J.2_Cybersecurity-Data Protection-AI 12.21.25_Revised.pdf

PDF 184 KB Posted

Attached to
Parametric Railway Line Capacity Modeling Federal contract opportunity
Solicitation number
693JJ626Q000005
Issued by
Department of Transportation Federal Railroad Administration

About this file

This is a contract appendix establishing mandatory cybersecurity, Zero Trust, artificial intelligence, and data protection requirements for the Parametric Railway Line Capacity Model project Phase I. The appendix is tailored specifically for model development and delivery of model artifacts, explicitly excluding production hosting, enterprise Zero Trust architecture, FedRAMP authorization, and continuous Security Operations Center (SOC) operations, which are reserved for Phase II production contracts or option contract line items (CLINs).

The contractor must establish a documented information security program protecting the confidentiality, integrity, and availability of Government Data using administrative, technical, and physical safeguards appropriate to development and test environments. Key requirements include compliance with applicable Federal cybersecurity and privacy laws, relevant NIST guidance (NIST SP 800-53 controls), and DOT/FRA policies; encryption of data at rest and in transit using FRA-approved algorithms; role-based least-privilege access with multi-factor authentication; routine vulnerability scanning and patch management for contractor-controlled environments; incident response capability with notification within one hour for sensitive production data incidents or 24 hours for lower-impact incidents, followed by written reports within 72 hours; prohibition on using Government Data for training any AI/ML models without explicit prior written authorization; incorporation of security considerations into model artifact design and development; and data return or secure destruction in accordance with NIST SP 800-88 upon contract completion. The contractor bears responsibility for costs attributable to cybersecurity incidents caused by failure to comply with contractual security requirements, must ensure personnel complete initial and annual role-based cybersecurity and privacy awareness training, and must flow down essential data protection clauses (data handling, encryption, non-disclosure agreements, incident reporting, and return/destruction obligations) to all subcontractors. The Government retains unrestricted rights to all Government data, code, tools, and systems developed and maintains the right to request full copies at any time.

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

J.5 Addendum 2: Cybersecurity, AI, and Data Protection Contract Requirements.

╔ěكل

Cybersecurity, Zero Trust, AI and Data Protection Requirements

Preface: Tailored Applicability for Phase I Model Development — The Cybersecurity, Zero Trust, AI & Data Protection Appendix is hereby tailored for the Phase I scope of the Parametric Railway Line Capacity Model project. The provisions retained here apply to model development, delivery of model artifacts, and any limited non‑production demonstration artifacts. Production hosting, enterprise Zero Trust architecture, FedRAMP authorization, and continuous SOC operations are outside the Phase I scope and will be addressed, if needed, in subsequent Phase II production contracts or option CLINs.

This Appendix is written to be contract-enforceable, technology-neutral, and is an integral part of the Contract between the Government and the Contractor and establishes mandatory Cybersecurity, Zero Trust, AI and Data Protection Requirements.

1. Definitions

1.1 “Government Data” means all data, information, records, or content created, collected, processed, stored, transmitted, or maintained on behalf of the Government under this Contract, including but not limited to Sensitive Information and PII.

1.2 “Cybersecurity Incident” A cyber incident is an event that could jeopardize the confidentiality, integrity, or availability of digital information or information systems or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies of an information system or Government Data.

1.3 “Personally Identifiable Information (PII)”: Information that can be used to distinguish or trace an individual’s identity—such as name, social security number, biometric data records— either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual (e.g., date and place of birth, mother’s maiden name, etc.)..

2. Information Security Program The Contractor shall establish, implement, maintain, and continuously improve a documented information security program appropriate to the scope of work for this contract that protects the confidentiality, integrity, and availability of Government Data used in model development. The program shall include administrative, technical, and physical safeguards commensurate with sensitivity of the data and the Contractor’s environment (development/test workspaces). The Contractor is not required to implement enterprise hosting security controls (e.g., FedRAMP) unless explicitly stated in a separate CLIN.

3. Compliance With Laws, Regulations, and Standards

(1) Compliance — In performing this contract, the Contractor shall comply with applicable Federal cybersecurity and privacy laws and DOT/FRA policies. For Phase I model development, the Contractor must comply with relevant NIST guidance (e.g., NIST SP 800‑53 controls applicable to contractor-hosted

Dockery, Ray (FRA) Recommend using this preface to explain that the appendix has been tailored for Phase I.

Dockery, Ray (FRA) Keep. No change.

Dockery, Ray (FRA) Modify development environments) and OMB/DOT policy memos as applicable to non-production handling of Government data. Requirements that apply to production hosting (FedRAMP, ATO processes) are reserved for Government-hosted production environments and Phase II application contracts.

4. Data Handling, PII Protection, and Access Control Government Data shall be used only to perform the obligations of this contract. The Contractor shall handle, store, transmit, and dispose of Government Data in accordance with Government data classification and handling requirements, and operate only within Government‑approved secure environments for sensitive or production datasets. The Contractor shall implement: (a) encryption for data at rest and in transit per FRA-approved algorithms; (b) role‑based least-privilege access for personnel with a need-to-know; (c) multi-factor authentication for accounts providing access to Government Data; and (d) logging sufficient for auditing access. The Contractor shall not disclose Government Data to third parties without written authorization from the Government.

7. Vulnerability Management The Contractor shall perform routine vulnerability scanning and patch management for Contractor‑controlled development environments used for the contract and shall remediate high‑severity findings in a timely manner. For work performed in Government‑provided or Government‑approved environments, the Contractor shall coordinate with FRA IT to address vulnerabilities per Government procedures. Continuous 24/7 monitoring and SOC operations remain Government responsibilities for production hosting.

8. Incident Response and Reporting The Contractor shall maintain an incident response capability and shall notify the Government of any actual or suspected cybersecurity or privacy incident involving Government Data or systems within one

(1) hour of initial discovery for incidents impacting sensitive production data or systems; for lower-impact incidents, initial notification within 24 hours is acceptable. A written incident report shall follow within 72 hours describing impact, mitigations, and planned corrective actions.

9. Subcontractor The Contractor shall ensure that subcontractors with access to Government Data comply with the essential data protection requirements in this Appendix (data handling, encryption, NDA, incident reporting). The Government will identify any additional flow-down obligations for specific subcontractor roles.

10. Audit, Assessment, and Right to Review The Government reserves the right to assess or audit the Contractor’s cybersecurity and data protection controls related to this contract. The Contractor shall provide reasonable access to documentation and personnel and shall cooperate in assessments limited to the contract scope and data-handling environments.

Dockery, Ray (FRA) Keep, but tailor & scope for Parametric Model

11. Data Retention, Return, and Destruction

11.1 Upon completion or termination of the Contract, the Contractor shall return all Government Data or securely destroy such data in accordance with NIST SP 800-88.

11.2 The Contractor shall provide written certification of data destruction upon request.

12. Breach Liability The Contractor shall be responsible for costs attributable to a cybersecurity incident caused by the Contractor’s failure to comply with contractual security requirements, including reasonable remediation and notification costs.

13. Training The Contractor shall ensure personnel with access to Government Data complete initial and annual role-based cybersecurity and privacy awareness training relevant to their tasks under this contract.

14. Zero Trust Principles

The Contractor shall follow identity-centric security practices for Contractor-issued accounts (strong authentication, MFA) and least-privilege access. Implementation of enterprise Zero Trust Architecture components (e.g., network micro-segmentation, enterprise continuous device posture enforcement) is the Government’s responsibility for production environments and is not required of the Contractor for Phase I model development.

15. Artificial Intelligence (AI), Generative AI, and Machine Learning (ML) Restrictions

The Contractor shall not use Government Data for training, tuning, or operating Contractor-owned or third‑party AI/ML models, nor incorporate Government Data into any public or shared training datasets, unless the Government provides explicit prior written authorization specifying scope, purpose, and retention. If authorized, the Contractor must meet additional documentation, segregation, and oversight requirements to be specified by the Government.

16. Systems Security Engineering Requirement:

The Contractor shall incorporate security considerations into design and development of the model artifacts (secure coding, dependency management, supply chain risk awareness, and documentation of security considerations). Comprehensive SSE responsibilities for production systems will be addressed under Government‑led Phase II arrangements.

17. Restrictions on Disclosure of Information and Data

Except as authorized in writing by the Contracting Officer, the Contractor shall not disclose, orally or in writing, any:

Proprietary Information, Privacy Information, Privileged Information, Government Information or data stored, processed, or handled in providing services under this Contract or which may come into the possession of the Contractor in providing services under this Contract or which may come into the possession of the Contractor in providing services under this Contract.

18. Protection of Information, Confidentiality, Non-disclosure, and Data Rights

The government will retain unrestricted rights to government data, code, tools, and systems developed under this contract. The government retains ownership of all created/loaded data, code, tools, and applications hosted on vendor’s infrastructure, as well as maintains the right to request full copies of these at any time.

20. Survival The obligations in this Appendix related to data protection, confidentiality, incident reporting, destruction/return of Government Data, and records retention shall survive expiration or termination of the Contract. Other clauses tied specifically to production hosting or continuous monitoring do not survive in Phase I unless explicitly included in a subsequent Phase II agreement.

21. Contract Passthrough The Contractor shall include in all subcontracts (including lower-tier subcontracts) the essential data protection clauses of this Appendix (data handling, NDA, incident reporting, encryption, and return/destruction obligations). Full passthrough of other production-oriented obligations (FedRAMP, ATO responsibilities, continuous monitoring) is not required for Phase I subcontracting unless expressly specified by the Government.

File details come from the government source that posted it. Updated .