RFQ 2032H5-24-Q-00126-Amendment 0001.pdf
PDF 1 MB Posted
- Attached to
- eA3-STI Information Technology Program Management Services Federal contract opportunity
- Solicitation number
- 2032H5-24-Q-00126
About this file
This document is an amendment to a Request for Quotation (RFQ) for information technology program management services for the Internal Revenue Service's Authentication, Authorization & Access Strategic Transformation and Integration Support (eA3-STI) effort.
The key details are:
- This amendment provides responses to questions submitted by offerors, revises the expected frequency of executive reports, and replaces the FISMA contract language with updated requirements.
- The original RFQ solicitation number is 2032H5-24-Q-00126, and the incumbent contractor is eTelligent Group, LLC under contract 2032H5-22-F-00206.
- The services required include program management, transformation support, strategic planning, and integration services to support the IRS's information systems and cybersecurity initiatives.
- Offerors must have a GSA Multiple Award Schedule contract and may propose subcontractors subject to government approval.
- Proposals are due in response to the original RFQ solicitation number 2032H5-24-Q-00126.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ 2032H5-24-Q-00126.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OMB Control No. 1505-0080
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
1. CONTRACT ID CODE PAGE OF PAGES
2. AMENDMENT/MODIFICATION NO. 4. REQUISITION/PURCHASE REQ. NO. 5. PROJECT NO. (If applicable)
3. EFFECTIVE DATE
07/15/2024 5000192142
6. ISSUED BY CODE 3431 7. ADMINISTERED BY (If other than Item 6) CODE
Internal Revenue Service Procurement 5000 Ellin Road Lanham, MD 20706
Leona M. Brown 240-613-5175
See Item 6
8. NAME AND ADDRESS OF CONTRACTOR (No. Street, county, State and ZIP: Code)
To All Offerors
(x) 9A. AMENDMENT OF SOLICITATION
NO. 2032H5-24-Q-00126
9B. DATED (SEE ITEM 11)
07/02/2024
10A. MODIFICATION OF CONTRACT/ORDER NO.
x
10B. DATED (SEE ITEM 13)
CODE FACILITY CODE
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
is not extended.
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:
(a) By completing Items 8 and 15 and returning _____ copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATA SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and data specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,
IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
(x) A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN ITEM 10A.
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER Specify type of modification and authority)
E. IMPORTANT: Contractor is not, is required to sign this document and return ____ copies to the issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
THE PURPOSE OF THIS AMENDMENT IS TO CHANGE SUBJECT REQUEST FOR QUOTATION (RFQ) AS FOLLOWS:
1. RFQ questions and responses are hereby provided in accordance with Attachment 1 of this Amendment entitled, “RFQ Questions and Responses”.
2. RFQ Attachment 2, FISMA Contract Language, is hereby removed and replaced with Attachment 2 entitled, "FISMA Cybersecurity Requirements Language".
Except at provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print) 16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)
LEONA BROWN 240-613-5175
15B. CONTRACTOR/OFFEROR 15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 16C. DATE SIGNED
(Signature of person authorized to sign)
BY _____________________________________________
(Signature of Contracting Officer)
NSN 7540-01-152-8070 30-105 STANDARD FORM 30 (REV. 10-83)
PREVIOUS EDITION UNUSABLE Computer Generated Prescribed by GSA
FAR (48 CFR) 53.243
X 1
X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers is extended, X
2032H5-24-Q-00126, Amendment 0001
Attachment 1
RFQ QUESTIONS AND RESPONSES
1. Is there an incumbent? If yes, what is the incumbent's name, contract number, award amount and duration?
Response: The incumbent contractor is eTelligent Group, LLC. The contract number is 2032H5-22-F-00206. The contract was awarded on February 28, 2022 and will expire on August 27, 2024. The current value is $8,625,751.20.
2. Are resumes required?
Response: Resumes are not required.
3. What are the title(s) of the key personnel?
Response: There are no positions designated as key personnel.
4. Section 3.1, Ramp-Up, Page 42 – “The Government estimates this task will take one month to complete after the award.” To increase the chances of a quality ramp-up and improve the consistency of proposal submissions, will the Government provide the baseline staffing expectations that went into the Independent Government Cost Estimate (IGCE)?
Response: The Government’s estimates are provided in Attachment 1, Estimated Level of Effort (LOE) on page 112 of the RFQ. This information has been provided to allow offerors to gauge the scope of the requirement but is not intended as a mandatory labor-mix.
5. Section 3.3, Transformation Support; Bullet 5, Page 46 – “Provide strategy and technical support for the application and integration of tools needed for program execution, including tools for program management, development, and testing.” - Will the Government list all the tools needed for program execution, including the tools for program management, deployment, and testing?
Response: It is the government’s expectation that the vendor will provide a strategy and technical support for the application and integration of tools needed for program execution, including those for program management, deployment, and testing. Some of the tools that are currently used are the IBM Rational tool set, ProSight, Splunk Enterprise Tool, Penetration Testing Tools, IBM RACF, ServiceNow, and Okta.
6. Section 3.4, Strategic Planning Section, Bullet 3.1, Page 47 – “Support IAM leadership strategic collaboration and long-term planning to inform organizational direction, make informed decisions, and alignment on commitments.” – To improve the transition, will the Government provide any high-level commitments for implementation that currently exist?
Response: It is the government’s expectation that the vendor will conduct an inventory of all application and integration tools and develop a strategy and provide technical support for those tools, including those for program management, development, and testing.
7. Section 3.3, Transformation Support, Page 44 – “The contractor shall provide technical integration services to support upfront identification of program dependencies and integration points, as well as continuous monitoring, management, and response to anticipate and mitigate associated impacts to successful delivery of any Program. Contractor integration support shall span the entire lifecycle of any program, from program initiation through delivery and operation of program capabilities.” - Is an Enterprise Architect required as a key personnel position to support the technical integration?
Response: There are no positions designated as key personnel. However, the Government expects the vendor to provide qualified personnel to support all aspects of the requirement with the appropriate skillsets to accomplish assigned tasks.
8. Section 3.2, Program Management; Deliverable Activities #3, Page 44 – “Creation of executive reports, approximately 30 per month to support monthly communications, weekly project status report and bi-monthly CIO (Chief Information Officer) executive briefings. This includes coordination, consolidation, and development of final communications materials from across the program's key initiatives.” - Will the Government share the details of what makes up the 30 executive reports per month? Is there a standard format? Are these daily status reports?
Response: The number of executive reports was misstated. The approximate number of reports is 3 per month, not 30.
(1) Section 3.2 Program Management Support, Deliverable Activities include support for, Paragraph 3 is hereby revised to read:
“3. Creation of executive reports, approximately 3 per month to support monthly communications, weekly project status report and bi-monthly CIO (Chief Information Officer) executive briefings. This includes coordination, consolidation, and development of final communications materials from across the program’s key initiatives.”
(2) Table 1: Schedule of Deliverables, Deliverable No. 5, Due Date/Frequency is hereby revised to “Approx 3/month”.
Yes, there are standard formats for the reports.
9. RFQ - General Question - Will the Government share the incumbent's name and contract number?
Response: See Question #1.
10. Section 3.2, Page 44 - The PWS states that Deliverable Activities include support for: "Creation of executive reports, approximately 30 per month to support monthly communications, weekly project status report and bi-monthly CIO (Chief Information Officer) executive briefings. Could the Government confirm that the expectation is indeed to create 30 executive reports per month, i.e. ~1.5 per working day during the month?
Response: See Question #8.
11. Section 3.3, Page 45 - "Contractor support will focus on (among other items) "Migration of SADI off SiteMinder to Ping Identity, Microservices". Could the Government provide more detail on the status-quo and phasing of this migration, i.e. planning, deployment etc.?
Response: The migration of SADI off SiteMinder to Ping Identity is to improve security and identity management for external and internal users enabling SiteMinder retirement, including the delivering a modernized Identity Credentialing and Access Management
(ICAM).
12. Page 2 - Schedule of Supplies/Services - Potential travel is noted on pages 57 and 110; no CLIN is included in the Schedule of Supplies/Services (page 2).
Would the Government consider adding a CLIN for Travel and Other Direct Costs (ODCs)?
Response: As stated on page 110, a Travel CLIN will be added to the resultant task order that will include a “Not to Exceed” dollar amount to reimburse any travel costs in accordance with Federal Travel Regulations and FAR 31.205-46. Travel costs will not be considered under the price evaluation. There are no other ODCs under this requirement.
13. Pages 44 and 54, CIO Executive Briefings; Schedule of Deliverables - The RFQ states on page 54 that Deliverable #4, CIO Executive Briefings, is “bi-weekly.” Page 44 notes “bi-monthly” CIO (Chief Information Officer) executive briefings. We kindly request the Government to consider amending the deliverable table on page 54 to consistently note the CIO briefings as “bi-monthly.” In addition, we would like the Government to consider defining “bi-monthly” as every two months.
Response: The frequency of CIO Executive Briefings was misstated in the Schedule of Deliverables. Table 1: Schedule of Deliverables, Deliverable No. 4, Due
Date/Frequency is hereby revised to “Bi-monthly”.
“Bi-monthly” is defined as every two months.
14. Pages 44 and 54, Executive Reports, Schedule of Deliverables, Deliverable #5, Executive Reports, includes approximately 30 per month, implying more than 1 executive report a day. Could the Government clarify that it is asking for more than 1 executive report per day? Would the Government consider changing the Deliverable #5 frequency to weekly?
Response: See Question #8.
15. The RFQ on page 103 under 'RFQ NOTICES, CONDITIONS AND INSTRUCTIONS - Contractor Teaming Arrangements (CTA)/Subcontracting: CTAs will not be considered for award under this RFQ; however, offerors may propose subcontracting arrangements subject to FAR 52.219-14, Limitations on Subcontracting. The prime contractor must have a GSA MAS contract and all pricing shall be in accordance with the prime contractor’s GSA MAS contract, including any applicable discounts. The use of subcontractors will require prior approval by the IRS. We are planning to use a subcontractor for this opportunity.
Could you please clarify the process for obtaining this approval?
Response: Offerors should provide the company names, addresses and Unique Entity Identifiers (UEI) of all subcontractors in the assumptions or explanatory notes of Volume II, Pricing Information. Any information regarding the subcontractors’ technical roles, responsibilities and attributes should be included in the offeror’s Technical Quote and/or Management Approach, as applicable. Any technical information provided in Volume I, Technical Information, will be used for evaluation purposes, not subcontractor approval.
Subcontractor approval is contingent upon a brief responsibility review and the prime contractor’s adherence to FAR 52.219-14, Limitations on Subcontracting.
16. Regarding the submission of Volume II, Pricing Information, the RFQ specifies that the volume should include the offeror's Price Quote, a fully executed copy of the RFQ, and a copy of the offeror’s GSA MAS pricing schedule.
It is also mentioned that offerors may use MS Excel to format where appropriate and include supporting documentation with a summary page. Could you please clarify if the Price Quote and its supporting documentation (such as the summary page and details of discounts or line-item breakdowns) should be combined into a single Excel document, or if they should be submitted as separate documents within Volume II?
Response: The Price Quote consists of the offeror’s proposed firm-fixed prices for each contract line item (CLIN) as well as the supporting documentation. Offerors shall complete the SF 1449 as indicated under Section 3.2 Volume II, Pricing Information (Page 107) as part of their full execution of the RFQ. Offerors shall also provide a separate Excel document as supporting documentation for the prices proposed on the
SF 1449. The Excel document may include multiple pages as needed (i.e., summary page, line-item details/breakdown, option year breakdown, etc.).
FISMA Cybersecurity Requirements Language
Informa�on Systems and Informa�on Security Controls for Contrac�ng Ac�ons Subject to Federal Informa�on Security Moderniza�on Act (FISMA) and Federal Risk and Authoriza�on Management Program (FedRAMP)
In performance of this contract, the contractor agrees to comply with the following cybersecurity requirements and assumes responsibility for compliance by its personnel and subcontractors (and their personnel):
1. General. The contractor shall ensure IRS informa�on and informa�on systems are always protected. The contractor shall develop, implement, and maintain effec�ve controls and methodologies in its business processes, physical environments, and human capital or personnel prac�ces that meet or otherwise adhere to the security and privacy controls, requirements, and objec�ves described in applicable security and privacy control guidelines, and their respec�ve contracts. Pursuant to the Federal Informa�on Security Moderniza�on Act (FISMA) and Federal Risk and Authoriza�on Management Program (FedRAMP), the contractor shall provide minimum security controls required to protect Federal informa�on and informa�on systems in accordance with the Internal Revenue Manual (IRM) Part 10.8 series and the current version of Na�onal Ins�tute of Standards and Technology (NIST) Special Publica�on (SP) 800-53, Security Privacy Controls for Informa�on Systems and Organiza�ons.
2. Business En�tlement Access Request System (BEARS) /En�tlement - Role-based user permission groups. The contractor shall ensure all applica�ons and pla�orms integrate with the IRS to establish least privilege BEARS en�tlements for all roles that prevent any one role from authorizing a transac�on from end to end.
3. Privileged User Management and Access System (PUMAS). The contractor shall ensure all applica�ons and pla�orms integrate with the IRS’s PUMAS to secure, provision, manage, control, and monitor all ac�vi�es associated with all types of privileged iden��es to include, but not limited to, privileged user accounts, service accounts, and secrets management for on-premises and cloud-based applica�ons and infrastructure.
4. Log Management and Enterprise Security Audit Trails (ESAT). The contractor shall ensure systems provide audit trails in an approved automated format acceptable to the IRS for all user ac�ons and ac�vi�es when using or maintaining the system. In accordance with NIST 800-53 Audit and Accountability (AU) controls, applica�ons and pla�orms shall integrate with ESAT for audit logging to support organiza�on-wide analysis and correla�on for situa�onal awareness.
The contractor shall provide to the IRS to be used in accordance with OMB Memo 21-31, the system logs for both services implemented on servers within the authorization boundary and services deployed on Cloud Service Offerings. The contractor shall collect and maintain network
Attachment 2 2032H5-24-Q-00126, Amendment 0001
SPJCB
Highlight and system logs on Federal Information Systems for both on-premises systems and connections hosted by third parties, and when it is necessary to address a cyber incident on Federal Civilian Execu�ve Branch Information Systems.
5. Federated Authen�ca�on Services Technology (FAST)/Homeland Security Presiden�al Direc�ve 12 (HSPD-12) Compliant Authen�ca�on. The contractor shall ensure the system enforces the use of phishing resistant, modern mul�factor authen�ca�on (MFA) compliant with Treasury, Federal and HSPD-12 Policy/Guidance. Use of MFA shall be at the exclusion of all other authen�ca�on methods i.e., username and password.
The contractor shall support a secure, multi-factor method of remote authentication and authorization to identified IRS Administrators that will allow IRS designated personnel the ability to perform management duties on the system. The contractor shall support MFA including phishing resistant MFA (e.g., Fast Identity Online/Web Authentication and public key infrastructure (PKI)) as required by Office of Management and Budget (OMB) Memo 22-09. The contractor shall support a secure, multi-factor method of remote authentication and authorization to identified contractor administrators that will allow contractor designated personnel the ability to perform management duties on the system.
Use of federated MFA may be leveraged by adop�ng one or more of the following Treasury/IRS Enterprise Services:
i. Secure Access Digital Iden�ty (SADI) for authen�ca�ng external users.
ii. IRS Ac�ve Directory Federa�on Services (ADFS) for internal IRS users
iii. Common Access Iden�ty Assurance (CAIA)/Treasury Enterprise Authen�ca�on
Service (TEAS) in support of all Treasury
6. Cryptography Key Establishment and Management (System and Communica�ons Protec�on (SC-12)). The contractor shall establish and manage cryptographic keys for required cryptography employed within the informa�on system in accordance with centralized management of key genera�on, distribu�on, storage, access, and destruc�on in accordance with NIST SP 800-57, Recommenda�on for Key Management.
7. Data-at-Rest and Data-in-Motion Encryption of all IRS Data. The contractor shall ensure all applica�ons encrypt data at rest (per NIST 800-53, latest revision, SC-28) and data in transit (per NIST 800-53, latest revision, SC-9). SC-28 and SC-9 must pass all objec�ve criteria stated in NIST 800-53. In addi�on, the encryp�on solu�on must meet or exceed all Federal Informa�on Processing Standards (FIPS) 140 standards. All web traffic will enforce Hypertext Transfer Protocol (HTTPS) Secure Sockets Layer/Transport Layer Security (SSL/TLS) protocols.
8. Data Jurisdic�on. The contractor and subcontractors shall iden�fy all data centers that the data at rest or data backup will reside. All data will be guaranteed to reside (and transit) within the United States (or U.S. territories).
Attachment 2 2032H5-24-Q-00126, Amendment 0001
9. Non-repudia�on. The contractor shall ensure the sender of informa�on is provided with proof of delivery, and the recipient is provided with proof of the sender’s iden�ty. The IRS uses digital cer�ficates to confirm the iden�ty of Internet users sending x.509 standard encrypted informa�on, to verify the integrity and origin of file contents. The contractor shall agree to install United States Treasury TLS site cer�ficates for the purpose of authen�ca�ng traffic between the contractor applica�on and the IRS. The use of SSL or TLS to facilitate arbitrary transmission control protocol (TCP) and user datagram protocol (UDP) or other protocols (effec�vely, anything other than HTTP) inside the encrypted TLS tunnel between an internal IRS client and an external server cannot be used. Site-to-site virtual private network (VPN) or internet protocol security (IPsec) can be used as long as there are verifiable controls to ensure that the vendor end of that tunnel is an environment that is a closed environment. That is, the environment must be isolated at the network layer from other customers services by the offeror and does not provide for communica�ons to other services (e.g., a gateway or rou�ng service to endpoints outside of the control of the vendor submi�ng the proposal, etc.).
10. Media Transport. The contractor shall document activities associated with the transport of IRS agency information stored on digital and non-digital media and employ cryptographic mechanisms to protect the confidentiality and integrity of this information during transport outside of controlled areas. The contractor shall ensure all digital media, containing IRS information, that is transported outside of controlled areas must be encrypted using FIPS 140-2 level 2, FIPS 140-3 or National Security Agency (NSA) approved cryptography; nondigital media must be secured using the same policies and procedures as paper. The contractor shall ensure media, containing IRS information that is transported outside of controlled areas must ensure accountability. This can be accomplished through appropriate actions such as logging and a documented chain of custody form. IRS data that resides on mobile/portable devices (e.g., USB flash drives, external hard drives, and SD cards) must be encrypted. All IRS data residing on laptop computing devices must be protected with NIST-approved encryption software.
11. Boundary Protection. The contractor shall ensure that IRS information, other than unrestricted information, being transmitted from Federal government entities to external entities using cloud services is inspected by Trusted Internet Connections (TIC) processes, or the contractor shall route all external connections through a TIC in accordance with OMB Memo 19-26.
12. Security Alerts, Advisories, and Directives. The contractor, subcontractor or cloud service provider shall provide a list of personnel, iden�fied by role, with system administra�on, monitoring, and/or security responsibili�es who shall receive security alerts, advisories, and direc�ves.
13. Developer Security Testing and Evaluation. The contractor shall provide the IRS with all test plans and test results developed under IRS IRM 10.8.24.3.15.9 (SA-11: Developer Security Testing and Evaluation) at least 30 days prior to the release of any new code, settings, enhancement(s) or deprecation of features.
14. So�ware Bill of Materials (SBOM)/Attestation. The contractor shall provide a software build/bill of materials, and attestation in accordance with OMB Memo 22-18 using CISA templates. https://www.cisa.gov/sbom
15. RA-05 Vulnerability Mi�ga�on. Per Binding Opera�onal Direc�ve (BOD) 22-01, the contractor shall ensure the applica�on or system at the �me of the Authority to Opera�on (ATO) must not contain any vulnerability listed in the Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabili�es Catalog whose CISA remedia�on due date has been exceeded.
16. Vulnerability Monitoring and Scanning. Vulnerability monitoring includes scanning for patch levels;
scanning for func�ons, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or opera�ng incorrectly. The contractor shall implement vulnerability scanning as defined by IRS IT Security Policy and NIST requirements to include NIST SP 800-70.
The contractor shall, monitor and scan for vulnerabili�es in the system and hosted applica�ons using vulnerability monitoring tools and techniques, and when new vulnerabili�es poten�ally affec�ng the system are iden�fied and reported, perform analysis and remedia�on ac�vi�es.
The contractor will provide an environment that adheres to NIST SP 800-207 Zero Trust Architecture and CISA Binding Opera�onal Direc�ves. Non-compliant condi�ons are unacceptable for new technologies and cannot be remediated via a Risk Based Decision (RBD) or Risk Acceptance Form and Tool (RAFT). Non-compliance discovered in exis�ng so�ware (SW) or hardware (HW) will result in SW or HW being placed into quaran�ne un�l non-compliance issues are remediated to the sa�sfac�on of the government.
If approved for exis�ng SW or HW, the contractor shall create a plan of ac�ons and milestones Plan of Ac�ons and Milestones (POA&Ms) to iden�fy and track remedia�on of the iden�fied risks/vulnerabili�es for any vulnerabili�es iden�fied that cannot be remediated within 30 days.
The contractor shall report POA&Ms progress to the government as requested and at minimum monthly. The affected SW and HW shall remain in quaran�ne un�l such �me the government is sa�sfied the remedia�on ac�on/s have raised the level of compliance to an acceptable level (defined by the government).
The contractor shall provide all compliance scan results in an IRS acceptable format (i.e., CSV, JSON, or XML).
17. Cybersecurity Supply Chain Risk Management (C-SCRM). In accordance with the request for proposal (RFP), statement of work (SOW) or performance work statement (PWS) requirements, the contractor agrees to take complete responsibility for all actions of its Subcontractors.
Subcontractors are expected to meet all requirements set forth in the RFP, SOW, or PWS agreed to by the prime contract holder. The contractor shall identify all subcontractors who will perform services, including their name, the nature of services to be performed, address, telephone, email, federal tax identification number (TIN), and anticipated dollar value of each
Attachment 2 2032H5-24-Q-00126, Amendment 0001 https://www.cisa.gov/sbom https://www.cisa.gov/news-events/directives/binding-operational-directive-22-01 https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog subcontract before any work is performed by the subcontractor. The IRS reserves the right to reject subcontractors identified by the contractor that pose a significant risk to IRS and the IRS IT Infrastructure as defined by Federally mandated C-SCRM requirements and Publica�on 4812.
Any subcontractors not listed in the contractor’s proposal submission, who are engaged by the contractor, must be pre-approved, in writing, by the IRS.
The contractor shall manage the supply chain risk lifecycle of their products, services and subcontractor �ers using risk assessment methods and procedures iden�fied by the current version of NIST SP 800-161. The assessment must consider documented processes, documented controls, all-source intelligence, public informa�on, foreign ownership, control, or influence (FOCI), Country of Origin (COO), ownership and leadership personnel, comparisons against Federal Government restric�on lists, and iden�fica�on of product vulnerabili�es through the CISA na�onal known vulnerability databases.
The contractor shall comply with NIST Secure So�ware Development Framework (SSDF) SP 800- 218 for its products and services or map to the SSDF to demonstrate a framework for well-secured products. The contractor shall apply the SSDF to the en�re product lifecycle including design, development, tes�ng and opera�ons. The contractor shall secure all code in a so�ware versioning library located in a secured environment with access enabled for the government requirements, so�ware review and oversight roles. This tool must facilitate task management, versioning, check-in/check-out/commits, repor�ng, tes�ng, automa�on, deficiencies, and vulnerabili�es, debugging, flagging and traceability as examples. Addi�onally, the vendor shall iden�fy all instances of ar�ficial intelligence (AI) used in informa�on and communica�on technology (ICT) product development or suppor�ng ICT product capabili�es.
The contractor will provide an environment that adheres to NIST SP 800-207 Zero Trust Architecture and CISA Binding Operational Directive 23-02. Non-compliant conditions are unacceptable for new technologies and cannot be remediated via a Risk Based Decision (RBD) or Risk Acceptance Form and Tool (RAFT). Non-compliance discovered in existing software or hardware will result in software or hardware being placed into quarantine until non-compliance issues are remediated to the satisfaction of the government.
The federal government has the authority to conduct site reviews for compliance valida�on. Full coopera�on by contractor and third-party providers is required for audits and forensics. The contractor must support IRS in its efforts to assess and monitor the contractor systems and infrastructure. The contractor must provide logical and physical access to the contractor’s facili�es, installa�ons, technical capabili�es, opera�ons, documenta�on, records, and databases upon request.
Within 14 business days of a request from IRS Cybersecurity, the contractor shall provide the following:
i. The vendor shall provide the completed CISA Common Form documen�ng their atesta�on to the OMB 23-16 mandated secure so�ware development requirements. The contractor shall only use so�ware provided by so�ware producers who can atest to and demonstrate compliance with the Government-specified secure so�ware development prac�ces, Security and Privacy controls and
Cybersecurity Supply Chain Risk Management Prac�ces, as described in the NIST Guidance, including so�ware renewals and major version changes upon or prior to award. For any prac�ces from the NIST guidance that the so�ware producer cannot atest, the contractor shall provide documented prac�ces in place to mi�gate those risks along with a POA&M to remediate in accordance with OMB Memorandum M- 22-18, Enhancing the Security of the So�ware Supply Chain through Secure So�ware Development Practices (September 14, 2022) and M-23-16 Update to Memorandum M-22-18, Enhancing the Security of the So�ware Supply Chain through Secure So�ware Development Prac�ces (June 9, 2023).
ii. The contractor shall develop and provide an organiza�on-wide strategy for managing supply chain risks associated with the development, acquisi�on, maintenance, and disposal of systems, system components, and system services as it relates to the products and services delivered to the IRS.
iii. The contractor shall provide evidence of a C-SCRM Plan that iden�fies supply chain risk with their product or services, components, suppliers, and contractors. The contractor shall review and update the supply chain risk management plan annually.
iv. During all contract phases, including the request for proposal (RFP) and/or request for informa�on (RFI), the contractor may be required to provide responses to the IRS Cybersecurity Supply Chain Risk Assessment Ques�onnaire that contains a list of ques�ons based on the current version of NIST SP 800-53 Supply Chain Risk Management security controls and the current version of NIST SP 800-161, Cybersecurity Supply Chain Risk Management Prac�ces for Systems and Organiza�ons. The ques�onnaire will be provided to the vendor by IRS/Cybersecurity and is tailored for each procurement to assess the maturity of the contractor’s C-SCRM capabili�es and any C-SCRM related risks rela�ng to the contractor and its supplier supply chain components, subsystems, intellectual property, and other services relevant to the procurement.
18. Security Authorization/Certification and Accreditation Process. The IRS’ FIPS 199 baseline is a moderate. All solu�ons must, at a minimum, meet moderate NIST SP 800-53 security and privacy controls. However, a�er officially comple�ng the FIPS 199 it may be determined that the solu�on is a FIPS 199 high or has addi�onal control overlays above the standard baseline.
Cloud service providers and contractors developing vendor-built solu�ons must review NIST SP 800-63, use its decision trees to obtain an overview of all digital iden�ty requirements, and read the applicable NIST SP 800-63 volumes to determine specific requirements that apply to their cloud offerings. A digital iden�ty risk assessment (DIRA) will be completed to determine the appropriate authen�ca�on level; however, the IRS baseline is Iden�ty Assurance Level 2 and the solu�on must integrate with the IRS authen�ca�on solu�on.
The cloud service provider/contractor systems that collect, maintain, contain or use agency informa�on or an informa�on system on behalf of the agency (a General Support System (GSS), with a FIPS 199 security categoriza�on) must ensure annual reviews and con�nued security cer�fica�on and accredita�on. Some of the key elements of this IT risk and impact assessment process are project security deliverables such as the System Security Plan (SSP), Informa�on System Con�ngency Plan (ISCP), Business Impact Analysis (BIA) with documenta�on of inclusion of the 12-hour Maximum Tolerable Down�me (MTD) for IRS Mission Essen�al Func�ons (MEFs) and evidence of recovery capability within that 12-hour �meframe, Interconnec�on Security Agreement (ISA), Security Risk Assessment (SRAs), Data Impact Assessments (DIAs), Risk Analyses, Security Threat Analyses, Audit Plan, Source Code Review, Security Control Assessment (SCA), and/or Event-Driven Security Control Assessment (ED-SCA). All systems that complete this process will, at a minimum, meet FedRAMP, Federal Con�nuity Direc�ves (FCDs) 1 & 2, Treasury and IRS requirements. All systems must follow the NIST risk management framework (RMF) and the IRS processes suppor�ng the RMF.
19. Data Loss Prevention (DLP) Software. The cloud service provider/contractor shall implement DLP software to assure existing software will operate effec�vely in the cloud.
The cloud service provider/contractor shall be responsible for all patching and vulnerability management (PVM) of so�ware and other systems’ components suppor�ng services when doing business with the IRS to prevent proac�vely the exploita�on of IT vulnerabili�es that may exist within the cloud service provider/contractor opera�ng environment. Such patching and vulnerability management must meet the requirements and recommenda�ons of NIST SP 800-40, as amended, with special emphasis on assuring that the vendor’s PVM systems and programs apply standardized configura�ons with automated con�nuous monitoring of the same to assess and mi�gate risks associated with known and unknown IT vulnerabili�es in the cloud service provider/contractor opera�ng environment.
Furthermore, the cloud service provider/contractor shall apply standardized and automated acceptable versioning control systems that use a centralized model to capture, store, and authorize all so�ware development control func�ons on a shared device that is accessible to all developers authorized to revise so�ware suppor�ng the services when doing business with the IRS. Such versioning control systems must be configured and maintained to make sure all so�ware products deployed in the cloud service provider/contractor opera�ng environment and serving the IRS are compa�ble with exis�ng systems and architecture of the IRS.
20. Data Ownership. The delivery of data to the cloud service provider/credential service provider/contractor does not transfer any element of ownership; and as between the customer and data host, the IRS retains all right, title and interest in the data.
The cloud service provider/creden�al service provider/contractor role with respect to the data is limited to a storage func�on to fulfill its obliga�on to provide hos�ng services, and the cloud service provider/creden�al service provider/contractor will not interfere with the IRS’s access.
The cloud service provider/creden�al service provider/contractor is a “custodian” with respect to the data.
The cloud service provider/creden�al service provider/contractor shall delete or shall return the IRS’s data in an agreed-upon format, at any �me at the user’s request. The cloud service provider/creden�al service provider/contractor shall provide the IRS Contracting Officer/Contracting Officer Representative with a copy of the disposal record and no�fica�on once disposal is complete.
| 2032H5-23-Q-00140-Amendment 0001.pdf |
| AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT |
| X |
| FISMA CybSecRequireContracts Lang V10.0-AmendCopy.pdf |
| 20. Data Ownership. The delivery of data to the cloud service provider/credential service provider/contractor does not transfer any element of ownership; and as between the customer and data host, the IRS retains all right, title and interest in the d... |
File details come from the government source that posted it. Updated .