Attachment B - FS Security Rules of Behavior.pdf

PDF 164 KB Posted

Attached to
RFQ - Physical Security Equipment Maintenance Federal contract opportunity
Solicitation number
RFQ-CIO-30110000-23-012
Issued by
Department of the Treasury Bureau of the Fiscal Service

About this file

This document contains the Bureau of the Fiscal Service's rules of behavior for information technology systems and facilities. Users who access Fiscal Service data, equipment, systems or facilities must follow these rules, which include properly using and securing resources, protecting data from unauthorized access and reporting security issues. The rules also specify requirements for passwords, remote access, software usage and handling of printed materials. By signing the rules of behavior, users acknowledge their responsibility to comply with the security requirements and understand that violations may result in administrative or legal action.

The related federal contract opportunity is a solicitation for physical security equipment maintenance services issued by the Department of the Treasury Bureau of the Fiscal Service. Solicitation number RFQ-CIO-30110000-23-012 seeks offers for this requirement but provides no further details on products, pricing terms, response dates or other salient information.

View the file

Other files for this federal contract opportunity

Other files attached to RFQ - Physical Security Equipment Maintenance, newest first.
File Type Posted
RFQ-CIO-30110000-23-012 Amend 0001.pdf PDF
Attch D (1-2) - Pricing Spreadsheet Amend 0001.xlsx XLSX spreadsheet
Attachment A - Physcial Security Systems.pdf PDF
Attch D (1-2) - Pricing Spreadsheet.xlsx XLSX spreadsheet
RFQ-CIO-30110000-23-012.pdf PDF
Attachment C - Security Controls Rules of Behavior Agreement.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFQ-CIO-30110000-23-012

Attachment B - Bureau of the Fiscal Service (Fiscal Service) IT Rules of Behavior

The Contractor shall sign IT Rules of Behavior.

Fiscal Service Security Rules of Behavior

SUBJECT:

The Bureau of the Fiscal Service (Fiscal Service) Security Rules of Behavior (Rules of Behavior)

PURPOSE:

The Rules of Behavior define responsibilities and procedures for the secure use of Fiscal Service data, equipment, information technology (IT) systems, and facilities. By reading and signing the Rules of Behavior, Users (defined below) acknowledge their responsibility for complying with the Rules of Behavior.

SCOPE:

The Rules of Behavior apply to Users (not public users) who access or maintain any Fiscal Service data, equipment, IT systems, or facilities, regardless of location (e.g., whether you are at your regular duty station or a remote work location). Users are individuals who have access to Fiscal Service data, equipment, IT systems or facilities for the purpose of performing work on behalf of Fiscal Service. Examples of Users include, but are not limited to, Fiscal Service employees and employees of contractors, sub-contractors, and agents. At Fiscal Service’s discretion, certain individuals who have access to Fiscal Service data, equipment, IT systems, or facilities may not be considered Users under this definition and as such may not be required to sign these Rules of Behavior. In addition to the rules and requirements contained within this document, Users should note that other federal laws and regulations apply when accessing Fiscal Service resources (e.g., licensing agreements and copyright laws), but are considered outside the scope of this document.

Users SHALL:

Follow these rules regarding Fiscal Service facilities:

● Use facilities properly and follow laws, regulations, and policies governing the use and entrance to such facilities.

● Do not threaten any person or organization.

● Do not commit acts of violence against any person, organization, equipment, or facility.

● Do not bring prohibited items (e.g., weapons) into a Fiscal Service facility.

Follow these rules regarding Fiscal Service data, equipment, and IT systems:

● Use Fiscal Service data, equipment, and IT systems properly and follow laws, regulations, and policies governing the use of such resources (Base Line Security Requirements, (BLSRs), Treasury Information Technology Security Program (TD-P 85-01), the Treasury Security Manual (TD-P 15-71), and Fiscal Service Policies).

● Protect Fiscal Service data, equipment and IT systems from loss, theft, damage, and unauthorized use or disclosure.

● Secure mobile media (paper and digital) based on the sensitivity of the information contained.

● Use appropriate sensitivity markings on mobile media (paper and digital).

● Promptly report any known or suspected security breaches or threats, including lost, stolen, or improper/suspicious use of Fiscal Service data, equipment, IT systems, or facilities to the Service Desk at 304-480- 7777.

● Do not attempt to circumvent any security controls.

● Logoff, lock, or secure workstation/laptop to prevent unauthorized access to Fiscal Service IT systems or services.

● Do not read, alter, insert, copy, or delete any Fiscal Service data except in accordance with assigned job responsibilities, guidance, policies, or regulations. The ability to access data does not equate to the authority to access data. In particular, Users must not browse or search Fiscal Service data except in the performance of authorized duties.

RFQ-CIO-30110000-23-012

● Do not reveal any data processed or stored by Fiscal Service except as required by job responsibilities and within established procedures.

● Do not dial-in or remotely access Fiscal Service IT systems unless authorized to do so, such as an approved telework agreement authorizing remote access over the bureau’s VPN software.

● Do not install or use unauthorized software on Fiscal Service equipment.

● Retrieve all hard copy sensitive printouts in a timely manner.

● Take reasonable precautions to prevent unauthorized individuals from viewing screen contents or printed documents.

● Do not open e-mail attachments, or click links, from unknown or suspicious sources.

● Be responsible for all activities associated with their assigned user IDs, passwords, access tokens, identification badges, Personal Identity Verification cards, or other official identification device or method used to gain access to Fiscal Service data, equipment, IT systems, or facilities.

● Use only equipment and software provided by Fiscal Service or that has been approved for use by Fiscal Service’s CIO or designee to conduct Fiscal Service business.

● Comply with Fiscal Service social media policy, including restrictions on publishing Fiscal Service information to social media and public websites.

Follow these rules regarding access credentials:

● Protect passwords from improper disclosure. Do not reveal passwords, PINs, or other access credentials.

Password or PIN disclosure is considered a security violation and is to be reported as such.

● Do not share passwords with anyone else or use another person’s password or other access credential such as, but not limited to, someone else’s PIV card.

● Change passwords as required by expiration dates.

● Choose hard to guess, non-dictionary passwords that use a minimum of twelve alphanumeric characters containing at least one numeric character and two alpha characters, both UPPER and lower case, and include a special character.

ACCEPTANCE:

I have read the Fiscal Service Security Rules of Behavior and fully understand the security requirements. I further understand that violation of these rules may be grounds for legal and/or administrative action by the Fiscal Service and may result in actions up to and including disciplinary action, termination of access, termination of employment, contract termination, and/or prosecution under federal law.

User’s Name: (printed)

User’s Signature: (signature)

Date:

Attachment B - Bureau of the Fiscal Service (Fiscal Service) IT Rules of Behavior

File details come from the government source that posted it. Updated .