AMEND 0007 COL.pdf

PDF 621 KB Posted

Attached to
Fire Alarm Replacement at FCC Coleman Federal contract opportunity
Solicitation number
15B30221B00000001
Issued by
Department of Justice Bureau of Prisons Field Acquisition Office

About this file

This document contains a federal government solicitation and related opportunity for a construction contract. The Federal Bureau of Prisons is seeking to award a firm-fixed-price contract for a project to replace the fire alarm system at the Federal Correctional Complex in Coleman, Florida. The project scope involves removing the existing system and installing a new fire alarm system. The performance period is 365 calendar days from the notice to proceed. The NAICS code is 238210 with a small business size standard of $16.5 million. The estimated value of the project is between $1 million to $5 million. The solicitation will be distributed solely through the Contract Opportunities website and requires an active SAM registration and MPIN to access secure documents. All future information will also be distributed through this website. Interested parties must continuously monitor the site for amendments. To qualify for award, firms must meet the small business size standard in their SAM registration. This is a 100 percent small business set-aside.

View the file

Other files for this federal contract opportunity

Other files attached to Fire Alarm Replacement at FCC Coleman, newest first.
File Type Posted
Bid Abstract.pdf PDF
4 - Drawings REV F-001.pdf PDF
5 - Construction Wage Rate 9242021.pdf PDF
AMEND 0006 COL.pdf PDF
AMEND 0005 COL.pdf PDF
AMEND 0004 COL.pdf PDF
Site Visit Meeting Minutes.pdf PDF
5 - Construction Wage Rate 7092021.pdf PDF
Questions and Answers FCC Coleman.pdf PDF
AMEND 0003 COL.pdf PDF
AMEND 0002 COL.pdf PDF
AMEND 0001 COL.pdf PDF
4 - Drawings.pdf PDF
3 - Specification.pdf PDF
1 - Instructions to Bidders.pdf PDF
7 - Criminal History Check Form.pdf PDF
6 - SF24 Bid Bond.pdf PDF
5 - Construction Wage Rate.pdf PDF
2 - Solicitation.pdf PDF
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT 1. CONTRACT ID CODE PAGE OF PAGES

2. AMENDMENT/MODIFICATION NO. 3. EFFECTIVE DATE 4. REQUISITION/PURCHASE REQ. NO. 5. PROJECT NO. (If applicable)

6. ISSUED BY CODE 7. ADMINISTERED BY (If other than Item 6) CODE

8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code) 9A. AMENDMENT OF SOLICITATION NO.

9B. DATED (SEE ITEM 11)

10A. MODIFICATION OF CONTRACT/ORDER NO.

10B. DATED (SEE ITEM 13)

CODE FACILITY CODE

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

The above numbered solicitation is amended as set forth in Item 14. The hour a nd date specified for receipt of Offers is extended, is not extended.

Offers must acknowledge receipt of this amendment prior to the hour and date sp ecified in the solicitation or as amended, by one of the following methods:

(a) By completing Items 8 and 15, and returning copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or

(c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

12. ACCOUNTING AND APPROPRIATION DATA (If required)

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

D. OTHER (Specify type of modification and authority)

E. IMPORTANT:

Contractor is not, is required to sign this document and return copies to the issuing office.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force a nd effect.

15A. NAME AND TITLE OF SIGNER (Type or print) 16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)

15B. CONTRACTOR/OFFEROR

(Signature of person authorized to sign)

15C. DATE SIGNED 16B. UNITED STATES OF AMERICA

BY

(Signature of Contracting Officer)

16C. DATE SIGNED

PREVIOUS EDITION UNUSABLE

STANDARD FORM 30 (Rev. 10-83) Prescribed by GSA

FAR (48 CFR) 53.243

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

This form was electronically produced by Elite Federal Forms, Inc.

( ) A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER

NO. IN ITEM 10A.

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.)

SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

1 2

00007 10/06/2021 0309-21 3D4V

FAO

Federal Bureau of Prisons US Armed Forces Reserve Complex/FAO 346 Marine forces Drive Grand Prairie, TX 75051

FAO

Federal Bureau of Prisons US Armed Forces Reserve Complex/FAO 346 Marine forces Drive Grand Prairie, TX 75051

15B30221B00000001

6/30/2021

FAO

See Block 14 Continuation Sheet(s)

Martin Guidry

15B30221B00000001 /00007

FIRE ALARM REPLACEMENT

FCC COLEMAN

The following changes are made to the Solicitation:

A. INCORPORATE CLAUSES

1) Solicitation Section 4:

APN-2021-06 – Whistleblower Information Distribution (OCT 2021) Within 30 days of contract award, the contractor and its subcontractors must distribute the “Whistleblower Information for Employees of DOJ Contractors, Subcontractors, Grantees, or Sub-Grantees or Personal Services Contractors” (“Whistleblower Information”) document to their employees performing work in support of the products and services delivered under this contract (https://oig.justice.gov/sites/default/files/2020-04/NDAA-brochure.pdf). By agreeing to the terms and conditions of this contract, the prime contractor acknowledges receipt of this requirement, in accordance with 41 U.S.C. § 4712 and FAR 3.908 & 52.203-17, and commits to distribution. Within 45 days of award, the contractor must provide confirmation to the contracting officer verifying that it has distributed the whistleblower information as required.

2) 52.223-99 Ensuring Adequate COVID-19 Safety Protocols for Federal Contractors (OCT 2021) (Deviation)

(a) Definition. As used in this clause – United States or its outlying areas means—

(1) The fifty States;

(2) The District of Columbia;

(3) The commonwealths of Puerto Rico and the Northern Mariana Islands;

(4) The territories of American Samoa, Guam, and the United States Virgin Islands; and

(5) The minor outlying islands of Baker Island, Howland Island, Jarvis Island, Johnston Atoll, Kingman Reef, Midway Islands, Navassa Island, Palmyra Atoll, and Wake Atoll.

(b) Authority. This clause implements Executive Order 14042, Ensuring Adequate COVID Safety Protocols for Federal Contractors, dated September 9, 2021 (published in the Federal Register on September 14, 2021, 86 FR 50985).

(c) Compliance. The Contractor shall comply with all guidance, including guidance conveyed through Frequently Asked Questions, as amended during the performance of this contract, for contractor or subcontractor workplace locations published by the Safer Federal Workforce Task Force (Task Force Guidance) at https:/www.saferfederalworkforce.gov/contractors/.

(d) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (d), in subcontracts at any tier that exceed the simplified acquisition threshold, as defined in Federal Acquisition Regulation 2.101 on the date of subcontract award, and are for services, including construction, performed in whole or in part within the United States or its outlying areas.

(End of clause)

Solicitation Section 5 - Attachments Identifier 6&7:

Attachment 1: Executive Order 14042 Definitions of Terms (see attachment) Attachment 2: FAQs on Vaccination and Safety Protocols (see attachment)

3) APN2021-07 – Contractor Privacy Requirements (NOV 2021) (see attachment)

B. BID OPENING DUE DATE EXTENDED TO WEDNESDAY, 10/20/2021 2:00 PM CST.

NO OTHER CHANGES ARE MADE AT THIS TIME.

Acquisition Policy Notice 2021-07

CONTRACTOR PRIVACY REQUIREMENTS (NOV 2021)

A. Limiting Access to Privacy Act and Other Sensitive Information

(1) Privacy Act Information

In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.1 Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.

(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment

The Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or Workplace as a Service (WaaS), if WaaS is authorized by the statement of work. Government information shall remain within the confines of authorized Government networks at all times.

Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.

(3) Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

1 “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).

http://www.dhs.gov/privacy http://www.dhs.gov/privacy http://www.gpo.gov/fdsys/

(4) Separation Checklist for Contractor Employees

The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (PII)2, in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.

In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).

Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.

B. Privacy Training, Safeguarding, and Remediation

(1) Required Security and Privacy Training for Contractors

2 As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.

The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj. The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.

The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.

(2) Safeguarding PII Requirements

Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page3 relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII).

This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.

(3) Non-Disclosure Agreement Requirement

Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:

a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and

3 The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.

https://www.justice.gov/jmd/learndoj https://www.congress.gov/bill/113th-congress/senate-bill/2521/text?overview=closed https://www.congress.gov/bill/113th-congress/senate-bill/2521/text?overview=closed https://www.justice.gov/opcl/resources

b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.

The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.

(4) Prohibition on Use of PII in Vendor Billing and Administrative Records

The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.

(5) Reporting Actual or Suspected Data Breach

Contractors must report any actual or suspected breach of PII within one hour of discovery.4 A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.

a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.015, Reporting and Response Procedures for a Breach of Personally Identifiable Information.

b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and

4 As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”

5 https://www.justice.gov/file/4336/download mailto:dojcert@usdoj.gov https://www.justice.gov/file/4336/download the Contracting Officer within one (1) hour of the initial discovery.

c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:

i. Narrative or detailed description of the events surrounding the suspected loss or compromise of information.6 Date, time, and location of the incident.

ii. Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.

iii. Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.7

iv. Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.

v. Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.8

vi. Actions that have been or will be taken to minimize damage and/or mitigate further compromise.

vii. Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.

d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of

PII.

(6) Victim Remediation

6 As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used; extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.

7 As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.

8 As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.

mailto:dojcert@usdoj.gov

At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach. The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.

C. Government Records Training, Ownership, and Management

(1) Records Management Training and Compliance

a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR. This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.

b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.

(2) Records Creation, Ownership, and Disposition

a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information. The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law.

Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.

javascript:void(0);

javascript:void(0);

b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.

D. Data Privacy and Oversight

(1) Restrictions on Testing or Training Using Real Data Containing PII

The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.

(2) Requirements for Contractor IT Systems Hosting Government Data

The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.

(3) Requirement to Support Privacy Compliance

a) If this contract requires the development, maintenance or administration of information technology9, the Contractor shall support the completion of the

9 As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project10 to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.

b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion. The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53, Rev. 5;

and compliance with the Privacy Act of 1974, E-Government Act of 2002, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.

10 In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of information) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.

https://dojnet.doj.gov/privacy/

Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.

(End of Clause)

Attachment 1

Executive Order 14042 Definitions of Terms Excerpted from the Safer Federal Workforce Task Force Website

Definitions | Safer Federal Workforce

Community transmission – means the level of community transmission as set forth in the CDC COVID-19 Data Tracker County View.

Contract and contract-like instrument – has the meaning set forth in the Department of Labor’s proposed rule, “Increasing the Minimum Wage for Federal Contractors,” 86 Fed. Reg. 38,816, 38,887 (July 22, 2021).

If the Department of Labor issues a final rule relating to that proposed rule, this term shall have the meaning set forth in that final rule.

That proposed rule defines a contract or contract-like instrument as an agreement between two or more parties creating obligations that are enforceable or otherwise recognizable at law. This definition includes, but is not limited to, a mutually binding legal relationship obligating one party to furnish services (including construction) and another party to pay for them. The term contract includes all contracts and any subcontracts of any tier thereunder, whether negotiated or advertised, including any procurement actions, lease agreements, cooperative agreements, provider agreements, intergovernmental service agreements, service agreements, licenses, permits, or any other type of agreement, regardless of nomenclature, type, or particular form, and whether entered into verbally or in writing. The term contract shall be interpreted broadly as to include, but not be limited to, any contract within the definition provided in the FAR at 48 CFR chapter 1 or applicable Federal statutes. This definition includes, but is not limited to, any contract that may be covered under any Federal procurement statute. Contracts may be the result of competitive bidding or awarded to a single source under applicable authority to do so. In addition to bilateral instruments, contracts include, but are not limited to, awards and notices of awards; job orders or task letters issued under basic ordering agreements; letter contracts; orders, such as purchase orders, under which the contract becomes effective by written acceptance or performance; exercised contract options; and bilateral contract modifications. The term contract includes contracts covered by the Service Contract Act, contracts covered by the Davis-Bacon Act, concessions contracts not otherwise subject to the Service Contract Act, and contracts in connection with Federal property or land and related to offering services for Federal employees, their dependents, or the general public.

Contractor or subcontractor workplace location – means a location where covered contract employees work, including a covered contractor workplace or Federal workplace.

Covered contract – means any contract or contract-like instrument that includes the clause described in Section 2(a) of the order.

Covered contractor – means a prime contractor or subcontractor at any tier who is party to a covered contract.

Covered contractor employee – means any full-time or part-time employee of a covered contractor working on or in connection with a covered contract or working at a covered contractor workplace. This includes employees of covered contractors who are not themselves working on or in connection with a covered contract.

https://www.saferfederalworkforce.gov/downloads/Draft%20contractor%20guidance%20doc_20210922.pdf https://covid.cdc.gov/covid-data-tracker/#county-view https://covid.cdc.gov/covid-data-tracker/#county-view https://www.federalregister.gov/documents/2021/07/22/2021-15348/increasing-the-minimum-wage-for-federal-contractors

Covered contractor workplace – means a location controlled by a covered contractor at which any employee of a covered contractor working on or in connection with a covered contract is likely to be present during the period of performance for a covered contract. A covered contractor workplace does not include a covered contractor employee’s residence.

Federal workplace – means any place, site, installation, building, room, or facility in which any Federal executive department or agency conducts official business, or is within an executive department or agency’s jurisdiction, custody, or control.

Fully vaccinated – People are considered fully vaccinated for COVID-19 two weeks after they have received the second dose in a two-dose series, or two weeks after they have received a single-dose vaccine. There is currently no post-vaccination time limit on fully vaccinated status; should such a limit be determined by the Centers for Disease Control and Prevention, that limit will be considered by the Task Force and OMB for possible updating of this Guidance.

For purposes of this Guidance, people are considered fully vaccinated if they have received COVID-19 vaccines currently approved or authorized for emergency use by the U.S. Food and Drug Administration (Pfizer-BioNTech, Moderna, and Johnson & Johnson [J&J]/Janssen COVID-19 vaccines) or COVID-19 vaccines that have been listed for emergency use by the World Health Organization (e.g., AstraZeneca/Oxford).

More information is available at Interim Clinical Considerations for Use of COVID-19 Vaccines | CDC.

Clinical trial participants from a U.S. site who are documented to have received the full series of an “active” (not placebo) COVID-19 vaccine candidate, for which vaccine efficacy has been independently confirmed (e.g., by a data and safety monitoring board), can be considered fully vaccinated two weeks after they have completed the vaccine series. Currently, the Novavax COVID-19 vaccine meets these criteria. More information is available at the CDC website here.

Mask – means any mask that is consistent with CDC recommendations as set forth in Types of Masks and Respirators | CDC. This may include the following: disposable masks, masks that fit properly (snugly around the nose and chin with no large gaps around the sides of the face), masks made with breathable fabric (such as cotton), masks made with tightly woven fabric (i.e., fabrics that do not let light pass through when held up to a light source), masks with two or three layers, masks with inner filter pockets, and filtering facepiece respirators that are approved by the National Institute for Occupational Safety and Health or consistent with international standards. The following do not constitute masks for purposes of this Guidance: masks with exhalation valves, vents, or other openings; face shields only (without mask); or masks with single-layer fabric or thin fabric that does not block light.

https://www.cdc.gov/coronavirus/2019-ncov/vaccines/fully-vaccinated.html https://www.cdc.gov/vaccines/covid-19/clinical-considerations/covid-19-vaccines-us.html https://www.cdc.gov/vaccines/covid-19/clinical-considerations/covid-19-vaccines-us.html#vaccinated-part-clinical-trail https://www.cdc.gov/coronavirus/2019-ncov/prevent-getting-sick/types-of-masks.html https://www.cdc.gov/coronavirus/2019-ncov/prevent-getting-sick/types-of-masks.html

Attachment 2

FAQs on Vaccination and Safety Protocols Excerpted from the Safer Federal Workforce Task Force Website

Vaccinations | Safer Federal Workforce

Q: Can agencies incorporate vaccination requirements into contracts that are not covered by Executive Order 14042 (Ensuring Adequate COVID Safety Protocols for Contractors)?

A: Yes. Agencies are strongly encouraged to incorporate vaccination requirements into contracts that are not covered by Executive Order 14042, consistent with applicable law. This might include, for example, incorporating vaccination requirements into contracts in advance of when they are otherwise required by the Executive Order or incorporating requirements into contracts that are not covered by the Executive Order, such as contracts under the Simplified Acquisition Threshold. Implementation of such additional requirements should generally follow the Safer Federal Workforce Task Force’s guidance for implementing the vaccination requirement in Executive Order 14042.

Q: Should agencies inquire regarding the vaccination status of onsite contractor employees?

A: Prior to contractor employees being subject to a contractual requirement to be vaccinated, agencies need to ask about the vaccination status of those onsite contractor employees. Onsite contractor employees must attest to the truthfulness of the response they provide. If an onsite contractor employee chooses not to provide a response, they will be treated as not fully vaccinated for the purpose of agency safety protocols. In requesting this information, agencies should comply with any applicable federal laws, including requirements under the Privacy Act and the Paperwork Reduction Act, and any applicable collective bargaining obligations.

Q: Do onsite contractor employees need to provide proof of a negative COVID-19 test?

A: Prior to being subject to a contractual requirement to be vaccinated, onsite contractor employees who are not fully vaccinated or who decline to provide information about their vaccination status must provide proof of a negative COVID-19 test from no later than the previous 3 days prior to entry to a federal building.

If a contractor employee is regularly tested pursuant to an agency testing program, then they do not need to provide proof of a negative COVID-19 test from no later than the previous 3 days prior to entry to a federal building unless required to by the agency testing program.

Q: How should an agency ask onsite contractor employees about their vaccination status?

A: Prior to being subject to a contractual requirement to be vaccinated, onsite contractor employees should be provided with the Certification of Vaccination form when they enter a federal building or federally controlled indoor worksite.

Unless an agency has an existing system of records notice that permits it to collect and maintain this information on its contractor employees, agencies will direct onsite contractor employees to complete the Certification of Vaccination form and keep it with them during their time on federal premises—they may be asked to show the form upon entry to a federal building or federally controlled indoor worksite and to a federal employee who oversees their work.

Prior to being subject to a contractual requirement to be vaccinated, onsite contractor employees who are not fully vaccinated (or who decline to disclose vaccination status) are required to show proof of a negative https://www.saferfederalworkforce.gov/faq/vaccinations/ https://www.saferfederalworkforce.gov/downloads/CertificationVaccinationPRAv7.pdf

COVID-19 test result from within the previous 3 days before entry to a federal building or federally controlled indoor worksite. If a contractor employee is regularly tested pursuant to an agency testing program, then they do not need to provide proof of a negative COVID-19 test from no later than the previous 3 days prior to entry to a federal building unless required to by the agency testing program.

Agencies may email Certification of Vaccination form to contractor employees in advance of their time on-site or utilize a unique tool or application to share the form with contractor employees and enable them to easily complete it, but the agency will not maintain Certification of Vaccination forms from contractor employees at this time unless an agency has a system of records notice that covers its collection of this information from onsite contractor employees. Any such collection, storage, or maintenance of the attestation disclosure forms may implicate the Privacy Act and Paperwork Reduction Act.

Prior to having a contractual requirement for its employees to be vaccinated and if authorized and consistent with the terms of the contract, an agency may work with a contractor to facilitate compliance by its onsite employees with the agency’s safety protocols, such as by having the company attest that all onsite contractor employees are fully vaccinated.

Q: What type of negative COVID-19 test result must a visitor or onsite contractor employee who is not fully vaccinated show documentation of in order to enter a federal building?

A: Agencies may determine what types of tests a visitor or onsite contractor employee who is not subject to a contractual requirement to be vaccinated can show documentation of in order to enter a federal building, provided that the tests are authorized by the U.S. Food and Drug Administration to detect current infection and produce a dated result.

Q: If an agency has a system of records notice that covers its collection of information on vaccination status from onsite contractor employees, can the agency collect that information?

A: Yes, if an agency has a system of records notice that covers its collection of the requisite information—as reflected in the Certification of Vaccination form—from onsite contractor employees consistent with the Privacy Act, it may do so. The agency should ensure such a collection is also consistent with the Paperwork Reduction Act. The agency should provide a means for individuals to update their vaccination status over time.

Q: How do covered contractors determine vaccination status of visitors to covered contractor workplaces?

A: Covered contractors should post signage at entrances to covered contractor workplaces providing information on safety protocols for fully vaccinated and not fully vaccinated individuals, including the protocols defined in the masking and physical distancing section above, and instruct individuals to follow the appropriate workplace safety protocols while at the covered contractor workplace. Covered contractors may take other reasonable steps, such as by communicating workplace safety protocols to visitors prior to their arrival at a covered contractor workplace or requiring all visitors to follow masking and physical distancing protocols for not fully vaccinated individuals.

Q: Do covered contractors need to provide onsite vaccinations to their employees?

A: Covered contractors should ensure their employees are aware of convenient opportunities to be vaccinated. Although covered contractors may choose to provide vaccinations at their facilities or https://www.saferfederalworkforce.gov/downloads/CertificationVaccinationPRAv7.pdf http://www.vaccines.gov/ http://www.vaccines.gov/ workplaces, given the widespread availability of vaccinations, covered contractors are not required to do so.

Q: What should a contractor employee do if a covered contractor employee has lost or does not have a copy of required vaccination documentation?

A: If covered contractor employees need new vaccination cards or copies of other documentation proof of vaccination, they should contact the vaccination provider site where they received their vaccine. Their provider should be able to provide them with new cards or documentation with up-to-date information about the vaccinations they have received. If the location where the covered contractor employees received their COVID-19 vaccine is no longer operating, the covered contractor employees should contact their State or local health department’s immunization information system (IIS) for assistance. Covered contractor employees should contact their State or local health department if they have additional questions about vaccination cards or vaccination records. An attestation of vaccination by the covered contractor employee is not an acceptable substitute for documentation of proof of vaccination.

Q: Who is responsible for determining if a covered contractor employee must be provided an accommodation because of a disability or because of a sincerely held religious belief, practice, or observance?

A: A covered contractor may be required to provide an accommodation to contractor employees who communicate to the covered contractor that they are not vaccinated for COVID-19, or that they cannot wear a mask, because of a disability (which would include medical conditions) or because of a sincerely held religious belief, practice, or observance. A covered contractor should review and consider what, if any, accommodation it must offer. The contractor is responsible for considering, and dispositioning, such requests for accommodations regardless of the covered contractor employee’s place of performance. If the agency that is the party to the covered contract is a “joint employer” for purposes of compliance with the Rehabilitation Act and Title VII of the Civil Rights Act, both the agency and the covered contractor should review and consider what, if any, accommodation they must offer.

Q: Are covered contractor employees who have a prior COVID-19 infection required to be vaccinated?

A: Yes, covered contractor employees who have had a prior COVID-19 infection are required to be vaccinated. More information from CDC can be found here.

Q: Can a covered contractor accept a recent antibody test from a covered contractor employee to prove vaccination status?

A: No. A covered contractor cannot accept a recent antibody test from a covered contractor employee to prove vaccination status.

Q: Does this Guidance apply to outdoor contractor or subcontractor workplace locations?

A: Yes, this Guidance applies to contractor or subcontractor workplace locations that are outdoors.

Q: If a covered contractor employee is likely to be present during the period of performance for a covered contract on only one floor or a separate area of a building, site, or facility controlled by a covered contractor, do other areas of the building, site, or facility controlled by a covered contractor constitute a covered contractor workplace?

https://www.cdc.gov/vaccines/programs/iis/contacts-locate-records.html#state https://www.cdc.gov/coronavirus/2019-ncov/php/hd-search/index.html https://www.cdc.gov/coronavirus/2019-ncov/vaccines/faq.html?s_cid=11572:covid%2520vaccine%2520after%2520having%2520covid:sem.ga:p:RG:GM:gen:PTN.Grants:FY21

A: Yes, unless a covered contractor can affirmatively determine that none of its employees on another floor or in separate areas of the building will come into contact with a covered contractor employee during the period of performance of a covered contract. This would include affirmatively determining that there will be no interactions between covered contractor employees and non-covered contractor employees in those locations during the period of performance on a covered contract, including interactions through use of common areas such as lobbies, security clearance areas, elevators, stairwells, meeting rooms, kitchens, dining areas, and parking garages.

Q: If a covered contractor employee performs their duties in or at only one building, site, or facility on a campus controlled by a covered contractor with multiple buildings, sites, or facilities, are the other buildings, sites, or facility controlled by a covered contractor considered a covered contractor workplace?

A: Yes, unless a covered contractor can affirmatively determine that none of its employees in or at one building, site, or facility will come into contact with a covered contractor employee during the period of performance of a covered contract. This would include affirmatively determining that there will be no interactions between covered contractor employees and non-covered contractor employees in those locations during the period of performance on a covered contract, including interactions through use of common areas such as lobbies, security clearance areas, elevators, stairwells, meeting rooms, kitchens, dining areas, and parking garages.

Q: Are the workplace safety protocols enumerated above the same irrespective of whether the work is performed at a covered contractor workplace or at a Federal workplace?

A: Yes. The Guidance applies to all covered contractor employees and to all contractor or subcontractor workplace locations.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .