SOO Appendix 2 - Baseline Compliance Contract Guidelines.pdf

PDF 324 KB Posted

Attached to
LMS Implementation for BIE Federal contract opportunity
Solicitation number
140A2321R0001
Issued by
Department of the Interior Bureau of Indian Affairs Bureau of Indian Education

About this file

This document provides guidelines for information technology and cybersecurity compliance requirements to be incorporated into Department of Interior contracts involving IT products or services. Key requirements include compliance with DOI IT security policies and procedures, federal regulations such as FISMA and NIST 800-53, privacy controls, Section 508 accessibility standards, records management policies, and personnel security measures. Contractors must submit documentation including a system security plan, continuous monitoring plan, privacy impact assessment, privacy plan, contingency plan, security assessment report, plan of action and milestones, vulnerability scans, continuous monitoring reports, penetration tests, and audit documentation. Incident response procedures and privacy breach reporting are also outlined. Training compliance and security incident reports must be provided annually or as incidents occur.

View the file

Other files for this federal contract opportunity

Other files attached to LMS Implementation for BIE, newest first.
File Type Posted
Attachment 3 - SOO A0002_0002.pdf PDF
Sol_140A2321R0001_Amd_0002.pdf PDF
Attachment 4 - QA_0002.pdf PDF
Sol_140A2321R0001_Amd_0001.pdf PDF
SOO Appendix 1 School List.xlsx XLSX spreadsheet
Sol_140A2321R0001.pdf PDF
B08 SF1449 140A2321R0001.pdf PDF
SOO Appendix 3 Standard Operating Procedures.pdf PDF
Attachment 1 - IDIQ Pricing.xlsx XLSX spreadsheet
Attachment 3 - SOO.pdf PDF
Attachment 2 - Position Descriptions.pdf PDF
A2321R0001 Synopsis.pdf PDF
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DOI Information Management and Technology Compliance Acquisition Guidelines

Baseline Compliance Contract Guidelines

Table of Contents Section 1.0 – Information Technology & Cybersecurity Requirements

Section 2.0 – Government Oversight, Monitoring and Contractor Responsibilities

Section 3.0 – Cybersecurity Incident Response

Section 4.0 – Privacy Requirements

Section 5.0 – Section 508 Requirements

Section 6.0 – Records Management Requirements

Section 7.0 – Contractor Personnel Security Requirements

Section 8.0 – Table of Deliverables and Reporting Requirements

Section 9.0 – Reference Documents

Section 10.0 – Glossary

This document provides guidance regarding what IT concerns must be incorporated, as applicable, in all Department of the Interior (DOI) contract actions that involve IT products or services. Contracting Officer Representatives (CORs) and/or the requirement owner shall work closely with their contracting officer to ensure the below requirements are properly addressed in IT contracts within the appropriate section. Any referenced regulation or policy should be linked to or otherwise provided to the contractor.

Section 1.0 – Information Technology & Cybersecurity Requirements

Compliance with IT Security Policies

(a) Information systems and system services provided to the Department of the Interior (DOI) by the Contractor must comply with current DOI Information Technology (IT) Cybersecurity and Privacy Control Standards, privacy policies and other related guidance.

(b) Contractors are also required to comply with current Federal regulations and guidance found in the Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP) for cloud hosted systems, the Privacy Act of 1974, Section 208 of the E-Government Act of 2002, Federal Information Processing Standards (FIPS) and the National Institute of Standards and Technology (NIST) 800-Series Special Publications (SP), Office of Management and Budget (OMB) memoranda, and other relevant Federal laws and regulations that DOI must comply with.

(1) Information shall be managed in accordance with applicable laws, regulations, executive orders, and policies regarding the safeguarding and dissemination of Controlled Unclassified Information (CUI). Personally Identifiable Information (PII) is a subset of information designated as CUI, and Sensitive PII is a subset of PII that requires additional controls and safeguards. See Section 4 Privacy.

(2) Information Systems are required to maintain a FISMA compliant Assessment and Authorization (A&A) documentation package compliant with NIST SP 800-34, NIST SP 800-37, NIST SP 800-53, NIST SP 800-60 etc. current versions and FIPS 199.

(3) Cryptographic modules used to protect DOI information must be compliant with the current FIPS 140 version and validated by the Cryptographic Module Validation Program.

(4) Vulnerability Scanning - All systems must be scanned monthly with a vulnerability analysis tool using authenticated scans that are acceptable to DOI.

(5) Vulnerabilities and weaknesses shall be remediated in accordance with (IAW) current Departmental mandated time frames commensurate with the level of risk.

(6) Information system management - The Contractor must provide the following in alignment with DOI’s continuous monitoring strategy:

(i) patch management

(ii) antivirus

(iii) malware detection

(iv) event management

(v) configuration management

(vi) license management

(vii) incident management

(7) All cloud hosted Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS) or other ‘as a Service’ offering shall be compliant with FedRAMP and the language within the DOI cloud hosting program guidelines.

(8) Access to all Government data stored outside the confines of a DOI managed data center shall comply with current Trusted Internet Connections (TIC) requirements.

(9) All contractors requiring access to Government data shall be cleared at appropriate levels as follows:

(i) Low Risk position will require a National Agency Check with Written Inquiries (NACI) or equivalent investigation;

(ii) Moderate Risk position will require either a Limited Background Investigation (LBI) or a Minimum Background Investigation (MBI) based on the CO’s determination; and,

(iii) High Risk position will require a Background Investigation (BI).

(10) Contractors operating information systems on behalf of DOI must comply with

FISMA reporting requirements. Annual and quarterly data collection will be coordinated by DOI System Owners. Contractors must provide DOI with the requested information based on the timeframes provided with each request. Contractor systems must comply with near real time feeds in accordance with Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM) requirements as coordinated by DOI.

Reporting requirements are determined by OMB and may change each reporting period.

The Contractor will provide DOI with all information to fully satisfy FISMA reporting requirements for Contractor systems.

(11) Managed IT systems must comply with Internet Protocol version 6 (IPv6) as prescribed by DOI and in compliance with Federal IPv6 requirements.

Section 2.0 – Government Oversight, Monitoring and Contractor Responsibilities

Contract performance is an ongoing, interactive process between Government and Contractor representatives regarding external and Contractor managed systems. The following outline Government and Contractor roles, responsibilities, Information System Security Officer (ISSO) Standard Operating Procedure (SOP), monitoring and reporting requirements. The Government System Owner (SO), Contracting Officer’s Representative (COR), and ISSO are responsible for monitoring and reporting to appropriate Government management (including the Contracting Officer) the performance or non-performance of contractor adherence and enforcement of required security controls.

(a) Government oversight responsibilities and monitoring of contractor managed systems:

(1) Contractor managed systems are required to assign an Information System Security Officer (ISSO) and System Owner (SO) within their organization to https://doimspp.sharepoint.com/:w:/s/ITSPWG/EeKg2o2Jqk9HqawdyCf3KQ0BmGqi447zm9_4bygr72zuzg?e=5XVCdZ support the processes described in this section. Contractor ISSO and SO resources are required to comply with DOI or other approved annual and Role Based Security Training (RBST) requirements.

(2) Contractor managed systems are required to comply with FISMA and DOI Policy as described in Section 1.0. DOI Specific documents will be provided upon request or after award.

(3) In addition, contractors are required to comply with DHS or other Government Oversight bodies regarding Cybersecurity related mandates and directives (Binding Operational Directives (BOD), etc.) or any additional ad-hoc reporting requirements.

(4) Contractor managed systems are required to submit Continuous Monitoring Reports per the Continuous Monitoring Plan to the assigned ISSO per the timelines prescribed in the plan.

(5) Contractor managed systems are required to adhere to NIST 800-53 current version and submit to an annual assessment performed in coordination with the DOI ISSO personnel or approved contract. All results of the annual assessment become the property of DOI.

(6) Contractor managed systems may be asked to submit to a penetration test (at the digression of the awarding program) in coordination with the DOI ISSO personnel or approved contract.

(7) The contractor must allow logical access to all DOI data and systems for audit purposes.

(b) Contractor Responsibility for Performance Management: The Contractor provides all management, administrative, clerical, and supervisory functions required for the effective and efficient performance of a contract.

(1) The Contractor cannot use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in a contract.

(2) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change.

Section 3.0 – Cybersecurity Incident Response

Both contract employees and Information system service providers are responsible for recognizing and reporting security incidents. Information system service providers will receive the current version of the DOI Incident Response Plan, Policy and Handbook at time of award, in addition to Bureau or Office specific guidance for appropriate reporting and response at all levels. All suspected or confirmed Information Security Incidents must be reported in accordance with the requirements below even if it is believed the incident may be limited, small, or insignificant. DOI CIRC and Bureau/Office Incident Response Teams will determine when an incident requires additional focus and attention.

(1) Contractor employees and Information system service providers must report all information security incidents to the appropriate Bureau or Office Incident Response team AND the DOI Computer Incident Response Center (DOI CIRC) immediately, and no later than 1 hour after “becoming aware of the incident,” at:

DOICIRC@ios.doi.gov, (703) 648-5655, regardless of day or time. Any contractor action to respond, contain, remediate or recover against security event is defined as “becoming aware of the incident.”

(2) When notifying the DOI CIRC or the appropriate Bureau or Office Incident Response team, copy the Contracting Officer (CO) and Contracting Officers Representative (COR) if possible, or if reporting by phone or CO’s or COR email is not immediately available, contact the CO and the COR immediately after reporting the incident to DOI CIRC or the appropriate Bureau or Office Incident Response team.. The Contractor is responsible for positively verifying that notification was received and acknowledged by the CO or the COR. If you have questions regarding these procedures, please contact the CO or the COR.

(3) Contractor cannot include any Sensitive Information in the subject or body of any e-mail. Contractor shall transmit Sensitive Information using NIST Federal Information Processing Standard (FIPS) 140-2, Security Requirements for Cryptographic Modules, compliant encryption methods to protect Sensitive Information in email attachments. Passwords must not be communicated in the same email as the attachment. Contractor should contact the CO or COR if encryption software is needed.

Section 4.0 – Privacy Requirements

4.1 Privacy Act Requirements

Contractor shall not remove PII or Privacy Act material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When Privacy Act records, information, data, documentary material, and/or equipment is no longer required, it shall be returned to the Department’s control or the Contractor must hold it until otherwise directed.

Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer.

4.2 Privacy Controls

(a) Contractor shall meet the requirements the E-Government Act, FISMA, applicable Federal privacy laws, NIST, OMB, and DOI privacy requirements (including but not limited to those listed in the Table of Authorities) for the collection, handling, processing, and sharing of PII, and mailto:DOICIRC@ios.doi.gov ensure compliance with the privacy controls requirements of the current version of NIST SP 800- 53, FIPS 199, FIPS 200, and DOI Privacy Control standards as appropriate for the sensitivity of the system. Contractor shall monitor the information system and update controls for continued privacy compliance on an ongoing basis and shall provide status reports to DOI upon request.

(b) Contractor may be required to provide all necessary support to assist DOI in meeting the requirements of the Privacy Act and related laws, and shall provide supporting documentation and access to information upon request by authorized agency officials. Support in this context includes timely responding to requests for information from DOI about the access, creation, collection, use, storage, maintenance, transmission, sharing or disposition of PII on the Contractor’s system or processes, and providing timely review of relevant compliance documents for factual accuracy for:

(1) Requests for access or disclosure of records to individuals;

(2) Subpoenas or other judicial process;

(3) Discovery and litigation processes;

(4) Accounting of disclosures of records to third parties when authorized;

(5) Privacy impact assessments and related privacy artifacts;

(6) System of records notices;

(7) Privacy complaints and incidents; and

(8) Audits or remedial activities related to oversight of PII and system of records.

4.3 Privacy Breach Reporting Requirements

(a) Contractor shall provide notice to DOI CIRC or the appropriate Bureau or Office Incident Response team of any known or suspected breach of PII and meet breach reporting and mitigation requirements in accordance with the DOI Privacy Breach Response Plan or Bureau or Office applicable response plan. The report of a breach of PII is be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information or has otherwise failed to meet the requirements of the contract.

(b) Contractor shall report all known or suspected breaches in electronic or physical form to the CO, COR, and the DOI CIRC or Bureau/Office point of contact as specified within the appropriate response plan AND Privacy Officer (PO)/ Associated Privacy Officer (APO) via email within one hour of discovery via email within one hour of discovery at DOICIRC@ios.doi.gov or (703) 648-5655.

(1) Contractor will only include non-restricted data in the subject or body of any e-mail. Where necessary, sensitive PII shall be transmitted using encryption methods to protect controlled unclassified information in attachments in accordance with FIPS cryptographic requirements. Passwords shall be securely communicated separately.

(2) Contractor shall not contact individuals impacted by a breach involving PII until directed by the government. All determinations related to response activities, appropriate notifications to individuals and Federal agencies and other organizations, and any remedial actions will be made by DOI officials.

mailto:DOICIRC@ios.doi.gov

(c) Contractor shall take immediate action to contain and mitigate the impact of the breach, and cooperate with DOI officials to investigate the breach and determine remedial measures.

(1) Contractor shall provide full access and cooperation for all activities determined by DOI to be required to ensure an effective breach response, including providing all requested images, log files, and event information to facilitate rapid resolution of breaches.

(2) Breach response activities determined to be required by DOI may include but are not limited to, inspections; investigations; forensic reviews; data analyses and processing;

and final determinations of responsibility for the breach and/or liability for any additional response activities.

(3) DOI, at its sole discretion, may obtain the assistance of Federal agencies and/or third-party firms to aid in breach response activities, as needed.

(d) Provide a detailed written analysis with the following data elements available at the time of the breach, and a follow up report with any additional information or updates within 24 hours of the initial breach report, that shall address all relevant information concerning the compromise:

(1) Government programs, platforms or systems involved;

(2) Location(s) of the breach;

(3) Date and time the breach was discovered;

(4) Nature of the event (loss, theft, unauthorized access);

(5) Description or summary of events;

(6) Description of PII involved, such as name, Social Security number, date of birth, etc.;

(7) Number of potentially impacted individuals; and

(8) Estimated number of records exposed or compromised.

(e) Contractor shall collaborate with DOI officials on breach remedial activities to include notifications, credit monitoring, establishing a call center, or other relief to affected individuals as appropriate under the circumstances of the breach as proscribed in the contract. The Contractor shall have the capability to notify individuals whose PII resided in the Contractor system at the time of the breach not later than 5 business days after being directed to notify individuals. Contractor shall not proceed with notifications unless the CO has directed in writing that notification is appropriate, subject to prior approval by DOI Privacy Officials, in accordance with the DOI Privacy Breach Response Plan. Notification may require the Contractor’s use of address verification and/or address location services. All determinations, including response activities, notifications to affected individuals and/or Federal agencies, and related services will be made by authorized DOI officials at DOI’s discretion.

(f) Contractor may be responsible for costs and related resource allocations resulting from a breach. Contractor may also be required to reimburse DOI for the cost of individual notifications and remediation services procured as the result of a breach of PII. Acquisition teams must work with their Solicitor’s Office to address this when drafting a solicitation or contract.

Section 5.0 – Section 508 Requirements

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use information and communication technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public who have disabilities shall have access to, and use of, information and data that is comparable to people without disabilities.

(a) Products, platforms and services delivered as part of a work statement that are ICT, or contain ICT, shall conform to the Revised 508 Standards, which are located at 36 CFR §

1194.1 & Appendices A, C and D and available at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines. In the revised regulation, ICT replaced the term Electronic and Information Technology (EIT) used in the original 508 standards.

Applicable Functional Performance Criteria: All functional performance criteria in Chapter 3 apply to when using an alternative design or technology that results to achieve substantially equivalent or greater accessibility and usability by individuals with disabilities than would be provided by conformance to one or more of the requirements in Chapters 4 and 5 of the Revised 508 Standards, or when Chapters 4 or 5 do not address one or more functions of ICT.

Applicable 508 requirements for electronic content features and components (including Electronic training materials): All requirements in E205 apply, including all Web Content Accessibility Guidelines (WCAG) 2.0 Level AA Success Criteria Apply.

Applicable 508 requirements for software features and components (including Software infrastructure): All requirements in Chapter 5 apply, including all WCAG 2.0 Level AA Success Criteria, 502 Interoperability with Assistive Technology, and 503 Application.

Applicable 508 requirements for hardware features and components: All requirements in Chapter 4 apply.

Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply.

(b) When providing installation, configuration or integration services for ICT, the Contractor shall not reduce the original ICT item’s level of Section 508 conformance prior to the services being performed.

(c) When providing maintenance upgrades, substitutions, and replacements to ICT, the Offeror shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement. The agency reserves the right to request an Accessibility Conformance Report (ACR) for proposed substitutions and replacements prior to acceptance.

https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines

(d) Offerors shall provide an ACR for each commercially available ICT item offered through this contract. The ACR should be created using the Voluntary Product Accessibility Template (VPAT) Version 2.4Rev 508 (or later), located at https://www.itic.org/policy/accessibility/vpat.

(e) When developing or modifying ICT for the government, the Offeror shall ensure the ICT fully conforms to the applicable Section 508 Standards. When modifying a commercially available or government-owned ICT, the Offeror shall not reduce the original ICT Item’s level of Section 508 conformance.

(f) When developing or modifying web and software ICT, the Offeror shall demonstrate Section 508 conformance by providing Section 508 test results based on the versions of the DHS Trusted Tester Methodology currently approved for use, as defined at https://www.dhs.gov/compliance-test-processes. The Offeror shall use testers who are certified by DHS on how to use the DHS Trusted Tester Methodology (e.g. “DHS Certified Trusted Testers”) to conduct accessibility testing. Information on how testers can become certified is located at https://www.dhs.gov/publication/trusted-tester-resources.

(g) Offeror personnel shall possess the knowledge, skills and abilities necessary to address the applicable revised Section 508 Standards for each ICT.

(h) Exceptions for this work statement have been determined by DOI and only the exceptions described in 375 Departmental Manual (DM) 8 DOI Section 508 Program and Responsibilities, dated February 5, 2016 may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to 375 DM 8.

Where ICT conforming to one or more requirements in the Revised 508 Standards is not commercially available, the agency shall procure the ICT that best meets the Revised 508 Standards consistent with the agency’s business needs, in accordance with 36 CFR 1194 E202.7 and 375 DM 8. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DOI Section 508 Office according to 375 DM 8 and 36 CFR 1194 E202.6.

Section 6.0 – Records Management Requirements

6.1 Applicability

This section applies to all Contractors whose employees create, work with, or otherwise handle “Federal Records”, as defined in 44 U.S.C. § 3301, regardless of the medium in which the record exists. This includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

The term Federal Record:

https://www.itic.org/policy/accessibility/vpat https://www.dhs.gov/compliance-test-processes https://www.dhs.gov/publication/trusted-tester-resources https://www.dhs.gov/publication/trusted-tester-resources https://www.doi.gov/sites/doi.gov/files/elips/documents/Chapter%208_%20Section%20508%20Program%20and%20Responsibilities.docx https://www.doi.gov/sites/doi.gov/files/elips/documents/Chapter%208_%20Section%20508%20Program%20and%20Responsibilities.docx

(a) includes all Departmental records.

(b) does not include personal materials.

(c) applies to records created, received, or maintained by Contractors pursuant to their

Departmental contract.

(d) may include deliverables and documentation associated with deliverables.

6.2 Requirements related to Laws and Policies

(a) The Contractor shall ensure creation and maintenance of Federal records in accordance with all applicable records management laws and regulations, including but not limited to, the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33); Code of Federal Regulations (CFR) (36 CFR Chapter XII Subchapter B; 36 CFR 1220-1236); National Archives and Records Administration (NARA) Bulletins, direction and guidance; and Departmental policy.

(b) The Contractor shall coordinate with the appropriate Departmental and Bureau Records Management Programs to ensure the identification, storage, retrieval, preservation, access, control markings, and disposition of records using the official Departmental record keeping system(s). This includes the implementation of all technical aspects to appropriately interconnect and or transfer records to the system(s). Any exceptions to using this system must be expressly presented by the Contractor in writing to and approved by the Departmental and/or Bureau Records Management Programs.

Thereafter, each major or minor variance must be expressly presented in writing.

(c) In accordance with 36 CFR 1222.32, all records including data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, the Privacy Act of 1974 (5 U.S.C.

552a), as amended, and Executive Order 13556 Controlled Unclassified Information, and must be managed and scheduled for disposition only as permitted by statute or regulation.

(d) In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal laws and regulations. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

(e) The Department and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of the Department or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity and Responsible Records Officer.

Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to the

Bureau Records Officer, who will promptly report the occurrence to NARA in accordance with 36 CFR 1230.

(f) The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of information, data, documentary material, records and/or equipment are properly protected in accordance with Federal law and policy, Executive Orders, and Controlled Unclassified Information regulations. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to the Department’s control in the format designated by the Department or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer.

(g) The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and the Department’s guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

(h) The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with Departmental policy.

(i) The Contractor shall not create or maintain any records containing any non-public information that are not specifically tied to or authorized by the contract.

(j) The Department owns the rights to all data and records produced as part of this contract.

All deliverables under the contract are the property of the U.S. Government for which the Department shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by the Federal Acquisitions Regulation (FAR).

6.3 Requirements related to the support of Records Management Functions

(a) The Contractor shall support records management functions through the life of the project and termination of the contract, unless otherwise expressly noted in writing from the Departmental Records Management Office.

(b) The Contractor shall provide a mechanism for reliably deleting DOI data upon request by

DOI.

(c) When the Department or bureau contracts for the design, development, or operation of a system of records on individuals on behalf of the Department to accomplish an agency function, the agency must make and preserve records to sufficiently document all planning, design, development or operation of the system.

(d) The routine disposition of records created and maintained by DOI and the Contractor may be suspended through coordination of the Departmental Records Officer, Bureau/Office Records Officer, the Records Management Contact, the Program Manager or Site Manager. A records schedule disposition suspension may be required to—

(1) Suspend the routine disposition of the Department and Contractor records to support an investigation;

(2) Preserve records for research;

(3) Identify lessons learned in recovery operations from natural disasters or other emergencies’; and

(4) Provide evidence for a legal action.

(e) In accordance with the Federal Records Act and the CFRs, Federal agencies must ensure that adequate training is provided to all agency personnel on policies, responsibilities and techniques for the implementation of record keeping requirements and the distinction between records and non-record materials, regardless of media. Contractor personnel are considered agency personnel while supporting the operations and assets for the agency.

Therefore, Contractor employees are required to complete DOI mandated training, including information security awareness, privacy, and records management training before accessing any the DOI information systems.

(f) Contracted staff with official DOI electronic messaging accounts must comply with all related policies.

Section 7.0 – Contractor Personnel Security Requirements

Federal Personal Identification Card Requirements

Acquired services shall comply with the following regulations and requirements. Homeland Security Presidential Directive-12 requires that all Federal entities ensure that all Contractors have current and approved security background investigations that are equivalent to investigations performed on Federal employees. The Contractor shall comply with DOI-AAAP- 0081 policy requirements. Background investigations will be performed by the Office of Personnel Management (OPM).

Performance of this contract requires Contractor personnel to have a Federal Government-issued personal identification card before being allowed unsupervised access to a DOI facility and/or information. The Contracting Officer’s Representative (COR) will be the sponsoring official and will make the arrangements for personal identity verification and card issuance.

At least two weeks before start of contract performance, the Contractor will identify all Contractor and subcontractor personnel who will require (physical and/or logical) access for performance of work under this contract. The Contractor must make their personnel https://doimspp.sharepoint.com/:w:/r/sites/DOI-AAAPResources/_layouts/15/Doc.aspx?sourcedoc=%7B2187F182-D91D-4F67-9FB0-7AD8E7124DD8%7D&file=DOI-AAAP-0081%2C%20Implementation%20of%20Homeland%20Security%20Presidential%20Directive-12%20(HSPD-12)%20at%20DOI%20for%20Contractors%20and%20Recipients.docx&action=default&mobileredirect=true&DefaultItemOpen=1 https://doimspp.sharepoint.com/:w:/r/sites/DOI-AAAPResources/_layouts/15/Doc.aspx?sourcedoc=%7B2187F182-D91D-4F67-9FB0-7AD8E7124DD8%7D&file=DOI-AAAP-0081%2C%20Implementation%20of%20Homeland%20Security%20Presidential%20Directive-12%20(HSPD-12)%20at%20DOI%20for%20Contractors%20and%20Recipients.docx&action=default&mobileredirect=true&DefaultItemOpen=1 available at the place and time specified by the COR in order to initiate screening and background investigations. The contract and contractors will be bound by an NDA to be facilitated by the COR. The following forms, or their equivalent, will be used to initiate the credentialing process:

(a) Office of Personnel Management (OPM) Standard Form 85 or 85P

(b) Official Form 306

(c) Fingerprint card (local procedures may require the fingerprinting to done at a police station; in this case, any charges are to be borne by the Contractor)

(d) Release to Obtain Credit Information

(e) Personal Identity Verification card application (web-based)

Contractor employees are required to give, and to authorize others to give, full, frank, and truthful answers to relevant and material questions needed to reach a suitability determination. Refusal or failure to furnish or authorize provision of information may constitute grounds for denial or revocation of credentials. Government personnel may contact the Contractor personnel being screened or investigated in person, by telephone or in writing, and the Contractor agrees to make available for such contact.

Alternatively, if an individual has already been credentialed by another agency through OPM, and that credential has not yet expired, further investigation may not be necessary.

The Contractor is required to provide the COR with documentation that supports the individual’s status where a previous credential is involved.

During performance of the contract, the Contractor will keep the COR apprised of changes in personnel to ensure that performance is not delayed by compliance with credentialing processes. Cards that have been lost, damaged, or stolen must be reported to the COR and Issuing Office within 24 hours. Replacement will be at the Contractor’s expense. If reissuance of expired credentials is needed, it will be coordinated through the COR.

At the end of contract performance, or when a Contractor employee is no longer working under this contract, the Contractor will ensure that all identification cards are returned to the COR.

Before starting work under this contract, a National Agency Check (NAC) will be conducted to verify the identity of the individual applying for clearance. Upon successful completion of the NAC process, an identification card will be issued and access granted.

Simultaneously, a NAC with Inquiries (NACI) will be initiated to determine the individual’s suitability for the position. If the NACI adjudication is favorable, nothing more needs to be done. If the adjudication is unfavorable, the credentials will be revoked.

In the event of a disagreement between the Contractor and the Government concerning the suitability of an individual to perform work under this contract, DOI shall have the right of final determination.

This requirement must be incorporated into any subcontracts that require subcontractor personnel to have regular and routine unsupervised access to a Federally controlled facility for more than 180 calendar days or any unsupervised access to a Federally controlled Level 3 or 4 information system.

Section 8.0 – Table of Deliverables and Reporting Requirements

Title Description Due

Date/Frequency Government Approval and Surveillance

Cybersecurity(

CS)

Documentation

As described in, and in accordance with, the IT Security and Privacy Requirements documents.

(Documents include but not limited to, IT Security Policies, Privacy Plan, PIA).

Upon Completion prior to authorization to move to Service Ready status

Contracting Officer’s Representative (COR), Government Information System Owner, and Government Authorizing Official

(AO)

System Security Plan

(SSP)

As described in, and in accordance with, the IT Security and Privacy Requirements documents.

(Documents include but not limited to, IT Security Policies, Privacy Plan, PIA).

Upon Completion prior to authorization to move to Service Ready status

COR, Government Information System Owner, Government

AO

Continuous Monitoring Plan (CMP)

As described in, and in accordance with, the IT Security and Privacy Requirements documents.

(Documents include but not limited to, IT Security Policies, Privacy Plan, PIA).

Upon Completion prior to authorization to move to Service Ready status

COR, Government Information System Owner, Government

AO

Privacy Impact Assessment

(PIA)

An analysis of privacy risk and mitigating privacy controls to protect PII prior to the development or purchase

Upon completion prior to authorization to move to Service Ready status;

COR, Government Information System Owner, Government

AO

of information technology.

updated as needed to address privacy risk as part of the CMP

System Privacy Plan

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Upon Completion prior to authorization to move to Service Ready status

COR, Government Information System Owner, Government

AO

Contingency Plan

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Upon Completion prior to authorization to move to Service Ready status

COR, Government Information System Owner, Government

AO

Independent Assessor’s Security Assessment Plan and Report

(SAP/SAR)

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Upon Completion prior to authorization to move to Service Ready status

COR, Government Information System Owner, Government

AO

Plan of Action and Milestones

(POA&M)

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Upon Completion prior to authorization to move to Service Ready status and Quarterly Thereafter

COR, Government Information System Owner, Government

AO

Vulnerability and Security Configuration Scan Report

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Monthly COR, Government Information System Owner

Continuous Monitoring Report

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Monthly COR, Government Information System Owner, Government

AO

Independent Penetration Testing and Report

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Annually COR, Government Information System Owner, Government

AO

Documentation for Audit Requirements

As described in, and in accordance with, the IT Security and Privacy Requirements document.

30 calendar days after written request

COR, Government Information System Owner, Government

AO

Training Compliance Report

As described in, and in accordance with, the IT

Annually COR, Government Information System Owner

Security and Privacy Requirements document.

Security Incidents

As described in, and in accordance with, the IT Security and Privacy Requirements document.

Per Incident (immediately but not more than 2 hours)

CO, COR, Government Information System Owner, Government

AO, DOI CIRC

Contractor Employee Report

Report of all Contractor employees that have access to DOI Data with status of required background checks as specified.

Annually on contract award anniversary date and within 3 business days upon written request

COR

Section 9.0 – Reference Documents

All DOI-specific documents referenced in this document necessary for Contractor review and reference can be provided by the CO/COR.

Section 10.0 – Glossary

Please refer to the NIST online glossary at: https://csrc.nist.gov/glossary�HYPERLINK "http://www.doi.gov/ocio/information_assurance/Policies.cfm"\] https://csrc.nist.gov/glossary%22%EF%B7%9FHYPERLINK%20%22http:/www.doi.gov/ocio/information_assurance/Policies.cfm

Section 1.0 – Information Technology & Cybersecurity Requirements
Section 2.0 – Government Oversight, Monitoring and Contractor Responsibilities
Section 3.0 – Cybersecurity Incident Response
Section 4.0 – Privacy Requirements
Section 5.0 – Section 508 Requirements
Section 6.0 – Records Management Requirements
Section 7.0 – Contractor Personnel Security Requirements
Section 8.0 – Table of Deliverables and Reporting Requirements
Section 9.0 – Reference Documents
Section 10.0 – Glossary

File details come from the government source that posted it. Updated .