View the file

Other files for this federal contract opportunity

Other files attached to International Technical, Operational, and Professional Support Services (ITOPS 4. 0), newest first.
File Type Posted
Real RFTOP South Africa 042923.pdf PDF
RFP 75D30123R63271 042223.pdf PDF
RFTOP Sample BRAZIL QA 042923.pdf PDF
Admendment 0001 050423.pdf PDF
RFTOP RWANDA Q A_ 042923.pdf PDF
RFTOP GHANA QA_042923.pdf PDF
Sample RFTOP Brazil 042923.pdf PDF
Real RFTOP Ghana 042923.pdf PDF
Real RFTOP Rwanda 042923.pdf PDF
RFTOP South Africa 042923.pdf PDF
IDIQ QA 042223.pdf PDF
14 QASP IDIQ.doc DOC document
10 RFTOP RWANDA QA format.docx DOCX document
6 Past Performance Survey.doc DOC document
RFP 75D30123R63271 031516.pdf PDF
12 RFTOP SOUTH AFRICA QA format.docx DOCX document
3 Real RFTOP Ghana.pdf PDF
2 Real RFTOP Rwanda.pdf PDF
11 RFTOP GHANA QA format.docx DOCX document
4 Real RFTOP South Africa.pdf PDF
13 Sample Business Proposal Spreadsheet.xlsx XLSX spreadsheet
9 Sample RFTOP BRAZIL QA format.docx DOCX document
8 IDIQ QA format.docx DOCX document
7 Proposal Preparation Certification V 2 0.docx DOCX document
5 Sample Consent Letter.docx DOCX document
Show all 25

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sample Request for Task Order Proposal (RFTOP)

Note: This is a sample task order only. It will not be awarded.

RFTOP NUMBER OR NAME Brazil

This Sample RFTOP incorporates provisions and clauses documented therein in the Indefinite

Delivery, Indefinite Quantity (IDIQ), RFP 75D30122R63271.

This sample RFTOP is a Cost-Reimbursement (Cost Plus Fixed Fee task) type.

Note: Only small businesses can provide a proposal response to this Sample task order.

ITOPSS 3.0 Request for Task Order Proposal (RFTOP)

1.Required Security Level Level 5 (Public Trust)

2.Type of Task Order Cost Plus Fixed Fee

3. Security Background

Requirements

Contractor is required to perform security/background checks prior to task order performance, based on the security level required. Note: This is sample task order and will not be awarded.

4. PWS Reference C.3.2.2 Operational Support Services

5. Period of Performance 6/1/2023 to 05/31/2025 - Note: This is sample task order and will not be awarded.

7.Number of Option Years, if applicable

Place of Performance Brazil

8.Task Order Administration Not Applicable since this is a Sample RFTOP

AUTHORITY TO OBLIGATE THE GOVERNMENT: The Task Order Contracting Officer is the only individual who may legally commit the U.S. Government to the expenditure of public funds. The Contractor may not incur costs chargeable to this task order before the receipt of either a task order signed by the Contracting

Officer or a specific written authorization from the Contracting Officer.

SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS

Note: Only small businesses can provide a proposal response to this Sample

Base Year

CLIN SUPPLIES / SERVICES QTY /

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL

COST PLUS

FIXED FEE

0001 Provide ITOPSS support services per as outlined in the Performance Work

Statement as set forth in Section C of the

Service Letters A, B, C:

Ltr A Program Operations Assistant

Ltr B Database Manager

Ltr C Extramural Program Manager

Period of Performance: 6/01/2023 to

5/31/2024

1 Job $ $ $

TOTAL

Option Year 1

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

1001 Provide ITOPSS support services per as outlined in the Performance Work

Period of Performance: 6/01/2024 to

5/31/2025

1 Job

Option Year 2

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

2001 Provide ITOPSS support services per as outlined in the Performance Work

Option Year 3

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

3001 Provide ITOPSS support services per as outlined in the Performance Work

Option Year 4

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

4001 Provide ITOPSS support services per as outlined in the Performance Work

Recapitulation:

CLIN ESTIMATED COST FIXED FEE TOTAL COST

PLUS FIXED FEE

Professional Support Services – Brazil

C. PERFORMANCE-BASED WORK STATEMENT (PWS)

C.1 Background and Need:

CDC’s mission is to promote the health and quality of life of people by preventing and controlling disease, injury, and disability. CDC through its Center for Global Health is in a position to bring its scientific expertise and credibility to the U.S. Global Health Initiative: “to protect the health of our people, while saving lives, reducing suffering, and supporting the health and dignity of people everywhere.” The key elements of CDC’s global health strategy are:

• Assist Ministries of Health to plan, effectively manage, and evaluate health programs;

• Achieve goals adopted by USG programs and international organizations to improve health, including disease eradication and elimination targets;

• Expand CDC’s global health programs that focus on the leading causes of mortality, morbidity and disability, especially chronic disease and injuries;

• Generate and apply new knowledge to achieve health goals; and

• Strengthen health systems and their impact.

CDC Field Epidemiology Training Program (FETP) is requesting the contractor seek a Resident

Advisor (RA) to reside and work in Samoa. A Resident Advisors (RA) is needed in country to develop a cadre of Ministry of health (MOH) field epidemiologists so that they are available for strengthening surveillance and outbreak response throughout the country. The FETP RA will help the Brazil MOH develop and strengthen the country’s capacity to prevent, respond and contain disease threats.

C. 2 Project Objective:

Provide continued support of Ministries of Health and engage local counterparts to strengthen field epidemiology.

C.2.A Overall Services and Service Information

All services require full-time, 40-Hour work weeks unless noted otherwise.

Service

Ltr

Service Title Approx. # of

People to

Provide

Services

A Program Operations Assistance 1

B Database Manager 1

C Extramural Program Manager 1

C.2.B Future Services

I. Additional services, applicable to this task order, may be required in the future. Additional services within 30% of those originally competed will not be re-competed for the duration of this task order. Services that go beyond the 30% limit will be competed under a new

Request for Task Order Proposal (RFTOP).

Example: 10 Services are initially competed and awarded o Task Order would allow for No More Than (3) Additional Services on this task order.

C.2.C Service Table A:

Service Title: Program Operations Assistant

Estimated Period of Performance: 6/01/2023 to 5/31/2025

# of Options, if applicable: 4

Place of Performance: Brazil

Embassy Access and Security Level: Level 5

Service Objectives: The primary responsibility for the Program Operations Assistant is to provide ongoing support to the CDC Brazil office, prepare routine administrative and management reports, assist in technical scientific reports, support travelers, and other duties as assigned. The Program Operations Assistant will coordinate activities with the COR, Brazil Office Country Director, and Deputy Director. The service will require excellent time management skills and the ability to prioritize work in addition to excellent written and verbal skills. The Program

Operations Assistant will require strong organizational skills.

A.1 Task Requirements:

A.1.1 Work with CDC Brazil office to facilitate the administrative tasks and daily requests. Assist in all administrative work inclusive of but not limited to the following:

A.1.2 Weekly reviews and maintains adequate office supplies for the CDC Brazil office. Prepare purchase requests for needed supplies; places and expedites orders for supplies; verifies receipt of supplies; prepares vouchers for reimbursement and ensuring appropriate approvals are obtained, submitted to US Embassy for reimbursement, and other inventory related activities. Follow up with services providers e.g. Internet Company, Phone Central

Company, Office Stationary Suppliers, Printing Companies, etc. may be required.

A.1.3 Weekly performance of accounting tasks such as completing financial documents and coordinate with the

Office of Acquisition Services (OAS) to ensure documents are submitted correctly and reimbursement for travelers, local travel reimbursement, etc. and reviewing monthly accounts

A.1.4 Weekly ensures that all scans, faxes, e-mails and electronically filed documents at the request of the CDC

Brazil office, COR, or CDC HQ are completed.

Task Deliverables:

Deliverables/Reports Task Requirement Recipient Due Date

Monthly Report A.1.1 – A.1.4 COR

Monthly by the 3rd

Minimum Qualifications and/or Certifications:

I.

• 4 years’ prior work experience in Administration position related to public health activities

• Prior work experience in public health office

• Course work in Public Health or Project Management

• Proficiency in MS Office (MS Excel and MS PowerPoint, in particular)

• Excellent time management skills and the ability to prioritize work

• Excellent written and verbal communication skills

• Strong organizational skills with the ability to multi-task

II. Only U.S. citizens or non-U.S. citizens who have lived in the U.S. at least three of the last five years are eligible to provide services under this task order. The exception to this is an incumbent non-U.S.

citizen employee with current, valid security clearance for physical and logical access to CDC and embassy facilities and network.

III. If the exception stated above is used, Do not include any contractor employee who is considered an ordinarily resident in your proposal. The definition of an ordinarily resident is listed below.

Ordinarily resident: A U.S. citizen or Third Country National who: (1) is a local resident;(2) has legal, permanent resident status within the host country; and (3) is subject to host country employment and tax laws. This also includes host country citizens.

Note: Service Letter A is not married, has no kids and lives in the United States as a citizen.

Travel Amount (Only applies to performance of Task Order):

Not-To-Exceed (NTE) $0 USD/Per Period of Performance

(Includes Transportation, Lodging/M&IE, etc.)

***Personal Development is not Allowable***

Government-Furnished Property (to include but not limited to laptop, blackberry, access to printers and office supplies, etc.):

• Workstation/laptop (software includes: Microsoft Office Suite and specific software to perform duties Access to transportation via United States Government (USG) vehicle as a passenger

• Other: desk office supplies, telephone and internet/hotspot at duty station (per written requirements)

• Office Space

Contractor Furnished Property, if applicable:

N/A

C.2.C Service Table B:

Service Title: Database Manager

Service Objectives: Assist in the design, development, update and implementation of data collection tools; data management, analysis, and reporting; and assisting the host country in updates and maintenance of electronic

(digital) systems, in support of public health infectious disease surveillance and research in Brazil region where U.S.

CDC projects are conducted.

B.1 Task Requirements:

B.1.1 Assist other staff to update, develop, and maintain the public health infectious disease database systems.

Duties include:

B.1.2 Recommend utilization of software programs such as Microsoft Access, Visual C, Visual Basic C, and other data packages in the performance of daily activities.

B.1.3 Aid in the training, deployment, and troubleshooting for the use of the digital data collection tools in the public health surveillance and research sites.

B.1.4 Provide training, assistance, and guidance to partners who use the database systems in administrative and technical areas including data transfer processes, analytics, data entry practices, data manipulation, and troubleshooting.

Monthly Report B.1.1 – B.1.4 COR

Monthly Report on management and processing of database systems and assist in database validation/completion

B.1.1 – B.1.4 COR Monthly by the 3rd

Travel Reimbursement

Report

B.1.1 – B.1.4 COR 15 day after completion of travel

• Bachelor’s degree in Management Information System (MIS), Computer Science or Information

Technology

• At least 15+ years of experience working in public health surveillance projects and computer science, information technology or international partners

• Experience in developing databases and data analysis

• 15+ years’ experience in providing technical support to strengthen the data management and improve data quality and providing advice/support to principle investigators for harmonized data management system (in terms of content, frequency, and data exchange format) for ministries of health, CDC, and other partners;

• Good communication skills;

• Ability to work both independently and effectively with interdisciplinary colleagues at different levels of the organization.

II. Only U.S. citizens or non-U.S. citizens who have lived in the U.S. at least three of the last five years are eligible to provide services under this task order. The exception to this is an incumbent non-U.S.

citizen employee with current, valid security clearance for physical and logical access to CDC and embassy facilities and network.

III. If the exception stated above is used, Do not include any contractor employee who is considered an legal, permanent resident status within the host country; and (3) is subject to host country employment

Note: Service Letter B is married, has no kids and lives in the United States as a citizen. Service Letter B will be bringing their spouse with them for this opportunity.

Travel – NTE $15,000.00 (Overall Estimated Travel Cost) :

• 3 Trips for an estimated 5 days each.

Actual travel may vary by a couple of days.

Not-To-Exceed (NTE) $15,000 USD/ performance period.

Note: Use the $15,000 per performance period as the TOTAL value per year.

Note: No conference travel is allowed. If a conference travel is requited, the Contracting Officer will issue a formal modification in advance.

Government-Furnished Property (to include but not limited to laptop, blackberry, access to printers and office

• Other: desk office supplies, telephone and internet/hotspot at duty station (per written

C.2.C Service Table C:

Service Title: Extramural Program Manager

Service Objectives: Assist the CDC Brazil Office with implementation, monitoring, and oversight of Grants, Contract and Financial Management projects.

C.1 Task Requirements:

C.1 – Provide oversite related to the initiation, administration, and/or close-out of contracts, grants, and/or cooperative agreements, including responsibility for development, negotiation, and monitoring performance.

C.1.1 - Manage or assists in the management of contracts, grant/cooperative agreement pre- and post award, administration, and/or close-out activities.

C.1.2 - Serve as point of contact for involvement with Center staff regarding program study activities needing assistance from financial management and the procurement and grants office.

C.1.3 - Participate in periodic (monthly or as otherwise agreed upon) calls with country support staff in headquarters

(CDC-Atlanta)

Monthly Report C.1 – C.1.3 COR

Contract, Grant

Management and

Purchase Order status

C.1 – C.1.3 COR Monthly by the 3rd

Travel Reimbursement

Report

C.1 – C.134 COR 15 day after completion of travel

• Bachelor’s Degree in Business or Financial Management

• 4 years’ prior work experience in Administration position related to public health activities

• Prior work experience in public health office

• At least 10+ years of experience working in public health federal contracts and grants

• Good communication skills;

• Ability to work both independently and effectively with interdisciplinary colleagues at different levels of the organization.

• Experience with Financial Management System and Budget

II. Only U.S. citizens or non-U.S. citizens who have lived in the U.S. at least three of the last five years are eligible to provide services under this task order. The exception to this is an incumbent non-U.S.

citizen employee with current, valid security clearance for physical and logical access to CDC and embassy facilities and network.

III. If the exception stated above is used, Do not include any contractor employee who is considered an legal, permanent resident status within the host country; and (3) is subject to host country employment

Note: Service Letter C is married, with 2 kids ages 8 and 12 and lives in the United States as a citizen. Service Letter

C will be bringing their family with them for this opportunity .

Travel – NTE $15,000.00 (Overall Estimated Travel Cost) :

• 3 Trips for an estimated 5 days each.

Actual travel may vary by a couple of days.

Not-To-Exceed (NTE) $15,000 USD/ performance period.

Note: Use the $15,000 per performance period as the TOTAL value per year.

Note: No conference travel is allowed. If a conference travel is requited, the Contracting Officer will issue a formal modification in advance.

Government-Furnished Property (to include but not limited to laptop, blackberry, access to printers and office

• Other: desk office supplies, telephone and internet/hotspot at duty station (per written

C.3 Place of Performance

Brazil

C.4 Performance-Based Matrix

C.5 Authority to Obligate Government

The Task Order Contracting Officer is the only individual who may legally commit the U.S.

Government to the expenditure of public funds. The Contractor may not incur costs chargeable to this task order before the receipt of either a task order signed by the Contracting Officer or a

Service

Required

Measures of

Success Indicators

Standards -

Criteria for

Acceptance

Method of

Surveillance

"Incentives"

Positive or

Negative

All Tasks and

Deliverables from Service

Table A, B &

C.

Contractor shall perform all tasks/services in accordance with

(IAW) applicable regulatory standards, task order requirements, and procedural guidelines as stated in this task order.

100% of

Services/tasks adhere to applicable regulatory standards, task order requirements, and procedural guidelines as stated in this task order.

COR

approval and observation.

Positive: Past

Performance and

Evaluation will be used in determining awards for future task orders for similar services;

Negative:

Performance evaluations will include any services that failed to meet acceptable standards and will be used in determining awards for future task orders for similar services

Timeliness –

(1)All tasks, reports, and deliverables completed within due date specified in Section C.3

100% of time –All tasks, reports, and deliverables shall be performed by due date specified in Section C.3 unless delay is approved in advanced by COR.

COR

approval and observation.

Positive: Past

Performance and

Evaluation will be used in determining awards for future task orders for similar services;

Negative:

Performance evaluations will include any services that failed to meet acceptable standards and will be used in determining awards for future task orders for similar services.

specific written authorization from the Contracting Officer.

C.6 Security Background Requirements

Contractor employees are required to receive Level 5/NACI security/background checks prior to task order performance. The security process is initiated when contracting organization provides contractor employee’s NACI results to the Office of Safety, Security and Asset Management personnel and personal identifying information to the Headquarters Contracting Officer

Representative.

D. Not Used

E. Refer to Base Contract Section E

F. Refer to Base Contract Section F

F.1 See CLINS for Period of performance.

G. CONTRACT/TASK ORDER ADMINISTRATION DATA

The Clauses found in the IDIQ base shall contract remain in full force and effect for this Task Order.

G.1 See Cover for Contact Information

G.2 CDCA_G01101 Contractor Billing Instructions for Cost-Type Contracts (Mar 2022)

The Contractor shall submit a detailed breakout of costs and supporting backup information and shall place the following signed Contractor Certification on each invoice/voucher submitted under this contract:

I certify that this voucher reflects (fill in Contractor’s name) request for reimbursement of allowable and allocable costs incurred in specific performance of work authorized under Contract

(fill in contract number)/Task (fill-in task order number, if applicable), and that these costs are true and accurate to the best of my knowledge and belief.

(Original Signature of Authorized Official)

Typed Name and Title of Signatory

Introduction

Reimbursement procedures related to negotiated cost-type contracts require that Contractors submit to the Government adequately prepared claims. The instructions that follow are provided for

Contractors’ use in the preparation and submission of invoices or vouchers requesting reimbursement for work performed. The preparation of invoices or vouchers as outlined below will aid in the review and approval of claims and enable prompt payment to the Contractor.

1. Forms to Be Used

In requesting reimbursement, Contractors may use the regular Government voucher form, Standard

Form 1034, “Public Voucher for Purchases and Services Other Than Personal,” and Standard Form

1035, “Continuation Sheet,” or the Contractor’s own invoice form. If the Contractor desires to use the Government’s standard forms, a request for the forms should be submitted to the Contracting

Officer. If the Contractor uses his own invoice, the billing must conform to the instructions set forth herein.

2. Submission of Invoices or Vouchers

Will be conducted in accordance with HHSAR 352.232-71 Electronic Submission of Payment

Requests

3. Preparation of Invoices or Vouchers- All invoices or vouchers must include the following information:

a. Summary of All Costs – typically inserted on the Standard Form 1034

A summary of all current costs must be shown. This summary consists of a list identifying the general categories and the amounts incurred during the period covered by the billing, together with the portion of fixed fee (if any) payable for that period. The reimbursable costs incurred and the dates of the period for which the charges are claimed must fall within the period specified in the contract.

b. Details of Costs Claimed – typically inserted on the Standard Form 1035 (continuation sheet)

A detailed breakdown must be provided to substantiate the categories shown on the summary of costs. The following describes some of the categories that might appear on your billings:

(1) Direct Labor

Direct Labor costs consist of salaries and wages paid for scientific, technical, and other work performed directly for the contract and pursuant to the contract terms. Labor costs, excluding fringe benefits and overtime premium pay, will be billed as follows:

List the titles and amounts for employees whose salaries or wages, or portions thereof, were charged to the contract; show the rate (or hours) worked, and amount for each individual. The cost of direct labor, which is charged directly to the contract, must be supported by time records maintained in the contractor’s office.

(2) Fringe Benefits

If it is the Contractor’s established practice to treat fringe benefits as a direct cost, such costs should be billed separately as a single item.

NOTE: Fringe benefits, bonuses, etc., are usually treated as indirect costs for inclusion in the overhead pool; however, they may be treated as direct labor costs or as an “Other Direct Charge” if such treatment is in accordance with the Contractor’s established accounting procedures.

(3) Premium Pay

Premium pay is the difference between the rates and amounts paid for overtime or shift work and amount normally paid on a straight time basis. Generally such pay is not included in the direct labor base and should not be included in the billing for “direct labor” unless the Contractor has consistently followed this practice in the past as a matter of policy. Premium pay of any kind unless provided for in the contract must be authorized by the Contracting Officer in advance. Billings for unauthorized premium pays have caused frequent delays in payment due to suspensions and exchange of correspondence. Citations of authorization for premium pay will avoid delays in payment. Authorized premium pay may be shown as a single item on the summary of costs.

However, it must be separately itemized for each position, or job category, showing the amount, and a citation of the Contracting Officer’s letter of authorization on the continuation sheet of the invoice or voucher.

(4) Materials and Supplies

Only those items, which the Contractor normally treats as “direct costs”, should be claimed under this heading. Major classifications of material only should be billed separately under appropriate classification. Items costing less than $25.00 may be listed by category of materials or supplies.

Show the description and dollar amount of individual classifications. All such charges must be supported by the Contractor’s office records.

(5) Travel

When authorized in the contract as a direct cost, travel costs that are directly related to specific contract performance may be billed as a direct cost. Travel cost detail should show:

(a) Name of traveler and official title,

(b) Purpose of trip,

(c) Dates of departure and return to starting point (station or airport),

(d) Transportation costs, identified as to rail, air, private automobile (including mileage and rate) and taxi.

(e) If claim for subsistence is on per diem basis, show number of days, rate and amount, as authorized in contract.1 If claim is based on actual cost of subsistence, show, on a daily basis, the amounts claimed for lodging and meals separately.

(f) Reference to Contracting Officer’s letter of authorization if required by contract.

1For purposes of computing per diem charges in lieu of actual subsistence charges, unless otherwise provided in the contract, a day is divided into four quarters that begin at 12 midnight, 6:00 AM, 12 noon, and 6:00 PM. For example, at an authorized per diem rate of $35.00 per day, a traveler who departed at 9:15 AM on July 15 and returned at 6:45 PM on July 18 would be entitled to $131.25.

(6) Consultant Fees

Identify the consultant by name, number of days utilized, and amount of fee.

(7) Equipment

Nonexpendable personal property must be specifically approved in writing by the Contracting

Officer or authorized by the terms of the contract. Billing data should include a description of item, make model, quantity, unit cost, total cost, and date approved by the Contracting Officer, if applicable. A copy of the vendor’s bill may be submitted in lieu of the identifying information.

(8) Burden

Pending establishment of final contract indirect cost rates for each of the Contractor’s fiscal years, the Contractor will be reimbursed based on his submittal of provisional rates as set forth in the contract. The contract may provide for more than one type of indirect cost rate, such as overhead rate, and general and administrative expense rate, in which case the direct cost bases (e.g., direct labor, total direct cost, etc.)

(9) Fixed Fee

Ordinarily the fixed fee is stated in the contract as a lump sum and may be billed in the ratio of incurred costs to total estimated cost as set forth in the contract, with the final 15 percent to be billed on the final invoice or voucher. Contract terms govern the method of payments.

c. Cumulative Amount Claimed – typically inserted on Standard Form 1035 (continuation sheet) separate section/page

The Contractor must show the cumulative amounts claimed by categories from the contract award date through the date of the current invoice or voucher, as well as the estimated cost to complete per category.

QUICK CHECKLIST FOR INVOICE SUBMISSION:

• Standard Forms 1034 and 1035 recommended. If submitting own forms, statement must conform to billing instructions

• Quarterly billing as a minimum

• Vouchers must be collated

• Detail of Cost Claimed

G.3 CDCP_G010 Contract Communications/Correspondence

(Jul 1999)

The Contractor shall identify all correspondence, reports, and other data pertinent to this contract by imprinting thereon the contract number from Page 1 of the contract.

G.4 352.232-71 Electronic Submission of Payment Request

(a) Definitions. As used in this clause—

(1) “ Payment request” means a bill, voucher, invoice, or request for contract financing payment with associated supporting documentation. The payment request must comply with the requirements identified in FAR 32.905(b), “Content of Invoices” and the applicable Payment clause included in this contract.

(b) Except as provided in paragraph (c) of this clause, the Contractor shall submit payment requests electronically using the Department of Treasury Invoice Processing Platform (IPP) or successor system. Information regarding IPP, including IPP Customer Support contact information, is available at www.ipp.gov or any successor site.

(c) The Contractor may submit payment requests using other than IPP only when the Contracting

Officer authorizes alternate procedures in writing in accordance with HHS procedures.

(d) If alternate payment procedures are authorized, the Contractor shall include a copy of the

Contracting Officer's written authorization with each payment request.

(End of Clause)

H. Special Provisions

The Clauses found in the IDIQ base shall contract remain in full force and effect for this Task

Order.

Note : The non personal service clause is in Section H of the base contract.

H.1. Ability to Legally Provide Services Overseas

a. The Prime Contractor is responsible for acquiring all legally appropriate work permits and visas, without CDC assistance, to ensure that services are performed in accordance with host country requirements.

b. In the event that the Prime Contractor is unable to acquire all legally appropriate work permits and visas, after reasonable time has been allowed for host country appeals (if necessary), CDC may terminate the task order.

b.1. “Reasonable Time” is relative based upon each country’s circumstances. CDC has not set a timeline for making this decision, but will communicate directly with the Prime Contractor and COR throughout the process of acquiring all legally appropriate work permits and visas.

H.2. Information Security and/or Physical Access Security

A. Baseline Security Requirements

1) Applicability. The requirements herein apply whether the entire contract or order

(hereafter “contract”), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal

Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology”

(IT), the term as used in this section includes computers, ancillary equipment

(including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

2) Safeguarding Information and Information Systems. In accordance with the Federal

Information Processing Standards Publication (FIPS) 199, Standards for Security

Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information

Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.

3) Information Security Categorization. In accordance with FIPS 199 and National

Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II:

Appendices to Guide for Mapping Types of Information and Information Systems to

Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall

Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [X] Low [] Moderate [ ] High

Integrity: [] Low [X] Moderate [ ] High

Availability: [X] Low [] Moderate [ ] High

Overall Risk Level: [] Low [X] Moderate [ ] High

Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[] No PII [X] Yes PII

4) Personally Identifiable Information (PII). Per the Office of Management and Budget

(OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.

PII Confidentiality Impact Level has been determined to be: [ ] Low [] Moderate [ ] High

5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at

32 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term

“handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg.

63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:

a. marked appropriately;

b. disclosed to authorized personnel on a Need-To-Know basis;

c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for

Federal Information Systems and Organizations applicable baseline if handled by a

Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and

d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.

Destruction of information and/or data shall be accomplished in accordance with NIST SP

800-88, Guidelines for Media Sanitization.

6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.

7) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of

HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the

Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:

a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

8) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol

Version 6 (IPv6).

9) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP

Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.

10) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.

Document Deliverable

Title/Description

Due Date

Roster Roster By effective date of this contract

Contractor Employee

Non-Disclosure

Agreement (NDA)

Contractor Employee

Non-Disclosure

Agreement (NDA)

Prior to performing any work on behalf of

HHS

Privacy Threshold

Analysis (PTA)/

Privacy Impact

Assessment (PIA)

Assist in the completion of a PTA/PIA form

In conjunction with contract award

Training Records Copy of training records for all mandatory training

In conjunction with contract award and annually thereafter or upon request

Rules of Behavior Signed ROB for all employees

Initiation of contract and at least annually thereafter

Incident Response Incident Report (as incidents or breaches occur)

As soon as possible and without reasonable delay and no later than 1 hour of discovery

Incident Response Incident and Breach

Response Plan

Upon request from government

Personnel Security

Responsibilities

List of Personnel with defined roles and responsibilities

Prior to performing any work on behalf of

HHS

11)

Standard for Encryption. The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and

Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS

140-2 validated encryption solution.

c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use have been validated under the

Cryptographic Module Validation Program to confirm compliance with FIPS 140-2.

The Contractor shall provide a written copy of the validation documentation to the

COR.

e. Use the Key Management system on the HHS personal identification verification

(PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys.

Encryption keys shall be provided to CDC Office of Chief Information Security

Officer (OCISO).

12) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this

Personnel Security

Responsibilities

Off-boarding documentation, equipment and badge when leaving contract

Prior to performing any work on behalf of

HHS

Background

Investigation

Onboarding documentation when beginning contract

Prior to performing any work on behalf of

HHS

Certification of

Sanitization of

Government and

Government Activity-

Related Files, Information, and

Devices

Form or deliverables required by CDC

At contract expiration

Contract Initiation and

Expiration

If the procurement involves a system or cloud service, additional documentation will be required, such as

Disposition/Decommissi on Plan

At contract expiration contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO

Representative (COR) prior to performing any work under this acquisition.

13) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The

Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.

a. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle

(SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.

B. Training

1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable

HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract.

Thereafter, the employees shall complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.

2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.

All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.

3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

C. Rules of Behavior

1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.

2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC

Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.

D. Incident Response

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT

Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by Federal Information Security

Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally

Identifiable Information” (03 January 2017) states:

Definition of an Incident:

An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

Definition of a Breach:

The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

It further adds:

A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.

The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.

Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:

1) The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.

2) All contractors and subcontractors shall properly encrypt PII in accordance with

OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any

PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.

3) All contractors and subcontractors shall participate in regular training on how to identify and report a breach.

4) All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer

Security Incident Response Center (CSIRC) or CDC Computer Incident Response

Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655-

2245, whether the response is positive or negative.

5) All contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.

6) All contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with

HHS/CDC Policy and the HHS/CDC Breach Response Plan and to assist with responding to a breach.

7) Cloud service providers shall use guidance provided in the FedRAMP Incident

Communications Procedures when deciding when to report directly to US-CERT first or notify CDC first.

8) Identify roles and responsibilities, in accordance with HHS/CDC Breach

Response Policy and the HHS/CDC Breach Response Plan. To this end, the

Contractor shall NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative. If so, instructed by the

Contracting Officer or representative, all notifications must be pre-approved by the appropriate CDC officials, consistent with HHS/CDC Breach Response Plan, and the Contractor shall then send CDC- approved notifications to affected individuals;

and,

9) Acknowledge that CDC will not interpret report of a breach, by itself, as conclusive evidence that the contractor or its subcontractor failed to provide adequate safeguards for PII.

E. Position Sensitivity…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .