Attachment_A_-_Statement_of_Objectives.pdf
PDF 111 KB Posted
- Attached to
- Case Management System Federal contract opportunity
- Solicitation number
- EDEFCM16Q0001
About this file
Attachment A - Statement of Objectives 7.29.16
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FBO_Award_Notice.pdf | ||
| Additional_Vendor_Questions_and_Responses.pdf | ||
| Attachment_A_-_Statement_of_Objectives.pdf | ||
| Vendor_Questions_and_Responses.pdf | ||
| Amendment_to_CLINs.pdf | ||
| EDEFCM16Q0001_Case_Management_System.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Solicitation No. EDEFCM16Q0001 Attachment A – July 29, 2016
Statement of Objectives
Case Management System
EDEFCM16Q0001
I. Purpose
The U.S. Department of Education (ED) Office of Inspector General (OIG) Investigations Services (IS or Investigations) requires the services of a contractor to host a Commercial off the Shelf (COTS) investigative case management system. The system will be used for case activity/document management, event tracking, result tracking, time tracking, training tracking, and reporting for internal performance measures and requirements from Congress. The system must be operational and all requirements must be met by March 1, 2017 so that Fiscal Year quarterly, semi-annual, and annual results and reports are produced from the same system.
The contractor will provide technical support and maintenance of the product. All work must be performed and in compliance with Federal and Department regulations.
II. Background
The current case management system, U.S. Department of Education Investigative Tracking System (EDITS), does not meet the needs of ED OIG. Specifically, ad-hoc reporting is not possible, changes to the system cannot be made in a timely manner without information technology experts, and IS needs a solution with greater flexibility.
EDITS is housed on in–house servers that work off of a 2008 R2 SQL Server and a .NET version
4.0 platform. It is classified as a Tier 2 Major Application (MA) residing on the local area network (LAN) general support system (GSS), which resides on the Department of Education network (EDUCATE) as a child domain. The MA requires special attention to security due to the risk and magnitude of the harm that could result from the loss, misuse, unauthorized access, or modification of the information in the application. Currently, users access the system through e-Authentication in the form of Government issued Personal Identity Verification (PIV) card. It is a front end web application running on Internet Information Services (IIS) and .NET platforms. The back end Microsoft SQL server authenticates the user and contains the investigative data.
The system provides personnel with a mechanism to process numerous types of complaints. The case management system stores and retrieves the complaint supporting information that could be a paragraph, a page, or hundreds of pages. The following databases are part of the current application: Activities, documents sensitive, documents standard, Hotline, inventory, investigators, OIG MIS, EX Parte, Grand Jury, Sequestration, Outreach, Sources, Time and Training. We are currently working with a total of approximately 80-100 users.
OIG users access the current system using a Government issued laptop, a Windows domain account, a PIV, and SQL user accounts. The government issued laptop complies with the United
States Government Configuration Baseline (USGCB). It runs the Windows 7 Operating System and Internet Explorer 9 or 11. We use Microsoft Office 2010 with a likely upgrade to 2013. Any COTS product will need to be accessible using the same configuration.
On average, we receive approximately 5,000 hotline complaints and open nearly 700 preliminary cases and 85 full investigations each year.
III. Scope
The Statement of Objectives (SOO) addresses the scope of the procurement. The procurement shall:
1. Provide COTS case management software (CMS) that meets the objectives listed in Section XII and that is customizable by non-information technology personnel.
2. Provide hosted COTS CMS software that has agency Federal Risk and Authorization Management Program (FedRAMP) Software as a Service (SaaS) authorization, FedRAMP SaaS provisional authorization (PATO), or will complete all actions necessary and submit a complete FedRAMP package for agency authorization by February 1, 2017. This includes the implementation of all FedRAMP security controls, independent assessment conducted by an approved third-party assessment organization (3PAO), and the creation and submission of all required documentation. A FedRamp-compliant ATO issued by the OIG will be required.
3. Provide a hosting environment during development and configuration of the CMS.
4. Provide migration services from legacy system (with support from previous contractor) to hosted environment.
5. Provide a public facing hotline website. The hotline website form must securely transfer the original complaint data collected from the website to the CMS both in PDF format and by populating CMS fields that are editable by appropriate personnel. See Technical Requirements for Hotline in Section XII.
The product must meet the technical requirements and the contractor shall provide an oral/visual presentation upon request to demonstrate how the requirement can be met.
IV. Period and Place of Performance
The base Period of Performance will be 1 year from the date of award with four, one year options. The first year includes initial configuration of the system and assistance with importing data and documents from the current CMS, as well as any customization or minor development work necessary to meet all requirements (must be completed and tested by go live date). For option years, the contractor will provide COTS licensing (if not perpetual), software maintenance (software patches/upgrades), help desk support for administrators, and hosting, to include all required system administration, maintenance, and security services. The contractor may choose to provide software-as-a-service in lieu of a perpetual license; however, the contractor is encouraged to provide the option to move to a perpetual license at the end of the base year or any option year.
The contractor will perform the majority of the work off-site. Occasional meetings and at other required times, work may be performed at the ED-OIG Headquarters site located at 550 12th Street S.W., Washington, D.C. If the contractor is required to travel to a field location other than the Washington, DC location, the travel costs (transportation and per diem) will be paid by the Government subject to prior approval by the Contracting Officer.
V. Review of Deliverables
On a regular basis, no less than once a month, the contractor will report their deliverables to the Contracting Officer’s Representative (COR) in a monthly status report until the system is fully operational. Project documentation/presentation must be developed using an acceptable format.
VI. Government furnished equipment
No equipment will be furnished by the government with the exception of access to the government servers, as needed, and a PIV card necessary for testing.
VII. Personnel
Any contractor personnel who has access to the investigative data or administrator level access to the database or the case management system is required to have and maintain a 6c, or above, public trust clearance (noncritical-sensitive ADP) and provide documentation to the COR prior to start of the project. If contractor personnel do not already have appropriate clearances, the agency will pay for the background investigation; however, the contractor is still required to comply with the timelines of the contract.
VIII. Non-Disclosure Agreement
Standard non-disclosure statements must be provided as required for system administration personnel who may have access to government data in the course of their duties.
IX. Accessibility
The system must meet technical standards for Section 508 compliance at 36 C.F.R. 1194.21 and
1194.22. Information about the Section 508 Electronic and Information Technology (EIT) Accessibility Standards may be obtained via the Web at the following URL:
http://www.Section508.gov.
http://www.section508.gov/
X. Data Isolation and Portability
All data (e-mail traffic, contact information, calendar contents, etc.) remains the property of the government. The contractor must ensure that the government retains access and download capability of all data for research, investigation, transfer, or migration to other systems.
XI. Confidentiality, Security, and Privacy
The contractor shall be responsible for the following privacy and security safeguards:
a. The work on this project may require or allow contractor personnel access to Privacy Information. The contractor shall be responsible for complying with the requirements of the Privacy Act, 5 U.S.C. 552a, the E-Government Act of 2002, 44 U.S.C. § 101, the Federal Information Security Management Act, 44 U.S.C. §3541 (FISMA), as well as OMB directives OMB M-06-16, OMB M-07-16, FIPS 201 and FIPS 140-2.
The Contractor shall abide by and follow all applicable federal and state regulations, such as the FAR, and all departmental privacy policies, procedures, processes, and standards.
b. All data at rest will reside within the contiguous United States, the District of Columbia, and Alaska (CONUS) with a minimum of two data center facilities at two different and distant geographic locations.
XII. Performance Objectives
The contractor shall demonstrate that the objective can be met out of the box or with custom work. The contractor shall adequately describe how the following objectives can be met.
1.1. Security and Data Integrity
1.1.1. For base year and option years, the procurement shall include maintenance support/assistance calls with OIG key personnel.
1.1.2. The system must support and require two-factor user authentication via HSPD-12 PIV card.
1.1.3. The procurement shall provide maintenance support to include security and other patching for system as well as all updates that provide new capabilities, in base and option years.
1.1.4. The system must have a pre-logon warning banner (Accept or Decline). The language will be provided by the government.
1.1.5. System vulnerabilities identified by the contractor or ED OIG shall be remediated within 30 days or in accordance with requirements specified in approved FedRAMP documentation.
1.1.6. The contractor shall develop application databases in accordance with FIPS 140-2 data encryption requirements.
1.1.7. All communications to and from the case management system and hotline servers must be established in accordance with FIPS 140-2 data encryption requirements (e.g., TLS). Any temporary files stored on the server must be encrypted.
1.1.8. The system must provide the ability to set a user’s session to automatically end or time out within a specified length of time.
1.1.9. The system security and access to records is controlled by role based permissions.
1.1.10. The role based permissions must have the ability to assign read only or read-write access to cases and to fields/areas within a case.
1.1.11. Users must not be able to bypass role based permissions by running reports or conducting searches.
1.1.12. The system shall provide additional security protection to case documents or chronology entries marked as grand jury, sensitive, or ex-parte. The access to this information must be limited to a case-specific list of users (trumps other role based security) defined by the case agent or supervisor respective to each marking (grand jury, sensitive, ex-parte).*
1.1.13. The system shall provide additional security protection to a case marked as sensitive.
The access to the entire case must be limited to a case-specific list of users (trumps other role based security) defined by the case agent or supervisor or predefined role (non-administrator) that has access to all sensitive cases.
1.1.14. The system shall provide the ability to limit editing of information in a case based on its status such as not allowing edits to fields after a case is closed.
1.1.15. The system shall have system auditing capability to track user activity. This includes logging changes made to a case along with the date/time stamp and the user. The access to and ability to clear the logs must be restricted to a specific role.*
1.1.16. The system shall limits one session per user at any given time.
1.1.17. Appropriate OIG personnel must be able to add/disable users, assign/change roles, define permission based roles, and other administrative functions without the assistance of the contractor or information technology specialist.
1.1.18. Security roles must support organizational structure.
1.2. System
1.2.1. The system shall provide a single easy to use Graphical User Interface into the system.
1.2.2. The system shall allow for multi-user simultaneous access to CMS and individual cases. The system shall support a total of 110 active users with 20 simultaneous users accessing the system at any given time.
1.2.3. The system shall support the upload of all industry standard document, audio, video, and picture formats.
1.2.4. The document section shall support Web Distributed Authoring and Versioning (WEBDav), enabling the online creation, editing, and version control for standard Microsoft Office products such as Microsoft Word, Excel, and InfoPath.
1.2.5. The text entry areas shall have a Spell Checking feature.
1.2.6. The system must be scalable such that custom fields can be added to case screens or individual/entity screens by ED OIG personnel without the assistance of the contractor or an information technology specialist. The field types shall include text boxes, text areas, check boxes, date, multi-select pick lists, dropdowns, number fields, and supports data validation.*
1.2.7. The system must be configurable such that field labels and messages can be altered to match the organizations standard terminology.
1.2.8. The system shall have the ability to, at regular intervals, update database lookup tables with standardized lists of government programs, schools, and other pick lists, compensating for duplicates or changes.*
1.2.9. The system shall have the ability to automatically complete a company entity screen based on a picklist of schools, which can be updated regularly as described above in requirement 1.2.8. Note: The list is approximately 51,200 records.
1.2.10. The system shall have the ability to automatically complete a company entity screen based on a search of System for Awards Management (SAM) using the SAM application programming interface (API).
1.2.11. The system shall have the ability to identify and prevent entry of duplicate entities based on specific unique fields such as SSN, School ID, or DUNS number to ensure standardized/consistent entry and linking of records, as needed.*
1.2.12. The system shall have the ability to perform automated address standardization/verification.*
1.2.13. The system shall have a customizable Home Page Dashboard based on user role.
1.3. Case Management (Universal to Complaint, Preliminary, or Investigation)
The system shall:
1.3.1. Act as the single repository for all case related information;
1.3.2. With appropriate permissions, allow users the ability to initiate a case type (e.g., complaint, preliminary, or investigation);
1.3.3. Generate a unique case number that incorporates the fiscal year and that resets and assigns a next number by fiscal year. It is preferred that the case number be maintained as case changes from a preliminary to an investigation;*
1.3.4. With appropriate permissions, allow users the ability to convert a Complaint to a Preliminary, and a Preliminary to an Investigation while preserving associated data and documents.*
1.3.5. Have the ability to assign users to an investigation and specify investigative role in investigation (e.g., lead agent);
1.3.6. Have the ability to create spin off investigations (e.g., tracks related cases);*
1.3.7. Retain all case numbers associated or preceding a complaint, lead, or investigation;
1.3.8. Have the capability of assigning and tracking multiple violations to each subject in the case;*
1.3.9. Support various case categorization fields to include complaint source, crime type
(multi-select), proactive/reactive/source generated, suspect type, and affected program (multi-select);
1.3.10. Allow users to create entities, associate them with a case, and categorize the type within a case (Subject, Victim, Witness, Incidental);
1.3.11. Allow the ability to change the status of an entity (witness to subject);
1.3.12. Be capable of recording multiple investigation techniques (search warrant, wiretap) for a case to include the date the technique was used. This may include multiple activities on the same date for the same case (e.g. multiple warrants on the same day);*
1.3.13. Have the ability to sort documents and other items in the case based on type and date;
1.3.14. Maintain and display a running online chronology of case events/notes entered by the case agent, including who added the entry;*
1.3.15. Categorize chronology entries, but with a default value (e.g. General Comment, Case
Review, etc.)
1.3.16. Automatically enter events in the chronology based on the entry of specific information within the case (e.g.,when an interview is uploaded, a chron entry documenting the event is automatically created);*
1.3.17. Require supervisor approval for specified case document types;*
1.3.18. Have the ability, with appropriate permissions, to delete approved documents;
1.3.19. Automatically deletes draft revisions after a document is marked final/approved or the ability to mass delete drafts for a case;*
1.3.20. Maintain record/log, preferably in the case chronology, of changes to case type
(Complaint, Preliminary, Investigation) and case status (Opened, Closed, Closed Pending) including date, person performing action, and previous and new state;
1.3.21. Have the ability to have all interviews, indictments, convictions, sentencings, and acceptances/declinations associated with an entity in the case;*
1.3.22. Have the ability to logically attach files to documents and number the attachments.
For example, a memorandum of interview (MOI) may have a waiver of rights and a document shown during the interview attached to the MOI;*
1.3.23. Have the ability to delete all records associated with an investigation once a records retention period has been reached (e.g., 10 years after the end of the fiscal year when the case was closed); and
1.3.24. Have the ability to track the referral of cases to other agencies/organizations.
1.4. Hotline
1.4.1. The procurement shall provide and develop a public facing hotline complaint form website for the public to provide initial complaints to the hotline.
1.4.2. The website must be hosted on Department of Education server and use .Net or Cold Fusion programming languages or if the contractor will be hosting the site, it must be within the FedRAMP authorization boundary, but outside the Agency Information System Authorization Boundary.
1.4.3. The website must be written in HTML and .Net or Cold Fusion.
1.4.4. The submission of any new complaint requires captcha.
1.4.5. The public facing website must meet 508 compliance standards.
1.4.6. The public facing webpage must support ability to switch languages for page in accordance with the Limited English Proficiency requirements (foreign language text will be provided).
1.4.7. Information collected from the hotline website must automatically and expeditiously be securely transmitted to the CMS and populate the appropriate fields in a new complaint record. The hotline website must not retain any user data.
1.4.8. The system has the ability to edit the pre-populated fields from the hotline complaint.*
1.4.9. The initial information collected from the hotline website must be converted to single PDF document and attached to initial CMS record to preserve the initial complaint.*
1.4.10. In accord with OMB Memorandum M-05-04, and with the NIST SP 800-44, all publicly accessible Federal websites and web services must have HTTPS enabled, and shall only provide service over a secure connection, and e-mail applications must have SMTP enabled.
1.5. Investigation
The system is capable of:
1.5.1. Assigning and tracking multiple administrative actions to each subject in a case;
1.5.2. Assigning and tracking multiple legal actions to each subject in a case;
1.5.3. Assigning and tracking multiple statutes and sentencing actions (fines, assessments, restitution, confinement, probation, supervised release, community service) to each subject in a case;*
1.5.4. Assigning and tracking multiple financial results (recoveries, fines, savings) to each subject in a case; *
1.5.5. Creating electronic templates (e.g. interviews and Reports of Investigation) with automated population of certain case information;*
1.5.6. Assigning and tracking multiple case statuses and properly route the case based on the status for appropriate action;
1.5.7. Creating automated workflow processes with the ability to document to approve and assign tasks;*
1.5.8. Having time and event notification;
1.5.9. Locking a case to prevent further editing;
1.5.10. Closing a case with follow-up actions pending in order to lock all case information with the exception of the follow-up action/results fields;
1.5.11. Automatically triggering actions, to include email notifications and dashboard indicators;
1.5.12. Providing notification on the user’s dashboard and/or by email;
1.5.13. Verifying specified information has been entered prior to allowing case closing; and
1.5.14. Customizing the case closing actions for investigations.
1.6. Reporting (FOIA, eDiscovery, Indexing, Searching, and Reporting)
1.6.1. Generating reports on activities and investigations conducted by OIG personnel assigned to an investigation;
1.6.2. Performing full text searches and retrieval of documents;
1.6.3. Providing person search capabilities for fast name checks;
1.6.4. Performing quick searches based on the most common system fields;
1.6.5. Performing advanced searches with options to provide specific search criteria for most database fields;
1.6.6. Changing search result column displays, ordering and sorting characteristics;
1.6.7. Creating and producing ad hoc reports where multiple fields and criteria can be specified;*
1.6.8. Producing complex ad hoc reports, such as all investigations associated with a query of entities (e.g. list all cases where an employee was a subject in the investigation);*
1.6.9. Performing time computations to report information such as days in status, days since last investigative activity, and investigative results;
1.6.10. Producing reports in Excel/CSV format;
1.6.11. Producing reports in PDF format;
1.6.12. Saving ad-hoc reports including search criteria used and fields included and allow quick access for future use;
1.6.13. Creating and producing common reports, in multiple formats, to be used to meet the requirements of Semi-Annual Reporting to Congress, the CIGIE Report to the President, and other regularly repeated reporting such as performance metrics;*
1.6.14. Downloading all documents for a case in a zip file;
1.6.15. Downloading multiple user-selected documents for a case in a zip file; and
1.6.16. Generating a report containing all case fields for a specific case.
1.7. Time and Costs
1.7.1. Tracking time charged by user to a case or non-case activity;
1.7.2. Creating a defined list of non-case activities to which time can be charged;
1.7.3. Tracking expenses associated with each case by user;
1.7.4. From a monthly entry screen, allowing users to add employee hours to cases and non-case activities for multiple cases;* and
1.7.5. Tracking hours worked and calculate unscheduled duty hours as required by 5 U.S.C.
5545a, Availability pay for criminal investigators, and 5 CFR 550.183(b), Substantial hours requirement.
1.8. Training
1.8.1. Acting as the repository for tracking agent completion of general training;
1.8.2. Allowing agents to create a training record (course name, hours, completion date, category, and expiration date), attach supporting documents, and route for approval;
1.8.3. Allowing approved training instructors to enter a training class for multiple users at one time;
1.8.4. Allowing agents to view their training;
1.8.5. Allowing for setting expiration dates to specific training entries;
1.8.6. Allowing for the categorization of training;
1.8.7. Generating a report based by region, by expiration date, user, and/or category for a given time period; and
1.8.8. Sending automated emails 30 days before and upon expiration of training.
1.9. Use of Force Training
1.9.1. With appropriate permissions, the system has the ability to create multiple records from one form that includes date of training, the training type(s) that occurred, total hours, results of training (pass/fail), user(s) who attended, and instructor(s). *
1.9.2. When selecting the agent who attended training, the system has the ability to automatically reflect the weapon type(s) used.
1.9.3. The system has the ability for an OIG administrator to modify pick lists of training types.
1.9.4. The system has the ability to report and filter, with appropriate permissions, by training type, region, office, and agent.
1.9.5. The system has the ability for agents to view their training.
1.9.6. The system has the ability for supervisors to view training for their region.
1.9.7. The system has the ability to attach training attendance forms and score sheets to the training date record.
1.9.8. The system shall maintain an inventory of OIG weapons, personal weapons, and the region and agent they are assigned to.
1.10. Other
1.10.1. The system may have the ability track outreach activity and fraud awareness briefings conducted by agents not associated with a case. (Desired, not required)
1.10.2. The system may have the ability to link outreach or fraud awareness activities to a specific case generated due to the activity. (Desired, not required)
1.10.3. The contractor shall provide a user manual in Microsoft Word outlining all functions of the system utilizing a hyperlinked table of contents for each portion of the manual.
1.10.4. The contractor shall provide a data dictionary table in Word or Excel that describes the fields and relationships in the system.
1.10.5. The contractor shall provide two remote or on-site training sessions for administrator functions by February 1, 2017. The training shall cover the creation of ad-hoc and common reports.
1.10.6. It is desired that the system be able to operate on a Windows 2012 Server virtual machine running Microsoft SQL Server version 2014.
1.11. Data Migration
The system shall be capable of:
1.11.1. Mass importing legacy case information (entity fields, result fields, case fields, etc.)
1.11.2. Mass importing legacy case documents in a variety of standard formats (.DOC, .JPEG, .WAV, .PDF) to include the importing of metadata such as upload date, description, user, etc.)
1.11.3. Mass importing individual case chronology entries per case.
Hosting Performance Objectives
The contractor must provide hosted COTS CMS software that has agency Federal Risk and Authorization Management Program (FedRAMP) Software as a Service (SaaS) authorization, FedRAMP SaaS provisional authorization (PATO), or will complete all actions necessary and submit a complete FedRAMP package for agency authorization by February 1, 2017. This includes the implementation of all FedRAMP security controls, independent assessment conducted by an approved third-party assessment organization (3PAO), and the creation and submission of all required documentation.*
1.12 Hosting Business Objectives
The contractor shall:
1.12.1 Provide all support operations necessary to fully install and configure the CMS in the hosted environment;
1.12.2 Provide cloud hosting services solely within the United States for CMS; and
1.12.3 Provide software licenses as outlined in Section 1.10.6.
1.13 Hosting Management Objectives
The contractor shall:
1.13.1 Maintain clear government visibility into program cost, schedule, technical performance, and risk, including periodic reporting;
1.13.2 Provide meaningful reporting and analytics that provide the Government with up-to-date and comprehensive information regarding technical and management performance;
1.13.3 Provide a brief description on the management of subcontractor relationships and contracts. Outline the roles and responsibilities per party involved in the service and where key responsibilities reside;
1.13.4 Provide a transition plan detailing milestones, activities, and timelines;
1.13.5 Provide backup and recovery;
1.13.6 Provide patch management;
1.13.7 Provide system software support services;
1.13.8 Provide on-going technical support;
1.13.9 Provide database management and administration;
1.13.10Provide system monitoring and notification;
1.13.11 Provide at least 8-1/2 hours of help/service desk support every weekday covering the time period 08:00-16:30.
1.13.12Provide network support services; and 1.13.13Ensure continuity of operations.
1.14 Hosting Technical Objectives
The contractor shall:
1.14.1 Provide all technical advisory services necessary to fully host the CMS in the cloud;
1.14.2 Provide cloud environment to support the complete system lifecycle;
1.14.3 Provide post-deployment cloud support and security services;
1.14.4 Provide backup, recovery and disaster recovery procedures and processes in the cloud environment for the target applications and services that support the following objectives:
• Recovery Point Objective (RPO) – Ability to recover files for any specific day within a rolling one month period.
• Recovery Time Objective (RTO) – Ability to recover files within two (2) business days.
• Data Backup Location – Data backups maintained or replicated at a site geographically disparate from the production site such that the loss of one data center does not prohibit recovery of data within the prescribed RTO.
• Ability to stand up the full services at a geographically disparate location from the primary production site within 1 business day in case of complete failure at the primary site (failover); and
1.14.5 Provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4. Specific criteria to be deemed IPv6 capable are: An IPv6 Capable system must meet the IPv6 base requirements defined by the USGv6 Profile and Testing program as found here “http://w3.antd.nist.gov/usgv6/testing.html”. Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities. Systems shall implement IPv4/IPv6dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems shall employ IPv6.
1.15 Hosting Security Objectives
The contractor must:
1.15.1 Apply the appropriate set of impact baseline controls as required in FedRAMP Cloud Computing Security Requirements Baseline document (NIST Special Publication 800-53, Revision 4) to ensure compliance to security standards for a “Moderate” system;
1.15.2 Maintain a security management continuous monitoring environment that meets FedRAMP Cloud Computer Security Requirements Baseline and FedRAMP Continuous Monitoring Requirements;
1.15.3 Provide support and security services in compliance and alignment with FedRAMP standardized security assessment, authorization, and continuous monitoring policies http://w3.antd.nist.gov/usgv6/testing.html as required by the scope of the project. Assessment and Authorization (A&A) activities will be included as part of the hosting;
1.15.4 Undergo Security Assessment and Authorization (A&A) prior to going into production and undergo Continuous Monitoring. The contractor must follow NIST SP 800-37, 800-34, 800-18, 800-30, 800-60, 800-53, 800-53A, Federal Information Processing Standard (FIPS) 199 and 200. The contractor will work with OIG to define a clearly demarcated security authorization boundary for Cloud Environment.
The contractor will provide supporting documentation to Government as necessary for the A&A process;
1.15.5 Provide access to the Government in order to verify compliance with the requirements for an Information Technology security program. The Government reserves the right to conduct on-site inspections. The contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review;
1.15.6 Ensure hosting security and privacy that are consistent with the NIST Special Publication 800-144 – “Guidelines on Security and Privacy in Public Cloud Computing” or other applicable standards and guidelines. The contractor will take appropriate and timely action to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost;
1.15.7 Consistent with continuous monitoring requirement, scan the system monthly with a vulnerability analysis tool that is acceptable to government. All “safe” or “non-destructive” checks must be turned on. An electronic copy of each report and session data will be provide to the COR. The government will reserve the right to conduct unannounced and prearranged independent vulnerability scans using Government personnel or another contactor. The contractor will take appropriate and timely action to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost. The contractor must comply with audit logging standards per OIG policy. The audit records must contain sufficient information to, at a minimum, establish what type of event occurred, when (date and time) the event occurred, where the event occurred, the source of the event, the outcome (success or failure) of the event, and the identity of any user/subject associated with the event. The contractor must provide patch management, antivirus, malware detection, event management, configuration management, license management, and incident management in alignment with OIG’s continuous monitoring strategy. The contractor/application will undergo annual security testing;
1.15.8 Provide security for data transfers both in transit and at rest resulting from the migration of the applications or services to the cloud;
1.15.9 Provide support for specified auditable events related to the applications or services;
1.15.10 Provide minimum full backup of configuration and data weekly with nightly backup of differential changes. The full backups must be maintained at a geographically separated location;
1.15.11Provide must support two failover tests annually (Fail over from primary server/system to backup server/system in alternate geographic location.)
1.15.12 Provide must be able to lock down access to the CMS to only specific Internet Protocol address ranges; and
1.15.13 Notify ED OIG immediately upon identification of any suspected unauthorized access to ED OIG data. Must report all computer security incidents to the United States Computer Emergency Readiness Team (US-CERT) in accordance with US- CERT “Incident Categories and Reporting Timeframes” in, Appendix J, Table J-1 of NIST SP 800-61 (as amended), Any incident that involves compromised Personally Identifiable Information (PII) must be reported to US-CERT within 1 hour of detection regardless of the incident category reporting timeframe.
1.16 Privacy Objectives
1.16.1 To the extent required to carry out the FedRAMP assessment and authorization process and FedRAMP continuous monitoring, to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public Government data collected and stored by the contractor, the contractor shall afford the Government access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases.
1.16.2 If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer must immediately bring the situation to the attention of the other party.
1.16.3 The contractor must also comply with any additional FedRAMP privacy requirements.
1.16.4 The Government has the right to perform manual or automated audits, scans, reviews, or other inspections of the vendor’s IT environment being used to provide or facilitate services for the Government. The contractor must follow privacy and security safeguards from the Federal Acquisitions Regulations (FAR) clause 52.239-1.
1.16.5 If the contractor chooses to run its own automated scans or audits, results from these scans may, at the Government’s discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by the Government. In addition, the results of vendor-conducted scans shall be provided, in full, to the Government.
| I. Purpose |
| II. Background |
| III. Scope |
| IV. Period and Place of Performance |
| V. Review of Deliverables |
| VI. Government furnished equipment |
| VII. Personnel |
| VIII. Non-Disclosure Agreement |
| Standard non-disclosure statements must be provided as required for system administration personnel who may have access to government data in the course of their duties. |
| IX. Accessibility |
| X. Data Isolation and Portability |
| XI. Confidentiality, Security, and Privacy |
| XII. Performance Objectives |
| 1.1. Security and Data Integrity |
| 1.2. System |
| 1.3. Case Management (Universal to Complaint, Preliminary, or Investigation) The system shall: |
| 1.4. Hotline |
| 1.5. Investigation |
| 1.6. Reporting (FOIA, eDiscovery, Indexing, Searching, and Reporting) The system is capable of: |
| 1.7. Time and Costs The system is capable of: |
| 1.8. Training The system is capable of: |
| 1.9. Use of Force Training |
| 1.10. Other |
| 1.11. Data Migration The system shall be capable of: |
| 1.11.1. Mass importing legacy case information (entity fields, result fields, case fields, etc.) |
| 1.11.2. Mass importing legacy case documents in a variety of standard formats (.DOC, .JPEG, .WAV, .PDF) to include the importing of metadata such as upload date, description, user, etc.) |
| 1.11.3. Mass importing individual case chronology entries per case. |
| Hosting Performance Objectives |
| 1.12 Hosting Business Objectives |
| 1.13 Hosting Management Objectives |
| The contractor shall: |
| 1.14 Hosting Technical Objectives |
| 1.15 Hosting Security Objectives The contractor must: |
| 1.16 Privacy Objectives |
File details come from the government source that posted it. Updated .