HHSA_Security_Compliance.docx

DOCX document 27 KB Posted

Attached to
HIPAA Privacy and Security Policy Services Federal contract opportunity
Solicitation number
2015-Q-17159
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Pittsburgh

About this file

FISMA

View the file

Other files for this federal contract opportunity

Other files attached to HIPAA Privacy and Security Policy Services, newest first.
File Type Posted
Questions.pdf PDF
Relevant_Contracts_Reference_Sheet.docx DOCX document
Solicitation_2015-Q-17159.pdf PDF
PWS_HIPAA_05.04.15.pdf PDF
Past-Present_Performance_Questionnaire.docx DOCX document
ACH-Vendor.pdf PDF
Supplemental_Instructions.pdf PDF
QASP.pdf PDF
Client_Authorization_Letter.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HHSA Security Compliance requirements for the EGovernment Act of 2002 (FISMA)

The below information complies with HHSA Security compliance requirements for the EGovernment Act of 2002 (FISMA) HHSAR 352.239-70 Standard for Security Configurations (Oct 2009) HHSAR 352.239-72 Security Requirements for Federal Information Technology Resources (Oct 2009).

HHSAR 352.239-71 Standard for Encryption Language (Oct 2009).

Security Compliance The Performance Work Statement (PWS) requires the successful offeror to have the ability to host and maintain a system for data collection, management, use, and reporting to support activities funded by the federal government.

IMPORTANT NOTE TO OFFERORS: The following information shall be addressed in a separate section of Offerors’ Technical Proposal entitled, “Information Security.” Information Security is applicable to this solicitation because all information systems developed, operated, or used by or on behalf of the Federal Government must comply with Federal Information Security laws, policies and standards. We provide the following information to assist in the preparation of proposals in order to assure that the existing data system, which would be licensed for use by CDC awardees and CDC employees, meet the security standards described below.

The EGovernment Act of 2002, (Federal Information Management Act) and the below federal policies dictate the framework for assuring information security for data systems operated by or on behalf of the Federal government. These are summarized below.

OMB Circular A-130 (http://www.whitehouse.gov/omb/Circulars_a130_a130trans4/) establishes policy for the management of Federal information resources, pursuant to a number of laws and regulations, including the Paperwork Reduction Act of 1980 (amended in 1995), the Computer Security Act of 1987, and other laws. Circular A-130 requires all federal information systems to have security plans, emergency response capabilities, designated individuals who are responsible for security, security awareness training, and regular review of the system. Appendix III of Circular A-130, entitled “Security of Federal Automated Information Resources,” establishes a minimum set of controls to be included in Federal automated information security programs; assigns Federal agency responsibilities for the security of automated information; and links agency automated information security programs (such as the DHHS AISSP) with OMB Circular No. A-123 The Federal Information Security Management Act of 2002 (P.L. 107-347) (FISMA) (http://csrc.nist.gov/policies/FISMA-final.pdf) requires each agency to develop, document, and implement an agency-wide information security program to safeguard information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, offeror (including sub-offeror), or other source. The National Institute of Standards and Technology (NIST) has issued a number of publications that provide guidance in the establishment of minimum security controls for management, operational, and technical safeguards needed to protect the confidentiality, integrity, and availability of a Federal information system and its information.

Pursuant to Federal and HHS Information Security Program Policies the following standards and guidelines apply:

1. FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf),

1. FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf)

1. NIST Special Publication 800-18, Guide to Developing Security Plans for Federal Information Systems (http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf)

1. NIST Special Publication 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories Vol. 1 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf) and Vol. 2 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf).

1. NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations (http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final-errata.pdf).

1. NIST Special Publication 800-63, Electronic Authentication Guideline (http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf) The Offeror should demonstrate understanding of security requirements by attaching a Draft Data System Security Plan or information system security plan (SSP). The SSP should be a brief and general narrative description of the system and its integration with the CDC Network Infrastructure.

The initial draft and all subsequent versions of the SSP must be prepared and submitted by the Offeror to the contracting officer (CO) and to the contracting officer’s representative (COR), in Microsoft Word compatible format. The successful Offeror shall be responsible for ensuring that the security plan is acceptable to the COR and the National Center for HIV/AIDS, Viral Hepatitis, STD, and TB Prevention (NCHHSTP) Information System Security Officer (ISSO) as well as any subsequent federal reviewers (e.g., Center and/or HHS officials, OMB officials, etc.). Comments shall be conveyed to the Offeror by the COR and/or the CO.

Once an award is made, the COR and the CO will review the draft SSP and any subsequent versions and submit recommendations/comments to the Offeror within 14 working days after receipt. The Offeror shall incorporate the COR’s recommendations and submit paper and electronic copies of the security plan to the CO and to the technical monitor within five working days after receipt of the technical monitor's comments. The resultant contract will require the draft SSP to be finalized in coordination with the COR no later than 90 calendar days after contract award. Also, the successful Offeror, in conjunction with the NCHHSTP ISSO, is required to update and resubmit its SSP to the Center every three years following award or when a modification has been made to its internal system. In addition to developing and maintaining an SSP, the successful Offeror in conjunction with the NCHHST ISSO shall be responsible for continuously assessing and assuring information security for the project and for updating the security plan as needed throughout the duration of the agreement.

The SSP is part of the Certification and Accreditation (C&A) process required by the EGovernment Act of 2002 and NIST Special Publication 800-18 and will include selected mandatory controls required by NIST Special Publication 800-53, Volume I & II. The successful offeror in conjunction with the NCHHSTP ISSO will submit C&A documentation to the CDC Chief Information System Officer (CISO). The successful completion of the C&A documents will result in an award of an Authority To Operate (ATO). Based on guidance in FIPS 199 and NIST SP 800-60 the system will be assigned an overall security category (SC) of LOW or MODERATE based on (confidentiality, LOW/MODERATE), (integrity, LOW/MODERATE), and (availability, LOW/MODERATE) impact levels. These impact levels will be initially determined by the NCHHSTP ISSO and confirmed by the CDC OCISO Certifying Authority as part of the Certification and Accreditation process.

The successful Offeror is responsible for providing pertinent security information to the NCHHSTP ISSO and Security Staff and assisting in completing the below CDC Certification and Accreditation documents. Appropriate security templates will be provided to the successful Offeror by the NCHHSTP Security Staff. Completed documents will be sent to the CISO for review, approval and subsequent issuance of an ATO.

1. Baseline System Information (BSI)

1. Privacy Impact Assessment (PIA)

1. Host Characterization Worksheet (HCW)

1. System Security Plan (SSP)

1. Security Baseline Worksheet (SBW)

1. Business Continuity Plan (BCP)

1. Risk Assessment Report (RAR) The Offeror shall respond to the following seven security–associated requirements in the application:

1. Position Sensitivity Designations CDC requires a Public Trust Level 5 for the following The following position sensitivity designations and associated clearance and investigation requirements apply under this licensing contract:

Level 5: Public Trust - Moderate Risk (Requires Suitability Determination with NACIC, MBI or LBI). Licensor employees assigned to a Level 5 position with no previous investigation and approval shall undergo a National Agency Check and Inquiry Investigation plus a Credit Check (NACIC), a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

Upon award, the Licensor will be required to submit a roster of all staff (including sub-offeror staff) working under the contract that will have the ability to access sensitive NCHHSTP HIV information from the system. The roster shall be submitted to the COR, with a copy to the CO, within 14 calendar days of the effective date of the contract. Any revisions to the roster as a result of staffing changes shall be submitted within 15 calendar days of the change. The CO shall notify the licensor of the appropriate level of suitability investigations to be performed, but Licensor employees and subcontractors who have met investigative requirements within the last five years may only require an updated or upgraded investigation. An electronic template, “Roster of Employees Requiring Suitability Investigations,” is available for offeror use at: http://ais.nci.nih.gov/forms/Suitability-roster.xls. Upon receipt of the Government’s notification of applicable suitability investigations required, the Licensor shall complete and submit the required forms within 30 days of the notification.

Non-Disclosure Agreements The Offeror and any sub-Offerors or employees are forbidden from sharing any technical or logistical information they may gain in conjunction with matters related to this task order that could jeopardize the physical or information security of CDC or its employees, projects, or information systems.

The following apply to Licensor employees and their subcontractors associated with the project:

a. Personnel may not begin work under the contract until the contractor has submitted the employee roster and non-disclosure agreements as described above.

b. Personnel without necessary background investigations will not have access to sensitive project data.

c. Violation of these conditions may lead to termination of the contract.

It is the Offeror's responsibility to ensure that all employees have met CDC and federal requirements, such as, for example, completion of background checks, before gaining or utilizing access to CDC information technology resources.

2. Privacy Compliance Licensor in conjunction with CDC Center ISSO shall conduct and maintain an initial Privacy Impact Assessment (PIA) as defined by Section 208 of the E-Government Act of 2002. Periodic reviews shall be conducted by the system owner, with assistance from the CDC Center ISSO and offeror, to determine if a major change to the system has occurred, and if a PIA update is needed.

3. Offeror’s Official Responsible for Information Security The offeror shall include in the “Information Security” part of the Technical Proposal the name and title of its official who will be responsible for all information security requirements should the offeror be selected for an award.

4. Rules of Behavior The offeror’s employees and subcontractors shall comply with the HHS Information Technology General Rules of Behavior.

5. Information Security Training HHS policy requires that contractors and subcontractors shall receive security training commensurate with their responsibilities for performing work under the terms and conditions of their contractual agreements. The successful offeror shall be responsible for assuring that each employee, including subcontractors, has completed the HHS Computer Security Awareness Training course (or another course designated by CDC) prior to performing any contract work, and thereafter completing the HHS-specified annual refresher course during the period of performance of the contract. This would be provided at the Offeror's expense and would be the Offeror's responsibility to plan and arrange.

The successful offeror shall maintain a listing of all individuals who have completed this training and shall submit this listing to the COR.

6. HSPD-12 Compliance Federal Information Processing Standard 201 (FIPS-201) (vii) compliant, Homeland Security Presidential Directive 12 (HSPD-12) card readers shall: (a) be included with the purchase of servers, desktops, and laptops; and (b) comply with FAR Subpart 4.13, Personal Identity Verification.

7. Encryption All sensitive CDC-funded data stored on desktop computers used on behalf of HHS shall be secured either through a FIPS 140-2 compliant encryption solution or through adequate physical security and operational controls at the desktop’s residing location.

All mobile devices, portable media and transfer data files that contain sensitive CDC- data shall be encrypted using FIPS 140-2 compliant algorithms.

1 | Page

File details come from the government source that posted it. Updated .