RFQ STRATUS Pool 2 Attch B Security Requirements.pdf
PDF 211 KB Posted
- Attached to
- USDA STRATUS Cloud Basic Ordering Agreement (BOA) Pool 2: Integration and Development Support Services On-Ramp Federal contract opportunity
- Solicitation number
- 12314425Q0065
About this file
This document is Attachment B of the USDA STRATUS Cloud Basic Ordering Agreement (BOA) Solicitation, focusing specifically on security requirements for Pool 2: Integration and Development Support Services. The attachment details comprehensive cybersecurity guidelines and responsibilities for authorized vendors, including compliance with Federal Risk Authorization Management Program (FedRAMP), National Institute of Standards and Technology (NIST) standards, and USDA-specific cloud computing regulations.
Key security requirements include maintaining continuous monitoring programs, complying with Executive Order 13556 regarding Controlled Unclassified Information, implementing fortified security with cyber defenses across system levels, and obtaining a valid Authority to Operate (ATO) from USDA. Authorized vendors must coordinate with assessment and evaluation entities, remediate security findings within specified timeframes (15 days for critical issues, 30 days for others), and ensure compliance with FedRAMP controls for FISMA Low and Moderate Risk Categorizations. The document outlines specific responsibilities for authorized assessment entities, USDA ordering entities, and vendors in maintaining robust cybersecurity protocols throughout the contract lifecycle.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION NO. 12314425Q0065
STRATUS CLOUD BASIC ORDERING AGREEMENT
POOL 2: INTEGRATION AND DEVELOPMENT SUPPORT SERVICES
ATTACHMENT B
SECURITY REQUIREMENTS
Attachment B: Security Requirements – RFQ 12314425Q0065 Page 2 of 6
Attachment B: Security Requirements
B.1. USDA STRATUS Blanket Ordering Agreement (BOA) Security Requirements – Pool 2
The Contractor shall establish and maintain a security program and security controls per Federal Risk Authorization Management Program (FedRAMP) and Cloud Security and Privacy Requirements as specified as well as compliance with current Federal and United States Department of Agriculture (USDA) policies and directives.
B.1.1 Definitions
B.1.1.1 Authorization and Evaluation Entity - An authorized assessment and evaluation entity is an explicitly identified government entity under this BOA, that is authorized to conduct and perform independent assessments and evaluations leveraging best practices and guidelines established by NIST and commercial standards.
a) United States Federal Government - The following US Federal Government agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:
• Cybersecurity and Infrastructure Security Agency (CISA)
• Government Accounting Office (GAO)
• National Security Agency (NSA) / Central Security Service (CSS)
• Office of the Director of National Intelligence (ODNI)
b) United States Department of Defense - The following DoD agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:
• Director Operational Test & Evaluation (DOT&E)
• Marine Corps Forces Cyberspace Command Sixteenth Air Force (AFCYBER)
• US Army Cyber Command (ARCYBER)
• US Cyber Command (USCC) 157
• US Fleet Cyber Command
• Department of Defense Cloud Authorization Services (DCAS)
c) United States Department of Agriculture (USDA) – The following USDA agencies or subordinate agencies, components, and offices are authorized assessment and evaluation entities:
• Office of the Chief Information Officer (OCIO)
• Digital Infrastructure Service Center (DISC)
B.1.1.2 Authorized Vendor - An authorized vendor is an entity that has been awarded a USDA BOA award by the BOA Administering function. An authorized vendor can be a Pool 1 – Cloud Service Provider (CSP); Pool 2 – Application Developer (AppDev), Operations & Maintenance (O&M), and/or System Integrator (SI); and/or Pool 3 – Software as a Service (SaaS) provider.
Attachment B: Security Requirements – RFQ 12314425Q0065 Page 3 of 6
Cloud Service Provider (CSP) - A CSP is an entity that directly operates and manages the cloud services (i.e., IaaS, PaaS, SaaS, etc.) technology (e.g., facility, hardware, software).
B.1.2 Responsibilities
B.1.2.1 Authorized Assessment and Evaluation Entity Responsibilities – Authorization and Evaluation Entities as defined in Section B.1.1 have the following responsibilities as related to all USDA Stratus Pool 2 Task Orders:
a) Cybersecurity Assessments and Evaluations - Authorized assessment and evaluation entities are responsible for conducting and performing announced and unannounced independent cybersecurity (e.g., OCIO, DISC, etc.) and operational (e.g., performance, SLAs) assessments and evaluations (e.g., OT&E) of the cloud services (i.e., IaaS, PaaS, SaaS, etc.)
architectures (e.g., compute, networking, storage) and security domains involved in the processing, transporting, and / or storing authorized ordering entities data.
b) Coordination - Authorized assessment and evaluation entities are responsible for coordinating assessment and evaluation activities with the authorized vendors.
Coordination responsibilities shall include planning, execution, and post assessment and evaluation activities (e.g., remediations, Plan of Actions and Milestones (POA&Ms).
c) Cost - Authorized assessment and evaluation entities are responsible for their assessment and evaluation costs.
d) Findings and Recommendations - Authorized assessment and evaluation entities are responsible for documenting the assessment and evaluation findings and recommendations (e.g., reports).
e) Communication and Distribution - Authorized assessment and evaluation entities are responsible for communicating and distributing the assessment and evaluation findings and recommendations to the following:
• BOA Contracting Officer (CO)
• Task Order Contracting Officer Representative (TO COR)
• Authorized assessment and evaluation entities (e.g., OCIO, DISC, etc.)
• Assessed and evaluated authorized vendor(s)
B.1.2.2. USDA Authorized Ordering Entity (Mission Owners) – Authorized Ordering Entities have the following responsibilities as related to all USDA Stratus Pool 2 Task Orders:
a) Cybersecurity Assessments and Evaluations
• Findings and Recommendations - Authorized ordering entities are responsible for receiving and reviewing authorized assessment and evaluation entities' assessment and evaluation findings and recommendations (e.g., reports).
• Suspension and Termination of Task Order(s) - Authorized ordering entities are responsible for evaluating and determining if the findings and recommendations of an assessment and evaluation warrants the suspension or termination (i.e., termination for cause, termination for convenience) of a TO(s) awarded under this BOA.
• USDA Authorization Management Program Reporting - Authorized USDA ordering entities are responsible for reporting and submitting issued ATO(s) to USDA OCIO and FedRAMP.
Attachment B: Security Requirements – RFQ 12314425Q0065 Page 4 of 6
Authorized USDA ordering entities are responsible for reporting and submitting any ATO Assessment & Authorization (A&A) identified inconsistencies (i.e., with FedRAMP authorization, with USDA OCIO authorization), concerns, or issues to OCIO and FedRAMP.
• Cybersecurity Incident Reporting - Authorized USDA ordering entities are responsible for reporting of cybersecurity incidents to the BOA Contracting Officer and to their TO(s) authorized vendors to ensure the authorized vendor can take appropriate mitigation actions.
B.1.2.3 Authorized Vendor – Pool 2 Vendors
a) Coordination - Authorized vendors shall be responsible for coordinating assessment and evaluation activities with the authorized assessment and evaluation entities. Coordination responsibilities shall include planning, execution, and post assessment and evaluation activities (e.g., remediations, POA&Ms).
b) Findings and Recommendations - Authorized vendors shall be responsible for receiving and reviewing authorized assessment and evaluation entities' assessment and evaluation findings and recommendations (e.g., reports).
c) Mitigation and Remediation - Authorized vendors shall be responsible for evaluating, determining, and executing the appropriate mitigation and remediation activities (e.g., fixes, patches, updates) in response to the findings and recommendations of an assessment and evaluation. Findings shall be remediated within established USDA timeframes; 15 days for Critical, and 30 days for all others.
d) Public Disclosure and Release - Authorized vendors shall be responsible for reviewing the written notifications from authorized assessment and evaluation entities including the provided unclassified versions of the assessment and evaluation findings and recommendations and timely reply, within 30 calendar days, to the authorized assessment and evaluation entities of any concerns or objections to the public disclosure or release.
B.1.2.4 Cybersecurity Authorization to Operate (ATO)
a) Notification of Terms and Conditions Discrepancies - Authorized vendors shall be responsible for immediately notifying the BOA Contracting Officer when a conflict, discrepancy, or issue is identified between the applicable laws, regulations, policies, and Terms & Conditions of the US, USDA STRATUS BOA, or their TO(s).
b) Performance Conflict Elevation - Authorized vendors shall be responsible for elevating unresolvable performance conflicts with authorized ordering entities to the BOA Contracting Officer for arbitration and resolution.
c) Department of Defense Cloud Authorization Services Authorization(s) - Vendors shall be responsible for obtaining and maintaining DCAS authorization(s) for their CSO(s) (i.e., IaaS, PaaS, SaaS, etc.) in accordance with DCAS regulations and policies.
d) Federal Risk and Authorization Management Program Authorization(s) - Vendors shall be responsible for obtaining and maintaining FedRAMP authorization(s) for their CSO(s) (i.e., IaaS, PaaS, SaaS, etc.) in accordance with FedRAMP regulations and policies.
e) Cybersecurity Incident Reporting - Authorized vendors are responsible for timely reporting cybersecurity incidents to the TO(s) Contracting Authority to ensure awareness of the incident and mitigating actions the authorized vendor is performing.
Attachment B: Security Requirements – RFQ 12314425Q0065 Page 5 of 6
B.1.3 Applicable Security Controls, Compliance, and Policies
Authorized Vendors under the USDA STRATUS BOA for ordering Pool 2 Providers shall comply with USDA high level security policy/guidelines, to include:
B.1.3.1 Ensure ongoing Assessment and Authorization (A&A) of the cloud service tenant according to the appropriate level and conform with the Federal Information Security Modernization Act (FISMA), the Federal Information Processing Standards (FIPS) 199 Categorization (Low, Moderate, High), and Office of Management and Budget (OMB) Circular A-130, and Federal Risk Management Program (FedRAMP) standards.
B.1.3.2 Comply and meet thresholds set in the National Institute of Standards and Technology (NIST) SP 800-53 Risk Management Framework “Security and Privacy Controls for Federal Information Systems and Organizations.”
a) CA-1 Security Assessment and Authorization Policies and Procedures - Formal, documented security assessment and authorization policies that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Formal, documented procedures to facilitate the implementation of the security assessment and authorization policies and associated security assessment and authorization controls.
b) CA-7 Continuous Monitoring – The organization establishes a continuous monitoring strategy and implements a continuous monitoring program that includes: a configuration management process for the information system and its constituent components; a determination of the security impact of changes to the information system and environment of operation; Ongoing security control assessments in accordance with the organizational continuous monitoring strategy; and Reporting the security state of the information system to the Authorizing Official at least quarterly.
B.1.3.3 Information and data management shall comply with Executive Order 13556 regarding Controlled Unclassified Information (CUI), Personally Identifiable Information (PII) a subset of CUI, and Sensitive PII a subset of PII that requires additional controls and safeguards.
B.1.3.4 Maintain strong physical security controls, managed access to the virtual environment, and maintain strong separation between virtual workloads and environments. Provide clear segregation of data unless otherwise specified, at the application level, and storage level.
B.1.3.5 Fortified Security – Security that enables cyber defenses from the “root” level of systems through the application layer and down to the data layer with improved capabilities including continuous monitoring and auditing; automated threat detection; resiliency against persistent adversarial threat;
encryption at rest and in transits; and an operating environment that meets or exceeds USDA information security requirements.
B.1.3.6 Cybersecurity and Infrastructure Security Agency (CISA) Cybersecurity Division Trusted Internet Connections (TIC) Reference Architecture Document Version 2.0 - TIC is a federal cybersecurity initiative intended to enhance network and boundary security across the Federal Government. The Office of Management and Budget (OMB), the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), and the General Services Administration (GSA) oversee the TIC initiative through a robust program that sets guidance and an execution framework for agencies to implement a baseline boundary security standard.
Attachment B: Security Requirements – RFQ 12314425Q0065 Page 6 of 6
B.1.3.7 USDA Specific Guidance - The Contractor shall comply with cloud security and privacy requirements specified below including with directed mandates to protect and defend information systems from recurring security threats or in response to real-time vulnerabilities.
a) USDA Department Regulation DR-3650-001 Cloud Computing - This Departmental Regulation (DR) updates the United States Department of Agriculture (USDA) policy for implementing the Office of Management and Budget’s (OMB) Federal Cloud Computing Strategy (Cloud Smart) across the USDA’s information technology (IT) portfolio of information and information systems. Link - https://www.usda.gov/directives/dr-3650-001
b) FedRAMP compliant as assessed by a third-party assessment organization (as defined in Section 1.1.1 “Authorization and Evaluation Entity”) authorized and accredited for this purpose by the USDA and FedRAMP.
c) Compliant with all FedRAMP controls required for the FISMA Low and Moderate Level of Risk Categorization.
d) At all times be operating under a valid Authority to Operate (ATO) granted by USDA for at least the FISMA Low Level of Risk Categorization.
e) Determined by USDA to effectively meet the controls required by FedRAMP after a pre-award review of the security control test results used to authorize the service. USDA will conduct the pre-award review of the security control test results used to authorize the service within a 2-week window after the technical evaluation is completed but before the award executed. USDA will be responsible for conducting the pre-award review and is solely responsible for making the decision as it pertains to issuance of the ATO.
https://www.usda.gov/directives/dr-3650-001
| B.1.1 Definitions |
| B.1.2 Responsibilities |
| B.1.3 Applicable Security Controls, Compliance, and Policies |
File details come from the government source that posted it. Updated .