A4_-_Attachment_IT_and_Security_Requirements.pdf
PDF 431 KB Posted
- Attached to
- WRBR AUTOMATED FEE MACHINES Federal contract opportunity
- Solicitation number
- 140P5325Q0046
About this file
This is an IT and Security Requirements appendix for fee collection equipment, software, and services contracts with the National Park Service (NPS), dated December 18, 2014. The document establishes mandatory cybersecurity and access requirements that contractors must meet when handling federal information systems and data, including compliance with Federal Information Security Management Act (FISMA) requirements, NIST 800-53 security controls for "moderate" impact systems, and FedRAMP authorization for hosted services. Contractors must securely configure all computers accessing DOI information, provide evidence of compliance upon request, ensure all software functions within secure DOI environments, and implement FIPS 140-2 compliant cryptographic protections for mobile devices.
The appendix details extensive personnel security requirements including background investigations (NACI and MBI Standard Form 85P), Personal Identity Verification (PIV) smart card issuance, annual role-based security training for privileged users, and DOI non-disclosure agreement compliance. Contractors needing network access must complete Federal Information Systems Security Awareness training, obtain government-furnished laptops with pre-installed Windows 7 and Microsoft Office Suite 2010, and connect to NPS networks at least every two weeks for security updates. The document also mandates Section 508 accessibility compliance for all electronic and information technology, requires detailed technical documentation for software approval including network ports and data flow diagrams, and establishes procedures for government-furnished equipment management including contractor responsibility for damage and timely return of all government property upon contract completion.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A1_-_WRBR_AFM_Scope_of_Work_-_Final_-_Revised_7-16-205.pdf | ||
| A5_-_Attachment_WRBR_PCI_Data_Protection_Addendum.pdf | ||
| A6_-_DOL_Wage_Determination.pdf | ||
| Sol_140P5325Q0046.pdf | ||
| A3_-_Attachment_WRBR_AFM_Section_508_GPAT_Accessibility.pdf | ||
| A2_-_Price_Schedule.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Appendix: IT and Security Requirements (for Fee Collection Equipment, Software, and Services) Version Date: 2014-12-18
*Procurement Sensitive*
1.0 Overview
This appendix identifies the IT and security requirements that are ancillary to the functional and technical requirements of the Statement of Work, but apply to the performance of the Statement of Work. The requirements include Federal IT security (FISMA) requirements, requirements for contractor access to government facilities and systems, and requirements for government-furnished equipment to be used to access government systems.
2.0 Federal IT Security Management Act (FISMA) Requirements
Protecting federally-owned data and systems is a high priority and compliance with all relevant security policies is essential. All contractors that manage federally-owed data must adhere to and demonstrate compliance with all relevant security standards including the DOI IT Security Control Standards, which are based on the NIST 800-53 (Current Rev) Security and Privacy Controls for Federal Information Systems and Organizations, henceforth referred to as NIST 800-53.
2.1 Security Controls
Any servers, systems, computers, software, etc. that are managed by the contractor, whether on or off the NPS network, and store or process federal information on behalf of the NPS must adhere to the relevant security controls and standards in NIST Special Publication 800-53 (Current Rev) Security and Privacy Controls for Federal Information Systems and Organizations, henceforth referred to as NIST 800- 53 for a system classified as of “moderate” impact.
Contractors must upon request of the NPS, provide evidence of compliance with any of applicable IT security requirements and controls.
For hosted services, a https://www.fedramp.gov/ authorization to operate (provisional or agency) may be used to demonstrate compliance with NIST 800-53.
Note: DOI has issued a mandatory use policy for the Department of the Interior Foundation Cloud Hosting Services Contracts which requires all bureaus to evaluate use one of ten DOI’s Cloud Hosting IDIQ contract vehicles prior to ordering hardware, software, or hosting services. See NIST 800-145 for the definition of Cloud Computing.
2.2 Secure Configuration of Computers
The contractor must securely configure any computers which will access, store, and/or transmit DOI information, per NIST 800-53 control: CM-6 Configuration Settings, and related enhancements 1 and 3.
http://cloud.cio.gov/fedramp http://cloud.doi.gov/doi/docs/CIO0000505-20140106-MANDATORY-USE-POLICY-FOR-DOI-FOUNDATION-CLOUD-HOSTING-SERVICES-CONTRACTS.pdf http://cloud.doi.gov/doi/docs/CIO0000505-20140106-MANDATORY-USE-POLICY-FOR-DOI-FOUNDATION-CLOUD-HOSTING-SERVICES-CONTRACTS.pdf http://cloud.doi.gov/waiver
*Procurement Sensitive*
2.3 Key Personnel
The contractor must notify the COR immediately when key personnel with access to DOI information are reassigned or leave the service provider’s employment (whether voluntarily or through termination), per NIST 800-53 control: PS-7.Third-Party Personnel Security.
2.4 Non-Disclosure
The contractor must read, understand and agree to the DOI Non-Disclosure Agreement, per NIST 800- 53control PS-6, Access Agreements.
2.5 Role-Based Security Training for Privileged Users
All contractor employees with privileged access to systems that store NPS data must participate in annual, role-based training to ensure that the services provided and personnel skill sets are current and ensure comprehensive and efficient service, per NIST 800-53 controlAT-3, Security Training.
2.6 Software
The contractor must ensure that all software furnished or used in performance of the contract will be able to function properly within the secure configuration environments of the relevant DOI information system, per NIST 800-53 control CM-6, Configuration Settings, and related enhancements 1 and 3.
2.7 Mobile Device Security
For mobile devices provided, contractor must provide evidence that the product utilizes cryptographic protections using cryptographic modules that comply with the FIPS PUB 140-2 standards, per NIST 800- 53A control SC-13.1.1.
2.8 Cryptographic Capabilities for Mobile Devices
For mobile devices provided, the contractor must document, in detail, the cryptographic capabilities of the product, including key management procedures, to assure that the information system protects the confidentiality and the integrity of the data at rest, per NIST 800-53A control SC-28.1.1.
2.9 Technical Information Provided to NPS for Software Approval to use on the ESN Network
In order for the NPS to properly secure and document equipment in the NPS environment, the contractor must, upon request of the COR, provide the NPS with any necessary technical information on equipment or services provided. Technical information may include but is not limited to:
• List of network ports that the application uses
• Description of any network communication or communication with other applications that occurs
*Procurement Sensitive*
• Database schemas, if the application is a database
• Detailed data flow diagrams and architectural diagrams
• Detailed description of any areas in the application that could request or store personally identifiable information (PII)
• Processes and rules for authentication and user account management
• Security controls
• Security certifications that the application may hold. (i.e. FIPS 140-2, FedRamp, or any other certification related to Federal Government Standards)
• Software functions and interface requirements
Section 508 of the Rehabilitation Act 3.0
In 1998, Congress amended the Rehabilitation Act of 1973 to require Federal agencies to make their electronic and information technology (EIT) accessible to people with disabilities. Inaccessible technology interferes with an ability to obtain and use information quickly and easily. Section 508 was enacted to eliminate barriers in information technology, open new opportunities for people with disabilities, and encourage development of technologies that will help achieve these goals. The law applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology. All EIT procured under this RFP, including POS units and software applications, must comply with the requirements of Section 508. Additional information about Section 508 compliance can be found at http://www.section508.gov.
The contractor must complete Attachment– [Equipment] Section 508 Accessibility Requirements.docx for the applicable requirements. The contractor must indicate the compliance of the proposed solution as: Fully, Partially, Not, or Don’t Know.
Contractor Requirements for Unsupervised Access to NPS Facilities, Systems, and 4.0 Data
Both the FAR (Personal Identity Verification of Contractor Personnel ) and NIST guidance (NIST 800-53 control PS-7, Third Party Personnel Security) requires that the contractor provide evidence that all personnel who will have unsupervised access to DOI information, systems, or facilities have successfully adjudicated background checks and appropriate security clearances and that background check level is commensurate with a Federal employee employed in a similar position.
The following describes the process within the DOI and NPS.
(for Fee Collection Equipment, Software, and Services)
Version Date: 2014-12-18
*Procurement Sensitive*
4.1 Background Investigation and Personal Identity Verification Procedures
4.1.1 Applicability
This section is applicable if the performance of this contract requires contractor personnel to have unsupervised access to a DOI/NPS [facility and/or information system]. The Contracting Officer’s Representative (COR) will be the sponsoring official, and will make the arrangements for personal identity verification and card issuance.
This requirement must be incorporated into any subcontracts that require subcontractor personnel to have regular and routine unsupervised access to a federally-controlled facility for more than 180 calendar days or any unsupervised access to a federally controlled Level 3 or 4 information systems or access to a federal information system.
4.1.2 Background Investigation Process
Upon award of this contract, a National Agency Check with Inquires (NACI) will be conducted to verify the identity of the individual applying for clearance.
Simultaneously, a Moderate Risk Background Investigation (MBI), Standard Form (SF) 85P will be initiated to determine the individual’s suitability for the position. If the MBI adjudication is favorable, nothing more needs to be done. If the adjudication is unfavorable, the credentials will be revoked. In the event of a disagreement between the Contractor and the Government concerning the suitability of an individual to perform work under this contract, the Contracting Officer shall have the right of final determination.
4.1.3 Credentialing Process
Upon award of the contract and prior to the start of contract performance, the Contractor will identify all contractor and subcontractor personnel who will require [physical1 and/or logical2] access for performance of work under this contract. The Contractor must make their personnel available at the place and time specified by the COR in order to initiate screening and background investigations.
The COR, or designee will provide instructions and forms, used to initiate the credentialing process which may include the following:
1 Physical Access. A “Federally controlled facility” is federally owned or leased space, whether for single or multi-tenant occupancy, all or any portion of which is under the jurisdiction, custody or control of DOI. If a building is shared with non-government tenants, only access to the Federal area is controlled. The requirements for contractor credentialing apply even if there is no guard, card reader, or other physical control at the entrance to the office. The 180 calendar day period begins on the first day of the individual’s affiliation with DOI (in this case, the date that contract performance begins rather than contract award) and ends exactly 180 days later, regardless of the number of times the contractor actually accessed a building or IT system.
2 Logical Access. An “information technology system” is defined in the Federal Information Security Management Act of 2002 (44 U.S.C.
§3503(8)). Use of an information system by a contractor on behalf of an agency is defined in 44 U.S.C. §3544(a) (1) (A). If a contractor needs any amount of unsupervised access to a DOI IT system, HSPD-12 compliant credentials must be issued regardless of the duration of access. The credentialing requirement applies whether the contractor accesses the IT system from the premises of a DOI facility, from their own facility, through the Internet, or by any other means.
(for Fee Collection Equipment, Software, and Services)
Version Date: 2014-12-18
*Procurement Sensitive*
• OPM Standard Form 85 or 85P National Agency Check with Inquires (NACI)
• OF-306 Declaration for Federal Employment
• FD-258, Fingerprint card (local procedures may require the fingerprinting to done at a police station and mailed directly to the designated official in the HSPD-12 Contractor letter; in this case, any charges are to be borne by the contractor)
• Release to Obtain Credit Information for any investigation higher than a NACI
• Personal Identity Verification (PIV) card application
Contractor employees are required to give, and to authorize others to give, full, frank, and truthful answers to relevant and material questions needed to reach a suitability determination. Refusal or failure to furnish or authorize provision of information may constitute grounds for denial or revocation of credentials. Government personnel may contact the contractor personnel being screened or investigated in person, by telephone or in writing, and the Contractor agrees to make them available for such contact.
4.1.4 Contractor Personnel Already Credentialed by another Agency
Alternatively, if an individual has already been credentialed by another agency through OPM, and that credential has not yet expired, further investigation may not be necessary. Provide the COR with documentation that supports the individual’s status.
4.1.5 Changes in Contractor Personnel
During performance of the contract, the Contractor will keep the COR apprised of changes in personnel to ensure that performance is not delayed by compliance with credentialing processes. Cards that have been lost, damaged, or stolen must be reported to the COR and Issuing Office within 24 hours.
Replacement will be at the contractor’s expense. If re-issuance of expired credentials is needed, it will be coordinated through the COR.
4.1.6 Conclusion of Contract Performance
At the end of contract performance, or when a contractor employee is no longer working under this contract, the Contractor will ensure that all identification cards are returned to the COR.
Planning, meeting, and development may begin on this contract; however logical access to the DOI or NPS systems, network, or unsupervised access to DOI or NPS buildings will not be granted until a favorable report from the fingerprint print report of the National Agency Check with Inquiries (NACI) process is received.
http://www.opm.gov/forms/html/sf.asp http://www.opm.gov/forms/Optional-forms/
*Procurement Sensitive*
4.2 Contractor Personnel Access to the DOI/NPS Information Systems
4.2.1 Applicability
This section is applicable IF performance of this contract requires contractor personnel to have unsupervised access to a DOI information system and/or the NPS network (i.e., to provide remote support).
4.2.2 Network Access Request Process
The contractor personnel, with the COR as the sponsoring official, must complete the following steps prior to being permitted to access the DOI/NPS network:
1. Complete the Minimum Background Investigation (MBI) with a positive determination.
2. Complete the Federal Information Systems Security Awareness & Privacy & Records
Management (FISSA) training. This is annually required training in order to maintain a current AD account, and includes acceptance of the Rules of Behavior for use of the NPS network.
3. Complete and submit the required network package forms provided by the COR.
4. Obtain a Personal Identity Verification (PIV) smart card, which must be used for two-factor authentication to all computers on the DOI/NPS network, and must be used for remote VPN access to the DOI/NPS network.
5. Obtain a government-furnished laptop or other computer.
Government Furnished Equipment (GFE) 5.0
5.1 Applicability
Contractors needing NPS network access for equipment or software installation, support, or training, will be furnished with a government computer which may only be used to access any POS units or back-office database software.
5.2 Prerequisites
To be issued government furnished equipment (GFE), the following pre-requisites must have been met:
• Contractor employee’s background investigation must have been cleared
• Contractor’s employee has read, understood and agreed to complete all required access agreements and training prior to being granted access to DOI information. (Rules of Behavior, Account Form(s), Security Awareness Training (FISSA+), Wireless Access ROB, etc.), per NIST 800- 53 controls AT-2, PL-4, PS-6 o The FISSA+ and ROB must be completed before work begins and every 12 months thereafter. Failure to complete this requirement may result in a disruption of network access.
*Procurement Sensitive*
5.3 Hardware / Software
IF the hardware or software will be used over the NPS Network and the contractor requires logical access to access government networks (either on-site or via remote VPN), the government will provide the contractor with a limited number of government-owned laptop computers. Laptops will be provided in an “as-is” condition to the contractor upon completion of the prerequisites (above) and approval of the COR.
Government-furnished laptops will include the following software pre-installed:
• Windows 7
• Microsoft Office Suite 2010
• Adobe Acrobat
• NPS-approved virus protection software
• Microsoft Internet Explorer
5.4 Request GFE
The contractor must request to the government if GFE is required for their performance of the contract.
The contractor must provide a request (and upon NPS approval) for licenses for additional software and identify hardware drivers (i.e., printers) to be loaded.
If additional software is requested, the Contractor must identify the role of the contractor employees requiring the software, with justification for why the contractor employee requires the additional software. License requests are subject to government approval, and if approved, the government will be responsible for purchase of the licenses.
5.5 Confirmation of Possession
Upon request the contractor must provide confirmation of the issued GFE is in their possession.
5.6 Acceptance of GFE
Upon receipt of the GFE, the contractor is given 5 days to inspect the GFE for acceptance. After this period, damage, repairs, replacement, and/or refurbishment of the GFE will be at the contractor’s expense (FAR 52.245-1).
5.7 Maintenance of GFE
The contractor must ensure the GFE is maintained with current OS patches and anti-virus software. This is particularly important when the GFE is used remotely from the DOI WAN on a regular basis. The contractor must connect the GFE to the NPS Network via VPN or directly at least once every two weeks to ensure that all security files are up to date.
*Procurement Sensitive*
5.8 Damaged GFE
The contractor is responsible for any damage to the GFE.
5.9 Return GFE
The contractor must return all government furnished information and property at end of the contract or when the government requests the information or property. DOI will own the intellectual property rights to work developed on its behalf to the maximum extent possible, per NIST 800-53 control PS-4, Personnel Termination, and FAR 52.227-14 Rights in Data - General.
5.10 Government Furnished Property (GFP), Services and Data
In order to provide the ability for the equipment to function, the park will provide connectivity as described in the Statement of Work and Appendix-Connectivity Description.
In accordance with FAR 52.245-1, Alternate 1 and FAR 52.245-9, Use and Charges clauses the Government will provide to the Contractor, Government furnished and Government owned property to support the Contractor in providing required services as specified in the SOW for this solicitation.
All Government furnished and Government owned property, including any altered or derivative version of said property, must be returned to the Government within 10 days of request by the COR or CO, or within 10 days of after contract has expired
5.11 Exclusive Rights
The Government will provide and/or retain the exclusive rights to the GFP
Publications and Document References 6.0
List of applicable Laws, Regulations, Policy’s, and Guides
Law/Reg./Policy/Guides Affects What? Requirement
Federal Information Security Management Act of (FISMA)
NIST 800-53
FedRAMP
DOI 375 DM19
Information Security
Requires attention to IT security in all agency applications, and accountability to OMB and Congress. It requires:
“Standards to be used by all agencies to categorize all information and information systems” according to risk levels.
“Guidelines recommending the types of information and systems” for each risk category.
“Minimum information security requirements” for information and systems in each category.
Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. https://cloud.cio.gov/strategy/; https://www.cio.gov/policies-and-priorities/cybersecurity/ for Cloud Service Providers (CSPs);
http://cloud.cio.gov/fedramp https://cio.gov/protect/fedramp/ https://www.cio.gov/policies-and-priorities/cybersecurity/
*Procurement Sensitive*
National Institute of Standards and Technology (NIST) Special Publications and Federal Information Processing Standard Publications (FIPS)located at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
HSPD-12 Information Security and Network Access
Homeland Security Presidential Directive 12: Policy for a Common Identification
FAR Clause 52.204-9, Personal Identity Verification of Contractor Personnel
DOI HSPD-12 Directive, Policy and Guide, Documents and Links
OMB A-123 Fee Collection Policies
OMB Circular A-123, Management's Responsibility for Internal Control.
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://www.dhs.gov/homeland-security-presidential-directive-12 http://www.dhs.gov/homeland-security-presidential-directive-12 https://acquisition.gov/far/current/html/52_200_206.html http://www.doi.gov/hspd12/index.cfm https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://www.acquisition.gov/far/52.204-9 https://www.doi.gov/sites/doi.gov/files/migrated/hspd12/upload/PIV_Guide_v1_final.doc https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2016/m-16-17.pdf
| 1.0 Overview |
| 2.0 Federal IT Security Management Act (FISMA) Requirements |
| 2.1 Security Controls |
| 2.2 Secure Configuration of Computers |
| 2.3 Key Personnel |
| 2.4 Non-Disclosure |
| 2.5 Role-Based Security Training for Privileged Users |
| 2.6 Software |
| 2.7 Mobile Device Security |
| 2.8 Cryptographic Capabilities for Mobile Devices |
| 2.9 Technical Information Provided to NPS for Software Approval to use on the ESN Network |
| 3.0 Section 508 of the Rehabilitation Act |
| 4.0 Contractor Requirements for Unsupervised Access to NPS Facilities, Systems, and Data |
| 4.1 Background Investigation and Personal Identity Verification Procedures |
| 4.1.1 Applicability |
| 4.1.2 Background Investigation Process |
| 4.1.3 Credentialing Process |
| 4.1.4 Contractor Personnel Already Credentialed by another Agency |
| 4.1.5 Changes in Contractor Personnel |
| 4.1.6 Conclusion of Contract Performance |
| 4.2 Contractor Personnel Access to the DOI/NPS Information Systems |
| 4.2.1 Applicability |
| 4.2.2 Network Access Request Process |
| 5.0 Government Furnished Equipment (GFE) |
| 5.1 Applicability |
| 5.2 Prerequisites |
| 5.3 Hardware / Software |
| 5.4 Request GFE |
| 5.5 Confirmation of Possession |
| 5.6 Acceptance of GFE |
| 5.7 Maintenance of GFE |
| 5.8 Damaged GFE |
| 5.9 Return GFE |
| 5.10 Government Furnished Property (GFP), Services and Data |
| 5.11 Exclusive Rights |
| 6.0 Publications and Document References |
| List of applicable Laws, Regulations, Policy’s, and Guides |
File details come from the government source that posted it. Updated .