Attachment_7_Software_Vendor_Integrity_Statement_Guidelines_Website.docx
DOCX document 15 KB Posted
- Attached to
- Advanced Joint Terminal Attack Controller Training System (AAJTS) Federal contract opportunity
- Solicitation number
- ID07170051
- Issued by
- GSA Federal Acquisition Service
About this file
Software Vendor Integrity Statement Guidelines Website
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SECTION J
Attachment 7 Software Vendor Integrity Statement Guidelines: Website
DESCRIPTION
The Vendor Integrity Statement shall be a written and signed Contractor certification that assures that the web site development was conducted in accordance with DoD and Air Force web administration, policies, and procedures, has no elements that might be detrimental to the secure operation of the resource operating system. Elements detrimental to the secure operation include:
| a. | Trojans, worms, logic bombs, Malicious code, and other computer viruses |
| b. | Backdoors, Ad-ware, Spy-ware, or web bugs that have the ability to track user behavior |
| c. | Web services or code that permits functions and operations that are beyond the actual intent of the web site |
| d. | Software will not run with operating system configured securely |
| e. | Unpatched vulnerabilities |
| f. | Unauthorized release of sensitive/“For Official Use Only” data to the public |
| g. | Unauthorized access to sensitive/“For Official Use Only” data |
| h. | Weak passwords |
| i. | Hot fixes (patches) are not installed |
CONTENT AND FORMAT
The Vendor Integrity Statement for Web Site shall consist of the following certification, dated and signed by an authorized representative of the Contractor, on company letterhead. A sample follows:
Software Vendor Integrity Statement: Website Sample
TO: Add USAF GPO RE: Vendor Integrity Statement for Web Site developed under Contract XX-X-XXXX
I certify that the xxxx Web Site has been developed in accordance with Office of the Assistant Secretary of Defense (OASD) web policies and is in good working order. There are no elements that might be detrimental to the secure operation of the web site and server operating system. The software runs with the operating system configured according to DODI 8500.01, Cybersecurity, paragraph 9.b.11.
Signed, Company Representative
Attachment ( )
File details come from the government source that posted it.