Att 13 - 7.2 Cybersecurity Regulations.pdf

PDF 20 KB Posted

Attached to
Long-Term Capabilities Requirements Document Development Support (LT-CRDS) Federal contract opportunity
Solicitation number
HT001124R0064
Issued by
Defense Health Agency

About this file

This document outlines cybersecurity regulations and guidance that a vendor must comply with to fulfill a federal contract supporting long-term capabilities requirements development for the Defense Health Agency. The vendor will need to adhere to regulations including HIPAA, FISMA, E-Government Act, OMB guidance, NIST special publications on risk management and security controls, FIPS publications on cryptographic modules and information system security, and various DoD instructions related to personnel security, cybersecurity, PKI, risk management framework, and privacy of health information. The vendor must also comply with guidance from the Defense Health Agency on isolation architecture, security categorization, operation, and continuous monitoring of facility-related control systems.

The related federal contract opportunity is a solicitation from the Defense Health Agency to provide long-term capabilities requirements document development support. The solicitation number, agency, and opportunity type are provided.

View the file

Other files for this federal contract opportunity

Other files attached to Long-Term Capabilities Requirements Document Development Support (LT-CRDS), newest first.
File Type Posted
HT001124R0064-0002.pdf PDF
HT001124R0064-0001 LT-CRDS Amend 0001.pdf PDF
Att 18 - LT-CRDS RFP Q and A Sheet Final.pdf PDF
Att 14 - 7.2 FRCS Responsibility Matrix.pdf PDF
Att 11 - 7.1.2_DHA Mandatory Training List 2023.pdf PDF
Att 9 - 7.1.1_DHA CAC Request Process.pdf PDF
Att 7 - LT-CRDS QASP Draft.doc DOC document
Att 4 - LT-CRDS Sample Consent Letter.docx DOCX document
Att 3 - LT-CRDS Past Performance Questionnaire.docx DOCX document
Att 1 - LT-CRDS PWS.pdf PDF
Att 16 - 7.2 DHA_Form_49_DHA KTR.pdf PDF
Att 8 - LT-CRDS DD Form 254.pdf PDF
Att 6 - LT-CRDS CDRL Portfolio.pdf PDF
Att 2 - LT-CRDS Pricing Sheet.xlsx XLSX spreadsheet
Att 17 - WD 2015-4281 Rev 27.pdf PDF
Att 15 - 7.2 Risk Assessment Framework.pdf PDF
Att 10 - 7.1.1_DMDC TASS Application.xlsx XLSX spreadsheet
Att 5 - LT-CRDS OCI Contract List.xlsx XLSX spreadsheet
Att 8 - LT-CRDS DD Form 254 scanned pdf.pdf PDF
HT001124R0064 LT-CRDS RFP.pdf PDF
Att 12 - 7.1.3 DHA New Employee Handbook.pdf PDF
Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 3

Cybersecurity Regulations and Guidance

The Vendor shall use and comply with the most recent published versions of the following references, as well as all regulations or guidance referenced within those publications:

(a) United States Law

(i) The Health Insurance Portability and Accountability Act of 1996 (HIPAA)

(ii) The Federal Information Security Management Act (FISMA)

(iii) The E-Government Act of 2002

(b) Office of Management and Budget (OMB)

The following publications are located at https://www.whitehouse.gov/omb/agency/default

(i) Circular A-130

(ii) Guidance M-05-24, Implementation of Homeland Security Presidential Directive

(HSPD) 12-Policy for a Common Identification Standard for Federal Employees and Vendors

(c) National Institute of Standards and Technology (NIST) The following publications are located at http://www.nist.gov/publication-portal.cfm

(i) NIST Special Publication (SP) 800-37 – Guide for Applying the Risk Management

Framework (RMF) to Federal Information Systems

(ii) NIST SP 800-39—Managing Information Security Risk: Organization, Mission and

Information System View

(iii) NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations

(iv) NIST SP 800-60—Volume 1 Revision 1: Guide for Mapping Types of Information and Information Systems to Security Categories

(d) Federal Information Processing Standards (FIPS) The following publications are located at http://www.nist.gov/itl/fipscurrent.cfm

(i) FIPS Publication (FIPS PUB) 140-2, Security Requirements for Cryptographic

Modules

(ii) FIPS PUB 199 – Standards for Security Categorization of Federal Information and

Information Systems

(iii) FIPS PUB 200: Minimum Security Requirements for Federal Information and

Information Systems

(iv) FIPS PUB 201-2, Personal Identity Verification of Federal Employees and Vendors

(e) Department of Defense (DoD)

The following publications are located at http://www.dtic.mil/whs/directives/

(i) DoD Instruction 5200.2, DoD Personnel Security Program (PSP)

(ii) DoD Instruction 8500.1, Cybersecurity https://www.whitehouse.gov/omb/agency/default http://www.nist.gov/publication-portal.cfm http://www.nist.gov/itl/fipscurrent.cfm http://www.dtic.mil/whs/directives/

(iii) DoD Instruction 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling

(iv) DoD Instruction 8510.01, Risk Management Framework Process (RMF)

(v) DoD Instruction 8551.1, Ports, Protocols, and Services Management (PPSM)

(vi) DoD Instruction 8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs

(vii) DoD Instruction 6025.18, Privacy of Individually Identifiable Health Information in

DoD Health Care Programs

(viii) DoD Directive 5400.11, DoD Privacy Program

(f) The following publications are located at https://home.facilities.health.mil/low-voltage-system.

(i) DHA PM Standard Isolation Architecture for Cybersecurity of FRCS

(ii) Security Categorization for Facility-Related Control Systems (FRCS)

(iii) Facility-Related Control Systems (FRCS) Overlay

(iv) Standard Operating Procedure (SOP) for Facility-Related Control Systems (FRCS)

Assessments

(v) Guidance for Facility-Related Control Systems (FRCS) Continuous Monitoring https://home.facilities.health.mil/low-voltage-system

File details come from the government source that posted it. Updated .