Attachment_K_-_IT_Memo_of_Understanding.pdf
PDF 67 KB Posted
- Attached to
- Automated Track Inspection Program (ATIP) Federal contract opportunity
- Solicitation number
- DTFR5316R00382
About this file
Attachment K
View the file
Other files for this federal contract opportunity
Show all 25
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment K
ATTACHMENT K
Information Technology Memorandum of Understanding
MEMORANDUM OF UNDERSTANDING (MOU)
MOU Between The Federal Railroad Administration Office of IT
AND (Contractor Name).
System Name: Automated Track Inspection Program (ATIP)
Date of Authorization:
References: (a) NIST 800-47
(b) Under Contract No. DTFR53-13-D-00013
(c) NIST Special Publication 800-18, Guide for Developing Security Plans for Information Technology Systems.
(d) DOT H 1350.253, Departmental Guide to Certification/Accreditation of Information Systems.
(e) DOT H 1350.271, Departmental Guide to Information Protection for Senior Management.
(f) DOT H 1350.260, Departmental Guide to Protecting Information Technology.
(g) DOT H 1350.273, Departmental Guide to Information Protection for Contractors.
(h) DOT USER ACCESS AUTHORIZATION/REVOCATION form.
Attachments:
1) FRA Project Proposed Firewall/VPN Gateway Implementation (to be provided by the contractor)
2) Firewall/VPN Configuration Details (to be provided by the contractor)
3) Federal Railroad Administration IT System Rules of Behavior
A. PURPOSE
This agreement establishes the responsibilities between Federal Railroad Administration Office of Safety and ENSCO. This MOU has been developed to fulfillthe requirements of the above references. The Contractor has reviewed the above references and the proposed solution meets or exceeds the requirements contained therein. The contractor will complete and submit a DOT USER ACCESS AUTHORIZATION/REVOCATION form prior to requested date of actions.
This MOU describes a list of interconnected systems between Federal Railroad Administration Office of Safety and the Contractor for the purpose of establishing the VPN connection as link between FRA Headquarters center and ATIP Processing Center managed and maintained by the Contractor.
<<< Provide an overall proposed VPN architecture overview of the implementation here >>>
Figure 1 Proposed VPN Architecture
B. GENERAL
1. This agreement covers access to ATIP Processing Center as follows:
a. Connectivity supports Contract No. DTFR53-16-D-xxxxx
BACKGROUND
It is the intent of both parties to this agreement to interconnect the following information technology (IT) systems to maintain data integrity between "FRA in-house databases" and "ATIP testing system and database." The Contractor requires the access to the FRA in-house databases for updating purposes, and FRA Office of Safety requires the use of the Contractor’s testing, processing center and database, as approved and directed by Contract No. DTFR53-16-D-xxxxx to successfully carry out this mission critical project for FRA Office of Safety. The expected benefit of the interconnection is to expedite the processing of data within prescribed timelines.
The communication medium is Virtual Private Network (VPN) and the speed requirement for ATIP Processing Center access is DSL or better.
Each IT system is described below:
FRA Headquarters
– Name: FRA ATIP Databases
– Function: Master Databases used for in-house processing as stored on RRS-22 Server
– Location: 1200 New Jersey Ave SE Washington, D.C.
– Description of data: All data pertaining to the ATIP system.
– Sensitivity: Sensitive but not classified
ATIP Processing Center
– Name:
– Function: ATIP Contractor
– Headquarters Location:
– Site Location:
– Description of data, including sensitivity or classification: All ATIP Databases including but not limited to Accident/Incident databases, Railroad Inspection Databases, Grade Crossing Inventory
Sensitivity: Sensitive but not classified
C. RESPONSIBILITIES
1. FRA Office of Information Technology Office shall provide permission for connectivity to a DOT-approved facility (reference the C & A and applicable only to the original location) specified in ATIP Processing Center – Site Location.
2. Each site agrees to provide prompt notification to the corresponding site of any changes that could affect the security posture of this link or systems connected thereto.
3. FRA will certify and accredit the FRA LAN and WAN which includes the ATIP system located at FRA Headquarters and the FRA communication lines.
4. The Contractor’s ATIP Processing Center will provide the proper technical and management personnel in order fulfill the Information Technology certification and accreditation requirements initiated by FRA in accordance with DOT mandates and conducted by DOT and/or FRA designee(s) vendor(s) paid for by the initiating office.
5. In regards to privileged user roles, the Contractor administrators have rights at both sites.
FRA Headquarters will be responsible for all issues dealing with network Operations, and Connectivity. The Contractor’s administrators and designated users that are cleared for access have full authority in the change of data, access rights for different users as specified by the contract cited above and frequency of upload, and all aspects related to the data process, upload and availability of the ATIP system.
6. Firewalls and Intrusion Detection Systems (IDS) should be deployed at each site to monitor lines. Only ports/sockets used by the VPN clients are enabled on the link.
Access Control Lists (ACLs) on routers are configured to only allow users with specific accounts with the VPN client. No email access is enabled.
7. The Contractor will endeavor to stay abreast of security threats that may impact the system covered by this MOU (e.g., identified system vulnerabilities should be patched as soon as possible).
8. The following assumptions are made:
1. FRA will provide the mission critical server systems as specified in the Government Furnished Equipment in the Performance Work Statement.
2. Each site would be responsible for routine maintenance pertaining to its specific site, except if the maintenance is related to the VPN access, then, FRA is responsible for making sure the Contractor has the proper configurations to get access to the ATIP systems hosted at FRA site.
Both parties commit to jointly help each other for resolution of issues dealing with trouble calls, once the problem(s) is/are identified, the appropriate party should make every effort to come up with a solution in a reasonable amount of time.
D. COMMUNICATIONS
Frequent formal communications are essential to ensure the successful management and operation of the interconnection. The parties (FRA Office of IT in proxy for the Office of Safety ATIP Program and the Contractor agree to maintain open lines of communication between designated staff at both the managerial and technical levels. All communications described herein must be conducted in writing unless otherwise noted.
The owners of FRA Headquarters System and the Contractor’s ATIP Processing Center System agree to designate and provide contact information for technical leads for their respective system, and to facilitate direct contacts between technical leads to support the management and operation of the interconnection. To safeguard the confidentiality, integrity, and availability of the connected systems and the data they store, process, and transmit, the parties agree to provide notice of specific events within the time frames indicated below:
• Security Incidents: Technical staff will immediately notify their designated counterparts by telephone or e-mail when a security incident(s) is detected, and follow up via written communication within 2 hours, so the other party may take steps to determine whether its system has been compromised and to take appropriate security precautions. The system owner will receive formal notification in writing within five (5) business days after detection of the incident(s).
• Disasters and Other Contingencies: Technical staff will immediately notify their designated counterparts by telephone or e-mail and follow up via written communication within 24 hours, in the event of a disaster or other contingency that disrupts the normal operation of one or both of the connected systems.
• Material Changes to System Configuration: Planned technical changes to the system architecture will be reported to technical staff before such changes are implemented. The initiating party agrees to conduct a risk assessment based on the new system architecture and to modify and re-sign the MOU within one (1) month of implementation. If the changes are initiated by the Contractor, FRA approval will be required prior to implementation to assure compliance to DOT guidelines and mandates.
• Personnel Changes: The parties agree to provide notification of the separation or long-term absence of their respective system owner or technical lead. In addition, both parties will provide notification of any changes in point of contact information. Both parties also will provide notification of changes to user profiles, including users who resign or change jobs.
E. SECURITY
Both parties agree to work together to ensure the joint security of the connected systems and the data they store, process, and transmit, as specified in the MOU. Each party certifies that its respective system is designed, managed, and operated in compliance with all relevant federal laws, regulations, and policies.
F. TIMELINE
This agreement remains in effect until superseded by another MOU or until the end of the contract support.
G. DOT MANDATES
Miscellaneous information by DOT Law (IAW DOT H 1350.253):
• FRA Office of IT will be responsible for security, back up, and maintenance of the application or system. FRA NOC (Network Operations Center)
• List of interconnected systems (including Internet); Internet
• Unique system identifiers, if appropriate; FRA,
• Name of system(s); ATIP
• Organization owning the other system(s); FRA
• Type of interconnection (TCP/IP, Dial, SNA, etc.); VPN through TCP/IP
• Short discussion of major concerns or considerations in determining interconnection;
Maintain security throughout implementation with VPN and PIX
• Types of Managerial, Operational, and Technical Security implemented to protect application or system. NetContinuum, PIX, and VPN Firewall
• System of Record, if applicable (Privacy Act data); No, records not retrievable by individual name – Under Privacy Act of 1974.
• Sensitivity level of each system; Sensitive but not Classified
• Interaction among systems; the only systems involved are the ATIP Databases through the web interface for upload and retrieval of data.
• Rules of Behavior of the other systems that need to be considered in the protection of this system: Users cannot be logged in to any other systems at the same time a user is logged into ATIP via VPN connections. All sessions will be terminated upon illegal behavior or detection of intrusion to other systems connected to the site other than the ones authorized. This system cannot be used for any purpose other than the one outlined above under the title: Purpose.
• All contractor personnel assigned to the contract that are using the FRA/ENSCO VPN solution must complete the Federal Railroad Administration IT System Rules of Behavior form provided (attachment #3) prior to accessing the FRA network. The completed form must be sent to Mr. Tim Pemberton at tim.pemberton@dot.gov.
G. IMPLEMENTATION
This agreement remains in effect until superseded by another MOU or until the end of the contract support.
H. SIGNATORY AUTHORITY
I agree to the terms of this Memorandum of Understanding (or Agreement).
FRA IT Director , IT and Support Systems <<<Contractor Title>>>
Arnel Rivera <<<Contractor Name>>>
Signature Date Signature Date
File details come from the government source that posted it. Updated .