Attachment B - NSF 030.pdf
PDF 240 KB Posted
- Attached to
- EAC BAA—Improving NSF’s Analytic Capacity Federal contract opportunity
- Solicitation number
- NSFEACBAA-22-01
About this file
This document contains a Broad Agency Announcement from the National Science Foundation seeking proposals from for-profit businesses, universities, and other institutions of higher education to conduct research projects supporting the strategic objectives of the NSF. Specifically, the NSF is interested in proposals using machine learning techniques to analyze the NSF's portfolio of investments by different characteristics in order to improve the NSF's analytic capacity. The deadline for proposals is not specified. The research conducted under awards made from this solicitation would support the NSF in analyzing trends in its investment portfolio and gaining insights to aid strategic decision making.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment C - Response from the Government.pdf | ||
| Attachment A - NSF Technical Reference Model.pdf | ||
| Amendment 0003_EAC BAA.pdf | ||
| Amendment 0002_EAC BAA.pdf | ||
| Amendment 0001_EAC BAA.pdf | ||
| EAC BAA Final.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NSF 030 - SECURITY REQUIREMENTS AND ACCESS TO NATIONAL SCIENCE
FOUNDATION FACILITIES AND UNCLASSIFIED INFORMATION TECHNOLOGY
RESOURCES (MAY 2021-VERSION 3)
Prescription for inclusion: Include this clause in solicitations and contracts/orders when the Contractor requires an NSF ID Badge, Local Area Network (LAN) account to access government information, NSF IT Systems, or needs access to NSF beyond the NSF Visitor Access process.
Applicable Laws and Regulations
1. Records Management by Federal Agencies [44 USC 31]
2. Privacy Act of 1974 as amended [5 USC 552a]
3. Federal Information Security Modernization Act (FISMA) of 2014 [Title III, PL 113-
283]
4. Homeland Security Presidential Directive 12 (HSPD-12), “Policy for a Common
Identification Standard for Federal Employees and Contractors”
5. Presidential Policy Directive 21 (PPD-21), "Critical Infrastructure Security and
Resilience"
6. Federal Agency Responsibilities for Review, Reporting, and Publication Under the
Privacy Act [OMB Circular A-108, as amended]
7. Management's Responsibility for Enterprise Risk Management and Internal Control
[OMB Circular A-123, Revised 7/15/2016]
8. Managing Information as a Strategic Resource [OMB Circular A-130, revised 7/28/2016]
9. Guidance on Inter-Agency Sharing of Personal Data – Protecting Personal Privacy [OMB
M-01-05]
10. Safeguarding Against and Responding to the Breach of Personally Identifiable
Information [OMB M-07-16]
11. Ensuring New Acquisitions Include Common Security Configurations [OMB M-07-18]
12. Completing the Transition to Internet Protocol Version 6 (IPv6) [OMB M-21-07]
13. Controlled Unclassified Information [CFR 2002]
Applicable Standards and Guidance
1. Security Requirements for Cryptographic Modules [FIPS Publication 140-3]
2. Standards for Security Categorization of Federal Information and Information Systems
[FIPS Publication 199]
3. Minimum Security Requirements for Federal Information and Information Systems [FIPS
Publication 200]
4. Personal Identity Verification (PIV) of Federal Employees and Contractors [FIPS
Publication 201-2]
5. Guide for Developing Security Plans for Federal Information Systems [NIST SP 800-18]
6. Guide for Conducting Risk Assessments [NIST SP 800-30]
7. Contingency Planning Guide for Federal Information Systems [NIST SP 800-34]
8. Risk Management Framework for Information Systems and Organizations: A System
Life Cycle Approach for Security and Privacy [NIST SP 800-37]
9. Managing Information Security Risk: Organization, Mission, and Information System
View [NIST SP 800-39]
10. Security and Privacy Controls for Information Systems and Organizations [NIST SP 800- 53]
11. Control Baselines for Information Systems and Organizations [NIST SP 800-53B]
12. Guide for Mapping Types of Information and Information Systems to Security Categories
[NIST SP 800-60]
13. Computer Security Incident Handling Guide [NIST SP 800-61]
14. Security Considerations in the System Development Life Cycle [NIST SP 800-64]
15. Technical Guide to Information Security Testing and Assessment [NIST SP 800-115]
16. Guide for Security-Focused Configuration Management of Information Systems [NIST
SP 800-128]
17. Information Security Continuous Monitoring for Federal Information Systems and
Organizations [NIST SP 800-137]
18. Supply Chain Risk Management Practices for Federal Information Systems and
Organizations [NIST SP 800-161]
19. Framework for Improving Critical Infrastructure Cybersecurity [NIST Cybersecurity
Framework 1.1, April 16, 2018]
20. Advanced Encryption Standard [FIPS 197]
21. Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
[NIST SP 800-171R2]
NSF Policies (NSF Policies are available through the Contracting Officer)
1. NSF Manual 7, "Information Security Handbook"
2. NSF Personnel (PER) Manual
3. NSF Bulletin 13-09 Onboarding and Separation Policy for Contractors
4. NSF Bulletin 19-14 Mobile Communications Devices
5. NSF Policy Regarding the Privacy of Sensitive Information
6. NSF Privacy Impact Assessment Policy
7. NSF Privacy Impact Assessment Guide and Template
8. NSF Privacy Threshold Analysis Guide and Template
9. NSF Privacy Breach Plan
10. NSF Computer Security Incident Response and Recovery Procedure
11. Information Security and Privacy Continuous Monitoring Program
1. General
a. Policy Compliance - All Contractor personnel performing under this contract and requiring access to NSF information systems, networks, or information must comply with all Federal Information Security Modernization Act (FISMA), Office of Management and Budget (OMB), Homeland Security Presidential Directive 12 (HSPD-12), National Institute of Standards and Technology (NIST) and NSF IT security and privacy policies, procedures and guidance.
b. Compliance with Onboarding and Separation Procedures - The Contractor is responsible for its employees’ conduct and establishing in- and out-processing procedures that ensure accomplishment of the actions identified in this clause.
c. Contractor Self-Identification - In accordance with requirements set forth in the
Federal Acquisition Regulation (FAR) and guidance issued by OMB, all Contractor personnel attending meetings, interacting with NSF staff to complete work assignments, and working in other situations where their Contractor status is not obvious to third parties or internal agency staff, are required to identify themselves as Contractor employees, including email signature blocks and voicemail. Contractors interacting with Government staff or the public for purely administrative functions, such as for forwarding telephone calls, may be exempted from this self-identification requirement.
d. Expiration of Contract - Contractor personnel access to NSF facilities for work performance will be revoked upon expiration of this contract or task orders issued hereunder.
e. Incorporation in Subcontracts - The Contractor shall incorporate the substance of this clause in all subcontracts.
2. Personnel Onboarding
a. Federal Identity Card - Contractor personnel assigned to work at NSF facilities shall be issued a Personal Identity Verification (PIV) card that permits their entrance to NSF facilities without going through visitor access processes. Contractor personnel may also be granted certain other privileges such as NSF email accounts and/or access to NSF information systems. This access shall be provided solely at the discretion of NSF, and may be revoked or withdrawn at any time, without notice or cause, by the Contracting Officer.
b. Background Investigation - Contractor personnel requiring access to systems operated by a Contractor for the NSF or interconnected to an NSF network, or requiring access to NSF information shall be investigated at an appropriate level. The Contractor shall not work on the contract until a favorable determination is granted. The FBI National Criminal History Check must be completed, and the investigation must be released to the Defense Counterintelligence and Security Agency (DCSA) before the cards are issued. NSF shall submit the Tier 1 (or higher level) investigation to DCSA using the standard personnel investigation forms listed in this clause, see 2.d. Required Forms. Contractors are required to report to the Division of Administrative Services (DAS) ID Card office during business hours to be electronically fingerprinted, inputted into the online Electronic Questionnaire for Investigations Processing (eQIP) system and provide other required documents to begin the investigations process. The Contractor shall submit the required forms to the NSF Personnel Security Office within five (5) days after award or assignment of an individual to a position requiring investigation.
c. Level of Investigation - Guidance for selecting the appropriate level of investigation is based on the risk of adverse impact to the NSF. The levels of risk for which investigation is required is determined by the DCSA Position Designation Record (PDR) tool. For example, IT positions typically result in a Tier 1 or Tier 2 investigation level.
i. DCSA Tier 1: Individuals having privileged access or limited privileged access to systems whose misuse can cause significant adverse impact to NSF programs. These systems include, for example, those that interconnect with a NSF network in a way that exceeds access by the general public, such as bypassing firewalls; and systems operated by a Contractor for NSF whose function, data, or information has substantial cost to replace, even if these systems are not interconnected with an NSF network.
ii. DCSA Tier 2: Individuals having privileged access or limited privileged access to systems whose misuse can cause very serious adverse impact to NSF systems and programs.
d. Required Forms - Investigation for individuals shall employ forms appropriate for the level of risk as follows:
i. DCSA Tier 1: Electronic fingerprints, online Standard Form (SF) 85 Questionnaire for Non-Sensitive Positions, Official Form (OF) 306 Declaration for Federal Employment, Credit Report Notice Form and resume.
ii. DCSA Tier 2: Electronic fingerprints, Electronic and Standard Form (SF) 85- P Questionnaire for Public Trust Positions, Official Form (OF) 306 Declaration for Federal Employment, Credit Report Notice Form and resume.
e. Proof of Investigation - Investigation of Contractor personnel may be waived by the
Personnel Security Office for individuals in cases where proof of prior investigation at the Tier 1, 2 or higher level within the last two years can be obtained.
f. Physical Access to NSF Headquarters - Contractor personnel requiring routine physical access to NSF facilities for more than six months require a Personal Identity Verification (PIV) or Personal Identity Verification Interoperability (PIV-I) card.
g. Records Management Training – The Contractor shall ensure that its employees, in the performance of the contract, receive Records Management Training as it is made available in the learning management system.
h. IT Security and Privacy Awareness Training - The Contractor shall ensure that its employees, in performance of the contract, receive initial IT Security and Privacy Awareness Training before being granted access to NSF systems and networks, and receive refresher IT Security and Privacy Awareness Training annually. The Contractor may use web-based training available from NSF to meet this requirement.
i. Rules of Behavior - The Contractor shall ensure that its employees, in performance of the contract, sign and submit the “National Science Foundation (NSF) IT Security and Privacy Awareness Training Rules of Behavior” before receiving access to NSF systems and networks. Additionally, the Rules of Behavior will be signed and submitted annually at the completion of the IT Security and Privacy Awareness Training referenced in 2.h. above.
j. Insider Threat Training – If a Contractor receives, or must hold, a national security clearance, the Contractor shall ensure its contractor(s), in the performance of the contract, receive NSF Insider Threat training within 30 days of receiving a clearance, and annually thereafter.
k. Contractor Separation - At any time during the term of this contract or task orders issued hereunder, Contractor personnel issued a PIV card, granted access to NSF email or any other NSF information, that do not require any further access, and/or at completion, expiration or termination of any such contract or task order where access has been granted, shall follow the requirements in the Contractor Onboarding and Separation Guide, specifically:
i. Complete and submit the online Contractor/Guest Exit Form, which will result in termination of all access to any NSF email accounts and information systems.
ii. Report to the lobby floor visitor center to identify themselves to the personnel present and surrender their PIV.
iii. Notify the Contracting Officer Representative (COR) and appropriate Property Custodian of any NSF equipment or information to be surrendered to
NSF.
3. Access Controls for NSF Systems and Information - The Contractor shall be responsible for Information Technology (IT) security for all systems used in performance of this contract, or those which are connected to an NSF network. This clause is applicable to all or any part of the contract that includes IT resources or services in which the Contractor must have physical or electronic access to NSF’s information, including sensitive information and personally identifiable information, contained in unclassified systems that directly support the mission of the Agency. The access includes information technology, hardware, software, and the management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.
4. Remote Access – The Contractor may have the need to access NSF information systems remotely. The Contractor will remotely access NSF systems only through approved mechanisms. All remote access sessions will be encrypted using NSF services to protect NSF data and information.
5. Protection of Sensitive and Personally Identifiable Information (PII) - NSF's privacy program includes policies, plans, training, and technical safeguards to protect sensitive information, which includes Personally Identifiable Information (PII). NSF recognizes the importance of protecting sensitive information and implements policy, guidance, and best practices to safeguard information from inappropriate access, use, or disclosure.
a. Information Types - The term, Information, is synonymous with Data, regardless of format or medium. PII is a subset of Sensitive Information. Sensitive PII is a subset of PII, and therefore a subset of Sensitive Information. All requirements for Sensitive
Information apply to PII and Sensitive PII. All requirements for PII apply to Sensitive PII. The hierarchy of sensitive information is as follows and defined below:
i. Sensitive Information - Sensitive Information is any information, which if lost, compromised, or disclosed, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual, the Government, or the Government’s interests. Sensitive Information is subject to stricter handling requirements because of the increased risk if the data are compromised. Some categories of sensitive information include financial, medical or health, legal, strategic and business, human resources, PII and sensitive PII. These categories of information require appropriate protection as stand-alone information and may require additional protection in aggregate.
ii. Personally Identifiable Information (PII) - PII, as defined in OMB Memorandum M-07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information, refers to information that can be used to distinguish or trace an individual’s identity, such as their name, social security number, biometric records, etc., either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, etc. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information that is publicly available — in any medium and from any source
— is or can be combined to identify an individual. As an example, PII includes a name or an email address because these pieces of information uniquely identify an individual, but alone may not constitute Sensitive PII.
iii. Sensitive PII - Sensitive PII refers to information that can be used to target, harm, or coerce an individual or entity, assume or alter an individual’s or entity’s identity, or alter the outcome of an individual’s or entity’s activities.
Sensitive PII requires stricter handling because of the increased risk to an individual if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as Social Security numbers (SSN) or biometric identifiers. Other information such as a financial account, date of birth, maiden names, citizenship status, or medical information, in conjunction with the identity of an individual (directly or indirectly inferred), are also considered Sensitive PII. The context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or compliant.
b. Access to Information - While performing official duties, Contractors may have the need to access sensitive information or PII. Sensitive information includes proposal reviews, reviewer identity tied to specific reviews or panels, unfunded proposals, proprietary parts of funded proposals, and other similar information. Most of the sensitive information maintained by NSF falls within Privacy Act systems of records, which places disclosure restrictions on NSF and provides access rights to individuals. Sensitive information may also exist in other types of records, such as databases, log files, email, and correspondence files. All Contractor personnel are responsible for recognizing sensitive information and avoiding inappropriate or accidental access, use, or disclosure in accordance with Privacy Act and NSF IT security and privacy policies.
c. Responsibility to Identify and Protect PII - All Contractor personnel are responsible for recognizing PII and avoiding inappropriate or accidental access, use, or disclosure in accordance with NSF IT policies. Actual business sensitive information (i.e., names of reviewers, PIs, budget information, etc.) from NSF systems should not be used for illustration purposes. If business sensitive information is used, it must be obscured or redacted.
d. Information Use - The Contractor must not use or redistribute any NSF information processed, stored, or transmitted by the Contractor except as specified in the Contract.
e. NSF Privacy Program and PII - PII may be in the scope of the acquisition and PII may be stored, processed, or transmitted in the Contractor's information system. The collection, maintenance or dissemination of any PII that is subject to the Privacy Act and/or the E-Government Act will be handled in full accordance with all NSF rules of behavior and in accordance with NSF Privacy Program requirements. The Contractor shall ensure that any PII stored on any Contractor system as a function of the contract is encrypted at rest and in transit in accordance with NSF policy.
f. PII Guidelines - PII (should it come into scope) will require the following guidelines be adhered to.
i. The Contractor’s information system must be authorized at least at the FIPS PUB 199 Moderate level.
ii. For any system that collects, maintains or disseminates PII, a Privacy Threshold Analysis (PTA) and Privacy Impact Assessment (PIA) must be completed by the contractor and provided to the NSF Privacy Office (DIS Privacy Liaison) (https://www.nsf.gov/policies/privacy.jsp) for review along with the other authorization to operate (ATO) documents.
iii. If the system retrieves information using name or personal identifier, the Office of General Counsel should be consulted to make a determination as to whether the Privacy Act applies and whether a System of Records Notice (SORN) is in place.
iv. If a data collection involves Privacy Act protected information, a Privacy Act Statement (i.e., Privacy Notice) must be provided to users prior to their use of the application on what data is being collected and why, as well as the authority for the collection and the impact of not providing some or all of it.
The Privacy Act Statement must be available to the individual directly on the https://www.nsf.gov/policies/privacy.jsp form used to collect the information. Providing a link back to the Statement from the form is acceptable.
6. Systems and Information Integrity
a. Vulnerability Management - If access, including remote access, is through a Contractor-managed system, the Contractor is responsible for IT security patching and maintenance of the system. NSF is responsible for security and patching of NSF managed devices, including Contractor devices if they have an NSF image, when the Contractor device is connected to the NSF network.
b. NSF Configuration Baseline - The Contractor shall certify applications are fully functional and operate correctly as intended on systems using the established NSF configuration baseline. The standard installation, operation, maintenance, updates, and/or patching of software, including software purchased under this Agreement, shall not alter the configuration settings from the approved established NSF configuration baseline configuration. Offerings that require installation should follow OMB M-07-18, Ensuring New Acquisitions Include Common Security Configurations. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges. The Contractor shall use Security Content Automation Protocol (SCAP) validated tools with established NSF configuration baseline scanner capability to certify their products operate correctly with established NSF configuration baseline settings and do not alter established NSF configuration baselines.
c. Mobile Devices – Personally owned mobile devices are permitted to connect to NSF
IT resources and services (such as email, calendar, contacts, etc.). If the Contractor wishes to use a personally owned mobile device, the device must first be enrolled in Mobile Device Services (MDS). Use of personally owned mobile devices must be in accordance with the NSF MDS Terms of Use and enrollment guides.
7. Continuous Monitoring and Ongoing Authorization
a. Security Assessment and Authorization (A&A)
i. Major Applications - For Information Systems NSF has identified as Major Applications or General Support Systems (GSS) that are not connected to a NSF network, but for which the Contractor has operational responsibility on behalf of NSF, the Contractor must conform to all NSF policy guidance and reporting requirements regarding Assessment and Authorization (A&A) of IT systems. NSF shall perform all assessment activities as outlined in NIST SP 800-37, while the Contractor will provide full support and documentation to NSF for this effort. Unless otherwise specified by NSF, NSF shall fulfill the roles of “Senior Agency Information Security Officer" (or "Chief Information Security Officer”) and “Authorizing Official” as outlined in NIST SP 800-37 Appendix D. For all Contractor Operated systems, NSF shall establish accreditation boundaries and A&A schedules.
ii. Timeline - The A&A activities will be done prior to service commencement (go-live into Production) and periodically thereafter as required by Federal or NSF policies. This is currently every three years or according to ongoing authorization plans unless there is a major change.
b. Continuous Monitoring – Continuous monitoring is an important activity of NSF’s IT
Security and Privacy Program. Continuous monitoring assures NSF infrastructure and information assets are protected while maintaining an open and collaborative environment for scientific research and discovery. NSF’s Information Security Continuous Monitoring (ISCM) program contributes to NSF’s Enterprise Risk Management approach, which is charged to develop, mitigate, and manage significant risks to NSF.
ISCM activities incorporate compliance with the Federal Information Security Modernization Act (FISMA) and ongoing operational security for a system throughout its lifecycle. NSF’s continuous monitoring approach assesses the security state of information systems based on FISMA security requirements and NIST guidance.
c. Cloud Services – If cloud services are used to support NSF, the Contractor shall implement the controls contained within the Federal Risk and Authorization Management Program (FedRAMP) Cloud Computing Security Requirements Baseline and FedRAMP Continuous Monitoring Requirements for Low and Moderate impact systems (as defined in FIPS PUB 199). FedRAMP documents define requirements for compliance to meet minimum Federal information security and privacy requirements for Low or Moderate impact systems. The FedRAMP baseline controls are based on NIST Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations and includes a set of additional controls for use within systems providing cloud services to the federal government.
The Contractor shall generally, substantially, and in good faith follow FedRAMP guidelines and security guidance. In situations where there are no procedural guides, the Contractor shall use generally accepted industry best practices for IT security.
d. Risk Management – NSF manages enterprise information security and privacy risk in compliance with NIST SP 800-39, Managing Information Security Risk:
Organization, Mission, and Information System View and the Framework for Improving Critical Infrastructure Cybersecurity (the Framework). The Framework encourages agencies to operate within an implementation tier that includes formally approved policies and procedures, an integrated risk management program, and collaboration and partnership with external parties to develop, maintain, and enhance a holistic cybersecurity environment. NSF uses the Framework's adaptive process to identify and respond to cybersecurity risk.
NSF monitoring activities are based on NIST Special Publication (SP) 800-37, Risk Management Framework for Information Systems and Organizations: A System Life
Cycle Approach for Security and Privacy. The risk management framework process emphasizes the continuous monitoring of information systems through enhanced monitoring and providing essential information for risk-based decisions.
The Contractor shall apply appropriate techniques to manage and mitigate risk during the acquisition, implementation, and operation of information technology at NSF. The techniques include but are not limited to prudent project management; continuous collection and evaluation of risk-based assessment data; prototyping prior to implementation; post implementation reviews; and focusing on risks and returns using quantifiable measurements.
e. Supply Chain Risk Management – Supply chain risk means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of an information system (as that term is defined at 44 U.S.C. 3542(b)) so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system.
i. The Contractor shall provide information system(s) in compliance with the annual Consolidated and Further Continuing Appropriations Act regarding the acquisition of high impact or moderate impact systems in effect at the time of award.
ii. The Contractor shall mitigate supply chain risk in the provision of supplies and services to the Government.
iii. The Contractor shall maintain threat awareness while supplying the Government with products and services.
iv. The Contractor products and services shall comply with industry standard development and engineering principles to ensure security requirements are incorporated throughout the development and delivery process.
v. The Contractor shall incorporate secure configuration in products and services that are consistent with organizational risk management.
8. Cooperation with Audits
a. Contractor Cooperation - The Contractor (and subcontractors) shall fully cooperate with all audits, inspections, investigations, or other reviews conducted by or on behalf of the Contracting Officer or the Chief Information Security Officer or designated representative including the IT Security Officer. Full cooperation includes, but is not limited to, prompt disclosure to authorized requestors of information sufficient to identify the nature and extent of any computer security incident, including a breach of sensitive information or personally identifiable information and the individuals responsible for such activity. The Contractor’s (and any subcontractors’) cooperation with audits, inspections, investigations, and reviews conducted under this clause will be provided at no additional cost to the Government.
b. Government Data and Records - The Contractor (or subcontractor) shall timely produce to the Contracting Officer, a Contracting Officer’s Representative (COR), or the Chief Information Security Officer, Government data, information, or records under the control of or in the possession of the Contractor pursuant to this contract, which the Agency, may request in furtherance of other audits, inspections, investigations, reviews or litigation in which the Senior Agency Information Security Officer (or Chief Information Security Officer) is involved. Requests for production under this paragraph shall specify a reasonable deadline for compliance which will presumptively determine whether response to the request has been made in a timely manner. Unless expressly provided otherwise elsewhere in this contract, the production of data, information, or records under this paragraph will be at no additional cost to the Government.
9. Incident Response
a. Notification - In the event of any violation or computer security incident, the Contractor shall promptly notify the Chief Information Security Officer or the agency IT Security Officer.
b. Incident Data Preservation - In the event of any suspected violation of Federal laws and regulations such as illegal activity, computer security incidents, violations of Agency policy, malicious or otherwise prohibited use, (as defined in NIST Special Publication 800-61, Computer Security Incident Handling Guide), including but not limited to those constituting an actual or potential threat or hazard to the integrity, availability, or confidentiality of agency information in the possession or under the control of the Contractor (or subcontractor), or to the function of information systems operated by the Contractor (or subcontractor) in the performance of this contract, the Contractor (or subcontractor) shall preserve such data, records, logs and other evidence which are reasonably necessary to conduct a thorough investigation of the computer security incident.
c. Notification to Inspector General - If an incident is determined to be actual or suspected criminal activity, the Chief Information Security Officer will make the determination to notify the agency’s Office of the Inspector General (OIG).
(End of Clause)
File details come from the government source that posted it. Updated .