MSS_PWS_Attach_4_DHA_Instructions_for_Contractor_Access.docx
DOCX document 31 KB Posted
- Attached to
- Medical Support Services Final RFP Federal contract opportunity
- Solicitation number
- 110515MSS01
- Issued by
- Defense Health Agency
About this file
MSS PWS IT Access Procedures
View the file
Other files for this federal contract opportunity
Show all 42
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE HEALTH AGENCY
Administration and Business Management Mission Assurance Division Instructions for Contractor Access DoD IT Systems and the Common Access Card
BACKGROUND
The Department of Defense (DoD) requires contractor personnel designated for assignment to an ADP/IT position to undergo a successful security screening before being granted access to DoD information technology (IT) systems that contain sensitive data.
Effective October 1, 2009, DoD transitioned to the Electronic Questionnaires for Investigations Processing (e-QIP) for the processing of investigative Standard Forms (SFs) to include SF-85 (Questionnaire for Non-Sensitive Positions), SF-85P (Questionnaire for Public Trust Positions), and SF-86 (Questionnaire for National Security Positions). e-QIP is a web-based automated system managed by the Office of Personnel Management (OPM), which facilitates the processing of SFs for background investigations. Companies having a Defense Health Agency (DHA) contracts have positions of Public Trust and require the submission of the SF-86. The DHA, Personnel Security Branch (PSB) coordinates with companies on the use of e-QIP. PSB shall provide each Facility Security Officer (FSO) the training necessary to access and use e-QIP. FSOs are required to initiate in e-QIP a background investigation in accordance with their position designations.
PURPOSE
The purpose of this instruction is to define the Contractor’s responsibilities when contractor personnel require access to DoD IT systems.
SCOPE
Contractor/Order. Upon notification that a contract/order has been awarded, the contractor awarded the contract/order shall:
Contact the Personnel Security Branch (PSB) and provide the company name, mailing address, e-mail address, telephone number and the name of the Facility Security Officer (FSO) or designated official.
Provide the contract number, delivery order number, and contract period of performance.
Formal Designations Required. Contractor personnel in positions requiring access to the following must be in positions designated as ADP/IT-I (critical sensitive) or ADP/IT-II (non-critical sensitive):
1. Access to a secure DoD facility;
Access to a DoD IS or a DoD Common Access Card (CAC)-enabled network;
Access to DEERS or the B2B Gateway.
ADP/IT Position Sensitivity Designations. An ADP/IT position category is a designator that indicates the level of IT access required to fulfill the responsibilities of the position, including the potential risk for an individual assigned to the position to adversely impact DoD missions or functions. The contractor’s Facility Security Officer (FSO) shall use the guidance below to determine a contractor employee’s specific ADP/IT level. Contractor personnel designated for assignment to a ADP/IT position shall undergo a successful background security screening before being granted access to DoD IT systems (e.g., test and/or production) and /or any DoD/DHA data directly extracted from those contained on any system (e.g, test and /or production) that contains sensitive data.
ADP/IT-I: Critical Sensitive Position. A position where the individual is responsible for the development and administration of MHS IS/network security programs and has the direction and control of risk analysis and/or threat assessment. The required investigation is a Tier 5 (formerly a Single-Scope Background Investigation (SSBI)) or equivalent. Responsibilities include:
1. Significant involvement in life-critical or mission-critical systems.
Responsibility for the preparation or approval of data for input into a system, which does not necessarily involve personal access to the system, but with relatively high risk for effecting severe damage to persons, properties or systems, or realizing significant personal gain.
Relatively high risk assignments associated with or directly involving the accounting, disbursement, authorization for disbursement from systems of:
Dollar amounts of 10 million dollars per year, or greater; or Lesser amounts if the activities of the individuals are not subject to technical review by higher authority in the ADP/IT-I category to ensure the integrity of the system.
Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring, and/or management of systems hardware and software.
Other positions as designated by the DHA that involve a relatively high risk for causing severe damage to persons, property or systems, or potential for realizing a significant personal gain.
ADP/IT-II: Non-Critical Sensitive Position. A position where an individual is responsible for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the ADP/IT- I category. The required investigation is a Tier 3 (formerly a National Agency Check with Law Enforcement and Credit (NACLC) check) or equivalent. Responsibilities include, but are not limited to:
1. Access to and/or processing of proprietary data, information requiring protection, or government-developed privileged information involving the award of contracts.
1. Accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than 10 million dollars per year.
1. Other positions as designated by the DHA that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in ADP/IT-I positions.
Employee Prescreening. The contractors shall conduct thorough reviews of information submitted on an individual’s application for employment in a position that requires either an ADP/IT background check or involves access via a contractor system to data protected by either the Privacy Act of 1974, as amended, or the HHS HIPAA Privacy and Security Final Rule. For contractors working in the United States (U.S.) and the District of Columbia, this prescreening shall include reviews that:
1. Verify United States citizenship;
1. Verify education (degrees and certifications) required for the position in question;
1. Screen for negative criminal history at all levels (federal, state, and local);
1. Screen for egregious financial history; for example, where adverse actions by creditors over time indicate a pattern of financial irresponsibility or where the applicant has taken on excessive debt or is involved in multiple disputes with creditors.
For contractors working outside the United States and District of Columbia, this prescreening shall include reviews that:
1. Verify United States citizenship;
1. Verify education (degrees and certifications) required for the position in question;
1. Screen for negative criminal history, to the maximum extent possible as permitted by local laws of the host government;
1. Screen for egregious financial history, to the maximum extent possible as permitted by local laws of the host government.
The prescreening shall be conducted as part of the preemployment screening and shall be completed before the assignment of any personnel to a position requiring the aforementioned ADP/IT accesses. The prescreening may be performed by the contractor’s personnel security specialists, human resource manager, hiring manager, or similar individual.
FSO Roles and Responsibilities. The contractor FSO shall:
1. Be a U.S. citizen.
1. Possess a favorably adjudicated NACLC or equivalent investigation.
1. Provide list of applicants to PSB for verification of security eligibility.
1. Initiate applicant’s security questionnaire in e-QIP.
1. Select the appropriate Agency Use Block (AUB) template in e-QIP.
1. Notify the Contracting Officer’s Representative (COR) by e-mail that an e-QIP request has been initiated and requires approval.
1. Inform applicant to complete security questionnaire in e-QIP within 10 calendar days.
1. Perform initial review of applications for required information.
1. Mail two FD258 fingerprint cards to PSB or Capture and transmit e-fingerprints to OPM via Secured Web Fingerprint Transmission (SWFT)
1. Verify applicant’s citizenship and upload proof of citizenship document to investigation request before releasing case to PSB.
1. Serve as the main point of contact (POC) for the applicant.
1. Monitor the e-QIP request, which includes ensuring the applicant completes the
1. e-QIP form within designated time period.
1. Cancel or delete an e-QIP request on an applicant.
1. Act as POC if DoD Central Adjudication Facility (DoD CAF) requires additional information on contractor employees.
Additional Requirements/Information
1. Background Investigation Request for ADP/IT-I.
Contractors requiring an ADP/IT-I investigation for their personnel shall have their FSOs coordinate and submit a written request on contractor letterhead to the DHA COR for endorsement. The request letter shall be signed by, at a minimum, the FSO or other appropriate executive. It shall include a detailed job description which justifies the requirement for the ADP/IT-I. The justification letter shall be emailed to PSB.
1. Reinvestigation Requirements.
Contractor personnel in positions designated as ADP/IT-I and ADP/IT-II have reinvestigation requirements. ADP/IT-I positions are critical sensitive and shall be re-investigated every five years. ADP/ IT-II positions are non-critical sensitive and shall be re-investigated every 10 years. The reinvestigation shall be initiated within 60 days of the closed date of the last investigation. The FSO shall track the reinvestigation requirement for contractor employees and initiate new investigations, as required above. Fingerprints are not required for re-investigations unless specifically requested.
Reciprocal Acceptance of Prior Investigation.
An investigation is reciprocated when a new contractor employee has an existing Favorably adjudicated investigation that meets the appropriate level of investigation required; and the break in service has been two years or less. The FSO shall verify prior investigation and if valid, provide PSB with the new employee’s name, Social Security Number (SSN) and Date of Birth (DOB).
Requests for Additional Information.
PSB may require additional information while the contractor employee’s investigation is in progress. The FSO will be notified to provide the information by a specified date or the investigation may be rejected or returned unacceptable. The FSO shall review applications for required information prior to release, to reduce case rejections and requests for additional information.
Notification of Employee Termination and Unfavorable Personnel Security Determination.
The FSO shall notify PSB immediately when a contractor employee is terminated from a DHA contract. E-mail notification shall include the employee’s name and termination date. If a contractor moves an employee to another DHA contract, PSB shall be notified immediately, especially when a contractor employee is being moved from an unclassified contract to a classified contract.
PSB will notify the FSO by e-mail when a contractor employee has received an unfavorable personnel security determination. Upon receipt of a denial letter from PSB, the FSO shall immediately terminate the employee’s access to DoD IT systems. The return receipt letter and the denial letter from PSB are attached to the e-mail notification from PSB. The return receipt letter shall be returned to PSB no later than one week after receipt, to verify compliance with termination of employee’s access.
Transfers between Contractors.
When contractor employees transfer employment from one DHA contractor to another DHA contractor while their investigation for ADP/IT trustworthiness determination is in process, the scheduled investigation may be applied to the new employing contractor. It shall be the responsibility of the new employer to provide notification to PSB when this type of transfer occurs. The notification shall contain employee’s name and effective date of transfer.
Notification and Mailing.
The contractor shall process sensitive information according to applicable laws and DoD policies related to privacy and confidentiality. The contractor shall transmit PII or PHI via encrypted e-mail or the OPM secure portal. The contractor shall use the following information to contact the PSB.
Mailing Address:
Defense Health Agency ATTN: Personnel Security Branch 7700 Arlington Blvd., Suite 5101 Falls Church, VA 22042-5101 E-mail address: Dha.ncr.security.mbx.personnel-security-eqip@mail.mil Common Access Card (CAC) Issuance.
1. CAC is the standard identification for Service members, Department of Defense (DoD) civilian employees, and eligible DoD contractor personnel. It is the principal card used to enable both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely. Access to the DoD network requires the use of a computer with Government-controlled configuration or use of a DoD-approved remote access procedure in accordance with the DISA Security Technical Implementation Guide (DISA STIG).
1. Trust Associated Sponsorship System (TASS), is a web-based system that allows eligible DoD contractors to apply for a CAC through the Internet. Government sponsors (also known as Trusted Agent (TA)) approve the application to receive government credentials.
FSO Roles and Responsibilities. The contractor FSO shall:
1. Identify contractor support personnel who require a CAC for accessing DoD networks and facilities.
1. Verify the applicant’s background investigation by submitting a request to PSB.
1. Complete Sections I and III of the Defense Health Agency (DHA) Form 33, for the initial and/or renewal CAC.
1. Submit the form (DHA Form 33) to the COR for approval.
1. Email the completed form to: (Dha.ncr.security.mbx.personnel-security-tass@mail.mil).
1. Establish out-processing procedures to collect the CAC when an employee quits, is terminated from the company, or when the CAC is no longer required.
1. Notify the TA to revoke the employee’s CAC.
1. CACs shall be returned in accordance with paragraph 16.
CAC Guidelines and Restrictions.
1. Any person willfully altering, damaging, lending, counterfeiting, or using these cards in any unauthorized manner is subject to fine or imprisonment or both, as prescribed in sections 499, 506, 509, 701, and 1001 of title 18, United States Code (USC). Section 701 prohibits photographing or otherwise reproducing or possessing DoD ID cards in an unauthorized manner, under penalty of fine or imprisonment or both. Unauthorized or fraudulent use of ID cards would exist if bearers used the card to obtain benefits and privileges to which they are not entitled. Examples of authorized photocopying include photocopying of DoD ID cards to facilitate medical care processing, check cashing, voting, tax matters, compliance with appendix 501 of title 50, USC (also known as “The Service member’s Civil Relief Act”), or administering other military-related benefits to eligible beneficiaries. Whenever possible, the ID card shall be electronically authenticated in lieu of photographing the card.
CAC cards shall not be amended, modified, or overprinted by any means. No stickers other adhesive materials are to be placed on either side of an ID card. Holes shall not be punched into ID cards.
Access.
The granting of access is determined by the contractor or system owner as prescribed by the DoD.
Accountability.
CAC holders shall maintain accountability of their CACs at all times while affiliated with the DoD.
Multiple Cards.
In instances where an individual has been issued more than one CAC card (e.g., an individual that is eligible for a CAC card as both a Reservist and as a contractor employee), only the CAC card that most accurately depicts the capacity in which the individual is affiliated with the DoD should be utilized at any given time.
Renewal and Expiration.
CACs may be renewed 90 days prior to the CAC expiration date. The CAC will be issued for three years or until the contract end date, whichever is shorter.
Replacement.
Within 24 hours of becoming aware of the loss of a CAC card, the contractor shall provide the RAPIDS issuance site a letter from the FSO confirming the CAC has been reported lost, stolen, confiscated or destroyed, along with a copy of a valid (unexpired) State or Federal Government-issued picture ID.
Retrieval.
The CAC is property of the U.S. Government and shall be retrieved from the contractor employee if the ID has expired, or is damaged or compromised. Additionally, CACs shall be retrieved if the employee is no longer affiliated with the DoD contractor or no longer meets the eligibility requirements for the card. The CAC shall be returned to the following address within one week using FedEx Delivery service:
Defense Health Agency Mission Assurance Division Personnel Security Branch
ATTN: TASS
7700 Arlington Blvd, Suite 5101 Falls Church, VA 22042-5101 E-mail address: Dha.ncr.security.mbx.personnel-security-tass@mail.mil Updated June 30, 2016
File details come from the government source that posted it. Updated .