ATTACHMENT B - SaaS Contract Language.docx

DOCX document 24 KB Posted

Attached to
DA10--Software/Hardware Purchase & Install | CCTV/Security Weapon Detection System Federal contract opportunity
Solicitation number
36C24423Q1184
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 4

About this file

This document contains templated language for a Software-as-a-Service contract. Key requirements include the selected information system solution must comply with the Federal Information Security Management Act and FedRAMP requirements. The contractor must assist with the VA authorization to access process, provide an incident response plan within 14 days of award and complete a tabletop exercise within 21 days. The contractor is required to provide a system boundary diagram, FedRAMP system security plan and supporting documentation, and a third-party security assessment plan and report at time of award. The contractor must provide the VA access to facilities and documentation and notify the VA of any new threats discovered. Live VA data can only be used with a FedRAMP authorization and agency authorization to operate. Required deliverables include the system boundary diagram, security plan and documentation, and third-party security assessment plan and report.

View the file

Other files for this federal contract opportunity

Other files attached to DA10--Software/Hardware Purchase & Install | CCTV/Security Weapon Detection System, newest first.
File Type Posted
36C24423Q1184 0002_1.docx DOCX document
36C24423Q1184 0001_1.docx DOCX document
ATTACHMENT A - SOW.docx DOCX document
ATTACHMENT C - SCA Act WD 2015-4215 Rev 22 Dated 06-30-2023.pdf PDF
36C24423Q1184_1.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C24423Q1184_1 ATTACHMENT B - SaaS Templated Language Software-as-a-Service (SaaS) Templated Language | VA Data VA Data Please insert the following language into the requirements section:

ASSESSMENT, AUTHORIZATION, and CONTINUOUS MONITORING

1. The information system solution selected by the Contractor shall comply with the Federal Information Security Management Act (FISMA)

2. The Contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement

3. The Contractor shall, where applicable, assist with the VA ATO Process to help achieve agency authorization of the cloud service or migrated application.

4. The Contractor shall provide IRP scenario within 14 days and complete Table-Top exercise within 21 days of award unless current VA IRP can be provided

5. The Contractor shall provide a System Boundary Diagram that demonstrates implementation and any proposed VA interconnections including required ports and protocols at the time award

6. The Contractor shall complete a FedRAMP System Security Plan (SSP) and supporting documentation at the time of award

7. The Contractor shall complete a Third-Party Assessment Organization (3PAO) Security Assessment Plan (SAP) at the time of award

8. The Contractor shall complete a 3PAO Security Assessment Report (SAR) at the time of award

9. The Contractor shall afford VA access to the Contractor’s and Cloud Service Provider’s (CSP) facilities, installations, technical capabilities, operations, documentation, records, and databases

10. If new or unanticipated threats or hazards are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with the security addendum B

11. The Contractor shall not release any data without the consent of VA in writing. All requests for release must be submitted in writing to the Contracting Officer’s Representative (COR)/Contracting Officer (CO)

12. In order for live VA data to be used in this system, a FedRAMP Authorization and Agency ATO will be required

Deliverables:

A. System Boundary Diagram B. FedRAMP System Security Plan (SSP) and supporting documentation C. 3PAO Security Assessment Plan (SAP) 3PAO Security Assessment Report (SAR)

File details come from the government source that posted it. Updated .