Amendment_3_Attachment_1_InformationAndPhysicalAccessSecurity.pdf

PDF 258 KB Posted

Attached to
Cancer Prevention Agent Development Program: Early Phase Clinical Research Federal contract opportunity
Solicitation number
N01CN05014-69
Issued by
Department of Health and Human Services National Institutes of Health

About this file

Amendment 3 Attachment 1- Information and Physical Access Security

View the file

Other files for this federal contract opportunity

Other files attached to Cancer Prevention Agent Development Program: Early Phase Clinical Research, newest first.
File Type Posted
amendment3.pdf PDF
Transcript_of_Preproposal_Conference_Held_04272011.pdf PDF
ATTACHMENT_1_PACKAGINGANDDELIVERYOFTHEPROPOSAL_05042011.pdf PDF
amendment2.pdf PDF
amendment1.pdf PDF
Attachment_1_PACKAGING_AND_DELIVERY_OF_PROPOSALS_revised.pdf PDF
N01CN05014-69.pdf PDF
RFPAttachmentNondisclosure.pdf PDF
Attachment_3_Statement_of_Work.pdf PDF
Attachment_1_PACKAGING_AND_DELIVERY_OF_PROPOSALS.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION C - DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

ARTICLE C.2 REPORTING REQUIREMENTS

b. Other Reports/Deliverables – Item #1 is revised to include items d-g

1. Information Security and Physical Access Reporting Requirements

The Contractor shall submit the following reports as required by the INFORMATION AND PHYSICAL ACCESS SECURITY Article in SECTION H of this contract. Note: Each report listed below includes a reference to the appropriate subparagraph of this article.

a. Roster of Employees Requiring Suitability Investigations

The Contractor shall submit a roster, by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under the contract who will develop, have the ability to access, or host and/or maintain a Federal information system(s). The roster shall be submitted to the Contracting Officer's Technical Representative (COTR), with a copy to the Contracting Officer, within 14 calendar days of the effective date of the contract.

(Reference subparagraph A.e. of the INFORMATION AND PHYSICAL ACCESS SECURITY Article in SECTION H of this contract.)

b. Reporting of New and Departing Employees

The Contractor shall notify the Contracting Officer's Technical Representative (COTR) and Contracting Officer within five working days of staffing changes for positions that require suitability determinations as follows:

i. New Employees who have or will have access to HHS Information systems or data: Provide the name, position title, e-mail address, and phone number of the new employee.

Provide the name, position title and suitability level held by the former incumbent. If the employee is filling a new position, provide a description of the position and the Government will determine the appropriate security level.

ii. Departing Employees: 1) Provide the name, position title, and security clearance level held by or pending for the individual; and

2) Perform and document the actions identified in the "Employee Separation Checklist", attached in Section J, ATTACHMENTS of this contract, when a Contractor/Subcontractor employee terminates work under this contract. All documentation shall be made available to the COTR and/or Contracting Officer upon request.

(Reference subparagraph E.2.a-c. of the INFORMATION AND PHYSICAL ACCESS SECURITY Article in SECTION H of this contract.)

c. Contractor - Employee Non-Disclosure Agreement(s)

The contractor shall complete and submit a signed and witnessed "Commitment to Protect Non-Public Information - Contractor Agreement" form for each contractor and subcontractor employee who may have access to non-public Department information under this contract. This form is located at:

http://ocio.nih.gov/docs/public/Nondisclosure.pdf .

http://ocio.nih.gov/docs/public/Nondisclosure.pdf

(Reference subparagraph E.2.d. of the INFORMATION AND PHYSICAL ACCESS

d. IT Security Plan (IT-SP)

In accordance with HHSAR Clause 352.239-72, Security Requirements For Federal Information Technology Resources, the contractor shall submit the IT-SP within thirty (30) days after contract award. The IT-SP shall be consistent with, and further detail the approach to, IT security contained in the Contractor's bid or proposal that resulted in the award of this contract. The IT-SP shall describe the processes and procedures that the Contractor will follow to ensure appropriate security of IT resources that are developed, processed, or used under this contract. If the IT-SP only applies to a portion of the contract, the Contractor shall specify those parts of the contract to which the IT-SP applies.

The Contractor shall review and update the IT-SP in accordance with NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems and FIPS 200, on an annual basis.

(Reference subparagraph D.c.1. of the INFORMATION AND PHYSICAL

e. IT Risk Assessment (IT-RA)

Federal Information Technology Resources, the contractor shall submit the IT-RA within thirty (30) days after contract award. The IT-RA shall be consistent, in form and content, with NIST SP 800-30, Risk Management Guide for Information Technology Systems, and any additions or augmentations described in the HHS- OCIO Information Systems Security and Privacy Policy.

The Contractor shall update the IT-RA on an annual basis.

(Reference subparagraph D.c.2. of the INFORMATION AND PHYSICAL ACCESS

f. FIPS 199 Assessment

Federal Information Technology Resources, the Contractor shall submit a FIPS 199 Assessment within thirty (30) days after contract award. The FIPS 199 Assessment shall be consistent with the cited NIST standard.

(Reference subparagraph D.c.3. of the INFORMATION AND PHYSICAL ACCESS SECURITY Article in SECITON H of this contract.

g. IT Security Certification and Accreditation (IT-SC&A)

Federal Information Technology Resources, the Contractor shall submit written proof to the Contracting Officer that an IT-SC&A was performed within three (3) months after contract award.

The Contractor shall perform an annual security control assessment and provide to the Contracting Officer verification that the IT-SC&A remains valid.

(Reference subparagraph D.c.4. of the INFORMATION AND PHYSICAL

SECTION F - DELIVERIES OR PERFORMANCE

ARTICLE F.2 DELIVERIES – is revised change the numbering for deliverables and to add deliverables 26-29.

Satisfactory performance of the final contract shall be deemed to occur upon performance of the work described in the Statement of Work Article in SECTION C of this contract and upon delivery and acceptance by the Contracting Officer, or the duly authorized representative, of the following items in accordance with the stated delivery schedule:

a. The items specified below as described in the REPORTING REQUIREMENTS Article in SECTION C of this contract will be required to be delivered F.o.b. Destination as set forth in FAR 52.247-35, F.o.b. DESTINATION, WITHIN CONSIGNEES PREMISES (APRIL 1984), and in accordance with and by the date(s) specified below and any specifications stated in SECTION D, PACKAGING, MARKING AND SHIPPING, of this contract:

Item No.

Deliverable Description Addressee Due Date

1 Contractor-Employee Non- Disclosure Agreements

COTR, CO Prior to commencing work on the contract

2 Multi-Institution Monitoring Plan

PIO, COTR 30 calendar days after contract award

3 Master Data and Safety Monitoring Plan

PIO, COTR 60 calendar days after contract award

4 Protocol-specific Data and Safety Monitoring Plan

PIO To be provided with the submission of each protocol

5 Human Subjects Education certification

DCP’s regulatory contractor

Within 60 calendar days of award and yearly thereafter

6 Letter of Intent (LOI) PIO 60 calendar days after DCP announcement of the request for LOIs

7 Contract Work Assignment COTR With submission of Protocol

8 Protocol with informed consent document, appendices, and all Additional Study Documents

PIO First submission due 60 calendar days from DCP approval of LOI, and Revisions due as specified in the Consensus Review document

9 Protocol Amendments PIO As necessity determines after protocol is initiated

10 Biomarker and Pharmacokinetic Method Development Document

PIO First submission due 60 calendar days from DCP approval of LOI, and Revisions due as specified in the Consensus Review document

11 Monthly Data Reporting- Protocol Specific

DCP’s secure file transfer site

10th calendar day of the month after Final Study Approval

12 Protocol-related administrative and regulatory documents

DCP’s regulatory contractor

Prior to Final Study Approval, in consultation with COTR

Item No.

Deliverable Description Addressee Due Date

13 Adverse Events Reports Study Medical Monitor Due in accordance with DCP Adverse Event Reporting Chart

14 Biological specimens

DCP’s specimen biorepository (site to be determined)

Prior to or upon expiration of contract, as requested by COTR

15 Draft and Final Study Manuscript

PIO, Study Medical/Scientific Monitor

Draft: 120 calendar days after completion of study

Final: one month after publication

16 Biomarker and Other Laboratory Study Analyses

PIO, Study Medical/Scientific Monitor

After completion of study and as agreed upon with study Medical/Scientific Monitor

17 Complete, cleaned, audited, locked data set (on disc)

DCP’s regulatory contractor (to be determined)

120 calendar days after completion of study

18 Quarterly Progress Reports including expenditure summary for each clinical trial

PIO, COTR, CO 30 calendar days following the end of each quarter

19 Annual Progress Report PIO, COTR, CO 42 calendar days following the end of each contract year

20 Inclusion Enrollment Report PIO, COTR, CO Annually

21 Draft Final Contract Report PIO, COTR, CO 60 calendar days prior to the expiration date of the contract

22 Final Contract Report PIO, COTR, CO By Contract expiration date

23 Roster of Employees Requiring Suitability Investigations

COTR, CO Fourteen (14) calendar days after award

24 Reporting of New and Departing Employees

COTR, CO Within five working days of staffing changes for positions that require suitability determinations

25 Section 508 Report COTR, CO Sixty (60) calendar days prior to the end of each contract year.

26 IT Security Plan (IT-SP) COTR, CO Within 30 days of contract award and annually thereafter

27 IT Risk Assessment (IT-RA) COTR, CO Within 30 days of contract award and annually thereafter

28 FIPS 199 Assessment COTR, CO

Within 30 days of contract award

29 IT Security Certification and Accreditation (IT-SC&A)

COTR, CO Within 3 months after contract award and annually thereafter

b. As indicated above, items shall be addressed and delivered to:

Addressee

Contracting Officer’s Technical Representative (COTR) Division of Cancer Prevention National Cancer Institute Executive Plaza North, Room

6130 EXECUTIVE BLVD

BETHESDA, MD 20892

DCP Protocol Information Office (PIO) Division of Cancer Prevention National Cancer Institute Executive Plaza North, Room 2050

6130 EXECUTIVE BLVD

BETHESDA, MD 20892

Preferred electronic delivery to: nci_dcp_pio@mail.nih.gov

Contracting Officer (CO) Research Contracts and Acquisition Branch National Cancer Institute Executive Plaza South, Room 603

6120 EXECUTIVE BLVD MSC 7220

BETHESDA, MD 20892-7220

DCP’s Regulatory Contractor – Will be provided

Study Medical/Scientific Monitor – Will be provided

SECTION H - SPECIAL CONTRACT REQUIREMENTS

ARTICLE H.20 INFORMATION AND PHYSICAL ACCESS SECURITY – Item D, on page 29 of original RFP is changed to E. and a new D for HHSAR 352.239-72 is added.

A. HHS-Controlled Facilities and Information Systems Security – is unchanged

a. To perform the work specified herein, Contractor personnel are expected to have routine

(1) physical access to an HHS-controlled facility; (2) physical access to an HHS-controlled information system; (3) access to sensitive HHS data or information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

b. To gain routine physical access to an HHS-controlled information system, and/or access to sensitive data or information, the Contractor and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; Office of Management and Budget Memorandum (M-05-24); and Federal Information Processing Standards Publication (FIPS PUB) Number 201; and with the personal identity verification and investigations procedures contained in the following documents:

1. HHS Information Security Program Policy ( http://www.hhs.gov/read/irmpolicy/121504.html )

2. HHS Office of Security and Drug Testing, Personnel Security/Suitability Handbook, dated February 1, 2005 ( http://www.hhs.gov/ohr/manual/pssh.pdf )

3. HHS HSPD-12 Policy Document, v. 2.0 ( http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy200 5/m05-24.pdf )

4. Information regarding background checks/badges ( http://idbadge.nih.gov/background/index.asp )

c. Position Sensitivity Levels:

This contract will entail the following position sensitivity levels:

[ ] Level 6: Public Trust - High Risk. Contractor/subcontractor employees assigned to Level 6 positions shall undergo a Suitability Determination and Background Investigation

(MBI).

[ X ] Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

[ X ] Level 1: Non-Sensitive. Contractor/subcontractor employees assigned to Level 1 positions shall undergo a Suitability Determination and National Check and Inquiry Investigation (NACI).

d. The personnel investigation procedures for Contractor personnel require that the Contractor prepare and submit background check/investigation forms based on the type of investigation required. The minimum Government investigation for a non-sensitive position is a National Agency Check and Inquiries (NACI) with fingerprinting. More restricted positions - i.e., those above non-sensitive, require more extensive documentation and investigation.

The Contractor shall submit a roster, by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under the contract who will develop, have the ability to access and/or maintain a Federal Information System(s). The roster shall be submitted to the Contracting Officer's Technical Representative (COTR), with a copy to the Contracting Officer, within 14 calendar days after the effective date of the contract. The Contracting Officer shall notify the Contractor of the appropriate level of suitability investigations to be performed. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at: http://ocio.nih.gov/docs/public/Suitability-roster.xls .

Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

The Contractor shall notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the contract and if they have previously been the subject of national agency checks or background investigations.

All contractor and subcontractor employees shall comply with the conditions established http://www.hhs.gov/read/irmpolicy/121504.html http://www.hhs.gov/read/irmpolicy/121504.html http://www.hhs.gov/ohr/manual/pssh.pdf http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://idbadge.nih.gov/background/index.asp http://ocio.nih.gov/docs/public/Suitability-roster.xls for their designated position sensitivity level prior to performing any work under this contract.

Contractors may begin work after the fingerprint check has been completed.

e. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-14. Accordingly, the Contractor shall ensure that any additional employees whose names it submits for work under this contract have a reasonable chance for approval.

f. Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the contract price of no more that the cost of the additional investigation(s).

g. The Contractor shall include language similar to this "HHS Controlled Facilities and Information Systems Security" language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

h. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.

i. Within 7 calendar days after the Government's final acceptance of the work under this contract, or upon termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.

B. Standard for Security Configurations, HHSAR 352.239-70, (January 2010) – is unchanged

a. The Contractor shall configure its computers that contain HHS data with the applicable Federal Desktop Core Configuration (FDCC) (see http://nvd.nist.gov/fdcc/index.cfm ) and ensure that its computers have and maintain the latest operating system patch level and anti-virus software level.

Note: FDCC is applicable to all computing systems using Windows XPTM and Windows VistaTM, including desktops and laptops - regardless of function - but not including servers.

b. The Contractor shall apply approved security configurations to information technology (IT) that is used to process information on behalf of HHS. The following security configuration requirements apply: FDCC

c. The Contractor shall ensure IT applications operated on behalf of HHS are fully functional and operate correctly on systems configured in accordance with the above configuration requirements. The Contractor shall use Security Content Automation Protocol (SCAP)-validated tools with FDCC Scanner capability to ensure its products operate correctly with FDCC configurations and do not alter FDCC settings - see http://nvd.nist.gov/validation.cfm . The Contractor shall test applicable product versions with all relevant and current updates and patches installed. The Contractor shall ensure currently supported versions of information technology products met the latest FDCC major version and subsequent major versions.

d. The Contractor shall ensure IT applications designed for end users run in the standard user context without requiring elevated administrative privileges.

http://nvd.nist.gov/fdcc/index.cfm http://nvd.nist.gov/validation.cfm http://nvd.nist.gov/validation.cfm

e. The Contractor shall ensure hardware and software installation, operation, maintenance, update, and patching will not alter the configuration settings or requirements specified above.

f. The Contractor shall (1) include Federal Information Processing Standard (FIPS) 201-compliant ( see http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf ), Homeland Security Presidential Directive 12 (HSPD-12) card readers with the purchase of servers, desktops, and laptops; and (2) comply with FAR Subpart 4.13, Personal Identity Verification.

g. The Contractor shall ensure that its subcontractors (at all tiers) which perform work under this contract comply with the requirements contained in this clause.

C. Standard for Encryption language, HHSAR 352.239-71, (January 2010) – is unchanged

a. The Contractor shall use Federal Information processing Standard (FIPS) 140-2-compliant encryption (Security) Requirements for Cryptographic Module, as amended) to protect all instances of HHS sensitive information during storage and transmission. (Note:

The Government has determined that HHS information under this contract is considered "sensitive" in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems, dated February 2004).

b. The Contractor shall verify that the selected encryption product has been validated under the Cryptographic Module Validation Program (see http://csrc.nist.gov/cryptval/ ) to confirm compliance with FIPS 140-2 (as amended). The Contractor shall provide a written copy of the validation documentation to the Contracting Officer and the Contracting Officer's Technical Representative.

c. The Contractor shall use the Key Management Key (see FIPS 201, Chapter 4, as amended) on the HHS personal identification verification (PIV) card; or alternatively, the Contractor shall establish and use a key recovery mechanism to ensure the ability for authorized personnel to decrypt and recover all encrypted information (see http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf ). The Contractor shall notify the Contracting Officer and the Contracting Officer's Technical Representative of personnel authorized to decrypt and recover all encrypted information.

d. The Contractor shall securely generate and manage encryption keys to prevent unauthorized decryption of information in accordance with FIPS 140-2 (as amended).

e. The Contractor shall ensure that this standard is incorporated into the Contractor's property management/control system or establish a separate procedure to account for all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive HHS information.

f. The Contractor shall ensure that its subcontractors (all all tiers) which perform work under this contract comply with the requirements contained in this clause.

D. Security Requirements For Federal Information Technology Resources, HHSAR 352.239- 72, (January 2010)

a. Applicability . This clause applies whether the entire contract or order (hereafter "contract"), or portion thereof, includes information technology resources or services in which the Contractor has physical or logical (electronic) access to, or operates a Department of Health and Human Services (HHS) system containing, information that directly supports HHS' mission. The term "information technology (IT)", as used in this clause, includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services) and related resources. This clause does not apply to national security systems as defined in

FISMA.

http://csrc.nist.gov/cryptval/ http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf

b. Contractor responsibilities . The Contractor is responsible for the following:

1. Protecting Federal information and Federal information systems in order to ensure their -

a. Integrity, which means guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity;

b. Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and

c. Availability, which means ensuring timely and reliable access to and use of information.

2. Providing security of any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor, regardless of location, on behalf of HHS.

3. Adopting, and implementing, at a minimum, the policies, procedures, controls and standards of the HHS Information Security Program to ensure the integrity, confidentiality, and availability of Federal information and Federal information systems for which the Contractor is responsible under this contract or to which it may otherwise have access under this contract. The HHS Information Security Program is outlined in the HHS Information Security Program Policy, which is available on the HHS Office of the Chief Information Officer's (OCIO) Web site.

c. Contractor security deliverables . In accordance with the timeframes specified, the Contractor shall prepare and submit the following security documents to the Contracting Officer for review, comment, and acceptance:

1. IT Security Plan (IT-SP) - due within 30 days after contract award. The IT-SP shall be consistent with, and further detail the approach to, IT security contained in the Contractor's bid or proposal that resulted in the award of this contract. The IT-SP shall describe the processes and procedures that the Contractor will follow to ensure appropriate security of IT resources that are developed, processed, or used under this contract. If the IT-SP only applies to a portion of the contract, the Contractor shall specify those parts of the contract to which the IT-SP applies.

a. The Contractor's IT-SP shall comply with applicable Federal laws that include, but are not limited to, the Federal Information Security Management Act (FISMA) of 2002 (Title III of the E-Government Act of 2002, Public Law 107-347), and the following Federal and HHS policies and procedures:

i. Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources, Appendix III, Security of Federal Automation Information Resources.

ii. National Institutes of Standards and Technology (NIST) Special Publication (SP) 800-18, Guide for Developing Security Plans for Information Systems, in form and content, and with any pertinent contract Statement of Work/Performance Work Statement (SOW/PWS) requirements. The IT-SP shall identify and document appropriate IT security controls consistent with the sensitivity of the information and the requirements of Federal Information Processing Standard (FIPS) 200, Recommend Security Controls for Federal Information Systems. The Contractor shall review and update the IT-SP in accordance with NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems and FIPS 200, on an annual basis.

iii. HHS-OCIO Information Systems Security and Privacy Policy.

2. IT Risk Assessment (IT-RA) - due within 30 days after contract award. The IT- RA shall be consistent, in form and content, with NIST SP 800-30, Risk

Management Guide for Information Technology Systems, and any additions or augmentations described in the HHS-OCIO Information Systems Security and Privacy Policy. After resolution of any comments provided by the Government on the draft IT-RA, the Contracting Officer shall accept the IT-RA and incorporate the Contractor's final version into the contract for Contractor implementation and maintenance. The Contractor shall update the IT-RA on an annual basis.

3. FIPS 199 Standards for Security Categorization of Federal Information and Information Systems Assessment (FIPS 199 Assessment) - due within 30 days after contract award. The FIPS 199 Assessment shall be consistent with the cited NIST standard. After resolution of any comments by the Government on the draft FIPS 199 Assessment, the Contracting Officer shall accept the FIPS 199 Assessment and incorporate the Contractor's final version into the contract.

4. IT Security Certification and Accreditation (IT-SC&A) - due within 3 months after contract award. The Contractor shall submit written proof to the Contracting Officer that an IT-SC&A was performed for applicable information systems - see paragraph (a) of this clause. The Contractor shall perform the IT-SC&A in accordance with the HHS Chief Information Security Officer's Certification and Accreditation Checklist; NIST SP 800-37, Guide for the Security, Certification and Accreditation of Federal Information Systems; and NIST 800-53, Recommended Security Controls for Federal Information Systems. An authorized senior management official shall sign the draft IT-SC&A and provided it to the Contracting Officer for review, comment, and acceptance.

b. After resolution of any comments provided by the Government on the draft IT SC&A, the Contracting Officer shall accept the IT-SC&A and incorporate the Contractor's final version into the contract as a compliance requirement.

c. The Contractor shall also perform an annual security control assessment and provide to the Contracting Officer verification that the IT-SC&A remains valid. Evidence of a valid system accreditation includes written results of:

i. Annual testing of the system contingency plan; and

ii. The performance of security control testing and evaluation.

d. Personal identity verification. The Contractor shall identify its employees with access to systems operated by the Contractor for HHS or connected to HHS systems and networks. The Contracting Officer's Technical Representative (COTR) shall identify, for those identified employees, position sensitivity levels that are commensurate with the responsibilities and risks associated with their assigned positions. The Contractor shall comply with the HSPD-12 requirements contained in "HHS-Controlled Facilities and Information Systems Security" requirements specified in the SOW/PWS of this contract.

e. Contractor and subcontractor employee training. The Contractor shall ensure that its employees, and those of its subcontractors, performing under this contract complete HHS-furnished initial and refresher security and privacy education and awareness training before being granted access to systems operated by the Contractor on behalf of HHS or access to HHS systems and networks. The Contractor shall provide documentation to the COTR evidencing that Contractor employees have completed the required training.

f. Government access for IT inspection. The Contractor shall afford the Government access to the Contractor's and subcontractors' facilities, installations, operations, documentation, databases, and personnel used in performance of this contract to the extent required to carry out a program of IT inspection (to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the integrity, confidentiality, and availability, of HHS data or to the protection of information systems operated on behalf of HHS.

g. Subcontracts. The Contractor shall incorporate the substance of this clause in all subcontracts that require protection of Federal information and Federal information systems as described in paragraph (a) of this clause, including those subcontracts that -

a. Have physical or electronic access to HHS' computer systems, networks, or IT infrastructure; or

b. Use information systems to generate, store, process, or exchange data with HHS or on behalf of HHS, regardless of whether the data resides on a HHS or the Contractor's information system.

h. Contractor employment notice. The Contractor shall immediately notify the Contracting Officer when an employee either begins or terminates employment (or is no longer assigned to the HHS project under this contract), if that employee has, or had, access to HHS information systems or data.

i. Document information. The Contractor shall contact the Contracting Officer for any documents, information, or forms necessary to comply with the requirements of this clause.

j. Contractor responsibilities upon physical completion of the contract. The Contractor shall return all HHS information and IT resources provided to the Contractor during contract performance and certify that all HHS information has been purged from Contractor-owned systems used in contract performance.

k. Failure to comply. Failure on the part of the Contractor or its subcontractors to comply with the terms of this clause shall be grounds for the Contracting Officer to terminate this contract.

E. Additional NIH Requirements – #4 is added

1. INFORMATION SECURITY TRAINING

In addition to any training covered under paragraph (e) of HHSAR 352.239-72, the contractor shall comply with the below training:

a. Mandatory Training

iii. All Contractor employees having access to (1) Federal information or a Federal information system or (2) sensitive data/information as defined at HHSAR 304.1300(a)(4), shall complete the NIH Computer Security Awareness Training course at http://irtsectraining.nih.gov/ before performing any work under this contract. Thereafter, Contractor employees having access to the information identified above shall complete an annual NIH-specified refresher course during the life of this contract. The Contractor shall also ensure subcontractor compliance with this training requirement.

iv. The Contractor shall maintain a listing by name and title of each Contractor/Subcontractor employee working on this contract and having access of the kind in paragraph 1.a(1) above, who has completed the NIH required training. Any additional security training completed by the Contractor/Subcontractor staff shall be included on this listing. The list shall be provided to the COTR and/or Contracting Officer upon request.

b. Role-based Training

HHS requires role-based training when responsibilities associated with a given role or position, could, upon execution, have the potential to adversely impact the security posture of one or more HHS systems. Read further guidance at Secure One HHS Memorandum on Role-Based Training Requirement .

For additional information see the following: http://ocio.nih.gov/security/security-communicating.htm#RoleBased .

The Contractor shall maintain a list of all information security training completed http://irtsectraining.nih.gov/ http://ocio.nih.gov/security/security-communicating.htm#RoleBased by each contractor/subcontractor employee working under this contract. The list

c. Rules of Behavior

The Contractor shall ensure that all employees, including subcontractor employees, comply with the NIH Information Technology General Rules of Behavior ( http://ocio.nih.gov/security/nihitrob.html ), which are contained in the NIH Information Security Awareness Training Course http://irtsectraining.nih.gov

2. PERSONNEL SECURITY RESPONSIBILITIES

The contractor shall comply with the below personnel security responsibilities:

a. In accordance with Paragraph (h) of HHSAR 352.239-72, the Contractor shall notify the Contracting officer and the COTR within five working days before a new employee assumes a position that requires access to HHS information systems or data, or when an employee with such access stops working on this contract. The Government will initiate a background investigation on new employees assuming a position that requires access to HHS information systems or data, and will stop pending background investigations for employees that no longer work under the contract or no longer have such access.

b. New contractor employees who have or will have access to HHS information systems or data: The Contractor shall provide the COTR with the name, position title, e-mail address, and phone number of all new contract employees working under the contract and provide the name, position title and position sensitivity level held by the former incumbent. If an employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate position sensitivity level.

c. Departing contractor employees: The Contractor shall provide the COTR with the name, position title, and position sensitivity level held by or pending for departing employees. The Contractor shall perform and document the actions identified in the Contractor Employee Separation Checklist ( http://ocio.nih.gov/nihsecurity/Emp-sep-checklist.pdf ) when a Contractor/subcontractor employee terminates work under this contract. All documentation shall be made available to the COTR upon request.

d. Commitment to Protect Non-Public Departmental Information and Data.

The Contractor, and any subcontractors performing under this contract, shall not release, publish, or disclose non-public Departmental information to unauthorized personnel, and shall protect such information in accordance with provisions of the following laws and any other pertinent laws and regulations governing the confidentiality of such information:

- 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records)

- 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information)

- Public Law 96-511 (Paperwork Reduction Act)

Each employee, including subcontractors, having access to non-public Department information under this acquisition shall complete the "Commitment to Protect Non-Public Information - Contractor Employee Agreement" located at:

http://ocio.nih.gov/docs/public/Nondisclosure.pdf . A copy of each signed and http://ocio.nih.gov/security/nihitrob.html http://irtsectraining.nih.gov/ http://ocio.nih.gov/nihsecurity/Emp-sep-checklist.pdf http://ocio.nih.gov/nihsecurity/Emp-sep-checklist.pdf witnessed Non-Disclosure agreement shall be submitted to the Project Officer/COTR prior to performing any work under this acquisition.

3. Loss and/or Disclosure of Personally Identifiable Information (PII) - Notification of Data Breach

The Contractor shall report all suspected or confirmed incidents involving the loss and/or disclosure of PII in electronic or physical form.

Notification shall be made to the NIH Incident Response Team (IRT) via email ( IRT@mail.nih.gov ) within one hour of discovering the incident.

The Contractor shall follow up with IRT by completing and submitting one of the applicable two forms below within three (3) work days of incident discovery:

NIH PII Spillage Report at: http://ocio.nih.gov/docs/public/PII_Spillage_Report.doc NIH Lost or Stolen Assets Report at: http://ocio.nih.gov/docs/public/Lost_or_Stolen.doc

4. SECURITY CATEGORIZATION OF FEDERAL INFORMATION AND INFORMATION

SYSTEMS (FIPS 199 Assessment) – is added

a. Information Type:

[ X ] Administrative, Management and Support Information:

[ X ] Mission Based Information:

b. Security Categories and Levels:

Confidentiality Level: [ ] Low [ X ] Moderate [ ] High Integrity Level: [ ] Low [ X] Moderate [ ] High Availability Level: [X] Low [ ] Moderate [ ] High

Overall Level: [ ] Low [ X ] Moderate [ ] High

c. In accordance with HHSAR Clause 352.239-72, the contractor shall submit a FIPS 199 Assessment within 30 days after contract award. Any differences between the contractor's assessment and the information contained herein, will be resolved, and if required, the contract will be modified to incorporate the final FIPS 199 Assessment.

SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS

2. INSTRUCTIONS TO OFFERORS

b. TECHNICAL PROPOSAL INSTRUCTIONS

6. Information and Physical Access Security is applicable to this solicitation and the following information is provided to assist in proposal preparation. This section is revised to add item D.

IMPORTANT NOTE TO OFFERORS: The following information shall be addressed in a separate section of the Technical Proposal entitled "Information Security."

mailto:IRT@mail.nih.gov http://ocio.nih.gov/docs/public/PII_Spillage_Report.doc http://ocio.nih.gov/docs/public/Lost_or_Stolen.doc

The Homeland Security Presidential Directive (HSPD)-12 and the Federal Information Security Management Act of 2002 (P.L. 107-347) (FISMA) requires each agency to develop, document, and implement an agency-wide information security program to safeguard information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor (including subcontractor), or other source.

A. HHS-Controlled Facilities and Information Systems Security – is unchanged

a. To perform the work specified herein, Contractor personnel are expected to have routine (1) physical access to an HHS-controlled facility; (2) physical access to an HHS-controlled information system; (3) access to sensitive HHS data or information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

b. To gain routine physical access to an HHS-controlled information system, and/or access to sensitive data or information, the Contractor and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; Office of Management and Budget Memorandum (M-05-24); and Federal Information Processing Standards Publication (FIPS PUB) Number 201; and with the personal identity verification and investigations procedures contained in the following documents:

1. HHS Information Security Program Policy ( http://www.hhs.gov/read/irmpolicy/121504.html )

2. HHS Office of Security and Drug Testing, Personnel Security/Suitability Handbook, dated February 1, 2005 ( http://www.hhs.gov/ohr/manual/pssh.pdf )

3. HHS HSPD-12 Policy Document, v. 2.0 ( http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memorand a/fy2005/m05-24.pdf )

4. Information regarding background checks/badges ( http://idbadge.nih.gov/background/index.asp )

c. Position Sensitivity Levels:

This contract will entail the following position sensitivity levels:

[ ] Level 6: Public Trust - High Risk. Contractor/subcontractor employees assigned to Level 6 positions shall undergo a Suitability Determination and Background Investigation (MBI).

[ X ] Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

[ X ] Level 1: Non-Sensitive. Contractor/subcontractor employees assigned to Level 1 positions shall undergo a Suitability Determination and National Check and Inquiry Investigation (NACI).

d. The personnel investigation procedures for Contractor personnel require that the Contractor prepare and submit background check/investigation forms based on the type of investigation required. The minimum Government investigation for a non-http://www.hhs.gov/read/irmpolicy/121504.html http://www.hhs.gov/read/irmpolicy/121504.html http://www.hhs.gov/ohr/manual/pssh.pdf http://www.hhs.gov/ohr/manual/pssh.pdf http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://idbadge.nih.gov/background/index.asp sensitive position is a National Agency Check and Inquiries (NACI) with fingerprinting. More restricted positions - i.e., those above non-sensitive, require more extensive documentation and investigation.

The Contractor shall submit a roster, by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under the contract who will develop, have the ability to access and/or maintain a Federal Information System(s). The roster shall be submitted to the Contracting Officer's Technical Representative (COTR), with a copy to the Contracting Officer, within 14 calendar days after the effective date of the contract. The Contracting Officer shall notify the Contractor of the appropriate level of suitability investigations to be performed. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at:

http://ocio.nih.gov/docs/public/Suitability-roster.xls .

Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

The Contractor shall notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the contract and if they have previously been the subject of national agency checks or background investigations.

All contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract.

Contractors may begin work after the fingerprint check has been completed.

e. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-14. Accordingly, the Contractor shall ensure that any additional employees whose names it submits for work under this contract have a reasonable chance for approval.

f. Typically, the Government investigates personnel at no cost to the Contractor.

However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the contract price of no more that the cost of the additional investigation(s).

g. The Contractor shall include language similar to this "HHS Controlled Facilities and Information Systems Security" language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system;

(3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

h. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.

i. Within 7 calendar days after the Government's final acceptance of the work under this contract, or upon termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.

B. Standard for Security Configurations, HHSAR 352.239-70, (January 2010) – is unchanged.

a. The Contractor shall configure its computers that contain HHS data with the applicable Federal Desktop Core Configuration (FDCC) (see http://nvd.nist.gov/fdcc/index.cfm ) and ensure that its computers have and maintain the latest operating system patch level and anti-virus software level.

Note: FDCC is applicable to all computing systems using Windows XPTM and Windows VistaTM, including desktops and laptops - regardless of function - but not including servers.

b. The Contractor shall apply approved security configurations to information technology (IT) that is used to process information on behalf of HHS. The following security configuration requirements apply: FDCC

c. The Contractor shall ensure IT applications operated on behalf of HHS are fully functional and operate correctly on systems configured in accordance with the above configuration requirements. The Contractor shall use Security Content Automation Protocol (SCAP)-validated tools with FDCC Scanner capability to ensure its products operate correctly with FDCC configurations and do not alter FDCC settings - see http://nvd.nist.gov/validation.cfm . The Contractor shall test applicable product versions with all relevant and current updates and patches installed. The Contractor shall ensure currently supported versions of information technology products met the latest FDCC major version and subsequent major versions.

d. The Contractor shall ensure IT applications designed for end users run in the standard user context without requiring elevated administrative privileges.

e. The Contractor shall ensure hardware and software installation, operation, maintenance, update, and patching will not alter the configuration settings or requirements specified above.

f. The Contractor shall (1) include Federal Information Processing Standard (FIPS) 201-compliant ( see http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf ), Homeland Security Presidential Directive 12 (HSPD-12) card readers with the purchase of servers, desktops, and laptops; and (2) comply with FAR Subpart 4.13, Personal Identity Verification.

g. The Contractor shall ensure that its subcontractors (at all tiers) which perform work under this contract comply with the requirements contained in this clause.

C. Standard for Encryption language, HHSAR 352.239-71, (January 2010) – is unchanged

a. The Contractor shall use Federal Information processing Standard (FIPS) 140-2-compliant encryption (Security) Requirements for Cryptographic Module, as amended) to protect all instances of HHS sensitive information during storage and transmission. (Note: The Government has determined that HHS information under this contract is considered "sensitive" in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems, dated February 2004).

b. The Contractor shall verify that the selected encryption product has been validated under the Cryptographic Module Validation Program (see http://csrc.nist.gov/cryptval/ ) to confirm compliance with FIPS 140-2 (as amended). The Contractor shall provide a written copy of the validation documentation to the Contracting Officer and the Contracting Officer's Technical Representative.

http://nvd.nist.gov/fdcc/index.cfm http://nvd.nist.gov/fdcc/index.cfm http://nvd.nist.gov/validation.cfm http://nvd.nist.gov/validation.cfm http://csrc.nist.gov/cryptval/ http://csrc.nist.gov/cryptval/

c. The Contractor shall use the Key Management Key (see FIPS 201, Chapter 4, as amended) on the HHS personal identification verification (PIV) card; or alternatively, the Contractor shall establish and use a key recovery mechanism to ensure the ability for authorized personnel to decrypt and recover all encrypted information (see http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf ). The Contractor shall notify the Contracting Officer and the Contracting Officer's Technical Representative of personnel authorized to decrypt and recover all encrypted information.

d. The Contractor shall securely generate and manage encryption keys to prevent unauthorized decryption of information in accordance with FIPS 140-2 (as amended).

e. The Contractor shall ensure that this standard is incorporated into the Contractor's property management/control system or establish a separate procedure to account for all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive HHS information.

f. The Contractor shall ensure that its subcontractors (all all tiers) which perform work under this contract comply with the requirements contained in this clause.

D. Security Requirements For Federal…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .