IT_SECURITY_CLAUSE.pdf
PDF 120 KB Posted
- Attached to
- ENGINEERING AND INFORMATION Federal contract opportunity
- Solicitation number
- 73351018R0011
About this file
This request for proposal solicits engineering and information technology support services through multiple award indefinite delivery indefinite quantity contracts. The Small Business Administration seeks to enter contracts to provide analysis, technical assistance, engineering, and IT development support to the Office of the Chief Information Officer and program offices. The base period of performance is 12 months with four 12-month option periods. The North American Industry Classification System code is 541519 with a small business size standard of $27.5 million. The government will award up to three 8(a) set-aside contracts on a firm fixed price basis. Offerors must submit technical approach, management approach and quality control plan, experience of proposed staff, prior experience and past performance, and a price proposal by July 31, 2018.
Attachment E - IT Security Clause
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 73351018R0011_SF_30_Amendment_0002.pdf | ||
| RFQENGINEERING_AND_INFORMATION_TECHNOLOGY_SUPPORT_SERVICES_amendment_0002_072518.pdf | ||
| att_C_Past_Performance_Questionnaire_v.pdf | ||
| att_B_Labor_Category_pricing_sheet.pdf | ||
| att_A_Technical_Task_Order__FINAL__062918.pdf | ||
| att_D_Confidentiality_and_Non-Disclosure_Agreement.pdf | ||
| 73351018R0011_SF_1449.pdf | ||
| RFQENGINEERING_AND_INFORMATION_TECHNOLOGY_SUPPORT_SERVICES_07072018.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment E
IT Security Acquisition Language
1. Purpose
The U.S. Small Business Administration (SBA) must provide information security for the information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. The Federal Information Security Modernization Act of 2014 (FISMA) describes Federal agency security responsibilities as including “information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.”
This includes services which are either fully or partially provided; including other agency hosted, outsourced, and cloud computing solutions. FISMA has a somewhat broader applicability than prior security law and applies to both information and information systems used by the agency, contractors, and other organizations and sources. Agency information security programs apply to all organizations (sources) which possess or use Federal information – or which operate, use, or have access to Federal information systems (whether automated or manual) – on behalf of a Federal agency, information systems used or operated by an agency or other organization on behalf of an agency.
This document applies to all Agency contracts in which SBA sensitive information is stored, generated, transmitted or exchanged by an SBA contractor, subcontractor or third-party, or on behalf of any of these entities regardless of format. The regulations in this document also pertain to information residing on an SBA or a non-SBA system in order for the contractor, subcontractor or third party to perform their contractual obligations to SBA, standing in lieu of SBA or acting on SBA’s behalf.
All requirements identified or referenced in this document shall be interpreted and implemented implicitly for all system components unless otherwise directed by the SBA.
All requirements identified or referenced in this document shall be implemented at the time of contract award unless otherwise directed by the government.
All requirements identified or referenced in this document shall apply to all contractors and subcontractors that will have access to Controlled Unclassified Information (CUI), collect or maintain CUI on behalf of the agency, operate federal information systems, including contractor information systems operated on behalf of the agency, to collect, process, store, or transmit CUI.
All physical and/or logical access to the IT system or supporting facilities deemed necessary by the SBA shall be granted to the SBA or its designated representative(s) by the Contractor under Federal Acquisition Regulation (FAR) Part 52.246 (Contractor Inspection Requirements).
2. Policies and Regulations
Contractors entering into an agreement for services to the SBA or its Federal customers shall be contractually subject to all SBA and Federal IT Security standards, policies, and reporting requirements.
The contractor shall meet and comply with all SBA IT Security Policies, SBA and NIST guidelines, other Government-wide laws and regulations for protection and security of Information Technology.
Contractors are required to comply with the SBA, FIPS, and NIST, Federal requirements outlined below (or successor documents):
• SBA Information Technology (IT) Security Policy (SOP 90 47 4), as amended.
• Federal Information Security Modernization Act of 2014, as amended.
• Clinger-Cohen Act of 1996 also known as the “Information Technology Management Reform Act of 1996,” as amended.
• Privacy Act of 1974 (5 U.S.C. § 552a), as amended.
• Federal Information Technology Acquisition Reform Act (FITARA) of 2014, as amended.
• Chief Financial Officers Act of 1990 (Public Law 101–576), as amended.
• Homeland Security Presidential Directive (HSPD-12), “Policy for a Common Identification Standard for Federal Employees and Contractors,” as amended.
• Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information Resources”, and Appendix III, “Security of Federal Automated Information Systems”, as amended.
• OMB Memorandum M-04-04, “E-Authentication Guidance for Federal Agencies,” as amended.
• FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information Systems,” as amended.
• FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information Systems,” as amended.
• FIPS PUB 140-2, “Security Requirements for Cryptographic Modules,” as amended.
• NIST Special Publication 800-18, “Guide for Developing Security Plans for Federal Information Systems,” as amended.
• NIST Special Publication 800-30 Revision 1, “Guide for Conducting Risk Assessments,” as amended.
• NIST Special Publication 800-34 Revision 1, “Contingency Planning Guide for Information Technology Systems,” as amended.
• NIST Special Publication 800-37 Revision 1, “Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Lifecycle Approach,” as amended.
• NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology Systems,” as amended.
• NIST Special Publication 800-53 Revision 4, “Security and Privacy Controls for Federal Information Systems and Organizations,” as amended.
• NIST Special Publication 800-53A Revision 4, “Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans,” as amended.
• NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” as amended.
3. Security and Privacy Requirements
FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems,” is a mandatory federal standard that defines the minimum security requirements for federal information and information systems in seventeen security-related areas. Contractor systems supporting SBA must meet the minimum security requirements through the use of the security controls in accordance with NIST Special Publication 800-53, Revision 4 (as amended and hereafter described as NIST 800-53), and “Recommended Security and Privacy Controls for Federal Information Systems.
Data contained within all SBA computer systems are governed by Agency record disclosure and privacy regulations (13 C.F.R. part 102), IT Security regulations as well as other regulations, statutes and guidance, including the Privacy Act of 1974, as amended (5 U.S.C. § 552a). In addition, various Federal requirements obligate SBA to establish controls to limit access to Personally Identifiable Information (PII) and sensitive data, as defined below, to authorized personnel. These include OMB Circular A-130, Appendix III, and OMB Memoranda M-10-15, M-09-29, M-08-21, M-07-19, M-07-16, M-06-16, and M- 06-15.
Contractors leveraging cloud solutions must utilize a Cloud Service Provider (CSP) with an existing Federal Risk and Authorization Management Program (FedRAMP) Joint Authorization Board (JAB) Provisional Authorization to Operate (ATO) or Agency ATO at all service models [Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)].
To comply with the Federal standard, the SBA must determine the security category of the information and information system in accordance with FIPS 199, “Standards for Security Categorization of Federal Information and Information Systems”, and then the contractor shall apply the appropriately tailored set of Low, Moderate, or High impact baseline security controls in NIST 800-53, as determined by the SBA.
The Contractor shall use SBA and NIST guidelines, Defense Information Security Agency (DISA) Security Technical Implementation Guides (STIGs), or industry guidelines in securing their systems.
4. Essential Security Controls
All NIST 800-53 controls must be implemented as per the applicable FIPS 199 Low, Moderate, or High baseline. Controls, control enhancements, or parts of controls or enhancement may be implemented jointly between the Contractor and CSP as applicable. The following table identifies essential security controls from the respective baselines to highlight their importance and to understand the potential implementation costs. The Contractor shall make the proposed system and security architecture of the information system available to the Office of the Chief Information Officer for review and approval before commencement of system build.
Control ID Control Title Baseline Implementation Guidance
AC-02 Account Management L, M, H The contractor shall perform an annual user recertification for all roles implemented within the information system.
AC-17 (3) Remote Access | Managed Access Control Points M, H The information system routes privileged authentication traffic to external hosted infrastructures / applications through SBA’s managed network access control points and are subject to the Trusted Internet Connections (TIC) and the U.S. Department of Homeland Security’s (DHS’) Einstein monitoring system.
AC-20 Use of External Information Systems L, M, H Physical access to the contractor’s office areas that contain PII and sensitive data shall be controlled to prevent unauthorized personnel from acquiring access to this data. The contractor shall not release SBA data outside of its facility, either orally or in written form, without the express written consent of the SBA CO/COR.
AU-02 Audit Events L, M, H Information systems shall implement audit configuration requirements including but not limited to: successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. Web applications should log all admin activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes. Web applications should log all admin activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes.
AT-02/
AT-03 Security Awareness Training L, M, H All contractors with access to SBA’s IT systems and/or PII and sensitive data shall complete the annual Computer Security Awareness Training (CSAT) and role based training as necessary
CA-07 Continuous Monitoring L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall integrate with SBA implemented continuous monitoring, Continuous Diagnostics and Monitoring (CDM), and Security Operation Center (SOC) capabilities.
CM-06 Configuration Settings L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall configure their systems in agreement with SBA policies and guidelines, DISA STIGs, NIST guidelines, or manufacturer guidelines as appropriate.
CP-07 Alternative Processing Site M, H FIPS 199 Moderate and High impact systems must implement processing across geographically-disparate locations to ensure fault tolerance. Infrastructure as a Service architectures must implement a multi-region strategy.
CP-08 Telecom Services M, H FIP 199 Moderate and High impact information systems must implement alternate telecom services to support resumption when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.
IA-02 (1) Identification and Authentication (Organizational Users) | Network Access to Privileged Accounts L, M, H All information systems shall implement multi-factor authentication for privileged accounts.
IA-02 (2) Identification and Authentication (Organizational Users) | Network Access to Non- Privileged Accounts L, M, H FIPS 199 Moderate and High impact information systems must implement multi-factor authentication for non-privileged accounts.
IA-02 (12) Identification and Authentication | Acceptance of PIV Credentials L, M, H Information systems with an e-authentication assurance level of 3 or above, used by federal employees or contractors must accept federal Personal Identity Verification (PIV) cards and verify them in accordance with guidance in OMB M-11-33.
IA-07 Cryptographic Module Authentication L, M, H The information system shall implement FIPS 140-2 validated encryption modules for authentication functions. Reference:
http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/1401vend.htm
IR-04 Incident Handling L, M, H The Contractor shall cooperate with agency incident response activities, including but not limited to, providing logical and physical access to compute resources and media for investigative, examination, or forensic purposes.
IR-06 Incident Reporting L, M, H The contractor shall report all suspected security incidents to the SBA Security Operations Center in accordance with U.S. CERT reporting requirements.
MP-04 Media Storage M, H Digital media including magnetic tapes, external/removable hard drives, flash/thumb drives, diskettes, compact disks and digital video disks shall be encrypted using a FIPS 140-2 validated encryption module.
MP-05 Media Transport M, H Digital media including magnetic tapes, external/removable hard drives, flash/thumb drives and digital video disks shall be encrypted using a FIPS 140-2 validated encryption module during transport outside of controlled areas.
PL-02 System Security Plan L, M, H The contractor must develop a final System Security Plan (SSP) within thirty (30) calendar days from contract award. The SSP must be updated at least annually. The SSP will be reviewed by the Contracting Officer’s Technical Representative (COR) or designated technical point of contact. The SSP must document administrative, technical, and physical security measures at the contractor’s computer facility to protect PII and sensitive data from unauthorized disclosure, alteration, or misuse; prevent unauthorized access to the contractor’s computer system; and protect the availability of data and services to SBA. All controls and enhancements must be described in detail, focusing on how each control or enhancement is implemented. All technical controls must be described for all technologies included in the system boundary
PL-08 Information Security Architecture M, H All information system security architectures must be reviewed and approved by the Office of the Chief Information Officer prior to development or implementation.
PS-03 Personnel Screening L, M, H Pursuant to Federal Acquisition Regulation (FAR) clause 52.204- 9, incorporated into this solicitation and the resulting contract, each contractor and subcontractor must comply with Agency Personal Identity Verification (PIV) procedures. These procedures must be followed when the contractor and or subcontractor will have: unescorted physical access to a federally-controlled facility, and/or access to a federally controlled information system (including, but not limited to computer systems, networks, or information technology infrastructure).
RA-05 Vulnerability Scanning L, M, H All information system must complete quarterly privileged authenticated operating system, web, and database vulnerability and configuration scanning and provide results to the SBA on a quarterly basis.
SC-08 / SC-08 (1) Transmission Confidentiality and Integration M, H Implemented encryption algorithms and cryptographic modules shall be FIPS-approved and FIPS 140-2 validated, respectively.
o Digital signature encryption algorithms - Reference:
(http://csrc.nist.gov/groups/ST/toolkit/digital_signatures.html#Approved o Block cypher encryption algorithms - Reference:
http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.html#Approved o Secure hashing algorithms – Reference:
http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html#Approved
Internet-facing systems shall enforce HTTPS and implement HTTP Strict Transport Security (HSTS).
SC-13 Cryptographic Protection | FIPS Validated Cryptography L, M, H Implemented encryption algorithms and cryptographic modules shall be FIPS-approved and FIPS 140-2 validated, respectively.
o Digital signature encryption algorithms - Reference:
(http://csrc.nist.gov/groups/ST/toolkit/digital_signatures.html#Approved o Block cypher encryption algorithms - Reference:
http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.html#Approved o Secure hashing algorithms – Reference:
http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html#Approved
SC-22 Architecture and Provisioning for Name / Address Resolution Service L, M, H Information systems shall be Domain Name System Security Extensions (DNSSEC) compliant as per OMB Memorandum, M-08-23, which requires all Federal Government departments and agencies that have registered and are operating second level .gov to be DNSSEC.
SC-28 (1) Protection of Information at Rest | Cryptographic Protection Required for Systems with PII Only System bearing PII must implement protect information at rest. At a minimum, fields bearing PII data must be encrypted with field level encryption. Encryption algorithms shall be FIPS-approved; implemented encryption modules shall be FIPS 140-2 validated
SI-02 Flaw Remediation L, M, H All systems must establish monthly flaw remediation (patch) processes. High and Critical risk findings must be remediated prior to go-live. Post go-live, all critical and high [CVSS Base Score ≥ 7.0] vulnerabilities identified must be mitigated within 30 calendar days and all other [CVSS Base Score < 7.0 vulnerabilities mitigated within 90 calendar days.
SI-03 Malicious Code Protection L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall implement anti-malware capabilities for all assets.
SI-04 Information System Monitoring L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall integrate with SBA implemented continuous monitoring, Continuous Diagnostics and Monitoring (CDM), and Security Operation Center (SOC) capabilities.
SI-10 Information Input Validation M, H All systems accepting input from end users must validate the input in accordance with the OWASP Top 10 Web Application Security Vulnerabilities.
5. Assessment and Authorization (A&A) Activities
The implementation of a new Federal Government IT system requires a formal approval process known as Assessment and Authorization (A&A). NIST Special Publication 800-37, Revision 1, provides guidelines for performing the A&A process. The Contractor system/application must have a valid assessment and authorization, known as an Authority to Operate (ATO) (signed by the Federal government) before going into operation and processing SBA information. The failure to obtain and maintain a valid ATO may result in the termination of the contract. The system must have a new A&A conducted (signed by the Federal government) at least every three (3) years or at the discretion of the Authorizing Official when there is a significant change to the system’s security posture. All NIST 800-53 Revision 4 controls must be tested/assessed every three (3) years or as defined by SBA policy.
Assessing the System
a. The Contractor shall comply with Assessment and Authorization (A&A) requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement. The Level of Effort for the A&A is based on the System’s NIST Federal Information Processing Standard (FIPS) Publication 199 categorization. The contractor shall create, maintain and update the following A&A documentation:
• System Security Plan (SSP) completed in agreement with NIST Special Publication 800-18, Revision 1 (or successor document), “Guide for Developing Security Plans for Federal Information Systems”. The SSP shall include as appendices required policies and procedures across 18 control families mandated per FIPS 200, Rules of Behavior, and Interconnection Agreements (in agreement with NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology Systems”).
• Contingency Plan and test Report completed in agreement with NIST Special Publication 800-34.
• Privacy Threshold Analysis/Privacy Impact Assessment (PTA/PIA)
• Configuration Management Plan (CMP).
b. Information systems must be assessed and authorized every three (3) years, whenever there is a significant change to the system’s security posture, and updated annually in accordance with NIST Special Publication 800-37 Revision 1, “Guide for the Security Certification and Accreditation of Federal Information Systems.”
c. At the Moderate impact level and higher, the contractor or Government (as determined in the contract) will be responsible for providing an independent Security Assessment/Risk Assessment in accordance with SBA Policy.
d. If the Government is responsible for providing a Security Assessment/Risk Assessment, the Contractor shall allow SBA employees (or SBA-designated third party contractors) to conduct A&A activities to include control reviews in accordance with NIST 800-53/NIST 800-53A. Review activities include but are not limited to operating system vulnerability scanning, web application scanning, and database scanning of applicable systems that support the processing, transportation, storage, or security of SBA information. This includes the general support system infrastructure.
e. Identified gaps between required 800-53 controls and the contractor’s implementation as documented in the Security Assessment/Risk Assessment report shall be tracked for mitigation as a Plan of Action and Milestones (POA&M) item within SBA’s Cyber Security Assessment Management (CSAM) implementation. Depending on the severity of the gaps, the Government may require them to be remediated before an Authorization to Operate is issued.
f. The Contractor is responsible for mitigating all security risks found during A&A and continuous monitoring activities. All high-risk vulnerabilities must be mitigated within 30 days and all moderate risk vulnerabilities must be mitigated within 90 days from the date vulnerabilities are formally identified.
The Government will determine the risk rating of vulnerabilities.
Authorization of the System
a. Upon receipt of the Security Authorization Package, the Authorizing Official (AO), in coordination with the SBA Office of the CIO, System Owner (SO), Information System Security Manager (ISSM), and Information System Security Officer (ISSO) will render an authorization decision to:
• Authorize system operation w/out any restrictions or limitations on its operation;
• Authorize system operation w/ restriction or limitation on its operation, or;
• Not authorize for operation.
b. The Contractor shall provide access to the Federal Government, or their designee acting as their agent, when requested, in order to verify compliance with the requirements for an Information Technology security program, and in response to security incidents. At its option, the Government may choose to conduct on site surveys. The Contractor shall make appropriate personnel available for interviews and documentation during this review. If documentation is considered proprietary or sensitive, these documents may be reviewed on-site under the hosting Contractor’s supervision.
6. Continuous Monitoring Deliverables and Schedule
Maintenance of the security authorization to operate will be through continuous monitoring of security controls of the contractors system and its environment of operation to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to SBA per the schedules below. The submitted deliverables (or lack thereof) provide a current understanding of the security state and risk posture of the information systems. They allow SBA AOs to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur. The contractor is required to provide the following deliverables to the CO/COR during the performance of the contract.
Deliverable Control ID Frequency
Plan of Action & Milestones (POA&M) Updates CA-05 Quarterly
Vulnerability Scanning RA-05 Quarterly
System Security Plan Update PL-02 Annually
Contingency Plan Update CP-02 Annually
Contingency Plan Test Report CP-07 Annually
User Certification AC-02 Annually
Separation of Duties Matrix AC-05 Annually
Baseline Configuration Settings CM-06 Annually
Configuration Management Plan CM-09 Annually
Incident Response Test Report IR-03 Annually
Results of Review of Physical Access Records PE-08 Annually
Personnel Screening and Security PS-07 Continuous
File details come from the government source that posted it. Updated .