7 - CDCS ROB.docx

DOCX document 29 KB Posted

Attached to
Private Counsel Debt Collection - IDIQ Federal contract opportunity
Solicitation number
15JPSS24R00000049
Issued by
Department of Justice Offices Boards and Divisions Justice Management Division

About this file

This document contains the Rules of Behavior (ROB) for users of the Consolidated Debt Collection System (CDCS), which is a financial system of record used by the Department of Justice (DOJ). The ROB outlines the applicable laws, regulations, and DOJ standards that users must comply with, including requirements for handling personally identifiable information (PII), reporting security incidents, protecting data and systems, and proper use of government-furnished equipment. The document also describes penalties for noncompliance, which can include disciplinary actions, loss of system access, and potential criminal prosecution.

The related federal contract opportunity is for an Indefinite Delivery/Indefinite Quantity (IDIQ) contract for Private Counsel Debt Collection services, solicitation number 15JPSS24R00000049, issued by the Department of Justice Offices, Boards and Divisions, Justice Management Division. The solicitation provides a combined synopsis/solicitation but does not contain additional details about the required products or services.

View the file

Other files for this federal contract opportunity

Other files attached to Private Counsel Debt Collection - IDIQ, newest first.
File Type Posted
IDIQ Solicitation Qs and As.docx DOCX document
SF-30 (AMD 0001).pdf PDF
Sample Employment Commitment Letter.docx DOCX document
Past Performance Proposal Template.docx DOCX document
Exhibit B - List of Federal Judicial Districts.docx DOCX document
1 - Statement of Work.docx DOCX document
4 - Contract Line Item Number Descriptions.docx DOCX document
6 - DOJ ROB for General Users - v12.pdf PDF
Past Performance Questionnaire.docx DOCX document
Price Proposal Template.xlsx XLSX spreadsheet
3 - List of Acronyms.docx DOCX document
5 - Confidentiality Agreement.docx DOCX document
9 - TOP Refunds and Disbursements Instructions.pdf PDF
Technical Proposal Template.docx DOCX document
SF-1449.doc DOC document
Exhibit A - Pricing Table.xlsx XLSX spreadsheet
8 - DOJ PC TOP Policy Statement.pdf PDF
Combined Synopsis_Solicitation.doc DOC document
2 - Quality Assurance Surveillance Plan.docx DOCX document
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Consolidated Debt Collection System (CDCS) Rules of Behavior Consolidated Debt Collection System Rules of Behavior (ROB) for General Users Version 3.3

Introduction As a user of Department of Justice (DOJ) Information Technology (IT) data and systems, you are the first line of defense in support of Department and Component IT security. As a knowledgeable user, you are the foundation of a successful security program. The Rules of Behavior (ROB) for General Users concern use, security, and acceptable level of risk for Department systems. The rules also highlight that taking personal responsibility for the security of an information system and the data it contains is an essential part of your job.

The intent of the ROB is to summarize for you, a user of DOJ IT resources, the applicable laws and requirements from various Federal and DOJ documents. These include, but are not limited to, the Office of Management and Budget (OMB) Circular A-130, DOJ Order Cybersecurity Program (series), DOJ Order 2740.1 (series), and the DOJ IT Security Standard.

To remain compliant with all applicable laws, Federal regulations, and DOJ Standards, the Consolidated Debt Collection System (CDCS) Program Management Office (PMO) reserves the right to update these ROB at any time. Please direct all questions relating to the ROB to your Help Desk, Security Manager, or Supervisor.

Who is covered by these rules?

The following rules of behavior apply to all users of the CDCS whether Department of Justice (DOJ) employees, private counsel users, or development contractors. CDCS is a financial System of Record and, as such, must comply with the requirements of OMB Circular A-123, Management Accountability and Controls, as well as the Federal Financial Management Improvement Act of 1996 (FFMIA), and OMB Circular A-127, Financial Management System Requirements. All individuals given access to the DOJ CDCS Information Systems must understand that these principles are based on Federal laws, regulations and DOJ Orders. As such, as indicated above there are consequences for non-compliance with principles of behavior. Whether the subject individual is a DOJ employee, contractor or other, management has the right to impose appropriate sanctions and/or cease the individual’s access to computer systems.

What are the penalties for noncompliance?

Compliance with applicable laws, policies and standards will be enforced through sanctions commensurate with the level of infraction. Actions may include a verbal or written warning, removal of system access for a specific period of time, reassignment to other duties, or termination, depending on the severity of the violation. In addition, activities that lead to or cause the disclosure of classified information may result in criminal prosecution under the U.S. Code, Title 18, Section 798, and other applicable statutes.

Unauthorized browsing or inspection of Federal Taxpayer Information (Internal Revenue Code Sec. 7213A) is punishable with a fine of up to $1,000 and/or up to one year imprisonment. Unauthorized disclosure of Tax Return information (Internal Revenue Code Sec. 7213) is a felony punishable with a fine of up to $5,000 and/or up to five years in prison. In addition to these penalties, any Federal employee convicted under Sec. 7213 or Sec. 7213A will be dismissed from employment.

I [print name] understand that when using DOJ automated IT systems, that I will be held accountable for my actions related to the information resources entrusted to me. I further understand the following items:

Accountability All users must be accountable for their actions and responsibilities related to information resources entrusted to them.

Users of Personal Information

Users must acquire and use personally identifiable information (PII) only in ways that respect an individual's privacy and are in compliance with the Privacy Impact Assessment (PIA) for CDCS. The CDCS collects PII to track and correspond with debtors, as well as to locate and collect debtor assets. The personal information is necessary to properly track and collect fines and other debts owed to the Department of Justice, other Government agencies, and 3rd parties. All users must protect sensitive information from disclosure to unauthorized individuals or groups.

Reporting

1. Report all security violations, incidents, and vulnerabilities immediately to your office’s DOSM (District Office Security Managers) and the EOUSA Information Systems Security Officer (ISSO).

2. All security incidents regarding loss or theft must also be reported immediately to the EOUSA Security Programs Manager (SPM).

General

1. Comply with all Federal laws and Department and Component policies and requirements, including DOJ Orders and Standards. Use DOJ information and information systems for lawful, official use, and authorized purposes only.

2. Do not generate, download, store, copy, or send offensive or inappropriate e-mail messages, documents, images, videos, sound files, etc. Limit distribution of e-mail to only those with a “need to know”.

3. Do not open e-mails from suspicious sources (e.g., people you don’t recognize, know, or normally communicate with) and do not visit untrusted or inappropriate Websites (unless authorized). Only download files from known and reliable sources and use virus-checking procedures prior to file use.

4. Protect and safeguard all DOJ information, including that containing personally identifiable information (PII), commensurate with the sensitivity and value of the data at risk. Protect and safeguard all DOJ information and information systems from unauthorized access, unauthorized or inadvertent modification, disclosure, damage, destruction, loss, theft, denial of service, improper sanitization, and/or improper use.

5. Verify that each computer-readable data extract containing sensitive data has been erased within 90 days of origination or that its use is still required.

6. Unless authorized by an approved waiver, encrypt all Departmental Sensitive but Unclassified (SBU) data on mobile computers, laptops, tablets, and/or removable media (e.g., removable hard drives, thumb drives, and DVDs) using Department-approved solutions. Use only authorized removable media (e.g., Component approved thumb drives). For classified environments, follow the procedures required for those networks for data storage and transport. (Remember all data is considered sensitive unless designated as non-sensitive by the Component Director.)

7. Read and understand the DOJ standard security warning banner that appears prior to logging onto the network or mobile device.

8. Screen-lock or log-off your computer when leaving the work area. Log-off when departing for the day.

9. Keep all government-furnished equipment (GFE) mobile devices assigned to you in your physical presence whenever possible. When it is necessary for you to be away from your GFE, particularly at a non-secure location, secure all your portable electronic devices and removable media, preferably out- of-sight (e.g. in a locked container). In some locations, hotel safes are not considered very secure and hotel staff may not be trustworthy.

10. Do not auto-forward emails from your DOJ email account to your personal email account (e.g., Gmail, Yahoo, and Hotmail).

11. Ensure that individuals have the proper clearance, authorization, and need-to-know before providing access to any CDCS information.

12. Consent to monitoring and search of any IT equipment that is brought into or removed from DOJ owned, controlled, or leased facilities.

13. Properly mark and label classified and sensitive documents, electronic equipment, and media in accordance with the DOJ Security Program Operating Manual (SPOM) and DOJ Order 2620.7.

14.

15. Adhere to Separation of Duties principles. Understand conflict of interest in responsibilities, roles, and functions within a system or application. Duties of the System Administrator and Information System Security Officer (ISSO) should not be combined.

16. Unless specifically authorized, do not change any configurations and/or settings of the operating system and security-related software. Do not attempt to circumvent or test the security controls of the system. Do not bypass native mobile device operating system controls to gain increased privileges (i.e., jailbreaking or rooting the device).

17. Do not use anonymizer sites on the Internet, which bypass the Department security mechanisms designed to protect systems from malicious Internet sites.

18. Follow your organization’s telework guidelines when working remotely and/or accessing DOJ information remotely.

19. Take action to reduce damage caused by security incidents, as appropriate, e.g., lock up property, log off of a terminal, and disconnect a PC with a virus from the LAN.

Classified Systems/Information

1. Do not process classified information on an unclassified system. Send classified email only on systems authorized for that purpose and for the highest level of the classified data involved.

2. When in use, operate IT systems only in those areas or facilities certified for the highest classification or sensitivity level of the information involved. When not in use, store a classified computer, hard drive, removable media, etc. in an approved security container or in a facility approved for open storage.

3. Use classified laptops and similar devices only upon receiving approval from your security office, which must coordinate with the Department Security Officer (DSO) and Chief Information Officer (CIO).

Passwords

1. Adhere to at least the minimum password requirements for the system on which you are working. Change the default password upon using your account for the first time.

2. Do not share account passwords with anyone and protect passwords at the highest classification and sensitivity level of the system to which they apply.

3. Never use the same or similar password for multiple accounts and especially between/among your personal accounts and DOJ or other government systems.

4. If your password has been compromised, or is suspected of being compromised, change it immediately and report the incident to your Systems Administrator and District Officer Security Manager.

5. Protect the privilege user passwords at highest level demanded by the sensitivity level of the system.

Hardware

1. Unless specifically authorized, do not add, modify, or remove hardware, nor connect unauthorized accessories or communications connections to Department IT resources.

2. Unless specifically authorized, do not access the internal components of the computer, nor remove the computer or its hard drive from DOJ facilities.

3. Wipe all devices prior to reissue. There is no expectation of maintaining any personal information, data, or applications on these devices.

Software

1. Do not copy or distribute intellectual property — including music, software, documentation, and other copyrighted materials — without permission or license from the copyright owner. Only use DOJ- licensed and authorized software.

2. Unless specifically authorized, do not install any software.

3. Unless specifically authorized, do not attempt to access any electronic audit trails that may exist on the computer.

Travel Users

1. While travelling, minimize the information on your IT system to what is required to perform that particular mission and destroy copies of sensitive data when no longer required.

2. Power down IT devices when possible and not needed. If the IT device is needed but not the associated network capability, turn off/disable the network/wireless network functionality. (See the Secure Use of Wireless Networks FAQ at http://dojnet.doj.gov/jmd/irm/itsecurity/ises_team.php)

3. In a foreign country or airline, assume your transmissions (including cellular services) and conversations are being intercepted, read, and/or heard.

4. When possible, keep your remote access token separate from the laptop/tablet (preferably on your person).

Mobile Computing & Remote Access Users

1. Use mobile GFE (e.g., laptop, tablet, Smartphone) for official business and authorized uses. Mobile GFE is for use by DOJ personnel only (no spouse or relative) and shall only connect through an authorized DOJ remote access network when accessing the Internet.

2. Software and applications can only be downloaded and installed on Departmental mobile GFE as authorized. Ensure that all software is properly purchased, licensed, and obtained from DOJ approved sources before installing it on mobile GFE.

3. Limit Short Message Service (SMS) messages to non-sensitive information if SMS is approved by the Authorizing Official.

4. Only connect to secure wireless networks where possible and take precautionary measures to prevent the compromise of DOJ data when insecure wireless networks must be used. (See the Secure Use of Wireless Networks FAQ at http://dojnet.doj.gov/jmd/irm/itsecurity/ises_team.php) Remote Web Access

1. Ensure the confidentiality of government information when using remote web access (e.g., OWA) from a non-GFE client (public or private). This includes the following:

a. When downloading attachments to registered non-GFE private computers, immediately remove any attachments, encrypt them locally, or transfer them to an approved encrypted USG drive;

b. Delete attachments when finished on registered non-GFE private computers; and

c. Do not download attachments on non-GFE public computers.

2. Do not print emails in public areas and with public non-GFE printers. Users may print with non-GFE private printers at home. Users will be held responsible for the compromise of Government information through negligence or a willful act.

3. Maintain a reasonable security posture (i.e., updated antivirus, local firewall, updated OS and software patch levels) on registered non-GFE private computers used for remote web access.

CDCS Security Rules

1. Integrity

a. Do not introduce unauthorized, inaccurate, or false information into CDCS.

b. Do not use system privileges to misuse or exploit information in CDCS.

c. Do not alter files or data improperly. If files or data appear to be altered improperly or are missing, notify your System Manager and Security Manager.

2. Availability

a. Plan for contingencies such as disaster, loss of information, and disclosure of information by preparing alternate work strategies and recovery mechanisms.

b. Make backups of hard drive files on a regular basis.

c. Complete transactions and save records before stepping away from your workstation. Log out of the application if you will be away for a period of time.

3. Work at Home and Private Counsel Users

a. Work at home users may not use personally-owned hardware, software, or network connectivity for any work purposes without prior Department of Justice approval.

b.

c. All on-site safeguards for handling PII apply to off-site work.

d. Do not disclose or distribute JSRA Token IDs or passwords.

4. Managers

a. Notify your staff’s security personnel and the CDCS Help Desk whenever a employee is no longer supporting the CDCS program.

a. Assist departing employees in completing the CDCS Exit Checklist for the complete return of all issued government property and the removal of information system access held in the name of the departed.

b. Counsel terminating employees on non-disclosure of confidentially-sensitive information.

c. Terminate access to information and computer systems immediately in the event of employee separation.

d. Escort employee off the premises when there is likelihood of sabotage, as with an unfriendly termination or separation.

e. Keep an inventory of all computer equipment and software you have in your office.

f. Track all security incidents occurring within your area of responsibility.

5. Private Counsel

a. Personally Identifiable Information (PII) must be safeguarded at all times and stored on the provided encrypted storage device.

b. Safeguarding the thumb drives is extremely important because of the sensitivity of the data stored within.

c. Files stored on the flash drives (i.e., encrypted storage device) must never be transmitted over standard e-mail or electronically transmitted over any non-secured transmission facilities.

d. Lost or stolen devices must be reported to DOJ immediately.

e. JSRA Tokens and thumb drives must be returned to DOJ immediately upon termination of an employee or private counsel contract.

f. Private Counsel are required to abide by all regulations provided in this document and specified contractual obligations.

I understand that the CDCS PMO and central System Administrators will regularly review system logs and conduct spot-checks to determine if I am complying with policies and controls placed on the use of CDCS resources.

I acknowledge that I have read the CDCS Rules of Behavior, understand my responsibilities and agree to comply with the Rules delineated herein. I acknowledge that any violation of these Rules may be cause for disciplinary action.

__
SignatureDate

File details come from the government source that posted it. Updated .