PWS Appendix 2 - NARA IT Security Requirements Language - Unclassified.docx

DOCX document 52 KB Posted

Attached to
Presidential Libraries, Visitor Services System (VSS) Federal contract opportunity
Solicitation number
88310320Q00115
Issued by
National Archives and Records Administration

About this file

This document contains a solicitation for a federal contract opportunity. The National Archives and Records Administration is seeking to continue operations and maintenance and hosting of its current Visitor Services System. The period of performance will be a base year plus four option years. Quotations are due by September 11, 2020 and must be submitted to the identified contracting officer via email. The requirement is for a brand name product from ACME Technologies, Inc. for their ticketing system. The contractor must submit a completed schedule of prices and required quotation information with its response or the quotation will be deemed technically unacceptable.

View the file

Other files for this federal contract opportunity

Other files attached to Presidential Libraries, Visitor Services System (VSS), newest first.
File Type Posted
88310320Q00115 Amendment 001 SF30.docx DOCX document
Justification and Approval FAR 13.5 Sole-Source Justification_FINAL All Signatures.pdf PDF
PWS Appendix 1 - SDLC_Methodology.docx DOCX document
88310320Q00115 VSS Enclosures 1-7 FINAL.docx DOCX document
PWS Appendix 3 - Configuration Management Plan.pdf PDF
PWS Appendix 4 - Version_Description_Document_Template.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

NARA

IT Security Requirements Language

NATIONAL ARCHIVES AND RECORDS ADMINISTRATION

July 17, 2017

Version 1.7

Table of Contents

A.Applicability to Contractors and Subcontractors4
B.NARA Security Requirements4

A. Applicability to Contractors and Subcontractors

The below requirements apply to all contractors and subcontractors, including cloud service providers ("CSPs"), and personnel of contractors, subcontractors, and CSPs that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of NARA Information. These requirements establish and implement specific NARA security requirements applicable to the reference contract.

B. NARA Security Requirements

1. Contractor shall comply with all security requirements, including but not limited to the regulations and guidance found in the following:

· Federal information Security Modernization Act of 20 14 ("FISMA"),

· Privacy Act of 1 974,

· E-Government Act of 2002,

· National Institute of Standards and Technology ("'N I ST") Special Publications ("SP") including NIST SP 800-37, 800-53, and 800-60 Volumes I and II,

· Federal Information Processing Standards ("FIPS") Publications 140-2, 199, and 200,

· Office of Management and Budget (OMB) Circular A-130, OM B Memoranda, and

· Federal Risk and Authorization Management Program ("'FedRAMP")

2. All hardware, software, and services provided under this contract must be compliant with NARA 804 IT Systems Security Policy, IT Security Requirements document, IT Security Methodologies and Continuous Monitoring Concept of Operations. See Attachment ___

3. Any information system operated for or on behalf of NARA must:

a. Have been evaluated and approved by a 3PAO certified under FedRAMP and Contractor has provided the most current Security Assessment Report ("SAR") to the NARA Contracting Officer for consideration as part of the Contractor's overall System Security Plan, and any subsequent SARs within 30 days of issuance, and has received an ATO from the NARA Authorizing Official responsible for maintaining the security confidentiality, integrity, and availability of the NARA Information under contract; or,

b. If not certified under FedRAMP, the information system must receive an ATO signed by the NARA Authorizing Official in accordance with NARA 804 and its supplements.

4. The Contractor must ensure that the information system allows NARA to access and retrieve any NARA Information processed, stored or transmitted in an information system under this Contract within 48 hours from the request. To ensure that NARA can fully and appropriately search and retrieve NARA Information from the information system, access shall include any schemas, meta-data, and other associated data artifacts.

5. A Security Authorization of any infrastructure directly in support of the NARA information system shall be performed as a general support system (GSS) prior to NARA occupancy to characterize the network, identify threats, identify vulnerabilities, analyze existing and planned security controls, determine likelihood of threat, analyze impact, determine risk, recommend controls, perform remediation on identified deficiencies, and document the result.

6. On a periodic basis, NARA, including the NARA Office of Inspector General, may choose to evaluate any or all of the security controls implemented by the contractor under these requirements. Evaluation could include, but is not limited to vulnerability scanning. NARA reserves the right to conduct audits at its discretion. With ten working days’ notice, at the request of the Government, the contractor shall fully cooperate and facilitate in a Government-sponsored security control assessment at each location wherein NARA information is processed or stored, or information systems are developed or operated. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) determined by NARA in the event of a security incident.

7. The contractor shall participate in NARA’ Continuous Monitoring Strategy and methods or shall provide a Continuous Monitoring capability that NARA determines acceptable.

8. Security Operations

· The Contractor shall operate a Security Operations Center (SOC) to provide the security services described below.

· The SOC personnel shall provide 24x7x365 staff to monitor the contractor’s network and all of its devices.

· The contractor staff shall analyze the information generated by the monitoring devices for security events, respond to real-time events, correlate security device events, and perform continuous monitoring.

9. Computer Incident Response Services

· The Contractor shall provide Computer Incident Response Team (CIRT) services.

· The contractor shall notify the NARA IT Security Management Division of any incident within one hour of detection and work with NARA throughout the incident duration.

10. Firewall Management and Monitoring

· The Contractor shall provide firewall management services that include the design, configuration, implementation, maintenance, and operation of all firewalls within the hosted infrastructure in accordance with NARA architecture and security policy.

· The contractor shall provide all maintenance to include configuration, patching, rule maintenance (add, modify, delete), and comply with NARA’ configuration management / release management requirements when changes are required.

· Firewalls shall operate 24x7x365. If an abnormality or anomaly is identified, the contractor shall notify the appropriate NARA point of contact in accordance with the incident response plan.

11. Intrusion Detection Systems and Monitoring

· The Contractor shall provide the design, configuration, implementation, and maintenance of the sensors and hardware that are required to support its Network Intrusion Detection Solution (NIDS).

· The contractor is responsible for creating and maintaining the NIDS rule sets. The NIDS solution should provide real-time alerts.

· These alerts and other relevant information shall be located in a central repository.

· The NIDS shall operate 24x7x365.

12. Vulnerability Assessments The Contractor shall provide all information from any managed systems to NARA, as requested, and shall assist, as needed, to perform periodic vulnerability assessments of the network, operating systems, and applications to identify vulnerabilities and propose mitigations.

13. The contractor shall apply patches that are required by vendors and the NARA system owner.

14. Secure Protocols The Contractor shall utilize HTTPS-only, with HSTS for internal and external websites

15. Trusted Internet Connection The Contractor shall provide a Trusted Internet Connection 2.0 compliant interconnection architecture and support continued compliance with OMB requirements.

16. IPv6 requirements

The Contractor shall ensure that all systems, including hardware, software, firmware, and/or network components developed, procured, or acquired in support and/or performance of this contract using the Internet Protocol are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 800-119). In addition, all products or systems using the Internet Protocol shall maintain operability with both Internet Protocol (IP) IPv4 and IPv6.

17. Homeland Security Presidential Directive 12 (HSPD-12) Compliance

· Procurements for software products or software developments shall be compliant with HSPD-12 by accepting Personal Identification Verification (PIV) credentials as the common means of authentication for access for federal employees and contractors.

· PIV-enabled information systems must demonstrate that they can correctly work with PIV credentials by responding to the cryptographic challenge in the authentication protocol before granting access.

· If a system is identified to be non-compliant with HSPD-12 for PIV credential enablement, a remediation plan for achieving HSPD-12 compliance shall be required for review, evaluation, and approval by the CISO.

image1.png

File details come from the government source that posted it. Updated .