Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf

PDF 204 KB Posted

Attached to
Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
Solicitation number
75P00126R00003
Issued by
Not on record

About this file

This document is an External System Control Implementation Policy and Procedures document for the Administration for Children and Families (ACF) Office of the Chief Information Officer (OCIO), dated December 3, 2025. The policy establishes comprehensive cybersecurity requirements for external systems connecting to ACF systems, including cloud service providers, contractor-operated systems, partner agency systems, and third-party applications.

Key requirements include mandatory security control implementation equivalent to ACF's baseline controls, obtaining an Authority to Operate (ATO) memo within the past 3 years, submitting documented evidence of control implementation (such as System Security Plans and Security Assessment Reports), and executing formal security agreements. External system providers must establish information security and privacy programs meeting ACF baseline requirements, demonstrate executive-level security commitment, and provide regular compliance reporting. Non-compliance may result in connection termination, with regular audits to verify ongoing adherence to the policy. The document is grounded in federal cybersecurity regulations including FISMA, NIST guidelines, and HHS Information Security Program Policy.

View the file

Other files for this federal contract opportunity

Other files attached to Legal Services for Unaccompanied Alien Children (UAC), newest first.
File Type Posted
Amendment 15 - Attachment K Direct Representation Case Inventory Report June 06 2026.pdf PDF
Amendment 15 - RFP UAC Legal Services.pdf PDF
Attachment-G5-ACF_Incident Response Plan_V1.0.docx DOCX document
Attachment E - Quality Assurance Surveillance Plan (QASP) UAC Legal Services_20260515.docx DOCX document
Attachment-G8-ACF_System Categorization_V1.0.docx DOCX document
Attachment-G7-ACF_Privacy Impact Assessment_V1.0.docx DOCX document
Attachment I - Contractor Past Performance Narrative Template_20260513.docx DOCX document
Attachment C - Standard Form (SF)-1449_20260513.pdf PDF
Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services_20260515.docx DOCX document
Attachment A - Pricing Worksheet UAC Legal Services_20260513.xlsx XLSX spreadsheet
Attachment-G6-ACF_Interconnection Security Agreement_V1.0.docx DOCX document
Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx DOCX document
Attachment-G2-ACF_Business Impact Analysis.docx_V1.0.docx DOCX document
Attachment-G1-ACF_ E-Authentication Agreement_V1.0.docx DOCX document
Attachment H - Glossary of Abbreviations and Acronyms_20260513.docx DOCX document
Attachment F - ACF External System Control Implementation Policy and Procedures_20251203.docx DOCX document
RFP UAC LEGAL SERVICES 20260515.pdf PDF
Attachment J- Questions and Answers_2026.03.24 (Amd 0010).pdf PDF
75P00126R00003_2026.03.24 (Amd 0010).pdf PDF
Attachment A- Pricing Worksheet_2026.03.24 (Amd 0010).xlsx XLSX spreadsheet
Attachment C- Standard Form (SF)-1449.pdf PDF
Attachment A- Pricing Worksheet UAC Legal Services (Amd. 0007) 2026.02.23.xlsx XLSX spreadsheet
Attachment B- Section C- PWS (Amd 0007) 2026.02.23.pdf PDF
Attachment E- Quality Assurance Surveillance Plan (QASP) (Amd. 0007) 2026.02.23.pdf PDF
Attachment H- Glossary of Abbreviations and Acronyms.pdf PDF
75P00126R00003_2026.02.23.pdf PDF
Attachment D - ORR Facilities by State.xlsx XLSX spreadsheet
Attachment F- ACF External System Control Implementation Policy and Procedures.pdf PDF
Attachment I- Past Performance Questionnaire.docx DOCX document
Attachment G- ATO Templates-2025.zip ZIP file
Attachment C- Standard Form (SF)-1449.pdf PDF
QA-75P00126R00003(Rev1) (Amd 0004)(12.11.2025)#Q127.pdf PDF
75P00126R00003 (Rev2)(Amd 0004)(12.11.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev2) (Amd 0004)(12.11.2025).xlsx XLSX spreadsheet
Attachment A- Performance Work Statement (PWS) (Rev1) (Amd 0003) (12.09.2025).pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP)(Rev1)(Amd 0003)(12.09.2025).pdf PDF
QA-75P00126R00003(12.09.2025) (Amd 0003).pdf PDF
75P00126R00003 (Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment J- Selected Controls (Low) (Amd 0003).xlsx XLSX spreadsheet
Attachment H- ATO Templates_2025 (Amd 0003).zip ZIP file
Attachment B-Pricing Worksheet UAC Legal Services (Rev1) (Amd 0003)(12.09.2025).xlsx XLSX spreadsheet
Attachment E- ORR Facilities by State (Amd 0003).pdf PDF
Attachment I- Selected Controls (Moderate) (Amd 0003).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services (11.25.2025).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services.xlsx XLSX spreadsheet
Attachment C- HHS Subcontracting Plan Review Form.doc DOC document
75P00126R00003.pdf PDF
Attachment A - Performance Work Statement (PWS)_2025.11.24.pdf PDF
Attachment D- Standard Form (SF)-1449.pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP).pdf PDF
Show all 50

Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ACF External System Control Implementation Policy and Procedures

ACF OCIO

Version 0.1

Dated 12/3/2025

ACF External System Control Implementation Policy and Procedures ACF OCIO

Version 0.1 ACF External System Control Implementation Policy and Procedures ii

Table 1. Document Revision History

Version Date Pages Affected Description Author

0.1 12/3/2025 All Initial Version Cybersecurity & Privacy (CSP) Team

Version 0.1 ACF External System Control Implementation Policy and Procedures iii

Table of Contents

1. Policy Statement

2. Authority

3. Scope

4. Compliance and Enforcement

5. Roles and Responsibilities

6. Requirements

Access Control-20 (AC-20): Use of External Information Systems Protecting Controlled Unclassified Information on External System

7. Appendix References

Version 0.1 1

1. Policy Statement The Administration for Children and Families (ACF) require all external systems that connect to, interface with, or provide services to ACF systems to implement ACF baseline security controls to ensure consistent security posture and risk management across the enterprise.

2. Authority

• Federal Information Security Modernization Act (FISMA)

• NIST SP 800-53 Rev. 5

• HHS Information Security and Privacy Policy (IS2P): Available on the HHS intranet.

Policies, Standards, Memoranda & Guides

• OMB Memoranda on Federal Cybersecurity

• Executive Order 13556, "Controlled Unclassified Information" (November 4, 2010).

• 32 CFR Part 2002, "Controlled Unclassified Information"

• Federal Information Security Modernization Act (FISMA) of 2014

• Privacy Act of 1974, as amended

• Federal Records Act

3. Scope This policy applies to all external systems, including but not limited to:

• Cloud service providers

• Contractor-operated systems

• Partner agency systems

• Third-party applications and services

• Interconnected systems https://intranet.hhs.gov/it/cybersecurity/policies/index.html

Version 0.1 2

4. Compliance and Enforcement Non-compliance may result in connection termination.

Regular audits will verify ongoing compliance.

Escalation procedures defined for non-compliance issues.

Version 0.1 3

5. Roles and Responsibilities Roles Responsibilities ACF ISSO/SSPO Policy enforcement and compliance monitoring A&A Team Assessment coordination and validation External System Owner Control implementation and documentation Contracting Officer (COR) Contract compliance enforcement Authorizing Official (AO) Making risk-based decision to authorize system

6. Requirements ACF requires that any external information system connected to ACF systems must have an approved Authority to Operate (ATO) memo completed within the past 3 years. A security assessment or risk assessment will take place as soon as possible if Security Authorization is not already in place.

In addition, when ACF systems enter a trust relationship with external organizations, the following ACF-defined controls must be implemented:

• Documented description, specific use, and access restrictions for how restricted or highly restricted data will be processed, stored, or transmitted.

• Cloud Service Providers (and other external system owners) must enforce:

o Access controls aligned to documented and approved user roles, responsibilities, and privileges.

o Monthly reviews of all system accounts and access.

o Least privilege access for all users.

Access Control-20 (AC-20): Use of External Information Systems External systems connecting to ACF must:

1. Control Implementation: Implement security controls equivalent to ACF's system baseline controls as defined in the current ACF Control Baseline in Appendix X (Appendix X Rev5-Low and Appendix X Rev5-Moderate)

2. Provide documented evidence of control implementation through:

• System Security Plans (SSP)

• Security Assessment Reports (SAR)

Version 0.1 4

• Plan of Action and Milestones (POA&Ms)

• Continuous monitoring reports

3. Submit to independent security control assessment by ACF-approved assessors or provide assessment report or certification (e.g. SOC 2 or ISO 27001 certification). The assessment must have occurred within 3 years of intended connection to the ACF system.

4. Execute formal agreements (Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), or contracts) specifying security control requirements.

Protecting Controlled Unclassified Information on External System External system providers must:

1. Establish and maintain information security and privacy programs that meet or exceed ACF baseline requirements as advised or stipulated within the security and privacy requirements (standard language) stipulated in contract or collaborative agreement.

ACF Tech Standard Language Document.p

2. Demonstrate executive-level commitment to security program implementation.

3. Provide regular compliance reporting aligned with ACF's continuous monitoring strategy.

Version 0.1 5

7. Appendix Standards and Guidelines

• NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations"

• NIST Special Publication 800-53, "Security and Privacy Controls for Federal Information Systems and Organizations"

• CISA Cybersecurity Framework

• HHS Information Security Program Policy

References Chapter 2: Interagency Agreement: Available on the HHS intranet.

Chapter 2 - Interagency Agreemen

ACF Appendix X Rev5 Moderate and Low Baseline Control Selections:

Appendix X-Rev5-Moderate.xlsx

Appendix X Rev5-Low.xlsx https://intranet.hhs.gov/manual/fmdg/volume-viii-chapter-2#6.1

1. Policy Statement
2. Authority
3. Scope
4. Compliance and Enforcement
5. Roles and Responsibilities
6. Requirements
Access Control-20 (AC-20): Use of External Information Systems
Protecting Controlled Unclassified Information on External System
7. Appendix
References

File details come from the government source that posted it. Updated .