Attachment 3 Baseline Security References.pdf
PDF 106 KB Posted
- Attached to
- RD Application Sustainment Operations & Maintenance Support Federal contract opportunity
- Solicitation number
- 12SAD125R0002
About this file
This document is a list of federal security and compliance standards that Rural Development applications and systems must adhere to throughout the entire software development lifecycle (SDLC). The document compiles references to critical cybersecurity and information protection regulations, including key standards from the Office of Management and Budget, Federal Information Security Modernization Act, Executive Order 14028, and multiple National Institute of Standards and Technology (NIST) Special Publications. The referenced documents cover areas such as risk management, security controls, cybersecurity supply chain risk management, protecting controlled unclassified information, microservices API security strategies, and guidelines for protecting personally identifiable information. The document emphasizes that new standards and requirements will be incorporated into the SDLC as they become available, ensuring ongoing compliance with evolving federal security mandates.
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
All Rural Development applications and systems must adhere to Federal security and compliance standards throughout the entire software development lifecycle (SDLC).
This document lists references current requirements, noting that new standards and requirements will be incorporated throughout the SDLC as they become available.
• Office of Management and Budget (OMB) Circular A-130, Managing Information as a Strategic Resource;
• Federal Information Technology Acquisition Reform Act of 2014 (FITARA);
• Federal Information Security Modernization Act of 2014 (FISMA), 44 United States Code
(U.S.C.) § 3551, et seq.;
• Executive Order 14028 Improving the Nation’s Cybersecurity (2021);
• Computer Matching and Privacy Protection Act of 1988, P.L. 100-503, October 1988 (CMA)
• National Institute of Standards and Technology (NIST) Special Publications (SP) 800-37
Revision 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
• National Institute of Standards and Technology (NIST) Special Publications (SP) 800-53 Revision 5, Security and Privacy Controls for Federal Information Systems and Organizations;
• National Institute of Standards and Technology (NIST) Special Publications SP 800-160 Vol. 1 Rev. 1, Engineering Trustworthy Secure Systems | CSRC (nist.gov), Engineering Trustworthy Secure Systems;
• National Institute of Standards and Technology (NIST) Special Publications (SP) 800-161 Revision 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations;
• National Institute of Standards and Technology (NIST) Special Publications (SP) 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations;
• National Institute of Standards and Technology (NIST) Special Publications (SP) 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171;
• National Institute of Standards and Technology (NIST) Special Publications (SP) 800-204 Security Strategies for Microservices APIs; including Parts 204A, 204B and 204C;
• National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity Version 1.1;
• National Institute of Standards and Technology (NIST) Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) SP 800-122
• RD Software Source Code Policy, Jan 1, 2023 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/OMB/circulars/a130/a130revised.pdf https://www.usda.gov/ocio/guidelines-and-compliance-resources/fitara https://www.govinfo.gov/app/details/PLAW-113publ283/ https://www.govinfo.gov/app/details/PLAW-113publ283/ https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity https://www.federalregister.gov/documents/2016/02/17/2016-03164/computer-matching-and-privacy-protection-act-of-1988-report-of-matching-program-corporation-for https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://csrc.nist.gov/pubs/sp/800/160/v1/r1/final https://csrc.nist.gov/pubs/sp/800/160/v1/r1/final https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-172/final https://csrc.nist.gov/publications/detail/sp/800-204/final https://www.nist.gov/cyberframework https://csrc.nist.gov/publications/detail/sp/800-122/final
File details come from the government source that posted it. Updated .