_Statement_of_Work_-_FCHS2_Attachment_2_Authorities_and_Prohibitions.docx

DOCX document 79 KB Posted

Attached to
Foundation Cloud Hosting Services (FCHS2) Cloud Co Federal contract opportunity
Solicitation number
DOIDFBO220040
Issued by
Department of the Interior Departmental Offices Interior Business Center

View the file

Other files for this federal contract opportunity

Other files attached to Foundation Cloud Hosting Services (FCHS2) Cloud Co, newest first.
File Type Posted
FCHS2_Department_of_the_Interior_Q_A_from_RFI_and_Industry_Day_-_Final_0003.xlsx XLSX spreadsheet
Sol_DOIDFBO220040_Amd_0003.pdf PDF
Sol_DOIDFBO220040_Amd_0002.pdf PDF
Sol_DOIDFBO220040_Amd_0001.pdf PDF
_Statement_of_Work_-_FCHS2_Attachment_1_Security_Objectives-Cybersecurity-and-Governance.docx DOCX document
Statement_of_Work_for_FCHS_Follow_On_2023-2033_IDIQ_Contract.pdf PDF
Cover_Sheet_for_Request_for_Information_-_draft.docx DOCX document
Sol_DOIDFBO220040.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Section C – Statement of Work Attachment 1 Authorities and Prohibitions

The Statement of Work (SOW) Attachment 2 identifies applicable laws, policies, directives, regulations, standards, and guideline authorities and prohibitions related to the products and services offered under the Foundation Cloud Hosting Services or FCHS2 contract.

1 Department of the Interior Policies and Directives The following are Department of the Interior cloud related policies and directives all DOI bureaus and offices comply.

· Department Manual Series 02 Part 112, Chapter 24 – OCIO Oversight Responsibilities

· OCIO Directive 2018-006 DOI Privacy Threshold Analysis Guide

· DOI Secretary Order 3340 Strengthening and Securing Information Management and Technology at the Department of the Interior (FITARA compliance), August 2016

· DOI Mandatory Use of Cloud Contracts Policy Aug 2018

· OCIO Pre-approved Enterprise and Mandatory Use Cloud Contracts Sept 2020 (addendum)

· OCIO Cloud Definition and Registration Policy Apr 2021

1.1 Federal Authorities

The FCHS2 contract is a federal wide procurement umbrella provisioned to acquire cloud services, either positioned “Ready” or already “Authorized” according to the 2019 Federal Cloud Computing Strategy – Cloud Smart, a long-term, high-level strategy to drive cloud adoption in Federal agencies. FCHS2 shall offer Cloud Smart services that focus on three inter-related areas to drive cloud adoption through building knowledge in government and removing burdensome policy barriers.

Table of Cloud Smart Adoption Areas

Strategy
Initiative
Security
Modernize security policies to focus on risk-based decision-making, automation, and moving protections closer to data.
Procurement
Improve the ability of agencies to purchase cloud solutions through repeatable practices and sharing knowledge.
Workforce
Upskill, retrain, and recruit key talent for cybersecurity, acquisition, and cloud engineering.

1.2 National Institute of Standards Technologies

Task orders under FCHS2 shall align and meet minimum Risk Management Framework thresholds according to the IT System(s) categorization level (Low, Moderate, High) and relative Security and Privacy Controls.

Contractors shall identify barriers or incidences in task order proposals that do not meet NIST standards and thresholds, along with recommendations for closing elevated risk gaps.

FCHS2 task order services will have a wide range of service requests whether partial or full support services within the IT System life-cycle. Agencies may request just cloud service license and/or ongoing technical support for both managing the IT System Management and/or assisting with the Assessment & Authorization process.

Federal Information Security Modernization Act (FISMA) of 2014 requires federal agencies to develop, document, and implement an agency-wide program to provide information security for the information and systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other sources.

FCHS2 services shall align and meet minimum thresholds identified under the National Institute of Standards Technologies (NIST) publications including, but not limited to the following Special Publications (SP) identified below under the Risk Management Framework – Security Life Cycle diagram.

2 Applicable Laws and Executive Orders The following are the most common and applicable federal laws and executive orders aligned with the FCHS2 contract requirements. Contractors shall be familiar and within compliance of applicable federal laws and orders.

Document Name
Issuance Date
Privacy Act (P.L. 93-579)
December 1974
FOIA, Freedom of Information Act (FOIA), 5 U.S.C. § 552, As Amended By Public Law No. 104-231, 110 Stat. 3048, Electronic Freedom of Information Act
Amendments of 1996
FISMA, Federal Information Security Modernization Act of 2014 (Public Law 113-283; December 18, 2014). Federal Information Security Modernization Act (FISMA), 44 U.S.C. § 3551 et seq., The original FISMA was Federal Information Security Management Act of 2002 (Public Law 107-347 (Title III); December 17, 2002), in the E-Government Act of 2002.
December 2014
Securing International Information: Executive Order (EO) 13873 on Securing the Information and Communications Technology and Services Supply Chain (May 15, 2019)
May 15, 2019
Incident Response: Guidance on Federal Information Security and Privacy – Incident Response Playbook Requirements under, OMB M-22-05
December 6, 2021
Vulnerability Disclosure: Public vulnerability disclosure programs under, OMB Memorandum M-20-32, Improving Vulnerability Identification, Management and Remediation
September 20, 2020
Title 32 Code of Federal Regulations, Sec. 2002.4, Definitions.
2018 ed
Title 40 U.S. Code, Sec. 11331, Responsibilities for Federal information systems standards.
2017 ed
OMB CIO FITARA, Federal Information Technology Acquisition Reform Act (Clinger-Cohen Act of 1996)
November 2018
OMB Circular No. A-123, Management's Responsibility for Enterprise Risk Management and Internal Control. (M-16-17)
July 2016
OMB Circular A-130, Managing Information as a Strategic Resource
July 2016
Supply Chain and Critical Software Executive Order 14028, Improving the Nation’s Cybersecurity (May 2021) and a National Initiative for Improving Cybersecurity in Supply Chains under the SECURE Technology Act (December 21, 2018) and Federal Acquisition Supply Chain Security Act (September 01, 2020); Critical Software: Protecting Critical Software, Through Enhanced Security measures under M-21-30
May 2021
Strengthening Cybersecurity Executive Order (E.O.) 13800, Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure (May 11, 2017) and OMB M-19-03 Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program (December 10, 2018), Binding Operational Directive 1802-Securing High Value Asset, and OMB M-17-25 Reporting Guidance (May 19, 2017)
May 2017
Open Data OMB Directive M-13-13, Open Data Policy-Managing Information as an Asset
May 2013
TIC OMB Directive M-19-26 Update to the Trusted Internet Connections (TIC) Initiative
September 2019
IPV6 – OMB Directive M-21-07, Completing the Transition to Internet Protocol Version 6 (IPv6); and USGv6 guidance Executive Order (EO) M-21-07
November 2020
Section 508 Amendment to the Rehabilitation Act of 1973
1998
WCAG 2.x (or later), Web Content Accessibility Guidelines by the Web Accessibility Initiative (WAI) of the World Wide Web Consortium (W3C)
December 2008
The 21st Century Integrated Digital Experience Act (21st Century IDEA)
December 2018
MEGABYTE Act, Making Electronic Government Accountable by Yielding Tangible Efficiencies Act of 2016 or the MEGABYTE Act of 2016 Making
July 2016

3 Prohibitions This section is related to various prohibitions within cloud services and contractors under the FCHS2 contract.

DOI requests contractors to refrain from and to actively prevent adware, spam, and remarketing of information. The Contractor shall not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the DOI. The Contractor and/or their agents shall not resell nor otherwise redistribute information gained from its access to FCHS2 contract users.

Contractors shall require each of their administrative employees that interfaces with the cloud services customized applications and government data to sign non-disclosure agreements at onset of project implementation. Non-disclosure agreements will be supplied by the Contracting Officer, or the Contractor may elect equivalent and approved alternative.

A government approved logon banner must be displayed on the first page of any public access web pages. Logon warning banners must be automatically incorporated into IT Systems initial logon process and require periodic credentialed acceptance for all (federal and contractor) personnel accessing the federal IT System.

image1.jpg

File details come from the government source that posted it. Updated .