Attachment G Security Requirements.pdf

PDF 307 KB Posted

Attached to
RFP - Medical Evaluations and Services Federal contract opportunity
Solicitation number
15F06725R0000538
Issued by
Department of Justice Federal Bureau of Investigation

About this file

This document is a detailed General Security Requirements clause for a federal contract, primarily focused on information system security and cybersecurity protocols for contractors working with the FBI and Department of Justice (DOJ). The requirements cover comprehensive security measures including protecting confidentiality, integrity, and availability of government information, with strict guidelines on handling sensitive data, managing potential security incidents, and maintaining robust cybersecurity practices.

Key requirements include implementing NIST SP 800-171 security standards, protecting personally identifiable information (PII), conducting annual security awareness training, maintaining system security plans, reporting security incidents within one hour of discovery, encrypting sensitive data, limiting system access, performing continuous monitoring, and ensuring compliance with federal information security regulations. The document also outlines specific protocols for cloud computing systems, mandating FedRAMP authorization, providing DOJ access to information, and maintaining detailed security management processes. Contractors must adhere to these stringent security measures across all aspects of information handling, system design, personnel access, and incident response.

View the file

Other files for this federal contract opportunity

Other files attached to RFP - Medical Evaluations and Services, newest first.
File Type Posted
RFP_Medical Evaluations and Services Amendment 2 - 7JAN2026.pdf PDF
Attachment D Pricing Spreadsheet_Amend 3.xlsx XLSX spreadsheet
15F06725R0000538 - Fit for Duty - 7JAN2026 QandA.xlsx XLSX spreadsheet
FBI Clauses 11 and 5.pdf PDF
FD-900.pdf PDF
FD-1126.pdf PDF
FBI and DOJ Full Text Clauses.pdf PDF
FD-899.pdf PDF
FD-1065.pdf PDF
FD-1093A.pdf PDF
FD-1093.pdf PDF
FD-1065a.pdf PDF
FD-967.pdf PDF
Attachment D Pricing Spreadsheet_Amend 2.xlsx XLSX spreadsheet
15F06725R0000538 - Med Eval and Serv - Responses - Amend 2.xlsx XLSX spreadsheet
Attachment D Pricing Spreadsheet_Amend 1.xlsx XLSX spreadsheet
Attachment F SF-33 Amend 1.pdf PDF
RFP_Medical Evaluations and Services Amendment 1 - 22DEC2025.pdf PDF
Attachment C Past Performance Information Sheet.docx DOCX document
Attachment A Statement of Work_Amend 1.pdf PDF
Attachment E Location_Services.xlsx XLSX spreadsheet
RFP_Medical Evaluations and Services.pdf PDF
Attachment B Question and Answers Template.xlsx XLSX spreadsheet
Attachment H Color Vision Instructions.pdf PDF
Attachment D Pricing Spreadsheet.xlsx XLSX spreadsheet
Attachment A Statement of Work.pdf PDF
Attachment C Past Performance Information Sheet.docx DOCX document
Attachment E Location_Services.xlsx XLSX spreadsheet
Attachment F SF33.pdf PDF
Show all 29

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

General Security Requirements General

The contractor shall perform in accordance with the Federal Information Processing Standards Publication (FIPS) 199, Standards for Security Categorization of federal Information and Information Systems, the Contractor (and / or any subcontract shall protect Government information to ensure:

• Confidentiality: preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity: guarding against improper information modification or destruction, and ensuring information non- repudiation and authenticity;

• Availability: ensuring timely and reliable access to and use of information Security for any Contractor systems, and information contained therein, operated by the Contractor on behalf of the FBI regardless of location.

In addition, if new or unanticipated threats or hazards are discovered by either the agency or the Contractor, and existing safeguards have ceased to function, the discovery shall be immediately reported within one (1) hour or less, bringing the situation to the attention of the other party. The Contractor shall ensure PPN does not store any government identification, including Socia Security Number and driver’s license.

The contractor shall store Information as it is or may be sensitive because it requires security to protect its confidentiality, integrity, and / or availability. The Contractor shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M- 06-16, Protection of Sensitive Agency Information by security with a FIPS 140-2 validated solution.

The contractor shall store any information provided to the Contractor by FBI or collected by the Contractor on behalf of FBI shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom FBI records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontract can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with FBI and other applicable policies.

Unauthorized disclosure of information shall be subject to the following laws and regulations: 18 USC 641 (Criminal Code: Public Money, Property or Record)

18 USC 1905 (Criminal Code: Disclosure of Confidential Information); and44 USC, Chapter 35, Subchapter I (Paperwork Reduction Act)

The contractor shall perform all procurements using Internet Protocol and shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPV6). The contractor shall adhere to any new versions as applicable.

The contractor shall perform All new and existing public-facing government websites that shall be configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to always assume HTTPS to reduce the number of in security redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal- facing websites, the HTTPS is not required, but it is highly recommended.

The contractor shall perform If using encryption, the Contractor shall:

Comply with the FBI Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information. Encrypt all sensitive federal data and information (i.e., Personally Identifiable Information (PII), protected health information (PHI), proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile device, backup media, etc.) with FIPS 140-2 validated encryption solution. Secure all devices (i.e. desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet FBI-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computer, and other mobile devices and portable media that store or process sensitive government information (including PII).

Verify that the encryption solutions in use have been validated under the

Cryptographic Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validated documentation to the COR upon request.

The contractor shall assist The FBI in developing a process by which medical examination and laboratory information is received electronically. To support this effort, the Contractor may be called upon by FBI to conduct the Privacy Threshold Analysis (PTA) for the information system and / or information handled under this contract to determine whether a full Privacy Impact Assessment (PIA) needs to be completed.

If the results of the PTA show that a full PIA is needed, the Contractor shall assist with completing a PIA for the system or information after completion of the PTA and in accordance with FBI policy and OMB M-03- 22, Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002.

The Contractor shall assist in reviewing the PIA at least every three (3) years throughout the system development lifecycle (SDLC) / information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.

The contractor shall protect against privacy incidents. Federal Information Security Modernization Act (FISMA) defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by FISMA as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for “other than an authorized purpose”. In the event of a suspected or confirmed incident or breach, the Contractor (and / or any subcontractor) shall:

Protect all sensitive information, including any PII created, stored, or transmitted in performance of this contract to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption. NOT notify affected individuals unless so instructed by the Contracting Officer (CO) or COR. If instructed by the CO or COR, the Contractor shall send FBI recommended notifications to affected individuals for approval. Report all suspected and confirmed information security and privacy incidents, including incidents involving PII and / or breaches, in any medium or form (paper, oral, or electronic), no later than one (1) hour from the time of incident to the COR, CO (or their designee) no later than one (1) hour from the time of incident. This reporting is consistent with the applicable FBI and DOJ policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report shall include at a minimum; company and point of contact information, contract /task order identification information, impact classifications /threat vector, and the type of information compromised. In addition, the Contractor shall: cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach does not include any sensitive information in the subject or body of any reporting e- mail; and encrypt sensitive information in attachments to email, media, etc.

Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks, or applying additional security controls. This may also involve physical access to contractor facilities during a breach / incident investigation.

The contractor shall follow and adhere to NIST SP 800-64, Security Considerations in the SDLC, at a minimum for system development and provide system documentation at designated intervals (specifically at the expiration of the contract) within the enterprise life cycle (EPLC) that require artifact review and approval.

The contractor shall perform as part of contract closeout and at expiration of the contract, the Contractor shall provide all required documentation to the COR to certify that, at the government’s discretion, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

The contractor shall maintain all information in accordance with Executive Order 13556 – Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and FBI policies and shall destroy records ninety (90) days after date of delivery appointment unless authorized in writing by the COR.

The contractor shall treat all records containing employee medical information as confidential and maintain them in accordance with 5 U.S.C. 552a and the Privacy Act of 1974. HHSAR Subpart

324.70 – Health Insurance Portability and Accountability Act of 1996 (HIPPA) is applicable to this requirement. As such, the Contractor shall be HIPAA compliant in accordance with this subpart and 45 CFR 160 and 164 as applicable.

The contractor shall perform subject to the Privacy Act of 1974, because it provides for the design, development, or operation of a system of records on individuals.

The contractor shall perform including, all Providers, Practitioners and staff who have direct contact with FBI employees or applicants and are responsible for securely storing the medical files, shall be subject to an FBI security check (National Agency Check) or Limited Escorted Access request (LAR) (depending on the required level of facility access required), as described below:

For individuals requiring access to FBI facilities, creating or reviewing FBI medical records, performing on-site services at FBI locations and/or storing medical files, a Limited Escorted

Access Requests (LAR) is required, which includes a National Agency Check with Local Agency Checks (NCLAC), interviews, completion of an SF-85, fingerprints and a credit check. This shall be completed by the FBI at the provider’s location or the local FBI field office as directed. Each member of the Contractor’s direct staff, new provider or office personnel shall complete the LAR prior to being responsible for securely storing, medical files for FBI employees and applicants.

The FBI will process the FBI security check and/or LAR at no cost to the Contractor. The Contractor shall comply with the FBI security check and/or LAR process described in the contract. If the Contractor’s provider has not been cleared and is unable or unwilling to participate in the FBI security check and/or LAR, the Contractor shall locate another clinic willing to undergo the background investigation process.

PPN clinics shall have at least one (1) designated employee cleared (LAR with fingerprints) to access FBI employee medical records. Appointments for FBI employees shall be scheduled to correspond to the availability of the authorized designated office personnel and examining provider.

All medical documents for FBI employees at PPN clinics shall be maintained on paper. until an electronic system is approved. These documents shall be maintained in a secure, locked filing cabinet or locked room, separate from other medical files and with access restricted to cleared individuals only for the temporary period between service completion and return to the Contractor.

No paper originals or copies are to be permanently stored at any provider locations longer than thirty (30) days past the appointment. Use of electronic medical records by PPN clinics are prohibited unless otherwise pre - approved, in writing by the COR. The Contractor shall not photocopy, or in any way retain, any identification documents belonging to FBI personnel, including, but not limited to FBI documents, or personal driver licenses. The Contractor shall not use PII. The Contractor shall utilize a designated FBI office address on all records.

G.1.1 Personnel / Physical Security Requirements

All individuals performing work on this contract shall be processed for a limited escorted access request (LAR). LARs are for uncleared personnel who require routine and recurring escorted access to FBI facilities or space who are properly vetted. LARs are also used to vet uncleared personnel needing access to information up to the UNCLASSIFED//Law Enforcement Sensitive (LES) designation. In this case the individuals that will have access to FBI applicants or employees’ personal information.

Required forms to be completed (once all are submitted, known to OSO-QT, as a LAR package):

• Standard Form (SF) – 85, “Questionnaire for Non-Sensitive Positions, including the accompanying “Authorization for Release of Information”

• FD-857a, “Non-Sensitive Information Nondisclosure Agreement”.

• Fingerprints, FD-258, Applicant Fingerprint Card (this will be used to place a stop). This process may or may not require the candidates to be fingerprinted. If so, the candidates shall be printed at the nearest FBI office at the requested date/time.

The LAR packages are processed by Security, for each individual submission and an escorted access determination is made as to whether an individual poses any risk to the FBI if allowed limited escorted access. FBI Security must evaluate everyone independently and make final determinations that are consistent with the interests and needs of the FBI.

G.1.2 Information Security

The FBI intends to transition from paper-based to electronic processing of medical orders and results. The contractor shall support either. When using paper-based, the Contractor shall follow all processing, handling, shipping, and storage of information per provided requirements. Any loss of data shall be considered a security incident and require immediate notification to FBI COR and designated contacts. FedRAMP certification is strongly urged.

The precise system requirements for the Contractor shall vary depending if the awardee’s system has been deemed as federal or non-federal. The Contractor shall support the authorization to operate (ATO) or authorization to use (ATU). The Contractor shall follow the following standards/policies as deemed appropriate by the FBI as applicable to the Contractor's federal or non-federal systems:

• NIST.SP 800-171R3

• NIST.SP 800-53R5

• DOJ 05

• DOJ Order 904

• DOJ SAA Appendix C

• Security of Department Information and Systems DOJ-05 (OCT 2023)

The FBI has sole discretion of the process, and may determine internal systems or processes are capable, if in the best interest of the government.

Security of Department Information and Systems DOJ-05 (OCT 2023)

I. Applicability to Contractors and Subcontractors Section 2839.102 of the Justice Acquisition Regulation (JAR), (48 C.F.R. § 2839.102), applies to this contract. Accordingly, all contractors are obligated to comply with all applicable DOJ security policies, directives, or guidance documents, including the security requirements in the provisions in this contract clause. This contract clause applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of the contractors and subcontractors (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information. The security requirements set forth herein are in addition to those required by the Federal Acquisition Regulation (“FAR”), and any other applicable laws, mandates, contract clauses, DOJ policies, directives or guidance documents and Executive Orders pertaining to the development and operation of Information Systems and/or the protection of Government Information. This clause does not alter or diminish any existing rights, obligations, or liability under any other civil and/or criminal law, rule, regulation, or mandate.

II. General Definitions The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.

A. Authorization to Operate (“ATO”), as defined in National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-37 Revision 2, is the official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls.

B. Cloud Computing, as defined in DOJ Order 0904 Cybersecurity Program, is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

This cloud model is composed of five essential characteristics, three service models, and four deployment models in accordance with NIST SP 800-145.

C. Covered Contract is any contract, order or other agreement under which the contractor, or a subcontractor at any tier, including a cloud service provider, may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information (as defined below) in the course of providing a product or service to the Department, with the exception of acquisitions under the micro-purchase threshold.

D. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information under a Covered Contract.

E. Data means recorded information, regardless of form or the media on which it may be recorded. The term includes technical data, computer software, and personally identifiable information (PII) (defined below). The term does not include information incidental to contract administration, such as financial, administrative, cost or pricing, or management information.

F. DOJ Information, as defined in DOJ Order 0904, means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by the Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired to perform the contract.

G. Information, as defined in DOJ Order 0904, is any communication or representation of knowledge such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. This includes any communication or representation of knowledge in an electronic format that allows it to be stored, retrieved, or transmitted.

H. Information System, means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502(8)).

I. Personally Identifiable Information (“PII”), as defined in the FAR 24.101, means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. It includes but is not limited to common data elements such as names, addresses, dates of birth, and places of employment, to identity documents, Social Security numbers or other government-issued identifiers, precise location information, medical history, and biometric records. This definition covers all PII that is created by or becomes available to the contractor, including its employees, subcontractors, or affiliates, as a result of performing under this contract. PII, as supplementally defined in DOJ Order 0904, also includes information about an individual maintained by an agency, including, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and information, which can be used to distinguish or trace an individual’s identity.

J. Private Cloud, as defined in NIST SP 800-145, is the deployment model for cloud infrastructure provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off premises.

K. Security Breach means any security incident (as defined below) that directly relates to the loss of control, compromise, exfiltration, manipulation, unauthorized disclosure, unauthorized acquisition, unauthorized exposure or unauthorized access or any similar occurrence of any Covered Information System or any DOJ Information or any PII accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system. This includes incidents where (1) a person other than an authorized user accesses or potentially accesses PII or DOJ Information or (2) an authorized user accesses or potentially accesses PII or DOJ Information for an unauthorized purpose.

a. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed security breach (as defined above).

b. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed security breach (as defined above).

L. Security Incident means any occurrence that (1) may actually or imminently jeopardize, without lawful authority, the availability, integrity, authentication, confidentiality, or nonrepudiation of DOJ Information or a Covered Information System; or (2) may constitute a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

a. Potential Security Incident means any suspected, but unconfirmed security incident (as defined above).

b. Confirmed Security Incident means any confirmed security incident (as defined above).

M. Vulnerability, as defined in DOJ Vulnerability Management Plan, and the OCIO Information Security Management Procedure, means a weakness or flaw discovered in the design of a system that, when exploited, may result in a loss of confidentially, integrity, or availability of DOJ Information or an Information System.

III. Confidentiality and Non-Disclosure of DOJ Information A. Preliminary and final contract deliverables and all associated working papers and material generated by the Contractor developed using DOJ Information, product, source code, and/or methods of operations, are the property of the U.S. Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Representative (“COR”) at the conclusion of the contract. The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14 (Rights in Data-General). The Contractor will define a method of monitoring the development activity to include any activity associated with DOJ Information, product, source code, and methods of operations. The data rights and development details shall be defined within the Contract.

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf

If the Contractor intends to utilize its existing data, for which it has a patent or copyright, to develop a contract deliverable, it is incumbent upon the Contractor to negotiate with the CO the proper FAR Part 27 clauses in the contract to protect its existing data.

B. Pursuant to FAR 52.227-14(d)(2), all documents and data produced in the performance of this contract containing DOJ Information, product code, source code, and/or methods of operations are the property of the U.S. Government and, without the prior written permission of the CO, the Contractor shall neither reproduce nor release such information to any third-party at any time, including during performance or following expiration and/or termination of the contract.

C. Any DOJ Information made available to the Contractor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, the Contractor assumes responsibility for the protection of the confidentiality of all DOJ Information processed, stored, or transmitted by the Contractor. The Contractor shall comply with information security responsibilities and duties throughout the contract and after expiration/termination as appropriate per contract close-out activities. When requested by the CO (typically no more than annually), the Contractor shall provide a report to the CO identifying, to the best of the Contractor’s knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed, stored, or transmitted under the Contract, including an estimate of the number of individuals for whom PII has been processed, stored or transmitted under the Contract and whether such information includes social security numbers (in whole or in part).

Background

Section 2839.102 of the Justice Acquisition Regulation (JAR), (48 C.F.R. § 2839.102), , Management of risk, requires contracts involving DOJ Information and Information Systems to comply with the security requirements prescribed in FAR 39.102 and all applicable DOJ security requirements, including without limitation all DOJ Policy Statements and DOJ Policy Instructions established under the DOJ Acquisition Management Order relating to the Management of Risk of DOJ (FBI) Information and Information Systems when residing on or transiting through a contractor’s/subcontractor’s internal information system or network, and to report cyber incidents that affect that system or network to FBI. The “DOJ Security and Privacy Assessment and Authorization Handbook Appendix C – Authorization to Use Plan – Nonfederal Organizations”, hereto referred to, for the purposes of this methodology as “Appendix C” further states that to provide adequate security, the Contractor shall implement, at a minimum, the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations”.[1] Contractors are also required to flow down Appendix C to all subcontracts for operationally critical support, or for which subcontract performance will involve FBI Information. Contractors must mark or otherwise identify, in accordance with direction contained within the specific contract, FBI Information that is collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of performance of the contract.

https://dojfbi-my.sharepoint.us/personal/rtshifflet_fbi_gov/Documents/R.%20Shifflet%20Contracts/QTC/Recompete/RFP_Medical%20Evaluations%20and%20Services%20v2.docx#_ftn1

The FBI, requires, among other things, offerors to represent they will implement the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. To document implementation of NIST SP 800-171, the contractor must develop, document, and periodically update a system security plan that describes system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. If implementation of the security requirements is not complete, companies must develop and implement plans of action to describe when and how any unimplemented security requirements will be met.

(On-Site or Virtual) NIST SP 800-171 FBI Assessment

1. The Assessment, conducted by FBI personnel who have been trained in accordance with FBI policy and procedures to conduct the assessment, requires a thorough on-site or virtual /examination/demonstration of the Contractor’s system security plan and implementation of the NIST SP 800-171 security requirements.

2. The Assessment is conducted using NIST SP 800-171A, “Assessing Security Requirements for Controlled Unclassified Information.” The assessment will determine if the implementation meets the requirements by reviewing appropriate evidence and/or demonstration (e.g., recent scanning results, system inventories, configuration baselines, demonstration of multifactor authentication).

3. An on-site NIST SP 800-171 FBI Assessment is the preferred methodology for a full evaluation of the risk to FBI Information because of the ability to verify and validate the effectiveness of the safeguards that implement security requirements defined in NIST Special Publication 800-171. While a Assessment maybe be conducted virtually in lieu of onsite, a virtual assessment will not fully cover all the NIST SP 800-171 requirements, resulting in a less than full understanding of overall risk.

4. A virtual Assessment utilizes the same methodology as the on-site with added data protections processes enacted to protect the data that is shared with assessment teams.

All data is transmitted through FBI Teleporter, is uploaded to the DOJ Governance, Risk, and Compliance (GRC) repository and made available only to the Information System Security Officer (ISSO) and Information System Security Manager (ISSM) assigned to the system, the Authorizing Official and their Designated Representative. With concurrence from the companies being assessed, the assessment verifies and examines all documents utilizing the NIST SP 800-171A methodology minus the demonstration or testing of some requirements. In some cases, a follow-up on-site assessment of the items not assessed may be required or requested.

The contractor shall complete the attached workbook in Annex B and submit results along with a System Security Plan to the FBI. The Assessment consists of a review of the workbook, a thorough document review and discussion with the contractor regarding the results to obtain additional information or clarification as needed, combined with government validation that the security requirements have been implemented as described in the system security plan. Network access by FBI personnel is not required.

Annex B - (Contractor Self-Assessment) NIST SP 800-171 FBI Assessment Results Format

• Score implementation of the security requirements in NIST SP 800-171 based on Section 5 and Annex A of this document.

• Document (self) NIST SP 800-171 FBI Assessment score and deliver via email to the Contracting Officer.

• Information required for results include:

o Date of the assessment o Summary level score (e.g., 95 out of 110, NOT the individual value for each requirement) o Scope of the Basic Assessment - Identify each system security plan (security requirement 3.12.4) supporting the performance of this contract. Additionally, a brief description of the plan architecture may be required, if more than one plan exists.

o Plan of Action Completion Date – date that a score of 110 is expected to be achieved for each system security plan assessed (i.e., all requirements implemented) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171 (security requirement 3.12.2).

NIST SP 800-171 FBI Assessment Scoring Template

Security Requirement Value Comment

3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

3.1.2 Limit system access to the types of

transactions and functions that authorized users are permitted to execute.

3.1.3 Control the flow of FBI Information in

accordance with approved authorizations.

3.1.4 Separate the duties of individuals to reduce

the risk of malevolent activity without collusion.

3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts.

3.1.6 Use non-privileged accounts or roles when

accessing non-security functions.

3.1.7 Prevent non-privileged users from executing

privileged functions and capture the execution of such functions in audit logs.

3.1.8 Limit unsuccessful logon attempts. 1

3.1.9 Provide privacy and security notices consistent

with applicable FBI Information rules.

3.1.10 Use session lock with pattern-hiding displays

to prevent access and viewing of data after a period of inactivity.

3.1.11 Terminate (automatically) a user session after

a defined condition.

3.1.12 Monitor and control remote access sessions. 5 Do not subtract points if remote access not permitted

3.1.13 Employ cryptographic mechanisms to protect

the confidentiality of remote access sessions.

5 Do not subtract points if remote access not permitted

3.1.14 Route remote access via managed access

control points.

3.1.15 Authorize remote execution of privileged

commands and remote access to security relevant information.

3.1.16 Authorize wireless access prior to allowing

such connections.

5 Do not subtract points if wireless access not permitted

3.1.17 Protect wireless access using authentication

and encryption.

5 Do not subtract points if wireless access not permitted

3.1.18 Control connection of mobile devices. 5 Do not subtract points if connection of mobile devices is not permitted

3.1.19 Encrypt FBI Information on mobile devices and

mobile computing platforms

3 Exposure limited to FBI Information on mobile platform

3.1.20 Verify and control/limit connections to and use

of external systems.

3.1.21 Limit use of portable storage devices on

external systems.

3.1.22 Control FBI Information posted or processed

on publicly accessible systems.

3.2.1 Ensure that managers, systems

administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

3.2.2 Ensure that personnel are trained to carry out

their assigned information security related duties and responsibilities.

3.2.3 Provide security awareness training on

recognizing and reporting potential indicators of insider threat.

3.3.1 Create and retain system audit logs and

records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

3.3.2 Ensure that the actions of individual system

users can be uniquely traced to those users so they can be held accountable for their actions.

3.3.3 Review and update logged events. 1

3.3.4 Alert in the event of an audit logging process

failure.

3.3.5 Correlate audit record review, analysis, and

reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

3.3.6 Provide audit record reduction and report

generation to support on-demand analysis and reporting.

3.3.7 Provide a system capability that compares

and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

3.3.8 Protect audit information and audit logging

tools from unauthorized access, modification, and deletion.

3.3.9 Limit management of audit logging

functionality to a subset of privileged users.

3.4.1 Establish and maintain baseline

configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.

3.4.2 Establish and enforce security configuration

settings for information technology products employed in organizational systems.

3.4.3 Track, review, approve or disapprove, and log

changes to organizational systems.

3.4.4 Analyze the security impact of changes prior

to implementation.

3.4.5 Define, document, approve, and enforce

physical and logical access restrictions associated with changes to organizational systems.

3.4.6 Employ the principle of least functionality by

configuring organizational systems to provide only essential capabilities.

3.4.7 Restrict, disable, or prevent the use of

nonessential programs, functions, ports, protocols, and services.

3.4.8 Apply deny-by-exception (blacklisting) policy

to prevent the use of unauthorized software or deny-all, permit-by-exception

(whitelisting) policy to allow the execution of authorized software.

3.4.9 Control and monitor user-installed software. 1

3.5.1 Identify system users, processes acting on

behalf of users, and devices.

3.5.2 Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.

3.5.3 Use multifactor authentication (MFA) for local

and network access to privileged accounts and for network access to nonprivileged accounts.

3 to 5 Subtract 5 points if MFA not implemented. Subtract 3 points if implemented for remote and privileged users, but not the general user

3.5.4 Employ replay-resistant authentication

mechanisms for network access to privileged and non-privileged accounts.

3.5.5 Prevent reuse of identifiers for a defined

period.

3.5.6 Disable identifiers after a defined period of

inactivity.

3.5.7 Enforce a minimum password complexity and

change of characters when new passwords are created.

3.5.8 Prohibit password reuse for a specified

number of generations.

3.5.9 Allow temporary password use for system

logons with an immediate change to a permanent password.

3.5.10 Store and transmit only cryptographically

protected passwords.

5 Encrypted representations of passwords include, for example, encrypted versions of passwords and one-way cryptographic hashes of passwords

3.5.11 Obscure feedback of authentication

information.

3.6.1 Establish an operational incident-handling

capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

3.6.2 Track, document, and report incidents to

designated officials and/or authorities both internal and external to the organization.

3.6.3 Test the organizational incident response

capability.

3.7.1 Perform maintenance on organizational

systems.

3.7.2 Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

3.7.3 Ensure equipment removed for off-site

maintenance is sanitized of any FBI Information.

3.7.4 Check media containing diagnostic and test

programs for malicious code before the media are used in organizational systems.

3.7.5 Require multifactor authentication to

establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.

3.7.6 Supervise the maintenance activities of

maintenance personnel without required access authorization.

3.8.1 Protect (i.e., physically control and securely

store) system media containing FBI Information, both paper and digital.

3 Exposure limited to FBI Information on media

3.8.2 Limit access to FBI Information on system

media to authorized users.

3 Exposure limited to FBI Information on media

3.8.3 Sanitize or destroy system media containing

FBI Information before disposal or release for reuse.

5 While exposure limited to FBI Information on media, failure to sanitize can result in continual exposure of FBI Information

3.8.4 Mark media with necessary FBI Information

markings and distribution limitations.

3.8.5 Control access to media containing FBI

Information and maintain accountability for media during transport outside of controlled areas.

3.8.6 Implement cryptographic mechanisms to

protect the confidentiality of FBI Information stored on digital media during transport unless otherwise protected by alternative physical safeguards.

3.8.7 Control the use of removable media on system

components.

3.8.8 Prohibit the use of portable storage devices

when such devices have no identifiable owner.

3.8.9 Protect the confidentiality of backup FBI

Information at storage locations.

3.9.1 Screen individuals prior to authorizing access

to organizational systems containing FBI Information.

3.9.2 Ensure that organizational systems containing

FBI Information are protected during and after personnel actions such as terminations and transfers.

3.10.1 Limit physical access to organizational

systems, equipment, and the respective operating environments to authorized individuals.

3.10.2 Protect and monitor the physical facility and

support infrastructure for organizational systems.

3.10.3 Escort visitors and monitor visitor activity. 1

3.10.4 Maintain audit logs of physical access. 1

3.10.5 Control and manage physical access devices. 1

3.10.6 Enforce safeguarding measures for FBI

Information at alternate work sites.

3.11.1 Periodically assess the risk to organizational

operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of FBI Information.

3.11.2 Scan for vulnerabilities in organizational

systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

3.11.3 Remediate vulnerabilities in accordance with

risk assessments.

3.12.1 Periodically assess the security controls in

organizational systems to determine if the controls are effective in their application.

3.12.2 Develop and implement plans of action

designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

3.12.3 Monitor security controls on an ongoing basis

to ensure the continued effectiveness of the controls.

3.12.4 Develop, document, and periodically update

system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

NA The absence of a system security plan would result in a finding that ‘an assessment could not be completed due to incomplete information and noncompliance with Appendix C.’

3.13.1 Monitor, control, and protect communications

(i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.

3.13.2 Employ architectural designs, software

development techniques, and systems engineering principles that promote effective information security within organizational systems.

3.13.3 Separate user functionality from system

management functionality.

3.13.4 Prevent unauthorized and unintended

information transfer via shared system resources.

3.13.5 Implement subnetworks for publicly

accessible system components that are physically or logically separated from internal networks.

3.13.6 Deny network communications traffic by

default and allow network communications traffic by exception (i.e., deny all, permit by exception).

3.13.7 Prevent remote devices from simultaneously

establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).

3.13.8 Implement cryptographic mechanisms to

prevent unauthorized disclosure of FBI Information during transmission unless otherwise protected by alternative physical safeguards.

3.13.9 Terminate network connections associated

with communications sessions at the end of the sessions or after a defined period of inactivity.

3.13.10 Establish and manage cryptographic keys for

cryptography employed in organizational systems.

3.13.11 Employ FIPS-validated cryptography when

used to protect the confidentiality of FBI Information.

3 to 5 Subtract 5 points if no cryptography is employed; 3 points if mostly not FIPS validated

3.13.12 Prohibit remote activation of collaborative

computing devices and provide indication of devices in use to users present at the device.

3.13.13 Control and monitor the use of mobile code. 1

3.13.14 Control and monitor the use of Voice over

Internet Protocol (VoIP) technologies.

3.13.15 Protect the authenticity of communications

sessions.

3.13.16 Protect the confidentiality of FBI Information at

rest.

3.14.1 Identify, report, and correct system flaws in a

timely manner.

3.14.2 Provide protection from malicious code at

designated locations within organizational systems.

3.14.3 Monitor system security alerts and advisories

and take action in response.

3.14.4 Update malicious code protection

mechanisms when new releases are available.

3.14.5 Perform periodic scans of organizational

systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

3.14.6 Monitor organizational systems, including

inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

3.14.7 Identify unauthorized use of organizational

systems

[1] The DOJ does not officially recognize CUI; FBI Unclassified information and any dissemination controls will be considered in its place.

https://dojfbi-my.sharepoint.us/personal/rtshifflet_fbi_gov/Documents/R.%20Shifflet%20Contracts/QTC/Recompete/RFP_Medical%20Evaluations%20and%20Services%20v2.docx#_ftnref1

IV. Compliance with Information Technology Security Policies, Procedures and Requirements

A. For all Covered Information Systems, in addition to any other applicable requirements, as set forth in Part I, the Contractor shall comply with the security requirements of the Federal Information Security Modernization Act of 2014 (“FISMA”), Privacy Act of 1974, E-Government Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, 199, and 200, Federal Risk and Authorization Management Program (“FedRAMP”), DOJ IT Security Standards as amended, and OMB Memoranda relating to the security of information and/or Federal Information Systems.

B. In addition, for all Covered Information Systems, the Contractor shall comply with the following requirements, which are listed here only to highlight certain specific applicable requirements from one of the sources identified in the first paragraph of this Section. This is not an exhaustive list of all such requirements with which the Contractor is obligated to comply, and the omission of a requirement from this list should not be construed as negating the materiality of that requirement. These requirements and those in the authorities in the prior paragraph should be read together.

1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise.

2. Providing security awareness training at least annually to all Contractor employees and contractors involved with the Covered Contract. Such training shall include, but not be limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information Systems.

3. Creating, protecting, and retaining, in accordance with applicable requirements but in any event at least until the expiration of the contract, Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information.

4. Maintaining authorizations to operate any Covered Information System.

5. Performing continuous monitoring on all Covered Information Systems, to include but not be limited to, collecting, reviewing, and analyzing appropriate logs and timely investigating security alerts and potential security incidents.

6. Establishing and maintaining baseline configurations and current inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Covered Information Systems.

7. Ensuring appropriate contingency planning has been performed, including DOJ Information and Covered Information System backups.

8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .