Attachment A - Security Requirements.pdf
PDF 897 KB Posted
- Attached to
- Mainframe Cloud Transition Services and Support Federal contract opportunity
- Solicitation number
- RFP-CIO-30100000-23-001
About this file
This solicitation requests proposals for a single-award Indefinite Delivery Indefinite Quantity contract to provide Mainframe Cloud Transition Services and Support. Offerors must propose either an IBM SmartCloud solution or an equivalent capability to transition the Bureau of Fiscal Service's mainframe to a cloud environment. Key dates include questions due by January 3rd, 2023 and proposals due by January 9th, 2023. The selected contractor will provide minimum requirements as outlined in the Performance Work Statement, including transitioning the mainframe to a cloud that is located, operated, and maintained within the U.S. The contract will have a one year base period and four one-year options and will be administered by the Department of the Treasury Bureau of Fiscal Service on behalf of their Information and Security Services.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP-CIO-30100000-23-001 (Amd. 2).pdf | ||
| Attachment I (1-3) - Order 1 Pricing (Amd. 1).xlsx | XLSX spreadsheet | |
| Attachment H - Order 1 PWS (Amd. 1).pdf | ||
| Attachment E - Pricing Workbook (Amd. 1).xlsx | XLSX spreadsheet | |
| Questions and Responses (Amd. 1).pdf | ||
| RFP-CIO-30100000-23-001 (Amd. 1).pdf | ||
| Attachment K - Roles and Responsibilities.xlsx | XLSX spreadsheet | |
| Attachment E - Pricing Workbook.xlsx | XLSX spreadsheet | |
| Attachment F - Accessibility Requirements Statement.pdf | ||
| RFP-CIO-30100000-23-001.pdf | ||
| Attachment B - Security Rules of Behavior Agreement.pdf | ||
| Attachment C - Non-Disclosure Agreement.pdf | ||
| Attachment G - Small Business Participation Plan.pdf | ||
| Attachment I (1-3) - Order 1 Pricing.xlsx | XLSX spreadsheet | |
| Attachment J - Subcontracting Plan.pdf | ||
| Attachment D - Security Controls Rules of Behavior Agreement.pdf | ||
| Attachment H - Order 1 PWS.pdf |
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP-CIO-30100000-23-001
Attachment A – Security Requirements
1 Applicability Attachment A – Security Requirements details high-level security requirements that may apply to procured products, systems, and services.
This attachment applies to the Contractor, its subcontractors, and contractor personnel, including fiscal and financial agents (hereafter referred to collectively as “Contractor”) and addresses specific Bureau of the Fiscal Service (Fiscal Service) requirements in addition to those included in the Federal Acquisition Regulation (FAR), the Privacy Act of 1974 (5 U.S.C. §552a), the Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191, 110 Stat. 1936), the Sarbanes-Oxley Act of 2002 (Pub. L.
107-204, 116 Stat 745), and other laws, mandates, or executive orders pertaining to the development and operations of information systems and the protection of sensitive information and data. The following should not be construed to alter or diminish civil and/or criminal liabilities provided under various laws or mandates.
2 Information Types The term “information” is synonymous with data, regardless of format or medium.
2.1 Sensitive But Unclassified Information
Sensitive But Unclassified information (SBU) is any information, the loss, misuse, or unauthorized access to or modification of which could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under the Privacy Act but which has not been specifically authorized under criteria established by an executive order or an act of Congress to be kept secret in the interest of national defense or foreign policy. SBU information is subject to stricter handling requirements than less sensitive non-SBU information because of the increased risk if the data are compromised. Some categories of SBU include financial, medical, health, legal, strategic, and business information. Personally Identifiable Information and Sensitive PII are also considered to be SBU. These categories of information require appropriate protection individually and may require additional protection when aggregated with other sensitive information.
2.2 Controlled Unclassified Information
CUI is defined as information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic; requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.
2.3 Personally Identifiable Information
Personally Identifiable Information (PII) as defined in OMB Memorandum M-07-16, refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information that is publicly available — in any medium and from any source — is or can be combined to identify an individual. As an example, PII includes a name and an address because it uniquely identifies an individual, but alone may not constitute PII.
2.4 Sensitive Personally Identifiable Information
Sensitive PII refers to information that can be used to target, harm, or coerce an individual or entity;
assume or alter an individual’s or entity’s identity; or alter the outcome of an individual’s or entity’s activities. Sensitive PII requires stricter handling because of the increased risk to an individual or associates if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as Social Security numbers (SSN) or biometric identifiers. Other information such as a financial account, date of birth, maiden names, citizenship status, or medical information, in conjunction with the identity of an individual (directly or indirectly inferred), are also considered Sensitive PII. In addition, the context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or complaint.
3 Information Protection The Contractor's employees, facilities, services and product(s) must meet applicable United States (U.S.)
federal government laws, directives, executive orders, standards, guidelines, and other requirements for information security, privacy, personnel security, physical security, and data encryption. The Contractor must follow United States Government, Treasury, and Fiscal Service procedures for proper handling of SBU, CUI and PII. The Contractor may be required to assist with security reviews by providing information about processes, software, facilities, personnel, and equipment through interviews, on-site inspections (if necessary), and documentary evidence.
The contractor must be responsible for implementing security and privacy controls to protect information used, gathered, or developed as a result of work under this contract. The strength of security and privacy controls implemented must be consistent with the FIPS 199 categorization High of the information, as determined by Fiscal Service. The contractor must document security and privacy controls in place to protect information and apply controls to protect such documentation from unauthorized disclosure.
Security and privacy control documentation must include an allocation of responsibility between control providers regarding control implementation. The documentation must also include a description of the security and privacy controls implemented and demonstrated use of a system development lifecycle in the implementation of security and privacy controls. The contractor must establish processes to identify and address weaknesses or deficiencies in their supply chain. Supply chain controls will be implemented as part of these processes and documented by the contractor.
Information systems and services performing work on behalf of the Fiscal Service must be located, operated and maintained within the U.S.; operations and maintenance of systems must be conducted by personnel physically located within the U.S or its territories. “Operated” refers to carrying out administrator/privileged user functions, such as, database administration, patching, upgrades and maintenance. Administrator/ privileged access must not be permitted from outside of the U.S. Foreign remote maintenance, systems monitoring, foreign “call service centers,” “help desks,” and the like are prohibited. Fiscal Service information must be accessed only by personnel meeting or surpassing the Treasury citizenship requirements (as determined by Personnel Security, see section 7 below). Extra precautions should be in place for other types of access from foreign locations.
When needed per Fiscal Service direction, the Contractor and Fiscal Service officials must prepare a Memorandum of Understanding (MOU) or Interconnection Security Agreement (ISA) prior to connecting to external information systems and in accordance with Fiscal Service processes. The Contractor is required to use Fiscal Service’s MOU or ISA document. Modifications to the template language are not allowed. Any computer equipment used by or on behalf of the Fiscal Service must support the latest Transport Layer Security (TLS) standard and comply with current NIST guidance.
The Contractor must report any suspected security incident by phone to the Fiscal Service IT Service Desk immediately upon identification of a suspected security incident: 304-480-7777.
4 Federal Regulatory Requirements and Industry Standards The Contractor's performance and systems must comply with applicable federal government laws, directives, executive orders, standards, guidelines, and other requirements for information security, personnel security, physical security, and data encryption. The Contractor's performance and systems must comply with the most current versions of the following applicable Federal and industry information technology regulatory requirements and standards:
Federal Information Security Modernization Act of 2014 (FISMA) FIPS 140, Security Requirements for Cryptographic Modules FIPS 199, Standards for Security Categorization of Federal Information and Information Systems FIPS 200, Minimum Security Requirements for Federal Information and Information Systems FIPS 201-2, Personal Identity Verification for Federal Employees and Contractors Fiscal Service Baseline Security Requirements (BLSRs) NIST Cybersecurity Framework NIST Privacy Framework
NIST SP 800-37
NIST SP 800-53
NIST SP 800-53A
NIST SP 800-63-3
NIST SP 800-137
NIST SP 800-171
OMB Circular A-123 OMB Circular A-130 Public Law 93-579, The Privacy Act of 1974 IRS Publication 1075 TD P 85-01 - Treasury Information Technology Security Program TD P 15-71 - Department of the Treasury Security Manual
4.1 Privacy Act Compliance
(a) Contractors must comply with the Privacy Act’s requirements in the design, development, or operation of any system of records containing PII developed or operated for Fiscal Service or to accomplish a Fiscal Service function for a System of Records (SOR)1. Contractors must assist in the completion of any required Privacy Threshold Analysis (PTA) and/or Privacy Impact Analysis
(PIA).
(b) In the event of violations of the Act, a civil action may be brought against Fiscal Service when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an Fiscal Service function, and criminal penalties may be imposed upon the officers or employees of Fiscal Service when the violation concerns the operation of a SOR on individuals to accomplish an Fiscal Service function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish a Fiscal Service function, the Contractor is considered to be an employee of the agency.
5 Security and Privacy Awareness Training The Contractor and subcontractor personnel who require access to Fiscal Service information or information systems will be required to review and sign Rules of Behavior, and complete security awareness training prior to being granted access. For the first 60 days of user access, reviewing and signing the Rules of Behavior is adequate for meeting the security awareness training requirement. If the security awareness training requirement is not completed, access may be revoked. Security and Privacy training will be required on a recurring annual basis, of all contractor and subcontractor staff performing work for Fiscal Service, provided by Fiscal Service and/or by the contractor. Access may be revoked if the annual security training is not completed. When necessary, Contractors and subcontractors will be required to sign Non-disclosure agreements.
1 “System of Records” is defined as a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
6 Cloud and FedRAMP Requirements
Cloud based systems or services must comply with OMB Federal Risk and Authorization Management Program (FedRAMP) requirements as well as FedRAMP Privacy requirements. These requirements are in addition to U.S. Government, Department of the Treasury, and Fiscal Service requirements specified throughout this document. Cloud Service Providers must have FedRAMP compliant security documentation sufficient to obtain a provisional authorization.
Cloud based systems or services must have a FedRAMP third party assessment organization (3PAO) security assessment. Contractor must obtain this assessment service and coordinate completion of assessment. Cloud Service Providers must comply with FedRAMP guidance regarding continuous monitoring activities. Fiscal Service must have access to ongoing continuous monitoring documentation, such as POA&M documentation.
Contractors must be responsible for the following privacy and security safeguards:
1. To the extent required to carry out the FedRAMP assessment and authorization process and FedRAMP continuous monitoring, to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public Government data collected and stored by the Contractor, the Contractor must afford the Government access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases.
2. If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer must immediately bring the situation to the attention of the other party.
3. The contractor must also comply with any additional FedRAMP privacy requirements.
4. The Government has the right to perform manual or automated audits, scans, reviews, or other inspections of the vendor’s IT environment being used to provide or facilitate services for the Government. In accordance with the Federal Acquisitions Regulations (FAR) clause 52.239-1, the contractor must be responsible for the following privacy and security safeguards:
(a) The Contractor must not publish or disclose in any manner, without the Contracting Officer’s written consent, the details of any safeguards either designed or developed by the Contractor under this contract or otherwise provided by the Government.
Exception - Disclosure to a Consumer Agency for purposes of C&A verification.
(b) To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor must afford the Government access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases.
(c) If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer must immediately bring the situation to the attention of the other party.
If the vendor chooses to run its own automated scans or audits, results from these scans may, at the Government’s discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration must be approved by the Government. In addition, the results of vendor-conducted scans must be provided, in full, to the Government.
The government will retain unrestricted rights to government data. The government retains ownership of any user created/loaded data and applications hosted on vendor’s infrastructure, as well as maintains the right to request full copies of these at any time.
The data that is processed and stored by the various applications within the network infrastructure may contain financial data as well as PII. This data and PII must be protected against unauthorized access, disclosure or modification, theft, or destruction. The contractor must ensure that the facilities that house the network infrastructure are physically secure.
Identified gaps between required Fiscal Service and FedRAMP Security Control Baselines and Continuous Monitoring controls, and the contractor's implementation, as documented in the Security Assessment Report, must be tracked by the contractor for mitigation in a Plan of Action and Milestones (POA&M) document. Depending on the severity of the gaps, the Government may require them to be remediated before an authorization is granted.
The contractor is responsible for mitigating all security risks found during SA&A, and continuous monitoring activities.
Fiscal Service may choose to cancel the (Contract/award) and terminate any outstanding orders if the contractor has its provisional authorization revoked and/or the deficiencies are greater than agency risk tolerance thresholds.
The vendor is advised to review the FedRAMP guidance documents to determine the level of effort that will be necessary to complete the requirements. All FedRAMP documents and templates are available at the FedRAMP website (https://www.fedramp.gov).
Maintenance of the FedRAMP Provisional Authorization will be through continuous monitoring and periodic audit of the operational controls within a contractor’s system, environment, and processes to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to the FedRAMP PMO as required by FedRAMP Requirements. The submitted deliverables (or lack thereof) provide a current understanding of the security state and risk posture of the information systems. The deliverables will allow the FedRAMP JAB to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur. Contractors will be required to provide updated deliverables and automated data feeds as defined in the FedRAMP Continuous Monitoring Plan.
7 Bureau of the Fiscal Service (Fiscal Service) Personnel Security and Suitability Requirements for Contractors and Subcontractors
7.1 GENERAL
The Bureau of the Fiscal Service (Fiscal Service) has determined that performance of this contract requires that the Contractor, subcontractor(s), and vendor(s) (herein known as Contractor), requires access to Sensitive but Unclassified (SBU) information (herein known as unclassified information). The contract was evaluated as:
“High Risk” - All contractor and subcontractor personnel who require access to Treasury or Bureau-owned or controlled facilities and security items or technology systems will be a U.S. citizen.
The Contractor will abide by the requirements set forth in the Non-Disclosure Agreement, included in the contract, for the protection of unclassified information at its cleared facility. If the Contractor has access to unclassified information at the Fiscal Service or other Government Facility, it will abide by the requirements set by that agency.
7.2 SUITABILITY DETERMINATION
Contractor personnel assigned to this contract, even those who possess a National Security Clearance shall undergo suitability screening conducted by the Fiscal Service Personnel Security staff. Fiscal Service shall have and exercise full control over granting, denying, withholding, or terminating unescorted government facility and/or sensitive Government information access for these contractor employees based upon the results of a background investigation.
7.3 Personnel Security Background Requirements
Performance of this contract requires contractor and subcontractor personnel to have signed and submitted a Non-Disclosure Agreement (NDA), have an appropriate level background investigation initiated, have a favorable Federal Bureau of Investigations (FBI) fingerprint check completed, and be issued a Federal Government personnel identification card before being allowed unsupervised physical access to Federal Government facilities and/or logical access to Federal Government Information Technology (IT) Systems, databases or information. The Contracting Officer's Representative (COR) will be the sponsoring official and will coordinate with Fiscal Service's Personnel Security to arrange the background investigation and credentialing process.
At least two weeks before start of contract performance, the Contractor shall identify all contractor and subcontractor personnel who shall require physical access to Federal Government facilities and/or logical access to Federal IT systems, databases or information for the performance of work under this contract. Identified contractor and subcontractor personnel shall complete and return the below listed documents to the COR. The Contractor shall make their personnel available at the place and time specified by the COR in order to initiate the credentialing process.
Office of Personnel Management (OPM) Electronic Questionnaire for Investigation Processing (e-QIP) portal to provide historical background information for background investigations:
http://www.opm.gov/e-qip/ (Electronically submitted to Fiscal Service)
OF 306 (fillable forms available at http://www.opm.gov/forms/html/of.asp) Fair Credit Reporting Release (Electronically submitted to Fiscal Service ) Non-Disclosure Agreement (NDA)(attached)
Background investigations shall be processed in accordance with the Office of Personnel Management (OPM) standards. To commence the process, each contractor will be required to supply the COR with their full name, date of birth, place of birth (city and state), social security number, and valid email address. With this information, Fiscal Service Personnel Security staff will initiate the contractor in the Electronic Questionnaire for Investigations Processing System (e-QIP). The Personnel Security Specialist will further provide the contractor online instructions and the website address where the Contractor will provide the required information needed to conduct the Contractor background investigation.
A Background Investigation is required to satisfy HSPD-12 background investigation requirements for identified contractor and subcontractor personnel requiring physical access to Federal Government facilities and/or logical access to Federal IT systems, databases or information. This process provides the government with a means to positively identify and make a suitability determination regarding the applicant under this contract. Upon receipt of a favorable FBI fingerprint check and submission of completed questionnaire (e-Qip) and required forms, the contractor's identification card will be issued and/or unsupervised physical access to Government facilities granted.
Contractor and subcontractor personnel are required to give, and authorize others to give, full, frank, and truthful answers to relevant and material questions needed to reach a suitability determination.
Refusal or failure to furnish or authorize provision of information may constitute grounds for denial or revocation of credentials. Government investigative personnel may contact contractor/subcontractor personnel being screened or investigated in person, by telephone, or in writing. The contractor shall ensure that all contractor and subcontractor personnel are available for such contact and that timely responses to investigative requests are provided.
Alternatively, if it is verified that an individual is already vetted by another agency at the appropriate level of background investigation, and the investigation was completed less than five (5) years prior to the start of the contractor's initial physical/logical access date, then further investigation may not be necessary. If this is applicable, the Contractor shall provide the COR with the name of the agency that conducted the investigation and completion date, if known.
If at any point during this process investigative results are unfavorably adjudicated, the individual will be denied further admittance to work on the contract, including both physical and/or logical access. In the event of a disagreement between the Contractor and the Government concerning the suitability of an individual to perform work under this contract, the Government shall have the right of final determination.
During performance of the contract, the Contractor shall keep the COR apprised of any changes in contractor or subcontractor personnel to ensure that work performance is not delayed by compliance with the credentialing process. Identification cards that are lost, damaged or stolen shall be reported to the COR and Issuing Office within eighteen (18) hours. Replacement shall be at the Contractor's expense. If re-issuance of expired credentials is needed, it will be coordinated through the COR.
At the end of the contract performance, or when a contractor/subcontractor employee is no longer working under this contract, the contractor shall ensure that all identification cards are returned to the COR. If the Contractor does not return all identification cards, last payment may be withheld.
This requirement shall be incorporated into any subcontracts that require subcontractor personnel to have regular and routine unsupervised physical access to a federally controlled facility for six (6) months or more, and/or any logical access to a federally controlled information system.
Definitions:
Physical Access: Is the ability to enter a federally owned facility or federally leased space:
If federal space is limited to a portion of a building then HSPD-12 applies only to that portion owned or leased by the federal government.
Logical Access:
In computer security, being able to interact with data through access control procedures such as identification, authentication, and authorization. User based authenticated access to the application, systems and the data that is processed.
File details come from the government source that posted it. Updated .