15B11925Q00000005.pdf

PDF 120 KB Posted

Attached to
FCI Gilmer Passover 2025 Federal contract opportunity
Solicitation number
15B11925Q00000005
Issued by
Department of Justice Bureau of Prisons Federal Correctional Institution Gilmer

About this file

This is a Request for Quotation (RFQ) issued by the Federal Bureau of Prisons FCI Gilmer for Passover food items for 2025. The solicitation requires various kosher food products including Continental Breakfast with Tuna, Eggplant Parmesan, Sliced Salami, Plain Omelet, Cheese Omelet, various meat dishes (Boiled Chicken, Filet of Sole, Pot Roast, Roast Turkey), Passover Seder Box for 2, Matzo Wafers, Grape Juice, Macaroons, and other traditional Passover food items. Quantities range from 2 to 37 cases depending on the item.

The RFQ response is due by 8:00 a.m. ET on February 13, 2025. This is not a small business set-aside. Award will be made by line item to responsive/responsible vendors whose offers conform to the solicitation requirements and are most advantageous to the government, with past performance considered approximately equal to price. All deliveries must be FOB destination and completed prior to the start of Passover. Vendors must be registered in SAM.gov, and quotes must be submitted electronically to mxfrye@bop.gov. The solicitation includes extensive Department of Justice information security requirements for contractors who will handle DOJ information systems or data.

View the file

Other files for this federal contract opportunity

Other files attached to FCI Gilmer Passover 2025, newest first.
File Type Posted
15B11925Q00000005 00002.pdf PDF
Cover Letter Passover.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

15B11925Q00000005 Page 1 of 21

REQUEST FOR QUOTATION

(THIS IS NOT AN ORDER)

THIS RFQ IS IS NOT A SMALL BUSINESS SET-ASIDEX

PAGE OF PAGES

1 21

1. REQUEST NO.

15B11925Q00000005

2. DATE ISSUED

02/11/2025

3. REQUISITION/PURCHASE REQUEST NO.

15B11925PR000055

4. CERT. FOR NAT. DEF.

UNDER BDSA REG. 2 AND/

OR DMS REG. 1

RATING

Federal Bureau of Prisons FCI Gilmer

201 FCI LANE

Glenville, WV 26351

5a. ISSUED BY 6. DELIVER BY (Date)

7. DELIVERY

OTHER

(See Schedule)

FOB DESTINATION X

9. DESTINATION

5b. FOR INFORMATION CALL (NO COLLECT CALLS) a. NAME OF CONSIGNEE

NAME

Shannon Catron scatron@bop.gov

TELEPHONE NUMBER

AREA CODE NUMBER

Ext.:

8. TO:

b. STREET ADDRESS

c. CITY

a. NAME b. COMPANY

c. STREET ADDRESS

d. CITY e. STATE f. ZIP CODE d. STATE e. ZIP CODE

10. PLEASE FURNISH QUOTATIONS TO THE

ISSUING OFFICE IN BLOCK 5a ON OR BEFORE CLOSE OF BUSINESS (Date)

02/13/2025 08:00 ET

IMPORTANT: This is a request for information, and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it to the address in Block 5a. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or service. Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this Request for Quotation must be completed by the quoter.

11. SCHEDULE (Include applicable Federal, State and local taxes)

ITEM NO.

(a)

SUPPLIES/SERVICES

(b)

QUANTITY

(c)

UNIT

(d)

UNIT PRICE

(e)

AMOUNT

(f)

Passover 2025 Firm Fixed Price

See Continuation Sheet(s)

12. DISCOUNT FOR PROMPT PAYMENT

a. 10 CALENDAR DAYS (%)

0.00 %

b. 20 CALENDAR DAYS (%)

0.00 %

c. 30 CALENDAR DAYS (%)

0.00 %

d. CALENDAR DAYS

NUMBER

PERCENTAGE

0.00 NOTE: Additional provisions and representations [ ] are [ X ] are not attached.

13. NAME AND ADDRESS OF QUOTER 14. SIGNATURE OF PERSON AUTHORIZED TO SIGN

QUOTATION

15. DATE OF

QUOTATION

a. NAME OF QUOTER

b. STREET ADDRESS 16. SIGNER

a. NAME (Type or print) b. TELEPHONE

c. COUNTY AREA CODE

d. CITY e. STATE f. ZIP CODE c. TITLE (Type or print) NUMBER

AUTHORIZED FOR LOCAL REPRODUCTION

Previous edition not usable

STANDARD FORM 18 (REV. 6-95)

Prescribed by GSA-FAR (48 CFR) 53.215-1(a)

15B11925Q00000005 Page 2 of 21

Section 1 - Commodity or Services Schedule

SCHEDULE OF SUPPLIES/SERVICES

CONTINUATION SHEET

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 Continental Breakfast w/Tuna & PC Mayo

PSC: 8940

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0011 PC Margarine (Invd. Cups)

PSC: 8940

7 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0012 Eggplant Parmesan

PSC: 8945

22 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0015 Sliced Salami

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0016 PC Cream Cheese

PSC: 8945

6 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0017 plain omelet

PSC: 8940

12 EA $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0019 Boiled Chicken w/Potatoes & Garden Vegetables

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0020 Filet of Sole w/whipped potatoes & carrots

PSC: 8945

22 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0021 Pot Roast of Beef w/ Potatoes & seasoned Carrots

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0022 Roast Chicken w/Potato Pudding & Carrot Tzimmes

PSC: 8945

22 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0023 Roast Turkey w/sweet Potato & Seasoned Broccoli

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0024 Rib Eye Roast w/Potato Kugel & Carrot Tzimmes 12 CS $________ $_________________

15B11925Q00000005 Page 3 of 21

PSC: 8945

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0025 Passover Seder Box for 2

PSC: 8945

35 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0026 Cheese Omelet

PSC: 8940

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0027 PC Jelly

PSC: 8945

10 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0028 Cheese Blintzes

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0029 Gefilte Fish in Jelled Broth

PSC: 8945

37 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0030 Poached Salmon (bone-in) w/Potatoes & Carrots

PSC: 8945

14 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0031 Chicken Soup w/Chicken & Matzo Ball

PSC: 8945

28 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0032 Matzo Wafers

PSC: 8945

30 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0033 Salisbury Steak w/ whipped potatoes & eggplant creole

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0035 Wrapped nut cake / cupcake

PSC: 8945

8 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0036 Grape Juice Plastic Bottle

PSC: 8945

35 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0037 Wrapped Macaroons

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0039 Boiled Beef w/ Potatoes & Garden Veg

PSC: 8945

12 CS $________ $_________________

15B11925Q00000005 Page 4 of 21

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0041 Bone-in Roast Chicken with Potatoes

PSC: 8945

10 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0042 Wrapped Jelly Cookies

PSC: 8945

10 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0043 Brownie Cupcake

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0044 Beef Goulash w/ Broccoli souffle & Crinkle Cut Carrots

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0045 Tuna Pouch

PSC: 8945

34 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0046 Tea Bags Wrapped Individually

PSC: 8910

5 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0047 Sugar Substitute

PSC: 8945

2 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0048 Apple Juice Brick Pack

PSC: 8945

12 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0049 Apple Sauce

PSC: 8945

8 CS $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0050 Shipping

PSC: 8145

1 EA $________ $_________________

15B11925Q00000005 Page 5 of 21

Section 2 - Contract Clauses

Clauses By Reference

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov

Clause Title Fill-ins (if applicable)

52.204-27 Prohibition on a ByteDance Covered Application (Jun

2023)

DOJ-02 Contractor Privacy Requirements (JAN 2022)

Clauses By Full Text

52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial Products and Commercial Services (Jan 2025)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities (Dec 2023) (Section 1634 of Pub. L. 115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(Nov 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015).

(5) 52.232-40, Providing Accelerated Payments to Small Business Subcontractors (Mar 2023) (31 U.S.C. 3903 and 10 U.S.C. 3801).

(6) 52.233-3, Protest After Award (Aug 1996) (31 U.S.C. 3553).

(7) 52.233-4, Applicable Law for Breach of Contract Claim (Oct 2004)(Public Laws 108-77 and 108-78 (19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

15B11925Q00000005 Page 6 of 21

[Contracting Officer check as appropriate.]

__ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Jun 2020), with Alternate I (Nov 2021) (41 U.S.C. 4704 and 10 U.S.C. 4655).

__ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (Nov 2021) (41 U.S.C. 3509).

__ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (Jun 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)

__ (4) 52.203-17, Contractor Employee Whistleblower Rights (Nov 2023) (41 U.S.C. 4712); this clause does not apply to contracts of DoD, NASA, the Coast Guard, or applicable elements of the intelligence community--see FAR 3.900(a).

__ (5) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (Jun 2020) (Pub. L. 109-282) (31 U.S.C. 6101 note).

__ (6) [Reserved].

__ (7) 52.204-14, Service Contract Reporting Requirements (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).

__ (8) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).

X (9) 52.204-27, Prohibition on a ByteDance Covered Application (Jun 2023) (Section 102 of Division R of Pub. L.

117-328).

__ (10) 52.204-28, Federal Acquisition Supply Chain Security Act Orders-Federal Supply Schedules, Governmentwide Acquisition Contracts, and Multi-Agency Contracts. (Dec 2023) (Pub. L. 115-390, title II).

__ (11)(i) 52.204-30, Federal Acquisition Supply Chain Security Act Orders-Prohibition. (Dec 2023) (Pub. L. 115-390, title

II).

__ (ii) Alternate I (Dec 2023) of 52.204-30.

__ (12) 52.209-6, Protecting the Government's Interest When Subcontracting with Contractors Debarred, Suspended, Proposed for Debarment, or Voluntarily Excluded. (Jan 2025) (31 U.S.C. 6101 note).

__ (13) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Oct 2018) (41 U.S.C.

2313).

__ (14) [Reserved].

__ (15) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Oct 2022) (15 U.S.C. 657a).

__ (16) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Oct 2022) (if the offeror elects to waive the preference, it shall so indicate in its offer) (15 U.S.C. 657a).

__ (17) [Reserved]

X (18)(i) 52.219-6, Notice of Total Small Business Set-Aside (Nov 2020) (15 U.S.C. 644).

__ (ii) Alternate I (Mar 2020) of 52.219-6.

__ (19)(i) 52.219-7, Notice of Partial Small Business Set-Aside (Nov 2020) (15 U.S.C. 644).

__ (ii) Alternate I (Mar 2020) of 52.219-7.

__ (20) 52.219-8, Utilization of Small Business Concerns (Feb 2024) (15 U.S.C. 637(d)(2) and (3)).

15B11925Q00000005 Page 7 of 21

__ (21)(i) 52.219-9, Small Business Subcontracting Plan (Jan 2025) (15 U.S.C. 637(d)(4)).

__ (ii) Alternate I (Nov 2016) of 52.219-9.

__ (iii) Alternate II (Nov 2016) of 52.219-9.

__ (iv) Alternate III (Jun 2020) of 52.219-9.

__ (v) Alternate IV (Jan 2025) of 52.219-9.

__ (22)(i) 52.219-13, Notice of Set-Aside of Orders (Mar 2020) (15 U.S.C. 644(r)).

__ (ii) Alternate I (Mar 2020) of 52.219-13.

__ (23) 52.219-14, Limitations on Subcontracting (Oct 2022) (15 U.S.C. 657s).

__ (24) 52.219-16, Liquidated Damages-Subcontracting Plan (Sep 2021) (15 U.S.C. 637(d)(4)(F)(i)).

__ (25) 52.219-27, Notice of Set-Aside for, or Sole-Source Award to, Service-Disabled Veteran-Owned Small Business (SDVOSB) Concerns Eligible Under the SDVOSB Program (Feb 2024) (15 U.S.C. 657f).

X (26)(i) 52.219-28, Postaward Small Business Program Rerepresentation (Jan 2025) (15 U.S.C. 632(a)(2)).

__ (ii) Alternate I (Mar 2020) of 52.219-28.

__ (27) 52.219-29, Notice of Set-Aside for, or Sole-Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (Oct 2022) (15 U.S.C. 637(m)).

__ (28) 52.219-30, Notice of Set-Aside for, or Sole-Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (Oct 2022) (15 U.S.C. 637(m)).

__ (29) 52.219-32, Orders Issued Directly Under Small Business Reserves (Mar 2020) (15 U.S.C. 644(r)).

__ (30) 52.219-33, Nonmanufacturer Rule (Sep 2021) (15 U.S.C. 637(a)(17)).

X (31) 52.222-3, Convict Labor (Jun 2003) (E.O. 11755).

X (32) 52.222-19, Child Labor-Cooperation with Authorities and Remedies (Jan 2025) (E.O. 13126).

X (33) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).

__ (34)(i) 52.222-26, Equal Opportunity (Sep 2016) (E.O. 11246).

__ (ii) Alternate I (Feb 1999) of 52.222-26.

__ (35)(i) 52.222-35, Equal Opportunity for Veterans (Jun 2020) (38 U.S.C. 4212).

__ (ii) Alternate I (Jul 2014) of 52.222-35.

__ (36)(i) 52.222-36, Equal Opportunity for Workers with Disabilities (Jun 2020) (29 U.S.C. 793).

__ (ii) Alternate I (Jul 2014) of 52.222-36.

__ (37) 52.222-37, Employment Reports on Veterans (Jun 2020) (38 U.S.C. 4212).

__ (38) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496).

__ (39)(i) 52.222-50, Combating Trafficking in Persons (Nov 2021) (22 U.S.C. chapter 78 and E.O. 13627).

__ (ii) Alternate I (Mar 2015) of 52.222-50 (22 U.S.C. chapter 78 and E.O. 13627).

15B11925Q00000005 Page 8 of 21

__ (40) 52.222-54, Employment Eligibility Verification (Jan 2025) (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial products or commercial services as prescribed in FAR 22.1803.)

__ (41)(i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA-Designated Items (May 2008) (42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

__ (ii) Alternate I (May 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

__ (42) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (May 2024) (42 U.S.C. 7671, et seq.).

__ (43) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (May 2024) (42 U.S.C. 7671, et seq.).

__ (44) 52.223-20, Aerosols (May 2024) (42 U.S.C. 7671, et seq.).

__ (45) 52.223-21, Foams (May 2024) (42 U.S.C. 7671, et seq.).

__ (46) 52.223-23, Sustainable Products and Services (May 2024) (E.O. 14057, 7 U.S.C. 8102, 42 U.S.C. 6962, 42 U.S.C. 8259b, and 42 U.S.C. 7671l).

__ (47)(i) 52.224-3, Privacy Training (Jan 2017) (5 U.S.C. 552a).

__ (ii) Alternate I (Jan 2017) of 52.224-3.

X (48)(i) 52.225-1, Buy American--Supplies (Oct 2022) (41 U.S.C. chapter 83).

__ (ii) Alternate I (Oct 2022) of 52.225-1.

__ (49)(i) 52.225-3, Buy American-Free Trade Agreements-Israeli Trade Act (Nov 2023) (19 U.S.C. 3301 note, 19 U.S.C.

2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, 19 U.S.C. chapter 29 (sections 4501-4732), Public Law 103-182, 108-77, 108-78, 108-286, 108-302, 109-53, 109-169, 109-283, 110-138, 112-41, 112-42, and 112-43.

__ (ii) Alternate I [Reserved].

__ (iii) Alternate II (Jan 2025) of 52.225-3.

__ (iv) Alternate III (Feb 2024) of 52.225-3.

__ (v) Alternate IV (Oct 2022) of 52.225-3.

__ (50) 52.225-5, Trade Agreements (Nov 2023) (19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note).

__ (51) 52.225-13, Restrictions on Certain Foreign Purchases (Feb 2021) (E.O.'s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).

__ (52) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. Subtitle A, Part V, Subpart G Note).

__ (53) 52.226-4, Notice of Disaster or Emergency Area Set-Aside (Nov 2007) (42 U.S.C. 5150).

__ (54) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (Nov 2007) (42 U.S.C. 5150).

__ (55) 52.226-8, Encouraging Contractor Policies to Ban Text Messaging While Driving (May 2024) (E.O. 13513).

__ (56) 52.229-12, Tax on Certain Foreign Procurements (Feb 2021).

15B11925Q00000005 Page 9 of 21

__ (57) 52.232-29, Terms for Financing of Purchases of Commercial Products and Commercial Services (Nov 2021) (41 U.S.C. 4505, 10 U.S.C. 3805).

__ (58) 52.232-30, Installment Payments for Commercial Products and Commercial Services (Nov 2021) (41 U.S.C. 4505, 10 U.S.C. 3805).

__ (59) 52.232-33, Payment by Electronic Funds Transfer--System for Award Management (Oct 2018) (31 U.S.C. 3332).

__ (60) 52.232-34, Payment by Electronic Funds Transfer--Other than System for Award Management (Jul 2013) (31 U.S.C. 3332).

__ (61) 52.232-36, Payment by Third Party (May 2014) (31 U.S.C. 3332).

X (62) 52.239-1, Privacy or Security Safeguards (Aug 1996) (5 U.S.C. 552a).

__ (63) 52.240-1, Prohibition on Unmanned Aircraft Systems Manufactured or Assembled by American Security Drone Act-Covered Foreign Entities (Nov 2024) (Sections 1821-1826, Pub. L. 118-31, 41 U.S.C. 3901 note prec.).

__ (64) 52.242-5, Payments to Small Business Subcontractors (Jan 2017)(15 U.S.C. 637(d)(13)).

__ (65)(i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (Nov 2021) (46 U.S.C. 55305 and 10 U.S.C. 2631).

__ (ii) Alternate I (Apr 2003) of 52.247-64.

__ (iii) Alternate II (Nov 2021) of 52.247-64.

(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

[Contracting Officer check as appropriate.]

__ (1) 52.222-41, Service Contract Labor Standards (Aug 2018) (41 U.S.C. chapter 67).

__ (2) 52.222-42, Statement of Equivalent Rates for Federal Hires (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).

__ (3) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (Multiple Year and Option Contracts) (Aug 2018) (29 U.S.C. 206 and 41 U.S.C. chapter 67).

__ (4) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards--Price Adjustment (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).

__ (5) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment--Requirements (May 2014) (41 U.S.C. chapter 67).

__ (6) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-- Requirements (May 2014) (41 U.S.C. chapter 67).

__ (7) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026 (Jan 2022).

__ (8) 52.222-62, Paid Sick Leave Under Executive Order 13706 (Jan 2022) (E.O. 13706).

__ (9) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (Jun 2020) (42 U.S.C. 1792).

__ (10) 52.247-69, Reporting Requirement for U.S.-Flag Air Carriers Regarding Training to Prevent Human Trafficking (Jan 2025) (49 U.S.C. 40118(g)).

15B11925Q00000005 Page 10 of 21

(d) Comptroller General Examination of Record. The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, as defined in FAR 2.101, on the date of award of this contract and does not contain the clause at 52.215-2, Audit and Records-- Negotiation.

(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor's directly pertinent records involving transactions related to this contract.

(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.

(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.

(e)(1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c), and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial products or commercial services. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause--

(i) 52.203-13, Contractor Code of Business Ethics and Conduct (Nov 2021) (41 U.S.C. 3509).

(ii) 52.203-17, Contractor Employee Whistleblower Rights (Nov 2023) (41 U.S.C. 4712).

(iii) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(iv) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities (Dec 2023) (Section 1634 of Pub. L. 115-91).

(v) 52.204–25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(Nov 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(vi) 52.204-27, Prohibition on a ByteDance Covered Application (Jun 2023) (Section 102 of Division R of Pub. L.

117-328).

(vii)(A) 52.204-30, Federal Acquisition Supply Chain Security Act Orders-Prohibition. (Dec 2023) (Pub. L. 115-390, title II).

(B) Alternate I (Dec 2023) of 52.204-30.

(viii) 52.219-8, Utilization of Small Business Concerns (Jan 2025) (15 U.S.C. 637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds the applicable threshold specified in FAR 19.702(a) on the date of subcontract award, the subcontractor must include 52.219-8 in lower tier subcontracts that offer subcontracting opportunities.

(ix) 52.222-21, Prohibition of Segregated Facilities (Apr 2015)

(x) 52.222-26, Equal Opportunity (Sept 2016) (E.O. 11246).

(xi) 52.222-35, Equal Opportunity for Veterans (Jun 2020) (38 U.S.C. 4212).

(xii) 52.222-36, Equal Opportunity for Workers with Disabilities (Jun 2020) (29 U.S.C. 793).

(xiii) 52.222-37, Employment Reports on Veterans (Jun 2020) (38 U.S.C. 4212)

15B11925Q00000005 Page 11 of 21

(xiv) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.

(xv) 52.222-41, Service Contract Labor Standards (Aug 2018) (41 U.S.C. chapter 67).

(xvi) (A) 52.222-50, Combating Trafficking in Persons (Nov 2021) (22 U.S.C. chapter 78 and E.O 13627).

(B) Alternate I (Mar 2015) of 52.222-50 (22 U.S.C. chapter 78 and E.O 13627).

(xvii) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment-Requirements (May 2014) (41 U.S.C. chapter 67).

(xviii) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services- Requirements (May 2014) (41 U.S.C. chapter 67).

(xix) 52.222-54, Employment Eligibility Verification (Jan 2025) (E.O. 12989).

(xx) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026 (Jan 2022).

(xxi) 52.222-62, Paid Sick Leave Under Executive Order 13706 (Jan 2022) (E.O. 13706).

(xxii)(A) 52.224-3, Privacy Training (Jan 2017) (5 U.S.C. 552a).

(B) Alternate I (Jan 2017) of 52.224-3.

(xxiii) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. Subtitle A, Part V, Subpart G Note).

(xxiv) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (Jun 2020) (42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.

(xxv) 52.232-40, Providing Accelerated Payments to Small Business Subcontractors (Mar 2023) (31 U.S.C. 3903 and 10 U.S.C. 3801). Flow down required in accordance with paragraph (c) of 52.232-40.

(xxvi) 52.240-1, Prohibition on Unmanned Aircraft Systems Manufactured or Assembled by American Security Drone Act- Covered Foreign Entities (Nov 2024) (Sections 1821-1826, Pub. L. 118-31, 41 U.S.C. 3901 note prec.).

(xxvii) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (Nov 2021) (46 U.S.C. 55305 and 10 U.S.C. 2631). Flow down required in accordance with paragraph (d) of FAR clause 52.247-64.

(2) While not required, the Contractor may include in its subcontracts for commercial products and commercial services a minimal number of additional clauses necessary to satisfy its contractual obligations.

(End of clause)

DOJ-05 Security of Department Information and Systems DOJ-05 (OCT 2023)

I. Applicability to Contractors and Subcontractors Section 2839.102 of the Justice Acquisition Regulation (JAR), (48 C.F.R. § 2839.102), applies to this contract. Accordingly, all contractors are obligated to comply with all applicable DOJ security policies, directives, or guidance documents, including the security requirements in the provisions in this contract clause. This contract clause applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of the contractors and subcontractors (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information. The security requirements set forth herein are in addition to those required by the Federal Acquisition Regulation (“FAR”), and any other applicable laws, mandates, contract clauses, DOJ policies, directives or guidance documents and Executive Orders pertaining to the development and operation of Information Systems and/or the

15B11925Q00000005 Page 12 of 21 protection of Government Information. This clause does not alter or diminish any existing rights, obligations, or liability under any other civil and/or criminal law, rule, regulation, or mandate.

II. General Definitions The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.

A. Authorization to Operate (“ATO”), as defined in National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-37 Revision 2, is the official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls.

B. Cloud Computing, as defined in DOJ Order 0904 Cybersecurity Program, is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics, three service models, and four deployment models in accordance with NIST SP 800-145.

C. Covered Contract is any contract, order or other agreement under which the contractor, or a subcontractor at any tier, including a cloud service provider, may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information (as defined below) in the course of providing a product or service to the Department, with the exception of acquisitions under the micro-purchase threshold.

D. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information under a Covered Contract.

E. Data means recorded information, regardless of form or the media on which it may be recorded. The term includes technical data, computer software, and personally identifiable information (PII) (defined below). The term does not include information incidental to contract administration, such as financial, administrative, cost or pricing, or management information.

F. DOJ Information, as defined in DOJ Order 0904, means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by the Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired to perform the contract.

G. Information, as defined in DOJ Order 0904, is any communication or representation of knowledge such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. This includes any communication or representation of knowledge in an electronic format that allows it to be stored, retrieved, or transmitted.

H. Information System, means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502(8)).

I. Personally Identifiable Information (“PII”), as defined in the FAR 24.101, means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. It includes but is not limited to common data elements such as names, addresses, dates of birth, and places of employment, to identity documents, Social Security numbers or other government-issued identifiers, precise location information, medical history, and biometric records.

This definition covers all PII that is created by or becomes available to the contractor, including its employees, subcontractors, or affiliates, as a result of performing under this contract. PII, as supplementally defined in DOJ Order 0904, also includes information about an individual maintained by an agency, including, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and information, which can be used to distinguish or trace an individual’s identity.

J. Private Cloud, as defined in NIST SP 800-145, is the deployment model for cloud infrastructure provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off premises.

15B11925Q00000005 Page 13 of 21

K. Security Breach means any security incident (as defined below) that directly relates to the loss of control, compromise, exfiltration, manipulation, unauthorized disclosure, unauthorized acquisition, unauthorized exposure or unauthorized access or any similar occurrence of any Covered Information System or any DOJ Information or any PII accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system. This includes incidents where (1) a person other than an authorized user accesses or potentially accesses PII or DOJ Information or (2) an authorized user accesses or potentially accesses PII or DOJ Information for an unauthorized purpose.

a. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed security breach (as defined above).

b. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed security breach (as defined above).

L. Security Incident means any occurrence that (1) may actually or imminently jeopardize, without lawful authority, the availability, integrity, authentication, confidentiality, or nonrepudiation of DOJ Information or a Covered Information System; or (2) may constitute a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

a. Potential Security Incident means any suspected, but unconfirmed security incident (as defined above).

b. Confirmed Security Incident means any confirmed security incident (as defined above).

M. Vulnerability, as defined in DOJ Vulnerability Management Plan, and the OCIO Information Security Management Procedure, means a weakness or flaw discovered in the design of a system that, when exploited, may result in a loss of confidentially, integrity, or availability of DOJ Information or an Information System.

III. Confidentiality and Non-Disclosure of DOJ Information A. Preliminary and final contract deliverables and all associated working papers and material generated by the Contractor developed using DOJ Information, product, source code, and/or methods of operations, are the property of the U.S. Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Representative (“COR”) at the conclusion of the contract. The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14 (Rights in Data-General). The Contractor will define a method of monitoring the development activity to include any activity associated with DOJ Information, product, source code, and methods of operations. The data rights and development details shall be defined within the Contract.

If the Contractor intends to utilize its existing data, for which it has a patent or copyright, to develop a contract deliverable, it is incumbent upon the Contractor to negotiate with the CO the proper FAR Part 27 clauses in the contract to protect its existing data.

B. Pursuant to FAR 52.227-14(d)(2), all documents and data produced in the performance of this contract containing DOJ Information, product code, source code, and/or methods of operations are the property of the U.S. Government and, without the prior written permission of the CO, the Contractor shall neither reproduce nor release such information to any third-party at any time, including during performance or following expiration and/ or termination of the contract.

C. Any DOJ Information made available to the Contractor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, the Contractor assumes responsibility for the protection of the confidentiality of all DOJ Information processed, stored, or transmitted by the Contractor. The Contractor shall comply with information security responsibilities and duties throughout the contract and after expiration/termination as appropriate per contract close-out activities. When requested by the CO (typically no more than annually), the Contractor shall provide a report to the CO identifying, to the best of the Contractor’s knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed, stored, or transmitted under the Contract, including an estimate of the number of individuals for whom PII has been processed, stored or transmitted under the Contract and whether such information includes social security numbers (in whole or in part).

15B11925Q00000005 Page 14 of 21

IV. Compliance with Information Technology Security Policies, Procedures and Requirements A. For all Covered Information Systems, in addition to any other applicable requirements, as set forth in Part I, the Contractor shall comply with the security requirements of the Federal Information Security Modernization Act of 2014 (“FISMA”), Privacy Act of 1974, E-Government Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, 199, and 200, Federal Risk and Authorization Management Program (“FedRAMP”), DOJ IT Security Standards as amended, and OMB Memoranda relating to the security of information and/or Federal Information Systems.

B. In addition, for all Covered Information Systems, the Contractor shall comply with the following requirements, which are listed here only to highlight certain specific applicable requirements from one of the sources identified in the first paragraph of this Section. This is not an exhaustive list of all such requirements with which the Contractor is obligated to comply, and the omission of a requirement from this list should not be construed as negating the materiality of that requirement. These requirements and those in the authorities in the prior paragraph should be read together.

1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise.

2. Providing security awareness training at least annually to all Contractor employees and contractors involved with the Covered Contract. Such training shall include, but not be limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information Systems.

3. Creating, protecting, and retaining, in accordance with applicable requirements but in any event at least until the expiration of the contract, Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information.

4. Maintaining authorizations to operate any Covered Information System.

5. Performing continuous monitoring on all Covered Information Systems, to include but not be limited to, collecting, reviewing, and analyzing appropriate logs and timely investigating security alerts and potential security incidents.

6. Establishing and maintaining baseline configurations and current inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Covered Information Systems.

7. Ensuring appropriate contingency planning has been performed, including DOJ Information and Covered Information System backups.

8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication methods as defined by NIST 800-63-3, Digital Identity Guidelines or current revision.

9. Establishing and maintaining an operational incident handling capability for Covered Information Systems that includes adequate and timely development, logging, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and timely reporting incidents to appropriate officials and authorities within the Contractor’s organization and the DOJ.

10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms, and personnel used to conduct such maintenance.

15B11925Q00000005 Page 15 of 21

11. Protecting Covered Information System media containing DOJ Information, including paper, digital and electronic media, and DOJ assets under Contractor control; protecting them from environmental impacts, access, and equipment positioning requirements defined; limiting access to DOJ Information to authorized users; and sanitizing or destroying Covered Information System media containing DOJ Information before disposal, release or reuse of such media.

12. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Information Systems to authorized personnel according to DOJ 03.

13. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with DOJ Security standards including personnel background checks.

14. Continuously assessing the risk to DOJ Information in Covered Information Systems, including scanning and remediating vulnerabilities, or implementing appropriate mitigation in accordance with DOJ policy, and ensuring the timely removal of assets no longer supported by the Contractor.

15. Continuously monitoring the application of security controls of Covered Information Systems, assessing the efficacy of such controls, and developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in such Covered Information Systems.

16. Monitoring, controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Covered Information Systems, and employing architectural designs, software development techniques, and systems engineering principles that promote effective security.

17. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection from malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate and timely action in response.

18. Ensuring return of Government Furnished Equipment (“GFE”) and/or PIV card assets within 10 business days of notification for end of use (contract end, staff change, etc.).

19. Complying with rights in data (FAR 52.227-14) as to the development, management, and protection of DOJ Information.

20. Reporting on risks or known issues impacting DOJ Services (staffing, hardware, process, changes, etc.) through the Contractor’s CO or COR, DOJ Service Owner (“SO”), and Government Technical Manager (“GTM”) including risk mitigation activities.

21. Reporting through the Contractor’s CO or COR on any projected or planned changes in corporate ownership, covered information system design, and/or any technical changes that could impact the confidentiality, integrity or availability of DOJ Information, data, or systems. Changes to system design must be updated through the authorization process per NIST SP 800-37 Revision 2, Step 6 (‘Continuous Monitoring”) or current NIST revision.

22. When, as part of operating within the DOJ environment, the Contractor’s covered information system is subject to review, audit, or assessment by third parties, facilitating DOJ access to information system resources, facilities, personnel, and documentation in a timely manner as required by the auditors. Should a third-party organization conduct a review of any Covered Information System, the Contractor must provide a copy of the report to DOJ, through the CO and COR.

23. Completing an attestation that meets OMB Memorandum M-22-18 for software procurements following the template attestation form developed by NIST. The attestation form must be returned to the CO and COR for sharing with the component Chief Information Officer (CIO).

24. Reporting on outages impacting DOJ Services through the Contractor’s CO, COR, and DOJ Service Owner (SO) to include event and mitigation details.

C. The Contractor shall not process, store, or transmit DOJ Information using a Covered Information System without first obtaining an ATO for each Covered Information System. The ATO shall be signed by the Authorizing

15B11925Q00000005 Page 16 of 21

Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under this contract. (For Cloud Computing Systems, see Section V, below.)

D. The Contractor shall ensure compliance with DOJ-03 (Personnel Security Requirements for Contractor Employees) as to all Covered Information Systems.

E. When requested by the DOJ CO or COR as described below, the Contractor shall provide DOJ, including the Office of Inspector General (“OIG”) and Federal law enforcement components, (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and

(2) physical access to the Contractor’s facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by DOJ or agents acting on behalf of DOJ, and such access shall be provided within 72 hours of the request. Additionally, the Contractor shall cooperate with DOJ’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of DOJ Information.

F. The use of Contractor-owned laptops or other portable digital or electronic media to process or store DOJ Information covered by this clause or access a Covered Information System is prohibited unless the CO approves it in writing after the Contractor has provided a letter certifying compliance with the following requirements. For any requirements which include the use or storage of PII, the Senior Component Official for Privacy must also approve. Any additional requirements set forth for the use or storage of PII under DOJ-02, Contractor Privacy Requirements, are in addition to, not superseded by, the requirements set forth here.

1. Media must be encrypted using a NIST FIPS 140-2 approved product.

2. The Contractor must develop and implement a process to ensure that security and other applications software is kept up to date.

3. Where applicable, media must utilize antivirus software and a host-based firewall mechanism.

4. The Contractor must log all computer-readable data extracts from databases holding DOJ Information and verify that each extract including such data has been erased within 90 days of extraction or that its use is still required. All DOJ Information should be treated by the Contractor as sensitive information unless specifically designated as non-sensitive by the DOJ.

5. A Rules of Behavior (ROB) form must be signed and acknowledged annually by users. These rules must address, at a minimum, authorized, and official use, prohibition against unauthorized users and use, and the protection of DOJ Information. The form also must notify the users that they have no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contractor-owned laptops or other portable digital or electronic media.

6. Cybersecurity Awareness Training (CSAT) shall be provided annually by Contractor for all users of Covered Information System. This training must be submitted to, and approved by, the CO or COR in advance of being provided to users. Users must complete and acknowledge having received CSAT each year. At a minimum, CSAT provided by contractors must include:

a. Insider Threat Detection and Reporting – Importance of detecting, methodologies, indicators, and reporting

b. Privacy Awareness – Privacy Act and PII

c. General Cybersecurity – Information security, trends in advance persistent threats, social engineering/phishing, appropriate use, mobile devices, remote access, basic security best practices

G. Contractors shall not store DOJ information on Contractor-owned removable IT (e.g., media such as a thumb drive or external hard drive) unless expressly authorized in writing by the DOJ CO or COR in the performance of their contract.

H. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with NIST SP 900-88, Guidelines for Media Sanitization.

I. The Contractor must keep an accurate inventory of digital or electronic media used in the performance of DOJ contracts.

1…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .