_Statement_of_Work_-_FCHS2_Attachment_2_Authorities_and_Prohibitions.docx
DOCX document 79 KB Posted
- Attached to
- Foundation Cloud Hosting Services (FCHS2) Cloud Co Federal contract opportunity
- Solicitation number
- DOIDFBO220040
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FCHS2_Department_of_the_Interior_Q_A_from_RFI_and_Industry_Day_-_Final_0003.xlsx | XLSX spreadsheet | |
| Sol_DOIDFBO220040_Amd_0003.pdf | ||
| Sol_DOIDFBO220040_Amd_0002.pdf | ||
| Sol_DOIDFBO220040_Amd_0001.pdf | ||
| _Statement_of_Work_-_FCHS2_Attachment_1_Security_Objectives-Cybersecurity-and-Governance.docx | DOCX document | |
| Statement_of_Work_for_FCHS_Follow_On_2023-2033_IDIQ_Contract.pdf | ||
| Cover_Sheet_for_Request_for_Information_-_draft.docx | DOCX document | |
| Sol_DOIDFBO220040.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section C – Statement of Work Attachment 1 Authorities and Prohibitions
The Statement of Work (SOW) Attachment 2 identifies applicable laws, policies, directives, regulations, standards, and guideline authorities and prohibitions related to the products and services offered under the Foundation Cloud Hosting Services or FCHS2 contract.
1 Department of the Interior Policies and Directives The following are Department of the Interior cloud related policies and directives all DOI bureaus and offices comply.
· Department Manual Series 02 Part 112, Chapter 24 – OCIO Oversight Responsibilities
· OCIO Directive 2018-006 DOI Privacy Threshold Analysis Guide
· DOI Secretary Order 3340 Strengthening and Securing Information Management and Technology at the Department of the Interior (FITARA compliance), August 2016
· DOI Mandatory Use of Cloud Contracts Policy Aug 2018
· OCIO Pre-approved Enterprise and Mandatory Use Cloud Contracts Sept 2020 (addendum)
· OCIO Cloud Definition and Registration Policy Apr 2021
1.1 Federal Authorities
The FCHS2 contract is a federal wide procurement umbrella provisioned to acquire cloud services, either positioned “Ready” or already “Authorized” according to the 2019 Federal Cloud Computing Strategy – Cloud Smart, a long-term, high-level strategy to drive cloud adoption in Federal agencies. FCHS2 shall offer Cloud Smart services that focus on three inter-related areas to drive cloud adoption through building knowledge in government and removing burdensome policy barriers.
Table of Cloud Smart Adoption Areas
| Strategy | |
| Initiative |
| Security |
| Modernize security policies to focus on risk-based decision-making, automation, and moving protections closer to data. |
| Procurement | |
| Improve the ability of agencies to purchase cloud solutions through repeatable practices and sharing knowledge. |
| Workforce | |
| Upskill, retrain, and recruit key talent for cybersecurity, acquisition, and cloud engineering. |
1.2 National Institute of Standards Technologies
Task orders under FCHS2 shall align and meet minimum Risk Management Framework thresholds according to the IT System(s) categorization level (Low, Moderate, High) and relative Security and Privacy Controls.
Contractors shall identify barriers or incidences in task order proposals that do not meet NIST standards and thresholds, along with recommendations for closing elevated risk gaps.
FCHS2 task order services will have a wide range of service requests whether partial or full support services within the IT System life-cycle. Agencies may request just cloud service license and/or ongoing technical support for both managing the IT System Management and/or assisting with the Assessment & Authorization process.
Federal Information Security Modernization Act (FISMA) of 2014 requires federal agencies to develop, document, and implement an agency-wide program to provide information security for the information and systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other sources.
FCHS2 services shall align and meet minimum thresholds identified under the National Institute of Standards Technologies (NIST) publications including, but not limited to the following Special Publications (SP) identified below under the Risk Management Framework – Security Life Cycle diagram.
2 Applicable Laws and Executive Orders The following are the most common and applicable federal laws and executive orders aligned with the FCHS2 contract requirements. Contractors shall be familiar and within compliance of applicable federal laws and orders.
| Document Name |
| Issuance Date |
| Privacy Act (P.L. 93-579) |
| December 1974 |
| FOIA, Freedom of Information Act (FOIA), 5 U.S.C. § 552, As Amended By Public Law No. 104-231, 110 Stat. 3048, Electronic Freedom of Information Act |
| Amendments of 1996 |
| FISMA, Federal Information Security Modernization Act of 2014 (Public Law 113-283; December 18, 2014). Federal Information Security Modernization Act (FISMA), 44 U.S.C. § 3551 et seq., The original FISMA was Federal Information Security Management Act of 2002 (Public Law 107-347 (Title III); December 17, 2002), in the E-Government Act of 2002. |
| December 2014 |
| Securing International Information: Executive Order (EO) 13873 on Securing the Information and Communications Technology and Services Supply Chain (May 15, 2019) |
| May 15, 2019 |
| Incident Response: Guidance on Federal Information Security and Privacy – Incident Response Playbook Requirements under, OMB M-22-05 |
| December 6, 2021 |
| Vulnerability Disclosure: Public vulnerability disclosure programs under, OMB Memorandum M-20-32, Improving Vulnerability Identification, Management and Remediation |
| September 20, 2020 |
| Title 32 Code of Federal Regulations, Sec. 2002.4, Definitions. |
| 2018 ed |
| Title 40 U.S. Code, Sec. 11331, Responsibilities for Federal information systems standards. |
| 2017 ed |
| OMB CIO FITARA, Federal Information Technology Acquisition Reform Act (Clinger-Cohen Act of 1996) |
| November 2018 |
| OMB Circular No. A-123, Management's Responsibility for Enterprise Risk Management and Internal Control. (M-16-17) |
| July 2016 |
| OMB Circular A-130, Managing Information as a Strategic Resource |
| July 2016 |
| Supply Chain and Critical Software Executive Order 14028, Improving the Nation’s Cybersecurity (May 2021) and a National Initiative for Improving Cybersecurity in Supply Chains under the SECURE Technology Act (December 21, 2018) and Federal Acquisition Supply Chain Security Act (September 01, 2020); Critical Software: Protecting Critical Software, Through Enhanced Security measures under M-21-30 |
| May 2021 |
| Strengthening Cybersecurity Executive Order (E.O.) 13800, Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure (May 11, 2017) and OMB M-19-03 Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program (December 10, 2018), Binding Operational Directive 1802-Securing High Value Asset, and OMB M-17-25 Reporting Guidance (May 19, 2017) |
| May 2017 |
| Open Data OMB Directive M-13-13, Open Data Policy-Managing Information as an Asset |
| May 2013 |
| TIC OMB Directive M-19-26 Update to the Trusted Internet Connections (TIC) Initiative |
| September 2019 |
| IPV6 – OMB Directive M-21-07, Completing the Transition to Internet Protocol Version 6 (IPv6); and USGv6 guidance Executive Order (EO) M-21-07 |
| November 2020 |
| Section 508 Amendment to the Rehabilitation Act of 1973 |
| 1998 |
| WCAG 2.x (or later), Web Content Accessibility Guidelines by the Web Accessibility Initiative (WAI) of the World Wide Web Consortium (W3C) |
| December 2008 |
| The 21st Century Integrated Digital Experience Act (21st Century IDEA) |
| December 2018 |
| MEGABYTE Act, Making Electronic Government Accountable by Yielding Tangible Efficiencies Act of 2016 or the MEGABYTE Act of 2016 Making |
| July 2016 |
3 Prohibitions This section is related to various prohibitions within cloud services and contractors under the FCHS2 contract.
DOI requests contractors to refrain from and to actively prevent adware, spam, and remarketing of information. The Contractor shall not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the DOI. The Contractor and/or their agents shall not resell nor otherwise redistribute information gained from its access to FCHS2 contract users.
Contractors shall require each of their administrative employees that interfaces with the cloud services customized applications and government data to sign non-disclosure agreements at onset of project implementation. Non-disclosure agreements will be supplied by the Contracting Officer, or the Contractor may elect equivalent and approved alternative.
A government approved logon banner must be displayed on the first page of any public access web pages. Logon warning banners must be automatically incorporated into IT Systems initial logon process and require periodic credentialed acceptance for all (federal and contractor) personnel accessing the federal IT System.
image1.jpg
File details come from the government source that posted it. Updated .