N01PC65003-74_Amendment_6_SF_30_FINAL.pdf

PDF 2 MB Posted

Attached to
Surveillance, Epidemiology, and End Results (SEER) Program Federal contract opportunity
Solicitation number
N01PC65003-74
Issued by
Department of Health and Human Services National Institutes of Health

About this file

Amendment #06 to respond to questions received in regard to RFP: N01PC65003-74.

View the file

Other files for this federal contract opportunity

Other files attached to Surveillance, Epidemiology, and End Results (SEER) Program, newest first.
File Type Posted
N01PC65003-74_Amendment_12_Final.pdf PDF
N01PC65003-74_Amendment_11_final.pdf PDF
N01PC65003-74_Amendment_10_final.pdf PDF
N01PC65003-74_Amendment_9_FINAL.pdf PDF
N01PC65003-74_Amendment_8_SF_30_53017_FINAL.pdf PDF
N01PC65003-74_Amendment_7_SF_30_Final.pdf PDF
REVISION_TO_AMENDMENT_05.docx DOCX document
N01PC65003-74_Amendment_5_SF_30_final.pdf PDF
Attachment_17_Spreadsheet_of_Proposed_Estimated_Costs.xlsx XLSX spreadsheet
N01PC65003-74_Amendment_4_SF_30_final.pdf PDF
Attachment_2_Intent_to_propose_corrected_5917.pdf PDF
N01PC65003-74_Amendment_3_SF_30_final.pdf PDF
N01PC65003-74_Amendment_2_SF_30_final.pdf PDF
N01PC65003-74_Amendment_1.pdf PDF
N01PC65003-74_W_attachments_FINAL.pdf PDF
Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AMENDMENT TO SOLICITATION

REQUEST FOR PROPOSAL: N01PC65003-74

AMENDMENT No. 06

Date of Issuance: May 19, 2017

Please note there is no non-password protected version of the link in question #16 of Amendment #04, released on 5/11/2017.

“Page 33 (Section H. B. 2) and Page 75 (Section L.17.B.2) both list the URL https://ocio.nih.gov/InfoSecurity/Policy/Pages/CM.aspx which requires a username and password; therefore, we are unable to obtain the Federal Desktop Core Configuration (FDCC). Can the FDCC be made available as an attachment or amendment? Or, can a different URL that does not require a username/password be provided?”

The attached document titled “HHS Information Systems Security and Privacy Policy” is provided in lieu of the link.

1. Definition of “HHS-Controlled” Facilities and Information Systems (p. 32, ARTIICLE H.18)

a. Section A.a. of ARTICLE H.18 states that “Contractor personnel are expected to have routine (1) physical access to an HHS-controlled facility; (2) physical access to an HHS-controlled information system; (3) access to sensitive HHS data or information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).” (p. 32). Can the Government provide more information on what registries might consider as an “HHS-controlled facility” and what they consider to be “HHS data or information”? These are important considerations as states are not likely to consider their cancer surveillance data as “federal” data, but rather the states are likely to consider all data to belong to the states and shared with NCI.

i. Does the Government consider surveillance data collected by registries to be “HHS data”?

ii. Does the Government consider registry facilities to be “HHS facilities”?

iii. Does the Government consider the IMS data center to be an “HHS facility”?

iv. Does the Government consider SEER*DMS to be an “HHS information system”?

v. Does the Government consider other database management software and information systems managed locally at the registry (i.e., not part of SEER*DMS) to be “HHS information systems”?

b. Section C.a. (p. 34) - What does the Government consider “HHS sensitive information”? While there is no doubt that the information collected under the proposed contract is “sensitive”, the question is whether it is “HHS” sensitive information? Aren’t these data state data (not HHS) data?

c. Section D.a. (p. 34) – The applicability of the Security Requirements for Federal

Information Technology Resources states that it applies if “Contractor has physical or logical (electronic) access to, or operates a Department of Health and Human Services (HHS) system containing, information that directly supports HHS’ mission.”

What does the Government consider to be the HHS systems being accessed by registries?

RESPONSE: Refer to the attached document “HHS Information Security and Policy”.

The resultant contractors will be conducting business on behalf of the Federal Government. Therefore, for sample Task Order A and other applicable Task Orders FISMA requirements do apply.

2. Timing/Content of Data Files (page 14, Part 1, Section C, #9): “These submissions shall contain complete data for all patients diagnosed prior to January 1st of the preceding year.”

Statement conflicts with the example immediately following: “data submitted in February and November of 2019 will include all cases diagnosed through calendar year 2018.” According to the first statement, in February and November of 2019 we should be submitting all cases diagnosed prior to January 1, 2018 (i.e., diagnoses through December 31, 2017). But the example in the second statement implies that February and November 2019 submissions should include cases diagnosed through December 31, 2018. Because State Law requires hospitals to report cases within 6 months of diagnosis, we will not receive all 2018 cases until mid-way through 2019 (i.e., June 30, 2019). It would not be possible to include them in the February 2019 submission, and they will not be complete for the November 2019 submission. Please clarify.

RESPONSE: Please refer to Question #23 of Amendment #04. Also, see Task Area #3.2 of the Task Order A Statement of Work (Attachment #4).

3. Amendment #04 includes the Excel spreadsheet that we must use for this proposal but it’s only for 7 years and the proposal is for 10 years, are we do add the other 3 years to the Excel spreadsheet?

RESPONSE: Offerors can add the additional 3 years to Attachment #17 Excel spreadsheet to meet the requirements of the RFP.

4. Could you please provide the incumbent company and Point of Contact on the SEER Base contract which is set to expire on July 31, 2017?

RESPONSE: There are multiple incumbents. See https://seer.cancer.gov/registries/list.html.

5. We are planning on responding to this RFP. Where can we find the documents and updates?

RESPONSE: As required for all Federal procurements all documents and updates are posted to FedBizOps. This RFP solicitation and its amendments can be found at:

https://www.fbo.gov/index?s=opportunity&mode=form&id=4f3054a7148e8a12c8269dceab9 0de90&tab=core&_cview=1

6. We are a small 8a company. Is this solicitation being set-aside?

RESPONSE: No, there are no set-asides associated with this procurement. The Government issued a Small Business Sources Sought Notice #HHS-NIH-NCI-SBSS- PCPSB-5003-74. Based upon responses and mandatory qualification criteria, this acquisition is full and option.

7. Are we supposed to confirm receipt of the amendments that we have received to date (5)?

RESPONSE: Offerors are required to acknowledge receipt of each amendment in accordance with Item #11 of the Amendment facepage. Please review the language in item #11 of each amendment facepage.

8. What if an Offeror does not need legal agreements with entities reporting cases? It is covered by our state law. If this is not adequate, we will need further discussion and possibly more funding. (Base Statement of Work, Task Area 3 – Core Infrastructure Support Activities, Item 1.a.3; also noted in Statement of Work Task Order A, Item 1.a.3.

RESPONSE: If this is covered by state law then an Offeror in the subject state will not need to establish such agreements. Keep in mind, however, that state laws vary from state to state and the Statement of Work must cover all possibilities.

9. Who should be listed as Key Personnel?

RESPONSE: As indicated in both the Technical Evaluation Factors (Item 8 in Section M) and the Additional Technical Proposal Instructions (Attachment 14) the Government considers the position of Principal Investigator and Registry Operations Supervisor/Registry Director/Registry Manager as Key Personnel. It is the Offerors business decision to determine who will be named in these positions to meet the requirements of the RFP including all three SOWs.

10. Past Performance Factor, page 119: “The evaluation will be based on information obtained from references provided by the Offeror”. Is it acceptable to provide Contractor Performance Assessment Reports (CPARs) and NAACCR and SEER data quality reports? If yes, what period of time is appropriate? Is the Offeror to expected to seek references speaking to performance from other sources, such as collaborators, state cancer registry, etc.?

RESPONSE: Please refer to number 2 under Section 2: Business Proposal Discussions and attachments for information on what is required under the Past Performance Factor. Additionally, refer to the response to question #33 in Amendment #04. Also refer to Section L. 2.a.16. on page 72 of the solicitation for specific details.

11. Is there a page limit for biosketches? Is it the standard 5-page limit?

RESPONSE: There are no page limits for length of each NIH Biosketch. Also, refer to Section L.2.a.16. on page #72 of the solicitation.

12. What are the technical proposal instructions and page limits for Task Order C?

RESPONSE: Task Order C does not require a technical proposal. Please see letter G of the General Instructions in Attachment #14: Additional Technical Proposal Instructions.

13. What are the timelines for the peer review, administrative review, and notification of awards?

RESPONSE: This Government cannot answer this question. Please remember proposals are due by 4:00pm Eastern July 10, 2017. Refer to Article F.1 Period of Performance, which applies to this IDIQ.

14. Attachment 1 page 2 states that one Excel workbook must be submitted, but Attachment 21 “Organization of Business Proposal” instructions state to submit an Excel budget for Sections 3, 4, and 5. Should offerors submit three separate Excel workbooks (one for each sample task order) or one Excel workbook for all task orders?

RESPONSE: Offerors should submit Excel spreadsheets to eCPS in accordance with Attachment #21.

Office of the Chief Information Officer

Office of the Assistant Secretary for Administration

Department of Health and Human Services

HHS Information Systems Security and Privacy Policy

July 30, 2014

Project: HHS OCIO Policy

Document Number: HHS-OCIO-2014-0001

Table of Contents

Table of Contents

1. Purpose

2. Background

3. Scope

4. Policy

4.1. Department-Mandated Controls

4.2. OpDiv/StaffDiv Controls

5. Information and Assistance

6. Effective Date/Implementation

7. Approved

Appendix A: Roles and Responsibilities

Appendix B: Security Control Section

Access Control (AC)

Awareness and Training (AT)

Audit and Accountability (AU)

Security Assessment and Authorization (CA)

Configuration Management (CM)

Contingency Planning (CP)

Identification and Authentication (IA)

Incident Response (IR)

Maintenance (MA)

Media Protection (MP)

Physical and Environmental Protection (PE)

Planning (PL)

Program Management (PM)

Personnel Security (PS)

Risk Assessment (RA)

Systems and Services Acquisition (SA)

Systems and Communication Protection (SC)

System and Information Integrity (SI)

Appendix C: Privacy Control Section

Authority and Purpose (AP)

Accountability, Audit, and Risk Management (AR)

Data Quality and Integrity (DI)

Data Minimization and Retention (DM)

Individual Participation and Redress (IP)

Security (SE)

Transparency (TR)

Use Limitation (UL)

Appendix D: Glossary

Appendix E: Acronyms

Appendix F: Authorities

1. Federal Directives and Policies

2. Statutes

3. HHS Policy

4. OMB Policy and Memoranda

5. NIST Guidance

Appendix G: Minimum Set of HHS Roles Assigned Significant Responsibilities for Information Security

Appendix H: System Component Inventory Requirements

Appendix I: Information System Media

Information Systems Security and Privacy Policy

1. Purpose

The Department of Health and Human Services (HHS), Office of the Chief Information

Officer (OCIO), HHS-OCIO Information Systems Security and Privacy Policy (henceforth

“the Policy”) provides direction to the information technology (IT) security programs of

Operating Divisions (OpDivs) and Staff Divisions (StaffDivs) for the security and privacy of HHS data in accordance with the Federal Information Security Management Act of 2002

(FISMA).

The Policy is a reissuance in order to comply with the updated requirements of the National

Institute of Standards and Technology’s (NIST) Special Publication (SP) 800-53, Revision

4, as amended. This Policy establishes comprehensive IT security and privacy requirements for the IT security programs and information systems of OpDivs and StaffDivs. For the controls that are to be applied without needing any specific OpDiv parameters, this Policy will be the authoritative source. OpDivs do not have to develop internal policies to supplement the stated requirements. The Policy also includes the complementary HHS-

OCIO Information Systems Security and Privacy Policy Control Section (henceforth the

“Control Section”), which replaces the previous Information Security and Privacy Policy

Handbook. The Control Section outlines IT security and privacy policy requirements for IT security and privacy programs and information systems in more detail, and is organized according to information assurance (IA) control families (as defined by NIST SP 800-53) to make the document easy to use and scalable for the future.

This Policy supersedes the HHS-OCIO-2011-0003, Policy for Information Systems Security and Privacy, dated July 7, 2011, and incorporates retired policies HHS-OCIO-2009-0003, Policy for Information Systems Security and Privacy, HHS-OCIO-2007-0002.001, Policy for Department-wide Information Security. This document does not supersede any other applicable law or higher level agency directive, policy, or guidance. All references noted below are subject to periodic revision, update, and reissuance.

The Policy codifies the Department’s authority to develop, document, implement, and oversee a Department-wide IT security and privacy program to provide IT security and privacy for the information and information systems that support the operations and assets of the Department, including those provided or managed by another Federal agency, contractor, or other source. OpDivs and StaffDivs must comply with and support the implementation of a Department-wide IT security and privacy program, to include compliance with Federal requirements and programmatic policies, standards, procedures, and IT security controls.

2. Background

The HHS Cybersecurity Program (henceforth “the Program”) has evolved and matured over the last several years as new Federal requirements have been published, as advances in technology have been made, and as new threats to the Department’s infrastructure have emerged. Additionally, concerns over the unauthorized disclosure of protected health information (PHI) and personally identifiable information (PII) have placed IT security and privacy issues at the forefront of the national dialogue, positively impacting the way in which public, private, and government organizations provide services and protect information.

To better serve IT security and privacy stakeholders, the Department recognized the need to appropriately incorporate, cross-reference, and organize its IT security and privacy policy requirements in a manner that clearly explains the scope and applicability of the requirements. The format in which those requirements are presented should be scalable to accommodate the modification or addition of new requirements over time. As a result, this

Policy was developed to incorporate privacy requirements as well as other requirements cross-referenced in individually-released Department policies, standards, and memoranda.

3. Scope

This Policy applies to all HHS organizational components (OpDivs and StaffDivs), and all personnel conducting business for, and on behalf of, the Department, whether directly or through contractual relationships. This Policy does not supersede any other applicable law, higher level agency directive, or existing labor management agreement in place as of the effective date of this Policy.

Department officials must apply this Policy to employees, contractor personnel, interns and other non-government employees conducting business for the Department, or on its behalf through contractual relationships or memoranda of agreement, when using HHS information systems or resources. All organizations collecting or maintaining information, or using or operating information systems on behalf of the Department, are also subject to the stipulations of this Policy. The content of and compliance with this Policy must be incorporated into applicable contract language, as appropriate.

Agencies shall use this Policy or may create a more restrictive OpDiv/StaffDiv policy which is in no way less restrictive, less comprehensive, or less compliant with, this Policy.

The Policy does not apply to any network or system that processes, stores, or transmits foreign intelligence or national security information under the cognizance of the Special

Assistant to the Secretary (National Security) pursuant to Executive Order (E.O.) 12333, United States Intelligence Activities, or subsequent orders. The Special Assistant to the

Secretary (National Security) is the point of contact (POC) for issuing IT security and privacy policy and guidance for these systems. Questions about the Health Information

Technology Economic and Clinical Health (HITECH) Act or the Health Insurance

Portability and Accountability Act of 1996 (HIPAA) Security Rule and the HIPAA Privacy

Rule should be directed to the HHS Office for Civil Rights (OCR).

The Department acknowledges that OpDivs/StaffDivs require flexibility in implementing this Policy. Variations in terminology may currently exist across the OpDivs/StaffDivs, and there may be variations in the titles of roles. These variations are acceptable.

For cases in which an OpDiv/StaffDiv cannot comply with these requirements, justification for noncompliance must be documented using the Department Information Security

Policy/Standard Waiver.

Justification may also be documented in security artifacts, such as security plans drafted pursuant to the NIST SP 800-37, which are subject to approval by the Authorizing Official

(AO) (formerly known as the Designated Approving Authority) or Authorizing Official

Designated Representative as part of an OpDiv/StaffDiv security authorization process.

4. Policy

4.1. Department-Mandated Controls

This section addresses mandates for the secure development, operations, and maintenance of information systems.

4.1.1 OpDivs/StaffDivs must use NIST SP 800-37, Guide for Applying the Risk

Management Framework to Federal Information Systems: A Security Life Cycle

Approach, as the methodology for the security assessment and authorization

(SA&A) of information systems (formerly known as “certification and accreditation” or “C&A”), in accordance with FISMA and direction from the

Office of Management and Budget (OMB).

4.1.2 OpDivs/StaffDivs must ensure that information systems provide adequate, risk-based protection in the control areas defined in the Federal Information

Processing Standard (FIPS) 200, Minimum Security Requirements for Federal

Information and Information Systems, by using the appropriate baseline security controls as established in NIST SP 800-53, Recommended Security Controls for

Federal Information Systems, in accordance with the impact level for the system as defined in FIPS 199, Standards for Security Categorization of Federal

Information and Information Systems.

4.1.2.1 For instances in which NIST directs agencies to make assignments and selections within the confines of NIST SP 800-53 controls, the Program created standard parameters which OpDivs/StaffDivs must utilize for systems categorized as Low, Moderate, or High. The term “the organization” is used throughout these controls to make clear that, unless a component is specifically mentioned, these are a baseline regardless of organizational component or system, and may be enhanced as necessary based on that component’s mission.

4.1.2.2 Deviations from the HHS assignments and selections within the Control

Section are permitted, providing the resulting parameters are consistent with NIST SP 800-53 or minimum government-wide parameters.

Exceptions cannot be granted to the controls themselves as they are

Federal Government-wide standards; however, the compensating security control policy applies (see Section 4.1.6).

4.1.2.3 OpDivs/StaffDivs may exercise flexibility in the solutions used to meet the control requirement, so long as the baseline requirement is met.

4.1.3 Information assurance and privacy activities conducted within the Department must be consistent with the guidance, methodologies, and intent prescribed by the

NIST SP series, in particular NIST SP 800-53, and other relevant Federal laws and guidance documents. It is incumbent upon each OpDiv to appropriately follow the steps in the NIST SP 800-37 Risk Management Framework (RMF) to select, implement, assess, authorize, and monitor such controls commensurate with a system’s FIPS 199 categorization.

4.1.4 As new Federal requirements are published, OpDivs/StaffDivs must ensure that systems that are in development comply with those newly published requirements before those systems are granted a security authorization, and that existing (i.e., operational) systems comply with the new requirements within one year.

4.1.4.1 If any issues are identified that would prevent the implementation of a new Federal requirement on a development system, the Information

System Security Officer (ISSO) or System Owner must bring this issue to the attention of the AO or Authorizing Official Designated

Representative as soon as the issue is identified so that a plan can be developed to implement or mitigate the requirement, or the risk can be accepted. When the final security authorization package is delivered, and it has been agreed that the requirement would not be implemented, the

AO or Authorizing Official Designated Representative must acknowledge the gap in the form of a Plan of Action and Milestones

(POA&M), and must indicate an anticipated time period when the requirement will be met or explicitly accept the risk to organizational operations and assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.

4.1.4.2 If a new Federal requirement cannot be implemented on an operational system, the ISSO or System Owner must bring this to the attention of the

AO or Authorizing Official Designated Representative. The AO or

Authorizing Official Designated Representative must acknowledge the gap in the form of a Plan of Action and Milestones (POA&M), and must either indicate an anticipated time period when the requirement will be met or document the risk-based decision not to comply with the requirement.

4.1.5 OpDivs/StaffDivs may employ compensating security controls only after the following conditions are met:

4.1.5.1 The OpDiv/StaffDiv selects the compensating security control(s) from the security control catalog in NIST SP 800-53, when applicable;

4.1.5.2 The OpDiv/StaffDiv develops a complete and convincing rationale and justification for how the chosen compensating security control(s) provide an equivalent security capability or level of protection for the information system; and

4.1.5.3 The OpDiv/StaffDiv assesses and formally accepts (i.e., in writing) the risk associated with employing the compensating security control(s) in the information system.

4.1.6 OpDivs/StaffDivs must review the use of compensating security controls, document those controls in the security plan and other appropriate security documentation for the information system, and request approval of those controls from the AO or Authorizing Official Designated Representative for the information system.

4.1.7 OpDivs/StaffDivs must apply the controls in the updated Control Section to their

IT security and privacy programs and to their information systems as appropriate.

The Program changed the IS2P and accompanying Handbook by integrating the

HHS minimum requirements into a copy of Revision 4, establishing the HHS minimum requirements for IT security and privacy programs within the

OpDivs/StaffDivs and to address common system security control questions that fall outside the scope of NIST SP 800-53.

4.2. OpDiv/StaffDiv Controls

This section establishes the authority of the OpDivs/StaffDivs to develop their own security controls for information systems.

4.2.1 OpDivs/StaffDivs may decide whether to issue any additional OpDiv/StaffDiv-wide security controls for OpDiv/StaffDiv information systems to augment the government and Department-wide controls specified herein. OpDivs/StaffDivs must ensure that parameters are established and documented for each parameterized control, unless set by the Department.

4.2.2 OpDivs/StaffDivs may develop system-specific security controls and parameters.

When needed and/or appropriate, it is an OpDiv/StaffDiv decision whether to set parameters OpDiv/StaffDiv-wide, on a system-by-system basis, or some combination thereof.

5. Information and Assistance

HHS OCIO policies and standards are posted on the following website:

http://www.hhs.gov/ocio/policy/index.html.

Direct any questions, comments, suggestions, or requests for further information to the

HHS Cybersecurity Program at HHS.Cybersecurity@hhs.gov or (202) 205-9581.

http://www.hhs.gov/ocio/policy/index.html mailto:HHS.Cybersecurity@hhs.gov

6. Effective Date/Implementation

The effective date of this Policy is the date the Policy is approved.

These policies and procedures will not be implemented in any recognized bargaining unit until the union has been provided notice of the proposed changes and given an opportunity to fully exercise its representational rights.

The HHS policies contained in this issuance must be exercised in accordance with Public

Law 93-638, the Indian Self-Determination and Education Assistance Act, as amended, and the Secretary’s policy statement dated December 14, 2010, as amended, titled U. S.

Department of Health and Human Services Tribal Consultation Policy. It is HHS policy to consult with Indian people to the greatest practicable extent and to the extent permitted by law before taking actions that affect these governments and people; to assess the impact of the Department’s plans, projects, programs, and activities on tribal and other available resources; and to remove any procedural impediments to working directly with tribal governments or Indian people.

7. Approved

/s/ July 30, 2014

Frank Baitman DATE

HHS Chief Information Officer

Appendix A: Roles and Responsibilities

1. Secretary of HHS

2. OpDiv Heads

3. Office of Finance (OF)/Assistant Secretary for Financial Resources (ASFR)/Chief

Financial Officer (CFO)

4. ASFR/Office of Grants and Acquisition Policy and Accountability (OGAPA)/Division of

Acquisition (DA)

5. Office of Security and Strategic Information (OSSI)

6. ASA/Deputy Assistant Secretary for Human Resources (DASHR)

7. ASA/Deputy Assistant Secretary for Information Technology (DASIT)/HHS Chief

Information Officer (CIO)

8. HHS Senior Agency Official for Privacy (SAOP)

9. Office of Information Security (OIS)/HHS Chief Information Security Officer (CISO)

10. OpDiv CIOs

11. OpDiv CISOs

12. HHS Computer Security Incident Response Center (CSIRC)

13. OpDiv Computer Security Incident Response Team (CSIRT)

14. HHS Privacy Incident Response Team (PIRT)

15. OpDiv Senior Official for Privacy (SOP)

16. OpDiv Privacy Act Contact

17. Authorizing Official (AO) or Authorizing Official Designated Representative

18. Security Control Assessor

19. Information System Security Officer (ISSO)

20. Program Executive

21. System Owner

22. Data Owner/Business Owner

23. Website Owner/Administrator

24. Contingency Planning Coordinator

25. System Developer and Maintainer

26. System/Network Administrator

27. Contracting Officers and Contracting Officer’s Representative

28. Project/Program Manager

29. Human Resource Officer

30. Supervisor

31. All Users

32. HHS Records Officer

33. HHS Privacy Act Officer

1. Secretary of HHS

The responsibilities of the Secretary of HHS include, but are not limited to:

1.1 Ensuring that a Department-wide IT security and privacy program is developed, documented, and implemented to provide security for all systems, networks, and data that support Department operations;

1.2 Ensuring that IT security and privacy management processes are integrated with

HHS strategic and operational planning processes;

1.3 Ensuring the provision of resources necessary to administer the Program;

1.4 Protecting information systems and data by allocating resources commensurate with the risk and magnitude of harm posed by unauthorized access, modification, disclosure, disruption, use, and/or destruction; or as recommended by law;

1.5 Ensuring that senior HHS officials provide IT security and privacy for operations and IT resources under their control;

1.5.1 Delegating to the HHS CIO the authority to ensure compliance with the

Program;

1.5.2 Ensuring that HHS has trained Federal and contractor personnel to support compliance with the Program; and

1.5.3 Ensuring that the HHS CIO, in coordination with the OpDiv CIOs, reports annually on the effectiveness of the Program and on any required remedial actions.

1.6 Establishing, through the development and implementation of policies, the organizational commitment to information security and privacy, and the actions required to effectively manage risk and protect the core missions and business functions being carried out by the organization; and

1.7 Establishing appropriate accountability for information security and privacy, and providing active support and oversight of monitoring and improvement for the information security and privacy program.

2. OpDiv Heads

The responsibilities of each OpDiv Head include, but are not limited to:

2.1 Providing IT security and privacy protections commensurate with the risk and magnitude of harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of the following:

2.1.1 Information collected or maintained by or on behalf of the OpDiv; and

2.1.2 Information systems used or operated by the OpDiv, a contractor of the

OpDiv, or another organization on behalf of the OpDiv.

2.2 Complying with the requirements of FISMA (Title III of the E-Government Act) and Department-related policies, procedures, standards, and guidelines, including:

2.2.1 IT security and privacy requirements promulgated under OMB Circular

A-130, Appendix III; and

2.2.2 IT security and privacy standards and guidelines issued by OMB in accordance with NIST guidance, including Presidential Directives such as Homeland Security Presidential Directive 12 (HSPD-12), Policy for a

Common Identification Standards for Federal Employees and

Contractors.

2.3 Ensuring that IT security and privacy management processes are integrated with

OpDiv strategic and operational planning processes;

2.4 Ensuring that senior OpDiv officials provide IT security and privacy for the information and information systems that support the operations and assets under their control;

2.5 Designating a senior OpDiv official as the OpDiv CIO, and delegating to the

OpDiv CIO the authority to ensure compliance with the security requirements imposed on the OpDiv under FISMA;

2.6 Delegating responsibility and authority for management of OpDiv IT security and privacy programs to the OpDiv CIOs;

2.7 Ensuring that the OpDiv has trained personnel sufficiently to assist the OpDiv in complying with the security and privacy requirements under FISMA and

Department policies; and

2.8 Ensuring that the OpDiv CIO, in coordination with other senior OpDiv officials, reports annually to the OpDiv Head on the effectiveness of the OpDiv IT security and privacy program, including the progress of any remedial actions.

3. OF/ASFR/CFO

The responsibilities of the OF/ASFR/CFO include, but are not limited to:

3.1 Coordinating the Department’s internal controls program to ensure comprehensiveness and to establish responsibility for uniform security level designations for the financial management system according to the guidelines of

OMB Circular A-127, Financial Management Systems; and

3.2 Targeting/selecting entities to be reviewed per OMB Circular A-123, Management's Responsibility for Internal Control, applying risk-based, business-driven logic to maximize the effectiveness of the evaluations.

4. ASFR/OGAPA/DA

The responsibilities of the ASFR/OGAPA/DA include, but are not limited to:

4.1 Partnering with the HHS CIO and the Program to develop and implement IT security and privacy-related contract clauses for incorporation in all current and future contracts; and

4.2 Ensuring that contracting officers (COs) enforce the requirements of IT security and privacy clauses.

5. OSSI

The responsibilities of OSSI include, but are not limited to:

5.1 Providing overall leadership for the development, coordination, application, and evaluation of all policies and activities within the Department that relate to physical and personnel security, the security of classified information, and the exchange and coordination of national security-related strategic information with other Federal agencies and the national security community, including national security-related relationships with law enforcement organizations and public safety agencies;

5.2 Providing current and timely intelligence or national security information to the

HHS CSIRC and OpDiv CSIRCs and other key personnel responsible for incident response;

5.3 Ensuring the implementation of communications security, including the use of secure telecommunications equipment and classified information systems, for the discussion and handling of classified information in support of the detection, defense, and response to security and privacy vulnerabilities, threats, and incidents;

5.4 Protecting employees and visitors and Department-owned and -occupied critical infrastructure;

5.5 Assuring the integration of strategic medical, public health, biomedical, and national security information;

5.6 Managing and administering the flow of classified information;

5.7 Providing national security information services to all components within the

Office of the Secretary (OS); and

5.8 Approving visits by a foreign national to any HHS laboratory or other facility designated as Critical Infrastructure.

6. ASA/DASHR

The responsibilities of the ASA/DASHR include, but are not limited to:

6.1 Partnering with the HHS CIO, OpDivs, and system administrators who operate critical systems to develop, implement, and oversee personnel security controls for access to sensitive information (as defined by the HHS Standard for the

Definition of Sensitive Information); and

6.2 Ensuring that personnel officers notify the OpDiv ISSO, or designated POC for physical and logical access controls, of an employee’s separation within one business day.

7. ASA/DASIT/HHS CIO

The responsibilities of the HHS CIO include, but are not limited to:

7.1 Primary responsibility and authority for management of the Department’s IT security program;

7.2 Ensuring HHS compliance with Federal regulations and FISMA IT security and privacy program implementation requirements;

7.3 Ensuring the development and maintenance of a Department-wide IT security and privacy program to include the development and implementation of policies, standards, procedures, and IT security controls resulting in adequate security for all organizational information systems and environments of operation for those systems;

7.4 Requiring the development and implementation of protections for HHS information and information systems commensurate with the risk and magnitude of harm posed by unauthorized access, modification, disclosure, disruption, use, and/or destruction, or as recommended by law;

7.5 Ensuring the dissemination of Department-wide IT security and privacy policy for OpDiv review and comment;

7.6 Reporting annually, in coordination with OpDiv/StaffDiv Heads, to the

Secretary of HHS on the effectiveness of the Program, including progress of remedial actions;

7.7 Appointing the HHS CISO to fulfill the responsibilities of the CIO in developing and maintaining a Department-wide IT security and privacy program;

7.8 Defining and establishing the minimum security control requirements in accordance with data sensitivity and system criticality;

7.9 Preparing any report that may be required of HHS to satisfy the reporting requirements of OMB Circular A-130 and FISMA;

7.10 Coordinating with the Secretary of HHS to ensure the provision of resources necessary to administer the Program;

7.11 Providing advice and assistance to OS and other senior management personnel to ensure that information resources are acquired and managed for the

Department in accordance with the goals of the Capital Planning and Investment

Control (CPIC) process;

7.12 Determining, based on organizational priorities, the appropriate allocation of resources dedicated to the protection of the information systems supporting the organization's missions and business functions;

7.13 Providing leadership for developing, promulgating, and enforcing agency information resource management policies, standards, and guidelines, and for procedures on data management, enterprise performance life cycle (EPLC) management, security, telecommunications, IT reviews, and other related areas;

7.14 Establishing, implementing, and enforcing a Department-wide framework to facilitate an incident response program, ensuring proper and timely reporting to the United States Computer Emergency Readiness Team (US-CERT);

7.15 Establishing a Department-wide framework to facilitate the development of

Privacy Impact Assessment (PIA) Summaries for all Department systems, as instructed by OMB;

7.16 Primary authority to resolve any disputes from Office of Inspector General

(OIG) reviews and audits that cannot be resolved at the OpDiv level;

7.17 Overseeing personnel with significant responsibilities for information security and ensuring that the personnel are adequately trained;

7.18 Assisting senior organizational officials concerning their security responsibilities;

7.19 Performing the Risk Executive function for the Department;

As the Department’s Risk Executive, with the support of the HHS CISO, the HHS CIO also works closely with AOs across the OpDivs/StaffDivs and their designated representatives to execute the following responsibilities:

7.20 Ensuring information security considerations are integrated into programming/planning/budgeting cycles, enterprise architectures, and acquisition/system development life cycles;

7.21 Ensuring information systems are covered by approved security plans and are authorized to operate;

7.22 Ensuring information security-related activities required across the organization are accomplished in an efficient, cost-effective, and timely manner;

7.23 Ensuring a centralized reporting process is in place for appropriate information security-related activities; and

7.24 Executing the RMF tasks as outlined in NIST SP 800-37.

8. HHS SAOP

Within HHS, the CIO serves in the role of SAOP. The responsibilities of the SAOP include, but are not limited to:

8.1 Ensuring the proper implementation of information privacy protections, including full compliance with Federal laws, regulations, and policies relating to information privacy, such as the Privacy Act of 1974 (henceforth, “Privacy

Act”) 5 U.S.C. Section 552a, and the E-Government Act of 2002;

8.2 Maintaining appropriate documentation regarding compliance with information privacy laws, regulations, and HHS policies;

8.3 Overseeing, coordinating, and facilitating the Department’s privacy compliance efforts, including reviewing documented information privacy procedures to ensure comprehensiveness and currency, and coordinating any necessary revisions;

8.4 Coordinating privacy-related reporting activities as mandated by Federal legislation and OMB guidance;

8.5 Approving the Department’s submission of the Privacy Management portion of the annual FISMA report;

8.6 Maintaining a central policy-making role in the Department’s development and evaluation of legislative, regulatory, and other policy proposals pertaining to information privacy issues, including those relating to the agency’s collection, use, sharing, and disclosure of personal information;

8.7 Ensuring that data sharing activities occur within applicable privacy laws and with appropriate safeguards;

8.8 Designating responsibility for oversight of the PIA process to the OpDiv SOP;

8.9 Establishing a framework to facilitate the development of PIA Summaries for all OpDiv systems, as instructed by OMB;

8.10 Ensuring PIAs are conducted for information systems and online collections, and coordinating submission of all Department PIA Summaries to OMB;

8.11 Reviewing and acknowledging the completion and accuracy of PIAs by designating PIAs as approved for Web publishing via the Department’s PIA reporting tool;

8.12 Allocating proper resources to permit identification and remediation of privacy weaknesses;

8.13 Ensuring the Department’s employees, contractors, and stakeholders receive appropriate privacy training;

8.14 Providing education programs regarding information privacy laws, regulations, policies, and procedures governing the Department’s handling of PII;

8.15 Serving as the Chair of the Privacy Incident Response Team (PIRT);

8.16 Reviewing and approving any use of a multi-session Web measurement and customization technology that collects PII;

8.17 Providing the public with notice of proposed use of a multi-session Web measurement and customization technology that collects PII, and an opportunity to comment on the proposed use;

8.18 Reviewing the Department’s practices related to the use of Web measurement and customization technologies annually and making the results of the review available to the public;

8.19 Consulting with OpDivs during the planning, implementation, and post-implementation review of a third-party Website or application; and

8.20 Designating responsibility to the HHS CISO for the management and oversight of the privacy components of FISMA and related OMB guidance.

9. OIS/HHS CISO

The responsibilities of the HHS CISO include but are not limited to:

9.1 Providing leadership in IT security and privacy policy, guidance, and expert advice among OpDivs and the StaffDivs in developing, promoting, and maintaining IT security and privacy measures to adequately and cost effectively protect and ensure the confidentiality, integrity and timely availability of all information in the custody of the Department, as well as the information systems required to meet the Department’s current and future business needs;

9.2 Assisting and advising the HHS CIO in the development, documentation, and implementation of the Program (e.g., issuing policy, maintaining situational awareness, and performing compliance oversight) in order to provide IT security and privacy safeguards for the electronic information and information systems that support the operations and assets of the Department, including those provided or managed by another Federal organization or bureau, contractor, or other source;

9.3 Ensuring that all IT resources are reviewed for compliance with established

Department and external policies, standards, and regulations;

9.4 Monitoring OpDiv/StaffDiv IT security and privacy program activities;

9.5 Fostering communication and collaboration among the Department’s security and privacy stakeholders to share knowledge and to better understand threats to

Department information;

9.6 Carrying out the CIO security and SAOP responsibilities under FISMA and overseeing the preparation of quarterly and annual FISMA reports;

9.7 Developing and implementing an IT security performance measurement program to evaluate the effectiveness of technical and non-technical IT security safeguards used to protect the Department’s information;

9.8 Coordinating OSSI requirements for personnel clearances, position sensitivity, and access to information systems with the appropriate office;

9.9 Ensuring that all HHS-owned telephony equipment is provided with system and physical protection;

9.10 Implementing a security incident monitoring program for all Department systems and networks;

9.11 Disseminating information on potential security threats and recommended safeguards;

9.12 Ensuring the Department-wide implementation of Federal policies and procedures related to IT security and privacy incident response;

9.13 Overseeing the HHS CSIRC and managing the resources that support HHS

CSIRC operations;

9.14 Ensuring, in coordination with the HHS CIO and ASFR/OGAPA/DA, that all IT acquisitions include Department security and privacy considerations;

9.15 Serving as the primary liaison for the CIO to AOs, System Owners, primary operational IT infrastructure managers1 , ISSOs, and SOPs;

9.16 Providing management and oversight of activities under IT critical information protection (CIP);

9.17 Serving, as necessary, as an Authorizing Official Designated Representative or

Security Control Assessor;

9.18 Executing the RMF tasks as listed in NIST SP 800-37.

10. OpDiv CIOs

The responsibilities of each OpDiv CIO2 are to provide leadership to activities including, but not limited to:

10.1 Reporting quarterly to the HHS CIO on the effectiveness of the OpDiv’s IT security and privacy program, including the progress of any remedial actions;

10.2 Appointing an OpDiv CISO to fulfill the responsibilities of the OpDiv CIO in maintaining the OpDiv IT security program;

10.3 Managing internal security reviews of the program business cases, alternatives analyses, and other specific investment documents;

10.4 Managing and certifying an inventory of all current and proposed investments containing an IT component in accordance with the HHS CPIC process;

1 The HHS role of the Primary Operational IT Infrastructure Manager maps to the NIST SP 800-37 role of Common Control Providers.

2 The OpDiv CIOs perform the OpDiv Risk Executive (function) on behalf of the OpDiv Heads.

10.5 Ensuring that policies, procedures, and practices are consistent with Department requirements in order to ensure that programs, systems, and data are secure and protected from unauthorized access that might lead to the alteration, damage, or destruction of automated resources, unintended release of HHS data, or denial of service (DoS);

10.6 Ensuring that all employees and contractors comply with Department and

OpDiv IT security and privacy policies;

10.7 Ensuring the establishment of a computer security incident response team

(CSIRT) to participate in the investigation and resolution of incidents within the

OpDiv;

10.8 Establishing, implementing, and enforcing an OpDiv-wide framework to facilitate an incident response program (including PII and PHI breaches) that ensures proper and timely reporting to HHS;

10.9 Managing an inventory of all major information systems, devices and other items per FISMA requirements and as required by OMB;

10.10 Ensuring mandatory security training, education, and awareness activities are undertaken by all personnel using, operating, supervising, or managing information systems;

10.11 Exercising primary responsibility and authority for management of the OpDiv’s

IT security program;

10.12 Serving as one of six Primary Operational IT Infrastructure Managers3 (applies to the CIO for the Centers for Disease Control and Prevention (CDC), Food and

Drug Administration (FDA), Indian Health Service (IHS), Centers for Medicare and Medicaid Services (CMS), National Institutes of Health (NIH), and OS).

When an OpDiv CIO performs as a Primary Operational IT Infrastructure

Manager, he/she is responsible for performing IT risk-management duties.

Where an information system relies (or partially relies) on one of the six

Primary Operational IT infrastructures, the associated Primary Operational IT

Infrastructure Manager(s) must concur with the risk acceptance by also signing the security authorization package as the AO;

10.13 Resolving any disputes from OIG reviews and audits at the OpDiv level, where possible. If disputes cannot be resolved, the disputes must be escalated to the

HHS CIO;

3 Reference HHS Secretary Memorandum: Security of Information Technology Systems, and HHS OCIO Memorandum: Process Guidance for

Security Risk-Based Decisions Involving the Primary Operational Information Technology Infrastructure Managers. The ASA internal realignment abolished the OS CIO position; those duties are now performed by the HHS CIO who serves as the Primary Operational IT

Infrastructure Manager for OS.

10.14 Developing a strategy for the continuous monitoring4 of security control effectiveness and any proposed or actual changes to the information system and its environment of operation5; and

10.15 Executing the RMF tasks as listed in NIST SP 800-37.

11. OpDiv CISOs

The responsibilities of each OpDiv CISO include, but are not limited to:

11.1 Leading OpDiv IT security and privacy programs and promoting proper IT security and privacy practices;

11.2 Supporting the HHS CISO in the implementation of the Program;

11.3 Fostering communication and collaboration among the OpDiv’s security and privacy stakeholders to share knowledge and to better understand threats to

OpDiv information;

11.4 Providing information about the OpDiv IT security and privacy policies to management and throughout the OpDiv;

11.5 Providing advice and assistance to other organizational personnel concerning the security of sensitive information and of critical data processing capabilities;

11.6 Advising the OpDiv CIO about security-related incidents in accordance with the security breach reporting procedures developed and implemented by the

Department and/or OpDiv;

11.7 Disseminating information on potential security threats and recommended safeguards;

11.8 Ensuring OpDiv-wide implementation of Department and OpDiv policies and procedures that relate to IT security and privacy incident response;

11.9 Collaborating with the PIRT Coordinator when the PIRT Coordinator is engaging the OpDiv POC for information collection and clarification, and sitting on the HHS PIRT while the breach is under investigation;

11.10 Coordinating with OpDiv Senior Official for Privacy to ensure privacy implications are addressed when PII incident response activities occur within the OpDiv;

4 The monitoring strategy may be included in the security plan to support the concept of near real-time risk management and ongoing authorization. The approval of the monitoring strategy may be obtained in conjunction with the security plan approval. The monitoring of security controls continues throughout the EPLC.

5 This is the responsibility of the System Owner or the Primary Operational IT Infrastructure Manager.

11.11 Ensuring that roles with significant security responsibilities are identified and documented per the HHS Memorandum: Role-Based Training of Personnel with

Significant Security Responsibilities;

11.12 Conducting security education and awareness training needs assessments to determine appropriate training resources and to coordinate training activities for target populations;

11.13 Supporting general privacy awareness and role-based training activities for all personnel using, operating, supervising, or managing information systems;

11.14 Assisting System Owners in establishing…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .