A17 A1 Appendix B SSAA Final.docx

DOCX document 19 KB Posted

Attached to
FOIA Case Management System and Support Services Federal contract opportunity
Solicitation number
63NLRB23Q0007
Issued by
National Labor Relations Board

About this file

This document outlines system security requirements for a contractor providing a FOIA case management system and support services to the National Labor Relations Board. The contractor must complete NLRB's system security authorization process, including developing required security documentation using NLRB templates, undergoing an independent security assessment, and obtaining an Authority to Operate signed by the NLRB Authorizing Official. The contractor is responsible for continuous monitoring and assessment of controls according to NLRB standards. The FOIA case management system must support privacy compliance activities such as PTAs, PIAs and SORNs. Quotes are requested for the FOIA case management solution and support services with a response due date not provided.

View the file

Other files for this federal contract opportunity

Other files attached to FOIA Case Management System and Support Services, newest first.
File Type Posted
A17 RFQ QAs 022223.pdf PDF
A17 A1 PWS - FOIA CMS 022223 Amd 01.docx DOCX document
A17 RFQ_02223 Amd 01.pdf PDF
A17 A1 Appendix C RTM 022223 Amd 01.xlsx XLSX spreadsheet
A17 RFQ_021423.pdf PDF
A17 A1 Appendix C RTM Final.xlsx XLSX spreadsheet
A17 A2 Past Performance Information.docx DOCX document
A17 A1 PWS - FOIA CMS 021423.docx DOCX document
A17 A1 Appendix A SLA Final.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix B – System Security Assessment and Authorization Requirements

1. Authority to Operate The Contractor shall not input, store, process, output, and/or transmit NLRB data within a Contractor IT system without an Authority to Operate (ATO) signed by the NLRB Authorizing Official (AO) granted via the Agency’s System Security Authorization (SSA) process. The NLRB process for obtaining and maintaining ATO is in accordance with NIST SP 800-37 Risk Management Framework for Information Systems and Organizations. The Contractor shall adhere to current NLRB policies, procedures, and guidance for the SSA process as defined below.

Complete the Security Authorization Process. The SSA process shall proceed according to the NIST SP 800-37 Risk Management Framework for Information Systems and Organizations or any successor publication including templates.

a. System Security Assessment and Authorization Process Documentation. SSA documentation shall be developed by the Contractor using the NLRB provided security documentation templates. SSA documentation consists of the following: Security Categorization Worksheet, System Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s).

b. Independent Assessment. Contractor shall have an independent third party perform an assessment of the NLRB-prescribed security and privacy controls as outlined in NIST SP 800-53r5 to determine the extent to which the selected controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting security and privacy requirements for the system and the NLRB. Should the independent assessment find deficiencies, the Contractor shall follow the direction of the NLRB to create and track Plans of Action & Milestones (POA&Ms) to be included in the final authorization package. NLRB has the unilateral right to determine if the results and mitigation strategy are acceptable. In the case of unacceptable results or mitigation strategy, or if the Contractor does not remediate control weaknesses in a timely manner as established in POA&Ms, NLRB may treat the failure as an event of default.

c. Support the Completion of the Privacy Compliance Documentation. As part of the SSA process, the Contractor may be required to support the NLRB in the completion of a Privacy Threshold Analysis (PTA). The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a contractor IT system that will store, maintain, and use PII. Upon review of the PTA, the OCISO Privacy Section determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the NLRB in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the NLRB about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the NLRB’s privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at www.nlrb.gov/privacy.

d. Authorization to Operate. Upon completion of the SSA documentation and independent assessment, the Contractor shall submit a signed SSA package, validated by the independent third party, to the Oversight Manager for acceptance by the NLRB Authorizing Official (AO), or designee, at least thirty (30) days prior to the use of the system. The NLRB is the final authority on the compliance of the SSA package and may limit the number of resubmissions of a modified SSA package. Once the ATO has been granted by the NLRB AO the Contracting Officer shall incorporate the ATO letter into the contract as a compliance document. The NLRB’s issuance of the ATO does not alleviate the Contractor’s responsibility to ensure the controls are implemented and operating effectively. The SSA package must include the following:

Deliverables (30 Days Prior to System Use)

Security and privacy plans

Security and privacy assessment reports

Plan of action and milestones

Supporting assessment evidence or other documentation, as required.

e. Continuous Monitoring/Ongoing Assessment. After an initial authorization, the Contractor shall have the security and privacy controls assessed on an ongoing basis in accordance with NIST SP 800-37 and based on the NLRB Control Assessment Frequency. Ongoing assessment of the control effectiveness is part of the continuous monitoring activities of the NLRB. Adherence to the terms and conditions specified by the AO as part of the authorization decision are also monitored. Ongoing control assessment continues as the information generated as part of continuous monitoring is correlated, analyzed, and reported to the Oversight Manager for acceptance by the NLRB AO. The Solution needs to undergo a Security Impact Assessment (SIA) whenever any changes/modifications are made to the Solution. Should the independent assessment find deficiencies, the Contractor must follow the direction of the NLRB to create and track Plans of Action & Milestones (POA&Ms) to be included in the final authorization package. NLRB has the unilateral right to determine if the results and mitigation strategy are acceptable. In the case of unacceptable results or mitigation strategy, or if the Contractor does not remediate control weaknesses in a timely manner as established in POA&Ms, NLRB may treat the failure as an event of default.

File details come from the government source that posted it. Updated .