B08_SOW_Final.docx

DOCX document 44 KB Posted

Attached to
RF-PCI COMPLIANCE SERVICES Federal contract opportunity
Solicitation number
140P2123Q0113
Issued by
Department of the Interior National Park Service

About this file

This statement of work outlines requirements for PCI DSS compliance support services for the National Park Service. The contractor shall provide PCI policy guidance, scope reduction guidance, documentation of the NPS cardholder data environment comprising over 800 payment terminals, facilitation of self-assessment questionnaires for up to 750 merchant IDs, an annual attestation of compliance, and unlimited vulnerability scans plus up to 10 annual external penetration tests of the NPS payment environment. Deliverables include ongoing maintenance of the cardholder data environment documentation, aggregated self-assessment questionnaires by December 1 each year, the attestation of compliance by December 1, and penetration test reports by December 31. The base period of performance is one year with four optional one-year extensions. The contractor shall not require travel as the government will provide all necessary information electronically.

View the file

Other files for this federal contract opportunity

Other files attached to RF-PCI COMPLIANCE SERVICES, newest first.
File Type Posted
Sol_140P2123Q0113.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work

Payment Card Industry Data Security Standards (PCI DSS) Compliance Support for the National Park Service

2023-07-31

Contents

BACKGROUND2
SCOPE2
REQUIREMENTS3
PCI Security Standards Policy Guidance3
PCI DSS Scope Reduction Guidance3
Cardholder Data Environment (CDE)3
Self-assessment Questionnaires (SAQ)4
Attestation of Compliance (AOC)4
PCI Vulnerability Scans4
External Penetration Testing4
Deliverables4
Delivery Instructions5
Travel5
Additional Considerations6

BACKGROUND

The National Park Service (NPS) is a U.S. Federal Agency under the Department of the Interior (DOI). The NPS manages more than 400 national parks, monuments, and other conservation areas and historic properties. The Recreation Fee Program oversees all credit card processing inside the NPS, which includes approximately 650 merchant accounts that are collectively processing approximately 6 million credit card transactions annually. Each year the NPS is required by Treasury and its processor, WorldPay, to validate compliance with the Payment Card Industry Data Security Standards (PCI DSS) requirements for all processing “payment channels.” As a credit card merchant, the NPS must meet appropriate Payment Card Industry (PCI) standards to securely process, store and transmit cardholder data.

The Recreation Fee Program manages all credit card processing activities whose merchant account is registered to the NPS through WorldPay (this excludes concessioners and other groups that have contractual relationships with the NPS outside the scope of this contract). The Recreation Fee Program issues guidance for establishing credit card processing merchant accounts, implementing credit card acceptance programs, purchasing credit card processing equipment and consulting with parks on PCI DSS related issues including recommendations for connectivity and processing appropriate to the site’s environment. The Recreation Fee Program also issues service wide updates on payment card industry banking initiatives.

Card Processing Venues: The scope of credit card processing covered by this initiative is not limited to collection of recreation fees (under the authorization of the Federal Lands Recreation Enhancement Act), but includes a cross section of programs across the NPS, including but not limited to: Special Park Users, Commercial Use Authorization permits, Wilderness/Backcountry permit fees, emergency services, administration/budget, etc. Note that the scope of this initiative does not include PCI compliance for Recreation.gov (interagency reservation system), concessionaires (food service and lodging providers) or NPS cooperating and “friends” associations (e.g., gift shops and or books stores located in the parks).

Card Processing Devices: The NPS operates several of point-of-sale devices and application(s) which provide fee collection and management for NPS fee-collecting parks, sites, and divisions. These devices include Windows-based point-of-sale terminals, parking meters, self-pay stations, standalone swipe terminals, and browser-based Pay.gov pages. The following is a list of terminal types, as listed by Worldpay, with the number of terminals associated with it:

Terminal Type
Count of Terminals
Ingenico Desk 3500 E2EE
8
Ingenico Desk 3500 WIFI E2EE
1
Ingenico iCT220 CTLS 3.X SSL E2EE
5
VAR - Element Payments
154
VAR - HWP LG PAYGOV
3
VAR - MainStreet/Monetra -510
5
VAR - Mobile Accept
1
VAR - Pay.gov
431
VAR - Prop Software - Other
149
VAR - ROAMPay EMV Flat Rate
1
VAR - Tender Retail
8
VAR - USAePay 610
1
VAR - VenTek
72
VeriFone Vx520 DC CTLS E2EE
1
Grand Total
840

Note that these numbers may change slightly, as park sites add or eliminate terminals.

Card Processing Environments: The NPS Point-of-Sale architecture is comprised of a hybrid architecture made up of on premise and cloud based systems and processes. The government will provide to the successful vendor a list of common controls that are managed at a global level (Department or Agency).

PCI Self-Assessment Questionnaires (SAQs):

Merchant IDs at the same location may be combined into a single SAQ. The following represent the number of SAQs facilitated for the NPS in the 2022 compliance cycle:

SAQ Type
Count of SAQ Type
A
29
A-EP
2
B
1
C
10
P2PE
136
Grand Total
183

SCOPE

The National Park Service is seeking a Qualified Security Assessor (QSA) and Approved Scanning Vendor (ASV) with extensive PCI assessment experience to assist the Recreation Fee program in providing the following services:

· PCI Security Standards policy guidance

· PCI DSS scope reduction practices guidance

· National Park Service Cardholder Data Environment (CDE) Documentation

· Facilitated self-assessment questionnaires (SAQ) for each MID

· Attestation of Compliance (AOC)

· PCI DSS vulnerability scans (self-service)

The period of performance of this contract will be one base year with four one-year options.

REQUIREMENTS

The successful offeror will:

PCI Security Standards Policy Guidance

· Provide guidance to the NPS on overall strategy regarding compliance with PCI security standards, development and interpretation of policies, advice and guidance on changes to PCI Data Security Standards, and remediation of specific issues uncovered during the SAQ process

PCI DSS Scope Reduction Guidance

· Provide the NPS with guidance on reduction of PCI scope, including:

· Deployment of Point-to-Point Encryption (P2PE) solutions

· Assessment and authoring of white papers on P2PE solutions, if requested

· Reduction of applicable controls to those required by the P2PE SAQ

· Segmentation

Cardholder Data Environment (CDE)

· Document the National Park Service cardholder data environment (CDE) in a secure digital medium that the Recreation Fee Program can work with during the PCI DSS compliance processes. Documentation

· The CDE will include, but is not limited to, Network Components, Point-of-Sale (POS) systems, Servers, Applications, Virtual Components and Third-party IT systems.

· Develop and support a maintenance process to keep the CDE up to date, to be approved by the National Park Service Recreation Fee Program before implementation

· Update the CDE in accordance with the CDE maintenance process described above, as new information is discovered or provided

Self-assessment Questionnaires (SAQ)

· Determine which self-assessment questionnaire is applicable for each merchant account.

· Schedule, facilitate, collect, and input all data for all merchant accounts to complete PCI DSS related self-assessment questionnaires into a system of their own choosing at no additional cost to the government, for a maximum of 750 merchant accounts (actual number may be less). Merchant accounts at the same physical location may be combined into a single SAQ.

· Address any concerns identified during the facilitation with the merchant account point of contact and the Recreation Fee Management Program

· Aggregate responses and provide access to the aggregated responses to the Recreation Fee Management Program

· Provide an aggregated SAQ to be signed by the National Park Service

Attestation of Compliance (AOC)

· Provide a PCI Attestation of Compliance (AOC) to be signed by the NPS annually, no later than December 1st of each year.

PCI Vulnerability Scans

· Provide the NPS with access to a self-service vulnerability scanning tool that will allow NPS to conduct unlimited on-demand PCI vulnerability scans of its CDE

External Penetration Testing

· Provide the NPS with an annual external penetration test on up to 10 IP addresses across the NPS CDE

· A penetration test report should be produced after each test. The report should focus on what data was compromised, if any, and how. The report should detail the actual method of the attack and exploit and recommendations for improving the NPS’s security posture across the CDE

· Each penetration test report should be stored after each test report has been delivered to the Recreation Fee program staff

Deliverables

Table 1 List of Deliverables

Required Deliverables/Reports Required Due Date Description of Deliverable Content

Access to Self-Service Vulnerability Scanning System
Within 7 days of award
Cardholder Data Environment
Within 15 days of contract award

Initial creation and population of the NPS CDE will be required within 90 of contract award.

CDE will be updated at a minimum following the schedule below:

· updated pre-and post SAQ

Self-assessment Questionnaires Distributed
September 1st of each calendar year
SAQ elicitation will begin September 1st of each calendar year
SAQ Summary Report
December 1st of each calendar year
Includes at minimum, merchant ID, type of SAQ performed, date performed, and pass/fail.
Attestation of Compliance
December 1st of each calendar year
Penetration Test
December 31st of each calendar year

Delivery Instructions

CDE access shall be made available to the government on the requirement delivery date.

One copy of each report will be submitted to the Contracting Officer’s Representative. The contractor shall deliver each report in a mutually agreed upon format. Deliverables are to be transmitted with a cover letter, on the prime contractor’s letterhead, describing the contents.

Travel

Contractor employees will not be required to travel for providing the government with PCI DSS compliance services. The government will not pay for any travel.

Additional Considerations

There is no anticipated need for Government Furnished Equipment relevant to providing the deliverables.

The government will share all currently known government information related to the merchant accounts as well as IP addresses upon successful contract award.

Architectural diagrams and/or documentation will not be provided.

File details come from the government source that posted it. Updated .