Attachment F - ACF External System Control Implementation Policy and Procedures_20251203.docx
DOCX document 157 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is a policy and procedures document establishing security control requirements for external systems connecting to Administration for Children and Families (ACF) information systems.
The ACF External System Control Implementation Policy requires all external systems—including cloud service providers, contractor-operated systems, partner agency systems, third-party applications, and interconnected systems—to implement ACF baseline security controls to ensure consistent security posture and risk management. External systems must obtain an approved Authority to Operate (ATO) memo completed within the past three years, with security or risk assessments conducted promptly if authorization is not already in place. Compliance requirements include implementing security controls equivalent to ACF's system baseline controls (defined in ACF Control Baseline Rev5-Low and Rev5-Moderate), submitting documented evidence through System Security Plans, Security Assessment Reports, Plans of Action and Milestones, and continuous monitoring reports, and undergoing independent security control assessment by ACF-approved assessors or providing third-party certifications (SOC 2 or ISO 27001) completed within three years of intended connection. External system providers must establish information security and privacy programs meeting or exceeding ACF baseline requirements, demonstrate executive-level commitment to security implementation, and provide regular compliance reporting aligned with ACF's continuous monitoring strategy. The policy references Federal Information Security Modernization Act (FISMA), NIST SP 800-53 Rev. 5, OMB cybersecurity memoranda, Executive Order 13556 on Controlled Unclassified Information, and the Privacy Act of 1974. Non-compliance may result in connection termination, with regular audits verifying ongoing compliance and escalation procedures defined for non-compliance issues.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ACF External System Control Implementation Policy and Procedures
ACF OCIO
Version 0.1
Dated 12/3/2025
Table 1. Document Revision History
| Version |
| Date |
| Pages Affected |
| Description |
| Author |
| 0.1 |
| 12/3/2025 |
| All |
| Initial Version |
| Cybersecurity & Privacy (CSP) Team |
ACF External System Control Implementation Policy and Procedures iii
Table of Contents
| Policy Statement | 1 |
| Authority | 1 |
| Scope | 1 |
| Compliance and Enforcement | 2 |
| Roles and Responsibilities | 3 |
| Requirements | 3 |
| Access Control-20 (AC-20): Use of External Information Systems | 3 |
| Protecting Controlled Unclassified Information on External System | 4 |
| Appendix | 5 |
| References | 5 |
1. Policy Statement The Administration for Children and Families (ACF) require all external systems that connect to, interface with, or provide services to ACF systems to implement ACF baseline security controls to ensure consistent security posture and risk management across the enterprise.
2. Authority
· Federal Information Security Modernization Act (FISMA)
· NIST SP 800-53 Rev. 5
· HHS Information Security and Privacy Policy (IS2P): Available on the HHS intranet.
Policies, Standards, Memoranda & Guide
· OMB Memoranda on Federal Cybersecurity
· Executive Order 13556, "Controlled Unclassified Information" (November 4, 2010).
· 32 CFR Part 2002, "Controlled Unclassified Information"
· Federal Information Security Modernization Act (FISMA) of 2014
· Privacy Act of 1974, as amended
· Federal Records Act
3. Scope This policy applies to all external systems, including but not limited to:
· Cloud service providers
· Contractor-operated systems
· Partner agency systems
· Third-party applications and services
· Interconnected systems
4. Compliance and Enforcement Non-compliance may result in connection termination. Regular audits will verify ongoing compliance.
Escalation procedures defined for non-compliance issues.
5. Roles and Responsibilities
| Roles |
| Responsibilities |
| ACF ISSO/SSPO |
| Policy enforcement and compliance monitoring |
| A&A Team |
| Assessment coordination and validation |
| External System Owner |
| Control implementation and documentation |
| Contracting Officer (COR) |
| Contract compliance enforcement |
| Authorizing Official (AO) |
| Making risk-based decision to authorize system |
6. Requirements ACF requires that any external information system connected to ACF systems must have an approved Authority to Operate (ATO) memo completed within the past 3 years. A security assessment or risk assessment will take place as soon as possible if Security Authorization is not already in place.
In addition, when ACF systems enter a trust relationship with external organizations, the following ACF-defined controls must be implemented:
· Documented description, specific use, and access restrictions for how restricted or highly restricted data will be processed, stored, or transmitted.
· Cloud Service Providers (and other external system owners) must enforce:
· Access controls aligned to documented and approved user roles, responsibilities, and privileges.
· Monthly reviews of all system accounts and access.
· Least privilege access for all users.
Access Control-20 (AC-20): Use of External Information Systems External systems connecting to ACF must:
1. Control Implementation: Implement security controls equivalent to ACF's system baseline controls as defined in the current ACF Control Baseline in Appendix X (Appendix X Rev5-Low and Appendix X Rev5-Moderate)
2. Provide documented evidence of control implementation through:
· System Security Plans (SSP)
· Security Assessment Reports (SAR)
· Plan of Action and Milestones (POA&Ms)
· Continuous monitoring reports
3. Submit to independent security control assessment by ACF-approved assessors or provide assessment report or certification (e.g. SOC 2 or ISO 27001 certification). The assessment must have occurred within 3 years of intended connection to the ACF system.
4. Execute formal agreements (Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), or contracts) specifying security control requirements.
Protecting Controlled Unclassified Information on External System External system providers must:
1. Establish and maintain information security and privacy programs that meet or exceed ACF baseline requirements as advised or stipulated within the security and privacy requirements (standard language) stipulated in contract or collaborative agreement.
ACF Tech Standard Language Document.
2. Demonstrate executive-level commitment to security program implementation.
3. Provide regular compliance reporting aligned with ACF's continuous monitoring strategy.
7. Appendix Standards and Guidelines
· NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations"
· NIST Special Publication 800-53, "Security and Privacy Controls for Federal Information Systems and Organizations"
· CISA Cybersecurity Framework
· HHS Information Security Program Policy
References Chapter 2: Interagency Agreement: Available on the HHS intranet.
Chapter 2 - Interagency Agreeme
ACF Appendix X Rev5 Moderate and Low Baseline Control Selections:
Appendix X-Rev5-Moderate.xlsx
Appendix X Rev5-Low.xlsx image2.png image3.png image4.png image1.png
File details come from the government source that posted it. Updated .