II_2_FISMA_ Contract_Language_IT_SCaaS_Final.pdf

PDF 269 KB Posted

Attached to
Pilot IRS EDCMO SCaaS Request for Proposal Federal contract opportunity
Solicitation number
2032H8-21-R-124899
Issued by
Department of the Treasury Internal Revenue Service

About this file

This document outlines standard information security contract language for federal contractors providing information technology services to the Internal Revenue Service. Key details include requirements for NIST and FISMA compliance, protecting sensitive personally identifiable information, handling security incidents, maintaining data and systems within the United States, complying with IRS policies on access controls, auditing, encryption and more. Contractors must meet requirements for accreditation, continuous monitoring, backups and disaster recovery. The document establishes terms for jurisdiction over IRS data, disposition of data, and termination of contracts.

View the file

Other files for this federal contract opportunity

Other files attached to Pilot IRS EDCMO SCaaS Request for Proposal, newest first.
File Type Posted
II_2_Pilot_IRS_SCaaS_Demonstrated_Report_Data.pdf PDF
II_2_Clauses_Provision_Attachment_SCaaS_FINAL.pdf PDF
II_1_Pilot_IRS_Final_RFP.pdf PDF
II_2_Attachment_2032H8-21-R-124899_Minimum_Technical_Digitization_Specifications.pdf PDF
II_2_QASP_SCaaS_Final.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FISMA Contract Language (IT Systems / Applications or Services)

Revised February 2021

INFORMATION SECURITY / FEDERAL INFORMATION SECURITY

MODERNIZATION ACT (FISMA)

Pursuant to the Federal Information Security Modernization Act (FISMA), Title III of the E-Government Act of 2014 (Pub. L. 113–283), the contractor shall provide minimum security controls required to protect Federal information and information systems in accordance with NIST Special Publication 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. The contractor shall provide a risk-based process for selecting the security controls necessary to satisfy the minimum-security requirements in accordance with Federal Information Processing Standard (FIPS) 199. The term information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentially, integrity and availability. An information system is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. Information resources include information and related resources, such as personnel, equipment, funds, and information technology.

The contractor shall provide information security protections commensurate with the risk and magnitude of the harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information collected or maintained by or on behalf of the agency;

or information systems used or operated by an agency or by a contractor or subcontractor of an agency. This applies to individuals and organizations having contractual arrangements with the IRS, including employees, contractors, vendors, and outsourcing providers, which use or operate information technology systems containing IRS data.

IRS information or information system with a FIPS 199 security categorization impact level of low, moderate or high, and those systems identified by the As Built Architecture (ABA) and agency FISMA Master Inventory.

The potential impact values for confidentiality, integrity, and availability may not always be the same for a particular information system; the high-water mark concept must be used to determine the overall impact level of the information system. Thus, a low-impact system is an information system in which all three of the security objectives are low. A moderate-impact system is an information system in which at least one of the security objectives is moderate and no security objective is greater than moderate. And finally, a high-impact system is an information system in which at least one security objective is high. The determination of information system impact levels must be accomplished prior to the consideration of minimum-security requirements and the selection of appropriate security controls for those information systems.

FedRAMP security requirements shall be applied to all IRS cloud services and products and shall be implemented and complied with as part of a competed FedRAMP authorization.

The enforcement of FedRAMP requirements shall be done through Service Level Agreements (SLA)/Contracts. IRS shall utilize aggregated and individual security categorization information when assessing interagency and CSP connections with different FIPS 199 Category Impact levels.

(e.g., High Impact system connecting to Moderate Impact system etc.)

THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)

GUIDANCE FOR INFORMATION SECURITY

The contractor shall follow Information Security guidance established by the National Institute of Standards and Technology (NIST). The contractor shall establish the minimum-security controls identified in NIST Special Publication 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations for FISMA compliance. The contractor shall follow the best practices and guidance established by NIST special publication 800 Series and Federal Information Processing Standards (FIPS) for computer security. The IRS may determine such applicable Information Technology (IT) Security standards and policies.

Office of the President Management and Budget (OMB) Policies for Security of Federal Automated Information Resources The contractor shall implement protections for personally identifiable information being accessed remotely or transported outside of the agency’s secured, physical perimeter, and/or stored offsite.

In those instances where personally identifiable information is transported to a remote site of the contractor, the contractor shall implement NIST Special Publication 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations security controls and IRS specific security procedures to ensure that information is transported in encrypted form. The contractor shall comply with OMB Circular Policy M-17-12: Preparing for and Responding to a Breach of Personally Identifiable Information.

TREASURY / IRS POLICIES FOR INFORMATION TECHNOLOGY (IT) SECURITY

The contractor shall comply with FedRAMP Framework, Department of Treasury Directive TD P 85- 01, Internal Revenue Manual (IRM) 10.8.1, Information Technology (IT) Security Policy and Guidance and Internal Revenue Manual (IRM) 10.8.24, Information Technology (IT) Security, Cloud Computing Security Policy. The contractor shall comply with IRS IRMs when developing or administering IRS information and information systems.

The contractor shall comply with the Taxpayer Browsing Protection Act of 1997 - Unauthorized Access (UNAX), the Act amends the Internal Revenue Code 6103 of 1986 to prevent the unauthorized inspection of taxpayer returns or tax return information.

The contractor/contractor personnel are bound by the Records Management by Federal Agencies (44 U.S.C. Chapter 31) regarding the care and retention of federal records.

FEDERAL INFORMATION PROCESSING STANDARD (FIPS)-201-2

Homeland Security Presidential Directive-12 [HSPD-12], August 27, 2004, established the requirements for a common identification standard for identity credentials issued by Federal departments and agencies to Federal employees and contractors (including contractor employees) for gaining physical access to federally controlled facilities and logical access to federally controlled information systems. HSPD-12 directs the Department of Commerce to develop a FIPS publication to define such a common identity credential. In accordance with HSPD-12, this Standard defines the technical requirements for the identity credential that:

(a) is issued based on sound criteria for verifying an individual employee’s identity;

(b) is strongly resistant to identity fraud, tampering, counterfeiting, and terrorist exploitation;

(c) can be rapidly authenticated electronically; and

(d) is issued only by providers whose reliability has been established by an official accreditation process.

The standard for a Personal Identity Verification (PIV) system is based on secure and reliable forms of identity credentials issued by the Federal government to its contractors. These credentials are intended to authenticate individuals who require access to federally controlled facilities, information systems, and applications. A PIV Card must be personalized with identity information for the individual to whom the card is issued, in order to perform identity verification both by humans and automated systems. Humans can use the physical card for visual comparisons, whereas automated systems can use the electronically stored data on the card to conduct automated identity verification

IRS will determine the level of security and authentication mechanisms appropriate for their applications and will employ only information technology products on the FIPS 201-approved products list for PIV capability implementation within organization information systems.

CSPs must review SP 800-63-3, use its decision trees to obtain an overview of all digital identity requirements, and read the applicable 800-63 volumes to determine specific requirements that apply to their cloud offerings.

SECURITY AUTHORIZATION / CERTIFICATION AND ACCREDITATION PROCESS

CSP/Contractor systems that collect, maintain, contain or use agency information or an information system on behalf of the agency (a General Support System (GSS), with a FIPS 199 security categorization) must ensure annual reviews and continued security certification and accreditation. Some of the key elements of this IT risk and impact assessment process are project security deliverables such as the System Security Plan (SSP), Information System Contingency Plan (ISCP), Interconnection Security Agreement (ISA), Security Risk Assessment (SRAs), Data Impact Assessments (DIAs), Risk Analyses, Security Threat Analyses, Audit Plan, Source Code Review, Security Control Assessment (SCA), and/or Event-Driven Security Control Assessment (ED-SCA). All systems that complete this process will, at a minimum, meet FedRAMP, Treasury and IRS requirements.

INFORMATION SYSTEMS AND INFORMATION SECURITY CONTROLS FOR

CONTRACTING ACTIONS SUBJECT TO IRS PUBLICATION 4812 REVISION 10-201

(Note: Publication 4812 is a layperson's guide to NIST SP 800-53, Rev 4 when access to IRS information or information systems under contracts for services on behalf of the IRS is outside of IRS controlled facilities or the direct control of the Service as opposed to Internal Revenue Manual

10.8.1 - Information Technology (IT) Security, Policy and Guidance, which applies when contractors are accessing IRS information and information systems at Government controlled facilities.)

https://www.irs.gov/irm/part10/irm_10-008-001.html https://www.irs.gov/irm/part10/irm_10-008-001.html

In performance of this contract, the contractor agrees to comply with the following requirements and assumes responsibility for compliance by its employees and subcontractors (and their employees):

(a) General. The contractor shall ensure IRS information and information systems (those of the IRS and/or the contractor, as appropriate) are always protected. In order to do so, the contractor shall develop, implement, and maintain effective controls and methodologies in its business processes, physical environments, and human capital or personnel practices that meet or otherwise adhere to the security controls, requirements, and objectives described in applicable security control guidelines, and their respective contracts.

(b) The contractor will be required to input data into a system, to be defined by the IRS, to describe the security controls being used to protect information.

(c) Publication (PUB) 4812 Applicability. This contracting action is subject to Publication 4812 – Contractor Security Controls. PUB 4812 is available at:

http://www.irs.gov/pub/irs-procure/Publication-4812---Contractor--Security- Controls.pdf.

CONTRACTOR (AND SUBCONTRACTOR) SITE AND INFORMATION

TECHNOLOGY (SOFTWARE, HARDWARE AND DATA) LOCATION

The CSP/Contractor headquarters, infrastructure, servers (including back-up servers) and data must be physically located in the United States (or U.S. territories).

The infrastructure associated with services outsourced by the CSP/Contractor must located in the United States (or U.S. territories).

The current version and all subsequent versions of the software implemented by the CSP/Contractor must be escrowed in the United States (or U.S. territories) at the CSP’s expense to protect the code in the event the CSP declares bankruptcy.

Data stored outside the United States cannot be protected under the Privacy Act of 1974 or safe harbor framework and may allow for certain local or foreign law enforcement authorities to search IRS data pursuant to a court order, subpoena, or informal request outside the control of the IRS.

The Clarifying Lawful Overseas Use of Data ("CLOUD") Act enacted into law on March 23, 2018 provides that U.S. law-enforcement orders issued under the Stored Communications Act (SCA) may reach certain data located in other countries.

http://www.irs.gov/pub/irs-procure/Publication-4812---Contractor--Security-Controls.pdf http://www.irs.gov/pub/irs-procure/Publication-4812---Contractor--Security-Controls.pdf

Recognizing the limits of existing law enforcement tools and privacy laws to govern requests for electronic evidence in the age of cloud computing, the CLOUD Act establishes processes and procedures for law enforcement requests for data in other countries.

Although the Act expands the geographic scope of the SCA, it does not change who is subject to SCA orders or what type of data is subject to U.S. law-enforcement requests under the SCA.

The CLOUD Act lays out the circumstances under which a "provider of electronic communication service or remote computing service" must comply with a U.S. law-enforcement order to disclose data within its "possession, custody, or control," even when that data is "located … outside the United States."

ALTERNATE STORAGE

The CSP/Contractor shall establish an alternate storage site including necessary agreements to permit the storage and retrieval of information system backup information. The alternate storage site shall be geographically separated within the United States (or U.S. territories) from the contractor site to enable recovery of operations. The alternate storage site is separated from the primary storage site so as not to be susceptible to the same hazards and identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outlines explicit mitigation actions. All backup data that contains SBU information shall be encrypted.

The alternate storage site shall provide information security safeguards equivalent to that of the primary site.

BACKUPS

Backups must be provided as part of the CSP service offering.

All backup data that contains SBU information shall be encrypted.

(1) The IRS or CSP/Contractor shall conduct backups for information contained in the information system at the following frequency:

• User-level: daily incremental; weekly full

• System-level: daily incremental; weekly full

• Information system configuration; daily incremental; weekly full

Note: The defined backup frequencies are above IRM 10.8.1 baseline and assigned by FedRAMP.

(2) The CSP/Contractor shall maintain:

• At least three backup copies of user-level information (at least one of which is available online) or provides an equivalent alternative.

• At least three backup copies of system-level information (at least one of which is available online) or provides an equivalent alternative.

• At least three backup copies of information system documentation including security information (at least one of which is available online) or provides an equivalent alternative.

Note: This requirement is defined by FedRAMP.

(3) The IRS or CSP/Contractor shall determine what elements of the cloud environment require the Information System Backup control.

(4) The CSP/Contractor shall determine how Information System Backup is going to be verified and the appropriate periodicity of the check.

(5) Backup copies of the operating system (i.e., deployed operating system with agency defined configurations and controls) and other critical information system software, as well as copies of the information system inventory (including hardware, software, and firmware components) shall be stored in a separate facility or in a fire-rated container that is not collocated with the operational system.

Note: This requirement is assigned to Moderate and High impact systems by FedRAMP.

DATA LOSS PREVENTION (DLP) SOFTWARE

The CSP/Contractor shall implement data loss prevention (DLP) software to assure existing software will operate effectively in the cloud.

The CSP/Contractor shall be responsible for all patching and vulnerability management (PVM) of software and other systems’ components supporting services provided under this agreement so as to prevent proactively the exploitation of IT vulnerabilities that may exist within the CSP/Contractor operating environment. Such patching and vulnerability management shall meet the requirements and recommendations of NIST SP 800-40, as amended, with special emphasis on assuring that the vendor’s PVM systems and programs apply standardized configurations with automated continuous monitoring of the same to assess and mitigate risks associated with known and unknown IT vulnerabilities in the CSP/Contractor operating environment.

Furthermore, the CSP/Contractor shall apply standardized and automated acceptable versioning control systems that use a centralized model to capture, store, and authorize all software development control functions on a shared device that is accessible to all developers authorized to revise software supporting the services provided under this agreement. Such versioning control systems shall be configured and maintained to make sure all software products deployed in the CSP/Contractor operating environment and serving the IRS are compatible with existing systems and architecture of the IRS.

USE OF OUTSOURCED / CONTRACTOR FACILITIES TO PROCESS IRS SBU DATA

The infrastructure associated with services outsourced by the CSP/contractor must located in the United States (or U.S. territories).

If IRS products/applications/data/services/solutions are hosted and/or managed by a CSP (outside the IRS network boundaries/facilities (e.g., outsourced)) then all such products/applications/data/services/solutions shall go through (and maintain) the Federal Risk and Authorization Management Program (FedRAMP) certification, and meet all of the IRS unique business/legal requirements (including applicable PUB 4812 requirements, etc.).

(Note: FedRAMP is mandatory for all IRS cloud deployments and cloud service models at the Federal Information Processing Standards (FIPS) 199 Low, Moderate and High impact levels.

FedRAMP does not apply for internal housed IRS systems that are operated for IRS use only.

This service model would be considered an On-Site-Private Cloud.)

Special contract language shall be included in all types of Cloud Service Provider (CSP) contracts/non-disclosure agreements/Service Level agreements to address all potential CSP risks (e.g., Data Governance, Data Protection, Data Location, Data Availability, Data Confidentiality, Data Integrity, Data Access, Data Backup, Data Encryption, Data Breach Notification, Contract Exit Conditions, Contract Termination Conditions, Data Disposal, Data Retention, User/Device/Service AAA services (e.g., Authentication, Authorization, Audit Logging, Background Checks etc.). The Vendor shall pay special attention to the logical and physical separation of IRS data, applications and communications to maintain security. Vendors are encouraged to manage any cloud environments containing IRS data with only other Federal or State and local Government customers operating at the same security level. The IRS shall control and maintain the centralized/authoritative control (in-house) of ALL the IRS authorized Users/Devices/Services Authentication, Authorization, and Auditing (AAA) functions, even if a particular IRS application/data/service/solution is hosted in a third-party cloud environment.

Outsourced operations shall report monthly for FISMA and Treasury submission. This includes all systems in the following environments: production, disaster recovery, training, development, and testing.

ENCRYPTION

(1) The IRS or CSP shall ensure that the information system implements FIPS-validated or National Security Agency (NSA)-approved cryptography in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

IRS sensitive data (e.g., Sensitive But Unclassified (SBU), Personally Identifiable Information (PII) that is processed, stored, or transmitted by an information system outside of IRS facilities or IRS IT information system shall be protected with FIPS 140-2 or later validated cryptographic modules with approved modes of operation. The vendor shall provide a system that implements (encryption standard) that provides for origin authentication, data integrity, and signer non-repudiation. Consider AU-11 audit Records retention

A list of NIST validated modules is available at the following link:

http://csrc.nist.gov/groups/STM/cmvp/validation.html.

The CSP/Contractor shall ensure all SBU information is protected at rest, in transit, and in exchanges (i.e., internal and external communications). Limit access to SBU information to http://www.gsa.gov/portal/category/102371?utm_source=OCM&amp%3Bamp%3Butm_medium=print-radio&amp%3Bamp%3Butm_term=HP_13_SpecialTopics_fedramp&amp%3Bamp%3Butm_campaign=shortcuts http://mits.web.irs.gov/cybersecurity/Divisions/SRM/Compliance/InfraReviews.htm http://csrc.nist.gov/groups/STM/cmvp/validation.html authorized personnel (those favorably adjudicated and trained) with a need to know and ensure internal and external exchanges are conducted only through secure or encrypted channels. The CSP/Contractor shall employ encryption concepts and approved standards to ensure the confidentiality, integrity, and availability of the SBU information, consistent with the security controls under Publication 4812 and any security requirements specified elsewhere in the contract.

Contractual liability to the government only exists with the prime contractor.

The CSP/contractor shall retain operational configuration and control of data repository systems used to process and store government data to include any or remote work. The CSP/contractor shall not subcontract the operational configuration and control of any government data.

IRS retains exclusive ownership over all its data; the CSP/Contractor acquires no rights or licenses through the agreement, including intellectual property rights or licenses, to use the IRS data for its own purposes; and that the CSP/Contractor does not acquire and may not claim any interest in the data due to security. If CSP/Contractor moves data, the IRS will not lose rights and access to conduct audits.

Intellectual property, including original works created using the cloud infrastructure, may be stored. IRS must ensure that the cloud provider contract respects the IRS’ right to any intellectual property or original works as far as possible without compromising the quality of service offered (e.g., backups may be a necessary part of offering a good service level).

CONTRACTOR SYSTEM REVIEW / SITE VISIT

In conjunction with the use of outsourced / Contractor facilities, the contractor shall be subject to at the option / discretion of the IRS, to periodically test and inspection (annually) and evaluate the effectiveness of information security controls and techniques. The assessment of information security controls may be performed by an agency independent auditor, security team or Inspector General, and shall include testing of management, operational, and technical controls, as indicated by the security plan, of every information system that maintain, collect, operate or use federal information on behalf of the agency. The agency and contractor shall document and maintain a remedial action plan, also known as a Plan of Action and Milestones (POA&M) to address any deficiencies identified during the test and evaluation. The contractor must cost-effectively reduce information security risks to an acceptable level within the scope, terms and conditions of the

CONTRACTOR SYSTEM OVERSIGHT/COMPLIANCE

(a) The Contractor, service providers, and third-party vendors must complete the IRS Security – Assessments (IT Security Product Questionnaire) and submit the assessments to the Contracting Officer and Cybersecurity for review and evaluation. This is a supplemental requirement and does not replace contract requirements under FISMA. The federal government has the authority to conduct site reviews for compliance validation. Full cooperation by Contractor and third-party providers is required for audits and forensics.

(b) The Contractor must support IRS in its efforts to assess and monitor the Contractor systems and infrastructure. The Contractor must provide logical and physical access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases upon request. The Contractor will be expected to perform automated scans and continuous monitoring activities which may include, but will not limited be to, authenticated and unauthenticated scans of networks, operating systems, applications, and databases and provide the results of the scans to the IRS Cybersecurity, or designate, or allow IRS (or its designate) to run the scans directly.

(c) All Contractor systems must participate in Information Security Continuous Monitoring (ISCM) and Reporting as defined in the IRS IT Policy.

(d) All Contractor systems must perform vulnerability scanning as defined by IRS IT Security Policy and provide scanning reports to the IRS Cybersecurity, or designate, on a monthly basis.

(e) All Contractor systems must participate in the implementation of automated security controls testing mechanisms and provide automated test results in Security Compliant Automation Protocol (SCAP) compliant data to the IRS Cybersecurity, or designate, on a monthly basis.

SAFEGUARDING / PROTECTING SENSITIVE PERSONALLY IDENTIFIABLE

INFORMATION (PII)

Sensitive PII is defined as any information that permits the identity of an individual to be directly or indirectly inferred, including any information that is linked or linkable to that individual, regardless of whether the individual is a U.S. citizen, legal permanent resident, or employee or contractor to the Department. Sensitive PII is Personally Identifiable Information, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.

Information Systems can be either electronic or manual. IRM 10.8.1 requires IRS sensitive information is to be handled and protected at the contractor's site, including any information stored, processed, or transmitted using the contractor's computer systems. Contractor personnel shall perform a background investigation and/or clearance required; receive security awareness and specialized IT security training required for contractor activities or facilities; and any facility physical security requirements.

IRS sensitive data (e.g., Sensitive But Unclassified (SBU), Personally Identifiable Information (PII) that is processed, stored, or transmitted by an information system outside of IRS facilities or IRS IT information system shall be protected with FIPS 140-2 or later validated cryptographic modules with approved modes of operation.

A list of NIST validated modules is available at the following link:

http://csrc.nist.gov/groups/STM/cmvp/validation.html.

(1) The CSP/Contractor shall ensure that individuals accessing an information system processing, storing, or transmitting information requiring special protection satisfy the personnel screening criteria.

(2) The organization shall:

http://csrc.nist.gov/groups/STM/cmvp/validation.html

Screen individuals prior to authorizing access to the information system; and Rescreen individuals according to FedRAMP Assignments: for national security clearances; a reinvestigation is required during the 5th year for top secret security clearance, the 10th year for secret security clearance, and 15th year for confidential security clearance. For moderate risk law enforcement and high impact public trust level, a reinvestigation is required during the 5th year.

There is no reinvestigation for other moderate risk positions or any low risk positions].

The CSP/Contractor shall ensure that data is used, only as identified, in the IRS contract and that the data will be used for nothing else to ensure the privacy of the individual.

The CSP/Contractor is responsible for maintaining an inventory of all PII provided to the contractor, generated by the contractor, or used by the contractor sufficient to enable notification to taxpayers, if disclosed. The inventory of PII must be updated semi-annually with a final inventory notification provided to the COR.

Most IRS information is categorized as Sensitive But Unclassified (SBU). This includes:

(a) Federal Tax Information (FTI)

(b) Personally Identifiable Information (PII)

(c) Protected Health Information (PHI)

(d) Certain procurement information

(e) System vulnerabilities

(f) Case selection methodologies

(g) Systems information

(h) Enforcement procedures

(i) Investigation information

(j) Proprietary processes or algorithms used in investigative work or tax processing

Note: Live data, which is defined as production data in use (production, testing, development), often contains SBU.

Various laws and regulations have addressed the need to protect sensitive information held by government agencies including the Federal Information Security Modernization Act (FISMA), the EGovernment Act of 2014, the Privacy Act of 1974, and OMB Circular A-130, Management of Federal Information Resources. FISMA requires agencies to have a security program and controls for systems to protect their sensitive information. Therefore, the contractor shall comply with OMB policies and Treasury / IRS specific policies, procedures or guidance to protect sensitive information.

CONTRACTOR RIGHTS TO ACCESS DATA

Access Control requirements shall be implemented as defined within Internal Revenue Manual (IRM) 10.8.1, Information Technology (IT) Security, Policy and Guidance and Publication 4812.

1) The CSP/Contractor shall not access, use, or disclose Government data unless specifically authorized by the terms of this contract or a task order issued hereunder. If authorized by the terms of this contract or a task order issued hereunder, any access to, or use or disclosure of, Government data shall only be for purposes specified in this contract or task order. CSP/Contractor shall ensure that each of its employees and representatives, and any others (e.g., subcontractor employees) performing duties hereunder, shall, prior to obtaining access to any Government data, sign a contract or task order specific nondisclosure agreement.

2) The CSP/Contractor shall use Government-related data only to manage the operational environment that supports the government data and for no other purpose unless otherwise permitted with the prior written approval of the Contracting Officer.

CSP/Contractor shall:

a. Be subject to background investigations at the risk level appropriate to the sensitivity of the position and sensitivity/classification of the data.

b. Not access sensitive IT systems until they have at least a favorably adjudicated National Agency Check (a component of the full background investigation).

c. Be responsible for protecting any Personally Identifiable Information (PII) that they have in their possession, whether it is paper-based or in electronic form.

d. Understand the provisions and applicable criminal penalties under Public Law 105-35, Taxpayer Browsing Protection Act, shall also apply to all contractors and contractor employees.

e. Comply with all executive, legislative and Department of Treasury and IRS security policies and procedures.

f. Minimize the threat of viruses by write-protecting removable media, routinely scanning files, systems and media for viruses and never circumventing anti-virus safeguards.

A breach of the obligations or restrictions may subject the CSP/Contractor to criminal, civil, administrative, and contractual actions in law and equity for penalties, damages, and any other appropriate remedies by any party adversely affected by the breach.

HANDLING INFORMATION SECURITY INCIDENTS

The IRS Computer Security Incident Response Capability (CSIRC) defines a security incident as: “any adverse event whereby some aspect of computer security could be threatened.

Adverse events may include the loss of data confidentiality, disruption of data or system integrity, disruption or denial of availability, loss of accountability, or damage to any part of the system.”

User Compromise, Disclosure of Taxpayer/Sensitive Data, Malicious Code (successful or unsuccessful), Denial of Service (DoS) (successful or unsuccessful), Website Defacement, Identity Theft, Misuse of Resources or Policy Violation, Loss or Theft of IT Equipment, IRM/LEM Non- Compliance, Unauthorized Access Attempt, Probe/Scan, and any other security incident that may threaten or damage any IRS or federal agency information or information system(s).

Contractors and their employees must be aware of their responsibilities under the law to safeguard PII and sensitive information, the procedures to follow when data is lost or compromised and the penalties for unauthorized disclosure of PII and sensitive information. Contractors should refer to Data Breach Information for IRS Contractors on irs.gov https://www.irs.gov/about-irs/procurement/data-breach-information-for-irs-contractors, Pub 4465-A, Protecting Federal Tax Information for Contractors, and Pub 4812, Contractor Security Controls, for information about a contractor’s responsibilities to protect Federal Tax Information (FTI) and incident/data breach response and reporting procedures.

It is critical to report an incident/data breach as soon as actionable information is available so a response/reaction can be initiated. Incident/data breach updates and any additional notifications to Treasury Inspector General for Tax Administration (TIGTA) and/or Local Law Enforcement can be completed after the initial report to the Office of Taxpayer Correspondence (OTC), Privacy, Governmental Liaison and Disclosure/Incident Management Office (PGLD/IM), or the Computer Security Incident Response Center (CSIRC) is submitted.

https://www.irs.gov/about-irs/procurement/data-breach-information-for-irs-contractors https://www.irs.gov/about-irs/procurement/data-breach-information-for-irs-contractors

All physical security incidents and/or threats should be reported to the SAMC within 30 minutes of incident discovery. SAMC operates 365 days a year, 24 hours a day, seven days a week. Incidents may be reported to the SAMC through any of the following methods:

Primary Method of Reporting: Website incident reporting link, https://tscc.enterprise.irs.gov/irc/

Alternate Reporting Methods:

Telephone: 202-317- 6124 or 1-866-216-4809 (toll free hotline) Fax: 202-317-6129 Email: samc@irs.gov The CSP/Contractor shall report security incident information according to U.S. Computer Emergency Response, Department of Treasury, IRS, and the FedRAMP Incident Communications procedures.

All incidents related to IRS processing, information or information systems shall be reported within one (1) hour to the CO, COR, and CSIRC. Contact the CSIRC through any of the following methods:

CSIRC Contacts: Telephone: 240.613.3606 E-mail to csirc@irs.gov

The CSP/Contractor shall be accountable for incident responsiveness, including providing specific time frames for restoration of secure services in the event of an incident.

The CSP/Contractor shall provide and maintain insurance, to include cybersecurity insurance, throughout the performance of this contract, as specified in the Schedule or elsewhere in the

Before commencing performance under this contract, the CSP/Contractor shall provide proof of insurance to the Agency. The CSP/Contractor shall resubmit the proof of insurance within 30 days of notification of any material change that occurs during the performance of the contract.

The CSP/Contractor shall insert the substance of this clause, including this paragraph (c), in subcontracts under this contract that require work with or in support of storage and retrieval of electronic/digital government data and shall require subcontractors to provide and maintain the insurance required in the Schedule or elsewhere in the contract. The CSP shall maintain a copy of all subcontractors’ proofs of required insurance and shall make copies available to the Contracting Officer upon request.

CONTRACTOR BOUNDARY PROTECTION

The CSP/Contractor shall ensure IRS data is not comingled with the data from other organizations.

The CSP/Contractor shall implement boundary protection mechanisms at servers, workstations, and mobile devices.

https://tscc.enterprise.irs.gov/irc/ mailto:samc@irs.gov mailto:csirc@irs.gov

The CSP/Contractor shall isolate the information system from other internal information system components by implementing physically separate subnetworks with managed interfaces to other components of the system.

The CSP/Contractor shall define key information security tools, mechanisms, and support components associated with system and security administration and isolate those tools, mechanisms, and support components from other internal information system components via physically or logically separate subnetworks.

Note: These requirements are above the IRM 10.8.1 baseline and are assigned to Moderate-impact systems by FedRAMP

CLOUD SERVICE PROVIDER’S INFORMATION OUTPUT HANDLING AND

RETENTION

The CSP/Contractor shall handle and retain data within the information system, according to record retention standards. The IRS shall identify the record retention standards to the contractor. In addition, once the contract expires, all data shall be returned to the IRS, unless specifically identified otherwise in the contract. No records shall be maintained, in paper or electronically, unless approved by the IRS COR. Once disposal is complete, a copy of the disposal record and notification must be provided to the IRS CO/COR.

JURISDICTION OVER IRS DATA AND CONTRACT TERMS DATA

The CSP/Contractor shall maintain all data within the United States (or U.S. territories).

Jurisdiction over IRS data and contract terms must not be divided. The CSP/Contractor shall provide the IRS with a list of the physical locations which may contain government data. The CSP/Contractor shall provide information about the jurisdictions in which data may be stored and processed and any risks resulting from the location of those jurisdictions must be evaluated. The CSP/Contractor shall identify all data centers that the data at rest or data backup will reside.

The CSP will work with the Information Owner to understand the business rules for information/data store, collected in the Cloud.

DATA COLLECTED, PROCESSED AND TRANSFERRED

Data provided by the IRS and their customers must be collected, processed, and transferred in accordance with the contract terms established between the IRS and the cloud provider.

Sensitive But Unclassified (SBU) information, data, and/or equipment will only be disclosed to authorized personnel on a Need-To-Know basis. The CSP/Contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to IRS control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following NIST Special Publication 800-88, Guidelines for Media Sanitization.

The disposition of all data will be at the written direction of the COR, this may include documents returned to IRS control; destroyed; or held as specified until otherwise directed. Items returned to the IRS shall be hand carried or sent by certified mail to the COR.

The CSP/Contractor shall have adequate programs in place to protect the information received and information from unauthorized use, access, and disclosure. The CSP/Contractor programs for protecting information received must include documenting notification to employees and subcontractors (at any tier), who will have access to SBU information, the importance of protecting SBU information in general, and returns and return information, and information protected by the Privacy Act; in particular, the disclosure restrictions that apply and the criminal or civil sanctions, penalties, or punishments that may be imposed for unauthorized disclosure or inspection. Disclosure practices and the safeguards used to protect the confidentiality of information entrusted to the Government (and, as provided under the IRC and the Privacy Act) are subject to continual assessment and oversight to ensure their adequacy and efficacy.

DISPOSITION OF DATA

The delivery of data to the CSP/Contractor does not transfer any element of ownership; and, as between the customer and data host, the customer retains all right, title and interest in the data.

The CSP/Contractor role with respect to the data is limited to a storage function to fulfill its obligation to provide hosting services, and the CSP/Contractor will not interfere with the customer’s access.

The CSP/Contractor is a “bailee for hire” with respect to the data (that is, a person compensated for holding the property as bailee).

The CSP/Contractor will delete or will return the customer’s data in an agreed-upon format, at any time at the user’s request.

The CSP/Contractor must provide the IRS CO/COR with a copy of the disposal record and notification once disposal is complete.

TERMINATION OF CONTRACT

At the end of the contract period, or if the contract is terminated within the contract period, the CSP/Contractor shall coordinate with the IRS to ensure contractor and contractor employee access privileges to IRS information, IRS systems and facilities are revoked in a timely manner, as necessary.

CSP/Contractor shall confirm to IRS officials that information furnished under the contract has been properly returned, disposed, or destroyed.

Information and IT assets shall be returned to the IRS, destroyed and/or sanitized, as required or directed by the IRS. This includes assuring the IRS that all IT assets, including laptops, information systems, servers, routers, printers, faxes, switches, voice recordings, and all removable and fixed media have been sanitized of all IRS information prior to returning into production for other use.

CSP/Contractor required to return IRS information and property (as a part of the contract requirements) shall use a process that ensures that the confidentiality of the SBU information is always protected during transport.

A log shall be maintained to ensure that all media destroyed has identified the date of destruction, content of media, serial number, type of media (CD, DVD, Closed Caption Television (CCTV), etc.) destruction performed, personnel performing destruction, and witness.

All VoIP shall be sanitized prior to returning to production, when SBU information is stored on these devices.

All hard drives and removable media shall be inventoried, sanitized, and logged to demonstrate data destruction for all IT assets used to handle SBU data.

All hard copies shall be returned using double-wrapped envelopes and traceable mail.

E-Discovery In the event of litigation procedures, the CSP shall comply with any and all request to furnish informational data directly to the IRS for electronic discovery (E-discovery) purposes. The IRS shall have the authority to request hardcopy documents or electronically stored information (ESI) from the CSP that is relevant to any legal proceedings.

FOIA Request The CSP shall not directly disclose any IRS owned data to a third-party requestor who is seeking information through the Freedom of Information Act (FOIA). All FOIA request regarding IRS information and information systems shall be processed directly by the IRS FOIA office. Third-party requestors must contact the respective FOIA public liaison for their state. This information can be found at the following: https://www.irs.gov/privacy-disclosure/irs-disclosure-offices https://www.irs.gov/privacy-disclosure/irs-disclosure-offices

FISMA Contract Language
INFORMATION SECURITY / FEDERAL INFORMATION SECURITY MODERNIZATION ACT (FISMA)
THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST) GUIDANCE FOR INFORMATION SECURITY
TREASURY / IRS POLICIES FOR INFORMATION TECHNOLOGY (IT) SECURITY
FEDERAL INFORMATION PROCESSING STANDARD (FIPS)-201-2
SECURITY AUTHORIZATION / CERTIFICATION AND ACCREDITATION PROCESS
INFORMATION SYSTEMS AND INFORMATION SECURITY CONTROLS FOR CONTRACTING ACTIONS SUBJECT TO IRS PUBLICATION 4812 REVISION 10-201
CONTRACTOR (AND SUBCONTRACTOR) SITE AND INFORMATION TECHNOLOGY (SOFTWARE, HARDWARE AND DATA) LOCATION
ALTERNATE STORAGE
BACKUPS
DATA LOSS PREVENTION (DLP) SOFTWARE
USE OF OUTSOURCED / CONTRACTOR FACILITIES TO PROCESS IRS SBU DATA
CONTRACTOR SYSTEM REVIEW / SITE VISIT
SAFEGUARDING / PROTECTING SENSITIVE PERSONALLY IDENTIFIABLE INFORMATION (PII)
CONTRACTOR RIGHTS TO ACCESS DATA
HANDLING INFORMATION SECURITY INCIDENTS
CONTRACTOR BOUNDARY PROTECTION
CLOUD SERVICE PROVIDER’S INFORMATION OUTPUT HANDLING AND RETENTION
JURISDICTION OVER IRS DATA AND CONTRACT TERMS DATA
DATA COLLECTED, PROCESSED AND TRANSFERRED
DISPOSITION OF DATA
TERMINATION OF CONTRACT
E-Discovery
FOIA Request

File details come from the government source that posted it. Updated .