Amendment_Number_four_security_clauses.docx
DOCX document 24 KB Posted
- Attached to
- Pediatric Rehabilitation Physician Federal contract opportunity
- Solicitation number
- CC-P14-001231
About this file
Attachment Number Four - Security Clauses
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_Number_5.pdf | ||
| Attachment_Number_One_-SOW.pdf | ||
| Attachment_Number_8_-_Infectious_Disease_Control_Policy_Memo_July_12_2010.docx | DOCX document | |
| Attachment_number_3_-_Invoicing_instructions.PDF | ||
| Attachment_number_6.pdf | ||
| Combined_solicitation-synopsis_Revised_.pdf | ||
| Attachment_2_prooposalprepinstructions.pdf | ||
| Attachment_Number_7_-_Rights_in_Data.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment Number 4 – Security Clauses CC-P14-001231 Amendment Number One
NIH Information and Physical Access Security Acquisition/Solicitation Language
ARTICLE H. . NIH INFORMATION AND PHYSICAL ACCESS SECURITY
This acquisition requires the Contractor to:
· develop, have the ability to access, or host and/or maintain Federal information and/or Federal information system(s).
· access, or use, Personally Identifiable Information (PII), including instances of remote access to or physical removal of such information beyond agency premises or control.
· have regular or prolonged physical access to a “Federally-controlled facility,” as defined in FAR Subpart 2.1.
The Contractor and all subcontractors performing under this acquisition shall comply with the following requirements:
a. Information Type
[ ] Administrative, Management and Support Information:
[X ] Mission Based Information:
Health Care Research and Practitioner Education Information Type
Health Care Research and Practitioner Education fosters advancement in health discovery and knowledge. This includes developing new strategies to handle diseases; promoting health knowledge advancement; identifying new means for delivery of services, methods, decision models and practices; making strides in quality improvement; managing clinical trials and research quality; and providing for practitioner education.
b. Security Categories and Levels
| Confidentiality | Level: | [ X ] Low | [ ] Moderate | [ ] High | ||
| Integrity | Level: | [ ] Low | [] Moderate | [X ] High | ||
| Availability | Level: | [ X ] Low | [ ] Moderate | [ ] High |
Overall Level: [ ] Low [ ] Moderate [ X ] High
c. Position Sensitivity Designations
The following sensitivity level(s), clearance type(s), and investigation requirements apply to this contract:
[ ] Level 6: Public Trust - High Risk. Contractor/subcontractor employees assigned to Level 6 positions shall undergo a Suitability Determination and Background Investigation (BI).
[ ] Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).
[ X ] Level 1: Non-Sensitive Contractor/subcontractor employees assigned to Level 1 positions shall undergo a Suitability Determination and National Agency Check and Inquiry Investigation (NACI).
The Contractor shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a federal information system(s). The roster shall be submitted to the Project Officer, with a copy to the Contracting Officer, within 14 calendar days of the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within 15 calendar days of the change. The Contracting Officer will notify the Contractor of the appropriate level of investigation required for each staff member. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at http://ocio.nih.gov/docs/public/Suitability-roster.xls
Suitability Investigations are required for contractors who will need access to NIH information systems and/or to NIH physical space. However, contractors who do not need access to NIH physical space will not need an NIH ID Badge. Each contract employee needing a suitability investigation will be contacted via email by the NIH Office of Personnel Security and Access Control (DPSAC) within 30 days. The DPSAC email message will contain instructions regarding fingerprinting as well as links to the electronic forms contract employees must complete.
Additional information can be found at the following website: http://idbadge.nih.gov/background/index.asp
All contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract.
Contractors may begin work after the fingerprint check has been completed.
d. Information Security Training d.1 Mandatory Training
All employees having access to (1) Federal information or a Federal information system or (2) personally identifiable information, shall complete the NIH Information Security Awareness Training course at http://irtsectraining.nih.gov/ before performing any work under this contract. Thereafter, employees having access to the information identified above shall complete an annual NIH-specified refresher course during the life of this contract. The Contractor shall also ensure subcontractor compliance with this training requirement.
d.2 Role-based Training
HHS requires role-based training when responsibilities associated with a given role or position, could, upon execution, have the potential to adversely impact the security posture of one or more HHS systems. Read further guidance at: Secure One HHS Memorandum on Role-Based Training Requirement“
For additional information see the following: http://ocio.nih.gov/security/security-communicating.htm#RoleBased
The Contractor shall maintain a list of all information security training completed by each contractor/subcontractor employee working under this contract. The list shall be provided to the Project Officer and/or Contracting Officer upon request.
e. Rules of Behavior
The Contractor shall ensure that all employees, including subcontractor employees, comply with the NIH Information Technology General Rules of Behavior, which are available at http://ocio.nih.gov/security/nihitrob.html.
f. Personnel Security Responsibilities
1. The Contractor shall notify the Contracting Officer, Project Officer, and I/C ISSO within five working days before a new employee assumes a position that requires a suitability determination or when an employee with a suitability determination or security clearance stops working under this contract. The Government will initiate a background investigation on new employees requiring suitability determination and will stop pending background investigations for employees that no longer work under this acquisition.
2. The Contractor shall provide the Project Officer with the name, position title, e-mail address, and phone number of all new contract employees working under the contract and provide the name, position title and suitability determination level held by the former incumbent. If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
3. The Contractor shall provide the Project Officer with the name, position title, and suitability determination level held by or pending for departing employees.
Perform and document the actions identified in the Contractor Employee Separation Checklist (attached) when a Contractor/subcontractor employee terminates work under this contract. All documentation shall be made available to the Project Officer and/or Contracting Officer upon request.
g. Commitment to Protect Non-Public Departmental Information and Data
1. Contractor Agreement
The Contractor, and any subcontractors performing under this contract, shall not release, publish, or disclose non-public Departmental information to unauthorized personnel, and shall protect such information in accordance with provisions of the following laws and any other pertinent laws and regulations governing the confidentiality of such information:
| - 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records) | |
| - 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information) | |
| - Public Law 96-511 (Paperwork Reduction Act) |
2. Contractor Employee Non-Disclosure Agreement
Each employee, including subcontractors, having access to non-public Department information under this acquisition shall complete the Commitment to Protect Non-Public Information – Contractor Employee Agreement A copy of each signed and witnessed Non-Disclosure agreement shall be submitted to the Project Officer prior to performing any work under this acquisition.
h. Loss and/or Disclosure of Personally Identifiable Information (PII) – Notification of Data Breach
The Contractor shall report all suspected or confirmed incidents involving the loss and/or disclosure of PII in electronic or physical form. Notification shall be made to the NIH Incident Response Team via email (IRT@mail.nih.gov) within one hour of discovering the incident. The Contractor shall follow-up with IRT by completing and submitting one of the following two forms within three (3) work days:
| NIH PII Spillage Report [ http://ocio.nih.gov/docs/public/PII_Spillage_Report.doc ] |
| NIH Lost or Stolen Assets Report [ http://ocio.nih.gov/docs/public/Lost_or_Stolen.doc |
i. Data Encryption
The following encryption requirements apply to all laptop computers containing HHS data at rest and/or HHS data in transit. The date by which the Contractor shall be in compliance will be set by the Project Officer, however, device encryption shall occur before any sensitive data is stored on the laptop computer/mobile device, or within 45 days of the start of the contract, whichever occurs first.
1. The Contractor shall secure all laptop computers used on behalf of the government using a Federal Information Processing Standard (FIPS) 140-2 compliant whole-disk encryption solution. The cryptographic module used by an encryption or other cryptographic product must be tested and validated under the Cryptographic Module Validation Program to confirm compliance with the requirements of FIPS PUB 140-2 (as amended). For additional information, refer to http://csrc.nist.gov/cryptval.
2. The Contractor shall secure all mobile devices, including non-HHS laptops and portable media that contain sensitive HHS information by using a FIPS 140-2 compliant product. Data at rest includes all HHS data regardless of where it is stored.
3. The Contractor shall use a FIPS 140-2 compliant key recovery mechanism so that encrypted information can be decrypted and accessed by authorized personnel. Use of encryption keys which are not recoverable by authorized personnel is prohibited. Key recovery is required by “OMB Guidance to Federal Agencies on Data Availability and Encryption”, November 26, 2001, http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf.
Encryption key management shall comply with all HHS and NIH policies (http://intranet.hhs.gov/infosec/docs/guidance/hhs_standard_2007.pdf) and shall provide adequate protection to prevent unauthorized decryption of the information.
All media used to store information shall be encrypted until it is sanitized or destroyed in accordance with NIH procedures. Contact the NIH Center for Information Technology for assistance (http://cit.nih.gov/ProductsAndServices/ServiceCatalog/Services.htm?Service=Media+Sanitization+Service).
j. Physical Access Security
In accordance with OMB Memorandum M-05-24, the Contractor shall ensure that background investigations are conducted for all contractor/subcontractor personnel who have (1) access to sensitive information, (2) access to Federal information systems, (3) regular or prolonged physical access to Federally-controlled facilities, or (4) any combination thereof. OMB Memorandum M-05-24 is available at http://www.whitehouse.gov/omb/memoranda/fy2005/m05-24.pdf. Agency personal identification verification policy and procedures are identified below:
HHS Office of Security and Drug Testing, Personnel Security/Suitability Handbook (02-01-05): http://www.hhs.gov/oamp/policies/personnel_security_suitability_handbook.html
k. Using Secure Computers to Access Federal Information
1. The Contractor shall use an FDCC compliant computer when processing information on behalf of the Federal government.
| 2. | The Contractor shall install computer virus detection software on all computers used to access information on behalf of the Federal government. Virus detection software and virus detection signatures shall be kept current. |
| l. | Special Information Security Requirements for Foreign Contractors/Subcontractors |
When foreign contractors/subcontractors perform work under this acquisition at non-US Federal Government facilities, provisions of HSPD-12 do NOT apply.
m. REFERENCES: INFORMATION SECURITY INCLUDING PERSONALLY IDENTIFIABLE INFORMATION
n. REFERENCES: PHYSICAL ACCESS SECURITY
Rev 02-07-2014
File details come from the government source that posted it. Updated .