Travel Services Contract Language - DRAFT.pdf

PDF 125 KB Posted

Attached to
Travel Support Services Federal contract opportunity
Solicitation number
70US09RFIOCT2022
Issued by
Department of Homeland Security US Secret Service

View the file

Other files for this federal contract opportunity

Other files attached to Travel Support Services, newest first.
File Type Posted
RFI 70US09RFIOCT2022 QA.pdf PDF
Travel Services Information Security Requirements - DRAFT.pdf PDF
REQUEST FOR INFORMATION TRAVEL SERVICES.pdf PDF
STATEMENT OF WORK TRAVEL SERVICES RFI.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Security Requirements

Government information security guidelines do not distinguish between services and products, nor do they distinguish whether the hosting systems are Government-owned or contractor-owned. All Contractor components within the accreditation boundary that contain U.S. Government data shall be required to achieve and maintain the same level of security and protection required for Government-owned information systems.

The Contractor shall be responsible for protecting US Government information against unauthorized access of any form. Events involving a confirmed or suspected breach or compromise of the system or data may result in suspension of the service by the Contracting Officer. The Government may pursue termination for cause and the payment of damages.

The Contractor is required to comply with all of the following list of statutes, Executive Orders, Presidential Directives, Office of Management and Budget directives, DHS policies and National Institute of Standards and Technology guidelines apply to Secret Service information systems operated by the agency or on behalf of the agency The Government will identify additional applicable statutory, regulatory, policy, and federal guidelines as appropriate.

Independent Third-Party Assessment Organization

The Contractor shall engage a FedRAMP-approved Third Party Assessment Organizations (3PAO) or an A2LA approved 3PAO no non-cloud service offerings. A2LA ensures the 3PAO meets the requirements of ISO/IEC 17020 (as revised) to develop a security authorization package to achieve the Authority to Operate as granted by the Secret Service.

Secret Service Security Authorization

The Contractor shall achieve a Government granted authority to operate within 180 days of contract award. A risk acceptance memorandum may be granted by the Government prior to the Contractor achieving the authority to operate. Extensions to the deadline for achieving the authority to operate may be granted at the sole discretion of the Government.

The Government reserves the right to withdraw the authority to operate or risk acceptance memorandum for the Contractor system at any time for failure to comply with federal statutes, regulations, policy, or the terms of this contract. The Contractor may not operate a production system on behalf of the Government without the authority to operate or a risk acceptance memorandum.

The Contractor is responsible for all costs associated with achieving the Authority to Operate as granted by the Secret Service.

Cloud Service Offerings

For cloud-based solutions, if the Contractor has not achieved FedRAMP Authorized on the date of award for the contract, the Contractor shall achieve FedRAMP Authorized status in accordance with the FedRAMP Work Breakdown Structure. The Contractor must achieve FedRAMP In-Process within three months of contract award.

The Contractor is responsible for all costs associated with achieving FedRAMP Authorized.

The Contractor may achieve FedRAMP Authorized via the FedRAMP Joint Assessment Board (JAB) or the FedRAMP Agency Authorization process. If the Contractor is pursuing an Agency Authorization, the Contractor shall utilize the FedRAMP Just in Time Linear Approach documented in the FedRAMP Agency Authorization Playbook.

The Government has sole discretion for sponsoring the Contractor in the FedRAMP process. The Government may withdraw its FedRAMP sponsorship at any time for failure to comply with federal statutes, regulations, policy, or the terms of this contract.

Information Categorization

The minimum FIPS-199 categorization for the Contractor delivered solution shall be Moderate. The Government shall review the Contractor’s and independent third-party assessment organization’s (3PAO) FIPS 199 categorization of the solution. The Government may choose, at its sole discretion, to accept a FIPS 199 categorization of Moderate or designate the Contractor solution as a High impact system. If the FIPS-199 categorization is Moderate, the Contractor shall satisfy security controls for the Moderate impact level and any additional security controls specified by the Government. If the FIPS-199 categorization is High, the Contractor shall satisfy security controls for the High impact level and any additional security controls specified by the Government.

Data Sovereignty

All Government data must remain in the United States. Data may not be stored, processed, transmitted, or accessed in or from any country other than the United States. All Government data on non- Government systems must remain within the authorization boundary unless its removal is authorized in writing by the Government.

Limited Purpose of Data

The Contractor may not disclose Government data to a third party outside the terms of this contract without the written authorization of the Government. The Contractor shall not use Government data for purposes outside the terms of this contract without written authorization of the Government.

The Government has unlimited rights to all documents/material produced under this contract. All documents and materials produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.

Identity and Authentication Control

The Contractor shall implement Identity Assurance Level (IAL3), Authenticator Assurance Level (AAL3), and Federation Assurance Level (FAL3) for privileged accounts. IAL3, AAL3, and FAL3 are defined in NIST 800-63, Digital Identity Guidelines. Non-privileged accounts should implement IAL, AAL, and FAL in accordance with Government analysis of NIST 800-63, Digital Identity Guidelines.

Vulnerability Management

The Contractor shall remediate all Information Security Vulnerability Management (ISVM) notices provided by the Government as well as vulnerabilities published in the National Vulnerability Database (NVDB) that are identified in software, databases, operating systems, and firmware. Information Security Vulnerability Management (ISVM) notices shall be remediated within the stated time documented by the ISVM notice.

For cloud service offerings, the Contractor shall remediate all vulnerabilities in accordance with the requirements defined in RA-5 of the applicable FedRAMP security control baseline.

The Government reserves the right to call for ad hoc reports, logs or screen shots, and so forth to support the requirement to perform vulnerability management. These artifacts shall be provided to the Government COR within seven (7) calendar days from the request.

Continuous Monitoring

For non-cloud service offerings, the Contractor shall comply with the DHS Information Security Performance Plan.

For cloud service offerings, the Contractor shall comply with the FedRAMP Continuous Monitoring Strategy guide.

The Contractor shall provide the Government a monthly report of the remediation progress for Plans of Action and Milestones (POA&Ms). The Contractor shall use the FedRAMP POA&M Template as the monthly report format.

The Government reserves the right to call for ad hoc reports, logs or screen shots, and so forth to support the requirement to perform continuous security monitoring and Office of the Inspector General (OIG) audits. These artifacts shall be provided to the Government COR within seven (7) calendar days from the request.

The Contractor shall allow the Government or its designated representative to perform quarterly scans, including penetration scans, as part of the continuous security monitoring.

Secure Code

The Contractor shall perform manual quality assurance checks for all non-COTS code deployed to the production environment prior to its deployment. The Contractor shall perform automated static analysis on all non-COTS code deployed to the production environment. The Contractor shall perform automated dynamic analysis on all non-COTS code deployed in the production environment. The Contractor shall validate and remediate all critical vulnerabilities prior to deploying code to the production environment.

Web Security

The Contractor shall not employ mobile code within its Web content that my harbor malicious content and therefore be blocked by Federal firewall, consequently denying functionality to users. Mobile code technology explicitly prohibited in delivering functionality includes but is not limited to ActiveX, UNIX Shell Scripts, Disk Operating System (DOS) Batch Scripts, Flash animation, Shockwave movies, macros, unsigned Java applets, or other unsigned mobile code.

The Contractor shall accept only Transport Layer Security (TLS) mode of operational connections from browsers or mobile device applications or obtain approval from the Government COR for other solutions.

The Contractor shall only accept Internet Protocol Security (IPSEC) connections for VPNs or obtain approval from the Government COR for other solutions.

Malware Defense

The Contractor shall ensure systems within the accreditation boundary employ anti-malware software. Anti-malware signatures must be updated every 15 days. Heuristic anti-malware tools must continuously operate.

Incident Response

In the event of a suspected or confirmed unauthorized access and/or unauthorized disclosure of data from the Contractor operated system on behalf of the Government, or other security event to include system outages and personnel security, the Contractor shall notify the Government Security Operations Center within one hour of identifying the security event.

In the event of a confirmed data breach or other security incident the Contractor shall engage an independent incident response company to review all information compromised by the data breach or security event.

The Government is responsible all crisis communications regarding an incident. The Contractor shall not communicate any information to any entity without the written approval of the Government. The Contractor is permitted to communicate with its corporate counsel, cyber breach insurer, and third-party incident response company.

The Contractor shall participate in one Government-led incident response tabletop exercises annually.

Supply Chain Risk Management

For non-cloud service offerings, the Contractor shall provide a Software Bill of Materials (SBOM) in the approved NIST format. The Contractor shall provide an updated SBOM for all changes in the production environment.

For cloud-service offerings, the Contractor shall provide a Software Bill of Materials (SBOM) in an approved NIST format per FedRAMP requirements. The Contractor shall provide an updated SBOM for all changes in the production environment.

The Contractor may not use software components that contain Critical or High impact vulnerabilities as identified by the National Vulnerability Database or otherwise prohibited by the Government. The Contractor is responsible for all costs associated with upgrading software components to eliminate vulnerabilities.

Audit

The Government reserves the right to audit the Contractor at any time during the period of performance.

The Government must provide the Contractor with written notice 14 days in advance of an audit not associated with a suspected data breach or confirmed data breach. The Government must provide the Contractor with written notice 24 hours in advance of an audit associated with a suspected data breach or confirmed data breach.

Failure by the Contractor to operate its network and information systems within the accreditation boundary in a manner consistent with the artifacts provided in support of its certification and accreditation may result in the suspension of the service. A temporary suspension for 15 calendar days or more will be evaluated by the Government for further action. The Government will pursue alternatives that include termination for cause and the payment of damages.

File details come from the government source that posted it. Updated .