B02 RFQ STRATUS Pool 2 Attachment B - Security Requirements.pdf
PDF 282 KB Posted
- Attached to
- USDA STRATUS Cloud Basic Ordering Agreement (BOA) Pool 2: Integration and Development Federal contract opportunity
- Solicitation number
- 12314423Q0143
About this file
This document outlines security requirements for the United States Department of Agriculture (USDA) STRATUS Cloud Basic Ordering Agreement (BOA) Pool 2 for Integration and Development Support Services. Vendors under the BOA must establish and maintain a security program per the Federal Risk Authorization Management Program (FedRAMP) and Cloud Security and Privacy Requirements. Vendors must comply with NIST SP 800-53 security controls, continuous monitoring, controlled unclassified information handling procedures, and physical/logical separation of tenant environments. The agreement also specifies responsibilities for authorized assessment and evaluation entities from government agencies to conduct security assessments, and responsibilities for USDA ordering entities and vendors related to assessment findings and cyber incident reporting.
View the file
Other files for this federal contract opportunity
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION NO. 12314423Q0143
STRATUS CLOUD BASIC ORDERING AGREEMENT
POOL 2: INTEGRATION AND DEVELOPMENT SUPPORT SERVICES
ATTACHMENT B
SECURITY REQUIREMENTS
Attachment B: Security Requirements
B.1. USDA STRATUS Blanket Ordering Agreement (BOA) Security Requirements – Pool 2
The Contractor shall establish and maintain a security program and security controls per Federal Risk
Authorization Management Program (FedRAMP) and Cloud Security and Privacy Requirements as specified as well as compliance with current Federal and United States Department of Agriculture (USDA) policies and directives.
B.1.1 Definitions
B.1.1.1 Authorization and Evaluation Entity ‐ An authorized assessment and evaluation entity is an explicitly identified government entity under this BOA, that is authorized to conduct and perform independent assessments and evaluations leveraging best practices and guidelines established by NIST and commercial standards.
a) United States Federal Government ‐ The following US Federal Government agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:
Cybersecurity and Infrastructure Security Agency (CISA)
Government Accounting Office (GAO)
National Security Agency (NSA) / Central Security Service (CSS)
Office of the Director of National Intelligence (ODNI)
b) United States Department of Defense ‐ The following DoD agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:
Director Operational Test & Evaluation (DOT&E)
Marine Corps Forces Cyberspace Command Sixteenth Air Force (AFCYBER)
US Army Cyber Command (ARCYBER)
US Cyber Command (USCC) 157
US Fleet Cyber Command
Department of Defense Cloud Authorization Services (DCAS)
c) United States Department of Agriculture (USDA) – The following USDA agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:
Office of the Chief Information Officer (OCIO)
Digital Infrastructure Service Center (DISC)
B.1.1.2 Authorized Vendor ‐ An authorized vendor is an entity that has been awarded a USDA BOA award by the BOA Administering function. An authorized vendor can be a Pool 1 – Cloud Service Provider (CSP); Pool 2 – Application Developer (AppDev), Operations & Maintenance (O&M), and/or System Integrator (SI); and/or Pool 3 – Software as a Service (SaaS) provider.
Cloud Service Provider (CSP) ‐ A CSP is an entity that directly operates and manages the cloud services (i.e., IaaS, PaaS, SaaS, etc.) technology (e.g., facility, hardware, software).
B.1.2 Responsibilities
B.1.2.1 Authorized Assessment and Evaluation Entity Responsibilities – Authorization and Evaluation Entities as defined in Section 0 have the following responsibilities as related to all USDA Stratus Pool 2 Task Orders:
a) Cybersecurity Assessments and Evaluations ‐ Authorized assessment and evaluation entities are responsible for conducting and performing announced and unannounced independent cybersecurity (e.g., OCIO, DISC, etc.) and operational (e.g., performance, SLAs) assessments and evaluations (e.g., OT&E) of the cloud services (i.e., IaaS, PaaS, SaaS, etc.)
architectures (e.g., compute, networking, storage) and security domains involved in the processing, transporting, and / or storing authorized ordering entities data.
b) Coordination ‐ Authorized assessment and evaluation entities are responsible for coordinating assessment and evaluation activities with the authorized vendors.
Coordination responsibilities shall include planning, execution, and post assessment and evaluation activities (e.g., remediations, Plan of Actions and Milestones (POA&Ms).
c) Cost ‐ Authorized assessment and evaluation entities are responsible for their assessment and evaluation costs.
d) Findings and Recommendations ‐ Authorized assessment and evaluation entities are responsible for documenting the assessment and evaluation findings and recommendations (e.g., reports).
e) Communication and Distribution ‐ Authorized assessment and evaluation entities are responsible for communicating and distributing the assessment and evaluation findings and recommendations to the following:
BOA Contracting Officer (CO)
Task Order Contracting Officer Representative (TO COR)
Authorized assessment and evaluation entities (e.g., OCIO, DISC, etc.)
Assessed and evaluated authorized vendor(s)
B.1.2.2. USDA Authorized Ordering Entity (Mission Owners) – Authorized Ordering Entities have the following responsibilities as related to all USDA Stratus Pool 2 Task Orders:
a) Cybersecurity Assessments and Evaluations
Findings and Recommendations ‐ Authorized ordering entities are responsible for receiving and reviewing authorized assessment and evaluation entities' assessment and evaluation findings and recommendations (e.g., reports).
Suspension and Termination of Task Order(s) ‐ Authorized ordering entities are responsible for evaluating and determining if the findings and recommendations of an assessment and evaluation warrants the suspension or termination (i.e., termination for cause, termination for convenience) of a TO(s) awarded under this BOA.
USDA Authorization Management Program Reporting ‐ Authorized USDA ordering entities are responsible for reporting and submitting issued ATO(s) to USDA OCIO and FedRAMP.
Authorized USDA ordering entities are responsible for reporting and submitting any ATO Assessment & Authorization (A&A) identified inconsistencies (i.e., with FedRAMP authorization, with USDA OCIO authorization), concerns, or issues to OCIO and FedRAMP.
Cybersecurity Incident Reporting ‐ Authorized USDA ordering entities are responsible for reporting of cybersecurity incidents to the BOA Contracting Officer and to their TO(s) authorized vendors to ensure the authorized vendor can take appropriate mitigation actions.
B.1.2.3 Authorized Vendor – Pool 2 Vendors
b) Coordination ‐ Authorized vendors shall be responsible for coordinating assessment and evaluation activities with the authorized assessment and evaluation entities. Coordination responsibilities shall include planning, execution, and post assessment and evaluation activities (e.g., remediations, POA&Ms).
c) Findings and Recommendations ‐ Authorized vendors shall be responsible for receiving and reviewing authorized assessment and evaluation entities' assessment and evaluation findings and recommendations (e.g., reports).
d) Mitigation and Remediation ‐ Authorized vendors shall be responsible for evaluating, determining, and executing the appropriate mitigation and remediation activities (e.g., fixes, patches, updates) in response to the findings and recommendations of an assessment and evaluation. Findings shall be remediated within established USDA timeframes; 15 days for Critical, and 30 days for all others.
e) Public Disclosure and Release ‐ Authorized vendors shall be responsible for reviewing the written notifications from authorized assessment and evaluation entities including the provided unclassified versions of the assessment and evaluation findings and recommendations and timely reply, within 30 calendar days, to the authorized assessment and evaluation entities of any concerns or objections to the public disclosure or release.
B.1.2.4 Cybersecurity Authorization to Operate (ATO)
a) Notification of Terms and Conditions Discrepancies ‐ Authorized vendors shall be responsible for immediately notifying the BOA Contracting Officer when a conflict, discrepancy, or issue is identified between the applicable laws, regulations, policies, and Terms & Conditions of the US, USDA STRATUS BOA, or their TO(s).
b) Performance Conflict Elevation ‐ Authorized vendors shall be responsible for elevating unresolvable performance conflicts with authorized ordering entities to the BOA Contracting Officer for arbitration and resolution.
c) Department of Defense Cloud Authorization Services Authorization(s) ‐ Vendors shall be responsible for obtaining and maintaining DCAS authorization(s) for their CSO(s) (i.e., IaaS, PaaS, SaaS, etc.) in accordance with DCAS regulations and policies.
d) Federal Risk and Authorization Management Program Authorization(s) ‐ Vendors shall be responsible for obtaining and maintaining FedRAMP authorization(s) for their CSO(s) (i.e., IaaS, PaaS, SaaS, etc.) in accordance with FedRAMP regulations and policies.
e) Cybersecurity Incident Reporting ‐ Authorized vendors are responsible for timely reporting cybersecurity incidents to the TO(s) Contracting Authority to ensure awareness of the incident and mitigating actions the authorized vendor is performing.
B.1.3 Applicable Security Controls, Compliance, and Policies
Authorized Vendors under the USDA STRATUS BOA for ordering Pool 2 Providers shall comply with USDA high level security policy/guidelines, to include:
B.1.3.1 Ensure ongoing Assessment and Authorization (A&A) of the cloud service tenant according to the appropriate level and conform with the Federal Information Security Modernization Act (FISMA), the Federal Information Processing Standards (FIPS) 199 Categorization (Low, Moderate, High), and Office of Management and Budget (OMB) Circular A‐130, and Federal Risk Management Program (FedRAMP) standards.
B.1.3.2 Comply and meet thresholds set in the National Institute of Standards and Technology (NIST) SP 800‐53 Risk Management Framework “Security and Privacy Controls for Federal Information Systems and Organizations.”
a) CA‐1 Security Assessment and Authorization Policies and Procedures ‐ Formal, documented security assessment and authorization policies that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Formal, documented procedures to facilitate the implementation of the security assessment and authorization policies and associated security assessment and authorization controls.
b) CA‐7 Continuous Monitoring – The organization establishes a continuous monitoring strategy and implements a continuous monitoring program that includes: a configuration management process for the information system and its constituent components; a determination of the security impact of changes to the information system and environment of operation; Ongoing security control assessments in accordance with the organizational continuous monitoring strategy; and Reporting the security state of the information system to the Authorizing Official at least quarterly.
B.1.3.3 Information and data management shall comply with Executive Order 13556 regarding Controlled Unclassified Information (CUI), Personally Identifiable Information (PII) a subset of CUI, and Sensitive PII a subset of PII that requires additional controls and safeguards.
B.1.3.4 Maintain strong physical security controls, managed access to the virtual environment, and maintain strong separation between virtual workloads and environments. Provide clear segregation of data unless otherwise specified, at the application level, and storage level.
B.1.3.5 Fortified Security – Security that enables cyber defenses from the “root” level of systems through the application layer and down to the data layer with improved capabilities including continuous monitoring and auditing; automated threat detection; resiliency against persistent adversarial threat;
encryption at rest and in transits; and an operating environment that meets or exceeds USDA information security requirements.
B.1.3.6 Cybersecurity and Infrastructure Security Agency (CISA) Cybersecurity Division Trusted Internet Connections (TIC) Reference Architecture Document Version 2.0 ‐ TIC is a federal cybersecurity initiative intended to enhance network and boundary security across the Federal Government. The Office of Management and Budget (OMB), the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), and the General Services Administration (GSA) oversee the TIC initiative through a robust program that sets guidance and an execution framework for agencies to implement a baseline boundary security standard.
B.1.3.7 USDA Specific Guidance ‐ The Contractor shall comply with cloud security and privacy requirements specified below including with directed mandates to protect and defend information systems from recurring security threats or in response to real‐time vulnerabilities.
a) USDA Department Regulation DR‐3650‐001 Cloud Computing ‐ This Departmental Regulation (DR) updates the United States Department of Agriculture (USDA) policy for implementing the Office of Management and Budget’s (OMB) Federal Cloud Computing Strategy (Cloud Smart) across the USDA’s information technology (IT) portfolio of information and information systems. Link ‐ https://www.usda.gov/directives/dr‐3650‐001
b) FedRAMP compliant as assessed by a third‐party assessment organization (as defined in Section 0 “Authorization and Evaluation Entity”) authorized and accredited for this purpose by the USDA and FedRAMP.
c) Compliant with all FedRAMP controls required for the FISMA Low and Moderate Level of Risk Categorization.
d) At all times be operating under a valid Authority to Operate (ATO) granted by USDA for at least the FISMA Low Level of Risk Categorization.
e) Determined by USDA to effectively meet the controls required by FedRAMP after a pre‐ award review of the security control test results used to authorize the service. USDA will conduct the pre‐award review of the security control test results used to authorize the service within a 2‐week window after the technical evaluation is completed but before the award executed. USDA will be responsible for conducting the pre‐award review and is solely responsible for making the decision as it pertains to issuance of the ATO.
File details come from the government source that posted it. Updated .