FCHS2_Section_J_Attachment_1_Security_Objectives_-_Service_Level_Agreements.pdf
PDF 508 KB Posted
- Attached to
- DOI Foundation Cloud Hosting Services (FCHS2) Federal contract opportunity
- Solicitation number
- 140D0423R0002
View the file
Other files for this federal contract opportunity
Show all 46
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Foundation Cloud Hosting Services II (FCHS2) Section J Attachment 1
J-1
SECTION J - ATTACHMENT 01
C.5 Security Objectives – Service Level Agreements Section J – Attachment 1 is a continuance of the Section C Statement of Work. This attachment covers security and privacy objectives by setting Service Level Agreement (SLA) metrics. In addition, see Attachment 2, “Information Technology Baseline Compliance Contract Guidelines” which is a mandatory policy for all DOI IT System compliance.
The government is requesting Contractors describe the right way to host their cloud environments and configure their cloud services, not the other way around. Individual DOI task orders shall not be less restrictive than Attachment 1 and/or Attachment 2 unless otherwise approved.
“The most important Security Law is The Federal Information Security Management Act (FISMA), which is the foundation of most cybersecurity policy in the U.S. today. This requires agencies to follow a series of processes to secure information systems created or used by the government. The Office of Management and Budget (OMB) has issued memoranda on many security topics, in addition to the security standards created by the The National Institute of Standards and Technology (NIST). The Inspector General (IG) of an agency is also required by FISMA to assess the overall cybersecurity program on an annual basis.”
The following categories are based on ISO_IEC_19086 standards to include (1) accessibility, (2) availability, (3) performance, (4) service reliability, (5) data management, (6) information security, (7) service support, and (8) governance.
Assurances, Inspection, Penalties/Provisions To baseline SLA commitments of cloud compute services, the government is requesting Contractor proposals include:
1. Assurance you can meet the standard (default) levels as required in a monthly billing cycle; or propose alternative SLA standards, as applicable, and as appropriate for the cloud computing service and to achieve an agreed baseline between the government and Contractor; and
2. Identify the commercially reasonable inspection technique to measure SLA metric compliance, including self-test, no response, error message, % threshold, etc. as appropriate for that service; and
3. A penalty or provision in the event of not meeting that service level, such as service credits.
Use Table 11 Service Level Baselines below for responding to this requirement. Adjust measures and Penalty/Provision, add rows, etc. as applicable. List NA for metrics that do not fall within your responsibility scope or not provisioned, nor applied in the respective cloud compute service.
The assumption is the minimum standards (default) will be measured and achieved when the cloud service is in full steady-state production mode and after migration and development phases are complete. The Information System Security Officers (ISSOs) should develop Plan of Action https://digitalpolicy.us/laws/fisma/ https://digitalpolicy.us/laws/fisma/ https://digitalpolicy.us/info/policymaking-offices/#omb https://www.whitehouse.gov/omb/information-for-agencies/memoranda/ https://csrc.nist.gov/ https://digitalpolicy.us/info/policymaking-offices/#nist
J-2
& Milestones (POAM) early in the process that identify under compliant SLAs, such as HSPD- 12 compliant PIV authentication not yet provisioned.
C.5.1 Accessibility Cloud Service Provider solutions shall provide and protect millions of people who have disabilities that impede their ability to use Information and Communications Technology (ICT).
C.5.1.1 Section 508 of the Rehabilitation Act The creation and maintenance of software applications and websites with content and links, shall comply with Section 508 of the Rehabilitation Act of 1973 (29 U.S.C §794(d)) and Web Content Accessibility Guidelines (WCAG). IT solutions shall provide assistive technologies such as magnifiers, screen readers, braille readers and alternative input devices are available on client computing platforms to make the use of ICT, including cloud services, easier for people with disabilities.
C.5.1.2 Web Accessibility When suppling, developing or modifying web and software ICT, the Contractor shall demonstrate Section 508 conformance by submitting the Voluntary Product Accessibility Template (VPAT) or provide Section 508 test results based on the versions of the DHS Trusted Tester Methodology currently approved for use, as defined at https://www.dhs.gov/compliance-test-processes.
The following standards and guidelines for Information and Communication Technology (ICT) services is available and shall be used to monitor compliance and provide cloud services to persons with disabilities including:
• W3C Web Content Accessibility Guidelines (WCAG) 2.0, Level A and AA Guidelines, also published as ISO/IEC 40500:2012,
• ISO/IEC TR 29138 (all parts) — Accessibility considerations for people with disabilities,
• ISO/IEC Guide 71 — Guide for addressing accessibility in standards,
• Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d) in the
United States of America
• Applicable ICT Accessibility Provisions from Information and Communication
Technology (ICT) Standards and Guidelines (36 CFR Part 1194)
C.5.2 Availability Contractor shall provide cloud services that optimize availability on multiple aspects. Any availability measures identified below as “default” are considered minimum performance levels.
C.5.2.1 Authentication Contractor shall provide a zero-trust phishing-resistant security plan in compliance with OMB M-22-09. The plan shall include proposed authentication types based on security classification (low, moderate, high) for all end-user integration points such as Azure Active Directory (Azure AD) using employee SAML PIV and OAuth or Login.gov and applies to all private and externally facing public systems. All physical and logical authentications shall be configured https://www.dhs.gov/compliance-test-processes https://www.dhs.gov/compliance-test-processes
J-3 with compliant multi-factor authentication (MFA), single sign-on (SSO) – (FIDO2, WebAuthn, role-based LDAP, etc.).
Proposals shall focus delivery on both (1) a unified comprehensive solution that leverages the entire IT System boundary and (2) reduces end user confusion and management complexity.
1) Agency Personnel Authentication: Contractor shall provide a trusted security communication channel for cloud environment management to support the Government’s PIV Card authentication of remote access (OMB M-11-11 HSPD-12 Policy for a Common Identification Standard for Federal Employees and Contractors). The DOI Agency requires all cloud service offerings to be configured with Active Directory Federated Services (ADFS) using SAML 2.0 Single Sign-on Authentication prior to going into production stage.
2) Public / Customer Authentication: Contractor shall provide a phishing-resistant “Identity Authentication” single sign-on credentialling option configured for external facing customer services that meet the M-22-09 “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles” (e.g.login.gov). Contractor shall propose option(s) to establish effective customer authentication including license and startup configuration support services.
DOI currently has an agreement with GSA to provision Department-wide Login.gov licenses. Vendors should expect the government to provide the Login.gov licenses and therefore, only include support services to configure, test, and implement Login.gov between the vendor’s cloud service and public.
3) Contractor Personnel: Contractors authenticating into Agency cloud services shall also comply with Homeland Security Presidential Directive (HSPD-12) that require all federal entities and associated contractors have security background investigations equivalent to federal employees. Background investigations will be performed by the Office of Personnel Management (OPM).
• In accordance with FAR Subpart 4.13 Personnel Identify Verification, the solicitation will include the Federal Information Processing Standards Publication (FIPS PUB) Number 201, "Personal Identity Verification of Federal Employees and Contractors"; and the Office of Management and Budget (OMB) Guidance M-05-24, dated August 5, 2005, "Implementation of Homeland Security Presidential Directive (HSPD) 12-Policy for a Common Identification Standard for Federal Employees and Contractors."
• In accordance with FAR Subpart 4.19 Basic Safeguarding of Covered Contractor Information Systems the solicitation will include FAR Clause 52.204-21 Basic Safeguarding of Covered Contractor Information Systems (NOV 2021).
Three levels of background clearances exist
a. Standard –Low risk positions require a National Agency Check with Written Inquiries (NACI) or equivalent investigation
J-4
b. Moderate risk positions will be identified within individual task orders. These require either a Limited Background Investigation (LBI) or a Minimum Background Investigation (MBI) based on case-by-case determination
c. High risk positions require a full Background Investigation (BI)
If level of background is not specified, Contractor shall provide support personnel cleared at the minimum (Low) background investigation level. Minimum background investigations seek information about support personnel employment, criminal, and personal history in an effort to investigate behavioral reliability, integrity, and personal adjustment. Individual task orders will identify elevated security credentials if needed.
IT Systems within the Department that process Sensitive Compartmented Information (SCI) must meet the same security standards as systems that process controlled unclassified information. Department programs and contractors shall comply with NIST Special Publication 800-59, Guideline for Identifying an Information System as a National Security System.
1) Systems processing collateral (non-SCI) national security information must comply with security policy established by the Committee on National Security Systems (CNSS).
2) Systems processing SCI must comply with security policy established by the Director of National Intelligence (DNI) in Intelligence Community Directive (ICD) 503, Intelligence Community Information Technology Systems Security Risk Management, Certification and Accreditation.
C.5.2.2 Secure Software Development Framework (SSDF) - Supply Chain Security Contractor shall develop and deliver software aligned to the NIST Special Publication 800-281 Secure Software Development Framework (SSDF) publication principles. They should (1) ensure their people, processes, and technology are prepared to perform, (2) protect all components of their software from tampering and unauthorized access, (3) produce well-secured software with minimal security vulnerabilities, and (4) identify residual vulnerabilities in software releases and response appropriately.
Contractor is expected to integrate the NIST SSDF Guidance under Executive Order 14028 Section 4e into their existing software lifecycle management practices to ensure only secure and trustworthy products. SSDF practices help software producers reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent recurrence. Section 4e principles include:
• Using administratively separate build environments,
• Auditing trust relationships,
• Establishing multi-factor authentication and conditional access,
• Employing encryption for data,
• Monitoring operations and alerts and responding to attempted and actual cyber incidents o Provide artifacts that demonstrate compliance, o Employ automated tools, or comparable processes to maintain trusted source code supply chains, J-5 o As requested, make publicly available summary information the artifacts of tools and processes, o Maintain accurate up-to-date data, origin, or code, components, and controls, o Provide software bill of materials (SBOM), o Participate in vulnerability disclosure program that includes reporting and disclosure process, o Attesting to conformity with SSD practices, o Ensure and attest (to the extent practicable) the integrity and origin of open-source software used within any portion of product.
C.5.2.3 Systems Uptime - Downtime Contractor shall deliver several tiers of uptime (of all Contractor controlled resources) in terms of percentage of minutes/hours a month the resources shall be fully operational and available.
Planned scheduled downtime and meet mean-time-to-recovery are counted as the system being fully operational.
Uptime default or “fully operational systems” shall be >= 99.90% (greater than or equal to) which is depicted in Band 3, unless otherwise identified or negotiated in individual task orders.
Table 1 Uptime Service Band
Uptime Service Band Minimum
Maximum
Maximum Planned Downtime
Band 1 99.99% 100.0% <4 minutes/month Band 2 99.90% 99.99% <43 minutes/month
Band 3 (default) 99% 99.90% <7.2 hours/month Band 4 95% 95% <36 hours/month Band 5 93% 99% <50 hours/month
Contractor shall provide support services that accommodate several maintenance windows.
Planned downtime shall be at or better than the Band 5 (default) timeframe listed below or otherwise identified in the individual task order and agreed upon by application system owner.
1) All software upgrades and patching shall be coordinated with the IT System customers.
2) The Contractor shall notify system administrators of routine patches and version control services at least 48 hours in advance.
Table 2 Downtime Service Band
Downtime Service Band Minimum
Maximum (<) Notes
Band 1 (high availability) 0.1 min Band 2 0.1 min 1 hr Band 3 1 hr 2 hr Band 4 2 hr 4 hr
Band 5 (default) 4 hr 8 hr During non-peak times
J-6
Band 6 8 hr 24 hr
C.5.2.4 Disaster Recovery Plan Contractor shall provide backup, recovery and disaster recovery parameters in a Disaster Recovery Plan for the (1) Recovery Time Objective (RTO) and (2) Recovery Point Objective (RPO) and (3) Mean-Time-To-Recovery (MTTR). Combinations of compute services, storage, file systems, applications, programming interfaces, and data are defined as the minimum availability requirements.
The Contractor shall meet at least the minimum performance requirement and may propose one or more alternative service bands to provide either a more robust service level for mission critical applications or less stringent service level to save on test/sandbox or similar services.
Figure 1 Last Backup Recovery Point
Defaults are set for the following minimum objectives:
1) Recovery Time Objective (RTO) – ability to recover files within 48 hours of request and 24 hours for High Value Assets. Identifies how long it takes to restore. The maximum allowable downtime to restore the incident back to normal operations for both administrators and users.
Table 3 Recovery Time Objective (RTO)
Recovery Time Objective (RTO) From To Band 1 0 minutes 5 minutes Band 2 5 minutes 4 hours
Band 3 (High Value Asset) 4 hours 24 hours Band 4 (default) 24 hours 48 hours
Band 5 48 hours 7 days
2) Recovery Point Objective (RPO) – ability to recover files from a failure occurrence to the last valid backup, defaulting to the most recent. The RPO is set to guarantee that following a triggering event, systems will be reverted to a prior state no older than 24 hours old for any specific day within a rolling two (2) month period.
Table 4 Recovery Point Objective (RPO)
Recovery Point Objective (RPO) From To
J-7
Band 1 0 minutes 5 minutes Band 2 5 minutes 4 hours
Band 3 (default) 4 hours 24 hours Band 4 24 hours 48 hours Band 5 48 hours 7 days
3) Mean Time To Recovery (MTTR) – the elapsed average time required to complete a recovery is set for eight (8) hours. Recovery time begins with time of failure and ends with system back to normal operations. Depending on the size of individual restore requests the calculated “Average” is from the aggregate of all restore requests over the timeline of 180 days.
Table 5 Mean Time To Restore (MTTR)
Mean-Time-to-Restore Bands Time to Restore
Band 1 0 to 2 hours Band 2 2 to 4 hours
Band 3 (Default) 4 to 8 hours Band 4 8 to 24 hours
In summary, the Contractor shall guarantee that, following a triggering event, systems will be reverted to a prior state no older than (24 hours) old and have capacity to roll back for two (2) months and systems will be made operational within (48) hours, but with a 180-day elapsed average for recovery set at (8 hours); unless otherwise identified differently in the individual task order.
C.5.3 Performance Contractor shall provide on-demand services for the scale of basic resources that must be readily provisional. Contractors shall deliver their standards, defaults, suggestions and tiered options of provisional performance services including the speed the hosted system can respond to changes on demand and other measurable performance levels. Specified times shall be identified in proposals.
Resources shall be brought online and available for use within time. After a request has been made (either manually or automatically in response to configurable triggers), resources (e.g., storage, virtual machines) shall be available within time.
C.5.3.1 Agency Managed Hosting IaaS/PaaS Platforms Administrators must be able to provision performance defaults through a cloud-based dashboard/portal. Authorized users shall be able to establish the resource scaling sequence most appropriate to their application when configuring automatic scaling. Contractor may propose alternative methods for meeting the automated, scalable objectives to streamline incremental provisioning for common, cost-effective configurations.
J-8
C.5.3.2 Adapt to Demand Fluctuations Contractor shall ensure system infrastructure is able to accommodate on-demand fluctuations with minimal impact on system performance. Anticipated seasonality, minimum, peak, and average demand rates will be provided to facilitate resource planning.
Latency shall be managed, by the Contractor, to optimize IT System responsiveness to end users and ensure functionality of the hosted application. Contractor shall deploy Virtual Application Hosting as applicable to improve user experience.
C.5.3.3 Performance Metrics Provision cloud services to permit visibility for monitoring and managing variations in performance metrics such as:
1) Provide clear access and visibility to ongoing performance and resources usage.
2) Provide role filtered self-management tools to support billing, monitoring, and reporting on service management function.
3) Provide visibility into usage metering using metrics and granularity appropriate to the type of service.
4) Provide a suite of reports, dashboards, and alarms to monitor and track operational and infrastructure performance (e.g., incidents, service usage, capacity, SLA adherence).
5) Provide automatic monitoring of resource utilization and other events such as failure of service, degraded service, etc. via service dashboard or other electronic mean.
6) Provide the ability to filter and view usage and invoicing by: Technical Service Line, bureau (and sub-bureau), program, IT System, IT System type, IT System Life-Cycle, Security Level, and other elements which may be identified in individual Task Orders.
7) Provide access to all log files generated by the hosted application, associated middleware, operating system, and underlying virtual and physical infrastructure.
8) Provide online reporting metrics interface for all resource utilization including metrics such as: current utilization, historical average, and peak for a user defined window of time.
C.5.3.4 Continuous Monitoring In accordance with FedRAMP and/or FISMA compliant requirements, Contractor shall deliver a Security Assessment Plan (SAP) and a Security Assessment Report (SAR) according to NIST Special Publication 800-53 (latest rev) on all applicable Cloud Services.
DOI requires all cloud service providers to perform continuous monitoring. Contractors shall provide and deliver a Continuous Monitoring Plan (CMP) consistent with NIST standards, including NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. The continuous monitoring program must address, at a minimum
1) the effectiveness of deployed security controls
2) changes to information systems and the environments in which the system operates
3) compliance to federal legislation, directives, policies, standards, and guidance with regard to information security and risk management.
J-9
Within the CMP, the Contractor shall develop and maintain a Plan of Action and Milestones (POA&M) report with all known IT security vulnerabilities and weaknesses and associated risk mitigation timelines for remediation. All corrective actions and related information shall be included in a monthly POA&M report and submitted according to SO/ISSO personnel according to FedRAMP or equivalent authorization requirements.
C.5.3.5 Contractor Awareness Training Within a component of continuous monitoring, all users, including Contractor administrators who authenticate into cloud instances, must be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibility changes. This is in accordance with the Federal Title 5, Code of Federal Regulations, Part 930.301, Subpart C.
All contractors requiring access to Government data shall be cleared at one of the following levels and as identified in task orders:
1) Low Risk position will require a National Agency Check with Written Inquiries (NACI) or equivalent investigation;
2) Moderate Risk position will require either a Limited Background Investigation (LBI) or a Minimum Background Investigation (MBI) based on the CO’s determination; and,
3) High Risk position will require a Background Investigation (BI).
C.5.4 Service Reliability Contractor shall deliver a Disaster Recovery Plan for each cloud provider that includes (at a minimum) service resilience, fault tolerance, customer data backup and restore, and disaster recovery reliability. Contractor shall provide automated on-demand ability for IT Systems to back up at current instance or as requested at alternate geographical location up to at least 250 miles away. The Contractor may offer software and alternate backup process solutions within their proposals.
C.5.4.1 Backup Solutions Administrators must be allowed to establish several backup solutions including:
1) Backup routines can be set through web-management console or file interface scripts.
2) Backup frequency including hourly, nightly, weekly based on automated schedule or on-demand
3) Backup components such as new, updated data only or full operating environment
4) Backup type including Full, Incremental, Differential, Mirror
5) Backup state including live readily available for automated recovery, data at rest, blob or cold archive storage
6) Backup key word searchability and filetype retention including documents, photos, videos, and associated metadata
7) Backup Length of Time and State that backup will be retained (how long to keep backups and the state they reside within that timeline); example 30 days readily available online and then convert to long term storage for up to 3 years
J-10
8) Backup method and tenancy including single or multi tenancy of public cloud-to-cloud (C2C), hybrid/private-to-cloud (P2C), mobile-to-cloud (M2C)
9) Backup encryption meets 256-bit AES encryption standards using a user-defined key that is not stored anywhere on servers
10) Backup meets FIPS 140-3 compliance and industry standards (e.g. HIPAA, PCI, Sarbanes-Oxley (SOX), CiscoIOS, Gramm-Leach-Bliley, and SEC / FINRA).
C.5.4.2 Retention Contractor shall meet a variety of retention and restore settings including:
1) Weekly retention, 15 minutes to restore
2) Monthly retention, 4 hours to restore
3) Yearly retention, 25 hours to restore
4) Ability to set a custom time period
C.5.4.3 Backup and Restore Service Levels Contractor shall meet backup and restore service levels including the average time required to complete a restore request. Given that the size of a restore request will influence time required to restore it, these service levels are calculated as the average of all restore requests (both big and small) over a month. Unless otherwise noted in individual statements of work, backup solutions must
1) Be an agentless architecture solution
2) Meet 100TB backup capacity in under 8 hours
3) Be scalable into the petabyte range of data
4) Must be able to test and verify without restoring to production
5) Ability to launch VM directly from de-duplicated compressed backup file located on backup repository
6) Provide end-to-end 256 AES Encryption
C.5.5 Data Management Data security and availability requirement levels are identified in each IT Systems categorization as low, moderate, or high. The contractor shall deliver a full description with each task order identifying theirs and the customers roles and responsibilities of securing and protecting data.
Information shall be provided in the form of a Control Implementation Summary (CIS) worksheet and Customer Responsibility Matrix (CRM) or equivalent.
C.5.5.1 Hosting Environments Hosting environments provisioned by service providers must demonstrate an appropriate level of security by meeting the requirements of the Federal Information Security and Management Act (FISMA) for moderate-impact systems, and related agency-specific policies. This includes a formal agency security authorization review covering security controls, continuous monitoring, and identification of risks. The agency must consider and accept the risks before Authority to Operate (ATO) will be granted.
J-11
As a standard, the DOI requires the service provider environment qualify for ATO no later than 180 calendar days from the date of award. Moreover, the service provider must become compliant with Federal Risk and Authorization Management Program (FedRAMP) requirements within 180 calendar days of the date it becomes available and must maintain compliance throughout the period of performance. The continuous monitoring provided must comply with the NIST Special Publication 800-137 framework and Department of Homeland Security (DHS) guidance.
1) Contractor shall provide security for non-standard data transfers both in transit and at rest resulting from the migration of the applications or services to the cloud.
2) Contractor shall provide support for specified auditable events related to the applications or services.
3) Contractor shall provide at time of initiating new individual task orders, the cloud service provider and customer responsibility requirements for when end-of-life, repurchasing, decommissioning occurs including timelines and limits of preservation, removal, snapshots, deletion, sanitizing and other associated requirements of government customized application, configured hosting services, compute instances, and government data storage on the last day (and timeline beyond) task order period of performance.
C.5.5.2 Intellectual Property (IP) The Contractor shall ensure the protection of government intellectual property (IP) and data ownership rights and those of any licensors.
1) Contractor shall identify Intellectual Property components owned and managed by them or the cloud service provider or by the Government.
2) Contractor shall identify in their proposal any expected additional Intellectual Property and licensing "buy-out" costs at end of life-cycle or Task Order termination.
C.5.5.2 Federal Information Processing Standard - FIPS 140-3 All task orders shall meet the following minimal Federal mandates of cloud security and boundary thresholds:
1) Cryptographic modules are consistently validated to FIPS 140-2 and 140-3 as applicable and aligned to the Cryptographic Module Validation Program (CMVP) requirements under NIST Special Publication 800-140 A-F and ISO/IEC 19790:2012 and ISO/IEC 24759:2017.
2) Systems fully support user authentication via Agency Common Access Card (CAC) or Personal Identity Verification (PIV) credentials as identified in OMB Memorandum M- 11-11;
3) Systems operate at Digital Identity Level 2 or higher;
4) Cloud Service Provider has ability to remediate High vulnerabilities with 30-days, Moderate vulnerabilities within 90 days, and Low vulnerabilities within 180 days;
J-12
5) Cloud Service Provider meets Federal Records Management Requirements, including ability to support record holds, National Archives and Records Administration (NARA) requirements, and Freedom of Information Act (FOIA) requirements;
6) Cloud Service Provider’s external DNS security (NDSSEC) provides origin authentication and integrity verification.
All Cloud Service Provider solutions shall meet FIPS 140-2 certification and provide the capability to encrypt all data, including backups. Environments shall employ appropriate levels of encryption including data in-transit between user endpoint and cloud services and at-rest sensitive data according to Federal Information Processing Standard Publication (FIPS) 140-2 a mandatory standard for the protection of sensitive or valuable data within Federal IT systems.
Additionally, FIPS 140-3 shall be used as an incremental advancement for compliant and validated cryptographic modules, algorithms, and conditional algorithm self-tests.
C.5.5.4 Continental United States (CONUS) Contractor shall select cloud services that access, transmit, process, house, and store all sensitive agency information, including information subject to the Privacy Act and Personally Identifiable Information (PII), only within the sole jurisdiction of the United States Federal Government (i.e., within the continental United States, Hawaii, Alaska, Puerto Rico, Guam, and the Virgin Islands).
Contractor shall ensure all IaaS/PaaS cloud service providers have capacity to implement cloud service infrastructure and data storage redundancy in at least two facilities located within the sole jurisdiction of the United States Federal Government (i.e., within the continental United States, Hawaii, Alaska, Puerto Rico, Guam, and the Virgin Islands) with adequate geographical separation of at least 250 miles with one serving as the primary site and the other as an alternate backup Disaster Recovery (DR) site capable of restoration and resumption of IT services and complete preservation and reconstitution of all DOI data/information within 24 hours of failure of the services normally provided by the primary site.
C.5.5.5 Protection of PII - Privacy The Contractor shall adhere to and comply with applicable Laws, Executive Orders and Executive Branch Policy regarding privacy during design, build, testing, operations and maintenance of the information system and the security controls designed to safeguard agency information. Privacy requirements are applicable when DOI information is generated, accessed, stored, processed, or exchanged with DOI or on behalf of DOI by a service provider or subcontracted service provider, regardless of whether the information resides on a DOI information system or a service provider/subcontracted service provider’s information system.
1) The service provider shall protect unauthorized disclosure and the confidentiality, integrity, and availability of Government electronic information and resources according to the categorization and NIST SP 800-53.
2) Contractor shall not remove PII or Privacy Act material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity.
J-13
3) When Privacy Act records, information, data, documentary material, and/or equipment is no longer required, it shall be returned to the Governments control, or the Contractor must hold it until otherwise directed. Items returned to the Government shall be securely mailed or electronically transmitted.
4) Contractor may be required to provide necessary support to assist the Government in meeting the requirements of the Privacy Act and related laws and shall cooperate to provide supporting documentation and access to information upon request by authorized agency officials. Support in this context includes:
• Requests for access or disclosure of records to individuals
• Subpoenas or other judicial process
• Discovery and litigation processes
• Accounting of disclosures of records to third parties when authorized
• Privacy impact assessments and related privacy artifacts
• System of records notices;
• Privacy complaints and incidents
• Audits or remedial activities related to oversight of PII and system of records
5) Contractor shall comply with applicable authorities to Federal CUI Systems: (1) EO
13556, Controlled Unclassified Information, November 4, 2010, (2) 32 CFR 2002 Controlled Unclassified Information (Implementing Directive), (3) The Federal CUI Registry, (4) Departmental standards.
C.5.5.6 Logging and Monitoring Focus To provide resiliency against successful attacks on cloud services, including those due to customer misconfigurations, proposals should include sufficient logging and monitoring governance. DOI requests vendor proposals include support measures that focus on the following list when aligned to the respective task order(s).
1) Cloud Environments General:
Provide 12 months active storage and 18 months cold data storage for any activity on Breakglass Account(s) (which should never have to be used); Conditional Access Policy Changes, Changes to Environment Policies (e.g. Azure Subscription, AWS Services, Google Solutions, etc.) in Management Logs; Privileged Role Changes; Virtual Network (VNet) Changes; Deletions of Delete Locks, Changes to Logging Policies; Privileged Identity Management (PIM) and Identity Protection Changes; Changes to Alert Rules (Audit the Auditor); Key Vault/Key Management Changes; Storage File Access Logs, File Hashes; Baseline Deviations for Prod App and Data Tiers; IDS / IPS / NTA / NDR / SIEM Logs; API Activity Logs; Authentication Logs; Firewall Logs; Web Proxy/WAF Logs; Service Metrics; Billing Data; Flow Logs; Remote Access/VPN Logs; System/OS Logs; DLP Logs; DNS Query/Response Logs
2) Cloud AWS:
J-14
Provide 12 months active storage, 18 months cold storage, and 72 hours packet capture for AWS Cloudtrail; Amazon Cloudwatch Logs; AWS Config; Amazon S3 Access Logs; Amazon VPC Flow Logs; AWS WAF Logs; AWS Shield, AWS Guardduty; AWS Security Hub
3) Cloud Azure:
Provide 12 months active storage and 18 months cold data storage for Azure Active Directory Logs; Activity Logs; Unified Audit Logs (w/ Advanced Audit Features)
4) Cloud GCP:
Provide 12 months active storage and 18 months cold data storage for Access Transparency Audit Log; Admin Audit Log; Data Studio Audit Log; Drive Audit Log;
Email Audit Log; Groups Audit Log, LDAP Audit Log; Login Audit Log; Devices Audit Log; Sail Audit Log; Token Audit Log; User Accounts Audit Log, OAuth Token Audit Log; Security Reports
C.5.6 Information Security This section covers some of the most critical Contractor management requirements. Some task orders will request minimal information security management from the Contractor, but others will request full support of major and high value assets. In all cases, the Contractor will be expected to have an intricate knowledge of Federal Regulations identified below. They shall facilitate the Assessment & Authorization process in order to achieve a full Authority to Operate
(ATO).
C.5.6.1 Security Objectives The security objectives below are aligned federal directives. Contractors shall describe how their solutions meet these thresholds within individual task order proposals where they differ or provide additional, or value-added information. Individual task orders will identify variations, reduced or elevated requirements for that specific program, application, IT System, or service.
Objectives are to offer services that achieve Governance - Regulation Adherence and that meet the following overarching Federal statutes:
1) Ensure advanced, intelligent, automated approach to be able to achieve ongoing Assessment and Authorization (A&A) of the cloud service tenant according to the appropriate level and conform with the Federal Information Security Modernization Act (FISMA), the , OMB Circular A-130, and Executive Order (EO) 14028 “Improving the Nation’s Cybersecurity” FedRAMP standards.
2) Information shall comply with Executive Order 13556 regarding Controlled Unclassified Information (CUI), Personally Identifiable Information (PII) a subset of CUI, and Sensitive PII a subset of PII that requires additional controls and safeguards. (See also NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.)
https://www.congress.gov/bill/113th-congress/senate-bill/2521 https://www.federalregister.gov/documents/2016/07/28/2016-17872/revision-of-omb-circular-no-a-130-managing-information-as-a-strategic-resource https://www.federalregister.gov/documents/2010/11/09/2010-28360/controlled-unclassified-information https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf
J-15
3) Recommend and maintain zero-trust strong physical security controls, managed access to the virtual environment, and maintain strong separation between virtual workloads and environments. Provide clear segregation of data unless otherwise specified, at the application level, and storage level. (OMB M-22-09 Moving the U.S. Government Toward Zero Trust Cybersecurity Principles)
4) Provide accessibility through both Internet Protocol Version 6 (IPv6) and IPv4. If not already IPv6 compliant, the Contractor shall provide the Government with a statement regarding its plans and timeframe to implement IPv6. Technical objectives shall meet OMB M-21-07 IPv6 Completing the Transition to Internet Protocol Version 6 (IPv6) service level and NIST Special Publication 500-267 A (or most recent version).
5) Provide the ability to control (including restricting) government access to the cloud service from government specified networks, in accordance with the Office of Management and Budget (OMB) Memorandum M-19-26 (previously M-08-05), “Implementation of Trusted Internet Connections (TIC),” and the Department of Homeland Security’s “Trusted Internet Connections (TIC) Reference Architecture Document Version 2.0 (or 3.0 as available).” If not currently able to provide this ability, the Contractor shall provide the Government with a statement regarding its plans to have such capability, including timeframe. (OMB M-19-26 Update to the Trusted Internet Connections (TIC) Initiative)
C.5.6.2 Security Controls Administration Assessing, monitoring, and documenting all aspects of security controls requires a cadre of experienced staffing resource. To recapture time and resources, the Department encourages Contractors and cloud service providers to adopt, standardize, and streamline security controls management. For example, using Open Security Controls Assessment Language (OSCAL) for compiling FedRAMP documentation. OSCAL is a framework (expressed in XML, JSON, YAML) to take FedRAMP documentation that is properly formatted with NIST OSCAL schemas and check the content for correctness.
FedRAMP's adoption of OSCAL allows providers to use this framework to perform logical validations, i.e. business rule checks, on documentation content. (See May 2022 FedRAMP Receives First OSCAL System Security Plan | FedRAMP.gov)
The Contractor services and associated solutions shall implement the following requirements:
1) Conduct annual penetration testing using a qualified and competent independent third-party assessor/evaluator subject to approval by the agency Authorizing Official.
2) For Infrastructure as a Service (moderate or higher) implementations provide storage redundancy in at least two facilities located at least 250 miles with one serving as the primary site and the other as an alternate backup Disaster Recovery (DR) site capable of restoration and resumption of services and complete preservation and reconstitution of all DOI data/information within 24 hours of failure of the services normally provided by the primary site.
3) Provide a Data Loss Prevention (DLP) capability to detect and prevent the potential loss, exposure, or confidentiality risks to DOI’s sensitive agency information, including https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf#:%7E:text=The%20agency-wide%20IPv6%20policy%20must%20require%20that%2C%20no,the%20use%20of%20IPv4%20for%20all%20systems%3B%203.
https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf https://www.fedramp.gov/templates/ https://pages.nist.gov/OSCAL/ https://pages.nist.gov/OSCAL/ https://www.youtube.com/watch?v=WCPkt56vZ-s https://www.fedramp.gov/2022-05-19-first-oscal-system-security-plan/ https://www.fedramp.gov/2022-05-19-first-oscal-system-security-plan/
J-16 information subject to the Privacy Act and Personally Identifiable Information (PII), resulting from intentional or unintentional disclosure to external entities.
4) Provide e-Discovery, a process in which electronic data is sought and located, capabilities that enable compliance with legal mandates and requests capabilities to support legal hold requests.
C.5.6.3 Security Plan Contractor shall ensure and deliver Cloud Service Providers document and submit Security Plans (SP) identifying the risk impact rating for the IT Systems confidentiality, integrity, and availability according to the NIST Special Publication SP 800-37: Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach.
The objective is achieving all Cybersecurity & Infrastructure Security Agency (CISA) Binding Operational Directives (BOD) and applicable federal requirements for each environment. IT System contractors and government system owners and security officers will identify and assign security roles and coverage. Collectively they coordinate implementing the security controls and any required tailoring based upon the categorization level. To meet this objective, Contractors shall comply and meet thresholds set in the NIST SP 800-53 Risk Management Framework “Security and Privacy Controls for Federal Information Systems and Organizations.”
Supplemental guidelines include:
• NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View and
• NIST SP 800-18 Guide for Developing Security Plans for Federal Information Systems
• NIST SP 800-60 Mapping Types of Information and Information Systems to Security
Categories
• NIST SP 800-34 Contingency Planning Guide for Federal Information Systems
Environments shall be configured for the ability to provide any application and operating system logs associated with an incident, as well as a file system timeline for potentially compromised hosts and any additional files referenced during forensic analysis. Allow for memory dumps and forensic images of any systems that were possibly compromised.
C.5.6.4 IdAAM Seamlessly integrate with the Agency Identity, Authorization and Access Management (IdAAM) solution that consists of the Microsoft Active Directory (AD) and Public Key Infrastructure (PKI) architecture and associated Certificate Authority and DOI HSPD-12 PIV SmartCard-based credentials.
C.5.6.5 Government Configuration Baseline Provide solutions that conform to the Federal Desktop Core Configuration (FDCC) and United States Government Configuration Baseline (USGCB) security configuration requirements; and that are compatible with end-user client computing devices, operating systems, and client software/interfaces (e.g., workstations, laptops, mobile/portable devices) that are configured in accordance with those specifications; and that do not alter, or require alteration of, those baseline standard security configurations https://www.nist.gov/privacy-framework/nist-sp-800-37 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://csrc.nist.gov/publications/detail/sp/800-39/final https://csrc.nist.gov/publications/detail/sp/800-18/archive/1998-12-01 https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final
J-17
C.5.6.6 Incident Response Upon any security or privacy breach, Cloud Service Provider(s) under these task orders shall immediately (within 1 hour) report all incidents involving potential risks to the confidentiality, integrity, or availability of the IT System. Contractor shall submit an email to the following incumbents designated at time of task order initiation or when notified of personnel changes.
Contractor shall follow the Incident Response procedures for all privacy breaches and take immediate action (within 1 hour when identified) to contain and mitigate the impact of the breach and cooperate with Government officials to investigate the breach and determine remedial measures. Contractor shall document:
• Government programs and/or platforms
• Location of breach(es)
• Date and time breach was discovered
• Nature of event (loss, theft, unauthorized access)
• Description of summary of events
• Description of personally identifiable information PII) involved
• Number of potentially impacted individuals
• Estimated number of records, data sets, etc. exposed or compromised
This shall be reported regardless of day or time.
1) Department of the Interior - Computer Incident Response Center (DOI-CIRC) at doicirc@ios.doi.gov and 703-648-5655. For non-DOI agencies, submit to their equivalent
2) Contracting Officer
3) Authorizing Official and/or System Owner
4) Information System Security Officer and/or Cloud Service Provider portal within max.gov
Note: Emails shall not contain Sensitive Information in the subject or body but instead encrypted within an attachment according to the NIST Federal Information Processing Standards (FIPS) 140-2 Security Requirements for Cryptographic Modules.
C.5.6.7 Prohibitions Prohibitions describes various prohibitions within cloud services and contractors.
1) Adware: DOI requests contractors to refrain from and to actively prevent adware, spam, and remarketing of information. The Contractor shall not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the Agency. The Contractor and/or their agents shall not resell nor otherwise redistribute information gained from its access to contract users.
2) Non-Disclosure Agreements: Contractors shall require each of their administrative employees that interfaces with the cloud services customized applications and government data to sign non-disclosure agreements at onset of project mailto:doicirc@ios.doi.gov
J-18 implementation. Non-disclosure agreements will be supplied by the Contracting Officer, or the Contractor may elect equivalent and approved alternative.
3) Government Banners: A government approved logon banner must be displayed on the first page of any public access web pages. Logon warning banners must be automatically incorporated into IT Systems initial logon process and require periodic credentialed acceptance for all (federal and contractor) personnel accessing the federal IT System.
C.5.7 Service Support Contractor shall describe and deliver help desk and support services. These may include a variety of means in reaching their support teams including trouble ticketing system, Tier 0 support website, support email boxes, chat operators, on-demand videos, recurring group forums, etc.
Contractor shall describe their core (default) and optional (additional) support offerings. Type of support descriptions should include service 1) availability and 2) Time to Respond (acknowledge) requests and 3) Costs if not included.
C.5.7.1 Support Severity Levels Contractor shall compare their support tiers and “mean-time-to” options based upon the Severity Levels below. Mean-time-to calculations should be based on a 180-day average of all restores and measured against the initial response time until satisfactory resolution or escalation occurs.
Table 6 Severity Levels
Severity 1: Emergency (Health and Safety) 15 minutes – 4 hours Severity 2: Mission Priority (Bureau Director) 60 minutes – 8 hours Severity 3: Routine 2 hours – 24 hours
Upon contacting support services (helpdesk), the Contractor shall acknowledge the request within their mean-time-to acknowledge and resolve the request within their mean-time-to restore.
If the individual task order or task proposal does not describe alternate band requirements, the contractor shall meet the Band 3 default below.
Table 7 MTTR with Severity Levels
Mean-Time-to-Restore
Bands Severity 1 Severity 2 Severity 3
Band 1 0 min to 15 min 15 min to 1 hr 1 hr to 2 hr Band 2 0 min to 1 hr 1 hr to 2 hr 2 hr to 4 hr
Band 3 (default) 0 hr to 2 hr 2 hr to 4 hr 4 hr to 8 hr Band 4 2 hr to 4 hr 4 hr to 8 hr 8 hr to 24 hr
Within thirty (30) days of any major outage occurrence resulting in greater than 1-hour of unscheduled downtime, the Contractor shall describe the outage including description of root-cause and fix. If cause is related to an associated Cybersecurity & Infrastructure Security Agency (CISA) vulnerability, Contractor shall report and fully comply with requirements as identified within the respective Emergency Directive (ED) YY-###.
J-19
C.5.7.2 Support Availability Times Contractors shall provide their hours of availability the customer can expect to reach a live support or service person able to take down a request for service or log a trouble ticket, based upon available time zones in the Continental United States (CONUS).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .