Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf
PDF 204 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This document is an External System Control Implementation Policy and Procedures document for the Administration for Children and Families (ACF) Office of the Chief Information Officer (OCIO), dated December 3, 2025. The policy establishes comprehensive cybersecurity requirements for external systems connecting to ACF systems, including cloud service providers, contractor-operated systems, partner agency systems, and third-party applications.
Key requirements include mandatory security control implementation equivalent to ACF's baseline controls, obtaining an Authority to Operate (ATO) memo within the past 3 years, submitting documented evidence of control implementation (such as System Security Plans and Security Assessment Reports), and executing formal security agreements. External system providers must establish information security and privacy programs meeting ACF baseline requirements, demonstrate executive-level security commitment, and provide regular compliance reporting. Non-compliance may result in connection termination, with regular audits to verify ongoing adherence to the policy. The document is grounded in federal cybersecurity regulations including FISMA, NIST guidelines, and HHS Information Security Program Policy.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ACF External System Control Implementation Policy and Procedures
ACF OCIO
Version 0.1
Dated 12/3/2025
ACF External System Control Implementation Policy and Procedures ACF OCIO
Version 0.1 ACF External System Control Implementation Policy and Procedures ii
Table 1. Document Revision History
Version Date Pages Affected Description Author
0.1 12/3/2025 All Initial Version Cybersecurity & Privacy (CSP) Team
Version 0.1 ACF External System Control Implementation Policy and Procedures iii
Table of Contents
1. Policy Statement
2. Authority
3. Scope
4. Compliance and Enforcement
5. Roles and Responsibilities
6. Requirements
Access Control-20 (AC-20): Use of External Information Systems Protecting Controlled Unclassified Information on External System
7. Appendix References
Version 0.1 1
1. Policy Statement The Administration for Children and Families (ACF) require all external systems that connect to, interface with, or provide services to ACF systems to implement ACF baseline security controls to ensure consistent security posture and risk management across the enterprise.
2. Authority
• Federal Information Security Modernization Act (FISMA)
• NIST SP 800-53 Rev. 5
• HHS Information Security and Privacy Policy (IS2P): Available on the HHS intranet.
Policies, Standards, Memoranda & Guides
• OMB Memoranda on Federal Cybersecurity
• Executive Order 13556, "Controlled Unclassified Information" (November 4, 2010).
• 32 CFR Part 2002, "Controlled Unclassified Information"
• Federal Information Security Modernization Act (FISMA) of 2014
• Privacy Act of 1974, as amended
• Federal Records Act
3. Scope This policy applies to all external systems, including but not limited to:
• Cloud service providers
• Contractor-operated systems
• Partner agency systems
• Third-party applications and services
• Interconnected systems https://intranet.hhs.gov/it/cybersecurity/policies/index.html
Version 0.1 2
4. Compliance and Enforcement Non-compliance may result in connection termination.
Regular audits will verify ongoing compliance.
Escalation procedures defined for non-compliance issues.
Version 0.1 3
5. Roles and Responsibilities Roles Responsibilities ACF ISSO/SSPO Policy enforcement and compliance monitoring A&A Team Assessment coordination and validation External System Owner Control implementation and documentation Contracting Officer (COR) Contract compliance enforcement Authorizing Official (AO) Making risk-based decision to authorize system
6. Requirements ACF requires that any external information system connected to ACF systems must have an approved Authority to Operate (ATO) memo completed within the past 3 years. A security assessment or risk assessment will take place as soon as possible if Security Authorization is not already in place.
In addition, when ACF systems enter a trust relationship with external organizations, the following ACF-defined controls must be implemented:
• Documented description, specific use, and access restrictions for how restricted or highly restricted data will be processed, stored, or transmitted.
• Cloud Service Providers (and other external system owners) must enforce:
o Access controls aligned to documented and approved user roles, responsibilities, and privileges.
o Monthly reviews of all system accounts and access.
o Least privilege access for all users.
Access Control-20 (AC-20): Use of External Information Systems External systems connecting to ACF must:
1. Control Implementation: Implement security controls equivalent to ACF's system baseline controls as defined in the current ACF Control Baseline in Appendix X (Appendix X Rev5-Low and Appendix X Rev5-Moderate)
2. Provide documented evidence of control implementation through:
• System Security Plans (SSP)
• Security Assessment Reports (SAR)
Version 0.1 4
• Plan of Action and Milestones (POA&Ms)
• Continuous monitoring reports
3. Submit to independent security control assessment by ACF-approved assessors or provide assessment report or certification (e.g. SOC 2 or ISO 27001 certification). The assessment must have occurred within 3 years of intended connection to the ACF system.
4. Execute formal agreements (Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), or contracts) specifying security control requirements.
Protecting Controlled Unclassified Information on External System External system providers must:
1. Establish and maintain information security and privacy programs that meet or exceed ACF baseline requirements as advised or stipulated within the security and privacy requirements (standard language) stipulated in contract or collaborative agreement.
ACF Tech Standard Language Document.p
2. Demonstrate executive-level commitment to security program implementation.
3. Provide regular compliance reporting aligned with ACF's continuous monitoring strategy.
Version 0.1 5
7. Appendix Standards and Guidelines
• NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations"
• NIST Special Publication 800-53, "Security and Privacy Controls for Federal Information Systems and Organizations"
• CISA Cybersecurity Framework
• HHS Information Security Program Policy
References Chapter 2: Interagency Agreement: Available on the HHS intranet.
Chapter 2 - Interagency Agreemen
ACF Appendix X Rev5 Moderate and Low Baseline Control Selections:
Appendix X-Rev5-Moderate.xlsx
Appendix X Rev5-Low.xlsx https://intranet.hhs.gov/manual/fmdg/volume-viii-chapter-2#6.1
| 1. Policy Statement |
| 2. Authority |
| 3. Scope |
| 4. Compliance and Enforcement |
| 5. Roles and Responsibilities |
| 6. Requirements |
| Access Control-20 (AC-20): Use of External Information Systems |
| Protecting Controlled Unclassified Information on External System |
| 7. Appendix |
| References |
File details come from the government source that posted it. Updated .