Attachment 38 - IT Security Requirements - 2020-04.docx

DOCX document 20 KB Posted

Attached to
Patent Data and Document Management (PDDM) Federal contract opportunity
Solicitation number
1333BJ20R00151004
Issued by
Department of Commerce US Patent and Trademark Office

About this file

This document outlines IT security requirements for the Patent Data and Document Management solicitation from the United States Patent and Trademark Office. The vendor must comply with the Federal Information Security Management Act and the Federal Information Security Modernization Act by following the Risk Management Framework process described in NIST Special Publication 800-37. This includes categorizing the system, selecting and implementing security controls, assessing controls, authorizing the system with CISO and CIO signatures, and ongoing monitoring. If personal information is stored, a Privacy Impact Analysis must also be approved. For cloud services, the vendor must use a FedRAMP approved provider and implement controls according to the service model. Additional policies and handbooks provide further guidance on security and cloud usage.

View the file

Other files for this federal contract opportunity

Other files attached to Patent Data and Document Management (PDDM), newest first.
File Type Posted
1333BJ20R00151004_Amendment 0003_track changes.pdf PDF
Attachment 39 - Transition Plan Framework_updated.docx DOCX document
Attachment 13a - FEPIB 2020-06.doc DOC document
Attachment 26 - DCB 2020-14.docx DOCX document
Attachment 40-Pricing Template_updated.xlsx XLSX spreadsheet
Attachment 08 - Glossary of Terms_updated.docx DOCX document
Attachment 26 - DCB 2020-17.docx DOCX document
Attachment 26 - DCB 2020-16.docx DOCX document
Attachment 13a - FEPIB 2020-04.doc DOC document
PDDM RFP Questions and Responses.pdf PDF
Amendment 0001_1333BJ20R00151004.pdf PDF
Attachment 25b - Consolidated Listing of Official Gazette Notices_2018-01-25.pdf PDF
Attachment 05c - QA of EFS WEb Submissions Error Categories and Historical Volumes.xlsx XLSX spreadsheet
Attachment 16 - PG Pub Processes.pdf PDF
Attachment 39 - Transition Plan Framework.docx DOCX document
Attachment 13a - FEPIB 2020-02.doc DOC document
Attachment 25a - eOG_manual_2020.docx DOCX document
Attachment 14 - Quality Assurance of EFS-Web Submissions20190917.docx DOCX document
Attachment 10b.zip ZIP file
Attachment 13 - Front End Processing (FEP) Manual for Indexing and Scanning.docx DOCX document
Attachment 38b - IT_Security_Handbook.pdf PDF
Attachment 33 - PALM Basics.pptx PPTX presentation
Attachment 05a - Historical Data_Page Counts and Volumes.docx DOCX document
Attachment 41 - Past Performance Questionnaire.docx DOCX document
Attachment 31a - DCB 2020-None.docx DOCX document
Attachment 26.zip ZIP file
Attachment 17b - (jpg) u-bibdat1.jpg JPG image
Attachment 18 - DCB 2020-04.docx DOCX document
Attachment 38a - Cloud Services Usage Policy.pdf PDF
Attachment 13a - FEPIB 2020-03.doc DOC document
Attachment 08 - Glossary of Terms.docx DOCX document
Attachment 17d - (jpg) us-request-v15-2013-01-25.jpg JPG image
Attachment 07 - IFW Document Codes - Document Code Dictionary 2020-04-15.pdf PDF
Attachment 03a - USPTO Computer Specs.xlsx XLSX spreadsheet
Attachment 43 - Surveillance Plan.docx DOCX document
Request for Proposals No. 1333BJ20R00151004.pdf PDF
Attachment 18 - DCB 2020-12.docx DOCX document
Attachment 05b- Weekly Serialized Filings.xls XLS spreadsheet
Attachment 32 - CofC Patent Term Adjustment SOP_Nov 13 2017.pptx PPTX presentation
Attachment 12 - Front End Processes.pdf PDF
Attachment 37 - PreExam Manual with Supplemental Instructions 9-20-2018.pdf PDF
Attachment 30 - Certificate of Correction Process.pdf PDF
Attachment 27 - Grant - Red Book Instructions.docx DOCX document
Attachment 10c - Link to USPTO Website.docx DOCX document
Attachment 17e - (txt) -ExportTOC1.txt TXT text file
Attachment 21 - Post Allowance Processes.pdf PDF
Attachment 35a - PE2E-eDRS-Manual.pdf PDF
Attachment 28 - Grant - Yellow Book Instructions.docx DOCX document
Attachment 23 - DataEntryManual-NON-UTILITY-2020.doc DOC document
Attachment 17c - (jpg) u-suppub8-2012-12-04.jpg JPG image
Show all 50

Patent Data and Document Management (PDDM) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

IT Security Requirements The vendor shall comply with The Federal Information Security Management Act (FISMA 2002) and now Federal Information Security Modernization Act (FISMA) 2014, Public Law 113-283.

In order to comply with FISMA, Risk Management Framework process must be followed that is described in NIST SP 800-37, Rev 2 (always follow the current revision) https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

1. Categorize the system by following FIPS 199 and NIST SP 800-60 https://csrc.nist.gov/publications/detail/fips/199/final https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final

2. Select Security controls (always follow the current revision) https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/final

3. Implement Security Controls using the above (current revision) publication

4. Assess Security Controls in accordance with below publication https://csrc.nist.gov/publications/detail/sp/800-53a/rev-4/final

5. Authorize the system (requires CISO and CIO signatures) NOTE: If a systems stores PII data, Privacy Impact Analysis (PIA) shall be conducted and approved prior to obtaining an authorization to operate, otherwise ATO will not be considered valid. A PIA shall be reviewed and approved by the DOC Chief Privacy Officer 60 days prior to ATO date.

6. Monitor the security controls on an ongoing basis for effectiveness, conducting security impact analysis for changes.

(NOTE: Annual re-authorization is required on all USPTO systems that process USPTO data) If the data is stored in the cloud, it must be a FedRAMP approved cloud service provider. https://marketplace.fedramp.gov/#/products?sort=productName Depending on the Cloud Service Model (i.e. IaaS, PaaS, and SaaS) selected by the Vendor it is the Vendor’s responsibility for implementing Security Controls applicable to the platform and the application.

For additional information, see the below policies and IT security handbook.

Attachment 38a - Cloud Services Usage Policy Attachment 38b - IT Security Handbook All cybersecurity related policies and procedures are located here:

*Link will be provided at contract award.

File details come from the government source that posted it. Updated .