83310125R0003 - Attach. 3 Cyber Security Requirements.docx
DOCX document 27 KB Posted
- Attached to
- Risk Assessment & Risk Spreading Tool Federal contract opportunity
- Solicitation number
- 83310125R0003
- Issued by
- Export Import Bank of the US
About this file
This document is an attachment to Solicitation 83310125R0003 detailing comprehensive cybersecurity requirements for contractors working with the Export-Import Bank of the United States (EXIM). The attachment mandates strict compliance with federal information security standards, including FISMA, NIST guidelines, and FedRAMP regulations, covering 17 specific cybersecurity requirements such as limiting system access, performing continuous monitoring, maintaining system configurations, implementing incident handling procedures, and protecting information systems.
The cybersecurity requirements have extensive provisions for cloud computing, information system security breaches, and personally identifiable information (PII) protection. Contractors must obtain an Authority to Operate (ATO) for each covered information system, report potential and confirmed security breaches within specified timeframes, provide full access to EXIM for investigations, and ensure all subcontractors and cloud service providers adhere to the same security standards. The requirements are comprehensive and place significant responsibility on contractors to maintain robust cybersecurity practices throughout the contract's duration, with potential contract suspension or termination for non-compliance.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 83310125R0003 - Attach. 2 Requirement Description.pdf | ||
| 83310125R0003 Attach. 1 SF1449.pdf | ||
| 83310125R0003 Attach. 4 PPQ.docx | DOCX document | |
| Combined Solicitation Synopsis 83310125R0003 .pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Solicitation: 83310125R003 Attachment 3 Compliance with Information Technology Security Policies, Procedures and Requirements For all Covered Information Systems, Contractor shall comply with all security requirements, including but not limited to the regulations and guidance found in the Federal Information Security Management Act of 2014 (“FISMA”), Privacy Act of 1974, E-Government Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, 199, and 200, OMB Memoranda, Federal Risk and Authorization Management Program (“FedRAMP”).
These requirements include but are not limited to:
1. Limiting access to EXIM Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise;
2. Providing security awareness training including, but not limited to, recognizing and reporting potential indicators of insider threats to users and managers of EXIM Information and Covered Information Systems;
3. Creating, protecting, and retaining Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or EXIM Information;
4. Maintaining authorizations to operate any Covered Information System;
5. Performing continuous monitoring on all Covered Information Systems;
6. Establishing and maintaining baseline configurations and inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Information Systems;
7. Ensuring appropriate contingency planning has been performed, including EXIM Information and Covered Information System backups;
8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication methods where required;
9. Establishing an operational incident handling capability for Covered Information Systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and reporting incidents to appropriate officials and authorities within Contractor’s organization and the EXIM
10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms, and personnel used to conduct such maintenance;
11. Protecting Covered Information System media containing EXIM Information, including paper, digital and electronic media; limiting access to EXIM Information to authorized users; and sanitizing or destroying Covered Information System media containing EXIM Information before disposal, release or reuse of such media;
12. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Information Systems to authorized U.S. citizens unless a waiver has been granted by the Contracting Officer (“CO”), and protecting the physical facilities and support infrastructure for such Information Systems;
13. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with EXIM Security standards;
14. Assessing the risk to EXIM Information in Covered Information Systems periodically, including scanning for vulnerabilities and remediating such vulnerabilities in accordance with EXIM policy and ensuring the timely removal of assets no longer supported by the Contractor;
15. Assessing the security controls of Covered Information Systems periodically to determine if the controls are effective in their application, developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in such Information Systems, and monitoring security controls on an ongoing basis to ensure the continued effectiveness of the controls;
16. Monitoring, controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Information Systems, and employing architectural designs, software development techniques, and systems engineering principles that promote effective security; and
17. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection from malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate action in response.
B. Contractor shall not process, store, or transmit EXIM Information using a Covered Information System without first obtaining an Authority to Operate (“ATO”) for each Covered Information System. The ATO shall be signed by the Authorizing Official for the EXIM component responsible for maintaining the security, confidentiality, integrity, and availability of the EXIM Information under this contract.
C. When requested by the EXIM CO or COR, or other EXIM official as described below, in connection with EXIM’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of EXIM Information, Contractor shall provide EXIM, including the Office of Inspector General (“OIG”) (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Contractor’s facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by EXIM or agents acting on behalf of EXIM, and such access shall be provided within 72 hours of the request. Additionally, Contractor shall cooperate with EXIM’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of EXIM Information.
D. The use of Contractor-owned laptops or other portable digital or electronic media to process or store EXIM Information covered by this clause is prohibited until Contractor provides a letter to the EXIM CO, and obtains the CO’s approval, certifying compliance with the following requirements:
1. Media must be encrypted using a NIST FIPS 140-2 approved product;
2. Contractor must develop and implement a process to ensure that security and other applications software is kept up-to-date;
3. Where applicable, media must utilize antivirus software and a host-based firewall mechanism;
4. Contractor must log all computer-readable data extracts from databases holding EXIM Information and verify that each extract including such data has been erased within 90 days of extraction or that its use is still required. All EXIM Information is sensitive information unless specifically designated as non-sensitive by the EXIM; and,
5. A Rules of Behavior (“ROB”) form must be signed by users. These rules must address, at a minimum, authorized and official use, prohibition against unauthorized users and use, and the protection of EXIM Information. The form also must notify the user that he or she has no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contractor-owned laptops or other portable digital or electronic media.
F. Contractor-owned removable media containing EXIM Information shall not be removed from EXIM facilities without prior approval of the EXIM CO or COR.
G. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with EXIM security requirements.
H. Contractor must keep an accurate inventory of digital or electronic media used in the performance of EXIM contracts.
I. Contractor must remove all EXIM Information from Contractor media and return all such information to the EXIM within 15 days of the expiration or termination of the contract, unless otherwise extended by the CO, or waived (in part or whole) by the CO, and all such information shall be returned to the EXIM in a format and form acceptable to the EXIM. The removal and return of all EXIM Information must be accomplished in accordance with EXIM IT Security Standard requirements, and an official of the Contractor shall provide a written certification certifying the removal and return of all such information to the CO within 15 days of the removal and return of all EXIM Information.
J. EXIM, at its discretion, may suspend Contractor’s access to any EXIM Information, or terminate the contract, when EXIM suspects that Contractor has failed to comply with any security requirement, or in the event of an Information System Security Incident, where the Bank determines that either event gives cause for such action. The suspension of access to EXIM Information may last until such time as EXIM, in its sole discretion, determines that the situation giving rise to such action has been corrected or no longer exists. Contractor understands that any suspension or termination in accordance with this provision shall be at no cost to the EXIM, and that upon request by the CO, Contractor must immediately return all EXIM Information to EXIM, as well as any media upon which EXIM Information resides, at Contractor’s expense.
Cloud Computing A. Cloud Computing means an Information System having the essential characteristics described in NIST SP 800-145, The NIST Definition of Cloud Computing. For the sake of this provision and clause, Cloud Computing includes Software as a Service, Platform as a Service, and Infrastructure as a Service, and deployment in a Private Cloud, Community Cloud, Public Cloud, or Hybrid Cloud.
B. Contractor may not utilize the Cloud system of any CSP unless:
1. The Cloud system and CSP have been evaluated and approved by a 3PAO certified under FedRAMP and Contractor has provided the most current Security Assessment Report (“SAR”) to the EXIM CO for consideration as part of Contractor’s overall System Security Plan, and any subsequent SARs within 30 days of issuance, and has received an ATO from the Authorizing Official for the EXIM component responsible for maintaining the security confidentiality, integrity, and availability of the EXIM Information under contract; or,
2. If not certified under FedRAMP, the Cloud System and CSP have received an ATO signed by the Authorizing Official for the EXIM component responsible for maintaining the security, confidentiality, integrity, and availability of the EXIM Information under the contract.
C. Contractor must ensure that the CSP allows EXIM to access and retrieve any EXIM Information processed, stored or transmitted in a Cloud system under this Contract within a reasonable time of any such request, but in no event less than 48 hours from the request. To ensure that the EXIM can fully and appropriately search and retrieve EXIM Information from the Cloud system, access shall include any schemas, meta-data, and other associated data artifacts.
Information System Security Breach or Incident A. Definitions
1. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any EXIM Information accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system.
2. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed, Covered Information System Security Breach.
3. Security Incident means any Confirmed or Potential Covered Information System Security Breach.
B. Confirmed Breach. Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the EXIM CO and the CO's Representative (“COR”). If the Confirmed Breach occurs outside of regular business hours and/or neither the EXIM CO nor the COR can be reached, Contractor must email Security.Incident@exim.gov immediately (and in no event later than within 1 hour of discovery of the Confirmed Breach), and shall notify the CO and COR as soon as practicable.
C. Potential Breach.
1. Contractor shall report any Potential Breach within 72 hours of detection to the EXIM CO and the COR, unless Contractor has (a) completed its investigation of the Potential Breach in accordance with its own internal policies and procedures for identification, investigation and mitigation of Security Incidents and (b) determined that there has been no Confirmed Breach.
2. If Contractor has not made a determination within 72 hours of detection of the Potential Breach whether an Confirmed Breach has occurred, Contractor shall report the Potential Breach to the EXIM CO and COR within one-hour (i.e., 73 hours from detection of the Potential Breach). If the time by which to report the Potential Breach occurs outside of regular business hours and/or neither the EXIM CO nor the COR can be reached, Contractor must email Security.Incident@exim.gov) within one-hour (i.e., 73 hours from detection of the Potential Breach) and contact the EXIM CO and COR as soon as practicable.
D. Any report submitted in accordance with paragraphs (B) and (C), above, shall identify (1) both the Information Systems and EXIM Information involved or at risk, including the type, amount, and level of sensitivity of the EXIM Information and, if the EXIM Information contains PII, the estimated number of unique instances of PII, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the US-CERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by EXIM. Contractor shall continue to provide written updates to the EXIM CO regarding the status of the Security Incident at least every three (3) calendar days until informed otherwise by the EXIM CO.
E. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident will be made by EXIM senior officials or the EXIM Core Management Team at EXIM’s discretion.
F. Upon notification of a Security Incident in accordance with this section, Contractor must provide to EXIM full access to any affected or potentially affected facility and/or Information System, including access by the EXIM OIG and Federal law enforcement organizations, and undertake any and all response actions EXIM determines are required to ensure the protection of EXIM Information, including providing all requested images, log files, and event information to facilitate rapid resolution of any Security Incident.
G. EXIM, at its sole discretion, may obtain, and Contractor will permit, the assistance of other federal agencies and/or third-party contractors or firms to aid in response activities related to any Security Incident. Additionally, EXIM, at its sole discretion, may require Contractor to retain, at Contractor’s expense, a Third-Party Assessing Organization (3PAO), acceptable to EXIM, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.
H. Response activities related to any Security Incident undertaken by EXIM, including activities undertaken by Contractor, other federal agencies, and any third-party contractors or firms at the request or direction of EXIM, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Security Incident and/or liability for any additional response activities. Contractor shall be responsible for all costs and related resource allocations required for all such response activities related to any Security Incident, including the cost of any penetration testing.
Personally Identifiable Information Notification Requirement Contractor certifies that it has a security policy in place that contains procedures to promptly notify any individual whose Personally Identifiable Information (“PII”) was, or is reasonably determined by EXIM to have been, compromised. Any notification shall be coordinated with the EXIM CO and shall not proceed until the EXIM has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by Contractor shall be coordinated with, and subject to the approval of, EXIM. Contractor shall be responsible for taking corrective action consistent with EXIM Data Breach Notification Procedures and as directed by the EXIM CO, including all costs and expenses associated with such corrective action, which may include providing credit monitoring to any individuals whose PII was actually or potentially compromised.
Pass-through of Security Requirements to Subcontractors and CSPs The requirements set forth in the preceding paragraphs of this clause apply to all subcontractors and CSPs who perform work in connection with this Contract, including any CSP providing services for any other CSP under this Contract, and Contractor shall flow down this clause to all subcontractors and CSPs performing under this contract. Any breach by any subcontractor or CSP of any of the provisions set forth in this clause will be attributed to Contractor.
File details come from the government source that posted it. Updated .