J-20 Information Security Attestation.docx
DOCX document 19 KB Posted
- Attached to
- DME MAC Jurisdiction A Federal contract opportunity
- Solicitation number
- RFP-CMS-2010-0004
About this file
J-20 Information Security Attestation
View the file
Other files for this federal contract opportunity
Show all 50
DME MAC Jurisdiction A has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CMS-RFP-2010-0004
(insert company letterhead here)
Attachment J.20 Information Security Attestation (Insert Offeror/Company Name) understands and unconditionally assents to the conditions and requirements set forth in the Business Partner System Security Manual (IOM 100-17) and section C.3 of the SOW. Specifically, (Insert Offeror/Company Name) attests to the system security requirements listed in the table below.
Information Security Requirements
1. (Insert Offeror/Company Name) has an Information System Risk Assessment developed in accordance with CMS methodology and/or NIST standards that accurately reflects its current environment.
2. (Insert Offeror/Company Name) has a System Security Plan that complies with CMS Methodology listed in section C.3 of the SOW and/or NIST standards that accurately reflects its current environment.
3. (Insert Offeror/Company Name) is compliant with the Health Insurance Portability and Accountability Act security requirements set forth in 45 CFR Parts 160, 162, and 164.
4. (Insert Offeror/Company Name) has a Continuity of Operations (Disaster Recovery/Contingency Plan) developed in accordance with the Business Partner System Security Manual found at www.cms.hhs.gov/informationsecurity.
5. (Insert Offeror/Company Name) has baseline configuration documentation for all platforms that support the Medicare lines of business and has a configuration management program in place that was developed in accordance with NIST standards.
It is agreed upon and understood that the organization’s Attestations and disclosure documents will become a part of the organization’s proposal.
As an individual with authority to bind the (Insert Offeror/Company Name), I accept responsibility for this written document.
(signature)
(type full name)
Vice President, Medicare Operations
(signature)
(type full name)
Chief Information Officer
(signature)
(type full name)
System Security Officer
Source Selection Information – See FAR 2.101 and 3.104
File details come from the government source that posted it. Updated .