MAS - Synergetics Incorporated - 47QTCA21D005F
PDF 938 KB
- Attached to
- Federal Supply Schedule 47QTCA21D005F Federal contract IDV
- Contract number
- 47QTCA21D005F
- Issued by
- GSA Federal Acquisition Service
About this file
This document provides pricing details for a federal supply schedule contract held by Synergetics Incorporated. The contract was awarded on February 22, 2021 through the GSA Federal Acquisition Service and has a period of performance through February 21, 2026.
Under contract number 47QTCA21D005F, Synergetics offers information technology professional services and software licenses. Pricing is provided for 14 labor categories ranging from $74.42 to $158.62 per hour for the first year. Software products offered include an IMD or OpenFLISTM platform with add-on applications in large, medium, and small configurations. Mobile applications, APIs, and software maintenance services are also available. Quantity discounts are provided for multi-year software licenses.
Synergetics Incorporated Pricelist and/or Vendor Terms and Conditions for 47QTCA21D005F, a Federal Supply Schedule awarded to Synergetics Incorporated, under Multiple Award Schedule (MAS)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
GENERAL SERVICES ADMINISTRATION
Federal Acquisition Service
Authorized Federal Supply Schedule FSS Price List
Online access to contract ordering information, terms and conditions, pricing, and the option to create an electronic delivery order are available through GSA Advantage!®. The website for GSA Advantage!® is:
https://www.GSAAdvantage.gov
Multiple Award Schedule (MAS)
FSC Group: Information Technology: IT Services and Software
Contract Number: 47QTCA21D005F
Contract Period: February 22, 2021 through February 21, 2031
Synergetics Incorporated 1520 S. College Ave.
Fort Collins, Colorado 80524 Phone: (970)498-9723 Fax: (970)498-9775
E-mail: gsa-mas@synergetics.com
Website: https://www.synergetics.com
Contract Administration: Rajiv Mehta, rpm@synergetics.com
Business Size: Small, SBA Certified Small Disadvantaged Business
Price list current as of Modification PO-0025 effective December 15, 2025
For more information on ordering from Federal Supply Schedules go to the GSA Schedules page at GSA.gov.
mailto:rpm@synergetics.com
CUSTOMER INFORMATION
1a. Table of awarded Special Item Numbers (SINs):
SIN # SIN Title 54151S Information Technology Professional Services 511210 Software Licenses OLM Order Level Materials
1b. Identification of the lowest priced service for each special item number awarded in the contract: See Services Plus Price Proposal Template
1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided. See Services Plus Price Proposal Template
2. Maximum order for each SIN: SIN 54151S and 511210 $500,000; OLM $250,000
3. Minimum order: $100.00
4. Geographic coverage (delivery area): Domestic Only
5. Point(s) of production: US
6. Discount from list prices or statement of net price: Net prices are included on this price list.
7. Quantity discounts:
SIN 511210 Software: additional 20% for 2nd platforms (total 25%); additional 25% each for 3rd or more platforms (total 30% each) is offered. Quantity discounts for Software are available on annual subscriptions only.
SIN 54151S Services: additional ½% for single orders over $500,00
8. Prompt payment terms: 1% 10 days, Net 30 days Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions.
9. Foreign items: Not Applicable.
10a. Time of delivery: TBD on per task order basis.
10b. Expedited delivery: Items available for expedited delivery are noted in this price list.
10c. Overnight and 2-day delivery: Contact Contractor
10d. Urgent requirements: Contact Contractor
11. F.O.B. point(s): Destination
12a. Ordering address(es):
Synergetics Incorporated 1520 S. College Ave.
Fort Collins, Colorado 80524 Phone: (970) 498-9723
12b. Ordering procedures: For supplies and services, the ordering procedures, information on Blanket Purchase Agreements (BPAs) are found in Federal Acquisition Regulation
(FAR)
8.405-3.
13. Payment address:
Synergetics Incorporated 1520 S. College Ave.
Fort Collins, Colorado 80524 Phone: (970) 498-9723
14. Warranty provision: Standard Commercial Warranty.
15. Export packing charges: Not Applicable.
16. Terms and conditions of rental, maintenance, and repair: Not Applicable.
17. Terms and conditions of installation: Not Applicable.
18. Terms and conditions of repair parts: Not Applicable.
18a. Terms and conditions for any other services: Not Applicable.
19. List of service and distribution points: Not Applicable.
20. List of participating dealers: Not Applicable.
21. Preventative maintenance: Not Applicable.
22a. Special attributes such as environmental attributes: Not Applicable.
22b. Section 508 compliance: Not Applicable.
23. Unique Entity Identifier (UEI) number: LF2NR9LR1EM4
24. Notification regarding registration in the System for Award Management (SAM) database: Registered
TERMS AND CONDITIONS APPLICABLE TO INFORMATION TECHNOLOGY (IT)
PROFESSIONAL SERVICES (SPECIAL ITEM NUMBER 132-51)
1. SCOPE
a. The prices, terms and conditions stated under Special Item Number 132-51 Information
Technology Professional Services apply exclusively to IT Services within the scope of this Information Technology Schedule.
b. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.
2. PERFORMANCE INCENTIVES i-fss-60 Performance Incentives (April 2000)
a. Performance incentives may be agreed upon between the Contractor and the ordering activity on individual fixed price orders or Blanket Purchase Agreements under this contract.
b. The ordering activity must establish a maximum performance incentive price for these services and/or total solutions on individual orders or Blanket Purchase Agreements.
c. Incentives should be designed to relate results achieved by the contractor to specified targets.
To the maximum extent practicable, ordering activities shall consider establishing incentives where performance is critical to the ordering activity’s mission and incentives are likely to motivate the contractor. Incentives shall be based on objectively measurable tasks.
3. ORDER
a. Agencies may use written orders, EDI orders, blanket purchase agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
4. PERFORMANCE OF SERVICES
a. The Contractor shall commence performance of services on the date agreed to by the
Contractor and the ordering activity.
b. The Contractor agrees to render services only during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.
d. Any Contractor travel required in the performance of IT Services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts.
5. STOP-WORK ORDER (FAR 52.242-15) (AUG 1989)
a. The Contracting Officer may, at any time, by written order to the Contractor, require the
Contractor to stop all, or any part, of the work called for by this contract for a period of 90 days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 days after a stop-work is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the Contracting Officer shall either-
1. Cancel the stop-work order; or
2. Terminate the work covered by the order as provided in the Default, or the Termination for Convenience of the Government, clause of this contract.
b. If a stop-work order issued under this clause is canceled or the period of the order or any extension thereof expires, the Contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule or contract price, or both, and the contract shall be modified, in writing, accordingly, if-
1. The stop-work order results in an increase in the time required for, or in the Contractor's cost properly allocable to, the performance of any part of this contract; and
2. The Contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage; provided, that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and act upon the claim submitted at any time before final payment under this contract.
c. If a stop-work order is not canceled and the work covered by the order is terminated for the convenience of the Government, the Contracting Officer shall allow reasonable costs resulting from the stop-work order in arriving at the termination settlement.
d. If a stop-work order is not canceled and the work covered by the order is terminated for default, the Contracting Officer shall allow, by equitable adjustment or otherwise, reasonable costs resulting from the stop-work order.
6. INSPECTION OF SERVICES
In accordance with FAR 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (MAR 2009) (DEVIATION I - FEB 2007) for Firm-Fixed Price orders and FAR 52.212-4
CONTRACT TERMS AND CONDITIONS - COMMERCIAL ITEMS (MAR 2009)
(ALTERNATE I - OCT 2008) (DEVIATION I – FEB 2007) applies to Time-and-Materials and Labor-Hour Contracts orders placed under this contract.
7. RESPONSIBILITIES OF THE CONTRACTOR
The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR 52.227-14 (Dec 2007) Rights in Data – General, may apply.
8. RESPONSIBILITIES OF THE ORDERING ACTIVITY
Subject to security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite IT Services.
9. INDEPENDENT CONTRACTOR
All IT Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.
10. ORGANIZATIONAL CONFLICTS OF INTEREST
a. Definitions.
“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.
“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the
Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.
An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.
b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR
9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at
FAR 9.508.
11. INVOICES
The Contractor, upon completion of the work ordered, shall submit invoices for IT services.
Progress payments may be authorized by the ordering activity on individual orders if appropriate.
Progress payments shall be based upon completion of defined milestones or interim products.
Invoices shall be submitted monthly for recurring services performed during the preceding month.
12. PAYMENTS
For firm-fixed price orders the ordering activity shall pay the Contractor, upon submission of proper invoices or vouchers, the prices stipulated in this contract for service rendered and accepted. Progress payments shall be made only when authorized by the order. For time-and-materials orders, the Payments under Time-and-Materials and Labor-Hour Contracts at FAR 52.212-4 (MAR 2009) (ALTERNATE I – OCT 2008) (DEVIATION I – FEB 2007) applies to time-and-materials orders placed under this contract.
For labor-hour orders, the Payment under Time-and-Materials and Labor-Hour Contracts at FAR 52.212-4 (MAR 2009) (ALTERNATE I – OCT 2008) (DEVIATION I – FEB 2007) applies to labor-hour orders placed under this contract. 52.216-31(Feb 2007) Time- and-Materials/Labor- Hour Proposal Requirements—Commercial Item Acquisition As prescribed in 16.601(e)(3), insert the following provision:
a. The Government contemplates award of a Time-and-Materials or Labor-Hour type of contract resulting from this solicitation.
b. The offeror must specify fixed hourly rates in its offer that include wages, overhead, general and administrative expenses, and profit. The offeror must specify whether the fixed hourly rate for each labor category applies to labor performed by—
1. The offeror;
2. Subcontractors; and/or
3. Divisions, subsidiaries, or affiliates of the offeror under a common control.
13. RESUMES
Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.
14. INCIDENTAL SUPPORT COSTS
Incidental support costs are available outside the scope of this contract. The costs will be negotiated separately with the ordering activity in accordance with the guidelines set forth in the
FAR.
15. APPROVAL OF SUBCONTRACTS
The ordering activity may require that the Contractor receive, from the ordering activity's Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.
16. DESCRIPTION OF IT SERVICES – See Services Plus PPT
Additional Services.
• This license agreement can be amended through collaboration between Synergetics and the
Government to add additional products or services at a later date, subsequent to the initial contract.
IMD/ OpenFLISÒ
License Agreement
This license is for:
IMD
OpenFLISÒ
Summary.
• Synergetics developed the IMD/ OpenFLISÒsoftware at private expense and licenses it as a
Service (SaaS) Platform. Synergetics will license the OpenFLISÒ Platform and the hosting of these individual products (the “Products”) in the OpenFLISÒ Platform.
• Synergetics will provide the LICENSEE:
1. A subscription-based license to IMD/ OpenFLISÒ Platform (the “Platform”)
2. Connection and ability to produce products with IMD/ host on OpenFLISÒ. Products categorized as:
a. IMD/ OpenFLISÒ Primary – Large or IMD/ OpenFLISÒ Add-On - Large:
i. FED LOG, UDR, Data Connect (TDP), FLIS Search, PUB LOG, and
FMS
b. IMD/ OpenFLISÒAdd-On – Medium
c. IMD/ OpenFLISÒ Add-On – Small
3. Service Level Agreement (SLA) to adhere to the Key Performance Parameters (KPPs) and other performance requirement metrics outlined as set forth in this Supplement.
OpenFLISÒ Platform Description.
• The Platform is a COTS SaaS environment, deployed either within the LICENSEE enclave or hosted in the Cloud by Synergetics. Synergetics retains all rights to:
o Platform Single Sign-on (SSO) Authentication (*only OpenFLISÒ) o Platform Dashboard o Platform Source Data Collation o Platform Database Management o Platform Selection o Platform Knowledge Management Systems and Content o Platform Analytics Systems and Software o Platform Cybersecurity Systems o Platform Software o Platform Maintenance and Documentation o Platform Development o Platform Features o Platform/ Product Creation Software o Product Testing and Reporting Software o Product Dissemination Management Process o Product Tenant Support Processes
• As an exception, Synergetics acknowledges that LICENSEE retains the rights for configuration items developed as part of this contract. These include the following:
o Product Production Scripts that end in *.BAT o Product ETL Scripts that end in *.SQL.
o Product Definition Files that end in *.DEF, *.YML o Product Analytics Data o Product Testing and Reporting Data o Product Maintenance and Documentation
Ownership of OpenFLISÒ Software and Custom Module Configurations.
• IMD Software/ OpenFLISÒ Platform – Features, and Software. Synergetics owns all title, copyright and IP Rights in IMD/ the OpenFLISÒPlatform and all Features. “IP Rights” means all forms of intellectual property rights and protections throughout the world, including, but not limited to: any (a) patents, (b) copyrights, (c) trademarks and service marks, (d) trade secrets, and
(e) any other proprietary rights and protections, whether currently existing or hereafter developed or acquired.
• LICENSEE’s Unlimited Rights to Custom Module Configuration. Any configuration assets developed under professional services CLINs, including definition files, Extract Transform Load (ETL) scripts, and custom integration (i.e., connection to AMPS) (“Product Configuration”) shall be the sole property of LICENSEE, and Synergetics hereby assigns to LICENSEE all rights, title, and interest in Product Configuration.
• Rights in Data/ Federal Acquisition. Platform, Features, and Software are "commercial items," as defined at Federal Acquisition Regulation (FAR) 48 C.F.R. 2.101, consisting of "commercial computer software" and "commercial computer software documentation" as such terms are used in FAR 12.212. Consistent with FAR 12.211 (Technical Data), FAR 12.212 (Computer Software), and Defense Federal Acquisition Regulation Supplement (DFAR) 227.7202-1 through 227.7202- 4, Government end users will acquire only those rights to the Platform, Features, Software, and any related documentation set forth in this Supplement. Any provision that is inconsistent with Federal procurement regulations are not enforceable against the U.S. Government.
License Terms.
• LICENSEE agrees to pay Synergetics the License Fees (“Fees”) described on the Payment
Schedule, including (a) an annual license fee (the “Annual License Fee”) for the right to use IMD in the production of all selected products/ enable the OpenFLISÒ Platform, payable at the beginning of the license term.
• LICENSEE acknowledges and understands that if the License Fees are not paid for any reason, that LICENSEE shall no longer have access to IMD/ the OpenFLISÒ Platform.
Payment Terms.
• License fees are due upon contract award.
Warranty.
• Except for pre-negotiated contractual obligations, Synergetics makes no express or implied warranties with respect to the IMD/ OpenFLISÒ software, including without limitation, warranties of merchantability and/ or fitness for a particular purpose. Except as expressly indicated in this agreement, Synergetics does not warrant that the operation of the service will meet LICENSEE’s specific requirements.
SERVICE LEVEL AGREEMENT (SLA) SUPPLEMENT
Synergetics shall provide a Service Level Agreement (SLA) for the Open OpenFLISÒ software and each product. Synergetics will not provide any source code or software documentation to the OpenFLISÒ software.
• “Basic” tiered service is included in the subscription service fees and provided at no additional charge.
• “Enhanced” and “Premium” tiered services are available upon the payment of additional fees as follows:
Table 1 shows the Basic SLA included with this license agreement and will meet and exceed all the requirements of the RFQ. Two additional columns are provided as options in the event the Government chooses to increase the level of service.
In addition to the standard SLAs below, Synergetics encourages our tenants to evaluate needs and, if required, collaborate with the Synergetics team to customize service levels to meet mission needs.
TABLE 1: SYNERGETICS SERVICE LEVELS
Type Basic (Per RFQ)
INCLUDED
Enhanced (Optional) +$300,000/year/ product
Premium (Optional) +$900,000/year/ product PaaS Service Levels Availability (Uptime) 98% 99.9% 99.99% Disaster Recovery 72 hours 36 hours 24 hours Product Service Levels Use Volume 25,000 concurrent users 50,000 concurrent users 75,000 concurrent users Transaction Volume 3,000,000 database updates/ hour 5,000,000 database updates/ hour 7,500,000 database updates/ hour For File Sizes <100mB User Interface Refresh Rate
<3 seconds <2 seconds <2 seconds
File(s) size < 100mB screen to screen transfer
<8 seconds <4 seconds <2 seconds
File(s) size < 100mB Search returns
<10 seconds <5 seconds <5 seconds
File(s) size < 100mB Import
<5 minutes <3minutes <1minutes
File(s) size < 100mB Screen Data
<5 minutes <3 minutes <2 minutes
File(s) size < 100mB Send to Routing (System to System)
<10 seconds <5 seconds <2 seconds
File(s) size < 100mB Save
<10 seconds <3 seconds <3 seconds
File(s) size < 100mB Back
<10 seconds <5 seconds <3 seconds
File(s) size < 100mB Export
<30 Seconds <15 Seconds <10 Seconds
File(s) size < 100mB Upload attachments
<10 seconds <5 seconds <3 seconds
Mass Load/ Query File Transaction processing over 100mb <300 <60 seconds <30 seconds <20 seconds 301-1000 <3 minutes <2 minutes <1 minutes 1001-5000 <60 minutes <30 minutes <15 minutes >5000 <24 hours <12 hours <8 hours Problem Resolution for All Services
Support Tiers Tier 3 (6-6) Tiers 2, 3 (24x7) Tiers 1, 2, 3 (24x7) Critical Response - 1 hour
Resolution - 24 hours Response - 30 minutes Resolution - 12 hours
Response - 30 minutes Resolution - 8 hours
High Response -2 business days Resolution - 5 business days
Response -1 business day Resolution - 3 business days
Response -8 hours Resolution - 2 business days
Medium Response -5 business days Resolution - 15 business days
Response -3 business days Resolution - 10 business days
Response -1 business day Resolution - 7 business days
Low Response -15 business days Resolution - 45 business days
Response - 7 business days Resolution - 30 business days
Response -5 business days Resolution - 15 business days
Product List Applicability (not limited to)
UDR
Data Connect (TDP) FLIS Search FED LOG (including all variations)
PUB LOG
MEDALS
SLES
Note: All numbers in Table 1 are subject to Tenant imposed boundaries.
Tenant Responsibilities
The tenant agrees to adhere to the NIST 800-63A - Enrollment and Identity Proofing Standards, which establishes rigorous guidelines for the enrollment and verification of users' identities. The tenant assumes responsibility for implementing identity proofing processes that verify the real-world existence of individuals and confirm that they are who they claim to be. Specifically, the tenant will:
1. Establish and follow a strong Identity Assurance Level (IAL) that is appropriate for the services accessed by the tenant's users within OpenFLISÒ.
2. Execute a comprehensive vetting process that includes collecting, validating, and verifying identity evidence and biographic information as per the guidelines set by NIST 800-63A.
3. Implement effective binding processes between the applicants and their authenticators, ensuring that the proofing process is resistant to fraudulent attempts and unauthorized account creation.
4. Maintain records of the identity proofing transactions, including consent obtained from individuals for the collection of their Personal Identifiable Information (PII) as part of the proofing process.
5. Ensure that all personnel involved in the identity proofing process are adequately trained and capable of executing their duties in compliance with the identity proofing requirements.
Control Tenant Responsibility Description AC-2(a) Tenants will identify authorized non-privileged user types and access methods for
OpenFLISÒ. Account management, including account approval and user termination, is the tenant’s responsibility.
AC-2(b) Tenants are responsible for assigning account managers to manage end-user account lifecycles for their agency.
AC-2(c) Tenants will own the account management process, including user account approval and termination for non-privileged user accounts in OpenFLISÒ.
AC-2(d) Tenants will specify authorized non-privileged users and outline the access conditions, modules, applications, and user termination processes.
AC-2(f) Tenant-designated account managers define roles and enable, modify, disable, and remove user accounts as per the tenant’s policies.
AC-2(h) Tenants must inform Synergetics about changes in account manager accounts, user terminations/transfers, and privilege changes.
AC-2(j) Tenants are responsible for reviewing non-privileged user accounts at intervals they decide upon.
AC-2(3)(d) Tenants submit requests to have disabled accounts re-enabled and are responsible for the process.
AC-2(4) Tenants own the process of managing, approving, and terminating non-privileged user accounts in OpenFLISÒ.
AC-4(21) Tenants define data types, categorizations, and assist with data mapping, as well as defining application modules for user access.
AC-6 Tenants will designate Tenant Account Managers responsible for granting access to OpenFLISÒ products and modules.
AC-6(7)(a) Tenants are responsible for performing account reviews to support organizational processes and account reviews.
AC-6(7)(b) Tenants will notify Synergetics of changes to account manager accounts, user terminations/transfers, or privilege changes.
AC-17(a) Tenants are responsible for establishing rules and ensuring documentation and training on these rules are available.
AC-17(b) Tenants establish parameters for non-privileged user access to the system.
AC-19(a) Tenants are responsible for determining device and browser restrictions for
OpenFLISÒ access.
AC-19(5) Tenants will determine, configure, and control device encryption mechanisms required for OpenFLISÒ access.
AC-20(a) Tenants are responsible for establishing terms and conditions for system-to-system interconnections with OpenFLISÒ.
AC-20(1)(a) Tenants are responsible for establishing terms and conditions for system-to-system interconnections with OpenFLISÒ.
AC-20(1)(b) Tenants are responsible for establishing terms and conditions, connection types, and verifying controls for system-to-system interconnections.
AC-21(a) Tenants are responsible for determining discretion in sharing controlled information.
AC-22(a) Tenants designate authorized personnel to post publicly accessible information on deployed resources.
AC-22(b) Tenants are responsible for training personnel to prevent disclosure of nonpublic information.
AC-22(c) Tenants review content of controlled information prior to public posting.
AC-22(d) Tenants periodically review publicly available content for nonpublic information.
AT-2(a) Tenants provide security awareness training, including PII training, to all users prior to system access.
AT-2(2) Tenants ensure security awareness and training include insider threat training.
AT-4(a) Tenants are responsible for documenting and monitoring training for all system users.
AT-4(b) Tenants retain training records for no less than 5 years from completion.
CA-2(f) Tenants are responsible for delivering security assessment results to the required roles.
CM-2(7)(a) Tenants develop policies for accessing OpenFLISÒ in high-risk situations.
CM-2(7)(b) Tenants develop policies for devices returning from high-risk situations.
IA-4(4) Tenants decide which identifiers to track, which Synergetics will implement.
IA-5(a) Tenants manage authenticators and verify identities during initial distribution.
IA-5(b) Tenants establish initial content for authenticators.
IA-5(c) Tenants ensure authenticators have sufficient strength for intended use.
IA-5(d) Tenants implement procedures for authenticator distribution and revocation.
IA-5(e) Tenants are responsible for changing default authenticator content before deployment.
IA-5(f) Tenants must refresh authenticators regularly, adhering to specific timelines for each type of authenticator.
IA-5(g) Tenants are tasked with protecting authenticator content from unauthorized disclosure and modification.
IA-5(h) Tenants implement security safeguards to protect authenticators, such as password masking.
IA-5(i) This control is not applicable to the tenant.
IA-5(2)(a) While OpenFLISÒ enforces CAC/PIV authentication, tenants are responsible for issuing the CAC/PIV cards.
IA-5(2)(b) OpenFLISÒ configures CAC/PIV authentication and tenants inherit the certificate validation from the issuing authority.
IA-8 Tenants define the access parameters and policies for non-organizational users in coordination with the ISM and System Owner.
IA-8(1) Tenants provide users with access tokens and supply OpenFLISÒ with root certificates for chain of trust validation.
IR-6(a) Tenants must report security incidents to appropriate external organizations within required timelines.
IR-6(b) Tenants report security incidents to their organizational personnel as mandated by agency policy.
IR-7 Tenant users report incidents to appropriate internal personnel using standard organizational processes.
IR-7(1) Tenant users report incidents to appropriate internal personnel using standard organizational processes.
MP-3(a) Tenants collaborate with the OpenFLISÒ ISM to define media marking procedures within the platform.
MP-3(b) Tenants work with the OpenFLISÒ ISM to establish exceptions to standard media marking procedures.
PL-4(b) Tenants must establish rules of behavior and acceptable use policies for their users, to be incorporated into OpenFLISÒ guidelines.
PL-4(c) Tenant account managers are tasked with annual reviews of OpenFLISÒ rules of behavior.
PL-4(d) Tenant account managers are tasked with annual reviews of OpenFLISÒ rules of behavior.
PS-2(a) Tenant inputs and contract requirements can influence the risk designations within
OpenFLISÒ, subject to change.
PS-2(b) Tenants are accountable for screening individuals before granting access and may set additional requirements for Synergetics employees.
PS-3(b) Tenant contracts may specify roles that necessitate periodic reinvestigation.
PS-3(3)(a) Tenants dictate additional screening criteria in their contracts with OpenFLISÒ, as per information type requirements.
PS-3(3)(b) Tenants dictate additional screening criteria in their contracts with OpenFLISÒ, as per information type requirements.
SA-9(a) Tenants are responsible for maintaining FedRAMP authorizations when connecting OpenFLISÒ to external data sources.
SA-9(b) Tenants oversee documenting and overseeing user roles and responsibilities within OpenFLISÒ.
SA-9(c) Tenants monitor external service providers using their defined methods and techniques.
SC-2 Tenants specify data types for databases and regulate access to products and modules, including QA/Test web interfaces.
SC-7(3) Tenants design connection requirements to link with OpenFLISÒ.
SC-12 Tenants handle the distribution and management of cryptographic keys used with
OpenFLISÒ data connections.
SC-13(b) Tenants implement their defined cryptography within their resources in compliance with relevant regulations.
SC-17(a) Tenants issue public key certificates through approved service providers.
SC-17(b) OpenFLISÒ accepts tenant-designated root CAs for CAC/PIV authentication.
SC-18(a) Tenants define allowed mobile code technologies and establish usage restrictions and guidance.
SC-18(b) Tenants authorize, monitor, and control mobile code use within their resources.
SI-12 Tenants specify data handling and retention policies for their unique requirements in their contract with OpenFLISÒ.
The tenant shall provide Synergetics with their organization's established Rules of Behavior for end users.
These rules, which outline acceptable use and user conduct expectations, will be integrated into the OpenFLISÒ terms and conditions and/or privacy policy as deemed appropriate. This integration ensures that all users have the opportunity to review and agree to these stipulations before gaining access to the OpenFLISÒ system. Moreover, the inclusion of the tenant's Rules of Behavior within the OpenFLISÒ framework allows for consistent reference, promoting continuous adherence to the expected standards of behavior and reinforcing the tenant's commitment to maintaining a secure and responsible user environment within the platform.
Synergetics commits to providing the tenant with an up-to-date copy of the OpenFLISÒ team members' Rules of Behavior. This document will detail the conduct expectations and usage guidelines for both internal privileged and non-privileged users of the OpenFLISÒ system. By furnishing this information, Synergetics ensures transparency in its operations and allows the tenant to understand the behavioral standards to which Synergetics' team members are held. This practice fosters trust between Synergetics and the tenant, ensuring that both parties are aligned in their commitment to maintaining a secure and professional environment within the OpenFLISÒ platform.
Security and Privacy Considerations for OpenFLISÒ’ Development Lifecycle.
The OpenFLISÒ Cloud Architect is also tasked with adhering to the security requirements of the FedRAMP Moderate Baseline In accordance with the Service Level Agreement (SLA), Synergetics mandates the use of Common Criteria (ISO/IEC 15408) evaluated products within OpenFLISÒ. To ensure the integrity and security of the OpenFLISÒ platform, all products are expected to meet the evaluation standards as listed on recognized sites such as the National Information Assurance Partnership (NIAP) Common Criteria Evaluation and Validation Scheme (CCEVS) and the Common Criteria Portal.
Synergetics requires that the OpenFLISÒ Cloud Architect complies with the Federal Acquisition Regulation (FAR) Subpart 7.103, as well as Section 889 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year 2019 (Pub. L. 115-232), and FAR Subpart 4.21. These regulations are imperative to address security concerns in the system acquisitions process and any updates related to the Federal Information Security Management Act (FISMA).
The OpenFLISÒ Cloud Architect is responsible for providing a thorough description of the functional properties of the security controls employed within the system. BICEP configurations, which replace Azure Resource Manager (ARM) templates, define the Infrastructure as Code (IaC) for the platform.
These configurations outline the system components, interconnections, and security configurations within the authorization boundary, and are maintained within OpenFLISÒ' Azure DevOps configuration management repository.
Security Requirements, managing external system interfaces and services, and providing applicable diagrams. This includes supplying both high-level and low-level system design details, source code, and vulnerability scan results for code deployed across the Development, QA/Test, and Production environments of OpenFLISÒ. The Cloud Architect must document the organization detail of the scripting language used, any custom scripts created for OpenFLISÒ, conduct a formal risk assessment of all identified vulnerabilities, create a remediation plan, and outline operational risks for vulnerabilities that cannot be remediated. These findings are reported to the Information System Security Manager (ISM) and Information System Security Officer (ISSO), where the ISSO will create a Plan of Actions and Milestones (POA&M) for the vulnerabilities to be included in the Continuous Monitoring (ConMon) monthly reports as per FedRAMP requirements.
Considering that many of OpenFLISÒ' information system components are based on Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) models, OpenFLISÒ may not directly control several systems required to review, manage, and configure these elements. Hence, Azure Government is tasked with the responsibility for those items which are beyond the scope of OpenFLISÒ' capabilities.
The OpenFLISÒ Cloud Architect is required to identify and document the intended functions, ports, protocols, and services expected to be utilized by the application(s) from the early stages of the System Development Life Cycle (SDLC) and continuously throughout the lifecycle of the system to accommodate changing requirements and tenant needs. These requirements are documented and included in this System Security Plan. The ISM ensures any changes are recorded, and the ISSO verifies the proper implementation of these aspects for optimal security effectiveness.
OpenFLISÒ implements Common Access Card (CAC)/Personal Identity Verification (PIV) authentication for tenant access to the information system, with Synergetics employing FIPS 201 approved products for this authentication process. The OpenFLISÒ Cloud Architect provisions IaaS and PaaS components supporting this authentication and leverages tenant root certificates for CAC/PIV validation, ensuring a secure and compliant user authentication framework.
Synergetics’ OpenFLISÒ Supply Chain Risk Management Plan (SCRMP)
Purpose The purpose of this Supply Chain Risk Management (SCRM) Plan is to outline OpenFLISÒ' component authenticity process and measures taken to ensure that it is not incorporating into the platform any system components and/or software that are counterfeit, unreliable, or contain malicious logic or code.
Scope This plan applies to all components and software integrated into the OpenFLISÒ platform, including those from third-party vendors.
Component Authenticity Process
1. Identification of Components: OpenFLISÒ will maintain a list of all system components and software integrated into the platform and identify those that are critical to system security and performance.
2. Component Evaluation: Each component and software will be evaluated for authenticity and reliability by conducting a risk assessment and verifying the vendor's reputation, supply chain practices, and history of producing reliable products. Vendors may be chosen from the list of 50 preselected vendors below, without extra supply chain risk analysis and approval from Synergetics leadership.
3. Authentication: OpenFLISÒ will verify the authenticity of each component and software through rigorous testing and quality assurance processes. This includes verifying the component's physical markings, packaging, and electronic signatures.
4. Traceability: OpenFLISÒ will maintain a record of all components and software used in the platform, including their origin, supply chain history, and verification of authenticity.
5. Mitigation: In case any counterfeit, unreliable, or malicious components or software are identified, OpenFLISÒ will take immediate corrective action to mitigate the risk. This may include replacement of the affected components, code review, and security testing.
Measures Taken to Ensure Component Authenticity
• Supply Chain Visibility OpenFLISÒ maintains visibility into the entire supply chain of each component and software to identify potential vulnerabilities and risks.
• Vendor Assessment OpenFLISÒ assesses each vendor's security and supply chain practices to ensure that they have sufficient measures in place to mitigate risks.
• Continuous Monitoring OpenFLISÒ continuously monitors the supply chain and perform regular testing and auditing of all components and software to detect any potential vulnerabilities.
• Collaboration OpenFLISÒ collaborates with industry and government partners to exchange information, best practices, and lessons learned to enhance the security of the supply chain.
• Conclusion OpenFLISÒ takes supply chain security seriously and implements measures to ensure component authenticity and reliability. The Component Authenticity Process outlined in this plan provides a framework for mitigating risks associated with counterfeit, unreliable, or malicious components and software. By continuously monitoring the supply chain and collaborating with partners, OpenFLISÒ ensures that the platform remains secure, reliable, and resilient.
Preselected Vendors The vendors below are preselected by Synergetics as trusted suppliers of hardware and software products.
They are ranked from 1-50, with 1 being the highest level of trust.
1. Apple - Known for iPhones, Mac computers, iPads, and more.
2. Microsoft - Renowned for its Windows operating system, Surface devices, and cloud services.
3. Intel - One of the world's premier semiconductor chip manufacturers.
4. Dell Technologies - Produces a wide range of computing products, from personal computers to enterprise servers.
5. IBM - While known more for services in recent years, it has a deep history in computer hardware.
6. HP (Hewlett-Packard) - Produces laptops, desktops, printers, and enterprise hardware.
7. Cisco Systems - A leader in networking hardware, software, and telecommunications equipment.
8. Qualcomm - Specializes in semiconductors, wireless technology, and providing chips for many smartphones.
9. NVIDIA - Globally recognized for its graphics processing units (GPUs) and AI technologies.
10. Oracle - Beyond its software solutions, it offers hardware systems and storage solutions.
11. Western Digital - Renowned for storage solutions, particularly HDDs and SSDs.
12. Seagate Technology - Another prominent name in the data storage sector, producing HDDs and
SSDs.
13. AMD (Advanced Micro Devices) - A key player in the semiconductor space, particularly CPUs and GPUs.
14. NetApp - Specializes in data storage and management solutions.
15. Micron Technology - Produces semiconductor devices, especially computer memory and data storage.
16. SanDisk (a brand of Western Digital) - Known for flash storage solutions like SD cards and
USB drives.
17. Xerox - Beyond its historic role in copying solutions, it offers IT services and digital solutions.
18. Logitech - Computer peripherals like keyboards, mice, webcams, and audio devices.
19. Juniper Networks - Specializes in networking products, such as routers, switches, and security devices.
20. Cray (now part of Hewlett Packard Enterprise) - Renowned for supercomputing solutions.
21. Palo Alto Networks - Cybersecurity solutions, firewalls, and threat detection systems.
22. Fortinet - Network security appliances and cybersecurity solutions provider.
23. Super Micro Computer - Server technology and green computing solutions.
24. Applied Materials - Produces semiconductor manufacturing equipment.
25. Texas Instruments - Semiconductors and various electronics for industrial, automotive, and consumer markets.
26. Symantec (now part of Broadcom) - Known for its cybersecurity solutions.
27. Brocade Communications Systems (acquired by Broadcom) - Networking hardware and software.
28. Broadcom - Diverse semiconductor solutions and software.
29. VMware - Virtualization and cloud infrastructure solutions.
30. Autodesk - Software company known for CAD, 3D design, and media applications.
31. Analog Devices - Specializes in data conversion and signal processing technology.
32. FireEye - Cybersecurity appliances and threat intelligence services.
33. Rackspace Technology - Cloud computing services and solutions.
34. NCR Corporation - Point-of-sale terminals, ATMs, and other technology for consumer transactions.
35. Aruba Networks (a Hewlett Packard Enterprise company) - Networking solutions, especially for wireless networks.
36. National Instruments - Produces automated test equipment and virtual instrumentation software.
37. Akamai Technologies - Content delivery network and cloud service provider.
38. ServiceNow - Cloud computing solutions mostly for IT service management.
39. F5 Networks - Networking appliances such as application delivery controllers.
40. Citrix Systems - Software for server, application, and desktop virtualization.
41. Avaya - Enterprise communications, particularly unified communications and contact center solutions.
42. Splunk - Produces software for searching, monitoring, and analyzing machine-generated big data.
43. Verisign - Provides domain name registry services and internet infrastructure.
44. Teradata - Focused on data warehousing and analytics.
45. Commvault - Enterprise data protection, backup, and recovery solutions.
46. KLA Corporation - Supplies process control and yield management solutions for the semiconductor industry.
47. Trimble - Advanced positioning solutions utilizing GPS technology.
48. Cadence Design Systems - Electronic design automation software and services.
49. Lam Research - Supplier of wafer fabrication equipment and services.
50. Zebra Technologies - Tracking technology, printers, and enterprise mobility solutions.
File details come from the government source that posted it. Updated .