Attachment 1 Security and Privacy Appendix D Security Deliverables.docx

DOCX document 38 KB Posted

Attached to
Live cell imaging system Federal contract opportunity
Solicitation number
FDA-RFQ-CDER-2022-112869
Issued by
Department of Health and Human Services Food and Drug Administration

View the file

Other files for this federal contract opportunity

Other files attached to Live cell imaging system, newest first.
File Type Posted
Attachment 2 Security and Privacy Language.docx DOCX document
FDA-RFQ-CDER-2022-112869-Live cell imaging system.docx DOCX document
Attachment 3 NDA.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

OAGS Note: For submission via ALP, please only submit the table below containing the applicable deliverables. Rows with deliverables that are determined to be not applicable to your specific requirement should be deleted from the table. Consult with your ISSO/Privacy Officer for any questions on applicability.

Appendix D. List of Deliverables The following table details a listing of possible deliverables that may be completed by the contractor (at a minimum) and included in the Schedule of Deliverables]. Please note that deliverables from section 2 apply to sections 3, 4, and 5.

Document Section
Deliverable Title/Description
Due Date
Applicable

(y/n)

2 – Roster
Roster
Within [add specific timeline] of the effective

date of this contract

2 – Contractor Employee Non- Disclosure Agreement (NDA)
Contractor Employee Non- Disclosure Agreement (NDA)
Prior to performing any work on behalf of HHS/FDA

2 – Privacy Threshold Analysis (PTA)/ Privacy Impact Assessment (PIA)

Assist in the completion of a PTA/PIA form
Per timeline as specified by the FDA Privacy POCs. after contract award
2 – Training Records
Copy of training records for all mandatory training
In conjunction with

contract award and annually thereafter or upon request

2 – Rules of Behavior
Signed ROB for all employees
Initiation of contract and at

least annually thereafter x

2 – Incident Response
Incident Report (as incidents or breaches occur)
As soon as possible and without reasonable delay and no later than 1 hour of

discovery

2 – Incident Response
Incident and Breach Response Plan
Upon request from Government
2 – Personnel Security Responsibilities
List of Personnel with defined roles and responsibilities
Within a time directed by the COR that is before an employee begins working on this contract.
x
2 – Personnel Security Responsibilities
Off-boarding documentation, equipment and badge when leaving contract
The last day that work is being performed after the Government’s final acceptance of the work

under this contract, or in the event of a termination of the contract.

x

2 – Background Investigation
Onboarding documentation when beginning contract.
Prior to performing any work on behalf of HHS/FDA
x

2 - Certification of Sanitization of Government and Government Activity- Related Files, Information, and Devices.

Form or deliverables required by FDA.
At contract expiration.
2 – Contract Initiation and Expiration
If the procurement involves a system or cloud service, additional documentation will be

required, such as Disposition/Decommission Plan At contract initiation and expiration, or as directed by COR.

4 – Security Assessment and Authorization (SA&A)
SA&A Package

· SSP

· SCF

· SAR

· POA&M

· Authorization Letter

· ISCP and ISCPT Report

· E-Auth (if applicable)

· PTA/PIA/SPP (if applicable)

· Interconnection/Data Use Agreements (if applicable)

· Authorization Letter

· Configuration Management Plan (if applicable)

· Configuration Baseline documents Due after contract award.

5 – Protection of Information in a Cloud Environment

Contract expiration
Due within [insert contract-specific timeline] after contract award.
5 – SA&A Process for Cloud Services
SA&A Package

· SSP

· SAR

· POA&M

· CMP

· CP and CPT Report

· E-Auth (if applicable)

· PTA/PIA (if applicable)

· Penetration Test Results

· Interconnection/Data Use/Agreements (if applicable)

· Service Level Agreement

· Authorization Letter

· Configuration Management Plan (if applicable)

· Configuration Baseline Due within [insert contract-specific timeline] after contract award.

5 – Reporting and Continuous Monitoring

POA&M updates; Revised security documentation/Agreements
Monthly/as requested by Add Due date (TBD)

5 – Security Alerts, Advisories, and Directives

List of personnel with designated roles and responsibilities
FDA -Specified
5 – Incident Reporting
· Incident reports (as needed)

Incident Response Plan FDA-Specified

6 – Other IT Procurements (Non- Commercial and Open Source Computer Software Procurements)

Computer software, including the source code.
Prior to performing any work on behalf of HHS/FDA

Excerpted from FDA Security and Privacy Language for Information and Information Technology Procurements, May 2020, Version 2.0

File details come from the government source that posted it. Updated .