09.11_Attachment_F_-_ICE_Cybersecurity_Contract_Language_Catalog.docx

DOCX document 314 KB Posted

Attached to
eClinical Works Software License and Support Federal contract opportunity
Solicitation number
70CTD019Q00000082
Issued by
Immigration and Customs Enforcement

About this file

This performance work statement outlines requirements for the maintenance and annual support of eClinicalWorks software products. Immigration and Customs Enforcement seeks to acquire enterprise licenses for eClinicalWorks maintenance support over five base years and five option years. Key details include clinical software products from eClinicalWorks, maintenance and support services, a sole source award to eClinicalWorks due to proprietary software, and pricing from September 2019 through March 2025. Deliverables include help desk support, updates, and operating system compatibility for eClinicalWorks suites.

Attachment F

View the file

Other files for this federal contract opportunity

Other files attached to eClinical Works Software License and Support, newest first.
File Type Posted
Amendment_One.pdf PDF
09.11_Attachment_E_-_HSAR_Deviation_15-01_Safeguarding_of_Sensitive_Information.docx DOCX document
09.11_Attachment_B_-Terms_and_Conditions.doc DOC document
09.11_Solicitation_70CTD019Q00000082.pdf PDF
09.11_Attachment_D_-_RFQ_Instructions.docx DOCX document
eCW_JOFOC_Redacted.pdf PDF
09.11_Attachment_A_-_PWS.docx DOCX document
09.11_Attachment_C_-_IGP_Requirements_Clause.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Department of Homeland Security Immigration and Customs Enforcement Office of the Chief Information Officer

Attachment F: Cybersecurity Contract Language Catalog

Version 2.0 April 4, 2018

Revision History

Version
Date
Revised by
Comments
1.0
18 October 2013
ICE IAD
Initial Draft
1.1
1 November 2013
ICE IAD
Added Appendices A, B, and C that provide example contract language related to security requirements.
1.2
21 November 2013
ICE IAD
Added Appendices D, E, F, and G that provide example contract language related to security requirements.
1.2
29 July 2014
ICE IAD
Reviewed to Verify References were Up to Date.
9 January 2018
Hunter Shaw, Kathy Smith, Rick Inzunza
Cleaned up appendices, added instructions, and refined Appendix B (Cloud Services).
2.0
4 April 2018
Hunter Shaw, Kathy Smith
Addressed OPLA’s 3/23/2018 feedback.

TABLE OF CONTENTS

1INTRODUCTION AND PURPOSE1
2Instructions on Using This Catalog2
3DOCUMENT REFERENCES3
4ICE CYBERSECURITY REQUIREMENTS MATRIX4
APPENDIX A. General Cybersecurity Contract Requirements15
APPENDIX B. Cloud Services Contract Requirements24
APPENDIX C. COTS Software Contract Requirements39
APPENDIX D. Custom Software/GOTS Contract Requirements43
APPENDIX E. Mobile Device Contract Requirements47
APPENDIX F. Hardware Contract Requirement50
APPENDIX G. Professional Services Contract Requirements52

APPENDIX H. HIGH RISK CONTRACT REQUIREMENTS…………………………….52

LIST OF FIGURES

Table 31: Contract Language Document References3
Table 41: ICE Cybersecurity Contract Language Matrix5

ii

1. INTRODUCTION AND PURPOSE

Federal law requires that all government information systems be protected against unauthorized access or use. The Federal Information Security Management Act (FISMA) is the key cybersecurity statute and requires Federal agencies to implement organization-wide cybersecurity programs. The U.S. Department of Homeland Security (DHS) has instantiated FISMA in several organizational publications.

FISMA and related DHS cybersecurity policies and requirements apply to all information technology (IT) solutions deployed across DHS. They apply to all IT solutions operated by or on behalf of DHS. As many Immigration and Customs Enforcement (ICE) information systems are developed or maintained by contract resources, incorporating cybersecurity requirements into all ICE contracts is a critical component of the overall DHS cybersecurity program.

The purpose of this document is to help ICE Program Managers (PMs) align IT acquisition with DHS cybersecurity policies and guidelines. This document provides references to DHS and other guidance that provides text that can be incorporated into ICE acquisition documents. It provides references to specific sections in the guidance documents that apply to certain acquisition types. PMs should incorporate the referenced language into their acquisition documents to cover required cybersecurity requirements.IMPORTANT NOTE If the acquisition being prepared is being let under an existing contract (e.g., EAGLE), refer to the base contract for the cybersecurity clauses in place. Those may cover the cybersecurity requirements noted in this document.

The remainder of this document is organized into four parts:

· Section 2 provides instructions on how a Program Manager (PM) should use this catalog to generate the cybersecurity requirements relevant to their acquisition.

· Section 3 provides a table of references for cybersecurity-related publications that are applicable to ICE IT acquisitions. This same table provides a link to the location of the publication.

· Section 4 provides a matrix of the cybersecurity requirements mapped to different contract categories

· Section 5 contains instructions on how to use this catalog to incorporate cybersecurity requirements into an IT contract.

The final part of this document consists of several appendices organized by contract category and includes the relevant cybersecurity contract clauses for each. The contract clauses contained in each appendix have been taken directly from the references identified in section 3. Use the appropriate appendix to determine specific contract clauses required for the acquisition being sought.

INSTRUCTIONS ON USING THIS CATALOG

1. Create a new document to contain the cybersecurity language for your acquisition. Reference this document in the appropriate sections of your contract (e.g., “See Appendix 1 for cybersecurity requirements for this contract”).

2. Read the contract category descriptions in Section 4 and determine which categories apply to your acquisition.

· ALL acquisitions must include the requirements in this catalog’s Appendix A, ”General Cybersecurity Contract Requirements”.

· ALL IT acquisitions should map to at least one additional contract category.

· If you cannot determine your contract category, please consult with IAD.

3. For each category/appendix that is relevant to your acquisition:

a. For each major-numbered sub-section of the appendix (e.g., “A.1”, “A.2”):

i. Review the italicized wording at the start of the sub-section to see if the sub-section applies to your acquisition. In most instances, the italicized wording differentiates between “Classified” and “Sensitive but Unclassified” contracts.

ii. If the sub-section applies to your acquisition, then copy & paste all the wording below the italics.

iii. If the sub-section does not apply to your acquisition, then skip it.

4. If you included more than one additional contract category appendix, then check for duplicate requirements and remove them.

· Tip: the matrix in Section 4 will indicate which appendices share the same requirement wording.

5. Complete any fill-in-the-blanks with the appropriate information for your particular contract; these are indicated by square-bracketed, italicized, red font. Also remove the brackets, the italics, and change the font color to black.

DOCUMENT REFERENCES

Table 3-1 contains a list of cybersecurity references that are applicable to ICE acquisitions. Several documents listed contain language that can be copied directly into an acquisition document to cover cybersecurity requirements. Others are listed as references in case additional detail on a given requirement is needed. There are three columns in the table:

Document Number: Provides the number assigned to a document or suite of documents (if applicable). Document numbers beginning with “MD” are DHS Management Directives.

Document Name: The name of the publication or program.

Reference Link: Contains a link (if available) to the website containing the publication. Click on the link or copy and paste the link into the browser URL field, to access the publication.

Table 31: Contract Language Document References Document Abbreviation

Document Name
Reference Link
ITAR
Information Technology Acquisition Review (ITAR) Quick Essentials Guide V3.0
http://dhsconnect.dhs.gov/org/comp/mgmt/ocio/bm/Documents/ITAR/ITAR%20Quick%20Essentials%20Guide%20V3_0%202013.pdf#search=ITAR%20guide%20v3%2E0
HSAR
Homeland Security Acquisition Regulation (HSAR)
http://dhsconnect.dhs.gov/org/comp/mgmt/cpo/Documents/ch3001.html
FR
Federal Risk and Authorization Management Program (FedRAMP)
https://www.fedramp.gov/resources/documents-2016/
BYODTK
White House Digital Government Bring Your Own Device Toolkit
https://obamawhitehouse.archives.gov/digitalgov/bring-your-own-device

ICE CYBERSECURITY REQUIREMENTS MATRIX

Table 41 contains a list of specific sections from the cybersecurity references in section 3 that are applicable to ICE IT acquisitions. The contract language from the referenced sections can be copied directly into an acquisition document to cover cybersecurity requirements for the acquisition. The language from the referenced sections may need to be adjusted slightly for each specific acquisition, but provide the baseline from which to start.

The table is organized by service/contract category being acquired in order to provide guidance on the language required for each specific acquisition. An “X” in a row under the contract category indicates that the referenced section is applicable to an acquisition of that type. References with an “X” under the “General Reqs” column are applicable to all IT acquisition types.

A brief description of each column in the table is provided below.

Requirement Source:

Doc: Provides a short abbreviation of the document or program from which the section or document is found. Refer to Table 3-1 in section 3 for the full document name.

Section Number: Contains the contract language (if applicable) in the publication. Note that in some cases, for example FedRAMP, the Section Number field provides the name of the document that contains the contract language.

Section Name: Referenced publication containing the contract language. In some cases, the referenced section is already covered by another publication. For those, a notation has been added letting the reader know where it is covered and that the language from this section can be omitted. Those sections have been left in the table so the reader knows how to handle them when looking through the source document.

Contract Category:

General Requirements: This column identifies contract language that is general in nature and is to be included in all acquisition types.

Cloud Services: This column identifies contract language that applies to all types of cloud services acquisitions: Infrastructure-as-a-Service, Platform-as-a-Service, Software-as-a-Service, etc.

· Exception: For applications that reside/will reside on the ICE Cloud GSS, their cloud service acquisitions/task orders do not require this category of Cloud Services cybersecurity contract language because the overarching ICE Cloud GSS contract covers these cybersecurity requirements.

SW - COTS: This column identifies contract language that applies to the purchase, installation, and/or operations and maintenance of commercial-off-the-shelf (COTS) software.

SW - Custom/GOTS: This column identifies contract language that applies to acquisitions under which custom software is to be developed and maintained specifically for the government or existing Government-off-the shelf (GOTS) is to be implemented.

Mobile Devices: This column identifies contract language that applies to acquisitions of mobile devices.

HW: This column identifies contract language that applies to hardware acquisitions.

Professional Services: This column identifies contract language that applies to professional services acquisitions (e.g., staff augmentation).

High Risk Contracts: This column identifies contract language that applies to product support or vendor services where they will be exposed to ICE sensitive data, work off site, or work performed out of the continental United States.

Requirement Characteristics:

SBU: This column identifies contract language that applies to acquisitions involving ICE Sensitive But Unclassified (SBU) information or access to SBU information.

Classified: This column identifies contract language that applies to acquisitions involving ICE Classified information or access to classified information.

Input Required: This column identifies contract language that requires updates to incorporate ICE-specific information. The place where specific information is needed will be in bracketed, italicized, red font.

Table 41: ICE Cybersecurity Contract Language Matrix

Doc
Section Number
Section Name
General Reqs
Cloud Svcs
SW - COTS
SW – Custom/ GOTS
Mobile Devices
HW
Prof Svcs
SBU
Classified
Input Req’d
Appendix:
A
B
C
D
E
F
G
ITAR
4.5.3.1
Compliance with DHS Security Policy Terms and Conditions
X

X

ITAR
4.5.3.2
Encryption Compliance
X
X
X
X
X

X

ITAR
4.5.3.3
Access to Unclassified Facilities, IT Resources, and Sensitive Information Requirement Clause Inclusion Instruction (Refers to HSAR 3052.204-70, Security requirements for unclassified IT resources)
X

X

ITAR
4.5.3.4
Security Review
X

X

ITAR
4.5.3.5
Interconnection Security Agreement (ISA)
X
X
X
X

X

ITAR
4.5.3.6
Required Protections for DHS Systems Hosted in Non-DHS Data Centers

X

X

ITAR
4.5.3.7
Supply Chain Risk Management
X
X
X
ITAR
4.5.3.8
Personal Identification Verification (PIV) Credential Compliance
X
X
X

X

X
X
ITAR
4.5.3.9
Security Requirements for Unclassified IT Resources Clause (refers to HSAR 3052.204-70)
X
X
X
ITAR
4.5.3.10
Contractor Employee Access Clause (use language from HSAR 3052.204-70 and alternates at 3052.204-71)

Note: This section provides guidance on applying HSAR 3052.204-71 (when to use the basic clause or the two alternate clauses included).

X

X
X
ITAR
4.5.4.1
Compliance with DHS Security Policy
X

X

ITAR
4.5.4.2
Encryption Compliance
X
X
X
X
X

X

ITAR
4.5.4.3
Handling or Processing of Classified Information
X
X
X
X

X

X
X
ITAR
4.5.4.4
Security Review Terms and Conditions
X

X

ITAR
4.5.4.5
Interconnection Security Agreement (ISA)
X
X
X
X

X

ITAR
4.5.4.6
Required Protections for DHS Systems Hosted in Non-DHS Data Centers
X
X

X

ITAR
4.5.4.7
Contractor Employee Access Clause (refers to Section 4.5.3.9)
X
X
X
HSAR
3052.204-70
Security requirements for unclassified technology resources
X
X
X
X
HSAR
3052.204-71
Contractor employee access
X
X
X
FR
Std Contract Language
FedRAMP IT Systems Security Requirements

X

X
X
X
FR
Std Contract Language
FedRAMP Privacy Requirements

X

X
X
FR
Std Contract Language
Sensitive Information Storage

X

X
X
FR
Std Contract Language
Protection of Information

X

X
X
FR
Std Contract Language
Security Classification

X

X
X
FR
Std Contract Language
Confidentiality and Nondisclosure

X

X
X
X
FR
Std Contract Language
Disclosure of Information

X

X
X
FR
Std Contract Language
FedRAMP Security Requirements Overview

X

X
X
FR
Std Contract Language
FedRAMP Security Compliance Requirements

X

X
X
FR
Std Contract Language
Required FedRAMP Policies and Regulations

X

X
X
FR
Std Contract Language
Assessment and Authorization

X

X
X
FR
Std Contract Language
Assessment of the System

X

X
X
FR
Std Contract Language
Authorization of System

X

X
X
FR
Std Contract Language
Reporting and Continuous Monitoring

X

X
X
X
FR
Control-Specific Clauses
Data Jurisdiction

Include if there are data location requirements (e.g., no foreign data centers)

X
X
X
FR
Control-Specific Clauses
FIPS 140-2 Validated Cryptography for Secure Communications

Note: This requirement is covered by ITAR Sections 4.5.3.2 and 4.5.4.2. The ITAR language takes precedence.

[X]

X
X
X
FR
Control-Specific Clauses
AU-10(5): Non-Repudiation

X

X
X
FR
Control-Specific Clauses
AU-11: Audit Record Retention

Note: This requirement is covered by ITAR Section 4.5.3.7.

[X]

X
X
FR
Control-Specific Clauses
IA-2(1), (2), (3) and (8): Identification and Authentication (Organizational Users) Multi-Factor Authentication

X

X
X
X
FR
Control-Specific Clauses
IA-8: Identification and Authentication (Non-Organizational Users)

X

X
X
FR
Control-Specific Clauses
IR-6: Incident Reporting Timeframes

Note: This language should be reconciled with the “Computer Incident Response Services Terms and Conditions” in ITAR Section 4.5.3.6

X

X
X
FR
Control-Specific Clauses
MP-5(2) and (4): Media Transport

X

X
X
X
FR
Control-Specific Clauses
PS-3: Personnel Screening

Note: This language is covered in HSAR Section 3052.204-71. The HSAR language takes precedence.

[X]

X
X
FR
Control-Specific Clauses
SC-7(1) – Boundary Protection (TIC)

X

X
X
FR
Control-Specific Clauses
SC-28 – Protection of Information at Rest

X

X
X
FR
Control-Specific Clauses
SI-5 – Security Alerts, Advisories, and Directives

X

X
X

BYODTK

Privacy Expectations
X
X
X

BYODTK

Sample #3, Mobile IT Device Policy, Section 4.3
X
X
X
n/a
n/a
Patch Management

Note: This language is extracted from ITAR 4.5.3.6 and 4.5.4.6 to apply to all SW and HW

X
X
X

X

X
X
HSAR
High Risk Contract Requirements.
Safeguarding of Sensitive Information and Information Technology Security and Privacy Training
X
X
X
X
X
X
X

General Cybersecurity Contract RequirementsIMPORTANT CAUTION Reference to contract requirements and clauses is current as of the date of publication. Due diligence should be exercised by all stakeholders in the process to confirm accuracy and applicability of the requirements identified in this Appendix.

In accordance with ITAR 4.5.4.1 – Compliance with DHS Security Policy Terms and Conditions.

The following requirement should be incorporated into all acquisition documents for CLASSIFIED REQUESTS:

Compliance with DHS Security Policy Terms and Conditions:

All hardware, software, and services provided under this task order must be compliant with DHS 4300B DHS Sensitive System Policy and DHS 4300B Sensitive Systems Handbook.

In accordance with ITAR 4.5.3.1 – Compliance with DHS Security Policy Terms and Conditions.

The following requirement should be incorporated into all acquisition documents for SBU REQUESTS:

Compliance with DHS Security Policy Terms and Conditions:

All hardware, software, and services provided under this task order must be compliant with DHS 4300A DHS Sensitive System Policy and DHS 4300A Sensitive Systems Handbook.

In accordance with ITAR 4.5.3.4 and ITAR 4.5.4.4 – Security Review The following clause should be incorporated into ALL acquisition documents:

Security Review Terms and Conditions The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford ICE, including the organization of ICE Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer Technical Representative (COTR), and other government oversight organizations, access to the Contractor's facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor will contact ICE Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to ICE. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of ICE data or the function of computer system operated on behalf of ICE, and to preserve evidence of computer crime.

In accordance with ITAR 4.5.3.7 – Supply Chain Risk Management The following clause should be incorporated into ALL acquisition documents, but exclude services-only contracts:

Supply Chain Risk Management Terms and Conditions The Contractors supplying the Government hardware and software shall provide the manufacturer's name, address, state and/or domain of registration, and the Data Universal Numbering System (DUNS) number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNs number of those suppliers must also be provided.

Subcontractors are subject to the same general requirements and standards as prime contractors. Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.

The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.

Contractors shall provide, implement, and maintain a Supply Chain Risk Management Plan that addresses internal and external practices and controls employed to minimize the risk posed by counterfeits and vulnerabilities in systems, components, and software.

The Plan shall describe the processes and procedures that will be followed to ensure appropriate supply chain protection of information system resources developed, processed, or used under this contract.

The Supply Chain Risk Management Plan shall address the following elements:

(i) How risks from the supply chain will be identified;

(ii) What processes and security measures will be adopted to manage these risks to the system or system components; and How the risks and associated security measures will be updated and monitored.

The Supply Chain Risk Management Plan shall remain current through the life of the contract or period of performance. The Supply Chain Risk Management Plan shall be provided to the Contracting Officer Representative (COR/CO) 30 days post award.

The Contractor acknowledges the Government's requirement to assess the Contractors Supply Chain Risk posture. The Contractor understands and agrees that the Government retains the right to cancel or terminate the contract, if the Government determines that continuing the contract presents a risk to national security.

The Contractor shall disclose, and the Government will consider, relevant industry standard certifications, recognitions and awards, and acknowledgments.

The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the CO. Contractors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.

The Contractor shall be excused from using new OEM (i.e. "grey market, "previously used) components only with formal Government approval. Such components shall be procured from their original source and have them shipped only from manufacturers authorized shipment points.

For software products, the contractor shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “end of life"). Software updates and patches must be made available to the government for all products procured under this contract.

Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.

All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the contract, the period of performance, or one calendar year from the date the activity occurred.

These records must be readily available for inspection by any agent designated by the U.S. Government as having the authority to examine them.

This transit process shall minimize the number of times en route components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments. The supplier, at the Government's request, shall be able to provide shipping status at any time during transit.

The Contractor is fully liable for all damage, deterioration, or losses incurred during shipping and handling, unless the damage, deterioration, or loss is due to the Government. The Contractor shall provide a packing slip which shall accompany each container or package with the information identifying the contract number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact. The contractor shall send a shipping notification to the intended government recipient or contracting officer. This shipping notification shall be sent electronically and will state the contract number, the order number, a description of the hardware/software being ship (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.

In accordance with HSAR 3052.204-70 - Security requirements for unclassified IT resources, with ITAR 4.5.3.3 – Access to Unclassified Facilities, IT Resources, and Sensitive Information Requirement Clause Inclusion Instruction, with ITAR 4.5.3.9 – Security Requirements for Unclassified Information Technology Resources Clause, with ITAR 4.5.4.6 – Required Protections for DHS Systems Hosted in Non-DHS Data Centers, and with ITAR 4.5.4.7 – Contractor Employee Access Clause . As prescribed in (HSAR) 48 CFR 3004.470-3 Contract clauses:

The following clause should be incorporated into ALL acquisition documents:

Security Requirements For Unclassified Information Technology Resources (JUN 2006) The Contractor shall be responsible for IT security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency’s mission.

The Contractor shall provide, implement, and maintain an IT Security Plan. This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.

Within [insert number of days] days after contract award, the contractor shall submit for approval its IT Security Plan, which shall be consistent with and further detail the approach contained in the offeror's proposal. The plan, as approved by the Contracting Officer (CO), shall be incorporated into the contract as a compliance document.

The Contractor’s IT Security Plan shall comply with Federal laws that include, but are not limited to, the Computer Security Act of 1987 (40 U.S.C. 1441 et seq.); the Government Information Security Reform Act of 2000; and the FISMA of 2002; and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130.

The security plan shall specifically include instructions regarding handling and protecting sensitive information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.

Examples of tasks that require security provisions include:

a) Acquisition, transmission or analysis of data owned by DHS with significant replacement cost should the contractor’s copy be corrupted; and

b) Access to DHS networks or computers at a level beyond that granted the public (e.g., such as bypassing a firewall).

At the expiration of the contract, the contractor shall return all sensitive DHS information and IT resources provided to the contractor during the contract, and certify that all non-public DHS information has been purged from any contractor-owned system. Components shall conduct reviews to ensure that the security requirements in the contract are implemented and enforced.

A.5.1 Contractor IT Security Accreditation The following clause should only be incorporated into acquisition documents involving contractor systems that house ICE data:

Contractor IT Security Accreditation Within 6 months after contract, the contractor shall submit written proof of IT Security accreditation to DHS for approval by DHS CO. Accreditation will proceed according to the criteria of DHS Sensitive System Policy Publication, 4300A (Version 2.1, July 26, 2004) or any replacement publication, which the CO will provide upon request. This accreditation will include a final security plan, risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan. This accreditation, when accepted by the CO, shall be incorporated into the contract as a compliance document. The contractor shall comply with the approved accreditation documentation.

1. In accordance with HSAR 3052.204-71 - Contractor Employee Access The following clause should be incorporated into ALL acquisition documents:

Contractor Employee Access (Sep 2012) Sensitive Information, as used in this clause, means any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy.

This definition includes the following categories of information:

a) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

b) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

c) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

d) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

e) “Information Technology Resources” include, but are not limited to, computer equipment, networking equipment, telecommunications equipment, cabling, network drives, computer drives, network software, computer software, software programs, intranet sites, and internet sites.

Contractor employees working on this contract must complete such forms as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability. Completed forms shall be submitted as directed by the CO. Upon the CO's request, the Contractor's employees shall be fingerprinted, or subject to other investigations as required. All Contractor employees requiring recurring access to Government facilities or access to sensitive information or IT resources are required to have a favorably adjudicated background investigation prior to commencing work on this contract unless this requirement is waived under Departmental procedures.

The CO may require the Contractor to prohibit individuals from working on the contract if the Government deems their initial or continued employment contrary to the public interest for any reason. Including, but not limited to, carelessness, insubordination, incompetence, or security concerns.

Work under this contract may involve access to sensitive information. Therefore, the Contractor shall not disclose, orally or in writing, any sensitive information to any person unless authorized in writing by the CO. For those Contractor employees authorized access to sensitive information, the Contractor shall ensure that these persons receive training concerning the protection and disclosure of sensitive information both during and after contract performance.

The Contractor shall include the substance of this clause in all subcontracts at any tier where the subcontractor may have access to Government facilities, sensitive information, or resources.

A.1 In accordance with ITAR 4.5.3.10 – Contractor Employee Access Clause (use language from HSAR 3052.204-70 and alternates at 3052.204-71).

[OCIO IAD Internal Notes If the contractor requires recurring access to government facilities, or will require access to sensitive information, as prescribed in (HSAR) 48 CFR 3004.470-3(b), insert a clause substantially the same as HSAR 3052.204-70 (extracted above), with appropriate alternates located in HSAR 3052.204-71.

The chart describes how to apply HSAR 3052.204-71 to acquisition documents:

Task requires recurring access to Government facilities or access to sensitive information

· Basic Clause (HSAR 3052.204-70) Requires access to IT resources

· Basic Clause + Alternate I No IT access, but access to sensitive information is limited to U.S. Citizens and lawful permanent residents

· Basic Clause + Alternate II End of OCIO IAD Internal Notes]

The following Alternate clauses should be evaluated for ALL acquisition documents:

A.7.1 Alternate I When the contract will require Contractor employees to have access to Information Technology (IT) resources, add the following paragraphs:

Contractor IT Resource Access (Sep 2012)

1) Before receiving access to IT resources under this contract the individual must receive a security briefing, which the Contracting Officer’s Technical Representative (COTR) will arrange, and complete any nondisclosure agreement furnished by DHS.

2) The Contractor shall have access only to those areas of DHS information technology resources explicitly stated in this contract or approved by the COTR in writing as necessary for performance of the work under this contract. Any attempts by Contractor personnel to gain access to any information technology resources not expressly authorized by the statement of work, other terms and conditions in this contract, or as approved in writing by the COTR, is strictly prohibited. In the event of violation of this provision, DHS will take appropriate actions with regard to the contract and the individual(s) involved.

3) Contractor access to DHS networks from a remote location is a temporary privilege for mutual convenience while the Contractor performs business for DHS Component. It is not a right, a guarantee of access, a condition of the contract, or Government Furnished Equipment (GFE).

4) Contractor access will be terminated for unauthorized use. The Contractor agrees to hold and save DHS harmless from any unauthorized use and agrees not to request additional time or money under the contract for any delays resulting from unauthorized use or access.

5) Non-U.S. citizens shall not be authorized to access or assist in the development, operation, management or maintenance of Department IT systems under the contract, unless a waiver has been granted by the Head of the Component or designee, with the concurrence of both the Department’s Chief Security Officer (CSO) and the Chief Information Officer (CIO) or their designees. Within DHS Headquarters, the waiver may be granted only with the approval of both the CSO and the CIO or their designees. In order for a waiver to be granted:

a) There must be a compelling reason for using this individual as opposed to a U. S. citizen; and

b) The waiver must be in the best interest of the Government.

6) Contractors shall identify in their proposals the names and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the contracting officer.

A.7.2 Alternate II When the Department has determined the contract will not require access to IT resources, but contract employee access to sensitive information or Government facilities must be limited to U.S. citizens and lawful permanent residents, add the following paragraphs:

Sensitive Information Limited to U.S. Citizens and Lawful Permanent Residents (JUN 2006)

1) Each individual employed under the contract shall be a citizen of the United States of America, or an alien who has been lawfully admitted for permanent residence as evidenced by a Permanent Resident Card (USCIS I-551). Any exceptions must be approved by the Department’s Chief Security Officer or designee.

2) Contractors shall identify in their proposals, the names, and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the contracting officer

A.8 In accordance with White House Digital Government BYODTK – Privacy Expectations The following passage should be included in ALL acquisition documents:

Privacy Expectations Government contractor employees do not have a right, nor should they have an expectation, of privacy while using Government provided devices at any time, including accessing the Internet and using e-mail and voice communications. To the extent that employees wish that their private activities remain private, they should avoid using the Government provided device for limited personal use. By acceptance of the government provided device, employees imply their consent to disclosing and/or monitoring of device usage, including the contents of any files or information maintained or passed -through that device.

A.9 In accordance with White House Digital Government BYODTK – Mobile Information Technology Device Policy The following passage should be included in ALL acquisition documents for Mobile devices:

Mobile Information Technology Device Usage Users who conduct official DHS ICE business on a mobile IT device must:

1. Sign the Remote Access and Mobile IT Device User Agreement Form.

1. Operate the device in compliance with this policy, all applicable federal requirements, and the DHS ICE Remote Access and Mobile Information Technology Guide.

1. Not process or access Classified information on the device.

1. Use only approved and authorized DHS ICE owned devices to physically attach to DHS ICE IT systems.

1. Store only the minimum amount, if any, of Personally Identifiable Information (PII) and electronic Protected Health Information (ePHI) necessary to do one’s work, and immediately delete the PII or ePHI when no longer needed. Users shall receive written approval from their supervisor before accessing, processing, transmitting, or storing DHS ICE Sensitive Information such as PII or ePHI.

1. Exercise extra care to preclude the compromise, loss, or theft of the device, especially during travel.

1. Immediately contact the DHS ICE Service Desk and their immediate supervisor if the IT device is lost, stolen, damaged, destroyed, compromised, or non-functional.

1. Abide by all federal and local laws for using the device while operating a motor vehicle (e.g. users are banned from text messaging while driving federally owned vehicles, and text messaging to conduct DHS ICE business while driving non-government vehicles).

Users who are issued a DHS ICE owned mobile IT device must also:

a) Comply with DHS 4300A Sensitive Systems Handbook Attachment Q.

b) Not disable or alter security features on the device.

c) Only use the DHS ICE owned device for official government use and limited personal use.

d) Reimburse the OCIO for any personal charges incurred that are above the established fixed cost for the Agency’s use of the device (e.g. roaming charges incurred for personal calls).

e) Be required to reimburse DHS ICE if the mobile IT device is lost, stolen, damaged or destroyed as a result of negligence, improper use, or willful action on the employee’s part and if determined by ICE.

Cloud Services Contract RequirementsIMPORTANT CAUTION Reference to contract requirements and clauses is current as of the date of publication. Due diligence should be exercised by all stakeholders in the process to confirm accuracy and applicability of the requirements identified in this Appendix.

In accordance with ITAR 4.5.3.2 – Encryption Compliance The following requirement should be incorporated into all acquisition documents for SBU REQUESTS:

Encryption Compliance Terms and Conditions If encryption is required, the following methods are acceptable for encrypting sensitive information:

a) FIPS 197 (Advanced Encryption Standard (AES)) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2.

b) National Security Agency (NSA) Type 2 or Type 1 encryption.

c) Public Key Infrastructure (PKI) (see paragraph 5.5.2.1 of the Department of Homeland Security (DHS) IT Security Program Handbook (DHS Management Directive (MD) 4300A) for Sensitive Systems).

In accordance with ITAR 4.5.3.5 and ITAR 4.5.4.5 – Interconnection Security Agreement (ISA) If the service requested requires a connection to a non-DHS/ICE, Contractor systems, or DHS/ICE system of different sensitivity, the following requirement should be incorporated into ALL acquisition documents:

ISA Terms and Conditions Interconnections between DHS/ICE and non-DHS/ICE IT systems shall be established only through controlled interfaces and via approved service providers. The controlled interfaces shall be authorized at the highest security level of information on the network. Connections with other Federal agencies shall be documented based on interagency agreements; memoranda of understanding, service level agreements or interconnection security agreements.

In accordance with ITAR 4.5.3.6 and ITAR 4.5.4.6 – Required Protections for DHS/ICE Systems Hosted in Non-DHS/ICE Data Centers The following terms and conditions should be included for ALL information systems which are hosted, operated, maintained, and used on behalf of DHS/ICE at non-DHS/ICE facilities:

1) Security Authorization Terms and Conditions A Security Authorization of any infrastructure directly in support of DHS/ICE information system shall be performed as a general support system (GSS) prior to DHS/ICE occupancy to characterize the network, identify threats, identify vulnerabilities, analyze existing and planned security controls, determine likelihood of threat, analyze impact, determine risk, recommend controls, perform remediation on identified deficiencies, and document the results. The Security Authorization (SA) shall be performed in accordance with DHS/ICE Security Policy and the controls provided by the hosting provider shall be equal to or stronger than the FIPS 199 security categorization of DHS/ICE information system.

At the beginning of the contract, and upon request thereafter (generally at the deployment of a new system or renewal of a System Authority to Operate), the contractor/Cloud Service Provider (CSP) shall provide the results of an independent assessment and verification of security controls. The independent assessment and verification shall apply the same standards that DHS/ICE applies in the SA process of its information systems. Any deficiencies noted during this assessment shall be provided to the COR for entry into DHS/ICE POA&M Management Process. ICE shall use DHS' POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies shall be corrected within the timeframes dictated by DHS/ICE POA&M Management Process. CSP procedures shall be subject to periodic, unannounced assessments by DHS/ICE officials. The documented physical aspects associated with CSP activities shall also be subject to such assessments. Inspections of CSP physical facilities will be scheduled in advance and coordinated with the provider in accordance with their facility procedures.On a periodic basis, DHS and its Components, including DHS Office of Inspector General, may choose to evaluate any or all of the security controls implemented by the contractor under these clauses. Evaluation could include, but is not limited to vulnerability scanning. The DHS and its Components reserve the right to conduct audits at their discretion. With ten working days’ notice, at the request of the Government, the CSP and reseller shall fully cooperate and facilitate in a Government-sponsored security control assessment at each location wherein DHS/ICE information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of DHS/ICE, including those initiated by the Office of the Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) determined by DHS/ICE in the event of a security incident.

2) Enterprise Security Architecture Terms and Conditions

3) The CSP shall utilize and adhere to DHS/ICE Enterprise Security Architecture in accordance with applicable laws and DHS/ICE policies to the satisfaction of DHS/ICE COR. Continuous Monitoring Terms and Conditions The CSP shall participate in the DHS/ICE Continuous Monitoring methodologies and, shall provide a Continuous Monitoring capability over their resources as required by FedRAMP. The DHS Chief Information Security Officer (CISO) issues annual updates to its Continuous Monitoring requirements via the Annual Information Security Performance Plan. At a minimum, the CSP shall adhere to all ITAR and FedRAMP continuous monitoring requirements and ensure that DHS/ICE can implement and integrate the following processes:

a) Asset Management

b) Vulnerability Management

c) Configuration Management

d) Malware Management

e) Log Integration

f) Security Information Event Management (SIEM) Integration

g) Patch Management

h) Providing near-real-time security status information to DHS/ICE SOC Specific Protections Terms and Conditions

i) Specific protections that shall be provided by the CSP include, but are not limited to the following:

Specific Operations Terms and Conditions The Contractor shall operate a SOC to provide security for the below mentioned services. The CSP shall support regular reviews with DHS/ICE Information Security Office to coordinate and synchronize the security posture of the CSP hosting facility with that of DHS Data Centers. The SOC personnel shall provide 24x7x365 staff to monitor the network and all of its devices. The CSP staff shall also analyze the information generated by the devices for security events, respond to real-time events, correlate security device events, and perform continuous monitoring. It is recommended that the CSP staff shall also maintain a trouble ticket system in which incidents and outages are recorded. In the event of an incident, the CSP facility SOC shall adhere to the incident response plan.

4) Computer Incident Response Services Terms and Conditions The CSP shall provide Computer Incident Response Team (CIRT) services. The CSP shall adhere to the standard Incident Reporting process as determined by the Component and is defined by a DHS/ICE-specific incident response plan that adheres to DHS/ICE policy and procedure for reporting incidents. The CSP shall conduct Incident Response Exercises to ensure all personnel are familiar with the plan. The CSP shall notify DHS/ICE SOC of any incident in accordance with the Incident Response Plan and work with DHS/ICE throughout the incident duration.

5) Intrusion Detection Systems and Monitoring Terms and Conditions The Contractor shall provide the design, configuration, implementation, and maintenance of the sensors and hardware that are required to support the NIDS solution. The contractor is responsible for creating and maintaining the NIDS rule sets for their facility(s). The NIDS solution should provide real-time alerts. These alerts and other relevant information shall be located in a central repository. The NIDS shall operate 24x7x365. A summary of alerts shall be made available to DHS/ICE as requested. If an abnormality or anomaly is identified, the contractor shall notify the appropriate DHS/ICE point of contact in accordance with the incident response plan.

6) Physical and Information Security and Monitoring Terms and Conditions The CSP shall provide a facility using appropriate protective measures to provide for physical security. All facilities will be located within the United States. The CSP shall maintain a process to control physical access to all DHS/ICE IT assets. DHS/ICE IT Assets shall be monitored 24x7x365. A summary of unauthorized access attempts shall be reported to the appropriate DHS/ICE security office.

7) Vulnerability Assessments Terms and Conditions The CSP and reseller shall provide all information from any managed device to DHS/ICE, as requested, and shall assist, as needed, to perform periodic vulnerability assessments of the network, operating systems, and applications to identify vulnerabilities and propose mitigations. Vulnerability assessments shall be included as part of compliance with the continuous monitoring of the system.

8) Anti-malware (e.g., virus, spam) Terms and Conditions The CSP shall design, implement, monitor, and manage to provide comprehensive anti-malware service. The CSP shall provide all maintenance for the system providing the anti-malware capabilities to include configuration, definition updates, when changes are required. A summary of alerts shall be reported to DHS/ICE SOC in weekly status report. If an abnormality or anomaly is identified, the CSP shall notify the appropriate DHS/ICE point of contact in accordance with the incident response plan.

9) Log Retention Terms and Conditions Log files for all infrastructure devices, physical access, and anti-malware should be retained online for 180 days and offline for three years.

In accordance with ITAR 4.5.3.8 – Personal Identification Verification (PIV) Credential Compliance The following requirement should be incorporated into ALL acquisition documents:

Personal Identification Verification (PIV) Credential Compliance Terms and Conditions

a) Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting HSPD-12 PIV credentials as a method of identity verification and authentication.

b) Procurements for software products or software developments shall be compliant by accepting PIV credentials as the common means of authentication for access for federal employees and contractors.

c) PIV-enabled information systems must demonstrate that they can correctly work with PIV credentials by responding to the cryptographic challenge in the authentication protocol before granting access.

d) If a system is identified to be non-compliant with HSPD-12 for PIV credential enablement, a remediation plan for achieving HSPD-12 compliance shall be required for review, evaluation, and approval by the CISO.

In accordance with ITAR 4.5.4.2 – Encryption Compliance The…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .