ESRD J-20a Information Security Attestation.docx
DOCX document 17 KB Posted
- Attached to
- End Stage Renal Disease Network 18 Federal contract opportunity
- Solicitation number
- CMS-2012-ESRD-FFPCOMP
About this file
J-20A - Information Security Attestation
View the file
Other files for this federal contract opportunity
Show all 32
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CMS-2012-ESRD-FFPCOMP
(insert company letterhead here)
Attachment J.20a Information Security Attestation (Insert Offeror/Company Name) understands and unconditionally assents to the conditions and requirements set forth section C.3.6 of the SOW. Specifically, (Insert Offeror/Company Name) attests to the system security requirements listed in the table below.
Information Security Requirements
1. (Insert Offeror/Company Name) has an Information System Risk Assessment developed in accordance with CMS methodology and/or NIST standards that accurately reflects its current environment.
2. (Insert Offeror/Company Name) has a System Security Plan that complies with CMS Methodology.
3. (Insert Offeror/Company Name) is compliant with the Health Insurance Portability and Accountability Act security requirements set forth in 45 CFR Parts 160, 162, and 164.
4. (Insert Offeror/Company Name) has a Continuity of Operations (Disaster Recovery/Contingency Plan) developed in accordance with the Business Partner System Security Manual found at www.cms.hhs.gov/informationsecurity under “Policies”.
5. (Insert Offeror/Company Name) has baseline configuration documentation for all platforms that support the ESRD lines of business and has a configuration management program in place that was developed in accordance with NIST standards.
It is agreed upon and understood that the organization’s Attestations and disclosure documents will become a part of the organization’s proposal.
As an individual with authority to bind the (Insert Offeror/Company Name), I accept responsibility for this written document.
(signature)
(type full name)
President, ESRD Operations
(signature)
(type full name)
Chief Information Officer
(signature)
(type full name)
System Security Officer
Source Selection Information – See FAR 2.101 and 3.104
File details come from the government source that posted it. Updated .