08.09_Solicitation_Attachment 1 - SOW.pdf

PDF 599 KB Posted

Attached to
Government Purchase Card Automated System Federal contract opportunity
Solicitation number
192121FLMURQ0027A
Issued by
Immigration and Customs Enforcement

About this file

This combined synopsis/solicitation from U.S. Immigration and Customs Enforcement seeks a commercial off-the-shelf automated purchase card system. Key requirements include a paperless electronic form and routing system to process approximately 7,000 purchase card transactions per month made by 900 cardholders and approved by 1,700 officials. The system must provide visibility into transactions, establish compliance rules, and generate reports on spending, users, pending requests, and itemized purchases. It should also include a search function, three-way matching of requests to receipts, auditing, and an optional financial tracking module. The base period of performance is 12 months to pilot the system with four additional 12-month option periods. Proposals are due by the date specified in the solicitation, and the award date will also be included if provided.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Solicitation # 192121FLMURQ0027 July 16, 2021

U.S. Immigration and Customs Enforcement (ICE) Office of Acquisition Management (OAQ)

Statement of Work (SOW) Automated Purchase Card Approval System

Contents 1 Overview

2 Background

3 Scope o Paperless o Form o Routing o Hierarchy o Visibility o Establish Rules o Accessibility o Retention o Reporting o Search Function o Matching o Reconciliation and Document close out o Auditing o Receiving o Catalog o Financial o Printing/Download o Support o Access o Logging o Training

4 Objectives, Requirements, and Deliverables

4.1 Government Furnished Information

5 Place and Period of Performance

6 Compliance Requirements

7 Government Roles and Responsibilities

7.1 Contracting Officer (CO)

7.2 Contracting Officer’s Representative (COR)

8 Travel

9 Privacy and Records Requirements

10 Cyber Security Requirements

11 Employee Conduct

12 Removing Contractor Employees

13 Business Relations

14 Release of Information

15 Disclosure

16 Physical Security

17 Organizational Conflict of Interest

18 Data Use, Disclosure of Information and Handling of Sensitive Information

19 Safeguarding Government Property

20 Accessibility Requirements

21 DHS Form 1501

1 Overview

This Statement of Work (SOW) is being issued to obtain a solution that provides a robust, automated government purchase card routing system. The solution sought must provide the minimum requirements outlined in the Scope section of this SOW.

These requirements will enable the Department of Homeland Security (DHS), Immigration and Customs Enforcement (ICE) the ability to provide a streamlined and robust solution for the government purchase card program users.

The approximate number and type of users of the system will include, but are not limited to, the following:

Number of Cardholders (note this number may fluctuate)

Number of Approving Officials (note this number may fluctuate and includes alternates)

Other Users (managers, other approvers)

Average number of transaction/requests per month

900 1700 1000 7,000

2 Background

The Department of Homeland Security (DHS), Immigration and Customs Enforcement (ICE), Office of Acquisition Management (OAQ) has a need for a commercial off the shelf (COTS) Automated Purchase Card Approval System. The solution must provide an automated, paperless purchase card approval processing system with customizable options.

DHS Purchase Card Policy requires cardholders to complete a purchase card worksheet prior to placing an order. The process is manual and often labor intensive, leading to unnecessary administrative cost. This requirement is intended to reduce the manual effort, using an automated processing solution that provides paperless approvals, routing, policy compliance, and audit readiness capabilities.

With an automated purchase card worksheet solution, the purchase card program can efficiently manage cost, streamline audit requirements, and provide stakeholders with additional oversight over the program. An automated solution will be used to assist with mitigating risks associated with the program.

3 Scope

The scope of this SOW is to provide a COTS solution that supports the number of users outlined in Section 1 and meets all the following minimum requirements:

o Paperless – The system must be a paperless, automated enterprise procurement system for purchase card (credit card) requests.

o Form – The system must have a fillable request form that routes for approvals. DHS has a form (DHS Form 1501) that must be used as the request (see Section 21 form example). The system must be dynamic and able to allow for customizing new fields when/if necessary, without incurring additional charges or fees.

o Routing – The system must route requests for review and approvals. The approvals route through a minimum of four (4) individuals (Cardholder, Funding Official, Approving Official, third-party Receiver). However, the approvals may include additional individuals (Property Custodian, Local Field Office). Therefore, the solution must include functionality to include additional approvals.

o Hierarchy – The system should be capable of integrating with agency’s bank hierarchy structure. The hierarchy structure will be provided to the awardee after contract award.

o Visibility – The system must provide access to designated purchase card managers over all transaction documentation. The access will provide managers the ability to retrieve information and documents related to transactions. The access must provide robust search capabilities. Search options include by:

Cardholder Approving Official Merchant Amount of request Description of items/service Date of transaction o Establish Rules – The system must provide established rules to comply with Federal

Acquisition Regulation (FAR), DHS and ICE Purchase Card policies/procedure. The system must be flexible to incorporate new rules. Rules will be provided to the awardee. Although not all inclusive, rules may include but are not limited to the following:

Separation of Duties for review and approvals.

Tracking that shows approval and routing dates, comments, and changes to the request.

Reminder notification for recurring expenses; reminding the user to obtain approvals.

All requests must have supporting documentation. Reminders/alerts must be incorporated to ensure users attach supporting documentation to their requests.

Reminder notification to close out requests timely. This includes capturing the third-party receiver’s signature.

Email notification to the individuals in the routing process when the request is in their que for approval/signature.

o Accessibility – The system must allow accessibility of documents from any location via computer, smart phone or other.

o Retention - Document must be accessible for a period of 6 years from the transaction date.

o Reporting – The system must have reporting capabilities to include, but not limited to:

Track spending Track users Track pending requests Socio-economic spend Custom reports Track merchants/vendors Track details on items purchases (example: uniforms, cable service, etc.)

o Search Function – The system must have a search function that allows purchase card managers to search for specific information. Example: Search for amount, card holder name, merchant, product.

o Matching – The system must be able to match bank’s transaction report to an approved document, matching between the request/DHS 1501, receiver, and invoice. 3-Way matching capability between request, receiving signature, and invoice.

o Reconciliation and Document close out – The system must be capable of importing purchase card data from the agency’s servicing bank’s system (currently Citimanager) at any time. The data must be auto-matched to purchasing and invoice data and presented to the purchase card holders to allow them to match transactions and close out active requests.

o Auditing – The system should have the functionality to provide various alerts to the administrator and purchase card holders of potential audit flags that should be reviewed.

Audit flags may include, but are not limited to, audit test attributes such as taxes were charged. The audit test attributes will be provided to the awardee.

o Receiving – The system must allow for partial receipt as well as full receipt of order.

o Catalog – The system should have “punch out” capability allowing the user to access merchant catalogs that have been approved by the agency administrator. The system should also have the capability of loading catalogs and/or spreadsheets with approved items.

Catalog searches should enable comparison shopping, and comparison supporting documentation must be automatically attached to the purchase request when desired.

Integration – The system must provide an integrated e-commerce shopping experience for requestors to include catalogs, punch out to vendor’s websites and manual requests.

Favorites – The system must allow users to create a favorites list which integrates with (catalogs, punch outs and manual requests) o Financial – The system should provide financial tracking capabilities and be customizable.

The tracking may include the ability to enter a beginning balance and draw down from that balance. The system does not interface with ICE’s financial system. Therefore, the tracking should be an option available to the user if they choose to use the functionality.

o Printing/Download – The system must allow users and administrators to print and/or download all documentation.

Printing/downloading one request – The system must be capable of generating a consolidated document output that includes the DHS Form 1501 and all attachments into one document; this should be a click and print ability.

Printing/downloading multiple request – The system should have the ability to print multiple requests with associated attachments via a batch printing/download capability.

o Support – The vendor must provide customer support to agency users. This includes assistance with the system and any updates to the system deemed necessary by the administrator.

o Access – The system must have restricted access to approved ICE personnel. Any other access to ICE documentation must be approved by the administrator via written request.

o Logging – The system must have the capability to log user access and action.

o Training – The vendor must provide user training. The training shall be provided to the administrators as a train-the-trainer type of training. This will allow the administrator to deliver training that aligns with other training requirements. In addition, the vendor must provide a recorded how-to video and a how-to manual.

4 Objectives, Requirements, and Deliverables

The Contractor shall provide a solution that meets or exceeds the minimum requirements as outlined in Section 3, supports the approximate number of users outlined in Section 1, and satisfies any other requirements outlined in the SOW and/or Attachment 2 – Terms and Conditions. The Base Year (shown in Section 5 Period of Performance) will be a pilot year in which the system will be analyzed to ensure that it meets the minimum requirements of the agency and can support all users. The goal is to increase the oversight of the program, increase audit compliance rates and provide a user-friendly forum. Additionally, the Contractor shall provide all deliverables as described in the below Deliverables Table.

The Contractor shall attend a Post Award Conference with the Contracting Officer, COR, and all other applicable Government stakeholders no later than five (5) business days after the date of contract award. The purpose of the Post Award Conference, which will be chaired by the COR, is to discuss technical and contracting objectives of this contract and review the Contractor's draft project plan for comments/finalization. The Post Award Conference will be held at virtually via Microsoft TEAMS.

The Contractor shall provide a draft Project Plan at the Post Award Conference for the Government’s review and comment. The Contractor shall provide a final Project Plan to the Contracting Officer’s Representative (COR) no later than ten (10) business days after the Post Award Conference.

The Project Plan shall address, at a minimum:

• The Contractor’s overall approach to management of the task.

• The roles and responsibilities of team members.

• A timeline to fulfill all deliverables and deliver a fully functioning solution that has been integrated, tested, and approved by all applicable ICE personnel. The timeline shall include any expected coordination with the ICE Office of the Chief Information Officer (OCIO) specific to ATOs or any other IT security requirements.

• Training schedule with description of training content and materials.

All deliverables shall be prepared in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows and Microsoft Office Applications) as applicable. Deliverables shall be delivered electronically to the COR/technical representative by the close of business Central Time (CT), unless otherwise stated in the Deliverable Table. In the event the Contractor anticipates difficulty in complying with any deliverable, the Contractor shall provide written notification immediately to the COR and government PM. Each notification shall give pertinent details, including the date by which the Contractor expects to make delivery.

The COR and/or PM will review deliverables prior to acceptance and provide the contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR/technical representative will send an e-mail to the Contractor notifying it that the deliverable has been accepted. The COR/PM will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the SOW and/or Contractor’s proposal. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions. The Contractor shall have ten (10) business days to make corrections and redeliver. The Contractor shall immediately inform the COR if unable to meet the resubmission deadline.

Acceptance by the Government of satisfactory products/services will be made once all the terms, conditions and requirement in this SOW are fulfilled including the following delivery requirements:

Deliverables Table

Item SOW Reference(s)

Deliverables Due Date Distribution

1 4 Post Award Conference 5 Days After Award CO, COR, PM 2 4 Draft Project Plan 5 Days After Award CO, COR, PM 3 4 Final Project Plan 10 Days After Post

Award Conference

CO, COR, PM

4 3 & 4 Fully functioning Government approved PCARD Solution

3 Months After Date of Award

COR, PM, ICE

IT Personnel as Applicable

5 3 Training Materials 2 Weeks After Delivery of Government Approved PCARD Solution

COR, PM

4.1 Government Furnished Information

The Government will provide information/documents to the contractor to meet the requirements of this SOW. Documents may include member’s list, bank hierarchy structure, object class codes, punch out merchant shopping information and any other documents within the scope of the contract. The contractor shall coordinate with the Contracting Officer’s Representative (COR) to obtain requested documents.

5 Place and Period of Performance

The primary place of performance will be at Contractor’s facility. The period of performance will consist of a twelve (12) month Base Period and four (4), twelve (12) month Option Periods.

The Government is not obligated to exercise the optional periods of performance. It will be the Government’s unilateral right to exercise the option years. Once the option is exercised, the Contractor is required to perform/deliver all services and/or requirements when ordered during the scheduled period of performance of this contract.

6 Compliance Requirements

The solution will be housed on the merchant’s host site with secure access for users. The solution will not interface with the Government’s servers. Any Personal Identifiable Information

(PII) must remain secure. PII is defines as: any representation of information that permits the identity of the individual to whom the information applies to be reasonably inferred by either direct or indirect means.

7 Government Roles and Responsibilities

The following personnel will oversee and coordinate surveillance activities.

7.1 Contracting Officer (CO)

The CO will ensure performance of all necessary actions for effective contracting, ensure compliance with the contract terms, and will safeguard the interests of the United States in the contractual relationship. The CO will also assure that the contractor receives impartial, fair, and equitable treatment under this contract. The CO is ultimately responsible for the final determination of the adequacy of the contractor’s performance.

7.2 Contracting Officer’s Representative (COR)

The COR is responsible for technical administration of the contract and will assure proper government surveillance of the contractor’s performance. The COR provides technical direction to the Contractor within the scope of the contract. The COR will provide requested documents to meet the objective of the contract. The COR is not authorized to alter the contract’s terms or conditions. Such changes must be authorized by the Contracting Officer in a written modification to the contract.

8 Travel

There will be no contractor travel in performance of this contract. No travel will be reimbursed.

9 Privacy and Records Requirements

All records received, created, used, and maintained by the contractor for this effort shall be protected as sensitive data, in accordance with government laws, to include the FAR, Part 24, Protection of Privacy and Freedom of Information, and shall be returned and provided to the government upon contract completion.

All data created for government use and delivered to or falling under the legal control of the government are federal records and shall be managed in accordance with records management legislation as codified at 44 U.S.C. Chapters 21, 29, 31, and 33, the Freedom of Information Act (5 U.S.C. 552), and the Privacy Act (5 U.S.C. 552a), and shall be scheduled for disposition in accordance with 36 CFR 1228.

As prescribed in FAR 24.104, under the Privacy Act Notification Clause (Apr 1984), the contractor shall comply with clauses 52.224-1 and 52.224-2. Clause 52.224-1 specifically states that when the design, development, or operation of a system of records on individuals is required to accomplish an agency function, the contractor will be required to design, develop, or operate a system of records on individuals to accomplish an agency function subject to the Privacy Act of 1974, Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Act may involve the imposition of criminal penalties.

Clause 52.224-2

The contractor agrees to-

Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies the systems of records and the design, development, or operation work that the contractor is to perform

a. Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work stated in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and

b. Include this clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a system or records.

In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency.

a. "Operation of a system of records," as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records.

b. Record," as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person's name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voiceprint or a photograph.

c. "System of records on individuals," as used in this clause, means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.

All contractor employees for this effort will also be required to sign a Non-disclosure statement, Acknowledgement and Agreement Handling Sensitive Government Data and Other Government Property and are subject to the security requirements of the SOW. This form will be signed prior to beginning work for this effort.

Privacy Requirements For Contractor And Personnel

In addition to FAR 52.224-1 Privacy Act Notification (APR 1984), 52.224-2 Privacy Act (APR 1984), FAR 52.224-3 Privacy Training (JAN 2017), and HSAR Clauses, the following instructions must be included in their entirety in all contracts.

Limiting Access to Privacy Act and Other Sensitive Information

In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984), and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DHS system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.dhs.gov/system-records-notices-sorns. Applicable SORNS of other agencies may be accessed through the agencies’ websites or by searching GovInfo, available at https://www.govinfo.gov that replaced the FDsys website in December 2018. SORNs may be updated at any time.

Prohibition on Performing Work Outside a Government Facility/Network/Equipment

The Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or Workplace as a Service (WaaS) if WaaS is authorized by the statement of work. Government information shall remain within the confines of authorized Government networks at all times. Except where telework is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of telework authorizations.

Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract.

The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

Separation Checklist for Contractor Employees https://www.dhs.gov/system-records-notices-sorns https://www.govinfo.gov/

Contractor shall complete a separation checklist before any employee or Subcontractor employee terminates working on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposal of sensitive personally identifiable information (PII), in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to sensitive PII.

In the event of adverse job actions resulting in the dismissal of an employee or Subcontractor employee, the Contractor shall notify the Contracting Officer’s Representative (COR) within 24 hours. For normal separations, the Contractor shall submit the checklist on the last day of employment or work on the contract.

As requested, contractors shall assist the ICE Point of Contact (ICE/POC), Contracting Officer, or COR with completing ICE Form 50-005/Contractor Employee Separation Clearance Checklist by returning all Government-furnished property including but not limited to computer equipment, media, credentials and passports, smart cards, mobile devices, PIV cards, calling cards, and keys and terminating access to all user accounts and systems.

Contractor’s Commercial License Agreement and Government Electronic Information Rights

Except as stated in the Statement of Work and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases) and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and are considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

Privacy Lead Requirements

If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy documentation, the Contractor shall assign or procure a Privacy Lead, to be listed under the SOW required Contractor Personnel section. The Privacy Lead shall be responsible for providing adequate support to DHS to ensure DHS can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance. The Privacy Lead shall work with personnel from the program office, the ICE Privacy Unit, the Office of the Chief Information Officer, and the Records and Data Management Unit to ensure that the privacy documentation is kept on schedule, that the answers to questions in the PIA are thorough and complete, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.

The Privacy Lead:

Must have excellent writing skills, the ability to explain technology clearly for a non-technical audience, and the ability to synthesize information from a variety of sources.

Must have excellent verbal communication and organizational skills.

Must have experience writing PIAs. Ideally the candidate would have experience writing PIAs for DHS.

Must be knowledgeable about the Privacy Act of 1974 and the E-Government Act of 2002.

Must be able to work well with others.

If a Privacy Lead is already in place with the program office and the contract involves IT system builds or substantial changes that may require privacy documentation, the requirement for a separate Private Lead specifically assigned under this contract may be waived provided the Contractor agrees to have the existing Privacy Lead coordinate with and support the ICE Privacy POC to ensure privacy concerns are proactively reviewed and so ICE can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance if required. The Contractor shall work with personnel from the program office, the ICE Office of Information Governance and Privacy, and the Office of the Chief Information Officer to ensure that the privacy documentation is kept on schedule, that the answers to questions in any privacy documents are thorough and complete, that all records management requirements are met, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.

10 Security and Cyber Security Requirements

SENSITIVE /BUT UNCLASSIFED (SBU) CONTRACTS SECURITY REQUIREMENTS

GENERAL

The United States Immigration and Customs Enforcement (ICE) has determined that performance of the tasks as described in Contract TBD requires that the Contractor, subcontractor(s), vendor(s), etc. (herein known as Contractor) have access to sensitive DHS information, and that the Contractor will adhere to the following.

PRELIMINARY FITNESS DETERMINATION

ICE will exercise full control over granting, denying, withholding or terminating unescorted government facility and/or sensitive Government information access for contractor employees, based upon the results of a Fitness screening process. ICE may, as it deems appropriate, authorize and make a favorable expedited preliminary Fitness determination based on preliminary security checks. The preliminary Fitness determination will allow the contractor employee to commence work temporarily prior to the completion of a Full Field Background Investigation. The granting of a favorable preliminary Fitness shall not be considered as assurance that a favorable final Fitness determination will follow as a result thereof. The granting of preliminary Fitness or final Fitness shall in no way prevent, preclude, or bar the withdrawal or termination of any such access by ICE, at any time during the term of the contract. No employee of the Contractor shall be allowed to enter on duty and/or access sensitive information or systems without a favorable preliminary Fitness determination or final Fitness determination by the Office of Professional Responsibility (OPR), Personnel Security. No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable preliminary Fitness determination or final Fitness determination by OPR Personnel Security. Contract employees are processed under DHS Instruction 121-01-007-001 (Personnel Security, Suitability and Fitness Program), or successor thereto; those having direct contact with Detainees will also have 6 CFR § 115.117 considerations made as part of the Fitness screening process. (Sexual Abuse and Assault Prevention Standards) implemented pursuant to Public Law 108-79 (Prison Rape Elimination Act (PREA) of 2003)

BACKGROUND INVESTIGATIONS

Contractor employees (to include applicants, temporaries, part-time and replacement employees) under the contract, needing access to sensitive information and/or ICE Detainees, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract.

The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. Background investigations will be processed through OPR Personnel Security. Contractor employees nominated by a Contracting Officer Representative for consideration to support this contract shall submit the following security vetting documentation to OPR Personnel Security, through the Contracting Officer Representative (COR), within 10 days of notification by OPR Personnel Security of nomination by the COR and initiation of an Electronic Questionnaire for Investigation Processing (e-QIP) in the Office of Personnel Management (OPM) automated on-line system.

1. Standard Form 85P (Standard Form 85PS (With supplement to 85P required for armed positions)), “Questionnaire for Public Trust Positions” Form completed on-line and archived by the contractor employee in their OPM e-QIP account.

2. Signature Release Forms (Three total) generated by OPM e-QIP upon completion of Questionnaire (e-signature recommended/acceptable – instructions provided to applicant by OPR Personnel Security). Completed on-line and archived by the contractor employee in their OPM e-QIP account.

3. Two (2) SF 87 (Rev. December 2017) Fingerprint Cards. (Two Original Cards sent via COR to OPR Personnel Security)

4. Foreign National Relatives or Associates Statement. (This document sent as an attachment in an e-mail to contractor employee from OPR Personnel Security – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

5. DHS 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act” (This document sent as an attachment in an e-mail to contractor employee from OPR Personnel Security – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

6. Optional Form 306 Declaration for Federal Employment (This document sent as an attachment in an e-mail to contractor employee from OPR Personnel Security – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

7. If occupying PREA designated position: Questionnaire regarding conduct defined under 6 CFR § 115.117 (Sexual Abuse and Assault Prevention Standards) (This document sent as an attachment in an e-mail to contractor employee from OPR Personnel Security – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

8. One additional document may be applicable if contractor employee was born abroad. If applicable, additional form and instructions will be provided to contractor employee. (If applicable, the document will be sent as an attachment in an e-mail to contractor employee from OPR Personnel Security – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

Contractor employees who have an adequate, current investigation by another Federal Agency may not be required to submit complete security packages; the investigation may be accepted under reciprocity. The questionnaire related to 6 CFR § 115.117 listed above in item 7 will be required for positions designated under PREA.

An adequate and current investigation is one where the investigation is not more than five years old, meets the contract risk level requirement, and applicant has not had a break in service of more than two years. (Executive Order 13488 amended under Executive Order 13764/DHS Instruction 121-01-007-01)

Required information for submission of security packet will be provided by OPR Personnel Security at the time of award of the contract. Only complete packages will be accepted by the OPR Personnel Security as notified by the COR.

To ensure adequate background investigative coverage, contractor employees must currently reside in the United States or its Territories. Additionally, contractor employees are required to have resided within the Unites States or its Territories for three or more years out of the last five (ICE retains the right to deem a contractor employee ineligible due to insufficient background coverage). This time-line is assessed based on the signature date of the standard form questionnaire submitted for the applied position. Contractor employees falling under the following situations may be exempt from the residency requirement: 1) work or worked for the U.S. Government in foreign countries in federal civilian or military capacities; 2) were or are dependents accompanying a federal civilian or a military employee serving in foreign countries so long as they were or are authorized by the U.S. Government to accompany their federal civilian or military sponsor in the foreign location; 3) worked as a contractor employee, volunteer, consultant or intern on behalf of the federal government overseas, where stateside coverage can be obtained to complete the background investigation; 4) studied abroad at a U.S.

affiliated college or university; or 5) have a current and adequate background investigation (commensurate with the position risk/sensitivity levels) completed for a federal or contractor employee position, barring any break in federal employment or federal sponsorship.

Only U.S. Citizens and Legal Permanent Residents are eligible for employment on contracts requiring access to DHS sensitive information unless an exception is granted as outlined under DHS Instruction 121-01-007-001. Per DHS Sensitive Systems Policy Directive 4300A, only U.S. citizens are eligible for positions requiring access to DHS Information Technology (IT) systems or positions that are involved in the development, operation, management, or maintenance of DHS IT systems, unless an exception is granted as outlined under DHS Instruction 121-01-007-001.

TRANSFERS FROM OTHER DHS CONTRACTS:

Contractor employees may be eligible for transfer from other DHS Component contracts provided they have an adequate and current investigation meeting the new assignment requirement. If the contractor employee does not meet the new assignment requirement a DHS 11000-25 with ICE supplemental page will be submitted to OPR Personnel Security to initiate a new investigation.

Transfers will be accomplished by submitting a DHS 11000-25 with ICE supplemental page indicating “Contract Change.” The questionnaire related to 6 CFR § 115.117 listed above in item 7 will be required for positions designated under PREA.

CONTINUED ELIGIBILITY

ICE reserves the right and prerogative to deny and/or restrict facility and information access of any contractor employee whose actions conflict with Fitness standards contained in DHS Instruction 121-01-007-01, Chapter 3, paragraph 6.B or who violate standards of conduct under 6 CFR § 115.117. The Contracting Officer or their representative can determine if a risk of compromising sensitive Government information exists or if the efficiency of service is at risk and may direct immediate removal of a contractor employee from contract support. The OPR Personnel Security will conduct periodic reinvestigations every 5 years, or when derogatory information is received, to evaluate continued Fitness of contractor employees.

REQUIRED REPORTS

The Contractor will notify OPR Personnel Security, via the COR, of all terminations/resignations of contractor employees under the contract within five days of occurrence. The Contractor will return any expired ICE issued identification cards and building passes of terminated/ resigned employees to the COR. If an identification card or building pass is not available to be returned, a report must be submitted to the COR referencing the pass or card number, name of individual to whom issued, the last known location and disposition of the pass or card. The COR will return the identification cards and building passes to the responsible ID Unit.

The Contractor will report any adverse information coming to their attention concerning contractor employees under the contract to the OPR Personnel Security, via the COR, as soon as possible. Reports based on rumor or innuendo should not be made. The subsequent termination of employment of an employee does not obviate the requirement to submit this report. The report shall include the contractor employees’ name and social security number, along with the adverse information being reported.

The Contractor will provide, through the COR a Quarterly Report containing the names of contractor employees who are active, pending hire, have departed within the quarter or have had a legal name change (Submitted with documentation). The list shall include the Name, Position and SSN (Last Four) and should be derived from system(s) used for contractor payroll/voucher processing to ensure accuracy.

CORs will submit reports to psu-industrial-security@ice.dhs.gov

Contractors, who are involved with management and/or use of information/data deemed “sensitive” to include ‘law enforcement sensitive” are required to complete the DHS Form 11000-6-Sensitive but Unclassified Information NDA for contractor access to sensitive information. The NDA will be administered by the COR to the all contract personnel within 10 calendar days of the entry on duty date. The completed form shall remain on file with the COR for purpose of administration and inspection.

Sensitive information as defined under the Computer Security Act of 1987, Public Law 100-235 is information not otherwise categorized by statute or regulation that if disclosed could have an adverse impact on the welfare or privacy of individuals or on the welfare or conduct of Federal programs or other programs or operations essential to the national interest. Examples of sensitive information include personal data such as Social Security numbers; trade secrets; system vulnerability information; pre-solicitation procurement documents, such as statements of work;

and information pertaining to law enforcement investigative methods; similarly, detailed reports related to computer security deficiencies in internal controls are also sensitive information because of the potential damage that could be caused by the misuse of this information. All sensitive information must be protected from loss, misuse, modification, and unauthorized access in accordance with DHS Management Directive 11042.1, DHS Policy for Sensitive Information and ICE Policy 4003, Safeguarding Law Enforcement Sensitive Information.”

Any unauthorized disclosure of information should be reported to ICE.ADSEC@ICE.dhs.gov.

SECURITY MANAGEMENT

The Contractor shall appoint a senior official to act as the Corporate Security Officer. The individual will interface with the OPR Personnel Security through the COR on all security matters, to include physical, personnel, and protection of all Government information and data accessed by the Contractor.

The COR and the OPR Personnel Security shall have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements under this contract. Should the COR determine that the Contractor is not complying with the security requirements of this contract, the Contractor will be informed in writing by the Contracting Officer of the proper action to be taken in order to effect compliance with such requirements.

INFORMATION TECHNOLOGY SECURITY CLEARANCE

When sensitive government information is processed on Department telecommunications and automated information systems, the Contractor agrees to provide for the administrative control of sensitive data being processed and to adhere to the procedures governing such data as outlined in DHS MD 4300.1, Information Technology Systems Security. or its replacement. Contractor employees must have favorably adjudicated background investigations commensurate with the defined sensitivity level.

Contractor employees who fail to comply with Department security policy are subject to having their access to Department IT systems and facilities terminated, whether or not the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g., Privacy Act).

INFORMATION TECHNOLOGY SECURITY TRAINING AND OVERSIGHT

In accordance with Chief Information Office requirements and provisions, all contractor employees accessing Department IT systems or processing DHS sensitive data via an IT system will require an ICE issued/provisioned Personal Identity Verification (PIV) card. Additionally, Cybersecurity Awareness Training (CSAT) will be required upon initial access and annually thereafter. CSAT training will be provided by the appropriate component agency of DHS.

Contractor employees, who are involved with management, use, or operation of any IT systems that handle sensitive information within or under the supervision of the Department, shall receive periodic training at least annually in security awareness and accepted security practices, systems rules of behavior, to include Unauthorized Disclosure Training, available on PALMS or by contacting ICE.ADSEC@ICE.dhs.gov. Department contractor employees, with significant security responsibilities, shall receive specialized training specific to their security responsibilities annually. The level of training shall be commensurate with the individual’s duties and responsibilities and is intended to promote a consistent understanding of the principles and concepts of telecommunications and IT systems security.

All personnel who access Department information systems will be continually evaluated while performing these duties. System Administrators should be aware of any unusual or inappropriate behavior by personnel accessing systems. Any unauthorized access, sharing of passwords, or other questionable security procedures should be reported to the local Security Office or Information System Security Officer (ISSO).

Compliance with DHS Security Policy Terms and Conditions:

All hardware, software, and services provided under this Statement of Work must be compliant with DHS 4300A DHS Sensitive System Policy and DHS 4300A Sensitive Systems Handbook.

Security Review Terms and Conditions

The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford ICE, including the organization of ICE Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer’s Representative (COR), and other government oversight organizations, access to the Contractor's facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor will contact ICE Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to ICE. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of ICE data or the function of computer system operated on behalf of ICE, and to preserve evidence of computer crime.

Supply Chain Risk Management Terms and Conditions

The Contractors supplying the Government hardware and software shall provide the manufacturer's name, address, state and/or domain of registration, and the Data Universal Numbering System (DUNS) number for all components comprising the hardware and software.

If subcontractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNs number of those suppliers must also be provided.

Subcontractors are subject to the same general requirements and standards as prime contractors.

Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.

The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.

Contractors shall provide, implement, and maintain a Supply Chain Risk Management Plan that addresses internal and external practices and controls employed to minimize the risk posed by counterfeits and vulnerabilities in systems, components, and software.

The Plan shall describe the processes and procedures that will be followed to ensure appropriate supply chain protection of information system resources developed, processed, or used under this contract.

The Supply Chain Risk Management Plan shall address the following elements:

(i) How risks from the supply chain will be identified;

(ii) What processes and security measures will be adopted to manage these risks to the system or system components; and

(iii) How the risks and associated security measures will be updated and monitored.

The Supply Chain Risk Management Plan shall remain current through the life of the contract or period of performance. The Supply Chain Risk Management Plan shall be provided to the Contracting Officer Representative (COR/CO) 30 days post award.

The Contractor acknowledges the Government's requirement to assess the Contractors Supply Chain Risk posture. The Contractor understands and agrees that the Government retains the right to cancel or terminate the contract, if the Government determines that continuing the contract presents a risk to national security.

The Contractor shall disclose, and the Government will consider, relevant industry standard certifications, recognitions and awards, and acknowledgments.

The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the CO. Contractors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.

The Contractor shall be excused from using new OEM (i.e. "grey market, "previously used) components only with formal Government approval. Such components shall be procured from their original source and have them shipped only from manufacturers authorized shipment points.

For software products, the contractor shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “end of life"). Software updates and patches must be made available to the government for all products procured under this contract.

Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.

All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the contract, the period of performance, or one calendar year from the date the activity occurred.

These records must be readily available for inspection by any agent designated by the U.S.

Government as having the authority to examine them.

This transit process shall minimize the number of times en route components undergo a…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .