Attachment 1(a) - Cyber Security and Privacy Standards and Policies (CSPSP).pdf

PDF 256 KB Posted

Attached to
State and Tribal Technical Assistance and Resources Training and Technical Assistance for TANF Programs Federal contract opportunity
Solicitation number
75ACF124R00019
Issued by
Department of Health and Human Services Administration for Children and Families

About this file

This document is an Attachment 1(a) titled "Cyber Security and Privacy Standards and Policies (CSPSP)" that lists various federal policies, standards, and guidelines related to cybersecurity and privacy that apply to this federal contract opportunity.

The related federal contract opportunity is for "State and Tribal Technical Assistance and Resources Training and Technical Assistance for TANF Programs" solicitation number 75ACF124R00019. The Department of Health and Human Services, Administration for Children and Families is seeking services to provide training and technical assistance to support State and Tribal Temporary Assistance for Needy Family (TANF) programs. The key details, requirements, and objectives of the Statement of Work are provided separately.

View the file

Other files for this federal contract opportunity

Other files attached to State and Tribal Technical Assistance and Resources Training and Technical Assistance for TANF Programs, newest first.
File Type Posted
75ACF124R00019 - Amendment 0001.pdf PDF
Attachment 1 - Statement of Work (SOW) - Attachment 0001.pdf PDF
Attachment 2 - Pricing Sheet - Amendment 0001.xlsx XLSX spreadsheet
Attachment 7 - Questions and Answers.pdf PDF
Attachment 6 - Quality Assurance Surveillance Plan (QASP).pdf PDF
Attachment 4 - Problem Notification Report (PNR).pdf PDF
Attachment 5 - Conflict of Interest Statement-Non-Disclosure.pdf PDF
75ACF124R00019.pdf PDF
Attachment 1 - Statement of Work (SOW).pdf PDF
Attachment 3 - Service Wage Rates Determination No. 2015-4281 Rev. 30.pdf PDF
Attachment 2 - Pricing Sheet.xlsx XLSX spreadsheet
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 1(a) CSPSP STAR

Cyber Security and Privacy Standards and Policies (CSPSP)

1) FIPS PUB 201, Personal Identity Verification (PIV) of Federal Employees and Contractors, as amended.

2) National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

3) FIPS PUB 199, Standards for Security Categorization of Federal Information and

Information Systems

4) FIPS 140-3, Security Requirements for Cryptographic Modules

5) National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Rev. 2, P

6) NIST Interagency/Internal Report (NISTIR) 7622, Notional Supply Chain Risk Management Practices for Federal Information Systems

7) NIST IR 7511 Revision 4, Security Content Automation Protocol (SCAP) Version 1.2 Validation Program Test Requirements, as amended.

8) NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information

9) NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

10) NIST SP 800-145, The NIST Definition of Cloud Computing

11) NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations

12) NIST SP 800-18 Revision 1, Guide for Developing Security Plans for Federal Information Systems

13) NIST SP 800-34 Revision 1, Contingency Planning Guide for Information Technology Systems

14) NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

15) NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System

16) NIST SP 800-53A Revision 1, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans

17) NIST SP 800-53B, Control Baselines for Information Systems and Organizations

Attachment 1(a) CSPSP STAR

18) NIST SP 800-60 Revision 1, Guide for Mapping Types of Information and Information Systems to Security Categories

19) NIST SP 800-61, Computer Security Incident Handling Guide Rev. 2

20) NIST SP 800-63 B, Digital Identity Guidelines: Authentication and Lifecycle Management

21) National Archives and Records Administration (NARA) Bulletin 20013-02 (2013)

22) FedRAMP Standard Contract Clauses

23) Buy American Act, 41 U.S.C. §§ 8301-8305

24) Office of Personnel Management (OPM) Position Sensitivity Designation Automated Tool

25) Public Law 115-390, Strengthening and Enhancing Cyber-capabilities by Utilizing Risk

Exposure (SECURE) Technology Act

26) United States Government Configuration Baseline (USGCB)

27) DHS Supply Chain Risks for Information and Communication Technology

28) Executive Order (EO) 14028 “Improving the Nation’s Cybersecurity (14028)

29) Office of Management and Budget (OMB), Circular A-130, Managing Information as a Strategic Resource

30) Office of Management and Budget (OMB) M-21-31 Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents

31) OMB M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

32) OMB M-04-04, E-Authentication Guidance for Federal Agencies

33) OMB M-06-15, Safeguarding Personally Identifiable Information

34) OMB M-06-19, Safeguarding Against and Responding to the Breach of Personally Identifiable Information

35) OMB M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information

36) OMB M-17-12, Preparing for and Responding to a Breach of PII

37) OMB M-19-26: Update to the TIC Initiative, TIC 3.0

38) OMB M-19-17, Enabling Mission Delivery through Improved Identity, Credential, and Access Management

39) OMB M-07-18, Ensuring New Procurements Include Common Security Configurations

File details come from the government source that posted it. Updated .