12444021Q0001 Attach 3 DM 4620-002.pdf

PDF 737 KB Posted

Attached to
Janitorial Services - Cherokee National Forest Ocoee RD Federal contract opportunity
Solicitation number
12444021Q0001
Issued by
Department of Agriculture Forest Service

View the file

Other files for this federal contract opportunity

Other files attached to Janitorial Services - Cherokee National Forest Ocoee RD, newest first.
File Type Posted
12444021Q0001 Attach 5 Experience Questionnaire.docx DOCX document
12444021Q0001 Attach 1 GSA Cleaning and Disinfection Procedures.pdf PDF
12444021Q0001 Attach 6 Performance Assessment Questionnaire.pdf PDF
12444021Q0001 Attach 4 Quality Assurance Surveillance Plan.pdf PDF
12444021Q0001 SF 1449 Continuation Sheet.pdf PDF
12444021Q0001 Attach 2 WD Polk County.pdf PDF
12444021Q0001 SF 1449.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DM 4620-002

United States Department of Agriculture

Office of Security Services

COMMON IDENTIFICATION STANDARD FOR

U.S. DEPARTMENT OF AGRICULTURE EMPLOYEES AND

CONTRACTORS

DM 4620-002

Attachment 3 Solicitation 12444021Q0001 Janitorial Services - Ocoee Ranger District

COMMON IDENTIFICATION STANDARD FOR U.S. DEPARTMENT OF AGRICULTURE

EMPLOYEES AND CONTRACTORS

TABLE OF CONTENTS

Page

Table of Contents i

Chapter 1 Overview 1

1. Purpose 1 2 Special Instructions 3

3. Background 3

4. Applicability 4

5. Credentialing Standards 5

6. Reciprocity of Credentialing Determinations 6 Chapter 2 PIV-I 9

1. PIV-I Applicability 9

2. Privacy Policy 10

3. Background Investigation Requirements 11

4. Registration, Identity Proofing, and Credential Issuance 12

5. Expiration Date Requirements 16

6. Temporary Badges 16

7. Contracting Impacts 17

8. Audit and Records Management 17

9. Use of Approved Forms 17

10. Reporting Requirements 18 Chapter 3 PIV-II 20

1. PIV-II Overview 20

2. PIV-II Applicability 21

3. Registration, Identity Proofing, Credential Issuance, and

Revocation 21

4. Physical Access Control Systems (PACS) 27

5. Logical Access Control Systems (LACS) 29 Chapter 4 Training 31

Appendix A Definitions A-1 Appendix B Abbreviations B-1 Appendix C PIV-II Standard Operating Procedures C-1 Appendix D LincPass Distribution Risk Assessment D-1 Figure D-1 LincPass Distribution Risk Assessment D-1 Appendix E PIV-II Credential Topology and Examples of Temporary Badges E-1 Figure E-1 Front of PIV-II Credential E-2 Figure E-3 Back of PIV-II Credential E-3 Figure E-4 Example of LincPass E-4 Figure E-5 Example of USDA Site Badge E-6 i

Figure E-6 Example 1—Visitor Badge E-7 Figure E-7 Example 2 —Visitor Badge E-8 Appendix F Training for PIV-II F-1 Appendix G Training for Non-PACS Facilities G-1 Appendix H ePACS Technical Requirements H-1 Appendix I Form AD-1197 I-1 Appendix J Amendments Log J-1 ii

January 14, 2009 DM 4620-002

U.S. DEPARTMENT OF AGRICULTURE

WASHINGTON, DC 20250

DEPARTMENTAL MANUAL Number:

DM 4620-002

DATE:

January 14, 2009

SUBJECT:

Common Identification Standard for U.S.

Department of Agriculture Employees and Contractors OPI:

Office of Security Services

(OSS)

CHAPTER 1

OVERVIEW

1. PURPOSE

This Departmental Manual (DM) provides policies and procedures for USDA staff to meet the Personal Identity Verification (PIV) requirements of the directives and standards:

a. Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors, August 27, 2004

b. U.S. Department of Commerce, National Institute of Standards and Technology (NIST) Federal Information Processing Standard Publication 201- 1 (FIPS 201-1), Personal Identity Verification (PIV) of Federal Employees and Contractors, March 2006

c. Office of Management and Budget (OMB) Memorandum, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors M-05-24, August 5, 2005

d. OMB Memorandum, Acquisition of Products and Services for Implementation of HSPD-12, M-06-18, June 30, 2006

e. OMB Memorandum, Validating and Monitoring Agency Issuance of Personal Identity Verification Cards, M-07-06, January 11, 2007

DM 4620-002 January 14, 2009

f. U.S. Department of Commerce, National Institute of Standards and Technology, Special Publications (SP):

(1) 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems, May 2004

(2) 800-53, Recommended Security Controls for Federal Information Systems, February 2005

(3) 800-63, Electronic Authentication Guideline, Appendix A, June 2004

(4) 800-73-1, Interfaces for Personal Identity Verification, April 2006

(5) 800-76-1, Biometric Data Specification for Personal Identity Verification, January 2007

(6) 800-78-1, Cryptographic Algorithms and Key Sizes for Personal Identity Verification, July 2006

(7) 800-79, Guidelines for the Certification and Accreditation of PIV Card Issuing Organizations, July 2005

(8) 800-85a, PIV Card Application and Middleware Interface Test (SP 800- 73 Compliance), April 5, 2006

(9) 800-85b, PIV Data Model Conformance Test Guidelines, July 2006

(10) 800-87, Codes for the Identification of Federal and Federally Assisted Organizations, January 2006.

(11) 800-96, PIV Card/Reader Interoperability Guidelines, September 2006

(12) 800-104, A Scheme for PIV Visual Card Topography

g. Federal Acquisition Regulation, FAR Case 2005-15, Common Identification Standard for Contractors

h. Office of Personnel Management (OPM) Memorandum, Interim Credentialing Standards for Issuing Personal Identity Verification Cards Under HSPD-12, December 18, 2007

HSPD-12 mandates the development and implementation of a mandatory, Government-wide Standard for secure and reliable forms of identification issued to Federal employees and contractors.

FIPS 201-1 (1) defines a reliable, Government-wide PIV system for use in applications such as access to Federally controlled facilities or information systems,

(2) specifies a PIV system within which common identification badges can be created and later used to verify a claimed identity, and (3) requires identity proofing and background investigations to verify identity.

OMB Implementation Memorandum M-05-24 provides guidance for implementing the requirements in FIPS 201-1 and HSPD-12. The guidance clarifies timelines, applicability, and the requirements of PIV-I and PIV-II. OMB Memorandum M- 07-06 provides the guidance for reporting the number of PIV credentials issued by quarter. Beginning March 1, 2007 and each quarter thereafter, agencies will post their reports on their Federal agency public Web site.

USDA mission areas, agencies, and staff offices are referred to hereafter as “agency” or “agencies.”

2. SPECIAL INSTRUCTIONS

DM 4620-002 is a new Departmental Manual and does not replace any previous Departmental Manual. Agency HSPD-12 designated Points of Contact (POC) are responsible for the distribution of DR 4620-002 and DM 4620-002 and the administration of the program within their agencies.

3. BACKGROUND

Government agencies use a wide range of methods to authenticate Federal employees and contractors as a requirement to enter Government buildings and use Government systems. Federal agencies use authentication mechanisms to allow access to specific areas or systems. The methods and level of assurance for authentication (i.e., identification) and authorization (i.e., permission) vary widely from agency to agency, and sometimes within a single agency.

HSPD-12 requires that all Government agencies develop specific and consistent standards for both physical and logical identification systems. NIST’s FIPS 201-1 establishes detailed standards on implementing processes and systems to fulfill the requirements of HSPD-12. FIPS 201-1 outlines two phases to implementing an HSPD-12 program. Phase I (PIV-I) describes the registration and identity proofing process. Phase II (PIV-II) describes the technical and interoperability requirements of an HSPD-12-compliant system.

The 2002 Federal Information Security Management Act (FISMA) does not permit waivers to the FIPS 201-1 standards.

4. APPLICABILITY

According to FIPS 201-1, the standard “is applicable to identification issued by Federal departments and agencies to Federal employees and contractors (including contractor employees) for gaining physical access to Federally- controlled facilities and logical access to Federally-controlled information systems except for “national security systems” as defined by 44 U.S.C. 3542(b)(2).

Specifically, PIV applies to all Employees (as defined in title 5 U.S.C §2105 “Employee”) within a department or agency. Further defined by Executive Order (EO) 12968, “Employee” means a person, other than the President and Vice President, employed by, detailed or assigned to, USDA, including members of the Armed Forces; an expert or consultant to USDA; an industrial or commercial contractor, licensee, certificate holder, or grantee of USDA, including all subcontractors; a personal services contractor; or any other category of person who acts on behalf of an agency as determined by the agency head.

In addition, all part time employees and contractor employees who require routine access to federally controlled facilities and/or information systems will be subject to PIV. Federal employees who submitted their retirement paperwork and will retire within 6 months of submission are not subject to PIV and do not need to enroll in the HSPD-12 program. Refer to the LincPass Distribution Risk Assessment in Appendix D for guidance with regard to part time employees and contractors.

Temporary employees and contractors, short-term employees and contractors, guests, occasional visitors to Federal facilities, and individuals needing remote access to systems or applications can be issued alternate badges as described in Chapter 2, Section 6 of this Manual. These individuals are subject to a badge risk assessment just as full-time Federal employees and contractors are. Such individuals shall have in their written work agreements (volunteer agreement, guest researcher agreement, memorandum of understanding, extramural agreement, etc.)

a statement as to whether the agency risk assessment requires a PIV ID credential, and the eligibility requirements for a PIV ID credential. Refer to the LincPass Distribution Risk Assessment in Appendix D and on the Physical Security website, http://www.usda.gov/da/pmd/physprop.htm.

FIPS 201-1 also contains a special-risk security provision: “The U.S. Government has personnel, facilities, and other assets deployed and operating worldwide under a vast range of threats (e.g., terrorist, technical, intelligence), particularly heightened overseas. For those agencies with particularly sensitive OCONUS threats, the issuance, holding, and/or use of PIV credentials with full technical capabilities as described herein may result in unacceptably high risk. In such cases of extant risk (e.g., to facilities, individuals, operations, the national interest, or the national security), by the presence and/or use of full-capability PIV credentials, the Secretary of Agriculture may issue a select number of maximum security badges that do not contain (or otherwise do not fully support) the wireless and/or biometric capabilities otherwise required/referenced herein. To the greatest extent practicable, agencies should minimize the number of requests for such special-risk security badges so as to support inter-agency interoperability and the President’s policy. Use of other risk-mitigating technical (e.g., high-assurance on-off switches for the wireless capability) and procedural mechanisms in such situations is preferable, and as such is also explicitly permitted and encouraged. As protective security technology advances, this need for this provision will be re-assessed as the standard undergoes the normal review and update process.”

Since foreign national employees and contractors may not have lived in the U.S.

long enough for a background investigation to be meaningful, USDA should conduct an equivalent investigation, consistent with requirements of this Manual.

OMB will establish an interagency working group to explore whether guidance is necessary with respect to background investigations for foreign national employees and contractors. Pending receipt of OMB guidance, if any, agencies shall at a minimum complete a National Agency Check with Inquiries (NACI) for foreign national employees and contractors who have lived in the U.S. continuously for the past 5 years prior to employment. Agencies shall contact the Personnel and Document Security Division (PDSD), and the Office of Security Services (OSS) for guidance on conducting background investigations for foreign national employees and contractors who have not lived in the U.S. continuously for the past five years prior to employment.

5. CREDENTIALING STANDARDS

a. HSPD-12 Minimum PIV Card Credentialing Standards. In accordance with OPM guidelines, a PIV card will not be issued to an individual if any of the following applies:

(1) The individual is known to be or reasonably suspected of being a terrorist;

(2) The employer is unable to verify the individual’s claimed identity;

(3) There is reasonable basis to believe the individual has submitted fraudulent information concerning his or her identity;

(4) There is a reasonable basis to believe the individual will attempt to gain unauthorized access to classified documents, information protected by the Privacy Act, information that is proprietary in nature, or other sensitive or protected information;

(5) There is a reasonable basis to believe the individual will use an identity credential outside the workplace or inappropriately; or

(6) There is a reasonable basis to believe the individual will use Federally-controlled information systems unlawfully, make unauthorized modifications to such systems, corrupt or destroy such systems, or engage in inappropriate uses of such systems.

b. Supplemental PIV Card Credentialing Standards: USDA may work with individuals who do not require a suitability determination or a security clearance. In such cases, there is flexibility to apply supplemental credentialing standards in addition to the six basic standards in the previous section. These supplemental standards are intended to ensure that the grant of a PIV card to an individual does not create unacceptable risk, when the individual is not subject to an adjudication of suitability for employment in the competitive service under 5 CFR part 731, or qualification for employment in the excepted service under 5 CFR part 302 or under a similar authority, or of eligibility for access to classified information under E.O. 12968. These standards may be applied based on the risk associated with the position or work on the contract.

An agency may consider denying or revoking a PIV card to an individual based on one of these supplemental credentialing standards. In the following standards, an “unacceptable risk” refers to an unacceptable risk to life, safety, or health of employees, contractors, vendors, or visitors; to the Government’s physical assets or information systems; to personal property; to records, including classified, privileged, proprietary, financial, or medical records; or to the privacy of data subjects.

(1) There is a reasonable basis to believe, based on the individual’s misconduct or negligence in employment, that issuance of a PIV card poses an unacceptable risk;

(2) There is a reasonable basis to believe, based on the individual’s criminal or dishonest conduct, that issuance of a PIV card poses an unacceptable risk;

(3) There is a reasonable basis to believe, based on the individual’s material, intentional false statement, deception, or fraud in connection with Federal or contract employment, that issuance of a PIV card poses an unacceptable risk;

(4) There is a reasonable basis to believe, based on the nature or duration of the individual’s alcohol abuse without evidence of substantial rehabilitation, that issuance of a PIV card poses an unacceptable risk;

(5) There is a reasonable basis to believe, based on the nature or duration of the individual’s illegal use of narcotics, drugs, or other controlled substances without evidence of substantial rehabilitation, that issuance of a PIV card poses an unacceptable risk;

(6) A statutory or regulatory bar prevents the individual’s contract employment; or would prevent Federal employment under circumstances that furnish a reasonable basis to believe that issuance of a PIV card poses and unacceptable risk; or

(7) The individual has knowingly and willfully engaged in acts or activities designed to overthrow the U.S. Government by force.

6. RECIPROCITY OF CREDENTIALING DETERMINATIONS

OMB guidance requires agencies to accept PIV card credentialing determination for a person transferring from another agency when the possession of a valid Federal identity credential can be verified by the person’s former agency and the individual has undergone the required NACI or other suitability or National Security investigation at the person’s former agency.

At the agency’s discretion, a person may be ineligible for a PIV card when the former employing agency (1) determined he or she is unsuitable for employment in the competitive service, (2) denied (or revoked) his or her security clearance, or (3) disqualified him or her from an appointment in the excepted service or from working on a Federal contract. Credentialing determinations are maintained by the granting agency in the Identity Management System (IDMS). This system will allow agencies to certify each other the HSPD-12 credentialing of employees, and contractor employees.

If a person’s eligibility for a PIV card is unfavorably adjudicated for reasons other than standards 1-6 of Section 5, sub-section a, and the person moves to a lower-risk position, the gaining agency or office may reconsider the person’s eligibility for a PIV card.

CHAPTER 2

PIV-I

1. PIV-I APPLICABILITY

PIV-I requires the implementation of registration, identity proofing, and issuance procedures in line with the requirements of FIPS 201-1. To comply with this requirement, agencies must adopt and implement DR 4620-002 and DM 4620-002.

According to FIPS 201-1 PIV-I applies to employees and contractors requiring routine access to Federally-controlled facilities or information systems, who have begun work on or after October 27, 2005. USDA has determined that all full time employees (FTEs) will require a LincPass, while part time employees’ and contractors’ need for a LincPass (USDA’s PIV-I and II compliant credential), will be assessed based on the level of access required using the risk assessment tool described in Appendix D of this document, LincPass Distribution Risk Assessment.

All individuals shall follow the procedures outlined in the Appendices to apply for and receive their credentials. Agencies will continue to issue existing badges using PIV-I processes until the USAccess system is implemented. The processes for application, registration, and issuance will change with this solution, as well as roles and responsibilities. The PIV-II procedures and processes utilizing USAccess are discussed in detail in Chapter 3.

2. PRIVACY POLICY

HSPD-12 explicitly states that “protect[ing] personal privacy” is a requirement of the PIV system. As such, agencies shall implement the PIV system in accordance with the spirit and letter of all privacy controls specified in FIPS 201-1, as well as those specified in Federal privacy laws and policies including but not limited to the E-Government Act of 2002, the Privacy Act of 1974, and OMB Memorandum M- 03-22 (OMB322), as applicable.

Background investigation records are subject to the Privacy Act. Agencies must ensure those records are:

a. Secured against unauthorized access.

b. Accessed by only those whose official duties require such access.

c. Stored in a locked metal file cabinet or secure room.

Agencies must also:

a. Establish procedures to allow employees or their designated representatives access to their own records, while ensuring that the records remain subject to agency control at all times.

b. Ensure that those authorized to access personnel records subject to the Privacy Act understand how to apply the Act’s restrictions on disclosing information from a system of records.

c. Coordinate with appropriate department or agency officials to define consequences for violating privacy policies of the PIV system.

See OPM’s Guide to Personnel Recordkeeping, Chapters 1 and 6, at:

http://www.opm.gov/feddata/recguide.pdf for instructions on proper safeguarding of personnel records, and DR 3080, Records Management, at:

www.ocio.usda.gov/records/doc/DR3080-001.htm.

Agencies with active roles in the HSPD-12 processes must ensure the following items are secured in a GSA-approved Class V container with a Kaba Mas (formerly known as Mas Hamilton) X09 lock:

a. Plastic stock used to make ID credentials

b. ID credentials awaiting destruction

c. ID credentials not in the personal custody of authorized users

3. BACKGROUND INVESTIGATION REQUIREMENTS

a. A NACI is the minimum background investigation that must be performed for all individuals to whom this Directive applies, except when the position requires a more in-depth OPM or National Security community background investigation (OPM/NS BI). In such cases the OPM/NS BI shall be scheduled in lieu of the NACI through the Personnel and Document Security Division

(PDSD).

The above requirement may also be met by referencing a previous favorably adjudicated NACI or other OPM/NS BI. Agency human resources offices can meet the above requirement by completing the SF-75, Request for Preliminary Employment Data, Section K, Security Data, for federal employees transferring to the Department. Applicants experiencing a break in Federal service exceeding two years must undergo a new NACI.

b. Agencies are responsible for ensuring proper position sensitivity designation for employees and contractors, and completion of background investigations consistent with those designations. Agencies must also ensure that periodic reinvestigations are scheduled as required through PDSD.

c. Agencies will submit the SF-85, Questionnaire for Non-Sensitive Positions, and related documents needed to conduct an NACI, directly to OPM and make final PIV identity and suitability determinations on all persons serving in low-risk or non-sensitive positions.

d. Agencies may utilize the Enrollment Station for submitting the FBI fingerprint check to OPM. The Applicant must be sponsored in the USAccess system prior to using the Enrollment Station to submit the fingerprint check. If an agency requires a pre-hiring decision fingerprint check for new employees, they may continue to follow their current processes for obtaining and submitting fingerprint checks instead of submitting the fingerprint check via the Enrollment Station.

e. USDA agencies may issue a provisional credential after successful adjudication of the FBI fingerprint check. Completion and successful adjudication of the final NACI results or OPM/NS BI are still required. Upon completion of a background investigation, and at the time of determination of suitability, eligibility for access to classified information under E.O. 12968, or to work on a contract, should be made by the agency with a final credentialing determination. Alternatively, agencies may issue a PIV card after a single and final credentialing determination is made based on a completed background investigation, eligibility for access to classified information under E.O. 12968, or qualification for an appointment in the expected service or to work on a contract, is made on the same person.

f. Applicants shall submit SF-85 forms via OPM’s Electronic Questionnaire for Investigations Processing (a USDA accepted background investigation process) system located on the OPM secure Web site when available. Use of a USDA accepted background investigation process must be facilitated by agency human resources or other designated representatives. Completing a USDA accepted background investigation process Web-based security questionnaires will lead to improved processing time of all types of investigations and dramatically reduce the overall error and rejection rates of federal security questionnaires.

g. In the case of non-US citizens at U.S.-Based Locations and in U.S. Territories, immigration status and employment authorization of non-US citizens must be verified with the Department of Homeland Security (DHS) in accordance with OMB Memorandum 07-21. Acceptable DHS credentials to prove employment authorizations include, but are not limited to:

Unexpired Permanent Resident Card (I-551)

Unexpired Employment Authorization Document (I-766)

Unexpired foreign passport with a valid I-94 or I-94A for a class of admission that permits employment.

(1) For non-U.S. citizens in the U.S. or U.S. territory for 3 years or more, a background investigation (NACI or equivalent) must be initiated after immigration status and employment authorization have been verified

(2) For non-U.S citizens in the U.S. or U.S territory for less than three years, agencies may delay the background investigation until the individual has been in the U.S or U.S. territory for at least three years. Before a PIV card may be issued to a non-U.S. citizen, the individual’s immigration status and employment authorization must be verified, an FBI finger print based on criminal history must be completed, and a check must be made of Specially Designated Nationals (SDN) and Blocked Persons List. If the agency decides to delay the background investigation, the agency may request the following national agency checks:

FBI Investigation Files (name check search)

Central Intelligence Agency (CIA)

Department of State Security

Citizen and Immigration Services Check (Former INS)

(3) In the case of non-US citizens at foreign locations, agencies must initiate the completion of a background investigation before applying the credentialing standards. However, the type of background investigation may vary based on the standing reciprocity treaties concerning identity assurance that exist between the United States and its Allies with the host country. In most cases, OPM will not be able to conduct a NACI, unless the non-U.S. citizen is or has been residing in the United States.

(4) For those non-U.S. citizens where NACI or equivalent cannot be performed, an alternative facility access identity credential may be issued at the discretion of the Department of State Chief of Mission Authority, Department of Defense Installation Commander, and/or other agency official as appropriate based on a risk determination

See OSS guidance for instructions on scheduling and adjudicating background investigations at www.usda.gov/da/pdsd.

4. REGISTRATION, IDENTITY PROOFING, AND CREDENTIAL ISSUANCE

The PIV-I process contains critical roles associated with the identity proofing, registration, and issuance process. These roles may be collateral duties assigned to personnel who have other primary duties. The PIV identity proofing, registration and issuance process shall adhere to the principle of separation of duties to ensure that no single individual has the capability to issue a PIV credential without the cooperation of another authorized person.

a. Roles and Responsibilities

The roles and responsibilities initially defined for the PIV-I process have been redefined for PIV-II. See Chapter 3 for more information on PIV-II roles and responsibilities.

b. Registration, Identity Proofing, and Issuance Procedures

The procedures initially defined for the PIV-I process have been redefined for PIV-II. See Appendix C for more information on PIV-II procedures.

c. Adjudication

(1) When making a PIV eligibility determination, the Adjudicator must find whether or not the identity provided to the Sponsor and Registrar during the registration process is the Applicant’s true identity. The Adjudicator will consult with the federal Applicant or employee’s servicing human resources office before making a final determination whether to deny or revoke a credential.

If the adjudication confirms the individual’s true identity but reveals potentially disqualifying information that involve criteria 1 through 8 below, an adjudication under Title 5, C.F.R. Part 731 shall be conducted.

Title, 5 C.F.R. Part 731 criteria are:

(a) Misconduct or negligence in employment

(b) Criminal or dishonest conduct

(c) Material, intentional false statement or deception or fraud in examination or appointment

(d) Refusal to furnish testimony as required by §5.4 of Title 5, C.F.R.

(e) Alcohol abuse of a nature and duration which suggests that the applicant or appointee would be prevented from performing the duties of the position in question, or would constitute a direct threat to the property or safety of others

(f) Illegal use of narcotics, drugs, or other controlled substances, without evidence of substantial rehabilitation

(g) Knowing and willful engagement in acts or activities designed to overthrow the U.S. Government by force

(h) Any statutory or regulatory bar which prevents the lawful employment of the person involved in the position in question

(2) When making a suitability determination under Title 5 C.F.R. Part 731, the following factors shall be considered to the extent they are deemed pertinent to the individual case:

(a) The nature of the position for which the person is applying or in which the person is employed

(b) The nature and seriousness of the conduct

(c) The circumstances surrounding the conduct

(d) The recency of the conduct

(e) The age of the person involved at the time of the conduct

(f) Contributing societal conditions

(g) The absence or presence of rehabilitation or efforts toward rehabilitation

d. Appeal Procedures for Denial or Revocation of Credential

(1) Appeal Rights for Federal Service Applicants

When the Adjudicator determines that a Applicant has not provided his or her true identity during the registration process or is found unsuitable, and the determination results in a decision by the agency to withdraw an employment offer, or remove the employee from the federal service, the procedures and appeals rights of either 5 CFR Part 731, Subparts D and E (Suitability), 5 CFR Part 315, Subpart H (Probationary Employees), or 5 CFR Part 752, Subparts D through F (Adverse Actions) will be followed, depending on the employment status of the federal service Applicant, appointee, or employee. Employees who are removed from federal service are entitled to dispute this action using applicable grievance, appeal, or complaint procedures available under Federal regulations, Departmental directives, or collective bargaining agreement (if the employee is covered).

(2) Appeal Rights for Contract Applicants

(a) Notice of Proposed Action - When the Adjudicator determines that an Applicant has not provided his or her true identity or is found unsuitable, the Adjudicator shall provide the Applicant reasonable notice of the determination including the reason(s) the Applicant has been determined to not have provided his or her true identity or is otherwise unsuitable. The notice shall state the specific reasons for the determination, and that the individual has the right to answer the notice in writing. The notice shall inform the Applicant of the time limits for response, as well as the address to which such response should be made.

(b) Answer - The Applicant may respond to the determination in writing and furnish documentation that addresses the validity, truthfulness, and/or completeness of the specific reasons for the determination in support of the response.

(c) Decision – After consideration of the proposed determination and any documentation submitted by the Applicant for reconsideration of the proposed determination, the Agency Head/Staff Office Director or his/her designee, will issue a written decision to the Contracting Officer (CO), who relays the decision to the Applicant’s company Program Manager and the Contracting Officer’s Technical Representative (COTR). The CO will notify the company that the Applicant was found unsuitable to work on a USDA contract based on suitability guidelines. The company is responsible for notifying the Applicant of the decision and removing the individual from the worksite. The COTR is responsible for ensuring the action is accomplished without delay.

Specific details regarding the suitability issues will not be provided to the CO, the company, the COTR or the Program Manager, in an effort to protect the Applicant’s privacy. The reconsideration decision will be final and is not subject to appeal.

e. Record Retention

(1) The SF-85, SF-85P, SF-86, OF-306, SF-87, FD-258, and summaries of reports and other records reflecting the processing of the NACI or OPM/NS BI, exclusive of copies of investigative reports furnished by the investigative agency: Destroy upon notification of death or not later than five years after separation or transfer of employee or no later than five years after contract relationship expires, which ever is applicable.

(2) Investigative reports and related documents furnished to agencies by investigative organizations for use in making PIV ID credential eligibility determinations: Destroy in accordance with the investigating agency instructions.

(3) Appeal records related to unsuccessful adjudications: Destroy no sooner than 4 years but no later than seven years after final appeal decision.

See GSA Records Schedule 1 and 18 at:

http://www.archives.gov/records-mgmt/ardor/records-schedules.html and DR 3080-001, Records Management, at:

http://www.ocio.usda.gov/directives/doc/DR3080-001.pdf.

5. EXPIRATION DATE REQUIREMENTS

All PIV credentials issued to the USDA must have an expiration date printed on them. The expiration date for all credentials must be five years or less from the date of issuance. PIV credentials for contractors must expire at the end of the contract period of performance.

All badges issued to applicable employees and contractors must be replaced with PIV-compliant credentials no later than October 27, 2009.

6. TEMPORARY BADGES

USDA has identified categories of individuals, temporary employees or contractors, guests, volunteers, student interns, and occasional visitors, who will not require a LincPass. These individuals, however, may need badges to gain access to facilities but do not require secure access. These individuals will have limited access to such places as the front entrance of the facility, their immediate workspace, and open areas such as a cafeteria, snack bar, employee break room, restroom, and similar open areas, as directed and controlled by the facility. Agencies may choose to implement stricter requirements at their own discretion following the LincPass Distribution Risk Assessment. See Appendix E for more information on the types of credentials/badges USDA issues.

a. Site Badge

A Site badge is issued locally by the facility to persons that do not require a LincPass but need access to the facility or information system to conduct temporary work. Also, a site badge is issued to individuals who require a LincPass after having fingerprints taken and waiting for credential to be printed and returned for activation.

b. Visitor Badge

This type of card can be either a plastic card turned in after the visit and sequentially numbered, or a paper tag that can be worn and disposed of upon completion of the visit. The paper or plastic badge has the expiration date clearly visible. The maximum issuance for this type of badge is 24 hours, and requires continuous escort.

In addition, should an employee or contractor forget their credential on a particular day, they will be issued a visitor badge after their identity is confirmed.

7. CONTRACTING IMPACTS

a. All contractors must abide by the identity proofing and registration requirements outlined in Chapter 2, Section 4 above. USDA contract statements of work must indicate that all contractors requiring routine access to Federally-controlled facilities or information systems must go through the identity proofing and registration process, and must have been successfully identity proofed, and have a successfully adjudicated NACI or OPM/NS BI to serve on the contract.

b. Contractor ID credentials will be issued after they have been successfully identity proofed, and upon a successfully adjudicated NACI or OPM/NS BI.

All contracts must specify periods of performance. Contractors must, by contract law, renew their credentials after 5 years if they have not yet reached the end of their period of performance.

c. Certain PIV language must be implemented in all contracts. This language is found in FAR Subpart 4.13, Personal Identity Verification of Contractor Personnel. HSPD-12 clauses include FAR Clause 52.204-9 and AGAR Clause 452.204-71. AGAR Advisory 81, Common Identification Standard for Contractors, contains additional HSPD-12 procurement guidance.

8. AUDIT AND RECORDS MANAGEMENT

The Office of Inspector General has responsibility for auditing identity proofing and registration records. As such, all agencies should be prepared for such reviews.

Agencies must comply with DR 3080-001, “Records Management,” for the creation, maintenance, use, and disposition of all records associated with the PIV process.

9. USE OF APPROVED FORMS

To comply with the Paperwork Reduction Act (PRA) of 1995, all agencies will be required to use OMB approved forms throughout the identity proofing and registration process. Most of these forms are standard Federal Government-wide forms that have been available for many years. In addition to the Government-wide forms, the USDA has created an additional PIV specific form that will fulfill the information gathering requirements of the PIV program. The following is a list of approved forms for use in the PIV-I process:

a. AD-1197: PIV-I Request and Issuance Approval Form or OMB-approved equivalent (see Appendix I).

b. FD-258: Fingerprint Chart used to conduct contractor FBI fingerprint checks.

c. OF-306: Declaration for Federal Employment

d. OF-612: Optional Application for Federal Employment

e. OPM OFI-79A: Report of Agency Adjudicative Action on OPM Personnel Investigations

f. Standard Form (SF) 85:

OPM Questionnaire for Non-Sensitive Positions (to be completed using a USDA accepted background investigation process when available)

g. SF 85P: OPM Questionnaire for Public Trust Positions (to be completed using a USDA accepted background investigation process)

h. SF 86: OPM Questionnaire for National Security Positions (to be completed using a USDA accepted background investigation process)

i. SF 87: Fingerprint Chart used to conduct FBI fingerprint checks for federal appointees and employees and Applicants for federal employment.

10. REPORTING REQUIREMENTS

Agencies are required to submit quarterly and annual reports on their credential programs to ensure controls are in place for tracking all credentials. Agencies must submit the following reports to OSS within 15 days of the end of each quarter and the fiscal year:

a. Number of credentials issued during designated period

b. Number of credentials renewed during designated period

c. Number of credentials lost during designated period

d. Number of credentials stolen during designated period

e. Number of credentials revoked during designated period

f. Number of credentials suspended during designated period

g. Number of credentials retired during designated period

h. Number of credentials expired during designated period

Beginning on March 1, 2007 and each quarter thereafter, agencies are required to post a report on number of credentials issued on their public websites per OMB Memorandum M-07-06. This memorandum provides the guidance for reporting the number of credentials issued by quarter and includes the report template.

CHAPTER 3

PIV-II

1. PIV-II OVERVIEW

PIV-II is the implementation phase that meets the technical interoperability requirements of HSPD-12. Specifically, PIV-II addresses the technical infrastructure for providing interoperable credentials for federal employees and contractors. All authentication mechanisms described in FIPS 201-1 are to be met with the use of integrated circuit cards.

FIPS 201-1 describes minimum technical requirements for the PIV-II-compliant credentials. These requirements include interfacing specifications, cryptographic specifications, PKI and certificate specifications, card topology specifications, and biometric data specifications. The PIV-II-compliant credentials issued will be used to control physical access to all Federally controlled facilities and logical access to all Federally controlled information systems through a contact or contactless interface. USDA has named their common ID card the LincPass, as it is designed to link a person’s identity to an identification card and the card to a person’s ability to access Federal buildings and computer systems.

For PIV-II, the USDA will be using the USAccess system, a system-based model with increased functionality to improve efficiency and accuracy in processing PIV applications. A planned rollout to USDA employees and contractors will be phased in by organization and geographic location. PIV-II will include three new logical subsystems:

a. PIV Front-End Subsystem - PIV credential and biometric readers, and Personal Identification Number (PIN) input device. The PIV credential holder interacts with the front-end subsystem to gain physical or logical access to the desired Federal resource.

b. Credential Issuance and Management Subsystem - the components responsible for identity proofing and registration, card and key issuance and management, and various repositories and services required as part of the verification infrastructure.

c. Access Control Subsystem – the physical and logical access control systems and authorization data.

2. PIV-II APPLICABILITY

PIV-II applies to all full-time employees, contractors, and others assigned to or associated with the agency who require routine access to federally controlled facilities and/or information systems. Applicability to other individuals will be based on a LincPass risk assessment and is subject to rule making procedures. PIV- II applies to the facilities and information systems as defined in FAR Subpart 2.1, Definitions. Note: The information in Chapter 2, Sections 2, 3, 4c, 4d, 4e, 5, 6, 7, 8, 9, and 10 apply to PIV-II processes and procedures.

3. REGISTRATION, IDENTITY PROOFING, CREDENTIAL ISSUANCE, AND

REVOCATION

The PIV-II process contains critical roles associated with the identity proofing, registration, and issuance process. These roles may be collateral duties assigned to personnel who have other primary duties. The PIV identity proofing, registration and issuance process shall adhere to the principle of separation of duties to ensure that no single individual has the capability to issue a PIV credential without the cooperation of another authorized person.

The following roles shall be employed for identity proofing, registration, and issuance prior to complete implementation of USAccess system. See Appendix C for more detailed information on the PIV-II processes.

a. Roles and Responsibilities

(1) Applicant. The Applicant is an individual requesting a credential from an agency that is a participant in the USAccess system. Applicant responsibilities include:

(a) Provide Sponsor with any necessary information.

(b) If no Background Investigation completed or in progress, input information into e-QIP (if available) or fill out the appropriate SF- 8X form.

(c) Submit fingerprints for a background check.

(d) Schedule an enrollment appointment.

(e) Appear for the enrollment appointment at the time and place scheduled.

(f) Provide the Registrar with two I-9 listed identity documents.

(g) Submit to a digital photo taken by the Registrar.

(h) Submit 10 rolled fingerprints.

(i) Digitally sign the enrollment package.

(j) Pick up the credential at the specified time and place.

(k) Take the credential to an Activation station to activate it via biometric verification.

(l) Set a PIN for the credential at the Activation Station.

(m) Provide a digital signature.

(n) Complete IT Security Awareness Training.

(2) Sponsor. The Sponsor is the employer or agency official responsible for authorizing an individual to apply for a credential, who has undergone Sponsor training, and is designated to perform Sponsor functions. In the case of contractor employees, the Sponsor may be the COR, COTR, or other designated program official. Sponsor responsibilities include:

(a) Enter Applicant’s information into EmpowHR or other HR System.

(b) For part time employees and non-employees, determine if an Applicant needs a LincPass utilizing the Risk Assessment Tool.

(c) Determine if Applicants already have favorably adjudicated background investigations via OPM for employees or through prior agency HR or Security offices for contractors.

(d) If (c) is no, set up Applicant for a USDA accepted background investigation process, or review the Applicant’s SF-85, SF 85P or SF-86, Questionnaire for Non-Sensitive Positions, and OF-306, Declaration for Federal Employment.

(e) Modify Applicant’s record based on updates to user status and relevant information.

(f) Suspend or revoke LincPass via EmpowHR or USAccess.

(g) Recover revoked credentials and send to the Security Officer for destruction.

(h) Recover suspended credentials and sent to the Security Officer for secure storage pending resolution of issue(s).

(i) Initiate re-enrollments for current or previous cardholders.

(3) Registrar. The Registrar is an individual responsible for identify proofing the Applicant, as well as capturing biographic information, digital photo, and biometrics. The Registrar’s responsibilities include:

(a) Manage schedule for enrollment workstations in case of scheduling conflicts.

(b) Answer any privacy or system related questions that an Applicant may have.

(c) Locate and open the Applicant’s information, and verify the information with the Applicant.

(d) Contact the Sponsor if the Applicant’s record can not be found in the system to investigate and resolve the problem.

(e) Verify and scan the Applicant’s two identity source (I-9) documents.

(f) Enter FBI-required Applicant data.

(g) Capture the Applicant’s facial image in the system via a digital photograph.

(h) Capture ten rolled fingerprints into the system.

(i) Verify the primary and secondary fingerprints against the minutiae to ensure that the templates will work when put on the credential.

(j) Flag any issues during enrollment.

(k) Digitally sign and send enrollment package to Credential Printing Facility, and inform Applicant of next steps (i.e. credential issuance and activation process).

(4) U.S. Office of Personnel Management. OPM is responsible for coordinating the FBI fingerprint check, when applicable, and conducting the NACI and background investigation. A direct link from the Enrollment Station to the FBI for submitting fingerprints will be implemented in the near future, but it is the individual agency’s decision as to whether to utilize the enrollment station for submitting fingerprints to OPM or to keep using current processes.

(5) Agency Adjudicator. The agency Adjudicator is a Government employee of the sponsoring agency who adjudicates or resolves any issues or failures of the background check process and gives the notification to print. A contractor employee may recommend how to adjudicate a background investigation and record the results in the HSPD-12 system, however a federal employee must sign off on the recommendation first. Agency Adjudicator responsibilities include:

(a) Receive manual reports on background checks.

(b) Confirm NACI or FBI checks, denial of credential if “fail” results.

(c) Respond to inquires on adjudication status from Applicants.

(d) Adjudicate final background investigation results.

(e) Update OPF/contract file or ensure agency receives appropriate documentation.

(6) Issuer/Activator. The Issuer/Activator is the individual responsible for processing credential activations. The Issuer/Activator verifies that the Applicant is the person to whom the credentials are to be issued and guides the Applicant through the issuance process.

Most activation stations will be unattended, meaning that Applicants will use the system without assistance to activate their credentials. In the event that there is an issue causing the unattended activation to fail, the Issuer/Activator will assist the Applicant in completing the activation, or collect the credential, note the issue in the system, and flag the record for issue resolution.

Issuer/Activator responsibilities include:

(a) Receive “to-be-activated” credentials from issuing station, signs for packages (dependent on shipping model).

(b) Log credential into the system, sending out electronic notifications to the Applicants (TBD).

(c) Control secure storage of credentials in a locked safe, logging all action items taken into or out of the safe.

(d) Hand the credential to the individual after verifying their ID.

(e) Verify that the Applicant information in the system and credential display information are correct.

(f) Visually check the Applicant’s facial image against the IDMS photo and the LincPass photo to verify that Applicant information and credential display info match if there is no fingerprint record.

(g) Flag the credential in the system and note problems with activation.

(h) Retrieve the credential if activation fails.

(7) Agency Role Administrator. The Agency Role Administrator is the individual responsible for managing the agency’s Sponsor, Adjudicator, Registrar, and Issuer/Activators. The Agency Role Administrator will verify that the appropriate separation of duty policies are followed and will verify that all the training certification requirements have been met.

Agency Role Administrator responsibilities include:

(a) Authority on separation of roles within agency.

(b) Provide written documentation of any allowance involving a combination of roles.

(c) Approve portal privileges for new role holders, verifying separation of duties and training.

(d) Revoke role privileges and portal access for users within the agency when appropriate.

(8) USDA Security Officer. The USDA Security Officer is the individual responsible for maintaining credential security as well as physical building security within USDA. The USDA Security Officer is nominated by the Department. USDA Security Officer responsibilities include:

(a) Access all records in the system.

(b) Delegate authority to designated Security Officers for record access.

(c) Provide oversight to Security Officers to ensure completed training, certification, and issuance of credentials.

(d) Report to the Agency Role Administrator that designated Security Officers are trained, certified, and credentialed.

(e) Manage employees’ and contractors’ “credential status” when required.

(f) Grant necessary access privileges when required.

(g) When required, immediately…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .