36C10D25Q0141 0002.docx

DOCX document 63 KB Posted

Attached to
J061--Portland RO Uninterruptable Power Source Maintenance Federal contract opportunity
Solicitation number
36C10D25Q0141
Issued by
Department of Veterans Affairs

About this file

This document is an Amendment (Standard Form 30) to a VA solicitation for 36C10D25Q0141, specifically updating Appendix C with new security language for VA information and information systems security requirements. The amendment provides a comprehensive update to VA Handbook 6500.6, Contract Security, focusing on enhanced security protocols for contractors accessing, handling, or developing VA information systems.

The amendment details extensive security requirements across 14 sections, including provisions for access to VA information systems, training mandates, security incident investigations, information system design and development, hosting and operations, product integrity, anti-virus protections, cryptographic requirements, patching governance, and specialized device security. Key requirements include mandatory cybersecurity training, immediate reporting of security incidents, compliance with federal information security standards, encryption protocols, vulnerability management, and strict controls on device and software procurement, authentication, and maintenance. The update aims to strengthen VA's information security posture by establishing rigorous standards for contractors interacting with VA information technology infrastructure.

View the file

Other files for this federal contract opportunity

Other files attached to J061--Portland RO Uninterruptable Power Source Maintenance, newest first.
File Type Posted
36C10D25Q0141 0003.docx DOCX document
36C10D25Q0141 0001.docx DOCX document
P07 Wage Determination 2015-5563 Revision 25 Dated 05302025 for Portland Multnomah County.pdf PDF
36C10D25Q0141_1.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

5. PROJECT NUMBER (if applicable)

CODE

7. ADMINISTERED BY

2. AMENDMENT/MODIFICATION NUMBER

CODE

6. ISSUED BY

8. NAME AND ADDRESS OF CONTRACTOR

4. REQUISITION/PURCHASE REQ. NUMBER

3. EFFECTIVE DATE

9A. AMENDMENT OF SOLICITATION NUMBER

9B. DATED

PAGE OF PAGES

10A. MODIFICATION OF CONTRACT/ORDER NUMBER

10B. DATED

BPA NO.

1. CONTRACT ID CODE

FACILITY CODE

CODE

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

E. IMPORTANT:

is extended,

(a) By completing Items 8 and 15, and returning __________ copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY is not extended.

12. ACCOUNTING AND APPROPRIATION DATA

(REV. 11/2016)

is required to sign this document and return ___________ copies to the issuing office.

is not, A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN ITEM 10A.

15C. DATE SIGNED

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER

Contractor

16C. DATE SIGNED

14. DESCRIPTION OF AMENDMENT/MODIFICATION

16B. UNITED STATES OF AMERICA

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER

16A. NAME AND TITLE OF CONTRACTING OFFICER

15B. CONTRACTOR/OFFEROR

STANDARD FORM 30

PREVIOUS EDITION NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.243 (Type or print) (Type or print) (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

(Number, street, county, State and ZIP Code) (If other than Item 6) (Specify type of modification and authority) (such as changes in paying office, appropriation date, etc.)

(If required)

(SEE ITEM 11)

(SEE ITEM 13)

(X)

CHECK

ONE

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

(Signature of person authorized to sign) (Signature of Contracting Officer)

VA

07-23-2025 00101 Department of Veterans Affairs Veterans Benefits Administration Acquisition Directorate 1800 G Street NW Washington

DC

20006 00101 Department of Veterans Affairs Veterans Benefits Administration Acquisition Directorate 1800 G Street NW Washington

DC

20006 To all Offerors/Bidders

36C10D25Q0141

X X X X Amendment to add updated Appendix C security language.

Craig Harris Contracting Officer

VA-VBA-2024-0012

UPDATE TO VA HANDBOOK 6500.6, CONTRACT SECURITY, APPENDIX C VA INFORMATIONANDINFORMATIONSYSTEMSECURITY/PRIVACYLANGUAGE FOR INCLUSION INTO CONTRACTS, AS APPROPRIATE

1. PURPOSE:ThepurposeofthisnoticeistoamendtheDepartmentofVeterans Affairs (VA) Handbook 6500.6, Contract Security, to include updated security language for Appendix C.

2. POLICY:

a. The Office of Information Security published VA Handbook 6500.6, Contract SecurityonMarch12,2010.Thishandbookiscurrentlyunderrevisionandwill incorporate many updates and changes but must go through departmental concurrence prior to publication.

b. This notice replaces VA Handbook 6500.6, Appendix C, VA Information and InformationSystemSecurity/PrivacyLanguageforInclusionintoContracts,as appropriate, to incorporate updated security language.

c. Thischangewilltakeplaceimmediatelyandshouldbeappliedtothecurrent version of VA Handbook 6500.6 Appendix C.

3. RESPONSIBLEOFFICE:OfficeofInformationandTechnology(OIT)(005);Office of Information Security (005R).

4. RELATEDHANDBOOK:VAHandbook6500.6,ContractSecurity,datedMarch12,2010.

5. RESCISSION:This notice will be rescinded and guidance incorporated into the appropriatedirective/handbooknolaterthanoneyearafterthedateofpublication.

Department of Veterans Affairs Washington, DC 20420

VA

NOTICE

24- April 22, CERTIFIEDBY:

/s/ Guy T. Kiyokawa AssistantSecretaryfor Enterprise Integration

DISTRIBUTION:ElectronicOnly

BYDIRECTIONOFTHESECRETARY OF VETERANS AFFAIRS:

/s/ Kurt D. DelBene AssistantSecretaryfor InformationandTechnologyand Chief Information Officer

APPENDIXC—VAINFORMATIONANDINFORMATIONSYSTEMSECURITYAND PRIVACY LANGUAGE FOR INCLUSION IN CONTRACTS, AS APPROPRIATE NOTE:Any sections (1-14) which DO NOT apply should not be included in the StatementofWork(SOW),PerformanceWorkStatement(PWS),ProductDescription (PD) or contract.

1. GENERAL.This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards,VAdirectivesandhandbooks,asVApersonnelregardinginformationand information system security and privacy.

2. VAINFORMATIONCUSTODIALLANGUAGE.Thisentiresectionappliestoall acquisitions requiring any Information Security and Privacy language.

a. The Government shall receive unlimited rights to data/intellectual property first producedanddeliveredintheperformanceofthiscontractororder(hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof.The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19,Commercial Computer SoftwareLicense.

b. Information made available to the contractor by VA for the performance or administrationofthiscontractwillbeusedonlyforthepurposesspecifiedinthe service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14Rights in Data – General.

c. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliancewithFederalandVArequirementsrelatedtodataprotection,data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.

d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staffassociatedwiththecontract)toVA,VA'sOfficeInspectorGeneral(OIG), VA

Handbook

6500.6 APPENDIX C

April 22, C-and/orGovernmentAccountabilityOffice(GAO)staffduringperiodiccontrol assessments, audits, or investigations.

e. ThecontractormayonlyuseVAinformationwithinthetermsofthecontractand applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification andadjustment necessary to implement the new laws, regulations, and/or policies.

f. ThecontractorshallnotmakecopiesofVAinformationexceptasspecifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.

g. IfaVeteransHealthAdministration(VHA)contractisterminatedfordefaultor cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.

h. ThecontractorshallstoreandtransmitVAsensitiveinformationinanencrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for CryptographicModules(oritssuccessor)validatedandinconformancewithVA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS)Implementations.

i. Thecontractor’sfirewallandwebservicessecuritycontrols,asapplicable,shall meet or exceed VA’s minimum requirements.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA informationonlyintwosituations:(i)inresponsetoaqualifyingorderofacourt of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for productionof orinquiriesabout, VAinformation and information systemstothe VA CO for response.

k. Notwithstanding the provision above, the contractor shall not release VA recordsprotectedbyTitle38U.S.C.§5705,Confidentialityofmedicalquality- assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain

VA

HANDBOOK

6500.6 APPENDIX C

April 22, C-medicalrecordspertaining to drug addiction,sickle cellanemia, alcoholismor alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above- mentionedinformation,thecontractorshallimmediatelyrefersuchcourtorder or other requests to the VA CO for response.

l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordancewithVADirective6500andIdentityandAccessManagement(IAM) SecurityprocessesspecifiedintheVAInformationSecurityKnowledgeService.

m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management,VAHandbook6300.1,RecordsManagementProcedures,and applicable VA Records Control Schedules.

n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88,Guidelines forMediaSanitizationpriortoterminationorcompletionofthiscontract.Ifdirected by the COR/CO, the contractor shall return all Federal Records to VA fordisposition.

o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA.The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative(COR)orCO.ItemsshallbereturnedsecurelyviaVA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method(USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the trackinginformation.Self-certificationbythecontractorthatthedatadestruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.

p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.)usedtostore,processoraccessVAinformationwillnotbereturnedtothe contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.

3. ACCESSTOVAINFORMATIONANDVAINFORMATIONSYSTEMS.Thissection applies when any person requires access to information made available to the contractorbyVAfortheperformanceoradministrationofthiscontractorinformation developed by the contractor in performance or administration of the contract.

a. Acontractor/subcontractorshallrequestlogical(technical)orphysicalaccessto VA information and VA information systems for their employees and subcontractorsonly to the extent necessaryto perform the servicesspecified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.

b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems(seeSection4,Training,below).TheROBcontainstheminimumuser compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems.Users who require privileged access shall completetheVAelevatedprivilegeaccessrequestprocessesbeforeprivileged access is granted.

c. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710,PersonnelSuitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsibleforthesepoliciesandprocedures.Contractpersonnelwhorequire access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States.All contractors and subcontractors working with VA information must be permanentlylocatedwithinajurisdictionsubjecttothelawoftheUnitedStates oritsTerritoriestothemaximumextentfeasible.Ifservicesareproposedtobe performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

e. ThecontractorshallnotifytheCOR/COinwritingimmediately(nolaterthan24 hours) after personnel separation or occurrence of other causes. Causes may include the following:

(1) Contractor/subcontractorpersonnelnolongerhasaneedforaccesstoVA information or VA information systems.

C-4

VA

Handbook

6500.6 APPENDIX C

April 22,

(2) Contractor/subcontractor personnel are terminated, suspended, or otherwisehastheirworkonaVAprojectdiscontinuedforanyreason.

(3) Contractor believes their own personnel or subcontractor personnel may poseathreattotheircompany’sworkingenvironmentortoanycompany- owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.

(4) Any previously undisclosed changes to contractor/subcontractor backgroundhistoryarebroughttolight,includingbutnotlimitedto changes to background investigation or employee record.

(5) Contractor/subcontractorpersonnelhavetheirauthorizationtoworkinthe United States revoked.

(6) AgreementbywhichcontractorprovidesproductsandservicestoVAhas either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.

f. Insuchcasesofcontractfulfillment,termination,orothercauses;thecontractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens.Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

g. Contractors/subcontractors who no longer require VA accesses will return VA- issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shallbereturnedtothenearestVAPIVBadgeIssuanceOffice.Oncetheyhave had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VACOR/CO.

4. TRAINING.Thisentiresectionappliestoallacquisitionswhichincludesection3.

a. AllcontractorsandsubcontractorsrequiringaccesstoVAinformationandVA information systems shall successfully complete the following before being granted access to VA information and its systems:

(1) VA Privacy and Information Security Awareness and Rules of Behavior course(TalentManagementSystem(TMS)#10176)initiallyandannuallythereafter.

VA

Handbook

6500.6 APPENDIX C

April 22, C-

(2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the OrganizationalRulesofBehavior,relatingtoaccesstoVAinformationand information systems initially and annually thereafter; and

(3) Successfullycompleteanyadditionalcybersecurityorprivacytraining,as required for VA personnel with equivalent information system or informationaccess[tobe defined bythe VAprogramofficialandprovided to the VA CO for inclusion in the solicitation document – i.e., any role- based information security training].

b. ThecontractorshallprovidetotheCOR/COacopyofthetrainingcertificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training is grounds for suspension or terminationofallphysicalorelectronicaccessprivilegesandremovalfromwork on the contract until such time as the required training is complete.

5. SECURITYINCIDENTINVESTIGATION.Thisentiresectionappliestoall acquisitions requiring any Information Security and Privacy language.

a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour)report suspected security / privacyincidentsto theVAOIT’sEnterpriseServiceDesk(ESD)bycalling(855)673-4357(TTY: 711). The ESD is OIT’s 24/7/365 single pointof contact forIT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or businessassociates shall, within one hour, provide the COR/CO the incident number received from the ESD.

b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor'snoticetoVAshallidentifytheinformationinvolvedandthe circumstances surrounding the incident, including the following:

(1) Thedateandtime(orapproximationof)theSecurityIncidentoccurred.

(2) Thenamesofindividualsinvolved(whenapplicable).

(3) Thephysicalandlogical(ifapplicable)locationoftheincident.

(4) WhytheSecurityIncident tookplace(i.e.,catalyst forthefailure).

(5) Theamountofdata belongingtoVAbelievedtohavebeencompromised.

(6) Theremediationmeasuresthecontractoristakingtoensurenofuture incidents of a similar nature.

c. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover.The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independentriskanalysisonbehalfofVA.Failuretocooperatemaybedeemed a material breach and grounds for contract termination.

d. VA IT contractors shall follow VA Handbook 6500, Risk Management FrameworkforVAInformationSystemsVAInformationSecurityProgram,and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.

e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to theappropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees,anditssubcontractorsandtheiremployeesshallcooperatewithVA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

f. The contractor shall comply with VA Handbook 6500.2,Management ofBreaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, managementandreportingproceduresassociatedwithmanagingofbreaches.

g. WithrespecttounsecuredProtectedHealthInformation(PHI),thecontractoris deemed tohave discovered adatabreachwhenthecontractorknew orshould have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.

h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processesormaintainsunderthecontract;thecontractorshallpayliquidated damagestotheVAassetforthinclause852.211-76,LiquidatedDamages—Reimbursement for Data Breach Costs.

6. INFORMATIONSYSTEMDESIGNANDDEVELOPMENT.Thisentiresection applies to information systems, systems, major applications, minor applications, enclaves,andplatforminformationtechnologies(toincludethesubcomponentsof each) designed or developed for or on behalf of VA by any non-VA entity.

a. InformationsystemsdesignedordevelopedonbehalfofVAatnon-VAfacilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards forthe protection of electronic Protected Health Information (PHI), outlined in 45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems and FIPS 200, Minimum Security Requirements for Federal Information Systems. Baseline security controls shall be implemented commensuratewiththeFIPS199system securitycategorization(referenceVA Handbook 6500 and VA Trusted Internet Connections (TIC) Architecture).

b. Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA Assessment and Authorization (A&A) processes in VA Handbook 6500 and VA Information Security Knowledge Service to obtain an Authority to Operate (ATO). VA Directive 6517, Risk ManagementFrameworkforCloudComputingServices,providesthesecurity and privacy requirements for cloud environments.

c. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500, VA Handbook 6517,Risk Management Framework for Cloud Computing Servicesand Information Security Knowledge Service specifications in delivered IT systems/solutions, productsand/orservices. If systems/solutions, products and/orservices donot directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution.ContractorsshallcomplywithFAR39.1,specificallytheprohibitionsreferenced.

d. The contractor (including producers and resellers) shall comply with Office of Management and Budget (OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M- 22-18 (September14, 2022). The term “software” includes firmware, operating systems,applicationsandapplicationservices(e.g.,cloud-basedsoftware),as well as products containing software. The contractor shall provide a self- attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program (FedRAMP) Third Party Assessor Organization (3PAO) or one approvedbytheagencywillbeacceptableinlieuofasoftwareproducer'sself-attestation.

e. The contractor shall ensure all delivered applications, systems and information systems are compliant with Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity managementrequirementsassetforthinOMBM-19-17,M-05-24,FIPS201-3, PersonalIdentityVerification(PIV)ofFederalEmployeesandContractors(or its successor), M-21-31 and supporting NIST guidance. This applies to Commercial Off-The-Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations.

f. The contractor shall ensure all contractor delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity Guidelines, for direct, assertion-based authenticationand/ortrust-basedauthentication,asdeterminedbythedesign and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common Access Card (CAC), as determined by the business need and compliance with VA Information Security Knowledge Service specifications.

g. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operatecorrectlyasintendedonsystemsincompliancewithVAbaselinesprior to acceptance or connection into an authorized VA computing environment. If the Defense Information Systems Agency (DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requiresthepopulationofoperatingsystemsandapplicationsincludesalllisted on the NIST National Checklist Program Checklist Repository.

h. The standard installation, operation, maintenance, updating and patching of softwareshallnotaltertheconfigurationsettingsfromVAapprovedbaseline configuration. Software developed for VA must be compatible with VA enterpriseinstallerservicesandinstalltothedefault“programfiles”directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on VA systems.

i. Applicationsdesignedfornormalenduserswillruninthestandardusercontext without elevated system administration privileges.

j. The contractor-delivered solutions shall reside on VA approved operating systems.ExceptionstothiswillonlybegrantedwiththewrittenapprovaloftheCOR/CO.

k. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development lifecycleoutlinedinNIST800-37,RiskManagementFrameworkforInformation Systems and Organizations: A System Life Cycle Approach for Security and Privacy, VA Directive and Handbook 6500, and VA Handbook 6517.

l. TheContractorshallcomplywiththePrivacyActof1974(theAct),FAR52.224- 2 Privacy Act, and VArules and regulations issued under the Actin the design, development, or operation of any system of records on individuals to accomplish a VA function.

m. The contractor shall ensure the security of all procured or developed informationsystems,systems,majorapplications,minorapplications,enclaves and platform information technologies, including their subcomponents (hereinafter referred to as “Information Systems”) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems.

n. When the contractor is responsible for operations or maintenance of the systems, the contractor shall apply the security fixes within the timeframe specifiedbytheassociatedcontrolsontheVAInformationSecurityKnowledge Service. When security fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the contractor shall provide written notice to the VA COR/CO that the patch has been validated as to not affecting the Systems within 10 business days.

7. INFORMATIONSYSTEMHOSTING,OPERATION,MAINTENANCEORUSE.

This entire section applies to information systems, systems, major applications, minorapplications,enclaves,andplatforminformationtechnologies(cloudandnon- cloud) hosted, operated, maintained, or used on behalf of VA at non-VA facilities.

a. The contractor shall comply with all Federal laws, regulations,and VA policies for Information systems (cloud and non-cloud) that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities. Security controls for collecting, processing, transmitting, and storing of VA sensitive information, must be in place. The controls will be tested by VA or a VA sanctioned 3PAO and approved by VA prior to hosting, operation, maintenance or use of the informationsystemorsystemsbyoronbehalfofVA.Thisincludesconducting compliance risk assessments, security architecture analysis, routine vulnerabilityscanning,systempatching, changemanagementproceduresand the completion of an acceptable contingency plan for each system. The contractor’ssecuritycontrolproceduresshallbethesameasproceduresused to secure VA-operated information systems.

b. Outsourcing (contractor facility, equipment, or staff) of systems or network operations, telecommunications services or other managed services require AssessmentandAuthorization(A&A)ofthecontractor’ssystemsinaccordance with VA Handbook 6500 as specified in VA Information Security Knowledge

Service. Major changes to the A&A package may require reviewing and updating all the documentation associated with the change. The contractor’s cloudcomputingsystemsshallcomplywithFedRAMPandVADirective6517requirements.

c. The contractor shall return all electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) on non-VA leased or non-VA owned IT equipment used to store, process or access VA information to VA in accordance with A&Apackage requirements. This applies when the contract is terminated or completed and prior to disposal of media. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Information Security Knowledge Service requirements and NIST 800-88. The contractor shall send a self-certification that the data destruction requirements abovehavebeenmettotheCOR/COwithin30businessdaysofterminationof the contract.

d. AllexternalinternetconnectionstoVAnetworkinvolvingVAinformationmust be in accordance with VA Trusted Internet Connection (TIC) Reference Architecture and VA Directive and Handbook 6513, Secure External Connections and reviewed and approved by VA prior to implementation. Government-owned contractor-operated systems, third party or business partner networks require a Memorandum of Understanding (MOU) and Interconnection Security Agreements (ISA).

e. Contractorproceduresshallbesubjecttoperiodic,announced,orunannounced assessments by VA officials, the OIG or a 3PAO. The physical security aspects associated with contractor activities are also subject to such assessments. The contractor shall report, in writing, any deficiencies noted during the above assessment to the VA COR/CO. The contractor shall use VA’s defined processes to document planned remedial actions that address identified deficiencies in information security policies, procedures, and practices. The contractor shall correct security deficiencies within the timeframes specified in the VA Information Security Knowledge Service.

f. All major information system changes which occur in the production environment shall be reviewed by the VA to determine the impact on privacy and security of the system. Based on the review results, updates to the AuthoritytoOperate(ATO)documentationandparametersmayberequiredto remain in compliance with VA Handbook 6500 and VA Information Security Knowledge Service requirements.

g. Thecontractorshallconductanannualprivacyandsecurityself-assessmenton all information systems and outsourced services as required. Copies of the assessment shall be provided to the COR/CO. The VA/Government reserves the right to conduct assessment using government personnel or a third-party if deemed necessary. The contractor shall correct or mitigate any weaknesses discovered during the assessment.

h. VA prohibits the installation and use of personally owned or contractor-owned equipment or software on VA information systems. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW, PWS, PD or contract. All security controls required for government furnished equipment must be utilized in VA approved Other Equipment (OE). Configuration changes to the contractor OE, must be funded by the owner of the equipment. All remote systems must use a VA-approved antivirus software and a personal (host-based or enclave based) firewall with a VA-approved configuration. The contractor shall ensure software on OE is kept current with all critical updates and patches. Owners of approved OE are responsibleforprovidingandmaintainingtheanti-virussoftwareandthefirewall on the non-VA owned OE. Approved contractor OE will be subject to technical inspection at any time.

i. The contractor shall notify the COR/CO within one hour of disclosure or successful exploits of any vulnerability which can compromise the confidentiality,integrity,oravailabilityoftheinformationsystems.Thesystemor effected component(s) need(s) to be isolated from the network. A forensic analysis needs to be conducted jointly with VA. Such issues will be remediated as quickly aspracticable, but innoeventlongerthan the timeframespecifiedby VA Information Security Knowledge Service. If sensitive personal information is compromised reference VA Handbook 6500.2 and Section 5, Security IncidentInvestigation.

j. For cases wherein the contractor discovers material defects or vulnerabilities impacting products and services they provide to VA, the contractor shall develop and implement policiesandprocedures fordisclosure to VA, as well as remediation. The contractor shall, within 30 business days of discovery, documentasummaryofthesevulnerabilitiesordefects.Thedocumentationwill include a description of the potential impact of each vulnerability and material defect, compensating security controls, mitigations, recommended corrective actions,root cause analysisand/orworkarounds(i.e.,monitoring).Should there exist any backdoors in the products or services they provide to VA (referring to methods for bypassing computer authentication), the contractor shall provide the VA CO/CO written assurance they have permanently remediated thesebackdoors.

k. All other vulnerabilities, including those discovered through routine scans or other assessments, will be remediated based on risk, in accordance with the remediation timelines specified by the VA Information Security Knowledge Service and/or the applicable timeframe mandated by Cybersecurity & InfrastructureSecurityAgency(CISA)BindingOperationalDirective(BOD)22- 01 and BOD 19-02 for Internet-accessible systems. Exceptions to this paragraph will only be granted with the approval of the COR/CO.

8. SECURITYANDPRIVACYCONTROLSCOMPLIANCETESTING,ASSESSMENT

ANDAUDITING.Thisentiresectionapplieswheneversection6or7isincluded.

a. ShouldVArequestit,thecontractorshallprovideacopyoftheir(corporation’s, sole proprietorship’s, partnership’s, limited liability company (LLC), or other business structure entity’s) policies, procedures, evidence and independent report summaries related to specified cybersecurity frameworks (International Organization forStandardization(ISO), NISTCybersecurity Framework (CSF), etc.). VA or its third-party/partner designee (if applicable) are further entitled to perform their own audits and security/penetration tests of the contractor’s IT or systemsandcontrols,toascertainwhetherthecontractoriscomplyingwiththe information security, network or system requirements mandated in the agreement between VA and the contractor.

b. Any audits or tests of the contractor or third-party designees/partner VA elects to carry out will commence within 30 business days of VA notification. Such audits, tests and assessments may include the following: (a): security/penetration tests which both sides agree will not unduly impact contractor operations; (b): interviews with pertinent stakeholders and practitioners; (c): document review; and (d): technical inspections of networks andsystemsthecontractorusestodestroy,maintain,receive,retain,oruseVAinformation.

c. As part of these audits, tests and assessments, the contractor shall provide all informationrequestedbyVA.Thisinformationincludes,butisnotlimitedto,the following: equipment lists, network or infrastructure diagrams, relevant policy documents, system logs or details on information systems accessing, transporting, or processing VA data.

d. Thecontractorandatitsownexpense,shallcomplywithanyrecommendations resulting from VA audits, inspections and tests. VA further retains the right to viewanyrelatedsecurityreportsthecontractorhasgeneratedaspartofitsown security assessment. The contractorshall also notify VAoftheexistenceofany such security reports or other related assessments, upon completion andvalidation.

e. VA appointed auditors or other government agency partners may be granted access to such documentation on a need-to-know basis and coordinated throughtheCOR/CO.Thecontractorshallcomplywithrecommendationswhich result from these regulatory assessments on the part of VA regulators and associated government agency partners.

9. PRODUCTINTEGRITY,AUTHENTICITY,PROVENANCE,ANTI-COUNTERFEIT

ANDANTI-TAMPERING.Thisentiresectionapplieswhentheacquisitioninvolves anyproduct(application,hardware,orsoftware)orwhensection6or7isincluded.

a. The contractor shall comply with Code of Federal Regulations (CFR) Title 15 Part 7, “Securing the Information and Communications Technology and Services(ICTS)SupplyChain”,whichprohibitsICTSTransactionsfromforeign adversaries. ICTS Transactions are defined as any acquisition, importation, transfer, installation, dealing in or use of any information and communications technologyorservice,includingongoingactivities,suchasmanagedservices, datatransmission,softwareupdates,repairsortheplatformingordatahosting of applications for consumer download.

b. When contracting terms require the contractor to procure equipment, the contractor shall purchase or acquire the equipment from an Original Equipment Manufacturer (OEM) or an authorized reseller of the OEM. The contractor shall attestthatequipmentprocuredfromanOEMorauthorizedresellerordistributor areauthentic.IfprocurementisunavailablefromanOEMorauthorizedreseller, the contractor shall submit in writing, details of the circumstances prohibiting this from happening and procure a product waiver from the VA COR/CO.

c. All contractors shall establish, implement, and provide documentation for risk management practices for supply chain delivery of hardware, software (to include patches) and firmware provided under this agreement. Documentation will include chain of custody practices, inventory management program, informationprotectionpractices,integritymanagementprogramforsub-supplier provided components, and replacement parts requests. The contractor shall make spare parts available. All contractor(s) shall specify how digital deliveryfor procured products, including patches, will be validated and monitored to ensure consistent delivery. The contractor shall apply encryption technology to protect procured products throughout the delivery process.

d. IfacontractorprovidessoftwareorpatchestoVA,thecontractorshallpublish or provide a hash conforming to the FIPS Security Requirements for Cryptographic Modules (FIPS 140-2 or successor).

e. Thecontractorshallprovideasoftwarebillofmaterials(SBOM)forprocured(to include licensed products) and consist of a list of components and associated metadata which make up the product. SBOMs must be generated in one of the data formats defined in the National Telecommunications and Information Administration (NTIA) report “The Minimum Elements for a Software Bill of Materials (SBOM).”

f. Contractorsshalluseorarrangefortheuseoftrustedchannelstoship procuredproducts,suchasU.S.registeredmailand/ortamper-evident packaging for physical deliveries.

g. Throughoutthedeliveryprocess,thecontractorshalldemonstrateacapability for detecting unauthorized access (tampering).

h. Thecontractorshalldemonstratechain-of-custodydocumentationforprocured products and require tamper-evident packaging for the delivery of thishardware.

10. VIRUSES,FIRMWAREANDMALWARE.Thisentiresectionapplieswhenthe acquisition involves any product (application, hardware, or software) or when section 6 or 7 is included.

a. Thecontractorshallexecuteduediligencetoensureallprovidedsoftwareand patches, including third-party patches, are free of viruses and/or malware before releasing them to or installing them on VA information systems.

b. The contractor warrants it has no knowledge of and did not insert, any malicious virus and/or malware code into any software or patches provided to VA which could potentially harm or disrupt VA information systems. The contractor shall use due diligence, if supplying third-party software or patches, toensurethethird-partyhasnotinsertedanymaliciouscodeand/orviruswhich could damage or disrupt VA information systems.

c. Thecontractorshallprovideorarrangefortheprovisionoftechnicaljustification as to why any “false positive” hit has taken place to ensure their code’s supply chain has not been compromised. Justification may be required, but is not limited to, when install files, scripts, firmware, or other contractor-delivered software solutions (including third-party install files, scripts, firmware, or other software) are flagged as malicious, infected, or suspicious by an anti-virusvendor.

d. The contractor shall not upload (intentionally or negligently) any virus, worm, malware or any harmful or malicious content, component and/or corrupted data/source code (hereinafter “virus or other malware”) onto VA computer and informationsystemsand/ornetworks.Ifintroduced(andthisclauseisviolated), upon written request from the VA CO, the contractor shall:

(1) Take all necessary action to correct the incident, to include any and all assistancetoVAtoeliminatethevirusorothermalwarethroughoutVA’s information networks, computer systems and information systems; and

(2) Usecommerciallyreasonableeffortstorestoreoperationalefficiencyand remediatedamagesduetodatalossordataintegritydamage,ifthevirus or other malware causes a loss of operational efficiency, data loss, or damage to data integrity.

11. CRYPTOGRAPHICREQUIREMENT.Thisentiresectionapplieswheneverthe acquisition includes section 6 or 7 is included.

a. The contractor shall document how the cryptographic system supporting the contractor’s products and/or services protect the confidentiality, data integrity, authenticationandnon-repudiationofdevicesanddataflowsintheunderlyingsystem.

b. Thecontractorshalluseonlyapprovedcryptographicmethodsasdefinedin FIPS 140-2 (or its successor) and NIST 800-52 standards when enabling encryption on its products.

c. Thecontractorshallprovideorarrangefortheprovisionofanautomated remote key-establishment method which protects the confidentiality and integrity of the cryptographic keys.

d. Thecontractorshallensureemergencyre-keyingofalldevicescanberemotely performed within 30 business days.

e. Thecontractorshallprovideorarrangefortheprovisionofamethodfor updating cryptographic primitives or algorithms.

12. PATCHINGGOVERNANCE.Thisentiresectionapplieswhenevertheacquisition includes section 7 is included

a. The contractor shall provide documentation detailing the patch management, vulnerability management, mitigation and update processes (to include third- party)priortotheconnectionofelectronicdevices,assetsorequipmenttoVA’s assets. This documentation will include information regarding the follow:

(1) Theresourcesandtechnicalcapabilitiestosustaintheprogramor process(e.g.,howtheintegrityof apatch isvalidated byVA);and

(2) Theapproachandcapabilitytoremediatenewlyreportedzero-day vulnerabilities for contractor products.

b. The contractor shall verify and provide documentation all procured products (includingthird-partyapplications,hardware,software,operatingsystems,and firmware) have appropriate updates and patches installed prior to delivery toVA.

c. The contractor shall provide or arrange the provision of appropriate software and firmware updates to remediate newly discovered vulnerabilities or weaknesses for their products and services within 30 days of discovery. Updatestoremediatecriticaloremergentvulnerabilitieswillbeprovidedwithin seven business days of discovery. If updates cannot be made available by contractor within these time periods, the contractor shall submit mitigations, methods of exploit detection and/or workarounds to the COR/CO prior to the above deadlines.

d. The contractor shall provide or arrange for the provision of appropriate hardware, software and/or firmware updates, when those products, including open-source software, are provided to the VA, to remediate newly discovered vulnerabilitiesorweaknesses.Remediationsofproductsorservicesprovidedto the VA’s system environment must be provided within 30 business days of availability from the original supplier and/or patching source. Updates to remediate critical vulnerabilities applicable to the Contractor’s use of the third- party productin its system environment will be provided within sevenbusiness days of availability from the original supplier and/or patching source. If applicablethird-partyupdatescannotbeintegrated,testedandmadeavailable byContractorwithinthesetimeperiods,mitigationsand/orworkaroundswillbe provided to the COR/CO before the above deadlines.

13. SPECIALIZEDDEVICES/SYSTEMS(MEDICALDEVICES,SPECIALPURPOSE

SYSTEMS, RESEARCH SCIENTIFIC COMPUTING).This entire section applies whentheacquisitionincludesoneormoreMedicalDevice,SpecialPurposeSystem or Research Scientific Computing Device. If appropriate, ensure selected clauses from section 6 or 7 and 8 through 12 are included.

a. Contractor supplies/delivered Medical Devices, Special Purpose Systems- OperationalTechnology(SPS-OT)andResearchScientificComputingDevices shall comply with all applicable Federal law, regulations, and VA policies. New developments require creation, testing, evaluation, and authorization in compliance with processes specified on the Specialized Device Cybersecurity Department Enterprise Risk Management (SDCD-ERM) Portal, VA Directive 6550,Pre-Procurement Assessment and Implementation of MedicalDevices/Systems, VA Handbook 6500, and the VA Information Security Knowledge Service. Deviations from Federal law, regulations, and VA Policy are identified and documented as part of VA Directive 6550 and/or the VA Enterprise Risk Analysis (ERA) processes for Specialized Devices/Systemsprocesses.

b. All contractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500 and Information Security Knowledge Service specifications in delivered IT systems/solutions,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .