Attachment 38a - Cloud Services Usage Policy.pdf

PDF 249 KB Posted

Attached to
Patent Data and Document Management (PDDM) Federal contract opportunity
Solicitation number
1333BJ20R00151004
Issued by
Department of Commerce US Patent and Trademark Office

About this file

This document contains a cloud services usage policy issued by the United States Patent and Trademark Office (USPTO). The policy establishes guidelines for the selection and use of cloud-based information systems by the USPTO to comply with relevant laws and standards. It requires that cloud computing services have a Federal Risk and Authorization Management Program authorization, undergo a risk assessment, and receive written approval from the USPTO Chief Information Officer and Authorizing Official. The policy provides definitions and guidance around issues including security, privacy, records management, and exceptions.

The related federal contract opportunity is a solicitation from the USPTO seeking contractor support to manage the entire life cycle of patent application processing from initial filing to final disposition. Interested offerors are directed to thoroughly review the request for proposals and statement of work, which include requirements, terms, and references.

View the file

Other files for this federal contract opportunity

Other files attached to Patent Data and Document Management (PDDM), newest first.
File Type Posted
1333BJ20R00151004_Amendment 0003_track changes.pdf PDF
PDDM RFP Questions and Responses Round Two_8.12.pdf PDF
Attachment 40-Pricing Template_updated.xlsx XLSX spreadsheet
Attachment 08 - Glossary of Terms_updated.docx DOCX document
Attachment 26 - DCB 2020-17.docx DOCX document
Attachment 26 - DCB 2020-16.docx DOCX document
Attachment 13a - FEPIB 2020-04.doc DOC document
PDDM RFP Questions and Responses.pdf PDF
Attachment 13a - FEPIB 2020-05.doc DOC document
Attachment 26 - DCB 2020-15.docx DOCX document
Attachment 05a - Historical Data_Page Counts and Volumes_updated.docx DOCX document
Attachment 3d - Current Compatible Printers.docx DOCX document
Attachment 26.zip ZIP file
Attachment 17b - (jpg) u-bibdat1.jpg JPG image
Attachment 18 - DCB 2020-04.docx DOCX document
Attachment 38 - IT Security Requirements - 2020-04.docx DOCX document
Attachment 13a - FEPIB 2020-03.doc DOC document
Attachment 08 - Glossary of Terms.docx DOCX document
Attachment 17d - (jpg) us-request-v15-2013-01-25.jpg JPG image
Attachment 07 - IFW Document Codes - Document Code Dictionary 2020-04-15.pdf PDF
Attachment 03a - USPTO Computer Specs.xlsx XLSX spreadsheet
Attachment 43 - Surveillance Plan.docx DOCX document
Request for Proposals No. 1333BJ20R00151004.pdf PDF
Attachment 18 - DCB 2020-12.docx DOCX document
Attachment 05b- Weekly Serialized Filings.xls XLS spreadsheet
Attachment 32 - CofC Patent Term Adjustment SOP_Nov 13 2017.pptx PPTX presentation
Attachment 12 - Front End Processes.pdf PDF
Attachment 37 - PreExam Manual with Supplemental Instructions 9-20-2018.pdf PDF
Attachment 30 - Certificate of Correction Process.pdf PDF
Attachment 27 - Grant - Red Book Instructions.docx DOCX document
Attachment 10c - Link to USPTO Website.docx DOCX document
Attachment 17e - (txt) -ExportTOC1.txt TXT text file
Attachment 21 - Post Allowance Processes.pdf PDF
Attachment 35a - PE2E-eDRS-Manual.pdf PDF
Attachment 28 - Grant - Yellow Book Instructions.docx DOCX document
Attachment 23 - DataEntryManual-NON-UTILITY-2020.doc DOC document
Attachment 17c - (jpg) u-suppub8-2012-12-04.jpg JPG image
Attachment 42 - Small Business Subcontracting Plan Template.docx DOCX document
Attachment 10a - Sample Issued Patents and Cooperative Patent Classification.docx DOCX document
Attachment 09 - Link to Patent Classifications and Definitions.docx DOCX document
Attachment 29a - Patent Official Gazette Notices.docx DOCX document
Attachment 36 - PE2E-OC OPESS Manual.pdf PDF
Attachment 31 - CofC_manual_PaDaCap_2020.docx DOCX document
Attachment 34 - PALM-Correspondence Processing.pptx PPTX presentation
Attachment 00 - Section J Technical References Index and Crosswalk.docx DOCX document
Attachment 01b - OCIO Personal Identity Verification (PIV) Card Authentication Policy OCIO-POL-49.pdf PDF
Attachment 02 - TIC Ref Arch v2.2 2017.pdf PDF
Attachment 04 - Crosswalk of CLINs to SOW and Historical Volumes.xlsx XLSX spreadsheet
Attachment 03c - Windows 10 LTSB Baseline for CEP - CEDP COR Systems Baseline.docx DOCX document
Attachment 03b - USPTO Enterprise Workstation Naming Convention.docx DOCX document
Show all 50

Patent Data and Document Management (PDDM) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

OFFICE OF THE CHIEF INFORMATION OFFICER

Cloud Services Usage Policy Version 1.0 1

CLOUD SERVICES USAGE POLICY

OCIO-POL-63

Date of Issuance: February 14, 2017

Effective Date: February 14, 2017

Version: 1.0

TABLE OF CONTENTS

Section

I. PURPOSE

II. AUTHORITY

III. SCOPE

IV. DEFINITIONS

V. POLICY

VI. GUIDANCE

VII. EXCEPTIONS

VIII. REFERENCES

IX. EFFECT ON OTHER POLICIES

I. PURPOSE

This policy establishes guidelines for the selection and use of cloud-based information systems by the

United States Patent and Trademark Office (USPTO). This policy is intended to supplement cloud usage policies established by the Office of Management and Budget (OMB), the Department of Commerce

(DOC), and other federal agencies.

II. AUTHORITY

This policy is issued pursuant to:

Federal Information Security Management Act of 2002 (FISMA)

Federal Information Security Modernization Act of 2014

Federal Cloud Computing Strategy

National Institute of Standards & Technology (NIST) SP 800-145

National Institute of Standards & Technology SP 800-53 Rev 4

U.S. Department of Commerce Cloud Computing Policy

U.S. Department of Commerce CITR-024

Cloud Services Usage Policy

Cloud Services Usage Policy Version 1.0 2

U.S. Patent and Trademark Office IT Security Handbook

III. SCOPE

This policy applies to any USPTO acquisition of cloud computing services. The product owner and/or project manager must coordinate planning with the OCIO early in the planning process to avoid unnecessary problems later in the planning and acquisition lifecycle.

This policy pertains to the acquisition of services from a cloud service provider outside of the US Patent and Trademark Office. Internal cloud computing services are already covered by existing requirements.

This policy also applies to information systems owned or operated by contractors on behalf of the

USPTO.

IV. DEFINITIONS

Cloud Computing: Cloud Computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. Cloud Computing services may be offered as an Infrastructure-as-a-Service, Platform-as-a-Service, or Software-as-a-Service.

Federal Risk Assessment and Management Program (FedRAMP): A government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

Joint Authorization Board (JAB): The primary governance and decision-making body for the FedRAMP program. The JAB reviews and provides joint provisional security authorizations of cloud solutions using a standardized baseline approach. Chief Information Officers from the Department of Defense, the

Department of Homeland Security, and the General Services Administration serve on the Joint

Authorization Board (JAB).

Security Assessment and Authorization: Security control assessments provide a line of defense in knowing the strengths and weaknesses of an organization’s information system. Security controls assessment determines whether security controls in an information system are operating as intended.

Security authorization is the official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations and assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.

Infrastructure as a Service (IaaS): The capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control of select networking components.

Platform as a Service (PaaS): The capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure

Cloud Services Usage Policy Version 1.0 3 including network, servers, operating systems, or storage, but has control over the deployed applications and possibly application hosting environment configurations.

Software as a Service (SaaS): The capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure. The applications are accessible from various client devices through a thin client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.

System Owner: An individual with day-to-day management and operational control over the system and direct oversight of the system/network administrators and operations staff. Although the Federal

Government has ultimate ownership of all USPTO data, systems and equipment, “owner” is the term commonly used by the National Institute of Standards and Technology (NIST) to refer to individuals with specific systems oversight responsibilities.

Authorizing Official: Official with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to agency operations (including mission, functions, image, or reputation), agency assets, or individuals.

Risk Acceptance Memorandum: A memorandum that documents known security risks which impacts the confidentiality, integrity, and availability of the information system. In addition to documenting the risk, the memorandum details any business justification to support the acceptance of risk in addition to any compensating security controls in place for risk mitigation. This memorandum is acknowledged and signed by the System Owner and Authorization Official.

Confidentiality: The property, that information is not made available or disclosed to unauthorized individuals, entities, or processes.

Integrity: Maintaining and assuring the accuracy and completeness of data over its entire life-cycle.

Availability: Ensuring that authorized parties are able to access the information or system when needed.

V. POLICY

Use of Cloud Computing services must be formally authorized in accordance with the NIST Risk

Management Framework and the USPTO assessment and authorization processes. Specifically:

Use of Cloud Computing services must comply with all current laws, IT security, and risk management policies.

Use of Cloud Computing services must comply with all privacy laws and regulations, and appropriate language must be included in the contract vehicle defining the Cloud Computing source responsibilities for maintaining privacy requirements.

Cloud Computing services must have an existing Agency or JAB Federal Risk and Authorization

Management Program (FedRAMP) authorization to be considered for use at USPTO. However, FedRAMP authorization alone is not sufficient to meet the requirement of authorization for

USPTO use of a particular service for a particular purpose. An appropriate Authorizing Official, sufficiently familiar with the context of the use of the service (including the mission requirements and associated Federal Information Processing Standard (FIPS) 199 impact level), and adequately

Cloud Services Usage Policy Version 1.0 4 informed of the associated risks through a risk assessment, must document an acceptance of risk and formal authorization of the use of the Cloud Computing service.

All use of Cloud Computing services must be approved in writing by the USPTO CIO and, when applicable, a designated Co-Authorizing Official. The Authorizing Official(s) will certify that security, privacy, and other IT management requirements have been adequately addressed prior to approving use of

Cloud Computing services.

The Cloud Computing service must meet all criteria documented in the DOC-CITR-024, “FedRAMP Applicability” policy before the Authorizing Official(s) provide written approval.

The Cloud Computing service may not be put into production use until written approval has been provided by the Authorizing Official(s).

The product owner and/or project manager must retain the CIO’s approval along with other investment documentation.

VI. GUIDANCE

In accordance with the DOC Cloud Computing Policy, the following issues should be considered carefully before adopting a Cloud Computing solution. The list below features some of the more important issues to consider, and to address in contract language, when appropriate:

Identify and consider appropriate existing contracts and Cloud Computing solutions already in use at the Department of Commerce or USPTO before acquiring new services.

When acquiring new services, consider how services can be architected and agreements written in a way that would enable broader use/adoption of the service across the rest of the organization.

IT Security:

o Match IT security requirements (including FIPS 199 impact level) and the security capabilities of the Cloud Computing implementation to those of the mission/business needs being supported.

o Weigh the security threats and opportunities that are present for public, private, and community Clouds.

o Consider how issues of logging, incident reporting, response, forensics, and other security-related functions should be addressed with respect to the Cloud Computing service provider.

o Consider how disaster recovery and continuity of operations planning will be addressed.

Privacy Impact:

o If Personally Identifiable Information (PII) or other sensitive information is involved, document how it will be protected and who is allowed access to it.

o If the Cloud Computing source is keeping user usage statistics, consider the privacy implications involved and define appropriate safeguards to assure user privacy is maintained. This would include session logs and security access logs, among others.

o Define how all relevant provisions of the Privacy Act will be enforced, and identify responsible parties.

Records Management:

o Identify all systems of records to be hosted in the cloud.

Cloud Services Usage Policy Version 1.0 5 o Identify the schedules for all records and include the information on retention as part of the agreement with the vendor.

o Specify the retention time for all system backups.

o Consider how records management and electronic discovery will be managed in the cloud environment.

Consider implications of using a service model that is different from the traditional use of

Government-owned and -operated infrastructure.

Identify which issues should be explicitly documented in service level agreements.

Consider issues of interoperability with existing systems.

Consider issues of data ownership and portability. How would you migrate from a given Cloud

Computing infrastructure to another one at some point in the future?

Examine the need for additional training for Departmental staff.

Focus on the requirement driving the need, not the technology used to implement it.

Determine how mature the industry offerings are for the implementation under consideration.

VII. EXCEPTIONS

Exceptions to this policy shall be determined on a case-by-case basis using the process as defined in the

USPTO IT Security Handbook and the IT Policy on Security Risk Acceptance (OCIO-POL-35). In some cases, a Risk Acceptance Memorandum may need to be issued to accept any residual security risk in order to operate the information system. Some Cloud Computing services may have security assessment and risk reports available, but not yet have FedRAMP authorization. Such services may be considered for conditional adoption following a complete risk assessment by USPTO.

VIII. REFERENCES

E-Government Act (Public Law 107-347), Title III - Federal Information Security

Management Act (FISMA), December 2002.

FIPS Publication 199, Standards for Security Categorization of Federal Information and

Information Systems, February 2004.

FIPS Publication 200, Minimum Security Requirements for Federal Information and

Information Systems, March 2006.

Office of Management and Budget (OMB) Circular A-130, Management of Federal

Information Resources, Appendix III, Revised November 2000.

OMB Memorandum M-03-22 Guidance for implementing the Privacy Provisions of the E-

Government Act of 2002.

OMB M-06-15, Safeguarding Personally Identifiable Information, May 2006.

OMB M-06-16, Protection of Sensitive Agency Information, June 2006.

OMB M-06-19, Reporting Incidents Involving Personally Identifiable Information and

Incorporating the Cost for Security in Agency Information Technology Investments, July 2006.

OMB M-07-16, Safeguarding Against and Responding to the Breach of Personally

Identifiable Information, May 2007.

Cloud Services Usage Policy Version 1.0 6

The Privacy Act of 1974, 5 U.S.C. §552a.

Federal Cloud Computing Strategy, February 8, 2011.

U.S. Department of Commerce, IT Security Program Policy, September 2014.

U.S. Department of Commerce, CITR-024 FedRAMP Applicability, March 29, 2016.

U.S. Department of Commerce, Cloud Computing Policy.

U.S. Patent and Trademark Office, Comprehensive Records Schedule.

U.S. Patent and Trademark Office, IT Policy on Security Risk Acceptance.

U.S. Patent and Trademark Office, IT Security Handbook.

U.S. Patent and Trademark Office, Rules of the Road.

IX. EFFECT ON OTHER POLICIES

This policy does not conflict with any existing OCIO or USPTO policies.

ISSUED BY:

OFFICE OF PRIMARY INTEREST: Office of Organizational Policy and Governance

File details come from the government source that posted it. Updated .