Attachment_F_-_OLAS_Special_Contract_Requirements.doc
DOC document 59 KB Posted
- Attached to
- On-Line Application Processing System Federal contract opportunity
- Solicitation number
- EDEOPO-16-R-0001
About this file
Attachment F
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| OLAS_Q A.docx | DOCX document | |
| OLAS_Informational_Attachments.zip | ZIP file | |
| Attachment_G_-_OLAS_CONOPS_and_High_Level_Requirements.pdf | ||
| Solicitation_Amendment_2.pdf | ||
| EDEOPO16R00010002_US.pdf | ||
| Attachment_B-_Pricing_Sheet.xlsx | XLSX spreadsheet | |
| Attachment_D-_OLAS_QASP.xml | XML file | |
| Attachment_A-_OLAS_PWS.xml | XML file | |
| Attachment_C-_OLAS_requirements_worksheet.xml | XML file | |
| Attachment_E_-_Past_Performance_Evaluation.xml | XML file | |
| Solicitation_(1).pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment F
Special Contract Requirements Compliance with ED IT Security Policy The contractor, and all sub-contractors, shall comply with the Department of Education’s IT security policy requirements, specifically those set forth in the ‘Handbook for Information Assurance Security Policy (OCIO-01)’, and other applicable procedures and guidance. The contractor, and all sub-contractors, shall develop and implement management, operational and technical security controls to assure required levels of protection for information systems. The contractor, and all sub-contractors, shall further comply with all applicable Federal IT security requirements including, but not limited to, the Federal Information Security Management Act (FISMA) of 2002, Office of Management and Budget (OMB) Circular A-130 Appendix III, Homeland Security Presidential Directives (HSPD), the National Institute of Standards and Technology (NIST) standards and guidance, and the Federal Risk and Authorization Management Program (FedRAMP) requirements and guidance.
These security requirements include, but are not limited to, the successful Security Authorization (SA) of the system (includes commercially owned and operated systems managed by the commercial vendor and its sub-contractors, supporting Department programs, contracts, and projects); obtaining a full Authority to Operate (ATO) before being granted operational status; performance of annual self-assessments of security controls; annual Contingency Plan testing; performance of periodic vulnerability scans; updating all information system security documentation as changes occur; and other continuous monitoring activities, which may include, mapping, penetration and other intrusive scanning. Full and unfettered access for the Department’s third party Managed Security Services Provider (MSSP) must be granted to access all computers and networks used for this system. Additionally, when there is a significant change to the system’s security posture, the system (Federal and commercial prime- and sub- contractors included) must have a new SA, with all required activities to obtain a new ATO, signed by the Authorizing Official (AO).
System security controls shall be designed and implemented consistent with NIST SP 800-53 Rev 4, ‘Recommended Security Controls for Federal Information Systems and Organizations.’ All NIST SP 800-53 controls must be tested / assessed no less than every 3 years, according to federal and Department policy. The risk impact level of the system will be determined via the completion of the Department's inventory form and shall meet the accurate depiction of security categorization as outlined in Federal Information Publishing Standards (FIPS) 199, ‘Standards for Security Categorization of Federal Information and Information Systems.’
System security documentation shall be developed to record and support the implementation of the security controls for the system. This documentation shall be maintained for the life of the system. The contractor, and all sub-contractors, shall review and update the system security documentation at least annually and after significant changes to the system, to ensure the relevance and accurate depiction of the implemented system controls and to reflect changes to the system and its environment of operation. Security documentation must be developed in accordance with the NIST 800 series and Department of Education policy and guidance.
The contractor, and all sub-contractors, shall allow Department employees (or Department designated third party contractors) access to the hosting facility to conduct SA activities to include control reviews in accordance with NIST SP 800-53, Rev. 4 and NIST SP 800-53A. The contractor, and all sub-contractors, shall be available for interviews and demonstrations of security control compliance to support the SA process and continuous monitoring of system security. In addition, if the system is rated as ‘Moderate’ or ‘High’ for FIPS 199 risk impact, vulnerability scanning and penetration testing shall be performed on the hosting facility and application as part of the SA process. Appropriate access agreements will be reviewed and signed before any scanning or testing occurs.
Identified deficiencies between required NIST SP 800-53 Rev. 4 controls and the contractor’s, and all sub-contractor’s implementation, as documented in the Risk Assessment Report, System Security Plan (SSP) and Security Assessment Report (SAR), shall be tracked for mitigation through the development of a Plan of Action and Milestones (POA&M) in accordance with the ‘Handbook for Information Assurance Security Policy (OCIO-01).’ Depending on the severity of the deficiencies, the Department may require remediation before an ATO is issued.
All awarded contracts shall ensure that:
1. Their IT product/system is monitored during all hours of operations using entrusted detective/preventive systems;
2. Their IT product/system has current antiviral products installed and operational;
3. Their IT product/system is scanned on a reoccurring basis;
4. Vulnerabilities are remediated in a timely manner on their IT product/system; and
5. Access/view for cyber security situational awareness on their IT product/system is made available to the Department CIRC (cyber incident response capability).
Internet Protocol version 6 (IPv6)
For IPv6, the contractor shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4. Specific criteria to be deemed IPv6 capable are:
· An IPv6 capable system that meets the IPv6 base requirements defined by the USGv6 Profile (http://www.antd.nist.gov/usgv6/profile.html).
· Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities.
· Systems shall implement IPv4/IPv6 dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems shall employ IPv6.
The contractor shall provide IPv6 technical support for system development, implementation and management.
Reporting of Data Security Breaches
If there is a suspected or known breach/disclosure of PII due to lost, theft, intercepted transfer, or other, the contractor must ensure that this breach is reported to the agency as soon as the contractor has knowledge of it. Per Office of Management and Budget Memorandum M-06-19, Federal agencies have a requirement to report breaches of PII security to a Federal incident response center. (PO) must notify the department within 30 minutes of discovering the incident (and the agency should not distinguish between suspected or confirmed breaches). The data security plan must be written to reflect this requirement, and the contractor must provide sufficient notification and documentation of the suspected loss, as it is understood at the time of notification to the agency for this requirement to be met. Follow-up reports of the final status of loss events will also be prepared by the contractor within a reasonable period of time as advised by the (PO) COR.
Compliance with ED Privacy Policy The contractor shall comply with all Department and Federal privacy control requirements for Federal information systems. The contractor shall be responsible for complying with the requirements of the Privacy Act, 5 U.S.C. 552a, the E-Government Act of 2002, 44 U.S.C. § 101, the Federal Information Security Management Act, 44 U.S.C. §3541 (FISMA), as well as OMB directives OMB M-06-16, OMB M-07-16, FIPS 201 and FIPS 140-2. The Contractor shall abide by and follow all Departmental privacy policies, procedures, processes, and standards. All electronically stored sensitive data shall be password protected.
The Contractor shall work with the contract’s project manager to complete a Privacy Impact Assessment (PIA), during the development cycle of new systems or for the operations phase of existing systems. The PIA shall be provided to the project manager, and approved by the Department’s Chief Privacy Officer, for those systems that are designed, operated, or developed for or on behalf of the Department at non-Departmental facilities. The Contractor must include on the website a privacy policy in accordance with Section 208 of the E-Government Act of 2002 and OMB Memorandum M-03-22.
Payment Terms
Payment terms for all PWS items are as follows:
PWS
Item
| Title |
| Payment Terms |
| 1.1 |
| Provide Software Solution |
| Firm-fixed-price (FFP) – paid upon acceptance of the configured generic solution |
| 1.2 |
| Configure Software Solution |
| Firm-fixed-price (FFP) – paid upon acceptance of the configured solution (for each program) |
| 1.3 |
| Support Federal System Authorization |
| Firm-fixed-price (FFP) – paid upon completion of the system authorization package and associated assessment support activities |
| 1.4 |
| Provide Training for Solution |
| Firm-fixed-price (FFP) |
| 1.5 |
| Maintain and Operate OLAS |
| Firm-fixed-price (FFP) |
| 1.6 |
| Provide Technical Support |
| Firm-fixed-price (FFP) |
| 1.7 |
| Provide Upgrades and Enhancements |
| Firm-fixed-price (FFP) |
| 1.8 |
| Update Solution Configuration (Optional) |
| Firm-fixed-price (FFP) |
File details come from the government source that posted it. Updated .