Attach 5 Cyber_Acquisition_Language_2022-02-25.pdf

PDF 299 KB Posted

Attached to
SBA OII Examinations and Related Services Federal contract opportunity
Solicitation number
73351022R0019
Issued by
Small Business Administration

View the file

Other files for this federal contract opportunity

Other files attached to SBA OII Examinations and Related Services, newest first.
File Type Posted
Attach 10 Q and A-OII Examinations and Related Services v18-30-22.xls XLS spreadsheet
73351022R0019 Amendment 1.pdf PDF
B04 - RFQ IDIQ SOW-OII Examination Svcs v1 8-23-22.docx DOCX document
Attach 10 Questions and Answers-OII Examinations and Related Services.xls XLS spreadsheet
Attach 1 SAMPLE-CoverMemo.docx DOCX document
Attach 10 Questions and Answers.xls XLS spreadsheet
B04 - RFQ IDIQ SOW-OII Examination Svcs 8-11-22.docx DOCX document
Attach 6 Non Disclosure.docx DOCX document
Attach 7 Credit Report Release for Employment.docx DOCX document
Attach 3 Pricing Sheet IDIQ 8-3-22.xlsx XLSX spreadsheet
Attach 4 Limitation on Subcontracting Report Template_APR2022.xlsx XLSX spreadsheet
Attach 2 SAMPLE-ExamReport.docx DOCX document
73351022R0019 SF1449 SBIC Exams.pdf PDF
Attach 8 Contractor e-QIP Checklist.docx DOCX document
Attach 9 Past Performance Questionnaire.docx DOCX document
Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

02/25/2022

Instructions to Offerors – Cybersecurity and Supply Chain Risk for IT Acquisitions

The following sentences must be added to the instructions to offerors section for all IT and

IT-related acquisitions:

o The offeror shall, as part of their technical proposal, provide a detailed description of how the proposed solution will adhere to the requirements included in the

“Appendix – Cybersecurity Language for IT Acquisitions” section of this solicitation.

o The offeror shall, as part of their technical proposal, provide a detailed description of how the proposed solution will manage and minimize supply chain risk, addressing the requirements included in the “Appendix – Cybersecurity Language for IT Acquisitions” section of this solicitation.

Appendix – Cybersecurity Language for IT Acquisitions

1. Purpose

The U.S. Small Business Administration (SBA) must provide information security for the information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. The Federal Information Security Modernization Act of 2014 (FISMA) describes Federal agency security responsibilities as including “information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.” This includes services which are either fully or partially provided; including other agency hosted, outsourced, and cloud computing solutions. FISMA has a somewhat broader applicability than prior security law and applies to both information and information systems used by the agency, contractors, and other organizations and sources. Agency information security programs apply to all organizations (sources) which possess or use Federal information – or which operate, use, or have access to Federal information systems (whether automated or manual) – on behalf of a Federal agency, information systems used or operated by an agency or other organization on behalf of an agency.

This document applies to all Agency contracts in which SBA sensitive information is stored, generated, transmitted or exchanged by an SBA contractor, subcontractor or third-party, or on behalf of any of these entities regardless of format. The regulations in this document also pertain to information residing on an SBA or a non-SBA system in order for the contractor, subcontractor or third party to perform their contractual obligations to SBA, standing in lieu of SBA or acting on SBA’s behalf.

The contractor shall leverage all applicable enterprise IT services available from the Office of the Chief Information Officer (OCIO), Information Security Division (ISD). The goal of enterprise services is to maintain enterprise protection and visibility of all agency IT systems. The agency expects a lower cost of ownership, less complexity, lower level of maintenance effort and overall cost savings over the life of the contract. The services include:

• Event log collection and aggregation

• Continuous monitoring

• Incident response

• Patch and configuration management

• Vulnerability scanning

• Penetration testing

• Incident response exercises

• Cybersecurity and privacy risk management

• Cybersecurity and privacy controls assessment

• Cybersecurity and privacy awareness training

All requirements identified or referenced in this document shall be interpreted and implemented implicitly for all system components unless otherwise directed by the SBA.

All requirements identified or referenced in this document shall be implemented at the time of contract award unless otherwise directed by the government.

All requirements identified or referenced in this document shall apply to all contractors and subcontractors that will have access to Controlled Unclassified Information (CUI), collect or maintain CUI on behalf of the agency, operate federal information systems, including contractor information systems operated on behalf of the agency, to collect, process, store, or transmit CUI.

All physical and/or logical access to the IT system or supporting facilities deemed necessary by the SBA shall be granted to the SBA or its designated representative(s) by the Contractor.

2. Policies and Regulations

Contractors entering into an agreement for services to the SBA or its Federal customers shall be contractually subject to all SBA and Federal IT Security standards, policies, and reporting requirements. The contractor shall meet and comply with all SBA IT Security Policies, SBA and NIST guidelines, other Government-wide laws and regulations for protection and security of Information Technology.

Contractors are required to comply with the SBA, FIPS, and NIST, Federal requirements outlined below (or successor documents):

• SBA Cybersecurity and Privacy Policy (SOP 90 47 5), as amended.

• Federal Information Security Modernization Act of 2014, as amended.

• Clinger-Cohen Act of 1996 also known as the “Information Technology Management

Reform Act of 1996,” as amended.

• Privacy Act of 1974 (5 U.S.C. § 552a), as amended.

• Federal Information Technology Acquisition Reform Act (FITARA) of 2014, as amended.

• Chief Financial Officers Act of 1990 (Public Law 101–576), as amended.

• Cyber Supply Chain Management and Transparency Act of 2014.

• Trade Agreements Act (TAA) of 1979 as amended.

• Homeland Security Presidential Directive (HSPD-12), “Policy for a Common

Identification Standard for Federal Employees and Contractors,” as amended.

• Office of Management and Budget (OMB) Circular A-130, “Management of Federal

Information Resources” as amended.

• FIPS PUB 199, “Standards for Security Categorization of Federal Information and

Information Systems,” as amended.

• FIPS PUB 200, “Minimum Security Requirements for Federal Information and

Information Systems,” as amended.

• FIPS PUB 140-2, “Security Requirements for Cryptographic Modules,” as amended.

• NIST Special Publication 800-18, “Guide for Developing Security Plans for Federal Information Systems,” as amended.

• NIST Special Publication 800-30-1, “Guide for Conducting Risk Assessments,” as amended.

• NIST Special Publication 800-34-1, “Contingency Planning Guide for Information Technology Systems,” as amended.

• NIST Special Publication 800-37-2, “Guide for Applying the Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” as amended.

• NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology Systems,” as amended.

• NIST Special Publication 800-53-5, “Security and Privacy Controls for Federal Information Systems and Organizations,” as amended.

• NIST Special Publication 800-53A-5, “Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans,” as amended.

• NIST Special Publication 800-161, “Supply Chain Risk Management Practices for Federal Information Systems and Organizations,” as amended.

• NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” as amended.

3. Security and Privacy Requirements

FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems,” is a mandatory federal standard that defines the minimum security requirements for federal information and information systems in seventeen security-related areas.

Contractor systems supporting SBA must meet the minimum security requirements through the use of the security controls in accordance with NIST Special Publication 800- 53, Revision 4 (as amended and hereafter described as NIST 800-53), and “Recommended Security and Privacy Controls for Federal Information Systems.

Data contained within all SBA computer systems are governed by Agency record disclosure and privacy regulations (13 C.F.R. part 102), IT Security regulations as well as other regulations, statutes and guidance, including the Privacy Act of 1974, as amended (5 U.S.C.

§ 552a). In addition, various Federal requirements obligate SBA to establish controls to limit access to Personally Identifiable Information (PII) and sensitive data, as defined below, to authorized personnel. These include OMB Circular A-130 and OMB Memoranda.

Contractors leveraging cloud solutions must utilize a Cloud Service Provider (CSP) with an existing Federal Risk and Authorization Management Program (FedRAMP) Joint Authorization Board (JAB) Provisional Authorization to Operate (ATO) or Agency ATO at all service models [Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)].

To comply with the Federal standard, the SBA must determine the security category of the information and information system in accordance with FIPS 199, “Standards for Security

Categorization of Federal Information and Information Systems”, and then the contractor shall apply the appropriately tailored set of Low, Moderate, or High impact baseline security controls in NIST 800-53, as determined by the SBA.

The Contractor shall use SBA and NIST guidelines, Defense Information Security Agency (DISA) Security Technical Implementation Guides (STIGs), or industry guidelines in securing their systems.

4. Supply Chain Risk Management

The contractor shall, as part of their technical proposal, describe how Supply Chain Risk Management (SCRM) is incorporated into the acquisition of the underlying technology that composes their solutions. Descriptions shall at a minimum describe how the contractor’s solutions satisfies the following regulatory components:

• The TAA of 1979 as amended.

• The Federal Acquisition Regulation (FAR) part 52.204-23 Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities.

• The Federal Acquisition Regulation (FAR) part 52.204-25 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment.

The contractor’s technical proposal shall describe how SCRM is to be addressed and monitored throughout the lifecycle of the acquisition.

5. Essential Security Controls

All NIST 800-53 controls must be implemented as per the applicable FIPS 199 Low, Moderate, or High baseline. Controls, control enhancements, or parts of controls or enhancement may be implemented jointly between the Contractor and CSP as applicable.

The following table identifies essential security controls from the respective baselines to highlight their importance and to understand the potential implementation costs. The Contractor shall make the proposed system and security architecture of the information system available to the Office of the Chief Information Officer for review and approval before commencement of system build.

Control

ID

Control Title Baseline Implementation Guidance

AC-02 Account Management

L, M, H The contractor shall perform an annual user recertification for all roles implemented within the information system.

AC-17

(03)

Remote Access | Managed Access Control Points

M, H The information system routes privileged authentication traffic to external hosted infrastructures / applications through SBA’s managed network access control points and are subject to the Trusted Internet Connections (TIC) and the U.S. Department of Homeland Security’s (DHS’) Einstein monitoring system.

Control

ID

Control Title Baseline Implementation Guidance

AC-20 Use of External Information Systems

L, M, H Physical access to the contractor’s office areas that contain PII and sensitive data shall be controlled to prevent unauthorized personnel from acquiring access to this data.

The contractor shall not release SBA data outside of its facility, either orally or in written form, without the express written consent of the SBA CO/COR.

AU-02 Audit Events L, M, H Information systems shall implement audit configuration requirements including but not limited to successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. Web applications should log all admin activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes. Web applications should log all admin activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes.

AT-02/

AT-03

Security Awareness Training

L, M, H All contractors with access to SBA’s IT systems and/or PII and sensitive data shall complete the annual Computer Security Awareness Training (CSAT) and role-based training as necessary

CA-07 Continuous Monitoring

L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall integrate with SBA implemented continuous monitoring, Continuous Diagnostics and Monitoring (CDM), and Security Operation Center (SOC) capabilities.

CA-08 Penetration Testing

L, M, H The contractor shall support, providing all physical and logical access necessary to the target system(s), in annual agency penetrations testing efforts.

CM-06 Configuration Settings

L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall configure their systems in agreement with SBA policies and guidelines, DISA STIGs, NIST guidelines, or manufacturer guidelines as appropriate.

CP-07 Alternative Processing Site

M, H FIPS 199 Moderate and High impact systems must implement processing across geographically disparate locations to ensure fault tolerance. Infrastructure as a Service architectures must implement a multi-region strategy.

CP-08 Telecom Services

M, H FIPS 199 Moderate and High impact information systems must implement alternate telecom services to support resumption when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.

Control Title Baseline Implementation Guidance

IA-02

(01)

Identification and Authentication (Organizational Users) | Network Access to Privileged Accounts

L, M, H All information systems shall implement multi-factor authentication for privileged accounts. All information systems must have the built-in capability to accept a Security Assertion markup Language (SAML) assertion from an existing SBA Single Sign On (SSO) capability [e.g., Active Directory Federation Services (ADFS), Azure Active Directory (AAD) Enterprise Applications].

IA-02

(02)

Identification and Authentication (Organizational Users) | Network Access to Non- Privileged Accounts

L, M, H FIPS 199 Moderate and High impact information systems must implement multi-factor authentication for non-privileged accounts. All information systems must have the built-in capability to accept a Security Assertion markup Language (SAML) assertion from an existing SBA Single Sign On (SSO) capability [e.g., Active Directory Federation Services (ADFS), Azure Active Directory (AAD) Enterprise Applications].

IA-02

(12)

Identification and Authentication | Acceptance of PIV Credentials

L, M, H Information systems with an e-authentication assurance level of 3 or above, used by federal employees or contractors must accept federal Personal Identity Verification (PIV) cards and verify them in accordance with guidance in OMB M-11-33.

IA-07 Cryptographic Module Authentication

L, M, H The information system shall implement FIPS 140-2 validated encryption modules for authentication functions. Reference:

http://csrc.nist.gov/groups/STM/cmvp/documents/140- 1/1401vend.htm

IR-04 Incident Handling

L, M, H The Contractor shall cooperate with agency incident response activities, including but not limited to, providing logical and physical access to compute resources and media for investigative, examination, or forensic purposes.

IR-06 Incident Reporting

L, M, H The contractor shall report all suspected security incidents to the SBA Security Operations Center in accordance with U.S. CERT reporting requirements.

MP-04 Media Storage M, H Digital media including magnetic tapes, external/removable hard drives, flash/thumb drives, diskettes, compact disks and digital video disks shall be encrypted using a FIPS 140-2 validated encryption module.

MP-05 Media Transport M, H Digital media including magnetic tapes, Control Title Baseline Implementation Guidance external/removable hard drives, flash/thumb drives and digital video disks shall be encrypted using a FIPS 140-2 validated encryption module during transport outside of controlled areas.

PL-02 System Security Plan

L, M, H The contractor must develop a final System Security Plan (SSP) within thirty (30) calendar days from contract award. The SSP must be updated at least annually. The SSP will be reviewed by the Contracting Officer’s Technical Representative (COR) or designated technical point of contact. The SSP must document administrative, technical, and physical security measures at the contractor’s computer facility to protect PII and sensitive data from unauthorized disclosure, alteration, or misuse;

prevent unauthorized access to the contractor’s computer system; and protect the availability of data and services to SBA. All controls and enhancements must be described in detail, focusing on how each control or enhancement is implemented. All technical controls must be described for all technologies included in the system boundary

PL-08 Information Security Architecture

M, H All information system security architectures must be reviewed and approved by the Office of the Chief Information Officer prior to development or implementation.

PS-03 Personnel Screening

L, M, H [Applies to acquisitions where the contract personnel are provided direct logical or physical access to agency data, compute resources, or offices.]

Pursuant to Federal Acquisition Regulation (FAR) clause 52.204-9, incorporated into this solicitation and the resulting contract, each contractor and subcontractor must comply with Agency Personal Identity Verification (PIV) procedures. These procedures must be followed when the contractor and or subcontractor will have unescorted physical access to a federally controlled facility, and/or access to a federally controlled information system (including, but not limited to computer systems, networks, or information technology infrastructure).

PS-04 Personnel Termination

L, M, H [Applies to acquisitions where the contract personnel are provided direct logical or physical access to agency data, compute resources, or offices.]

The Contractor shall provide weekly in electronic format to the CO and COR a current roster of individuals with direct logical or physical access to agency data, compute resources, or offices. Roster shall indicate any and all changes (additions and departures).

Control Title Baseline Implementation Guidance

RA-05 Vulnerability Scanning

L, M, H All information system must complete weekly privileged authenticated operating system, web, and database vulnerability and configuration scanning and provide results to the SBA on a weekly basis.

SA-04 /

SA-04

(01)

Acquisition Process | Functional Properties of Security Controls

L, M, H All external service providers (contractor hosted, contractor managed, proprietary, IaaS, PaaS, SaaS, resellers, etc.) shall include as part of their technical proposal attestations of Service Level Agreements (SLAs) for the following key areas:

o Response to Cybersecurity incidents o Availability of service o Data retention o Encryption of data at rest o Telecommunication service redundancy o Logical and Physical Data Access Limited to

Continental United States

SLA commitments and/or attestations must either be included in the offeror’s technical proposal or be provided by reference to publicly available Internet resources.

SA-22 Unsupported Components

L, M, H All major components of the contractor’s solution must be supported via enforceable manufacturer or other contractual agreement.

SC-08 /

SC-08

(01)

Transmission Confidentiality and Integration

M, H Implemented encryption algorithms and cryptographic modules shall be FIPS-approved and FIPS 140-2 validated, respectively.

o Digital signature encryption algorithms -

Reference: (http://csrc.nist.gov/groups/ST/toolkit/d igital_signatures.html#Approved o Block cypher encryption algorithms - Reference:

http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.

html#Approved o Secure hashing algorithms – Reference:

http://csrc.nist.gov/groups/ST/toolkit/secure_hashin g.html#Approved

Internet-facing systems shall enforce HTTPS and implement HTTP Strict Transport Security (HSTS).

SC-13 Cryptographic Protection | FIPS Validated Cryptography

L, M, H Implemented encryption algorithms and cryptographic modules shall be FIPS-approved and FIPS 140-2 validated, respectively.

o Digital signature encryption algorithms -

Reference: http://csrc.nist.gov/groups/ST/toolkit/di gital_signatures.html#Approved o Block cypher encryption algorithms - Reference:

http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.

html#Approved http://csrc.nist.gov/groups/ST/toolkit/digital_signatures.html#Approved http://csrc.nist.gov/groups/ST/toolkit/digital_signatures.html#Approved http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.html%23Approved http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.html%23Approved http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html%23Approved http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html%23Approved http://csrc.nist.gov/groups/ST/toolkit/digital_signatures.html#Approved http://csrc.nist.gov/groups/ST/toolkit/digital_signatures.html#Approved http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.html%23Approved http://csrc.nist.gov/groups/ST/toolkit/block_ciphers.html%23Approved

Control Title Baseline Implementation Guidance o Secure hashing algorithms – Reference:

http://csrc.nist.gov/groups/ST/toolkit/secure_hashin g.html#Approved

SC-22 Architecture and Provisioning for Name / Address Resolution Service

L, M, H Information systems shall be Domain Name System Security Extensions (DNSSEC) compliant as per OMB Memorandum, M-08-23, which requires all Federal Government departments and agencies that have registered and are operating second level .gov to be

DNSSEC.

SC-28 /

SC-28

(01)

Protection of Information at Rest | Cryptographic Protection

Required for Systems with PII Only

System bearing PII must implement protect information at rest. At a minimum, fields bearing PII data must be encrypted with field level encryption. Encryption algorithms shall be FIPS-approved; implemented encryption modules shall be FIPS 140-2 validated

SI-02 Flaw Remediation

L, M, H All systems must establish monthly flaw remediation (patch) processes. High and Critical risk findings must be remediated prior to go-live. Post go-live, all critical [CVSS Base Score = 10] vulnerabilities identified must be mitigated within 15 calendar days, high [CVSS Base Score ≥ 7.0] vulnerabilities identified must be mitigated within 30 calendar days and all other [CVSS Base Score < 7.0 vulnerabilities mitigated within 90 calendar days.

SI-03 Malicious Code Protection

L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall implement anti-malware capabilities for all assets.

SI-04 Information System Monitoring

L, M, H Information systems, including vendor owned / operated systems on behalf of the SBA, shall integrate with SBA implemented continuous monitoring, Continuous Diagnostics and Monitoring (CDM), and Security Operation Center (SOC) capabilities.

SI-10 Information Input Validation

M, H All systems accepting input from end users must validate the input in accordance with the OWASP Top 10 Web Application Security Vulnerabilities.

SI-12 Information Handling and Retention

L, M, H All external service providers (contractor hosted, contractor managed, proprietary, IaaS, PaaS, SaaS, etc.)

must describe, as part of their technical proposal, the means for ensuring that agency data stored and processed within the offeror’s solution is portable, interoperable, and owned by the agency.

Specifically, the offeror shall describe in detail the mechanism for exporting all agency data and meta-data into a Comma Separated Values (CSV), eXtensible Markup Language (XML), or equivalent structured format. This http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html%23Approved http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html%23Approved

Control Title Baseline Implementation Guidance mechanism shall be available to agency administrators as a routine practice, shall not have proprietary software nor Application Programming Interface (API) dependencies, and shall result in no additional cost to the agency, however often the mechanism is used.

SR-06 Supplier Reviews

M, H The contractor shall conduct due diligence reviews for suppliers of major IT components (hardware, software, or other) prior to introduction into their proposed solution.

SR-08 Notification Agreements

L, M, H The contractor shall notify the SBA CO and COR withing twenty-four (24) hours of all suspected and confirmed supply chain compromises. Determination of whether the compromise is of relevant to the services or solutions delivered to the SBA shall rest with the SBA.

SR-11 Component Authenticity

L, M, H The contractor shall propose and execute techniques to prevent the introduction of counterfeit or otherwise inauthentic components (hardware, software, or other) into their proposed solution. These techniques shall be conducted on a continual basis.

6. Assessment and Authorization (A&A) Activities

The implementation of a new Federal Government IT system requires a formal approval process known as Assessment and Authorization (A&A). NIST SP 800-37-2 provides guidelines for performing the A&A process. The Contractor system/application must have a valid assessment and authorization, known as an Authority to Operate (ATO) (signed by the Federal government) before going into operation and processing SBA information. The failure to obtain and maintain a valid ATO may result in the termination of the contract.

The system must have a new A&A conducted (signed by the Federal government) at least every three (3) years or at the discretion of the Authorizing Official when there is a significant change to the system’s security posture. All NIST 800-53-4 controls must be tested/assessed every three (3) years or as defined by SBA policy.

Assessing the System

a. The Contractor shall comply with Assessment and Authorization (A&A) requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement. The Level of Effort for the A&A is based on the System’s NIST Federal Information Processing Standard (FIPS) Publication 199 categorization. The contractor shall create, maintain and update the following A&A documentation:

• System Security Plan (SSP) completed in agreement with NIST SP 800-18-1 (or successor document), “Guide for Developing Security Plans for Federal Information Systems”. The SSP shall include as appendices required policies and procedures across 18 control families mandated per FIPS 200, Rules of Behavior, and Interconnection Agreements (in agreement with NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology Systems”).

• Contingency Plan and test Report completed in agreement with NIST Special Publication 800-34.

• Privacy Threshold Analysis/Privacy Impact Assessment (PTA/PIA)

• Configuration Management Plan (CMP).

b. Information systems must be assessed and authorized every three (3) years, whenever there is a significant change to the system’s security posture and updated annually in accordance with NIST Special Publication 800-37-2.

c. At the Moderate impact level and higher, the contractor or Government (as determined in the contract) will be responsible for providing an independent Security Assessment/Risk Assessment in accordance with SBA Policy.

d. If the Government is responsible for providing a Security Assessment/Risk Assessment, the Contractor shall allow SBA employees (or SBA-designated third-party contractors) to conduct A&A activities to include control reviews in accordance with NIST 800-53/NIST 800-53A. Review activities include but are not limited to operating system vulnerability scanning, web application scanning, and database scanning of applicable systems that support the processing, transportation, storage, or security of SBA information. This includes the general support system infrastructure.

e. Identified gaps between required 800-53 controls and the contractor’s implementation as documented in the Security Assessment/Risk Assessment report shall be tracked for mitigation as a Plan of Action and Milestones (POA&M) item within SBA’s Cyber Security Assessment Management (CSAM) implementation.

Depending on the severity of the gaps, the Government may require them to be remediated before an Authorization to Operate is issued.

f. The Contractor is responsible for mitigating all security risks found during A&A and continuous monitoring activities. All critical-risk vulnerabilities must be mitigated within 15 days, high-risk vulnerabilities must be mitigated within 30 days, and all moderate risk vulnerabilities must be mitigated within 90 days from the date vulnerabilities are formally identified. The Government will determine the risk rating of vulnerabilities.

Authorization of the System

a. Upon receipt of the Security Authorization Package, the Authorizing Official (AO), in coordination with the SBA Office of the CIO, System Owner (SO), Information System Security Manager (ISSM), and Information System Security Officer (ISSO) will render an authorization decision to:

• Authorize system operation w/out any restrictions or limitations on its operation;

• Authorize system operation w/ restriction or limitation on its operation, or;

• Not authorize for operation.

b. The Contractor shall provide access to the Federal Government, or their designee acting as their agent, when requested, in order to verify compliance with the requirements for an Information Technology security program, and in response to security incidents. At its option, the Government may choose to conduct on site surveys. The Contractor shall make appropriate personnel available for interviews and documentation during this review. If documentation is considered proprietary or sensitive, these documents may be reviewed on-site under the hosting Contractor’s supervision.

7. Continuous Monitoring Deliverables and Schedule

Maintenance of the security authorization to operate will be through continuous monitoring of security controls of the contractor’s system and its environment of operation to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to SBA per the schedules below. The submitted deliverables (or lack thereof) provide a current understanding of the security state and risk posture of the information systems.

They allow SBA AOs to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur. The contractor is required to provide the following deliverables to the CO/COR during the performance of the contract.

Deliverable Control ID Frequency Vulnerability Scanning RA-05 Weekly System Security Plan Update PL-02 Annually Contingency Plan Update CP-02 Annually Contingency Plan Test Report CP-07 Annually User Certification AC-02 Annually Separation of Duties Matrix AC-05 Annually Baseline Configuration Settings CM-06 Annually Configuration Management Plan CM-09 Annually Incident Response Test Report IR-03 Annually Automated API Feeds/Log Data to SBA SIEM SI-04 Continuous Results of Review of Physical Access Records PE-08 Annually Contractor Personnel Roster PS-04 Weekly Personnel Screening and Security PS-07 Continuous

File details come from the government source that posted it. Updated .