89603026Q0017.pdf
PDF 284 KB Posted
- Attached to
- Energy Velocity Federal contract opportunity
- Solicitation number
- 89603026Q0017
About this file
Summary
This is a Combined Synopsis/Solicitation Notice for the Federal Energy Regulatory Commission (FERC) seeking to procure a renewal license for the "Hitachi" EV and Velocity Suite software. The solicitation (Number 89603026Q0017) is issued as a Firm Fixed Price (FFP) contract to be awarded using Lowest Price Technically Acceptable evaluation criteria, considering price, delivery, and completeness. The contract includes a base period from April 1, 2026, through March 31, 2027, with four optional one-year extension periods running through March 31, 2031. The EV and Velocity Suite encompasses EV Power, EV Market-Ops, EV Fuels, EV Energy Map, EV Weather, FTR Trader, Velocity Suite Online, EV Transmission, Power Transactions, EV Grid Map, and EV Database Integration. Quotes are due March 25, 2026, at 1:00 PM Eastern Time, with questions due by March 23, 2026. All offerors must maintain current SAM registration. The place of performance is 888 First Street, NE, Washington, DC 20426, and the point of contact is Contract Specialist Trey Hair (trey.hair@ferc.gov, 202-502-6014). Proposals must be submitted electronically to the contracting specialist.
The solicitation includes comprehensive security and compliance requirements outlined in local provisions and FAR clauses, including background investigations and security clearances for contractor personnel, compliance with FISMA, NIST standards, and cybersecurity training. Additional requirements cover telecommunications equipment prohibitions, information protection, supply chain risk management, data breach reporting, and vulnerability assessments. FERC will own intellectual property rights to any custom software developed, and contractors must comply with privacy and confidentiality requirements, including non-disclosure agreements and proper handling of Controlled Unclassified Information. The contract contains standard federal provisions regarding holiday observances, facility closures, invoicing procedures, and option extensions up to 6 months for services or contract term extensions.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FY26 Energy Velocity SOW.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Combined Synopsis/Solicitation Notice
*= Required Field Combined Synopsis/Solicitation Notice
SUBJECT* Energy Velocity POP 04/01/2026
GENERAL INFORMATION
CONTRACTING OFFICE’S ZIP CODE* 20426
SOLICITATION NUMBER* 89603026Q0017
RESPONSE DATE/TIME/ZONE 03-25-2026 1:00pm EASTERN TIME, NEW YORK, USA
ARCHIVE 60 DAYS AFTER THE RESPONSE DATE
RECOVERY ACT FUNDS N
SET-ASIDE
PRODUCT SERVICE CODE* 7A21
NAICS CODE* 513210
CONTRACTING OFFICE ADDRESS Federal Energy Regulatory Commission
Procurement Division Attn: Trey Hair 888 First Street, NE, Room 4J Washington DC 20426
POINT OF CONTACT*
Contract Specialist Trey Hair trey.hair@ferc.gov
PLACE OF PERFORMANCE
ADDRESS 888 First Street, NE, Washington DC
Washington D.C.
POSTAL CODE 20426
COUNTRY USA
ADDITIONAL INFORMATION
AGENCY’S URL
URL DESCRIPTION
AGENCY CONTACT’S EMAIL ADDRESS Trey.hair@ferc.gov
EMAIL DESCRIPTION
DESCRIPTION
It is the intent of the Federal Energy Regulatory Commission is to obtain the “Hitachi” EV and Velocity Suite. The Government intends to award as a Firm Fixed Price (FFP) contract type and best value will be determined using the Lowest Price Technically Acceptable. Evaluation of each quote received will be based on price, delivery and completeness. Questions are due March 23, 2026, by 1:00 pm and Quotes are due by March 25, 2026, by 1:00 pm.
Eastern Standard Time (EST). Each offeror must have a current SAM registration. It is the vendor’s responsibility to ensure that the Government receives submitted quotes by the due date. Responses received after this date and time will be considered non-responsive. Please note that this request does not commit the government to pay any costs incurred in the submission of your offer, nor to contract for said services. The point of contact for this acquisition is: Trey Hair Contracting Specialist Phone: (202) 502-6014 Email: trey.hair@ferc.gov Quotes shall be submitted in electronic format to the Contracting specialist at trey.hair@ferc.gov
89603026Q0017
Table of Contents
SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS
B.1 PRICE/COST SCHEDULE
ITEM INFORMATION
B.2 DELIVERY SCHEDULE
SECTION C - CONTRACT CLAUSES
C.1 52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN TELECOMMUNICATIONS AND VIDEO
SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)
C.2 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)
C.3 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)
C.4 52.232-39 UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS (JUN 2013)
C.5 IT SYSTEMS & SERVICE CONTRACTS-- SECURITY REQUIREMENTS-- LOCAL PROVISION
C.6 OBSERVANCE OF LEGAL HOLIDAYS AND CLOSURE OF FERC FACILITIES --LOCAL PROVISION
C.7 CONTRACTING OFFICER REPRESENTATIVE (COR) APPOINTMENT--LOCAL PROVISION
C.8 INVOICING--LOCAL PROVISION
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS
SECTION E - SOLICITATION PROVISIONS
E.1 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE
SERVICES OR EQUIPMENT (NOV 2021)
89603026Q0017 Section B
SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS
B.1 PRICE/COST SCHEDULE
ITEM INFORMATION
ITEM
NUMBER
DESCRIPTION OF
SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
00001
1.00 EA __________________ __________________
EV and Velocity Suite Renewal Includes: EV Power, EV Market-Ops, EV Fuels, EV Energy Map, EV Weather, FTR Trader, Velocity Suite Online, EV Transmission, Power Transactions, EV Grid Map, EV Database Integration
Contract Period: Base POP Begin: 04-01-2026 POP End: 03-31-2027
10001
EV Energy Map, EV Weather, FTR Trader, Velocity Suite Online, EV Transmission, Power Transactions, EV Grid Map, EV Database Integration
Contract Period: Option 1 POP Begin: 04-01-2027 POP End: 03-31-2028
20001
EV Energy Map, EV Weather, FTR Trader, Velocity Suite Online, EV Transmission, Power Transactions, EV Grid Map, EV Database Integration
Contract Period: Option 2 POP Begin: 04-01-2028 POP End: 03-31-2029
30001
EV Energy Map, EV Weather, FTR Trader, Velocity Suite Online, EV Transmission, Power Transactions, EV Grid Map, EV Database Integration
Contract Period: Option 3 POP Begin: 04-01-2029 POP End: 03-31-2030
40001
EV Energy Map, EV Weather, FTR Trader, Velocity Suite Online, EV Transmission, Power Transactions, EV Grid Map, EV Database Integration
Contract Period: Option 4
POP Begin: 04-01-2030 POP End: 03-31-2031
GRAND TOTAL __________________
B.2 DELIVERY SCHEDULE
ITEM
NUMBER SHIPPING INFORMATION QUANTITY DELIVERY DATE
00001 SHIP TO: Federal Energy Regulatory Comm Attn: P-1 Warehouse 888 First Street NE Washington, DC 20426
USA
1.00
MARK FOR: 202-208-0200
10001 SHIP TO: Federal Energy Regulatory Comm Attn: P-1 Warehouse 888 First Street NE
20001 SHIP TO: Federal Energy Regulatory Comm Attn: P-1 Warehouse 888 First Street NE
30001 SHIP TO: Federal Energy Regulatory Comm Attn: P-1 Warehouse 888 First Street NE
40001 SHIP TO: Federal Energy Regulatory Comm Attn: P-1 Warehouse 888 First Street NE
89603026Q0017 Section C
SECTION C - CONTRACT CLAUSES
C.1 52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN
TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT
(NOV 2021)
(a) Definitions. As used in this clause—
Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet).
Covered foreign country means The People’s Republic of China.
Covered telecommunications equipment or services means—
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary or affiliate of such entities);
(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);
(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.
Critical technology means—
(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled—
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or
(ii) For reasons relating to regional stability or surreptitious listening;
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).
Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow the use of another’s network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone provider A to a customer of telephone company B) or sharing data and other information resources.
Reasonable inquiry means an inquiry designed to uncover any information in the entity’s possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include an internal or third-party audit.
Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high.
Substantial or essential component means any component necessary for the proper function or performance of a piece of equipment, system, or service.
(b) Prohibition. (1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115–232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The Contractor is prohibited from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104.
(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115–
232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract, or extending or renewing a contract, with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract.
(c) Exceptions. This clause does not prohibit contractors from providing—
(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(d) Reporting requirement. (1) In the event the Contractor identifies covered telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during contract performance, or the Contractor is notified of such by a subcontractor at any tier or by any other source, the
Contractor shall report the information in paragraph (d)(2) of this clause to the Contracting Officer, unless elsewhere in this contract are established procedures for reporting the information; in the case of the Department of Defense, the Contractor shall report to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.
(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause:
(i) Within one business day from the date of such identification or notification: The contract number; the order number(s), if applicable; supplier name; supplier unique entity identifier (if known); supplier Commercial and Government Entity (CAGE) code (if known); brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: Any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of covered telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.
(e) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (e) and excluding paragraph (b)(2), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services.
C.2 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)
The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 30 days .
C.3 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)
(a) The Government may extend the term of this contract by written notice to the Contractor within ; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least days before the contract expires. The preliminary notice does not commit the Government to an extension.
(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.
(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 5 years and 6 months.
C.4 52.232-39 UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS (JUN
2013)
(a) Except as stated in paragraph (b) of this clause, when any supply or service acquired under this contract is subject to any End User License Agreement (EULA), Terms of Service (TOS), or similar legal instrument or agreement, that includes any clause requiring the Government to indemnify the Contractor or any person or entity for damages, costs, https://dibnet.dod.mil/ https://dibnet.dod.mil/ fees, or any other loss or liability that would create an Anti-Deficiency Act violation (31 U.S.C. 1341), the following shall govern:
(1) Any such clause is unenforceable against the Government.
(2) Neither the Government nor any Government authorized end user shall be deemed to have agreed to such clause by virtue of it appearing in the EULA, TOS, or similar legal instrument or agreement. If the EULA, TOS, or similar legal instrument or agreement is invoked through an “I agree” click box or other comparable mechanism (e.g., “click-wrap” or “browse-wrap” agreements), execution does not bind the Government or any Government authorized end user to such clause.
(3) Any such clause is deemed to be stricken from the EULA, TOS, or similar legal instrument or agreement.
(b) Paragraph (a) of this clause does not apply to indemnification by the Government that is expressly authorized by statute and specifically authorized under applicable agency regulations and procedures.
C.5 IT SYSTEMS & SERVICE CONTRACTS-- SECURITY REQUIREMENTS-- LOCAL
PROVISION
Suitability Requirements/Background Investigations: Performance of this contract requires contractor personnel to complete Suitability Requirements in order to obtain a Federal Government issued personnel identification card before being allowed unsupervised access to a Federal Energy Regulatory Commission (FERC) facility and/or information system.
Each individual employed or otherwise retained by the Contractor to perform work under this contract will be fingerprinted at the FERC's Security Office, and will also submit to the designated Contracting Officer's Representative (COR) one completed Optional Form (OF) 306 (Declaration for Federal Employment), answer Questions 1,7-12, 15, and 16a only). The Contractor will be responsible for all costs associated with completing the forms required by the FERC's Security Office. Completed forms will be submitted to the COR, without alteration or changes to said forms, at least 10 working days before the individual may begin work or be given access to any agency records, data, or information in connection with this contract.
In addition to the forms above, individuals employed or retained by the contractor to fulfill contract positions or duties for 180 days or more, and any individual designated to fulfill certain sensitive contract positions or duties as determined by the FERC’s Security Officer, will be required to submit to the COR, one SF85 or SF85P (and any additional investigative forms) based on a risk determination by the FERC Security Officer that will take into account the sensitivity level of the contract position or duties assigned to the individual, the individual’s access, if any, to nonpublic or confidential information, and any other relevant considerations. The individual must submit these additional forms to the COR at least 5 working days before such.
Contractor employees may begin work on any day of the week, as directed by the COR, but will not have access to information technology (e.g., username and password) until processed through the FERC Security Office.
Background Investigation: All contractors and subcontractors performing work under this contract are subject to the same investigative requirements as those of regular FERC appointees or FERC employees with similar access requirements. Contract personnel who require access to National Security programs must have a valid Security Clearance, and will submit required documentation in accordance with FAR 52.204-2 Security Requirements.
Reimbursement of Cost for Security Investigations: All costs associated with the required security clearances, including the required Office of Personnel Management (OPM) investigation will be assumed by the winning offeror. The FERC will be credited for all such costs via a credit to the first invoice following the completion of any/all investigations.
Contract Specialist: ensure most recent OPM cost table is inserted here:
Previous Approval: If a Contractor employee has already been credentialed by another agency through the OPM, and that credential is less than one (1) year old, further investigation may not be necessary. The Contractor will provide the COR with documentation that supports the individual’s status. If option years exist under any given contract awarded to the contractor, reinvestigations of all contractor employees are required on an annual basis.
Return of Credentials: At the end of contract performance, or when a contractor employee is no longer working under this contract, the Contractor will ensure that all identification cards are returned to the COR. Failure to return identity cards may delay final invoice payment.
Non-Disclosure Agreement: The Contractor and all personnel assigned to the contract that require access to the FERC network agree not to divulge to any unauthorized person non-public or confidential information obtained from FERC in performance of their duties under the contract. All documentation, electronic data and information collected or generated by the Contractor in support of this contract will be considered Government property, and will be returned to the Government at the end of the performance period. The Contractor will be required to sign a NonDisclosure/Confidentiality Agreement prior to commencement of work to protect the proprietary/intellectual property of FERC.
Cyber Security and Privacy Training: All Contractor employees and subcontractor employees requiring access to FERC information and FERC information systems will complete the following before being granted access to FERC networks:
(a) Sign and acknowledge understanding of and responsibilities for compliance with the FERC Rules of Behavior relating to access to FERC information and information systems;
(b) Successfully complete FERC Cyber Security Awareness Training (CSAT) and annual refresher training as required;
(c) Successfully complete FERC General Privacy training and annual refresher training as required; and
(d) Successfully complete any additional cyber security or privacy training, as required for FERC personnel with equivalent information system access – e.g., any role-based information security training required in accordance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-16, Information Technology Security Training Requirements; and NIST SP 800-50, Building an Information Technology Security Awareness and Training Program.
The Contractor will provide to the COR a copy of the training certificates for each applicable employee within 1 week of contract start date and annually thereafter, as required.
Contractor Personnel Changes: The contractor must notify the COR immediately when an employee working on a FERC system is reassigned or leaves the contractor’s employ, and prior to an unfriendly termination. During performance of this contract, the Contractor will keep the COR apprised of changes in personnel to ensure that performance is not delayed by compliance with credentialing process.
Contractor Location: Custom software development and outsource operations must be located in the United States to the maximum extent practical. If such services are proposed to be performed abroad, the contractor must provide an acceptable security plan specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the United States (U.S.) may be an evaluation factor.
Applicable Standards: The contractors will follow the FERC System Development Life Cycle (SDLC), NIST SP 800-160, Volume 1, and the FERC SDLC Security Integration Guide.
Asset Valuation: The Contractor must use FIPS 199 and NIST SP 800-60 Volumes 1 and 2 for all information systems to determine mission impact, data sensitivity, risk level, bureau/departmental/national criticality, and whether the system is a Major Application, Minor Application, or General Support System.
Property Rights: FERC will own the intellectual property rights to any software developed on its behalf to the maximum extent practical. Generally, Federal Acquisition Regulation (FAR) 52.227-14, Rights in Data-General, and its alternates will be used in the contract. However, exceptions to this policy may be required as circumstances warrant, but must be approved by the FERC Contracting Officer.
Handling of Third-Party Requests for Access to Records: In the event that the contractor receives any subpoena or other voluntary or mandatory request for access to data first produced under this contract, the contractor will immediately notify the COR and the CO, so that the Government may intervene or take any other steps it deems necessary to protect its interests.
Security Assessment and Authorization: Major Applications and infrastructure systems must go through Security Assessment and Authorization (SA&A) prior to going into production, transitioning an information system to continuous monitoring after being granted an Authority-to-Operate (ATO), and remaining authorized or being re-authorized whenever there is a significant change that may affect cybersecurity. SA&A documents will be provided to the COR in both hard copy and electronic forms. In conducting SA&A, the contractor must follow NIST SP 800-37, Revision 2; SP 800-18, Revision 1; SP 800-30, Revision 1; SP 800-60, Revision 1; SP 800-53, Revision 5; SP 800-53A, Revision 5; Federal Information Processing Standard (FIPS) 140-2, 199 and 200, the associated FERC guides and templates, and the FERC Privacy Impact Assessment.
The Government will reserve the right to conduct the assessment, using either Government personnel or an independent contractor.
The contractor will take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.
The Designated Approving Authority for the system will be the official identified in FERC Secretarial Order No. 3255.
Security Controls:
Contractor Information Systems Subject to the Federal Information Security Modernization Act of 2014 (FISMA), All agency information systems, see 44 U.S.C. 3505(c), operated by or on behalf of the Government by a Contractor or subcontractor containing Federal data will be subject to the requirements of the FISMA, including routine testing without advance notice to or approval of the Contractor or its subcontractors. See 44 U.S.C 3544(b). There is a difference between information systems operated on behalf of the Government’ and a contractor’s internal system used to provide a product or service for the Government. An information system operated on behalf of the Government provides data processing services that the Government might otherwise perform itself but has decided to outsource. This includes systems operated exclusively for government use, and for systems operated for multiple users, (multiple Federal Government agencies or Government and private sector users such as email services, cloud services, etc.). A contractor’s internal information system is used to manage its business, and processes government data incidental to developing a product or service.
Contractors will be required to ensure compliance and validation with the security control requirements of the current version of NIST SP 800-53, Revision 5 or Federal Information Processing Standard (FIPS) 200 that are appropriate to the sensitivity and criticality of the information or information system. For information systems operated on behalf of the Government, FERC requires the contractor system to meet the appropriate baseline in NIST SP 800-53, Revision 5 as modified by FERC to meet its risk management requirements.
For Controlled Unclassified Information (CUI), the moderate baseline for confidentiality will be applied and adjusted for any specific protection requirements required by law, regulation, or government wide policy. When the contractor is operating the system to process data from more than one agency, or when there are non-government customers (e.g., cloud service providers), the FERC Office of the Chief Information Security Officer (CISO) will review the risk management and tailoring processes in NIST SP 800-37, Revision 2 and SP 800-53, Revision 5 to accommodate these situations. FERC requires contractors whose internal information systems will process CUI incidental to developing a product or service for the agency to meet the requirements of NIST SP 800-171, Revision 2, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, rather than NIST SP 800-53, Revision 5. Contractors will be required to ensure compliance and validation with FIPS 140-2 to ensure systems have the required encryption.
Information System Security Assessments: A contractor operating information systems or providing a service that generates, maintains, transmits, stores, or accesses information on behalf of FERC is required to ensure certain safeguards and an ATO are in place prior to operation of the information system per NIST SP 800-37, Revision 2. If possible, based on a risk assessment and a review of existing ATOs granted to the contractor by FERC or other agencies, FERC will use relevant existing ATOs as an indication of common controls and capabilities for the performance of multiple contracts. Many contractors operating in the commercial marketplace already receive a variety of independent assessments to protect other data and these will inform the FERC SA&A process that meets NIST standards and guidelines. FERC procedure for assessing information systems that a contractor is operating on behalf of FERC consist of the following:
(a) FERC will first use FIPS 199 to assess the impact level of the data that is to reside in the contractor’s information system in order to determine what types of controls should be applied, followed by determining whether it is appropriate to obtain an independent security assessment;
(b) FERC may accept independent third-party verification of security assessment results, contractor, or government assessment evidence based on its risk assessment;
(c) The assessment of privacy controls must be performed by the Senior Agency Official for Privacy (SAOP); and
(d) After performance under the contract has begun, the contractor will ensure FERC is granted access for security reviews on a periodic and event-driven basis for the life of the contract.
Security assessments not only confirm that contractors are maintaining their security posture; they also allow the FERC to validate the maintenance of the previously performed independent assessment. The contractor will afford FERC access to the contractor’s facilities, installations, operations, documentation, databases, information technology (IT) systems, devices, and personnel used in performance of the contract, regardless of location. Access will be provided to the extent required to conduct an inspection, evaluation, investigation, or audit and to preserve evidence of information security incidents. Prior to contract closeout, the contractor must:
(a) Certify and confirm the sanitization of government and government-activity-related files and information; and
(b) Submit the certification to the Contracting Officer following the template provided in NIST SP 800-88, Revision 1.
FERC will review the contractor’s sanitization certification to make sure any risk has been mitigated. To the extent that a contractor generated, maintained, transmitted, stored, or processed personally identifiable information (PII), the SAOP should review the certification. FERC will identify in the contract solicitation how they expect the contractor to demonstrate in its proposal that it meets the requirements of NIST SP 800-171, Revision 2, including the security assessment for contractor internal systems. This can range, depending upon the impact level of the information at risk, from simple attestation of compliance to detailed description of the system’s security architecture, controls, and provision of supporting test data.
Information Security Continuous Monitoring: Maintenance of the ATO will be through continuous monitoring of security controls of the contractor’s system and its environment of operation to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the information system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to FERC on a periodic basis. The submitted deliverables (or lack thereof) provide a current understanding of the cybersecurity state and risk posture of the information systems. Due to the increase and complexity of information security incidents, and the need to react quickly, FERC has prioritized Information Security Continuous Monitoring (ISCM), an initiative identified in NIST SP 800-53, Revision 5 and OMB Memorandum M-14-03. ISCM is defined in NIST SP 800- 137 “as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions” but is not limited to a specific program or technology. To assist agencies in establishing ISCM capabilities quickly, the DHS has created the Continuous Diagnostics and Mitigation (CDM) program and much of the information reported under ISCM is required under existing OMB guidance. If FERC determines that providing the DHS CDM capabilities to a contractor operating information systems on behalf of the Government is not feasible, the contract must ensure that at a minimum:
(a) Contractor-operated systems meet or exceed the information security continuous monitoring requirements identified in M-14-03; and
(b) FERC may elect to perform information security continuous monitoring and IT security scanning of contractor systems with tools and infrastructure of its choosing.
While existing contracts may direct the contractor to self-report required ISCM information to FERC, this approach may no longer be sufficient. FERC and contractors must therefore work together to determine and implement an appropriate solution that fulfills the ISCM requirements. FERC will work with DHS to ensure that the proposed solution fulfills the ISCM requirements identified in FISMA.
For systems not operated on behalf of the Government – contractor’s internal systems used to develop a product or service – continuous monitoring is part of the security assessment requirement in NIST SP 800-171.
Plan of Action and Milestones (POA&M) Management: The purpose of the POA&M is to facilitate a disciplined and structured approach to mitigating risks in accordance with contractor priorities. The POA&M identifies the tasks the contractor plans to accomplish, any milestones the contractor has set in place for meeting the tasks, and the scheduled completion dates the contractor has set for the milestones. The contractor must submit either a program or system level POA&M that covers all identified findings, vulnerabilities, deficiencies, discrepancies, weaknesses, or gaps between applicable OMB, NIST, and FERC cybersecurity and privacy requirements and guidance. If a finding is reported in a security assessment report and/or in the continuous monitoring activities, the finding must be covered by a POA&M. False positives along with supporting evidence do not have to be covered by a POA&M. Any cybersecurity or privacy finding for any external outsourced operation will require creation of a program-level POA&M. FERC is responsible for implementing and managing the POA&M process. Vulnerability scanning results will be managed and mitigated utilizing the FERC POA&M process. All critical and high risk findings must be remediated prior to an information system receiving an ATO.
Critical and high risk findings identified following ATO through continuous monitoring activities must be mitigated within 14 days for critical findings and 30 days for high findings. Moderate findings will have a mitigation date within 60 days of ATO or within 60 days of identification as part of continuous monitoring activities. Low findings will have a mitigation date assigned as capacity permits, but must be reviewed on an annual basis as part of continuous monitoring activities. The contractor must ensure that POA&Ms are prepared, documented, and maintained and that points of contact and resources are identified. The contractor must provide POA&M updates in accordance with the requirements and the schedule set forth in FERC guidance. A POA&M item can be closed when either of the following occurs:
(a) All corrective actions have been applied and evidence of mitigation has been provided. Evidence of mitigation can be verification by an independent assessor, a targeted vulnerability scan that covers the weakness domain, continuous monitoring scans, etc.
(b) A false positive request was submitted and approved by the Authorizing Official.
Waivers and Risk Acceptance Management: Waivers are official exceptions to FERC cybersecurity and privacy policy. A waiver is a request for additional time to address findings. Waivers are requested for various reasons. Some of these reasons include:
(a) The requestor needs more time to plan for the remediation efforts.
(b) The vendor has not released a fix for the vulnerability.
(c) The remediation efforts are dependent on the completion of other work.
The business justification for waiver request must be provided by the requestor. Approval is based on mission requirements and the best interest of FERC, when standard provisioning is inadequate. Waivers are not just an administrative process; rather, each request is evaluated from an enterprise perspective. Cybersecurity, information sharing, budgeting, interoperability, and mission scope, among others areas, are assessed. Before proceeding with a waiver request, the applicable FERC CISO or Information System Security Officer (ISSO) should be contacted to ascertain if a waiver is possible. The contractor may request waivers to, or exceptions from, any portion of FERC cybersecurity or privacy policy, for up to 6 (six) months, whenever they are unable to fully comply with cybersecurity or privacy requirements. Requests are made electronically, through the COR to the CISO and must include the operational justification, risk acceptance, risk mitigation measures, and a plan for bringing the program or information system into compliance. A second waiver request for up to 6 (six) months may be made only by the applicable FERC program manager or equivalent. Only signed and approved waiver requests are considered to be valid.
Waiver extensions are needed when a waiver is set to (or has) expired and/or the work has not yet been completed.
Resource constraints, shift in work priorities, vendor dependencies, and other issues could lead to a situation where a waiver extension is required. Waiver extensions should only be requested when absolutely necessary. Waiver extensions must be accompanied with a high level project plan detailing the work and timeframes for the remediation effort. Waiver extensions must also obtain approval by the COR, CISO, and Chief Information Officer (CIO).
A risk acceptance is requested when a finding cannot be remediated in the environment. A contractor may request a risk acceptance whenever it is unable to bring the program or system into compliance. Risk acceptances are generally limited to mission-specific systems that are not part of the FERC enterprise. This request is made through the COR to the CISO and must include the operational justification, risk acceptance, and risk mitigation measures. There are various reasons for a risk acceptance request. Typical scenarios at FERC are when remediating a finding will impact operations to critical systems. Risk acceptance should be requested only when absolutely necessary. In most cases, it is preferable to submit a long duration waiver or a deviation. It is the responsibility of the CISO to determine the best approach for waiver versus deviation and support this rationale through the approval process.
Cyber Security and Privacy Incident Reporting and Data Breaches: A Cyber Incident is an event that may have resulted in unauthorized access, loss or damage to FERC assets, information systems, or sensitive information, or an action that breaches FERC security procedures. A “cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein. Cyber incident reporting requirements for systems operated on behalf of the government and/or contractors’ internal systems are similar. The only distinction is that the reporting of cyber incidents affecting a contractor’s internal system is limited to incidents affecting CUI, not every cyber incident affecting the contractor system.
Timely contractor reporting of all cyber incidents involving the loss of confidentiality, integrity, or availability of data is critical to the Government’s ability to determine appropriate response actions and minimize harm from incidents. The Contractor will comply with all contractual and Federal information security, privacy and confidentiality requirements applicable to the operation, maintenance, or support of a Federal information system. The Contractor will be required to prevent and remedy data breaches and to provide the FERC with all necessary information and cooperation, and to take all other reasonable and necessary steps and precautions, to enable the FERC to satisfy its data breach reporting duties under applicable law, regulation, or policy in the event, if any, that a breach occurs.
In determining the appropriate timeline and reporting information, FERC will comply with Federal law, relevant OMB policies, and NIST standards and guidelines. FERC will also consider the sensitivity of the information stored by the contractor, the potential damage caused by delays in reporting, the requirements in the Department of Homeland Security (DHS) United States Computer Emergency Readiness Team (US-CERT) Federal Incident Notification Guidelines, or other risk factors, as deemed appropriate by FERC. At a minimum, contractual language will ensure that all known or suspected cyber incidents involving the loss of confidentiality, integrity, or availability of data for systems operated on behalf of the Government are reported to the designated agency Computer Security Incident Response Team (CSIRT) or Security Operations Center (SOC) within the timeline agreed upon in the contract. Contractors will adhere to OMB Memorandum 06-19 (July 12, 2006), particularly the mandated time frame requiring reporting of all incidents involving personally identifiable information to US-CERT within one hour of discovering the incident, as well as to any other subsequent laws, regulations, or policy governing data breaches that may arise during the performance of the contract.
All known cyber incidents in contractor internal systems must be reported if they involve the CUI in the system, but the contractor does not have to report all known or suspected cyber incidents. In addition to reporting to the SOC, the contractor will also report the security incident to the:
(a) Contracting Officer (CO);
(b) Contracting Officer Representative (COR);
(c) CISO; and
(d) SAOP (as necessary).
The Contractor will have an Information System Security Plan (ISSP) that includes policies and procedures necessary to ensure the timely detection of and reporting to the FERC of data breaches, as well as safeguards to prevent and mitigate the risk of, as well as to remedy, such breaches, if any. The contractor ISSP must address when and how the contractor is required to report information security incidents when they occur and when and how the contractor provides notification of breaches to affected individuals and third parties. At a minimum, FERC contractual language regarding incident reporting will include the following:
(a) Language to indicate that a cyber incident that is properly reported by the contractor will not, but itself, be interpreted as evidence that the contractor has failed to provide adequate information safeguards for CUI;
(b) The definition of what constitutes a cyber incident;
(c) The required timeline for first reporting to the agency;
(d) The types of information required in a cyber incident report to include: company and point of contact information, contract information, and the type of information compromised;
(e) The contractor will send only one report to each agency point of contact (POC) identified in the contracts, not a report for each contract from that agency. The report may contain information required by other agencies, so one report may satisfy the requirements of multiple agencies; and
(f) Specific government remedies if a contractor fails to report according to the agreed upon contractual language.
The specific requirements included in the contractual language will be based on Federal law, OMB policies, NIST standards and guidelines, and other applicable standards and policies. These policies and procedures should be developed according to the framework established in NIST SP 800-61, Revision 2. This approach to reporting will promote timely and meaningful information sharing that allows both the contractor and FERC to work closely together to investigate the incident, identify affected individuals, quickly respond to the incident, and take other appropriate actions as necessary.
To the maximum extent practicable, the Contractor will mitigate any harmful effects on individuals whose FERC information was accessed or disclosed in a security incident. In the event of a data breach with respect to any FERC sensitive information processed or maintained by the Contractor or subcontractor under the contract, the Contractor is responsible for damages to be paid to FERC.
Information System Hosting, Operation, Maintenance or Use: For information systems that are hosted, operated, maintained, or used on behalf of FERC at non-FERC facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance and validation requirements with all Privacy Act, FISMA, NIST, FIPS, and FERC security and privacy policies, processes, and procedures. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable information system contingency plan for each information system. The contractor’s security control procedures must be equivalent, to those procedures used to secure FERC information systems.
A privacy impact assessment (PIA) will be provided to the COR and approved by FERC Privacy Office prior to operational approval. Adequate security controls for collecting, processing, transmitting, and storing of PII, as determined by the FERC Privacy Office, must be in place, tested, and approved by FERC prior to hosting, operating, maintaining, or use of the information system, or systems by or on behalf of FERC. These security controls are to be assessed and stated within the PIA and if these security controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.
Outsourcing (contractor facility/contractor equipment/contractor staff) of information systems or network operations, telecommunications services, or other managed services requires SA&A of the contractor’s information systems in accordance with NIST SP 800-37, Revision 2 and privacy impact assessment of the contractor’s systems prior to operation of the information systems. All external Internet connections involving FERC information must be reviewed and approved by FERC prior to implementation. Government-owned (government facility/government equipment) contractor operated systems, third party or business partner networks require a system interconnection agreement and a memorandum of understanding (MOU) which details what data types will be shared, who will have access, and the appropriate level of security controls for all information systems connected to FERC networks. Contractors will develop MOUs in accordance with the FERC Business Partner Interconnection Policy and NIST SP 800-47.
The contractor’s information system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the FERC COR for entry into FERC’s POA&M management process. The contractor must use FERC POA&M process to document planned remedial actions to address any deficiencies in cybersecurity and privacy policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor procedures are subject to periodic, unannounced assessments by FERC officials, including the FERC Office of Inspector General. The physical security aspects associated with contractor activities must also be subject to such assessments. If major changes to the information system occur that may affect the privacy or security of the data or the information system, the SA&A of the information system may need to be reviewed, retested and re-authorized. This may require reviewing and updating all of the documentation PIA, System Security Plan, Information System Contingency Plan, etc.). The FERC CISO can provide guidance on whether a new SA&A would be necessary.
The contractor must conduct an annual self-assessment on all information systems and outsourced services as required.
Both hard copy and electronic copies of the assessment must be provided to the COR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor must take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such assessment, generally at no additional cost.
FERC prohibits the installation and use of personally-owned or contractor-owned equipment or software on FERC’s network. If non-FERC owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, Statements of Work (SOW) or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment.
All remote systems must be equipped with, and use, a FERC-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a FERC-approved configuration. Software must be kept current, including all critical updates and patches.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .