Attachment_B_-_CIO_12-2018__IT_Policy_Requirements_Guide_0.pdf
PDF 277 KB Posted
- Attached to
- 3D PDF Generator Federal contract opportunity
- Solicitation number
- 47HAA019Q0121
- Issued by
- GSA Office of Administrative Services
About this file
Attachment B
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_A_-_Security_and_Privacy_Requirements_for_IT_Acquisition_Efforts_CIO_IT_Security_09-48_Rev_4_01-25-2018.pdf | ||
| 3D_PDF_Generator_RFQ.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CIO-12-2018 IT Policy Requirements Guide
Office of the Chief Information Officer
IT Policy Requirements Guide
CIO-12-2018
U.S. General Services Administration 1
Table of Contents
1.0 Introduction ……………………………………………………………………………………………………………2
1.1 Scope…………………………………………………………………………………………………………….2
1.2 Purpose…………………………………………………………………………………………………………2
2.0 Contracting Life Cycle………………………………………………………………………………………………2
2.1 Contracting Life Cycle Graphic……………………………………………………………………….3
2.2 Contracting Phase Activities for COR …………………………………………………………….3
3.0 Non-Security & Non-Privacy IT Policies……………………………………………………………...4-10
4.0 Internal GSA Resources……………………………..……………………………………………..10
5.0 External GSA Resources…………………………….……………………………………………..10
U.S. General Services Administration 2
1.0 Introduction
The U.S. General Services Administration (GSA) has implemented various federal policies for providing direction, and constituting uniform rules and accountability for governing the acquisition and usage of information technology (IT). This document identifies GSA information technology policies other than security and privacy policies and provides guidance to help GSA employees and applicable contractors fulfill them. Having one comprehensive Guide identify policies will assist the GSA workforce’s understanding and implementation of policies. As policies are updated this guide will be updated.
1.1 Scope
This IT Policy Requirements Guide covers IT policies other than security and privacy because GSA CIO 09- 48 IT Security Procedural Guide covers all security and privacy IT policies. As a result of the close association of IT systems and IT governance processes in some cases one may be able to detect a relationship between the listed policies and what could be referred to as explicit IT security policy.
However the primary scope of this guide is on IT policies outside of security and privacy.
1.2 Purpose
The purpose of this Guide is to identify applicable non-security and non-privacy IT policies and provide guidance on implementing these policies. The applicability of IT policy to the contracting phases is used to help highlight critical requirements that the acquisition professional must adhere to. There is emphasis given to the Contracting Officer’s Representative (COR) due to his or her unique viewpoint in contract management. In addition, this guide identifies what IT policies a contractor must comply with when this guide has been incorporated into their contract. Section 3 specifies which policies are applicable for a contractor based on the products or services being acquired in the contract.
2.0 Contracting Life Cycle
Every acquisition, and its resulting contract, follows a four phase contracting life cycle. The Contracting Officer’s Representative (COR) has significant supporting involvement in each phase.
U.S. General Services Administration 3
2.1 Contracting Life Cycle Graphic
Source: Graphic is from DAU University’s “FCR 100 Contracting Officer Level 1” 2017 online course.
2.2 Contracting Phase Activities for COR
The following list some primary activities performed by the COR during the four contracting phases. The Contracting Officer (CO) has the actual authority to act as an agent for the Government and can delegate responsibilities to the COR. The COR oversees technical aspects of the contracts and performs most of the administrative functions required to ensure acceptable service or product. The CO relies on the COR to be his or her “eyes and ears” to help manage the contract.
(1.) Pre-Award
● Conducting Market Research
● Defining Requirements
● Support determining the Acquisition
Strategy
(2.) Post-Award
● Supporting creation of the Management Plan
& contract kick off meeting
● Creating of a COR Checklist
● Maintaining a COR Contract File
● Liaison/Communicating Concerns and
Information
● Ongoing Market Research to stay current with market conditions, technology advances, and industry trends
(3.) Contract Administration
● Monitoring Performance/Providing technical direction
● Managing Contract Changes
● Inspecting and accepting supplies and/or services
● Reviewing invoices and processing payments
(4.) Closeout
● Supporting contract closeout procedures**
● Providing contract evaluation in CPARS
● Completing contract file
**NOTE: Final invoice & payment, deobligation of funds, etc..
U.S. General Services Administration 4
3.0 Non-Security & Non-Privacy IT Policies
The chart below identifies which policies apply to GSA employees and the contractors. To determine if a policy applies, first check if there is a green check mark in the column with the heading, “Who has primary responsibilities?”. If there is a checkmark for an employee or contractor, then identify if the policy must be followed based on the scope of the policy as detailed in the column with the heading, “When does it apply?”.
Policy
Who has primary responsibilities?
When does it apply?
Which contracting phase does it apply?
GSA Contractor
CIO IL-16-03 GSA Open Source Software (OSS) Policy
This Instructional Letter (IL) establishes GSA policies for OAuth 2.0 integration of GSA.gov accounts with third party services including but not limited to Websites, Software as a Service (SaaS), mobile applications, and Google Apps Scripts.
See 5.
Responsibilities
a. b. c. d. e. f.
When there is a development requirement for new or existing software, component or functionality
- Pre-Award
- Contract Administration
CIO 2101.1 GSA Enterprise Information Technology Management (ITM) Policy
This policy reinforces several existing IT management processes; integrates GSA IT in all implementation, procurement, workforce, and IT-related budget matters; and strengthens our partnerships across GSA.
See 3.
Applicability c.
See 4.
Responsibilities
a. (1), (2), (3)(a)(b)
b. (1),(2),(3),(4)
When engaging with business lines, reviewing business plans, and/or conducting reviews (acquisition, budget, or post-implementation)
- Pre-Award
- Contract Administration
- Closeout
CIO 2102.1 Information Technology (IT) Integration Policy
Establishes GSA's privacy policies and procedures, provides guidance and direction on implementing program requirements, defines privacy related contracting requirements, and assigns responsibilities to ensure compliance with the Privacy Act of 1974.
Scope and applicability
a. b. c.
When acquiring any:
1.) new internal GSA IT solution 2.) major enhancement to existing project that has criteria of either:
a.) over $150k b.) cloud acquisition c.) BPA d.) RFI & market research e.) or high-priority IT acquisitions
-Pre-Award
-Post-Award
-Contract
-Closeout https://insite.gsa.gov/portal/content/536641 https://insite.gsa.gov/portal/content/536641 https://insite.gsa.gov/portal/content/554353 https://insite.gsa.gov/portal/content/554353 https://insite.gsa.gov/portal/content/554353 https://insite.gsa.gov/portal/content/673470 https://insite.gsa.gov/portal/content/673470 https://insite.gsa.gov/portal/content/673470 https://insite.gsa.gov/portal/content/673470
U.S. General Services Administration 5
3.0 continued
GSA Contractor
CIO 2104.1A CIO CHGE 1 GSA
Information Technology IT General Rules of Behavior
This Order sets forth the General Services Administration’s (GSA’s) policy on IT General Rules of Behavior.
See 4.
When accessing GSA IT resources to conduct business on behalf of, or with, GSA or GSA supported Government organizations, and to all GSA IT resources which process or store GSA data, whether leased or owned.
- Contract Administration
CIO 2105.1C CHGE 1 GSA Section 508: Managing Information and Communications Technology (ICT) for Individuals with Disabilities
This Order provides direction and guidance for ensuring information and communications technology allow persons with disabilities to have access to information and data that is comparable to the access of individuals without disabilities.
Responsibilities
a. Heads of Services and Staff Offices
(HSSO)
(1), (2), (3) (4)(a)(b)(c)(d) (e)(f)(g)
When developing, procuring, maintaining, or using information and communications technology
- Pre-Award
CIO 2105.2 P GSA Section 508 Procedures Handbook
This Order issues and transmits Handbook (HB), GSA Section 508 Procedures. Section 508 prohibits Federal agencies from procuring, developing, maintaining, or using EIT that is not accessible to people with disabilities, subject to an undue burden defense. If it is properly determined by the agency that meeting the Section 508 standards would impose an undue burden, GSA must provide individuals with disabilities with information and data involved by an alternative means of access that allows the individual to use the information and data.
When developing, procuring, maintaining, or using electronic and information technology
- Pre-Award
- Contract Administration https://insite.gsa.gov/portal/content/520917 https://insite.gsa.gov/portal/content/520917 https://insite.gsa.gov/portal/content/520917 https://insite.gsa.gov/portal/content/669274 https://insite.gsa.gov/portal/content/669274 https://insite.gsa.gov/portal/content/669274 https://insite.gsa.gov/portal/content/669274 https://www.gsa.gov/directives-library/gsa-section-508-procedures-handbook-21052-cio-p https://www.gsa.gov/directives-library/gsa-section-508-procedures-handbook-21052-cio-p
U.S. General Services Administration 6
GSA Contractor
CIO 2108.1 Software License Management
GSA is consolidating software license management and establishing a software license management program. This Order establishes software license management roles, responsibilities, and procedures.
applicability
a. b. c. d.
See 4.
Responsibilities
a. (1)(2) (3) (4)(5)(6)(7) b.(1)(2) applicability
a. b. c. d.
See 4.
Responsibilities
a. (1)(2) (3) (4)(5)(6)(7) b.(1)(2)
When there is a requirement to acquire software
- Pre-Award
- Contract Administration
- Closeout
CIO 2110.4 GSA Enterprise Architecture Policy
This Order establishes agency-wide policy, principles, roles and responsibilities for the establishment and implementation of the General Services Administration (GSA) Enterprise Architecture (EA).
a. b. c.
See 5.
Roles and responsibilities
When building EA or when there is a requirement to purchase new software
- Pre-Award
- Contract Administration
CIO 2130.2 Enterprise IT Governance
This policy provides direction and guidance on GSA Enterprise IT Governance (EIG). EIG is a structured decision-making framework for identifying, selecting, prioritizing, and tracking all IT investments and initiatives for the GSA enterprise.
EIG integrates new business-driven approaches to investment evaluation and selection with existing agency activities and programs (e.g., Spend Tracker and legacy PBS IT governance).
When EIG approval is needed
- Pre-Award https://insite.gsa.gov/portal/content/699570 https://insite.gsa.gov/portal/content/699570 https://insite.gsa.gov/portal/content/550585 https://insite.gsa.gov/portal/content/550585 https://insite.gsa.gov/portal/content/669238 https://insite.gsa.gov/portal/content/669238
U.S. General Services Administration 7
GSA Contractor
CIO 2135.2B GSA Information Technology (IT) Capital Planning and Investment Control
This Order establishes agency-wide policies, roles and responsibilities for GSA’s IT Capital Planning and Investment Control process (CPIC). CPIC is an integrated management process for the continuous selection, control, and evaluation of IT investments over their life cycles and is focused on achieving desired outcomes in support of GSA’s missions, goals, and objectives.
See 8.
CPIC
responsibilities a.b.c.d.
e.(1)(2)(3)(4) (5)(6)(7) f.Program/ Project Manager 1)(2)(3)(4) (5)(6)(7)(8)
When evaluating IT investments over their life cycles
- Pre-Award
- Post-Award
- Contract Administration
- Closeout
CIO 2140.4 Information Technology (IT) Solutions Life Cycle (SLC) Policy
This Order sets forth policy for planning and managing IT solutions developed for or operated by GSA. This policy has been developed to ensure the Solutions Life Cycle (SLC) discipline used is consistent with SLC guiding principles, acquisition planning requirements, and capital planning and investment control requirements. The term SLC replaces the term Software Development Life Cycle (SDLC) which was used in the past.
and scope
This policy applies to acquisition development, maintenance, enhancement, operation, and disposal of IT systems and solutions of any size, complexity, or significance that are part of the agency’s’ IT portfolio as defined in CIO
2135.2B GSA
Information Technology (IT) Capital Planning and Investment Control
- Pre-Award
- Post-Award
- Contract Administration
- Closeout
CIO 2142.1 P GSA Information and Data Quality Handbook
This order issues and transmits Handbook (HB), General Services Administration (GSA) Information and Data Quality Guidelines.
See 2.
When acquisition will result in a new asset or data update to an existing asset https://insite.gsa.gov/portal/content/519386 https://insite.gsa.gov/portal/content/519386 https://insite.gsa.gov/portal/content/519386 https://insite.gsa.gov/portal/content/526137 https://insite.gsa.gov/portal/content/526137 https://insite.gsa.gov/portal/content/526137 https://insite.gsa.gov/portal/content/523018 https://insite.gsa.gov/portal/content/523018
U.S. General Services Administration 8
GSA Contractor
CIO 2141.2 General Services Administration (GSA) Web Domain Names
This GSA Order sets forth GSA’s internal guidance to assist organizations desiring to obtain unique website identifications.
This Order provides domain name guidance for GSA staff organizations, including service, geographical, and operational areas.
Coverage
Applicable if an acquisition involves the need for a new domain name
- Pre-Award
CIO 2160.1F CHGE 2 GSA
information Technology (IT) Standards Profile
To ensure acquisition and use of standard information technologies and proper maintenance of the IT Standards Profile. The IT Standards Profile is the official GSA repository of all approved software applications. It is managed by GSA IT and can be found at ea.gsa.gov.
a. b. c. d. e.
See 5.
Responsibilities
a. b. c. d. e. f. g.
See 6.
Compliance a.
b. (1)(2)(3)(4) c.
d. (1)(2)
When acquiring or using information technologies in the conduct of GSA business
- Pre-Award
CIO 2160.2B CHGE 1 GSA
Electronic Messaging and Related Services
This Order updates GSA's directive on electronic messaging due to the move from a server-based messaging system to cloud-based e-mail and collaboration tools and additional federal requirements for managing electronic mail records. This directive addresses security, appropriate use, and recordkeeping of the GSA Enterprise Messaging Services (GEMS) in a cloud-based environment.
All authorized users who are granted access to GEMS and to all communications sent or received via
GEMS
- Pre-Award https://insite.gsa.gov/portal/content/593174 https://insite.gsa.gov/portal/content/593174 https://insite.gsa.gov/portal/content/593174 https://insite.gsa.gov/portal/content/546745 https://insite.gsa.gov/portal/content/546745 https://insite.gsa.gov/portal/content/546745 https://insite.gsa.gov/portal/content/520818 https://insite.gsa.gov/portal/content/520818 https://insite.gsa.gov/portal/content/520818
U.S. General Services Administration 9
GSA Contractor
CIO 2160.4A Provisioning of Information Technology (IT) Devices
This Order provides direction and guidance on the deployment of computer workstations, mobile devices, and printers for agency and designated contractor personnel.
a.
See 5.
Roles and responsibilities a.(1)(2) b.(1)(2) a.
When writing SOW.
Compliance with policy should be addressed in Statements of Work (SOWs) for contractors.
- Pre-Award
- Contract Administration
- Closeout
CIO 2164.1 Internal Clearance Process for GSA Data Assets
This Order provides the internal clearance process that the General Services Administration (GSA) must follow before releasing GSA data assets. GSA IT’s Office of Enterprise Information & Data Management (IDM) established this process in collaboration with the Office of General Counsel (OGC), the Freedom of Information Act (FOIA) Division, the Privacy Officer in GSA IT, and the Executive Secretariat Division.
The established clearance process ensures that the privacy, security, and confidentiality of GSA’s critical data assets are protected from unauthorized access, release, and dissemination.
Before releasing GSA data assets
CIO P 2165.2 GSA
Telecommunications Policy
This policy establishes the policy for General Services Administration (GSA) authorized users for utilization of GSA-provided telecommunications equipment, systems and services (hereafter, GSA telecommunications).
When creating any agreement (e.g.
MOU) that results in that process or handle of any GSA-owned information, data, or IT system equipment
- Pre-Award https://insite.gsa.gov/portal/content/513476 https://insite.gsa.gov/portal/content/513476 https://insite.gsa.gov/portal/content/513476 https://insite.gsa.gov/portal/content/699006 https://insite.gsa.gov/portal/content/699006 https://insite.gsa.gov/portal/content/634938 https://insite.gsa.gov/portal/content/634938
U.S. General Services Administration 10
GSA Contractor
CIO 7000.3 Information Technology Standards for Internal GSA Workplaces
This Order transmits the information technology (IT) standards for all new workplace projects, including new construction or alterations to existing space, for all GSA offices.
applicability applicability
When there is a requirement to purchase IT equipment for an internal GSA workplace
- Pre-Award
CIO 9297.1 GSA Data Release Policy
This Order provides GSA’s policy on releasing information relating to GSA employees, contractors, and others on whom GSA maintains information described in this document.
When releasing information to the public as through FOIA or other official requests and who collect, maintain, use, manage, or come in contact with personally identifiable or sensitive information owned by GSA
- Contract
- Contract Closeout
4.0 Internal GSA Resources
● GSA Acquisition Policy https://insite.gsa.gov/portal/content/510990
● GSA IT Policy Management https://insite.gsa.gov/portal/content/626370
● GSA IT Vendor Management https://insite.gsa.gov/portal/category/535534
5.0 External GSA Resources
● GSA Directives Library https://www.gsa.gov/directives-library https://insite.gsa.gov/portal/content/512009 https://insite.gsa.gov/portal/content/512009 https://insite.gsa.gov/portal/content/512009 https://insite.gsa.gov/portal/content/674050 https://insite.gsa.gov/portal/content/674050 https://insite.gsa.gov/portal/content/510990 https://insite.gsa.gov/portal/content/626370 https://insite.gsa.gov/portal/category/535534 https://www.gsa.gov/directives-library
File details come from the government source that posted it.