10PSPR-15-0020_Security_Wage_Rates.pdf

PDF 3 MB Posted

Attached to
CBP Kitchenette Renovation Federal contract opportunity
Solicitation number
10PSPR-15-0020
Issued by
General Services Administration Public Buildings Service Region 10

About this file

Security Requirements and Wage Rates

View the file

Other files for this federal contract opportunity

Other files attached to CBP Kitchenette Renovation, newest first.
File Type Posted
QA2.docx DOCX document
1-SF_30_RFP_SOW_Changes_MERGED.pdf PDF
SF_30_RFP_Extension_RFP-MERGE.pdf PDF
QA1.pdf PDF
3a-Kitchenette_Line_Item_Pricing_Spreadsheet.xlsx XLSX spreadsheet
10PSPR-15-0020_Request-for-Proposal.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

GENERAL SERVICES ADMINISTRATION

Washington, DC 20405

PBS P 3490.2

GSA POLICY AND PROCEDURE

SUBJECT: Document Security for Sensitive But Unclassified Building Information

1. Purpose. This directive describes GSA’s policy to protect sensitive but unclassified (SBU) building information for GSA-controlled space. GSA-controlled space includes owned, leased, and delegated Federal facilities. Not all building information is automatically considered sensitive but unclassified. Only specific applicable information, marked with SBU designations, needs to be controlled in accordance with this policy. GSA will use SBU terminology and markings on all building information in all formats (see Appendix B). Both legacy SBU and new SBU building information will be subject to the terms of this directive.

2. Background. GSA has been marking and managing sensitive but unclassified building information and has issued several updates to the policy since the bombing of the Alfred Murrah Federal Building in 1995.

Executive Order 13556, signed on November 4, 2010, establishes a program for managing Controlled Unclassified Information, with the National Archives and Records Administration (NARA) serving as the executive agent. This Executive Order emphasizes “…the openness and uniformity of Government-wide practice.” GSA has been working with NARA in developing Controlled Unclassified Information (CUI) standards and best practices. Upon completion of NARA’s CUI efforts and directives (with expected implementation to start April 2016), GSA’s SBU designation will be replaced with the NARA CUI designation and this directive will be updated to reflect the new CUI requirements.

3. Cancellation. PBS 3490.1A Document Security for Sensitive but Unclassified Building Information, issued June 1, 2009, is cancelled, effective immediately.

4. Scope and Applicability. This directive applies to the access to and generation, dissemination, storage, transfer and disposal of all SBU building information related to GSA-controlled space and to procurements to obtain, alter, or manage space, either Government-owned or leased, including GSA space that is delegated to other Federal agencies.

a. All sensitive building information shall be marked and managed as SBU in accordance with this directive.

http://www.gpo.gov/fdsys/pkg/FR-2010-11-09/pdf/2010-28360.pdf

i. General Services Administration Information Technology (GSA IT), along with PBS business lines, will develop a system to track project SBU building information, to be implemented in a phased approach and completed within five years of the issuance date of this directive.

b. Existing SBU documents shall be controlled under this directive when procuring and contracting for design and construction services for renovations to existing facilities. For new facilities, the building drawings and other related building information will be reviewed and may be designated SBU, as appropriate. This designation applies at the time SBU building information is turned over by the Architect-Engineering (A-E) personnel to the Government as part of the final construction control documents. However, not all building information will be designated as SBU.

THIS DIRECTIVE DOES NOT APPLY TO CLASSIFIED BUILDING INFORMATION,

which is governed by Executive Order 13526 - Classified National Security Information.

5. Policy Objectives. This directive has three principal objectives:

a. To diminish the potential that building information will be available for use by a person or persons with an interest in causing harm, and

b. To allow access to this information to those recipients who have a legitimate business need to know such information.

c. To ensure a “Business Need to Know” exists. All individuals must have a legitimate purpose to handle SBU building information. They must use good judgment, common sense and take reasonable care to ensure that sensitive building information is protected in accordance with this directive.

6. Definitions.

a. “SBU building information” is information related to GSA-controlled space that is sufficiently sensitive to warrant some level of protection from full and open public disclosure, but does not warrant classification. This information requires safeguarding and dissemination controls in order to diminish the potential that building information will be accessible to a person or persons with an interest in causing harm. Appendix A provides a list of examples of SBU building information. This list is for illustrative purposes and is not comprehensive.

b. A “Business Need to Know” exists when access to SBU building information is necessary for the conduct of official GSA business. Some examples of individuals who may have a legitimate “business need to know” are GSA project managers, staff from the Office of the Inspector General (OIG), authorized vendors, utilities, state and local fire department personnel, among others. This directive does not describe all instances of a legitimate “business need to know”.

7. Clarification of GSA Order CIO P 2181.1. All building drawings or building information should not be designated, automatically, as SBU. Refer to Appendix A of this document for guidance. GSA Order CIO P 2181.1 provides the policy and procedures for issuing and maintaining GSA credentials. Chapter 2, Section 4.b.(4) of GSA Order CIO P 2181.1 states, “Those individuals whose duties require a higher degree of trust, such as IT system administrators, those who handle financial transactions, or those who deal with PII, and other sensitive information (e.g., building drawings, etc.), will continue to require investigations associated with higher levels of trust such as the Minimum Background Investigation (MBI) or the Limited Background Investigation (LBI).” These requirements shall not be used to restrict access to SBU building information further than as clarified in Section 4 (Applicability) of this directive.

Access to sensitive building drawings may be granted on a 'Business Need to Know' basis (as concurred on by the respective GSA business line) without regard to the credentialing cited above.

8. Signature.

/S/_______________________________ September 2, 2014

NORMAN DONG

Commissioner Public Buildings Service

PBS P 3490.2 Document Security for Sensitive But Unclassified Building Information

Table of Contents

GENERAL REQUIREMENTS AND RESPONSIBILITIES……………………………………………1

SPECIFIC REQUIREMENTS AND RESPONSIBILITIES…………………………………………

Appendix A. Examples of Sensitive But Unclassified Building Information………………….….A-1

Appendix B. Sensitive But Unclassified Marking Information………………………………….…B-1

Appendix C. SBU Contract Clause………………………………………………………………….C-1

GENERAL REQUIREMENTS AND RESPONSIBILITIES

The principles governing the management of SBU building information are as follows for all GSA personnel and contractors:

1. SBU building information shall be controlled so that building information in electronic and hard copy formats are made available only to individuals who have a legitimate business need to know (see Appendices A and B).

2. Adequate controls shall be used to monitor access to and dissemination of SBU building information.

3. SBU building information shall be safeguarded during use and either properly destroyed or returned to GSA after use.

4. SBU information shall not be presented in public forums.

5. The SBU designation of each building’s information (for design, construction bidding, facility management, etc.) shall be based on the specific information’s level of sensitivity and the physical security level of the building itself.

SPECIFIC REQUIREMENTS AND RESPONSIBILITIES

1. Public Buildings Service. The Public Buildings Service (PBS) is ultimately responsible for protecting SBU building information from unauthorized use and for making the initial determination of whether an entire building, or portion thereof, is considered sensitive.

2. PBS Regional Commissioners (RCs). PBS RCs or authorized designee (or in the case of delegated buildings, agency officials), make the initial determination regarding whether a building’s documents/information or portion thereof are/is considered sensitive. That determination shall in turn trigger an action on the part of the PBS Project Manager or Program Manager to mark the necessary related building information as SBU.

a. RCs shall consider the physical security level of the building itself, as well as comparable building types and occupants in making the determination whether or not a building’s documents/information or portion thereof are/is sensitive.

b. The RC shall designate an individual responsible for controlling SBU building information.

c. RCs must implement this directive within their Regions in a uniform, consistent manner so that all items containing SBU building information are marked and handled appropriately.

d. In the case of a new building in the planning stages, for a single tenant, the RC in consultation with the tenant will hold decision-making authority in determining the appropriate sensitivity of building information.

e. In the case of a new building in the planning stages, for multiple tenants, the RC in consultation with all planned tenants will hold decision-making authority in determining the appropriate sensitivity of building information.

3. Tenants. In the case where the tenant or tenants require/s a greater sensitivity designation than for comparable building types and occupants, this tenant or group of tenants will be required to pay any extra costs associated with higher security requirements and less competition in procurement. The tenant/s will agree to fund such costs via rent, Reimbursable Work Authorization, etc., as applicable. Extra costs may be due to limits on Architect-Engineering (A-E) personnel access, bidding restrictions, reduced competition for construction or facility management, or other factors. The RC or designee will assist the tenant in identifying the cost of higher security requirements.

Within a Federal campus, the SBU designation may apply to one or more buildings as needed, but will not automatically apply to all buildings within the same campus if any particular building(s) is (are) designated as SBU.

4. PBS Project Manager or Program Manager (PM). The PBS PM is responsible for reviewing all building documents, identifying and marking SBU building information, and including instructions in Statements of Work (SOWs) for contractors to mark documents as SBU, if appropriate.

a. The PBS PM shall identify and mark as SBU, in electronic or paper formats, only the building information that meets the criteria for SBU, which must be controlled, as stated herein. The PBS PM shall refer to Appendix A of this directive for further guidance.

b. The PBS PM shall coordinate with various groups (tenants, stakeholders, the Facility Security Committee, etc.) on all matters pertaining to building information.

c. The PBS PM, in consultation with the Facility Security Committee (FSC), is responsible for reviewing all building information at every milestone where there is a change in the physical space or tenant, to validate SBU markings are correct and current.

d. If building information designation is found to be incorrectly marked or no longer required, the PBS PM shall follow the instructions related to Mandatory Review in paragraph 11 below.

5. Facility Security Committee (FSC). After construction is complete, FSC or its current equivalent, as established by the standards of the Interagency Security Committee (ISC), shall advise the PBS PM regarding specific building information where SBU markings are necessary.

a. When a building is not designated as sensitive, the FSC, or its current equivalent, may still determine that some specific building information must be controlled. In this case, the FSC shall advise the PM to mark only that specific building information as SBU. The FSC shall refer to Appendix A of this directive for further guidance.

6. Disseminators. Disseminators of SBU building information must comply with the all policy principles and requirements of this directive. SBU building drawings that are part of a procurement must be issued in accordance with FAR 5.102(a)(4) on the secure side of the FedBizOpps website (https://www.fbo.gov/), or any successor system, with proper document control protocols to allow legitimate registered vendors access to the documents for proposing and pricing the procurements.

7. Contracting Officers (COs). COs shall include the clause in Appendix C, or a similar updated clause per the General Services Administration Acquisition Manual (GSAM), in all solicitations (including Solicitations for Offers (SFOs)) and in all building contracts and/or final leases that may contain, require access to, or cause the generation of SBU building information. This applies to all contracts issued after issuance of this directive and implementation of the rule making process, whichever occurs later.

a. Examples of such contracts are A-E design, construction, facility management contracts, and related professional service contracts such as construction manager as agent (CMa) and Commissioning Agent (CxA) contracts.

https://www.fbo.gov/

b. COs must take appropriate action when they become aware that contractors have not fulfilled contractual obligations regarding the protection of SBU building information. Such action may include an investigation, referring the contractor for suspension or debarment proceedings, and/or terminating the contract for default.

8. GSA Employees. GSA Employees may disseminate SBU building information only after a proper review and the imprinting or affixing of a mark, as required by this directive (see Appendix B for marking guidance), and after determining that the recipient of SBU building information is authorized to receive such information before dissemination of that information.

9. General Counsel. The Office of General Counsel (OGC) provides legal advice concerning Freedom of Information Act (FOIA) requests that apply to SBU building information. OGC also provides counsel regarding the application of this directive.

10. All PBS Regional Commissioners, Assistant Commissioner and Deputy Assistant Commissioners must make their respective personnel aware of the requirements in this directive and require that their staffs be trained in the proper application of this directive, including encryption software applications available to GSA personnel and contractors:

11. Mandatory review. For building projects (for design, construction, facility management, etc.), the PBS PM is responsible for reviewing all building information which does or may contain SBU building information at regular milestones (such as change in use, configuration or tenant); the PBS PM is responsible for identifying and validating that SBU markings are correct and current. If building information designation is found to be incorrectly marked or no longer required, the PBS PM will correct the marking immediately or ensure that action is taken promptly to change or remove the marking.

12. Marking information. For any electronic or printed SBU building information created after the issuance date of this directive, pages containing SBU building information must have the markings shown in Appendix B imprinted or affixed.

13. Limiting dissemination to authorized recipients. SBU building information may be disseminated only after it is determined by GSA personnel that each recipient is authorized to receive it. The criterion to determine whether a recipient is authorized to receive SBU building information is that the recipient must have a legitimate business need to know, as further described in Section 4 (Scope and Applicability) of the transmittal for this directive.

a. Federal, State, and local government entities. GSA must provide SBU building information for the performance of official Federal, State, and local government functions, such as inspections, OIG audits, code compliance reviews and issuance of building permits, among other purposes. Public safety entities such as fire departments may require access to SBU building information on a ‘need to know’ basis. This directive must not prevent or encumber the dissemination of SBU building information to public safety entities.

b. Vendors, Nongovernment entities and utilities. Unless the action is exempt under FAR 4.1102, all disseminators are responsible for verifying that a contractor or contracting firm is currently registered as "active" in the System of Award Management (SAM) database at www.sam.gov and also has a legitimate business need to know SBU building information before releasing it to any contractor or firm. Nongovernment entities and/or utility companies may also require access to SBU building information for the performance of work on GSA-controlled space on a ‘need to know’ basis and do not necessarily need to register within the SAM database.

14. Electronic transmission of SBU building information. GSA employees, who electronically transmit SBU building information outside of the GSA network, must encrypt the data with an approved NIST algorithm, such as Advanced Encryption Standard (AES) or Triple Data Encryption Standard (3DES), in accordance with Federal Information Processing Standards Publication (FIPS PUB) 140-2, Security Requirements for Cryptographic Modules. As email outside of the GSA network is not encrypted, GSA personnel working within the GSA network may only transmit SBU building information using GSA-approved encryption procedures. (“Within the GSA network” means inside the firewall, including Citrix and GSA VPNs.)

15. Dissemination of SBU building information in non-electronic form or on portable electronic data storage devices. Portable electronic data storage devices include but are not limited to CDs, DVDs, and USB drives. Non-electronic forms of SBU building information include paper documents.

a. By mail. GSA employees must utilize only methods of shipping that provide confirmation of receipt of the SBU building information, such as track and confirm, proof of delivery, signature confirmation, or return receipts.

b. In person. GSA employees must provide SBU building information only to authorized representatives of Federal, State, local government entities, SAM-registered firms, and others that have a legitimate business need to know such information.

16. Safeguarding SBU building information. GSA employees must not take SBU building information outside of GSA facilities, except as necessary for the performance of a GSA project. If a GSA employee takes SBU building information outside of a GSA facility, access to the information must be limited to those with a legitimate business need to know. Such information must be returned to a GSA facility or destroyed when no longer needed for the performance of a GSA project. GSA employees must not store or retain SBU building information on any electronic device or media not owned by GSA.

17. Destroying SBU building information. When SBU information, in any format, is no longer needed, SBU building information must be destroyed such that the information is rendered unreadable and incapable of being restored, in accordance with GSA CIO IT

Security 06-32, Media Sanitization Guide and Appendix A of NIST Special Publication 800-88, Guidelines for Media Sanitation. Alternately, the SBU building information may be returned to the CO.

18. Freedom of Information Act (FOIA) requests. SBU markings do not control the decision of whether to disclose or release the information to any entity that files a FOIA request. Any determination to disclose SBU building information, in accordance with a FOIA request, must be made after consultation with the servicing legal office.

19. Reporting incidents of concern. Any actual or suspected unauthorized disclosure of SBU information must be reported immediately to the CO for the related contract or the appropriate RC. RCs are required immediately to notify the FSC for the building involved. Any incident involving suspected computer or cyber security breach or attack, as defined by NIST Special Publication 800-61, Computer Security Incident Handling Guide, must be reported in accordance with the current version of GSA CIO P 2100.1, Information Technology (IT) Security Policy Order and GSA CIO IT Security Procedural Guide: CIO-IT Security-01-02, Incident Response (IR).

A-1

Appendix A. Examples of Sensitive But Unclassified Building Information

Not all building information is automatically considered Sensitive But Unclassified (SBU). After the PBS Project Manager (PM) has reviewed, identified, and marked SBU building information, then access to the information must be controlled. SBU building information may be contained in any document (including drawings, specifications, virtual modeling, reports, studies, analyses) and in any format with information pertaining to:

1. Location and details of secure functions or secure space in a building, location or space. Examples include:

a. Prisoner or judges’ secure circulation paths or routes (both vertical and horizontal).

b. Detention or holding cells.

c. Sally ports.

d. Security areas, including but not limited to control rooms and incident command centers

e. Building automation systems.

f. Telephone and riser closets

2. Location and type of structural framing for the building, including any information regarding structural analysis. Examples include information related to:

a. Progressive collapse.

b. Seismic.

c. Building security.

i. Blast mitigation.

ii. Counterterrorism methods taken to protect the occupants and the building.

3. Risk assessments and information regarding security systems or strategies of any kind. Examples include:

a. Camera locations.

b. Nonpublic security guard post information (e.g., number, location, operations, etc.).

Note: In the case of building information related to a specific suite, room/space, or other component that is designated as SBU (i.e. Building Automation System (BAS) diagram, security camera layout, etc.), the SBU designation does not necessarily carry over to the entire building, or to the entire campus.

Note: Building information for a stand-alone steam plant facility or similar service facility and its associated tunnels shall be designated SBU when it services a building that is designated SBU.

B-1

Appendix B. Sensitive But Unclassified Marking Information

1. Any electronic or printed document, pages containing SBU building information must have the following markings:

SENSITIVE BUT UNCLASSIFIED (SBU)

PROPERTY OF THE UNITED STATES GOVERNMENT

FOR OFFICIAL USE ONLY

Do not remove this notice

Properly destroy or return documents when no longer needed

2. The following mark must be affixed to the cover or first page of any document (such as the cover page on a set of construction drawings).

SENSITIVE BUT UNCLASSIFIED (SBU)

PROPERTY OF THE UNITED STATES GOVERNMENT

COPYING, DISSEMINATION, OR DISTRIBUTION OF THIS DOCUMENT

TO UNAUTHORIZED RECIPIENTS IS PROHIBITED

Do not remove this notice Properly destroy or return documents when no longer needed

3. The previous two markings must be prominently labeled in bold type in a size appropriate for the document or portable electronic data storage device or both, if applicable. On a set of construction drawings, for example, the statements must be in a minimum of 14 point bold type or equivalent.

4. The SBU markings must be used regardless of the medium through which the information appears or is conveyed.

C-1

Appendix C. SBU Contract Clause

Contracting Officers (COs) shall include the following clause, or a similar updated clause per the General Services Administration Acquisition Manual (GSAM), in: (1) all solicitations containing SBU building information (including Solicitations for Offers (SFOs)); and shall include the following clause in: (2) contracts and/or final leases that may contain, require access to, or cause the generation of SBU building information.

[Begin clause]

Safeguarding and Dissemination of Sensitive But Unclassified (SBU) Building Information

This clause applies to all recipients of SBU building information, including offerors, bidders, awardees, contractors, subcontractors, lessors, suppliers and manufacturers.

1. Marking SBU. Contractor-generated documents that contain building information must be reviewed by GSA to identify any SBU content, before the original or any copies are disseminated to any other parties. If SBU content is identified, the Contracting Officer (CO) may direct the contractor, as specified elsewhere in this contract, to imprint or affix SBU document markings to the original documents and all copies, before any dissemination.

2. Authorized recipients.

a. Building information designated SBU must be protected with access strictly controlled and limited to those individuals having a legitimate business need to know such information. Those with a need to know may include Federal, State and local government entities, and nongovernment entities engaged in the conduct of business on behalf of or with GSA. Nongovernment entities may include architects, engineers, consultants, contractors, subcontractors, suppliers, utilities, and others submitting an offer or bid to GSA, or performing work under a GSA contract or subcontract. Recipient contractors must be registered as “active” in the System for Award Management (SAM) database at www.sam.gov and have a legitimate business need to know such information. If a subcontractor is not registered in the SAM and has a need to possess SBU building information, the subcontractor shall provide to the contractor its DUNS number or its tax ID number and a copy of its business license. The contractor shall keep this information related to the subcontractor for the duration of the contract and subcontract.

b. All GSA personnel and Contractors must be provided SBU building information when needed for the performance of official Federal, State, and local government functions, such as for code compliance reviews and for the issuance of building permits. Public safety entities such as fire and utility departments may require access to SBU building information on a need to know basis. This clause must

C-2 not prevent or encumber the dissemination of SBU building information to public safety entities.

3. Dissemination of SBU building information:

a. By electronic transmission. Electronic transmission of SBU information outside of the GSA network must use session encryption (or alternatively, file encryption). Encryption must be via an approved NIST algorithm with a valid certification, such as Advanced Encryption Standard (AES) or Triple Data Encryption Standard (3DES), in accordance with Federal Information Processing Standards Publication (FIPS PUB) 140-2, Security Requirements for Cryptographic Modules per GSA policy.

b. By nonelectronic form or on portable electronic data storage devices. Portable electronic data storage devices include, but are not limited to CDs, DVDs, and USB drives. Nonelectronic forms of SBU building information include paper documents, among other formats.

i. By mail. Contractors must utilize only methods of shipping that provide services for monitoring receipt such as track and confirm, proof of delivery, signature confirmation, or return receipt.

ii. In person. Contractors must provide SBU building information only to authorized recipients with a need to know such information. Further information on authorized recipients is found in Section 2 of this clause.

4. Record keeping. Contractors must maintain a list of all entities to which SBU is disseminated, in accordance with sections 2 and 3 of this clause. This list must include at a minimum: (1) the name of the State, Federal, or local government entity, utility, or firm to which SBU has been disseminated; (2) the name of the individual at the entity or firm who is responsible for protecting the SBU building information, with access strictly controlled and limited to those individuals having a legitimate business need to know such information; (3) contact information for the named individual; and (4) a description of the SBU building information provided. Once “as built” drawings are submitted, the contractor must collect all lists maintained in accordance with this clause, including those maintained by any subcontractors and/or suppliers, and submit them to the CO.

For Federal buildings, final payment may be withheld until the lists are received.

5. Safeguarding SBU documents. SBU building information (both electronic and paper formats) must be protected, with access strictly controlled and limited to those individuals having a legitimate business need to know such information. GSA contractors and subcontractors must not take SBU building information outside of GSA or their own facilities or network, except as necessary for the performance of that

C-3 contract. Access to the information must be limited to those with a legitimate business need to know.

6. Destroying SBU building information. When no longer needed, SBU building information must be destroyed so that marked information is rendered unreadable and incapable of being restored, in accordance with guidelines provided for media sanitization within GSA CIO IT Security 06-32, Media Sanitization Guide and Appendix A of NIST Special Publication 800-88, Guidelines for Media Sanitization. Alternatively, SBU building information may be returned to the CO.

7. Notice of disposal. The contractor must notify the CO that all SBU building information has been returned or destroyed by the contractor and its subcontractors or suppliers in accordance with paragraphs 4 and 6 of this clause, with the exception of the contractor's record copy. This notice must be submitted to the CO at the completion of the contract to receive final payment. For leases, this notice must be submitted to the CO at the completion of the lease term. The contractor may return the SBU documents to the CO rather than destroying them.

8. Incidents. All improper disclosures of SBU building information must be immediately reported to the CO at _________<insert address and contact information>____ . If the contract provides for progress payments, the CO may withhold approval of progress payments until the contractor provides a corrective action plan explaining how the contractor will prevent future improper disclosures of SBU building information.

Progress payments may also be withheld for failure to comply with any provision in this clause until the contractor provides a corrective action plan explaining how the contractor will rectify any noncompliance and comply with the clause in the future.

9. Subcontracts. The contractor and subcontractors must insert the substance of this clause in all subcontracts.

[End of clause]

(Contractor Guide for external use)

General Services Administration R10 Security Clearance Desk Guide (External use)

External Version 1.0 10/15/2009 1

Table of Contents

Introduction and background……………………………………

Escort Policy…………..……………………………………………………………….. 4 Escort Policy (flow chart)……………………………….…………………………... 5

Short-Term Contractor Policy (Less than 6 months)……………………………… 6 Short-Term Contractor Policy (flow chart)……………………

Long-Term Contractor Policy (Greater than 6 months)…………………..………. 11 Long-Term Contractor Policy (flow chart)……………………

Obtaining HSPD-12 Credentials……………………………………………………. 16 Returning/ Reporting lost or stolen a HSPD-12 credential…………….……… 19 Obtaining an HSPD-12 Credential (flowchart)…………………….……………. 21

Obtain a Building Identification Badge……………………………………………. 22

Previously Cleared Contractors (Reciprocity)……………………………………… 23

Child-care worker security clearance process…………………………………… 24 Child-care worker security clearance process (flowchart)……………………………27

Appendix:

Appendix A. HSPD-12 Presidential Directive………………………………………… 28

Appendix B. Instructions for completing CIW …….………………………………… 30 Contractor Information Worksheet (CIW) sample ………………….. 32

Appendix C. Encrypting Personally Identifiable Information instructions……….. 34

Appendix D. Instructions for completing the e-QIP invitation…………………….. 38

Appendix E. Instructions for completing the SF85P………………………………. 39

Appendix F. FD-258 Fingerprint Card Instructions…………

Appendix G. Instructing for completing GSA Form 176 (child care only)………………………………………………….……… 43

Appendix N. Additional Resources………………………………………………. 45

Appendix O. Terms and Acronyms………………………………………………….. 46

GSA Region 10 Security Contact Information………………………………………. 47

External Version 1.0 10/15/2009 2

GSA Region 10 Security Clearance Process

Introduction

The purpose of this guide is to establish a uniform procedure for access and background security clearances for the General Services Administration (GSA) Northwest/Artic Region 10 contract employees. Wide variations in security policies allow unauthorized individuals the ability to gain access to secure facilities and increase the likelihood of a security breach. This guide provides GSA Region 10’s officials and service centers a common set of criteria to ensure that all individuals given routine access to all GSA’s government space have submitted to the correct level of personnel security investigation in order to complete their work.

Background

This guide standardizes the security clearance process for all contractors across GSA’s Region 10 and ensures that all of our offices and personnel are following the same common criteria and policies.

It is intended to provide a greater sense of security, increase efficiency, reduce fraud and to protect the personal privacy of our customer agencies and contract companies.

Our security policy reflects the policy of the United States government as issued by the Homeland Security Presidential Directive-12 (HSPD-12) “Policy for a Common identification Standard for Federal Employees and Contractors,” to create a consistent policy on access and credentialing of contract employees. This policy requires that all contract employees who require routine access to GSA’s controlled facilities or its information systems to have a personnel security investigation. This guide provides an overview of these personnel security investigations, step by step instructions for each type of security clearance, and supplementary information to answer any additional questions and concerns that you may have. Our hope is to make the security clearance process a simple but thorough screening of all individuals requiring routine access into GSA’s controlled space which in turn will provide a safer and more dependable environment for our customer agencies, contractors and the general public.

Security Clearances

GSA’s Region 10 has two types of personnel security investigations depending on how long the contractor employee is required to be on site, except for contractors requiring access to the GSA IT network; all contractors requiring network access require the long-term NACI clearance. The type of security clearance is based upon the length of time the contract employee will be working within the “controlled space” not upon the duration of the contract. This guide explains what you need to know to get contractors on the site and working as quickly as possible. Regardless of the type of background check required, a satisfactory law enforcement check called Entry of Duty (EOD) determination, allows unescorted physical access to facilities for all contractors. The type of contractor determines which personal history form is required to be submitted. In either case, fingerprints and a Contractor Information Worksheet (CIW) are also required. The CIW form must be initiated by the GSA Requesting Official (example: Project Manager). A brief explanation of the security clearance processes follows below however each process is later explained in more detail.

1. Short-term contractor clearance This type of security clearance are for those who require routine access to federally controlled space for a period of six (6) months or less. This security clearance requires either a National Agency Check (NAC) or one must be escorted at all times. For

External Version 1.0 10/15/2009 3 unescorted access, a CIW, SF85P and two (2) sets of FD-258 (fingerprint cards) must be submitted to the Security Office. The CIW may be emailed to r10pbssecurity@gsa.gov. This initiates FPS to send an SF85P application via email to complete online. The signature pages from the SF85P application and fingerprint cards may be mailed to: GSA, PBS Security Office, 400 15th ST, SW, Auburn WA 98001.

A. Escorts are permitted for temporary contractors for very short duration; jobs ten days or less.

Escorts may be government employees or long term contractors (including contract guards) who have received an EOD and whose NACI is in process. Escorts must maintain control of those they are escorting at all times.

2. Long-term contractors This type of security clearance is required for those who require access to federally controlled space for more than six (6) months. This security clearance requires a National Agency Check with written Inquiries (NACI) and one must submit a SF85P. To begin this process, a CIW form must be completed and emailed to the GSA security office at r10pbssecurity@gsa.gov. The CIW is obtained from the GSA Requesting official. This will initiate the security clearance process, and the Federal Protective Service will email the applicant an invitation to enter e-QIP (OPM’s secure portal for security clearances). The applicant will then fill out the SF85P through e-QIP, print out signature pages, and mail them along with two sets of FD258 fingerprint cards)to the GSA, PBS Security office at 400 15th St SW, Auburn, WA 98001.

Additional Assistance

This guide will also assist to identify the correct clearance procedure to follow when starting a new construction project or building repair and alteration (R&A) project.

It will assist the Lease Administration Managers with differentiating the correct security clearance process in Leased Space (Level 4 & Level 3 100% Government Occupied Space and Leased Space in Level 3 not 100% Government Occupied and any space will a facility security level under 3.

It includes the security clearance procedures for applicants applying for child-care work in GSA controlled facilities.

GSA’s commitment to protect Personally Identifiable Information (PII)

Informing Applicants of Data Collected: All forms used in the security clearance process have a Privacy Act statement included that indicates what PII is collected, the purpose of its collection, whether it is optional or required, and the consequences of not providing the requested information.

Securing Information Technology (IT) Systems: All GSA IT systems must store and transmit data securely and have a completed a Privacy Impact Assessment (PIA) filed with the Privacy Office. The PIA ensures that the IT system complies with federal and GSA privacy regulations, including the Privacy Act. Instructions for encrypting and transmitting PII are included in this guide.

Securing Paper Forms: All paper forms containing PII data must be stored and transmitted in accordance with the GSA IT Security Policy and be protected from any unauthorized disclosure.

Designating Staff: All security related staff must be specifically designated to handle security clearance related PII data. All GSA staff are required to have completed privacy training and abide by the GSA IT Security Policy.

mailto:r10pbssecurity@gsa.gov

External Version 1.0 10/15/2009 4

Escort Policy Security Clearance Process

To provide a means for GSA Officials to complete emergency repairs, minor alterations, etc., GSA Region 10 has established a region wide policy whereby short-term contractor employees who perform work for no more than ten (10) consecutive days or require only intermittent (irregular) access are not required to undergo a personnel security investigation, provided the contractors are accompanied by a fully adjudicated escort. All Escort situations must have prior approval by a GSA Official.

Escort Policy Requirements

1. A contract employee may be escorted up to ten (10) days (days may be separated), by a fully favorable adjudicated contractor, federal employee, or security guard.

Note: For contractors that exceed the ten (10) day time frame or who require frequent or routine access to a federal space, see applicable short-term or long-term security clearance process.

2. A maximum of five (5) individuals may be escorted at anytime (ex. Ten (10) contract employees require two (2) fully favorable adjudicated escorts).

3. The GSA Requesting Official must ensure appropriate approval from building manager and/or any other agency security requirements.

4. The escort must maintain control, physical proximity, or other means of control of the escorted contract employee at all times.

When performing escort duties, the responsible individual must maintain control of the contractor(s) at all times, unless the contractor leaves the building or facility. An example of maintaining “control” is a contractor who is running cable through multiple rooms and is three rooms away from their fully adjudicated escort. However, a contractor who is working on the roof of a thirty-two story building while the fully adjudicated escort is on the first floor would not be considered to have control of the contract employee.

5. The escorted contract employee must wear an escort badge at all times. No photo is required on the escort badge.

External Version 1.0 10/15/2009 5

Escort Policy (owned space) Security Clearance Process

Flowchart A

Escort Policy

Owned Space

Security Clearance Process

Yes

No

Is the job less than 10 days?

See applicable short-term or long-term process

GSA Region 10 Escort Policy Requirements

Contract employee may be escorted up to ten (10) days (days may be separated), by a fully favorable adjudicated contractor, federal employee, or security guard.

A maximum of five (5) individuals may be escorted at anytime (ex.

Ten (10) contract employees require two (2) fully favorable adjudicated escorts).

Ensure appropriate approval from building manager and/or any other agency security requirements.

Escort must maintain control, physical proximity, or other means of control of the escorted contract employee at all times.

Escort Badge with no photo required.

Escort Policy

External Version 1.0 10/15/2009 6

Short-Term Contractor (Less than 6 Months) Security Clearance Process

When a GSA Requesting Official determines a contactor will require access to federal space for more than ten (10) days but less than six (6) months the contract employee is required to submit to a National Agency Check (NAC) personnel security investigation. To receive a NAC clearance, a Contractor Information Worksheet (CIW) version 2, SF85-P form through e-QIP submission, two sets of FD-258 fingerprint cards and signed signature pages are required for each employee. This level of personnel security investigation is not HSPD-12 compliant.

Also this type of personnel security investigation may not be used for persons requiring access to GSA computer systems. Contractors requiring access to information technology (IT) systems must complete a NACI, regardless of the duration of the contract or how long the individual will require access to a federal facility. For contract employees requiring IT access, refer to the submission process section for long-term clearances in this guide.

Short-Term Contractor submission procedures

1. When a National Agency Check (NAC) personnel security investigation is required, the GSA Requesting Official completes the Contractor Information Worksheet (CIW) sections 2, 3, 4 and 5, and then forwards via email to the contract company. The GSA Requesting Official has the overall responsibility to ensure that the CIW is complete and correct. Special attention should be given in the case of subcontractors to ensure the subcontract company’s information is correct.

The contract company representatives, as well as the contract employee are normally required to provide assistance in the completion of this form. Please refer to Appendix E for detailed instructions on how to complete the CIW.

2. The contract company representative completes the Contractor Information Worksheet (CIW) section 1 and any remaining portions of section 2 and then submits via email to the GSA Region 10 Security Office (r10pbssecurity@gsa.gov). The GSA requesting official must be copied on the email or the contractor may submit the CIW per the instructions provided by the GSA requesting official (ex. sends completed CIW to requesting official). The CIW serves as the requesting official’s acknowledgment that the contract employee is related to the project and that a security clearance is required.

Contractor Information Worksheet (CIW) completion guidelines

a. The CIW must contain a valid e-mail address for the contract employee in Section 1. This can be a personal or business e-mail address, but needs to be one that the contract employee or a contract company representative has regular access to. If the contract employee, doesn’t already have an e-mail address the employee may use one of the many free e-mail providers

(ex. MSN’s hotmail.com account). All notifications during the e-QIP process will be sent to this e-mail address.

b. The complete CIW must be typed and saved as a Microsoft Word document and then sent electronically as an attachment to the GSA Security Office email address. Please refer to Appendix G for directions on encrypting the document to prevent release of Personally Identifiable Information (PII).

External Version 1.0 10/15/2009 7

c. The CIW may be submitted to the GSA Security Office by either GSA requesting official or the contract company representative. If submitted by the contract company representative directly to GSA’s Security Office, the requesting official must be copied on the email.

Submissions which do not include the GSA requesting official’s e-mail address will not be accepted.

d. An incorrect or incomplete CIW will be returned to the sender for corrections.

3. After the CIW is emailed to GSA’ s Security Office, the information is inputted into GSA’s security database and forwarded to the Federal Protective Service (FPS) a agency within the Department of Homeland Security (DHS).

4. FPS receives the CIW from the GSA Security Office and creates a user profile for the contract employee. This initiates e-QIP email invitation to the contract employee that is sent to the e-mail address as provided in Section 1 of the CIW. Included in the invitation is an instructional reference guide to assist the applicant in the completion of the e-QIP file.

The contract employee has:

a. Seven (7) days to initially log into the e-QIP system before being considered delinquent.

b. Seven (7) days to complete the form in e-QIP before being considered delinquent.

c. If a contract employee is terminated from the e-QIP system the personnel security investigation has not yet begun therefore, no notice of initial adjudication will be made. Failure to complete the forms via e-QIP prohibits the contract employee from routine access on or in a federal facility.

5. The e-QIP invitation can be accessed from any computer connected to the internet. Included in the e-QIP invitation is the standard Form 85P, Questionnaire for Public Trust Positions (SF-85P) forms. The invitation includes an instructional reference guide however additional assistance for e-QIP completion has been included below and later in this guide.

e-QIP invitation completion assistance

a. The e-QIP frequently asked questions website: http://www.opm.gov/e-qip/faq.asp

b. If the contract employee is unable to access the e-QIP website or experiencing other technical problems, the individual may contact the OPM Help Desk at 1-866-631-3019. The hours of operation are 6:30am – 10:30pm, Monday through Friday and 7:30am – 3:00pm on Saturday, all times are Eastern Standard Time.

c. For other problems such as “golden question” reset or general e-QIP assistance call the FPS regional adjudicator. Points of contact and phone numbers are provided on all e-QIP related e-mails sent by FPS.

d. Once the on-line form is completed and validated, the contract employee needs to print out and sign all signature pages.

5A. In addition to completing the e-QIP invitation the contract employee must submit (2) two sets of FD-258 fingerprint cards.

1. The contract employee will need to obtain two sets FD-258 fingerprint cards. FD-258 fingerprint cards may be obtained from the GSA Security Office by request or at a local law enforcement agency. GSA has the Livescan electronic fingerprint system available at several http://www.opm.gov/e-qip/faq.asp

External Version 1.0 10/15/2009 8

GSA Service Centers, please verify with the GSA requesting official (ex. contracting officer, COR) the use and availability. Also, some law enforcement agencies provide fingerprinting services as part of the fee, others do not. The only acceptable fingerprint card is the FD-258;

no other card types will be accepted.

2. The personal information on both of the FD-258 fingerprint cards should be left blank until the fingerprints are recorded on the cards. Some organizations have electronic means to take fingerprints and the system will print the personal data on the card, while other providers do not have this capability, which results in the applicant having to hand-write the personal information on the cards in black ink only. Regardless of the method utilized to obtain the prints, the applicant is responsible for ensuring all personal information is filled out. Step-by-step instructions on how to properly fill out the personal information portion of the FD-258 card is available in Appendix J.

3. The contract employee must then deliver or mail the signature pages and two (2) sets of FD- 258 fingerprint cards to the Region 10 GSA Security Office, 400 15th Street SW, Room Northeast, Auburn, WA 98001-6599.

6. Receipt of the required signature forms and fingerprint cards are logged into the security database. The GSA Security Office then forwards to DHS FPS.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .