or a file convertible to a SCROM file format that can be posted on the agencys Learning Management System:
Technology Refreshment The contractor shall provide a technological refresh at any time during the period of performance should a technological advancement occur that would enhance the contractor s ability to perform data capture and management A The contractor shall provide a technological refresh on any identified services or abilities noted in this contract at any time during the period of performance should a technological advancement occur that would enhance the contractors ability to perform data capture and management B The offeror shall provide a solution for technology refresh to accomplish the following objectives for this task as follows 1 The contractor shall coordinate with the COR on scheduled releases because of implementation of new technology and associated training within 30 days of the release:
2 The Contractor shall provide written notification in writing via email text or alert via dedicated interface at least 24 hours in advance of any scheduled service outages 3 CSOSA reserves the right to modify its stated requirements per platform to take advantage of emerging technologies and enhanced capabilities to allow for optimal monitoring 4 The contractor shall only provide software that is the most recent generation and supported by the manufacturer Any replacement new or upgraded software specifications and delivery information shall be submitted in writing to the COR and approved by the CO 5 The contractor shall immediately no greater than 24 hours to take documented measures to correct all failures and deficiencies resulting from software or services acquired under contract During this time the contractor shall provide the COR documentation related to the timeframe for full resolution The contractor shall provide replacement software andor hardware as needed 6 Throughout the life of the contract the contractor shall provide the most recent generation of reliable software hardware and support services to mitigate the risk of obsolescence of existing technology 7 The contractor shall provide uptodate monitoring to include the ability to monitor new operating systems OS releases within a maximum of six 6 months from release of OS developers kit or a maximum of 90 days from market launch whichever is sooner:
Application Programming Interface API The Contractor shall provide a Representational State Transfer REST Application Programming Interface API affording CSOSA the opportunity to fetch records relevant to its use of the Contractors Case Management System CMS on demand over a secured Hypertext Transport Protocol HTTPS connection The API shall A Support changes ie insertupdatedelete operations performed against the Contractors CMS B Be accessible to authorized CSOSA staff within thirty days of task order award C Accept JavaScript Object Notation JSON blocks as requests:
D Return JSON blocks as responses E Include endpoints for retrieving system user records identifying and characterizing CSOSA users and vendor agents who have insertedupdateddeleted records related to CSOSA personnel CSOSA team configurations offender records device type device installation and uninstallation dates invoice periods line items unit costs and billable unit counts sufficient to support invoicing and CSOSA audits:
H1:
H1 CSOSA Contractor Information Security Requirements:
H11:
The Contractor shall meet and comply with Federal laws Executive Orders directives policies regulations standards and guidance as amended and extended for the protection of the information system and information during processing while in storage and during transmission The Contractor shall be required to comply with at a minimum a Federal Information Security Modernization Act of 2014 FISMA b Office of Management and Budget OMB Circular and Memoranda eg Circular A130 c US Department of Homeland Security Directives eg USCERT and HSPD12 d National Institute of Standards and Technology NIST Federal Information Processing Standards FIPS and Special Publication SP 800 Series eg FIPS 200 FIPS 199 FIPS 1402 SP 80018 SP 80037 SP 80053 Rev 4 SP 80060:
H12:
The Federal Information Security Modernization Act of 2014 FISMA requires the head of each agency to provide information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access use disclosure disruption modification or destruction of information It requires those measures to be in place for information collected or maintained by or on behalf of the agency and information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency:
The law defines the term information security to mean protecting information and information systems from unauthorized access use disclosure disruption modification or destruction in order to provide a Integrity which means guarding against improper information modification or destruction and includes ensuring information nonrepudiation and authenticity b Confidentiality which means preserving authorized restrictions on access and disclosure including means for protecting personal privacy and proprietary information and c Availability which means ensuring timely and reliable access to and use of information:
The Contractor shall provide and implement security controls as selected by CSOSA to meet the security requirements for a Moderate impact level system as defined in NIST SP 800:
53 as amended Security and Privacy Controls for Federal Information Systems and Organizations:
Executive departments and agencies procuring commercial and noncommercial cloud services or systems provided or managed by other departments or agencies contractors or other sources shall comply with FISMA requirements The Federal Risk and Authorization Management Program Fed RAMP is a governmentwide program that provides a standardized approach to FISMA compliance as it applies to cloudbased computing services It oversees and standardizes how to do security assessments authorizations and continuous monitoring for cloud products and services Fed RAMP requirements apply to all cloud deployment models eg Public Clouds Community Clouds Private Clouds Hybrid Clouds and all cloud service models eg Infrastructure as a Service Platform as a Service Software as a Service as defined by the National Institute of Standards and Technology NIST:
H2:
Security Assessment and Authorization and Continuous Monitoring The Contractor shall apply the appropriate set of baseline security controls as required in the National Institute of Standards and Technology NIST Special Publication SP 80053 as amended Security and Privacy Controls for Federal Information Systems and Organizations:
H21:
The Contractor shall be responsible for the cost of preparing the Security Authorization Package using NIST SP 80037 as amended Guide for Applying the Risk Management Framework to Federal Information Systems using Fed RAMP templates where available and maintaining compliance:
H22:
The Contractor shall be able to maintain a security management continuous monitoring environment that meets or exceeds the Continuous Monitoring requirements in SP 80037 Appendix G:
H3:
Requirements for Externally Hosted Services and Applications Since the Contractor s CMS is external to CSOSA the following requirements also apply:
H31:
CSOSA reserves the right to perform Penetration Testing If CSOSA exercises this right the Contractor shall allow Government employees or designated third parties to conduct Security Assessment activities to include control reviews in accordance with Fed RAMP requirements Review activities include but are not limited to scanning operating systems web applications wireless scanning network device scanning to include routers switches and firewall and IDSIPS databases and other applicable systems including general support structure that support the processing transportation storage or security of Government information for vulnerabilities:
H32:
Identified gaps between required Security Controls and the Contractor s implementation as documented in the System Security Plan SSP shall be tracked by the Contractor for mitigation in a Plan of Action and Milestones POAM document:
H33:
The Contractor is responsible for mitigating all security risks found during security assessment and accreditation and continuous monitoring activities All highrisk vulnerabilities shall be mitigated within 30 days and all moderate risk vulnerabilities shall be mitigated within 90 days from the date vulnerabilities are formally identified:
H34:
The Contractor shall provide access to the Federal Government or their designee acting as their agent when requested in order to verify compliance CSOSA reserves the right to conduct onsite inspections The Contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review:
H35:
CSOSA has the right to perform manual or automated audits scans reviews or other inspections of the Contractor s Information Technology IT environment being used to provide or facilitate services for CSOSA In accordance with the Federal Acquisitions Regulations FAR clause 522391 the Contractor shall be responsible for the following security safeguards:
H36:
The Contractor shall not publish or disclose in any manner without the COs written consent the details of any safeguards either designed or developed by the Contractor under this purchase order or otherwise provided by CSOSA:
H37:
H37 To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security integrity and confidentiality of Government data the Contractor shall afford CSOSA access to the Contractors facilities installations technical capabilities operations documentation records and databases within 72 hours The program of inspection shall include but is not limited to a Authenticated and unauthenticated operating systemnetwork vulnerability scans b Authenticated and unauthenticated web application vulnerability scans c Authenticated and unauthenticated database application vulnerability scans and d Automated scans can be performed by Government personnel or agents acting on behalf of CSOSA using Government operated equipment and Government specified tools:
H38:
If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor or if existing safeguards have ceased to function the discoverer shall immediately bring the situation to the attention of the other party:
H39:
If the Contractor chooses to run its own automated scans or audits results from these scans may at CSOSAs discretion be accepted in lieu of Government performed vulnerability scans In these cases scanning tools and their configuration shall be approved by CSOSA In addition the results of Contractorconducted scans shall be provided in full to CSOSA:
CSOSA may choose to cancel for convenience the ContractAward if the Contractor has its authorization revoked and the deficiencies are greater than agency risk tolerance thresholds:
The Contractor shall comply with CSOSA security and privacy requirements subject to change by the CSOSA Information Security Office and as mandated by Federal laws and policies including making available any documentation physical access and logical access needed to support this requirement:
The Contractor shall be responsible for properly protecting all information used gathered or developed as a result of work under this purchase order:
The Contractor shall also protect all Government data equipment etc by treating the information as sensitive All information about the systems gathered or created under this purchase order should be considered as Controlled Unclassified Information CUI It is anticipated that this information will be gathered created and stored within the primary work location If Contractor personnel shall remove any information from the primary work area they should protect it to the same extent they would their proprietary data andor company trade secrets:
CSOSA shall retain unrestricted rights to government data The ordering activity retains ownership of any user createdloaded data and applications hosted on Contractor s infrastructure as well as maintains the right to request full copies of these at any time:
The Contractor shall ensure that the facilities that house the network infrastructure are physically secure The data shall be available to CSOSA upon request within one business day or within the timeframe specified otherwise and shall not be used for any other purpose other than that specified herein:
The Contractor shall provide requested data at no additional cost to CSOSA No data shall be released by the Contractor without the consent of CSOSA in writing All requests for release shall be submitted in writing to the CO:
The Contractor shall provide full access and cooperation for all activities determined by CSOSA to be required to ensure an effective incident response including providing all requested images log files and event information to facilitate rapid resolution of cyber incidents:
The Contractor shall be responsible for all costs and related resource allocations required for all subsequent incident response activities determined to be required by CSOSA whether incurred by Government agents under purchase order or on assignment to CSOSA or by third party firms:
H4:
Additional Requirements for CSP hosted Services and Applications If the Contractors CMS is hosted in a commercial cloud service provider CSP environment like MS Azure Amazon Web Services AWS IBM Cloud Google Cloud or similar the following requirements apply The preferred level of Fed RAMP compliance status is moderate:
H41:
The Contractor shall implement the controls contained within the Fed RAMP Security Controls Baseline and Fed RAMP Continuous Monitoring Strategy Guide available at the Fed RAMP website httpswwwfedrampgovdocuments These documents define requirements for compliance to meet minimum Federal information security requirements:
H42:
The Contractor shall follow Fed RAMP guidelines and security guidance In situations where there are no procedural guides the Contractor shall use generally accepted industry best practices for information security:
H43:
The Contractor shall be responsible for the cost of preparing the Security Authorization Package using the Fed RAMP Security Assessment Framework SAF process using Fed RAMP templates where available and maintaining compliance:
H44:
The Contractor shall be responsible for preparing the Security Authorization Package using the Fed RAMP SAF Process and Fed RAMP Security Control Baseline Workbook:
H45:

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .