Attachment_P_-_IT_Security_and_Privacy_Lang.pdf
PDF 116 KB Posted
- Attached to
- Automated Track Inspection Program (ATIP) Federal contract opportunity
- Solicitation number
- DTFR5316R00382
About this file
Attachment P - IT Security & Privacy Language
View the file
Other files for this federal contract opportunity
Show all 25
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment P
ATTACHMENT P
SECURITY- PRIVACY REQUIREMENTS FOR
UNCLASSIFIED INFORMATION
TECHNOLOGY (IT) RESOURCES
(a) Required Policies and Regulations - The Contractor shall comply with all prevailing Department of Transportation (DOT), Federal Railroad Administration (FRA), and Federal IT Security standards, policies, and reporting requirements, including:
(1) Federal Information Security Management Act (FISMA) of 2002
(2) Clinger-Cohen Act of 1996 also known as the “Information Technology Management
Reform Act of 1996.”
(3) Privacy Act of 1974 (5 U.S.C. § 552a)
(4) Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information Resources”, and Appendix III, “Security of Federal Automated Information Systems”, as amended.
(5) OMB Memorandum M-03-22 – OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002
(6) OMB Memorandum M-04-04, “E-Authentication Guidance for Federal Agencies.”
(7) OMB Memorandum M-05-04, “Policies for Federal Agency Public Websites (December 17, 2004) Best Practices”
(8) OMB Memorandum M-05-24, “Implementation of Homeland Security Presidential
Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors”
(9) OMB Memorandum M-06-15, “Safeguarding Personally Identifiable Information (May
22, 2006)”
(10) OMB Memorandum M-06-16, “Protection of Sensitive Agency Information”
(11) OMB Memorandum M-06-19, “Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments (July 12, 2006)”
(12) OMB Memorandum M-06-20, “FY 2006 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management”
(13) OMB Memorandum M-07-16, “Safeguarding Against & Responding to Breach of
Personally Identifiable Information”
(14) OMB Memorandum M-07-19, “Reporting Instructions for the Federal Information
Security Management Act and Agency Privacy Management “
(15) OMB Memorandum M-08-22, “Guidance on the Federal Desktop Core Configuration
(FDCC)”
(16) Federal Information Processing Standards (FIPS) Publication (PUB) 199, “Standards for Security Categorization of Federal Information and Information Systems.”
(17) FIPS PUB 200, “Minimum Security Requirements for Federal Information and
Information Systems.”
(18) Federal Enterprise Architecture - Security and Privacy Profile (FEA-SPP) version 3 May 5,
(19) NIST SP 800-28, “Guidelines on Active Content and Mobile Code”
(20) NIST Special Publication 800-30, “Risk Management Guide for Information Technology
Security Risk Assessment Procedures for Information Technology Systems”
(21) NIST SP 800-37 rev 1, “Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach”
(22) NIST SP 800-44, “Guidelines on Securing Public Web Servers”
(23) NIST SP 800-47, “Security Guide for Interconnecting Information Technology Systems”
(24) NIST SP 800-53, “Recommended Security Controls for Federal Information Systems”
(25) NIST SP 800-61, “Computer Security Incident Handling Guide”
(26) NIST SP 800-63, “Electronic Authentication Guidance”
(27) NIST SP 800-64, “Security Considerations in the System Development Life Cycle”
NIST SP 800-77, “Guide to IPSec VPNs”
(28) NIST SP 800-83, “Guide to Malware Incident Prevention and Handling”
(29) NIST SP 800-87, “Codes for Identification of Federal and Federally-Assisted Organizations”
(30) NIST SP 800-96, “Guide to Secure Web Services”
(31) NIST SP 800-115, “Technical Guide to Information Security Testing and Assessment”
(32) NIST SP 800-122, “Guide to Protecting the Confidentiality of Personally Identifiable
Information (PII)”
(33) NIST SP 800-123, “Guide to General Server Security”
(34) NIST SP 800-125, “Guide to Security for Full Virtualization Technologies”
(35) NIST SP 800-128, “Guide for Security-Focused Configuration Management of Information Systems”
(36) NIST SP 800-137, “Information Security Continuous Monitoring for Federal Information
Systems and Organizations”
(37) C.F.R. Part 5 Subpart C (5 C.F.R 930.301), “Information Security Responsibilities For Employees Who Manage Or Use Federal Information Systems: Information systems security awareness training program”
(38) Center of Internet Security (CIS) Benchmarks/Guidelines (Level 1 for internal systems and Level 1&2 for external facing systems)
(39) National Vulnerability Database Guidelines
(40) DOT Order 1351.37, “Departmental Cybersecurity Policy”
(41) DOT Departmental Cybersecurity Compendium “Supplement to DOT Order 1351.37
Departmental Cybersecurity Policy”
(42) DOT Information Technology and Information Assurance Policy: Implementation of DOT’s Protection of Sensitive Personally Identifiable Information (SPII)
(43) DOT Security Authorization and Continuous Monitoring Guide version 1 23 January
(44) DOT Weakness Management Guide version 1.0, November 2, 2011
(45) DOT Automated Continuous Monitoring Guide version 1 February 20, 2013
(46) DOT Compendium with FRA Security and Privacy Baseline
(b) Applicability - The Contractor shall be responsible for Information Technology security for all systems connected to FRA network or operated by the Contractor for FRA, regardless of location. This clause is applicable to all or any part of the contract that includes information technology resources or services in which the Contractor has physical or electronic access to FRA information that supports the mission of FRA. The term information technology, as used in this clause, means any equipment or interconnected system or subsystem of equipment, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information. This includes both major applications and general supports systems as defined by OMB Circular A-130.
(c) Security Categorization - In accordance with FIPS 199, “Standards for Security
Categorization of Federal Information and Information Systems”, FRA has determined that the security category of the information or information system under this contract is [MODERATE]. The Contractor shall tailor an appropriate set of baseline security requirements as outlined in NIST Special Publication (SP) 800-53, “Recommended Security Controls for Federal Information Systems”, and the Center of Internet Security (CIS) guidelines (Level 1 for internal systems and Level 1&2 for external facing systems).
(d) Continuous Monitoring - The Contractor shall facilitate a consistent approach to managing security risks for FRA IT systems in accordance with National Institute of Standards and Technology (NIST) Special Publication 800-37 (as amended), Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, National Institute of Standards and Technology Special Publication 800-137 (as amended), Information Security Continuous Monitoring for Federal Information Systems and Organizations, DOT Security Authorization and Continuous Monitoring Performance Guide, and FRA Continuous Monitoring Plan. The Contractor shall provide oversight and monitoring of security controls for managing all systems and software operated by the Contractor. The Contractor shall develop methods for advising and auditing operational and business practices so as to ensure due diligence and provide adequate security for the systems under their control or responsibility.
The Contractor shall report on all in-scope FRA systems on an ongoing basis and inform the COR and ISSM when changes occur that may impact the security of the system.
The Contractor shall perform review activities to include, but are not limited to, weekly operating system vulnerability scanning, web application scanning, and database scanning of applicable systems that support the processing, transportation, storage, or security of FRA information using the relevant tools as required and directed by the ISSM, identify deficiencies and make recommendations for remedies to the ISSM. The Contractor shall develop the reporting processes necessary to provide FRA ISSM and Management with real-time visibility and scoring of the security posture and its assets.
The Contractor shall provide the relevant tools necessary for the execution of system security continuous monitoring to ensure completion of the above tasks.
(e) Availability of Documents and Access - The Contractor shall provide FRA (or FRA designated third party contractors) access to the Contractor’s and subcontractors’ facilities, installations, operations, documentation, databases, and personnel used in performance of the contract. Access shall be provided to the extent required to carry out physical security site assessments, investigations, and/or audits to safeguard against threats and hazards to the integrity, availability, and confidentially of FRA information or to the functions of information technology operated on behalf of FRA, and to preserve evidence of computer crime. To facilitate mandatory reviews, the Contractor shall ensure appropriate compartmentalization of FRA information, stored and/or processed, either by information systems in direct support of the Contractor or that are incidental to the contract.
(1) User Authorization Review Documents - Reference: NIST SP 800-53, “Recommended
Security Controls for Federal Information Systems” controls AC-2 – The Contractor shall provide the results of the annual review and validation of system users’ accounts to ensure the continued need for system access. The user authorization documents will illustrate the organization establishes, activates, modifies, reviews, disables, and removes information system accounts in accordance with documented account management procedures.
(2) Separation of Duties Matrix - Reference: NIST SP 800-53, “Recommended Security
Controls for Federal Information Systems” control AC-5 - The Contractor shall develop and furnish a separation of duties matrix reflecting proper segregation of duties for IT system maintenance, management, and development processes.
(3) Information Security Awareness and Training Records - Reference: NIST SP 800-53, “Recommended Security Controls for Federal Information Systems” control AT-4 –The Contractor shall ensure that employees receive security awareness (AT-2) and role-based information security technical training (AT-3) and shall provide documentation of this training to FRA. AT-2 requires basic security awareness training for FRA employees and contractors that support the operation of the Contractor system. AT-3 requires information security technical training to information system security roles. Training shall be consistent with the requirements contained in C.F.R. Part 5 Subpart C (5 C.F.R 930.301) and conducted at least annually.
(4) System(s) Baseline Configuration Standard Document - Reference: NIST SP 800-53, “Recommended Security Controls for Federal Information Systems” control CM-2 – the Contractor shall provide a well-defined, documented, and up-to-date a current baseline configuration of the information system.
(5) System Configuration Settings - Reference: NIST SP 800-53, “Recommended Security
Controls for Federal Information Systems” control CM-6 – The Contractor shall establish and document mandatory configuration settings for information technology products employed within the information system that reflect the most restrictive mode consistent with operational requirements. Configuration settings are the configurable security-related parameters of information technology products that compose the information system; and identify and document exceptions from the mandatory configuration settings for individual components within the information system based on explicit operational requirements. Systems should be configured in agreement with NIST guidelines at the NIST Checklist website (checklists.nist.gov) and the Center for Internet Security (CIS) guidelines (Level 1 - for internal information systems), Level 1&2 – for external facing information systems), and the National Vulnerability Database Guidelines, unless a waiver is granted by the FRA CIO/ISSM.
(6) Information System Interconnection Agreements - Reference: NIST SP 800-53, “Recommended Security Controls for Federal Information Systems” control CA-3 – The Contractor shall provide updated Interconnection Security Agreements (ISA) and supporting Memorandum of Agreement/Understanding (MOA/U), completed in accordance with NIST SP 800-47, “Security Guide for Connecting Information Technology Systems”, for existing and new interconnections. Per NIST SP 800-47, “Security Guide for Interconnecting Information Technology Systems” an interconnection is the direct connection of two or more IT systems for the purpose of sharing data and other information resources through a pipe, such as ISDN, T1, T3, DS3, VPN, etc.
(7) Rules of Behavior - Reference: NIST 800-53, “Recommended Security Controls for
Federal Information Systems” control PL-4 – The Contractor shall a. establish and make readily available to all information system users, the rules that describe their responsibilities and expected behavior with regard to information and information system usage; and b. receive signed acknowledgment from users indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the information system.
(f) Controlled Unclassified Information - All deliverables under this section shall be labeled according to the sensitivity of the information. FOR OFFICIAL USE ONLY (FOUO), Sensitive Security Information (SSI), and/or other designations as directed by FRA shall be applied to paper and electronic documents. External transmission/dissemination of sensitive unclassified information to or from a FRA computer must be encrypted. Certified encryption modules must be used in accordance with FIPS PUB 140-2, “Security requirements for Cryptographic Modules.” Handling, storage, processing, transmitting and discussing of Controlled Unclassified Information shall be in accordance with FRA guidance in order to prevent the release of such information to persons not authorized by FRA to have access to the information.
(g) Federal Desktop Core Configuration/US Government Configuration Baseline - The Contractor shall certify applications are fully functional and operate correctly as intended on systems using the Federal Desktop Core Configuration (FDCC)/US Government Configuration Baseline (USGCB). This includes Internet Explorer configured to operate on Windows. The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved FDCC/USGCB configuration. The information technology should also use the Windows Installer Service for installation to the default “program files” directory and should be able to silently install and uninstall. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges. The Contractor shall use Security Content Automation Protocol (SCAP) validated tools with FDCC/USGCB Scanner capability to certify their products operate correctly with FDCC/USGCB configurations and do not alter FDCC/USGCB settings.
(h) System Access Notice - The Contractor shall ensure that the following banners are displayed on all FRA systems (both public and private) operated by the Contractor prior to allowing authenticated access to the system(s):
“ATTENTION ATTENTION ATTENTION
• You are accessing a U.S. Government information system, which includes (1) this computer, (2) this computer network, (3) all computers connected to this network, and
(4) all devices and storage media attached to this network or to a computer on this network. This information system is provided for U.S. Government-authorized use only.
• Unauthorized or improper use of this system may result in disciplinary action, as well as civil and criminal penalties.
• By using this information system, you understand and consent to the following:
o You have no reasonable expectation of privacy regarding any communications or data transiting or stored on this information system. At any time, and for any lawful government purpose, the government may monitor, intercept, and search and seize any communication or data transiting or stored on this information system.
o Any communications or data transiting or stored on this information system may be disclosed or used for any lawful government purpose.
[click button: “I AGREE”]
(i) Privacy Act Notifications - As prescribed in the Federal Acquisition Regulation (FAR) clause 24.104, if the system involves the design, development, or operation of a system of records on individuals, the Contractor shall implement requirements in FAR clause 52.224-1, “Privacy Act Notification” and FAR clause 52.224-2, “Privacy Act.” The Contractor shall ensure that the following banner is displayed on all FRA systems that contain Privacy Act information operated by the Contractor prior to allowing anyone access to the system:
“This system contains information protected under the provisions of the Privacy Act of 1974 (Public Law 93-579). Any privacy information displayed on the screen or printed shall be protected from unauthorized disclosure. Individuals who violate privacy safeguards may be subject to disciplinary actions, a fine of up to $5,000, or both.”
(j) Non-Disclosure Agreements - The Contractor shall cooperate in good faith in defining non-disclosure agreements that other third parties must sign when acting as the Federal government’s agent.
(k) Non-Disclosure of Security Safeguards - In accordance with the Federal Acquisitions
Regulations (FAR) clause 52.239-1, the Contractor shall be responsible for the following privacy and security safeguards: The Contractor shall not publish or disclose in any manner, without the contracting officer’s written consent, the details of any safeguards either designed or developed by the Contractor under this contract or. If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.
(l) Security of Systems Handling Personally Identifiable Information And Privacy Incident Response
(a) Definitions.
“Breach” (may be used interchangeably with “Privacy Incident’) as used in this clause means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to Personally Identifiable Information, in usable form whether physical or electronic.
“Personally Identifiable Information (PII)” as used in this clause means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States.
Examples of PII include: name, date of birth, mailing address, telephone number, Social Security Number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), Internet protocol addresses, biometric identifiers (e.g., fingerprints), photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Personally Identifiable Information (Sensitive PII)” as used in this clause is a subset of Personally Identifiable Information, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. , Complete social security numbers (SSN), alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered Sensitive PII even if they are not coupled with additional PII. Additional examples include any groupings of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
(1) Driver’s license number, passport number, or truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Financial information such as account numbers or Electronic Funds Transfer
Information
(5) Medical Information
(6) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)
Other Personally Identifiable information may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains Personally Identifiable Information but it is not sensitive.
(b) Systems Access.
Work to be performed under this contract requires the handling of Sensitive PII. The contractor shall provide the Government access to, and information regarding systems the contractor operates on behalf of the Government under this contract, when requested by the Government, as part of its responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the Government in assuring compliance with such requirements. Government access shall include independent validation testing of controls, system penetration testing by the Government, Federal Information Security Management Act (FISMA) data reviews, and access by agency Inspectors General for its reviews.
(c) Systems Security
In performing its duties related to management, operation, and/or access of systems containing Sensitive PII under this contract, the contractor, its employees and subcontractors shall comply with applicable security requirements or any replacement publication and rules of conduct described in DOT Order 1351.37.
In addition, use of contractor-owned laptops or other media storage devices to process or store PII is prohibited under this contract until the contractor provides, and the contracting officer in coordination with CISO approves, written certification by the contractor that the following requirements are met:
(1) Laptops employ encryption using a NIST Federal Information Processing Standard (FIPS) 140-2 or successor approved product;
(2) The contractor has developed and implemented a process to ensure that security and other applications software are kept current;
(3) Mobile computing devices utilize anti-viral software and a host-based firewall mechanism;
(4) When no longer needed, all removable media and laptop hard drives shall be processed (i.e., sanitized, degaussed, or destroyed) in accordance with DOT security requirements.
(5) The contractor shall maintain an accurate inventory of devices used in the performance of this contract;
(6) Contractor employee annual training and rules of conduct/behavior shall be developed, conducted/issued, and acknowledged by employees in writing. Training and rules of conduct shall address at minimum:
(i) Authorized and official use;
(ii) Prohibition against use of personally-owned equipment to process, access, or store Sensitive PII;
(iii) Prohibition against access by unauthorized users and unauthorized use by authorized users; and
(iv) Protection of Sensitive PII;
All Sensitive PII obtained under this contract shall be removed from contractor-owned information technology assets upon termination or expiration of contractor work. Removal must be accomplished in accordance with DOT Order 1351.14 which the contracting officer will provide upon request. Certification of data removal will be performed by the contractor’s Project Manager and written notification confirming certification will be delivered to the contracting officer within 15 days of termination/expiration of contractor work.
(d) Data Security.
Contractor shall limit access to the data covered by this clause to those employees and subcontractors who require the information in order to perform their official duties under this contract. The contractor, contractor employees, and subcontractors must physically secure Sensitive PII when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss. When Sensitive PII is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed through means that will make the Sensitive PII irretrievable.
The contractor shall only use Sensitive PII obtained under this contract for purposes of the contract, and shall not collect or use such information for any other purpose without the prior written approval of the contracting officer. At expiration or termination of this contract, the contractor shall turn over all Sensitive PII obtained under the contract that is in its possession to the Government.
(e) Breach Response.
The contractor agrees that in the event of any actual or suspected breach of Sensitive PII (i.e., loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic), it shall immediately, and in no event later than one hour of discovery, report the breach to the contracting officer, the Contracting Officer’s Technical Representative (COTR), and the Information Systems Security Manager. The contractor is responsible for positively verifying that notification is received and acknowledged by at least one of the foregoing Government parties.
(f) Personally Identifiable Information Notification Requirement.
The contractor has in place procedures and the capability to promptly notify any individual whose Sensitive PII was, or is reasonably believed to have been, breached, as determined appropriate. The method and content of any notification by the contractor shall be coordinated with, and subject to the prior approval of the Government, based upon a risk-based analysis conducted by the Government in accordance with DOT Privacy incident Handling Guidance. Notification shall not proceed unless the Government has determined that: (1) notification is appropriate; and (2) would not impede a law enforcement investigation or jeopardize national security.
Subject to Government analysis of the breach and the terms of its instructions to the contractor regarding any resulting breach notification, a method of notification may include letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. At minimum, a notification should include: (1) a brief description of how the breach occurred; (2) a description of the types of personal information involved in the breach; (3) a statement as to whether the information was encrypted or protected by other means; (4) steps an individual may take to protect themselves; (5) what the agency is doing, if anything, to investigate the breach, to mitigate losses, and to protect against any further breaches; and (6) point of contact information identifying who affected individuals may contact for further information.
In the event that a Sensitive PII breach occurs as a result of the violation of a term of this contract by the contractor or its employees, the contractor shall, as directed by the contracting officer and at no cost to the Government, take timely action to correct or mitigate the violation, which may include providing notification and/or other identity protection services to affected individuals for a period not to exceed 12 months from discovery of the breach. Should the Government elect to provide and/or procure notification or identity protection services in response to a breach, the contractor will be responsible for reimbursing the Government for those expenses.
(g) Pass-Through of Security and Privacy Requirements to Subcontractors.
The contractor shall incorporate the substance of this clause, its terms and requirements, in all subcontracts under this contract, and to require written subcontractor acknowledgement of same. Violation by a subcontractor of any provision set forth in this clause will be attributed to the contractor.
[click button: “I AGREE”]
File details come from the government source that posted it. Updated .