Attachment-G6-ACF_Interconnection Security Agreement_V1.0.docx
DOCX document 126 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is an Interconnection Security Agreement (ISA) template for establishing secure connections between two systems within or across federal organizations. The document serves as a standardized framework for defining technical and security requirements governing data exchange between interconnected systems, with potential benefits including data and information exchange between authorized users, customized database access, and 24/7 communications capabilities.
The agreement requires documentation of multiple security parameters including general information and data descriptions, services offered (user or non-user services), data sensitivity categorization based on FIPS 199 standards, user community access authorizations and required characteristics, technical services for secure communication (including VPN tunnels and encryption specifications), rules of behavior, formal security plans, incident reporting procedures, audit trail responsibilities, authentication security parameters, operational security categorization (confidentiality, integrity, availability ratings), training and awareness requirements, equipment restrictions, and special connectivity considerations for dial-up and broadband connections. The agreement mandates inclusion of a topological diagram depicting endpoint-to-endpoint interconnectivity including all communications paths, circuits, and logical component locations. The ISA requires authorization signatures from the system owner, ACF Chief Information Security Officer (CISO) or Deputy CISO, and the partner organization, with a validity period that must be specified and reviewed at intervals, subject to termination by either party with 30 days' notice or immediate termination for noncompliance with security policies.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF
Interconnection Security Agreement Enter System Name
Between Enter staff Div. name and Enter Other Internal/External Organization Name
Version 1.0 Dated: 6/26/25
Table of Contents
| 1. Interconnection Statement of Requirements | 2 |
| 2. System Security Considerations | 3 |
| 2.1 General Information/Data Description | 3 |
| 2.2 Services Offered | 3 |
| 2.3 Data Sensitivity | 3 |
| 2.4 User Community | 4 |
| 2.5 Information Exchange Security | 4 |
| 2.6 Rules of Behavior | 4 |
| 2.7 Formal Security Plans | 4 |
| 2.8 Incident Reporting | 5 |
| 2.9 Audit Trail Responsibilities | 5 |
| 2.10 Security Parameters | 5 |
| 2.11 Operational Security Mode | 5 |
| 2.12 Training and Awareness | 6 |
| 2.13 Specific Equipment Restrictions | 6 |
| 2.14 System Connectivity | 6 |
| 3. Topology Drawing | 7 |
| 4. Approval and Authorization | 8 |
| Document Revision History | 9 |
1. Interconnection Statement of Requirements This interconnection security agreement pertains to the specified technical and security requirements regarding the interconnection between the two systems. The standard benefits that can be obtained between the interconnected systems can range, but not be limited to:
· The exchange of data and information between specific users
· Customized levels of access to proprietary databases
· Potential 24×7 communications
| Name |
| Acronym |
| Staff Div. Name | |
| Enter name | Enter acronym |
| Internal/External Org. | |
| Enter name | Enter acronym |
| System Name | |
| Enter name | Enter acronym |
| Internal/External System Name | |
| Enter name | Enter acronym |
Specify the information or data exchanged between the two systems:
Enter information or data
Specify the purpose of the exchange of information or data:
Enter purpose
Please reference the Interconnections section in the System Security Plan (SSP) for further details.
2. System Security Considerations
2.1 General Information/Data Description
Document the information & data that will be exchanged, as well as the location of the systems involved.
| Information/data that is exchanged: |
| System & location involved in the exchange: |
2.2 Services Offered
Specify whether the services offered are user services or not. If there are user services, summarize what they are and how data is exchanged (e.g., email, file transfer protocol, database query, file query) between the systems. List all services.
| Services offered: |
| If the service is a user service, summarize the data and how it is exchanged between systems: |
2.3 Data Sensitivity
This categorization should be based on FIPS 199 Standards for Security Categorization of Federal Information and Information Systems and NIST SP 800-60 Guide for Mapping Types of Information and Information Systems to Security Categories. The data categorization should match the overall system security categorization in the System Security Plan.
What is the data categorization?
Select an answer
2.4 User Community
List users’ access authorizations, the rights associated with each authorization type, and any required characteristics of the user community based on data sensitivity (e.g., employment status, nationality, or whether background checks or security clearances).
| User access authorization types |
| User rights |
| Required characteristics |
2.5 Information Exchange Security
Describe the technical services for secure system communication. Specify if a VPN tunnel is used and list any encryption types employed.
Enter description
2.6 Rules of Behavior
Provide each system’s Rules of Behavior governing users in compliance with the Privacy Act, OMB A-130.
Enter Rules of Behavior
2.7 Formal Security Plans
Provide the names of the formal security plans that govern each system and link to the documents. Include other relevant documents if applicable.
| System |
| System Security Plan |
| Other Relevant Documents |
2.8 Incident Reporting
Note that if either party discovers a security incident, that party is responsible for reporting it in accordance with agency-specific incident reporting procedures.
2.9 Audit Trail Responsibilities
Detail the activities that will be recorded by each or both agencies in the course of auditing application processes and user activities involving this interconnection.
Enter activities
2.10 Security Parameters
Provide the authentication security parameters being exchanged.
Enter security parameters
2.11 Operational Security Mode
Provide each system’s security categorization (confidentiality, integrity, and availability):
| System Security Categorization: |
| Rating: |
| Confidentiality Rating |
| Select answer |
| Integrity Rating |
| Select answer |
| Availability Rating |
| Select answer |
| Security Categorization |
| Select answer |
| Other Internal/External System Security Categorization: |
| Rating: |
| Confidentiality Rating |
| Select answer |
| Integrity Rating |
| Select answer |
| Availability Rating |
| Select answer |
| Security Categorization |
| Select answer |
2.12 Training and Awareness
Describe any security training and awareness required due to the interconnection and assign responsibility for the tasks performed.
Enter training and awareness details
2.13 Specific Equipment Restrictions
Describe any revised or new restrictions on terminals.
Enter revised information
2.14 System Connectivity
Describe special considerations for dial-up and broadband connections to systems involved in the interconnection agreement.
Enter special considerations
3. Topology Drawing Include a one-page topological drawing depicting the interconnectivity from endpoint to endpoint. Include the following:
All communications paths, circuits, and other features used for the interconnection.
All logical locations of components (e.g., mainframe computers, host processors, hubs, firewalls, encryption devices, routers, etc.)
Insert diagram:
4. Approval and Authorization This ISA is valid for Enter specific time frame after the latest date on either signature below if the technology documented herein does not change or if there are no other intervening requirements for update. At that time, it must be reviewed, updated, and reauthorized. Either party may terminate this agreement with 30 days advance notice. Noncompliance on the part of the party and/or its employees or contractors concerning security policies, standards, and procedures explained herein may result in immediate termination of this agreement.
Digital Signature for System Owner – Date
Digital Signature for ACF CISO or Deputy CISO – Date
Digital Signature for Partner – Date
Document Revision History
| Date |
| Version |
| Comments |
Version 1.0 Interconnection Security Agreement 1 image1.png image2.png image3.png
File details come from the government source that posted it. Updated .