Attachment VII - Requirements Traceability Matrix (TRP) - Final 02-22-2022.pdf
PDF 1 MB Posted
- Attached to
- DHS HSPD-12 IDMS Technology Refresh Project Federal contract opportunity
- Solicitation number
- 70RDAD22R00000001
About this file
This is a solicitation for an indefinite delivery indefinite quantity contract to provide a Homeland Security Presidential Directive 12-compliant identity enrollment system and credential management system solution for the Department of Homeland Security's identity management system technology refresh project. The solution will include initial integration and configuration services. The Office of Procurement Operations within DHS's Office of the Chief Security Officer will seek to refresh its existing identity management infrastructure with a new enrollment system and credential management system, integrated and configured by the selected contractor. Services will include replacement of aging identity proofing and issuance systems with modern solutions compliant with current standards for identity assurance levels 1 through 3.
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Requirement ID
FRQ-19.000
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.001 General Servers Threshold Demonstration Bus&Non-Func All servers shall support the ability to run in a high availability (HA) configuration.
FRQ-19.001.01 General Servers Threshold Demonstration Bus&Non-Func All servers shall support geographic separation of instances within the HA cluster.
FRQ-19.001.02 General Servers Threshold Demonstration Bus&Func All servers shall support load balancing across all instances of the HA cluster database.
FRQ-19.001.03 General Servers Threshold Demonstration Non-functional All servers shall support an orderly transition when an instance goes offline.
FRQ-19.001.04 General Servers Threshold Demonstration Functional All system server components shall support automatic recovery and resynchronization of an instance when it is brought back online.
FRQ-19.001.05 General General Threshold Demonstration Non-functional All system server components shall support the ability to run in a high availability configuration.
FRQ-19.001.06 General General Threshold Demonstration Non-functional All servers shall support fault tolerance.
FRQ-19.001.07 General Operations Threshold Demonstration Non-functional The system shall support 99.95% operational availability, measured monthly in a summary compliance report.
FRQ-19.001.08 General General Threshold Demonstration Non-functional All applications shall be cluster aware.
FRQ-19.002 General Policy/Privacy Threshold Demonstration Functional All data within the system shall be encrypted at rest, using Advanced
Encryption Standard (AES) with a minimum key length of 256 bits.
FRQ-19.003 General Cryptography Threshold Documentation Non-functional The system shall use cryptographic software, hardware, and algorithms that are certified under FIPS 140-2.
FRQ-19.003.01 General Cryptography Threshold Documentation Non-functional The system shall support Deterministic Random Bit Generators (DRBG) for all random number generation.
FRQ-19.003.02 General Cryptography Threshold Documentation Non-functional The system shall support SHA-256 at a minimum.
FRQ-19.003.03 General Cryptography Threshold Documentation Non-functional The system shall support AES for all symmetric encryption using a key strength of 256 bits at a minimum.
FRQ-19.003.04 General Cryptography Threshold Documentation Non-functional The system shall support RSA 2048 at a minimum.
FRQ-19.003.05 General Cryptography Threshold Documentation Non-functional The system shall support ECC P-256 at a minimum.
FRQ-19.003.06 General Cryptography Threshold Documentation Non-functional The system shall use DHS approved cryptographic protocols (e.g., TLS 1.2, TLS 1.3).
FRQ-19.003.07 General Cryptography Threshold Documentation Bus&Non-Func All cryptography shall run in FIPS certified mode per DHS 4300a.
FRQ-19.003.08 General PKI Threshold Demonstration Functional All asymmetric keys shall be certified by DHS PKI Services where possible
(i.e. DHS issued certificates).
FRQ-19.003.09 General Cryptography Threshold Demonstration Functional The system shall support crypto agility inclusive of the following:
1. Hashing algorithms
2. Symmetric algorithms
3. Asymmetric algorithms
4. Post-quantum algorithms
FRQ-19.003.10 General Cryptography Threshold Demonstration Functional Post-quantum algorithms shall be supported by calendar year end 2023 for Test and Evaluation purposes.
General RTM
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.004 General Security Threshold Demonstration Non-functional The system shall be designed to run in a Confidentiality HIGH, Integrity HIGH, Availability HIGH, configuration in accordance with FIPS 199.
FRQ-19.004.01 General Security Threshold Demonstration Non-functional The FIPS 199 H-H-H configuration shall also meet DHS security/monitoring requirements.
FRQ-19.005 General Operations Threshold Demonstration Functional The system shall be modular to support DHS selected deployment options.
FRQ-19.005.01 General Servers Threshold Demonstration Functional All servers shall run in a virtual machine environment.
FRQ-19.005.02 General Operations Threshold Demonstration Non-functional The system shall run on GFE hardware.
FRQ-19.005.03 General Servers Threshold Demonstration Non-functional The system shall be able to run on DHS selected Cloud, IaaS, or PaaS providers.
FRQ-19.006 General Change control Threshold Demonstration Non-functional The vendor shall provide the government all installation binaries and
GOTS source code for the system and associated dependencies.
FRQ-19.006.01 General Change control Threshold Demonstration Bus&Non-Func The vendor shall provide a DHS approved method providing secure chain of custody for delivery of all source code or binaries used for installation, update and associated dependencies.
FRQ-19.007 General Change control Threshold Demonstration Non-functional The vendor shall support DHS approved installation management servers for installation at DHS CIO Cloud Hosting facility named “Cirrus” (Microsoft Azure environment meeting FIPS 199 H-H-H controls and DHS security/monitoring requirements).
FRQ-19.007.01 General Change control Threshold Demonstration Functional The vendor shall support delivery of software to DHS within the DHS installation management server.
FRQ-19.007.02 General Change control Threshold Demonstration Functional The installation management server shall receive and store all DHS SELC managed change request updates to vendor software.
FRQ-19.007.03 General Change control Threshold Demonstration Functional The installation management server shall support initial installation of DHS approved images of vendor software on GFE hardware either immediately or on a schedule.
FRQ-19.007.04 General Change control Threshold Demonstration Functional The installation management server shall allow DHS to select which change requests to deploy and install on live systems (servers and workstations) either immediately or on a schedule.
FRQ-19.007.05 General Change control Threshold Demonstration Functional The installation management server shall allow DHS to select which live systems (servers or workstations) are to be updated either individually, by DHS Component, by geographic region, or all of DHS.
FRQ-19.008 General Cryptography Threshold Demonstration Functional Where possible, DHS issued certificates shall be used to secure the media and the transmission of all software, drivers, binaries, configurations for the solution.
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.009 General Scalability Threshold Demonstration Non-functional The system shall provide a database that meets DHS requirements, including:
1. The system shall support a minimum of 2,000,000 identities.
2. The system shall support a minimum of 500 DHS Credentialling Facilities.
3. The system shall support a minimum of 1,500,000 credentials.
4. The system shall support a minimum of 500 in process enrollments/issuances.
5. The system shall be designed to minimize transaction times (as measured from submit request to received response).
6. The system shall support sub-second response on all transactions (as measured from submit request to received response).
7. The system shall support DHS Customizable performance metrics collection.
8. The system shall support DHS Customizable metrics reporting.
FRQ-19.009.01 General Database Threshold Demonstration Functional The system shall support database tuning on a DHS selected schedule, including:
1. Tuning shall have minimal operational performance impact.
2. Tuning shall support data deconfliction.
3. Tuning shall support data normalization.
4. Tuning shall support data re-indexing.
FRQ-19.009.02 General Security Threshold Demonstration Functional The system shall support role based access control (RBAC).
FRQ-19.009.02.01 General Security Threshold Demonstration Functional The system's RBAC shall enforce hierarchical access to data.
FRQ-19.009.02.02 General Security Threshold Demonstration Functional The solution shall provide RBAC down to the data element as to who can view, create, modify, or delete, all data elements.
FRQ-19.009.02.03 General Security Threshold Demonstration Functional The system's RBAC shall support administrative roles that can assign user roles within the system.
FRQ-19.009.02.04 General Security Threshold Demonstration Functional RBAC shall support users with multiple roles.
FRQ-19.009.02.04.01 General Security Threshold Demonstration Functional User access (e.g., to data, workflows, reports, administrative functions) shall be constrained by all roles assigned to that user.
FRQ-19.009.02.05 General Security Threshold Demonstration Functional RBAC shall provide multiple control capabilities.
FRQ-19.009.02.05.01 General Security Threshold Demonstration Functional RBAC shall provide Process Roles to include:
Sponsor Enrollment Official DCF Manager PIV-O Lead Admin
ISSO
Privacy Official Registrar Reports Issuance Official
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.009.02.05.02 General Security Threshold Demonstration Functional RBAC shall provide controlled organizational data access, to include:
Global access Named Component access (e.g., HQ, USCIS, CBP, TSA, USSS)
FRQ-19.009.02.05.03 General Security Threshold Demonstration Functional RBAC shall provide access by Credential Type, to include:
PIV
PIV-I
PIV-O
FAC
Derived PIV
DAC
FIDO
TPM
Virtual Smart Card mDL
FRQ-19.009.02.05.03 General Security Threshold Demonstration Functional RBAC roles shall be controlled on a per user basis using a GUI, e.g., check boxes.
FRQ-19.010 General Standards Threshold Demonstration Bus&Non-Func The system shall support role separation in accordance with FIPS 201, enrollment, identity record management and credentialing.
FRQ-19.011 General Policy/Privacy Threshold Documentation Non-functional The system shall support the NIEM namespace for external data transfer.
FRQ-19.011.01 General Policy/Privacy Threshold Documentation Non-functional When NIEM does not support schema data elements, system supplier shall work with DHS to submit to NIEM and gain approval.
FRQ-19.012 General Security Threshold Demonstration Functional All routine access to the system shall use PIV PKI-Auth at a minimum.
FRQ-19.013 General Security Threshold Demonstration Functional All privileged access to any system component shall use DHS CyberArk or DHS Computer Associates Privilege Access Manager (CA/PAM).
FRQ-19.014 General Standards Threshold Demonstration Non-functional All UUID generators shall be in compliance with RFC 4122 UUID Version 1, 4 or 5.
FRQ-19.014.01 General Standards Threshold Demonstration Non-functional DHS shall approve vendor proposed version for UUIDs.
FRQ-19.015 General Security Threshold Demonstration Bus&Non-Func The system shall support DHS and Other Government Agency's (OGA) PIV credentials for Federal Enterprise interoperability.
FRQ-19.016 General Standards Threshold Demonstration Bus&Non-Func Technical solution must meet current FIPS 201, associated NIST special publications, OMB guidance, FPKI policies, and DHS policies and directives.
FRQ-19.017 General General Threshold Documentation Bus&Non-Func The vendor and solution shall support and comply with DHS processes.
FRQ-19.017.01 General Standards Threshold Documentation Bus&Non-Func The vendor shall support System Engineering Life Cycle (SELC) Waterfall model.
FRQ-19.017.01 General Standards Threshold Documentation Bus&Non-Func The vendor shall support System Engineering Life Cycle (SELC) Agile model.
FRQ-19.017.03 General Security Threshold Documentation Bus&Non-Func The vendor shall support DHS activities to satisfy Security Authorization.
FRQ-19.017.04 General Standards Threshold Documentation Bus&Non-Func The solution shall support DHS Enterprise Architecture (EA).
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.017.05 General Policy/Privacy Threshold Documentation Bus&Non-Func The solution shall support credential policies and processes (e.g., PIV, PIV- I, PIV-O, FAC, Derived PIV, DAC, FIDO, TPM, virtual smart card, mDL)
FRQ-19.017.06 General Policy/Privacy Threshold Documentation Bus&Non-Func The solution shall enforce DHS PKI Policies.
FRQ-19.017.07 General Auditing Threshold Documentation Bus&Non-Func The vendor shall support DHS activities to pass US Common Policy and
DHS Registration Practice Statement Annual Audit.
FRQ-19.017.08 General Policy/Privacy Threshold Documentation Bus&Non-Func The solution shall support ESSD Privacy Impact Assessment (PIA) FRQ-19.017.09 General Policy/Privacy Threshold Documentation Bus&Non-Func The solution shall support ESSD System of Records Notice (SORN)
FRQ-19.017.10 General Policy/Privacy Threshold Documentation Bus&Non-Func The vendor shall support DHS activities to achieve and maintain system and security authorizations.
FRQ-19.017.10.01 General Policy/Privacy Threshold Documentation Bus&Non-Func The vendor shall support DHS activities to achieve and maintain a Type Security Authorization.
FRQ-19.017.10.02 General Policy/Privacy Threshold Documentation Bus&Non-Func The vendor shall support DHS activities to achieve and maintain a system authorization package.
FRQ-19.018 General Workflow Threshold Demonstration Bus&Func The solution shall support DHS configurable workflow management and field manipulation.
FRQ-19.018.01 General Workflow Threshold Demonstration Functional Field manipulation shall be role based.
FRQ-19.018.01.01 General Workflow Threshold Demonstration Functional Field creation shall be role based.
FRQ-19.018.01.02 General Workflow Threshold Demonstration Functional Field editing shall be role based.
FRQ-19.018.02 General Workflow Threshold Demonstration Functional The workflow shall support configurable field based input validation.
FRQ-19.018.03 General Workflow Threshold Demonstration Functional The workflow shall support configurable required fields.
FRQ-19.018.04 General Workflow Threshold Demonstration Functional The workflow shall support input validation rules.
FRQ-19.018.04.01 General Workflow Threshold Demonstration Bus&Func Input validation rules shall be customizable by DHS.
FRQ-19.018.04.02 General Workflow Threshold Demonstration Functional Input validation rules shall ensure required fields are not blank.
FRQ-19.018.04.03 General Workflow Threshold Demonstration Functional Input validation rules shall enable blank (not filled in) optional fields.
FRQ-19.018.05 General Workflow Threshold Demonstration Functional The workflow shall support configurable optional fields.
FRQ-19.018.06 General Workflow Threshold Demonstration Functional The workflow shall support drop down lists in fields.
FRQ-19.019 General Workflow Threshold Demonstration Functional The solution shall provide workflow process Step Status FRQ-19.019.01 General Workflow Threshold Demonstration Functional The workflow shall communicate to the user the status of process tasks.
FRQ-19.020 General Security Threshold Demonstration Functional The solution shall monitor individual user access to the system.
FRQ-19.020.01 General Security Threshold Demonstration Functional When an individual user with a system role has not accessed the system within a DHS configurable number of days, their account shall be locked.
FRQ-19.020.01.01 General Security Threshold Demonstration Functional The default number of days shall be 45.
FRQ-19.020.01.02 General Security Threshold Demonstration Functional The user shall receive an error message stating locked due to inactivity.
FRQ-19.020.02 General Security Threshold Demonstration Functional An individual user account shall be locked after a configurable number of failed login attempts.
FRQ-19.020.02.01 General Security Threshold Demonstration Functional Consecutive login attempts, after the first three attempts, shall have a random, increasing delay timer between attempts.
FRQ-19.020.03 General Security Threshold Demonstration Functional An individual's active session shall automatically close when there has not been keyboard or mouse activity for 15 minutes.
Source Selection Information -- See FAR 2.101 and 3.104. DRAFT Page 5 of 13
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.021 General Web based/Open APIs
Threshold Demonstration Functional Web services shall be capable of scheduling data transfer using rules-based processes
FRQ-19.022 General Policy/Privacy Threshold Documentation Bus&Non-Func The solution shall be manufactured in the United States.
FRQ-19.022.01 General Policy/Privacy Threshold Documentation Bus&Non-Func The solution shall be Buy American Act (BAA) certified.
FRQ-19.022.02 General Policy/Privacy Threshold Documentation Bus&Non-Func When the solution or components of the solution are not manufactured within the United States, the solution or its components shall be Trade Agreement Act (TAA) certified.
FRQ-19.023 General Security Threshold Demonstration Functional The system shall provide the ability to protect VIP data from unauthorized disclosure or access and to prevent users from accessing their own data.
FRQ-19.023.01 General Security Threshold Demonstration Functional The solution shall monitor users with a system role viewing VIP/their own data.
FRQ-19.023.02 General Security Threshold Demonstration Functional The solution shall alert system administrators once a user accesses VIP data.
FRQ-19.023.02.01 General External interfaces Threshold Demonstration Functional The solution shall alert Insider Threat once a user accesses VIP data.
FRQ-19.023.03 General Security Threshold Demonstration Functional The solution shall alert system administrators once a user accesses their own data.
FRQ-19.023.03.01 General External interfaces Threshold Demonstration Functional The solution shall alert Insider Threat once a user accesses their own data.
FRQ-19.023.04 General Security Threshold Demonstration Functional The solution shall lock a user's account after accessing their own record.
FRQ-19.023.05 General Security Threshold Demonstration Functional The solution shall close the user's session after accessing their own record, with a DHS configurable notice screen.
FRQ-19.024 General Operations Threshold Demonstration Functional All elements of the system shall be capable of being remotely diagnosed, both CONUS and OCONUS, for problems.
FRQ-19.025 General General Threshold Demonstration Bus&Non-Func The solution shall communicate over and through existing DHS firewalls, networks, and circuits.
FRQ-19.025.01 General Communications Threshold Demonstration Functional The ES, eIDMS, and CMS solution shall use the following DHS approved encrypted protocols-TCP/IP port numbers:
1. TLS/Web Services (port 443)
2. TLS/HTTP (port 443)
3. SSH (port 22)
4. SFTP (port 22)
5. TLS/RDP (port 3389)
6. Vendor required protocols/ports as approved by DHS
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.025.02 General Communications Threshold Demonstration Functional The solution shall communicate with external systems using the following DHS approved encrypted and unencrypted protocols-TCP/IP port numbers:
1. Web Services (port 80)
2. TLS/Web Services (port 443)
3. HTTP (port 80)
4. TLS/HTTP (port 443)
5. SSH (port 22)
6. SFTP (port 22)
7. SMTP (port 25)
8. Secure SMTP (port 587)
9. LDAP (port 389)
10. LDAP (port 636)
11. TLS/RDP (port 3389)
12. RDP (port 3389)
13. External system required protocols/ports as approved by DHS.
FRQ-19.025.03 General Communications Threshold Demonstration Functional The solution shall support constrained bandwith conditions.
FRQ-19.026 General Policy/Privacy Threshold Demonstration Non-functional The solution shall transfer all data in a secure manner using DHS approved cryptographic protocols.
FRQ-19.027 General Training Threshold Documentation Bus&Non-Func The vendor shall provide in-person training and training materials, in close coordination with DHS, for all versions of the delivered solution.
FRQ-19.027.01 General Training Threshold Documentation Non-functional The vendor shall provide in depth in person training to include the following:
1. Configuration of the solution (internal & external)
2. Operations of the solution (internal & external)
3. Interface (internal & external)
4. Training sessions and materials to DHS selected trainers for train-the-trainer.
FRQ-19.027.02 General Training Threshold Documentation Non-functional The vendor shall provide User's Manuals for the solution.
FRQ-19.027.03 General Training Threshold Documentation Non-functional The vendor shall provide Operations Manuals for the solution.
FRQ-19.027.04 General Training Threshold Documentation Non-functional The vendor shall provide remote video training.
FRQ-19.027.05 General Training Threshold Documentation Non-functional The vendor shall provide Job Aids to include:
1. User assistance for common tasks.
2. Quick reference for common tasks.
3. Common error resolution
4. System build
FRQ-19.027.06 General Training Threshold Documentation Non-functional The vendor shall provide Administration Manuals (both privileged and non-privileged users) for the solution.
FRQ-19.027.07 General Training Threshold Documentation Non-functional The vendor shall provide Configuration Manuals for the solution.
FRQ-19.027.08 General Training Threshold Documentation Non-functional The vendor shall provide Installation Manuals for the solution.
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.027.09 General Training Threshold Documentation Non-functional The vendor shall provide sufficient training and documentation for the government to build the entire solution from the ground up.
FRQ-19.028 General Workstations Threshold Demonstration Bus&Non-Func Workstations for the solution shall run on GFE hardware with a DHS provided desktop software image.
FRQ-19.028.01 General Workstations Threshold Demonstration Non-functional The solution shall support thin clients FRQ-19.028.02 General Workstations Objective Demonstration Non-functional The solution shall support zero clients FRQ-19.028.04 General Workstations Objective Demonstration Bus&Non-Func Clients shall be installable without administrative privilege.
FRQ-19.028.05 General Workstations Objective Demonstration Bus&Non-Func Thick/thin/zero clients shall not embed smart card drivers.
FRQ-19.028.06 General Workstations Threshold Demonstration Non-functional The solution shall support USB 2.x for thin clients peripheral implementation FRQ-19.028.07 General Workstations Threshold Demonstration Non-functional The solution shall support USB 3.x for thin clients peripheral implementation FRQ-19.028.08 General Workstations Threshold Demonstration Non-functional The solution shall support a minimum of eight simultaneously connected
USB devices.
FRQ-19.028.08.01 General Workstations Threshold Demonstration Non-functional The solution shall support simultaneous bi-directional communication to all USB connected devices.
FRQ-19.028.09 General Workstations Threshold Demonstration Non-functional The solution shall support multiple monitors FRQ-19.028.10 General Workstations Objective Demonstration Bus&Non-Func The solution shall support workstations using virtualized terminal emulation (Citrix VDI, terminal services, VMware DaaS) FRQ-19.028.10.01 General Workstations Objective Demonstration Non-functional The solution shall support WYSE Thin OS firmware FRQ-19.028.10.02 General Workstations Objective Demonstration Non-functional The solution VD shall support Microsoft Windows based thin/zero clients
FRQ-19.028.10.03 General Workstations Objective Demonstration Functional The solution shall support PIV PKI-AUTH for authentication to the VDI client device
FRQ-19.028.10.03.01 General Workstations Objective Demonstration Functional The solution shall, as required by Role, support PIV PKI-AUTH+BIO for authentication to the VDI client device
FRQ-19.028.10.04 General Workstations Objective Demonstration Non-functional The solution shall support a backend VDI environment of all client machines and associated peripherals
FRQ-19.028.10.05 General Workstations Objective Demonstration Non-functional The solution shall support threat detection software on the VDI thin client itself independent of the OS
FRQ-19.028.10.06 General Workstations Objective Demonstration Non-functional The solution shall provide VDI thin/zero clients to support the system where possible, to replace traditional workstations.
FRQ-19.029 General Security Threshold Demonstration Bus&Func The system shall be integrated with DHS standard system monitoring tools, including:
1. Security monitoring at the Security Operations Center (SOC)
2. Performance monitoring at the Network Operations Center (NOC)
3. Continuous Diagnostics and Mitigation monitoring (CDM)
4. Standard agents (e.g., SNMP, syslog to Splunk)
5. Proprietary agents (e.g., clients installed and integrated with solution)
FRQ-19.030 General General Threshold Demonstration Non-functional Vendor shall use DHS approved system change, vulnerability, and antivirus, scanning tools on all provided system components.
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.030.01 General General Threshold Demonstration Bus&Non-Func All logs generated by the system analysis tool shall be provided to the assigned Information System Security Officer (ISSO) for review.
FRQ-19.030.02 General General Threshold Demonstration Business Vendor shall remediate all issues identified by the ISSO or System Owner.
FRQ-19.030.02.01 General General Threshold Demonstration Business Vendor shall mitigate all issues identified by the ISSO or System Owner that can not be remediated in the timeframe established by the ISSO or System Owner.
FRQ-19.031 General General Threshold Documentation Bus&Non-Func All user interfaces, training videos, and delivered solutions shall meet the accessibility requirements stipulated in Section 508.
FRQ-19.032 General PKI Threshold Demonstration Functional The solution shall support full path discovery and validation of certificates to a configurable root CA trust store.
FRQ-19.032.01 General PKI Threshold Demonstration Functional The solution shall check the expiration status of certificates for the entire trust chain.
FRQ-19.032.02 General PKI Threshold Demonstration Functional The solution shall be capable of checking the revocation status of certificates for the entire trust chain using OCSP.
FRQ-19.032.03 General PKI Threshold Demonstration Functional The solution shall be capable of checking the revocation status of certificates for the entire trust chain using CRL.
FRQ-19.032.04 General PKI Objective Demonstration Functional The solution shall be capable of checking the trust chain status of certificates using SCVP.
FRQ-19.032.05 General PKI Objective Demonstration Functional The solution shall be capable of full path validation for configured policy OIDs (e.g., PIV, PIV-I, Non-Federal Issued (NFI) credentials).
FRQ-19.033 General Reporting Threshold Demonstration Functional The solution shall provide a robust report generation capability.
FRQ-19.033.01 General Reporting Threshold Demonstration Functional The solution shall provide a report server with the ability to:
1. Provide a graphical user interface to create and manage reports
2. Provide a graphical user interface to manage role based access to reports
3. Provide a capability to query reporting data from a remote system
4. Provide interfaces to receive reporting data from remote systems
5. Provide Canned reports
6. Provide Ad hoc reports
FRQ-19.033.02 General Reporting Threshold Demonstration Functional The solution shall provide the ability for DHS to configure reports.
FRQ-19.033.03 General Reporting Threshold Demonstration Functional The solution shall provide the ability for DHS to create/modify/delete reports.
FRQ-19.033.04 General Reporting Threshold Demonstration Functional The solution shall provide role based access control for reports.
FRQ-19.033.05 General Reporting Threshold Demonstration Functional Role based access shall support control of system-wide reports.
FRQ-19.033.06 General Reporting Threshold Demonstration Functional Role based access shall support control of domain specific information
(e.g., Component level, Enrollment Official level, ISSO level, VIP information) reports.
FRQ-19.033.07 General Reporting Threshold Demonstration Functional The system shall provide read-only reporting capabilities.
FRQ-19.034 General Logging Threshold Demonstration Functional The solution shall provide verbose logging and features.
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.034.01 General Logging Threshold Demonstration Functional The solution shall log a user moving to a new section in a workflow.
FRQ-19.034.02 General Logging Threshold Demonstration Functional The solution shall log all ES/CMS data packages sent and received, including:
1. Enrollment Request
2. Enrollment Data
3. Credential Production Request
4. Credential Production Data
5. Credential Revocation Request
5.1. The user that requested revocation.
5.2. The reason for revocation.
6. Service Bureau Request
7. Service Bureau Production Data
FRQ-19.034.03 General Logging Threshold Demonstration Functional The solution shall log all modifications to a database record, including create, update, delete, location where change was made, and individual making the change.
FRQ-19.034.03.01 General Logging Threshold Demonstration Functional Where record modifications are automated workflows, the solution's logging shall provide traceability to the individual causing the modification.
FRQ-19.034.04 General Logging Threshold Demonstration Functional The solution shall log all software changes to the system.
FRQ-19.034.05 General Logging Threshold Demonstration Functional The solution shall log all configuration changes to the database schema.
FRQ-19.034.06 General Logging Threshold Demonstration Functional The solution shall log all workflow changes.
FRQ-19.035.07 General Logging Threshold Demonstration Functional The solution shall log all role changes for workflows.
FRQ-19.034.08 General Logging Threshold Demonstration Functional The solution shall log all role changes for users.
FRQ-19.034.09 General Logging Threshold Demonstration Functional The solution shall log all privileged access.
FRQ-19.034.10 General Logging Threshold Demonstration Functional The solution shall log all non-privileged access.
FRQ-19.034.11 General Logging Threshold Demonstration Functional The solution shall log the user ID while performing PIV workflow, credential workflow, identity workflow, administrative, security or audit functions.
FRQ-19.034.12 General Logging Threshold Demonstration Functional The solution shall record the each logon and logoff attempt by anyone accessing the system, including:
1. Date/time stamp of entry/access
2. DHS service access location
3. Login username
4. Attempts resulting in lockout
FRQ-19.034.13 General Logging Threshold Demonstration Functional The solution shall log activities that might modify, bypass, or negate information security safeguards.
FRQ-19.034.14 General Logging Threshold Demonstration Functional The solution shall log all information security-relevant actions.
FRQ-19.034.15 General Logging Threshold Demonstration Functional The solution shall log all activities performed using an administrator’s identity.
FRQ-19.034.16 General Logging Threshold Demonstration Functional The solution shall provide DHS configurable levels of verbose logging.
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.035 General Auditing Threshold Demonstration Functional The solution shall provide capability for audit records to be reviewed by authorized roles (e.g., the System Owner, CISO, ISSM, ISSO), including:
FRQ-19.035.01 General Auditing Threshold Demonstration Functional The solution shall protect audit records and audit logs from unauthorized access, modification, or destruction.
FRQ-19.035.01.01 General Auditing Threshold Demonstration Functional Audit record and log entry validation checks shall be performed regularly.
FRQ-19.035.01.02 General Auditing Threshold Demonstration Functional Audit record and log entry validation checks shall be performed on an adhoc basis.
FRQ-19.035.02 General Auditing Threshold Demonstration Functional At a minimum audit trail records shall be maintained online for at least ninety (90) days.
FRQ-19.035.03 General Auditing Threshold Demonstration Bus&Func Audit trail records shall be preserved (either online or offline) for a period of seven (7) years.
FRQ-19.035.03.01 General Auditing Threshold Demonstration Functional Audit trail records shall be easily be restored from offline to online for auditing purposes.
FRQ-19.035.03.02 General Auditing Threshold Demonstration Functional Audit trail records shall be easily be restored from offline to online for forensic analysis purposes.
FRQ-19.035.04 General Auditing Threshold Demonstration Functional The solution shall provide an audit and inspection process including a remote electronic audit capability.
FRQ-19.036 General Logging Threshold Demonstration Functional The system shall record the following for each planned equipment outage:
1. Date and time for start of outage by location
2. Estimated date and time for completion of outage
3. Actual date and time for completion of outage
4. Reason code and description/explanation for outage
FRQ-19.037 General Servers Threshold Demonstration Functional The system shall support DHS approved browsers (e.g., Chrome, Internet Explorer, Firefox, Edge, Safari)
FRQ-19.038 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Root Access to operating systems
FRQ-19.039 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Admin access to applications
FRQ-19.040 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Admin access to databases
FRQ-19.041 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Admin access to runtime environments
FRQ-19.042 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Administrative Control of RBAC roles
FRQ-19.043 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Administrative Control of users
FRQ-19.044 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Administrative Control of Patch management for the O/S
FRQ-19.045 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Administrative Control of Patch management for the application
FRQ-19.046 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Administrative Control of Patch management for the database engine
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-19.047 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Administrative Control of Patch management for the runtime environment
FRQ-19.048 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Access to O/S logging
FRQ-19.049 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Access to database engine logging
FRQ-19.050 General Privileged Access and Control
Threshold Demonstration Functional The government shall have Access to application logging
FRQ-19.051 General Privileged Access and Control
Threshold Demonstration Functional The government shall have full and open Integration with DHS monitoring services
FRQ-19.052 General Privileged Access and Control
Threshold Demonstration Functional The government shall have the ability to Buy, install, and use GFE HW devices
FRQ-19.053 General Privileged Access and Control
Threshold Demonstration Functional The government shall have the ability to Buy, install, and use GFE SW licenses
FRQ-21-054 General Web based/Open APIs
Threshold Demonstration Functional Web services shall be provided to send data to and receive data from external systems according to approved DHS ICDs.
FRQ-21-054.01 General Web based/Open APIs
Threshold Demonstration Functional Web services shall provide a configurable means to notify administrators (e.g. text, email).
FRQ-21-054.02 General Web based/Open APIs
Threshold Demonstration Functional Web services shall provide a configurable means to notify administrators by event type (e.g., failed delivery of a POST transaction).
FRQ-21-054.03 General Web based/Open APIs
Threshold Demonstration Functional Web services shall provide a configurable means to notify more than one administrator.
FRQ-21-054.04 General Web based/Open APIs
Threshold Demonstration Functional Web services interfaces shall provide delivery of POST data to an external system with queuing and guaranteed confirmation of delivery/acceptance.
FRQ-21-054.04.01 General Web based/Open APIs
Threshold Demonstration Functional The interface shall confirm delivery and acceptance of POST data.
FRQ-21-054.04.01.01 General Web based/Open APIs
Threshold Demonstration Functional Web services shall provide a configurable interval (secs, mins) for retry of transactions that are not confirmed for delivery and acceptance.
FRQ-21-054.04.01.02 General Web based/Open APIs
Threshold Demonstration Functional Web services shall provide a configurable number of retries for transactions that are not confirmed for delivery and acceptance.
FRQ-21-054.04.01.03 General Web based/Open APIs
Threshold Demonstration Functional Web services shall support individual transactions.
FRQ-21-054.04.01.04 General Web based/Open APIs
Threshold Demonstration Functional Web services shall support batch transactions.
FRQ-21-054.05 General Web based/Open APIs
Threshold Demonstration Functional When delivery/acceptance of a POST can not be confirmed within the configured interval and number of retries, administrator(s) shall be notified.
FRQ-21-054.06 General Web based/Open APIs
Threshold Demonstration Functional When delivery/acceptance of a POST can not be confirmed, the transaction shall be stored in a queue of failed transactions for review by administrators.
NFR-19-000
System Sub-System Status Verification Type Requirement
FRQ-21-054.07 General Web based/Open APIs
Threshold Demonstration Functional Web services shall be provided to receive POST data from external systems according to DHS approved ICDs.
FRQ-21-054.07.01 General Web based/Open APIs
Threshold Demonstration Functional When a received POST transaction fails data validation according to its ICD, administrator(s) shall be notified.
FRQ-21-054.07.02 General Web based/Open APIs
Threshold Demonstration Functional Web services shall provide receipt/acceptance notification to the external system.
FRQ-21-054.07.03 General Web based/Open APIs
Threshold Demonstration Functional When a received POST transaction fails data validation, the transaction shall be stored in a queue of failed transactions for review by administrators.
FRQ-21-054.08 General Web based/Open APIs
Threshold Demonstration Functional Webservices shall provide an administrative portal to review the failed transaction queue.
FRQ-21-054.09 General Web based/Open APIs
Threshold Demonstration Functional Webservices shall provide an administrative portal to correct and re-submit failed transactions.
FRQ-21-054.10 General Web based/Open APIs
Threshold Demonstration Functional Webservices shall provide administrative reports on transactions sent and received.
SOO Requirements System Sub-system Status Verification Type Requirement
Crypto Agile configuration support
CMS General Threshold Demonstration Bus&Non-Func The CMS shall support FIPS 140-2 Level 3 Hardware Security Modules
(HSM).
Crypto Agile configuration support
CMS General Threshold Demonstration Bus&Non-Func The CMS shall support SafeNet Assured Technologies Luna Security Appliance (Luna SA).
Crypto Agile configuration support
CMS General Threshold Demonstration Bus&Non-Func The HSM shall be American sourced.
Credential issuance and management
CMS External interfaces Threshold Demonstration Non-functional The solution shall comply with Federal Common Policy.
Credential issuance and management
CMS External interfaces Threshold Demonstration Non-functional The solution shall comply with Federal Bridge Certification Authority Policy.
Derived issuance and management
CMS Derived Mobile device Threshold Demonstration Non-functional The vendor shall participate in the iOS beta program to begin credential provisioning validation and testing prior to the release of major iOS upgrades.
Derived issuance and management
CMS Derived Mobile device Threshold Demonstration Non-functional The vendor shall immediately notify the government of any compatibility issues with forthcoming iOS releases.
Derived issuance and management
CMS Derived Mobile device Threshold Demonstration Non-functional When a functionality is not supported by the underlying key storage mechanism, the vendor shall provide an alternate method for DHS approval.
Derived issuance and management
CMS Derived Mobile device Objective Documentation Bus&Non-Func Vendor shall provide DHS with documentation on the authentication mechanism used and how any authenticators such as SCEP secrets are generated, used, and protected.
Derived issuance and management
CMS Derived Mobile device Objective Documentation Bus&Non-Func The certificate request mechanism shall incorporate interactive user authentication on the mobile device using a temporary secret generated for each specific credential issuance event (e.g., one-time password or Quick Response code).
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Non-functional The solution shall support integration with Mobile Device Management (MDM) solutions.
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Non-functional The solution shall support integration with the MDM solutions in use at
DHS
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Non-functional The solution shall support integration with VMWare Workspace ONE hosted on-premises in DHS.
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Non-functional The solution shall support integration with the VMWare Workspace ONE Software-as-a-Service environment.
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Non-functional The solution shall support integration with MobileIron.
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Non-functional The solution shall support integration with Blackberry UEM.
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Non-functional The solution shall support integration with Microsoft Intune.
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Bus&Non-Func The vendor shall provide any required information or configuration profiles to enable the MDM to manage any required app configuration (e.g., URLs).
Derived issuance and management
CMS Derived Mobile Device Mgr
Threshold Demonstration Bus&Non-Func The vendor shall provide any required mobile apps (e.g., key storage apps) to be provisioned to devices by the MDM.
Derived issuance and management
CMS Derived Mobile device Threshold Documentation Non-functional The cryptographic module used for key generation and storage must be validated to FIPS 140-2 Level 1 or higher.
CMS RTM
Derived issuance and management
CMS Derived Mobile device Objective Documentation Non-functional The solution shall enable app integration without requiring the consuming application to implement a proprietary SDK.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Bus&Func The CMS shall integrate with the Enterprise Identity Management solution (eIDMS).
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional The CMS shall receive a DHS approved standardized Credential Production Request (CPR) package from the eIDMS.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional The solution shall confirm receipt and acceptance of the CPR.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CMS shall support data validation of all CPRs from the eIDMS.
Web based/Open APIs CMS Workflow Threshold Demonstration Functional The workflow solution shall provide a review and report capability on CPR package's that fail data validation.
Web based/Open APIs CMS eIDMS-CMS data interface
Deleted Demonstration Functional CMS shall support batch CPRs from the eIDMS.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CPRs shall specify all information required to produce and issue a credential.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CPR shall supply the credential type (i.e. one of any credential type supported by the solution) to be produced.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CPR shall specify credential production facility: Service Bureau or Issuance Workstation.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CPR shall supply the electrical personalization data.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CPR shall supply the print data (including required topology profile).
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CPR shall specify production process:
1. Production using Issuance Workstation.
2. Production using Service Bureau.
2.1. Service Bureau credential delivery mailing address.
2.2. Service Bureau credential delivery requirements (e.g., 1 day, 2-3 day, 5+ days).
3. Expiration duration for credential type to be produced.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional The default expiration duration for DHS PIV Cards shall be six years minus one day.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Bus&Func The CMS shall deliver a standardized Card Production Data (CPD) package to the eIDMS.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional The solution shall confirm receipt and acceptance of the CPD package by the eIDMS.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional When delivery fails, the solution shall queue the request and retry delivery every minute for up to 30 minutes until it succeeds.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional When 30 delivery retries fail, the solution shall notify an eIDMS administrator.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional When 30 delivery retries fail, the solution shall notify a CMS administrator.
Web based/Open APIs CMS Workflow Threshold Demonstration Functional The workflow solution shall provide a review and report capability on CPD package's still in queue that have yet to be delivered.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CPD shall include all the information required by the eIDMS for credential records.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional At a minimum, the CPD package shall include:
1. Linking identifier to CPR.
2. Credential unique identifier (e.g., card serial number, IIN)
3. Expiration date of the credential.
4. All certificates issued per the Credential Type requested by the CPR.
5. Mobile device unique identifier for Derived PIV.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional The CMS shall support a DHS approved standardized Credential Revocation Request (CRR) from the eIDMS.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CRR shall supply unique identifier for the credential to be revoked (e.g., FASC-N, Card UUID).
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CRR shall supply reason codes, including:
1. For revocation of certificates.
2. For revocation of credentials (e.g., DHS PIV Card).
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CRR shall supply PKI certificate serial numbers to be revoked.
Web based/Open APIs CMS eIDMS-CMS data interface
Deleted Demonstration Bus&Func CMS shall support batch CRRs from the eIDMS.
Credential issuance and management
CMS External interfaces Threshold Demonstration Functional The CMS shall be capable of positively confirming completed certificate revocation by the Certificate Authority (CA).
Credential issuance and management
CMS External interfaces Threshold Demonstration Functional The CMS shall be capable of high priority revocation requests to the CA as required by DHS.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Bus&Func Upon revocation or destruction of a credential, the CMS shall send a DHS approved standardized Credential Revocation Data (CRD) package to the eIDMS.
Web based/Open APIs CMS eIDMS-CMS data interface
Deleted Demonstration Functional CRD shall support one credential at a time.
Web based/Open APIs CMS eIDMS-CMS data interface
Deleted Demonstration Bus&Func CRD shall support batch responses.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Bus&Func CRD shall support credential destruction status and logging by a DHS Credentialing Facility (DCF).
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CRD shall provide acknowledgement of completed revocations by the CA and CMS to the eIDMS.
Web based/Open APIs CMS eIDMS-CMS data interface
Threshold Demonstration Functional CMS shall support data validation of all CRRs from the eIDMS.
Web based/Open APIs CMS Workflow Threshold Demonstration Functional The workflow solution shall provide a review and report capability on CRR package's that fail data…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .