S01_1_RFQ_12FPC223Q0038_revised1Aug2023.pdf

PDF 1007 KB Posted

Attached to
FSA Kiosks Federal contract opportunity
Solicitation number
12FPC223Q0038
Issued by
Department of Agriculture Under Secretary for Farm Production and Conservation

About this file

This document is a request for quotation (RFQ) issued by the Department of Agriculture for the procurement of FSA kiosks. The RFQ seeks quotes to provide 5,023 Chrome OS devices to be deployed as kiosks and for seasonal workers across multiple regions in a two-phase delivery schedule. The devices must meet specified hardware requirements including Intel Core i3 or AMD processor, 8GB RAM, 64GB storage, 13-inch or larger touchscreen display, WiFi 6 connectivity, and a battery capable of lasting 8 hours. Vendors must also provide a one-year warranty and bundle each device with a Chrome Enterprise Upgrade perpetual license. Delivery of the first phase of 2,548 devices to various locations must be completed within 90 days, while the second phase of 2,473 devices must be delivered within 180 days of test device acceptance. Quotes are due on a firm-fixed price basis.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Solicitation Number - 12FPC223Q0038 FSA Kiosk

SECTION A-SOLICITATION/CONTRACT FORM:

REQUEST FOR QUOTATION

FSA Kiosks

USDA-Farm Production and Conservation RFQ No. 12FPC223Q0038

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in FAR subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation will not be issued.

The solicitation number 12FPC223Q0038 is issued as a Request for Quotation (RFQ) and the acquisition procedures at FAR subpart 13.5 are being utilized. The Government anticipates issuing a firm-fixed price purchase order off Contract Opportunities via System for Award Management (SAM.gov).

This is a 100% small business set-aside. The applicable North American Industry Classification System (NAICS) code is 334118 – Computer Terminal and Other Computer Peripheral Equipment Manufacturing, which has a size standard of 1000 employees. For more information on size standards, visit http://www.sba.gov/size.

This solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2023-04 Effective June 2, 2023.

A-1 TYPE OF CONTRACT:

This is a firm-fixed price Purchase Order.

A-2 PERIOD OF PERFORMANCE:

The period of performance for FSA Kiosks will be a one (1) base period with three separate delivery periods as outlined below:

Base Period of Performance: 08/16/2023 – 05/30/2024

SECTION B-CHROMEBOOK PRICING:

Description QTY Unit Price Total Price Test Devices 2 Phase 1 Delivery- Device (Standard Chrome OS Hardware Configurations)

Phase 2 Delivery- Device (Standard Chrome OS Hardware Configurations)

SECTION C: STATEMENT OF WORK:

Project Farm Service Agency Express Lightweight Hardware Device Initiative

1.0 Background

The United States Department of Agriculture (USDA), Farm Services Agency (FSA) administers and manages farm commodity, disaster, and loan programs as authorized by Congress through a network of federal, state, and county offices. The USDA FSA will deploy a Chrome OS device solution for USDA seasonal workers, kiosks for producers visiting county offices, frontline workers, and/or standard users who utilize standard productivity toolsets via web browsers or a Virtual Desktop solution.

2.0 Technical Requirements / Tasks

The Statement of Work (SOW) specifies the minimum device hardware and support requirements, delivery, schedule, warranty, and deliverables. Additionally, the SOW outlines the requirement for a “Chrome Enterprise Upgrade – Perpetual” license bundled with each device, compliance with Section 508 of the Rehabilitation Act of 1973, and the Information and Communications Technology Accessibility Standards (36 CFR 1194) developed by the Architectural and Transportation Barriers Compliance Board.

2.1 Device

The Contractor shall provide 5,023 complete standard Chrome OS hardware configurations (referred to as “Device”) sourced from original equipment manufacturers (OEMs). The Government does not prefer any specific make, model or brand, as long as the hardware and fulfills the specific configurations identified in section 2.1.

2.1.1 Minimum Device Support Requirements

• Device must have a Google Auto Update Expiration (AUE) date that is at minimum six years in the future beyond the date the order is placed.

• Devices must be bundled with “Chrome Enterprise Upgrade – Perpetual” license, making them bundled devices as defined by Google.

• Devices must meet current Electronic Product Environmental Assessment Tool (EPEAT) Bronze or higher and Energy Star requirements for energy conservation.

2.1.2 Minimum Device Hardware Requirements

• INTEL Core i3 processor or AMD equivalent or better

• Minimum 8GB RAM

• Minimum 64GB SSD storage

• Minimum diagonal display size 13”

• Touch Screen

• 360-degree Flip format (also known as “Convertible”)

• Wi-Fi 6

• Bluetooth

• At least one USB-C Type-C port (USB power delivery, display port)

• At least one USB Type-A port (preferred, but optional)

• Built-in camera (preferred, but optional)

• Battery shall last a minimum of 8 hours

• AC adaptor and power cable

2.1.3 Google Zero-Touch Enrollment

The Government will provide a pre-provisioning token created on the USDA’s Google Admin Console and USDA device enrollment domain to the Contractor for installation on each device. The exact secure method to provide this Government furnished information will be finalized during the kickoff meeting. The Contractor shall install the pre-provisioning token and enrollment domain on each device.

2.1.4 Warranty

All devices must have a minimum 1-year manufacturer device hardware mail-in warranty. The Contractor shall be the initial point of contact for ALL warranty issues for the first 30 days, after which it will be the OEM’s responsibility to provide support. The OEM shall provide, at a minimum, a toll-free telephone support number to the support desk. Support shall be available between the hours of 7:00 – 5:00 Central Time, Monday - Friday. Warranty support shall extend to all continental U.S. (CONUS) and outside of continental U.S. (OCONUS) locations. The Contractor shall identify any locations not covered by warranty support. The actual scope of warranty service for such locations shall be fully defined.

If the Government receives continuous and ongoing documented complaints with faulty performance of a model machine or its components or independent technical information identifying faulty components in each model during the performance period, the Government may request the Contractor to provide a suitable replacement model that is equal to or better than the faulty model.

2.1.5 Packaging and Labeling

Each Chrome OS device must be new and individually boxed in its manufacturer’s original packaging or equivalent.

Each box must be labeled with the Delivery Note from the Master Shipping and Tracking List (attachment A).

2.2 Test Devices

The Contractor shall participate in a kickoff meeting with the Contracting Officer, Contracting Officer Representative, and Government technical team within five (5) business days of contract award. During the meeting, the Government and Contractor will resolve any open questions or clarifications needed prior to delivery of the test devices. In addition, the Contractor shall describe the intended delivery plan for the devices.

To manage risk, the Government will test example devices to confirm the device model meets all specifications.

The Contractor shall within ten (10) business days of contract award deliver two (2) test devices meeting all specifications identified in section 2.1 to:

USDA-OCIO-CEC-TSD

210 Walnut Street RM 855 Des Moines, IA 50309 ATTN: Jeffry Tibbles

The Contractor shall complete the Master Shipping and Tracking List (attachment A) as described in section 3.1 for the test devices concurrent with device shipment.

The Government will test the devices within five (5) business days of receipt. The Government will inform the vendor of device acceptance or document any specific technical or operational issues discovered. The Contractor shall remediate any identified deficiencies within five (5) business days. Upon Government acceptance of the test devices, delivery of the remaining devices may commence.

3.0 Government Furnished Information

A copy of the Master Shipping and Tracking List is provided as attachment A to this statement of work. The Government will provide the Master Shipping and Tracking List via a Box account prior to the kickoff meeting and will grant the Contractor editor permissions. The Master Shipping and Tracking List will include the following information:

• Delivery Phase

• Region

• Preferred Delivery Sequence

• Office Name

• Shipping Address, City, State, Zip, and Phone

• Delivery Note to be included on device packaging

The Master Shipping and Tracking List will include space for the contractor to complete information required under section 2.2. The Government will use the List to provide device receipt and acceptance information.

3.1 Reporting

The Contractor shall update the Master Shipping and Tracking List (attachment A) in Box biweekly on Wednesdays with the following information for each device shipped through the preceding Sunday.

• Device serial number

• Wi-Fi MAC Address

• Google Automatic Update Expiration (AUE) Date

• Shipment Date

• Shipment Tracking Number

• Carrier

• Expected Delivery Date

• Contractor Notes for USDA (as needed)

The Government will update the Master Shipping and Tracking List (attachment A) biweekly on Fridays within Box with device receipt confirmation, device acceptance status, and USDA notes for contractor (as needed).

4.0 Delivery

The Contractor shall deliver devices (section 2.1) to the locations identified on the Master Shipping and Tracking List (attachment A). If multiple devices have the same shipping location, they may be delivered in a single shipment. All shipments must require signature. Most locations are USDA Headquarters or Service Center offices and may receive only standard packages during regular business hours (Monday – Friday, 9 a.m. – 4 p.m. local time). Delivery will occur in two phases.

The first phase will include all locations in the National, Northeast, Northwest, and Midwest regions. The Contractor shall ship devices to the locations in phase 1 in the preferred delivery sequence identified in the Master Shipping and Tracking List. The Contractor shall deliver the 2,546 devices in phase 1 no later than 90 calendar days after the government acceptance of the two (2) test devices.

The second phase will include all locations in the Southwest, Southeast, and Depot regions. The Contractor shall ship devices to the locations in phase 2 in the preferred delivery sequence identified in the Master Shipping and Tracking List. The Contractor shall deliver the 2,475 devices in phase 2 no later than 180 calendar days after the government acceptance of the two (2) test devices. Shipment to the Depot region may be a bulk shipment delivered on standard pallets to the warehouse dock.

The Government prefers continuous delivery of devices throughout the phase, rather than a bulk shipment at the end of each phase. Continuous delivery will streamline USDA coordination, testing, and acceptance of the devices.

5.0 Deliverables / Schedule

Key Deliverables

Item No. Deliverable Objective Due

1 Kickoff Coordinate technical, communication, and delivery details.

Ref. Subtask 2.2

No later than five (5) business days after contract award

2 Test devices (qty 2) Support device verification and acceptance prior to phased delivery.

Ref. Subtask 2.2

No later than ten (10) business days after contract award

3 Master Shipping and Tracking List

Report device-specific information and delivery status.

Ref. Subtask 2.3

Biweekly, Wednesdays by 5 p.m.

ET

4 Devices – Phase 1 (qty 2,548)

Device delivery to National, Northeast, Northwest, and Midwest regions

Ref. Subtask 2.1

No later than 90 days after government acceptance of test devices

5 Devices – Phase 2 (qty 2,473)

Device delivery to Southwest, Southeast, and Depot regions

Ref. Subtask 2.1

No later than 180 days after government acceptance of test devices

6.0 Invoicing

The contractor shall submit invoices monthly for all devices accepted by the Government through the last day of the preceding month.

Invoices shall be submitted electronically through the Department of Treasury's Invoice Processing Platform (IPP).

The contractor shall follow instructions on how to register and submit invoices via IPP as prescribed at the IPP website https://www.ipp.gov/.

Additional Information regarding what constitutes a proper invoice can be found by reviewing the Prompt Payment Act (31 USC Chapter 32 - PROMPT PAYMENT ACT).

A complete contractor-generated invoice shall be provided electronically (either as an attachment via IPP or via email direct to the ACO and COR) along with applicable back up documentation.

7.0 USDA IT Requirements

7.1 USDA Cyber Supply Chain Risk Management

7.1.1 Country of Origin

Country of Origin (COO) represents the country or countries of manufacture, production, design, or brand origin.

The expectation is: (1) the cargo is what it purports to be and in the quantity stated; (2) the cargo was in the continuous possession or control by the carrier who took charge of the cargo from the time it was loaded in the container at origin until the time it is delivered at final destination; and (3) there is evidence of the identify of each person or entity who had access to it during its movement and that the cargo remained in the same condition from the moment it was sealed in the container for transfer to the carrier who controlled possession until the moment that carrier released the cargo into the receipted custody of another.

Country of Origin guidelines are as follows:

• USDA will not use any product or its components (including hardware, software, and firmware) that are on the Department of Commerce Entity List. This includes countries where the development, manufacturing, maintenance, and service for the product are provided.

• Contractor shall identify the country (or countries) of origin of the procured product and its components (including hardware, software, and firmware).

• Contractor shall identify the countries where the development, manufacturing, maintenance, and service for the product are provided.

• Contractor shall notify USDA of changes in the list of countries where product maintenance or other services are provided in support of the procured product. This notification shall occur # days prior to initiating a change in the list of countries.

• Contractor shall ensure that all-source threat and vulnerability information includes any available foreign ownership and control (FOCI) data. This data should be reviewed periodically as mergers and acquisitions, if affecting a supplier, may impact both threat and vulnerability information and therefore SCRM.

• Contractor shall use trusted channels to ship procured products, such as U.S. registered mail.

• Contractor shall demonstrate a capability for detecting unauthorized access throughout the delivery processes.

• Contractor shall demonstrate chain-of-custody documentation for procured products as determined by USDA in its sole discretion and require tamper-evident packaging for the delivery of this product.

• Contractor shall implement anti-tamper technologies and techniques that provide a level of protection for critical information systems, system components, and information technology products against known related threats including modification, reverse engineering, and substitution.

7.1.2 Information and Communications Technology (ICT) Supply Chain Risk Management (SCRM) Software Development Lifecycle (SDLC) Information and Communications Technology (ICT) Supply Chain Risk Management (SCRM) Software Development Lifecyle (SDLC) is implemented as part of overall risk management activities, such as those described in NIST SP 800-39, Managing Information Security Risk. Activities should involve identifying and assessing applicable risks, determining appropriate mitigating actions, developing an ICT SCRM Plan to document selected mitigating actions, and monitoring performance against that Plan.

Contractor shall ensure the latest publication of NIST SP 800-161 - Supply Chain Risk Management Practices for Federal Information Systems and Organizations and NIST SP 800-37 - Risk Management Framework for Information Systems and Organizations are incorporated into their ICT SCRM SDLC process.

Consistent with the latest publication of NIST SP 800-161 and NIST SP 800-37, the acquisition community at the USDA and agencies will adopt an ICT SCRM SDLC approach to managing risk to information systems. The USDA, agencies, and personnel will integrate SCRM processes, activities and tasks throughout the life cycle of agency systems, components and services.

7.1.2.1 Continuous Diagnostic and Mitigation (CDM) Approved Products List (APL) Supply Chain Risk Management Plan The Continuous Diagnostics and Mitigation (CDM) Approved Products List (APL) Product Submission Instructions reference the requirement to submit a Supply Chain Risk Management Plan (SCRM) as part of that activity. The CDM APL SCRM Plan is in support of the National Institute of Standards (NIST) and the latest publication of NIST Special Publication (SP) 800-53 “SA-12” supply chain control. Contractor is responsible for providing the CDM APL SCRM Plan. The purpose of this document is to provide background information on the SCRM requirement and outline the instructions an offeror is to follow in completing and submitting the CDM APL SCRM Plan. The CDM APL SCRM Plan consists of (1) the completed questionnaires and (2) additional information the offeror wishes to provide. APL submission packages that do not include completed CDM-APL-SCRM questionnaires will fail conformance. Additional information can be submitted; APL packages will not fail conformance for the lack of providing SCRM information beyond the questionnaires for CDM-APL-SCRM.

The objective of CDM SCRM Plan is to provide information to Agencies and ordering activities about how the offeror identifies, assesses, and mitigates supply chain risks in order to facilitate better informed decision-making by Agencies and ordering activities. The CDM SCRM Plan is intended to provide visibility into, and improve the buyer’s understanding of, how the Offeror’s proposed products are developed, integrated and deployed; as well as the processes, procedures, and practices used to assure the integrity, security, resilience, and quality of those products.

The contractor shall include a CDM SCRM Plan with its proposal that addresses counterfeit and illegally modified products. The CDM SCRM plan shall describe the contractor’s approach to SCRM and demonstrate how the contractor’s approach will reduce and mitigate supply chain risks. For additional details on GSA’s internal guidance on supply chain risk management, see subpart GSAM 504.70.

The contractor shall provide a CDM SCRM plan to manage supply chain risk throughout each of the five (5) supply chain phases specified in its proposal: 1) design and engineering, 2) manufacturing and assembly, 3) distribution and warehousing, 4) operations and support, and 5) disposal and return. In addition to the components and processes for which the contractor is directly responsible, and as feasible, the contractor shall identify “specified supporting infrastructure beyond the system boundary” and where appropriate, include such infrastructure in its SCRM Plan.

The CDM SCRM Plan shall address at a minimum, but not be limited to, the following:

1. How the contractor ensures that requirements for genuine Information Technology Tools (ITT) are imposed upon its direct suppliers, whether the direct supplier is a systems integrator, reseller or OEM. The requirements for assurance and supporting evidence must include:

a. The contractor performs reasonable steps to ensure its SCRM Plan is performed for ITT in its delivered and installed configuration;

b. Equipment resellers from whom the contractor purchases ITT have valid licenses for OEM equipment and software;

c. The ITT OEM exercises strict quality control to ensure that counterfeit or illegally modified hardware or software components are not incorporated into the OEM product; and

d. The contractor ensures traceability of assurance and evidence of genuineness of ITT back to the licensed product and component OEMs.

2. The contractor’s use of system security engineering processes in specifying and designing a system that is protected against external threats and against hardware and software vulnerabilities.

3. The contractor’s strategy for implementing SCRM security requirements throughout the life of the contract. The SCRM plan shall address the security controls described in the latest publication of NIST SP 800-53. Implementation of the controls shall be tailored in scope to the effort and the specific information.

4. The criticality analysis (CA) process used by the contractor to determine Mission Critical Functions and the protection techniques (countermeasures and sub-countermeasures) used to achieve system protection and mission effectiveness. The CA shall describe the contractor’s supply chain for all critical hardware and software components (and material included in products), key suppliers, and include proof of company ownership and location (on-shore or off- shore) for key suppliers and component manufacturers.

5. How the contractor will ensure that products and components are not repaired and shipped as new products and components are provided to the government.

6. How the contractor will ensure that supply channels are monitored for counterfeit products throughout the product life cycle to include maintenance and repair.

7. How the contractor’s physical and logical delivery mechanisms will protect against unauthorized access, exposure of system components, information misuse, unauthorized modification, or redirection.

8. How the contractor’s operational processes (during maintenance, upgrade, patching, element replacement, or other sustainment activities) and disposal processes will limit opportunities for knowledge exposure, data release, or system compromise.

9. Which of the following identifies the relationship between the contractor and the manufacturer:

OEM, 2) authorized reseller, 3) authorized partner/distributor, or 4) unknown/unidentified source.

10. How the contractor will ensure independent verification and validation of assurances, and provide supporting evidence as required.

NIST SP 800-161 identifies supply chain risk management (SCRM) best practices. The offeror shall update its SCRM Plan to include any future changes to the NIST SCRM Guidelines and all such modifications to the Plan shall be made at no cost to the government.

7.1.2.2 SCRM Plan Submittal and Review

The plan shall be submitted with the contractor’s proposal. Updates shall be submitted on an annual basis to the CO and COR. All information included will be treated as Controlled Unclassified Information (CUI) pursuant to Executive Order 13556, shared only with government agencies, and used solely for the purposes of mission-essential risk management. All reviews shall be completed within a 45-day time period.

7.1.2.3 Manufacturing (Original Equipment Manufacturer (OEM)) Contractor developers shall perform industry best practices associated with security testing and evaluation consistent with the latest publication of Special Publication 800-115 - Technical Guide to Information Security Testing and Assessment. This includes, but is not limited to, the following:

• Implement a repeatable and documented assessment methodology;

• Analyze findings, and develop risk mitigation techniques to address weaknesses;

• Provide consistency and structure to security testing, which can minimize testing risks; and

• Address resource constraints associated with security assessments.

7.1.2.3.1 Counterfeit Parts/Replacement Parts

A product is genuine if it is not counterfeited, imitated, tampered or adulterated and is not gray market, remanufactured, or refurbished. Contractor shall report all suspected counterfeit material/items to the Government through the Government Industry Data Exchange Program (GIDEP) database and to the program office via e-mail to the Contracting Officer, Program Manager, and COR within five (5) working days of discovery. The Contractor shall prominently label all suspected counterfeit material/items and physically separate from all other supplies and shall not return or dispose suspected or confirmed counterfeit material/items to the supplier but hold such items for Government analysis and investigation. The Contractor shall aid the Government investigation including providing all documents associated with the purchase, shipping, and other relevant data on the counterfeit materials/items. The Government will provide final disposition instructions for confirmed counterfeit material/items to include turnover to the Government.

7.1.2.4 End of Life/Support Products

Any product within 18 months of End of Life/End of Support will not be procured by USDA.

7.1.2.4.1 Product Integrity [GSA SECTION 846 – COUNTERFEIT ITEMS]

7.1.2.4.1.2 Hardware, Software, and Patch Integrity and Authenticity:

If Contractor provides software or patches to USDA, [Contractor/Sub- Contractor] shall publish or provide a hash conforming to the Federal Information Processing Standard (FIPS) Security Requirements for Cryptographic Modules (FIPS 140-2) or similar standard information on the software and patches to enable USDA to use the hash value as a checksum to independently verify the integrity of the software and patches and avoid downloading the software or patches from Contractor’s website that has been surreptitiously infected with a virus or otherwise corrupted without the knowledge of Contractor.

a. Contractor is responsible for providing software that is free of vulnerabilities by validating that those Common Vulnerability and Exposures (CVE), common weakness enumeration (CWE);

b. Open Web Application Security Project (OWASP) items that are most dangerous to the mission are absent from the software and that the software operates at the least privilege required to complete its task;

and

c. Contractor shall establish, document, and implement risk management practices for supply chain delivery of hardware, software (including patches), and firmware provided under this Agreement.

7.1.2.4.1.3 Digital Delivery

Contractor shall specify how digital delivery for procured products (e.g., software, applications, and data) including patches will be validated and monitored to ensure the digital delivery remains as specified. If USDA deems that it is warranted, [Contractor/Sub- Contractor] shall apply encryption to protect procured products throughout the delivery process.

7.1.2.4.1.4 Firmware

a. Prior to the delivery of any products and services to USDA or any connection of electronic devices, assets or equipment to USDA’s electronic equipment, Contractor shall provide documentation regarding its patch management and vulnerability management and continuous monitoring (including third-party hardware, software, and firmware) for products, services, and any electronic device, asset, or equipment required to be connected to the assets of USDA during the provision of products and services under this Agreement. This documentation shall include information regarding:

• Resources and technical capabilities to sustain this program and process such as Contractor’s method or recommendation for how the integrity of a patch is validated by USDA;

• Contractor procedures to Check Software and the patches for authenticity and integrity of the products with integrity verification tools, to detect unauthorized changes to software, information system and the supply chain. An example of a validation procedure may be the use of digital signature by an OEM to prove that the software delivered is from its originating source. When digital signatures are used for this purpose, the organization should ensure, when receiving such software, that the signed upgrade/download was not altered;

• USDA will ensure that code authentication mechanisms such as digital signature, certificate is recognized and approved;

• Implement the use of cryptographic mechanisms, to authenticate software, hardware, information systems within the supply chain infrastructure;

• Contractor's approach and capability to remediate newly reported zero-day vulnerabilities; and

• Contractor shall ensure all developers are trained and held accountable for development of secure code.

b. Unless otherwise approved by the USDA in writing, current or supported version of Contractor products and services shall not require the use of out-of-date, unsupported, or end-of-life version of third-party components (e.g., Java, Flash, Web browser, etc.).

c. Contractor shall verify and provide documentation that procured products (including third-party hardware, software, firmware, and services) have appropriate updates and patches installed prior to delivery to USDA.

d. In providing the products and services described in this Agreement Contractor shall provide appropriate software and firmware updates to remediate newly discovered vulnerabilities or weaknesses within [a negotiated time period]. Updates to remediate critical vulnerabilities shall be provided within a shorter period than other updates, within 14 days. If updates cannot be made available by [Contractor/Sub- Contractor] within these time periods, Contractor shall provide mitigations within a negotiated time period.

e. When third-party hardware, software (including open-source software), and firmware is provided by Contractor to USDA, Contractor shall provide appropriate hardware, software, and firmware updates to remediate newly discovered vulnerabilities or weaknesses within [a negotiated time period]. Updates to remediate critical vulnerabilities shall be provided within a shorter period than other updates, within 14 days. If these third-party updates cannot be made available by Contractor within these time periods, Contractor shall provide mitigations within a negotiated time period.

7.1.2.4.2 Viruses and Malware

Contractor will use reasonable efforts to investigate whether computer viruses or malware is present in any software or patches before providing such software or patches to USDA.

a. Contractor warrants that it has no knowledge of any computer viruses or malware coded or introduced into any software or patches, and Contractor will not insert any code which would have the effect of disabling or otherwise shutting down all or a portion of such software or damaging information or functionality.

b. When installed files, scripts, firmware, or other Contractor deliverer software solutions are flagged as malicious, infected, or suspicious by an anti-virus vendor through open-source solutions, Contractor must provide technical proof as to why the “false positive” hit has taken place to ensure their code’s supply chain has not been compromised.

c. If a virus or other malware is found to have been coded or otherwise introduced as a result of Contractor’s breach of its obligations under this Agreement, Contractor shall immediately and at its own cost:

• Take all necessary remedial action and provide assistance to USDA to eliminate the virus or other malware throughout USDA’s information networks, computer systems, and information systems, regardless of whether such systems or networks are operated by or on behalf of USDA;

and

• If the virus or other malware causes a loss of operational efficiency or any loss of data (A) where Contractor is obligated under this Agreement to back up such data, take all steps necessary and provide all assistance required by USDA and its affiliates, and (B) where Contractor is not obligated under this Agreement to back up such data, use commercially reasonable efforts, in each case to mitigate the loss of or damage to such data and to restore the efficiency of such data.

7.1.2.5 Transport/Shipping

7.2.5.1 Chain of Custody

Chain of Custody apply throughout the ICT SCRM SDLC phases; therefore, refer to Section 7.1.3.1 – Chain of Custody.

7.1.2.5.2 Anti-Tamper Testing/Inspection

Tamper Resistance and Detection apply throughout the ICT SCRM SDLC phases; therefore, refer to Section 7.1.3.2

– Anti-Tamper and Detection.

7.1.2.6 Pre-Deployment

7.1.2.6.1 Chain of Custody

Chain of Custody apply throughout the ICT SCRM SDLC phases; therefore, refer to Section 7.1.3.1 – Chain of Custody.

7.1.2.6.2 Anti-Tamper Testing/Inspection

Tamper Resistance and Detection apply throughout the ICT SCRM SDLC phases; therefore, refer to Section 7.1.3.2

– Anti-Tamper and Detection.

7.1.2.6.3 Scanning/Malicious code (Optical Media/SW/Scan Info Systems) Contractor will use reasonable efforts to investigate whether computer viruses or malware is present in any software or patches before providing such software or patches to USDA. Refer to Section 7.1.2.4.2 - Viruses and Malware.

7.1.2.7 Deployment

7.1.2.7.1 System Configuration

Contractor is responsible for system configuration (i.e. System hardening) and must be in compliance with the USDA C2 level of security (based on the NSA Trusted Computer Security Evaluation Criteria) for all USDA IT Systems. System hardening, or C2, as defined by the NSA, includes making specific modifications to an operating system before it is put into use in order to aid in the reduction of operating risks and to increase system availability, confidentiality and integrity. In addition Contractor will comply to DISA Security Technical Implementation Guide

(STIG).

7.1.3 ALL-INCLUSIVE AREAS WITHIN ICT SCRM SDLC

This section contains activities that apply throughout the ICT SCRM SDLC; therefore Contractor are to adhere to the all-inclusive areas without exception.

7.1.3.1 Chain of Custody

Contractor is responsible for the end-to-end visibility and sensor technology that enables 24-7 monitoring of cargo which includes who touched it at either end; whether the cargo has deviated from its designated route; or whether the container or package has been opened in route. Sensors provide information on cargo conditions such as shock detectors, temperature, humidity, etc. These types of asset visibility measures safeguard both the physical security and quality of the shipment.

7.1.3.2 Tamper Resistance and Detection

Contractor shall use a combination of hardware and software techniques for tamper resistance and detection. These techniques should include but not limited to obfuscation and self-checking to make reverse engineering and modifications more difficult, time-consuming, and expensive for adversaries. Strong identification combined with tamper resistance and/or tamper detection is essential to protecting information systems, components, and products during distribution and when in use.

7.1.3.3 Incidents

7.1.3.3.1 Vendor Identified Incidents

Whenever a security incident occurs, Contractor agrees to notify USDA within # by telephone and email, and subsequently via written correspondence or form.

7.1.3.3.2 Incident Response

Upon any cyber incident, Contractor will adhere to USDA DR 3505-005 - Cybersecurity Incident Management.

Within five (5) days of notifying USDA of the security incident, Contractor shall recommend actions to be taken by USDA on USDA-controlled systems to reduce the risk of a recurrence of the same or a similar security incident, including, as appropriate, the provision of action plans and mitigating controls. Contractor shall coordinate with USDA in developing those action plans and mitigating controls. Contractor will provide USDA guidance and recommendations for long term remediation of any cybersecurity risks posed to USDA information, equipment, systems, and networks as well as any information necessary to assist USDA in any recovery efforts undertaken by USDA in response to the security incident.

7.1.3.3.3 Development and Implementation of a Response Plan

Contractor shall develop and implement policies and procedures to address security incidents (“Response Plan”) by mitigating the harmful effects of security incidents and remedying the occurrence to prevent the recurrence of security incidents in the future.

Contractor shall provide USDA access to inspect its Response Plan. The development and implementation of the Response Plan shall follow best practices that at a minimum are consistent with the contingency planning requirements of the latest publication:

• NIST Special Publication 800-61 Rev. 2, Computer Security Incident Handling Guide

• NIST Special Publication 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations o CP-1 through CP-137 o IR-1 through IR-10

Immediately upon learning of a security incident related to the products and services provided to USDA, Contractor shall implement its Response Plan and within 24 hours of implementing its Response Plan, shall notify USDA.

7.1.3.3.4 Prevention of Recurrence:

Within five (5) days of a security incident, Contractor shall develop and execute a plan that reduces the likelihood of the same or a similar security incident from occurring in the future consistent with the requirements of its Response Plan and NIST Special Publication 800- 61rev2 and NIST Special Publication 800-184, Guide for Cybersecurity Event Recovery (as may be amended) and shall communicate that plan to USDA. Contractor shall provide recommendations to USDA on actions that USDA may take to assist in the prevention of recurrence, as applicable or appropriate.

7.1.3.3.5 Customer Notification (CN):

Contractor will, at its sole cost and expense, assist and cooperate with USDA with respect to any investigation of a security incident, critical and high vulnerabilities and product flaws, disclosures to affected parties, and other remedial measures as requested by USDA in connection with a security incident or required under any applicable laws related to a Security Incident.

In the event a Security Incident results in USDA information being disclosed such that notification is required to be made to any person or entity, including without limitation any customer, shareholder, or current or former employee of USDA under any applicable laws, including privacy and consumer protection laws, or pursuant to a request or directive from a governmental authority, such notification will be provided by USDA, except as required by applicable law or approved by USDA in writing. USDA will have sole control over the timing and method of providing such notification.

7.1.3.3.6 Information Security Incidents

An Information Security Incident is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access of any Contractor or Government systems or information, including, but not limited to, Sensitive Information.

Information Security Incident Reporting Requirements All Information Security Incidents must be reported in accordance with the requirements below, even if it is believed the Incident may be limited, small, or insignificant.

The Contractor must report all Information Security Incidents immediately, but not later than 30 minutes after becoming aware of the Incident.

Copy the Contracting Officer Representative (COR) if possible, or if Contracting Officer Representative (COR) email is not immediately available; contact the Contracting Officer Representative (COR) immediately after reporting the incident.

Do NOT include any Sensitive Information in the subject or body of any e-mail. To transmit Sensitive Information, use FIPS 140-2 compliant encryption methods to protect Sensitive Information in attachments to email. Passwords must not be communicated in the same email as the attachment.

Information Security Incident Response Requirements All determinations related to Information Security Incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) must be made by authorized USDA officials.

The Contractor must provide full access and cooperation for all activities (determined by the authorized Government official to be required) to ensure an effective Incident Response, including providing all requested images, log files, and event information to facilitate rapid resolution of Information Security Incidents.

Incident Response activities determined to be required may include but are not limited to: inspections, investigations, forensic reviews, data analyses & processing, and final determinations of responsibility for the Incident and/or liability for any additional Response activities.

USDA, at its sole discretion, may obtain the assistance of Federal agencies and/or third-party firms to aid in Incident Response activities.

7.1.3.4 Vulnerabilities

7.1.3.4.1 Disclosure and Remediation of Known Vulnerabilities by Vendor Contractor shall develop and implement policies and procedures to address the disclosure and remediation by Contractor of vulnerabilities and material defects related to the products and services provided to USDA under this Agreement including the following:

a) Prior to the delivery of the procured product or service, Contractor shall provide summary documentation of publicly disclosed vulnerabilities and material defects related in the procured product or services, the potential impact of such vulnerabilities and material defects, the status of Contractor’s efforts to mitigate those publicly disclosed vulnerabilities and material defects, and Contractor’s recommended corrective actions, compensating security controls, mitigations, and/or procedural workarounds.

b) Contractor shall provide summary documentation of vulnerabilities and material defects in the procured product or services within thirty (30) calendar days after such vulnerabilities and material defects become known to Contractor. This includes summary documentation on vulnerabilities that have not been publicly disclosed or have only been identified after the delivery of the product. The summary documentation shall include a description of each vulnerability and material defects and its potential impact, root cause, and recommended corrective actions, compensating security controls, mitigations, and/or procedural workarounds.

c) Contractor shall disclose the existence of all known methods for bypassing computer authentication in the procured product or services, often referred to as backdoors, and provide written documentation that all such backdoors created by Contractor have been permanently deleted or disabled.

d) Contractor shall implement a vulnerability detection and remediation program consistent with the latest publication of NIST Special Publication 800-53 RA-5,18 SA-11/19 and SI-2 (as may be amended).

7.1.3.5 USDA’s Audit Rights

USDA or its third-party designee may, but is not obligated to, perform audits and security tests of Contractor’s IT or systems environment and procedural controls to determine Contractor’s compliance with the system, network, data, and information security requirements of this Agreement. These audits and tests may include coordinated security tests, interviews of relevant personnel, review of documentation, and technical inspection of systems and networks as they relate to the receipt, maintenance, use, retention, and authorized destruction of USDA Information.

Contractor shall provide all information reasonably requested by USDA in connection with any such audits and shall provide reasonable access and assistance to USDA upon request. Contractor will comply, within reasonable timeframes at its own cost and expense, with all reasonable recommendations that result from such inspections, tests, and audits. USDA reserves the right to view, upon request, any original security reports that Contractor has undertaken or commissioned to assess [Contractor/Sub- Contractor]’s own network security. If requested, copies of these reports will be sent via bonded courier to USDA security contact. Contractor will notify USDA of any such security reports or similar assessments once they have been completed. Any regulators of USDA or its affiliates shall have the same rights of audit as described herein upon request.

Evidence of compliance or successful documented operational implementation can be in the form of inspection/audit results, or artifacts related to applicable Supply Chain or Information Security Management System certifications (e.g. O-TTPS/ISO 20243:2018), or internal SCRM program test/inspection results related to quality, security, or supplier management programs.

7.1.3.6 Covered Telecommunication Equipment or Services (Section 889(a)(1)(B)) In support of FAR Case 2019-009 on Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act (NDAA) commonly referred to as “Section 889 Part”:

If the contractor confirms that it identified prohibited telecom used during contract performance and an existing waiver does not apply, the CO shall submit a Supply Chain Event Report to the SCRM Review Board, including, at a minimum:

a) A “critical date”, no less than three business days, for when a response from the SCRM Review Board is requested. The CO may proceed to the next step(s) below if the SCRM Review Board has not responded by the “critical date”.

b) The information provided by the offeror under paragraph (d) of the reporting clause at FAR 52.204-25.

c) Be aware that the SCRM Review Board may ask for additional information.

7.1.3.6.1 Identified Prohibited Telecom

If the contractor confirms that it identified prohibited telecom used during contract performance and there is no applicable waiver, the CO will need to determine whether or not an exception applies, if the prohibited telecom is not a substantial or essential component of a system, or if the prohibited telecom is not critical technology as part of any system.

a) The SCRM Review Board will provide to the CO, via response to the Supply Chain Event Report, information as to whether it thinks that continued performance or extension of the contract (or order) will result in a violation of the prohibition. If the SCRM Review Board has not responded by the “critical date”, the CO may decide without the SCRM Review Board’s input.

b) Resources for assisting the CO in making this determination, based on previous guidance provided by GSA’s SCRM Review Board, will be available on the Acquisition Portal at http://insite.gsa.gov/scrm.

c) If, after using such resources, the CO cannot make this determination on their own, the CO should consult with their acquisition team, technical experts, their management, and request additional assistance from the SCRM Review Board by contacting SCRM-Review-Board@gsa.gov.

d) If the CO determines that continued performance or extension of the contract (or order) will not result in a violation of the prohibition, the CO should document the file accordingly and may continue performance of and/or extend the contract (or order).

7.1.3.6.2 Exceptions Clarification

The statute includes two exceptions at 889 (a)(2)(A) and (B). (1) The exception at 889(a)(2)(A) allows the head of executive agency to procure with an entity “to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements”. (2) The exception at 889(a)(2)(B) allows an entity to procure “telecommunications equipment that cannot route or redirect user data traffic or [cannot] permit visibility into any user data or packets that such equipment transmits or otherwise handles.” The exception allowing for procurement of services that connect to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements applies only to a Government agency that is contracting with an entity to provide a service. Therefore, the exception does not apply to a contractor’s use of a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements. As a result, the Federal Government is prohibited from contracting with a contractor that uses covered telecommunications equipment or services to obtain backhaul services from an internet service provider, unless a waiver is granted.

7.1.3.7 Environmental Risks

Without proper risk aversion strategies, the supply chains can be disrupted by environmental factors; therefore, all the environment-related legislation made by governments and other regulatory bodies should be followed.

Negative environmental impacts such as carbon emissions can be reduced; waste must be disposed of properly; and chemicals handled properly to protect the environment. To avoid the dangers of natural disasters, Contractor must choose their location and mode of transport strategically. They should be flexible and responsive enough to absorb changes and capable enough to avoid any distortions in the supply chain.

7.2 Section 508 Requirements

E201.1 Scope ICT that is procured, developed, maintained, or used by agencies shall conform to the Revised 508 Standards.

E205.1 General Electronic content shall comply with E205.

E205.2 Public Facing Electronic content that is public facing shall conform to the accessibility requirements specified in E205.4.

E205.3 Agency Official Communication Electronic content that is not public facing shall conform to the accessibility requirements specified in E205.4 when such content constitutes official business and is communicated by an agency through one or more of the following:

• A. An emergency notification;

• B. An initial or final decision adjudicating an administrative claim or proceeding;

• C. An internal or external program or policy announcement;

• D. A notice of benefits, program eligibility, employment opportunity, or personnel action;

• E. A formal acknowledgement of receipt;

• F. A survey questionnaire;

• G. A template or form;

• H. Educational or training materials; or

• I. Intranet content designed as a Web page.

E205.4 Accessibility Standard (WCAG 2.0) - Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (Incorporated by reference, see 702.10.1).

E206.1 General. Where components of ICT are hardware and transmit information or have a user interface, such components shall conform to the requirements in Chapter 4.

E207.1 General Where components of ICT are software and transmit information or have a user interface, such components shall conform to E207 and the requirements in Chapter 5

Exception from E207.1 General: Software that is assistive technology and that supports the accessibility services of the platform shall not be required to conform to the requirements in Chapter 5.

E207.2 WCAG Conformance User interface components, as well as the content of platforms and applications, shall conform to Level A and Level AA Success Criteria and Conformance…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .