A40 Att 3 PWS ISA.pdf
PDF 2 MB Posted
- Attached to
- Credit Reporting Federal contract opportunity
- Solicitation number
- HS0021-23-R-0016
About this file
This is a combined synopsis/solicitation for multiple award IDIQ firm fixed price contracts to provide credit reporting services. The Defense Counterintelligence and Security Agency seeks up to three awardees to provide single credit bureau reports and tri-merge reports combining data from all three bureaus. The period of performance is five years with five one-year options. The solicitation response date is April 24, 2023, with a minimum order of 3,000 single reports and 100 tri-merge reports and maximum order of 5,000,000 single reports and 1,500,000 tri-merge reports. The NAICS code is 561450 for credit bureaus with a $41 million size standard. The acquisition is a 100% small business set-aside. The solicitation includes a performance work statement, data delivery schedule, interconnection security agreement, report examples, ordering guide template, and price workbook.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CUI
DCSA Background Investigation Enterprise System (BIES) Program Management Office (PMO)
Version 1
DD Month YYYY
INTERCONNECTION SECURITY
AGREEMENT BETWEEN DEFENSE
COUNTERINTELLIGENCE AND
SECURITY AGENCY (DCSA) AND
“ORGANIZATION B”
Controlled by: DCSA Controlled by: BIES PMO CUI Category: ISVI Distribution/Dissemination Control:
FEDCON
POC:
Chief Information Security Officer (CISO):
Ms. Roxanne Landreaux 571.305.6046 Roxanne.A.Landreaux.civ@mail.mil i
Document History
Revisions and version changes to this document are recorded within the following table. New versions are published when changes to the document equate to 10 percent or greater of the document's content, or if a change requires immediate implementation. This record is maintained throughout the life of the document.
This document will be reviewed at a minimum annually.
DATE VERSION DESCRIPTION OF CHANGE NAMES/NOTES
5/5/21 -- Initial development. Updated formatting and language throughout the document
Al Nees Cheryl Abrams
1.0 ii
THIS PAGE LEFT INTENTIONALLY BLANK
iii
TABLE OF CONTENTS
1. Introduction
1.1 Purpose
1.2 References
1.3 Scope
2. Interconnection Statement of Requirements
3. System Security Considerations
3.1 Data Description/Data sensitivity
3.2 Services Offered
3.3 User Community
3.4 Information Exchange Security
3.5 Rules of Behavior
3.6 Formal Security Policy
3.7 Incident Reporting
3.8 Audit Trail Responsibilities
3.9 Operational Security Mode
3.10 Training and Awareness
3.11 Specific Equipment Restrictions
3.12 DCSA Security Documentation
3.13 <Organization B> Security Documentation
3.14 Interconnection security agreement annual review audit
4. Topological Drawing
5. Signatory Authority Appendix A: Data Exchange Questionnaire (DEQ)
1. INTRODUCTION
1.1 PURPOSE
The intent of the Interconnection Security Agreement (ISA) is to document and formalize the interconnection agreement and the terms under which the Defense Counterintelligence and Security Agency (DCSA) and “Organization B” will abide by the agreement, based on all relevant technical, security and administrative requirements for the systems being interconnected. General guidance regarding the contents of an ISA is provided below; however, an ISA may be tailored by mutual consent of the participating organizations. A system that is approved by an ISA for interconnection with one organization’s system should meet the protection requirements equal to, or greater than, those implemented by the other organization’s system.
1.2 REFERENCES
The authority for interconnectivity between information technology (IT) systems is based on Office of Management and Budget (OMB) Circular A-130, Managing Information as a Strategic Resource (Appendix III), NIST 800-47, Security Guide for Interconnecting Information Technology Systems, and a signed Memorandum of Understanding (MOU) or Memorandum of Agreement (MOA) between the two organizations that are establishing the interconnection under DCSA agreement number XXXX.
1.3 SCOPE
This is effective in the following System Development Life Cycle (SDLC) phases:
CONCEPTS DEVELOPMENT DEPLOYMENT X
DESIGN OPERATIONS X
DEVELOPMENT X DISPOSAL X
2. INTERCONNECTION STATEMENT OF REQUIREMENTS
The requirements for interconnection between DCSA and “Organization B” are for the express purpose of exchanging data between “System A”, owned by DCSA, and “System B”, owned by “Organization B” in support of DCSA’s Background Investigation mission as approved and directed by [insert appropriate approving official] dated [specify date].
<Insert statement regarding specific purpose for the interconnection Include they type of data shared and benefits derived as a result of the interconnection.>
3. SYSTEM SECURITY CONSIDERATIONS
This section documents the security features that are in place to protect the confidentiality, integrity, and availability of the data and the systems being interconnected.
3.1 DATA DESCRIPTION/DATA SENSITIVITY
Data Usage <Identify the purpose and usage of the data to be transmitted>
Type of Data Transmitted <Provide description of the type of data / data elements transmitted over this interconnection>
Type of Connection <one-way, bi-directional/two-way, VPN, etc.>
Frequency of Transmission <Daily, Weekly, Monthly>
Overall Data Sensitivity The sensitivity of data exchanged between DCSA and “Organization B” is <Controlled Unclassified Information (CUI)>.
Categories of Sensitive Data Transmitted
Privacy (PRVCY) Sensitive Personally Identifiable Information (SPII)
Link to CUI categories: CUI Markings | National Archives>
3.2 SERVICES OFFERED
The interconnection between DCSA and “Organization B” is established for the purpose of exchanging data electronically between these organizations. No other services are provided.
< Add statement of the type of services offered and/or provided. Example: No user services are offered.
This connection only exchanges data between DCSA's system and Organization B's system via a dedicated in-house connection.>
3.3 USER COMMUNITY
All DCSA users with access to the data received from “Organization B” have been previously authorized by DCSA to access “System A” based on a need-to-know and appropriate access privileges granted for the sole purpose of supporting the DCSA Background Investigation mission.
<All Organization B users with access to <the data received from DCSA or DCSA “System A” are>
3.4 INFORMATION EXCHANGE SECURITY
The security of the information being passed on this <type of connection (ex: two-way)> connection is protected with FIPS 140-2 approved encryption mechanisms. “System A” is located within controlled access facilities. All access is controlled by authentication methods to validate the approved users.
<Organization B/System B add a statement regarding access control to your system (example: “System B” is located in…)>
Protocols https://www.archives.gov/cui/registry/category-marking-list https://www.archives.gov/cui/registry/category-marking-list
Key Management Security Protocol Transport Method / Transport Data Encryption Algorithm Message Digest Algorithms
Operational Parameters Key Lifetime Pre-Shared secret key
3.5 RULES OF BEHAVIOR
DCSA users are expected to protect data in accordance with the policies and standards of the Privacy Act of 1974, 5 U.S.C 552a, Managing Information as a Strategic Resource OMB A-130 and DCSA’s Information Technology Security Policy. Users who access DCSA applications and IT resources are required to comply with DCSA Computer Users Responsibilities statement. In addition, DCSA Rules of Behavior for Users of Information Technology requires that major applications have application-specific rules of behavior, which must be accepted and signed by application users.
<Organization B add User Rules of Behavior Statement>
3.6 FORMAL SECURITY POLICY
This interconnection must comply with all the below identified policies and standards:
• DCSA:
o National Institute of Standards and Technology (NIST) Special Publication (SP) 800-47 Revision 1, Managing the Security of Information Exchanges o Department of Defense (DoD) Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), July 19, 2022 o Office of Management and Budget (OMB) Circular A-130, Managing Information as a Strategic Resource o Committee on National Security Systems (CNSS) Instruction No. 1253, Security Categorization and Control Selection for National Security Systems o Defense Security Service (DSS) Assessment and Authorization Process Manual (DAAPM), August 2020 o Office of Management and Budget (OMB) Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information
• “Organization B”:
o < Add Interconnection Security / Information Sharing Policy>
3.7 INCIDENT REPORTING
DCSA, upon discovering a security incident, shall immediately notify the designated “Organization B” counterpart by telephone or e-mail so that “Organization B” can determine whether their system has been compromised and to take appropriate action.
Additionally, DCSA, upon discovering a security incident, shall immediately notify the OPM OCIO Security Operations Center by telephone or email within one (1) hour of discovering the incident so that OPM is aware of the incident, can determine if the OPM information technology infrastructure has been compromised and to take appropriate action, if necessary.
“Organization B”, upon discovering a security incident, shall report it in accordance with their specific incident reporting procedures shall immediately notify the DCSA Cyber Defense Operations in the table below. DCSA will follow appropriate incident response procedures.
OPM, upon discovering a security incident, in accordance with their specific incident reporting procedures shall immediately notify the DCSA Cyber Defense Operations by telephone or email so that DCSA is aware of the incident and take appropriate action. OPM Security Operations Center may be reached via email or by telephone.
DCSA Incident Response: OPM Incident Response: “Organization B” Incident Response:
DCSA Cyber Defense Operations Phone: 571-305-6001 Email: dcsa.quantico.dcsa-hq.mbx.cnd-soc@mail.mil
OCIO Security Operations Center Phone: 844-377-6109 Email: Cybersolutions@OPM.gov
3.8 AUDIT TRAIL RESPONSIBILITIES
Both organizations are responsible for auditing application processes and user activities relevant to this interconnection. Activities that will be captured in audit logs include, but not limited to the following event types:
• System startup and shutdown;
• User logon and logoff;
• Privilege escalation;
• Account creation;
• Password changes;
• Starting and stopping of processes and services;
• Installation and removal of software;
• System alerts and error messages;
• System administration activities;
• Access to and modification of Restricted Data;
• Identifier of the system that generated the event;
• Timestamp of the event;
• The action or type of event and any relevant data;
• Success or failure of the action;
• The user associated with the event; and
• Remote address, if the event occurs over a network connection.
DCSA policy requires that all Information Systems (IS), applications, and databases have auditing capabilities. Auditing should provide enough information to trace actions to specific times and users and to provide sufficient information to support after-the-fact investigations of security incidents. Audit logs will be reviewed on a regular basis. Anomalous events are to be investigated and, if necessary, reported in accordance with the Incident Reporting process described above in Section 3.7. Per DoD Information System Security Auditing Policy, audit logs will be retained for a minimum of one (1) year to support after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.
<”Organization B” add statement>
3.9 OPERATIONAL SECURITY MODE
Federal Right to Financial Privacy Act (RFPA) data traverses this interconnection. Though the data is not classified, it is Controlled Unclassified Information (CUI) and requires strong measures to provide a high level of confidence that data Confidentiality, Integrity and Availability are preserved. Examples of types of data and concerns regarding protection include:
• Personal information that traverses this interconnection must not be revealed to unauthorized persons; to do so would violate the Federal Right to Financial Privacy Act.
• Personal and financial data that traverse this interconnection must not be vulnerable to unauthorized changes; such changes could cause misreporting and/or inappropriate payments.
• Data that crosses this interconnection is critical to the timely completion of DCSA missions, such as distribution of payments, maintenance of personnel records and completion of background investigations; any unnecessary disruption of the data flow could delay DCSA from meeting commitments.
The Federal Information Processing Standards (FIPS) Publication 199 security categorization for these systems are:
System Confidentiality Integrity Availability Overall
[DCSA System]
System Confidentiality Integrity Availability Overall
[Organization B System Name]
3.10 TRAINING AND AWARENESS
All computer users, staff, internal and external contractors who have access to DCSA IT systems and DCSA applications must complete IT Security Awareness Training (DoD Cyber Awareness Challenge Training) and DoD Controlled Unclassified Information (CUI) Training as part of initial training and annually thereafter. Additionally, DCSA employees whose duties include security responsibilities shall receive specialized security training that includes the relevant policies, procedures, and rules of behavior associated with the exchanged information and the systems that process, store, and transmit the information. Specialized training will facilitate their unique role in the security of the Information System prior to receiving access to the system.
<Organization B add statement>
3.11 SPECIFIC EQUIPMENT RESTRICTIONS
<Add statement if needed.>
3.12 DCSA SECURITY DOCUMENTATION
The following Information Technology (IT) security documents are the specific plans and installation procedures that are being used to govern the protection of <System A> data.
• [DCSA System] Authorization to Operate (ATO); ATO granted on 01-Jan-2021 / Authorization Termination Date (ATD) is 19-Jan-2023
• [DCSA System] Categorization Level Agreement (CLA)
• [DCSA System] Privacy Impact Assessment (PIA)
• [DCSA System] System Security Plan (SSP)
• [DCSA System] Information System Contingency Plan (ISCP)
3.13 <ORGANIZATION B> SECURITY DOCUMENTATION
The following Information Technology (IT) security documents are the specific plans and installation procedures that are being used to govern the protection of <System B> data.
• “System B” Authorization to Operate (ATO); ATO granted on DD-MMM-YYYY / Authorization Termination Date (ATD) is DD-MMM-YYYY
• <Organization B add statement>
3.14 INTERCONNECTION SECURITY AGREEMENT ANNUAL REVIEW
AUDIT
As required by DCSA policy regarding annual reviews of ISA documentation, “Organization B” is responsible for participating in an annual review of this connection and all connection documentation, to include the ISA. Changes to “Organization B” personnel documented in this ISA or changes to the technical connection and/or connected system are to be communicated to DCSA. During DCSA BIES PMO’s annual ISA review timeframe, if an agency is unresponsive to requests for an ISA review, the connection in question is subject to be disconnected. It is important to notify the following groups of all changes to avoid connection disruption:
DCSA Group Email
DCSA COR TBD
DCSA BIES PMO ISA Coordinators
DCSA BIES ISA email distro:
dcsa.quantico.dcsa.list.peo-bies-isa@mail.mil
Justin Croyle, Justin.j.croyle.civ@mail.mil Niya Whiteside, Niya.whiteside.civ@mail.mil Marlon Holmes, Marlon.j.holmes2.civ@mail.mil Sammi Ly-Moy, Sammi.m.ly-moy.civ@mail.mil Rachel Leidy, Rachel.a.leidy.ctr@mail.mil (CTR)
4. TOPOLOGICAL DRAWING
Figure 1 illustrates all communication paths, circuits and other components used for the interconnection.
As of the signing of this ISA, the external agency attest that the topological diagram is true and accurate.
FIGURE 1: TOPOLOGICAL DRAWING
5. SIGNATORY AUTHORITY
This ISA will remain in effect for three (3) years following the effective date, after which it will expire without further action. This agreement will be reviewed annually or whenever a significant change occurs to ensure that security controls are operating properly and providing appropriate levels of protection. If the parties wish to extend this agreement, they may do so by reviewing and updating this agreement.
The newly signed agreement will explicitly supersede this agreement, which should be referenced by title and date in the appropriate section of this document. Either party may terminate this agreement with thirty days (30) advance notice, or it may be terminated immediately if a security incident necessitates prompt action.
DCSA / OPM Approval:
<First Name Last Name> System Owner (SO) Defense Counterintelligence and Security Agency
(DCSA)
[Digital Signature and Date]
Roxanne Landreaux Chief Information Security Officer (CISO) Defense Counterintelligence and Security Agency
(DCSA)
James Saunders Chief Information Security Officer (CISO) U.S. Office of Personnel Management (OPM)
[Organization B] Approval:
[Name] [Title] [Interconnected Agency Name]
Name]
Name]
APPENDIX A: DATA EXCHANGE QUESTIONNAIRE (DEQ)
Applicable only for Connect: Direct interconnections. Delete form if not applicable.
Interconnection Technical Points of Contact
Data Exchange Partner/Location:
Time zone: (EST, CST, MST, PST, etc.)
Data Exchange Partner Help Desk:
Phone Number:
Email Address:
Data Exchange Partner Network Contact:
Data Exchange Partner Network Administrator:
Data Exchange Partner Network Security Officer:
Data Exchange Partner Programmer/Database Administrator:
Other Data Exchange Partner Contacts:
NAME/ROLE:
Phone Number:
Email Address:
Organization:
Function:
Email Address:
Email Address:
Interconnection Technical Details
1. Host Type:
Windows PC Windows Server Unix MVS/zOS Series/AS400 Other
2. Can host currently reach the INTERNET? No Yes Yes/VPN Dedicated Circuit to DCSA (YES/NO)?
Speed of Network Connection:
If no Dedicated Circuit, INTERNET access? (YES/NO) Type of File Transfer desired: (PC/MAINFRAME):
3. Do you have the CONNECT:DIRECT software (YES/NO)?
If so, do you have the CONNECT:DIRECT SECURE+ (YES/NO)?
If so, which version/level do you use? (Connect:Direct) / (Secure+) If so, which certificate authority do you use? (DCSA uses Entrust.)
(Important: When providing user IDs and node names below, please refer to the DCSA Security policy for Connect:Direct configuration at the bottom of this document.)
4. Operating Environment (Check one): 1, 2 Test QA Production Other User ID(s) used to connect to DCSA:3 Customer NODE NAME: (Max 16 Chars.)
Who initiates the C:D connection? DCSA only Customer only Either Public IP addresses = or Associated public DNS name 4 = Port number =
5. Is there a firewall (YES/NO)?
If so, does it allow PORT 1364 for CONNECT:DIRECT?
6. Approximate size of data transfer (in bytes):
(DCSA use only)
7. DCSA Node Name: IP address: port:
DCSA User ID(s):
1 DCSA requires that one technical page be filled out for each operating environment. Once you complete this page for one environment, you may duplicate it and modify it for another environment to avoid retyping everything else on this page.
2 DCSA recommends using one node name per operating environment. This node name may be associated with one or more user IDs and one or more IP addresses. However, the configurations must conform to the requirements listed in the DCSA Security policy for Connect:Direct configuration at the bottom of this form.
3 One or more user IDs are required for you to initiate a connection with DCSA. If the connection is always initiated by DCSA, then a user ID is not required.
4 One or more IP addresses must be provided. DCSA will be forwarded to OPM Network Support to create firewall rules allowing traffic to/from these IPs. If a DNS name is provided, it will be forwarded to System Services Support for net map configuration; otherwise System Services Support will use the IPs for net map configuration. If more than six IP addresses are provided, a DNS name must be provided for net map configuration.
A DNS name is preferable from a C:D configuration perspective. However, even though C:D may be configured with a DNS, you must still supply DCSA with all underlying IP addresses. This is because DCSA network security requires specific firewall rules allowing access to specific IP addresses, or to specific IP address ranges.
DCSA Security Policy for Connect:Direct Configuration
• DCSA maintains two Connect:Direct server nodes – test and production.
• Partners exchanging data with DCSA are required to maintain connections to both DCSA’s test and production nodes.
• Because maintaining separate simultaneous nodes requires multiple instances of the software, and hence purchase of multiple software licenses, partners are encouraged 5 – but not required – to maintain their own separate test and production Connect:Direct nodes (See footnote on advisability of maintaining separate nodes). Currently DCSA will not maintain identical configurations in test and production simultaneously.
• When a connection is supporting only one business application, the partner is required to provide one node name and user
ID.
• When a connection supports more than one business application, the partner is required to distinguish between configurations according to the following rules:
o Partners running the server version of Connect:Direct must provide unique a user ID for each business application.
o Partners running FTP+ (the client version of Connect:Direct) must provide a unique node name for each business application.
These configuration requirements are illustrated by the following chart.
C:D/Secure+ Server FTP+ Client Node User ID Node User ID Business App1 Node1 User1 Node1 User1 Business App2 Node1 User2 Node2 User1 Business App3 Node1 User3 Node3 User1 Business Appn Node1 Usern Noden User1
Explanation of terms
C:D/Secure+ Server version of Connect:Direct (Partner) FTP+ Client version of Connect:Direct (Partner) Business App1-n One or more business applications supported by a Connect:Direct connection.
Node1-n Unique node names.
User1-n Unique user IDs.
5 Partners are encouraged to maintain separate nodes, despite the additional cost. This is because sometimes DCSA will implement updates or enhancements to its Connect:Direct software that can potentially influence connectivity with partners. In these situations, DCSA will typically apply changes to the test server a few weeks before changing the production server. This enables both sides to do any necessary troubleshooting without affecting production.
Important: Partners who elect to use a single node assume the risk of possible interruptions in production in the event that Connect:Direct or certificate upgrades occur, since the opportunity to test such changes on a test node would not be available. Additionally, since DCSA will not maintain identical configurations in test and production simultaneously, moving to test for one application will interrupt production transmissions for any other business application.
| 1. Introduction |
| 1.1 Purpose |
| 1.2 References |
| 1.3 Scope |
| 2. Interconnection Statement of Requirements |
| 3. System Security Considerations |
| 3.1 Data Description/Data sensitivity |
| 3.2 Services Offered |
| 3.3 User Community |
| 3.4 Information Exchange Security |
| 3.5 Rules of Behavior |
| 3.6 Formal Security Policy |
| 3.7 Incident Reporting |
| 3.8 Audit Trail Responsibilities |
| 3.9 Operational Security Mode |
| 3.10 Training and Awareness |
| 3.11 Specific Equipment Restrictions |
| 3.12 DCSA Security Documentation |
| 3.13 <Organization B> Security Documentation |
| 3.14 Interconnection security agreement annual review audit |
| 4. Topological Drawing |
| 5. Signatory Authority |
| Appendix A: Data Exchange Questionnaire (DEQ) |
File details come from the government source that posted it. Updated .