Attachment 1a ATO and ATC Sheeet.docx
DOCX document 18 KB Posted
- Attached to
- Patient Monitoring System Federal contract opportunity
- Solicitation number
- FA558720Q1029
About this file
This document outlines requirements for a patient monitoring system procurement. Vendors must have current Authorization to Operate and connect certifications for all offered products or agree to complete the certification process. Products must comply with Department of Defense Risk Management Framework and Information Assurance requirements, including software support timelines and security patch installation procedures. The solicitation seeks a turnkey patient monitoring solution for a 48th Medical Group hospital at RAF Lakenheath, England from the Department of the Air Force United States Air Forces in Europe - Air Forces Africa. Vendors must submit documentation demonstrating compliance with the outlined certification and security standards.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FA558720Q1029 Amendment 00003.pdf | ||
| Amendment 00002.pdf | ||
| Attachment I-Statement of Work 21 AUG 2020.pdf | ||
| FA558720Q1029 Amendment 00001.pdf | ||
| Attachment 4 MDERA.pdf | ||
| Attachment 1 Statement of Work.pdf | ||
| Solicitation FA558720Q1029.pdf | ||
| Attachment 3 DHA Cybersecurity-RMF Requirements (3-25-19).pdf | ||
| Attachment 2 Pricing Sheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1a; Authorization to Connect (ATC) and Authorization to Operate (ATO)
1. Vendors shall only quote items which already have an Authorization to Connect (ATC) or shall agree to complete the ATC. Vendors are required to submit copy of Authorization to Operate (ATO) for all offered products with their response and pricing.
2. Vendor agrees to comply with IA approval process and terms necessary to complete RMF IV&V process and achieve a system ATO.
1a. A strength rating shall be assigned if product is undergoing a RMF effort and system is past Step 3 of RMF or has an existing RMF ATO.
3. If no ATOC, Vendor must submit has provided and provide proof of a completed Medical Device Risk Assessment Questionnaire (MDREA) (v4.0) for the offered system.
2a. A strength rating shall be assigned if a Vendor does not have RMF ATO, but an evaluation of the Medical Device Risk Assessment questionnaire shows compliance with PKI, FIPS, or other IA requirements.
4. The system shall have an OS with current commercial support.
3a. A strength rating shall be applied if the OS has at least 72 months of commercial support.
5. All major component software applications (SQL, IIS, .Net, etc.) have current commercial support.
4a. A strength rating shall be applied if all major component software applications (i.e. SQL, IIS, .Net, etc.) have 72 months of commercial support.
6. Vendor provides full software inventory including associated ports, protocols, and support end dates.
7. Vendor has established policies and procedures to distribute and install security updates within a documented timeframe.
6a. A strength rating shall be applied if a Vendor has established policies and procedures to distribute and install security updates. All critical security patches approved/distributed/installed within 30 days.
8. Vendors shall only offer items, which already have an Authorization to Operate (ATO) and Authorization to Connect (ATC), or items for which the Vendor agrees to go through the IA approval process and obtain an RMF ATO/ATC.
9. Any offered system must meet DoD Cybersecurity/Risk Management Framework (RMF) and the attached Service Information Assurance (IA) requirements. Vendors are required to submit a signed copy of the DHA IA contract language agreeing to DHA Cybersecurity/IA Requirements, HIPAA requirements and B2B requirements.
10. Vendors are required to provide a completed Medical Device Equipment and Risk Assessment Questionnaire (v4.0) for the offered system along with their offer.
11. RMF shall be evaluated as part of the System Capability Factor. Vendors must meet all the above RMF minimum requirements. Vendors may be assigned strengths if they exceed any minimum requirement and/or meet any objective. Additionally, weaknesses may be assigned based on the vendor’s responses in the Medical Device Risk Assessment Questionnaire (v1.1). RMF weaknesses may include; but are not limited to; deficiencies in architecture or software versions, other services having cancelled RMF efforts due to vendor non-responses or inability to get an RMF, system having received a DATO from any service, and deficiencies that cannot be mitigated/accepted.
12. Submitting a quote for any requirement under this initiative constitutes full agreement to all DHA IA requirements.
13. System must have an ATO in place to be installed.
14. Failure to agree to the attached DHA IA requirements and to provide a completed Medical Device Risk Assessment Questionnaire shall result in rejection of the vendors quote. Failing to disclose that a system cannot meet IA requirements, failure to meet certification timeframes or failure to receive ATO may result in termination for cause in accordance with FAR 52.212-4(m).
File details come from the government source that posted it. Updated .