Attachment 38 - IT Security Requirements - 2020-04.docx
DOCX document 20 KB Posted
- Attached to
- Patent Data and Document Management (PDDM) Federal contract opportunity
- Solicitation number
- 1333BJ20R00151004
About this file
This document outlines IT security requirements for the Patent Data and Document Management solicitation from the United States Patent and Trademark Office. The vendor must comply with the Federal Information Security Management Act and the Federal Information Security Modernization Act by following the Risk Management Framework process described in NIST Special Publication 800-37. This includes categorizing the system, selecting and implementing security controls, assessing controls, authorizing the system with CISO and CIO signatures, and ongoing monitoring. If personal information is stored, a Privacy Impact Analysis must also be approved. For cloud services, the vendor must use a FedRAMP approved provider and implement controls according to the service model. Additional policies and handbooks provide further guidance on security and cloud usage.
View the file
Other files for this federal contract opportunity
Show all 50
Patent Data and Document Management (PDDM) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
IT Security Requirements The vendor shall comply with The Federal Information Security Management Act (FISMA 2002) and now Federal Information Security Modernization Act (FISMA) 2014, Public Law 113-283.
In order to comply with FISMA, Risk Management Framework process must be followed that is described in NIST SP 800-37, Rev 2 (always follow the current revision) https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
1. Categorize the system by following FIPS 199 and NIST SP 800-60 https://csrc.nist.gov/publications/detail/fips/199/final https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final
2. Select Security controls (always follow the current revision) https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/final
3. Implement Security Controls using the above (current revision) publication
4. Assess Security Controls in accordance with below publication https://csrc.nist.gov/publications/detail/sp/800-53a/rev-4/final
5. Authorize the system (requires CISO and CIO signatures) NOTE: If a systems stores PII data, Privacy Impact Analysis (PIA) shall be conducted and approved prior to obtaining an authorization to operate, otherwise ATO will not be considered valid. A PIA shall be reviewed and approved by the DOC Chief Privacy Officer 60 days prior to ATO date.
6. Monitor the security controls on an ongoing basis for effectiveness, conducting security impact analysis for changes.
(NOTE: Annual re-authorization is required on all USPTO systems that process USPTO data) If the data is stored in the cloud, it must be a FedRAMP approved cloud service provider. https://marketplace.fedramp.gov/#/products?sort=productName Depending on the Cloud Service Model (i.e. IaaS, PaaS, and SaaS) selected by the Vendor it is the Vendor’s responsibility for implementing Security Controls applicable to the platform and the application.
For additional information, see the below policies and IT security handbook.
Attachment 38a - Cloud Services Usage Policy Attachment 38b - IT Security Handbook All cybersecurity related policies and procedures are located here:
*Link will be provided at contract award.
File details come from the government source that posted it. Updated .