Attachment A - Physcial Security Systems.pdf
PDF 257 KB Posted
- Attached to
- RFQ - Physical Security Equipment Maintenance Federal contract opportunity
- Solicitation number
- RFQ-CIO-30110000-23-012
About this file
This attachment to a solicitation provides security requirements for physical security systems. It outlines that contractors must comply with regulations including FISMA, FIPS, NIST SP 800-53, OMB memoranda, and Treasury directives. Contractors must protect sensitive personally identifiable information and ensure any systems used are located and operated within the U.S. by U.S. citizens. All contractor personnel must complete annual security and privacy awareness training and may be subject to background checks. The solicitation specifies the Bureau of Fiscal Service and involves requirements for maintaining physical security equipment while complying with stringent federal requirements for safeguarding data.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ-CIO-30110000-23-012 Amend 0001.pdf | ||
| Attch D (1-2) - Pricing Spreadsheet Amend 0001.xlsx | XLSX spreadsheet | |
| RFQ-CIO-30110000-23-012.pdf | ||
| Attachment C - Security Controls Rules of Behavior Agreement.pdf | ||
| Attch D (1-2) - Pricing Spreadsheet.xlsx | XLSX spreadsheet | |
| Attachment B - FS Security Rules of Behavior.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFQ-CIO-30110000-23-012
Attachment A – Security Requirements
1 Applicability Attachment A – Security Requirements details high-level security requirements that may apply to procured products, systems, and services. All sections of this document must be included, even when they are not applicable. This ensures that the contractor is informed of requirements in the event they become applicable.
This attachment applies to the Contractor, its subcontractors, and contractor personnel, including fiscal and financial agents (hereafter referred to collectively as “Contractor”) and addresses specific Bureau of the Fiscal Service (Fiscal Service) requirements in addition to those included in the Federal Acquisition Regulation (FAR), the Privacy Act of 1974 (5 U.S.C. §552a), the Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191, 110 Stat. 1936), the Sarbanes-Oxley Act of 2002 (Pub. L.
107-204, 116 Stat 745), and other laws, mandates, or executive orders pertaining to the development and operations of information systems and the protection of sensitive information and data. The following should not be construed to alter or diminish civil and/or criminal liabilities provided under various laws or mandates.
2 Information Types The term “information” is synonymous with data, regardless of format or medium. Personally Identifiable Information (PII) is a subset of Sensitive But Unclassified (SBU) information. Sensitive PII is a subset of PII, and therefore a subset of SBU information. All requirements for SBU information apply to PII and Sensitive PII. All requirements for PII apply to Sensitive PII.
2.1 Sensitive But Unclassified Information
Sensitive But Unclassified information (SBU) is any information, the loss, misuse, or unauthorized access to or modification of which could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under the Privacy Act but which has not been specifically authorized under criteria established by an executive order or an act of Congress to be kept secret in the interest of national defense or foreign policy. SBU information is subject to stricter handling requirements than less sensitive non-SBU information because of the increased risk if the data are compromised. Some categories of SBU include financial, medical, health, legal, strategic , and business information. Personally Identifiable Information and Sensitive PII are also considered to be SBU. These categories of information require appropriate protection individually and may require additional protection when aggregated with other sensitive information.
2.2 Personally Identifiable Information
Personally Identifiable Information ( as defined in OMB Memorandum M-07-16, refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information that is publicly available — in any medium and from any source — is or can be combined to identify an individual. As an example, PII includes a name and an address because it uniquely identifies an individual, but alone may not constitute Sensitive PII.
2.3 Sensitive Personally Identifiable Information
Sensitive PII (refers to information that can be used to target, harm, or coerce an individual or entity;
assume or alter an individual’s or entity’s identity; or alter the outcome of an individual’s or entity’s activities. Sensitive PII requires stricter handling because of the increased risk to an individual or associates if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as Social Security numbers (SSN) or biometric identifiers. Other information such as a financial account, date of birth, maiden names, citizenship status, or medical information, in conjunction with the identity of an individual (directly or indirectly inferred), are also considered Sensitive PII. In addition, the context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or complaint.
3 Information Protection The Contractor's employees, facilities, services and product(s) shall meet applicable United States (U.S.)
federal government laws, directives, executive orders, standards, guidelines, and other requirements for information security, personnel security, physical security, and data encryption. The Contractor shall follow United States Government, Treasury, and Fiscal Service procedures for proper handling of SBU and PII. The Contractor may be required to assist with security reviews by providing information about processes, software, facilities, personnel, and equipment through interviews, on-site inspections (if necessary), and documentary evidence.
Sensitive But Unclassified information, data, and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to Government control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following NIST Special Publication 800-88, Guidelines for Media Sanitization.
The disposition of all data will be at the written direction of the COR, this may include documents returned to Government control; destroyed; or held as specified until otherwise directed. Items returned to the Government shall be hand carried or sent by certified mail to the COR.
The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The contractor shall also protect all Government data, equipment, etc.
Information systems and services performing work on behalf of the Fiscal Service shall be located, operated and maintained within the U.S.; operations and maintenance of systems shall be conducted by personnel physically located within the U.S or its territories. “Operated” refers to carrying out administrator/privileged user functions, such as, database administration, patching, upgrades and maintenance. Administrator/ privileged access shall not be permitted from outside of the U.S. Foreign remote maintenance, systems monitoring, foreign “call service centers,” “help desks,” and the like are prohibited. Fiscal Service information shall be accessed only by personnel meeting or surpassing the Treasury citizenship requirements (as determined by Personnel Security, see section 7 below). Extra precautions should be in place for other types of access from foreign locations.
Work shall be performed on systems secured at least at a FIPS 199 NOT APPLICABLE security category level.
Written approval by the Fiscal Service’s Chief Information Officer (CIO), or designee, is required prior to the use or storage of Fiscal Service SBU information, or the sharing of Fiscal Service SBU Information by the Contractor with any subcontractor, person, or entity other than Fiscal Service.
The Contractor must not remove SBU information from approved location(s), electronic device(s), or other container(s), without prior approval from the CIO or their designee.
Contracts and/or task orders for the acquisition of information systems or services processing SBU information for Fiscal Service shall clearly specify the delivery date of an acceptable Security Assessment & Authorization (SA&A) or similar security assessment package as may be prescribed by Fiscal Service.
The Contractor shall grant access to Fiscal Service to review any existing SA&A documentation.
When needed per Fiscal Service direction, the Contractor and Fiscal Service officials shall prepare an Interconnection Security Agreement (ISA) prior to connecting to external information systems and in accordance with Fiscal Service processes.
Any computer equipment used by or on behalf of the Fiscal Service shall support Transport Layer Security (TLS) v1.0 or greater and comply with NIST SP 800-52, Guidelines for Selection and Use of Transport Layer Security unless predetermined to be a standalone system.
Cryptographic modules used to protect Fiscal Service information must be compliant with the current FIPS 140 version and validated by the Cryptographic Module Validation Program (CMVP). The Contractor must provide the validation certificate number to Fiscal Service for verification. Encryption is required to protect federal and contractor data when transmitting between systems.
The Contractor shall be subject to periodic audits and reviews, as required by law. The Contractor shall provide reports with findings that result from audits and reviews to Fiscal Service within five business days of receipt. Within 15 business days, the Contractor shall propose a response and a plan of action with milestones. The Contractor shall resolve all findings prior to recurrence, and the contract shall include financial disincentives for repeat findings.
The Contractor may be required to provide Fiscal Service access to, and information regarding systems the contractor operates on behalf of Fiscal Service as part of its responsibility to ensure compliance with security requirements. Fiscal Service access may include independent validation testing of controls, system penetration testing, FISMA reviews, monthly data feed requirements as coordinated by Fiscal Service, and access by agency Inspector General for its review.
All information systems that input, store, process, and/or output Government information must be granted approval by the CIO, or designee for operation and/or use. The contractor must adhere to current Fiscal Service policies, procedures, and guidance for Security Assessment and Authorization (SA&A) activities.
Prior to SA&A, a Privacy Threshold Analysis (PTA) for all systems must be completed and provided to the Fiscal Service Privacy Officer, or designate, for a determination. If determination is made that a Privacy Impact Assessment (PIA) is required, it must be completed in accordance with Fiscal Service requirements.
The Contractor shall allow for physical inspection of facilities by Fiscal Service or representatives within 30 calendar days of a Fiscal Service request. The Contractor may propose to limit the number of physical inspection requests from Fiscal Service; the limit shall not be less than two times per calendar year.1 In addition to scheduled visits at the request of Fiscal Service, the Contractor shall allow scheduled physical inspections in support of Security Assessment & Authorization and physical inspections on demand in the event of a computer security incident. A computer security incident is defined as any adverse event that threatens computer security and may include but is not limited to:
loss of data confidentiality, disruption to data or system integrity, and denial of availability.
The Contractor shall report any suspected security incident by phone to the Fiscal Service IT Service Desk within one hour of identification of a suspected security incident: 304-480-7777.
The Contractor shall destroy all SBU information, obtained under this contract, from contractor-owned information technology assets. Certification of data destruction will be performed by the contractor’s Project Manager and
1 This limit does not apply to reviews that may be performed by GAO or OIG under their legal authority written notification confirming certification will be delivered to the contracting officer within 15 days of termination/expiration of contractor work.
4 Federal Regulatory Requirements and Industry Standards The Contractor's performance and systems shall comply with applicable federal government laws, directives, executive orders, standards, guidelines, and other requirements for information security, personnel security, physical security, and data encryption. The Contractor's performance and systems shall comply with the most current versions of the following applicable Federal and industry information technology regulatory requirements and standards. The most relevant documents will be Federal Information Security Management Act of 2002 (FISMA)
• FIPS 140-2, Security Requirements for Cryptographic Modules
• FIPS 191, Guideline for the Analysis of Local Area Network Security
• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems
• FIPS 201-1, Personal Identity Verification for Federal Employees and Contractors
• Fiscal Service Baseline Security Requirements (BLSRs)
• National Institute of Science and Technology (NIST) SP 800-12, An Introduction to Computer
Security - The NIST Handbook
• NIST SP 800-16, Information Technology Security Training Requirements: A Role and
Performance Based Model
• NIST SP 800-18, Guide for Developing Security Plans for Information Technology Systems
• NIST SP 800-27, Engineering Principles for Information Technology Security (A Baseline for
Achieving Security), Revision A
• NIST SP 800-28, Guidelines on Active Content and Mobile Code
• NIST SP 800-30, Guide to Conducting Risk Assessments
• NIST SP 800-34, Contingency Planning Guide for Federal Information Systems
• NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information
Systems: A Security Life Cycle Approach
• NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information
System View
• NIST SP 800-40, Procedures for Handling Security Patches
• NIST SP 800-41, Guidelines on Firewalls and Firewall Policy
• NIST SP 800-42, Guideline for Network Security Testing
• NIST SP 800-45, Guidelines for Electronic Mail Security
• NIST SP 800-46, Security for Telecommuting and Broadband Communications
• NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems
• NIST SP 800-48, Wireless Network Security
• NIST SP 800-50, Building an Information Technology Security Awareness and Training Program
• NIST SP 800-52, Guidelines for Selection and Use of Transport Layer Security
• NIST SP 800-53, Recommended Security Controls for Federal Information Systems and
Organizations
• NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information
Systems and Organizations
• NIST SP 800-55, Performance Measurement Guide for Information Security
• NIST SP 800-58, Security Considerations for Voice Over IP Systems
• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories
• NIST SP 800-61, Computer Security Incident Handling Guide
• NIST SP 800-63-1, Electronic Authentication Guideline
• NIST SP 800-68, Guidance for Securing Microsoft Windows XP Systems for IT Professionals: A
NIST Security Configuration Checklist
• NIST SP 800-70, National Checklist Program for IT Products – Guidelines for Checklist
Users and Developers
• NIST SP 800-77, Guide to IPSec VPNs
• NIST SP 800-81, Secure Domain Name System (DNS) Deployment Guide
• NIST SP 800-83, Guide to Malware Incident Prevention and Handling
• NIST SP 800-88, Media Sanitization Guide
• NIST SP 800-94, Guide to Intrusion Detection and Prevention Systems (IDPS)
• NIST SP 800-100, Information Security Handbook: A Guide for Managers
• NIST SP 800-114, User's Guide to Securing External Devices for Telework and Remote Access
• NIST SP 800-115, Technical Guide to Information Security Testing and Assessment
• NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
• NIST SP 800-125, Guide to Security for Full Virtualization Technologies
• NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems
• NIST SP 800-137, Information Security Continuous Monitoring for Federal Information
Systems and Organizations
• NIST SP 800-144, Guidelines on Security and Privacy in Public Cloud Computing
• NIST SP 800-145, A NIST Definition of Cloud Computing
• NIST SP 800-147, Basic Input/Output System (BIOS) Protection Guidelines
• NIST SP 800-153, Guidelines for Securing Wireless Local Area Networks (WLANs)
• Office of Management and Budget (OMB) Circular A-123, Management Accountability and Control
• OMB Circular A-130, Management of Federal Information Resources
• OMB Memorandum - Security Authorization of Information Systems in Cloud Computing
Environments
• OMB M-04-04, E-Authentication Guidance for Federal Agencies
• OMB M-05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 -
Policy for a Common Identification Standard for Federal Employees and Contractors
• OMB M-06-16, Protection of Sensitive Agency Information
• OMB M-07-11, Implementation of Commonly Accepted Security Configurations for Windows
Operating Systems
• OMB M-07-16, Safeguarding Against and Responding to the Breach of PII
• OMB M-07-18, Ensuring New Acquisitions Include Common Security Configurations
• OMB M-14-03, Enhancing the Security of Federal Information and Information Systems
• OMB M-15-01, Fiscal Year 2014-2015 Guidance on Improving Federal Information Security and
Privacy Management Practices
• OMB M-99-20, Security of Federal Automated Information Resources
• Public Law 93-579, The Privacy Act of 1974
• TD P 85-01 - Treasury Information Technology Security Program
• TD P 15-71 - Department of the Treasury Security Manual
New regulatory requirements and standards shall be adhered to as they are enacted or become effective, as applicable. The Contractor shall implement a process to support timely compliance with new requirements imposed by external authorities.
The Contractor shall comply with both Fiscal Service and Treasury requirements that extend above federal government and industry information technology regulatory requirements and standards. For example, Treasury hasimplemented more stringent security requirements in the Treasury Security Manual, TD P 85-01, than are typical for the federal government or the general information technology community. There are approximately 100 additional security control extensions in a variety of areas that go beyond NIST SP 800-53 guidance.
4.1 Privacy Act Compliance
(a) Contractors must comply with the Privacy Act’s requirements in the design, development, or operation of any system of records containing PII developed or operated for Fiscal Service or to accomplish a Fiscal Service function for a System of Records (SOR)2.
(b) In the event of violations of the Act, a civil action may be brought against Fiscal Service when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an Fiscal Service function, and criminal penalties may be imposed upon the officers or employees of Fiscal Service when the violation concerns the operation of a SOR on individuals to accomplish an Fiscal Service function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish a Fiscal Service function, the Contractor is considered to be an employee of the agency.
5 Security and Privacy Awareness Training The Contractor and subcontractor personnel who require access to Fiscal Service information or information systems will be required to review and sign Rules of Behavior, and complete security awareness training prior to being granted access. For the first 60 days of user access, reviewing and signing the Rules of Behavior is adequate for meeting the security awareness training requirement. If the security awareness training requirement is not completed within the first 60 days, access may be revoked. Security and Privacy training will be required on a recurring annual basis, of all contractor and subcontractor staff performing work for Fiscal Service on a recurring annual basis, provided by Fiscal Service and/or by the contractor. Access may be revoked if the annual security training is not completed. When necessary, Contractors and subcontractors will be required to sign Non-disclosure agreements.
6 Bureau of the Fiscal Service (Fiscal Service) Personnel Security and Suitability
Requirements for Contractors and Subcontractors
6.1 GENERAL
The Fiscal Service has determined that performance of this contract requires that the Contractor, subcontractor(s), and vendor(s) (herein known as Contractor), does not requires access to Sensitive but
Unclassified (SBU) information (herein known as unclassified information) and the contract was evaluated as:
“Limited Risk” All contractor personnel will be a U.S. citizen.
The Contractor will abide by the requirements set forth in the Non-Disclosure Agreement, included in the contract, for the protection of unclassified information at its cleared facility. If the Contractor has access to unclassified information at the Fiscal Service or other Government Facility, it will abide by the requirements set by that agency.
| Attachment A – Security Requirements |
| 2 Information Types |
| 2.1 Sensitive But Unclassified Information |
| 2.2 Personally Identifiable Information |
| 2.3 Sensitive Personally Identifiable Information |
| 3 Information Protection |
| 4 Federal Regulatory Requirements and Industry Standards |
| 4.1 Privacy Act Compliance |
| 5 Security and Privacy Awareness Training |
| 6.1 GENERAL |
File details come from the government source that posted it. Updated .