Attch 7_CUI Requirements Table 1.docx

DOCX document 17 KB Posted

Attached to
Philadelphia, PA S&RTS Federal contract opportunity
Solicitation number
HTC711-21-R-R003
Issued by
Department of Defense United States Transportation Command

About this file

This document contains an attachment with modified requirements for handling Controlled Unclassified Information (CUI) for a federal contract opportunity. The attachment outlines 16 modified National Institute of Standards and Technology (NIST) Special Publication 800-171 requirements for protecting Department of Defense (DoD) information related to Solicitation Number HTC711-21-R-R003 for Stevedoring and Related Terminal Services in Philadelphia, PA issued by the Department of Defense United States Transportation Command. The modified requirements address limiting information flow, providing privacy and security notices, encrypting information on mobile devices, controlling publicly accessible information, sanitizing equipment for off-site maintenance, protecting and limiting access to media containing information, screening personnel, and protecting information during personnel actions and at alternate work sites.

View the file

Other files for this federal contract opportunity

Other files attached to Philadelphia, PA S&RTS, newest first.
File Type Posted
HTC711-21-R-R003_0004.pdf PDF
Atch 2_SOR_ Philadelphia_12-21-20.xlsx XLSX spreadsheet
RFP_HTC711-21-R-R003_0003.pdf PDF
RFP_HTC711-21-R-R003_0002.pdf PDF
Atch 3_SRTS General Compliance Tool_Rev 01_2020.12-10.xlsx XLSX spreadsheet
Atch 1_Performance Work Statement_Rev 01_2020.12.10.pdf PDF
RFP_HTC711-21-R-R003_0001.pdf PDF
Atch 2_SOR Philadelphia_Rev 01_2020.12.09.xlsx XLSX spreadsheet
Attch 8_Cyber Security_NIST.SP.800-171_Template.xlsx XLSX spreadsheet
Atch 3_SRTS General Compliance Tool.xlsx XLSX spreadsheet
Atch 4_ Tech Worksheet Philadelphia (v.2020.11.04).docx DOCX document
Atch 5_WDOL_SF98_21-R-R003_2020.09.22.pdf PDF
Atch 6_Contractor Plan for Continuation of Essential Contractor Services.docx DOCX document
HTC711-21-R-R003_Philadelphia.pdf PDF
Atch 2_SOR Philadelphia.xlsx XLSX spreadsheet
Atch 1_Performance Work Statement.pdf PDF
Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 7

Table 1 – Modified NIST SP 800-171 Requirements

Req #
NIST SP 800-171 Requirement
USTRANSCOM Modified Requirement
3.1.3
Control the flow of CUI in accordance with approved authorizations.
Limit the flow of DoD information to organizations or individuals necessary for the performance of the operationally critical requirements of this contract.
3.1.9
Provide privacy and security notices consistent with applicable CUI rules.
Provide privacy and security notices consistent with U.S. Government and/or local governmental regulations.
3.1.19
Encrypt CUI on mobile devices and mobile computing platforms.
Provide adequate technical protections on mobile devices and computing platforms that process and/or store contractual information.
3.1.22
Control CUI posted or processed on publicly accessible systems.
Control DoD information posted or processed on publically accessible systems.
3.7.3
Ensure equipment removed for off-site maintenance is sanitized of any CUI.
Ensure equipment removed for off-site maintenance is sanitized of DoD information.
3.8.1
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
Protect (i.e., physically control and securely store) system media containing DoD information, both paper and digital.
3.8.2
Limit access to CUI on system media to authorized users.
Limit access to DoD information on system media to authorized users.
3.8.3
Sanitize or destroy system media containing CUI before disposal or release for reuse.
Sanitize or destroy system media containing DoD information before disposal or release for reuse.
3.8.4
Mark media with necessary CUI markings and distribution limitations.
Mark media with privacy and security notices consistent with U.S. Government and/or local government regulations.
3.8.5
Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.
Control access to and maintain accountability for media containing DoD information.
3.8.9
Protect the confidentiality of backup CUI at storage locations.
Provide information backup procedures (frequency, timeframe for storage, etc.) for DoD data located on contractor systems. Protect the confidentiality of backup materials containing DoD information.
3.9.1
Screen individuals prior to authorizing access to organizational systems containing CUI.
Screen individuals prior to authorizing access to organizational systems containing DoD information.
3.9.2
Ensure that CUI and organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
Ensure that DoD information and organizational systems containing DoD information are protected during and after personnel actions such as terminations and transfers.
3.10.6
Enforce safeguarding measures for CUI at alternate work sites (e.g., telework sites).
Enforce safeguarding measures for DoD Information at alternate work sites (e.g., telework sites).
3.11.1
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of DoD information.
3.13.8
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
Implement cryptographic mechanisms to prevent unauthorized disclosure of DoD information during transmission when possible unless otherwise protected by alternate physical safeguards.
3.13.11
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
Employ FIPS-validated cryptography when used to protect the confidentiality of DoD information within the organization’s systems and when possible when transmitting to external entities.
3.13.16
Protect the confidentiality of CUI at rest.
Protect the confidentiality of DoD information at rest.

File details come from the government source that posted it. Updated .