FBOP ATU Vendor Attestation (FINAL) 1.docx

DOCX document 159 KB Posted

Attached to
SU/MH in Garden Grove, CA Federal contract opportunity
Solicitation number
15BCTS25Q00000013
Issued by
Department of Justice Bureau of Prisons Central Office

About this file

This document is a Vendor Attestation for the Federal Bureau of Prisons (FBOP) that focuses on information security and data protection requirements. The attestation requires vendors to affirm robust security controls, including compliance with certifications such as SOC 2, ISO 27001, HIPAA, and other applicable standards. Key vendor obligations include storing DOJ data exclusively within the United States, using data only for contract performance, reporting potential security breaches within specified timeframes (1 hour for confirmed breaches, 24 hours for suspected breaches), and cooperating fully with DOJ's incident investigations.

The document contains comprehensive sections detailing vendor information security practices, including requirements for multi-factor authentication, principle of least privilege, data encryption, mobile device management, cyber security program implementation, vulnerability scanning, penetration testing, and patch management protocols. Vendors must also specify data ownership roles, confirm the types of sensitive information they will handle, and provide detailed descriptions of their security implementation strategies. The attestation concludes with a signature section where the vendor representative accepts responsibility for protecting DOJ data's confidentiality, integrity, and availability.

View the file

Other files for this federal contract opportunity

Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

[FBOP Proposed Attestation]

[BOP RRC, CMS & Credit Reporting Contracts: To Address ATU concerns]

The vendor affirms that they have security controls in place to protect DOJ information when that data is being stored, transmitted, processed, or displayed on the vendor’s information technologies. Applicable security controls include certifications indicating compliance with: state licensure requirements, SOC 2, ISO 27001, Payment Card Industry, HIPAA as applicable or other environment certifications that would be applicable (to be specified by the vendor). Vendor has attached documentation of said certifications as part of this affirmation.

The vendor affirms that internal controls are in place to identify and remediate vulnerabilities within any IT system in which DOJ information is stored and that DOJ data will be stored exclusively within the boundaries of the United States and that only US citizens have access to DOJ’s data. The vendor affirms that any DOJ information made available to vendor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. The vendor shall neither reproduce nor release such information to any third-party at any time, including during or after performance of the contract, without prior written permission of the CO or COR.

The vendor agrees to report any actual or suspected breach of DOJ Information within one hour of discovery of an actual breach, and within 24 hours of a suspected breach if vendor has not yet been able to determine whether a breach has occurred. A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses DOJ Information or (2) an authorized user accesses or potentially accesses DOJ Information for an other than authorized purpose. The report of a breach must be made to the CO or COR; if neither can be reached, the vendor must report the breach to the DOJ Security Operations Center (jsoc@usdoj.gov, 202-357-7000) and FBOP’s Information Security Program Office; the COR; and the Contracting Officer within one (1) hour of the initial discovery. The vendor should not disclose any details of the potential or confirmed breach to any individual not involved in responding to the breach. The vendor agrees to cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals. Such cooperation includes, but is not limited to, providing to DOJ full access to any facility and/or Information System affected or potentially affected the breah or potential breach, and to undertake any and all response actions DOJ determines are required to ensure the protection of DOJ Information, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. The vendor further agrees that it shall be responsible for all costs and related resource allocations that DOJ deems required for all such response activities related to any breach.

A. Vendor Information Types Questions

Yes
No
N/A
Description

☐ ☐ ☐ Is the data sensitive (as defined by NIST)?

☐ ☐ ☐ Does the data contain Personally Identifiable Information (PII)?

☐ ☐ ☐ Does the data contain Federal Tax Information (FTI)?

☐ ☐ ☐ Does the data contain Protected Health Information (PHI)?

☐ ☐ ☐ Does the data contain other Limited Official Use Information:

☐ Legal Privilege ☐ Legal Strategy ☐ Grand Jury ☐ Title III Information ☐ Protected Materials ☐ Privacy Act ☐ Procurement Sensitive ☐ Intellectual Property ☐ Law Enforcement Sensitive ☐ Infrastructure Sensitive

☐
☐
☐
Approximately how many records will be transmitted to the vendor during the contract period?

B. Vendor Information Security Questions

Yes
No
N/A
Description
☐
☐
☐
Is Multi Factor Authentication (MFA) used to access DOJ data?

Describe implementation: [Insert description for implementation] Explain N/A: [Insert explanation]

☐
☐
☐
Is the principle of least privilege employed for access management?

Describe implementation: [Insert description for implementation]

☐
☐
☐
Is sensitive data encrypted at rest and/or in transit (e.g., sensitive Personally Identifiable Information (PII), Federal Tax Information (FTI), health information (HIPAA))?

Describe implementation: [Insert description for implementation]

☐
☐
☐
Do portable devices require mobile device management tools before allowing access to corporate data, including email?

Describe implementation: [Insert description for implementation]

☐
☐
☐
Is there a formal cyber security program which includes policy enforcement?

Describe implementation: [Insert description for implementation]

☐
☐
☐
Are routine vulnerability scans of all system assets and endpoints performed?

Describe implementation: [Insert description for implementation]

☐
☐
☐
Are internal and external penetration tests conducted?

Describe implementation: [Insert description for implementation]

☐
☐
☐
Are known vulnerabilities mitigated or remediated within 30 for critical and high risk, and 90 days for medium risks?

Describe implementation: [Insert description for implementation]

· Critical Patch - to be installed within 30 days or sooner if possible

· High Risk Patch - to be installed within 60 days or sooner if possible

· Medium Risk Patch - to be installed within 90 days or sooner if possible

· Low Risk Patch - to be installed within the normal patching rotation, but within at least a year.

☐
☐
☐
Are monitoring services employed which will notify resources as needed 24x7x365 to support incident response?

Describe implementation: [Insert description for implementation]

☐
☐
☐
If sub-contractors are used, describe questionnaire and other requirements of sub-contractors:

Describe implementation: [Insert description for implementation]

C. Data Owners

Role
Responsible Party
Responsibilities
Data Steward
[Insert Responsible Party]
Entity who is responsible for the categorization, protection, usage, and quality of the data.
Data Steward
[Insert Responsible Party]
Entity who is responsible for the confidentiality, integrity, and availability of the data on a day-to-day basis.
Data Steward
[Insert Responsible Party]
Entity who is responsible for the confidentiality, integrity, and availability of data on a day-to-day basis.

D. Vendor Signature

[Vendor representative signature]
As the vendor representative, I attest that the information in sections A and B are accurate, and I accept the responsibility of protecting and ensuring the confidentiality, integrity, and availability of DOJ data on a day-to-day basis when it is on the vendor or subcontracted vendor networks.

image1.png

File details come from the government source that posted it. Updated .