Amendment 2 RFP CACS 71818 QA 2.pdf

PDF 308 KB Posted

Attached to
Comprehensive Analytical Chemistry Support Federal contract opportunity
Solicitation number
75D301-21-R-71818
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

This document contains answers to questions regarding a solicitation for comprehensive analytical chemistry support services. The solicitation was issued by the Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services. It seeks proposals for analytical chemistry support due by May 27, 2021. Key requirements include encrypting data at rest, multi-factor authentication for privileged and PII accounts, conducting security assessments and plans such as an ATO and IRP approved by CDC, background checks for contractor personnel working with NIOSH including a minimum NACI, vulnerability scanning weekly for high/HVA systems and monthly for all others, and addressing any vulnerabilities within 10 days.

View the file

Other files for this federal contract opportunity

Other files attached to Comprehensive Analytical Chemistry Support, newest first.
File Type Posted
Amendment 1 RFP CACS 71818 QA 1.pdf PDF
J.3 CEMB SOPs.zip ZIP file
J.5 Samples.zip ZIP file
J.2 PERFORMANCE_BASED_AWARD_FEE_EVALUATION_CRITERIA_3-25-2021.pdf PDF
J.1 HHS SubK Plan Template - updated 121620.doc DOC document
RFP 75D301-21-R-71818 CACS 4-27-21.pdf PDF
J.6 ACH-Vendor.pdf PDF
J.4 QA_Manual_Feb2021-2.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

1. CONTRACT ID CODE

PAGE OF PAGES

1 4

2. AMENDMENT/MODIFICATION NO.

00003

3. EFFECTIVE DATE

See Block 16C

4. REQUISITION/PURCHASE REQ. NO.

5. PROJECT NO. (If applicable)

6. ISSUED BY CODE 436 7. ADMINISTERED BY (If other than Item 6) CODE 436 Centers for Disease Control and Prevention

(CDC)

Office of Acquisition Services (OAS) 626 Cochrans Mill Rd Pittsburgh, PA 15236-0070

Centers for Disease Control and Prevention (CDC) Office of Acquisition Services (OAS) 626 Cochrans Mill Rd Pittsburgh, PA 15236-0070

8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)

X

9A. AMENDMENT OF SOLICITATION NO.

75D301-21-R-71818

9B. DATED (See Item 11)

04/27/2021

10A. MODIFICATION OF CONTRACT/ORDER NO.

10B. DATED (See Item 13)

CODE FACILITY CODE

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers is extended, X is not extended.

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:

(a) By completing Items 8 and 15, and returning 1 copy of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

12. ACCOUNTING AND APPROPRIATION DATA (If required)

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority)

E. IMPORTANT: Contractor is not, X is required to sign this document and return 1 copies to the issuing office.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

The purpose of this amendment is to answer questions. Part 2.

See Pages 2-4.

All other terms and conditions remain unchanged.

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER (Type or print)

16A. NAME OF CONTRACTING OFFICER

Diane J Meeder

15B. CONTRACTOR/OFFEROR

(Signature of person authorized to sign)

15C. DATE SIGNED

16B. UNITED STATES OF AMERICA

BY ___________________________________________

(Signature of Contracting Officer)

16C. DATE SIGNED

NSN 7540-01-152-8070 STANDARD FORM 30 (REV. 10-83)

PREVIOUS EDITION UNUSABLE 30-105 Prescribed by GSA

FAR (48 CFR) 53.243

ITEM 10A.

Answers to Questions #2 RFP#71818

1. In section 9 (pages 18 – 37), there are mentions of several new security requirements including SA&A, BSI, PTA, SSP, RAR, POA&M, a contingency plan, and an E-authentication assessment. Are these all required for this contract?

A.1-1.Yes.

If increased security measures are required, are these recoverable costs?

A.1-2. Costs may or may not be recoverable as direct or indirect costs. Per the FAR, allowable costs are costs that are reasonable and allocable to the contract and are in the terms of the contract, Cost Accounting Standards (CAS) and the FAR. Please see FAR 31 and FAR 31.201-2.

2. Is it necessary to encrypt data while it is at rest as long as it is being encrypted in transit? This is mentioned on page 21 of the RFP. If additional security measures are required, can the cost be recouped?

A.2 Data at rest must be encrypted to protect confidentiality and integrity of NIOSH information assets.

3. On page 24, section G-2, it states we must follow and adhere to NIST SP 800-64. This standard was withdrawn in 2019, is system documentation still required in this fashion?

A.3 800-64 was withdrawn as the content is out of date. Refer to NIST SP 800-160 Volume 1 for current information about system life cycle processes and systems security engineering, and the Risk Management Framework (SP 800-37 Rev. 2) for current information on system development life cycle processes and stages.

https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

4. On page 24 of RFP it states requirement for sanitization of government files and information. . Is it acceptable to sanitize government files and information through deletion of backup files after 7 years of retention as this is current company policy?

A.4 Data may be sanitized after meeting the 7-year retention requirement.

Note: NIOSH requires audit records retains for 7 Years, this timeframe provides support for after-the-fact investigations of security incidents and to meet regulatory and CDC/NIOSH information retention requirements.

5. On page 25 of RFP it is stated that card readers are a requirement for servers, printers, desktops, and laptops. Is this a necessary requirement as our servers are hosted in a data center? Is there an expectation that we must utilize cloud based architecture? Are card readers a requirement for printers, desktops and laptops or is having password protection enough?

A.5 Card readers must be included in the purchase of servers, printers, desktops, and laptops.

Cloud architecture is not mandated, but if cloud services are used then all HHS FedRAMP Privacy and Security Requirements Involving Cloud Services are applicable.

Card readers are a hardware requirement. Password protection is not sufficient. Hosting section outlines requirements for MFA. Employ multi-factor authentication to privileged accounts and non-privileged accounts with access to PII. This requires the use of two- factor authentication with one factor being separate from the computer itself.

6. Who is required to certify protection of agency data as specified on page 27? What would be defined as an

ATO? Is this internal or does it require an external auditor? If the auditor is required to be 3rd party, who will select the 3rd party auditing partner? Is an annual assessment / Pen test (page 28) required for this contract? If so, is it required to be performed by a 3rd party?

https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

A.6 The authorizing official with the authority to formally assume responsibility for operating an information system at an acceptable level of risk.

The official management decision to authorize operation of an information system and to explicitly accept the risk to organizational operations based on the implementation of an agreed-upon set of security controls.

It is the CTR’s responsibility to conduct the SA&A requirements. CDC/NIOSH acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the system security and privacy controls are implemented and operating effectively.

Yes, as part of hosting or operating a system on behalf of the government an Annual Assessment must be conducted and may include a Pen Test. Penetration testing conducted by the agency or independent third-party on behalf of the agency.

If cloud services are used then all HHS FedRAMP Privacy and Security Requirements Involving Cloud Services are applicable. This includes: A security control assessment must be conducted by a FedRAMP third-party assessment organization (3PAO) for the initial ATO and annually thereafter or whenever there is a significant change to the system’s security posture in accordance with the FedRAMP Continuous Monitoring Plan.

7. Is the Security Content Automation Protocol (SCAP) (page 29) a requirement for this contract? We utilize a different program (Rapid 7 Nexpose), is this acceptable?

A.7 Security Content Automation Protocol (SCAP) is a protocol. Rapid 7 Nexpose is a tool (vulnerability scanner) that supports SCAP. NIST lists Rapid7 Nexpose 6 on the NIST Security Content Automation Protocol Validation Program website. The vendor assertions document (aka Vendor Provided SCAP Information) was provided by the vendor. The descriptions do not imply endorsement by the U.S.

Government or NIST.

https://csrc.nist.gov/projects/security-content-automation-protocol https://csrc.nist.gov/projects/scap-validation-program/validated-products-and-modules/138-rapid7-scap-1-2-product-validation-record https://help.rapid7.com/nexpose/en-us/Files/SCAP_compliance.html

8. For Authenticated Vulnerability Scans and Application Scans on page 35, what applications need to be scanned and at what intervals? How would this be reported?

A.8 All systems and applications used to host or operate a system on behalf of the government must be scanned on a continuous basis. The frequency must be defined in the system security plan. This does not necessarily require constant scanning. Most systems are scanned at least weekly for vulnerabilities and applications are scanned at least monthly. Any update or change to the system require scanning to ensure additional vulnerabilities were not introduced as part of the change.

Scan results are typically provided via syslog in near real time with monthly reports provided via SFTP.

Other reporting options can be considered as part of the System Security Plan. Vulnerabilities that cannot be remediated within 10 days must be reported to the government as part of the POA&M process consistent with the HHS Standard for Plan of Action and Milestones and CDC policies.

9. The RFP states on page 29 that weekly scans and results are to be provided to C/I/O/ISSO and OCISO ISCM for systems with a FIPS 199 impact level of High, HVA, or if the system contains PII, and ensure scan results are submitted in either CSV or PDF format. What will need to be scanned and reported? Is this applicable since our systems will not contain PII?

https://csrc.nist.gov/projects/security-content-automation-protocol https://csrc.nist.gov/projects/scap-validation-program/validated-products-and-modules/138-rapid7-scap-1-2-product-validation-record https://csrc.nist.gov/projects/scap-validation-program/validated-products-and-modules/138-rapid7-scap-1-2-product-validation-record https://help.rapid7.com/nexpose/en-us/Files/SCAP_compliance.html

A.9 All system components on a monthly basis – required for systems which do not contain PII.

10. Our company policy dictates that we cannot provide our incident and breach response plan as mentioned on page 36. Is this acceptable? Can anything else be used to in lieu of the policy?

A.10 The vendor must provide an Incident and Breach Response Plan (IRP). The plan can be specific to the system hosted on behalf of the government as opposed to the vendors entire incident response plan. in accordance with HHS CDC, OMB, and US-CERT requirements and obtain approval from the CDC. In addition, the Contractor must follow the incident response and US-CERT reporting guidance contained in the FedRAMP Incident Communications

11. What is required for background checks for individuals working with NIOSH? Will employment prescreening background checks suffice? (Page 24)

A.11 The employees of the awardee that will work with NIOSH will undergo a government background investigation (BI) that includes questionnaires and fingerprinting. Employment prescreening background checks will not suffice. A minimum BI is a NACI.

2021-05-21T11:32:00-0400
Diane J. Meeder -S

File details come from the government source that posted it. Updated .