J-3_CYBERSECURITY_POLICIES_AND_REGULATIONS.pdf

PDF 24 KB Posted

Attached to
Veterans Technology Services 2 (VETS 2) GWAC Federal contract opportunity
Solicitation number
QTA0016AWA0001
Issued by
GSA Federal Acquisition Service

About this file

J-3 CYBERSECURITY POLICIES AND REGULATIONS

View the file

Other files for this federal contract opportunity

Other files attached to Veterans Technology Services 2 (VETS 2) GWAC, newest first.
File Type Posted
VETS_2_Supplement_to_Preaward_Notice.pdf PDF
VETS_2_Preaward_Notice_for_SB_Programs.pdf PDF
AMENDMENT_4_-_SF_30.pdf PDF
Amendment_4_-_Solicitation_QTA0016AWA0001.pdf PDF
QTA0016AWA0001_-_Q R__5.pdf PDF
Amendment_3_-_SF_30.pdf PDF
Amendment_3_-_Solicitation_QTA0016AWA0001.pdf PDF
QTA0016AWA0001_-_Q R__4.pdf PDF
Amendment_2_-_Solicitation_QTA0016AWA0001.pdf PDF
Amendment_2_-_SF_30.pdf PDF
QTA0016AWA0001_-_Q R__3.pdf PDF
Amendment_1_-_Solicitation_QTA0016AWA0001.pdf PDF
Amendment_1_-_J.P-12_FPDS_Sample.pdf PDF
QTA0016AWA0001_-_Q R__2.pdf PDF
Amendment_1_-_SF30.pdf PDF
Amendment_1_-_J.P-10_Direct_Labor_Rate_Ranges.pdf PDF
QTA0016AWA0001_-_Q R__1.pdf PDF
J.P-7_Relevant_Experience_Project_Template.docx DOCX document
J-1_PERFORMANCE_REQUIREMENTS_SUMMARY.pdf PDF
J.P-10_Direct_Labor_Rate_Ranges.pdf PDF
J.P-11_GSA_Form_527.pdf PDF
J-4_TRANSACTIONAL_DATA_REPORTING.pdf PDF
J.P-5_Document_Verification_and_Self_Scoring_Worksheet.xlsx XLSX spreadsheet
SOLICITATION_QTA0016AWA0001.pdf PDF
Section_A_-_SF33.pdf PDF
J-2_Labor_Categories_and_BLS_Service_Occupational_Classifications.pdf PDF
J.P-9_Cost_Price_Template.xlsx XLSX spreadsheet
J.P-8_Past_Performance_Rating_Form.docx DOCX document
J.P-6_JV_and_Subcontractor_Team_Project_Listing.xlsx XLSX spreadsheet
Show all 29

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

VETS 2

Solicitation QTA0016AWA0001

J-3 Cybersecurity Policies and Regulations

ATTACHMENT J-3

CYBERSECURITY POLICIES AND REGULATIONS

This attachment is in support of solicitation QTA0016AWA0001. Reference solicitation section H.5 for further information.

Contractors entering into an agreement for service to government activities shall be subject to all IT security standards, policies, reporting requirements, and government wide laws or regulations applicable to the protection of government wide information security, as listed below. Additional requirements may be included in individual Task Orders by the issuing agency OCO.

Contractors are required to comply with Federal Information Processing Standards (FIPS), the “Special Publication 800 series” guidelines published by NIST, and the requirements of FISMA.

• Federal Information Security Management Act (FISMA) of 2002.

• Clinger-Cohen Act of 1996 also known as the “Information Technology Management Reform Act of 1996.”

• Privacy Act of 1974 (5 U.S.C. § 552a).

• Homeland Security Presidential Directive (HSPD-12), “Policy for a Common Identification

Standard for Federal Employees and Contractors”, August 27, 2004.

• Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information

Resources”, and Appendix III, “Security of Federal Automated Information Systems”, as amended.

• OMB Memorandum M-04-04, “E-Authentication Guidance for Federal Agencies.”

• FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information

Systems.”

• FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information

Systems.”

• FIPS PUB 140-2, “Security Requirements for Cryptographic Modules.”

• NIST Special Publication 800-18 Rev 1, “Guide for Developing Security Plans for Federal

Information Systems.”

• NIST Special Publication 800-30, “Risk Management Guide for Information Technology Security

Risk Assessment Procedures for Information Technology Systems.”

• NIST Special Publication 800-34, “Contingency Planning Guide for Information Technology

Systems.”

• NIST Special Publication 800-37, Revision 1, “Guide for the Security Certification and

Accreditation of Federal Information Systems.”

• NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology

Systems.”

• NIST Special Publication 800-53 Revision 4, “Recommended Security Controls for Federal

Information Systems.”

• NIST Special Publication 800-53A, “Guide for Assessing the Security Controls in Federal

Information Systems.”

• NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal

Information Systems and Organizations” http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800 http://csrc.nist.gov/publications/PubsSPs.html#SP%20800

VETS 2

Solicitation QTA0016AWA0001

J-3 Cybersecurity Policies and Regulations

Required Policies and Regulations for GSA Issued Task Orders

The following applies to task orders awarded by GSA that involve access to sensitive data and IT resources to conduct business on behalf of, or with, GSA or GSA supported Government organizations regardless of dollar value.

In accordance with FAR 39.105, this section is included in the contract.

This section applies to all users of sensitive data and information technology (IT) resources, including contractors, subcontractors, lessors, suppliers and manufacturers.

The following GSA policies must be followed. These policies can be found at http://www.gsa.gov/directives

1. CIO P 2100.1 GSA Information Technology (IT) Security Policy

2. CIO P 2100.2B GSA Wireless Local Area Network (LAN) Security

3. CIO 2100.3B Mandatory Information Technology (IT) Security Training Requirement for Agency and

Contractor Employees with Significant Security Responsibilities

4. CIO 2104.1A GSA Information Technology IT General Rules of Behavior

5. CIO 2105.1 B GSA Section 508: Managing Electronic and Information Technology for Individuals with Disabilities

6. CIO 2106.1 GSA Social Media Policy

7. CIO 2107.1 Implementation of the Online Resource Reservation Software

8. CIO 2160.4 Provisioning of Information Technology (IT) Devices

9. CIO 2162.1 Digital Signatures

10. CIO P 2165.2 GSA Telecommunications Policy

11. CIO P 2180.1 GSA Rules of Behavior for Handling Personally Identifiable Information (Pll)

12. CIO 2182.2 Mandatory Use of Personal Identity Verification (PIV) Credentials

13. CIO P 1878.2A Conducting Privacy Impact Assessments (PIAs) in GSA

14. CIO IL-13-01 Mobile Devices and Applications

15. CIO IL-14-03 Information Technology (IT) Integration Policy

16. HCO 9297.1 GSA Data Release Policy

17. HCO 9297.2B GSA Information Breach Notification Policy

18. ADM P 9732.1 D Suitability and Personnel Security

The Contractor and Subcontractors must insert the substance of this section in all subcontracts.

http://www.gsa.gov/directives

File details come from the government source that posted it. Updated .