Attachment F- ACF External System Control Implementation Policy and Procedures.pdf

PDF 204 KB Posted

Attached to
Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
Solicitation number
75P00126R00003
Issued by
Not on record

About this file

This document is an ACF External System Control Implementation Policy and Procedures document issued by the Administration for Children and Families Office of the Chief Information Officer, Version 0.1, dated December 3, 2025.

The policy requires all external systems that connect to, interface with, or provide services to ACF systems to implement ACF baseline security controls to ensure consistent security posture and risk management. The policy applies to cloud service providers, contractor-operated systems, partner agency systems, third-party applications and services, and interconnected systems. External systems must obtain an approved Authority to Operate (ATO) memo completed within the past three years, with security assessments conducted if authorization is not already in place. Key requirements include implementing security controls equivalent to ACF's system baseline controls, providing documented evidence of implementation through System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action and Milestones (POA&Ms), and continuous monitoring reports, and submitting to independent security control assessment by ACF-approved assessors or providing certifications such as SOC 2 or ISO 27001 within three years of intended connection.

External system providers must establish information security and privacy programs meeting or exceeding ACF baseline requirements, enforce access controls aligned to documented user roles with monthly account reviews and least privilege access, and execute formal agreements such as Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), or contracts specifying security control requirements. Non-compliance may result in connection termination, with regular audits verifying ongoing compliance and escalation procedures defined for non-compliance issues. The policy is authorized under FISMA, NIST SP 800-53 Rev. 5, HHS Information Security and Privacy Policy, and related federal regulations regarding Controlled Unclassified Information.

View the file

Other files for this federal contract opportunity

Other files attached to Legal Services for Unaccompanied Alien Children (UAC), newest first.
File Type Posted
Amendment 15 - Attachment J - Section F Deliverables Table June 06 2026.pdf PDF
Amendment 15 - Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services June 06 2026.pdf PDF
Amendment 15 - Attachment L Questions and Answers June 06 2026.pdf PDF
Amendment 15 - RFP UAC Legal Services.pdf PDF
Attachment-G10-ACF_System Security Plan_V1.0.docx DOCX document
Attachment-G9-ACF_System Registration_V1.0.docx DOCX document
Attachment-G4-ACF_Contingency Plan.docx_V1.0.docx DOCX document
Attachment J - Section F Deliverables Schedules and Performance Requirements Summary Table_20260513.docx DOCX document
Attachment D - ORR Facilities by State_20260513.pdf PDF
Attachment-G5-ACF_Incident Response Plan_V1.0.docx DOCX document
Attachment E - Quality Assurance Surveillance Plan (QASP) UAC Legal Services_20260515.docx DOCX document
Attachment-G6-ACF_Interconnection Security Agreement_V1.0.docx DOCX document
Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx DOCX document
Attachment-G2-ACF_Business Impact Analysis.docx_V1.0.docx DOCX document
Attachment-G1-ACF_ E-Authentication Agreement_V1.0.docx DOCX document
Attachment H - Glossary of Abbreviations and Acronyms_20260513.docx DOCX document
Attachment F - ACF External System Control Implementation Policy and Procedures_20251203.docx DOCX document
RFP UAC LEGAL SERVICES 20260515.pdf PDF
Attachment B- Section C- PWS_2026.03.24 (Amd 0010).pdf PDF
Attachment J- Questions and Answers_2026.03.24 (Amd 0010).pdf PDF
Attachment A- Pricing Worksheet_2026.03.24 (Amd 0010).xlsx XLSX spreadsheet
Attachment C- Standard Form (SF)-1449.pdf PDF
Attachment C- Standard Form (SF)-1449.pdf PDF
Attachment A- Pricing Worksheet UAC Legal Services (Amd. 0007) 2026.02.23.xlsx XLSX spreadsheet
Attachment B- Section C- PWS (Amd 0007) 2026.02.23.pdf PDF
Attachment E- Quality Assurance Surveillance Plan (QASP) (Amd. 0007) 2026.02.23.pdf PDF
Attachment H- Glossary of Abbreviations and Acronyms.pdf PDF
Attachment G- ATO Templates-2025.zip ZIP file
75P00126R00003_2026.02.23.pdf PDF
Attachment D - ORR Facilities by State.xlsx XLSX spreadsheet
QA-75P00126R00003(Rev1) (Amd 0004)(12.11.2025)#Q127.pdf PDF
75P00126R00003 (Rev2)(Amd 0004)(12.11.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev2) (Amd 0004)(12.11.2025).xlsx XLSX spreadsheet
Attachment B-Pricing Worksheet UAC Legal Services (Rev1) (Amd 0003)(12.09.2025).xlsx XLSX spreadsheet
Attachment E- ORR Facilities by State (Amd 0003).pdf PDF
Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf PDF
Attachment I- Selected Controls (Moderate) (Amd 0003).xlsx XLSX spreadsheet
Attachment A- Performance Work Statement (PWS) (Rev1) (Amd 0003) (12.09.2025).pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP)(Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment H- ATO Templates_2025 (Amd 0003).zip ZIP file
QA-75P00126R00003(12.09.2025) (Amd 0003).pdf PDF
75P00126R00003 (Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment J- Selected Controls (Low) (Amd 0003).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services (11.25.2025).xlsx XLSX spreadsheet
Attachment F- Quality Assurance Surveillance Plan (QASP).pdf PDF
Attachment B- Pricing Worksheet UAC Legal Services.xlsx XLSX spreadsheet
Attachment C- HHS Subcontracting Plan Review Form.doc DOC document
75P00126R00003.pdf PDF
Attachment A - Performance Work Statement (PWS)_2025.11.24.pdf PDF
Attachment D- Standard Form (SF)-1449.pdf PDF
Show all 50

Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ACF External System Control Implementation Policy and Procedures

ACF OCIO

Version 0.1

Dated 12/3/2025

ACF External System Control Implementation Policy and Procedures ACF OCIO

Version 0.1 ACF External System Control Implementation Policy and Procedures ii

Table 1. Document Revision History

Version Date Pages Affected Description Author

0.1 12/3/2025 All Initial Version Cybersecurity & Privacy (CSP) Team

Version 0.1 ACF External System Control Implementation Policy and Procedures iii

Table of Contents

1. Policy Statement

2. Authority

3. Scope

4. Compliance and Enforcement

5. Roles and Responsibilities

6. Requirements

Access Control-20 (AC-20): Use of External Information Systems Protecting Controlled Unclassified Information on External System

7. Appendix References

Version 0.1 1

1. Policy Statement The Administration for Children and Families (ACF) require all external systems that connect to, interface with, or provide services to ACF systems to implement ACF baseline security controls to ensure consistent security posture and risk management across the enterprise.

2. Authority

• Federal Information Security Modernization Act (FISMA)

• NIST SP 800-53 Rev. 5

• HHS Information Security and Privacy Policy (IS2P): Available on the HHS intranet.

Policies, Standards, Memoranda & Guides

• OMB Memoranda on Federal Cybersecurity

• Executive Order 13556, "Controlled Unclassified Information" (November 4, 2010).

• 32 CFR Part 2002, "Controlled Unclassified Information"

• Federal Information Security Modernization Act (FISMA) of 2014

• Privacy Act of 1974, as amended

• Federal Records Act

3. Scope This policy applies to all external systems, including but not limited to:

• Cloud service providers

• Contractor-operated systems

• Partner agency systems

• Third-party applications and services

• Interconnected systems https://intranet.hhs.gov/it/cybersecurity/policies/index.html

Version 0.1 2

4. Compliance and Enforcement Non-compliance may result in connection termination.

Regular audits will verify ongoing compliance.

Escalation procedures defined for non-compliance issues.

Version 0.1 3

5. Roles and Responsibilities Roles Responsibilities ACF ISSO/SSPO Policy enforcement and compliance monitoring A&A Team Assessment coordination and validation External System Owner Control implementation and documentation Contracting Officer (COR) Contract compliance enforcement Authorizing Official (AO) Making risk-based decision to authorize system

6. Requirements ACF requires that any external information system connected to ACF systems must have an approved Authority to Operate (ATO) memo completed within the past 3 years. A security assessment or risk assessment will take place as soon as possible if Security Authorization is not already in place.

In addition, when ACF systems enter a trust relationship with external organizations, the following ACF-defined controls must be implemented:

• Documented description, specific use, and access restrictions for how restricted or highly restricted data will be processed, stored, or transmitted.

• Cloud Service Providers (and other external system owners) must enforce:

o Access controls aligned to documented and approved user roles, responsibilities, and privileges.

o Monthly reviews of all system accounts and access.

o Least privilege access for all users.

Access Control-20 (AC-20): Use of External Information Systems External systems connecting to ACF must:

1. Control Implementation: Implement security controls equivalent to ACF's system baseline controls as defined in the current ACF Control Baseline in Appendix X (Appendix X Rev5-Low and Appendix X Rev5-Moderate)

2. Provide documented evidence of control implementation through:

• System Security Plans (SSP)

• Security Assessment Reports (SAR)

Version 0.1 4

• Plan of Action and Milestones (POA&Ms)

• Continuous monitoring reports

3. Submit to independent security control assessment by ACF-approved assessors or provide assessment report or certification (e.g. SOC 2 or ISO 27001 certification). The assessment must have occurred within 3 years of intended connection to the ACF system.

4. Execute formal agreements (Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), or contracts) specifying security control requirements.

Protecting Controlled Unclassified Information on External System External system providers must:

1. Establish and maintain information security and privacy programs that meet or exceed ACF baseline requirements as advised or stipulated within the security and privacy requirements (standard language) stipulated in contract or collaborative agreement.

ACF Tech Standard Language Document.p

2. Demonstrate executive-level commitment to security program implementation.

3. Provide regular compliance reporting aligned with ACF's continuous monitoring strategy.

Version 0.1 5

7. Appendix Standards and Guidelines

• NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations"

• NIST Special Publication 800-53, "Security and Privacy Controls for Federal Information Systems and Organizations"

• CISA Cybersecurity Framework

• HHS Information Security Program Policy

References Chapter 2: Interagency Agreement: Available on the HHS intranet.

Chapter 2 - Interagency Agreemen

ACF Appendix X Rev5 Moderate and Low Baseline Control Selections:

Appendix X-Rev5-Moderate.xlsx

Appendix X Rev5-Low.xlsx https://intranet.hhs.gov/manual/fmdg/volume-viii-chapter-2#6.1

1. Policy Statement
2. Authority
3. Scope
4. Compliance and Enforcement
5. Roles and Responsibilities
6. Requirements
Access Control-20 (AC-20): Use of External Information Systems
Protecting Controlled Unclassified Information on External System
7. Appendix
References

File details come from the government source that posted it. Updated .