Attachments_A_(Security_Requirements).pdf
PDF 274 KB Posted
- Attached to
- Expert IBM Cognos Consulting and Support Services Federal contract opportunity
- Solicitation number
- TFSAFSA16CI0002
About this file
Attachment A (Security Requirements)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_000002_(TFSAFSA16CI0002).pdf | ||
| Amendment_000001_(TFSAFSA16CI0002).pdf | ||
| Attachment_B_(IPP_Waiver).pdf | ||
| TFSAFSA16CI0002.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment A – Security Requirements
1 Applicability Attachment A – Security Requirements details high-level security requirements that may apply to procured products, systems, and services. All sections of this document must be included, even when they are not applicable. This ensures that the contractor is informed of requirements in the event they become applicable.
This attachment applies to the Contractor, its subcontractors, and contractor personnel, including fiscal and financial agents (hereafter referred to collectively as “Contractor”) and addresses specific Bureau of the Fiscal Service (Fiscal Service) requirements in addition to those included in the Federal Acquisition Regulation (FAR), the Privacy Act of 1974 (5 U.S.C. §552a), the Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191, 110 Stat. 1936), the Sarbanes-Oxley Act of 2002 (Pub. L.
107-204, 116 Stat 745), and other laws, mandates, or executive orders pertaining to the development and operations of information systems and the protection of sensitive information and data. The following should not be construed to alter or diminish civil and/or criminal liabilities provided under various laws or mandates.
2 Information Types The term “information” is synonymous with data, regardless of format or medium. Personally Identifiable Information (PII) is a subset of Sensitive But Unclassified (SBU) information. Sensitive PII is a subset of PII, and therefore a subset of SBU information. All requirements for SBU information apply to PII and Sensitive PII. All requirements for PII apply to Sensitive PII.
2.1 Sensitive But Unclassified Information
Sensitive But Unclassified information (SBU) is any information, the loss, misuse, or unauthorized access to or modification of which could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under the Privacy Act but which has not been specifically authorized under criteria established by an executive order or an act of Congress to be kept secret in the interest of national defense or foreign policy. SBU information is subject to stricter handling requirements than less sensitive non-SBU information because of the increased risk if the data are compromised. Some categories of SBU include financial, medical, health, legal, strategic , and business information. Personally Identifiable Information and Sensitive PII are also considered to be SBU. These categories of information require appropriate protection individually and may require additional protection when aggregated with other sensitive information.
2.2 Personally Identifiable Information
Personally Identifiable Information ( as defined in OMB Memorandum M-07-16, refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information that is publicly available — in any medium and from any source — is or can be combined to identify an individual. As an example, PII includes a name and an address because it uniquely identifies an individual, but alone may not constitute Sensitive PII.
2.3 Sensitive Personally Identifiable Information
Sensitive PII (refers to information that can be used to target, harm, or coerce an individual or entity;
assume or alter an individual’s or entity’s identity; or alter the outcome of an individual’s or entity’s activities. Sensitive PII requires stricter handling because of the increased risk to an individual or associates if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as Social Security numbers (SSN) or biometric identifiers. Other information such as a financial account, date of birth, maiden names, citizenship status, or medical information, in conjunction with the identity of an individual (directly or indirectly inferred), are also considered Sensitive PII. In addition, the context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or complaint.
3 Information Protection The Contractor's employees, facilities, services and product(s) shall meet applicable United States (U.S.)
federal government laws, directives, executive orders, standards, guidelines, and other requirements for information security, personnel security, physical security, and data encryption. The Contractor shall follow United States Government, Treasury, and Fiscal Service procedures for proper handling of SBU and PII. The Contractor may be required to assist with security reviews by providing information about processes, software, facilities, personnel, and equipment through interviews, on-site inspections (if necessary), and documentary evidence.
Sensitive But Unclassified information, data, and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to Government control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following NIST Special Publication 800-88, Guidelines for Media Sanitization.
The disposition of all data will be at the written direction of the COR, this may include documents returned to Government control; destroyed; or held as specified until otherwise directed. Items returned to the Government shall be hand carried or sent by certified mail to the COR.
The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The contractor shall also protect all Government data, equipment, etc.
Information systems and services performing work on behalf of the Fiscal Service shall be located, operated and maintained within the U.S.; operations and maintenance of systems shall be conducted by personnel physically located within the U.S or its territories. “Operated” refers to carrying out administrator/privileged user functions, such as, database administration, patching, upgrades and maintenance. Administrator/ privileged access shall not be permitted from outside of the U.S. Foreign remote maintenance, systems monitoring, foreign “call service centers,” “help desks,” and the like are prohibited. Fiscal Service information shall be accessed only by personnel meeting or surpassing the Treasury citizenship requirements (as determined by Personnel Security, see section 8 below). Extra precautions should be in place for other types of access from foreign locations.
Work shall be performed on systems secured at least at a FIPS 199 LOW security category level.
Written approval by the Fiscal Service’s Chief Information Officer (CIO), or designee, is required prior to the use or storage of Fiscal Service SBU information, or the sharing of Fiscal Service SBU Information by the Contractor with any subcontractor, person, or entity other than Fiscal Service.
The Contractor must not remove SBU information from approved location(s), electronic device(s), or other container(s), without prior approval from the CIO or their designee.
Contracts and/or task orders for the acquisition of information systems or services processing SBU information for Fiscal Service shall clearly specify the delivery date of an acceptable Security Assessment & Authorization (SA&A) or similar security assessment package as may be prescribed by Fiscal Service.
The Contractor shall grant access to Fiscal Service to review any existing SA&A documentation.
When needed per Fiscal Service direction, the Contractor and Fiscal Service officials shall prepare an Interconnection Security Agreement (ISA) prior to connecting to external information systems and in accordance with Fiscal Service processes.
Any computer equipment used by or on behalf of the Fiscal Service shall support Transport Layer Security (TLS) v1.0 or greater and comply with NIST SP 800-52, Guidelines for Selection and Use of Transport Layer Security unless predetermined to be a standalone system.
Cryptographic modules used to protect Fiscal Service information must be compliant with the current FIPS 140 version and validated by the Cryptographic Module Validation Program (CMVP). The Contractor must provide the validation certificate number to Fiscal Service for verification. Encryption is required to protect federal and contractor data when transmitting between systems.
The Contractor shall be subject to periodic audits and reviews, as required by law. The Contractor shall provide reports with findings that result from audits and reviews to Fiscal Service within five business days of receipt. Within 15 business days, the Contractor shall propose a response and a plan of action with milestones. The Contractor shall resolve all findings prior to recurrence, and the contract shall include financial disincentives for repeat findings.
The Contractor may be required to provide Fiscal Service access to, and information regarding systems the contractor operates on behalf of Fiscal Service as part of its responsibility to ensure compliance with security requirements. Fiscal Service access may include independent validation testing of controls, system penetration testing, FISMA reviews, monthly data feed requirements as coordinated by Fiscal Service, and access by agency Inspector General for its review.
All information systems that input, store, process, and/or output Government information must be granted approval by the CIO, or designee for operation and/or use. The contractor must adhere to current Fiscal Service policies, procedures, and guidance for Security Assessment and Authorization (SA&A) activities.
Prior to SA&A, a Privacy Threshold Analysis (PTA) for all systems must be completed and provided to the Fiscal Service Privacy Officer, or designate, for a determination. If determination is made that a Privacy Impact Assessment (PIA) is required, it must be completed in accordance with Fiscal Service requirements.
The Contractor shall allow for physical inspection of facilities by Fiscal Service or representatives within 30 calendar days of a Fiscal Service request. The Contractor may propose to limit the number of physical inspection requests from Fiscal Service; the limit shall not be less than two times per calendar year.1 In addition to scheduled visits at the request of Fiscal Service, the Contractor shall allow scheduled physical inspections in support of Security Assessment & Authorization and physical inspections on demand in the event of a computer security incident. A computer security incident is defined as any adverse event that threatens computer security and may include but is not limited to:
loss of data confidentiality, disruption to data or system integrity, and denial of availability.
The Contractor shall report any suspected security incident by phone to the Fiscal Service IT Service Desk within one hour of identification of a suspected security incident: 304-480-7777.
The Contractor shall destroy all SBU information, obtained under this contract, from contractor-owned information technology assets. Certification of data destruction will be performed by the contractor’s Project Manager and written notification confirming certification will be delivered to the contracting officer within 15 days of termination/expiration of contractor work.
4 Federal Regulatory Requirements and Industry Standards The Contractor's performance and systems shall comply with applicable federal government laws, directives, executive orders, standards, guidelines, and other requirements for information security, personnel security, physical security, and data encryption. The Contractor's performance and systems shall comply with the most current versions of the following applicable Federal and industry information technology regulatory requirements and standards. The most relevant documents will be highlighted:
• Federal Information Security Management Act of 2002 (FISMA)
• FIPS 140-2, Security Requirements for Cryptographic Modules
• FIPS 191, Guideline for the Analysis of Local Area Network Security
1 This limit does not apply to reviews that may be performed by GAO or OIG under their legal authority
• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems
• FIPS 201-1, Personal Identity Verification for Federal Employees and Contractors
• Fiscal Service Baseline Security Requirements (BLSRs)
• National Institute of Science and Technology (NIST) SP 800-12, An Introduction to
Computer Security - The NIST Handbook
• NIST SP 800-16, Information Technology Security Training Requirements: A Role and Performance Based Model
• NIST SP 800-18, Guide for Developing Security Plans for Information Technology
Systems
• NIST SP 800-27, Engineering Principles for Information Technology Security (A
Baseline for Achieving Security), Revision A
• NIST SP 800-28, Guidelines on Active Content and Mobile Code
• NIST SP 800-30, Guide to Conducting Risk Assessments
• NIST SP 800-34, Contingency Planning Guide for Federal Information Systems
• NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal
Information Systems: A Security Life Cycle Approach
• NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and
Information System View
• NIST SP 800-40, Procedures for Handling Security Patches
• NIST SP 800-41, Guidelines on Firewalls and Firewall Policy
• NIST SP 800-42, Guideline for Network Security Testing
• NIST SP 800-45, Guidelines for Electronic Mail Security
• NIST SP 800-46, Security for Telecommuting and Broadband Communications
• NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems
• NIST SP 800-48, Wireless Network Security
• NIST SP 800-50, Building an Information Technology Security Awareness and
Training Program
• NIST SP 800-52, Guidelines for Selection and Use of Transport Layer Security
• NIST SP 800-53, Recommended Security Controls for Federal Information Systems and Organizations
• NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information
Systems and Organizations
• NIST SP 800-55, Performance Measurement Guide for Information Security
• NIST SP 800-58, Security Considerations for Voice Over IP Systems
• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories
• NIST SP 800-61, Computer Security Incident Handling Guide
• NIST SP 800-63-1, Electronic Authentication Guideline
• NIST SP 800-68, Guidance for Securing Microsoft Windows XP Systems for IT
Professionals: A NIST Security Configuration Checklist
• NIST SP 800-70, National Checklist Program for IT Products – Guidelines for Checklist Users and Developers
• NIST SP 800-77, Guide to IPSec VPNs
• NIST SP 800-81, Secure Domain Name System (DNS) Deployment Guide
• NIST SP 800-83, Guide to Malware Incident Prevention and Handling
• NIST SP 800-88, Media Sanitization Guide
• NIST SP 800-94, Guide to Intrusion Detection and Prevention Systems (IDPS)
• NIST SP 800-100, Information Security Handbook: A Guide for Managers
• NIST SP 800-114, User's Guide to Securing External Devices for Telework and
Remote Access
• NIST SP 800-115, Technical Guide to Information Security Testing and Assessment
• NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable
Information (PII)
• NIST SP 800-125, Guide to Security for Full Virtualization Technologies
• NIST SP 800-128, Guide for Security-Focused Configuration Management of
Information Systems
• NIST SP 800-137, Information Security Continuous Monitoring for Federal
Information Systems and Organizations
• NIST SP 800-144, Guidelines on Security and Privacy in Public Cloud Computing
• NIST SP 800-145, A NIST Definition of Cloud Computing
• NIST SP 800-147, Basic Input/Output System (BIOS) Protection Guidelines
• NIST SP 800-153, Guidelines for Securing Wireless Local Area Networks (WLANs)
• Office of Management and Budget (OMB) Circular A-123, Management Accountability and Control
• OMB Circular A-130, Management of Federal Information Resources
• OMB Memorandum - Security Authorization of Information Systems in Cloud
Computing Environments
• OMB M-04-04, E-Authentication Guidance for Federal Agencies
• OMB M-05-24, Implementation of Homeland Security Presidential Directive (HSPD)
12 - Policy for a Common Identification Standard for Federal Employees and Contractors
• OMB M-06-16, Protection of Sensitive Agency Information
• OMB M-07-11, Implementation of Commonly Accepted Security Configurations for
Windows Operating Systems
• OMB M-07-16, Safeguarding Against and Responding to the Breach of PII
• OMB M-07-18, Ensuring New Acquisitions Include Common Security Configurations
• OMB M-14-03, Enhancing the Security of Federal Information and Information
Systems
• OMB M-15-01, Fiscal Year 2014-2015 Guidance on Improving Federal Information
Security and Privacy Management Practices
• OMB M-99-20, Security of Federal Automated Information Resources
• Public Law 93-579, The Privacy Act of 1974
• TD P 85-01 - Treasury Information Technology Security Program
• TD P 15-71 - Department of the Treasury Security Manual
New regulatory requirements and standards shall be adhered to as they are enacted or become effective, as applicable. The Contractor shall implement a process to support timely compliance with new requirements imposed by external authorities.
The Contractor shall comply with both Fiscal Service and Treasury requirements that extend above federal government and industry information technology regulatory requirements and standards. For example, Treasury has implemented more stringent security requirements in the Treasury Security Manual, TD P 85-01, than are typical for the federal government or the general information technology community. There are approximately 100 additional security control extensions in a variety of areas that go beyond NIST SP 800-53 guidance.
4.1 Privacy Act Compliance
(a) Contractors must comply with the Privacy Act’s requirements in the design, development, or operation of any system of records containing PII developed or operated for Fiscal Service or to accomplish a Fiscal Service function for a System of Records (SOR)2.
(b) In the event of violations of the Act, a civil action may be brought against Fiscal Service when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an Fiscal Service function, and criminal penalties may be imposed upon the officers or employees of Fiscal Service when the violation concerns the operation of a SOR on individuals to accomplish an Fiscal Service function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish a Fiscal Service function, the Contractor is considered to be an employee of the agency.
5 Security and Privacy Awareness Training The Contractor and subcontractor personnel who require access to Fiscal Service information or information systems will be required to review and sign Rules of Behavior, and complete security awareness training prior to being granted access. For the first 60 days of user access, reviewing and signing the Rules of Behavior is adequate for meeting the security awareness training requirement. If the security awareness training requirement is not completed within the first 60 days, access may be revoked. Security and Privacy training will be required on a recurring annual basis, of all contractor and subcontractor staff performing work for Fiscal Service on a recurring annual basis, provided by Fiscal Service and/or by the contractor. Access may be revoked if the annual security training is not completed. When necessary, Contractors and subcontractors will be required to sign Non-disclosure agreements.
2 “System of Records” is defined as a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
6 Cloud and FedRAMP Requirements
Cloud based systems or services shall comply with OMB Federal Risk and Authorization Management Program (FedRAMP) requirements, as well as, FedRAMP Privacy requirements. These requirements are in addition to U.S. Government, Department of the Treasury, and Fiscal Service requirements specified throughout this document. Cloud Service Providers shall have FedRAMP compliant security documentation sufficient to obtain a provisional authorization.
Cloud based systems or services shall have a FedRAMP third party assessment organization (3PAO) security assessment. Contractor shall obtain this assessment service and coordinate completion of assessment at a FIPS 199 low security category level. Cloud Service Providers shall comply with FedRAMP guidance regarding continuous monitoring activities. Fiscal Service shall have access to ongoing continuous monitoring documentation, such as POA&M documentation.
Contractors shall be responsible for the following privacy and security safeguards:
1. To the extent required to carry out the FedRAMP assessment and authorization process and FedRAMP continuous monitoring, to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public Government data collected and stored by the Contractor, the Contractor shall afford the Government access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases.
2. If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.
3. The contractor shall also comply with any additional FedRAMP privacy requirements.
4. The Government has the right to perform manual or automated audits, scans, reviews, or other inspections of the vendor’s IT environment being used to provide or facilitate services for the Government. In accordance with the Federal Acquisitions Regulations (FAR) clause 52.239-1, the contractor shall be responsible for the following privacy and security safeguards:
(a) The Contractor shall not publish or disclose in any manner, without the Contracting Officer’s written consent, the details of any safeguards either designed or developed by the Contractor under this contract or otherwise provided by the Government.
Exception - Disclosure to a Consumer Agency for purposes of C&A verification.
(b) To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor shall afford the Government access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases.
(c) If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.
If the vendor chooses to run its own automated scans or audits, results from these scans may, at the Government’s discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by the Government. In addition, the results of vendor-conducted scans shall be provided, in full, to the Government.
The government will retain unrestricted rights to government data. The government retains ownership of any user created/loaded data and applications hosted on vendor’s infrastructure, as well as maintains the right to request full copies of these at any time.
The data that is processed and stored by the various applications within the network infrastructure may contain financial data, as well as, PII. This data and PII shall be protected against unauthorized access, disclosure or modification, theft, or destruction. The contractor shall ensure that the facilities that house the network infrastructure are physically secure.
Identified gaps between required Fiscal Service and FedRAMP Security Control Baselines and Continuous Monitoring controls, and the contractor's implementation, as documented in the Security Assessment Report, shall be tracked by the contractor for mitigation in a Plan of Action and Milestones (POA&M) document. Depending on the severity of the gaps, the Government may require them to be remediated before an authorization is granted.
The contractor is responsible for mitigating all security risks found during SA&A, and continuous monitoring activities. All high-risk vulnerabilities must be mitigated within 30 days and all moderate risk vulnerabilities must be mitigated within 30 days from the date vulnerabilities are formally identified.
The Government will determine the risk rating of vulnerabilities.
Fiscal Service may choose to cancel the (Contract/award) and terminate any outstanding orders if the contractor has its provisional authorization revoked and/or the deficiencies are greater than agency risk tolerance thresholds.
The vendor is advised to review the FedRAMP guidance documents to determine the level of effort that will be necessary to complete the requirements. All FedRAMP documents and templates are available at the FedRAMP website (http://cloud.cio.gov/fedramp).
Maintenance of the FedRAMP Provisional Authorization will be through continuous monitoring and periodic audit of the operational controls within a contractor’s system, environment, and processes to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to the FedRAMP PMO as required by FedRAMP Requirements. The submitted deliverables (or lack thereof) provide a current understanding of the security state and risk posture of the information systems. The deliverables will allow the FedRAMP JAB to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur. Contractors will be required to provide updated deliverables and automated data feeds as defined in the FedRAMP Continuous Monitoring Plan.
Additional Stipulations:
1. The FedRAMP deliverables shall be labeled “SENSITIVE BUT UNCLASSIFIED” (SBU) or contractor selected designation per document sensitivity. External transmission/dissemination of FOUO and SBU to or from a Government computer must be encrypted. Certified encryption modules must be used in accordance with FIPS PUB 140-2, “Security requirements for Cryptographic Modules.”
2. Federal Desktop Core Configuration & US Government Configuration Baseline: The contractor shall certify applications are fully functional and operate correctly as intended on systems using the Federal Desktop Core Configuration (FDCC) and US Government Configuration Baseline (USGCB). The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved FDCC/USGCB configuration. Offerings that require installation should follow OMB memorandum 07-18. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges. The contractor shall use Security Content Automation Protocol (SCAP) validated tools with FDCC/USGCB Scanner capability to certify their products operate correctly with FDCC/USGCB configurations and do not alter FDCC/USGCB settings.
3. As prescribed in the Federal Acquisition Regulation (FAR) Part 24.104, if the system involves the design, development, or operation of a system of records on individuals, the contractor shall implement requirements in FAR clause 52.224-1, “Privacy Act Notification” and FAR clause 52.224-2, “Privacy Act.”
4. The contractor shall cooperate in good faith in defining non-disclosure agreements that other third parties must sign when acting as the Federal government’s agent.
7 Bureau of the Fiscal Service (Fiscal Service) Personnel Security and Suitability Requirements for Contractors and Subcontractors
7.1 GENERAL
The Bureau of the Fiscal Service (BFS) has determined that performance of this contract requires that the Contractor, subcontractor(s), and vendor(s) (herein known as Contractor), requires access to Sensitive but Unclassified (SBU) information (herein known as unclassified information) and the contract was evaluated as "Moderate Risk." All contractor and subcontractor personnel who require access to Treasury or Bureau-owned or controlled facilities and security items or products, shall either be United States Citizens or have lawful Permanent Resident Alien (PRA) status, with at least three (3) or more years of United States residency.
The Contractor will abide by the requirements set forth in the Non-Disclosure Agreement, included in the contract, for the protection of unclassified information at its cleared facility. If the Contractor has access to unclassified information at the BFS or other Government Facility, it will abide by the requirements set by that agency.
B. SUITABILITY DETERMINATION
Contractor personnel, assigned to this contract, even those who possess a National Security Clearance, will not need access to classified information, although they must undergo suitability screening conducted by the Office of Security. BFS shall have and exercise full control over granting, denying, withholding, or terminating unescorted government facility and/or sensitive Government information access for these contractor employees, based upon the results of a background investigation.
C. BACKGROUND
52.204-9 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR PERSONNEL
(JAN 2011)
(a) The Contractor shall comply with agency personal identity verification procedures identified in the contract that implement Homeland Security Presidential Directive-12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and Federal Information Processing Standards Publication (FIPS PUB) Number 201.
(b) The Contractor shall account for all forms of Government-provided identification issued to the Contractor employees in connection with performance under this contract. The Contractor shall return such identification to the issuing agency at the earliest of any of the following, unless otherwise determined by the Government;
(1) When no longer needed for contract performance.
(2) Upon completion of the Contractor employee’s employment.
(3) Upon contract completion or termination.
(c) The Contracting Officer may delay final payment under a contract if the Contractor fails to comply with these requirements.
(d) The Contractor shall insert the substance of clause, including this paragraph (d), in all subcontracts when the subcontractor’s employees are required to have routine physical access to a Federally-controlled facility and/or routine access to a Federally-controlled information system. It shall be the responsibility of the prime Contractor to return such identification to the issuing agency in accordance with the terms set forth in paragraph (b) of this section, unless otherwise approved in writing by the Contracting Officer.
THE BUREAU OF FISCAL SERVICE ADDENDUM TO AB NO. 05-12R1
Performance of this contract requires contractor and subcontractor personnel to have signed and submitted a Non-Disclosure Agreement (NDA), have an appropriate level background investigation initiated, have a favorable Federal Bureau of Investigations (FBI) fingerprint check completed, and be issued a Federal Government personnel identification card before being allowed unsupervised physical access to Federal Government facilities and/or logical access to Federal Government Information
Technology (IT) Systems and databases. The Contracting Officer's Representative (COR) will be the sponsoring official and will coordinate with BFS's Personnel Security to arrange the background investigation and credentialing process.
At least two weeks before start of contract performance, the Contractor shall identify all contractor and subcontractor personnel who shall require physical access to Federal Government facilities and/or logical access to Federal IT systems or databases for the performance of work under this contract.
Identified contractor and subcontractor personnel shall complete and return the below listed documents to the COR. The Contractor must make their personnel available at the place and time specified by the COR in order to initiate the credentialing process.
• Office of Personnel Management (OPM) Electronic Questionnaire for Investigation Processing (e-QIP) portal to provide historical background information for background investigations:
http://www.opm.gov/e-qip/
• OF 306 (fillable forms available at http://www.opm.gov/forms/html/of.asp)
• Fair Credit Reporting Release
• Non-Disclosure Agreement (NDA)
Background investigations shall be processed in accordance with the Office of Personnel Management (OPM) standards. To commence the process, each contractor will be required to supply the COTR with their full name, their place of birth (city and state), their date of birth, and their social security number.
With this information, Fiscal Service’s Personnel Security staff will initiate the contractor in the Electronic Questionnaire for Investigations Processing System (e-QIP). The Personnel Security Specialist will further provide the contractor online instructions and the website address where you will provide the required information needed to conduct your background investigation.
These positions require a Minimum Background Investigation (MBI), which satisfies HSPD-12 background investigation requirements for identified contractor and subcontractor personnel requiring physical access to Federal Government facilities and/or logical access to Federal IT systems or databases.
This process provides the government with a means to positively identify and make a suitability determination regarding the applicant under this contract. Upon receipt of a favorable FBI fingerprint check, the contractor's identification card will be issued and/or unsupervised physical access to Government facilities granted.
Contractor and subcontractor personnel are required to give, and authorize others to give, full, frank, and truthful answers to relevant and material questions needed to reach a suitability determination.
Refusal or failure to furnish or authorize provision of information may constitute grounds for denial or revocation of credentials. Government investigative personnel may contact contractor/subcontractor personnel being screened or investigated in person, by telephone, or in writing. The contractor shall ensure that all contractor and subcontractor personnel are available for such contact and that timely responses to investigative requests are provided.
Alternatively, if it is verified that an individual is already vetted by another agency at the appropriate level of background investigation, and the investigation was completed less than five (5) years prior to the start of the contractor's initial physical/logical access date, then further investigation may not be http://www.opm.gov/forms/html/of.asp necessary. If this is applicable, the Contractor shall provide the COR with the name of the agency that conducted the investigation and completion date, if known.
If at any point during this process investigative results are unfavorably adjudicated, the individual will be denied further admittance to work on the contract, including both physical and/or logical access. In the event of a disagreement between the Contractor and the Government concerning the suitability of an individual to perform work under this contract, the Government shall have the right of final determination.
During performance of the contract, the Contractor shall keep the COR apprised of any changes in contractor or subcontractor personnel to ensure that work performance is not delayed by compliance with the credentialing process. Identification cards that are lost, damaged or stolen must be reported to the COR and Issuing Office within eighteen (18) hours. Replacement shall be at the Contractor's expense. If re-issuance of expired credentials is needed, it will be coordinated through the COR.
At the end of the contract performance, or when a contractor/subcontractor employee is no longer working under this contract, the contactor shall ensure that all identification cards are returned to the COR. If the Contractor does not return all identification cards, last payment may be withheld.
This requirement must be incorporated into any subcontracts that require subcontractor personnel to have regular and routine unsupervised physical access to a federally controlled facility for six (6) months or more, and/or any logical access to a federally controlled information system.
Definitions:
Physical Access: Is the ability to enter a federally owned facility or federally leased space:
Physical access requirements will be determined upon completion of a sensitivity determination of the contract by Personnel Security.
The Contractor will abide by the requirements set forth in the Non-Disclosure Agreement, included in the contract, for the protection of unclassified information at its cleared facility. If the Contractor has access to unclassified information at the Fiscal Service or other Government Facility, it will abide by the requirements set by that agency.
7.2 SUITABILITY DETERMINATION
Contractor personnel assigned to this contract, even those who possess a National Security Clearance shall undergo suitability screening conducted by the Fiscal Service Personnel Security staff. Fiscal Service shall have and exercise full control over granting, denying, withholding, or terminating unescorted government facility and/or sensitive Government information access for these contractor employees based upon the results of a background investigation.
7.3 Fiscal Service Addendum to AB No. 05-12R1
Performance of this contract requires contractor and subcontractor personnel to have signed and submitted a Non-Disclosure Agreement (NDA), have an appropriate level background investigation initiated, have a favorable Federal Bureau of Investigations (FBI) fingerprint check completed, and be issued a Federal Government personnel identification card before being allowed unsupervised physical access to Federal Government facilities and/or logical access to Federal Government Information Technology (IT) Systems, databases or information. The Contracting Officer's Representative (COR) will be the sponsoring official and will coordinate with Fiscal Service's Personnel Security to arrange the background investigation and credentialing process.
At least two weeks before start of contract performance, the Contractor shall identify all contractor and subcontractor personnel who shall require physical access to Federal Government facilities and/or logical access to Federal IT systems, databases or information for the performance of work under this contract. Identified contractor and subcontractor personnel shall complete and return the below listed documents to the COR. The Contractor shall make their personnel available at the place and time specified by the COR in order to initiate the credentialing process.
• Office of Personnel Management (OPM) Electronic Questionnaire for Investigation Processing (e-QIP) portal to provide historical background information for background investigations: http://www.opm.gov/e-qip/ (Electronically submitted to Fiscal Service)
• OF 306 (fillable forms available at http://www.opm.gov/forms/html/of.asp)
• Fair Credit Reporting Release (Electronically submitted to Fiscal Service )
• Non-Disclosure Agreement (NDA)(attached)
Background investigations shall be processed in accordance with the Office of Personnel Management (OPM) standards. To commence the process, each contractor will be required to supply the COR with their full name, date of birth, place of birth (city and state), social security number, and valid email address. With this information, Fiscal Service Personnel Security staff will initiate the contractor in the Electronic Questionnaire for Investigations Processing System (e-QIP). The Personnel Security Specialist will further provide the contractor online instructions and the website address where the Contractor will provide the required information needed to conduct the Contractor background investigation.
A Background Investigation is required to satisfy HSPD-12 background investigation requirements for identified contractor and subcontractor personnel requiring physical access to Federal Government facilities and/or logical access to Federal IT systems, databases or information. This process provides the government with a means to positively identify and make a suitability determination regarding the applicant under this contract. Upon receipt of a favorable FBI fingerprint check and submission of completed questionnaire (e-Qip) and required forms, the contractor's identification card will be issued and/or unsupervised physical access to Government facilities granted.
Contractor and subcontractor personnel are required to give, and authorize others to give, full, frank, and truthful answers to relevant and material questions needed to reach a suitability determination.
Refusal or failure to furnish or authorize provision of information may constitute grounds for denial or revocation of credentials. Government investigative personnel may contact contractor/subcontractor personnel being screened or investigated in person, by telephone, or in writing. The contractor shall http://www.opm.gov/e-qip/ http://www.opm.gov/forms/html/of.asp ensure that all contractor and subcontractor personnel are available for such contact and that timely responses to investigative requests are provided.
Alternatively, if it is verified that an individual is already vetted by another agency at the appropriate level of background investigation, and the investigation was completed less than five (5) years prior to the start of the contractor's initial physical/logical access date, then further investigation may not be necessary. If this is applicable, the Contractor shall provide the COR with the name of the agency that conducted the investigation and completion date, if known.
If at any point during this process investigative results are unfavorably adjudicated, the individual will be denied further admittance to work on the contract, including both physical and/or logical access. In the event of a disagreement between the Contractor and the Government concerning the suitability of an individual to perform work under this contract, the Government shall have the right of final determination.
During performance of the contract, the Contractor shall keep the COR apprised of any changes in contractor or subcontractor personnel to ensure that work performance is not delayed by compliance with the credentialing process. Identification cards that are lost, damaged or stolen shall be reported to the COR and Issuing Office within eighteen (18) hours. Replacement shall be at the Contractor's expense. If re-issuance of expired credentials is needed, it will be coordinated through the COR.
At the end of the contract performance, or when a contractor/subcontractor employee is no longer working under this contract, the contactor shall ensure that all identification cards are returned to the COR. If the Contractor does not return all identification cards, last payment may be withheld.
This requirement shall be incorporated into any subcontracts that require subcontractor personnel to have regular and routine unsupervised physical access to a federally controlled facility for six (6) months or more, and/or any logical access to a federally controlled information system.
Definitions:
Physical Access: Is the ability to enter a federally owned facility or federally leased space:
If federal space is limited to a portion of a building then HSPD-12 applies only to that portion owned or leased by the federal government.
Logical Access:
In computer security, being able to interact with data through access control procedures such as identification, authentication, and authorization. User based authenticated access to the application, systems and the data that is processed.
8 Proposal Instructions
8.1 READING ROOM FOR SECURITY CONTROL REVIEW
Prior to proposal submission, the offeror may schedule an appointment to review documentation for the security control requirements. Due to the security sensitive nature of this documentation, the Fiscal Service will not release this information as part of a Request for Proposals or other equivalent document. Appointments will be made for review of security control requirements documentation.
Appointments will be scheduled for two (2) hour blocks based on Fiscal Service’s representatives availability. Documentation reviews will be conducted Parkersburg, WV in the Bureau of the Fiscal Services offices. To schedule a security control requirements documentation review, the offeror shall contact the Procurement Office at purchasing@fiscal.treasury.gov.
The offeror shall be permitted to send a maximum of three (3) staff to review documentation. The offeror’s staff performing documentation review shall be U.S. Citizens. The offeror shall provide the Fiscal Service with the full name, for each staff member the offeror plans to send to review documentation. A signed Fiscal Service Security Controls Rules of Behavior Agreement and a signed Non-disclosure Agreement is required prior to the review. This information shall be provided to purchasing@fiscal.treasury.gov prior to the scheduled appointment.
The offeror’s staff members who have not supplied the requested information will not be permitted to review security control requirements documentation. The offeror’s staff shall present a photo ID issued by a federal or state government organization when they arrive to review documentation. The name on the photo ID must match the name previously provided to Fiscal Service. The offeror staff will be escorted and will not be permitted to remove copies of any documentation.
The offeror shall provide Fiscal Service with the full name, for each staff member, subcontractor, or others whom the offeror intends to grant access to information about security control requirements;
the offeror shall provide this information to Fiscal Service at least five (5) Government business days prior to scheduled reading room access appointment. All persons provided access to information about security control requirements by offeror shall be US citizens. The offeror shall not permit any individuals of whom Fiscal Service does not approve to have access to security control requirements information.
If the offeror intends to send staff with portable electronic devices (PEDs), the offeror shall provide Fiscal Service with the name of the encryption software product and the version number of the software at the time appointments are scheduled -- before 4:00 PM Eastern Time at least five (5) Government business days prior to scheduled reading room access appointment. Fiscal Service will not permit notes about security control requirements to be made using any unencrypted PED. Fiscal Service will confirm FIPS 140-2 validation and inspect PEDs. Should an offeror arrive with a PED that does not have FIPS 140- 2 validated full disk encryption software in use, the Fiscal Service will not permit the PED to be used.
8.2 Additional Instructions
The offeror shall explain in proposal how the offeror plans to secure Fiscal Service information in accordance with the requirements of this solicitation.
The offeror is responsible for the proper handling and protection of Sensitive Information to prevent unauthorized disclosure. The offeror must produce policy documentation
The offeror shall explain in proposal their process to support timely compliance with new security requirements and standards imposed by external authorities.
If applicable, the offeror shall explain in proposal how the offeror plans on patching and maintaining software, operating systems and device firmware.
Demonstrations
Offeror demonstrations shall not be conducted using systems containing SBU, PII, or other sensitive information.
For Cloud based systems or services being proposed, the offeror shall explain the following in proposal:
What is the Cloud provider's deployment model (Public / Private)?
What is the Cloud provider's service model (SaaS, PaaS, IaaS)?
Has the Cloud provider been assessed for FISMA compliance? If so, at what FIPS 199 level?
Has the cloud provider been granted a FedRAMP provisional or agency ATO for the systems or services being proposed? If so, please provide the package reference. If not, please indicate current status in relation to FedRAMP.
Does the Cloud provider provide non-negotiable or negotiable SLAs?
Does the Cloud provider adhere to mandatory Federal Laws and Regulations (Clinger-Cohen, OMB A- 130, Privacy Act, E-Gov, FISMA, NARA, FOIA, etc.)?
Are the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .