Amd.1_J.2_Cybersecurity-Data Protection-AI 12.21.25_Revised.pdf

PDF 165 KB Posted

Attached to
Parametric Railway Line Capacity Modeling Federal contract opportunity
Solicitation number
693JJ626Q000005
Issued by
Department of Transportation Federal Railroad Administration

About this file

This is an addendum establishing mandatory Cybersecurity, AI, and Data Protection contract requirements tailored specifically for Phase I model development of the Parametric Railway Line Capacity Model project. The requirements are scoped to exclude production hosting, enterprise Zero Trust architecture, FedRAMP authorization, and continuous Security Operations Center (SOC) operations, which are reserved for Phase II or subsequent contracts.

The Contractor must establish a documented information security program protecting Government Data confidentiality, integrity, and availability through administrative, technical, and physical safeguards appropriate to development and test environments. Key operational requirements include: compliance with applicable Federal cybersecurity laws, NIST SP 800-53 controls, and DOT/FRA policies; encryption of data at rest and in transit using FRA-approved algorithms; role-based least-privilege access with multi-factor authentication; routine vulnerability scanning and patch management with timely remediation of high-severity findings; and incident response procedures requiring notification within one hour for sensitive production data incidents or 24 hours for lower-impact incidents, with written reports due within 72 hours. Additional mandatory provisions address data handling and PII protection, prohibition on using Government Data to train Contractor-owned or third-party AI/ML models without explicit written authorization, personnel training in cybersecurity and privacy awareness, subcontractor compliance flow-down, data destruction per NIST SP 800-88 upon contract completion with written certification, contractor liability for breach costs resulting from non-compliance, and Government retention of unrestricted rights to all developed code, tools, systems, and data with the right to request full copies at any time. Obligations related to data protection, confidentiality, incident reporting, and records retention survive contract expiration or termination.

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

J.5 Addendum 2: Cybersecurity, AI, and Data Protection Contract Requirements.

╔ěكل

Cybersecurity, Zero Trust, AI and Data Protection Requirements

Preface: Tailored Applicability for Phase I Model Development — The Cybersecurity, Zero Trust, AI & Data Protection Appendix is hereby tailored for the Phase I scope of the Parametric Railway Line Capacity Model project. The provisions retained here apply to model development, delivery of model artifacts, and any limited non‑production demonstration artifacts. Production hosting, enterprise Zero Trust architecture, FedRAMP authorization, and continuous SOC operations are outside the Phase I scope and will be addressed, if needed, in subsequent Phase II production contracts or option CLINs.

This Appendix is written to be contract-enforceable, technology-neutral, and is an integral part of the Contract between the Government and the Contractor and establishes mandatory Cybersecurity, Zero Trust, AI and Data Protection Requirements.

1. Definitions

1.1 “Government Data” means all data, information, records, or content created, collected, processed, stored, transmitted, or maintained on behalf of the Government under this Contract, including but not limited to Sensitive Information and PII.

1.2 “Cybersecurity Incident” A cyber incident is an event that could jeopardize the confidentiality, integrity, or availability of digital information or information systems or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies of an information system or Government Data.

1.3 “Personally Identifiable Information (PII)”: Information that can be used to distinguish or trace an individual’s identity—such as name, social security number, biometric data records— either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual (e.g., date and place of birth, mother’s maiden name, etc.)..

2. Information Security Program The Contractor shall establish, implement, maintain, and continuously improve a documented information security program appropriate to the scope of work for this contract that protects the confidentiality, integrity, and availability of Government Data used in model development. The program shall include administrative, technical, and physical safeguards commensurate with sensitivity of the data and the Contractor’s environment (development/test workspaces). The Contractor is not required to implement enterprise hosting security controls (e.g., FedRAMP) unless explicitly stated in a separate CLIN.

3. Compliance With Laws, Regulations, and Standards

(1) Compliance — In performing this contract, the Contractor shall comply with applicable Federal cybersecurity and privacy laws and DOT/FRA policies. For Phase I model development, the Contractor must comply with relevant NIST guidance (e.g., NIST SP 800‑53 controls applicable to contractor-hosted development environments) and OMB/DOT policy memos as applicable to non-production handling of Government data. Requirements that apply to production hosting (FedRAMP, ATO processes) are reserved for Government-hosted production environments and Phase II application contracts.

4. Data Handling, PII Protection, and Access Control Government Data shall be used only to perform the obligations of this contract. The Contractor shall handle, store, transmit, and dispose of Government Data in accordance with Government data classification and handling requirements, and operate only within Government‑approved secure environments for sensitive or production datasets. The Contractor shall implement: (a) encryption for data at rest and in transit per FRA-approved algorithms; (b) role‑based least-privilege access for personnel with a need-to-know; (c) multi-factor authentication for accounts providing access to Government Data; and (d) logging sufficient for auditing access. The Contractor shall not disclose Government Data to third parties without written authorization from the Government.

7. Vulnerability Management The Contractor shall perform routine vulnerability scanning and patch management for Contractor‑controlled development environments used for the contract and shall remediate high‑severity findings in a timely manner. For work performed in Government‑provided or Government‑approved environments, the Contractor shall coordinate with FRA IT to address vulnerabilities per Government procedures. Continuous 24/7 monitoring and SOC operations remain Government responsibilities for production hosting.

8. Incident Response and Reporting The Contractor shall maintain an incident response capability and shall notify the Government of any actual or suspected cybersecurity or privacy incident involving Government Data or systems within one

(1) hour of initial discovery for incidents impacting sensitive production data or systems; for lower-impact incidents, initial notification within 24 hours is acceptable. A written incident report shall follow within 72 hours describing impact, mitigations, and planned corrective actions.

9. Subcontractor The Contractor shall ensure that subcontractors with access to Government Data comply with the essential data protection requirements in this Appendix (data handling, encryption, NDA, incident reporting). The Government will identify any additional flow-down obligations for specific subcontractor roles.

10. Audit, Assessment, and Right to Review The Government reserves the right to assess or audit the Contractor’s cybersecurity and data protection controls related to this contract. The Contractor shall provide reasonable access to documentation and personnel and shall cooperate in assessments limited to the contract scope and data-handling environments.

11. Data Retention, Return, and Destruction

11.1 Upon completion or termination of the Contract, the Contractor shall return all Government Data or securely destroy such data in accordance with NIST SP 800-88.

11.2 The Contractor shall provide written certification of data destruction upon request.

12. Breach Liability The Contractor shall be responsible for costs attributable to a cybersecurity incident caused by the Contractor’s failure to comply with contractual security requirements, including reasonable remediation and notification costs.

13. Training The Contractor shall ensure personnel with access to Government Data complete initial and annual role-based cybersecurity and privacy awareness training relevant to their tasks under this contract.

14. Zero Trust Principles

The Contractor shall follow identity-centric security practices for Contractor-issued accounts (strong authentication, MFA) and least-privilege access. Implementation of enterprise Zero Trust Architecture components (e.g., network micro-segmentation, enterprise continuous device posture enforcement) is the Government’s responsibility for production environments and is not required of the Contractor for Phase I model development.

15. Artificial Intelligence (AI), Generative AI, and Machine Learning (ML) Restrictions

The Contractor shall not use Government Data for training, tuning, or operating Contractor-owned or third‑party AI/ML models, nor incorporate Government Data into any public or shared training datasets, unless the Government provides explicit prior written authorization specifying scope, purpose, and retention. If authorized, the Contractor must meet additional documentation, segregation, and oversight requirements to be specified by the Government.

16. Systems Security Engineering Requirement:

The Contractor shall incorporate security considerations into design and development of the model artifacts (secure coding, dependency management, supply chain risk awareness, and documentation of security considerations). Comprehensive SSE responsibilities for production systems will be addressed under Government‑led Phase II arrangements.

17. Restrictions on Disclosure of Information and Data

Except as authorized in writing by the Contracting Officer, the Contractor shall not disclose, orally or in writing, any:

Proprietary Information, Privacy Information, Privileged Information, Government Information or data stored, processed, or handled in providing services under this Contract or which may come into the possession of the Contractor in providing services under this Contract or which may come into the possession of the Contractor in providing services under this Contract.

18. Protection of Information, Confidentiality, Non-disclosure, and Data Rights

The government will retain unrestricted rights to government data, code, tools, and systems developed under this contract. The government retains ownership of all created/loaded data, code, tools, and applications hosted on vendor’s infrastructure, as well as maintains the right to request full copies of these at any time.

20. Survival The obligations in this Appendix related to data protection, confidentiality, incident reporting, destruction/return of Government Data, and records retention shall survive expiration or termination of the Contract. Other clauses tied specifically to production hosting or continuous monitoring do not survive in Phase I unless explicitly included in a subsequent Phase II agreement.

21. Contract Passthrough The Contractor shall include in all subcontracts (including lower-tier subcontracts) the essential data protection clauses of this Appendix (data handling, NDA, incident reporting, encryption, and return/destruction obligations). Full passthrough of other production-oriented obligations (FedRAMP, ATO responsibilities, continuous monitoring) is not required for Phase I subcontracting unless expressly specified by the Government.

File details come from the government source that posted it. Updated .