Attachment F - ACF External System Control Implementation Policy and Procedures_20251203.docx

DOCX document 157 KB Posted

Attached to
Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
Solicitation number
75P00126R00003
Issued by
Not on record

About this file

This is a policy and procedures document establishing security control requirements for external systems connecting to Administration for Children and Families (ACF) information systems.

The ACF External System Control Implementation Policy requires all external systems—including cloud service providers, contractor-operated systems, partner agency systems, third-party applications, and interconnected systems—to implement ACF baseline security controls to ensure consistent security posture and risk management. External systems must obtain an approved Authority to Operate (ATO) memo completed within the past three years, with security or risk assessments conducted promptly if authorization is not already in place. Compliance requirements include implementing security controls equivalent to ACF's system baseline controls (defined in ACF Control Baseline Rev5-Low and Rev5-Moderate), submitting documented evidence through System Security Plans, Security Assessment Reports, Plans of Action and Milestones, and continuous monitoring reports, and undergoing independent security control assessment by ACF-approved assessors or providing third-party certifications (SOC 2 or ISO 27001) completed within three years of intended connection. External system providers must establish information security and privacy programs meeting or exceeding ACF baseline requirements, demonstrate executive-level commitment to security implementation, and provide regular compliance reporting aligned with ACF's continuous monitoring strategy. The policy references Federal Information Security Modernization Act (FISMA), NIST SP 800-53 Rev. 5, OMB cybersecurity memoranda, Executive Order 13556 on Controlled Unclassified Information, and the Privacy Act of 1974. Non-compliance may result in connection termination, with regular audits verifying ongoing compliance and escalation procedures defined for non-compliance issues.

View the file

Other files for this federal contract opportunity

Other files attached to Legal Services for Unaccompanied Alien Children (UAC), newest first.
File Type Posted
Amendment 15 - RFP UAC Legal Services.pdf PDF
Amendment 15 - Attachment K Direct Representation Case Inventory Report June 06 2026.pdf PDF
Amendment 15 - Attachment J - Section F Deliverables Table June 06 2026.pdf PDF
Amendment 15 - Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services June 06 2026.pdf PDF
Amendment 15 - Attachment L Questions and Answers June 06 2026.pdf PDF
Attachment-G6-ACF_Interconnection Security Agreement_V1.0.docx DOCX document
Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx DOCX document
Attachment-G2-ACF_Business Impact Analysis.docx_V1.0.docx DOCX document
Attachment-G1-ACF_ E-Authentication Agreement_V1.0.docx DOCX document
Attachment H - Glossary of Abbreviations and Acronyms_20260513.docx DOCX document
RFP UAC LEGAL SERVICES 20260515.pdf PDF
Attachment-G8-ACF_System Categorization_V1.0.docx DOCX document
Attachment-G7-ACF_Privacy Impact Assessment_V1.0.docx DOCX document
Attachment I - Contractor Past Performance Narrative Template_20260513.docx DOCX document
Attachment C - Standard Form (SF)-1449_20260513.pdf PDF
Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services_20260515.docx DOCX document
Attachment A - Pricing Worksheet UAC Legal Services_20260513.xlsx XLSX spreadsheet
Attachment-G10-ACF_System Security Plan_V1.0.docx DOCX document
Attachment-G9-ACF_System Registration_V1.0.docx DOCX document
Attachment-G4-ACF_Contingency Plan.docx_V1.0.docx DOCX document
Attachment J - Section F Deliverables Schedules and Performance Requirements Summary Table_20260513.docx DOCX document
Attachment D - ORR Facilities by State_20260513.pdf PDF
Attachment A- Pricing Worksheet_2026.03.24 (Amd 0010).xlsx XLSX spreadsheet
Attachment C- Standard Form (SF)-1449.pdf PDF
75P00126R00003_2026.03.24 (Amd 0010).pdf PDF
Attachment B- Section C- PWS_2026.03.24 (Amd 0010).pdf PDF
Attachment G- ATO Templates-2025.zip ZIP file
75P00126R00003_2026.02.23.pdf PDF
Attachment D - ORR Facilities by State.xlsx XLSX spreadsheet
Attachment F- ACF External System Control Implementation Policy and Procedures.pdf PDF
Attachment I- Past Performance Questionnaire.docx DOCX document
Attachment C- Standard Form (SF)-1449.pdf PDF
75P00126R00003 (Rev2)(Amd 0004)(12.11.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev2) (Amd 0004)(12.11.2025).xlsx XLSX spreadsheet
Attachment H- ATO Templates_2025 (Amd 0003).zip ZIP file
QA-75P00126R00003(12.09.2025) (Amd 0003).pdf PDF
75P00126R00003 (Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment J- Selected Controls (Low) (Amd 0003).xlsx XLSX spreadsheet
Attachment B-Pricing Worksheet UAC Legal Services (Rev1) (Amd 0003)(12.09.2025).xlsx XLSX spreadsheet
Attachment E- ORR Facilities by State (Amd 0003).pdf PDF
Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf PDF
Attachment I- Selected Controls (Moderate) (Amd 0003).xlsx XLSX spreadsheet
Attachment A- Performance Work Statement (PWS) (Rev1) (Amd 0003) (12.09.2025).pdf PDF
Attachment B- Pricing Worksheet UAC Legal Services (11.25.2025).xlsx XLSX spreadsheet
75P00126R00003.pdf PDF
Attachment A - Performance Work Statement (PWS)_2025.11.24.pdf PDF
Attachment D- Standard Form (SF)-1449.pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP).pdf PDF
Attachment B- Pricing Worksheet UAC Legal Services.xlsx XLSX spreadsheet
Attachment C- HHS Subcontracting Plan Review Form.doc DOC document
Show all 50

Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ACF External System Control Implementation Policy and Procedures

ACF OCIO

Version 0.1

Dated 12/3/2025

Table 1. Document Revision History

Version
Date
Pages Affected
Description
Author
0.1
12/3/2025
All
Initial Version
Cybersecurity & Privacy (CSP) Team

ACF External System Control Implementation Policy and Procedures iii

Table of Contents

Policy Statement1
Authority1
Scope1
Compliance and Enforcement2
Roles and Responsibilities3
Requirements3
Access Control-20 (AC-20): Use of External Information Systems3
Protecting Controlled Unclassified Information on External System4
Appendix5
References5

1. Policy Statement The Administration for Children and Families (ACF) require all external systems that connect to, interface with, or provide services to ACF systems to implement ACF baseline security controls to ensure consistent security posture and risk management across the enterprise.

2. Authority

· Federal Information Security Modernization Act (FISMA)

· NIST SP 800-53 Rev. 5

· HHS Information Security and Privacy Policy (IS2P): Available on the HHS intranet.

Policies, Standards, Memoranda & Guide

· OMB Memoranda on Federal Cybersecurity

· Executive Order 13556, "Controlled Unclassified Information" (November 4, 2010).

· 32 CFR Part 2002, "Controlled Unclassified Information"

· Federal Information Security Modernization Act (FISMA) of 2014

· Privacy Act of 1974, as amended

· Federal Records Act

3. Scope This policy applies to all external systems, including but not limited to:

· Cloud service providers

· Contractor-operated systems

· Partner agency systems

· Third-party applications and services

· Interconnected systems

4. Compliance and Enforcement Non-compliance may result in connection termination. Regular audits will verify ongoing compliance.

Escalation procedures defined for non-compliance issues.

5. Roles and Responsibilities

Roles
Responsibilities
ACF ISSO/SSPO
Policy enforcement and compliance monitoring
A&A Team
Assessment coordination and validation
External System Owner
Control implementation and documentation
Contracting Officer (COR)
Contract compliance enforcement
Authorizing Official (AO)
Making risk-based decision to authorize system

6. Requirements ACF requires that any external information system connected to ACF systems must have an approved Authority to Operate (ATO) memo completed within the past 3 years. A security assessment or risk assessment will take place as soon as possible if Security Authorization is not already in place.

In addition, when ACF systems enter a trust relationship with external organizations, the following ACF-defined controls must be implemented:

· Documented description, specific use, and access restrictions for how restricted or highly restricted data will be processed, stored, or transmitted.

· Cloud Service Providers (and other external system owners) must enforce:

· Access controls aligned to documented and approved user roles, responsibilities, and privileges.

· Monthly reviews of all system accounts and access.

· Least privilege access for all users.

Access Control-20 (AC-20): Use of External Information Systems External systems connecting to ACF must:

1. Control Implementation: Implement security controls equivalent to ACF's system baseline controls as defined in the current ACF Control Baseline in Appendix X (Appendix X Rev5-Low and Appendix X Rev5-Moderate)

2. Provide documented evidence of control implementation through:

· System Security Plans (SSP)

· Security Assessment Reports (SAR)

· Plan of Action and Milestones (POA&Ms)

· Continuous monitoring reports

3. Submit to independent security control assessment by ACF-approved assessors or provide assessment report or certification (e.g. SOC 2 or ISO 27001 certification). The assessment must have occurred within 3 years of intended connection to the ACF system.

4. Execute formal agreements (Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), or contracts) specifying security control requirements.

Protecting Controlled Unclassified Information on External System External system providers must:

1. Establish and maintain information security and privacy programs that meet or exceed ACF baseline requirements as advised or stipulated within the security and privacy requirements (standard language) stipulated in contract or collaborative agreement.

ACF Tech Standard Language Document.

2. Demonstrate executive-level commitment to security program implementation.

3. Provide regular compliance reporting aligned with ACF's continuous monitoring strategy.

7. Appendix Standards and Guidelines

· NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations"

· NIST Special Publication 800-53, "Security and Privacy Controls for Federal Information Systems and Organizations"

· CISA Cybersecurity Framework

· HHS Information Security Program Policy

References Chapter 2: Interagency Agreement: Available on the HHS intranet.

Chapter 2 - Interagency Agreeme

ACF Appendix X Rev5 Moderate and Low Baseline Control Selections:

Appendix X-Rev5-Moderate.xlsx

Appendix X Rev5-Low.xlsx image2.png image3.png image4.png image1.png

File details come from the government source that posted it. Updated .