A08_FISMA_-_Seismic_Refraction_Unit.pdf

PDF 245 KB Posted

Attached to
SEISMIC REFRACTION UNIT Federal contract opportunity
Solicitation number
140G0124Q0245
Issued by
Department of the Interior US Geological Survey Office of Acquisitions and Grants

About this file

This document is a FISMA 18-Point Checklist - IT Security Guidelines from the U.S. Geological Survey Office of Acquisition and Grants. It outlines the IT security requirements for various contractor activities related to a federal contract, including the development or maintenance of custom applications, outsourced IT services, and on-site support.

The key details are:

  • The contract requires background investigations, non-disclosure agreements, security awareness training, and personnel change notifications for contractor employees with access to USGS IT systems.
  • The contractor must follow NIST and DOI security standards, including security categorization, certification and accreditation, independent verification and validation, and vulnerability analysis.
  • For custom application development or maintenance, the contractor is responsible for the certification and accreditation process.
  • For IT services and system management, the government or a selected contractor will conduct the certification and accreditation.
  • The contractor must comply with incident reporting, quality control, self-assessment, and security control requirements.

View the file

Other files for this federal contract opportunity

Other files attached to SEISMIC REFRACTION UNIT, newest first.
File Type Posted
Sol_140G0124Q0245_Amd_0001.pdf PDF
A04_Salient_Characteristics_(amd_1)_0001.docx DOCX document
A06_Specifications_-_Seismic_Refraction_Unit.docx DOCX document
Sol_140G0124Q0245.pdf PDF
A08_508_-_Seismic_Refraction_Unit.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FISMA 18-Point Checklist – IT Security Guidelines

U.S. Geological Survey Office of Acquisition and Grants Questions to askoag@usgs.gov

December 14, 2022 Page 1 of 6

COTS

Hardware or Software

Development or

Maintenance of

Custom

Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

1 N/A Background Investigations. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

2 N/A Non-disclosure Agreement. Prior to receiving access to USGS computers, contractor employees shall be required to sign nondisclosure or other system security agreements, depending on the systems to be used and level of access granted.

Applies whenever any contractor employee has unsupervised access to a

USGS system (even if only basic network, internet or email or will develop custom applications) such as:

• User Access to USGS IT Systems known to contain sensitive or proprietary data

Contractor will have • IT Support services (greater than user access) access to Privacy • Development or Maintenance of Custom Applications

Act System of

Records - Work

• On-site contractor support and management of IT system

• Off-site contractor Oversight and Management of IT System under this contract will involve design,

• IT Security Services development or Privacy Act System: [Identify covered system(s) to which the contractor operation of (access

to) system(s) of records containing may have access] personal information protected by the

Work to be performed: [Summarize nature of the contractor's use of such records, such as]

Privacy Act (5 U.S.C.

Section 552a).

• User-level access to system containing protected records

• Operation or maintenance of Privacy Act System of records or computers hosting such system

• Design or modification of a Privacy Act system of records]

The contractor is not required or permitted to respond to requests for Privacy Act data or to make decisions about releases of data under the

Act. Contractor shall ensure its employees are instructed to safeguard against improper use or release of such data and advise them that violation of the Act may involve criminal penalties. The contractor will comply with FAR clause 52.224-2, Privacy Act, incorporated herein by reference and with DOI Privacy Act regulations at 43 CFR 2, Subpart D mailto:askoag@usgs.gov

Questions to askoag@usgs.gov

December 14, 2022 Page 2 of 6

COTS

Hardware or Software

Development or

Maintenance of

Custom

Applications

Outsourced IT

Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/

Performance Work Statement:

3 N/A Training. The Contractor shall perform in accordance with clause

“Security Requirements: Facility Access and Information Technology” -

Contractor employees must successfully complete DOI’s end-user computer security awareness training prior to being granted access to

DOI data or being issued a user account. Training must be renewed annually. Additionally, the contract employees must sign a Statement of

Responsibility (SOR) that states they have read the appropriate Rules of

Behavior and other applicable Information security policies.

4 N/A Personnel Changes. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information

Technology” - The contractor must notify the COR immediately when an employee working on a DOI system is reassigned or leaves the contractor’s employ.

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

• User Access to USGS IT Systems known to contain sensitive or proprietary data

• IT Support services (greater than user access)

• Development or Maintenance of Custom Applications *

• On-site contractor support and management of IT system

• Off-site contractor Oversight and Management of IT System

• IT Security Services *

*May not be applicable for off-site performance.

5 N/A Contractor Location. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

• User Access to USGS IT Systems known to contain sensitive or proprietary data

• IT Support services (greater than user access)

• Development or Maintenance of Custom Applications

• On-site contractor support and management of IT system

• Off-site contractor Oversight and Management of IT System

• IT Security Services

No portion of the services to be performed hereunder may be performed outside the United States without the express written permission of the Contracting Officer.

Questions to askoag@usgs.gov

December 14, 2022 Page 3 of 6

T

COTS

Hardware or Software

Development or

Maintenance of

Custom

Applications

Outsourced IT

Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/

Performance Work Statement:

If services are proposed to be performed abroad, the Contractor shall provide an acceptable security plan that addresses mitigation of problems related to communication, control, and protecting the confidentiality, integrity, and availability of IT systems and information.

A Security Plan Template is available upon request from the Contracting Officer.

6 N/A N/A Applicable Standards. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information

Technology” - Contractor must follow the DOI System Development Life Cycle (SDLC), NIST SP 800-64 and the DOI SDLC Security Integration Guide.

7 N/A Asset Valuation-Security Categorization: The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

User Access to USGS IT Systems – The Government is responsible for security categorization on USGS systems to which the Contractor may have access under this contract.

IT Support Services greater than User-Level Services Choose one:

➔ The Government is responsible for security categorization on USGS systems to which the Contractor may have access under this contract.

-➔ he Government has defined the [insert name of system to be developed, operated or maintained by the contractor] to be a [Major Application], [Minor Application] or [General support system] as defined in OMB Circular A-130, Appendix III and NIST SP800-53. The following risk and sensitivity levels have been assigned based on the FIPS 199 and the NIST SP 800-60.

Mission impact:

Data sensitivity:

Risk level:

Bureau/departmental/national criticality:

Off-Site Oversight and Management of IT System- The Contractor shall use the FIPS 199 and the NIST SP 800- 60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.

IT Security Services - Applies only if the purpose of the contract includes obtaining asset valuation services.

The Contractor shall use the FIPS 199 and the NIST SP 800- 60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.

https://doimspp.sharepoint.com/sites/usgs-OAG/AOP/guidefordevelopingsecurityplans.pdf

Questions to askoag@usgs.gov

May 11, 2021 Page 4 of 6

COTS

Hardware or Software

Development or

Maintenance of

Custom

Applications

Outsourced IT

Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/

Performance Work Statement:

8 Property Rights.

1. For Federal Supply Schedule orders or orders under an existing contract, rights to software acquired hereunder are set forth in the basic contract.

2. For open market contracts, the Government's rights in software delivered hereunder shall be as described in software developer's commercial software license agreement or the clause FAR 52.227-

19, Commercial Computer Software-Restricted Rights, whichever is greater.

The Government Select either shall be granted COTS or custom unlimited rights in software software or data language as produced applicable. If hereunder as both apply, described in FAR identify clause 52.227- software/data

17, Rights in deliverables

Data—Special governed by

Works, each clause.

incorporated by reference herein.

9 N/A Independent Verification and Validation (IV&V). The

Government is responsible for independent software verification and validation prior to being moved into production.

On-Site Contractor Support and Management of IT System Choose one:

➔ Software will be independently verified and validated by the Government or another selected contractor prior to being moved into production.

➔ Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide

Off-Site Contractor Operation and Management of IT System-Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide

IT Security Service - Applies only if the purpose of the contract includes obtaining IV&V services.

Questions to askoag@usgs.gov

December 14, 2022 Page 5 of 6

COTS

Hardware or Software

Development or

Maintenance of

Custom

Applications

Outsourced IT

Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/

Performance Work Statement:

10 N/A Certification & Accreditation.

User Access to USGS IT Systems or IT Supports Services (Greater than User Access Certification and Accreditation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

Development or Maintenance of Custom Applications The contractor will perform Certification and Accreditation (C&A) services on the application developed or maintained hereunder prior to going into production. The application must be re-accredited every three years or whenever there is a major change that affects security.

C&A documents will be provided to the COR in both hard copy and electronic forms. The contractor must follow NIST SP 800-37, 800-18, 800-30, 800-60, 800-53A, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment.

NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/ FIPS documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/.

The contractor may request copies of DOI documents by contacting the Contracting Officer.

The government reserves the right to conduct the ST&E using either Government personnel or an independent contractor. The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.

On-Site Contractor Support and Management of IT System or Off-Site Contractor Operation and Management of IT System The Contractor must maintain systems that are compliant with NIST SP 800-18, 800-30, 800-37, 800-53A, 800-60, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment. As required by the above, Major Applications and General Support Systems shall be certified and accredited (C&A) prior to going into production and re-accredited every three years or whenever there is a major change that affects security. C&A documents will be provided to the COR in both hard copy and electronic forms. NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor may request copies of DOI documents by contacting the Contracting Officer. The government will reserve the right to conduct the ST&E, using either Government personnel or an independent contractor. The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.

Applies if the purpose of the contract includes obtaining C&A services.

11 N/A for COTS

HW & SW, User Access to USGS IT Systems (other than IT services), IT Support Services (User Level or greater access)

N/A Internet Logon Banner. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information

Technology.”

Development or Maintenance of Custom Applications OR On-Site Contractor Support and Management of IT System OR Off-site Contractor Oversight and Management of IT

System- Web-based applications developed or maintained under this contract must contain a USGS approved logon banner:

https://portal.doi.net/CIO/ITPMgmt/Documents/IT Standards/IT Security/DOI Security Control Standards (based on NIST SP 800-53 Revision 3)/Access Control v1.4.pdf

12 N/A Incident Reporting. The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and

Information Technology” - The contractor must report computer security incidents affecting DOI data or systems in accordance with the DOI Computer Incident Response Guide.

mailto:askoag@usgs.gov http://csrc.nist.gov/publications/nistpubs/ http://csrc.nist.gov/publications/nistpubs/ http://csrc.nist.gov/publications/nistpubs/ https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf

Questions to askoag@usgs.gov

December 14, 2022 Page 6 of 6

COTS

Hardware or Software

Development or

Maintenance of

Custom

Applications

Outsourced IT

Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/

Performance Work Statement:

13 Quality Control. All software or hardware purchased must be free of malicious code such as viruses, Trojan horse programs, worms, spyware, etc. Validation of this must be written into the contract.

14 N/A N/A Self-Assessment. The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information

Technology” - The contractor must conduct an annual self-assessment in accordance with annual DOI guidance on all information systems in production.

15 N/A Vulnerability Analysis. Vulnerability Analysis on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

16 N/A Logon Banner. Contractor employees who access DOI information systems must acknowledge a government-approved legal warning banner prior to logging on to the system. This includes contractor owned information systems hosting DOI data.

17 N/A Security Controls.

The Contractor shall perform in accordance with contract clause “Security

Requirements: Facility Access and Information Technology” – The

Contractor shall ensure compliance with the security control requirements of the current version of NIST SP 800-53, Rev.1, which are applicable to the security categorization of the data or system. FIPS 199 and the NIST

SP 800-60 will be used to determine information types and security categorizations.

18 N/A N/A Contingency Plan.

The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology.”

For IT Support Services: The Contractor shall submit a contingency plan in accordance with NIST SP 800-34 and DOI IT Systems Contingency Plan

Guide.

mailto:askoag@usgs.gov

Check Box1: Off
Check Box2: Off
Check Box3: Off
Check Box4: Off
Check Box5: Off
Text6:
Check Box7: Off
Check Box8: Off
Check Box9: Off
Check Box10: Off
Check Box11: Off
Check Box12: Off
Check Box13: Off
Check Box14: Off
Check Box15: Off
Check Box16: Off
Check Box17: Off
Check Box18: Off
Check Box19: Off
Text20:
Text21:
Text22:
Text23:
Check Box24: Off
Check Box25: Off
Check Box26: Yes
Check Box27: Off
Check Box28: Off
Check Box29: Off
Check Box30: Off
Check Box31: Off
Check Box32: Off
Check Box33: Off
Check Box34: Off
Check Box35: Off
Check Box36: Off
Check Box37: Off
Check Box38: Off
Check Box39: Off
Check Box40: Off
Check Box41: Off
Check Box42: Off
Check Box43: Off
Check Box44: Off
Check Box45: Yes
Check Box46: Off
Check Box47: Off
Check Box48: Off
Check Box49: Off
Check Box50: Off
Check Box51: Off
Check Box52: Off
Check Box53: Off
Check Box54: Off
Check Box55: Off
Requirement Title:

File details come from the government source that posted it. Updated .