1.2.1-PWS.pdf
PDF 493 KB Posted
- Attached to
- Law Enforcement Investigative Database Subscription Federal contract opportunity
- Solicitation number
- 192126FLMURQ0071
- Issued by
- Immigration and Customs Enforcement
About this file
This is a Performance Work Statement (PWS) for a law enforcement investigative database subscription service to support the Department of Homeland Security's Immigration and Customs Enforcement (ICE) agency.
ICE seeks to procure a web-based law enforcement investigative database subscription platform to conduct criminal investigations protecting the United States against terrorists and criminal organizations. The system must support over 11,000 users across multiple ICE directorates including Homeland Security Investigations (HSI), Enforcement and Removal Operations (ERO), and the Office of Professional Responsibility (OPR), operating continuously (24/7/365) across more than 50 countries and 67 global locations. The database must enable investigations related to illegal border movement, transnational criminal organizations, terrorism, narcotics trafficking, human smuggling, financial crime, intellectual property theft, trade fraud, identity fraud, cyber crime, and other enforceable criminal and administrative laws. The Period of Performance consists of a base year plus four one-year option periods. The contractor must provide user accounts for 11,200 users and deliver comprehensive technical capabilities including entity resolution with duplicate elimination, API integration with existing ICE platforms (Palantir, PenLink, ICE Data Analytics), system-to-system connections, relevant scoring algorithms, link-chart visualization, sex offender registry searches, batch request processing for multiple SSNs/phone numbers, mobile application access, customizable reporting templates, asset identification functionality, audit trail logging for OPR oversight, incarceration and jail booking data access for 7,500 ERO users, and artificial intelligence-driven facial recognition platforms. Training and user management support (Task Area 1A) must include written instruction manuals, user account verification against authorized personnel lists using ORI matching against NLETS, 24-hour user provisioning/deprovisioning capability, initial and ongoing training through multiple delivery methods (on-site limited to Washington DC with maximum 2 visits annually, telephone, web-based, webinars, and on-demand), help desk support with unlimited technical assistance, and periodic system updates and maintenance. The contractor must establish and maintain a Quality Assurance Surveillance Plan (QASP) with draft submission at proposal and final submission within 20 days of award, followed by quarterly updates as needed. All security requirements comply with DHS National Security Systems Policy Directive 4300B and DHS Sensitive System Program 4300A, including encryption standards, supply chain risk management with documentation of all hardware/software manufacturers and DUNS numbers, incident reporting within 1 hour for PII/SPII breaches and 8 hours for other incidents, security authorization processes, continuous monitoring capabilities, and compliance with artificial intelligence governance requirements including human-in-the-loop oversight, explainability standards, data rights protection ensuring all government data remains government property, and prevention against vendor lock-in through use of industry-standard APIs and exportable outputs. The contractor must comply with Section 508 accessibility standards, privacy requirements under the Privacy Act of 1974, Controlled Unclassified Information (CUI) safeguarding procedures per FAR 3052.204-72 and 3052.204-73, and all applicable federal contracting regulations for commercial items. Invoices shall be submitted monthly to the Contracting Officer's Representative and designated Finance Center for services performed within 30 days of the period of performance end. The contract is identified as 70CMSD26CXXXXXXX with classified sensitivity marked as "LAW ENFORCEMENT SENSITIVE."
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
70CMSD26CXXXXXXX
Attachment 2-Performance Work Statement (PWS)
LAW ENFORCEMENT SENSITIVE Page 1 of 33
Performance Work Statement (PWS) Department of Homeland Security (DHS), Immigration and Customs Enforcement (ICE) Law Enforcement Investigative Database Subscription
July 22, 2026
1. BACKGROUND
The intent of this Performance Work Statement (PWS) is to procure a web-based law enforcement investigative database subscription service to assist Immigration, Customs and Enforcement (ICE) mission of conducting criminal investigations that protect the United States against terrorists and criminal organizations that threaten our safety and national security; to combat transnational criminal enterprises that see to exploit America’s legitimate trade, travel, and financial systems. ICE investigative agents require a robust analytical research tool for its in-depth exploration of persons of interest and vehicles.
The purpose of this contract is to provide ICE agents an investigative database system to further strategize arrests to minimize and, in some cases, avoid impact of potential injury. ICE requirement of a web-based law enforcement investigative database platform is to include integration access to public records and commercial data with uninterrupted service, integrate investigative capabilities with the license plate recognition capabilities to be utilized by multiple ICE Directorates to include but not limited to Homeland Security Investigations (HSI), Enforcement and Removal Operations (ERO) and Office of Professional Responsibility (OPR).
Use of this database subscription services furthers the criminal law enforcement mission.
1.1 DHS/ICE
ICE is the largest investigative agency in the Department of Homeland Security (DHS) and was formally established on March 1, 2003. ICE's primary mission is to protect national security, public safety, and the integrity of the US borders through the criminal and civil enforcement of federal laws governing border control, customs, trade, and immigration.
Contractor’s law enforcement investigative database may only be used in support of ICE’s statutorily authorized authority. As permitted by law, Contractor’s law enforcement investigative database may be used for the research and investigation of businesses and/or individuals known or suspected to be related to the enforcement of laws pertaining to the following categories listed below. The Excluded use cases and Included use cases apply to PWS paragraphs 3.1 and 3.2.
Excluded use cases:
• General research and investigations not associated with the activities below.
Included use cases:
• Research and investigations of businesses and/or Individuals known or suspected to be related to the enforcement of laws regarding:
LAW ENFORCEMENT SENSITIVE Page 2 of 33
• Illegal cross border movement of people, goods, money, technology and other contraband
• Transnational criminal organization activities
• Terrorism
• National security threats
• Narcotics smuggling and trafficking
• Transnational gang activity
• Child exploitation
• Human Smuggling and Trafficking
• Illegal import and export of controlled technology and weapons
• Financial crime, fraud, scams and money laundering
• Labor employment exploitation
• Cyber Crime
• Intellectual property theft and violations
• Trade fraud and commercial crimes
• Identity and Benefit Fraud
• Human Rights Violations and War Crimes
• International sanctions
• Cultural Property and Antiquities trafficking
• Determined to be at personal physical risk to themselves or others
• Other Enforceable Criminal and Administrative Laws
The law enforcement investigative database system currently supports over 11,000 users across multiple program areas with analytical data and concrete information to search high risk and politically exposed criminal activity worldwide. The database subscription service plays a crucial role in ICEs overall investigative mission success. Moreover, the agency can achieve cost savings to the government when reducing the work hours required for physical surveillance.
2.0 SCOPE/OBJECTIVES
The Department of Homeland Security (DHS), U.S. Immigration and Customs Enforcement (ICE) houses a large dataset of detailed data that is available to an assortment of approved law enforcement users. ICE criminal law enforcement mission; to enhance investigations to support all mission activities mentioned above in over 50 countries and 67 locations globally; to provide a platform where the continuity of public records and commercial data is available on an uninterrupted basis and to identify criminal suspects, businesses, and assets of targets of investigations for potential arrest, seizure and forfeiture will require the usage of a robust investigative database subscription service.
The scope of this requirement is to subscribe to and use the contractor's proprietary data, content, and analytical data to optimize ICE operational support functions to enable mission success. This includes supporting all aspects of ICE screening and vetting, lead development, and criminal analysis activities. It also includes, but is not limited to, conducting data extractions to identify unusual trends, data anomalies, and control breakdowns, identifying possible trends, patterns, and links to automate methods for detecting, monitoring, analyzing, summarizing and graphically representing patterns of relationships between entities, identifying potentially
LAW ENFORCEMENT SENSITIVE Page 3 of 33 criminal and fraudulent behavior before crime and fraud can materialize and detecting and reporting elements of crimes involving the exploitation or attempts to exploit the immigration and customs laws of the United States.
ICE requires web-based law enforcement investigative databases platform to provide constant (24 hour, seven days per week, 365 days a year) accessibility to a database for ICE law enforcement personnel across the United States in the execution of their official law enforcement duties.
The task areas listed constitute the technical scope of this PWS:
• Task Area 1: Database Functionality Requirements (CLIN 0001)
• Task Area 1A: Training and User Management Support (CLIN 0002)
Contractor shall provide user accounts for database access to 11,200 users.
3.0 TASK REQUIREMENTS
The ICE law enforcement investigative database platform shall contain a web-based, centralized database for client management and reporting. Generally, all users shall provide direct input into the database and output requests (reports) shall be generated directly from the database system.
The ICE participating programs shall provide input (i.e., client level data) and the contractor shall provide the database systems administrative and support for report generation. The investigative platform requires the best-supported investigative data and data-analytic management available in the marketplace; to allow readily available access to billions of public records and additional investigative content in an intuitive working environment.
The tasks required under this Performance Work Statement (PWS) require a community-wide data-analytic collection and management system that includes the following:
3.1 TASK AREA 1: DATABASE FUNCTIONAL REQUIREMENTS
• The government's requirement is that the database uses a matching algorithm to return search records that can identify and eliminate duplicated results. The database shall use Entity Resolution applied across results from all sources as they are returned. This maximizes the value of searching multiple sources and saves time by automating the process of record comparison.
• The government's requirement is that the database must be able to application programming interface (API) with ICE applications, such as but not limited to, Palantir platform, PenLink, and ICE Data Analytics.
• The government’s requirement is that the application shall provide a system-to-system (S2S) connection that merges the application’s public and proprietary data and made available via query operations and batch requests.
• The government's requirement is that the database must compare the input search criteria and score them against all records in their data sources. The database must use a Relevant Scoring application that allows them to return the most relevant and most current records at the top of the results list.
LAW ENFORCEMENT SENSITIVE Page 4 of 33
• The government's requirement is that the database program must have the ability to construct link charts. The database shall use Link-Chart Visualization and Mapping, which allows investigators to save selected results and report data indefinitely and provides the capability to generate link charts and map views of the data.
• The government’s requirement is that the application must search and display sex offender registries with queries based on, name, date of birth, address, phone number, and social security number.
• The government's requirement is that the database program must allow for multiple searches using unique criteria. Investigators must be allowed to enter specific search criteria once, the system then returns all relevant data, regardless of the source. The program must support search federation against both open-source and internal data repositories and include features like entity resolution, search filtering and charting and mapping across all supported sources.
• The government's requirement is that the database program must allow for Batch Requests where multiple social security numbers (SSN) and/or phone numbers may be queried at one time. This capability is both time- and cost-saving for Worksite and Identity Benefit Fraud investigations where multiple SSN's are queried at one time vs. one at a time.
• The government’s requirement is that the desktop and mobile application allows for queries and batch search requests based on, but not limited to: name, date of birth, address, phone number, social security number, license plate number, vehicle identification number, tail number, etc.
• The government's requirement is that the database must allow for mobile application “on the go” access. The law enforcement investigative research tool shall provide full access to core search and report capability from mobile, wireless devices, including HTML5-supported smartphones.
• Available functionality includes person, vehicle, aircraft, watercraft and phone searches and the National Comprehensive Report. Reports shall be saved automatically in a results tab for future viewing.
• The government’s requirement is that the database shall have the ability to conform to the investigator’s needs, so reports generated can be customized to an investigator or analyst case load. Users shall create report templates by setting report preferences, identifying which sections to include, and setting the sequence in which sections are displayed. For example, customers wanting to see only the asset-related information for an individual could create an “Asset Profile” report with the sections they want included, in the order that they want. The law enforcement online research tool 0shall also offer a workspace feature which allows users to save selected results and report data indefinitely and provides the ability to generate link-chart and map views of the data. Visualizing information on multiple subjects in a link-chart view makes it easier for investigators to discern possible connections or associations between subjects/entities.
• The government’s requirement is that the information provided by the law enforcement online research tool should enable ICE to effectively and quickly identify assets currently owned or previously owned/operated by suspect individuals and/or organizations under investigation. The research tool should allow for the flexibility of locating suspects' assets through a multitude of search
LAW ENFORCEMENT SENSITIVE Page 5 of 33 options. It should also offer the ability to create custom searches so investigators can retrieve information more specific to the time of criminal activity and/or by target name.
• The government’s requirement is that the information provided by the law enforcement online research tool should enable ICE OPR to effectively identify searching of a record/document and generate a corresponding audit record. the system shall allow OPR users to search, view, and export user profiles and view activity logs, to include but not limited to, user login/sign-on data, search history based on beginning and ending date and time.
• The government’s requirement is the system will have the capacity to:
o Generate program, agency, community, and, if applicable, collaborative level reports.
o Produce standard, built-in reports and forms to be queried by Area of
Responsibility (AOR), to include user reports, agency reports, component, location and sublocation reports and other reports as required.
o Perform integrated ad hoc reporting that maintains user level security restrictions while allowing for user flexibility in choosing tables and fields as well as filtering and conditional report aspects.
o Import and export data through XML and CSV formats, imports and exports and ability to securely strip data of identifiers and manage data transmission.
• The government’s requirement is that System Security will include Integrated technical safeguards to ensure a high level of privacy and security, including:
o Back-end server(s), including data encryption and transmission o Administrator controlled username and password access o Automatic timeout/log-off o Administrator controlled user level read, write, edit, and delete capabilities o Administrator controlled user level module and sub-module access o Automated audit trail o Information Security Industry Standard encryption and SSL certifications in compliance with Transport Layer Security (TLS) protocol compliant (TLS 1.2 and TLS 1.3)
All technical safeguards required to protect Personally Identifiable Information (PII) All security safeguards required for compliance.
• The government’s requirement is that the system will include access to incarceration data and jail booking data for up to 7,500 ERO users with unlimited searches, that allows searches based on previous 24 hours, 72 hours, and a date range to be set by the querying user.
• The government requires that the system includes an artificial intelligence (AI) driven identification system capable of leveraging non-attributable data, including anonymized behavioral indicators, device metadata, network signatures, commercial telemetry data, and passive environmental markers, in combination with known data points to infer the identity of the end user. The system should utilize advanced pattern recognition, multimodal
LAW ENFORCEMENT SENSITIVE Page 6 of 33 correlation engine, as close to real-time contextual enrichment to cross reference disparate data streams without relying on unique direct personal identifiers.
• The government requirement is that the system is capable of accessing advanced AI driven facial recognition platforms. Leveraging deep learning algorithms and large-scale image databases to perform high accuracy facial matching across diverse sources, including open-source media. The program must support bulk ingestions, rapid one to many comparisons, and integrations with existing targeting and case management.
3.2 TASK AREAS 1A: TRAINING AND USER MANAGEMENT SUPPORT.
The object of this task is to provide training to ICE personnel through on-site, remote, and/or on-demand training on the Law Enforcement Investigative database tool. Training and user management support is implemented to ensure proper guidance and navigation of the database tool is accessible to all assigned users.
• The contract shall provide written instruction manuals and guidance to facilitate use of the database investigative tool.
• The contract shall ensure the user has the ability to compare new user requests with lists of personnel authorized by ICE to utilize the database tool.
• The contractor shall ensure that all users have automatic verification of accounts with the ability to audit by using the user’s Originating Agency Identifier (ORI) to be matched against a current real-time list of active ORI numbers provided directly or indirectly by the National Law Enforcement Telecommunications System (NLETS).
• The contractor shall have the ability to add new users or delete existing users within 24 business hours of ICEs request.
• The contract shall provide initial training or subsequent training to orient persons to the use of the database investigative tool; to include the “Help Desk” support related to the use, access, and maintenance of the tool.
• The contractor shall provide customized training on-site, telephone and web-based training to include webinars and “on demand” classes and electronic quick reference guides for users. On-site training shall be limited to the Washington, DC location with a maximum of 2 training visits per year.
• The contract shall provide system training and escalation procedures as it pertains to agency administrators and shall include procedures for password resets to the database tool.
• The contractor shall provide unlimited technical support for all users.
• The contractor shall perform periodic or as needed updates (maintenance, refresh, etc.) to the overall database tool, web-based interface, and mobile application. The contractor shall also ensure to employ appropriate technical, administrative, and physical security
LAW ENFORCEMENT SENSITIVE Page 7 of 33 controls are in place to protect the integrity, availability and confidentiality of the data that resides on all of its systems.
4.0 OTHER APPLICABLE REQUIREMENTS
4.1 PERIOD OF PERFORMANCE
The Period of Performance will consist of a base year with four (4) one-year options.
4.2 PLACE OF PERFORMANCE
The primary place of performance will be the Contractor’s facilities with frequent visits to the Immigration and Customs Enforcement (ICE) headquarters facilities in the Washington Metro Area.
4.3 TRAVEL
Contractor travel is not required for this requirement. Local meetings or activities planned outside of the defined place of performance are permitted, but all expenses incurred are the responsibility of the contractor.
4.4 POST AWARD CONFERENCE
The Contractor shall attend Post Award Conference with the Contracting Officer and the COR no later than 5 business days after the date of award. The purpose of the Post Award Conference, which will be chaired by the Contracting Officer, is to discuss technical and contracting objectives of this contract. The Post Award Conference will be held either virtually (e.g., MS Teams, Zoom, Adobe Connect, etc.) and/or at the Government’s facility, location to be determined via teleconference.
4.5 INVOICES
A standard invoice template shall be provided by the contractor and confirmed by the COR for use on this contract. Invoices shall be verified by the Government COR and submitted on a monthly basis.
4.6 CONTRACTOR QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
The Contractor shall establish and maintain a Quality Assurance Surveillance Plan (QASP) to ensure the requirements of this contract are provided as specified. The Contractor shall provide a QASP describing the inspection system that they intend to use for the requested services listed.
The contractor shall implement procedures to identify, prevent and ensure non-recurrence of defective services. The Contractor’s draft QASP shall be required as part of their quote submittal. The CO will notify the Contractor of acceptance or the necessity for QASP modification of the plan no later than 10 business days after award. The Contractor shall provide a final QASP to the COR no later than 20 business days after award. The QASP shall be updated as changes occur and shall be submitted to the COR for review and subsequent CO acceptance by the government. The Performance Requirements Summary (PRS) and Performance Standards Matrix (PSM) is outlined in the Quality Assurance Surveillance Plan (QASP) Appendix A.
LAW ENFORCEMENT SENSITIVE Page 8 of 33
5.0 DELIVERABLES
The contractor shall provide the following deliverables in the format and frequency listed.
Deliverables Name PWS Paragraph Frequency
Kick-off Meeting/Post Award Conference
4.4 A kick-off meeting with
the government will be conducted within 5 days of award. Meeting minutes due from Contractor to COR & CO within 2 business days of the meeting.
Audit report, ad hoc reports, user manuals, etc.
3.1 Reports are due upon
request of the COR and/or as required. To include any subsequent updates.
Data Rights any work first produced such as user administrative and operations manuals and anything else first produced under this PWS if applicable.
One month prior to the end of the period of performance (POP).
QASP/Progress Reports
4.6 Draft due to the
government proposal.
Final QASP due to the COR and CO 20 days after award. Subsequent reports due quarterly and/or as requested.
Invoices
4.5 Invoice should be
submitted on a monthly basis to the COR and designated Finance Center for all services performed and no more than 30 days in the arrears of the last day of the POP.
5.1 GENERAL REPORT REQUIREMENTS
The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with ICE workstations (Windows XP and Microsoft Office Applications).
5.2 ACCEPTANCE CRITERIA
ICE will accept or reject deliverables within fifteen (15) business days after delivery. If rejected, LAW ENFORCEMENT SENSITIVE Page 9 of 33 the Contractor shall make corrections as specified and resubmit the deliverable for review and approval within five (5) business days provided however that contractor is not dependent upon a third party for performance. If the government does not reply within the specific timeframe than the deliverable shall be determined acceptable.
6.0 SECTION 508 COMPLIANCE
Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by P.L.
105-220 under Title IV (Rehabilitation Act Amendments of 1998) all Electronic and Information Technology (EIT) developed, procured, maintained and/or used under this contract shall be in compliance with the “Electronic and Information Technology Accessibility Standards” set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in 36 CFR Part 1194. The complete text of Section 508 Standards can be accessed at http://www.access-board.gov/ or at http://www.section508.gov.
7.0 PRIVACY REQUIREMENTS
Limiting Access to Privacy Act and Other Sensitive Information In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984), and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DHS system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.dhs.gov/system-records-notices-sorns. Applicable SORNS of other agencies may be accessed through the agencies’ websites or by searching GovInfo, available at https://www.govinfo.gov that replaced the FDsys website in December 2018. SORNs may be updated at any time.
Prohibition on Performing Work Outside a Government Facility/Network/Equipment The Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or Workplace as a Service (WaaS) if WaaS is authorized by the statement of work. Government information shall remain within the confines of authorized Government networks at all times. Except where telework is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of telework authorizations.
Prior Approval Required to Hire Subcontractors The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract.
The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.
Separation Checklist for Contractor Employees Contractor shall complete a separation checklist before any employee or Subcontractor employee http://www.access-board.gov/ http://www.section508.gov/ http://www.dhs.gov/system-records-notices-sorns http://www.govinfo.gov/
LAW ENFORCEMENT SENSITIVE Page 10 of 33 terminates working on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposal of sensitive personally identifiable information (PII), in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to sensitive PII.
In the event of adverse job actions resulting in the dismissal of an employee or Subcontractor employee, the Contractor shall notify the Contracting Officer’s Representative (COR) within 24 hours. For normal separations, the Contractor shall submit the checklist on the last day of employment or work on the contract.
As requested, contractors shall assist the ICE Point of Contact (ICE/POC), Contracting Officer, or COR with completing ICE Form 50-005/Contractor Employee Separation Clearance Checklist by returning all Government-furnished property including but not limited to computer equipment, media, credentials and passports, smart cards, mobile devices, PIV cards, calling cards, and keys and terminating access to all user accounts and systems.
Contractor’s Commercial License Agreement and Government Electronic Information Rights Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases) and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S.
Government and are considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.
Privacy Lead Requirements If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy documentation, the Contractor shall assign or procure a Privacy Lead, to be listed under the SOW or PWS’s required Contractor Personnel section. The Privacy Lead shall be responsible for providing adequate support to DHS to ensure DHS can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance.
The Privacy Lead shall work with personnel from the program office, the ICE Privacy Unit, the Office of the Chief Information Officer, and the Records and Data Management Unit to ensure that the privacy documentation is kept on schedule, that the answers to questions in the PIA are thorough and complete, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.
The Privacy Lead:
• Must have excellent writing skills, the ability to explain technology clearly for a non-technical audience, and the ability to synthesize information from a variety of sources.
• Must have excellent verbal communication and organizational skills.
• Must have experience writing PIAs. Ideally the candidate would have experience writing PIAs for DHS.
LAW ENFORCEMENT SENSITIVE Page 11 of 33
• Must be knowledgeable about the Privacy Act of 1974 and the E- Government Act of 2002.
• Must be able to work well with others.
If a Privacy Lead is already in place with the program office and the contract involves IT system builds or substantial changes that may require privacy documentation, the requirement for a separate Private Lead specifically assigned under this contract may be waived provided the Contractor agrees to have the existing Privacy Lead coordinate with and support the ICE Privacy POC to ensure privacy concerns are proactively reviewed and so ICE can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance if required.
The Contractor shall work with personnel from the program office, the ICE Office of Information Governance and Privacy, and the Office of the Chief Information Officer to ensure that the privacy documentation is kept on schedule, that the answers to questions in any privacy documents are thorough and complete, that all records management requirements are met, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.
8.0 SECURITY REQUIREMENTS MATRIX
OCIO/ Data Management Unit (DMU) - Data Ownership Contract Requirements Language
1. Accessibility of Government-owned Data All stored program data associated with this acquisition shall be owned by the Government. As such, it shall be made accessible to the Government in accordance with the Minimum Data Access Capability described below. This accessibility is required to allow full data transparency, flexibility in performing data analytics, and integration with data from other government programs.
In addition to the Minimum Data Access Capability, the Government prefers, but does not require, that program data be accessible via Enhanced Access Capabilities as described below.
Definition of “program data”: Program Data refers to any data resulting from ICE and DHS organizational activity. Examples of such data include but are not limited to administrative data resulting from human resource, management, and financial actions, as well as operational data resulting from performance of the ICE mission.
Definition of “associated with this acquisition”: Program Data is associated with an acquisition if it is created by
DHS organizational activity that is facilitated by the contractor. Examples of how a contractor might facilitate organizational activity follow:
o Program data is stored by contractor personnel o Program data is stored by software that is managed, developed, or used by the contractor o Program data is stored in a repository that is managed, developed, or used by the contractor
2. Minimum Data Access Capability
• The current version of all Program Data is accessible to the Government within 24 hours of request, as well as on any pre-defined schedule as required by the Government.
Data access can occur by various means, provided that Government security requirements are met, and data is accessible in a format that is acceptable to the Government. Examples include but are not limited to APIs that are consumable by the Government, files made available for Government download (e.g., Excel Spreadsheets), or direct database query by federal or contractor personnel.
LAW ENFORCEMENT SENSITIVE Page 12 of 33
• The contractor shall format program data accessed by the Government to anticipate the maximum file size of any data to be accessed. File size shall be small enough to assure rapid processing by government applications.
• The contractor shall provide the means for the Government to interpret accessible Program Data as follows:
o Data elements and groupings of data elements shall be clearly identifiable by labels embedded in the data itself, or by a separate schema or file layout which allows such elements and groupings to be identified.
In the case of a relational database schema defined through Data Definition Language (DDL), data elements would be represented as columns, and groupings of data would be represented as tables. In addition, relationships between tables would be described as foreign key relations.
o Labels or names used to identify data elements and groupings of data elements shall be approved by the Government. In addition, each label or name shall be associated with a government approved definition which describes the content of data held therein.
o Program data delivered to the Government shall conform to the Government approved definition for each data element and grouping of data elements.
o All data accessible by the Government shall be both machine readable and human-readable in plain text.
o All reference data associated with Program Data also needs to be accessible to the Government. Such reference data is required to provide complete understanding of a record.
Reference Data Example: Program data may include a city code which uniquely identifies a city.
Reference data associated with a city code may include its name, geographic boundaries, population, median income, etc. This example is provided for clarification of the meaning of reference data and may or may not apply to this specific acquisition. Examples of other reference data codes would include codes representing eye color, gender, country of origin, etc.
3. Enhanced Access Capabilities
The Government prefers that sharing of program data take place via an Application Programming Interface (API) or multiple APIs. APIs allow the Government to efficiently consume data via a widely recognized standard where the data has been completely abstracted from the technology platform that produces it.
In addition, the Government prefers that sharing of program data take place using techniques that enhance efficiency, such as Change Data Capture (CDC). CDC enhances efficiency of data transfer by providing only incremental updates to program data as opposed to providing all program data each time data is shared.
1. Compliance with Federal Laws and Policies; AI Use Limitations. The Contractor shall ensure any AI system or service provided complies with all applicable federal, Department of Homeland Security (DHS), and U.S. Immigration and Customs Enforcement (ICE) AI Policies, Directives, and Memos, as well as ICE AI governance requirements. The AI solution must align with the U.S. Constitution and all relevant laws and regulations, including privacy, civil rights, and civil liberties. Specifically:
a. The Contractor must stay current and comply with any updates or new AI policy and AI governance requirements issued during the contract term.
b. AI used to support law enforcement decisions or civil actions must include technical and operational safeguards to:
LAW ENFORCEMENT SENSITIVE Page 13 of 33
i. Establish human-in-the loop oversight.
ii. Document or label AI-generated content.
c. For AI used in determinations impacting individuals (e.g., risk assessments, identity verification), the Contractor must cooperate with federal, DHS, and ICE procedures for notice and appeal, providing explanations or adjusting outputs upon error findings.
d. The contract prohibits use of AI that violates DHS policy, including:
i. Using AI outputs as sole evidence for punitive or enforcement actions.
ii. Utilizing AI to make or support decisions on improper bases (e.g., predicting future behavior or emotional state leading to discriminatory or unlawful actions).
e. The Contractor must follow AI Use Case approval, Security Authorization, and ICE AI governance and AI risk management processes and requirements before developing, piloting, testing, or deploying AI in ICE environments or using ICE data.
f. The Contractor is responsible for complying with AI Security Control Baseline requirements.
2. Traceability, Auditability, and Transparency. The Contractor shall design, build, document, and operate the AI system or service to be explainable, auditable, and transparent. At a minimum, the Contractor shall:
a. Document the provenance of data used for AI training, fine-tuning, or operation.
b. Ensure data used for AI training, fine tuning, or operation was lawfully obtained and processed.
c. Document the provenance of any third-party AI models used (source, version, etc.).
d. Provide comprehensive system diagrams and inventories that map the AI systems’ API and system connections, data flows, and technical components.
e. Provide comprehensive documentation explaining how the AI system works, including any models and algorithms.
f. Ensure the AI system, where applicable, provides clear explanations or reasoning for its decisions or predictions.
g. Ensure AI outputs are traceable, auditable, meet evidentiary standards, and are explainable to non-technical users. Additionally:
i. Ensure GenAI inputs and their outputs are logged and preserved in line with federal, DHS, and ICE retention policies.
3. Data Rights and Solution Ownership. The contract shall clearly delineate data and intellectual property rights to protect ICE’s interests in the AI solution and associated data. Specifically:
a. All data provided by the Government or generated through the AI system belongs to the Government. The Contractor is prohibited from:
i. Using nonpublic agency data and outputted results to train publicly or commercially available AI algorithms, or any non-ICE systems outside the contract’s scope without ICE’s authorization.
ii. Using Government-furnished data or AI-generated data for purposes outside the contract without ICE authorization.
iii. Sharing, disclosing, or transferring Government data, AI models, or AI-outputs with third parties without ICE’s authorization.
b. The Contractor must grant the Government appropriate license rights in any custom-developed AI models, software, or deliverables. Intellectual Property (IP) rights will be negotiated consistent with federal law and the agency’s mission needs, aiming to avoid vendor lock-in. The Government may require broad or unlimited rights to certain deliverables (including source code or trained model files) for long-term use, maintenance, or integration of the AI solution.
c. ICE maintains ownership over and the Contractor must provide ICE access to:
LAW ENFORCEMENT SENSITIVE Page 14 of 33
i. Any derivative outputs of AI developed under the Contract, including data processed using AI.
ii. Any models trained, fine-tuned, or otherwise developed using ICE data.
4. Prevention Against Vendor Lock-In: To promote a competitive marketplace and long-term sustainability of ICE’s AI capabilities, the Contractor shall:
a. Utilize industry-standards, Application Programming Interfaces (APIs), and protocols wherever possible to ensure interoperability and combability within and between ICE and DHS systems.
b. Ensure inputs and outputs of the AI system are exportable in a non-proprietary, machine-readable format to facilitate integration or transfer of functions to other systems.
c. Where custom components are developed, deliver sufficient technical documentation and access to components (including source code, model weights, or other foundational code) to enable ICE’s long-term use of the AI system.
d. In the case of transitioning the AI system to another contractor or in-house provider, the Contractor must support knowledge transfer and provide all necessary documentation, models, data, derivative outputs, and software to enable sustained system use.
i. The Contract must also document estimated costs and related steps that will be required to exit the Contract.
5. Security, Testing & Evaluation, and Continuous Monitoring: The Contractor shall implement rigorous security and risk management measures for the AI solution, per federal standards, ICE procedures, and Office of Management and Budget (OMB) guidance on AI risks. Key requirements include:
a. If designated as a High Impact AI system, complying with all required AI Risk Management practices (per OMB, DHS, and ICE policy), unless officially granted a waiver.
b. Before deploying the AI system: The Contractor must provide testing and evaluation artifacts and support (including providing requisite access) to enable ICE independent test and evaluation processes to evaluate factors such as, but not limited to:
i. AI system performance, including accuracy and reliability.
ii. Compliance with DHS AI Security Controls.
iii. Resiliency against AI cybersecurity and operational threats, including system misuse/abuse.
iv. Completion of an AI impact assessment and/or other risk assessment procedures, in line with federal, DHS, and ICE policy and practices.
v. Fulfillment of functional, business, and technical requirements.
c. While operating the AI system: The Contractor must re-test system performance, security, resiliency, and abuse/mis-use vulnerabilities before deploying new AI models, fine-tuned models, or other changes to AI systems that require Change Requests.
d. Audit and Logging: Ensure compliance with DHS and ICE AI auditing and logging requirements, including, but not limited to audit and logging the access, usage, and modification of:
i. AI Guardrails deployed in GenAI systems.
ii. Models, including parameters and weights.
iii. AI system inputs and outputs (including prompts).
iv. Additional requirements as determined by federal, DHS, and ICE policy.
LAW ENFORCEMENT SENSITIVE Page 15 of 33
e. Continuous Monitoring: The Contractor shall implement continuous monitoring mechanisms to detect and respond to anomalies, biases, or performance degradation in AI systems. Additionally:
i. The Contractor shall establish protocols for the timely remediation of identified issues, including the potential suspension of AI system operations if necessary.
APPENDIX A. General Cybersecurity Contract Requirements
A.1 Compliance with DHS Security Policy Terms and Conditions.
Compliance with DHS Security Policy Terms and Conditions:
All hardware, software, and services provided under this task order must be compliant with DHS National Security Systems Policy Directive 4300B, Version 10.1, November 21, 2018' for NSS Collateral (Unclass, Secret or Top Secret Collateral).
A.2 Compliance with DHS Security Policy Terms and Conditions.
All hardware, software, and services provided under this task order must be compliant with DHS 4300A DHS Sensitive System Program 4300A version 13.4 Dec. 6, 2024 and attachments.
A.3 Security Review Security Review Terms and Conditions The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford ICE, including the organization of ICE Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer Representative (COR), and other government oversight organizations, access to the Contractor's facilities, installations, operations, documentation, databases and personnel used in the performance of this contract.
The Contractor will contact ICE Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to ICE. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of ICE data or the function of computer system operated on behalf of ICE, and to preserve evidence of computer crime.
A.4 Supply Chain Risk Management Supply Chain Risk Management Terms and Conditions The Contractors supplying the Government hardware and software shall provide the manufacturer's name, address, state and/or domain of registration, and the Data Universal Numbering System (DUNS) number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNs number of those suppliers must also be provided.
Subcontractors are subject to the same general requirements and standards as prime contractors.
Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.
The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.
LAW ENFORCEMENT SENSITIVE Page 16 of 33
Contractors shall provide, implement, and maintain a Supply Chain Risk Management Plan that addresses internal and external practices and controls employed to minimize the risk posed by counterfeits and vulnerabilities in systems, components, and software.
The Plan shall describe the processes and procedures that will be followed to ensure appropriate supply chain protection of information system resources developed, processed, or used under this contract.
The Supply Chain Risk Management Plan shall address the following elements:
(i) How risks from the supply chain will be identified;
(ii) What processes and security measures will be adopted to manage these risks to the system or system components; and
(iii) How the risks and associated security measures will be updated and monitored.
The Supply Chain Risk Management Plan shall remain current through the life of the contract or period of performance. The Supply Chain Risk Management Plan shall be provided to the Contracting Officer Representative (COR/CO) 30 days post award.
The Contractor acknowledges the Government's requirement to assess the Contractors Supply Chain Risk posture. The Contractor understands and agrees that the Government retains the right to cancel or terminate the contract, if the Government determines that continuing the contract presents a risk to national security.
The Contractor shall disclose, and the Government will consider, relevant industry standard certifications, recognitions and awards, and acknowledgments.
The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the CO. Contractors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.
The Contractor shall be excused from using new OEM (i.e. "grey market, "previously used) components only with formal Government approval. Such components shall be procured from their original source and have them shipped only from manufacturers authorized shipment points.
For software products, the contractor shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “end of life"). Software updates and patches must be made available to the government for all products procured under this contract.
Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.
All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the contract, the period of performance, or one calendar year from the date the activity occurred.
These records must be readily available for inspection by any agent designated by the U.S.
Government as having the authority to examine them.
This transit process shall minimize the number of times en route components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments. The
LAW ENFORCEMENT SENSITIVE Page 17 of 33 supplier, at the Government's request, shall be able to provide shipping status at any time during transit.
The Contractor is fully liable for all damage, deterioration, or losses incurred during shipping and handling, unless the damage, deterioration, or loss is due to the Government. The Contractor shall provide a packing slip which shall accompany each container or package with the information identifying the contract number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact. The contractor shall send a shipping notification to the intended government recipient or contracting officer. This shipping notification shall be sent electronically and will state the contract number, the order number, a description of the hardware/software being ship (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.
A.7 3052.204-72 SAFEGUARDING OF CONTROLLED UNCLASSIFIED INFORMATION (JULY 2023)
(a) Definitions. As used in this clause—
Adequate Security means security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls.
Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .