Requirements PWS CFP November 23.pdf

PDF 572 KB Posted

Attached to
College Financial Planning Federal contract opportunity
Solicitation number
AP1127
Issued by
Department of Education

About this file

This request for information (RFI) seeks information from potential offerors for the College Financing Plan requirement. The College Financing Plan is a standardized aid award letter that participating institutions use to notify students about their financial aid package and net price. It includes graduation rate and median borrowing data. The U.S. Department of Education is conducting market research and determining interest and capability for this requirement. Information submitted in response to the RFI may aid in finalizing the acquisition strategy. The College Financing Plan became available in 2013 and has been modified since. This RFI is not a request for proposal but invites information on relevant knowledge, skills, and capabilities.

View the file

Other files for this federal contract opportunity

Other files attached to College Financial Planning, newest first.
File Type Posted
RFI Instructions 1.11.2024.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

COLLEGE FINANCING PLAN

REQUIREMENTS

PERFORMANCE WORK STATEMENT

I. Introduction

A. Background

The College Financing Plan is a model aid award letter participating institutions use to notify students about their financial aid package with a special focus on the net price a student is responsible for paying after subtracting grant aid. The standardized form is designed to simplify the information prospective students receive about costs and financial aid so they can easily compare institutions and make informed decisions about where to attend school. The College Financing Plan (CFP) became available for use beginning in the 2013-2014 award year and has been modified several times since then, most recently in 2020.

B. Process and Rationale

The requirement for the CFP will be 60 months long. Within the 60 months, the CFP forms and documents are updated yearly, in July. The contractor will be sent updates to forms in May for updating. All updates and corrections will be completed within a 5-month period, by September 31.

II. Scope of Work

Independently and not as an agent of the United States Government, the contractor shall provide all personnel, materials, services, and facilities necessary for the project and perform the tasks as described below.

Task 1. Management

The contractor shall manage this project in an efficient manner that fosters communications with staff, the Contracting Officer's Representative (COR), and potential users of the data.

Subtask 1.1 Post Award Kick-Off Meeting

Within seven calendar days after contract award, the contract’s project director and other key project staff as identified in the proposal shall meet with the Contracting Officer, the Contracting Specialist, the COR, and other appropriate ED staff to review overall contract tasks, to identify potential problems and possible solutions, and to discuss areas of concern related to the proposed project staffing plan and other management requirements. The primary purpose of this meeting is to refine the management, staffing and scheduling plans. These refinements are not to alter the specifications of the contract, but to provide management information for use by both the contractor and the government in monitoring the work to be performed. This meeting is also to help the contractor to make use of the experience and materials that ED staff has gained over the years.

Subtask 1.2 Security Screening of Key Personnel

The contractor shall comply with all requirements of Departmental Directive: Contractor Employee Personnel Security Screenings (OM: 5-101). Positions under this task order require a 5c (Moderate) and 6c (High) clearance level

Subtask 1.3: Completion of Required Training

The contractor employees working in direct support of this contract shall complete the following training:

• The contractor shall attend the Department’s quarterly IT Security Awareness Training.

The training dates, locations and other information will be provided by the Contracting Officer's Representative (COR). The contractor shall report the status of contractor compliance when requested by the COR.

• The contractor shall complete other contractor training requirements as identified and required by the Department.

Deliverable(s): Due/Scheduled date Summary of post award kick-off meeting

One week after post award meeting

Security Screening of Key Personnel

As required by Departmental Directive: Contractor Employee Personnel Security Screenings (OM: 5- 101)

Required Security Training Ongoing, as required by Department

Subtask 1.4 Monthly Reports The contractor shall

• Submit monthly reports from May until September on the progress made in accomplishing each of the project tasks. These reports shall be submitted via IPP to the CS, CO, and the COR. The invoice and documentation of expenses shall be submitted simultaneously with the monthly report.

Deliverable(s): Due/Scheduled date Monthly Reports Monthly (May - September) 15th

Task 2. College Financing Plan

Subtask 2.1 Annual Updates and Maintenance (Undergraduate template) The contractor shall

• Perform annual updates to and maintenance of the Department’s College Financing Plan template, as requested.

• Provide an annotated College Financing Plan. This will describe and clarify the elements on the Financing Plan.

Subtask 2.1.2 Annual Updates and Maintenance (Graduate and Professional School template) The contractor shall

• Perform annual updates to and maintenance of the Department’s College Financing Plan template, as requested.

• Provide an annotated College Financing Plan. This will describe and clarify the elements on the Financing Plan.

Deliverable(s) Due Date

New and Annotated College Financing Plan templates (undergraduate) delivered

Annually beginning on July 1, 2024

New and Annotated College Financing Plan template (graduate/professional school) delivered

Annually beginning on July

508 compliant templates Annually beginning on July

Subtask 2.2 User Guide and Documentation The contractor shall

• Update the technical guide to reflect revisions to the undergraduate and graduate templates. The contractor shall update and revise the frequently asked questions (FAQs).

• Will provide the updated HTML specifications.

Deliverable(s) Due Date

Updated technical guides and FAQs (undergraduate, graduate/ professional school)

To be released with College Financing Plan

HTML Specifications (undergraduate, graduate/professional school students)

To be released with College Financing Plan

508 compliant version of the guides Same as above

Task 3 (optional) additional updates

Any additional updates that are requested during the October – April timeframe will occur under optional Task 3. These updates will be in additional to the May – September updates..

If requested, the contractor shall:

• Provide additional updates to the Undergraduate College Financing Plan template.

• Provide an updated Undergraduate annotated College Financing Plan.

• Provide additional updates to the Graduate/Professional School College Financing Plan template.

• Provide an updated Graduate/Professional Schoo annotated College Financing Plan.

• Provide an update to the technical guides to reflect revisions to the undergraduate and graduate templates.

• Provide the updated HTML specifications (undergrade and graduate/professional school).

Deliverable(s) Due/Scheduled Date Additional Updates to Undergraduate CFP and annotated plan

TBD

Additional Updates to Graduate/Professional School CFP and annotated plan

TBD

Updated Technical Guides TBD HTML Specifications TBD

Task 4 (optional) Transition

The contractor shall:

• Provide a transition plan of maintenance and support activities, specifically including turnover activities at the end of the contract, or whichever option year is not exercised.

• Provide a long-term transition of College Financing Plan maintenance and support activities. During the last three months of this task order, the contractor and ED team shall provide for a smooth transition to a successor contractor for long-term operations.

• Transition for the new College Finance Plan contract will include a series of formal meetings with staff from PPI, the COR, the current contractor, and the new contractor.

The contractor shall propose a list of anticipated meetings over a period of four weeks.

The contractor shall provide an agenda for up to four transition meetings. The current contractor shall provide documentation of all system requirements and databases.

Deliverable(s) Due/Scheduled Date Transition Plan 3 months before end of contract

Documentation* 3 months before end of contract Meeting Agendas 3 months before end of contract

*See Records Management section

Summary and Timeline of Deliverables Task Deliverable Due Date

1.1 Post Award meeting summary One week after post award meeting

1.2 Required Security Training Ongoing, as required by Department

1.3 Security Screening of Key

Personnel As required by Departmental Directive:

Contractor

Employee Personnel Security Screenings

(OM: 5-101)

1.4 Monthly reports Monthly (May - September) 15th

2.1 New and Annotated College

Financing Plan templates delivered (undergraduate)

Annually beginning on July 1, 2024

2.1.2

New and Annotated College Financing Plan template delivered (graduate/professional school) delivered

Annually beginning on July 1, 2024

2.2 Updated technical guides and

FAQs delivered (undergraduate, graduate/professional school)

To be released with College Financing Plan

2.3 HTML Specifications delivered

(undergraduate, graduate/professional school)

To be released with College Financing Plan

3 Additional Updates (optional) TBD 4 Transition (optional) TBD

III. Inspection and Acceptance Procedures

The contractor shall consult with the COR regarding any questions on major decisions regarding the development of deliverables. This process will include monthly phone calls to the Department and biannual visits to the Department to discuss potential project problems and progress. Preliminary drafts of all deliverables shall be provided at the earliest possible time to assure the final products will meet expectations with minimal revision.

Each deliverable shall include two revisions based on feedback from PPI. All materials shall be approved before release. No deliverables or data shall be released to anyone without the COR’s approval.

For each of the deliverables as indicated, the COR will provide feedback on them or provide written notice within 14 days from receipt.

All work performed by the contractor shall conform to all National Center for Education Statistics Statistical Standards, Style Standards and Web Standards. These standards can be found on the NCES website using the following links:

NCES Statistical Standards-http://nces.ed.gov/statprog

NCES Style Standards - http://nces.ed.gov/statprog/style.asp NCES Web Standards – See Appendix A http://nces.ed.gov/statprog http://nces.ed.gov/statprog/style.asp

The Contractor shall ensure that any non-Federal sponsored websites or content (outside of .gov, .mil, .Fed.us, etc.) that is linked to complies with “ED.gov” Management and Publishing Policies” at http://www2.ed.gov/internal/wwwstds.html#link and the OMB Memorandum http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-04.pdf.

508 Compliance standards can be found on the following websites:

The Matterhorn Protocol 1.1 – PDF Association

Web Content Accessibility Guidelines (WCAG) 2.1 (w3.org)

ISO 32000 (PDF) – PDF Association

IV. Summary of Abbreviations

CFP – College Financing Plan COR - Contracting Officer Representative CO - Contracting Officer CS - Contracting Specialist ED - U.S. Department of Education HEOA - Higher Education Opportunity Act IPEDS - Integrated Postsecondary Education Data System IPP - Invoice Processing Platform IT - Internet Technology NCES - National Center for Education Statistics OCIO - Office of the Chief Information Officer OPE - Office of Postsecondary Education PPI - Planning, Policy and Innovation The Department or ED - U.S. Department of Education

V. Security Information

Job Aid for Addressing Cybersecurity Requirements in ED IT Procurements Version: Nov 15, 2017

This is a Job Aid to assist Contracting Officer’s Representatives (CORs), Information System Owners (ISOs), Information System Security Officers (ISSOs), Program Managers, Project Managers (PMs), Source Selection Authorities (SSAs), and any other ED staff in the process of incorporating Information Technology (IT) security language for instances where ED/FSA have requirements to procure, develop, operate, modify, or maintain IT applications, or IT systems housing, storing, transmitting, processing, or receiving ED data or data that ED has permanent or temporary custody of, and is responsible for. This also applies to procurements for information resources and IT services, and should be reviewed for applicability to service level agreements (SLAs) involving IT and information resources.

ED/FSA staffs should work with your ISSO or with the OCIO (IAS) team, for any assistance required in making use of this job aid when developing statements of work (SOWs), statements of objectives (SSOs), SLAs, or any other procurement artifacts that need to be developed that http://www2.ed.gov/internal/wwwstds.html#link http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-04.pdf https://www.pdfa.org/resource/the-matterhorn-protocol/ https://www.w3.org/TR/WCAG21/ https://www.pdfa.org/resource/iso-32000-pdf/ involve IT and information resources. This document contains a large sampling of requirements statements for cybersecurity. Not all of these requirements statements will be applicable to every procurement. Expert assistance must be obtained from Department and FSA cybersecurity subject matter experts (SMEs) in order to determine the requirements statements that are most appropriate and applicable to your situation.

This document is organized into three sections: (1) Recommended language for all ED IT procurement that incorporate requirements to develop, operate, modify, or maintain IT applications or IT systems housing, storing, transmitting, processing, or receiving ED data or data that ED has permanent or temporary custody of, and is responsible for, and, (2) Situational language for IT acquisitions that meet certain conditions requiring the situational language, and

(3) Clauses to be provided by the ED/FSA contracts offices.

1. Recommended ED IT Security Language for ED IT acquisitions that incorporate requirements to procure, develop, operate, modify, or maintain IT applications or IT systems housing, storing, transmitting, processing, or receiving ED data or data that ED has permanent or temporary custody of, and is responsible for

The contractor shall:

• Complete/update the appropriate level of Security Accreditation (SA) documentation per NIST Risk Management Framework guidance, security controls testing, interagency security agreements (ISAs), and risk assessments in support of government issuance of security assessment and authorization to operate (ATO) decisions

• Ensure that systems/products/applications have the ability to facilitate single-sign-on capabilities and required support for HSPD 12 Personal Identity Verification (PIV) enablement and integration

• Include the capability for network traffic that flows between externally hosted systems and networks, to/from Department systems and networks, to be routed through one of the Department’s Trusted Internet Connections (TIC) gateways as part of the solution configuration. Implement controls to ensuring all possible traffic, including mobile and cloud, goes through a TIC. Implement connections between Department systems and networks with externally hosted systems that are in compliance with the requirements of the Trusted Internet Connections (TIC) initiative

• Architect contractor hosting environments to use security isolation and network segmentation principles in order to ensure that the environments are properly protected against an unauthorized access and threat from adversaries who may strive to move laterally across internal Department or contractor hosted systems and network segments.

• Provide an automated capability and process to scan and assess all systems and assets, and associated logs for malicious indicators of compromise (IOCs) identified by the Department regarding priority threat-actor Techniques, Tactics, and Procedures (TTPs);

the contractor is required to have the capability to scan for indicators of compromise within 24 hours of receipt of the indicators provided by the Department of Education from the Department of Homeland Security

• Implement and maintain capabilities and processes to support the timely detection of, reporting, and rapid response and recovery to cyber incidents in accordance with timelines and requirements specified in Federal guidance and Department cybersecurity incident reporting policy guidance

• In support of cybersecurity performance measure reporting, the contractor shall implement and maintain an automated software asset management/inventory and hardware asset inventory capability (e.g. scans/device discovery processes) at the enterprise-level.

• Implement capabilities to rapidly deploy emergency security patches and implement specific security control enhancements as directed by the Department of Homeland Security to all Federal Departments via mechanisms such as the DHS Cybersecurity Coordination, Assessment, and Response (C-CAR) action items, and DHS Binding Operational Directives (BODs).

• Implement capabilities and processes to patch all critical vulnerabilities identified to the Department of Education by DHS immediately or, at a minimum, within 30 days of patch release.

• Ensure robust physical and cybersecurity protections are in place for all of the Department’s high value assets (HVAs). The identification of HVAs by the Department will be an ongoing activity due to the dynamic nature of cybersecurity risks.

• Implement remote access solutions that only use multi-factor authentication solutions and that prohibit the use of split tunneling and/or dual-connected remote hosts where the connecting device has two active connections.

• Implement remote access solutions that scan for malware before allowing full connections and that time out after 30 minutes (or less) of inactivity and require re-authentication to re-establish a session

• Implement capabilities for all incoming email traffic to pass through anti-phishing and anti-spam filtration at the outermost border mail agent or server

• Implement capabilities for all incoming email traffic to be analyzed using sender authentication protocols (e.g., DKIM, DMARC, VBR, SPF, iprev)

• Implement capabilities that ensure that incoming email traffic is analyzed using a reputation filter (to perform threat assessment of sender)

• Implement capabilities that ensure that incoming email traffic is analyzed for detection of clickable URLs, embedded content, and attachments; and incoming email traffic is first analyzed for suspicious or potentially nefarious attachments and opened in a sandboxed environment or detonation chamber

• Implement capabilities for all outbound communications traffic to be checked at the external boundaries to detect encrypted exfiltration of information (i.e. capability to decrypt/interrogate and re-encrypt)

• Implement effective network segmentation design and security solutions to limit potential threats from adversaries attempting lateral movement across systems on the Department’s (or contractor’s networks), and also to better protect and securely isolate the Department’s HVAs

• Implement and maintain Information Security Continuous Monitoring (ISCM) and Continuous Diagnostics and Mitigation (CDM) capabilities for all IT assets to be subject to an automated inventory, configuration, and vulnerability management capability, with real time reporting

• Implement and maintain strong authentication capabilities requiring the technical enforcement of all users being required to use a Personal Identity Verification (PIV) card to authenticate to the network, (with exceptions for a very limited set of users specifically approved by the Department)

• Develop and maintain (or update existing) System Security Plans (SSP) and security controls assessment (SCA) test plans for the network general support system (GSS), and infrastructure systems

• Provide support to creating the security assessment and authorization (or accreditation) (SA&A) packages and documentation in accordance with the Risk Management Framework guidance and processes specified by NIST and Department guidance

• Implement security configurations on all IT assets and systems using DISA STIGs and other industry recognized best practices or guidance

• Perform security configuration management to include configuring all Windows based systems with the latest United States Government Configuration Baseline (USGCB) security settings available from the NIST website

• Support annual or emergent security audits and security scans that may be performed by the Office of Inspector General (OIG), the General Accountability Office (GAO), or the Department of Homeland Security (DHS)

• The contractor shall provide availability and accessibility to the Department, to the OIG, and to any third party vendors designated by the Department to: 1) Review audit findings; 2) Determine if corrective actions were properly implemented and the associated audit findings were properly closed; 3) Support cybersecurity incident analysis and forensics activities

• Produce scheduled Monthly/Quarterly/Annual security performance measure reports that align to the Department’s cybersecurity performance measure reporting requirements specified by OMB for FISMA, the President’s cybersecurity Cross Agency Priority (CAP) goals and targets, and CyberScope reporting. Security performance measure reports shall use the format and template specified in the Annual CIO FISMA metrics specified by OMB and DHS.

• Provide for the encryption for PII, CUI, Data at Rest and data in transit, Encryption solutions applied must be FIPS 140-2 validated.

• Document and track contractor personnel cyber training based on roles

• Develop, maintain, and publish a listing of Contractor-provided security controls, hybrid security controls, and “customer”-provided security controls, in support of systems security assessments and authorizations, and the issuance of authority to operate (ATO) decisions by the Department

• Provide security audit support (e.g. A-123), including scheduled and event-driven audits

• Capture and provide forensic disk images to support security incident analysis, malware analysis, or other investigative requirements (such as specific requests from the OIG or law enforcement)

• Provide support for threat monitoring and analysis, incident response, vulnerability management, risk management, continuous monitoring and reporting and other traditional security operations center activities

• Provide and maintain multi-factor authentication solutions utilizing the Personal Identity Verification (PIV) card (or a Department- approved Level of Authentication -4 solution);

and utilize FIPS 140-2 approved encryption for all remote access requirements

• Provide robust encryption capabilities to include services such as digitally signed and encrypted email, and default encryption for sensitive information held by the Department.

Solutions should be available to enable encryption of as much data at rest and data in transit as possible.

• Identify, perform, track, and report vulnerability and security weakness remediation and mitigation activities through the Department’s Plan of Action and Milestones process (POA&M) in accordance with Departmental information security policy

• Establish, maintain, and execute standard configuration management processes for all cybersecurity software and hardware

• Implement and maintain a Privileged Account Management Solution to improve the identity and access management of user accounts, while also meeting Department targets to tightly control and limit the number of users with elevated privileges

• Implement and maintain tightened processes for managing privileged user accounts, to include implementation of capabilities to limit functions that can be performed when using privileged accounts; limit the duration that privileged users can be logged in; limit the privileged functions that can be performed using remote access; prohibit Internet access when privileged users are performing systems administrations tasks; and ensure that privileged user activities are logged and regularly reviewed

• Document and maintain system security boundaries, system configuration details, and network diagrams, in support of security assessment and authorization to operate (ATO) processes

• Develop and implement processes for revising system security documentation on a scheduled and event-driven basis

• Provide support for maintaining system security documentation in support of FISMA reporting requirements and security compliance status in the Department’s Cyber Security Assessment and Management (CSAM) system

• Develop and submit system security documentation, risk assessments, security controls testing reports, and any required privacy impact analysis (PIA) to the Department in support of the Risk Management Framework processes and ATO decisions for IT environment components

• Develop corrective/remediation plans of action and milestones (POAMs) and strategies to address security audit and assessment findings, and other reports of system security weaknesses or non-compliance

• Develop and maintain a system security architecture; the contractor’s solution shall include effective network segmentation design and solutions to limit lateral movement across systems on the Department’s networks, and also better protect the Department’s HVAs

• Utilize PIV or other approved Level of Assurance 4, as defined in NIST SP 800-63-2 Electronic Authentication Guidelines, compliant Identity and Access Control mechanisms for network/domain administrative enterprise access.

• Maintain near real-time security monitoring and intrusion detection capabilities to enable the contractor and the Department to know the security risk posture of the network at any given time;

• Configure all Windows based systems with the latest United States Government Configuration Baseline (USGCB) security settings available from the NIST website

• Utilize multi-factor authentication, including integration and compliance with HSPD-12 PIV requirements, for all remote access solutions for the Department’s sensitive information systems

• Provide a multi-tier disaster recovery capability that provides the infrastructure and process to meet the recovery requirements of all of its High Value Assets (HVAs), and applications (Mission-Critical, Decision Support, Other)

• Provide IT Disaster Recovery Planning and Management capabilities and support o Define business risk and risk assessment o Develop disaster recovery strategies o Develop disaster recovery plans o Develop IT system contingency plans o Conduct disaster recovery exercises, training and awareness

• Provide Disaster Recovery Operational Services, including Contractor support to the Department in the planning, preparation, implementation, and documentation of a Disaster Recovery Program that includes the capabilities described below:

The contractor, and all sub-contractors, shall comply with the Department of Education’s IT security policy requirements, and other applicable procedures and guidance. The contractor, and all sub-contractors, shall develop and implement management, operational and technical security controls to assure required levels of protection for information systems. The contractor, and all sub-contractors, shall further comply with all applicable Federal IT security requirements including, but not limited to, the Federal Information Security Modernization Act (FISMA) of

2014, Office of Management and Budget (OMB) Circular A-130, Homeland Security Presidential Directives (HSPD), including HSPD-12, Personal Identity Verification (PIV) Enablement and Integration, and single sign-on, the most recent National Institute of Standards and Technology (NIST) special publications, standards and guidance, and the Federal Risk and Authorization Management Program (FedRAMP) requirements and guidance.

These security requirements include, but are not limited to, the successful Security Assessment and Authorization (SA&A) of the system (includes commercially owned and operated systems managed by the commercial vendor and its sub-contractors, supporting Department programs, contracts, and projects); obtaining a full Authority to Operate (ATO) before being granted operational status; performance of annual self-assessments of security controls; annual Contingency Plan testing; performance of periodic vulnerability scans; updating all information system security documentation as changes occur; and other continuous monitoring activities, which may include, mapping, penetration and other intrusive scanning. Full and unfettered access for any of the Department’s third party Managed Security Services Provider (MSSP) or Cyber-operations prevention testers, or vulnerability scanners, or auditors must be granted to access all computers and networks used for this system. Additionally, when there is a significant change to the system’s security posture, the system (Federal and commercial prime- and sub-contractors included) must have a new SA&A, with all required activities to obtain a new ATO, signed by the Authorizing Official (AO).

System security controls shall be designed and implemented consistent with the current, finalized version of the NIST SP 800-53, ‘Recommended Security Controls for Federal Information Systems and Organizations.’ All NIST SP 800-53 controls must be tested / assessed no less than every 3 years, according to federal and Department policy. The risk impact level of the system will be determined via the completion of the Department's inventory form and shall meet the accurate depiction of security categorization as outlined in Federal Information Publishing Standards (FIPS) 199, ‘Standards for Security Categorization of Federal Information and Information Systems.’

System security documentation shall be developed to record and support the implementation of the security controls for the system. This documentation shall be maintained for the life of the system. The contractor, and all sub-contractors, shall review and update the system security documentation at least annually and after significant changes to the system, to ensure the relevance and accurate depiction of the implemented system controls and to reflect changes to the system and its environment of operation. Security documentation must be developed in accordance with the NIST 800 series and Department of Education policy and guidance.

The contractor, and all sub-contractors, shall allow Department employees (or Department designated third party contractors) access to the hosting facility to conduct SA&A activities to include control reviews in accordance with the current, finalized version of the NIST SP 800-53, and the current, finalized version of the NIST SP 800-53A. The contractor, and all sub-contractors, shall be available for interviews and demonstrations of security control compliance to support the SA process and continuous monitoring of system security. In addition, if the system is rated as ‘Moderate’ or ‘High’ for FIPS 199 risk impact, vulnerability scanning and penetration testing shall be performed on the hosting facility and application as part of the

SA&A process. Appropriate access agreements will be reviewed and signed before any scanning or testing occurs.

Identified deficiencies between required security controls within the current, finalized version of the NIST SP 800-53 and the contractor’s, and all sub-contractor’s implementation, as documented in the Risk Assessment Report, System Security Plan (SSP) and Security Assessment Report (SAR), shall be tracked for mitigation through the development of a Plan of Action and Milestones (POA&M) in accordance with Department policy. Depending on the severity of the deficiencies, the Department may require remediation before an ATO is issued.

The contactor shall provide cybersecurity strategies, infrastructure hosting environments, and solutions that comply with the requirements of the Federal Information Security Modernization Act (FISMA), Department cybersecurity policy guidance, and guidance contained in the NIST Special Publications series such as NIST Special Publication 800-53 and other NIST Special Publications. The contractor shall provide solutions that support the Department’s efforts to implement and maintain effective protection activities such as reducing the attack surface and complexity of IT infrastructure; minimizing the use of administrative privileges;

utilizing strong authentication credentials; safeguarding data at rest and in-transit; training personnel; ensuring repeatable processes and procedures; adopting innovative and modern technology; ensuring strict domain separation of critical/sensitive information and information systems; implementing network segmentation architectures to better protect and isolate the Department’s high value assets and most sensitive information and data; and ensuring a current inventory of hardware and software components. The contractor shall include actions and initiatives to implement the NIST Cybersecurity Framework that emphasizes and measures capabilities to “Identify, Protect, Detect, Respond, and Recover,” and ensure that all applicable Service Level Agreements (SLA)s are adhered to, complied with, and satisfied.

All awarded contracts shall ensure that:

1. Their IT product/system is monitored during all hours of operations using entrusted detective/preventive systems;

2. Their IT product/system has current antiviral products installed and operational;

3. Their IT product/system is scanned on a reoccurring basis;

4. Vulnerabilities are remediated in a timely manner on their IT product/system; and

5. Access/view for cyber security situational awareness on their IT product/system is made available to the Department CIRC (cyber incident response capability).

6. All applicable Service Level Agreements (SLA)s are adhered to, complied with, and satisfied.

Internet Protocol version 6 (IPv6) For IPv6, the contractor shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4.

Specific criteria to be deemed IPv6 capable are:

• An IPv6 capable system that meets the IPv6 base requirements defined by the USGv6 Profile (http://www.antd.nist.gov/usgv6/profile.html).

• Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities.

• Systems shall implement IPv4/IPv6 dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems shall employ IPv6.

The contractor shall provide IPv6 technical support for system development, implementation and management.

Per OMB-M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, the following requirements statements should be added to all SOWs/SOOs/PWSs/BPAs/MOUs/IAAs/MOUs/ISAs that include the management of Personally Identifiable Information (PII) and / or Sensitive Personally Identifiable Information (SPII):

• The contractor shall cooperate with and exchange information with agency officials, as determined necessary by the agency, in order to effectively report and manage a suspected or confirmed breach.

• The contractor and subcontractors (at any tier) shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies and to comply with any agency-specific policies for protecting PII;

• The contractor shall complete regular Department training for contractors and subcontractors (at any tier) on how to identify and report a breach;

• The contractor and subcontractors (at any tier) shall report a suspected or confirmed breach in any medium or form, including paper, oral, and electronic, as soon as possible and without unreasonable delay, consistent with the agency's incident management policy and US-CERT notification guidelines;

• The contractor and subcontractors (at any tier) shall maintain capabilities to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector;

• The contractor shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with this Federal and Department PII Breach Response policies (such as OMB-M-17-12), the Department’s breach response plan, and to assist with responding to a breach;

• The contractor shall identify roles and responsibilities, in accordance with Federal and Department PII Breach Response policies (such as OMB-M-17-12), and the agency's breach response plan; and, http://www.antd.nist.gov/usgv6/profile.html

• The contractor shall be aware that a report of a breach shall not, by itself, be interpreted as evidence that the contractor or its subcontractor (at any tier) failed to provide adequate safeguards for PII.

Reporting of Data Security Breaches

If there is a suspected or known breach/disclosure of PII due to lost, theft, intercepted transfer, or other, the contractor must ensure that this breach is reported to the agency as soon as the contractor has knowledge of it. Per Office of Management and Budget Memorandum M-17-12, Federal agencies have a requirement to report breaches of PII security to the United States Computer Emergency Response Team (US-CERT).” The (PO) must notify the department within 30 minutes of discovering the incident (and the agency should not distinguish between suspected or confirmed breaches). The data security plan must be written to reflect this requirement, and the contractor must provide sufficient notification and documentation of the suspected loss, as it is understood at the time of notification to the agency for this requirement to be met. Follow-up reports of the final status of loss events will also be prepared by the contractor within a reasonable period of time as advised by the COR.

2. SITUATIONAL ED IT Security Language (for specific conditions)

• FOR E-MAIL:

In accord with BOD-18-01:

o Email Security: Agencies must configure all internet-facing mail servers to offer STARTTLS, and all second-level agency domains to have valid SPF/DMARC records. Additionally, agencies must ensure Secure Sockets Layer (SSL) v2 and SSLv3 are disabled on mail servers, and 3DES and RC4 ciphers are disabled on mail servers:

o Within one year after issuance of this directive, issued 10-16-2017 (so, due by 10-

16-2018), agencies will be required to set a DMARC policy of “reject” for all second-level domains and mail-sending hosts.

o In accord with OMB Memorandums M-17-06, and M-15-13, and M-08-23, M-10- 23, and with Binding Operational Directive (BOD) BOD-18-01, and with the NIST SP 800-52 and with the NIST SP 800-44, all e-mail applications must have SMTP enabled.

• FOR NON-PUBLIC-FACING WEBSITES:

o Implement capabilities for all inbound network traffic to pass through a web content filter, which provides anti-phishing, anti-malware, and blocking of malicious websites (e.g., fake software updates, fake antivirus offers, and phishing offers) o In accord with OMB Memorandums M-17-06, and M-15-13, and M-08-23, M-10-23, and with Binding Operational Directive (BOD) BOD-18-01, and with the NIST SP 800-52 and with the NIST SP 800-44, all Federal websites and web services must be accessible through a secure connection (HTTPS only, with HSTS), and e-mail applications must have SMTP enabled. The use of HTTPS is encouraged on intranets, but not explicitly required.

o In accord with BOD-18-01: In accord with OMB Memorandum M-08-23, in order to ensure Domain Name System Security (DNSSEC), all federal websites must be hosted on a *.gov location.

• FOR PUBLIC-FACING WEBSITES:

o Implement controls to ensure that all publicly accessible externally hosted Department websites and web services only provide service through a secure connection, (such as the Hypertext Transfer Protocol Secure (HTTPS)).

o Implement controls to ensure that all publicly accessible Department websites and web services only provide service through a secure connection, (such as the Hypertext Transfer Protocol Secure (HTTPS))

In accord with BOD-18-01:

o Web Security: Agencies must ensure all publicly accessible Federal websites and web services provide service through a secure connection (HTTPS-only, with HSTS);

SSLv2 and SSLv3 are disabled on web servers, and DES and RC4 ciphers are disabled on web servers; and must provide a list to DHS of agency second-level domains that can be HSTS preloaded, for which HTTPS will be enforced for all subdomains.

If an official public-facing website will be developed, modified, or maintained, then, in accord with OMB Memorandum M-17-06, each agency must use only an approved .gov or .mil domain for its official public-facing websites. The requirement to use only approved government domains does not apply in circumstances where the agency is a user or a customer of a third-party website or service that resides on a non-governmental domain.

OMB-17-06 Policies and Requirements for Public Websites

• For requirements involving web applications, web servers, and web services, the contractor shall follow the policies, principles, standards, and guidelines on information security and privacy, in accordance with FISMA, and implement security and privacy requirements as set forth in OMB Circular A-130 and National Institute of Standards and Technology (NIST) Special Publication 800-44, Guidelines on Securing Public Web Servers.

• The public expects Federal Government websites to be secure and their interactions with those websites to be private. The contractor shall comply with requirements specified in OMB Memorandum M-15-13, Policy to Require Secure Connections across Federal Websites and Web Services, that requires that all publicly accessible Federal websites and web services only provide service through a secure connection (HTTPS with HSTS).

• The contractor shall use only an approved .gov or .mil domain for official public-facing websites.

The requirement to use only approved government domains does not apply in circumstances where the Department is a user or a customer of a third-party website or service that resides on a non-governmental domain. Department use of third-party websites and applications must comply with all relevant privacy protection requirements and a careful analysis of privacy implications as specified in OMB Memorandum M-10-23, Guidance for Agency Use of Third-Party Websites.

o The contractor shall ensure compliance with Federal requirements to maintain public/external facing servers and services to use native IPv6. All procurements of networked information technology shall comply with Federal Acquisition Regulation (FAR) requirements for use of the U.S. Government IPv6 Profile and Test Program for the completeness and quality of their IPv6 capabilities

• FOR CLOUD SOLUTIONS:

o Implement controls to ensure that all publicly accessible externally hosted Department websites and web services only provide service through a secure connection, (such as the Hypertext Transfer Protocol Secure (HTTPS)).

o Only utilize FedRAMP approved cloud solutions. FedRAMP is mandatory for federal agency cloud deployments and service models at the low and moderate risk impact levels.

o If a cloud solution will be used, then an ED-issued, FedRAMP-Compliant Authorization To Operate (ATO) is a Federal and a Departmental requirement, and one must be obtained.

• FOR CYBEROPERATIONS, PENETRATION TESTING, VULNERABILITY

SCANNING, INTRUSION DETECTION, AND INCIDENT RESPONSE

FUNCTIONS:

o Implement scanning capabilities that assess for vulnerabilities using only Security

Content Automation Protocol (SCAP) validated products o Perform penetration and regular vulnerability testing and scanning of systems, IT devices, and websites. Vulnerability scanning shall be conducted at least monthly, with reports provided to the Department.

o Maintain the tools and capabilities to support asset discovery, to include passive network monitoring, active network monitoring, and automated network mapping o Maintain tools and capabilities to support behavior monitoring, to include NetFlow analysis and network traffic capture, which captures the Transmission Control Protocol/Internet Protocol (TCP/IP) stream, allowing for replay of activity to determine what happened during a breach or incident o Maintain tools and capabilities for intrusion prevention, to include host intrusion prevention systems (HIPS) and network intrusion prevention systems (NIPS) o Maintain a firewall system designed to prevent unauthorized access to or from any contractor systems and network o Maintain tool and capabilities to perform Security Incident/Event Management and Analysis, to include centralized logging, log correlation, and a Security Information and Event Management (SIEM) solution that provides centralized monitoring of security incidents; network behavior analytics to provide behavior-based detection to help protect against zero-day attacks; and a quarantine/sandbox environment that will isolate and analyze live traffic and/or suspected malware o Maintain tools and capabilities to perform vulnerability and risk management and analysis to include threat intelligence threat hunt capabilities, sharing platforms, risk management or trouble ticketing system, anti-malware and anti-phishing services o Maintain tools and capabilities to provide security situational awareness and visibility throughout the enterprise; this includes capabilities for full packet capture that collects detailed network information at the gateway and makes capture data available to analysts; endpoint incident response that enables searches all endpoints for Indicators of Compromise (IOCs) in a rapid fashion; and encrypted traffic inspection o If working as a SOC contractor or subcontractor, will provide a Daily Morning Report, 7 days per week, that summarizes the noteworthy daily security activities.

Examples include activities such as the daily count of security incidents detected (viruses, malware, etc. . .), email traffic analysis for spam and phishing attempts, vulnerability scan results and progress in closing open weaknesses from scan results.

The contractor is encouraged to propose a world class daily security morning report format, with the most noteworthy performance measures, to include any graphic displays, and charts to enhance reporting o Provide and maintain automated means of discovering, monitoring, and protecting sensitive data to ensure protection of data in motion, at rest, and in use o Provide and maintain an automated means of preventing unauthorized users and computing devices from accessing contractor hosted environments, including access via remote access, wired and wireless technologies o Provide and maintain externally facing web application firewall capabilities providing inbound and outbound traffic filtering o Provide and maintain an Out of Band network device management solution o Administer, operate, maintain, configure and tune cybersecurity software and hardware o Provide full government visibility of continuous monitoring tool configurations and output on a real-time basis as well as historical data/logs o Maintain the capability to perform periodic penetration testing, and also support for external agency red team testing, penetration testing, cyber hygiene web site vulnerability scanning tests and vulnerability assessments that the Department may need to conduct

• FOR GOVERNMENT FURNISHED EQUIPMENT (GFE):

o Implement capabilities to ensure that GFE endpoints are covered by an intrusion prevention system, and by an antivirus (AV) solution using file reputation services, checking files against cloud-hosted, continuously updated malware information o Implement capabilities to ensure that GFE endpoints are covered by an anti-exploitation tool (e.g., Microsoft’s Enhanced Mitigation Experience Toolkit (EMET) or similar) o Implement capabilities to ensure that GFE endpoints are protected by a browser-based (e.g., Microsoft SmartScreen Filter, Microsoft Phishing Filter, etc.) or enterprise-based tool to block known phishing websites and IP addresses

3. CLAUSES (Check with your Contracting Officer or COR for the most recent required clauses).

Records Management

Requirements:

1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law.

Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

4. The Department of Education (ED) and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of [Agency] or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .