II_2_FISMA_ Contract_Language_IT_AR_FINAL.pdf
PDF 317 KB Posted
- Attached to
- Pilot IRS EDCMO AR RFP Federal contract opportunity
- Solicitation number
- Not on record
About this file
This document outlines a draft Request for Proposal (RFP) for an Internal Revenue Service (IRS) Augmented Reality (AR) pilot program. The RFP seeks proposals for an AR solution to be issued the week of August 30th, with proposals due the week of September 7th. The IRS will hold a listening session on August 31st for interested vendors to ask questions about the draft RFP requirements. Vendors must register for the session by August 24th by emailing the points of contact provided with names and contact information for up to two attendees. The session will not be recorded and questions and answers will not be transcribed. The purpose is to gather vendor feedback on the draft RFP in lieu of a traditional question and answer period.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| II_1_Pilot_IRS_AR_RFP_Final.pdf | ||
| II_2_Clauses_Provision_Attachment_AR_FINAL.pdf | ||
| II_1_Pilot_IRS_Draft_RFP.pdf | ||
| II_2_Clauses_Provision_Attachment_AR_Draft.pdf | ||
| II_2_FISMA_ Contract_Language_IT_AR_Draft.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FISMA Contract Language (IT Systems / Applications or Services)
Revised July 2021
INFORMATION SECURITY / FEDERAL INFORMATION SECURITY
MODERNIZATION ACT (FISMA)
Pursuant to the Federal Information Security Modernization Act (FISMA), Title III of the E-Government Act of 2014 (Pub. L. 113–283), the contractor shall provide minimum security controls required to protect Federal information and information systems in accordance with NIST Special Publication 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. The contractor shall provide a risk-based process for selecting the security controls necessary to satisfy the minimum-security requirements in accordance with Federal Information Processing Standard (FIPS) 199. The term information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentially, integrity and availability. An information system is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. Information resources include information and related resources, such as personnel, equipment, funds, and information technology.
The contractor shall provide information security protections commensurate with the risk and magnitude of the harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information collected or maintained by or on behalf of the agency;
or information systems used or operated by an agency or by a contractor or subcontractor of an agency. This applies to individuals and organizations having contractual arrangements with the IRS, including employees, contractors, vendors, and outsourcing providers, which use or operate information technology systems containing IRS data.
IRS information or information system with a FIPS 199 security categorization impact level of low, moderate or high, and those systems identified by the As Built Architecture (ABA) and agency FISMA Master Inventory.
The potential impact values for confidentiality, integrity, and availability may not always be the same for a particular information system; the high-water mark concept must be used to determine the overall impact level of the information system. Thus, a low-impact system is an information system in which all three of the security objectives are low. A moderate-impact system is an information system in which at least one of the security objectives is moderate and no security objective is greater than moderate. And finally, a high-impact system is an information system in which at least one security objective is high. The determination of information system impact levels must be accomplished prior to the consideration of minimum-security requirements and the selection of appropriate security controls for those information systems.
Federal Risk and Authorization Management Program (FedRAMP) security requirements shall be applied to all IRS cloud services and products and shall be implemented and complied with as part of a competed FedRAMP authorization.
The enforcement of FedRAMP requirements shall be done through Service Level Agreements
(SLA)/Contracts. IRS shall utilize aggregated and individual security categorization information when assessing interagency and Cloud Service Provider (CSP) connections with different FIPS 199 Category Impact levels. (e.g., High Impact system connecting to Moderate Impact system etc.)
THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)
GUIDANCE FOR INFORMATION SECURITY
The contractor shall follow Information Security guidance established by the National Institute of Standards and Technology (NIST). The contractor shall establish the minimum-security controls identified in NIST Special Publication 800-53 Rev. 5, Security and Privacy Controls for Federal Information Systems and Organizations for FISMA compliance. The contractor shall follow the best practices and guidance established by NIST Special Publication 800 Series and Federal Information Processing Standards (FIPS) for computer security. The IRS may determine such applicable Information Technology (IT) Security standards and policies.
ADD TO ADDENDUM H OF CLAUSES SECTION
Office of the President Management and Budget (OMB) Policies for Security of Federal Automated Information Resources
The contractor shall implement protections for personally identifiable information being accessed remotely or transported outside of the agency’s secured, physical perimeter, and/or stored offsite.
In those instances where personally identifiable information is transported to a remote site of the contractor, the contractor shall implement NIST Special Publication 800-53 Rev. 5, Security and Privacy Controls for Federal Information Systems and Organizations security controls and IRS specific security procedures to ensure that information is transported in encrypted form. The contractor shall comply with OMB Circular Policy M-17-12: Preparing for and Responding to a Breach of Personally Identifiable Information.
TREASURY / IRS POLICIES FOR INFORMATION TECHNOLOGY (IT) SECURITY
The contractor shall comply with FedRAMP Framework, Department of Treasury Directive TD P 85- 01, Internal Revenue Manual (IRM) 10.8.1, Information Technology (IT) Security Policy and Guidance and Internal Revenue Manual (IRM) 10.8.24, Information Technology (IT) Security, Cloud Computing Security Policy. The contractor shall comply with IRS IRMs when developing or administering IRS information and information systems.
The contractor shall comply with the Taxpayer Browsing Protection Act of 1997 - Unauthorized Access (UNAX), the Act amends the Internal Revenue Code 6103 of 1986 to prevent the unauthorized inspection of taxpayer returns or tax return information.
The contractor/contractor personnel are bound by the Records Management by Federal Agencies (44 U.S.C. Chapter 31) regarding the care and retention of federal records.
FEDERAL INFORMATION PROCESSING STANDARD (FIPS)-201-2
Homeland Security Presidential Directive-12 [HSPD-12], August 27, 2004, established the requirements for a common identification standard for identity credentials issued by Federal departments and agencies to Federal employees and contractors (including contractor employees) for gaining physical access to federally controlled facilities and logical access to federally controlled information systems. HSPD-12 directs the Department of Commerce to develop a FIPS publication to define such a common identity credential. In accordance with HSPD-12, this Standard defines the technical requirements for the identity credential that:
(a) is issued based on sound criteria for verifying an individual employee’s identity;
(b) is strongly resistant to identity fraud, tampering, counterfeiting, and terrorist exploitation;
(c) can be rapidly authenticated electronically; and
(d) is issued only by providers whose reliability has been established by an official accreditation process.
The standard for a Personal Identity Verification (PIV) system is based on secure and reliable forms of identity credentials issued by the Federal government to its contractors. These credentials are intended to authenticate individuals who require access to federally controlled facilities, information systems, and applications. A PIV Card must be personalized with identity information for the individual to whom the card is issued, to perform identity verification both by humans and automated systems. Humans can use the physical card for visual comparisons, whereas automated systems can use the electronically stored data on the card to conduct automated identity verification
IRS will determine the level of security and authentication mechanisms appropriate for their applications and will employ only information technology products on the FIPS 201-approved products list for PIV capability implementation within organization information systems.
CSPs must review SP 800-63-3, use its decision trees to obtain an overview of all digital identity requirements, and read the applicable 800-63 volumes to determine specific requirements that apply to their cloud offerings.
SECURITY AUTHORIZATION / CERTIFICATION AND ACCREDITATION PROCESS
CSP/Contractor systems that collect, maintain, contain or use agency information or an information system on behalf of the agency (a General Support System (GSS), with a FIPS 199 security categorization) must ensure annual reviews and continued security certification and accreditation. Some of the key elements of this IT risk and impact assessment process are project security deliverables such as the System Security Plan (SSP), Information System Contingency Plan (ISCP), Interconnection Security Agreement (ISA), Security Risk Assessment (SRAs), Data Impact Assessments (DIAs), Risk Analyses, Security Threat Analyses, Audit Plan, Source Code Review, Security Control Assessment (SCA), and/or Event-Driven Security Control Assessment (ED-SCA). All systems that complete this process will, at a minimum, meet FedRAMP, Treasury and IRS requirements.
INFORMATION SYSTEMS AND INFORMATION SECURITY CONTROLS FOR
CONTRACTING ACTIONS SUBJECT TO IRS PUBLICATION 4812 REVISION 10-201
(Note: Publication 4812 is a layperson's guide to NIST SP 800-53, Rev. 5 when access to IRS information or information systems under contracts for services on behalf of the IRS is outside of IRS controlled facilities or the direct control of the Service as opposed to Internal Revenue Manual
10.8.1 - Information Technology (IT) Security, Policy and Guidance, which applies when contractors are accessing IRS information and information systems at Government controlled facilities.)
In performance of this contract, the contractor agrees to comply with the following requirements and assumes responsibility for compliance by its employees and subcontractors (and their employees):
(a) General. The contractor shall ensure IRS information and information systems (those of the IRS and/or the contractor, as appropriate) are always protected. In order to do so, the contractor shall develop, implement, and maintain effective controls and methodologies in its business processes, physical environments, and human capital or personnel practices that meet or otherwise adhere to the security controls, requirements, and objectives described in applicable security control guidelines, and their respective contracts.
(b) The contractor will be required to input data into a system, to be defined by the IRS, to describe the security controls being used to protect information.
(c) Publication (PUB) 4812 Applicability. This contracting action is subject to Publication 4812 – Contractor Security & Privacy Controls. PUB 4812 is available at: https://www.irs.gov/pub/irs-pdf/p4812.pdf
CONTRACTOR (AND SUBCONTRACTOR) SITE AND INFORMATION
TECHNOLOGY (SOFTWARE, HARDWARE AND DATA) LOCATION
The CSP/Contractor headquarters, infrastructure, servers (including back-up servers) and data must be physically located in the United States (or U.S. territories).
The infrastructure associated with services outsourced by the CSP/Contractor must located in the United States (or U.S. territories).
The current version and all subsequent versions of the software implemented by the CSP/Contractor must be escrowed in the United States (or U.S. territories) at the CSP’s expense to protect the code in the event the CSP declares bankruptcy.
Data stored outside the United States cannot be protected under the Privacy Act of 1974 or safe harbor framework and may allow for certain local or foreign law enforcement authorities to search IRS data pursuant to a court order, subpoena, or informal request outside the control of the IRS.
The Clarifying Lawful Overseas Use of Data ("CLOUD") Act enacted into law on March 23, 2018 provides that U.S. law-enforcement orders issued under the Stored Communications Act (SCA) may reach certain data located in other countries.
https://www.irs.gov/irm/part10/irm_10-008-001.html https://www.irs.gov/irm/part10/irm_10-008-001.html https://www.irs.gov/pub/irs-pdf/p4812.pdf
Recognizing the limits of existing law enforcement tools and privacy laws to govern requests for electronic evidence in the age of cloud computing, the CLOUD Act establishes processes and procedures for law enforcement requests for data in other countries.
Although the Act expands the geographic scope of the SCA, it does not change who is subject to SCA orders or what type of data is subject to U.S. law-enforcement requests under the SCA.
The CLOUD Act lays out the circumstances under which a "provider of electronic communication service or remote computing service" must comply with a U.S. law-enforcement order to disclose data within its "possession, custody, or control," even when that data is "located … outside the United States."
ALTERNATE STORAGE
The CSP/Contractor shall establish an alternate storage site including necessary agreements to permit the storage and retrieval of information system backup information. The alternate storage site shall be geographically separated within the United States (or U.S. territories) from the contractor site to enable recovery of operations. The alternate storage site is separated from the primary storage site so as not to be susceptible to the same hazards and identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outlines explicit mitigation actions. All backup data that contains SBU information shall be encrypted.
The alternate storage site shall provide information security safeguards equivalent to that of the primary site.
BACKUPS
Backups must be provided as part of the CSP service offering.
All backup data that contains SBU information shall be encrypted.
(1) The IRS or CSP/Contractor shall conduct backups for information contained in the information system at the following frequency:
• User-level: daily incremental; weekly full
• System-level: daily incremental; weekly full
• Information system configuration; daily incremental; weekly full
Note: The defined backup frequencies are above IRM 10.8.1 baseline and assigned by FedRAMP.
(2) The CSP/Contractor shall maintain:
• At least three backup copies of user-level information (at least one of which is available online) or provides an equivalent alternative.
• At least three backup copies of system-level information (at least one of which is available online) or provides an equivalent alternative.
• At least three backup copies of information system documentation including security information (at least one of which is available online) or provides an equivalent alternative.
Note: This requirement is defined by FedRAMP.
(3) The IRS or CSP/Contractor shall determine what elements of the cloud environment require the Information System Backup control.
(4) The CSP/Contractor shall determine how Information System Backup is going to be verified and the appropriate periodicity of the check.
(5) Backup copies of the operating system (i.e., deployed operating system with agency defined configurations and controls) and other critical information system software, as well as copies of the information system inventory (including hardware, software, and firmware components) shall be stored in a separate facility or in a fire-rated container that is not collocated with the operational system.
Note: This requirement is assigned to Moderate and High impact systems by FedRAMP.
DATA LOSS PREVENTION (DLP) SOFTWARE
The CSP/Contractor shall implement data loss prevention (DLP) software to assure existing software will operate effectively in the cloud.
The CSP/Contractor shall be responsible for all patching and vulnerability management (PVM) of software and other systems’ components supporting services provided under this agreement so as to prevent proactively the exploitation of IT vulnerabilities that may exist within the CSP/Contractor operating environment. Such patching and vulnerability management shall meet the requirements and recommendations of NIST SP 800-40, as amended, with special emphasis on assuring that the vendor’s PVM systems and programs apply standardized configurations with automated continuous monitoring of the same to assess and mitigate risks associated with known and unknown IT vulnerabilities in the CSP/Contractor operating environment.
Furthermore, the CSP/Contractor shall apply standardized and automated acceptable versioning control systems that use a centralized model to capture, store, and authorize all software development control functions on a shared device that is accessible to all developers authorized to revise software supporting the services provided under this agreement. Such versioning control systems shall be configured and maintained to make sure all software products deployed in the CSP/Contractor operating environment and serving the IRS are compatible with existing systems and architecture of the IRS.
CONTINUOUS MONITORING BASELINE CONTRACT DELIVERABLES
Cloud Continuous Monitoring baseline contract deliverables are needed as applicable, such as, but not limited to:
• Weekly Security Status Report
• Monthly Security Status Report
• Continuous Monitoring Plan
• Security Configuration and Change Management Plan
• Security Patch Management Plan
• Security Incident Handling, Monitoring and Response Plan
• Information System Contingency Plan (ISCP)
• Security Concept of Operations (Security CONOPS)
• Access Management Plan (AMP)
• System Security Plan (SSP)
• Authorization Boundary Memorandum
• Interconnection Security Agreements (ISA)
• Security Control Assessment (SCA) Test Plan
• Security Assessment Report (SAR) Mitigation Plan
• Privacy/Civil Liberties Impact Assessment (PCLIA)
• State of Security (SoS) Package
• FISMA Compliance Reports including, but not limited to, inventory, inventory change log, security configuration compliance reports, personal security, and POA&Ms.
• Information Security Status Package
• Alternate Site Processing Environment (ASPE) Plan
• Executive Summary of Analytical Results and Recommendations
• Key Management Practices Statement
• Contractor Security Assessments (CSA) Test Plan
• Configuration Compliance Summary Report
• Security Incident Report
• Mitigation Report
• FSTAR Mitigation Plan
• Incident Response Test Report
USE OF OUTSOURCED / CONTRACTOR FACILITIES TO PROCESS IRS SBU DATA
The infrastructure associated with services outsourced by the CSP/contractor must located in the United States (or U.S. territories).
If IRS products/applications/data/services/solutions are hosted and/or managed by a CSP (outside the IRS network boundaries/facilities (e.g., outsourced)) then all such products/applications/data/services/solutions shall go through (and maintain) the Federal Risk and Authorization Management Program (FedRAMP) certification, and meet all of the IRS unique business/legal requirements (including applicable PUB 4812 requirements, etc.).
(Note: FedRAMP is mandatory for all IRS cloud deployments and cloud service models at the Federal Information Processing Standards (FIPS) 199 Low, Moderate and High impact levels.
FedRAMP does not apply for internal housed IRS systems that are operated for IRS use only.
This service model would be considered an On-Site-Private Cloud.)
Special contract language shall be included in all types of Cloud Service Provider (CSP) contracts/non-disclosure agreements/Service Level agreements to address all potential CSP risks (e.g., Data Governance, Data Protection, Data Location, Data Availability, Data Confidentiality, Data Integrity, Data Access, Data Backup, Data Encryption, Data Breach Notification, Contract http://www.gsa.gov/portal/category/102371?utm_source=OCM&%3Bamp%3Butm_medium=print-radio&%3Bamp%3Butm_term=HP_13_SpecialTopics_fedramp&%3Bamp%3Butm_campaign=shortcuts http://mits.web.irs.gov/cybersecurity/Divisions/SRM/Compliance/InfraReviews.htm
Exit Conditions, Contract Termination Conditions, Data Disposal, Data Retention, User/Device/Service AAA services (e.g., Authentication, Authorization, Audit Logging, Background Checks etc.). The Vendor shall pay special attention to the logical and physical separation of IRS data, applications, and communications to maintain security. Vendors are encouraged to manage any cloud environments containing IRS data with only other Federal or State and local Government customers operating at the same security level. The IRS shall control and maintain the centralized/authoritative control (in-house) of ALL the IRS authorized Users/Devices/Services Authentication, Authorization, and Auditing (AAA) functions, even if a particular IRS application/data/service/solution is hosted in a third-party cloud environment.
Outsourced operations shall report monthly for FISMA and Treasury submission. This includes all systems in the following environments: production, disaster recovery, training, development, and testing.
ENCRYPTION
(1) The IRS or CSP shall ensure that the information system implements FIPS-validated or National Security Agency (NSA)-approved cryptography in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
IRS sensitive data (e.g., Sensitive But Unclassified (SBU), Personally Identifiable Information (PII) that is processed, stored, or transmitted by an information system outside of IRS facilities or IRS IT information system shall be protected with FIPS 140-2 or later validated cryptographic modules with approved modes of operation. The vendor shall provide a system that implements (encryption standard) that provides for origin authentication, data integrity, and signer non-repudiation. Consider AU-11 audit Records retention
A list of NIST validated modules is available at the following link: http://csrc.nist.gov/groups/STM/cmvp/validation.html.
The CSP/Contractor shall ensure all SBU information is protected at rest, in transit, and in exchanges (i.e., internal and external communications). Limit access to SBU information to authorized personnel (those favorably adjudicated and trained) with a need to know and ensure internal and external exchanges are conducted only through secure or encrypted channels. The CSP/Contractor shall employ encryption concepts and approved standards to ensure the confidentiality, integrity, and availability of the SBU information, consistent with the security controls under Publication 4812 and any security requirements specified elsewhere in the contract.
Contractual liability to the government only exists with the prime contractor.
The CSP/contractor shall retain operational configuration and control of data repository systems used to process and store government data to include any or remote work. The CSP/contractor shall not subcontract the operational configuration and control of any government data.
http://csrc.nist.gov/groups/STM/cmvp/validation.html
IRS retains exclusive ownership over all its data; the CSP/Contractor acquires no rights or licenses through the agreement, including intellectual property rights or licenses, to use the IRS data for its own purposes; and that the CSP/Contractor does not acquire and may not claim any interest in the data due to security. If CSP/Contractor moves data, the IRS will not lose rights and access to conduct audits.
Intellectual property, including original works created using the cloud infrastructure, may be stored. IRS must ensure that the cloud provider contract respects the IRS’ right to any intellectual property or original works as far as possible without compromising the quality of service offered (e.g., backups may be a necessary part of offering a good service level).
CONTRACTOR SYSTEM REVIEW / SITE VISIT
In conjunction with the use of outsourced / Contractor facilities, the contractor shall be subject to at the option / discretion of the IRS, to periodically test and inspection (annually) and evaluate the effectiveness of information security controls and techniques. The assessment of information security controls may be performed by an agency independent auditor, security team or Inspector General, and shall include testing of management, operational, and technical controls, as indicated by the security plan, of every information system that maintain, collect, operate or use federal information on behalf of the agency. The agency and contractor shall document and maintain a remedial action plan, also known as a Plan of Action and Milestones (POA&M) to address any deficiencies identified during the test and evaluation. The contractor must cost-effectively reduce information security risks to an acceptable level within the scope, terms and conditions of the
CONTRACTOR SYSTEM OVERSIGHT/COMPLIANCE
(a) The Contractor, service providers, and third-party vendors must complete the IRS Security – Assessments (IT Security Product Questionnaire) and submit the assessments to the Contracting Officer and Cybersecurity for review and evaluation. This is a supplemental requirement and does not replace contract requirements under FISMA. The federal government has the authority to conduct site reviews for compliance validation. Full cooperation by Contractor and third-party providers is required for audits and forensics.
(b) The Contractor must support IRS in its efforts to assess and monitor the Contractor systems and infrastructure. The Contractor must provide logical and physical access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases upon request. The Contractor will be expected to perform automated scans and continuous monitoring activities which may include, but will not be limited to, authenticated and unauthenticated scans of networks, operating systems, applications, and databases and provide the results of the scans to the IRS Cybersecurity, or designate, or allow IRS (or its designate) to run the scans directly.
(c) All Contractor systems must participate in Information Security Continuous Monitoring (ISCM) and Reporting as defined in the IRS IT Policy.
(d) All Contractor systems must perform vulnerability scanning as defined by IRS IT Security Policy and provide scanning reports to the IRS Cybersecurity, or designate, on a monthly basis.
(e) All Contractor systems must participate in the implementation of automated security controls testing mechanisms and provide automated test results in Security Compliant Automation Protocol
(SCAP) compliant data to the IRS Cybersecurity, or designate, on a monthly basis.
CONTRACTOR SECURITY TRAINING
IR1052.224-9001 Mandatory IRS Security Training for Information Systems, Information Protection and Facilities Physical Access (JUN 2021)
The Federal Information Security Modernization Act of 2014 (FISMA) requires each federal agency to provide periodic information security awareness training to all contractors/subcontractors involved in the management, use, or operation of Federal information and information systems. In addition, contractor/subcontractor personnel are subject to the Taxpayer Browsing Protection Act of 1997, which prohibits willful unauthorized inspection of returns and return information and details that any violation of the Act could result in civil and criminal penalties. Contractor/subcontractor personnel are subject to the Privacy Act of 1974 (5 U.S.C. 552a; Pub. L. No. 93-579), December 1974.
Contractor/subcontractor personnel are bound by the Records Management by 93 Federal Agencies (44 U.S.C. Chapter 31) regarding the care and retention of federal records.
1. The contractor must ensure all new contractor/subcontractor personnel complete all assigned briefings which are based on the responses provided on the Risk Assessment Checklist Form 14606.
These responses pertaining to access to any IRS system, including basic LAN, email and internet;
access to any Sensitive but Unclassified (SBU) data; and access to any IRS facility. Since new contractor/subcontractor personnel will not have access to the IRS training system, the COR shall provide softcopy versions of each briefing.
i. Exception: Contractor personnel (including subcontractors) performing under IRS contracts with Nonprofit Agencies Employing People Who Are Blind or Severely Disabled (as described in FAR Subpart 8.7) are exempted from the aforementioned briefing requirements, unless the contractor requests access to the training, or there is a compelling justification for requiring the training that is approved by the Contracting Officer (CO). An example of this would be in an instance where visually impaired personnel is assigned to perform systems development and has potential staff-like access to IRS information.
ii. Contractor/subcontractor personnel working with IRS information at contractor-controlled facilities with no access to the IRS network will be subject to all mandatory briefing excepting the Facilities Management Physical Security briefing as outlined in Publication 4812.
iii. Service Personnel: Inadvertent Sensitive Information Access Training
Contractor personnel performing: (i) janitorial and cleaning services (daylight operations), (ii) building maintenance, or (iii) other maintenance and repair and need staff-like access to IRS facilities are required to complete Inadvertent Access to Sensitive Information (SBU) Access training.
iv. Service Personnel Security Awareness Training: Contractor personnel providing services in the following categories are required to complete FMSS Physical Security Training:
o Medical;
o Cafeteria;
x1bsb Highlight o Landscaping;
o Janitorial and cleaning (daylight operations);
o Building maintenance; or o Other maintenance and repair
2. In combination these mandatory briefings are known as IRS Security Awareness Training (SAT).
The topics covered are: Cybersecurity Awareness, Privacy Information Protection and Disclosure, Unauthorized Access to Taxpayer Data, Records Management, Inadvertent Sensitive Information Access, Insider Threat and/or Facilities Physical Security. The completion of the assigned mandatory briefings constitutes the completion of the Security Orientation.
3. The SAT must be completed by contractor/subcontractor personnel within 5 business days of successful resolution of the suitability and eligibility for staff-like access as outlined in IR1052.204- 9000 Submission of Security Forms and Related Materials and before being granted access to SBU data. The date listed on the memo provided by IRS Personnel Security shall be used as the commencement date.
4. Training completion process:
The contractor must submit confirmation of completed SAT mandatory briefings for each contractor/subcontractor personnel by either:
i. Using Form 14616 signed and dated by the individual and authorized contractor management entity and returned to the COR. This option is used for new contractor/subcontractor personnel and any that do not have an IRS network account.
ii. Using the IRS training system which is available to all contractors with IRS network accounts
5. Annual Training. For contracts/orders/agreement exceeding one year in length, either on a multiyear or multiple year basis, the contractor must ensure that personnel complete assigned SAT mandatory briefings annually no later than October 31st of the current calendar year. The contractor must submit confirmation of completed annual SAT on all personnel unable to complete the briefings in the IRS training systems by submitting completed Form 14616 assigned to this contract/order/agreement, via email, to the COR, upon completion.
6. Contractor’s failure to comply with IRS privacy and security policy (to include completion and certification of SAT requirements within the timeframe specified) may be subject to suspension, revocation or termination (temporarily or permanently) of staff-like access to IRS IT systems and facilities.
7. Flow down of clauses. The contractor shall include and flow down, in its subcontracts (or arrangements or outsourced service agreements) that entails staff-like access to SBU information by a subcontractor, at any tier, the same Federal Acquisition Regulation (FAR) and local privacy and security or safeguard clauses or provisions for protecting SBU information or information systems that apply to and are incorporated in its prime contract with IRS.
SPECIALIZED IT SECURITY (SITS) TRAINING
This training is also referred to as role-based security training. If a Contractor performs tasks/services such as system administration, network administration, database administration, programmer developer or one of the other specialized IT security roles as defined in IRM 10.8.2.
IR1052.204-9002 IRS Specialized Information Technology (IT) Security Training (Role-Based) Requirements (JUN 2021)
(a) Consistent with the Federal Information Security Modernization Act of 2014 (FISMA), specialized information technology (IT) security training (role-based) shall be completed prior to access to Information Systems and annually thereafter by contractor and subcontractor personnel who have an IT security role or responsibility.
(b) Identifying contractor/subcontractor with a role or responsibility for IT security is completed by the Contractor, and verified by the COR, by completing the Risk Assessment Checklist (RAC). The roles listed in the RAC conform to those roles listed in the Internal Revenue Manual 10.8.1.2 that apply to contractor personnel. This process applies to new contractors/subcontractors, replacement personnel and for existing contractors/subcontractors whose roles change during their work on a contract. This includes, but is not limited to, having an approved elevated privilege to one or more IRS systems through the OL5081 process or Business Entitlement Access Request System
(BEARS).
(c) Prior to accessing any IT system, all contractor/subcontractor personnel must be successfully complete all provisions of IR1052.204-9000 Submission of Security Forms and Related Materials.
(d) In keeping with the Security Orientation outlined in IR1052.224-9001, contractors/subcontractors designated on the Risk Assessment Checklist as performing a role shall complete approved training equal to the assigned hours within 5 business days of receiving the Personnel Security’s memo approving staff-like access.
(e) Annual Requirements: Thereafter, on an annual basis within a FISMA year cycle beginning July 1st of each year, contractor/subcontractor personnel performing under this contract in the role identified herein is required to complete specialized IT security, role-based training by June 1st of the following year.
(f) Training Certificate/Notice: The contractor shall use the Government system identified by Cybersecurity to annually complete specialized IT security training (role-based). The COR will track the courses, hours completed and the adhere to the established due dates for each contractor/subcontractor personnel. Alternatively, courses may be completed outside of the Government system. Any courses taken outside of the Government system must be pre-approved by IRS Cybersecurity’s Security System Management team via the COR. Adequate information such as course outline/syllabus must be provided for evaluation. Once a course is approved, certificates of completion provided for each contractor/subcontractor shall be provided to COR in order to receive credit toward the required hours for the contractor/subcontractor personnel. Copies of completion certificates for externally completed course must be shared with the Contracting Officer upon request.
x1bsb Highlight
(g) Administrative Remedies: A contractor/subcontractor who fails to complete the specialized IT security training (role-based) requirements, within the timeframe specified, may be subject to suspension, revocation or termination (temporarily or permanently) of staff-like access to IRS IT systems.
(h) Flow down of clauses. The contractor shall include and flow down, in its subcontracts (or arrangements or outsourced service agreements) that entails staff-like access to SBU information by a subcontractor, at any tier, the same Federal Acquisition Regulation (FAR) and local security or safeguard clauses or provisions for protecting SBU information or information systems that apply to and are incorporated in its prime contract with IRS.
SAFEGUARDING / PROTECTING SENSITIVE PERSONALLY IDENTIFIABLE
INFORMATION (PII)
Sensitive PII is defined as any information that permits the identity of an individual to be directly or indirectly inferred, including any information that is linked or linkable to that individual, regardless of whether the individual is a U.S. citizen, legal permanent resident, or employee or contractor to the Department. Sensitive PII is Personally Identifiable Information, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
Information Systems can be either electronic or manual. IRM 10.8.1 requires IRS sensitive information is to be handled and protected at the contractor's site, including any information stored, processed, or transmitted using the contractor's computer systems. Contractor personnel shall perform a background investigation and/or clearance required; receive security awareness and specialized IT security training required for contractor activities or facilities; and any facility physical security requirements.
IRS sensitive data (e.g., Sensitive But Unclassified (SBU), Personally Identifiable Information (PII) that is processed, stored, or transmitted by an information system outside of IRS facilities or IRS IT information system shall be protected with FIPS 140-2 or later validated cryptographic modules with approved modes of operation.
A list of NIST validated modules is available at the following link: http://csrc.nist.gov/groups/STM/cmvp/validation.html.
(1) The CSP/Contractor shall ensure that individuals accessing an information system processing, storing or transmitting information requiring special protection satisfy the personnel screening criteria.
(2) The organization shall:
Screen individuals prior to authorizing access to the information system; and Rescreen individuals according to FedRAMP Assignments: for national security clearances; a reinvestigation is required during the 5th year for top secret security clearance, the 10th year for secret security clearance, and 15th year for confidential security clearance. For moderate risk law http://csrc.nist.gov/groups/STM/cmvp/validation.html enforcement and high impact public trust level, a reinvestigation is required during the 5th year.
There is no reinvestigation for other moderate risk positions or any low risk positions.
The CSP/Contractor shall ensure that data is used, only as identified, in the IRS contract and that the data will be used for nothing else to ensure the privacy of the individual.
The CSP/Contractor is responsible for maintaining an inventory of all PII provided to the contractor, generated by the contractor, or used by the contractor sufficient to enable notification to taxpayers, if disclosed. The inventory of PII must be updated semi-annually with a final inventory notification provided to the COR.
Most IRS information is categorized as Sensitive But Unclassified (SBU). This includes:
(a) Federal Tax Information (FTI)
(b) Personally Identifiable Information (PII)
(c) Protected Health Information (PHI)
(d) Certain procurement information
(e) System vulnerabilities
(f) Case selection methodologies
(g) Systems information
(h) Enforcement procedures
(i) Investigation information
(j) Proprietary processes or algorithms used in investigative work or tax processing
Note: Live data, which is defined as production data in use (production, testing, development), often contains SBU.
Various laws and regulations have addressed the need to protect sensitive information held by government agencies including the Federal Information Security Modernization Act (FISMA), the EGovernment Act of 2014, the Privacy Act of 1974, and OMB Circular A-130, Management of Federal Information Resources. FISMA requires agencies to have a security program and controls for systems to protect their sensitive information. Therefore, the contractor shall comply with OMB policies and Treasury / IRS specific policies, procedures or guidance to protect sensitive information.
CONTRACTOR RIGHTS TO ACCESS DATA
Access Control requirements shall be implemented as defined within Internal Revenue Manual (IRM) 10.8.1, Information Technology (IT) Security, Policy and Guidance and Publication 4812.
1) The CSP/Contractor shall not access, use, or disclose Government data unless specifically authorized by the terms of this contract or a task order issued hereunder. If authorized by the terms of this contract or a task order issued hereunder, any access to, or use or disclosure of, Government data shall only be for purposes specified in this contract or task order. CSP/Contractor shall ensure that each of its employees and representatives, and any others (e.g., subcontractor employees) performing duties hereunder, shall, prior to obtaining access to any Government data, sign a contract or task order specific nondisclosure agreement.
2) The CSP/Contractor shall use Government-related data only to manage the operational environment that supports the government data and for no other purpose unless otherwise permitted with the prior written approval of the Contracting Officer.
CSP/Contractor shall:
a. Be subject to background investigations at the risk level appropriate to the sensitivity of the position and sensitivity/classification of the data.
b. Not access sensitive IT systems until they have at least a favorably adjudicated National Agency Check (a component of the full background investigation).
c. Be responsible for protecting any Personally Identifiable Information (PII) that they have in their possession, whether it is paper-based or in electronic form.
d. Understand the provisions and applicable criminal penalties under Public Law 105-35, Taxpayer Browsing Protection Act, shall also apply to all contractors and contractor employees.
e. Comply with all executive, legislative and Department of Treasury and IRS security policies
f. Minimize the threat of viruses by write-protecting removable media, routinely scanning files, systems, and media for viruses and never circumventing anti-virus safeguards.
A breach of the obligations or restrictions may subject the CSP/Contractor to criminal, civil, administrative, and contractual actions in law and equity for penalties, damages, and any other appropriate remedies by any party adversely affected by the breach.
HANDLING INFORMATION SECURITY INCIDENTS
The IRS Computer Security Incident Response Capability (CSIRC) defines a security incident as: “any adverse event whereby some aspect of computer security could be threatened.
Adverse events may include the loss of data confidentiality, disruption of data or system integrity, disruption or denial of availability, loss of accountability, or damage to any part of the system.”
User Compromise, Disclosure of Taxpayer/Sensitive Data, Malicious Code (successful or unsuccessful), Denial of Service (DoS) (successful or unsuccessful), Website Defacement, Identity Theft, Misuse of Resources or Policy Violation, Loss or Theft of IT Equipment, IRM/LEM Non- Compliance, Unauthorized Access Attempt, Probe/Scan, and any other security incident that may threaten or damage any IRS or federal agency information or information system(s).
Contractors and their employees must be aware of their responsibilities under the law to safeguard PII and sensitive information, the procedures to follow when data is lost or compromised and the penalties for unauthorized disclosure of PII and sensitive information. Contractors should refer to Data Breach Information for IRS Contractors on irs.gov https://portal.ds.irsnet.gov/sites/vl003/RelatedResources/Doc13347-2020-01- Data%20Breach%20Response%20Playbook.pdf#search=contractors%20data%20breach Pub 4465-A, Protecting Federal Tax Information for Contractors, and Pub 4812, Contractor Security Controls, for information about a contractor’s responsibilities to protect Federal Tax Information (FTI) and incident/data breach response and reporting procedures.
It is critical to report an incident/data breach as soon as actionable information is available so a response/reaction can be initiated. Incident/data breach updates and any additional notifications to Treasury Inspector General for Tax Administration (TIGTA) and/or Local Law Enforcement can be completed after the initial report to the Office of Taxpayer Correspondence (OTC), Privacy, https://portal.ds.irsnet.gov/sites/vl003/RelatedResources/Doc13347-2020-01-Data%20Breach%20Response%20Playbook.pdf#search=contractors%20data%20breach https://portal.ds.irsnet.gov/sites/vl003/RelatedResources/Doc13347-2020-01-Data%20Breach%20Response%20Playbook.pdf#search=contractors%20data%20breach
Governmental Liaison and Disclosure/Incident Management Office (PGLD/IM), or the Computer Security Incident Response Center (CSIRC) is submitted.
All physical security incidents and/or threats should be reported to the SAMC within 30 minutes of incident discovery. SAMC operates 365 days a year, 24 hours a day, seven days a week. Incidents may be reported to the SAMC through any of the following methods:
Primary Method of Reporting: Website incident reporting link, https://tscc.enterprise.irs.gov/irc/
Alternate Reporting Methods:
Telephone: 202-317- 6124 or 1-866-216-4809 (toll free hotline) Fax: 202-317-6129 Email: samc@irs.gov
The CSP/Contractor shall report security incident information according to U.S. Computer Emergency Response, Department of Treasury, IRS, and the FedRAMP Incident Communications procedures.
All incidents related to IRS processing, information or information systems shall be reported within one (1) hour to the CO, COR, and CSIRC. Contact the CSIRC through any of the following methods:
CSIRC Contacts: Telephone: 240.613.3606 E-mail to csirc@irs.gov
The CSP/Contractor shall be accountable for incident responsiveness, including providing specific time frames for restoration of secure services in the event of an incident.
The CSP/Contractor shall provide and maintain insurance, to include cybersecurity insurance, throughout the performance of this contract, as specified in the Schedule or elsewhere in the
Before commencing performance under this contract, the CSP/Contractor shall provide proof of insurance to the Agency. The CSP/Contractor shall resubmit the proof of insurance within 30 days of notification of any material change that occurs during the performance of the contract.
The CSP/Contractor shall insert the substance of this clause, including this paragraph (c), in subcontracts under this contract that require work with or in support of storage and retrieval of electronic/digital government data and shall require subcontractors to provide and maintain the insurance required in the Schedule or elsewhere in the contract. The CSP shall maintain a copy of all subcontractors’ proofs of required insurance and shall make copies available to the Contracting Officer upon request.
CONTRACTOR BOUNDARY PROTECTION
The CSP/Contractor shall ensure IRS data is not comingled with the data from other organizations.
https://tscc.enterprise.irs.gov/irc/ mailto:samc@irs.gov mailto:csirc@irs.gov
The CSP/Contractor shall implement boundary protection mechanisms at servers, workstations, and mobile devices.
The CSP/Contractor shall isolate the information system from other internal information system components by implementing physically separate subnetworks with managed interfaces to other components of the system.
The CSP/Contractor shall define key information security tools, mechanisms, and support components associated with system and security administration and isolate those tools, mechanisms, and support components from other internal information system components via physically or logically separate subnetworks.
Note: These requirements are above the IRM 10.8.1 baseline and are assigned to Moderate-impact systems by FedRAMP
CLOUD SERVICE PROVIDER’S INFORMATION OUTPUT HANDLING AND
RETENTION
The CSP/Contractor shall handle and retain data within the information system, according to record retention standards. The IRS shall identify the record retention standards to the contractor. In addition, once the contract expires, all data shall be returned to the IRS, unless specifically identified otherwise in the contract. No records shall be maintained, in paper or electronically, unless approved by the IRS COR. Once disposal is complete, a copy of the disposal record and notification must be provided to the IRS CO/COR.
JURISDICTION OVER IRS DATA AND CONTRACT TERMS DATA
The CSP/Contractor shall maintain all data within the United States (or U.S. territories).
Jurisdiction over IRS data and contract terms must not be divided. The CSP/Contractor shall provide the IRS with a list of the physical locations which may contain government data. The CSP/Contractor shall provide information about the jurisdictions in which data may be stored and processed and any risks resulting from the location of those jurisdictions must be evaluated. The CSP/Contractor shall identify all data centers that the data at rest or data backup will reside.
The CSP will work with the Information Owner to understand the business rules for information/data store, collected in the Cloud.
DATA COLLECTED, PROCESSED AND TRANSFERRED
Data provided by the IRS and their customers must be collected, processed, and transferred in accordance with the contract terms established between the IRS and the cloud provider.
Sensitive But Unclassified (SBU) information, data, and/or equipment will only be disclosed to authorized personnel on a Need-To-Know basis.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .