Changes to page 29 of PWS regarding FedRAMP.pdf

PDF 188 KB Posted

Attached to
VISN 10 Cardiac Telemetry Services Federal contract opportunity
Solicitation number
36C25020R0042_1
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 10

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Page 29, paragraph 6.2 of Solicitation number 36C25020R0042 currently reads:

6.2. CLOUD SPECIFIC SECURITY AND PRIVACY REQUIREMENTS (CONDITIONAL)

a. The information system solution selected by the Contractor shall comply with the Federal

Information Security Management Act (FISMA)

b. The Contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement. The contractor shall create, maintain, and update the following documentation using FedRAMP requirements and templates, which are available at www.FedRAMP.gov. The FedRAMP ATO package is comprised of this documentation:

• Privacy Impact Assessment (PIA)

• FedRAMP Test Procedures and Results

• Security Assessment Report (SAR)

• System Security Plan (SSP)

• IT System Contingency Plan (CP)

• IT System Contingency Plan (CP) Test Results

• Plan of Action and Milestones (POA&M)

• Continuous Monitoring Plan (CMP)

• FedRAMP Control Tailoring Workbook

• Control Implementation Summary Table

• Results of Penetration Testing

• Software Code Review

• Interconnection Agreements/Service Level Agreements/Memorandum of Agreements

c. The information system must be assessed by an accredited 3PAO to support initial authorization and whenever there is a significant change to the system’s security posture in accordance with the FedRAMP Continuous Monitoring Plan.

d. Contractor shall apply the appropriate set of baseline controls in accordance with VA’s categorization of the system (as defined in FIPS 199), as required in the FedRAMP Security Requirements Baseline document to ensure compliance to security standards.

e. Contractor shall, where applicable, assist with the VA Authority to Operate (ATO) Process to help achieve agency authorization of a cloud service or migrated application.

f. Contractor shall maintain a security management continuous monitoring environment based upon the latest edition of FedRAMP Security Controls Baseline and FedRAMP Continuous Monitoring Strategy Plan.

g. Information systems must be assessed by an accredited 3PAO to support initial authorization and whenever there is a significant change to the system’s security posture in accordance with the FedRAMP Continuous Monitoring Plan.

h. To the extent required to carry out the FedRAMP assessment and authorization process and FedRAMP continuous monitoring, to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public VA data collected and stored by the Contractor, the Contractor shall afford VA access to the Contractor’s and Cloud Service http://www.fedramp.gov/

Provider’s facilities, installations, technical capabilities, operations, documentation, records, and databases.

i. If new or unanticipated threats or hazards are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with the Service Level Agreement (SLA) and Security Appendix B.

j. Contractor shall comply with all VA and FedRAMP privacy requirements.

k. VA has the right to perform manual or automated audits, scans, reviews, or other inspections of the vendor’s IT environment being used to provide or facilitate services for the VA.

l. Identified gaps between required FedRAMP Security Control Baselines and Continuous Monitoring controls and the contractor’s implementation as documented in the Security Assessment Report shall be tracked by the contractor for mitigation in a Plan of Action and Milestones (POA&M) document. Depending on the severity of the gaps, the Department may require them to be remediated before a provisional authorization is issued.

m. No data shall be released by the Contractor without the consent of VA in writing. All requests for release must be submitted in writing to the COR/CO.

n. VA may choose to cancel the Contract and terminate any outstanding orders if the contractor has its Authority to Operate (ATO) revoked and the deficiencies are greater than VA risk tolerance thresholds.

o. VA reserves the right to perform Penetration Testing. If VA exercises this right, the contractor shall allow VA employees (or designated third parties) to conduct Security Assessment activities to include control reviews in accordance with FedRAMP requirements.

p. FedRAMP deliverables shall be labeled “CONTROLLED UNCLASSIFIED INFORMATION” (CUI) or contractor selected designation per document sensitivity. External transmission/dissemination of FOUO and CUI to or from a VA computer must be encrypted.

Certified encryption modules must be used in accordance with FIPS PUB 140-2, “Security requirements for Cryptographic Modules.”

Page 29, paragraph 6.2 of Solicitation number 36C25020R0042 will now read:

6.2. ASSESSMENT, AUTHORIZATION, AND CONTINUOUS MONITORING (CONDITIONAL)

a. The information system solution selected by the Contractor shall comply with the Federal Information Security Management Act (FISMA).

b. The Contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.

c. Following guidance from the Federal CIO, VA will utilize existing JAB ATO or agency ATO issued by another agency as a starting point for FedRAMP requirements. If neither of those exist, VA will sponsor FedRAMP ATO. VA will be using the FedRAMP baselines as a starting point, since they are specifically tailored for cloud services.

https://www.fedramp.gov/agency-authorization/

d. The Contractor shall, where applicable, assist with the VA ATO Process to help achieve agency authorization of the cloud service or migrated application.

e. The Contractor shall complete a FedRAMP System Security Plan (SSP) and supporting documentation within 45 days after contract award. (If Data Security Categorization is High Impact, this will be due 85 days after contract award.)

f. The Contractor shall complete a Third-Party Assessment Organization (3PAO) Security Assessment Plan (SAP) within 90 days after contract award. (If Data Security Categorization is High Impact, this will be due after 130 days after contract award.)

g. The Contractor shall complete a 3PAO Security Assessment Report (SAR) within 140 days after contract award. (If Data Security Categorization is High Impact, this will be due 180 days after contract award.)

h. The Contractor shall afford VA access to the Contractor’s and Cloud Service Provider’s (CSP) facilities, installations, technical capabilities, operations, documentation, records, and databases.

i. If new or unanticipated threats or hazards are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with the security addendum B.

j. The Contractor shall not release any data without the consent of VA in writing. All requests for release must be submitted in writing to the Contracting Officer’s Representative (COR)/Contracting Officer (CO).

k. In order for live VA data to be used in this system, a FedRAMP Authorization and Agency ATO will be required.

Deliverables:

a. FedRAMP System Security Plan (SSP) and supporting documentation

b. VA Implementation Diagram: This is a VA specific architecture diagram demonstrating the proposed implementation of this system at VA (VAID)

c. 3PAO Security Assessment Plan (SAP)

d. 3PAO Security Assessment Report (SAR)

6.2. ASSESSMENT, AUTHORIZATION, and CONTINUOUS MONITORING (Conditional)

File details come from the government source that posted it. Updated .