Attachment_F_-_OLAS_Special_Contract_Requirements.doc

DOC document 59 KB Posted

Attached to
On-Line Application Processing System Federal contract opportunity
Solicitation number
EDEOPO-16-R-0001
Issued by
Department of Education Contracts and Acquisition Management

About this file

Attachment F

View the file

Other files for this federal contract opportunity

Other files attached to On-Line Application Processing System, newest first.
File Type Posted
OLAS_Q A.docx DOCX document
OLAS_Informational_Attachments.zip ZIP file
Attachment_G_-_OLAS_CONOPS_and_High_Level_Requirements.pdf PDF
Solicitation_Amendment_2.pdf PDF
EDEOPO16R00010002_US.pdf PDF
Attachment_B-_Pricing_Sheet.xlsx XLSX spreadsheet
Attachment_D-_OLAS_QASP.xml XML file
Attachment_A-_OLAS_PWS.xml XML file
Attachment_C-_OLAS_requirements_worksheet.xml XML file
Attachment_E_-_Past_Performance_Evaluation.xml XML file
Solicitation_(1).pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment F

Special Contract Requirements Compliance with ED IT Security Policy The contractor, and all sub-contractors, shall comply with the Department of Education’s IT security policy requirements, specifically those set forth in the ‘Handbook for Information Assurance Security Policy (OCIO-01)’, and other applicable procedures and guidance. The contractor, and all sub-contractors, shall develop and implement management, operational and technical security controls to assure required levels of protection for information systems. The contractor, and all sub-contractors, shall further comply with all applicable Federal IT security requirements including, but not limited to, the Federal Information Security Management Act (FISMA) of 2002, Office of Management and Budget (OMB) Circular A-130 Appendix III, Homeland Security Presidential Directives (HSPD), the National Institute of Standards and Technology (NIST) standards and guidance, and the Federal Risk and Authorization Management Program (FedRAMP) requirements and guidance.

These security requirements include, but are not limited to, the successful Security Authorization (SA) of the system (includes commercially owned and operated systems managed by the commercial vendor and its sub-contractors, supporting Department programs, contracts, and projects); obtaining a full Authority to Operate (ATO) before being granted operational status; performance of annual self-assessments of security controls; annual Contingency Plan testing; performance of periodic vulnerability scans; updating all information system security documentation as changes occur; and other continuous monitoring activities, which may include, mapping, penetration and other intrusive scanning. Full and unfettered access for the Department’s third party Managed Security Services Provider (MSSP) must be granted to access all computers and networks used for this system. Additionally, when there is a significant change to the system’s security posture, the system (Federal and commercial prime- and sub- contractors included) must have a new SA, with all required activities to obtain a new ATO, signed by the Authorizing Official (AO).

System security controls shall be designed and implemented consistent with NIST SP 800-53 Rev 4, ‘Recommended Security Controls for Federal Information Systems and Organizations.’ All NIST SP 800-53 controls must be tested / assessed no less than every 3 years, according to federal and Department policy. The risk impact level of the system will be determined via the completion of the Department's inventory form and shall meet the accurate depiction of security categorization as outlined in Federal Information Publishing Standards (FIPS) 199, ‘Standards for Security Categorization of Federal Information and Information Systems.’

System security documentation shall be developed to record and support the implementation of the security controls for the system. This documentation shall be maintained for the life of the system. The contractor, and all sub-contractors, shall review and update the system security documentation at least annually and after significant changes to the system, to ensure the relevance and accurate depiction of the implemented system controls and to reflect changes to the system and its environment of operation. Security documentation must be developed in accordance with the NIST 800 series and Department of Education policy and guidance.

The contractor, and all sub-contractors, shall allow Department employees (or Department designated third party contractors) access to the hosting facility to conduct SA activities to include control reviews in accordance with NIST SP 800-53, Rev. 4 and NIST SP 800-53A. The contractor, and all sub-contractors, shall be available for interviews and demonstrations of security control compliance to support the SA process and continuous monitoring of system security. In addition, if the system is rated as ‘Moderate’ or ‘High’ for FIPS 199 risk impact, vulnerability scanning and penetration testing shall be performed on the hosting facility and application as part of the SA process. Appropriate access agreements will be reviewed and signed before any scanning or testing occurs.

Identified deficiencies between required NIST SP 800-53 Rev. 4 controls and the contractor’s, and all sub-contractor’s implementation, as documented in the Risk Assessment Report, System Security Plan (SSP) and Security Assessment Report (SAR), shall be tracked for mitigation through the development of a Plan of Action and Milestones (POA&M) in accordance with the ‘Handbook for Information Assurance Security Policy (OCIO-01).’ Depending on the severity of the deficiencies, the Department may require remediation before an ATO is issued.

All awarded contracts shall ensure that:

1. Their IT product/system is monitored during all hours of operations using entrusted detective/preventive systems;

2. Their IT product/system has current antiviral products installed and operational;

3. Their IT product/system is scanned on a reoccurring basis;

4. Vulnerabilities are remediated in a timely manner on their IT product/system; and

5. Access/view for cyber security situational awareness on their IT product/system is made available to the Department CIRC (cyber incident response capability).

Internet Protocol version 6 (IPv6)

For IPv6, the contractor shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4. Specific criteria to be deemed IPv6 capable are:

· An IPv6 capable system that meets the IPv6 base requirements defined by the USGv6 Profile (http://www.antd.nist.gov/usgv6/profile.html).

· Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities.

· Systems shall implement IPv4/IPv6 dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems shall employ IPv6.

The contractor shall provide IPv6 technical support for system development, implementation and management.

Reporting of Data Security Breaches

If there is a suspected or known breach/disclosure of PII due to lost, theft, intercepted transfer, or other, the contractor must ensure that this breach is reported to the agency as soon as the contractor has knowledge of it. Per Office of Management and Budget Memorandum M-06-19, Federal agencies have a requirement to report breaches of PII security to a Federal incident response center. (PO) must notify the department within 30 minutes of discovering the incident (and the agency should not distinguish between suspected or confirmed breaches). The data security plan must be written to reflect this requirement, and the contractor must provide sufficient notification and documentation of the suspected loss, as it is understood at the time of notification to the agency for this requirement to be met. Follow-up reports of the final status of loss events will also be prepared by the contractor within a reasonable period of time as advised by the (PO) COR.

Compliance with ED Privacy Policy The contractor shall comply with all Department and Federal privacy control requirements for Federal information systems. The contractor shall be responsible for complying with the requirements of the Privacy Act, 5 U.S.C. 552a, the E-Government Act of 2002, 44 U.S.C. § 101, the Federal Information Security Management Act, 44 U.S.C. §3541 (FISMA), as well as OMB directives OMB M-06-16, OMB M-07-16, FIPS 201 and FIPS 140-2. The Contractor shall abide by and follow all Departmental privacy policies, procedures, processes, and standards. All electronically stored sensitive data shall be password protected.

The Contractor shall work with the contract’s project manager to complete a Privacy Impact Assessment (PIA), during the development cycle of new systems or for the operations phase of existing systems. The PIA shall be provided to the project manager, and approved by the Department’s Chief Privacy Officer, for those systems that are designed, operated, or developed for or on behalf of the Department at non-Departmental facilities. The Contractor must include on the website a privacy policy in accordance with Section 208 of the E-Government Act of 2002 and OMB Memorandum M-03-22.

Payment Terms

Payment terms for all PWS items are as follows:

PWS

Item

Title
Payment Terms
1.1
Provide Software Solution
Firm-fixed-price (FFP) – paid upon acceptance of the configured generic solution
1.2
Configure Software Solution
Firm-fixed-price (FFP) – paid upon acceptance of the configured solution (for each program)
1.3
Support Federal System Authorization
Firm-fixed-price (FFP) – paid upon completion of the system authorization package and associated assessment support activities
1.4
Provide Training for Solution
Firm-fixed-price (FFP)
1.5
Maintain and Operate OLAS
Firm-fixed-price (FFP)
1.6
Provide Technical Support
Firm-fixed-price (FFP)
1.7
Provide Upgrades and Enhancements
Firm-fixed-price (FFP)
1.8
Update Solution Configuration (Optional)
Firm-fixed-price (FFP)

File details come from the government source that posted it. Updated .