NCNA0000-20-01429 KW Security Statement of Work.docx
DOCX document 33 KB Posted
- Attached to
- SECURITY SYSTEM REPAIR: KEY WEST Federal contract opportunity
- Solicitation number
- 1305M2-20-Q-01429-NCNA
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ Combined Synopsis Solicitation.doc | DOC document | |
| Contractor Past Performance Reference Sheet.pdf | ||
| WD.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FKNMS KEY WEST SECURITY SYSTEM REPAIR
STATEMENT OF WORK
1. BACKGROUND
The National Oceanic and Atmospheric Administration’s Office of National Marine Sanctuaries (ONMS), Florida Keys National Marine Sanctuary (FKNMS) requires repairs and component replacements to portions of the closed network security system at the Key West office location.
2. GENERAL REQUIREMENTS
Portions of the FKNMS Key West security system entry access keypads and wiring were found to be damaged due to saltwater intrusion following Hurricane Irma that was initially undetected during the inspection of damage. Repair and/or replacement cabling, keypads, and other hardware shall be included in the bid pricing. The contractor shall remove and haul away damaged parts of the existing security system that are unable to be upgraded, and obtain, deliver and install, repair or replace parts listed in Section 3, Deliverables, of this document. The contractor will notify NOAA’s technical representative listed in Section 5 of this document once the contract is awarded and prior to scheduling any upgrades or installation. Hardware for the removal and installation and any special tools required are to be provided by the contractor. If there is any impact to the existing building structure it is to be repaired by the contractor.
3. DELIVERABLES
Deliver the following to NOAA ONMS Key West National Marine Sanctuary:
· Six replacement touchless entry pads
· Upgraded security software with user programming capabilities capable of running on a Windows 10 operation system.
· Repair and/or replacement where required of up to six mechanical door operators and up to six magnetic door position indicators, depending upon the extent of the electrical shorting that occurred from the hurricane damage. Two known door operators with panic bar-style devices, are known already to require replacement.
· Replacement where required of the existing building level controllers if required for integration into other hardware and software upgrades.
· Any additional hardware and software not listed above required for the integrated system to be operated upon delivery to the government.
· Detailed plans of any new components or repaired components requiring new instructions for operation, including notes for operation and maintenance of the system.
· 5-year manufacturer’s warranty.
· Component hardware and software deliverables must comply with specifications described in detail in Section 9, Information Technology and Security Considerations.
| 4. | PERIOD OF PERFORMANCE |
| September 1, 2020 – January 31, 2021 | |
| 5. | TECHNICAL REPRESENTATIVE |
John Genthert Facilities Coordinator NOAA/Florida Keys National Marine Sanctuary 305-809-4763Office 305-360-1179 Cell John.genthert@noaa.gov
6. GOVERNMENT POINT OF CONTACT (GPOC)
Kathleen Jamison Deputy Superintendent NOAA/Florida Keys National Marine Sanctuary 305-809-4689 Office 202-302-7600 Cell Kathleen.jamison@noaa.gov
7. INVOICING
All invoices shall be emailed to the GPOC.
8. DELIVERY ADDRESS
33 E. Quay Road Key West FL 33040
9. INFORMATION TECHNOLOGY AND SECURITY CONSIDERATIONS
This is not an IT acquisition, however, as the situation may require, the Contractor may have access to the NOAA network through computers provided by NOAA. There exists no current requirement for the Contractor to have access to any other DOC or NOAA IT systems, and no access to classified materials. The Contractor’s staff will be subject to DOC Security Processing Requirements for Contractor/Subcontractor Personnel Working on a Department of Commerce Site. The Contractor is required to comply with the DOC IT Security Program Policy & Minimum Implementation Standards available online at http://ocio.os.doc.gov.
The Contractor is required to meet the DOC IT Security Program Policy (ITSPP) and Commerce Information Technology Requirements (CITRs) (available at: https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements). DOC has issued Commerce Information Technology Requirements (CITRs) as policy enhancements to the DOC IT Security Program Policy and carries the same authority as the DOC ITSPP. The contractor is required to meet the NOAA IT Security Manual [NOAA policy] (available at: https://www.csp.noaa.gov/policies/manual/212-1301-V5-6-final.pdf). The DOC and NOAA policies identified above are sensitive documents and will be provide after contract award.
The Assessment and Authorization (A&A) requirements of Clause 48 CFR 1352.239-72 do not apply, and a Security Accreditation Package is not required.
The government will provide the necessary computer equipment and information to perform this contract. All work must be performed upon government furnished equipment and if additional hardware and/or software is/are needed, the Contractor must request the additional requirements from the Contracting Officer Representative (COR). It is a mandatory requirement for every NOAA IT user (government, Contractor, associate, or temporary personnel) to complete the NOAA Information Technology Security Awareness Course every year. Temporary personnel include visitors, guest workers, etc., who plan to work at a NOAA site and use NOAA IT resources. Both new and temporary employees must take the course within three days after initial issuance of NOAA IT equipment and annually.
The Contractor must use government furnished equipment (GFE), which is currently covered by an existing government Assessment and Authorization (A&A) package Contractor staff needing to perform work off-site using GFE shall sign all appropriate agreements and follow all appropriate regulations per NOS, NOAA, and DOC policies including NOAA and NOS property regulations. The Contractor shall comply with Help Desk and/or property requests to make the GFE available upon request to meet organizational property requirement and/or to maintain the GFE in accordance with the organizational defined security posture. All users who have been issued a Government furnished client endpoint computing device shall be accountable for the integrity and security of that device. The Contractor shall comply with existing and new NOS policies and memorandums specifically covering issued GFE.
It is the contractor’s responsibility to ensure Government Furnished desktops and or laptops are scanned, patched, and updated during the specified times mentioned above by keeping the desktop and laptops turned on and connected to the network when the devices are not being used, or by connecting laptops to the VPN or the internet when the devices are being used outside of the office. If an issue arises and require onsite helpdesk support, the contractor shall obtain helpdesk support at the Silver Spring location.
The Contractor shall safeguard GFE assigned for the duration of the contractor unless returned to the Government prior to the end of the contract. Lost, misplaced, or stolen GFE issued to the Contractor through this contract shall be reported to the Task Manager within 4 hours of detection. The Contractor shall assist with any security incident report filed related to the loss of the GFE and shall report to the Help Desk the GFE loss within 24 hours of detection. The Contractor or contractor staff assigned the GFE can be held accountable to reimburse the Government for cost of the GFE depending on the circumstance that resulted in the GFE loss.
The Contractor must consider IT Security controls throughout the lifecycle of this contract as outlined in NIST Special Publication 800-64 (http://csrc.nist.gov/publications/nistpubs/800-64-Rev2/SP800-64-Revision2.pdf).
The use of remote sensing technologies (e.g., unmanned aerial vehicles) will require additional compliance with DOC and NOAA policies including Privacy Act of 1975.
Cloud Services If the vendor proposes the use of cloud services, NOS requires an integrated technical solution that meets the security requirements below. These requirements apply to each PaaS, SaaS and/or IaaS tier to be managed by the Contractor and to any Contractor-supplied or third party supplied management interface that will be used to manage the service. The Contractor must meet adhere to the following security requirements:
1. Meet DOC and NOAA defined parameters for security control implementations;
2. Support Low and Moderate Impact IT Security Categorizations (per Federal Information Processing Standards Publication 199, Standards for Security Categorization of Federal Information and Information Systems" February 2004, and NIST Special Publication 800-60 Volume I & II, "Guide for Mapping Types of Information and Information Systems to Security Categories" August 2008);
3. Comply with DOC and NOAA Information Technology Security Policies;
4. Provide FIPS-201 compliant two factor authentication capability;
5. Provide Role-Based Access Control (RBAC) to services areas;
6. Possess a FedRAMP Agency Authorization to Operate (ATO) or Provisional Authorization to Operate (PATO) at Moderate Impact Security Categorization for the integrated technical solution (covering all functionality layered on top and the IaaS solution including the prime, integrator, broker and Infrastructure as a Service cloud service provider) throughout the length of this contract. The Contractor shall make the following reports available upon written request within five (5) business days and annually:
· Authorization Letter from General Services Administration GSA (or other Federal agency) providing its Authorization To Operate (ATO) through the FedRAMP program (FedRAMP Cloud Computing Security Requirements Baseline, http://cloud.cio.gov/document/fedramp-security-controls);
· Security Assessment Report http://cloud.cio.gov/fedramp/templateshttp://www.gsa.gov/portal/getMediaData?mediaId=172015)’
· Comprehensive inventory, description, risk assessment, and status of all existing Plan of Action and Milestones (POA&M);
· System Security Plan (http://cloud.cio.gov/fedramp/templates);
· Customer Responsibility Matrix identifying controls that the solution requires the Government to address:
· FedRAMP Control Implementation Summary (CIS) report (http://cloud.cio.gov/fedramp/templates);
· FedRAMP Control Tailoring Workbook (CTW) document (http://cloud.cio.gov/fedramp/templates);
· FedRAMP Security Assessment Plan (SAP) document (http://cloud.cio.gov/fedramp/templates);
· FedRAMP Self-Attestations (http://cloud.cio.gov/fedramp/templates).
7. Provide Government with on-site or remote access to perform annual security assessment activities;
8. Provide Government with access to System Security Package (SSP) and results of security tests performed at least annually;
9. Provide real-time access to VM system audit logs and scan data of technical solution utilized by NOAA;
10. Capability for VMs to integrate with DOC and NOAA Cybersecurity operation solutions:
· Include NOAA Security Operations Center (SOC) integration;
· Integrate into NOAA's implementation of ArcSight system providing real-time input data, which is physically located on the Silver Spring Metro Campus. TCP connection over SSL with sufficient bandwidth to send logs in a format ArcSight will accept;
· Integrate with NOAA Computer Incident Response Team (N-CIRT), for addressing suspected and actual incident handling, reporting and forensic data exchange to meet DOC, NOAA, and federal reporting requirements;
· Integrate with NOAA’s implementation of Homeland Security Presidential Directive 12 (HSPD-12) implementation for a Common Identification Standard for Federal Employees and Contractors (http://www.dhs.gov/homeland-security-presidential-directive-12);
· Integrate with NOAA Enterprise Continuous Monitoring Operations (ECMO) integration for meeting OMB memoranda M-10-15 and M-10-19, which requires all Federal agencies to continuously monitor security-related information from across the enterprise;
11. Ensure all NOAA data and applications (including VMs) must reside within the United States;
12. Provide an "Alternate Processing Site" in accordance with the NIST Security Control CP-7 (1), CP-7 (2), and CP-7 (3);
13. Provide role-based access controls and auditing of administrative actions;
14. Secure interface capabilities including but not limited to Secure Sockets Layer (SSL), Transport Layer Security (TLS), Internet Protocol (IP) Security (IPSec), and Secure Shell (SSH) for encrypted communications between NOAA locations and cloud-based services as well as between cloud-based services and the end users of NOAA applications on the Internet; and
15. Provide Government with full administrative control to the master account or its equivalent. A master account is defined as a highest (or root) level access mechanism to Government's information technology resources resident within the Contractor's cloud infrastructure. Full administrative control must support granular Role-based Access Controls (for example: Government granting access to cloud resellers/partners with limited access to the CSP financial and billing).
If the Contractor is proposing the use of custom developed software solutions (includes mobile application, web application and/or software product development), the Contractor must ensure secure management of user credentials (storing, transmitting, authenticating of user password must be encrypted). If the Contractor solutions use a Contractor developed or government furnished [mobile/web] application/ database/ network operating systems, the Contractor must:
1. DOC has issued Commerce Information Technology Requirements (CITRs) as policy enhancements to the DOC IT Security Program Policy and carries the same authority as the DOC ITSPP. The DOC ITSPP and DOC CITRs may not specifically identify [mobile/web] application/ database/ network operating systems, which may be applicable and will require Contractor to compliance with the requirements. The DOC policies will be provided to the Contractor at the start of the project. DOC policies are controlled unclassified information (CUI) and are restricted to only authorized personnel.
2. Throughout the lifecycle, the Contractor is required to incorporate security requirements. Development lifecycle must take into account the security controls catalogue contained within National Institutes of Standards and Technology’s (NIST) Special Publications 800-53 (SP 800-53) revision 4 Security and Privacy Controls for Federal Information Systems and Organizations.
· Organization’s Information System Security Officer (ISSO) will provide guidance to the Contractor for identifying security controls, documenting security controls and ongoing continuous monitoring of security controls.
· The Contractor must provide their security controls implementation including applicable architecture, diagrams, documentation, standard operating procedures supporting the development and operation of their solution. This documentation will be incorporated by the ISSO into appropriate Federal Information Security Management Act (FISMA) system security boundary, identified as NOAA6602.
3. This applies to all updates must undergo vulnerability scanning, secure baseline compliance scanning and mitigation of vulnerabilities and provide the appropriate documentation to the government for each update demonstrating this requirement has been met.
If the Contractor is proposing the use of mobile application, web application and/or software product development, appropriate planning needs to be included during the assessment of needs, requirements, development and testing. Security requirements must be incorporated into the mobile application development lifecycle along with the user functional requirements.
1. The developer must select and document secure baseline/checklist (see National Checklist Program below) for the application/software being developed to address IT security issues.
2. The developer must document any deviations/exceptions from selected secure baseline. This secure baseline best practice must be implemented throughout development of product.
3. The developer must perform a full source code review and application code scanning for vulnerabilities must be conducted. Any identified source code review deficiencies or scanner-identified vulnerabilities must be mitigated and any other generated supporting documentation including the raw vulnerability scanner reports must be provided. This applies to all source code updates that must undergo a full source code review, full source code scanning and mitigation of vulnerabilities with the appropriate documentation provided to the government for each update demonstrating this security requirement has been met. Source code must be provided to the government for each product update, enhancement and/or security flaw remediation.
4. If the solution includes a network operating system (i.e., Windows, Linux, etc.) or web server (i.e., Apache, Microsoft IIS, etc.) then all components (application, web server and network operating system) must have security checklist implemented and documented. System development lifecycle management of the application, web server and network operating system is expected. The government will provide, upon request, the current secure benchmarks being used for existing technologies to ensure compatibility. This applies to all updates must undergo vulnerability scanning, secure baseline compliance scanning and mitigation of vulnerabilities with the appropriate documentation provided to the government for each update demonstrating this requirement has been met.
5. The developer must ensure the solution doesn’t contain any spyware, malicious software, coding flaws or programming backdoors to circumvent the application functionality or the security of the application as described by the government. The solution must not access data stored on the device or request end user information without following all government (including OMB) requirements. The solution must not transmit stored data from the installed device without clearly notifying, fully describing the required data being transmitted and receiving the government’s approval.
If the Contractor is proposing the use of database development, appropriate planning needs to be included during the assessment of needs, requirements, development and testing. Security requirements must be incorporated into the database development lifecycle along with the user functional requirements.
1. The databases must implement a secure baseline checklist (see National Checklist Program below) for each database and perform databases vulnerability scanning for vulnerabilities.
2. The databases weaknesses as identified from any vulnerability/compliance scanner identified vulnerabilities must be mitigated. Mitigation supporting artifacts must include any generated supporting documentation including raw vulnerability scanner reports and documented security checklist with deviations, if deviations exist, must be provided.
3. This applies to all updates must undergo vulnerability scanning, secure baseline compliance scanning and mitigation of vulnerabilities with the appropriate documentation provided to the government for each update demonstrating this requirement has been met.
4. If the solution includes a network operating system (i.e., Windows, Linux, etc.) then both (database and network operating system) must have security checklist implemented and documented. System development lifecycle management of the database and network operating system is expected.
All electronic provided information by the Contractor must undergo malicious software scanning using a commercial anti-virus and anti-spyware software to ensure the information is free of known malicious software. The Contractor must work with the COR prior to sending the information to establish a secure method for transfer. One option could be a file encrypted with a password using a product like WinZip. The Contractor must encrypt any sensitive information that will be sent electronically (i.e., email); sensitive information includes, but not limited to:
· All information describing the implementation, configuration, settings, etc. for solution being developed (including Information Technology (IT) configuration, IT management, IT security, IT administration, IT architecture and/or information obtained while performing privileged access roles),
· The source code and database schema,
· The vulnerability scanning, secure baselines scanning, mitigation results,
· The secure baseline deviations,
· Internet Protocol, subnet mask and similar identification,
· System or component inventory information (hostname, IP address, MAC address, location, operating system, etc.),
· Personally identifiable information (PII) and/or Business-identifiable information (BII).
The Contractor must protect sensitive information and/or non-public information from unauthorized disclosure or modification. The Contractor working with the ISSO to determine the applicable sensitive security requirements that must be addressed. Sensitive information includes personally identifiable information (PII), Business-identifiable information (BII), Information Technology (IT) configuration, IT management, IT security, IT administration, IT architecture and/or information obtained while performing privileged access roles.
The Contractor includes the necessary product support and supporting documentation for the hardware and/or software that allows the sanitization (following NIST Special Publications 800-88 Guidelines for Media Sanitization, http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf) of the hardware and/or software upon the disposal of the product.
The Contractor must provide sufficient document demonstrating the software being provided complies with Office of Management and Budget Memorandum M-07-18 entitled Ensuring New Acquisitions Include Common Security Configurations and the FAR 39.101(d) regulations involving NIST common security configuration checklists including Federal Desktop Core Configuration (FDCC) or United States Government Configuration Baseline (USGCB) initiative. More information is available at National Checklist Program (NCP), (http://checklists.nist.gov), is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low-level guidance on setting the security configuration of operating systems and applications.
The Contractor must provide sufficient documentation that demonstrates the acquiring information technology has implemented common security configurations. Common security configurations are available from the National Institute of Standards and Technology’s website at http://checklists.nist.gov.
The Contractor must ensure that the product being purchased complies with the Homeland Security Presidential Directive 12 (HSPD-12) requirements from FAR 4.1302 stating: (a) In order to comply with FIPS PUB 201, agencies must purchase only approved personal identity verification products and services. (b) Agencies may acquire the approved products and services from the GSA, Federal Supply Schedule 70, Special Item Number (SIN) 132-62, HSPD-12 Product and Service Components, in accordance with ordering procedures outlined in FAR Subpart 8.4.
The Contractor must ensure that the product being purchased complies with Internet Protocol Version 6 (IPv6) requirements from FAR part 11.002 requirements which state that unless the agency Chief Information Officer waives the requirement, when acquiring information technology using Internet Protocol, the requirements documents must include reference to the appropriate technical capabilities defined in the USGv6 Profile (NIST Special Publication (SP) 500-267- http://www.nist.gov/itl/antd/usgv6.cfm) and the corresponding declarations of conformance defined in the USGv6 Test Program (http://www-x.antd.nist.gov/usgv6/index.html). To meet this requirement each DOC acquisition of IP protocol technology must express requirements for IPv6 capabilities in terms of the USGv6 Profile (i.e., using the USGV6 Capabilities Check List) and vendors must be required to document their product’s support of the requested capabilities through the USGv6 test program (reference http://www.antd.nist.gov/usgv6/) using the USGv6 Suppliers Declaration of Conformity.
The Contractor must provide sufficient document demonstrating the software being provided meets the following:
1. The standard installation, operation, maintenance, update and/or patching of software shall not alter the configuration settings from the approved FDCC/ USGCB/other secure configuration.
2. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
The Contractor must provide all supporting documentation or a reference to obtain the necessary material which describes the security capabilities, the design and development processes and the testing and evaluation procedures used by the product or services being provided for this acquisition. The Contractor must provide all supporting documentation or a reference to obtain the necessary material that describes all product or service updates and enhancements as they are implemented. The product or service supporting documentation could be the user and system administrator guides, which is documents the functional properties of the security controls employed to permit the analysis and testing of the security controls.
Ensuring Knowledge Transfer The Contractor shall provide, as necessary, periodic training whenever the Contractor introduces new processes, new technology or when the Contractor changes existing processes or technology. All processes and technology changes must be thoroughly documented. It is the responsibility of the Contractor to mentor government-identified personnel regarding the new or changed process or technologies. When there is a transition within the Contractor’s staffing, the Contractor shall be responsible for ensuring the incoming personnel is fully versed on any outstanding project deadlines, roles and responsibilities before the new person arrives on the job. In the case of when the services of the Contractor are no longer required, the Contractor shall begin the knowledge transfer to government personnel or its designated representative at least three weeks before the final contract termination date.
Protecting Against Data Dissemination and Restrictions Against Disclosure The Contractor agrees, in the performance of this contract, to keep the information furnished by the Government and designated by the Contracting Officer or Contracting Officer’s Technical Representative in the strictest confidence. The Contractor also agrees not to publish or otherwise divulge such information in whole or part, in any manner or form, nor to authorize or permit others to do so, taking such reasonable measures as are necessary to restrict access to such information while in the Contractor’s possession, to those employees needing such information to perform the work provided herein, i.e., on a “need to know” basis. The Contractor agrees to immediately notify the Contracting Officer in writing in the event that the Contractor determines or has reason to suspect a breach of this requirement.
The Contractor agrees that it will not disclose any information described in performance of this activity to any persons or individual unless prior written approval is obtained from the Contracting Officer. Whenever the Contractor is uncertain with regard to the proper handling of information/data under the contract, the Contractor shall obtain a written determination from the Contracting Officer. The Contractor agrees to insert the substance of this clause in any consultant agreement or subcontract hereunder.
The Contractor is required to comply with the Department of Commerce’s Commerce Acquisition Manual’s (CAM) 1337.70 Personnel Security Requirements (http://oam.eas.commerce.gov/docs/CAM1337.70%28Security%29.pdf).
File details come from the government source that posted it. Updated .