15B41520Q00000016 Mammo RFQ.pdf
PDF 5 MB Posted
- Attached to
- Mobile Mammogram Services Federal contract opportunity
- Solicitation number
- 15B41520Q00000016
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
15B41520Q00000016 Page 1 of 22
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 & 30
1. REQUISITION NUMBER
5. SOLICITATION NUMBER
15B41520Q00000016
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 6. SOLICITATION ISSUE
DATE
07/16/2020
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME b. TELEPHONE NUMBER (No collect calls) 8. OFFER DUE DATE / LOCAL
TIME
08/06/2020 16:00 CT
CODE 15B415
Federal Bureau of Prisons FCI Waseca 1000 University Dr SW Waseca, MN 56093
9. ISSUED BY X UNRESTRICTED OR SET ASIDE: % FOR
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD: 16,500,00
10. THE ACQUISITION IS
SEE
SCHEDULE
11. DELIVERY FOR FOB DESTINATION
UNLESS BLOCK IS MARKED
NET 30
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER DPAS
(15 CFR 700)
13b. RATING
X RFQ IFB RFP
14. METHOD OF SOLICITATION
15B415CODE15. DELIVER TO
Federal Bureau of Prisons FCI Waseca 1000 University Dr SW Waseca, MN 56093
CODE 15B41516. ADMINISTERED BY
Federal Bureau of Prisons FCI Waseca 1000 University Dr SW Waseca, MN 56093
FACILITY
CODE
CODE
TELEPHONE NO.
17a. CONTRACTOR/
OFFEROR
15B415CODE18a. PAYMENT WILL BE MADE BY
Federal Bureau of Prisons FCI Waseca 1000 University Dr SW Waseca, MN 56093
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER SEE ADDENDUM
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS
CHECKED
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
The contractor shall provide mobile mammography services for the female inmate population at FCI Waseca per the attached Statement of Work and the requirements of solicitation 15B41520Q00000016.
See Continuation Sheet(s) (Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
X 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE X ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
X 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN 1 COPIES TO
ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH
OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE
TERMS AND CONDITIONS SPECIFIED.
29. AWARD OF CONTRACT: REF. _____________________________ OFFER
DATED _________________ . YOUR OFFER ON SOLICITATION (BLOCK 5)
INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH HEREIN,
IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF THE CONTRACTING OFFICER (TYPE OR PRINT)
Jeremy Essler
31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
15B41520Q00000016 Page 2 of 22
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: _________________________________
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
PARTIAL FINAL
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
COMPLETE PARTIAL FINAL
36. PAYMENT 37. CHECK NUMBER
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
15B41520Q00000016 Page 3 of 22
Table of Contents
Section Description Page Number
1 Solicitation/Contract Form 2 Commodity or Services Schedule 3 Contract Clauses 4 List of Attachments 5 Solicitation Provisions
15B41520Q00000016 Page 4 of 22
Section 2 - Commodity or Services Schedule
SCHEDULE OF SUPPLIES/SERVICES
CONTINUATION SHEET
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 Base Year: Effective Date of Award(EDOA)-12 months
Firm Fixed Price
PSC: Q999
24 SS $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0002 Option Year 1: 13 months-24 months
Firm Fixed Price
PSC: Q999
24 $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0003 Option Year 2: 25 months-36 months
Firm Fixed Price
PSC: Q999
24 $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0004 Option Year 3: 37 months-48 months
Firm Fixed Price
PSC: Q999
24 $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0005 Option Year 4: 49 months-60 months
Firm Fixed Price
PSC: Q999
24 $________ $_________________
RP#0115-20
15B41520Q00000016 Page 5 of 22
Section 3 - Contract Clauses
Clauses By Reference
52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov
Clause Title Fill-ins (if applicable)
52.203-19 Prohibition on Requiring Certain Internal Confidentiality Agreements or
Statements (Jan 2017)
52.204-10 Reporting Executive Compensation and First-Tier Subcontract Awards
(Jun 2020)
52.204-13 System for Award Management Maintenance (Oct 2018)
52.204-19 Incorporation by Reference of Representations and Certifications (Dec
2014)
52.204-23 Prohibition on Contracting for Hardware, Software, and Services
Developed or Provided by Kaspersky Lab and Other Covered Entities
(Jul 2018)
52.204-25 Prohibition on Contracting for Certain Telecommunications and Video
Surveillance Services or Equipment (Aug 2019)
52.209-10 Prohibition on Contracting with Inverted Domestic Corporations (Nov
2015)
52.209-6 Protecting the Government's Interest When Subcontracting with
Contractors Debarred, Suspended, or Proposed for Debarment (Jun
2020)
52.217-9 Option to Extend the Term of the Contract (Mar 2000) (a) Period of Time: "the contract time period"
(a) Days: "60"
(c): "60"
52.219-28 Post-Award Small Business Program Rerepresentation (May 2020)
15B41520Q00000016 Page 6 of 22
Clause Title Fill-ins (if applicable)
52.222-21 Prohibition of Segregated Facilities (Apr 2015)
52.222-26 Equal Opportunity (Sept 2016)
52.222-3 Convict Labor (June 2003)
52.222-36 Equal Opportunity for Workers with Disabilities (Jun 2020)
52.222-41 Service Contract Labor Standards (Aug 2018)
52.222-43 Fair Labor Standards Act and Service Contract Labor Standards-Price
Adjustment (Multiple Year and Option Contracts) (Aug 2018)
52.222-50 Combating Trafficking in Persons (Jan 2019)
52.222-55 Minimum Wages Under Executive Order 13658 (Dec 2015)
52.222-62 Paid Sick Leave Under Executive Order 13706 (Jan 2017)
52.225-13 Restrictions on Certain Foreign Purchases (June 2008)
52.232-1 Payments (Apr 1984)
52.232-11 Extras (Apr 1984)
52.232-8 Discounts For Prompt Payment (Feb 2002)
52.232-18 Availability of Funds (Apr 1984)
52.232-23 Assignment of Claims (May 2014)
52.232-33 Payment by Electronic Funds Transfer-System for Award Management
(Oct 2018)
52.232-39 Unenforceability of Unauthorized Obligations (Jun 2013)
52.232-40 Providing Accelerated Payments to Small Business Subcontractors
(Dec 2013)
52.233-1 Alt I Disputes (May 2014) - Alternate I (Dec 1991)
52.233-3 Protest after Award (Aug 1996)
52.233-4 Applicable Law for Breach of Contract Claim (Oct 2004)
52.237-3 Continuity of Services (Jan 1991)
52.249-4 Termination for Convenience of the Government (Services) (Short
Form) (Apr 1984)
Clauses By Full Text
52.218-000 CONTINUING CONTRACT PERFORMANCE DURING A PANDEMIC INFLUENZA OR OTHER NATIONAL EMERGENCY (May 2008)
15B41520Q00000016 Page 7 of 22
During a Pandemic or other emergency we understand that our contractor workforce will experience the same high levels of absente eism as our federal employees. Although the Excusable Delays and Termination for Default clauses used in Government contracts list epidemics and quarantine restrictions among the reasons to excuse delays in contract performance, we expect our contractors to make a reasonable effort to keep performance at an acceptable level during emergency periods.
The Office of Personnel Management (OPM) has provided guidance to federal managers and employees on the kinds of actions to be taken to ensure the continuity of operations during emergency periods. This guidance is also applicable to our contract workforce. Co ntractors are expected to have reasonable policies in place for continuing work performance, particularly those performing mission c ritical services, during a pandemic influenza or other emergency situation.
The types of actions a federal contractor should reasonably take to help ensure performance are:
* Encourage employees to get inoculations or follow other preventive measures as advised by the public health service.
* Cross-train workers as backup for all positions performing critical services. This is particularly important for work such as guard services where telework is not an option.
* Implement telework to the greatest extent possible in the workgroup so systems are in place to support succe ssful remote work in an emergency.
* Communicate expectations to all employees regarding their roles and responsibilities in relation to remote work in the event of a pandemic health crisis or other emergency.
* Establish communication processes to notify employees of activation of this plan.
* Integrate pandemic health crisis response expectations into telework agreements.
* With the employee, assess requirements for working at home (supplies and equipment needed for an extende d telework period). Security concerns should be considered in making equipment choices; agencies or contract ors may wish to avoid use of employees' personal computers and provide them with PCs or laptops as appro priate.
* Determine how all employees who may telework will communicate with one another and with management to accomplish work.
* Practice telework regularly to ensure effectiveness.
* Make it clear that in emergency situations, employees must perform all duties assigned by management, even i f they are outside usual or customary duties.
* Identify how time and attendance will be maintained.
It is the contractor's responsibility to advise the Government Contracting Officer if they anticipate not being able to perform and to w ork with the Department to fill gaps as necessary. This means direct communication with the Contracting Officer or in his/her absence, another responsible person in the contracting office via telephone or email messages acknowledging the contractor's notification. The incumbent contractor is responsible for assisting the Department in estimating the adverse impacts of nonperformance and to work di ligently with the Department to develop a strategy for maintaining the continuity of operations.
The Department does reserve the right in such emergency situations to use Federal employees, employees of other agencies, contract s upport from other existing contractors, or to enter into new contracts for critical support services. Any new contracting efforts would be acquired following the guidance in the Office of federal Procurement Policy issuance "Emergency Acquisitions", May, 2007 and Subpart 18.2. Emergency Acquisition Flexibilities, of the Federal Acquisition Regulations.
[End of Clause]
52.21-603-70 Contracting Officer's Representative (COR) (June 2012)
(a)Tara Wieczorek ,AHSA , FCI Waseca,507-835-8972 ext. 2316, is hereby designated as the Contracting Officer's Representative ( COR) under this contract.
(b) The COR is responsible, as applicable, for: receiving all deliverables, inspecting and accepting the supplies or services provide he reunder in accordance with the terms and conditions of this contract; providing direction to the contractor which clarifies the contract or effort, fills in details or otherwise serves to accomplish the contractual Scope of Work; evaluating performance; and certifying all invoices/vouchers for acceptance of the supplies or services furnished for payment.
(c) The COR does not have the authority to alter the contractor's obligations under the contract, and/or modify any of the expressed ter ms, conditions, specifications, or cost of the agreement. If as a result of technical discussions it is desirable to alter/change contractual obligations or the Scope of Work, the Contracting Officer shall issue such changes.
15B41520Q00000016 Page 8 of 22
52.24-403-70 Notice of Contractor Personnel Security Requirements (OCT 2005)
Compliance with Homeland Security Presidential Directive-12 (HSPD-12) and Federal Information Processing Standard Publication
201 (FIPS 201) 1 entitled "Personal Identification Verification (PIV) for Federal Employees and Contractors," Phase I.
1. Long-Term Contractor Personnel:
In order to be compliant with HSPD-12/PIV I, the following investigative requirements must be met for each new long-term 2 contract or employee whose background investigation (BI) process begins on or after October 27, 2005:
a. Contractor Personnel must present two forms of identification in original form prior to badge issuance (acceptable documents are listed in Form I-9, OMB No. 1615-0047, "Employment Eligibility Verification," and at least one document must be a valid State or Federal government-issued picture ID);
b. Contractor Personnel must appear in person at least once before a DOJ official who is responsible for checking the identification documents. This identity proofing must be completed sometime during the clearance process but prior to badge issuance and must be documented by the DOJ official;
c. Contractor Personnel must undergo a BI commensurate with the designated risk level associated with the duties of each position. O utlined below are the minimum BI requirements for each risk level:
* High Risk - Background Investigation (5 year scope)
* Moderate Risk - Limited Background Investigation (LBI) or Minimum Background Investigation (MBI)
* Low Risk - National Agency Check with Inquiries (NACI) investigation
d. The pre-appointment BI waiver requirements for all position sensitivity levels are a:
1) Favorable review of the security questionnaire form;
2) Favorable fingerprint results;
3) Favorable credit report, if required;3
4) Waiver request memorandum, including both the Office of Personnel Management schedule date and position sensitivity/risk level;
and
5) Favorable review of the National Agency Check (NAC) 4 portion of the applicable BI that is determined by position sensitivity/risk level.
A badge may be issued following approval of the above waiver requirements.
If the NAC is not received within five days of OPM's scheduling date, the badge can be issued based on a favorable review of the Sec urity Questionnaire and the Federal Bureau of Investigation Criminal History Check (i.e., fingerprint check results).
e. Badge re-validation will occur once the investigation is completed and favorably adjudicated. If the BI results so justify, badges is sued under these procedures will be suspended or revoked.
2. Short-Term Contractor Personnel:
It is the policy of the DOJ that short-term contractors having access to DOJ information systems and/or DOJ facilities or space for six months or fewer are subject to the identity proofing requirements listed in items 1a. and 1b. above. The pre-appointment waiver requ irements for short-term contractors are:
a. Favorable review of the security questionnaire form;
b. Favorable fingerprint results;
c. Favorable credit report, if required;5 and
d. Waiver request memorandum indicating both the position sensitivity/risk level and the duration of the appointment. The commen surate BI does not need to be initiated.
A badge may be issued following approval of the above waiver requirements and the badge will expire six months from the date of issuance. This process can only be used once for a short-term contractor in a twelve month period. This will ensure that any consecu tive short-term appointments are subject to the full PIV-I identity proofing process.
For example, if a contractor employee requires daily access for a three or four-week period, this contractor would be cleared accord ing to the above short-term requirements. However, if a second request is submitted for the same contractor employee within a twelve -month period for the purpose of extending the initial contract or for employment under a totally different contract for another three or four-week period, this contractor would now be considered "long-term" and must be cleared according to the long-term requirements as stated in this interim policy.
3. Intermittent Contractors:
An exception to the above-mentioned short-term requirements would be intermittent contractors.
a. For purposes of this policy, "intermittent" is defined as those contractor employees needing access to DOJ information systems and/ or DOJ facilities or space for a maximum of one day per week, regardless of the duration of the required intermittent access. For exam ple, the water delivery contractor that delivers water one time each week and is working on a one-year contract.
b. Contractors requiring intermittent access should follow the Department's escort policy. Please reference the August 11, 2004, and January 29, 2001, Department Security Officer policy memoranda that conveys the requirements for contractor facility escorted acces s.
c. Due to extenuating circumstances, if a component requests unescorted access or DOJ IT system access for an intermittent contracto r, the same pre-employment background investigation waiver requirements that apply to short-term contractors are required.
15B41520Q00000016 Page 9 of 22
d. If an intermittent contractor is approved for unescorted access, the contractor will only be issued a daily badge. The daily badge will be issued upon entrance into a DOJ facility or space and must be returned upon exiting the same facility or space.
e. If an intermittent contractor is approved for unescorted access, the approval will not exceed one year. If the intermittent contractor requires unescorted access beyond one year, the contractor will need to be re-approved each year.
4. An individual transferring from another department or agency shall not be re-adjudicated provided the individual has a current (w ithin the last five years), favorably adjudicated BI meeting HSPD-12 and DOJ's BI requirements.
5. The DOJ's current escorted contractor policy remains unchanged by this acquisition notice.
Notes:
1. FIPS 201 is available at: www.csrc.nist.gov/publications/fips/fips201/FIPS-201-022505.pdf
2. Under HSPD-12, long-term contractors are contractors having access to DOJ information systems and/or DOJ facilities or space for six months or longer. The PIV-I identity proofing process, including initiation and adjudication of the required background inve stigation, is required for all new long-term contractors regardless of whether it is the current practice to issue a badge. The second p hase of HSPD-12 implementation (PIV-II) requires badge issuance to all affected long-term contractors.
3. For contractors in position sensitivity/risk levels above level 1, a favorable review of a credit check is required as part of the pre-ap pointment waiver package.
4. In order to avoid a delay in the hiring process, components should request an Advance NAC Report when initiating investigations t o OPM. Per OPM ' s instructions, to obtain an Advance NAC Report, a Code " 3" must be placed in block " B " of the " Agency Use Only " section of the investigative form. This report is available for all case types.
5.For contractors in position sensitivity/risk levels above level 1, a favorable review of a credit check is required as part of the pre-app ointment waiver package.
[End of Clause]
52.27-103-72 DOJ CONTRACTOR RESIDENCY REQUIREMENT BUREAU OF PRISONS (JUNE 2004)
For three of the five years immediately prior to submission of an offer/bid/quote, or prior to performance under a contract or commi tment, individuals or contractor employees providing services must have:
1. Legally resided in the United States (U.S.);
2. worked for the U.S. overseas in a Federal or military capacity; or
3. been a dependent of a Federal or military employee serving overseas.
If the individual is not a U.S. citizen, they must be from a country allied with the U.S. The following website provides current informa tion regarding allied countries: http://www.opm.gov/employ/html/citizen.htm By signing this contract or commitment document, or by commencing performance, the contractor agrees to this restriction.
[End of Clause]
DJAR-PGD-15-03 Security of Department Information and Systems
I. Applicability to Contractors and Subcontractors
This clause applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of contractors, sub contractors, and CSPs (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, dis seminate, transmit, or dispose of DOJ Information. It establishes and implements specific DOJ requirements applicable to this Contra
ct. The requirements established herein are in addition to those required by the Federal Acquisition Regulation (“FAR”), including F AR 11.002(g) and 52.239-1, the Privacy Act of 1974, and any other applicable laws, mandates, Procurement Guidance Documents, and Executive Orders pertaining to the development and operation of Information Systems and the protection of Government Inform ation. This clause does not alter or diminish any existing rights, obligation or liability under any other civil and/or criminal law, rule, regulation or mandate.
II. General Definitions
The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.
A. Information means any communication or representation of knowledge such as facts, data, or opinions, in any form or med ium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. Information includes information in an electronic f ormat that allows it be stored, retrieved or transmitted, also referred to as “data,” and “personally identifiable information” (“PII”), reg ardless of form.
B. Personally Identifiable Information (or PII) means any information about an individual maintained by an agency, incl uding, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and information, which can be used to distinguish or trace an individual's identity, such as his or her name, social security number, d
15B41520Q00000016 Page 10 of 22 ate and place of birth, mother's maiden name, biometric records, etc., including any other personal information which is linked or linka ble to an individual.
C. DOJ Information means any Information that is owned, produced, controlled, protected by, or otherwise within the custod y or responsibility of the DOJ, including, without limitation, Information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired in order to perform the contract.
D. Information System means any resources, or set of resources organized for accessing, collecting, storing, processing, main taining, using, sharing, retrieving, disseminating, transmitting, or disposing of (hereinafter collectively, “processing, storing, or transm itting”) Information.
E. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information.
III. Confidentiality and Non-disclosure of DOJ Information
A. Preliminary and final deliverables and all associated working papers and material generated by Contractor containing DOJ I nformation are the property of the U.S. Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Represent ative (“COR”) at the conclusion of the contract. The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14.
B. All documents produced in the performance of this contract containing DOJ Information are the property of the U.S. Gov ernment and Contractor shall neither reproduce nor release to any third-party at any time, including during or at expiration or terminat ion of the contract without the prior written permission of the CO.
C. Any DOJ information made available to Contractor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, Contractor assumes responsibility for the protection of the confidentiality of any and a ll DOJ Information processed, stored, or transmitted by the Contractor. When requested by the CO (typically no more than annually), Contractor shall provide a report to the CO identifying, to the best of Contractor’s knowledge and belief, the type, amount, and level o f sensitivity of the DOJ Information processed, stored, or transmitted under the Contract, including an estimate of the number of indivi duals for whom PII has been processed, stored or transmitted under the Contract and whether such information includes social security numbers (in whole or in part).
IV. Compliance with Information Technology Security Policies, Procedures and Requirements
A. For all Covered Information Systems, Contractor shall comply with all security requirements, including but not limited to the regulations and guidance found in the Federal Information Security Management Act of 2014 (“FISMA”), Privacy Act of 1974, E- Government Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, 199, and 200, OMB Memoranda, Federal Risk and Authorization Management Program (“FedRAMP”), DOJ IT Security Standards, including DOJ Order 2640.2, as amended. These requirements include but are not limited to:
1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise;
2. Providing security awareness training including, but not limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information Systems;
3. Creating, protecting, and retaining Covered Information System audit records, reports, and supporting documentation to en able reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information;
4. Maintaining authorizations to operate any Covered Information System;
5. Performing continuous monitoring on all Covered Information Systems;
15B41520Q00000016 Page 11 of 22
6. Establishing and maintaining baseline configurations and inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing s ecurity configuration settings for IT products employed in Information Systems;
7. Ensuring appropriate contingency planning has been performed, including DOJ Information and Covered Information Syste m backups;
8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and ver ifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication met hods where required;
9. Establishing an operational incident handling capability for Covered Information Systems that includes adequate preparati on, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and reporting incidents to appr opriate officials and authorities within Contractor’s organization and the DOJ;
10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, t echniques, mechanisms, and personnel used to conduct such maintenance;
12. Protecting Covered Information System media containing DOJ Information, including paper, digital and electronic media;
limiting access to DOJ Information to authorized users; and sanitizing or destroying Covered Information System media containing DOJ Information before disposal, release or reuse of such media;
13. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Inform ation Systems to authorized U.S. citizens unless a waiver has been granted by the Contracting Officer (“CO”), and protecting the phy sical facilities and support infrastructure for such Information Systems;
14. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with DOJ Security standards;
15. Assessing the risk to DOJ Information in Covered Information Systems periodically, including scanning for vulnerabilities a nd remediating such vulnerabilities in accordance with DOJ policy and ensuring the timely removal of assets no longer supported by t he Contractor;
16. Assessing the security controls of Covered Information Systems periodically to determine if the controls are effective in their application, developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in su ch Information Systems, and monitoring security controls on an ongoing basis to ensure the continued effectiveness of the controls;
17. Monitoring, controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Information Systems, and employing architectural designs, software development te chniques, and systems engineering principles that promote effective security; and
18. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection f rom malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate action in response.
B. Contractor shall not process, store, or transmit DOJ Information using a Covered Information System without first obtainin g an Authority to Operate (“ATO”) for each Covered Information System. The ATO shall be signed by the Authorizing Official for t he DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under this contract. The DOJ standards and requirements for obtaining an ATO may be found at DOJ Order 2640.2, as amended. (For Cloud Computing Systems, see Section V, below.)
C. Contractor shall ensure that no Non-U.S. citizen accesses or assists in the development, operation, management, or mainten ance of any DOJ Information System, unless a waiver has been granted by the by the DOJ Component Head (or his or her designee) r esponsible for the DOJ Information System, the DOJ Chief Information Officer, and the DOJ Security Officer.
D. When requested by the DOJ CO or COR, or other DOJ official as described below, in connection with DOJ’s efforts to ens ure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, in tegrity, and availability of DOJ Information, Contractor shall provide DOJ, including the Office of Inspector General (“OIG”) and Fe deral law enforcement components, (1) access to any and all information and records, including electronic information, regarding a C overed Information System, and (2) physical access to Contractor’s facilities, installations, systems, operations, documents, records, a nd databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews
15B41520Q00000016 Page 12 of 22 by DOJ or agents acting on behalf of DOJ, and such access shall be provided within 72 hours of the request. Additionally, Contractor shall cooperate with DOJ’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of DOJ In formation.
E. The use of Contractor-owned laptops or other portable digital or electronic media to process or store DOJ Information cove red by this clause is prohibited until Contractor provides a letter to the DOJ CO, and obtains the CO’s approval, certifying compliance with the following requirements:
1. Media must be encrypted using a NIST FIPS 140-2 approved product;
2. Contractor must develop and implement a process to ensure that security and other applications software is kept up-to-date;
3. Where applicable, media must utilize antivirus software and a host-based firewall mechanism;
4. Contractor must log all computer-readable data extracts from databases holding DOJ Information and verify that each extra ct including such data has been erased within 90 days of extraction or that its use is still required. All DOJ Information is sensitive information unless specifically designated as non-sensitive by the DOJ; and,
5. A Rules of Behavior (“ROB”) form must be signed by users. These rules must address, at a minimum, authorized and offi cial use, prohibition against unauthorized users and use, and the protection of DOJ Information. The form also must notify the user that he or she has no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contracto r-owned laptops or other portable digital or electronic media.
F. Contractor-owned removable media containing DOJ Information shall not be removed from DOJ facilities without prior ap proval of the DOJ CO or COR.
G. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with DOJ security requirements.
H. Contractor must keep an accurate inventory of digital or electronic media used in the performance of DOJ contracts.
I. Contractor must remove all DOJ Information from Contractor media and return all such information to the DOJ within 15 days of the expiration or termination of the contract, unless otherwise extended by the CO, or waived (in part or whole) by the CO, and all such information shall be returned to the DOJ in a format and form acceptable to the DOJ. The removal and return of all DOJ Information must be accomplished in accordance with DOJ IT Security Standard requirements, and an official of the Contractor shall provide a written certification certifying the removal and return of all such information to the CO within 15 days of the removal and re turn of all DOJ Information.
J. DOJ, at its discretion, may suspend Contractor’s access to any DOJ Information, or terminate the contract, when DOJ suspe cts that Contractor has failed to comply with any security requirement, or in the event of an Information System Security Incident (see Section V.E. below), where the Department determines that either event gives cause for such action. The suspension of access to DOJ Information may last until such time as DOJ, in its sole discretion, determines that the situation giving rise to such action has been c orrected or no longer exists. Contractor understands that any suspension or termination in accordance with this provision shall be at no cost to the DOJ, and that upon request by the CO, Contractor must immediately return all DOJ Information to DOJ, as well as any media upon which DOJ Information resides, at Contractor’s expense.
V. Cloud Computing
A. Cloud Computing means an Information System having the essential characteristics described in NIST SP 800-145, The NIST Definition of Cloud Computing. For the sake of this provision and clause, Cloud Computing includes Software as a Service, P latform as a Service, and Infrastructure as a Service, and deployment in a Private Cloud, Community Cloud, Public Cloud, or Hybrid Cloud.
B. Contractor may not utilize the Cloud system of any CSP unless:
1. The Cloud system and CSP have been evaluated and approved by a 3PAO certified under FedRAMP and Contractor has pr ovided the most current Security Assessment Report (“SAR”) to the DOJ CO for consideration as part of Contractor’s overall System Security Plan, and any subsequent SARs within 30 days of issuance, and has received an ATO from the Authorizing Official for the DOJ component responsible for maintaining the security confidentiality, integrity, and availability of the DOJ Information under cont ract; or, 15B41520Q00000016 Page 13 of 22
2. If not certified under FedRAMP, the Cloud System and CSP have received an ATO signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under the contract.
C. Contractor must ensure that the CSP allows DOJ to access and retrieve any DOJ Information processed, stored or transmi tted in a Cloud system under this Contract within a reasonable time of any such request, but in no event less than 48 hours from the request. To ensure that the DOJ can fully and appropriately search and retrieve DOJ Information from the Cloud system, access shall include any schemas, meta-data, and other associated data artifacts.
VI. Information System Security Breach or Incident
A. Definitions
1. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed unauthorized exposure, loss of contro l, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any DOJ Inform ation accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system.
2. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed, Covered Information System Security Breach.
3. Security Incident means any Confirmed or Potential Covered Information System Security Breach.
B. Confirmed Breach. Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confir med Breach to the DOJ CO and the CO's Representative (“COR”). If the Confirmed Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call DOJ-CERT at 1-866-US4-CERT (1-866-874-2378) im mediately (and in no event later than within 1 hour of discovery of the Confirmed Breach), and shall notify the CO and COR as soon a s practicable.
C. Potential Breach.
1. Contractor shall report any Potential Breach within 72 hours of detection to the DOJ CO and the COR, unless Contractor has
(a) completed its investigation of the Potential Breach in accordance with its own internal policies and procedures for identification, in vestigation and mitigation of Security Incidents and (b) determined that there has been no Confirmed Breach.
2. If Contractor has not made a determination within 72 hours of detection of the Potential Breach whether an Confirmed Brea ch has occurred, Contractor shall report the Potential Breach to the DOJ CO and COR within one-hour (i.e., 73 hours from detection o f the Potential Breach). If the time by which to report the Potential Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call the DOJ Computer Emergency Readiness Team (DOJ-CERT) at 1-866-U S4-CERT (1-866-874-2378) within one-hour (i.e., 73 hours from detection of the Potential Breach) and contact the DOJ CO and COR as soon as practicable.
D. Any report submitted in accordance with paragraphs (B) and (C), above, shall identify (1) both the Information Systems and DOJ Information involved or at risk, including the type, amount, and level of sensitivity of the DOJ Information and, if the DOJ In formation contains PII, the estimated number of unique instances of PII, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the US-CERT Federal Inci dent Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation d etails, and all available incident details; and (4) any other information specifically requested by theDOJ. Contractor shall continue to provide written updates to the DOJ CO regarding the status of the Security Incident at least every three (3) calendar days until inform ed otherwise by the DOJ CO.
E. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Secu rity Incident will be made by DOJ senior officials or the DOJ Core Management Team at DOJ’s discretion.
F. Upon notification of a Security Incident in accordance with this section, Contractor must provide to DOJ full access to any a ffected or potentially affected facility and/or Information System, including access by the DOJ OIG and Federal law enforcement orga nizations, and undertake any and all response actions DOJ determines are required to ensure the protection of DOJ Information, inclu ding providing all requested images, log files, and event information to facilitate rapid resolution of any Security Incident.
15B41520Q00000016 Page 14 of 22
G. DOJ, at its sole discretion, may obtain, and Contractor will permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any Security Incident. Additionally, DOJ, at its sole discretion, may require Contractor to retain, at Contractor’s expense, a Third Party Assessing Organization (3PAO), acceptable to DOJ, with expertise in inci dent response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security as sessment of all affected Information Systems.
H. Response activities related to any Security Incident undertaken by DOJ, including activities undertaken by Contractor, oth er federal agencies, and any third-party contractors or firms at the request or direction of DOJ, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Security Incident and/or liability for any additional response activities. Contractor shall be responsible for all costs and related resource allocations required for all such re sponse activities related to any Security Incident, including the cost of any penetration testing.
VII. Personally Identifiable Information Notification Requirement
Contractor certifies that it has a security policy in place that contains procedures to promptly notify any individual whose Personally Identifiable Information (“PII”) was, or is reasonably determined by DOJ to have been, compromised. Any notification shall be coordi nated with the DOJ CO and shall not proceed until the DOJ has made a determination that notification would not impede a law enfo rcement investigation or jeopardize national security. The method and content of any notification by Contractor shall be coordinated with, and subject to the approval of, DOJ. Contractor shall be responsible for taking corrective action consistent with DOJ Data Br each Notification Procedures and as directed by the DOJ CO, including all costs and expenses associated with such corrective action, which may include providing credit monitoring to any individuals whose PII was actually or potentially compromised.
VIII. Pass-through of Security Requirements to Subcontractors and CSPs The requirements set forth in the preceding paragraphs of this clause apply to all subcontractors and CSPs who perform work in conn ection with this Contract, including any CSP providing services for any other CSP under this Contract, and Contractor shall flow dow n this clause to all subcontractors and CSPs performing under this contract. Any breach by any subcontractor or CSP of any of the pr ovisions set forth in this clause will be attributed to Contractor.
2852.223-70 Unsafe Conditions Due to the Presence of Hazardous Material (June 1996)
(a) "Unsafe condition" as used in this clause means the actual or potential exposure of contractor or Government employees to a haza rdous material as defined in Federal Standard No. 313, and any revisions thereto during the term of this contract, or any other material or working condition designated by the Contracting Officer's Technical Representative (COTR) as potentially hazardous and requiring safety controls.
(b) The Occupational Safety and Health Administration (OSHA) is responsible for issuing and administering regulations that require c ontractors to apprise its employees of all hazards to which they may be exposed in the course of their employment; proper conditions and precautions for safe use and exposure; and related symptoms and emergency treatment in the event of exposure.
(c) Prior to commencement of work, contractors are required to inspect for and report to the contracting officer or designee the presenc e of, or suspected presence of, any unsafe condition including asbestos or other hazardous materials or working conditions in areas in which they will be working.
(d) If during the performance of the work under this contract, the contractor or any of its employees, or subcontractor employees, d iscovers the existence of an unsafe condition, the contractor shall immediately notify the contracting officer, or designee, (with written notice provided not later than three (3) working days thereafter) of the existence of an unsafe condition. Such notice shall include the contractor's recommendations for the protection and the safety of Government, contractor and subcontractor personnel and property th at may be exposed to the unsafe condition.
(e) When the Government receives notice of an unsafe condition from the contractor, the parties will agree on a course of action to mitigate the effects of that condition and, if necessary, the contract will be amended. Failure to agree on a course of action will cons titute a dispute under the Disputes clause of this contract.
(f) Nothing contained in this clause shall relieve the contractor or subcontractors from complying with applicable Federal, State, and local laws, codes, ordinances and regulations (including the obtaining of licenses and permits) in connection with hazardous material including but not limited to the use, disturbance, or disposal of such material.
(End of Clause)
52.204-21 Basic Safeguarding of Covered Contractor Information Systems (June 2016)
(a) Definitions. As used in this clause--
"Covered contractor information system" means an information system that is owned or operated by a contractor that processes, stores , or transmits Federal contract information.
15B41520Q00000016 Page 15 of 22
"Federal contract information" means information, not intended for public release, that is provided by or generated for the Governme nt under a contract to develop or deliver a product or service to the Government, but not including information provided by the Gove rnment to the public (such as on public Web sites) or simple transactional information, such as necessary to process payments.
"Information" means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, in cluding textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CN
SSI) 4009).
"Information system" means a discrete set of information resources organized for the collection, processing, maintenance, use, shari ng, dissemination, or disposition of information (44 U.S.C. 3502).
"Safeguarding" means measures or controls that are prescribed to protect information systems.
(b) Safeguarding requirements and procedures.
(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:
(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other inf ormation systems).
(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
(iii) Verify and control/limit connections to and use of external information systems.
(iv) Control information posted or processed on publicly accessible information systems.
(v) Identify information system users, processes acting on behalf of users, or devices.
(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational i nformation systems.
(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
(ix) Escort visitors and monitor visitor activity; maintain audit…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .