Attachment_3._Security_Requirements.pdf

PDF 102 KB Posted

Attached to
Administrative and Program Support Services Federal contract opportunity
Solicitation number
HSSCCG-17-R-00033
Issued by
Department of Homeland Security US Citizen and Immigration Services

About this file

Attachment 3. Security Requirements

View the file

Other files for this federal contract opportunity

Other files attached to Administrative and Program Support Services, newest first.
File Type Posted
Attachment_5._Contractor_Pricing_Schedule_Rev_3.pdf PDF
27Feb2018_Questions.pdf PDF
Attachment_7._WD_2015-4281_Rev._9.pdf PDF
Attachment_2._Terms_and_Conditions_Rev.2_Comparison.pdf PDF
Attachment_2._Terms_and_Conditions_Rev.2.pdf PDF
Attachment_5._Contractor_Pricing_Schedule_Rev.2_Comparison.pdf PDF
Attachment_6._WD_2015-4187_Rev._8.pdf PDF
Attachment_5._Contractor_Pricing_Schedule_Rev.2.pdf PDF
Attachment_8._WD_2015-5613_Rev._9.pdf PDF
Attachment_2._Terms_and_Conditions_Rev.1.pdf PDF
Attachment_1._Performance_Work_Statement_Rev.3.pdf PDF
Attachment_7._WD_2015-4281.pdf PDF
Attachment_8._WD_2015-5613.pdf PDF
Attachment_9._Government_Furnished_Property.pdf PDF
Attachment_6._WD_2015-4187.pdf PDF
Attachment_5._Contractor_Pricing_Schedule_Rev.1.pdf PDF
Attachment_3._Security_Requirements.pdf PDF
Attachment_4._Privacy_Clause_Requirement.pdf PDF
August102017_Answers.pdf PDF
Attachment_6._WD_2015-4187.pdf PDF
Attachment_7._WD_2015-4281.pdf PDF
Attachment_1._Performance_Work_Statement_Rev.3.pdf PDF
August42017_Answers.pdf PDF
Attachment_8._WD_2015-5613.pdf PDF
Attachment_2._Terms_and_Conditions_Rev.1.pdf PDF
Attachment_5._Contractor_Pricing_Schedule_Rev.1.pdf PDF
August32017_Answers.pdf PDF
Attachment_1._Performance_Work_Statement_Rev.2.pdf PDF
July_28_Answers.pdf PDF
Attachment_1._Performance_Work_Statement_Rev.1.pdf PDF
Attachment_10_-_Question_Submission_Form.xlsx XLSX spreadsheet
Attachment_7._WD_2015-4281.pdf PDF
Attachment_8._WD_2015-5613.pdf PDF
Attachment_6._WD_2015-4187.pdf PDF
Attachment_5._Contractor_Pricing_Schedule.pdf PDF
Attachment_9._Government_Furnished_Property.pdf PDF
Attachment_1._Performance_Work_Statement.pdf PDF
Attachment_2._Terms_and_Conditions.pdf PDF
Attachment_4._Privacy_Clause_Requirement.pdf PDF
Show all 39

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Citizenship and Immigration Services Office of Security and Integrity – Personnel Security Division

SECURITY REQUIREMENTS

GENERAL

U.S. Citizenship and Immigration Services (USCIS) has determined that performance of this contract requires that the Contractor, subcontractor(s), vendor(s), etc. (herein known as Contractor), requires access to sensitive but unclassified information, and that the Contractor will adhere to the following.

SUITABILITY DETERMINATION

USCIS shall have and exercise full control over granting, denying, withholding or terminating access of unescorted Contractor employees to government facilities and/or access of Contractor employees to sensitive but unclassified information based upon the results of a background investigation.

USCIS may, as it deems appropriate, authorize and make a favorable entry on duty (EOD) decision based on preliminary security checks. The favorable EOD decision would allow the employees to commence work temporarily prior to the completion of the full investigation. The granting of a favorable EOD decision shall not be considered as assurance that a full employment suitability authorization will follow as a result thereof. The granting of a favorable EOD decision or a full employment suitability determination shall in no way prevent, preclude, or bar the withdrawal or termination of any such access by USCIS, at any time during the term of the contract. No Contractor employee shall be allowed unescorted access to a Government facility without a favorable EOD decision or suitability determination by the Office of Security & Integrity Personnel Security Division (OSI PSD).

BACKGROUND INVESTIGATIONS

Contractor employees (to include applicants, temporaries, part-time and replacement employees) under the contract, needing access to sensitive but unclassified information shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract as outlined in the Position Designation Determination (PDD) for Contractor Personnel. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. All background investigations will be processed through OSI PSD.

To the extent the Position Designation Determination form reveals that the Contractor will not require access to sensitive but unclassified information or access to USCIS IT systems, OSI PSD may determine that preliminary security screening and or a complete background investigation is not required for performance on this contract.

Completed packages must be submitted to OSI PSD for prospective Contractor employees no less than 30 days before the starting date of the contract or 30 days prior to EOD of any employees, whether a replacement, addition, subcontractor employee, or vendor. The Contractor shall follow guidelines for package submission as set forth by OSI PSD. A complete package will include the

Page 1 of 8 Security Clause 5 w/IT tnvezina Typewritten Text

HSSCCG-17-R-00033

Attachment 3 tnvezina Typewritten Text tnvezina Typewritten Text following forms, in conjunction with security questionnaire submission of the SF-85P, “Security Questionnaire for Public Trust Positions” via e-QIP:

1. DHS Form 11000-6, “Conditional Access to Sensitive But Unclassified Information

Non-Disclosure Agreement”

2. FD Form 258, “Fingerprint Card” (2 copies)

3. Form DHS 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act”

4. Position Designation Determination for Contract Personnel Form

5. Foreign National Relatives or Associates Statement

6. OF 306, Declaration for Federal Employment (approved use for Federal Contract Employment)

7. ER-856, “Contract Employee Code Sheet”

EMPLOYMENT ELIGIBILITY

Be advised that unless an applicant requiring access to sensitive but unclassified information has resided in the U.S. for three of the past five years, OSI PSD may not be able to complete a satisfactory background investigation. In such cases, USCIS retains the right to deem an applicant as ineligible due to insufficient background information.

Only U.S. citizens are eligible for employment on contracts requiring access to Department of Homeland Security (DHS) Information Technology (IT) systems or involvement in the development, operation, management, or maintenance of DHS IT systems, unless a waiver has been granted by the Director of USCIS, or designee, with the concurrence of both the DHS Chief Security Officer and the Chief Information Officer or their designees. In instances where non-IT requirements contained in the contract can be met by using Legal Permanent Residents, those requirements shall be clearly described.

The Contractor must agree that each employee working on this contract will have a Social Security Card issued by the Social Security Administration.

CONTINUED ELIGIBILITY

If a prospective employee is found to be ineligible for access to USCIS facilities or information, the Contracting Officer’s Representative (COR) will advise the Contractor that the employee shall not continue to work or to be assigned to work under the contract.

In accordance with USCIS policy, contractors are required to undergo a periodic reinvestigation every five years. Security documents will be submitted to OSI PSD within ten business days following notification of a contractor’s reinvestigation requirement.

In support of the overall USCIS mission, Contractor employees are required to complete one-time or annual DHS/USCIS mandatory trainings. The Contractor shall certify annually, but no later than

Page 2 of 8 Security Clause 5 w/IT

December 31st each year, that required trainings have been completed. The certification of the completion of the trainings by all contractors shall be provided to both the COR and Contracting Officer.

• USCIS Security Awareness Training (required within 30 days of entry on duty for new contractors, and annually thereafter)

• USCIS Integrity Training (Annually)

• DHS Continuity of Operations Awareness Training (one-time training for contractors identified as providing an essential service)

• USCIS Office Safety Training (one-time training for contractors working within USCIS facilities; contractor companies may substitute their own training)

• USCIS Fire Prevention and Safety Training (one-time training for contractors working within USCIS facilities; contractor companies may substitute their own training)

USCIS reserves the right and prerogative to deny and/or restrict the facility and information access of any Contractor employee whose actions are in conflict with the standards of conduct or whom USCIS determines to present a risk of compromising sensitive but unclassified information and/or classified information.

Contract employees will report any adverse information concerning their personal conduct to OSI PSD. The report shall include the contractor’s name along with the adverse information being reported. Required reportable adverse information includes, but is not limited to, criminal charges and or arrests, negative change in financial circumstances, and any additional information that requires admission on the SF-85P security questionnaire.

In accordance with Homeland Security Presidential Directive-12 (HSPD-12) http://www.dhs.gov/homeland-security-presidential-directive-12 contractor employees who require access to United States Citizenship and Immigration Services (USCIS) facilities and/or utilize USCIS Information Technology (IT) systems, must be issued and maintain a Personal Identity Verification (PIV) card throughout the period of performance on their contract. Government-owned contractor-operated facilities are considered USCIS facilities.

After the Office of Security & Integrity, Personnel Security Division has notified the Contracting Officer’s Representative that a favorable entry on duty (EOD) determination has been rendered, contractor employees will need to obtain a PIV card.

For new EODs, contractor employees have [10 business days unless a different number is inserted] from their EOD date to comply with HSPD-12. For existing EODs, contractor employees have [10 business days unless a different number of days is inserted] from the date this clause is incorporated into the contract to comply with HSPD-12.

Contractor employees who do not have a PIV card must schedule an appointment to have one issued.

To schedule an appointment:

http://ecn.uscis.dhs.gov/team/mgmt/Offices/osi/FSD/HSPD12/PIV/default.aspx Contractors who are unable to access the hyperlink above shall contact the Contracting Officer’s Representative (COR) for assistance.

Contractor employees who do not have a PIV card will need to be escorted at all times by a government employee while at a USCIS facility and will not be allowed access to USCIS IT systems.

Page 3 of 8 Security Clause 5 w/IT http://www.dhs.gov/homeland-security-presidential-directive-12 http://ecn.uscis.dhs.gov/team/mgmt/Offices/osi/FSD/HSPD12/PIV/default.aspx

A contractor employee required to have a PIV card shall:

• Properly display the PIV card above the waist and below the neck with the photo facing out so that it is visible at all times while in a USCIS facility

• Keep their PIV card current

• Properly store the PIV card while not in use to prevent against loss or theft http://ecn.uscis.dhs.gov/team/mgmt/Offices/osi/FSD/HSPD12/SIR/default.aspx

OSI PSD must be notified of all terminations/ resignations within five days of occurrence. The Contractor will return any expired USCIS issued identification cards and HSPD-12 card, or those of terminated employees to the COR. If an identification card or HSPD-12 card is not available to be returned, a report must be submitted to the COR, referencing the card number, name of individual to whom issued, the last known location and disposition of the card.

SECURITY MANAGEMENT

The Contractor shall appoint a senior official to act as the Corporate Security Officer. The individual will interface with OSI through the COR on all security matters, to include physical, personnel, and protection of all Government information and data accessed by the Contractor.

The COR and OSI shall have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements under this contract. Should the COR determine that the Contractor is not complying with the security requirements of this contract the Contractor will be informed in writing by the Contracting Officer of the proper action to be taken in order to effect compliance with such requirements.

The Contractor shall be responsible for all damage or injuries resulting from the acts or omissions of their employees and/or any subcontractor(s) and their employees to include financial responsibility.

SECURITY PROGRAM BACKGROUND

The DHS has established a department wide IT security program based on the following Executive Orders (EO), public laws, and national policy:

• Public Law 107-296, Homeland Security Act of 2002.

• Federal Information Security Management Act (FISMA) of 2002, November 25, 2002.

• Public Law 104-106, Clinger-Cohen Act of 1996 [formerly, Information Technology

Management Reform Act (ITMRA)], February 10, 1996.

• Privacy Act of 1974, As Amended. 5 United States Code (U.S.C.) 552a, Public Law 93-579, Washington, D.C., July 14, 1987.

• Executive Order 12829, National Industrial Security Program, January 6, 1993.

• Executive Order 12958, Classified National Security Information, as amended.

• Executive Order 12968, Access to Classified Information, August 2, 1995.

• Executive Order 13231, Critical Infrastructure Protection in the Information Age, October

16, 2001

• National Industrial Security Program Operating Manual (NISPOM), February 2001.

• DHS Sensitive Systems Policy Publication 4300A v2.1, July 26, 2004

Page 4 of 8 Security Clause 5 w/IT http://ecn.uscis.dhs.gov/team/mgmt/Offices/osi/FSD/HSPD12/SIR/default.aspx

• DHS National Security Systems Policy Publication 4300B v2.1, July 26, 2004

• Homeland Security Presidential Directive 7, Critical Infrastructure Identification, Prioritization, and Protection, December 17, 2003.

• Office of Management and Budget (OMB) Circular A-130, Management of Federal

• Information Resources.

• National Security Directive (NSD) 42, National Policy for the Security of National Security

Telecommunications and Information Systems (U), July 5, 1990, CONFIDENTIAL.

• 5 Code of Federal Regulations (CFR) §2635, Office of Government Ethics, Standards of

Ethical Conduct for Employees of the Executive Branch.

• DHS SCG OS-002 (IT), National Security IT Systems Certification & Accreditation, March

2004.

• Department of State 12 Foreign Affairs Manual (FAM) 600, Information Security

• Technology, June 22, 2000.

• Department of State 12 FAM 500, Information Security, October 1, 1999.

• Executive Order 12472, Assignment of National Security and Emergency Preparedness

Telecommunications Functions, dated April 3, 1984.

• Presidential Decision Directive 67, Enduring Constitutional Government and Continuity of

Government Operations, dated October 21, 1998.

• FEMA Federal Preparedness Circular 65, Federal Executive Branch Continuity of

Operations (COOP), dated July 26, 1999.

• FEMA Federal Preparedness Circular 66, Test, Training and Exercise (TT&E) for Continuity of Operations (COOP), dated April 30, 2001.

• FEMA Federal Preparedness Circular 67, Acquisition of Alternate Facilities for Continuity of

Operations, dated April 30, 2001.

• Title 36 Code of Federal Regulations 1236, Management of Vital Records, revised as of July

1, 2000.

• National Institute of Standards and Technology (NIST) Special Publications for computer security and FISMA compliance.

GENERAL

Due to the sensitive nature of USCIS information, the contractor is required to develop and maintain a comprehensive Computer and Telecommunications Security Program to address the integrity, confidentiality, and availability of sensitive but unclassified (SBU) information during collection, storage, transmission, and disposal. The contractor’s security program shall adhere to the requirements set forth in the DHS Management Directive 4300 IT Systems Security Pub Volume 1 Part A and DHS Management Directive 4300 IT Systems Security Pub Volume I Part B. This shall include conformance with the DHS Sensitive Systems Handbook, DHS Management Directive 11042 Safeguarding Sensitive but Unclassified (For Official Use Only) Information and other DHS or USCIS guidelines and directives regarding information security requirements. The contractor shall establish a working relationship with the USCIS IT Security Office, headed by the Information Systems Security Program Manager (ISSM).

IT SYSTEMS SECURITY

In accordance with DHS Management Directive 4300.1 “Information Technology Systems Security”, USCIS Contractors shall ensure that all employees with access to USCIS IT Systems are in compliance with the requirement of this Management Directive. Specifically, all contractor

Page 5 of 8 Security Clause 5 w/IT employees with access to USCIS IT Systems meet the requirement for successfully completing the annual “Computer Security Awareness Training (CSAT).” All contractor employees are required to complete the training within 60-days from the date of entry on duty (EOD) and are required to complete the training yearly thereafter.

CSAT can be accessed at the following: http://otcd.uscis.dhs.gov/EDvantage.Default.asp or via remote access from a CD which can be obtained by contacting uscisitsecurity@dhs.gov.

IT SECURITY IN THE SYSTEMS DEVELOPMENT LIFE CYCLE (SDLC)

The USCIS SDLC Manual documents all system activities required for the development, operation, and disposition of IT security systems. Required systems analysis, deliverables, and security activities are identified in the SDLC manual by lifecycle phase. The contractor shall assist the appropriate USCIS ISSO with development and completion of all SDLC activities and deliverables contained in the SDLC. The SDLC is supplemented with information from DHS and USCIS Policies and procedures as well as the National Institute of Standards Special Procedures related to computer security and FISMA compliance. These activities include development of the following documents:

• Sensitive System Security Plan (SSSP): This is the primary reference that describes system sensitivity, criticality, security controls, policies, and procedures. The SSSP shall be based upon the completion of the DHS FIPS 199 workbook to categorize the system of application and completion of the RMS Questionnaire. The SSSP shall be completed as part of the System or Release Definition Process in the SDLC and shall not be waived or tailored.

• Privacy Impact Assessment (PIA) and System of Records Notification (SORN). For each new development activity, each incremental system update, or system recertification, a PIA and SORN shall be evaluated. If the system (or modification) triggers a PIA the contractor shall support the development of PIA and SORN as required. The Privacy Act of 1974 requires the PIA and shall be part of the SDLC process performed at either System or Release Definition.

• Contingency Plan (CP): This plan describes the steps to be taken to ensure that an automated system or facility can be recovered from service disruptions in the event of emergencies and/or disasters. The Contractor shall support annual contingency plan testing and shall provide a Contingency Plan Test Results Report.

• Security Test and Evaluation (ST&E): This document evaluates each security control and countermeasure to verify operation in the manner intended. Test parameters are established based on results of the RA. An ST&E shall be conducted for each Major Application and each General Support System as part of the certification process. The Contractor shall support this process.

• Risk Assessment (RA): This document identifies threats and vulnerabilities, assesses the impacts of the threats, evaluates in-place countermeasures, and identifies additional countermeasures necessary to ensure an acceptable level of security. The RA shall be completed after completing the NIST 800-53 evaluation, Contingency Plan Testing, and the ST&E. Identified weakness shall be documented in a Plan of Action and Milestone (POA&M) in the USCIS Trusted Agent FISMA (TAF) tool. Each POA&M entry shall identify the cost of mitigating the weakness and the schedule for mitigating the weakness, as well as a POC for the mitigation efforts.

• Certification and Accreditation (C&A): This program establishes the extent to which a particular design and implementation of an automated system and the facilities housing that system meet a specified set of security requirements, based on the RA of security features

Page 6 of 8 Security Clause 5 w/IT http://otcd.uscis.dhs.gov/EDvantage.Default.asp mailto:uscisitsecurity@dhs.gov and other technical requirements (certification), and the management authorization and approval of a system to process sensitive but unclassified information (accreditation). As appropriate the Contractor shall be granted access to the USCIS TAF and Risk Management System (RMS) tools to support C&A and its annual assessment requirements. Annual assessment activities shall include completion of the NIST 800-26 Self-Assessment in TAF, annual review of user accounts, and annual review of the FIPS categorization. C&A status shall be reviewed for each incremental system update and a new full C&A process completed when a major system revision is anticipated.

SECURITY ASSURANCES

DHS Management Directives 4300 requires compliance with standards set forth by NIST, for evaluating computer systems used for processing SBU information. The Contractor shall ensure that requirements are allocated in the functional requirements and system design documents to security requirements are based on the DHS policy, NIST standards and applicable legislation and regulatory requirements. Systems shall offer the following visible security features:

• User Identification and Authentication (I&A) – I&A is the process of telling a system the identity of a subject (for example, a user) (I) and providing that the subject is who it claims to be (A). Systems shall be designed so that the identity of each user shall be established prior to authorizing system access, each system user shall have his/her own user ID and password, and each user is authenticated before access is permitted. All system and database administrative users shall have strong authentication, with passwords that shall conform to established DHS standards. All USCIS Identification and Authentication shall be done using the Password Issuance Control System (PICS) or its successor. Under no circumstances will Identification and Authentication be performed by other than the USCIS standard system in use at the time of a systems development.

• Discretionary Access Control (DAC) – DAC is a DHS access policy that restricts access to system objects (for example, files, directories, devices) based on the identity of the users and/or groups to which they belong. All system files shall be protected by a secondary access control measure.

• Object Reuse – Object Reuse is the reassignment to a subject (for example, user) of a medium that previously contained an object (for example, file). Systems that use memory to temporarily store user I&A information and any other SBU information shall be cleared before reallocation.

• Audit – DHS systems shall provide facilities for transaction auditing, which is the examination of a set of chronological records that provide evidence of system and user activity. Evidence of active review of audit logs shall be provided to the USCIS IT Security Office on a monthly basis, identifying all security findings including failed log in attempts, attempts to access restricted information, and password change activity.

• Banner Pages – DHS systems shall provide appropriate security banners at start up identifying the system or application as being a Government asset and subject to government laws and regulations. This requirement does not apply to public facing internet pages, but shall apply to intranet applications.

Page 7 of 8 Security Clause 5 w/IT

DATA SECURITY

SBU systems shall be protected from unauthorized access, modification, and denial of service. The Contractor shall ensure that all aspects of data security requirements (i.e., confidentiality, integrity, and availability) are included in the functional requirements and system design, and ensure that they meet the minimum requirements as set forth in the DHS Sensitive Systems Handbook and USCIS policies and procedures. These requirements include:

• Integrity – The computer systems used for processing SBU shall have data integrity controls to ensure that data is not modified (intentionally or unintentionally) or repudiated by either the sender or the receiver of the information. A risk analysis and vulnerability assessment shall be performed to determine what type of data integrity controls (e.g., cyclical redundancy checks, message authentication codes, security hash functions, and digital signatures, etc.) shall be used.

• Confidentiality – Controls shall be included to ensure that SBU information collected, stored, and transmitted by the system is protected against compromise. A risk analysis and vulnerability assessment shall be performed to determine if threats to the SBU exist. If it exists, data encryption shall be used to mitigate such threats.

• Availability – Controls shall be included to ensure that the system is continuously working and all services are fully available within a timeframe commensurate with the availability needs of the user community and the criticality of the information processed.

• Data Labeling. – The contractor shall ensure that documents and media are labeled consistent with the DHS Sensitive Systems Handbook.

Page 8 of 8 Security Clause 5 w/IT

File details come from the government source that posted it. Updated .