Attachment-G5-ACF_Incident Response Plan_V1.0.docx

DOCX document 134 KB Posted

Attached to
Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
Solicitation number
75P00126R00003
Issued by
Not on record

About this file

This is an Incident Response Plan document for ACF (Administration for Children and Families) systems that outlines procedures, roles, and responsibilities for identifying, reporting, and managing security and privacy incidents.

The plan establishes a structured incident response framework requiring all system users to report suspected security events to their supervisors and the ACF Incident Response Team (IRT) at ACF_IRT@acf.hhs.gov. Upon receipt, the IRT Incident Coordinator creates a ticket in HHS Archer and automatically initiates either a Data Breach incident (if Personally Identifiable Information is involved) or an IT Security incident (if PII is not involved), with notifications sent to relevant Privacy and Security Operations teams. The plan defines incident prioritization using impact and urgency matrices, establishing four priority levels (PO, P1, P2, P3) with corresponding response times ranging from 4 to 24 hours and resolution times ranging from 16 to 72 hours. Key organizational roles include the ACF Chief Information Officer, Chief Information Security Officer, Senior Official for Privacy, System Owner, and various operational teams from the Office of the Chief Information Officer (OCIO). The plan specifies that vendors must request the CSIRC Security Incident Report form by emailing the IRT, and establishes mandatory notification requirements for external hosting personnel and organizations managing ACF data, requiring notification within one hour of discovering any suspected or confirmed incidents. Contact information tables and detailed role responsibilities are provided in appendices, though specific individual names and phone numbers are noted as requiring completion.

View the file

Other files for this federal contract opportunity

Other files attached to Legal Services for Unaccompanied Alien Children (UAC), newest first.
File Type Posted
Amendment 15 - Attachment J - Section F Deliverables Table June 06 2026.pdf PDF
Amendment 15 - Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services June 06 2026.pdf PDF
Amendment 15 - Attachment L Questions and Answers June 06 2026.pdf PDF
Amendment 15 - RFP UAC Legal Services.pdf PDF
Attachment E - Quality Assurance Surveillance Plan (QASP) UAC Legal Services_20260515.docx DOCX document
Attachment-G10-ACF_System Security Plan_V1.0.docx DOCX document
Attachment-G9-ACF_System Registration_V1.0.docx DOCX document
Attachment-G4-ACF_Contingency Plan.docx_V1.0.docx DOCX document
Attachment J - Section F Deliverables Schedules and Performance Requirements Summary Table_20260513.docx DOCX document
Attachment D - ORR Facilities by State_20260513.pdf PDF
Attachment-G6-ACF_Interconnection Security Agreement_V1.0.docx DOCX document
Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx DOCX document
Attachment-G2-ACF_Business Impact Analysis.docx_V1.0.docx DOCX document
Attachment-G1-ACF_ E-Authentication Agreement_V1.0.docx DOCX document
Attachment H - Glossary of Abbreviations and Acronyms_20260513.docx DOCX document
Attachment F - ACF External System Control Implementation Policy and Procedures_20251203.docx DOCX document
RFP UAC LEGAL SERVICES 20260515.pdf PDF
Attachment J- Questions and Answers_2026.03.24 (Amd 0010).pdf PDF
Attachment B- Section C- PWS_2026.03.24 (Amd 0010).pdf PDF
Attachment A- Pricing Worksheet_2026.03.24 (Amd 0010).xlsx XLSX spreadsheet
Attachment C- Standard Form (SF)-1449.pdf PDF
Attachment A- Pricing Worksheet UAC Legal Services (Amd. 0007) 2026.02.23.xlsx XLSX spreadsheet
Attachment B- Section C- PWS (Amd 0007) 2026.02.23.pdf PDF
Attachment E- Quality Assurance Surveillance Plan (QASP) (Amd. 0007) 2026.02.23.pdf PDF
Attachment H- Glossary of Abbreviations and Acronyms.pdf PDF
Attachment C- Standard Form (SF)-1449.pdf PDF
Attachment G- ATO Templates-2025.zip ZIP file
75P00126R00003_2026.02.23.pdf PDF
Attachment D - ORR Facilities by State.xlsx XLSX spreadsheet
Attachment F- ACF External System Control Implementation Policy and Procedures.pdf PDF
QA-75P00126R00003(Rev1) (Amd 0004)(12.11.2025)#Q127.pdf PDF
75P00126R00003 (Rev2)(Amd 0004)(12.11.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev2) (Amd 0004)(12.11.2025).xlsx XLSX spreadsheet
Attachment A- Performance Work Statement (PWS) (Rev1) (Amd 0003) (12.09.2025).pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP)(Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev1) (Amd 0003)(12.09.2025).xlsx XLSX spreadsheet
Attachment E- ORR Facilities by State (Amd 0003).pdf PDF
Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf PDF
Attachment I- Selected Controls (Moderate) (Amd 0003).xlsx XLSX spreadsheet
Attachment H- ATO Templates_2025 (Amd 0003).zip ZIP file
QA-75P00126R00003(12.09.2025) (Amd 0003).pdf PDF
75P00126R00003 (Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment J- Selected Controls (Low) (Amd 0003).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services (11.25.2025).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services.xlsx XLSX spreadsheet
Attachment C- HHS Subcontracting Plan Review Form.doc DOC document
Attachment F- Quality Assurance Surveillance Plan (QASP).pdf PDF
75P00126R00003.pdf PDF
Attachment A - Performance Work Statement (PWS)_2025.11.24.pdf PDF
Attachment D- Standard Form (SF)-1449.pdf PDF
Show all 50

Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Enter System Name ACF

Incident Response Plan Enter System Name

Version 1.0 Dated: 6/26/25

Table of Contents

1. Introduction and Purpose3
2. Incident Response Notifications and Procedures3
2.1 User Reporting of Security Incident3
2.2 ACF Incident Response Team (IRT) Procedures and Reporting4
2.3 Vendor Procedures and Reporting5
3. Contact Information6
4. Approval and Authorization8
APPENDIX A: Security Incident Prioritization: Urgency and Impact9
APPENDIX B: Incident Response Roles, Responsibilities, and Contacts12
Senior Leadership12
Operational Teams13
Support Teams14
Document Revision History16

1. Introduction and Purpose The Incident Response Plan (IRP) outlines the roles and responsibilities of system users, key contacts, and procedures for reporting incidents on ACF-owned systems. It includes steps for identifying, recording, classifying, and directing incidents to the right support group, guiding the resolution process. The plan provides the necessary information for the ACF Incident Response Team (IRT) to effectively address security and privacy incidents that could impact the system or its data.

The processes outlined in this plan depend on the ACF Incident Response Policy, the Computer Security Incident Management Plan (CSIM), the Breach Response Plan, and standard operating procedures (SOPs) used by the Incident Response Team (IRT). The IRT comprises personnel from the ACF Privacy and Security Operations Teams. Comment by Kase, Whitney (ACF) (CTR): Add requirement to document Recovery procedures.

2. Incident Response Notifications and Procedures Once a security incident or data breach has been identified on an ACF system, the following notifications and procedures are followed.

The ACF Incident Response Policy defines an incident as “any observable occurrence in a system or network,” including viruses, malicious user activity, and vulnerabilities associated with highly interconnected technology. Data breaches include any unauthorized sharing of Personally Identifiable Information (PII). PII includes, but is not limited to, name, Social Security number (SSN), date of birth, mother’s maiden name, financial records, email address, driver’s license number, passport number, and health information.

2.1 User Reporting of Security Incident

All users must report any security events they notice. This includes when an application acts strangely, if they access information they shouldn’t, or if they spot something unusual during security checks.

If a security incident is suspected or observed, users should inform their supervisor or manager and email the ACF Incident Response Team (IRT) at ACF_IRT@acf.hhs.gov.

2.2 ACF Incident Response Team (IRT) Procedures and Reporting

1) The ACF IRT Incident Coordinator confirms receipt of a reported incident and creates a ticket in HHS Archer, initiating the following:

a) If PII is involved, a Data Breach incident is automatically created, and notifications are sent to:

i) The ACF Privacy Team Breach Response Lead

ii) The OCIO SecOps team member assigned to the case

b) If PII is not involved, an IT Security incident is created, and a notification is sent only to the OCIO SecOps team member.

2) After creating the ticket, the Incident Coordinator notifies the ACF CIO, CISO, OCIO IT Security Specialist, and others (e.g., SO, COR) to coordinate the response.

3) The assigned Privacy or SecOps team member contacts the incident reporter and sends them the CSIRC Security Incident Report Form.

4) Based on incident priority level, the Privacy and SecOps members follow established SOPs and procedures, working with system contacts to resolve the issue.

5) The Privacy and SecOps members update the HHS Archer ticket with progress and upload relevant evidence.

6) The Incident Coordinator works with the system SSPO and provides regular status updates (weekly or as needed) to the ACF CIO, CISO, and OCIO Security Specialist.

7) Once the incident is resolved, the Privacy and SecOps teams request closure in HHS Archer. Comment by Kase, Whitney (ACF) (CTR): Add a requirement for Tabletops?

2.3 Vendor Procedures and Reporting

Please email ACF_IRT@acf.hhs.gov to request a CSIRC Security Incident Report form.

3. Contact Information The table below should provide contact information for all levels of the project. These contacts include the various teams and team leads that are involved in responding to an incident. See Appendix B for detailed roles and responsibilities.

Table 2. Contact Information

ACF Primary Incident Response Contacts

Name
Organization / Title
Address
Phone Number
Email
N/A
ACF IRT
330 C Street SW Washington, DC
N/A
ACF_IRT@acf.hhs.gov
N/A
ACF Privacy Team
330 C Street SW Washington, DC
N/A
OCIO.Privacy@acf.hhs.gov
N/A
ACF Security Operation (SecOps) Team
330 C Street SW Washington, DC
N/A
ACF.OCIO.Cybersecurity@acf.hhs.gov

ACF OCIO Senior Leadership

Name
Organization / Title
Address
Phone Number
Email
Add nameChief Information Officer
330 C Street SW Washington, DC
Add phone
Add email
Add nameChief Information Security Officer (CISO)
330 C Street SW Washington, DC
Add phone

Add email

Add nameSenior Officer for Privacy (SOP)
330 C Street SW Washington, DC
Add phone

Add email

ACF OCIO IT, Security, and Privacy Support Contacts

Name
Organization / Title
Address
Phone Number
Email
N/A
ACF OCIO Service Desk
330 C Street SW Washington, DC
Add phone

OCIO.Service.Desk@acf.hhs.gov

Add nameACF OCIO Operations System Admin
330 C Street SW Washington, DC
Add phone

Add email

Add nameSystem Security and Privacy Officer (SSPO)
330 C Street SW Washington, DC
Add phone

Add email

Add nameInformation System Security Engineer (ISSE)
330 C Street SW Washington, DC
Add phone

Add email

Add nameInformation System Security Manger (ISSM)
330 C Street SW Washington, DC
Add phone

Add email

ACF Program Office Contacts

Name
Organization / Title
Address
Phone Number
Email
Add nameBusiness Owner (BO)
Add address
Add phone

Add email

Add nameSystem Owner (SO)
Add address

Add phone

Add email

Add nameVendor P.M.
Add address
Add phone

Add email

Add nameVendor Technical P.O.C.
Add address

Add phone

Add email

4. Approval and Authorization The information contained in this IRP has been reviewed and approved by the following authority:

System Owner Digital Signature – Date

APPENDIX A: Security Incident Prioritization: Urgency and Impact Prioritization is established by ACF using the impact, urgency, and metrics defined in the tables below. Incident Response prioritization is managed via the ACF CISM Plan.

Not all incidents or events have equal impact on the organization. Once categorized, each event or incident is evaluated for how it may affect the environment. This initial assessment helps the ACF IRT investigate and remediate detected and reported issues by prioritizing events to maximize limited personnel resources.

The two key criteria to be evaluated are impact and urgency:

· Impact specifies the overall effect of an event or incident. This includes the number of affected users and the criticality of the affected system or data. Impact is also used to qualify the effect of reputation loss on the department, agency, or organization.

· Urgency combines the time it takes an incident to significantly impact business, the criticality of the system under attack, and the sensitivity of the data exposed.

Prioritization levels indicate two separate but related criteria that determine the level of effort required by the ACF IRT to perform the steps in the incident response lifecycle.

· Response time is the expected response time for creating an incident ticket after an event or incident is detected or reported. This includes the initial triage assessment and categorization steps.

· Resolution time is the expected window of time the ACF IRT has to perform their investigation, contain the effect, and apply mitigation strategies to the event or incident. Final resolution with remediation and root cause analysis is not accounted for in this calculation, as these events may take weeks or months.

The priority level of an event or incident is calculated as a combination of impact and urgency. These components are defined below.

Table 1. Impact and Urgency Descriptions

Impact Code
Example
Urgency Code
Example

Extensive / Widespread

An event or incident affecting all or most ACF assets across multiple data centers and applications. The exposed data is sensitive PII and has been verified to be exposed to the public. User data loss affects 500 unique individuals or more.
Severe
An incident or event affecting critical assets or high-value applications, or resulting in a complete work
Significant / Large
An event or incident affecting large portions of ACF assets in one or more data centers and affecting two or more applications. The exposed data is sensitive PII or is likely to be exposed to the public. User data loss affects 100 unique individuals or more.
High
An incident or event affecting core support assets or high-value applications, or significantly impacting business operations. With data exposure, the exposed data is sensitive PII.

Moderate / Limited

An event or incident affecting some ACF assets and at least one application. The exposed data is PII. User data loss affects 50 unique individuals or more.
Medium
An incident or event affecting assets or applications resulting in a moderate impact on business operations, but a workaround exists. With data exposure, the exposed data is PII.
Minor / Localized
An event or incident affecting some ACF assets. The exposed data may contain PII. User data loss affects fewer than 50 unique individuals.
Low
An incident or event resulting in little to no impact on business operations. With data exposure, the data exposed is not PII.

Table 2. Incident Response Prioritization Levels

Priority Level
Response Time
Resolution Time
PO
4 hrs.
16 hrs.
P1
8 hrs.
24 hrs.
P2
16 hrs.
40 hrs.
P3
24 hrs.
56 to 72 hrs.

Table 3. Incident Response Matric

Urgency
Impact Extensive / Widespread
Impact Significant / Large
Impact Moderate / Limited
Impact Mnor / Localized
Severe
PO
PO
P1
P2
High
P1
P1
P2
P3
Medium
P2
P2
P3
P3
Low
P3
P3
P3
P3

APPENDIX B: Incident Response Roles, Responsibilities, and Contacts Senior Leadership ACF Chief Information Officer (CIO)

· Establish, implement, and enforce the ACF Incident Response (IR) and Handling policy.

· Provide management oversight of the IR and handling process.

· Inform ACF senior leadership of any significant IT security or privacy incident (for example, major data compromise).

· If any employment action may be appropriate after an incident investigation is over, provide recommendations to the Office of Workforce Planning and Development.

ACF Chief Information Security Officer (CISO)

· Ensure ACF-wide implementation of plans and procedures related to IT security and privacy incident response.

· Oversee and manage the resources that support ACF IRT operations.

· Notify the CIO of any significant IT security or privacy incident.

ACF Senior Official for Privacy (SOP)

· Coordinate with the ACF IRT and the HHS Privacy Program about reports of a PII breach.

ACF Program Office Leadership

· Disseminate and ensure compliance with policies, plans, and procedures related to security and privacy incident responses in their respective office.

· Notify employees of any changes to existing policy or creation of new policy about the IR program.

· Cooperate with the ACF CISO and IRT on investigations into security and privacy incidents originating in their respective office.

Operational Teams

ACF IRT

· Draw on personnel from the functional teams in the OCIO: Enterprise Security, Security Operations, Privacy Program, and IT Governance.

· Establish and maintain IT security and privacy IR capabilities ensuring these capabilities are performed by the team or on their behalf.

· Report IT security and privacy incidents to the HHS CSIRC following the CSIRC Concept of Operations (CONOPS), specifically for incidents involving the actual or suspected loss of control over PII.

· Serve as the primary POC for HHS CSIRC and the HHS Privacy Program.

· Coordinate with the ACF Senior Official for Privacy in OCIO about PII breaches following IRT processes.

· Coordinate the ACF-wide response to IT security vulnerabilities, threats, and incidents.

· Facilitate information sharing across ACF regarding IT security vulnerabilities, threats, and incidents.

· Augment existing analysis capabilities and forensic services regarding security vulnerabilities, threats, and incidents.

· Comply with all reporting requirements and follow guidance from US-CERT and NIST.

· Report incidents involving confirmed or suspected violations of the law, or employee or contractor misconduct, to the Office of Inspector General (OIG) following HHS policies and procedures.

· Coordinate and provide IR support for ACF systems, applications, or data managed or hosted by another operating division or organization.

Enterprise Security

· Provide subject matter expertise on the overall impact assessment.

Security Operations

· Operate, manage, and maintain security tools.

· Create and deploy incident response use cases for alerts and investigations.

· Provide technical support and investigation response for computer security-related events and incidents.

Privacy Program

· Investigate events that affect privacy or constitute policy violations.

· Provide subject matter expertise for any event or incident that involves loss of confidentiality or integrity of ACF data.

IT Governance

· Provide oversight and subject matter expertise on policy and compliance-related issues.

ACF OCIO Operations Team

· Provide subject matter expertise on technical issues related to investigated events and incidents.

· Conduct data collection on behalf of the Security Operations Team on systems under its administrative control.

Support Teams Program Management Offices of Affected Systems or Assets Program Office System Owner

· Communicate to users, developers, and administrators of the system owner's designated information system about security and privacy IR requirements as outlined in this policy and additional plan and procedure documentation.

· Notify the ACF CISO and IRT of any suspected or confirmed IT security or privacy incidents occurring on the information system within one hour of discovery.

· Cooperate with ACF CISO and IRT on any investigation into security or privacy incidents affecting their information system.

· Coordinate communication between ACF IRT and other ACF POCs with System PM and the technical support team.

· Inform the Contracting Officer's Representative (COR) of the vendor contract of any changes needed to address the security incident.

· Contracting Officer’s Representative (COR)

· Communicate with the Contracting Officer (CO) and the contract's PM, ensuring any concerns, deficiencies, or changes to the contract are made to address the security incident.

· Track all vendor activities to address the security incident, which may impact contract performance, resources, and cost.

HHS CSIRC

· Serve as the primary entity responsible for maintaining HHS-wide operational IT security situational awareness and determining the overall IT security risk posture.

· Report all IT security and privacy incidents to US-CERT.

· Serve as the primary POC with US-CERT.

· Report to the ACF IRT on any action taken by the OIG regarding an ACF-reported incident involving confirmed or suspected violations of the law, or employee or contractor misconduct.

External Hosting and Operations Personnel

· Notify the ACF CISO, IRT, and System Owner of any suspected or confirmed IT security or privacy incidents involving ACF infrastructure, information systems, and data within one hour of discovery.

· Notify the ACF CISO and IRT of any suspected or confirmed IT security or privacy incidents occurring on ACF-managed networks within one hour of discovery.

· Ensure that security and privacy requirements are implemented and enforced.

· Assist in the incident investigation efforts and coordinate with the IRT to execute remediation activities.

External Organizations

· Notify the Program Office, ACF CISO, and IRT of any suspected or confirmed IT security or privacy incidents involving ACF data managed by the organization within one hour of discovery.

· Assist in the incident investigation efforts and coordinate with the ACF IRT to execute remediation activities.

Document Revision History

Date
Version
Comments

Version 1.0 Incident Response Plan 1 image1.png image2.png

File details come from the government source that posted it. Updated .