47QMCA23Q0019_Low_Impact_SaaS_Solution_Review_2023-06-01.xlsx
XLSX spreadsheet 31 KB Posted
- Attached to
- Vehicle Maintenance & Repair Authorization System Federal contract opportunity
- Solicitation number
- 47QMCA23Q0019
- Issued by
- GSA Federal Acquisition Service
About this file
This document outlines requirements for a low impact software as a service (SaaS) solution review. It requests completion of a SaaS solution profile template providing details of the service such as name, data description and sensitivity, authentication and authorization capabilities, and connection types. It also requires documentation of how system and security parameters deferred to customers are implemented according to GSA security policies. Vendors must submit the results of web application and operating system vulnerability scans on an annual basis. Acceptable flaw remediation processes must be demonstrated along with provision of a SOC 2/SSAE 18 audit report or specified vendor certifications. The related federal contract opportunity is for a vehicle maintenance and repair authorization system to enable GSA Fleet to manage all maintenance and repair orders processed through maintenance control centers and area maintenance centers.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_47QMCA23Q0019_Amd_0001.pdf | ||
| 47QMCA23Q0019_VPAT_508_Compliance_2023-06-01.doc | DOC document | |
| 47QMCA23Q0019_Price_Sheet_2023-06-01.xlsx | XLSX spreadsheet | |
| 47QMCA23Q0019_SOW_2023-06-01.docx | DOCX document | |
| Sol_47QMCA23Q0019.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
LiSaaS Review Checklist
| [Low Impact SaaS System Name] |
| The GSA requestor accepts the following LI-SaaS conditions: |
•The system is implemented for a limited duration (good through ATO period).
•The system uses data already in the public domain, or data that is non-sensitive and is considered FIPS 199 low impact.
•The system will only cause limited harm to GSA regardless of the consequence of an attack or compromise.
•The dollar cost for such deployments does not exceed $100,000 annually.
•Disruption in service, or the inability to access the service, will not have an impact to operations or business process.
| Task | Requested | Complete | Notes |
| (1) Completion of the SaaS Solution Integration Profile Template (https://insite.gsa.gov/cdnstatic/insite/SaaS_Solution_Profile_Template_08-11-2021.docx). This profile provides a summary of the service function and purpose provided by the SaaS solution. It includes the who, what, when, where, and how of the solution, including the following information and capabilities, as applicable. Instructions are contained in the template. |
a. SaaS Solution Name
b. Data Description and Sensitivity
c. Authentication and Authorization Capability
d. Multi-Factor Authentication Capability
e. Role-based Access Control Capability
f. Audit Logging Capability
g. Encryption in Transit Capability
h. Encryption in Storage Capability
i. Connection Type(s)
| (2) Document how system and security parameters deferred to customers are implemented. Do not use the vendor-supplied defaults for system passwords and other security parameters. GSA security policies and best practices should be used to the greatest extent possible. |
| (3) Submit latest web application scan results (e.g., NetSparker, Acunetix, Burp Suite Pro, etc.) annually. The OCISO can assist with web application scans if vendor(s) do not have an in house web application scanning capability. |
| (4) Submit latest operating system (OS) vulnerability scan results (e.g., Tenable Nessus, Qualys, nCircle, McAfee Vulnerability Manager, etc.). Reference NIST SP 800-53 control RA-5 - Vulnerability Monitoring and Scanning. |
| a. Vendors that are Payment Card Industry Data Security Standard (PCI DSS) compliant or have the McAfee Secure Seal or TrustGuard Seal may provide the results of their latest PCI DSS Compliant, McAfee Secure Seal or TrustGuard quarterly scan. |
| b. Vendors that do not meet the PCI DSS, McAfee, or TrustGuard standards listed, must provide their most recent OS vulnerability scan results. |
| (5) Verify that the vendor has an acceptable flaw remediation process. Vendors must be able to identify and remediate information system flaws in a timely manner (i.e., the process must describe how often scans are completed and how vulnerabilities are remediated). Reference NIST 800-53 control SI-2 – Flaw Remediation. |
| (6) Vendor shall either provide the results of their Service Organization Control (SOC) 2/Statements on Standards for Attestation Engagements (SSAE) 18 audit report and/or have one of the following vendor certifications SysTrust, WebTrust (American Institute of Certified Public Accountants (AICPA)-sponsored), ISO/IEC 27001, or PCI DSS Compliance. The SSAE/SOC 2 is not a form of security certification but it does provide independent third party attestation of the provider’s general operating environment and supporting processes. Vendors may also provide evidence of PCI security assessments, self-testing, and records from other external audits and assessors to supplement the SSAE/SOC 2 audit report or vendor certifications. Vendors are strongly encouraged to present as much information as possible to allow an adequate understanding of the application’s security posture and a determination of risk. Although the minimum requirement is for the SSAE/SOC 2 audit report or one of the vendor certifications; the GSA AO and the CISO will take a holistic view of the application based on all of the documentation presented to determine the overall risk of the application as well as any residual risks that may need to be accepted when considering the application for use. If the documentation presented does not provide an adequate understanding of the systems security posture and/or is deemed insufficient to make a risk determination; additional information will be required. |
&G &11Low Impact Software as a Service (SaaS) Solutions Review Checklist
&P image1.jpeg
File details come from the government source that posted it. Updated .