J-3_CYBERSECURITY_POLICIES_AND_REGULATIONS.pdf
PDF 24 KB Posted
- Attached to
- Veterans Technology Services 2 (VETS 2) GWAC Federal contract opportunity
- Solicitation number
- QTA0016AWA0001
- Issued by
- GSA Federal Acquisition Service
About this file
J-3 CYBERSECURITY POLICIES AND REGULATIONS
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
VETS 2
Solicitation QTA0016AWA0001
J-3 Cybersecurity Policies and Regulations
ATTACHMENT J-3
CYBERSECURITY POLICIES AND REGULATIONS
This attachment is in support of solicitation QTA0016AWA0001. Reference solicitation section H.5 for further information.
Contractors entering into an agreement for service to government activities shall be subject to all IT security standards, policies, reporting requirements, and government wide laws or regulations applicable to the protection of government wide information security, as listed below. Additional requirements may be included in individual Task Orders by the issuing agency OCO.
Contractors are required to comply with Federal Information Processing Standards (FIPS), the “Special Publication 800 series” guidelines published by NIST, and the requirements of FISMA.
• Federal Information Security Management Act (FISMA) of 2002.
• Clinger-Cohen Act of 1996 also known as the “Information Technology Management Reform Act of 1996.”
• Privacy Act of 1974 (5 U.S.C. § 552a).
• Homeland Security Presidential Directive (HSPD-12), “Policy for a Common Identification
Standard for Federal Employees and Contractors”, August 27, 2004.
• Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information
Resources”, and Appendix III, “Security of Federal Automated Information Systems”, as amended.
• OMB Memorandum M-04-04, “E-Authentication Guidance for Federal Agencies.”
• FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information
Systems.”
• FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information
Systems.”
• FIPS PUB 140-2, “Security Requirements for Cryptographic Modules.”
• NIST Special Publication 800-18 Rev 1, “Guide for Developing Security Plans for Federal
Information Systems.”
• NIST Special Publication 800-30, “Risk Management Guide for Information Technology Security
Risk Assessment Procedures for Information Technology Systems.”
• NIST Special Publication 800-34, “Contingency Planning Guide for Information Technology
Systems.”
• NIST Special Publication 800-37, Revision 1, “Guide for the Security Certification and
Accreditation of Federal Information Systems.”
• NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology
Systems.”
• NIST Special Publication 800-53 Revision 4, “Recommended Security Controls for Federal
Information Systems.”
• NIST Special Publication 800-53A, “Guide for Assessing the Security Controls in Federal
Information Systems.”
• NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal
Information Systems and Organizations” http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800
VETS 2
Solicitation QTA0016AWA0001
J-3 Cybersecurity Policies and Regulations
Required Policies and Regulations for GSA Issued Task Orders
The following applies to task orders awarded by GSA that involve access to sensitive data and IT resources to conduct business on behalf of, or with, GSA or GSA supported Government organizations regardless of dollar value.
In accordance with FAR 39.105, this section is included in the contract.
This section applies to all users of sensitive data and information technology (IT) resources, including contractors, subcontractors, lessors, suppliers and manufacturers.
The following GSA policies must be followed. These policies can be found at http://www.gsa.gov/directives
1. CIO P 2100.1 GSA Information Technology (IT) Security Policy
2. CIO P 2100.2B GSA Wireless Local Area Network (LAN) Security
3. CIO 2100.3B Mandatory Information Technology (IT) Security Training Requirement for Agency and
Contractor Employees with Significant Security Responsibilities
4. CIO 2104.1A GSA Information Technology IT General Rules of Behavior
5. CIO 2105.1 B GSA Section 508: Managing Electronic and Information Technology for Individuals with Disabilities
6. CIO 2106.1 GSA Social Media Policy
7. CIO 2107.1 Implementation of the Online Resource Reservation Software
8. CIO 2160.4 Provisioning of Information Technology (IT) Devices
9. CIO 2162.1 Digital Signatures
10. CIO P 2165.2 GSA Telecommunications Policy
11. CIO P 2180.1 GSA Rules of Behavior for Handling Personally Identifiable Information (Pll)
12. CIO 2182.2 Mandatory Use of Personal Identity Verification (PIV) Credentials
13. CIO P 1878.2A Conducting Privacy Impact Assessments (PIAs) in GSA
14. CIO IL-13-01 Mobile Devices and Applications
15. CIO IL-14-03 Information Technology (IT) Integration Policy
16. HCO 9297.1 GSA Data Release Policy
17. HCO 9297.2B GSA Information Breach Notification Policy
18. ADM P 9732.1 D Suitability and Personnel Security
The Contractor and Subcontractors must insert the substance of this section in all subcontracts.
http://www.gsa.gov/directives
File details come from the government source that posted it. Updated .