1.1.4 Florida Direct Lease PWS_Final_12NOV24.pdf
PDF 319 KB Posted
- Attached to
- Florida Direct Lease Request for Quote No. 70FBR425Q00000037 Federal contract opportunity
- Solicitation number
- 70FBR425Q00000037
- Issued by
- Federal Emergency Management Agency
About this file
This document is a Performance Work Statement (PWS) for a Federal Emergency Management Agency (FEMA) Direct Lease program in the state of Florida. The purpose of the requirement is to establish a Blanket Purchase Agreement (BPA) with contractors who have furnished 1-4 bedroom rental units available throughout designated counties in Florida. The contractor shall identify, inspect, and provide properties that meet HUD housing quality standards for FEMA to match with eligible disaster applicants. FEMA will provide the contractor with applicant information and coordinate the lease execution and move-in process. The contractor is responsible for all property management services including maintenance, utilities, and terminations. The PWS outlines the specific service requirements, deliverables, quality assurance, and contract administration details. The related federal contract opportunity is a Request for Quote (RFQ) solicitation to establish the Direct Lease BPA.
View the file
Other files for this federal contract opportunity
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
FLORIDA DIRECT LEASE PROPERTY MANAGEMENT
UNITED STATES DEPARTMENT OF HOMELAND SECURITY
FEDERAL EMEGENCY MANAGEMENT AGENCY (FEMA)
November 12, 2024
I. PURPOSE.
The Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA) has a requirement for Direct Lease Contractor(s) in the State of Florida. The FEMA Direct Lease program is a housing assistance program to rent existing rental units for the purpose of providing temporary housing to eligible applicants who are displaced due to the Presidentially declared major disaster in the
State of Florida. Note: The term Contractor will be used to refer to the Property Management company from this point on.
II. SCOPE.
The purpose of this requirement is to establish a Blanket Purchase Agreement (BPA) in accordance with the Federal Acquisition Regulation (FAR) Part 13, with the Contractor who have in their portfolio furnished 1-, 2-, 3-, and 4-bedroom rental units throughout the State of Florida. Currently, the units are required in the following counties: Citrus, Columbia, Dixie, Hamilton, Hernando, Lafayette, Levy, Madison, Okeechobee, Pasco, Pinellas, Suwannee, and Taylor. The Contractor shall provide for
FEMA’s consideration their list of all rental units they currently have available that meet FEMA’s needs. This includes existing furnished turn-key residential properties for lease (e.g., corporate apartments, vacation rentals, and second homes), (single family and multiple occupancy), or any other type of residential property accepted by FEMA. The Contractor shall provide FEMA a detailed daily report of current inventory that shows the status of each unit, and an electronic notification each time a new property becomes available for consideration. Reference Sample Direct Lease Daily Property
Tracker Sheet (PWS Attachment 2).
The Contractor and FEMA shall evaluate each property to ensure the property is safe, secure, sanitary, and functional. Safe means secure from hazards or threats to occupants. Sanitary means free of health hazards. Functional means an item or home capable of being used for its intended purpose. The following items are services to be performed by the Contractor for the Direct Lease
Agreements and associated Contracts:
1. Identify Properties. The Contractor shall only rent existing residential property.
a. The Contractor may only rent properties that comply with federal, state, and local occupancy standards, to provide complete and independent living facilities for one or more persons, including permanent provisions for living, sleeping, cooking, and sanitation. All utilities, appliances, and furnishings provided with the property must be safe and functional.
b. The Contractor shall prioritize properties that include accessibility features or can easily be conformed to accessible requirements without requiring FEMA to remove the improvements at the end of rental agreement; and are in proximity to accessible public transportation, schools, fire and emergency services, grocery stores, and health care services.
c. The monthly rent cost per unit may not exceed the amounts established by the U. S
Department of Housing and Urban Development (HUD), unless an increase is approved by the Contracting Officer (CO). Reference FY 2025 Fair Market Rent
(PWS Attachment 3) document for current (FY 2025) HUD rates per Florida counties. Reference Figure 1 below for County sample.
d. If required, the Government may establish a contract line item for one (1) month security deposit not-to-exceed one (1) month rent. The security deposit will be held by the Government in the event any damages (other than normal wear and tear) occur and will be invoiced based on the actual costs of damages verified between the Government and the Contractor. All damages above the cost of one month’s rent shall be the responsibility of the Contractor and/or tenant (FEMA applicant).
e. The Contractor shall implement and update a tracking spreadsheet for approved properties throughout the Direct Lease process. The tracking system must be approved by the Contracting Officer’s Representative (COR) prior to implementation. An example is provided at PWS Attachment 2 – Sample Direct
Lease Property Tracking Sheet.
Figure 1 - Maximum Monthly Rent FY2025 Fair Market Rent
FMR 1 BR 2 BR 3 BR 4BR
Citrus $951 $1,198 $1,679 $2,012
Columbia $820 $1,076 $1,305 $1,427
Dixie $711 $933 $1,195 $1,247
Hamilton $811 $933 $1,242 $1,247
Hernando $1,686 $1,978 $2,533 $3,082
Lafayette $885 $1,018 $1,226 $1,360
Levy $855 $989 $1,281 $1,358
Madison $811 $933 $1,152 $1,336
Okeechobee $848 $1,112 $1,364 $1,558
Pasco $1,686 $1,978 $2,533 $3,082
Pinellas $1,686 $1,978 $2,533 $3,082
Suwannee $810 $933 $1,178 $1,341
Taylor $811 $933 $1,298 $1,539
2. Property Inspections. The Contractor and FEMA shall inspect each property to ensure compliance with HUD’s Housing Quality Standards (HQS) and with Federal, State, and local occupancy standards prior to executing lease agreements with the housing applicants. Each inspection will also verify property owner’s capability to provide all property management services, including building maintenance. A copy of the Contractor signed inspection record confirming the property complies with Federal, State, and local occupancy standards; Direct Lease Property Inspection Checklist (HUD) (PWS Exhibit 3) is required at the end of the inspection and prior to contract award.
3. Contacting Applicants. FEMA will identify eligible applicants for the Direct
Lease program and may provide the following applicant information to Contractor:
applicant name, co-applicant names (if applicable), damage dwelling address, mailing address, and phone numbers, and e-mail addresses.
4. Matching Applicants. Once units are reported as available by the Contractor, FEMA will contact the applicant and coordinate with them to match the Direct Lease unit that fits the needs of the applicant. FEMA will also inform each applicant of the next steps towards their placement in a Direct Lease Unit, such as having a background check for properties that require it.
a. If a background check is required, the Contractor shall notify FEMA within one
(1) day in each instance regarding an applicant being denied due to adverse information in their background check. FEMA will prioritize properties that do not have a background check requirement for inclusion in the program.
5. Execute Lease Agreements. The Contractor shall complete and execute lease agreements with FEMA’s applicants through completion of the following documents within three (3) business days of completion. The Contractor shall provide the COR with the following documentation:
a. Sample Direct Lease Occupant Lease Agreement (PWS Exhibit 1)
b. Sample Direct Lease Contract Terms and Conditions (PWS Exhibit 2)
c. Direct Lease – Lease Addendum (PWS Exhibit 7)
d. And provide a copy of the lease agreement between the contractor and the property owner.
6. Move-in of Applicants (License-In). The Contractor and FEMA will be responsible for the move-in process for applicants into Direct Lease units. The Contractor and DHS-
FEMA shall conduct a walkthrough of the temporary housing unit with the applicant and ensure all the necessary paperwork is completed prior to completing a move-in.
a. A copy of the Sample Direct Lease Contract Terms and Conditions (PWS Exhibit
2)
b. A copy of the Sample Direct Lease Occupant Lease Agreement (PWS Exhibit 1);
and
c. A copy of the Temporary Housing Agreement (PWS Exhibit 4).
7. Lease Agreement Payments. FEMA shall make monthly rental payments to the
Contractor in accordance with the contract for each property that is awarded under the
BPA order according to the Contracting Officer approved price list, Individual BPA
Florida Direct Lease Price Listing (PWS Exhibit 5), and the terms negotiated by the
Contracting Officer and the Contractor for each unit.
8. Terminate Lease Agreements. FEMA will be responsible for any termination of assistance to applicants. The Contractor shall be responsible for eviction of applicants whose assistance has been terminated by FEMA. FEMA may terminate the lease for the housing unit by providing the Contractor with a written thirty (30) calendar day Notice to owner of FEMA Decision to Terminate Occupancy (PWS Exhibit 6).
9. Utilities. The cost of essential utilities (water/electricity/fuel) shall be included in a monthly rental rate established in the contract, as a Firm-Fixed price rate. Applicants will not be responsible for obtaining their own utility accounts and paying for utilities of any kind.
10. Maintenance and Other Services. All maintenance and services such as trash pickup, parking, lawn care, pest control, building maintenance, and storm preparations shall be the responsibility of the Contractor.
a. Emergency Repairs are repairs that resolve or mitigate the immediate threat or imminent danger to the health, safety, or security of the Unit Occupant and the
Unit/property, such as HVAC, water, electricity, and elevators not working properly. The COR shall be contacted within two (2) hours and work shall be initiated and completed within six (6) hours of work order receipt. Contractor shall place applicant(s) in alternative housing, if necessary, if repairs are not completed within sic (6) hours.
b. A complete emergency maintenance repair is defined as the imminent threat to life or property and is either completely repaired or temporarily repaired so that a permanent repair can be completed as regular maintenance.
c. In the event of a death in the Unit, the Contractor shall properly clean the Unit prior to another applicant being placed in the Unit, such as the proper biohazard clean up. The Contractor is responsible for securing the applicant’s personal belongings prior to the cleaning.
d. All Non-Emergency Repairs are repairs that are not an immediate threat or imminent danger to the health, safety, or security of the Unit Occupant and the
Unit/property. The COR shall be contacted within one (1) day and work shall be initiated and completed within three (3) days of work order receipt.
e. The Contractor shall submit a status report monthly which includes all maintenance issues.
11. Access and Functional Needs. A provision allowing the Contractor to make, at FEMA’s expense, reasonable modifications, or improvements to the property to provide a reasonable accommodation for an eligible applicant with a disability or other access or functional needs will be included in the BPA. All modifications or improvements will be coordinated with the COR, and the prior approval from the prior to the execution of work or incurrence of costs. All costs must be approved by the Contracting Officer and a Contract Line Item
Number (CLIN) established in the BPA order to track and pay this change.
III. INSPECTIONS.
1. All unit properties are subject to inspection by the FEMA and other applicable Government agencies. The Contractor shall participate by responding to all requests for information and inspection, or review findings by regulatory agencies. The Contractor shall allow the FEMA, or an entity or organization approved by the FEMA to conduct inspections of rental units, as required, to ensure an acceptable level of services and acceptable conditions of housing, as determined by the FEMA. No notice to the Contractor is required prior to an inspection. The
FEMA will share findings of the inspection with the Contractor. See Direct Lease Property
Inspection Checklist (HUD) (PWS Exhibit 3).
2. Prior to an applicant moving out, a joint inspection (FEMA and CONTRACTOR), to include pictures of the Unit and items in the Unit, will be conducted and any damage or missing items will be noted then. The Contractor has 30 calendar days from the move-out to file a claim for damages or for missing items.
IV. FURNISHED PROPERTY / TURNKEY IS DEFINED.
Unit Item Inventory Requirements. The Contractor shall do an inventory of each item they may want to file a replacement or damage claim on in a Unit at move out. No later than 30 calendar days after the scheduled FEMA move out inspection date, the Contractor shall submit any claims for damages and/or replacement of items above normal wear and tear. For Direct Lease units, the normal wear and tear period is for the one-year base period. Additional option periods beyond the one-year base period, shall only be accepted for destroyed items and shall not cover items listed in the living kit
(one time purchase items). Any claims made for damages shall be submitted with proof of damages and receipts of payment to a third party.
Prior to the move in of the FEMA applicant, the Contractor shall submit a completed Vendor Required
Unit Furnishing list of each item in the unit and provide the estimated replacement cost for the item.
Reference Vendor Required Unit Furnishing (PWS Attachment 5). At a minimum, the following items are required in each unit for the number of bedrooms per unit/hpusehold composition..
Items not listed on Vendor Required Unit Furnishing list will not be reimbursable.
1. At least 1 bed per bedroom (full size or larger)
2. At least 1 nightstand
3. One (1) dresser or built in or portable closet/wardrobe with hanger rod and shelves.
4. Curtains or Blinds or Shades for each window
5. Dining table with at least 4 chairs
6. Refrigerator
7. Cook top stove
8. Microwave
9. Water heater
10. One (1) Sofa
11. One (1) end table and 1 coffee table
12. One (1) or more AC Unit(s) suitable to adequately cool the entire unit
13. Weather Radio or TV
14. Living Kit (suitable for size of unit but minimum of 4 dining place settings – plates, bowls, cups, and glasses; 4 place settings silverware – fork, spoon, and knife; Cooking
Pots and Pans with lids; Cooking utensils; Bed-in-a-bag; 6-piece towel set; mattress cover, and all Safety equipment required by code/HUD housing standards i.e., Fire extinguisher, Smoke/Carbon Monoxide Detectors etc. The living kit will be part of the
Set-up Fee and not reimbursable for a missing item claim or for damages.
V. QUALITY ASSURANCE / QUALITY CONTROL PROVISIONS.
The Contractor is responsible for their quality control program. The Government will use their Quality
Assurance Surveillance Plan (QASP) to monitor the performance of the BPA order contract and quality of the services provided. The Contractor’s performance may be assessed in the Government’s Contractor
Performance Assessment Reporting System (CPARS).
Table 1. Deliverables and Performance Requirement Summary
# Deliverables DUE BY Performance Objective Performance Standards Performance
Threshold / Method of
Surveillance
1 Kick-off Meeting Minutes;
Progress Meeting Minutes
5 Days after meetings; submitted to COR
Contractor shall attend initial Kick-off meeting and
Progress Meetings.
PWS VI.1
At the Master BPA Agreement, Contractor shall meet with
FEMA for Kick-off meeting;
and progress meetings as required by the Contracting
Officer. The Contractor shall provide the meeting minutes within five business days after the meeting.
100% Compliance /
Deliverables
2 Direct Lease Property
Tracking document/website/Google
Drive
Daily by 7:30 AM local time;
submitted to the
COR
The Contractor shall provide detailed daily status reports of inventory and status of each unit.
PWS Attachment 2
At the Master BPA Agreement, Contractor shall implement and update a tracking spreadsheet for approved properties throughout the Direct Lease process.
100% Inspection /
Deliverables, complete
& accurate.
3 Training Privacy at DHS:
Protecting Personal Information
Training certificates – Within
30 days of Award and annually.
As stated in
Security Section
The Contractor shall provide proof of PPI training.
PWS - Information
Technology Security
Awareness Training (July
2023)
At the Master BPA Agreement, Contractor shall have all employees working with
Applicant’s PPI take the required training and submit certification to the COR.
100% of completed training certificates
4 Contractors and Consultants shall execute a DHS Form
11000-6, Sensitive but
Unclassified Information Non
Disclosure Agreement (NDA)
Prior to Award The Contractor shall provide completed DHS
Form 11000-6.
PWS - Information
Technology Security
Awareness Training (July
2023)
At the Master BPA Agreement, Contractor shall have all employees working with
Applicant’s PPI complete DHS
Form 11000-6 and submit certification to the COR.
100% Compliance
5 Available property listing.
Available units must meet
Property Inspection Checklist
(HUD) standards
With Proposal The Contractor shall ensure all units identified as available meets HUD standards.
At the Master BPA Agreement, Contractor shall ensure each property is in compliance with HUD’s Housing Quality
Standards (HQS) and with
Federal, State, and local occupancy standards prior to executing lease agreements with the housing applicants.
100% Compliance
CALL ORDERS
Threshold / Method of
Surveillance
6 Inspection Records, Direct
Lease Property Inspection
Checklist (HUD) standards
With Proposal The Contractor shall provide inspections and complete FEMA (HUD
Inspection Checklist)
PWS III
At the Call Orders, Contractor shall inspect each property to ensure compliance with
HUD’s Housing Quality
Standards (HQS) and with
Federal, State, and local occupancy standards prior to executing lease agreements with the housing applicants.
100% Compliance
7 Maintenance oversight reports Monthly The Contractor shall provide the COR with a monthly maintenance oversite report.
PWS II.10.e.
After Call Orders are issued and units are occupied the
Contractor will report to the
COR the status of units.
100% Inspection - COR will review each product for completeness & accuracy.
8 Incident Reports (If Any)
Management and/or corrective action report
3 days from the initial report.
The Contractor shall provide the COR with corrective action report for any Maintenance issues.
PWS II.10.d
After units are occupied
Contractor are to report any incident or maintenance request to the COR the status of units.
100% Inspection - COR will review each product for completeness & accuracy.
9 Executed lease agreements
(Includes: DL Contract and
Terms and Conditions, DL
Occupant Lease Agreement, Temporary Housing
Agreement, Direct Lease -
Lease Addendum)
Within one (1) day prior to LI
The Contractor shall provide completed and executed documents to
COR.
PWS II.5a,b,&c
Prior to Move-In Contractor will prepare and submit required documents to COR for review.
100% Inspection - COR will review each product for completeness & accuracy.
10 Invoices Monthly The Contractor shall submit monthly invoices for all Call Orders using SF
1034 – Public Voucher
(PWS Exhibit 4)
BPA – Invoice Section
After units are occupied
Contractor will submit monthly invoices.
100% Inspection - COR will review each product for completeness & accuracy.
11 Walkthrough report with pictures included with FEMA personnel – Contractor provided report/format
License In/Move
Out
The Contractor shall perform and submit walkthrough inspections for License-In and Move-
Out with pictures and submit to the COR
PWS II.6
At License-In and Move-Out
Contractor shall inspect property with FEMA personnel (IA Rep) and report inspections or issues to the
COR.
100% Inspection - COR will review each product for completeness & accuracy.
Threshold / Method of
Surveillance
12 Make sure Units meet/are:
1. HUD Housing Quality
Standards
2. Turnkey ready by
Vendor submitted availability date
3. Furnished per IA
Furniture requirements
4. Cleaned and made ready for re-occupancy after/when an applicant leaves a unit within the period of assistance
As required The Contractor shall comply with all occupancy requirements and report to COR any delays.
PWS II.2
Call Order - FEMA Use of the Rental Unit Terms and
Conditions
PWS IV
Call Order - FEMA Use of the Rental Unit Terms and
Conditions
As required Contractor will make sure units meet minimum HUD standards, are readily available, have required furnishings and made ready for re-occupancy when necessary.
100% Inspection - COR will review each product for completeness & accuracy.
13 Provide notices in timely manner.
1. Move out (72 hours)
2. Request for damages (30 days)
3. Lease violations (3 days)
Eviction Proceedings (3 days)
As required The Contractor shall provide all required notices in a timely manner as states in the PWS.
As required Contractor will submit all required reports to the COR.
100% Inspection - COR will review each product for completeness & accuracy.
14 Eviction/removal of Applicant handled according to FEMA standards
As required The Contractor shall execute all
Eviction/Removal of
Applicants.
Contractors are responsible for all eviction proceedings as required due to an applicant’s violation of program rules or end of the period of assistance
100% Inspection - COR will review each product for completeness & accuracy.
VI. GENERAL REQUIREMENTS.
1. KICK-OFF MEETING/PERIODIC PROGRESS MEETINGS
The Contractor agrees to attend a post award conference convened by the Contracting Officer, in accordance with Federal Acquisition Regulation (FAR) Subpart 42.5, within ten (10) business days after award, or the date established by the Contracting Officer. The Contracting Officer, COR, and other Government personnel, as appropriate, may meet periodically with the Contractor to review the Contractor's performance. At these meetings, the Contracting Officer will apprise the Contractor of how the Government views the Contractor's performance and the Contractor will apprise the
Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the Government, and the
Contractor shall provide minutes of the meeting within five (5) business days after the meeting.
2. PLACE OF PERFORMANCE
Florida – Within thirty (30) minutes to up to sixty (60) minutes commuting distance from the damaged dwelling, and that do not place an undue hardship on qualified disaster applicants. The
Government may adjust this requirement as needed, but not outside the State of Florida.
3. PERIOD OF PERFORMANCE
The period of performance (POP) for the master BPA is for five (5) years ordering period from the date of award. At the BPA Call order contract level, the POP may be for a base period of up to 12 months and may include at least a six-month Option period. Also, each BPA order contract will include FAR 52.217-8, Option to Extend Services.
4. GOVERNMENT POINTS OF CONTACT:
PRIMARY CONTRACTING OFFICER
Martin D. Meade (202) 304-6557
Martin.meade@fema.dhs.gov
Alternate CONTRACTING OFFICER
Jacinto A. Amposta, (202) 257-3965
Jacinto.amposta@fema.dhs.gov
PRIMARY CONTRACTING OFFICER’S REPRESENTATIVE
DiAnna “Arlene” Rhodes (202) 702-3241
Dianna.rhodes@fema.dhs.gov
Alternate CONTRACTING OFFICER’S REPRESENTATIVE
Anabel Quinones (202) 706-2696 anabel.quinones@fema.dhs.gov
FEMA PROGRAM MANAGER
Gentry Salter (202) 257-7059 gentry.salter@fema.dhs.gov
VII. DEFINITIONS & ACRONYMS.
1. DEFINITIONS
1.1. ATTACHMENT. Attachment means any documentation, appended to a contract, or incorporated by reference, which does not establish a requirement for deliverables.
1.2. CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the Government. The term used in this contract refers to the Prime
Contractor.
1.3. CONTRACTING OFFICER. A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the
Government. Note: The only individual who can legally bind the Government.
1.4. CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S.
Government appointed by the Contracting Officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor if that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract. The Government will provide a copy of each COR appointment letter to the
Contractor.
1.5. DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement (PWS).
mailto:Martin.meade@fema.dhs.gov mailto:Jacinto.amposta@fema.dhs.gov mailto:Dianna.rhodes@fema.dhs.gov mailto:anabel.quinones@fema.dhs.gov mailto:gentry.salter@fema.dhs.gov
1.6. DELIVERABLE. Anything that can be physically delivered but may include non-manufactured things such as meeting minutes or reports.
1.7. EXHIBIT. Exhibit means a document, referred to in a contract, which is attached and establishes requirements for deliverables.
1.8. FAIR MARKET RENTS. Fair Market Rents regularly published by HUD, represent the cost to rent a moderately-priced dwelling unit in the local housing market, inclusive of utility costs.
1.9. KEY PERSONNEL. Contractor personnel that may be evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key
Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
1.10. PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
1.11. QUALITY ASSURANCE. The Government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.
1.12. QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. This is an internal Government document.
1.13. QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.
1.14. SUBCONTRACTOR. One that enters into a contract with a Prime Contractor. The
Government does not have privity of contract with the subcontractor.
1.15. WORKDAY. The number of hours per day the Contractor provides services in accordance with the contract.
1.16. WORK WEEK. Monday through Friday, unless specified otherwise.
2. ACRONYMS
ADA American Disability Act
AFN Access and Functional Need
BPA Blanket Purchase Agreement
BPA Call Order Contract
CFR Code of Federal Regulations
CLIN Contract Line Item Number
CO Contracting Officer
COR Contracting Officer’s Representative
COTR Contracting Officer's Technical Representative
COTS Commercial-Off-the-Shelf
DOL Department of Labor
DHS Department of Homeland Security
FAR Federal Acquisition Regulation
FEMA Federal Emergency Management Agency
FMR Fair Market Rents (HUD)
FOD Field Operations Division
HUD U.S. Department of Housing and Urban Development
HSAM Homeland Security Acquisition Manual
HSAR Homeland Security Acquisition Regulation
OCI Organizational Conflict of Interest
ODC Other Direct Costs
PIV Personal Identity Verification card
PM Project Manager
POP Period of Performance
POC Point of Contact
PRS Performance Requirements Summary
PWS Performance Work Statement
QA Quality Assurance
QAP Quality Assurance Program
QASP Quality Assurance Surveillance Plan
QC Quality Control
QCP Quality Control Program
TE Technical Exhibit
VIII. APPLICABLE PWS ATTACHMENTS/EXHIBITS.
Attachments.
1. Sample Direct Lease Property Tracking Sheet (Excel)
2. Sample Direct Lease Daily Property Tracking Sheet
3. HUD FL FMR FY 2025
4. SF 1034 – Public Voucher
5. Vendor Required Unit Furnishing
Exhibits.
1. Direct Lease Occupant Lease Agreement
2. Direct Lease Terms and Conditions
3. Direct Lease Property Inspection Checklist (HUD)
4. Temporary Housing Agreement
5. Individual BPA Florida Direct Lease Price Listing (Excel)
6. Notice to Owner of FEMA Decision to Terminate Occupancy
7. Direct Lease – Lease Addendum
IX. ADDITIONAL PROVISIONS AND CLAUSES (Per Government Appendix G requirements).
SAFEGUARDING OF CONTROLLED UNCLASSIFIED INFORMATION (JULY 2023)
(a) Definitions. As used in this clause
Adequate Security means security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls. Controlled
Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:
(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical
Facility Anti-Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual
“Safeguarding Information Designated as Chemical-Terrorism Vulnerability Information” dated
September 2008);
(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure
Information Act of 2002 (title XXII, subtitle B of the Homeland Security Act of 2002 as amended through Pub. L. 116–283), PCII’s implementing regulations (6 CFR part 29), the PCII Program
Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security, the PCII Program Manager, or a PCII Program
Manager Designee;
(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive
Security Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the
Transportation Security Administration or designee), including Department of Homeland Security MD
11056.1, “Sensitive Security Information (SSI)” and, within the Transportation Security
Administration, TSA MD 2810.1, “SSI Program”;
(4) Homeland Security Agreement Information means information the Department of Homeland
Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement. The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion
Center Initiative and activities for cyber information sharing consistent with the Cybersecurity
Information Sharing Act of 2015;
(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;
(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;
(7) Information Systems Vulnerability Information (ISVI) means:
(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release; switching, router, and gateway information; interconnections and access methods;
and mission or business use/need. Examples of ISVI are systems inventories and enterprise architecture models. Information pertaining to national security systems and eligible for classification under Executive Order 13526 will be classified as appropriate; and/or
(ii) Information regarding developing or current technology, the release of which could hinder the objectives of the Department, compromise a technological advantage or countermeasure, cause a denial of service, or provide an adversary with sufficient information to clone, counterfeit, or circumvent a process or system;
(8) Operations Security Information means Department of Homeland Security information that could be collected, analyzed, and exploited by a foreign adversary to identify intentions, capabilities, operations, and vulnerabilities that threaten operational security for the missions of the Department;
(9) Personnel Security Information means information that could result in physical risk to Department of Homeland Security personnel or other individuals whom the Department is responsible for protecting;
(10) Physical Security Information means reviews or reports illustrating or disclosing facility infrastructure or security vulnerabilities related to the protection of Federal buildings, grounds, or property. For example, threat assessments, system security plans, contingency plans, risk management plans, business impact analysis studies, and certification and accreditation documentation;
(11) Privacy Information includes both Personally Identifiable Information (PII) and Sensitive
Personally Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual’s identity, either alone, or when combined with other information that is linked or linkable to a specific individual; and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
To determine whether information is PII, the DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not
PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual. Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.
(i) Examples of stand-alone PII that are particularly sensitive include: Social Security numbers
(SSNs), driver’s license or State identification numbers, Alien Registration Numbers (A-numbers), financial account numbers, and biometric identifiers.
(ii) Multiple pieces of information may present an increased risk of harm to the individual when combined, posing an increased risk of harm to the individual. SPII may also consist of any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
A. Truncated SSN (such as last 4 digits);
B. Date of birth (month, day, and year);
C. Citizenship or immigration status;
D. Ethnic or religious affiliation;
E. Sexual orientation;
F. Criminal history;
G. Medical information; and
H. System authentication information, such as mother’s birth name, account passwords, or personal identification numbers (PINs).
(iii) Other PII that may present an increased risk of harm to the individual depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. The context includes the purpose for which the PII was collected, maintained, and used. This assessment is critical because the same information in different contexts can reveal additional information about the impacted individual. Federal information means information created, collected, processed, maintained, disseminated, disclosed, or disposed of by or for the
Federal Government, in any medium or form. Federal information system means an information system used or operated by an agency or by a Contractor of an agency or by another organization on behalf of an agency. Handling means any use of controlled unclassified information, including but not limited to marking, safeguarding, transporting, disseminating, re-using, storing, capturing, and disposing of the information. Incident means an occurrence that—
(1) Actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or
(2) Constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
(iv) Information Resources means information and related resources, such as personnel, equipment, funds, and information technology. Information Security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide—
(1) Integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;
(2) Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and
(3) Availability, which means ensuring timely and reliable access to and use of information.
Information System means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
(b) Handling of Controlled Unclassified Information.
(1) Contractors and subcontractors must provide adequate security to protect CUI from unauthorized access and disclosure. Adequate security includes compliance with DHS policies and procedures in effect at the time of contract award. These policies and procedures are accessible at https://www.dhs.gov/dhs-security-and-trainingrequirements-contractors.
https://www.dhs.gov/dhs-security-and-trainingrequirements-contractors
(2) The Contractor shall not use or redistribute any CUI handled, collected, processed, stored, or transmitted by the Contractor except as specified in the contract.
(3) The Contractor shall not maintain SPII in its invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions. It is acceptable to maintain in these systems the names, titles, and contact information for the Contracting Officer’s Representative (COR) or other government personnel associated with the administration of the contract, as needed.
(4) Any government data provided, developed, or obtained under the contract, or otherwise under the control of the Contractor, shall not become part of the bankruptcy estate in the event a Contractor and/or subcontractor enters bankruptcy proceedings.
(c) Incident Reporting Requirements.
(1) Contractors and subcontractors shall report all known or suspected incidents to the Component
Security Operations Center (SOC) in accordance with Attachment F, Incident Response, to
DHS Policy Directive 4300A Information Technology System Security Program, Sensitive
Systems. If the Component SOC is not available, the Contractor shall report to the DHS
Enterprise SOC. Contact information for the DHS Enterprise SOC is accessible at https://www.dhs.gov/dhs-security-and-trainingrequirements-contractors. Subcontractors are required to notify the prime Contractor that it has reported a known or suspected incident to the
Department. Lower tier subcontractors are required to likewise notify their higher tier subcontractor, until the prime contractor is reached. The Contractor shall also notify the
Contracting Officer and COR using the contact information identified in the contract. If the report is made by phone, or the email address for the Contracting Officer or COR is not immediately available, the Contractor shall contact the Contracting Officer and COR immediately after reporting to the Component or DHS Enterprise SOC.
(2) All known or suspected incidents involving PII or SPII shall be reported within 1 hour of discovery. All other incidents shall be reported within 8 hours of discovery.
(3) CUI transmitted via email shall be protected by encryption or transmitted within secure communications systems. CUI shall be transmitted using a FIPS 140-2/140-3 Security
Requirements for Cryptographic Modules validated cryptographic module identified on https://csrc.nist.gov/projects/cryptographic-module-validationprogram/validated-modules.
When this is impractical or unavailable, for Federal information systems only, CUI may be transmitted over regular email channels. When using regular email channels, Contractors and subcontractors shall not include any CUI in the subject or body of any email. The CUI shall be included as a password-protected attachment with the password provided under separate cover, including as a separate email. Recipients of CUI information will comply with any email restrictions imposed by the originator.
(4) An incident shall not, by itself, be interpreted as evidence that the Contractor or Subcontractor has failed to provide adequate information security safeguards for CUI or has otherwise failed to meet the requirements of the contract.
(5) If an incident involves PII or SPII, in addition to the incident reporting guidelines in
Attachment F, Incident Response, to DHS Policy Directive 4300A Information Technology
System Security Program, Sensitive Systems, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
(i) Unique Entity Identifier (UEI);
(ii) Contract numbers affected unless all contracts by the company are affected;
(iii) Facility CAGE code if the location of the event is different than the prime Contractor location;
(iv) Point of contact (POC) if different than the POC recorded in the System for Award
Management (address, position, telephone, and email);
(v) Contracting Officer POC (address, telephone, and email);
(vi) Contract clearance level; (vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network; (viii) Government programs, platforms, or systems involved;
(ix) Location(s) of incident;
(x) Date and time the incident was discovered;
(xi) Server names where CUI resided at the time of the incident, both at the Contractor and subcontractor level;
(xii) Description of the government PII or SPII contained within the system; and
(xiii) Any additional information relevant to the incident.
(d) Incident Response Requirements.
(1) All determinations by the Department related to incidents, including response activities, will be made in writing by the Contracting Officer.
(2) The Contractor shall provide full access and cooperation for all activities determined by the
Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of incidents.
(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:
(i) Inspections;
(ii) Investigations;
(iii) Forensic reviews;
(iv) Data analyses and processing; and
(v) Revocation of the Authority to Operate (ATO), if applicable.
(4) The Contractor shall immediately preserve and protect images of known affected information systems and all available monitoring/packet capture data. The monitoring/packet capture data shall be retained for at least 180 days from submission of the incident report to allow DHS to request the media or decline interest. (5) The Government, at its sole discretion, may obtain assistance from other Federal agencies and/or third-party firms to aid in incident response activities.
(e) Certificate of Sanitization of Government and Government-Activity-Related Files and Information.
Upon the conclusion of the contract by expiration, termination, cancellation, or as otherwise indicated in the contract, the Contractor shall return all CUI to DHS and/or destroy it physically and/or logically as identified in the contract unless the contract states that return and/or destruction of CUI is not required. Destruction shall conform to the guidelines for media sanitization contained in NIST SP 800–88, Guidelines for Media Sanitization. The Contractor shall certify and confirm the sanitization of all government and government-activity related files and information. The Contractor shall submit the certification to the COR and Contracting
Officer following the template provided in NIST SP 800–88, Guidelines for Media
Sanitization, Appendix G.
(f) Other Reporting Requirements.
Incident reporting required by this clause in no way rescinds the Contractor’s responsibility for other incident reporting pertaining to its unclassified information systems under other clauses that may apply to its contract(s), or as a result of other applicable statutory or regulatory requirements, or other
U.S. Government requirements.
(g) Subcontracts.
The Contractor shall insert this clause in all subcontracts and require subcontractors to include this clause in all lower tier subcontracts when subcontractor employees will have access to
CUI; CUI will be collected or maintained on behalf of the agency by a subcontractor; or a subcontractor information system(s) will be used to process, store, or transmit CUI.
Information Technology Security Awareness Training (July 2023)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees
(hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Security Training Requirements.
(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part
930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. The Department of
Homeland Security (DHS) requires that Contractor employees take an annual Information Technology
Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all
Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the
Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award.
Subsequent training certificates to satisfy the annual training requirement shall be submitted to the
COR via e-mail notification not later than October 31st of each year. The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.
(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The
DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within thirty (30) days of contract award. Any new Contractor employees assigned to the contract shall also sign the
DHS Rules of Behavior before accessing DHS systems and sensitive information. The Contractor shall maintain signed copies of the DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, the Contractor shall e-mail copies of the signed
DHS Rules of Behavior to the COR not later than thirty (30) days after contract award for each employee. The DHS Rules of Behavior will be reviewed annually, and the COR will provide notification when a review is required.
Privacy Training Requirements
All Contractor and subcontractor employees that will have access to Personally Identifiable
Information (PII) and/or Sensitive PII (SPII) are required to take Privacy at DHS: Protecting Personal
Information before accessing PII and/or SPII. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors.
Training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall also complete the training before accessing PII and/or SPII. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Initial training certificates for each Contractor and subcontractor employee shall be provided to the COR not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year. The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.
Information…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .