SOO Appendix 3 Standard Operating Procedures.pdf
PDF 190 KB Posted
- Attached to
- LMS Implementation for BIE Federal contract opportunity
- Solicitation number
- 140A2321R0001
About this file
This document outlines standard operating procedures for oversight of contractor-managed systems within the Department of the Interior. It specifies that contractor-supported systems must meet minimum federal security requirements as defined in NIST SP 800-53. The contracting officer's representative and information system security officers must ensure systems comply with federal, agency, and service provider requirements throughout the system lifecycle. Specific requirements include compliance with FISMA, ATO documentation and approval, continuous monitoring plans, vulnerability scanning, weakness remediation, audit logging, personnel security checks, and annual security assessments. Relatedly, the opportunity notice seeks proposals for an LMS implementation to support the Bureau of Indian Education's strategic education transformation plan through an IDIQ contract with the Department of the Interior Bureau of Indian Affairs Bureau of Indian Education.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140A2321R0001_Amd_0002.pdf | ||
| Attachment 3 - SOO A0002_0002.pdf | ||
| Attachment 4 - QA_0002.pdf | ||
| Sol_140A2321R0001_Amd_0001.pdf | ||
| B08 SF1449 140A2321R0001.pdf | ||
| Attachment 1 - IDIQ Pricing.xlsx | XLSX spreadsheet | |
| Attachment 3 - SOO.pdf | ||
| SOO Appendix 2 - Baseline Compliance Contract Guidelines.pdf | ||
| SOO Appendix 1 School List.xlsx | XLSX spreadsheet | |
| Sol_140A2321R0001.pdf | ||
| Attachment 2 - Position Descriptions.pdf | ||
| A2321R0001 Synopsis.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DOI Information Management and Technology Compliance Acquisition Policy
Standard Operating Procedures for
Oversight of Contractor Managed Systems
Federal Information Processing Standard
The Federal Information Processing Standard (FIPS) 200, “Minimum Security Requirements for
Federal Information and Information Systems,” is a mandatory federal standard that defines the minimum-security requirements for federal information and information systems in eighteen security related areas. Contractor supported systems must meet the minimum-security requirements using the security controls in accordance with current National Institute of
Standards and Technology (NIST) Special Publication (SP) 800-53 (hereafter described as NIST
800-53).
Oversight Responsibilities
Contracting Officer Representative (COR) in conjunction with ISSOs, cybersecurity and IT representatives, Program Managers, etc. (hereafter referred to as designated contract support staff) must ensure that the Information Technology (IT) systems under their purview maintain operational and compliant with federal, service provider, and Agency IT security requirements.
Contracting Officer Representative (COR) should work with designated contract support staff to monitor contractor performance throughout the system lifecycle and ensure that security compliance is established and maintained. Additionally, any substantial change in the system boundary must be immediately reported to System Owner (SO) and Authorizing Official (AO).
Acquisition officials must coordinate with designated contract support staff, SO/AO and Bureau
Associate Chief Information Security Officers (ACISO) to determine and ensure that the necessary IT system’s security requirements have been adequately and appropriately addressed within the IT contract.
The COR in coordination with designated contract support staff is required to verify the contractor operated system is performing the following items below. If the contractor operated system does not meet the identified criteria, the COR is responsible for notifying the contractor to staff appropriate resources to maintain the system.
Specific security requirements include the following for the COR and/or ISSO to verify. Please note the requirements include but are not limited to the following:
• Federal Information Security Modernization Act (FISMA) and OMB Circular A-130.
The ISSO will verify the contractor is always following FISMA and OMB Circular A-
130 and working with the Agency to meet compliance requirements. The contractor shall agree to assist the Government in its compliance with the requirements set forth in
FISMA, by successfully completing the Assessment & Authorization (A&A) provided for in FISMA for all computer systems provided by the contractor. The contractor shall complete the A&A process on or before providing the Service Ready Notice.
• Support and provide (as required or directed) information, testing, or analysis for A&A for documentation that describes the security posture of the system and evaluation of system risks along with recommendations for correcting deficiencies.
• If cloud related, the ISSO will verify the contractor is operating in a Federal Risk and
Authorization Management Program (FedRAMP) boundary and review the client responsible controls. Where necessary provide implementation statements or verify implementation statements have been provided.
• The ISSO will review the Authority to Operate (ATO) and the contractor must receive and maintain an ATO from the Government AO. The security posture of the system must be acceptable to the Government AO or the AO may deny the authority to operate and the system would be shutdown. The ISSO will review any changes to the system and advise the AO and Bureau ACISO.
• NIST SP 800-53: The ISSO will verify the contractor is following the security control requirements of the current version of NIST SP 800-53 or FIPS 200 that are appropriate to the sensitivity and criticality of the data or system.
• Continuous Monitoring Plan: ISSO/COR is responsible for ensuring that the contract requires the contractor to submit a continuous monitoring plan that supports the DOI
Authorizing Officials (AO) ongoing authorization process. The plan must conform to the
NIST SP 800-137 and be formally approved by the Government AO. The Vendor shall submit monthly continuous monitoring reports to the ISSO. The ISSO will review CMP for contractor operated systems to ensure relevance with existing DOI Policy.
• Scans: The contractor must provide for system scans on a monthly basis with a vulnerability analysis tool that is acceptable to DOI. All “safe” or “nondestructive” checks must be turned on. The designated ISSO will review the scans to and work with the contractor to mitigate vulnerabilities.
• Weakness Resolution: In alignment with the timeframes set forth in DOI IT Security
Policy or otherwise mandated by Federal regulations, the contractor must provide or appropriate and timely action to correct or mitigate any weaknesses discovered during testing generally at no additional cost.
• Audit Logging: The contractor must provide for compliance with audit logging standards per DOI policy. The audit records must contain sufficient information to, at a minimum, establish what type of event occurred, when (date and time) the event occurred, where the event occurred, the source of the event, the outcome (success or failure) of the event, and the identity of any user/subject associated with the event and will be reviewed by the designated ISSO for anomalies or critical events.
• System Management: The contractor must align with DOI’s continuous monitoring strategy in Patch management, Antivirus, Malware detection, Event management, Configuration management, License management, Incident management, etc.
• Security Testing: The contractor must provide for annual security testing in alignment with DOI’s Continuous Monitoring Program.
• FISMA Security Requirements: The contractor will work with the government to ensure all aspects of the project meet the FISMA security requirements including but not limited to determining the system security authorization boundary (to be illustrated in the contractor provided architectural diagram) and providing support to receive the
Authorization to Operate (ATO) for the system.
• Contingency Plan: The contractor will submit a contingency plan in accordance with
NIST SP 800-34. The plan must be reviewed and approved by the ISSO. A copy of the annual test results will be provided to the COR and ISSO.
• The contractor shall perform personnel security / suitability checking in accordance with
FAR Part 52.204-9 (see Section I) and shall be validated by the COR.
• The COR will verify that all contractor personnel with access to government information that is within the security A&A scope must successfully complete a background investigation in accordance with Homeland Security Presidential Directive-12 (HSPD-
12) Office of Management and Budget (OMB) guidance M-05-24, M-11-11 “Continued
Implementation of Homeland Security Presidential Directive (HSPD-12) Policy for a
Common Identification Standard for Federal Employees and Contractors,” and as specified in agency-identified security directives and procedural guides.
• All NIST 800-53 controls must be tested and assessed no less than every three (3) years unless otherwise determined by the AO.
• The ISSO will review the controls for the contractor systems. The System Security Plan
(SSP) shall be completed in accordance with NIST SP 800-18, Revision 1 (hereafter listed as NIST SP 800-18 R1) and other relevant guidelines.
• The ISSO will verify the contractor operated system maintains an inventory that includes hardware, software and related information as identified in the Agency identified security directives and procedural guides (e.g. architectural diagrams, configuration information, Security Technical Implementation Guides (STIG’s), etc..).
• The designated ISSO will review the Privacy Impact Assessment (PIA) on an annual basis.
Incomplete artifacts within this list will be identified as weaknesses with the contractor operator system. Designated ISSO’s are to report to their System Owner and Authorizing Official weaknesses and/or non-compliance. CORs/ISSOs should also notify the Contracting Officer if there is ever a non-compliance or failure to perform issue.
Procedures for External Information System Services
Step 1: Privacy Impact Assessment (DOI Responsibility)
The information owner is required to complete a Privacy Impact Assessment to identify if there is any Personally Identifiable Information (PII) being generated, stored, processed, or exchanged by the system.
Step 2: Security Categorization (DOI Responsibility)
The information owner is required to categorize the system and the information processed, stored, or transmitted by the system in accordance with FIPS 199, Standards for Security
Categorization of Federal Information and Information Systems, and document the results
(including supporting rationale) in the system security plan.
Step 3: Information Security Documentation (DOI & Service Provider Responsibility)
The service provider is required to develop and maintain system security documentation that reflects the current security posture of the information system. The information security documentation and the required content are determined by NIST standards and DOI IT Security
Policies.
Step 4: Security Assessment (DOI & Service Provider Responsibility)
The service provider is required to perform a security assessment, using a trusted independent assessor, by assessing the controls identified in the DOI IT Security Policies and ensuring the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting security requirements.
Step 5: Authorization to Operate (DOI & Service Provider Responsibility)
The DOI Authorizing Official must approve the ATO. The ATO is a formal declaration by the authorizing official that an information service is approved to operate in a particular security mode, using a prescribed set of safeguards and at an acceptable level of risk.
Step 6: Continuous Monitoring (DOI & Service Provider Responsibility)
The information owner and service provider are required to maintain the security level of the system over time by implementing and monitoring the security controls identified in the DOI IT
Security Policies, and the supporting CMP, on an ongoing basis.
The Contracting Officer’s Representative (COR), Government system owner, and Government
Authorizing Official (AO) shall review the Continuous Monitoring Report as described in, and in accordance with, the IT Security and Privacy Requirements document and the IT CMP.
File details come from the government source that posted it. Updated .