DRAFT_-_Compliance_Statement_of_Work.pdf

PDF 349 KB Posted

Attached to
Compliance Litigation Support Federal contract opportunity
Solicitation number
05192015
Issued by
Department of Justice Offices Boards and Divisions Criminal Division

About this file

Draft Compliance Consultant SOW

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT - Statement of Work

Criminal Division – Fraud Section

Compliance Counsel

5/19/2015

Introduction & Background

The Department of Justice Criminal Division is responsible for the development, enforcement and supervision of all federal criminal laws except those specifically assigned to other divisions.

The Division and the 93 U.S. Attorneys have the responsibility for overseeing criminal matters as well as certain civil litigation. Criminal Division attorneys prosecute many nationally significant cases. In addition to its direct litigation responsibilities, the Division formulates and implements criminal enforcement policy and provides advice and assistance on criminal matters.

Within the Criminal Division the Fraud Section plays a unique and essential role in the

Department's fight against sophisticated economic crime. The Section is a front-line litigating unit that acts as a rapid response team, investigating and prosecuting complex white collar crime cases throughout the country. The Section is uniquely qualified to act in that capacity, based on its vast experience with sophisticated fraud schemes; its expertise in managing complex and multi-district litigation; and its ability to deploy resources effectively to address law enforcement priorities and respond to geographically shifting crime problems.

Scope of Work

To fulfill its mission, the Fraud Section seeks highly qualified compliance personnel to provide unique expertise in all compliance related issues allowing the Fraud section to better evaluate company remediation efforts.

Tasks

The required Compliance Counsel (1 FTE) will take part in all compliance related matters within the Fraud Section. In that capacity the compliance counsel will have both inward and outward facing duties which include the following tasks:

- Take the lead in establishing metrics for the Fraud Section attorneys to assess corporate remediation efforts. That effort will require devising general criteria for any compliance program as well as more tailored criteria specific to industries and the particular company at issue.

- Serve as the Fraud Section compliance subject matter expert (SME) in potential litigation or dispute involving the Government in any trial, hearing, or proceeding before any court, administrative tribunal, or agency. As a Fraud Section compliance SME the contractor may be required to testify.

- The Compliance Counsel will be instrumental in evaluating whether a corporate compliance program is effective and reasonable, or a mere paper program. The Compliance Counsel will thus take the lead in meeting with organizations that seek to establish successful remediation programs, so the Fraud Section can assess compliance efforts by companies seeking to demonstrate effective remediation.

- The Compliance Counsel shall benchmark with compliance officers in various industries in order to establish up to date metrics that reflect the realities of compliance in the multitude of industries in which the corporate actors who appear before the Fraud Section function.

- The Compliance Counsel shall work with DOJ monitors appointed in Fraud Section cases to establish and assess ongoing remediation efforts.

Minimum Qualifications (1FTE)

- Proven experience as a Chief Compliance Officer or related senior compliance position with significant control over day to day compliance programs within a multinational company.

- Bar-certified lawyer.

- Possess a wide knowledge of state of the art compliance programs and possess the ability to benchmark industries.

Desired Qualifications

- Proven compliance experience within the financial industry.

- Proven compliance experience within multiple industries (healthcare, financial services, insurance etc.).

Deliverables

Various deliverables shall be required during the performance of this work to include limited to written reports, recommendations and other deliverables as required.

Government Furnished Property

Government provided work space and various information technology equipment as required.

Security Provisions:

The security provisions applicable to this requirement are listed by reference below and by full text located in Attachment 1 of this statement of work. These provisions shall apply to the contractor, and the contractor shall place these same provisions into to any subcontracts supporting this effort.

Attachments 1 Security Provisions:

Contractor Personnel Security

Systems Data Security and Personal Identifiable Information

Conflicts of Interest:

Contract personnel assigned to this work agree not to consult or provide services in any manner or capacity to a direct competitor/defendant of the government during the duration of this agreement unless express written authorization to do so is given by the Contracting Officer. A direct competitor/defendant of the government for purposes of this agreement is defined as any individual, partnership, corporation, and/or other business entity under investigation by the

Department of Justice.

Travel

Travel may be required as part of this requirement and shall be conducted in accordance with the federal travel regulation (FTR).

Proprietary Rights

All proprietary rights with respect to the information, data and materials produced by the contractor in connection with this contract shall vest in the Government. Such information and materials include: reports, databases, plans, designs, procedures, recommendations and any other such physical or intellectual property. The contractor shall not publish or otherwise publicly provide any of the above without written approval by the contracting officer. This provision shall be placed into any subcontracts supporting this effort when a subcontract is entered into by the prime contractor and a subcontractor.

Non-Payment for Unauthorized Work

Any new or additional work performed by the contractor outside of the work defined herein, whether at the contractor’s own volition or at the request/direction of any individual other than the contracting officer or his/her designated representative as identified in this document, shall be at the sole financial risk of the contractor. Only a duly-appointed contracting officer is authorized to bind the Government to any addition to or change in the tasks, deliverables, duties, responsibilities, specifications, terms and/or conditions of this contract; and, only a duly appointed COR may provide technical direction with respect to those same tasks, deliverables, duties, responsibilities, specifications, terms and/or conditions.

Invoicing

All invoices shall be submitted electronically to CRM.Accounts.Payable@usdoj.gov as an original and one copy, and shall be addressed to the COR or Government

Program/Administrative POC indicated in this contract. To constitute a proper invoice, the invoice shall include the following information and supporting documentation:

Name of business

Unique invoice number and date of invoice

DUNS and Tax ID numbers

Contract/Order number

Description, price and quantity of services rendered or goods delivered

Period that services billed hereunder were rendered or goods were delivered

Payment terms

Name, title, phone number and email of official to contact regarding invoice and payment matters.

Payment

Payment shall be made through ACH direct deposit only. The contractor shall complete an ACH

Vendor/Miscellaneous Payment Enrollment Form which will be provided upon award. If the contractor’s ACH information changes, the contractor shall notify the contracting officer immediately. Partial payments for services rendered under this contract are authorized for mailto:CRM.Accounts.Payable@usdoj.gov services continuing longer than one month. Payment shall only be made after services have been rendered, received and accepted by the government. Payment will be made in accordance with the Prompt Payment Act.

Performance Period Location

The period of performance for this contract shall extend from the date of contract award for one year thereafter with one twelve month option period. The majority of work shall be conducted in a government provided facility located at 1400 NY Ave NW. Washington, DC 20005.

Administrative Contacts

Contracting Officer’s Representative

All day-to-day communications and technical guidance under this contract shall be conducted between the contractor and the following contracting officer’s representative (COR). The COR understands his/her authorities and limitations and will coordinate with the contracting officer as needed. The contractor may contact the contracting officer directly at any time should the need arise.

COR: Barbara Newman

Telephone Number: 202-353-7843

Email Address: barbara.newman@crm.usdoj.gov

Contracting Officer

The Government contracting officer for this award/contract is:

Brandon Morrison

Department of Justice, Criminal Division, Office of Procurement

1400 New York Avenue, Suite: 5000

Washington, D.C. 20530

Tel. 202.305.1207

Email Address: Brandon.m.morrison@usdoj.gov

Attachment 1

SECTION VII. SECURITY PROVISIONS

CONTRACTOR PERSONNEL SECURITY REQUIREMENTS – UNCLASSIFIED

A. Contractor Personnel

1. The work to be performed under this contract will involve access to unclassified information and/or facilities. All references to AContractor (or) personnel@ and AContractor employee@ in this clause shall include all individuals that will perform under this contract including individuals employed by the Contractor, team members, subcontractors, consultants, and/or independent contractors.

2. All Contractor personnel will be subject to a Public Trust Investigation (PTI). Except where specifically noted otherwise, the Government will be responsible for conducting the investigation and the cost of the investigation. All investigations will be conducted in accordance with applicable Executive Orders, DOJ Orders, Office of Personnel Management (OPM) guidance, Homeland Security Presidential Directive 12 (HSPD-12), and

Federal Information Processing Standard Publication 201 (FIPS 201).

3. PTI certifications will be accepted from other Federal agencies provided the investigation performed by the other agency meets or exceeds DOJ requirements.

4. The Contractor will not be permitted to commence performance under this contract until a sufficient number of its personnel, as determined by the Contracting Officer’s Representative (COR) and Security Programs

Manager (SPM), have received the requisite security approval.

5. During the life of the contract, the Contractor shall ensure that no contractor employee commences performance hereunder prior to receipt of a written authorization from the Contracting Officer, the COR or the SPM.

B. Access to Unclassified Information

1. Contractor personnel requiring access to unclassified information will fall under the following categories:

a) High Risk. High risk positions are those positions that have the potential for exceptionally serious impact on the integrity and efficiency of the DOJ and involve duties especially critical to the DOJ or a program mission with broad scope of policy or program authority.

b) Moderate Risk. Moderate risk positions are those positions that have the potential for moderate to serious impact on the integrity and efficiency of the DOJ. Duties involved are very important to the DOJ or program mission with significant program responsibility or delivery of services.

c) Low Risk. Low Risk positions are those positions that have limited potential for adversely affecting the national security operations of the Department.

C. Pre Appointment Background Investigations and Waivers

1. Background investigations must be conducted and favorably adjudicated for each contractor employee prior to commencing work on this contract. However, where programmatic needs do not permit the Government to wait for completion of the entire background investigation, a pre appointment background investigation waiver can be granted by the SPM, in consultation with the cognizant COR. The extent of the background investigation will vary depending upon the Risk Category associated with each position and whether each position is long- or short-term. Short-term is defined as contractor employees having access to Federally-controlled information systems and/or unescorted access to Federally-controlled facilities or space for six months or fewer. The requisite background investigation does not need to be initiated for short-term positions as part of the pre-employment waiver except in the case of non-U.S. citizen contractor employees. However, long-term contractor employees requiring unescorted access to Federally-controlled facilities and/or access to any Federally-controlled information system shall be subject to the requisite background investigations described below. A waiver will be disapproved if it develops derogatory information that cannot be resolved in the contractor employee=s favor. When a waiver has been disapproved, the COR, in consultation with the SPM, will determine (1) whether the contractor employee will no longer be considered for work on a DOJ contract or (2) whether to wait for the completion and favorable adjudication of the background investigation before the employee commences work on a Department contract. The minimum pre appointment investigative requirements are as follows:

a) High Risk Positions. The minimum background investigation required is a five year scope

Background Investigation (BI), and the five year reinvestigation required is an Access National

Agency Check with Inquiries (ANACI). The Standard Form (SF) 85P, Questionnaire for Public

Trust Positions, is required.

b) Moderate Risk Positions. The minimum background investigation required is a Minimum

Background Investigation (MBI) for Amoderate@ impact on the integrity and efficiency of the

DOJ or a Limited Background Investigation (LBI) for Aserious@ impact potential on the DOJ=s integrity and efficiency. The five year reinvestigation required is a National Agency Check with

Law and Credit (NACLC). The SF-85P is required.

c) Low Risk/Non-Sensitive Positions. The minimum background investigation required for Low

Risk/Non-Sensitive positions is a National Agency Check with Written Inquiries (NACI) and the required five year reinvestigation is also a NACI. The SF-85, Questionnaire for Non-Sensitive

Positions, is required.

2. The pre appointment background investigation waiver requirements include:

a) Favorable review of the security questionnaire form;

b) Favorable FBI fingerprint results;

c) Verification of citizenship (copy of a birth certificate, Naturalization Certificate, or U.S.

Passport);

d) Verification of compliance with the DOJ residency requirement;

e) Favorable credit report for contractor personnel in High Risk and Moderate Risk positions;

and,

f) Verification of the initiation of the appropriate background investigation for long-term

Contractor personnel.

D. Required Security Forms

1. The following forms must be completed and submitted by the Contractor=s Corporate Security Officer for each contract employee PTI:

a) FD-258 Applicant Fingerprint Card. Two sets are required per applicant. The Contractor may schedule appointments with the SPM to be digitally fingerprinted; otherwise, fingerprinting by the

FBI is required. All pertinent information must be completed by the individual taking the prints, or by the FBI if prints are taken there.

b) SF-85 Questionnaire for Non-Sensitive Positions -or- SF-85P Questionnaire for Public Trust

Positions. The contractor employee shall complete the SF-85/SF-85P via the Electronic Security

Questionnaires for Investigations Processing (e-QIP) System after first obtaining access to e-QIP from the SPM (see paragraph (c) below). The Contractor shall also submit a hard copy of the form

(as completed and signed by the contractor employee) with the remainder of the security package.

c) DOJ-555 Fair Credit Reporting Act Disclosure. Authorizes DOJ to obtain one or more consumer/credit reports on the individual. This is required for Contractor personnel in High Risk and Moderate Risk positions.

d) Foreign National Relatives and Associates Statement. This is only required if any relatives listed on the SF-85/SF-85P are foreign nationals.

d) Confidentiality Agreement for Contractor and Subcontractor Employee.

2. The Contractor shall also submit a credit report for each individual designated at the High Risk or

Moderate Risk level, and have resolved satisfactorily any individual credit issues.

E. Using e-QIP

Immediately after award, the Contractor shall designate an employee as its Ae-QIP Initiator@ and provide the name of this person to the COR. The e-QIP Initiator must have, at a minimum, a favorably adjudicated MBI and the appropriate DOJ security approval before being given access to e-QIP. After the e-QIP Initiator=s security approval is granted, the Contractor will be configured in e-QIP as a sub-agency to DOJ. The Contractor will then be responsible for initiating all contractor personnel in e-QIP for completion of the security questionnaire form and forwarding the electronic form along with a hard copy of the form (as completed and signed by the contractor employee) with the remainder of the security package to the designated DOJ representative. Subject to the prior approval of the SPM, the Contractor may designate an e-QIP Initiator for each subcontractor. Subcontractor e-QIP

Initiators must have, at a minimum, a favorably adjudicated MBI and the appropriate DOJ security approval before being given access to e-QIP.

F. Citizenship and Residency Requirements

1. Residency Requirement. Contractor employees, both United States (U.S.) citizens and non-U.S.

citizens, must meet the Department=s Residency Requirement, i.e., he/she must have lived in the U.S. three of the last five years immediately prior to employment under the Department contract; and/or worked for the U.S. overseas in a Federal or military capacity; and/or be a dependent of a Federal or military employee serving overseas. At the

Department=s sole discretion, the residency requirement may be waived by the Department Security Officer (DSO) on a case-by-case basis where justified by extenuating circumstances.

2. Citizenship. The DOJ gives strong priority to contractor employees that are U.S. citizens and nationals.

Any prospective contractor employee that is a foreign national must be from a country allied with the U.S. (See http://www.opm.gov/employ/html/Citizen.htm). At the Department=s sole discretion, a waiver of the allied nations list requirement may be granted by the DSO on a case-by-case basis where justified by extenuating circumstances.

The Contractor is responsible for verifying that all non-U.S. citizens working under this contract have been lawfully admitted to the U.S. Contractor employees requiring access to DOJ Information Technology (IT) resources are subject to the following additional restrictions:

Non-U.S. citizens are not authorized access to or permitted to assist in the development, operation, management or maintenance of DOJ IT systems unless a waiver has been granted by the Head of the DOJ component, with the concurrence of the DSO and the DOJ Chief Information Officer (CIO). Such a waiver will be granted only in exceptional and unique circumstances. It should be noted that the Justice

Consolidated Office Network (JCON) is a sensitive ADOJ IT system@ and any contractor employee that will need access to JCON must be a U.S. citizen or have received a waiver.

3. Dual Citizenship. U.S. citizens who hold dual citizenship with a foreign country may be considered for contract employment. However, how the contractor employee obtained or exercises his or her dual citizenship status will be a consideration in the adjudication process.

G. Procedures for Pre-Screening Applicants and Investigation

1. The Contractor shall perform the following pre-screening and investigation duties for all persons proposed for work under this contract:

a) Furnish to each proposed contract employee the forms described in Section D above and ensure that adequate instructions for completing the forms are provided to each applicant.

b) Ensure that applicants obtain two (2) complete sets of their fingerprints on the prescribed Form

FD-258 from an organization qualified to take fingerprints.

c) Collect completed forms from each applicant and review all forms for completeness and correctness. This includes, for example, satisfactory resolution of address issues or discrepancies.

Return any incomplete or incorrect form(s) to applicant(s) to be corrected and re-submitted.

d) Submit completed forms to the COR no later than fourteen (14) calendar days after receipt of the blank forms and access to e-QIP has been initiated.

e) As directed by the COR, initiate pre-appointment waivers for certain positions. This may entail performing credit history checks and submission of these checks as part of the security package, including satisfactory resolution of any issues prior to submission to the Government.

f) As directed by the COR, review all forms prior to their being submitted to DOJ to ensure that candidates meet DOJ requirements, including residency and citizenship requirements.

2. The Department will be responsible for the following:

a) Determine the appropriate risk level for each contract employee position.

b) Provide the Contractor an adequate supply of forms and instructions for completing the forms within five business days after award. Ensure that the Contractor is provided access to the e-QIP system as described in Section E above.

c) Ensure that completed security forms are forwarded to the appropriate investigating agency in accordance with appropriate internal procedures. The investigating agency will conduct the requisite investigations.

d) Determine whether pre-appointment background investigation waivers will be needed, and if so, which positions will require such waivers. The COR will notify the Contractor which pre-appointment waivers to initiate.

e) Notify the Contractor of the results of background investigations as they are completed and adjudicated. The COR will notify the Contractor of any applicants who are found ineligible for employment security approval so that the Contractor can immediately recruit and initiate paperwork to clear replacement applicants.

f) Notify the Contracting Officer when a sufficient number of contractor employees have received employment security approvals or pre-appointment waivers approvals. Upon receipt of this information and any other information which may be required elsewhere in the contract, the

Contracting Officer will issue the Contractor a Notice to Proceed which permits the commencement of work under the contract.

g) Maintain an up-to-date file of Certificates of Investigation (COI) and other background investigation-related documentation for all contractor employees throughout the life of the contract.

3. The investigating agency will furnish the relevant SPM the results of each proposed employees investigation through issuance of a Certificate of Investigation (COI). Upon receipt of the COI and any other pertinent documents from the investigating agency, the SPM will determine whether or not each proposed contractor employee should be granted employment security approval. This decision process is called Aadjudication. The

SPM will notify, if required, the investigating agency of the adjudicative determination of each investigation. If

OPM is the investigating agency, this will be accomplished by the SPM completing and submitting to OPM an INV

Form 79A, AReport of Agency Adjudicative Action.

H. Identity Proofing and Badging.

1. During the life of this contract, the right to unescorted access to Federally-controlled facilities and/or access to Federally-controlled information systems shall be made available after the contractor employees have (1) met the identity proofing requirements outlined below, and (2) completed all other security requirements stated elsewhere in this contract. During all operations on Government premises, the contractor employees shall comply with the rules and regulations governing the conduct of personnel and the operation of the facility. The Government reserves the right to require contractor employees to "sign-in" upon entry and "sign-out" upon departure from the

DOJ facility.

2. All contractor employees requiring unescorted access to Federally-controlled facilities and/or access to

Federally-controlled information systems (regardless of whether they will be issued a DOJ badge), shall comply with the identity proofing and registration requirements outlined below:

a) Contractor employees must present two forms of identification in original form prior to commencement of work under this contract and badge issuance (acceptable documents are listed in Form I-9, OMB No. 1615-0047, AEmployment Eligibility Verification,@ and at least one document must be a valid State or Federal government issued picture ID); and,

b) Contractor employees must appear in person at least once before a COR-designated DOJ official who is responsible for checking the identification documents. This identity proofing must be completed prior to commencement of work under this contract and badge issuance (as applicable), and must be documented by the DOJ official.

3. All contractor employees requiring unescorted access to a DOJ controlled facility shall comply with the badge requirements outlined below:

a) When any Contractor employees enter a DOJ building for the first time, the contractor employees shall allow one hour for security processing and the fabrication of buildings access badges.

b) Building access badges shall be subject to periodic review by the Contractor's Supervisor and checked against the employee's personal identification. The contractor employees shall present themselves for the issuance of renewed badges when required by the Government as scheduled by the Project Manager or his designee. The Contractor shall notify the COR when employee badges are lost, and must immediately apply for reissuance of a replacement badge. The Contractor shall pay for reissued building access badges. It is the Contractor's responsibility to return badges to the

COR when a contractor employee is dismissed, terminated or assigned to duties not within the scope of this contract.

I. Replacement Personnel

1. Security investigations are very costly to the Government. The Contractor shall make every effort to preclude incurrence of costs by the Government for security investigations for replacement of employees, and in so doing, shall assure that otherwise satisfactory and physically able employees assigned hereunder remain in contract performance for at least one (1) year. The Contractor shall take all necessary steps to assure that Contractor personnel who are selected for assignment to this contract are professionally qualified and personally reliable, of reputable background and sound character, and meet all other requirements stipulated herein.

2. The fact that the Government performs security investigations shall not in any manner relieve the

Contractor of its responsibility to assure that all personnel furnished are reliable and of reputable background and sound character. Should a security investigation conducted by the Government render ineligible a Contractor furnished employee, the Contracting Officer will investigate the cause and determine whether the Contractor has abdicated its responsibilities to make every effort to select reliable employees of reputable background and sound character? Should there be need to replace a contractor employee due to nonperformance, the Contracting Officer will determine whether the Contractor has abdicated its responsibilities to make every effort to select trained and experienced employees.

3. Should the Contracting Officer determine that the Contractor has failed to comply with the terms of

Section G.1, the Contractor may be held monetarily responsible, at a minimum, for all reasonable and necessary costs incurred by the Government to (a) provide coverage (performance) through assignment of individuals employed by the Government or third parties in those cases where absence of Contractor personnel would cause either a security threat or DOJ program disruption and (b) conduct security investigations in excess of those which would otherwise be required.

4. Nothing in this Clause shall require the Contractor to bear costs involved in the conduct of security investigations for replacement of an employee who becomes deceased or severely ill for a long period of time.

5. Acceptance by the Government of consideration to which the Government may be entitled pursuant to paragraph (c) above shall not be construed to establish a course of conduct which will serve to limit the rights and remedies otherwise available to the Government. Under no circumstances shall the Contractor fail to comply with the terms and conditions set forth herein without assuming liability for such failure as may be established pursuant to this Clause. The rights and remedies conferred upon the Government by this Clause are in addition to all and other rights and remedies specified elsewhere in this contract or established by law.

J. Automation Equipment and Media Neutral Materials

1. Media Neutral Materials: At the conclusion of the contract period, all media neutral materials used in conjunction with this contract shall be turned over to the COR for destruction and/or proper retention, in accordance with the Federal Records Act 44 U.S.C. Chapter 33 and DOJ records retention schedules. This includes not only paper records, but also all removable, "consumable" media such as floppy disks, magnetic tapes, typewriter ribbons, CD-ROMs, DAT tapes, etc. Any of these media neutral materials that become defective during contract performance shall be immediately turned over to the COR for destruction and/or retention. The Government shall not compensate the Contractor for the costs of these media neutral materials.

2. Other Electronic Media: At the conclusion of the contract period, the Contractor shall sanitize all other electronic media which has been used in connection with contract work, such as PC hard drives and memory, network server hard drives and memory, etc. according to DOJ approved procedures. For example, the Government will require the Contractor to degauss all such electronic media, or to write over the electronic media a specified number of times (e.g., five times using software such as Norton Disk Wipe). The Contractor shall also provide itemized certification that the degaussing has been completed for all equipment used in connection with the contract. If the Contractor is unable to degauss or sanitize the electronic media to the satisfaction of the SPM, the

Contractor shall turn the electronic media over to the COR for destruction. The Government shall not compensate the Contractor for the cost of this effort.

3. Defective Equipment, Electronic Media or Materials: If any PCs, hard drives, memory, servers, etc.

used in connection with the contract become defective during the contract performance period, the Contractor shall either turn the electronic media over to the Government for destruction, or sanitize the electronic media in accordance with Government approved procedures and certify the sanitization. This also applies, of course, to equipment/media the Contractor chooses to sell or dispose of for other reasons. The Government shall not compensate the Contractor for the cost of this effort.

4. Inspection: The Government reserves the right to inspect any equipment/media neutral certified by the

Contractor as having been degaussed or sanitized.

5. Maintenance and/or Removal of Equipment: The Contractor shall ensure that sensitive information does not remain on the electronic storage media, including hard disks and floppy disks, when the PC is removed from the Contractor's area for maintenance or other use. Maintenance personnel shall be escorted and monitored by

COR-designated Department of Justice personnel or Contractor personnel when allowed to perform on-site maintenance for the equipment. The electronic storage media shall be removed from the PC prior to removal of the

PC from the area for maintenance.

6. Special Marking: Any removable electronic storage media shall be appropriately marked with classification level.

K. Data Communications

1. The Contractor shall be responsible for ensuring the security of all data transmitted internally (e.g., within and between Contractor facilities) and data transmitted externally between the Contractor, its subcontractors, government personnel or any other entities. For transmission of sensitive, non-classified data, the COR may require the data to be encrypted in compliance with Federal Information Processing Standard (FIPS) 46-3, Data Encryption

Standard (DES) and "Security Level 1" of FIPS 140-2, Security Requirements for Cryptographic Modules, or their successors.

2. All encryption devices shall be made available for inspection upon initial award of a contract and semiannually or as otherwise directed by the SPM or COR.

L. Confidentiality of Data

1. Duplication or disclosure of the data and other information to which the Contractor will have access as a result of this contract is prohibited by Public Law and is subject to criminal penalties. The terms AContractor@ and

AContractor employee@ in this clause include all entities and individuals that will perform under this contract, including the Contractor, team member, subcontractor, consultant, and/or independent Contractor. It is understood that throughout performance of this contract, the Contractor will have access to confidential data which is either the sole property of the Department of Justice or is the sole property of other than the contracting parties. The

Contractor shall maintain the confidentiality of all data to which access may be gained throughout contract performance, whether title thereto vests in the Department of Justice or otherwise. AData@ in this context shall also include any information about cases or investigations the Contractor is working on, or otherwise has such information on or access to, including the names and subject matters of the cases or investigations. The Contractor shall not disclose or divulge any such information to anyone except to persons who have been approved by the COR and who meet all the following criteria:

Have DOJ/CRM security approval, Have Signed the DOJ Non-Disclosure Agreement

Have a need to know.

2. This limitation specifically applies to the Contractor=s management chain.

a) The Contractor shall not disclose said data, any interpretations and/or translations thereof, or data derivative there from, to unauthorized parties in contravention of these provisions, without the prior written approval of the COR or the party in which title thereto is wholly vested. The Contractor may be held responsible for any violations of confidentiality.

b) Upon termination of the contract, the Contractor shall not have nor claim any property or possessory right to any of the correspondence, files or materials, of whatever kind and description, or any copies or duplicates of such, whether developed/prepared by the Contractor or furnished by the

Government in connection with the performance of this contract; and that, upon demand, the

Contractor shall surrender immediately to the COR all such items, matters, materials and copies.

c) All contractor employees who will have access to confidential data shall sign a Confidentiality

Agreement. It is the responsibility of the Contractor to assure that such Agreements have been signed before access to confidential data is permitted.

SECURITY OF SYSTEMS AND DATA INCLUDING PERSONALLY IDENTIFIABLE DATA

A. Systems Security

1. The work to be performed under this contract requires the handling of data that originated within the

Department, data that the Contractor manages or acquires for the Department, and/or data that is acquired in order to perform the contract and concerns Department programs or personnel.

2. For all systems handling such data, the Contractor shall comply with all security requirements applicable to Department of Justice systems, including but not limited to all Executive Branch system security requirements (e.g., requirements imposed by OMB and NIST), DOJ IT Security Standards, and DOJ Order 2640.2E.

The Contractor shall provide DOJ access to and information regarding the Contractor’s systems when requested by the Department in connection with its efforts to ensure compliance with all such security requirements, and shall otherwise cooperate with the Department in such efforts. DOJ access shall include independent validation testing of controls, system penetration testing by DOJ, FISMA data reviews, and access by the DOJ Office of the Inspector

General for its reviews.

3. The use of Contractor-owned laptops or other media storage devices to process or store data covered by this clause is prohibited until the Contractor provides a letter to the Contracting Officer (CO) certifying to all of the following requirements (form letter is attached):

a) Laptops shall employ encryption using a NIST Federal Information Processing Standard (FIPS)

140-2 approved product;

b) The Contractor shall develop and implement a process to ensure that security and other applications software is kept up-to-date;

c) Mobile computing devices shall utilize anti-viral software and a host-based firewall mechanism.

d) The Contractor shall log all computer-readable data extracts from databases holding sensitive information and verify each extract including sensitive data has been erased within 90 days or its use is still required. All DOJ information shall be considered and treated as sensitive information unless designated as non-sensitive by the COR.

e) Contractor-owned removable media, such as removable hard drives, flash drives, CDs, and floppy disks, containing DOJ data, shall not be removed from DOJ facilities unless encrypted using a NIST

FIPS 140-2 approved product;

f) When no longer needed, all removable media and laptop hard drives shall be processed (sanitized, degaussed, or destroyed) in accordance with security requirements applicable to DOJ;

g) Contracting firms shall keep an accurate inventory of devices used on DOJ contracts;

h) Contractor-developed Rules of Behavior must shall be signed by all users. These rules shall address at a minimum: authorized and official use; prohibition against unauthorized use/users; and protection of sensitive data and personally identifiable information;

I) All DOJ data shall be removed from Contractor-owned laptops upon termination of Contractor work. This removal shall be accomplished in accordance with DOJ IT Security Standard requirements. Certification of data removal shall be performed by the Contractor’s project manager and a letter confirming certification will be delivered to the COR within fifteen (15) calendar days of termination of Contractor work.

4. If the contractor cannot certify to all the above requirements, the contractor shall request a government issued encrypted drive from the COR (form letter is attached). The contractor shall not begin performance under this contract until the contractor has received the drive from the COR. All other requirements above are applicable when using the encrypted drive.

B. Data Security

1. In the event of any actual or suspected breach of data as identified in Section A.1 (for example but not limited to: loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic, etc.), the Contractor shall immediately, but no later than within one hour of discovery or suspicion, report the breach to the CO and COR.

2. If the data breach occurs outside of regular business hours and neither the CO nor the COR can be reached, the Contractor shall call the DOJ Computer Emergency Readiness Team (DOJCERT) at 1-866-US4-CERT

(1-866-874-2378) within one hour of discovery of the breach. The Contractor shall also notify the CO and COR as soon as possible during regular business hours.

C. Personally Identifiable Information Notification Requirement

The Contractor shall have a security policy in place that contains procedures to promptly notify any individual whose personally identifiable information (as defined by OMB) was, or is reasonably believed to have been, breached. However, any such notification shall be coordinated with the CO and COR and shall not proceed until the

Department has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. Moreover, the method and content of any such notification by the Contractor shall be coordinated with, and be subject to the approval of, the CO and COR. The Contractor shall assume full responsibility for taking corrective action also consistent with the Department’s Data Breach Notification

Procedures, which may include offering credit monitoring when appropriate.

D. Pass-through of Security Requirements to Subcontractors

The requirements set forth in Sections A.1 through A.3 above, shall be inserted into all subcontracts that the contractor awards where work is performed in connection with this contract. For each subcontract, the Contractor must certify that it has required the subcontractor to adhere to all such requirements. Any breach by a subcontractor of any of the provisions set forth in this clause shall be attributed to the Contractor.

File details come from the government source that posted it. Updated .