National Oceanic and Atmospheric Administration (NOAA)<\/h3>\n
NOAA uses the Department of Commerce\u2019s eRA Commons.<\/a><\/p>\n NOAA Grants Policy<\/a><\/p>\n Awards from NSF are sent directly to OSP. PIs do not need to provide a copy to OSP. Awards are also available in the sponsor system (Research.gov).<\/p>\n PIs get access during proposal preparation<\/a>. The same user information is used to log into Research.gov<\/a> for project reporting and financial management.<\/p>\n Federal Contracts require compliance with numerous federal rules and regulations including the\u00a0Federal Acquisition Regulation (FAR)<\/a>.<\/p>\n Project set up, reporting, and management must be handled according to specific requirements in the contract. There can be a significant amount of planning, work, and cost involved to implement and follow these requirements.<\/p>\n In some cases, this planning and work must be done before the contract is even awarded.<\/p>\n Failure to comply, perform or follow deadlines in federal contracts can result in criminal\/civil and financial consequences for the PI and the University.<\/p>\n Many federal contracts and flow-through federal contracts require the use of E-Verify<\/a> to establish employment eligibility of designated employees. This requirement does not apply to grants.<\/p>\n During the award set up process, OSP notifies departments and PIs if their federal contracts contain the E-Verify clause. Visit the Integrated Service Center’s E-Verify guidance<\/a> for details on the process.<\/p>\n If the contract proposal requires the submission of a Small Business Subcontracting Plan, review the Procurement Services small business subcontracting plan instructions and worksheet<\/a>.<\/p>\n Check your contract to determine whether it includes requirements related to Homeland Security Presidential Directive 12 (HSPD-12<\/a>), Federal Information Processing Standards (FIPS), and\/or Federal Information Security Management Act (FISMA<\/a>).<\/p>\n If the contract includes them, these requirements may impact your budget, consider costs when preparing your proposal.<\/p>\n Information Technology (IT) Security Plans, Risk Assessment and FIPS 199 Assessment are all due within 30 days of the contract being awarded. Security Certification & Accreditation is due within 3 months after a contract has been awarded.<\/p>\n Due within 30 Days After Contract Award<\/b><\/p>\n IT Security Plans (IT-SP)<\/b><\/p>\n These plans must describe the process and procedures that will be followed to ensure the security of IT resources. It must also comply with numerous federal regulations such as: FISMA, National Institute of Standards and Technology (NIST) 800-18 and 800-26<\/a>, HHS Office of the Chief Information Officer (OCIO) Information Systems as well as others.<\/p>\n IT Risk Assessment (IT-RA)<\/b><\/p>\n Must be consistent with NIST 800-30-Risk Management Guide for Information Technology Systems and any additions for augmentations described in the HHS-OCIO Information Systems Security & Privacy Policy<\/p>\n FIPS 199 Assessment<\/b><\/p>\n Must follow the NIST standard<\/a>.<\/p>\n Due within 3 Months After Contract Award<\/b><\/p>\n IT Security Certification & Accreditation (IT-SCA)<\/b> Contractors must submit written proof that an IT-SCA was performed for applicable information systems. The draft IT-SCA must be signed by a senior management official.<\/p>\n Many sponsors have their own post award grants management systems. Set up access for required individuals including the PI. <\/span><\/p>\nResources<\/h4>\n
National Science Foundation (NSF)<\/h3>\n
<\/a>Federal Contracts<\/h2>\n
<\/a>E-Verify<\/h3>\n
<\/a>Small Business Subcontracting Plans<\/h3>\n
<\/a>Information and Security Requirements<\/h3>\n
Typical HSPD-12\/FIPS\/FISMA Requirements:<\/h4>\n
\nMust follow the HHS Chief Information Security Officer’s Certification & Accreditation Checklist, NIST 800-37, and 800-53.<\/p>\n<\/a>Federal Post Award Grants Management Systems<\/h2>\n
\n<\/p>\n