Atch 1_Governing Guidance and Directives.docx

DOCX document 22 KB Posted

Attached to
CSO Call 003 TRANSCOM "Medical" Regulating and Command & Control Evacuation System (TRAC2ES) Federal contract opportunity
Solicitation number
CSOCall_003_TRAC2ES
Issued by
Department of Defense United States Transportation Command

About this file

This is a governing guidance and directives attachment that establishes the regulatory and policy framework for the TRAC2ES (TRANSCOM Medical Regulating and Command & Control Evacuation System) contract. The document references over 80 federal regulations, DoD instructions, NIST standards, and other authoritative guidance documents that contractors must comply with throughout contract performance.

The governing directives span multiple compliance domains critical to TRAC2ES operations: information security and classification (32 CFR Part 117, DoD Manual 5200.01 series, NIST SP 800-171); cybersecurity and risk management (DoD Instruction 8500.01, NIST SP 800-37 and 800-53); personnel security and workforce management (DoD Manual 5200.02, DODD 8140.01); data protection and privacy (HIPAA implementation guidance, CUI standards per 32 CFR Part 2002); physical security and antiterrorism (DoD Instructions 2000.12 and O-2000.16); records management (DoD Instruction 5015.02); and system engineering standards (NIST 800-160 series, ISO/IEC/IEEE 12207-2017). Additionally, contractors must comply with health care-specific regulations including Army Regulation 40-66 for medical record administration and Air Force Manual 41-210 for patient administration support. The document emphasizes earned value management (ANSI/EIA 748E), information technology interoperability and security configuration management, identity authentication, and continuous monitoring strategies as established by USTRANSCOM's CIO memoranda and policies.

View the file

Other files for this federal contract opportunity

Other files attached to CSO Call 003 TRANSCOM "Medical" Regulating and Command & Control Evacuation System (TRAC2ES), newest first.
File Type Posted
2026.04.09_TRAC2ES_QA_SAM.gov.xlsx XLSX spreadsheet
2026.04.06_TRAC2ES_Q&A_SAM.gov.xlsx XLSX spreadsheet
Atch 3_NDA TDP.docx DOCX document
Atch 2_TDP.docx DOCX document
2026.03.09 CSO Call 003_TRAC2ES.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TRAC2ES

Attachment 1 Governing Guidance and Directives

• 32 Code of Federal Regulations (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM)

• 32 CFR Part 2002, Controlled Unclassified Information (CUI), 31 August 2023

• 36 CFR Part 1194, Information and Communication Technology Standards and Guidelines, 28 August 23

• American National Standards Institute (ANSI)/Electronic Industries Alliance (EIA) 748E: Earned Value Management, 16 February, 2026

• CJCS Instruction 5123.01H, Charter of the Joint Requirements Oversight Council (JROC) and Implementation of the Joint Capabilities Integration and Development System (JCIDS), August 31, 2018

• CJCS Instruction 6510.01F, Information Assurance (IA) and Support to Computer Network Defense (CND), June 9, 2015

• DD Form 254, Contract Security Classification Specification, April 1, 2018

• DFARS Subpart 239.71, Security and Privacy for Computer Systems https://www.acq.osd.mil/dpap/dars/dfars/pdf/r20080110/239_71.pdf

• DFARS 252.205-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, 10 November, 2025

• DoD Directive 5230.25, Withholding of Unclassified Technical Data from Public Disclosure, Change 2, 15 October 2018

• DODD 8140.01, Cyberspace Workforce Management, October 5, 2020

• DoD Instruction 1100.22, Policy and Procedures for Determining Workforce Mix, Change 1, December 1, 2017

• DoD Instruction 2000.12, DoD Antiterrorism Support to Force Protection, June 11, 2025

• DoD Instruction O-2000.16, DoD Antiterrorism Program Implementation: DoD Antiterrorism Program Standards, Volume 1, June 11, 2025

• DoD Instruction O-2000.16, DoD Antiterrorism Program Implementation: DoD Force Protection Condition (FPCON) System Volume 2, June 11, 2025

• DoD Instruction 5015.02, DoD Records Management Program, Change 1, 17 August 2017

• DoD Instruction 5200.01, “DOD Information Security Program and Protection of Sensitive Compartmented Information (SCI),” Change 2, October 1, 2020

• DoD Instruction 5025.13, DOD Plain Language Program, Change 2, February 9, 2024

• DoD Instruction 5200.08, Security of DoD Installations and Resources and the DoD Physical Security Review Board (PSRB), Change 3, November 20, 2015

• DoD Instruction 5200.48, Controlled Unclassified Information (CUI), March 6, 2020

• DOD Instruction 5400.11, DOD Privacy and Civil Liberties Programs, Change 1, 8 December 2020

• DoD Instruction 8320.02, Sharing Data, Information, and Information Technology (IT) Services in the Department of Defense, Change 1, June 24, 2020

• DoD Instruction 8330.01, Interoperability of Information Technology (IT), Including National Security Systems (NSS), September 27, 2022

• DoD Instruction 8500.01, Cybersecurity, Change 1, October 7, 2019

• DoD Instruction, 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), Change 2, July 19, 2022

• DoD Instruction 8520.02, Public Key Infrastructure and Public Key Enabling, May 18, 2023

• DoD Instruction 8520.03, Identity Authentication for Information Systems, May 19, 2023

• DoD Instruction 8520.04, Access Management for DoD Information Systems, September 3, 2024

• DoD Instruction 8530.03, Cyber Incident Response, 9 Aug 2023

• DoD Instruction 8551.01, Ports, Protocols, and Services Management (PPSM), May 31, 2023

• DoD Instruction 8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs, August 12. 2015

• DoD Instruction 8582.01, Security of Non-DoD Information Systems Processing Unclassified Nonpublic DoD Information, December 9, 2019

• DoD Manual 1000.13, Volume 1, Identification (ID) Cards for Members of the Uniformed Services, Their Dependents, and Other Eligible Individuals, Change 2, July 1, 2025

• DoD Manual 5200.01, Volume 1, DoD Information Security Program: Overview, Classification, and Declassification, Change 3, January 17, 2025

• DOD Manual 5200.01 Volume 2, DoD Information Security Program: Marking of Information, Change 4, July 28, 2020

• DOD Manual 5200.01 Volume 3, DoD Information Security Program: Protection of Classified Information, Change 4, January 17, 2025

• DoD Manual 5200.02, Procedures for the DoD Personnel Security Program (PSP), Change 1, October 29, 2020

• DoD Standard MIL-STD-881C, Work Breakdown Structures (WBS) for Defense Materiel Items, October 3, 2011

• DoDM 6025.18, Implementation of The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs, March 13, 2019

• FD Form 258, Fingerprint Card, October 21, 2023

• USTRANSCOM Instruction 4200.04, Vol 1, Patient Movement Enterprise, Change 1, June 10, 2022

• USTRANSCOM Instruction 4200.04, Vol 4, TRAC2ES, June 10, 2022

• USTRANSCOM Instruction 5200.10, Security Classification Guide, April 6, 2019

• USTRANSCOM Instruction 5200.08, Policy for Operations Security, June 17, 2023

• USTRANSCOM Instruction 5200.12, Physical Security, May 21, 2018

• USTCI 6600.01A, Policy for Cyberspace Workforce Management, August 16, 2024

• USTRANSCOM Instruction 6600.06A, Policy for Systems Security Awareness Program, September 20, 2023

• USTRANSCOM Instruction 6600.05, Policy for Data Management, October 8, 2024

• Air Force Manual 41-210, Patient Administration Support, January 11, 2026

• Army Regulation 40-66, Medical Record Administration, June 17, 2008

• Scott Air Force Base Instruction 31-101, June 21, 2018

• FIPS 140-2, Security Requirements for Cryptographic Modules, Change 2, December 3, 2002

• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006

• NIST SP 800-18 Revision 1, Guide for Developing Security Plans for Federal Information Systems February 2006

• NIST SP 800-30 Revision 1, Guide for Conducting Risk Assessments, September 2012

• NIST SP 800-37 Revision 2, Risk Management Framework for Information Systems and Organization: A System Life Cycle Approach for Security and Privacy, December 2018

• NIST SP 800-53, Revision 5, Security and Privacy Controls for Information Systems and Organizations, March 20, 2025NIST SP 800-53A Revision 5, Assessing Security and Privacy Controls in Information Systems and Organizations, September, 2020

• NIST SP 800-60, Revision 2, Guide for Mapping Types of Information and Information Systems to Security Categories, January 31, 2024

• NIST SP 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, April, 2025

• NIST SP 800-70, Rev 5, National Checklist Program for IT Products – Guidelines for Checklist Users and Developers, December 9, 2025

• NIST SP 800-125B, Secure Virtual network configuration for Virtual Machine (VM) Protection, March, 2016

• NIST SP 800-126, Rev 3, The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.3, February, 2018

• NIST SP 800-126A, SCAP 1.3 Component Specification Version Updates: An Annex to NIST Special Publication 800-126 Revision 3, February, 2018

• NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems, Updates October 10, 2019

• NIST 800-160, Vol 1, Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems. Updated January 3, 2018

• NIST 800-160, Vol 2, Rev 1, Developing Cyber Resilient Systems: A Systems Security Engineering Approach, December, 2021

• NIST SP 800-171, Rev 3, Protecting Controlled Unclassified Information in Nonfederal Systems, and Organizations, May 10, 2023

• NIST SP 800-175B, Rev 1, Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms, March, 2020

• NIST SP 800-207 Zero Trust Architecture. August 2020

• CNSS Instruction 1253, Security Categorization and Control Selection for National Security Systems, March 27, 2014

• 12207-2017 - ISO/IEC/IEEE Draft International Standard - Systems and software engineering – Software life cycle processes

• Executive Order (E.O.) 13691 of February 13, 2015. Promoting Private Sector Cybersecurity Information Sharing

• Office of Management and Budget (OMB) Memorandum 02-01, Guidance for Preparing and Submitting Security Plans of Action and Milestones, October 17, 2001

• USTRANSCOM Information System Continuous Monitoring Strategy

• USTRANSCOM Chief Information Officer (CIO) Memorandum, Risk Management Framework (RMF) Guidance, February 2022

• USTRANSCOM Chief Information Officer Memorandum, Delegation of Approval Authorities, June 24, 2025

File details come from the government source that posted it. Updated .