05 Technical Exhibits A-M (R0003)_Final.pdf
PDF 4 MB Posted
- Attached to
- DCSA Background Investigation Fieldwork Services Federal contract opportunity
- Solicitation number
- HS0021-22-R-0003
About this file
This is a request for proposals for background investigation fieldwork services. The Defense Counterintelligence and Security Agency is seeking proposals for conducting background investigations, including case-level and item-level fieldwork orders. Offerors must comply with instructions in Attachments 01-06, which provide details on the evaluation process, price schedule, performance work statement, provisions and clauses. Proposals are due by the date and time indicated in the solicitation posting. The North American Industry Classification System code for this opportunity is 561611.
View the file
Other files for this federal contract opportunity
Show all 40
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Defense Counterintelligence and Security Agency Background Investigation Fieldwork Services
Solicitation HS002122R0003
05 TECHNICAL EXHIBITS A-M
Technical Exhibit A. Background Investigation Information Technology Requirements
This document has been prepared to detail the IT requirements for contracts awarded by DCSA. It has been developed with the entirety of the IT community in mind, including, and most prominently, the IT security and privacy communities.
DCSA is committed to the protection and security of all Federal information under its control. This includes all information that is received, generated, processed, transmitted, or stored through, or by, any system operating in support of an official DCSA mission. The requirements apply to all Contractors with authorized access to Federal information or information systems owned or operated by or for the agency.
1. APPLICABILITY
1.1. This document applies to the Contractor, its subcontractors and teaming partners, and employees (hereafter referred to collectively as “Contractor”).
1.2. These requirements, including all of the references listed are applicable to all information, regardless of medium, maintained by the Contractor for the performance of this contract.
1.3. These requirements are in addition to all applicable requirements established by 5 United States Code (U.S.C.) 552a; and to all other requirements established by various Federal statutes, mandates, and Executive Orders for the management and security of Information and Information Systems. The following additional requirements should not be construed to alter or diminish civil and/or criminal liabilities provided under 5 U.S.C. 552a or any other applicable Federal statutes.
2. AUTHORIZATION TO HANDLE DCSA ELECTRONIC DATA
2.1. Prior to receiving, collecting, transmitting, storing, using, accessing, sharing, or removing DCSA data from any approved locations; the Contractor must receive approval in writing through the DCSA Risk Management Framework (RMF) process, as described in DoDI 8510.01 and DCSA Assessment and Authorization Process Manual (DAAPM), from the Chief Information Security Officer (CISO) and/or Authorizing Official (AO). Contractors are to ensure their major IT systems and capabilities have authorizations in accordance with DoDI 8510.01, DoDI 8582.01, and, when applicable, the DOD Cloud Computing Security Requirements Guide (SRG). Contractors will act as the Program Manager for the RMF process and will need to follow the RMF process accordingly.
2.2. The DCSA RMF guidance and processes for identifying, implementing, assessing and authorizing the operation of the Contractor’s information system can be found in DoDI 8510.01 and DAAPM. Any cross
DCSA BI Fieldwork 05 Technical Exhibits A-M RFP HS002122R0003 domain actions must receive approval from the CISO and/or AO and must receive proper trusted agent training prior to any data removal or sensitive data transfers.
2.3. If the Contractor should begin to receive, collect, transmit, store, use, access, or share DCSA data without appropriate approval, the Contractor must report this to the CISO and AO, and follow the DCSA Incident Response Plan.
3. INFORMATION SYSTEM SECURITY REQUIREMENT
3.1. The activities required by this contract necessitate the Contractor’s access to Government Information, including CUI. Contractors are required to comply with current Federal regulations and guidance found in Federal Information Security Management Act (FISMA) Public Law 107-347; 5 U.S.C.
552a; E-Government Act of 2002, Section 208; National Institute of Standards and Technology (NIST);
Federal Information Processing Standards (FIPS); Office of Management and Budget (OMB) Circular A-
130. The Contractor must comply with implementation of required security controls for protection of the Government Information based on the sensitivity of the data within the system as determined through DoDI 8510.01 and DCSA DAAPM.
3.2. The Contractor must implement and maintain an information security program that is compliant with FISMA Public Law 107-347, NIST Special Publication 800-53, OMB guidelines, DCSA security policies, and other applicable laws, throughout the performance of this contract.
3.3. The Contractor’s facilities and IT systems must meet the security requirements for the same security classification or greater as defined by FIPS Publication 199 as required for the protection of Government Information. DCSA will provide written approval of FIPS Publication 199 security categorization.
4. CONTINUOUS MONITORING REPORTING REQUIREMENTS
4.1. The Contractor must comply with the DCSA continuous monitoring (CM) reporting requirements as stated in DoDI 8510.01 and DCSA DAAPM. Contractors will be required to follow the annual CM plan, which provides a monthly security control self-assessment requirement. The assessment results of each of the security controls will be reported monthly, quarterly and annually in respective reports. In addition to the reports, artifacts will also be provided to support the assessment results.
4.2. DCSA may choose to coordinate quarterly site visits with the Contractor in an effort to ensure that the previous quarter’s CM report is complete, accurate, and has all artifacts submitted pertaining to each of the assessed controls.
4.3. Contractors must ensure their documents and policies are available upon request.
5. INFORMATION SECURITY INCIDENTS
Contractors must report any and all information security incident (ISI)s involving, or suspected of involving, IT systems and DCSA data within thirty (30) minutes of becoming aware of the ISI, regardless of the time of day or day of the week, and inclusive of Federal holidays and Federal office closures (i.e., the Contractor must report ISIs “24/7/365”). This requirement will take precedent over any Contractor-led internal investigation, evaluation, or confirmation of procedures or activities that occur as a result of the ISI. All ISI will be reported to the CISO and AO in accordance with the DCSA Incident Response Plan.
6. INFORMATION SECURITY INSPECTIONS
6.1. The Contractor must permit and cooperate with the scheduling of onsite and/or offsite information security inspections, which may occur prior to the notice to proceed with work, on a regular recurring basis during performance, following an actual or suspected ISI, or as otherwise deemed necessary by
DCSA.
6.2. DCSA will provide the Contractor with a Post-Inspection Report, which will state findings and specify the Contractor’s requirement for remediating findings to maintain compliance with this contract.
6.3. The Contractor must provide a formal response to the DCSA Post-Inspection Report to the CISO and AO within fifteen (15) business days of receipt of the report for critical/high risk findings, and within thirty (30) business days for all other findings.
7. ACCESS TO DCSA IT SYSTEMS
7.1. During the contract ramp-up period, the Contractor must provide an initial and complete list of employee names that require access to DCSA IT systems. This list will be provided at least thirty (30) business days prior to required access. Procedures will be provided at contract award. After the contract ramp-up period, the Contractor must submit individual access requests through procedures provided at contract award.
7.2. The Contractor must send a staffing change report by the fifth (5th) day of each month after contract award to the KO, COR, and DCSA System Access Management. The report must contain the listing of all staff members who separated or were hired under this contract in the past 60 business days. This form must be submitted even if no separations or hires have occurred during this period. Failure to submit a ‘Contractor Staffing Change Report’ each month may, at DCSA’s discretion, result in the suspension of all accounts associated with this contract.
7.3. Each Contractor employee is required to utilize a PIV and/or CAC to access DCSA IT systems, in accordance with the FIPS Publication 201. Using shared accounts to access DCSA IT systems is strictly prohibited. DCSA will disable accounts, and access to DCSA IT systems will be revoked and denied if Contractor employees share accounts. Users of the DCSA IT systems will be subject to periodic auditing to ensure compliance with DCSA policies.
7.4. All Contractor computer security violations will be handled in accordance with the DCSA Incident Response Plan. If a Contractor employee commits a computer security violation, their system access will be immediately terminated, pending investigation in accordance with the DCSA Incident Response Plan.
DCSA may require the Contractor to immediately remove individuals from work on the awarded contract, at any time, as a result of individual security violations. If at any time during Contract performance it is determined that the Contractor is not in full compliance with the security and cybersecurity requirements of the awarded contract, the Government may immediately suspend performance under the awarded contract and require the immediate return of all case materials to the Government at full Contractor expense. Any work suspension resulting from a security lapse will not be subject to equitable adjustment; all costs will be borne by the Contractor.
7.5. Upon request of the KO or COR, the Contractor must immediately return all DCSA Information, including, but not limited to, data stored on recovery media, tape backups, and images.
7.6. The COR and DCSA System Access Management must be notified at least five (5) business days prior to a Contractor employee being removed from a contract. For unplanned terminations or removals of Contractor employees from the Contractor organization, the COR and DCSA System Access Management must be notified within two (2) hours of the individual’s departure.
7.7. Inactivity on BIES may trigger an inquiry from DCSA to the Contractor to determine if access to DCSA systems is still needed. If DCSA system access is pulled from investigative personnel for any reason, that individual will be unable to transmit reports via BIES, and all GFI will be collected in accordance with performance work statement subsections 3.3.4. [Return of GFI for Inactive Personnel] or 3.3.5. [Return of GFI for Terminated, Suspended or Separated Personnel], as appropriate. The Contractor will be notified, monthly, of users who have been inactive for thirty (30) calendar days or more. The Contractor will be responsible for taking action for each user to either suspend or revoke access, or ensure that the user resumes activity.
8. ACCESS TO CONTRACTOR IT SYSTEMS
8.1. During contract performance and throughout any contract close-out period, the Contractor must provide DCSA, or a designee, with immediate access to all IT systems used by the Contractor to support the performance of the contract for the purpose of inspection and forensic analysis in the event of an
ISI.
8.2. Contractor will provide assistance or access to DCSA engineers to debug issues.
8.3. DCSA reserves the right to restrict access to all unpatched clients with 24 hours’ notice in the event an emergency patch is determined to be necessary.
8.4. DCSA will prevent network access to any Contractor workstation which does not have the DCSA Network Access Control Software client installed on an approved Contractor domain member workstation.
9. HARDWARE/SOFTWARE
9.1. The Contractor is to provide their own computers, printers, and systems to connect to the DCSA network, all of which will require approval through the DCSA RMF process as described in DCSA DAAPM.
Contractors must submit the Certificate of Networthiness to Enterprise Cybersecurity for the CISO and/or AO approval prior to connecting any non-GFI devices or other capabilities.
9.2. Laptop computers at DCSA are intrinsic components of one (1) or more DCSA Federal information systems and will therefore comply with the full scope of NIST Special Publication 800-53 security controls as stated in DoDI 8510.01. Within DCSA, laptops are components of larger DCSA Information
Systems and as such are supported by the full set of information security controls in the systems they are a part of. For laptops operated by a Contractor or other entity on behalf of DCSA, NIST references implementation and compliance requirements in Defense Information Systems Agency, Security Technical Implementation Guides (STIGs) which can be found at https://public.cyber.mil/stigs/.
9.3. The Contractor will provide the initial prototype of each model and brand of laptop or desktop for DCSA approval of its software configuration. If more than one (1) model or brand will be used by the Contractor, a prototype for each will need approved by DCSA. Updates to approved images require DCSA's reapproval before they are released for use. Any subsequent models or brand changes in laptops or PCs will also be submitted to DCSA for approval of configuration. Laptops and PCs will have Adobe Reader installed to enable use of the DCSA Investigator Handbook and other electronic documents provided on the Field Document Repository system.
9.4. Enforcement of DCSA laptop security control requirements is accomplished through various means to include continuous monitoring of all workstations and laptop connections to DCSA information systems. All connectivity is subject to ongoing monitoring and validation by DCSA’s network security team. Initial enforcement of laptop requirements is accomplished through baseline configurations in compliance with the guidelines in STIGs. Ongoing enforcement of DCSA-controlled laptops is managed by the designated DCSA team.
9.5. Laptop security specifications are as follows:
9.5.1. Laptop hardware must be compliant with the Trade Agreement Act;
9.5.2. Laptops must utilize Trusted Platform Module 1.2 or higher;
9.5.3. Laptops must have capability to support smart card readers for PIV/CAC authentication;
9.5.4. Company-provided laptop hardware will be required to run the approved version of Microsoft Windows.
9.5.5. Encryption of the laptop hard drive will be determined and managed by the Contractor, consistent with their RMF process.
9.6. The integrity and confidentiality of investigation data will be maintained through technical and procedural controls. Software requirements as defined by DCSA will be provided for the Contractor to use as elements of a secure software package configured by the Contractor. All software provided by DCSA is licensed or written by DCSA and is the property of DCSA, and all originals and copies must be returned to DCSA at completion of the contract or upon request. Reproduction of the software must be only for work performed for the purpose of completing investigative work for DCSA.
9.7. In order to ensure that only compliant and authorized machines are joining the DCSA network, all remote access must be brokered through DCSA’s non-persistent client-access virtual private network (VPN). Access to the VPN requires authentication through the use of PIV cards. All connecting vendor-managed systems are required to install DCSA’s Network Access Control (NAC), Endpoint Protection (EPP), and Data Loss Prevention software. The addition of the NAC component agent should not require laptop reimaging. Additionally, DCSA does not require the Contractor to seek image approval, as stated in section 3, with the addition of this NAC component. DCSA will utilize the NAC agent only for the purpose of monitoring endpoints, for proactively identifying potential threats. No DCSA software can be modified without having been previously approved by DCSA prior to use on the DCSA network.
9.8. DCSA requires Network access control software installed on client endpoints used to validate security compliance of the device connecting to the network. Upgrades will be managed by Contractor personnel. DCSA will attempt to provide approximately thirty (30) business days of advance notice prior to implementing an upgrade to the DCSA Network Access Control Software client.
9.9. The Contractor will provide credentials with administrative permissions to upgrade the DCSA Network Access Control Software client on applicable systems.
9.10. Contractor staff will be required to periodically upgrade the DCSA Network Access Control Software client to stay current with DCSA standards.
9.11. DCSA will provide at least thirty (30) business days of notice before entering a planned upgrade cycle and the Contractor would have thirty (30) business days from receipt of the DCSA Network Access Control Software Client upgrade or patch before DCSA would restrict access for any unpatched or un-upgraded client.
9.12. All machines will be upgraded with required operating system patches, or any other required DCSA patch in accordance with Chairman of the Joint Chiefs of Staff Instruction (CJCSI) 6510.01F within thirty
(30) business days after receipt of the patch to avoid DCSA removing or restricting access.
9.13. During any upgrade or patch cycle, DCSA will work with the Contractor to verify upgraded/patched hosts and debug any issues where upgraded/patched hosts are not reporting correctly to the management console before removing or restricting access for any non-compliant hosts.
9.14. DCSA reserves the right to enact emergency patching without notice if a high or critical vulnerability is discovered in the DCSA NAC software client.
9.15. Any deviation from the IT laptop or desktop requirements for reasonable accommodations will require pre-approval from DCSA prior to use.
10. VIDEO TELE-CONFERENCE (VTC) AUTHORIZED SERVICES
10.1. Adobe Connect Managed Services (ACMS) and Zoom for Government (Zoom) have received DoD provisional authorizations to operate at the data impact level of IL2. This means only Low confidentiality impact level PII may be processed and/or hosted on these platforms. Therefore, no background investigative material in the form of data and/or files may be shared or stored via these online collaboration capabilities. However, ACMS and Zoom may be used for voice and video purposes in accordance with DoD regulation and DCSA policies.
10.2. ACMS and Zoom are intended to provide the ability to conduct subject and source interviews in a virtual environment. While this provides a continuity of operations solution when personal contact is not possible during the background investigation process, it also increases the potential for the unauthorized and inadvertent disclosure of information. As such, the hosts of an ACMS and/or Zoom meeting/session must take additional precautions to avoid potential disclosures including the following:
10.2.1. Using ACMS and Zoom for the exclusive purposes of viewing and validating the identity of the subject or source being interviewed, and verbally communicating with that individual;
10.2.2. Refraining from transmitting of files through ACMS or Zoom; and
10.2.3. Refraining from screensharing through ACMS or Zoom.
10.3. To ensure compliance with the identified restrictions while using ACMS or Zoom by the hosts and users, the following system settings are required:
10.3.1. Encryption must be enabled.
10.3.2. File transfer must be disabled.
10.3.3. Screensharing must be disabled.
10.3.4. Chat functionality must be disabled.
10.3.5. Recording functionality must be disabled.
10.3.6. Each meeting/session must have its own unique hyperlink.
10.3.7. Passwords must be required for each meeting/session.
10.3.8. Meeting/session hyperlink must expire after joining meeting.
10.3.9. Meeting/session must be set to a private status.
10.3.10. Meeting/session must be locked once all attendees are present.
11. DATA PROTECTION REQUIREMENTS
11.1. DCSA data must be encrypted in transit and at rest using FIPS Publication 140 and validated by the Cryptographic Module Validation Program.
11.2. The Contractor must provide the validation certificate number to the CISO or COR for verification.
This must occur prior to award and upon any changes to the cryptographic module.
11.3. The Contractor must redact or mask all DCSA data that is not essential to users, including privileged users.
12. SECURITY MONITORING AND ALERTING REQUIREMENTS
All Contractor-operated systems that use or store DCSA information must meet or exceed DCSA IT security requirements pertaining to security monitoring and alerting in accordance with the DCSA Incident Response Plan. System and network visibility and policy enforcement will occur at the following levels:
Edge Server/Host Workstation/Laptop/Client
Network Application Database Storage User Alerting and Monitoring System, User, and Data Segmentation
13. CLOUD COMPUTING
13.1. Prior to using any commercial cloud service provider (CSP), the Contractor must follow the Cloud SRG and obtain approval from DCSA through the CISO or COR.
13.2. Information stored in a cloud environment remains the sole property of DCSA, not the Contractor or the CSP.
13.3. The CSP must provide all the protections levied on the Contractor, and must be held accountable for all other requirements for DCSA IT systems and data, unless waived in writing by DCSA, through the CISO, AO or COR.
13.4. The CSP must allow DCSA, through the COR, access to DCSA data including data schemas, meta data, and other associated data artifacts that are required to ensure DCSA can fully and appropriately retrieve DCSA data from the CSP.
13.5. The CSP, and any subcontractor or teaming partner CSPs, must adhere to the guidelines and process as indicated in DoDI 8510.01 and DCSA DAAPM.
14. COLLECTION, RETENTION AND DESTRUCTION OF DCSA MATERIALS
No later than 14 calendar days prior to the end of the contract performance period, or within 14 calendar days of request by the COR or KO, the Contractor must provide a plan for the collection, retention, and secure destruction of all DCSA materials, and all DCSA digital information such as records, files, and metadata in electronic or hardcopy format. This requirement includes, but is not limited to, information provided by DCSA, obtained by the Contractor while conducting activities in accordance with this contract, distributed for any purpose by the Contractor to any other related organization and/or any other component or separate business entity, and received from the Contractor by any other related organization and/or any other component or separate business entity.
15. TRAINING AND CERTIFICATION
15.1. Training
15.1.1. All Contractor personnel assigned to perform cyberspace work roles will be required to abide by training requirements identified in DCSA DAAPM, STIGs, and DoD Directive 8140.01 within 6 (six) months of onboarding.
15.1.2. All Contractor and subcontractor employees requiring access to DCSA offices, facilities and controlled access areas must complete DoD Cyber Awareness training in accordance with DoD Directive
8140.01 and DoD 8570.01-M. Non-compliance will result in revocation of system access. The training can be found at https://public.cyber.mil/training/cyber-awareness-challenge/. Completion of the training must be reported to the cyber workforce team and the COR.
15.1.3. New Contractor personnel will complete DoD Cyber Awareness Training prior to receiving access to and/or working on any DCSA systems. The Government will provide periodic mandatory DoD Cyber Awareness training for all Contractor employees working under the awarded contract, and such training will be completed by the due date assigned by DCSA. If any Contractor personnel do not complete the training by the due date, they will be removed from the Contract until the training has been completed.
15.1.4. Contractor personnel performing work related to IT security are required to complete specialized IT security training based on the role-based requirements stated in DCSA DAAPM. The Contractor must certify to the COR that IT security personnel have completed the requisite training requirements as identified in the baseline certifications in DoD 8570.01-M.
15.1.5. DCSA may, upon Contractor request, host formalized BIES management training for Contractor personnel and some field managers. An initial orientation will be given by DCSA on the use of BIES generated case management reports, case tracking, assigning cases, etc., for management and support staff personnel before cases are assigned to the Contractors.
15.2. Certification
15.2.1. New Contractor personnel filling either the Contractor Information System Security Manager or Contractor Information System Security Officer positions as defined in DCSA DAAPM must be certified to the Information Assurance Management (IAM) Training, Certification, and Workforce Management Level III as defined in DoD Directive 8140.01 and DoD 8570.01-M.
15.2.2. The Contractor must ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DoD Directive 8140.01 and DoD 8570.01-M. The Contractor must meet the applicable information assurance certification requirements defined by DoD, including the following:
15.2.2.1. DoD-approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01-M; and
15.2.2.2. Appropriate operating system certification for information assurance technical positions as required by DoD 8570.01-M.
15.2.3. Upon request by DCSA, the Contractor must provide documentation supporting the information assurance certification status of personnel performing information assurance functions.
15.2.4. Contractor personnel who do not have proper and current certifications will be denied access to DCSA information systems for the purpose of performing information assurance functions.
16. HOMELAND SECURITY PRESIDENTIAL DIRECTIVE-12 COMPLIANCE
16.1. All Contactor employees must consent to screening and sign an access agreement prior to accessing Government IT systems, and to rescreening according to changes in position risk designation or other requirements in accordance with the requirements in CJCSI 6510.01F.
16.2. COR approval is required prior to Contractor personnel accessing DCSA IT systems.
16.3. The Contractor must be in compliance with requirements in Instruction CJCSI 6510.01F.
16.4. All IT systems must enforce the use of PIV credentials, in accordance with the FIPS Publication 201.
Development and test IT systems may be approved to use alternate two-factor authentication, such as tokens, with the written approval of the DCSA Information Officer, through the KO or COR, prior to implementation.
Attachment:
Access to DCSA IT Systems Staffing Change Report Template (See PWS 7.1.17.)
Technical Exhibit B. Background Investigation Training Requirements
1. GENERAL REQUIREMENTS
1.1. The Contractor will be responsible for all initial and supplemental training using a curriculum that incorporates all Federally mandated standards, and bear the financial responsibility for all costs associated with initial, remedial, supplemental or other training, including, but not limited to, travel and lodging costs, meals, tuition, and similar incidental costs. DCSA reserves the right to audit and inspect any aspect of the training.
1.2. Training will include a security briefing (includes proper handling/storage of case materials) and standards of professional conduct.
1.3. If the Contractor chooses to develop (or already maintains) a learning management system, the Contractor must coordinate usage under this contract with DCSA and meet all necessary DCSA IT requirements prior to utilization.
1.4. The Contractor will provide certificates of completion for all personnel to the COR or to the KO upon request. Required training must be completed prior to conducting any investigative work on the contract.
1.5. A monthly training deliverable will be submitted to the COR by the 10th calendar day of each month to show all training completed during the reporting period. The report will include: last name, first name, middle initial (separate fields); course title; date completed; test score, if applicable; certificate number, if applicable; and credential issuance date, if applicable.
1.6. For non-BI required training, specifically IT, security, and PII training see PWS 7.1.21 and Technical Exhibit L.
2. TRAINING REQUIREMENTS FOR BACKGROUND INVESTIGATORS
2.1. Background Investigator Contractor personnel (to include any subcontractors working in support of this requirement) conducting work on the contract must be trained in accordance with the training requirements set forth in the Performance Accountability Council Background Investigator Training Standards prior to conducting any work on the awarded contract.
2.2. The Contractor must maintain records verifying that its investigator personnel possess the required training. These records will be retained for the lifecycle of the contract. This includes:
Training methodology (e.g., instructor-led classroom training, online training, on-the-job training
(OJT))*
Provider* Date completed* Specific element(s) of the National Training Standards (NTS) to which the training relates (e.g., program of instruction/course control document reference)* Method of assessing training performance outcomes*
Course titles/descriptions* Rosters (to include course title* and investigator name) All results and assessment tools Transcripts (to include remedial training)
* Items marked with an asterisk are specific requirements outlined in the National Training Standards Implementation Plan. Retained records must be available for a Government audit/inspection within 24 hours.
2.3. At its sole discretion, based upon DCSA policy and National Training Standards Implementation Plan, DCSA may grant reciprocity for investigators who previously completed NTS compliant training or were previously assessed meeting the criteria below. These options only apply under the following conditions:
The individual completed an NTS-compliant course of instruction and can provide the required documentation as outlined in the National Training Standards Implementation Plan.
The individual was working as a background investigator for, or on behalf of the agency, during the April-August 2015 timeframe and can provide documentation that their NTS compliance was verified with a documented assessment conducted in accordance with National Training Standards Implementation Plan.
Note: Completion of NTS-compliant training, or a documented assessment as outlined above, are the only acceptable circumstances for invoking reciprocity.
2.3.1. Contractors may call the COR to verify whether investigators have been assessed in compliance with the NTS.
2.3.2. DCSA may determine that investigators trained in accordance with the Performance Accountability Council Background Investigator Training Standards still require additional training in order to ensure quality case completion.
2.4. DCSA will review Contractor training plans for compliance with Performance Accountability Council Background Investigator Training Standards and DCSA policies and procedures.
2.5. All individuals conducting investigations are to be trained on DCSA’s requirements for BI’s as detailed in Qualifications and Training Requirements for Background Investigators (see section 3).
2.6. DCSA will assist Contractors in the development of their investigator training by providing DCSA instructional materials that, as a minimum, cover the following topics:
Investigator process/procedures Coverage Briefing Note taking Enhanced Subject Interviews Personal sources
Records Issues Field Work System Reporting
Note: Training materials provided by DCSA must be handled in accordance with classification markings and cannot be shared or released to outside entities.
2.6.1. The Contractor will augment the training (e.g., training materials to describe Contractor roles and responsibilities, internal control processes, testing, check-rides, mentoring) using the Contractor’s existing staff to ensure compliance with DCSA’s policies and procedures.
2.6.2. Upon request, DCSA will conduct an Investigator Train-the-Trainer program.
2.7. During the life of this contract, DCSA may offer/mandate background investigator training to candidates sponsored by the Contractors. This training will be in accordance with the Performance Accountability Council Background Investigator Training Standards.
2.8. During the life of this contract, supplemental standards and requirements may be developed that outline further requirements for investigations, which will require training of Contractor personnel. The Contractor will be responsible for all such training and will bear the financial responsibility for all costs including, but not limited to, travel and lodging, meals, tuition, and similar incidentals.
2.9. Electronic and/or hard copies of training materials, policies, guidance, and other documentation determined necessary by DCSA may be updated and revised periodically by DCSA. Any costs incurred by the Contractor for the distribution of these documents to personnel and any training time involved with implementation of updates or revisions are considered normal operating costs and will be the sole responsibility of the Contractor. Release of any portion of these documents, outside of personnel who have been cleared by DCSA to work on this Contract, is strictly prohibited without prior written approval from the KO or COR.
3. QUALIFICATIONS AND TRAINING REQUIREMENTS FOR BACKGROUND INVESTIGATORS
3.1. Qualifications for Background Investigator
Specialized Training Experience Education
*Successful completion of a Background Investigator NTS compliant investigator training course.
Exception: Incumbent investigators assessed as NTS compliant in accordance with the NTS Implementation Plan.
And/ Either
4 years of General Experience*
OR 4 year course of study leading to a bachelor’s degree
*Successful completion of a Background Investigator NTS compliant investigator training course.
AND 2 years of Specialized Experience** within the last 5 years
Specialized Training Experience Education
Exception: Incumbent investigators assessed as NTS compliant in accordance with the NTS Implementation Plan.
*Successful completion of a Background Investigator NTS compliant investigator training course.
Exception: Incumbent investigators assessed as NTS compliant in accordance with the NTS Implementation Plan.
AND 1 year of Specialized Experience** in Federal Background Investigations experience within the last 5 years
*General Experience is progressively responsible experience which demonstrates the ability to:
Problem solve: Analyze problems to identify significant factors, gather pertinent data, and recognize solutions.
Plan and organize work.
Communicate effectively orally and in writing on a professional level.
**Specialized Experience is progressively responsible experience which includes conducting:
General background investigations as a local, state, military, or Federal law enforcement officer.
Federal background investigations for a Federal agency.
3.1.1. Background Investigator training must include, but is not limited to the defined Federal Investigative Standards, identification of applicable Executive Orders, Security Executive Agent Directives and governing policies, methodology, issue resolution, interviewing techniques, but also the background investigator core competencies (technical competence, planning/case management, autonomy, interpersonal, oral and written communication skills, and technical application).
3.1.2. As a minimum, the Background Investigator training program will instruct students to perform/meet the following terminal performance objectives:
Given a BI assignment, conduct necessary planning functions to include preparing a briefing guide, prioritizing workload, scheduling appointments and performing administrative duties in accordance with the appropriate standards and/or agency policies;
Having planned a BI, conduct required fieldwork activities consisting of record reviews, source/reference interviews, subject interviews and pursuit of investigative issues in accordance with the appropriate standards and/or agency policies;
In accordance with the appropriate standards and/or agency policies, use the information obtained during the investigation to write and submit a Report of Investigation; and
In support of Investigative operations, perform administrative and supporting tasks required to maintain qualifications and operability, in accordance with agency policies and/or standards.
3.1.3. All investigator training materials and supporting documentation must comply with the Performance Accountability Council Background Investigator Training Standards and the National
Training Standards Implementation Plan, and applicable DCSA policies and procedures. Contractors may use their preferred training methodologies but must comply with the conditions outlined in the National Training Standards Implementation Plan. DCSA and other authorized entities have the right to inspect, verify, audit, or monitor the training and/or material at any time. Corrections/changes identified must be remediated upon notification.
3.1.4. The Contractor must maintain and provide upon request an investigator training matrix reflecting each NTS Performance Indicator (PI). The matrix will identify the specific location (e.g., document name, page number) where each PI is covered, as well as the enabling and terminal performance objectives supported. Similarly, all answer keys for tests, quizzes, and graded exercises will identify the PIs and supporting objectives for each item. This information is required to enable a review of training materials for compliance with the Performance Accountability Council Background Investigator Training Standards. The matrix is one tool used to support inspections, training program reviews, and/or audits.
The goal is to ensure evaluated PIs are communicated in accordance with DCSA policies and procedures, and assessed as required.
3.1.5. The Contractor must retain all training related information for the lifecycle of the contract. This includes course descriptions, rosters (to include course title and investigator name), dates of training, results, transcripts (to include remedial training), and assessment tools. Retained records must be available for a Government audit/inspection.
3.2. For new Background Investigator personnel, all training must comply with the Performance Accountability Council Background Investigator Training Standards and the National Training Standards Implementation Plan. The duration, format, and delivery of required training components and mentoring will be determined by the Contractor but must be a minimum of six (6) weeks. Training will address all aspects of the background investigator’s duties, including mock interviews and an OJT component and assessed proficient in all NTS performance indicators. Investigator trainee assessments will consist of knowledge assessments and practical evaluations. Investigators trainees must receive a minimum score of 80% on each assessment. Deficient areas must be remediated by the Contractor utilizing an appropriate methodology, e.g. OJT. The Contractor will establish a process by which new investigators are individually assessed and a determination is made as to that specific person’s individual training needs. Those training needs, aligned with the person’s knowledge, skills, abilities, and aptitude, should form the basis for determining the appropriate amount of required OJT time. The OJT process includes an environment where a trainee‘s work is observed, reviewed, or discussed by a senior staff member well versed in DCSA investigations, technology, policy, and procedures. Additional post-training audits are required for at least 30 days after the mentoring phase of training for new investigative personnel.
3.3. For experienced and trained investigative personnel, defined as having been trained in accordance with the Performance Accountability Council Background Investigator Training Standards and having specialized experience, the duration, format and delivery of required training components and mentoring will be determined by the Contractor to be appropriate for the individual and the position. All experienced and trained investigative personnel must be trained in all 78 performance indicators listed in the Performance Accountability Council Background Investigator Training Standards. Documentation that the Contractor has validated that the investigator has been trained, or assessed proficient in accordance with paragraph 3.1, in all 78 performance indicators must be provided within 24 hours of DCSA request.
3.3.1. Any investigative personnel who meet the definition of experienced and trained investigative personnel, and have satisfied the Performance Accountability Council Background Investigator Training Standards requirements as annotated above, are eligible to continue work in the same capacity with a separate employer. Experienced and trained investigators must demonstrate their NTS knowledge, skills, and abilities through a performance assessment to be defined by the Contractor. Deficient areas must be mitigated utilizing any methodology deemed appropriate by the Contractor, e.g. OJT. The minimum passing score is 80%. Documentation of the entire assessment process must be maintained and available for review by DCSA within 24 hours of request.
3.3.2. For investigative personnel with investigative experience but no experience on the DCSA contract conducting DCSA investigations, the Contractor must validate that the investigator has either completed an NTS-compliant course of instruction or been assessed in accordance with paragraph 3.1. The investigator must demonstrate proficiency for all 78 performance indicators and all DCSA policies and procedures prior to working as an investigator under this contract. Deficient areas must be mitigated utilizing any training methodology deemed appropriate by the Contractor.
3.4. When investigative personnel are shared by multiple Contractors, or personnel move from one contractor to another, both contractors must ensure the personnel are trained in accordance with the Performance Accountability Council Background Investigator Training Standards and maintain documentation in accordance with the National Training Standards Implementation Plan. The Contractor, at their discretion, may require additional training and/ or satisfactory completion of their own testing and assessments. The Contractor is required to maintain documentation as outlined in paragraph 2.2 and make any requested documentation available for DCSA review within 24 hours of request. When shared investigative personnel are unable to complete training requirements for any one of the participating Contractors, DCSA must be notified immediately.
4. QUALIFICATIONS AND TRAINING REQUIREMENTS FOR OTHER INVESTIGATIVE SUPPORT PERSONNEL
4.1. Investigative support personnel conducting investigative work (such as record collection) on the Contract shall be trained on DCSA’s requirements for background investigations, prior to conducting any work on the awarded contract. Investigative support personnel may include record researchers, or investigative technicians, or subcontractors working in support of this requirement.
4.2. The Contractor shall maintain records which verify that its personnel possess the required training.
These records will be retained for the lifecycle of the contract and shall be available for a Government audit/inspection within 24 hours. This includes:
Course descriptions;
Rosters (to include course title and personnel’s name);
Dates of training;
All results and assessment tools; and Transcripts (to include remedial training).
4.3. During the life of this contract, DCSA may offer/mandate training to candidates sponsored by the contractors. The Contractor will be responsible for all such training and will bear the financial responsibility for all costs including, but not limited to, travel and lodging costs, meals, tuition, and similar incidental costs.
4.4. Investigative Technician and Record Searcher personnel must successfully complete an Investigative Technician or Record Searcher training course, respectively and either have one year of general experience or a High School diploma. General experience is progressively responsible experience that demonstrates the ability to:
Problem solve: Analyze problems to identify significant factors, gather pertinent, data, and recognize solutions.
Plan and organize work.
Communicate effectively orally and in writing on a professional level.
4.5. The training will include, but is not limited to, instruction on all aspects of duties, conducting and reporting record searches, mock interviews, situations for obtaining records (if applicable to the position), a final exam that must be passed and remediation as necessary. The Contractor sets the minimum passing score consistent with the established standard of competence for the occupation, role, or skill. The training will also include any applicable duties defined by the Federal Investigative Standards, Executive Orders, Intelligence Community Directives and governing policies, methodology, issue resolution, and interviewing techniques. Training will include instruction on any applicable IT mission systems, such as Field Work System.
4.6. These personnel must receive mentoring with a senior experienced investigative person until the new personnel successfully demonstrates competency to complete all (or designated) tasks. Mentoring includes an environment where a trainee’s work is observed by a senior staff member well versed in DCSA investigations, technology, policy, and procedures. Additional post-training audits are required for at least 30 days after the mentoring phase of training for new investigative personnel.
Federal Background Investigator Training Program Curriculum and Investigator Field Course Curriculum (See PWS 7.1.5.)
Technical Exhibit C. Background Investigation Security Requirements
1. GENERAL
1.1. Security Requirements
The Contractor and any subcontractor(s)/consultants will comply with the provisions established in Federal regulations, DCSA policies and procedures for the protection of CUI and material. Any revisions to DCSA policies, procedures or manuals will be provided to the Contractor by DCSA, and incorporated by reference into this Contract. All personnel supporting this contract are responsible for completing any and all security related training. The Contractor agrees to insert terms that conform substantially to the language of this section in all subcontracts under this Contract that involve access to Classified Information and CUI.
1.2. Security Compliance
If at any time during Contract performance it is determined that the Contractor is not in full compliance with any of the security requirements of the Contract, the Government may immediately suspend performance under the Contract and require the immediate return of all case materials to the Government at full Contractor expense.
1.3. Adherence to NISPOM
The Contractor will adhere to the requirements established in the 32 CFR Part 117, National Industrial Security Program Operating Manual, DoD 5220.22-M/NISPOM, Chapter 1, Section 2, 1-201, and appoint a FSO to supervise and direct security measures necessary for implementing applicable requirements of the NISPOM and related Federal requirements for the protection of Classified Information and CUI.
1.4. Compliance with DCSA Policy on the Protection of Personally Identifiable Information The Contractor will ensure that all personnel comply in accordance with the Privacy Act of 1974, Personally Identifiable Information in 2 CFR Part 200.79 and all applicable DCSA privacy policy guidance.
(See Technical Exhibit E. Requirements for the Protection of Personally Identifiable Information for requirements pertaining to the protection of PII.)
1.5. Destruction Standards
The Contractor will adhere to 32 CFR Part 117 /NISPOM, DoD 5220.22-M/NISPOM, Chapter 5, Section 7 for the destruction of classified material. The Contractor will adhere to DoDI 5200.48 Controlled Unclassified Information, DSS 25-1 Information Security Policy, or its successor policy, for the destruction of CUI material.
1.6. Common Access Cards/Personal Identity Verification Cards, and Credentials The Contractor will establish and implement methods to mitigate the risk that CACs, PIVs, and/or other credentials are lost, misplaced, or used by unauthorized persons. This will be done in accordance with the security requirements provided in subsection 3.3.1. (Credentials and Badgeless Credentials) and
3.3.3. (Common Access Cards/Personal Identity Verification Cards) of this contract. The Contractor will immediately report any occurrences of lost items to the COR.
2. PERSONNEL SECURITY REQUIREMENTS
2.1. Provision of Staff
The Contractor will provide an adequate, qualified, trained, and investigated/adjudicated investigative support (clerical, technical, professional) staff with the skills necessary to perform all investigative functions referenced in this Contract and all attachments and references. Security/suitability requirements for personnel are found in Executive Orders 13526 and 12968, and credentialing and fitness standards.
2.2. Favorably Adjudicated Background Investigations
All Contractor personnel, to include their subcontractors, and consultants engaged in the performance of work under this Contract will have a completed, current investigation of the appropriate level relevant to the sensitivity of the position and access they require with a favorable eligibility determination. The level of investigation and eligibility determination or position of trust/suitability determination has been determined in accordance with current DoD and DCSA policy. The investigation must be favorably adjudicated by the DoD Consolidated Adjudications Facility (CAF) prior to the Contractor employee working under this Contract and prior to any subsequent change of position.
2.3. Reportable Requirements
The DoD CAF is…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .