Attachment 1 Security and Privacy Appendix D Security Deliverables.docx
DOCX document 38 KB Posted
- Attached to
- Live cell imaging system Federal contract opportunity
- Solicitation number
- FDA-RFQ-CDER-2022-112869
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 Security and Privacy Language.docx | DOCX document | |
| FDA-RFQ-CDER-2022-112869-Live cell imaging system.docx | DOCX document | |
| Attachment 3 NDA.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OAGS Note: For submission via ALP, please only submit the table below containing the applicable deliverables. Rows with deliverables that are determined to be not applicable to your specific requirement should be deleted from the table. Consult with your ISSO/Privacy Officer for any questions on applicability.
Appendix D. List of Deliverables The following table details a listing of possible deliverables that may be completed by the contractor (at a minimum) and included in the Schedule of Deliverables]. Please note that deliverables from section 2 apply to sections 3, 4, and 5.
| Document Section |
| Deliverable Title/Description |
| Due Date |
| Applicable |
(y/n)
| 2 – Roster |
| Roster |
| Within [add specific timeline] of the effective |
date of this contract
| 2 – Contractor Employee Non- Disclosure Agreement (NDA) |
| Contractor Employee Non- Disclosure Agreement (NDA) |
| Prior to performing any work on behalf of HHS/FDA |
2 – Privacy Threshold Analysis (PTA)/ Privacy Impact Assessment (PIA)
| Assist in the completion of a PTA/PIA form |
| Per timeline as specified by the FDA Privacy POCs. after contract award |
| 2 – Training Records |
| Copy of training records for all mandatory training |
| In conjunction with |
contract award and annually thereafter or upon request
| 2 – Rules of Behavior |
| Signed ROB for all employees |
| Initiation of contract and at |
least annually thereafter x
| 2 – Incident Response |
| Incident Report (as incidents or breaches occur) |
| As soon as possible and without reasonable delay and no later than 1 hour of |
discovery
| 2 – Incident Response |
| Incident and Breach Response Plan |
| Upon request from Government |
| 2 – Personnel Security Responsibilities |
| List of Personnel with defined roles and responsibilities |
| Within a time directed by the COR that is before an employee begins working on this contract. |
| x |
| 2 – Personnel Security Responsibilities |
| Off-boarding documentation, equipment and badge when leaving contract |
| The last day that work is being performed after the Government’s final acceptance of the work |
under this contract, or in the event of a termination of the contract.
x
| 2 – Background Investigation |
| Onboarding documentation when beginning contract. |
| Prior to performing any work on behalf of HHS/FDA |
| x |
2 - Certification of Sanitization of Government and Government Activity- Related Files, Information, and Devices.
| Form or deliverables required by FDA. |
| At contract expiration. |
| 2 – Contract Initiation and Expiration |
| If the procurement involves a system or cloud service, additional documentation will be |
required, such as Disposition/Decommission Plan At contract initiation and expiration, or as directed by COR.
| 4 – Security Assessment and Authorization (SA&A) |
| SA&A Package |
· SSP
· SCF
· SAR
· POA&M
· Authorization Letter
· ISCP and ISCPT Report
· E-Auth (if applicable)
· PTA/PIA/SPP (if applicable)
· Interconnection/Data Use Agreements (if applicable)
· Authorization Letter
· Configuration Management Plan (if applicable)
· Configuration Baseline documents Due after contract award.
5 – Protection of Information in a Cloud Environment
| Contract expiration |
| Due within [insert contract-specific timeline] after contract award. |
| 5 – SA&A Process for Cloud Services |
| SA&A Package |
· SSP
· SAR
· POA&M
· CMP
· CP and CPT Report
· E-Auth (if applicable)
· PTA/PIA (if applicable)
· Penetration Test Results
· Interconnection/Data Use/Agreements (if applicable)
· Service Level Agreement
· Authorization Letter
· Configuration Management Plan (if applicable)
· Configuration Baseline Due within [insert contract-specific timeline] after contract award.
5 – Reporting and Continuous Monitoring
| POA&M updates; Revised security documentation/Agreements |
| Monthly/as requested by Add Due date (TBD) |
5 – Security Alerts, Advisories, and Directives
| List of personnel with designated roles and responsibilities |
| FDA -Specified |
| 5 – Incident Reporting |
| · Incident reports (as needed) |
Incident Response Plan FDA-Specified
6 – Other IT Procurements (Non- Commercial and Open Source Computer Software Procurements)
| Computer software, including the source code. |
| Prior to performing any work on behalf of HHS/FDA |
Excerpted from FDA Security and Privacy Language for Information and Information Technology Procurements, May 2020, Version 2.0
File details come from the government source that posted it. Updated .