Request for Proposal.pdf

PDF 1 MB Posted

Attached to
Paying Agent-related Information Security Consultant (PAISC) Federal contract opportunity
Solicitation number
PBGC01-RP-12-0060
Issued by
Pension Benefit Guaranty Corporation

About this file

Request for Proposal

View the file

Other files for this federal contract opportunity

Other files attached to Paying Agent-related Information Security Consultant (PAISC), newest first.
File Type Posted
PAISC_Q A.pdf PDF
PAISC_Attachment A1.pdf PDF
PAISC_Attachment C.pdf PDF
FormSF30.pdf PDF
PAISC_Attachment B.pdf PDF
PAISC_Attachment A2.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFQ IFB RFP

ECONOMICALLY DISADVANTAGED

WOMEN-OWNED SMALL BUSINESS

(EDWOSB)

WOMEN-OWNED SMALL

BUSINESS (WOSB)

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

1. REQUISITION NUMBER PAGE OF

2. CONTRACT NO. 3. AWARD/EFFECTIVE

DATE

4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE

DATE

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME b. TELEPHONE NUMBER (No collect calls)

8. OFFER DUE DATE/

LOCAL TIME

9. ISSUED BY

13b. RATING

14. METHOD OF SOLICITATION

CODE

15. DELIVER TO 16. ADMINISTERED BY CODE

18a. PAYMENT WILL BE MADE BY CODEFACILITY

CODE

CODE

TELEPHONE NO.

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

SEE ADDENDUM

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

29. AWARD OF CONTRACT: REF.

DATED . YOUR OFFER ON SOLICITATION

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 3/2011)

Prescribed by GSA - FAR (48 CFR) 53.212

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

OFFER

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

ARE ARE NOT ATTACHED

ARE ARE NOT ATTACHED

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

17a CONTRACTOR/

OFFEROR.

CODE

8 (A)

SIZE STANDARD:

NAICS:

% FOR:SET ASIDE:UNRESTRICTED OR

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SMALL BUSINESS

10. THIS ACQUISITION IS

STANDARD FORM 1449 (REV. 3/2011) BACK

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

40. PAID BY

32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELPHONE NUMBER OF AUTHORZED GOVERNMENT REPRESENTATIVE

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED

CORRECT FOR

PARTIAL FINAL

37. CHECK NUMBER

38. S/R ACCOUNT NO. 39. S/R VOUCHER NUMBER

36. PAYMENT

COMPLETE PARTIAL FINAL

SCHEDULE Continued

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

PAGE 3 OF 60 PBGC01-RP-12-0025

Base Period 0001 The contractor shall provide all services required as proposed in the Performance Work Statement

Period of Performance: 10/01/2012 to 09/30/2013

1.00 LS

Option Period One

OPT

1001 The contractor shall provide all services as proposed in the Performance Work Statement

Period of Performance: 10/01/2013 to 09/30/2014

Option Period Two

2001 The contract shall provide all services as proposed in the

Performance Work Statement.

Period of Performance: 10/01/2014 to 09/30/2015

Option Period Three

3001 The contractor shall provide all services as proposed in the Performance Work Statement.

Period of Performance: 10/01/2015 to 09/30/2016

Option Period Four

4001 The contractor shall provide as services as proposed in the Performance Work Statement.

Period of Performance: 10/01/2016 to 09/30/2017

Table of Contents

PAGE 4 OF 60 PBGC01-RP-12-0025

SECTION B SUPPLIES OR SERVICES AND PRICES/COSTS

B. 2 PBGC-44-001 OTHER DIRECT COSTS (MAY 2012)

SECTION C DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

C. 2 Place of Performance

SECTION E INSPECTION AND ACCEPTANCE

E. 1 52.246-4 INSPECTION OF SERVICES--FIXED-PRICE (AUG 1996)

SECTION F DELIVERIES OR PERFORMANCE

F. 1 52.242-15 STOP-WORK ORDER (AUG 1989)

F. 2 52.242-17 GOVERNMENT DELAY OF WORK (APR 1984)

SECTION H SPECIAL CONTRACT REQUIREMENTS

H. 1 PBGC-00-001 PROFESSIONAL ATTIRE (OCT 2005)

H. 2 PBGC-03-001 CONFIDENTIALITY OF INFORMATION (OCT 2004)

H. 3 PBGC-03-002 ORGANIZATIONAL CONFLICTS OF INTEREST (OCT 2004)

H. 4 PBGC-03-004 DISPLAY OF PBGC IDENTIFICATION BADGES (APR 2007)

H. 5 PBGC-04-004 PBGC INFORMATION SECURITY (FEB 2011)

H. 6 PBGC-04-005 PROTECTION OF PERSONALLY IDENTIFIABLE INFORMATION (PII) (Feb 2012)

H. 7 PBGC-04-006 COMMON SECURITY CONFIGURATIONS FOR INFORMATION TECHNOLOGY ACQUISITION (JAN

2012)

H. 8 PBGC-09-001 RESTRICTIONS AGAINST DISCLOSURE OF INFORMATION (JAN 2012)

H. 9 PBGC-15-007 EXPENSES RELATED TO PROPOSAL SUBMISSION (OCT 2004)

H. 10 PBGC-15 001 INCORPORATION OF CONTRACTOR'S PROPOSAL (OCT 2004)

H. 11 PBGC-32-004 SUBMISSION OF INVOICES (JAN 2012)

H. 12 PBGC-37-001 KEY PERSONNEL (MAR 2012)

H. 13 PBGC-42-001 CONTRACTING OFFICER'S REPRESENTATIVE (JAN 2012)

H. 14 PBGC-42-002 OBSERVANCE OF LEGAL HOLIDAYS (JAN 2012)

H. 15 PBGC-46-001 INSPECTION AND ACCEPTANCE OF DELIVERABLES (JAN 2012)

SECTION I CONTRACT CLAUSES

I. 1 52.202-1 DEFINITIONS (JAN 2012)

I. 2 52.203-3 GRATUITIES (APR 1984)

I. 3 52.203-5 COVENANT AGAINST CONTINGENT FEES (APR 1984)

I. 4 52.203-7 ANTI-KICKBACK PROCEDURES (OCT 2010)

I. 5 52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN FEDERAL TRANSACTIONS (OCT 2010)

I. 6 52.204-4 PRINTED OR COPIED DOUBLE-SIDED ON POSTCONSUMER FIBER CONTENT PAPER (MAY 2011)

I. 7 52.223-6 DRUG-FREE WORKPLACE (MAY 2001)

I. 8 52.223-17 AFFIRMATIVE PROCUREMENT OF EPA-DESIGNATED ITEMS IN SERVICE AND CONSTRUCTION

CONTRACTS (MAY 2008)

I. 9 52.224-1 PRIVACY ACT NOTIFICATION (APR 1984)

I. 10 52.224-2 PRIVACY ACT (APR 1984)

I. 11 52.225-25 PROHIBITION ON CONTRACTING WITH ENTITIES ENGAGING IN SANCTIONED ACTIVITIES

RELATING TO IRAN--REPRESENTATION AND CERTIFICATION (NOV 2011)

I. 12 52.229-3 FEDERAL, STATE, AND LOCAL TAXES (APR 2003)

I. 13 52.232-1 PAYMENTS (APR 1984)

I. 14 52.232-8 DISCOUNTS FOR PROMPT PAYMENT (FEB 2002)

I. 15 52.232-11 EXTRAS (APR 1984)

I. 16 52.232-17 INTEREST (OCT 2010)

I. 17 52.233-1 DISPUTES (JUL 2002)

Table of Contents

PAGE 5 OF 60 PBGC01-RP-12-0025

I. 18 52.233-3 PROTEST AFTER AWARD (AUG 1996)

I. 19 52.233-4 APPLICABLE LAW FOR BREACH OF CONTRACT CLAIM (OCT 2004)

I. 20 52.237-3 CONTINUITY OF SERVICES (JAN 1991)

I. 21 52.244-6 SUBCONTRACTS FOR COMMERCIAL ITEMS (DEC 2010)

I. 22 52.204-7 CENTRAL CONTRACTOR REGISTRATION (FEB 2012)

I. 23 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (FEB 2012)

I. 24 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS--

COMMERCIAL ITEMS (APR 2012)

I. 25 52.216-24 LIMITATION OF GOVERNMENT LIABILITY (APR 1984)

I. 26 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)

I. 27 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)

I. 28 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

SECTION J LIST OF ATTACHMENTS

SECTION K REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF OFFERORS

K. 1 52.203-11 CERTIFICATION AND DISCLOSURE REGARDING PAYMENTS TO INFLUENCE CERTAIN FEDERAL

TRANSACTIONS (SEP 2007)

K. 2 52.209-2 PROHIBITION ON CONTRACTING WITH INVERTED DOMESTIC CORPORATIONS-REPRESENTATION (MAY

2011)

K. 3 52.203-2 CERTIFICATE OF INDEPENDENT PRICE DETERMINATION (APR 1985)

K. 4 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (FEB 2012)

K. 5 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS--COMMERCIAL ITEMS (APR 2012)

K. 6 52.222-22 PREVIOUS CONTRACTS AND COMPLIANCE REPORTS (FEB 1999)

K. 7 52.222-25 AFFIRMATIVE ACTION COMPLIANCE (APR 1984)

SECTION L INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS

L. 1 52.212-1 INSTRUCTIONS TO OFFERORS--COMMERCIAL ITEMS (FEB 2012)

L. 2 52.216-1 TYPE OF CONTRACT (APR 1984)

L. 3 52.233-2 SERVICE OF PROTEST (SEP 2006)

L. 4 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)

L. 5 Proposal Submission Instructions

SECTION M EVALUATION FACTORS FOR AWARD

M. 1 52.212-2 EVALUATION--COMMERCIAL ITEMS (JAN 1999)

PAGE 6 OF 60 PBGC01-RP-12-0025

SECTION B

SUPPLIES OR SERVICES AND PRICES/COSTS

B. 1

1.1 DESCRIPTION OF SERVICES

The Contractor shall provide the necessary services as described in the Performance Work Statement. The resulting contract under this Solicitation will be Performance-Based. This is Firm Fixed Price procurement.

1.2 PRICING SCHEDULE

Base Year

ITEM

SUPPLIES/SERVICES QTY UNIT

UNIT

PRICE

TOTAL

AMOUNT

CLIN

The Contractor shall perform all services required as proposed in the Performance Work Statement.

1 Lump Sum

CLIN

Travel NTE $10,000.00

Option Year One

TOTAL

AMOUNT

CLIN

The Contractor shall perform all services required as proposed in the Performance Work Statement.

Authorized Travel NTE

Option Year Two

TOTAL

AMOUNT

CLIN

The Contractor shall perform all services required as proposed in the Performance Work Statement.

PAGE 7 OF 60 PBGC01-RP-12-0025

Option Year Three

TOTAL

AMOUNT

CLIN

The Contractor shall perform all services required as proposed in the Performance Work Statement.

Option Year Four

TOTAL

AMOUNT

CLIN

The Contractor shall perform all services required as proposed in the Performance Work Statement.

B. 2 PBGC-44-001 OTHER DIRECT COSTS (MAY 2012)

The Contractor shall be reimbursed for the actual cost of other direct costs determined to be allowable in accordance with Part 31 of the Federal Acquisition Regulation and authorized by the Contracting Officer or his designee prior to the contractor incurring the charge.

PAGE 8 OF 60 PBGC01-RP-12-0025

If Travel and Per Diem are authorized they will be reimbursed in accordance with the Federal Travel Regulation (FTR) in effect at the time the travel is authorized by PBGC. All travel requirements must be met using the most economical form of transportation available and must be scheduled sufficiently in advance to take advantage of offered discount rates unless waived by the Contracting Officer. You may find the FTR at http://www.gsa.gov/ portal/content/104790.

PAGE 9 OF 60 PBGC01-RP-12-0025

SECTION C

DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

C. 1

Statement of Objectives (SOO) Paying Agent-related Information Security Consultant (PAISC) Contract

PBGC01-RFP-12-0060

05/25/2012

1.3 Scope

This section of the statement of objectives provides an explanation of the scope of this contract. The information is provided in three areas: (1) with regard to the information systems and business processes that will be associated with the work the contractor will be responsible for, (2) PBGC’s Directives, Memorandums, and other publications that the contractor will need to comply with, and (3) Federal mandates and laws that the contractor will need to adhere to within the scope of the work they will complete to satisfy this contract.

1.3.1 Paying Agent (PA) Program Systems and Business Processes Systems included in the PA program are those required for the payment of pension benefit to our participants and include transfer of payment files between PBGC and its primary paying agent. Furthermore, this program includes the system interaction to allow participants to see copies of their paper checks and images of their tax forms.

Characteristics of the paying agent program include the following key parameter approximations so that offers have a sense of size, breadth, and complexity of the paying agent program:

• Paying agent program is a third party web hosted system

• 50 servers within the boundary of the primary paying agent site

• 50 employees at the paying agent have access to PBGC information and/or support PBGC processes

• 500 PBGC employees use the paying agent system in some capacity

• 12 total different locations within the boundary of the paying agent program all located within the continental United States o Two locations for PBGC headquarters and back-up site o Two locations for Primary paying agent and back-up site o 8 locations for primary paying agent sub-contractors and back-up sites

Business processes and procedures included in the Paying Agent Program are those found in the PBGC’s Operations Manual and Policy Manual which directly relate to the payment of pension benefits to participants.

1.3.2 PBGC Memoranda, Directives, Standards, and other publications Below are listed those PBGC’s authoritative information which govern this contract. The contractor will be responsible for staying abreast of and implement new or modified directives, policies, standards, and procedures published during the life of this contract.

1.3.2.1 Enterprise Information Security Office (EISO) directives, programs, and policies (see Attachment A, for copies of these documents)

• PBGC Directive IM 05-02: PBGC Information Security Policy

• SE-PRO-01-01: OIT Information Systems Registration Process

• SE-PRO-02-01: PBGC Plan of Action and Milestones Process

PAGE 10 OF 60 PBGC01-RP-12-0025

• SE-PRO-03-01: PBGC User & Account Access Recertification Process

• SE-STD-01-01: PBGC Personnel Security Standard

• SE-STD-01-02: PBGC External Information Systems and Services Standard

• SE-STD-01-03: PBGC Public Information Security Standard

• SE-STD-01-04: PBGC System Privilege Standard

• SE-STD-01-05: PBGC Boundary Security Standard

• SE-STD-01-06: PBGC Transmission Integrity and Confidentially Standard

• SE-STD-01-07: PBGC Cryptography Standard

• SE-STD-01-08: PBGC Domain Name Services Security Standard

• SE-STD-01-09: PBGC Information Output Handling and Retention Standard

• SE-STD-01-10: PBGC Rules of Behavior Standard

• SE-STD-01-11: PBGC System Security Plan Standard

• SE-STD-01-12: PBGC Privacy Impact Assessment

• SE-STD-01-13: PBGC Security Categorization Standard

• SE-STD-01-14: PBGC Risk Assessment Standard

• SE-STD-01-15: PBGC Vulnerability Scanning Standard

• SE-STD-01-16: PBGC Plan of Action and Milestone Standard

• SE-STD-01-17: PBGC Life Cycle Security Standard

• SE-STD-01-18: PBGC Security Impact Analysis Standard

• SE-STD-01-19: PBGC Access Restrictions for Change Standard

• SE-STD-01-20: PBGC Physical & Environmental Security Standard

• SE-STD-01-21: PBGC Security Incident Handling Standard

• SE-STD-01-22: PBGC Security Audit Standard

• SE-STD-01-23: PBGC Information System Monitoring Standard

• SE-STD-01-24: PBGC Maintenance Security Standard

• SE-STD-01-25: PBGC Physical Access Standard

• SE-STD-01-26: PBGC Information System Connections Standard

• SE-STD-01-27: PBGC Identification and Authentication Standard

• SE-STD-01-28: PBGC Media Security Standard

• SE-STD-01-29: PBGC Security Training and Testing Standard

• SE-STD-01-30: PBGC System Protection Standard

• SE-STD-01-31: PBGC User-Installed Software Standard

• SE-STD-01-32: PBGC Access Control Standard

• SE-STD-01-33: PBGC Voice over Intranet Protocol Standard

1.3.2.2 PBGC Information Technology System Life Cycle Methodology (see Attachment B, for copies of these documents)

• PBGC Directive IM-05-07, PBGC’s Information Technology Solutions Life Cycle Methodology

• PM-PRO-01-01: IT Solutions Life Cycle Methodology Framework Narrative

• PM-STD-01-10: PBGC OIT - System Documentation Standard

• PM-STD-01-02: PBGC OIT - Design & COTS Configuration Document

Standard

• PM-STD-01-03: PBGC OIT - Requirements Document Standard

• PM-STD-01-04: Implementation and Training Plan Standard

• PM-STD-01-05: Lessons Learned Document Standard

PAGE 11 OF 60 PBGC01-RP-12-0025

1.3.2.3 Records management (see Attachment C, for copies of these documents)

• PBGC Records Management Guidance [Interim] (February 2012)

• PBGC Records Management Procedures (version 1.0)

1.3.2.4 Privacy information and security (see Attachment C, for copies of these documents)

• PBGC Directive IM 05-09, Information Privacy Program

• PBGC Directive IM 10-03, Protecting Sensitive Information

1.3.3 U.S. Federal laws and regulations, including but not limited to, the following Below are listed those Federal laws, regulations, and other publications which are highly relevant to this contract. The contractor will be responsible for staying abreast of and implement of any new or modified publications issued during the life of this contract.

1.3.3.1 The Office of Management and Budget (OMB) circulars, memorandums, and publications

• OMB Circular A-11, Part 7, Planning, Budgeting, Acquisition, and Management of Capital Assets, updated August, 2009, and the Capital Planning Guide, issued 2006

• OMB Circular A-123, Management’s Responsibility for Internal Control

• OMB Circular A-127, Financial Management Systems

• OMB Circular A-130, Management of Federal Information Resources, including Appendix III, Security of Federal Automated Information Resources

• OMB Memorandum 03-22, OMB Guidance for Implementing the Privacy

Provisions of the E-Government Act of 2002

• OMB Memorandum 06-16, Protection of Sensitive Agency Information

• OMB Memorandum 07-16, Safeguarding Against and Responding to the

Breach of Personally Identifiable Information

1.3.3.2 U.S. Department of Commerce’s National Institute of Standards and

Technology (NIST) publications including relevant Federal Information Processing Standards (FIPS)

• NIST SP 800-18, - Guide for Developing Security Plans for Federal Information Systems

• NIST SP 800-30 - Risk Management Guide for Information Technology Systems

• NIST SP 800-34 - Contingency Planning Guide for Information Technology Systems

• NIST SP 800-37 - Guide for Applying the Risk Management Framework to Federal Information Systems

• NIST SP 800-53 - Recommended Security Controls for Federal Information Systems and Organizations

• NIST SP 800-53A – Guide for Assessing the Security Controls in Federal Information Systems and Organizations

• NIST SP 800-60 Volume I and II - Guide for Mapping Types of Information and Information Systems to Security Categories

PAGE 12 OF 60 PBGC01-RP-12-0025

• NIST SP 800-122 - Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)

• NIST SP 800-137 – Information Security Continuous Monitoring for Federal Information Systems and Organizations

• FIPS 140-2, Security Requirements for Cryptographic Modules

• FIPS 199, Standards for Security Categorization of Federal Information and

Information Systems

• FIPS 200, Minimum Security Requirements for Federal Information and

Information Systems

• FIPS 201-1, Personal Identity Verification of Federal Employees and

Contractors

1.3.3.3 Other relevant U.S. Government information (publications, directives, acts, orders, etc.)

• 5 U.S.C., Privacy Act of 1974 PL 93-579, as amended

• 5 U.S.C., Privacy Act of 1974 PL 552a, as amended

• 18 U.S.C., Computer Fraud and Abuse Act

• Computer Security Act of 1987, Public Law No. 100-235

• Information Technology Management Reform Act of 1996

• Executive Order 13103, “Computer Software Piracy”

• Presidential Decision Directive 63 of May 22, 1998, Critical Infrastructure

Protection

• Title III of the E-Government Act of 2002 – Federal Information Security

Management Act of 2002 (FISMA), Public Law No. 107-347

• Government Paperwork Elimination Act of 1998 (GPEA), PL 105-277

• The Freedom of Information Act, PL 93-502

• The Federal Managers' Financial Integrity Act of 1982 (FMFIA), PL 97-255

• The Rehabilitation Act of 1973, as amended

• Government Accountability Office, Investment Management Executive

Guide, GAO-04-394G

• Federal Risk and Authorization Management Program (FedRAMP)

1.4 Requirements

Below are PBGC’s requirements of the contractor with regard to the services and deliverables for this contract. All of the activities and deliverables listed below will be completed with adherence to sections 1.3.2 and 1.3.3 of this statement of objectives.

Reference section 1.5 Deliverables for a detailed listing of all the required documents for which the contractor will be required to submit.

1.4.1 A holistic approach to Risk Management

The contractor will develop a Risk Management Program at the system information level (tier 3) based upon the Risk Management Framework (RMF) as outlined in the current version of NIST SP 800-37. This Risk Management Program will be based upon a

PAGE 13 OF 60 PBGC01-RP-12-0025

methodology that will ensure program compliance and use of PBGC’s EISO and/or industry best practices to support the most effective and efficient use of resources. It is expected that the Risk Management Program for this tier 3 effort will tie to and directly support PBGC’s Enterprise Risk Management Program. Furthermore, the Risk Management program will integrate with system development life cycle (specifically PBGC’s ITSLCM, see section 1.3.2.2).

1.4.2 Security Assessment and Authorization (SA&A)

The contractor will serve as project manager over the Security Assessment and Authorization (SA&A) process and complete system security tests and evaluations. This will include review of the PA’s self assessment of security controls. The contractor will conduct comprehensive evaluations of the security controls and other safeguards to determine and document the extent to which the design and implementation meet NIST and PBGC’s EISO requirements.

The contractor will support security authorization of the PA’s program systems by:

reviewing and evaluating system categorization; documenting and maintaining the PA program’s System Security Plan (SSP) and related control matrix; and developing Privacy Impact Assessment (PIA), Interconnection Security Agreement (ISA), and other PBGC specified EISO required documentation. The contractor will develop project schedules and serve as project manager for those activities needed for on-going authorization as outlined in NIST SP 800-37 process and PBGC’s EISO standards.

The contractor will be responsible for responding to emergent information system security authorization and security requirements from U.S. Federal Government and

PBGC.

1.4.3 Information Security Continuous Monitoring (ISCM) Program The Contractor will centrally manage the tier three level Information Security Continuous Monitoring (ISCM) program1

The contractor will support the establishment of the ISCM Strategy by: planning, selecting the security controls with associated tasks, which “provides security status information for all tiers and real-time updates for ongoing system authorization decisions” (NIST SP 800-137, p. 20). The contractor will perform risk assessments regarding changes to the PA system’s environment or impact due to PBGC’s changing environment, including Business Impact/Risk Assessment (BIA/RA) recommendations based on both security and business considerations, in coordination with PBGC’s EISO and the PA.

so that all necessary activities as required by NIST SP 800- 137 are planned and managed in a pro-active coordinated manner.

1 See NIST SP 800-137 (rev. 1), Chapter 3, which outlines the process for developing and implementing an ISCM program.

PAGE 14 OF 60 PBGC01-RP-12-0025

The contractor will then establish the ISCM Program by: developing a continuous monitoring plan that includes automated workflows to support efficient and effective process, and create a program schedule. The contractor will identify metrics for each control, establish monitoring and assessment frequencies, and develop the ISCM architecture that will be used to support information collection and delivery.

Then the contractor will implement the ISCM Program by: facilitating meetings with security team members from PBGC and its contractors; and develop, coordinate, support and test all NIST SP 800-53 controls.

Next the contractor will be responsible for analyzing data and reporting findings. This will require the contractor to collect security-related information and metrics and then assess the collected data. The contractor will perform data collection efforts (e.g.

interviews, site inspections, scanning, and other test activities) for control implementation by: serving as project manager for these type of efforts; supporting PBGC as subject matter expert; along with being responsible for gathering necessary artifacts from the PA and other sources.

The contractor will respond to findings. This step of the program will require the contractor to prepare appropriate reports and deliverables required to address information security finds. The contractor will manage the Plan of Action and Milestones (POA&M) process by: leading program meetings; maintaining records of the remediation and verification of activities; maintaining POA&M prioritization, tracking, and alerts; serving as the subject matter expert on mitigation strategies to ensure resolutions are in-line with PBGC’s EISO requirements; and assisting in the completion of POA&M remediation efforts.

The last, but by no means least step in the ISCM program will require the contractor to review and update the monitoring program and strategy on an on-going basis. The contractor will make recommendations and updates to the continuous monitoring plan based on the continually evolving environment and vulnerabilities. The contractor will also ensure the PA security program information and data (i.e., System Security Plan together with Risk Assessment Report, Security Assessment Report and POA&M) are current on an on-going basis.

1.4.4 Facilitate and support audits, compliance reviews, and other information requests The contractor will facilitate and support various audits and reviews as they relate to the PA systems by: helping to identify and map necessary artifacts to support auditors, facilitate compiling artifacts, provide auditors with access to needed program documentation (artifacts), coordinate and facilitate responses to questions, and serve as subject matter expert.

The contractor will facilitate and support IT system security-related information requests from internal and external sources, including, but not limited to, PBGC management, PAGE 15 OF 60 PBGC01-RP-12-0025

PBGC’s Enterprise Security Office (EISO), and the Office of Management and Budget

(OMB).

The contractor will support preparation of capital asset planning and business case summary with PA information security related information.

1.4.5 Automate compliance management and continuous monitoring support The contractor will provide an Information Security Management System (ISMS) for which security documents, reports, and artifacts can be maintained. This system must include the following features

• Centralized database that will store all compliance details and artifacts;

• Dashboard summarizing the overall security status of the system (e.g. number of controls implemented, planned, inherited, etc.);

• Built in NIST SP 800-53 control information – Including definitions and controls levels for PA program, systems, and subsystems;

• Ability to link artifacts to those NIST SP 800-53 controls for which it supports;

• Audit feature which logs all adds, deletes, and modifications for both documentation repository and user activity;

• Role-based user access to include administrative, read/write, and read only access;

• Report generation capability to facilitate custom and ad-hoc reports as needed; and

• Flexibility in adjusting to the evolving changes in compliance regulations and standards by allowing for quick and easy updates to the NIST controls.

Furthermore, the contractor will be responsible for ensuring the ISMS operations and maintenance. This will include, but not be limited to

• System authorization and access management,

• Daily system operations and server,

• Ongoing upgrades,

• Security management and authorization to operate processing, and

• Integration of workflows and process updates based on PBGC defined processes.

1.4.6 Program management support

The contractor will be responsible for leading meetings which will include preparing agendas, facilitation of sessions, meeting minutes, and coordination of action items.

Notification to attendees along with arranging for facilities and other resources needed to support various meetings will also be required of the contractor.

As a program manager, the contractor’s responsibilities include planning, preparing program and project schedules, coordination of activities, maintaining project documentation, and leading project team members in project tasks in support of reaching

PAGE 16 OF 60 PBGC01-RP-12-0025

program goals. The program manager is expected to be pro-active in identification of risk and when issues do materialize will implement agreed upon mitigating strategies to reduce program impact.

The contractor will also develop, review, and update the following key program management documents

• Program Management Plan – once developed reviewed at least annually

• Quality Assurance Plan – once developed reviewed at least annually

• Communications Plan - once developed reviewed at least annually

• Staffing Plan – once developed reviewed at least annually

• Risk Management Plan – once developed reviewed at least quarterly

• Program Schedule – once developed reviewed at least monthly

The contractor will hold regular program status update meetings with the Contracting Officer’s Representative (COR). The contractor will provide monthly status reports on program activities and ensure that all program and project documentation is delivered as outlined in program schedule (see section 1.5, Deliverables for further details).

1.4.7 Other services in support of risk management program

Supports system-specific contingency plans as it relates to both the PA and PBGC: will review and make recommendations; and coordinate, update and support exercises, as needed.

The contractor will provide information security guidance and technical expertise to Information System Owners (ISO), Information Owners (IO), Authorizing Official (AO), and others as defined by COR. The contractor will prepare security briefings and presentations to be used and presented by the IO, AO, and others as defined by COR.

The contractor may be asked to present program related information to PBGC management. The contractor will review and provide feedback on security-related policies, procedures, and templates as requested.

1.5 Deliverables

The following is a list of the key deliverables for which the offeror will be responsible for as a part of the contract. These documents will be developed, maintained, and updated as outlined in the Program Management Plan & Program Schedule.

1.5.1 Risk Management Plan

1.5.2 Security Assessment and Authorization (SA&A) Documentation

Baseline report for each control & tailoring plan

System Registration Documentation

• Classification and Determination Memo

PAGE 17 OF 60 PBGC01-RP-12-0025

• Categorization (FIPS 199) Document

• Privacy Threshold Analysis (PTA)

• Privacy Impact Assessment (PIA)

System Security Plan (SSP) and related matrix

Interconnection Security Agreement (ISA)

Memorandums of Understanding (MOU), if required

Security Assessment Report (SAR)

System Authorization Boundary Document

1.5.3 Information Security Continuous Monitoring (ISCM) Program Documentation ISCM Program Plan & project schedule

ISCM Risk Log

Attestation letters

External Scan summary reports

Plan of Action and Milestones (POA&M) reports

Risk Acceptance reports/documents

Request for Closure (RFC) reports/documents

Business Impact/Risk Assessment (BIA/RA) reports

1.5.4 Information Security Management System (ISMS) Documentation

1.5.5 Other Documentation

Authorizing Official (AO) Management Updates & Presentations

Meeting Agendas, minutes, and reports for Program meetings

1.5.6 Program Management Documentation

Program Management Plan

Quality Assurance Plan

Communications Plan

Staffing Plan

Risk Management Plan

Program Schedule – to include a program activities calendar, task list, deliverables List, PAGE 18 OF 60 PBGC01-RP-12-0025

Contract Administration Reports – such as Monthly status reports, Quarterly status reports

PAGE 19 OF 60 PBGC01-RP-12-0025

C. 2 Place of Performance

The primary place of performance will be Washington, DC; however travel/performance will be required to up to a total of 12 sites that may be located outside of the National Capital Region.

PAGE 20 OF 60 PBGC01-RP-12-0025

SECTION E

INSPECTION AND ACCEPTANCE

E. 1 52.246-4 INSPECTION OF SERVICES--FIXED-PRICE (AUG 1996)

(Reference 52.246-4)

PAGE 21 OF 60 PBGC01-RP-12-0025

SECTION F

DELIVERIES OR PERFORMANCE

F. 1 52.242-15 STOP-WORK ORDER (AUG 1989)

(Reference 52.242-15)

F. 2 52.242-17 GOVERNMENT DELAY OF WORK (APR 1984)

(Reference 52.242-17)

PAGE 22 OF 60 PBGC01-RP-12-0025

SECTION H

SPECIAL CONTRACT REQUIREMENTS

H. 1 PBGC-00-001 PROFESSIONAL ATTIRE (OCT 2005)

The Pension Benefit Guaranty Corporation receives many visitors who conduct business with the Corporation. Consequently, the professional appearance of those who work in PBGC facilities is important to maintaining confidence in PBGC and the pension insurance system. The Contractor shall ensure that its personnel who perform work in PBGC facilities present a neat, professional appearance appropriate to an office working environment. Some examples of inappropriate office attire include jeans, sneakers, sweat pants, lycra stretch pants, collar-less shirts, bare midriff tops, and spaghetti-strap tops. The Contractor shall ensure that its personnel exercise sound judgment in their choice of attire.

H. 2 PBGC-03-001 CONFIDENTIALITY OF INFORMATION (OCT 2004)

(a) To the extent that the work under this contract requires that the Contractor be given access to confidential or proprietary business, technical, or financial information belonging to the Government or other companies, the Contractor shall, after receipt thereof, treat such information as confidential and agree not to appropriate such information to its own use or to disclose such information to third parties unless specifically authorized by the Contracting Officer in writing. The foregoing obligations, however, shall not apply to:

(1) Information which, at the time of receipt by the Contractor, is in the public domain;

(2) Information which is published after receipt thereof by the Contractor or otherwise becomes part of the public domain through no fault of the Contractor;

(3) Information which the Contractor can demonstrate was already in his possession at the time of receipt from PBGC and was not acquired directly or indirectly from the Government or other companies;

(4) Information which the Contractor can demonstrate was received by it from a third party who did not require the Contractor to hold it in confidence.

(b) The Contractor shall obtain the written agreement, in a form satisfactory to the Contracting Officer or his designee, of each employee permitted access, whereby the employee agrees that he will not discuss, divulge or disclose any such information or data to any person or entity except those persons within the Contractor's organization directly concerned with the performance of the contract.

(c) The Contractor agrees, if requested by the Government, to sign an agreement identical, in all material respects, to the provisions of this clause, with each company supplying information to the Contractor under this contract, and to supply a copy of such agreement to the Contracting Officer. From time to time upon request of the Contracting Officer, the Contractor shall supply the Government with reports itemizing information received as confidential or proprietary and setting forth the company or companies from which the Contractor received such information.

(d) The Contractor agrees that upon request by PBGC it will execute a PBGC-approved agreement with any party whose proprietary data it is given access to or is furnished, restricting use and disclosure of the data.

Upon request by PBGC, such an agreement shall also be signed by Contractor personnel.

(e) This clause shall flow down to all subcontracts.

(End of Clause)

H. 3 PBGC-03-002 ORGANIZATIONAL CONFLICTS OF INTEREST (OCT 2004)

(a) Purpose. The purpose of this clause is to ensure that the contractor

(1) is not biased because of its financial, contractual, organizational, or other interests which relate to the work under this contract, and

(2) does not obtain any unfair competitive advantage over other parties by virtue of its performance of this contract.

PAGE 23 OF 60 PBGC01-RP-12-0025

(b) Scope. The restrictions described herein shall apply to performance or participation by the contractor and any of its partners, affiliates or their successors in interest (after this collectively referred to as the "contractor") in the activities covered by this clause as a prime contractor, subcontractor, cosponsor, joint venturer, consultant, or in any similar capacity. For the purpose of this clause, affiliation occurs when a business concern is controlled by or has the power to control another or when a third party has the power to control both.

(1) Use of Contractor's Work Product.

(i) The contractor shall be ineligible to participate in any capacity in PBGC contracts, subcontracts, or proposals therefor (solicited and unsolicited) which stem directly from the contractor's performance of work under this contract. Furthermore, unless so directed in writing by the Contracting Officer, the contractor shall not perform any advisory and assistance services work under this contract on any of its products or services or the products or services of another firm if the contractor is or has been substantially involved in their development or marketing. Nothing in this subparagraph shall preclude the contractor from competing for follow-on contracts for advisory and assistance services.

(ii) If, under this contract, the contractor prepares a complete or essentially complete statement of work or specifications to be used in competitive acquisitions, the contractor is ineligible to perform or participate in any capacity in any contractual effort which is based on such statement of work or specifications. The contractor shall not incorporate its products or services in such statement of work or specifications unless so directed in writing by the Contracting Officer, in which case the restriction in this subparagraph shall not apply.

(iii) Nothing in this clause precludes the contractor from offering or selling its standard commercial items to the Government.

(2) Access to and use of information.

(i) If the contractor, in the performance of this contract, obtains access to information, such as Corporate plans, policies, reports, studies, financial plans, internal data protected by the Privacy Act of 1974 (5 U.S.C. 552a), or data which has not been released or otherwise made available to the public, the contractor agrees that without prior written approval of the Contracting Officer it shall not:

(A) use such information for any private purpose unless the information has been released or otherwise made available to the public;

(B) compete for work for PBGC based on such information for a period of six months after either the completion of this contract or until such information is released or otherwise made available to the public, whichever is first;

(C) submit an unsolicited proposal to the Government which is based on such information until one year after such information is released or otherwise made available to the public; and

(D) release such information unless such information has previously been released or otherwise made available to the public by PBGC.

(ii) In addition, the contractor agrees that to the extent it receives or is given access to proprietary data, data protected by the Privacy Act of 1974 or other confidential or privileged technical, business, or financial information under this contract, it shall treat such information in accordance with all restrictions imposed on disclosure and use of such information.

(c) Disclosure after award.

(1) The contractor agrees that if changes, including additions, to the facts disclosed by it prior to award of this contract, occur during the performance of this contract, it shall make an immediate and full disclosure of such changes in writing to the Contracting Officer. Such disclosure may include a description of any action which the contractor has taken or proposes to take to avoid, neutralize, or mitigate any resulting conflict of interest. PBGC may, however, terminate the contract for convenience if it deems such termination to be in the best interest of the Government.

(2) In the event that the contractor was aware of facts required to be disclosed or the existence of an actual or potential organizational conflict of interest and did not disclose such facts or such conflict of interest to the Contracting Officer, PBGC may terminate this contract for default.

(d) Remedies. For breach of any of the above restrictions or for nondisclosure or misrepresentation of any facts required to be disclosed concerning this contract, including the existence of an actual or potential organizational conflict of interest at the time of or after award, the Government may terminate the contract for default, disqualify the contractor from subsequent related contractual efforts, and pursue such other remedies as may be permitted by law or this contract.

(e) Waiver. Requests for waiver under this clause shall be directed in

PAGE 24 OF 60 PBGC01-RP-12-0025

writing to the PBGC Office of General Counsel and a copy provided to the Contracting Officer, and shall include a full description of the requested waiver and the reasons in support of the request. If it is determined to be in the best interests of the Government, the Contracting Officer may grant such a waiver in writing.

(f) Subcontracts.

(1) The contractor shall include a clause, substantially similar to this clause, including this paragraph (f), in subcontracts expected to exceed the simplified acquisition threshold in FAR Part 13. The terms "contract," "contractor," and "Contracting Officer" shall be appropriately modified to preserve the Government's rights.

(2) Prior to the award under this contract of any such subcontracts for advisory and assistance services, the contractor shall obtain from the proposed subcontractor or consultant a disclosure of all existing or potential organizational conflicts of interest and shall determine in writing whether the interests disclosed present a significant potential for an organizational conflict of interest. Where an actual or significant potential organizational conflict of interest is identified, the contractor shall take actions to avoid, neutralize, or mitigate the organizational conflict to the satisfaction of the contractor. If the conflict cannot be avoided or neutralized, the contractor must obtain the approval of the PBGC Contracting Officer prior to entering into the subcontract.

H. 4 PBGC-03-004 DISPLAY OF PBGC IDENTIFICATION BADGES (APR 2007)

The Contractor shall comply with PBGC Directive Number GA-10-9, "Display of PBGC Identification Badges," the full content of which is located at http://www.pbgc.gov/docs/ GA_10_9.pdf All contract and sub-contract employees whose duties under this contract require their presence on designated PBGC facilities shall be clearly identifiable by a distinctive badge furnished by PBGC and shall observe and otherwise be subject to such security regulations as are in effect for the particular premises in accordance with PBGC Directive Number GA-10-9.

The PBGC-issued photo Identification Badge must be visible and be displayed at or above the waist. Badges may be displayed from either lanyard or clip style holders. The badge must be available for building security officer inspection in order to authenticate and validate.

Contractors that arrive to work without their Badge must: report to the Security Desk located in the 1200 K Street lobby; sign-in to the appropriate Log Book; present a valid government-issued form of photo identification to the security officer; contact a co-worker to vouch for him/her by signature in the log book; and, receive and display a temporary badge which shall be visible at all times and displayed at or above the waist.

Contractors shall be responsible for the care and protection of their Badge and promptly report all instances of loss or theft and initiate immediate action to replace the lost or stolen Badge. Contractors must relinquish their Badge upon separation or upon any circumstances which make the continued possession or use inappropriate.

Failure to comply with this Directive can result in refusal of admittance to PBGC designated facilities.

H. 5 PBGC-04-004 PBGC INFORMATION SECURITY (FEB 2011)

The provider of information technology shall adhere to:

1)Federal statutes, 2)Office of Management and Budget (OMB) guidance, 3)National Institute of Standards and Technology Federal Information Processing Standards and PBGC implementation of Security Guidelines (800 Series), (See 5a -- IM 05-2 below.)

4)Federal Information Systems Controls and Audit Manual (FISCAM), and 5)PBGC Orders relating to information security including:

a)IM 05-2 Information Technology Security Policies, http://www.pbgc.gov/docs/im_05_2.pdf b)IM 05-7 Information Technology Solutions Life Cycle Methodology (ITSLCM), http://www.pbgc.gov/docs/im_05_7.pdf and

PAGE 25 OF 60 PBGC01-RP-12-0025

c)IM 05-4 Use of Information Technology Resources.

http://www.pbgc.gov/docs/Im_05_4.pdf

The provider of information technology shall comply with PBGCs implementation of the following control frameworks including the:

1)Capability Maturity Model - Integrated (CMMI), 2)Control Objectives for Information and Related Technologies (COBIT), and 3)Information Technology Infrastructure Library (ITIL); and in addition, the provider of information technology shall certify the following:

a)Applications are fully functional and operate correctly as intended on systems using the Federal Desktop Core Configuration (FDCC). Once PBGC approves for implementation, this also includes Internet Explorer 7 configured to operate on Windows XP. For the Windows XP settings, see: http:// csrc.nist.gov/itsec/guidance_WinXP.html.

b)The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved FDCC configuration. The information technology should also use the Windows Installer Service for installation to the default program files directory and should be able to silently install and uninstall.

Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.

H. 6 PBGC-04-005 PROTECTION OF PERSONALLY IDENTIFIABLE INFORMATION (PII) (Feb 2012)

(a) To the extent that the work under this contract requires the Contractor be given access to personally identifiable information about an individual gathered and/or maintained by the Government or the Contractor (hereinafter referred to as PII), the Contractor shall after receipt thereof, treat such PII as confidential and safeguard such information from unauthorized use and disclosure.

(b) The Contractor agrees to allow access only to those employees who need the PII to perform services under this contract and agrees that PII will be used solely for the purpose of performing services under this contract. The Contractor shall ensure that its employees will not discuss, divulge or disclose any such PII to any person or entity except those persons within the Contractors organization directly concerned with the performance of the contract.

(c) The Contractor shall administer a monitoring process to ensure compliance with the provisions of this clause, promptly report any breaches to the Contracting Officers Representative (COR), and implement immediate, appropriate corrective actions to contain and prevent recurrence.

(d) The Contractor shall report to the COR immediately upon discovery of a real or suspected loss of PII. Protected PII is an individuals first name or first initial and last name in combination with any one or more of the following data elements including, but not limited to, social security number, passport number, credit card numbers, clearances, bank numbers, biometrics, date and place of birth, mothers maiden name, criminal, medical and financial records, educational transcripts, pension and participant plan, etc.

(e) The Contractor and employees shall adhere to PBGC Orders relating to the protection of sensitive and personally identifiable information including:

1. IM 10-2 Safeguarding Tax Return Information, http://www.pbgc.gov/docs/IM_10_2.pdf

2. IM 10-3 Protecting Sensitive Information, http://www.pbgc.gov/docs/IM_10_3.pdf

3. IM 05-9 Privacy Program, http://www.pbgc.gov/docs/IM_05_9.pdf

(Note: If unable to access these orders, the Contracting Officer will provide copies upon request.)

(f)The Government may terminate this contract for default or cause if the Contractor or an employee of the Contractor fails to comply with the provisions of this clause. The Government may also exercise any other rights and remedies provided by law or this contract, including criminal and civil penalties. In addition, the Contracting Officer or COR may direct the Contractor to remove from performance of the contract, any Contractor or subcontractor personnel who have improperly disclosed

PII.

PAGE 26 OF 60 PBGC01-RP-12-0025

(g) The Contractor shall include this clause in all subcontracts. However, such provision in the subcontracts shall not relieve Contractor of its obligation to assure compliance with the provisions of this clause.

H. 7 PBGC-04-006 COMMON SECURITY CONFIGURATIONS FOR INFORMATION TECHNOLOGY ACQUISITION (JAN 2012)

In acquiring Information Technology (IT) assets for the Government, the Contractor shall incorporate and comply with the latest version of all applicable information technology security policies and requirements, including, but not limited to, those published by PBGC, and the common security configurations defined by the National Institute of Standards and Technology [NIST] at http:// web.nvd.nist.gov/view/ncp/repository and http://checklist.nist.gov which are generally for desktop operating systems.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .