7.6 Cybersecurity Regulations and Guidance.pdf

PDF 20 KB Posted

Attached to
DoD HIV/AIDS Prevention Program (DHAPP) PM Support Federal contract opportunity
Solicitation number
HT0011-23-R-0109
Issued by
Defense Health Agency

About this file

This document contains a federal contract solicitation and related cybersecurity regulations and guidance information. The Defense Health Agency is seeking proposals for DoD HIV/AIDS Prevention Program project management support services. Offerors must comply with all current cybersecurity standards and regulations from the Department of Defense, Department of Health and Human Services, National Institute of Standards and Technology, and Office of Management and Budget. The solicitation is set aside for small businesses and will result in a firm fixed-price requirements contract for a base year plus four option years not to exceed 60 months total. Proposals are due by the date specified in the solicitation and should contain the offeror's best terms from both a price and technical standpoint.

View the file

Other files for this federal contract opportunity

Other files attached to DoD HIV/AIDS Prevention Program (DHAPP) PM Support, newest first.
File Type Posted
Amendment 0004_Attachment 2- Revised Pricing Sheet.xlsx XLSX spreadsheet
Amendment 0004_Attachment 3- Revised Qualifications.pdf PDF
HT001123R0109 Amendment 0004.pdf PDF
HT001123R0109 Amendment 0003.pdf PDF
Amendment 0003_Attachment 2- Revised Pricing Sheet.xlsx XLSX spreadsheet
Amendment 0003_Attachment 1- Revised PWS_DHAPP PM.pdf PDF
Amendment 0003 Change Page.pdf PDF
Questions and Responses-Final.pdf PDF
Attachment 2- Revised Pricing Sheet.xlsx XLSX spreadsheet
Attachment 1- Revised PWS_DHAPP PM-Final.pdf PDF
Amendment 0002 Change Page.pdf PDF
Attachment 3- Revised Qualifications-Final.pdf PDF
Attachment 8- Past Performance References.docx DOCX document
HT001123R0109 Amendment 0002.pdf PDF
HT001123R0109 Amdt 0001.pdf PDF
7.2 DMDC TASS Application.xlsx XLSX spreadsheet
Attachment 3- Qualifications.pdf PDF
Attachment 6- WD 2015-5635 Rev 23 (San Diego).pdf PDF
Attachment 7- WD 2015-4281 Rev 28 (Wash DC).pdf PDF
Attachment 2- Pricing Sheet.xlsx XLSX spreadsheet
Attachment 5- Estimated Level of Effort (Workload Hrs.).pdf PDF
RFP HT001123R0109 DHAPP PM.pdf PDF
7.1 DHA CAC Request Process.pdf PDF
7.7 Status of Force Agreement.pdf PDF
7.3 DHA Mandatory Training List- March 2023.pdf PDF
Attachment 1- PWS_DHAPP PM.pdf PDF
7.8 DHA FORM 49 Non-Disclosure.pdf PDF
Attachment 4- Consent Letter.docx DOCX document
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Cybersecurity Regulations and Guidance

The Vendor shall use and comply with the most recent published versions of the following references, as well as all regulations or guidance referenced within those publications:

(a) United States Law

(i) The Health Insurance Portability and Accountability Act of 1996 (HIPAA)

(ii) The Federal Information Security Management Act (FISMA)

(iii) The E-Government Act of 2002

(b) Office of Management and Budget (OMB) The following publications are located at https://www.whitehouse.gov/omb/agency/default

(i) Circular A-130

(ii) Guidance M-05-24, Implementation of Homeland Security Presidential Directive

(HSPD) 12-Policy for a Common Identification Standard for Federal Employees and Vendors

(c) National Institute of Standards and Technology (NIST) The following publications are located at http://www.nist.gov/publication-portal.cfm

(i) NIST Special Publication (SP) 800-37 – Guide for Applying the Risk Management

Framework (RMF) to Federal Information Systems

(ii) NIST SP 800-39—Managing Information Security Risk: Organization, Mission and

Information System View

(iii) NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations

(iv) NIST SP 800-60—Volume 1 Revision 1: Guide for Mapping Types of Information and Information Systems to Security Categories

(d) Federal Information Processing Standards (FIPS) The following publications are located at http://www.nist.gov/itl/fipscurrent.cfm

(i) FIPS Publication (FIPS PUB) 140-2, Security Requirements for Cryptographic

Modules

(ii) FIPS PUB 199 – Standards for Security Categorization of Federal Information and

Information Systems

(iii) FIPS PUB 200: Minimum Security Requirements for Federal Information and

Information Systems

(iv) FIPS PUB 201-2, Personal Identity Verification of Federal Employees and Vendors

(e) Department of Defense (DoD) The following publications are located at http://www.dtic.mil/whs/directives/

(i) DoD Instruction 5200.2, DoD Personnel Security Program (PSP)

(ii) DoD Instruction 8500.1, Cybersecurity https://www.whitehouse.gov/omb/agency/default http://www.nist.gov/publication-portal.cfm http://www.nist.gov/itl/fipscurrent.cfm http://www.dtic.mil/whs/directives/

(iii) DoD Instruction 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling

(iv) DoD Instruction 8510.01, Risk Management Framework Process (RMF)

(v) DoD Instruction 8551.1, Ports, Protocols, and Services Management (PPSM)

(vi) DoD Instruction 8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs

(vii) DoD Instruction 6025.18, Privacy of Individually Identifiable Health Information in

DoD Health Care Programs

(viii) DoD Directive 5400.11, DoD Privacy Program

(f) The following publications are located at https://home.facilities.health.mil/low-voltage-system.

(i) DHA PM Standard Isolation Architecture for Cybersecurity of FRCS

(ii) Security Categorization for Facility-Related Control Systems (FRCS)

(iii) Facility-Related Control Systems (FRCS) Overlay

(iv) Standard Operating Procedure (SOP) for Facility-Related Control Systems (FRCS)

Assessments

(v) Guidance for Facility-Related Control Systems (FRCS) Continuous Monitoring https://home.facilities.health.mil/low-voltage-system

File details come from the government source that posted it. Updated .