Attachment_3_Office_of_Information_Technology_Version_1_0912.docx

DOCX document 32 KB Posted

Attached to
CCTV Security Camera System Federal contract opportunity
Solicitation number
CNSHQ17T0055
Issued by
Corporation for National and Community Service Office of Procurement Services

View the file

Other files for this federal contract opportunity

Other files attached to CCTV Security Camera System, newest first.
File Type Posted
RFP_CNSHQ17T0055_0912.docx DOCX document
Appendix_a_b_and__c_Maps_of_Campus_Buildings_(003)_0912.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 3 Office of Information Technology (OIT) Contract Language Version 1.0

April 2017

1.Introduction2
2.Required FAR Clauses3
3.Laws, Standards, Policy and Guidance3
4.Information System and Application Security Requirements4
4.1Information System4
4.2Application Development6
5.Web Site Requirements9
6.Privacy Impact Assessment9
7.Usage of CNCS Information9
8.Privacy Breach Notification10
8.1Notifying Individuals of a Privacy Breach11
9.Personnel Security Requirements12
10.Recordkeeping13
11.Definitions13

Introduction The Office of Management and Budget (OMB) and Congress determined that the security of our Federal data and enhancing IT security resources are one of our highest priorities. Recognizing the need for agencies to have effective information security programs, Congress passed the Federal Information Security Modernization Act of 2014 (FISMA).

FISMA requires Federal agencies to implement and strengthen its cybersecurity protections when it acquires products or services that generate, collect, maintain, disseminate, store, or provides access to Controlled Unclassified Information (CUI), on behalf of the Federal government. FISMA, the Office of Management and Budget (OMB) policies, and National Institute of Standards and Technology (NIST) standards provide the overall framework for ensuring the effectiveness of information security controls that secure federal computer operations and assets to include those provided/managed by a contractor.

FISMA requirements apply to all federal contractors and organizations or sources that possess or use federal information or that operate, use, or have access to federal information systems [footnoteRef:1]on behalf of an agency. CNCS will follow NIST standards and OMB guidance for securing its information technology resources. [1: An information system is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. (CNSS 4009) CNCS defines information resources as any information (e.g. files, data, etc.), system, application or service that a CNCS employee or contractor can access.

In acquiring information technology, CNCS contracting officers shall include the appropriate information technology security policies and requirements for information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. Below are the requirements that must be inserted in all contracts that require information technology (IT) services or equipment. As new Federal requirements or updates to existing requirements are made, the Contractor shall apply those that are pertinent to the systems and processes they use in support of CNCS. CNCS will notify the Contractor in the event of new or changed requirements.

The Contractor shall ensure its subcontractors and data transfer partners provide the same level of security where applicable. The Contractor shall comply with and include all appropriate security provisions in any subcontract(s) awarded pursuant to this Contract. Contractors systems, services, and or technologies, upon entering into a contractual agreement with CNCS will be subject to CNCS policies, procedures, testing, reporting requirements, and general governance and oversight .

Required FAR Clauses The following FAR clauses are included in all IT service and/or IT service related solicitations and contracts.

· 52.224-1, Privacy Act Notification

· 52.224-2, Privacy Act

· 52.224-3, Privacy Training

· 52.202-1, Definitions

· 52.239-1, Privacy or Security Safeguards

· 52.204-21, Basic Safeguarding of Covered Contractor Information Systems

· 52.227-14, Rights in Data – General and Alternate V Laws, Standards, Policy and Guidance The activities as required by this contract necessitate the Contractor’s access to Government Information, including Controlled Unclassified Information (CUI) and personally identifiable information (PII). The contractor shall meet and comply with all CNCS’ Information Technology (IT) security policy requirements, NIST standards and OMB guidelines, and other applicable Government-wide laws and regulations that apply to the protection and security of IT systems.

Contractors are required to comply with current IT security and privacy requirements as outlined in CNCS policies and Federal statutes, regulations, policies and guidance, as applicable. These requirements include but are not limited to:

· Federal Information Security Modernization Act of 2014 (FISMA), as amended

· Privacy Act of 1974, (5 U.S.C. § 552a)

· E-Government Act of 2002, Section 208

· Title V - Confidential Information Protection and Statistical Efficiency Act of 2002 of the E-Government Act of 2002 (CIPSEA)

· Executive Order 13556 for Controlled Unclassified Information (CUI)

· Clinger-Cohen Act of 1996 also known as the “Information Technology Management Reform Act of 1996”

· Office of Management and Budget (OMB) Circular A-130, “Managing Strategic Information as a Resource”

· Office of Management and Budget (OMB) memorandums and circulars

· NIST Special Publication (SP) 800-18 (as amended), “Guide for Developing Security Plans for Federal Information Systems”

· NIST SP 800-30, “Risk Management Guide for Information Technology Security Risk Assessment Procedures for Information Technology Systems”

· NIST SP 800-34, “Contingency Planning Guide for Information Technology Systems”

· NIST SP 800-37, (as amended), “Guide for the Security Certification and Accreditation of Federal Information Systems”

· NIST SP 800-47, “Security Guide for Interconnecting Information Technology Systems”

· NIST SP 800-53 (as amended), “Recommended Security Controls for Federal Information Systems”

· NIST SP 800-53A (as amended), “Guide for Assessing the Security Controls in Federal Information Systems”

· FIPS PUB 140-2, “Security Requirements for Cryptographic Modules”

· FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information Systems”

· FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information Systems”

· CNCS Privacy Policy

· CNCS Cybersecurity Policy

· Any other relevant Federal laws, regulations, policies and guidance that CNCS must adhere to in the agency’s IT acquisition efforts The Contractor and any subcontractor must not publish or disclose in any manner without prior written consent, the data/information to which the Contractor will have access because of this contract, as this is the sole property of CNCS. Contractors/subcontractors may be held responsible for any violations of confidentiality.

Information System and Application Security Requirements If the contract requires the contractor to manage an information system or IT service on behalf of CNCS then the following sections should be included within the contract, as applicable, to protect privacy, civil liberties and security of the system.

Information System The Contractor shall comply with implementation of required security and privacy controls for protection of the CNCS information system based on the sensitivity of the data within the system as outlined by Federal, statutory and regulatory requirements and guidance, and CNCS policies and rules of behavior. The Contractor facilities and IT systems shall meet the security requirements for the same impact level or greater as defined by the FIPS 199 as required for the protection of Government Information.

The Contractor shall implement and maintain an Information security program that includes privacy and is consistent with CNCS’s approach to cybersecurity risk management and that is compliant with CNCS policies, FISMA, and applicable NIST Special Publications and OMB guidelines, and other applicable laws, throughout the performance of this contract.

The Contractor shall meet or exceed the continuous monitoring requirements identified in the CNCS Information Security Continuous Monitoring (ISCM) Strategy and Federal statutory and regulatory requirements and other applicable OMB and CNCS policies. Maintenance of the security authorization to operate will be through continuous monitoring of security controls of the contractors system and its environment of operation to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. The Contractor shall also store monthly continuous monitoring data at its location or a location identified by CNCS for a period not less than one year from the creation date.

a. Information System Security Officer (ISSO) - The Contractor is responsible for appointing a designated person as the ISSO for an information system as defined in this paragraph. The ISSO must have a level of experience in system security, continuous monitoring, and security assessments of at least two years.

b. Configuration Baselines/Security Configurations - The Contractor must configure its systems that contain CNCS information in accordance with configuration requirements that are defined in CNCS policies and procedures. CNCS follows the United States Government Configuration Baseline (USGCB) and Center for Internet Security (CIS) as the baseline configuration for all information systems. The Contractor shall not publish or disclose in any manner, without written consent, the details of any safeguards either designed or developed by the Contractor under this contract or otherwise provided by the Government.

c. Vulnerability Remediation - The Contractor must ensure implementation and maintenance of the latest updates/patches; anti-virus and vulnerability information/signatures; and other identified risks and security issue remediation in accordance with CNCS policy and procedures:

· If the contract requires a publicly accessible Internet Protocol (IP)/Uniform Resource Locator (URL) will add it to the passive vulnerability scan that is conducted by the Department of Homeland Security (DHS) / National Cybersecurity Assessments and Technical Services (NCATS). The passive vulnerability scan runs at least every 14 days. CNCS will review the results of the scan weekly and will provide the details of the scan result if a vulnerability is discovered. The Contractor will provide the following information to CNCS within 60 days of the contract award.

(1) IP address of website

(2) Website URL

(3) Primary point of contact who will be able to address any findings discovered during a NCATS scan.

d. Cryptographic Modules - The Contractor must use Federal Information Processing Standard (FIPS) compliant encryption technology to protect data and information systems at rest and in transit.

e. Statutory and Regulatory Requirements - The Contractor must comply with all requirements in the paragraphs above including the CNCS Cybersecurity and Privacy Policies, which lists in detail the requirements for Federal information systems.

f. Interconnection Security Agreements (ISA)[footnoteRef:2] - The contractor shall provide updated ISA and supporting Memorandum of Agreement/Understanding (MOA/U), completed in accordance with NIST 800-47, “Security Guide for Connecting Information Technology Systems”, for existing and new interconnections. [2: Per NIST 800-47, an interconnection is the direct connection of two or more IT systems for the purpose of sharing data and other information resources through a pipe, such as ISDN, T1, T3, DS3, VPN, etc.]

g. Reporting Requirements - The contractor shall immediately report and handle, as tasked, any threats, incidents, potential incidents/events, and any other hazards to the integrity, availability, and confidentiality of CNCS data and/or information systems and in compliance with requirements and procedures defined in the CNCS Incident Response Plan and any other relevant system documentation.

h. Access - The Contractor must provide CNCS, including CNCS’s Office of Inspector General, with access to the Contractor’s and Subcontractors’ facilities, installations, operations, documentation, databases, and personnel used in the performance of the contract.

i. Data Compartmentalization, Protection, and Retention - To maintain and protect the confidentiality, integrity, and availability of CNCS information, the Contractor shall ensure appropriate and required security and privacy controls for CNCS data/information including compartmentalization; FIPS-compliant encryption; and retention, in accordance with approved retention schedule(s).

j. Employee Termination - The Contractor shall immediately notify the COR when an employee plans to terminate employment or an employee is removed from the contract.

k. Contract Termination - Failure on the part of the Contractor to comply with the terms of this clause may result in termination of this contract.

Application Development The Contractor must state within the proposal a plan of how it will support the application security requirements associated with this contract and shall ensure that its subcontractors (at all tiers) that perform work under this contract comply with all security requirements. For any application developed under this contract, the Contractor must comply with the following:

a. Secure Coding - Identify the tools that the Contractor will use in its software development environment to enforce secure coding. The Contractor must provide and follow a set of written secure coding guidelines that, at a minimum, indicate how code will be formatted, structured, documented, and tested and otherwise comply with CNCS Software/System Development Lifecycle (SDLC) and change management policy and procedures.

b. Configuration Management - Document in writing and via the implemented CNCS tool(s) all changes to the application baseline and all related configuration and build files. Comply with CNCS configuration management policies and procedures. Provide written secure configuration guidelines that fully describe:

(i) all security relevant configuration options and their implications for the overall security of the application

(ii) the dependencies on the supporting platform, including, but not limited to, the operating system, web server, and application server

(iii) how the options should be configured to maximize security, provided that the “pre-set” configuration of the application must be secure.

c. Distribution – Document in writing a build process that demonstrates the method to deliver the application code to CNCS. This should include the verification and integrity of the application.

d. Disclosure - Document, in writing, any third-party software used in the application, including all libraries, frameworks, components, system privileges, and other products, whether commercial, free, open-source, or closed-source and ensure that use of such software has been formally approved by CNCS.

e. Security Controls - Comply with all requirements in the paragraphs above, including the standards defined by National Institute of Standards and Technology (NIST).

f. Testing

(1) Implement a security test plan and provide the test results to CNCS.

(2) Document, in writing, the procedures and the framework used to conduct code security review during the application development life cycle.

(3) To the extent that such testing discloses vulnerabilities or other security issues, submit new items for inclusion in the POAM and remediate new and existing POAM items to resolve vulnerabilities or other issues before the application is deployed in the production environment.

(4) Provide a written certification, signed by the Information Security Lead, that:

(i) the application meets the security requirements of the Contract;

(ii) all services were performed in accordance with the standard identified in the section above; and

(iii) all security issues were identified, documented in the System Security Plan (SSP) and POAM, and critical and high security issues are resolved prior to delivery.

g. Delivery and Acceptance of the Application - Once the testing required under the provisions above have been completed, the Contractor shall provide the following to support an authorization to operate:

(1) Provide security documentation (created during the development process) that includes evidence that the requirements for design, implementation, and testing were properly completed;

(2) Provide written warranty that the application does not contain any code that does not support a necessary function of the application or that weakens the security of the application, including computer viruses, worms, time bombs, back doors, Trojan horses, Easter eggs, and all other forms of malicious code;

(3) Ensure the SSP is complete and updated;

(4) Participate cooperatively and fully with the required Security Assessment and Authorization (SA&A) process in accordance with NIST and CNCS requirements.

h. Maintenance

(1) Investigating Security Issues For a period of time to be determined by the contract, after acceptance of the application, if a vulnerability or other security issue is discovered or suspected by the CNCS, or a vulnerability or other security issue comes to the attention of the Contractor by other means, the Contractor shall assist CNCS in performing an investigation to determine the nature of the vulnerability or other issue. Based on this investigation, the Contractor shall advise CNCS on the appropriate steps to mitigate the risk posed by the vulnerability or other issue.

(2) Patches and Updates For a period of time to be determined by the contract, the Contractor shall provide to CNCS error corrections, updates, patches, revisions, fixes, upgrades, and new releases of software included in the application. The Contractor shall warrant that: (i) all corrections, updates, patches, revisions, fixes, upgrades and new releases have been tested and validated on a test version of the application prior to distribution to CNCS; and (ii) it has verified the continued functionality of the application based on the testing and validation.

(3) Hardware/Software The Contractor shall ensure with CNCS approval that they are using the most current hardware/software available to support the application and/or system of record. The Contractor shall verify prior to delivery that the hardware/software listed in the SSP have not been identified by the vendor as being non-supported within one year of delivery.

Web Site Requirements The Contractor will apply the following requirements to their websites, as applicable.

1. If the website processes CUI it must use HTTPS and support HSTS.

a. The requirement to use only approved government domains (.gov) does not apply in circumstances where CNCS is a user/customer of a third-party website or service that resides on a non-governmental domain.

2. The Contractor shall participate in the General Service Administration’s (GSA) Digital Analytics Program (DAP) and deploy the DAP tracking code on all public facing websites that are operating on behalf of CNCS or CNCS is a customer .

3. The Contractor shall ensure the website is accessible, compatible and responsive on multiple mobile devices.

Privacy Impact Assessment The contractor must complete a Privacy Impact Assessments (PIAs) in accordance to the E-Government Act of 2002, sec. 208., and the Privacy Act of 1974, for contractor systems or new technologies that collect, maintains or disseminates personal identifiable information (PII) from 10 or members of the public.

In order to ensure the physical and information systems security of the confidential information, agencies shall conduct inspections of any off-site facility that harbors confidential information protected under CIPSEA Usage of CNCS Information Contractor shall:

1. Use the CNCS Controlled Unclassified Information (CUI) only for the purposes described herein the contractor

2. Not reproduce the CNCS CUI and will hold in confidence and protect the information from dissemination to, and use by, any third party

3. Except as required in performance obligations under the contract, it will not create any derivative work from CNCS CUI disclosed to such Contractor by the CNCS

4. Restrict access to the CNCS CUI to its personnel, agents, or consultants, if any, who have a need to have access and who have been advised of and have agreed in writing or are otherwise bound to treat such information in accordance with the terms of the contract

5. As part of the contract closeout, return or destroy all CNCS CUI in its possession upon termination or expiration of the contract or as otherwise requested by the CNCS. Contractor shall submit evidence of compliance with the close-out requirements in this provision, in a manner described by the CNCS, at its discretion.

6. Not commingle CNCS CUI with Contractor specific records.

7. Contractors engaging in cross-device tracking at all phases should truthfully disclose their tracking activities, accurately identify the categories of data collected involved, and provide meaningful information about whether and how cross-device tracking occurs.

8. Records created and maintained using electronic media such as Flickr, Tumblr, blogs, Google+, Pinterest social media sites, and a website, a wiki, email, or any other type of electronic communication may be covered in the agency’s Records Control Schedule and/or the General Records Schedules and should be managed in accordance with approved dispositions.

Privacy Breach Notification A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PU, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for other than authorized purpose. Often, an occurrence may be first identified as an incident, but later identified as a breach once it is determined that the incident involves PII, as is often the case with a lost or stolen laptop or electronic storage device.

In the event that the Contractor experiences a privacy breach that involves CNCS information, the Contractor is required to do the following:

· Notify CNCS’ POC or designee, within one hour of a suspected or confirmed breach, in any medium or form, including paper, oral, and electronic. If the CNCC POC or designee is unavailable, the contractor shall notify NCCIC/US CERT. Contractor shall provide at a minimum, the following information:

· Date and time the breach was discovered

· The type of information potentially compromised by the suspected or confirmed breach

· Number of individuals affected by the suspected or confirmed breach

· Steps taken to notify the individuals affected by the suspected or confirmed breach

· Identification of the breakdown in safeguards that led to the suspected or confirmed breach

· Any additional information relevant to the breach Understand that reporting a privacy breach shall not, by itself, be interpreted as evidence that the Contractor or its subcontractor (at any tier) failed to provide adequate safeguards for PII.

All determinations related to CNCS information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contractor in consultation with the CNCS COR and/or Chief Privacy Officer.

The Contractor shall provide full access and cooperation for all activities determined by the CNCS to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

Incident response activities determined to be required by the CNCS may include, but are not limited to, the following:

a. Inspections

b. Investigations

c. Forensic reviews

d. Data analyses and processing CNCS, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

Notifying Individuals of a Privacy Breach The Contractor shall not proceed with notification unless the COR, in consultation with the Chief Privacy Officer, has determined in writing that notification is appropriate.

The notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by CNCS. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:

· A brief description of the incident

· A description of the types of PII

· A statement as to whether the PII was encrypted or protected by other means

· Steps individuals may take to protect themselves

· What the Contractor is doing to investigate the incident, to mitigate the incident, and to protect against any future incidents

· Information on how to obtain additional information Personnel Security Requirements Prior to gaining access to CNCS’s information, systems, or secured physical space, individuals must meet CNCS Personnel Security background investigation requirements. Depending on position risk, as determined by CNCS, these requirements may include the following:

1. A background investigation (initiated by CNCS)

2. A commercial background investigation (initiated by CNCS or the individual’s company to CNCS’s standards)

3. Criminal history record information via a fingerprint check

4. Drug Testing These requirements may change at the discretion of CNCS, and access to individuals may be denied at any point.

Contractor shall furnish documentation reflecting favorable adjudication of background investigations for all personnel (including subcontractors) supporting the system.

The Contractor will bear the cost of obtaining and sustaining the background investigations. The Contractor must state within the proposal the number of individuals who will be assigned to this effort, with the type of completed background investigation they hold. It is the responsibility of the Contractor to provide the individuals with the required background investigation needed to complete the work.

The fact that the CNCS performs security investigations for contractor employees shall not in any manner relieve the Contractor of its responsibility to ensure that all personnel furnished are reliable and of reputable background and sound character.

In addition, the Contractor must provide evidence that all individuals assigned to the contract have completed some form of security/privacy awareness training (this can be either Contractor or CNCS provided training) and any other trainings applicable as specified by CNCS before access to CNCS information or information systems is granted.

Recordkeeping Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall cooperate and comply with Federal reporting requirements.

Definitions The following definitions apply to this contract:

a. Breach: The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

b. Controlled Unclassified Information (CUI): CUI is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended.

c. DAP: The Digital Analytics Program (DAP) offers advanced, easy Web analytics to federal agencies. The program is a hosted shared service provided by GSA’s Technology Transformation Service.

0. More information about DAP can be found at https://https.cio.gov/faq/

d. HSTS: HTTP Strict Transport Security (HSTS) is a simple and widely supported standard to protect visitors by ensuring that their browsers always connect to a website over HTTPS. HSTS exists to remove the need for the common, insecure practice of redirecting users from http:// to https://URLs.

0. More information about HSTS can be found at https://https.cio.gov/hsts/

e. HTTPS: Encrypts nearly all information sent between a client and a web service. When properly configured, an HTTPS connection guarantees three things:

0. Confidentiality. The visitor’s connection is encrypted, obscuring URLs, cookies, and other sensitive metadata.

0. Authenticity. The visitor is talking to the “real” website, and not to an impersonator or through a “man-in-the-middle”.

0. Integrity. The data sent between the visitor and the website has not been tampered with or modified.

0. A plain HTTP connection can be easily monitored, modified, and impersonated.

0. More information about federal HTTPS requirements can be found at https://https.cio.gov/faq/

f. Information: This term is synonymous with the term Data. Both terms refer to single or multiple instances of facts, ideas, knowledge, instructions, etc. in any medium or form that can be stored, transferred, communicated, or process.

g. Incident: An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

h. Information System: A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. (CNSS 4009)

0. CNCS defines information resources as any information (e.g. files, data, etc.), system, application or service that a CNCS employee or contractor can access.

i. Personally Identifiable Information (PII): Information that can be used to distinguish or trace an individual’s identity, alone or when combined with other information that is linked or linkable to a specific individual.

File details come from the government source that posted it. Updated .