15B61923Q00000002.pdf
PDF 139 KB Posted
- Attached to
- Water Treatment and Testing Federal contract opportunity
- Solicitation number
- 15B61923Q00000002
- Issued by
- Department of Justice Bureau of Prisons
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Chem Water SOW.pdf | ||
| Synopsis New.docx | DOCX document | |
| Cover Letter New.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
15B61923Q00000002 Page 1 of 37
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 & 30
1. REQUISITION NUMBER PAGE 1 OF
5. SOLICITATION NUMBER
15B61923Q00000002
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 6. SOLICITATION ISSUE
DATE
11/03/2022
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME her-quotes-s@bop.gov
b. TELEPHONE NUMBER (No collect calls) 8. OFFER DUE DATE / LOCAL
TIME
12/05/2022 02:00 PT
CODE 15B619
Federal Bureau of Prisons FCI Herlong 741-925 Herlong Access Rd A25 Herlong, CA 96113
9. ISSUED BY UNRESTRICTED OR X SET ASIDE:100.00 % FOR
X SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD: $7,500,000
10. THE ACQUISITION IS
SEE
SCHEDULE
11. DELIVERY FOR FOB DESTINATION
UNLESS BLOCK IS MARKED
NET 30
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER DPAS
(15 CFR 700)
13b. RATING
X RFQ IFB RFP
14. METHOD OF SOLICITATION
15B619CODE15. DELIVER TO
Federal Bureau of Prisons FCI Herlong 741-925 Herlong Access Rd A25 Herlong, CA 96113
CODE 15B61916. ADMINISTERED BY
Federal Bureau of Prisons FCI Herlong 741-925 Herlong Access Rd A25 Herlong, CA 96113
FACILITY
CODE
CODE
TELEPHONE NO.
17a. CONTRACTOR/
OFFEROR
BHERCODE18a. PAYMENT WILL BE MADE BY
Federal Bureau of Prisons FCI Herlong
PO BOX 900
Herlong, CA 96113 her-businessoffice-s@bop.gov
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER SEE ADDENDUM
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS
CHECKED
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
CHEMICAL WATER TREATMENT AND TESTING
BASED ON STATEMENT OF WORK AT FCI
HERLONG, CA 96113
Firm Fixed Price
See Continuation Sheet(s) (Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
X 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE X ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN ____ COPIES TO
ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH
OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE
TERMS AND CONDITIONS SPECIFIED.
29. AWARD OF CONTRACT: REF. _____________________________ OFFER
DATED _________________ . YOUR OFFER ON SOLICITATION (BLOCK 5)
INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH HEREIN,
IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF THE CONTRACTING OFFICER (TYPE OR PRINT)
Trevor Polan
31c. DATE SIGNED
11/03/2022
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
HER-0024-23
15B61923Q00000002 Page 2 of 37
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: _________________________________
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
PARTIAL FINAL
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
COMPLETE PARTIAL FINAL
36. PAYMENT 37. CHECK NUMBER
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
15B61923Q00000002 Page 3 of 37
Table of Contents
Section Description Page Number
1 Solicitation/Contract Form 2 Commodity or Services Schedule
2.1 Pricing Methodology
2.2 STATEMENT OF WORK
3 Contract Clauses
52.27-103-72 DOJ CONTRACTOR RESIDENCY REQUIREMENT BUREAU OF PRISONS (JUNE
2004) 2852.223-70 Unsafe Conditions Due to the Presence of Hazardous Material (June 1996) 52.21-603-70 Contracting Officer's Representative (COR) (June 2012) 52.24-403-70 Notice of Contractor Personnel Security Requirements (OCT 2005) 52.212-4 Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2021) 52.253-1 Computer Generated Forms (Jan 1991) 52.232-18 Availability of Funds (Apr 1984) 52.223-5 Pollution Prevention and Right-to-Know Information (May 2011) DOJ-02 Contractor Privacy Requirements (JAN 2022) 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders- Commercial Products and Commercial Services (May 2022) 52.216-18 Ordering (Aug 2020) 52.216-21 Requirements (Oct 1995) 52.217-8 Option to Extend Services (Nov 1999) 52.217-9 Option to Extend the Term of the Contract (Mar 2000)
4 List of Attachments 5 Solicitation Provisions
52.212-3 Offeror Representations and Certifications-Commercial Products and Commercial Services (May 2022)
5.1 Addendum to FAR 52.212-1, Instructions to Offerors-Commerical Items (Jan 2017) 52.212-1 Instructions to Offerors-Commercial Products and Commercial Services (Nov 2021) 52.204-7 System for Award Management (Oct 2018)
52.27-103-71 FAITH-BASED AND COMMUNITY-BASED ORGANIZATIONS (AUG 2005)
15B61923Q00000002 Page 4 of 37
Section 2 - Commodity or Services Schedule
SCHEDULE OF SUPPLIES/SERVICES
CONTINUATION SHEET
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
CHEMICAL WATER TREATMENT AND TESTING BASED ON
STATEMENT OF WORK AT FCI HERLONG, CA 96113
BASE YEAR: JANUARY 1, 2022 - SEPTEMBER 30, 2023
PSC: F103
1 YR $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
CHEMICAL WATER TREATMENT AND TESTING BASED ON
STATEMENT OF WORK AT FCI HERLONG, CA 96113
BASE YEAR: OCTOBER 1, 2023 - SEPTEMBER 30, 2024
PSC: F103
1 YR $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
CHEMICAL WATER TREATMENT AND TESTING BASED ON
STATEMENT OF WORK AT FCI HERLONG, CA 96113
BASE YEAR: OCTOBER 1, 2024 - SEPTEMBER 30, 2025
PSC: F103
1 YR $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
CHEMICAL WATER TREATMENT AND TESTING BASED ON
STATEMENT OF WORK AT FCI HERLONG, CA 96113
BASE YEAR: OCTOBER 1, 2025 - SEPTEMBER 30, 2026
PSC: F103
1 YR $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
CHEMICAL WATER TREATMENT AND TESTING BASED ON
STATEMENT OF WORK AT FCI HERLONG, CA 96113
BASE YEAR: OCTOBER 1, 2026 - SEPTEMBER 30, 2027
PSC: F103
1 YR $________ $_________________
2.1 Pricing Methodology
[EMPTY CLAUSE TEXT]
2.2 STATEMENT OF WORK
Background The Federal Bureau of Prisons, Federal Correctional Institution, Herlong, CA (hereinafter referred to as FCI Herlong) intends to make a single, firm, fixed- price award to a responsible entity for the chemical treatment program of the hot water boilers, hot loop, cold loop, cooling towers and the steam boiler.
Place of Performance The place of performance will be within the secure perimeter of the medium security level institution located at 741-925 Herlong Access Road, A-25, Herlong, CA 96113. This facility houses incarcerated inmates who are being held under the authority of the Federal Government by the Federal Bureau of Prisons (BOP).
15B61923Q00000002 Page 5 of 37
Scope of Work The contractor will provide chemical treatment analysis, all chemicals and equipment to successfully monitor and treat the equipment at FCI Herlong.
This will include and not limited to:
1-. Condenser water treatment products offered to include;
• Condenser water scale and corrosion inhibitor
• Oxidizing primary biocide (no straight bleach)
• Non-Oxidizing secondary biocide Operating statistics: 1000 Tons, 356/ days yr., 9.5/hrs. day, 60% load, 2.5 cycles maximum due to high silica content)
2. Closed loop treatment products to include;
• Closed loop corrosion inhibitor for mild steel and copper metals
• Either a Nitrite or Molybdate based product is acceptable for use in the closed loop systems Hot loop leaks, makes up 1200 GPD - Must be treated with scale and corrosion inhibitor -cooling tower type
3. Steam boiler system products to include;
• Combination polymer/phosphate sludge conditioner
• Sulfite oxygen scavenger
• Neutralizing amine corrosion control
• Each product must meet the description requirement. No "one drum" or combination products will be permitted.
Operating statistics: 50 HP, 75% condensate return, 24 hrs./day, 20% load, 9.5 cycles due to feedwater quality limitations.
• MSDS product data sheets must be provided for each treatment chemical.
Minimum of once monthly on-site service at each system location to include
• Full checks of all chemical control and dispensing equipment ( controllers, pumps and blowdown valves)
• Inspection of all water treatment related softeners
• Inspection and restocking of on-site test equipment and reagents used by plant operators
• Restocking of on-site product supplies Full on-site chemical analysis off all treated systems as listed below; City water testing requirements - Monthly pH Conductivity Total Alkalinity Total Hardness Silica Condenser water testing requirements - Monthly pH Conductivity Total Alkalinity Total Hardness Silica Bacteria levels Total Iron Total Copper Treatment levels Closed loops testing requirements - Monthly pH Conductivity Bacteria levels Total Iron Total Copper Treatment levels Steam Boiler system testing requirements -Monthly Boiler Water Samples - for all active boilers pH Conductivity P Alkalinity Total Alkalinity OH Alkalinity Silica Total Iron Treatment level - Phosphate/Polymer Treatment level - Sulfite DA Water Sample pH Conductivity
15B61923Q00000002 Page 6 of 37
Total Alkalinity Total Hardness Silica Total Iron Dissolved Oxygen Content Softener Water Sample pH Conductivity Total Alkalinity Total Hardness Condensate Return Sample pH Conductivity Total Iron Note: All test results must be presented in writing and reviewed with plant operators at time of service. These tests are the minimum requirement to be performed on a monthly basis for each sample listed.
A) It will be understood, that occasionally, the plant staff may request laboratory tests to be performed on various water samples from the condenser water, closed loop and steam boiler water systems. These laboratory tests will serve to verify results or to trouble shoot concerns with regard to the above mentioned systems. An unlimited number of these lab tests will be provided by the water treatment services company at no additional charge.
B) Training of plant personnel in use of testing equipment and safety/MSDS procedures as required.
C) Twice annual cooling tower cleaning to include; Distribution deck, Nozzles, fill media & sumps. Include a brief outline detailing the methods used to accomplish this task and time requirement.
D) Brush chiller tubes once annually.
Note: The water treatment services provider will bare all responsibility for the cost of lab fees, sample bottles. Water treatment provider must address wl,at tJ,ey will do in tl,e event of failure of the existing water softener for tl,e boiler system.
Condenser Water, chilled loop water and hot loop water:
Maintained cleanliness to insure no effect on chiller performance as measured by approach temperatures, amperage draw and heat transfer based on refrigerant temperatures.
Corrosion rates to specifications of;
Mild Steel: < 1. 0 mis per year.
Copper: < .1 mis per year Water Treatment provider must guarantee that all heat transfer surfaces will remain free from scale and biofouling or water treatment provider will bear the responsibility and cost for removal of same.
The Contractor must adhere to all applicable OSHA standards.
Equipment supply and warranty: Contractor shall be responsible for supply of and full maintenance or replacement of the following equipment (as a part of the contractor's annual contract price};
7 each - Walchem EZ series O - 22 GPD Chemical Pumps 1 each-Advantage LCFB-2E Condenser Water Controller 1 each - Pulsatrol ABC 102 Boiler Controller 1 each- Duradrive ¾" Condenser Bleed Valve 1 each-Jamesburry ½" Actuated Boiler Bleed Valve 4 each 15 Gallon Double wall Containment Tanks 6 Each 60 Gallon Double Wall Containment Tank Testing Supplies; Contractor will be responsible for supply of all chemical testing reagents and glassware for onsite staff testing needs (as part of the contractor's annual contract price). Tests to include;
Phosphate Sulfite P, M & OH Alkalinity Total Hardness Molybdate Nitrite Ph Calibration reagents (4.0, 7.0 & 9.0) Conductivity Calibration Standard - 1000 mmho' s Schedule of Performance The contractor's hours of work will be 7:15am to 2:00 pm, Monday through Friday, excluding federal holidays.
Education, Qualifications, Knowledge and Skills The individual/organization shall provide qualified personnel and obey the current Occupational Safety and Environmental Health Manual. The qualified personnel possess the knowledge of all applicable Federal, State, and Local code requirements.
Security Requirements
15B61923Q00000002 Page 7 of 37
The contractor will be required to adhere to all Federal Bureau of Prisons Regulations security requirements which will include passing applicable security clearances. The contractor will comply with Federal Bureau of Prisons search procedures outlined in Title 28, Code of Federal Regulations, Part 511. The contractor will be required to consent to search upon entering Bureau grounds. The contractor must submit a Tool and Equipment inventory form prior to starting work. The contractor will be escorted by Bureau staff at all times. Verbal interaction with the inmate population is prohibited and will not be tolerated for security purposes.
15B61923Q00000002 Page 8 of 37
Section 3 - Contract Clauses
A.1 ADDENDUM TO FAR 52.212-4, Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2021)
The terms and conditions for the following clauses are hereby incorporated into this solicitation and resulting contract as an addendum to FAR clause 52.212-4.
Clauses By Reference
52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov
Clause Title Fill-ins (if applicable)
52.212-4 Contract Terms and Conditions-Commercial Products and Commercial
Services (Nov 2021)
52.253-1 Computer Generated Forms (Jan 1991)
52.232-18 Availability of Funds (Apr 1984)
52.223-5 Pollution Prevention and Right-to-Know Information (May 2011)
Clauses By Full Text
52.27-103-72 DOJ CONTRACTOR RESIDENCY REQUIREMENT BUREAU OF PRISONS (JUNE 2004)
For three of the five years immediately prior to submission of an offer/bid/quote, or prior to performance under a contract or commitment, individuals or contractor employees providing services must have:
1. Legally resided in the United States (U.S.);
2. worked for the U.S. overseas in a Federal or military capacity; or
3. been a dependent of a Federal or military employee serving overseas.
If the individual is not a U.S. citizen, they must be from a country allied with the U.S. The following website provides current information regarding allied countries: http://www.opm.gov/employ/html/citizen.htm By signing this contract or commitment document, or by commencing performance, the contractor agrees to this restriction.
[End of Clause]
2852.223-70 Unsafe Conditions Due to the Presence of Hazardous Material (June 1996)
(a) "Unsafe condition" as used in this clause means the actual or potential exposure of contractor or Government employees to a hazardous material as defined in Federal Standard No. 313, and any revisions thereto during the term of this contract, or any other material or working condition designated by the Contracting Officer's Technical Representative (COTR) as potentially hazardous and requiring safety controls.
15B61923Q00000002 Page 9 of 37
(b) The Occupational Safety and Health Administration (OSHA) is responsible for issuing and administering regulations that require contractors to apprise its employees of all hazards to which they may be exposed in the course of their employment; proper conditions and precautions for safe use and exposure; and related symptoms and emergency treatment in the event of exposure.
(c) Prior to commencement of work, contractors are required to inspect for and report to the contracting officer or designee the presence of, or suspected presence of, any unsafe condition including asbestos or other hazardous materials or working conditions in areas in which they will be working.
(d) If during the performance of the work under this contract, the contractor or any of its employees, or subcontractor employees, discovers the existence of an unsafe condition, the contractor shall immediately notify the contracting officer, or designee, (with written notice provided not later than three (3) working days thereafter) of the existence of an unsafe condition. Such notice shall include the contractor's recommendations for the protection and the safety of Government, contractor and subcontractor personnel and property that may be exposed to the unsafe condition.
(e) When the Government receives notice of an unsafe condition from the contractor, the parties will agree on a course of action to mitigate the effects of that condition and, if necessary, the contract will be amended. Failure to agree on a course of action will constitute a dispute under the Disputes clause of this contract.
(f) Nothing contained in this clause shall relieve the contractor or subcontractors from complying with applicable Federal, State, and local laws, codes, ordinances and regulations (including the obtaining of licenses and permits) in connection with hazardous material including but not limited to the use, disturbance, or disposal of such material.
(End of Clause)
52.21-603-70 Contracting Officer's Representative (COR) (June 2012)
(a)Matthew Shirley ,Engineer Tech , FCI Herlong,(530) 827-8328, is hereby designated as the Contracting Officer's Representative (COR) under this contract.
(b) The COR is responsible, as applicable, for: receiving all deliverables, inspecting and accepting the supplies or services provide hereunder in accordance with the terms and conditions of this contract; providing direction to the contractor which clarifies the contractor effort, fills in details or otherwise serves to accomplish the contractual Scope of Work; evaluating performance; and certifying all invoices/vouchers for acceptance of the supplies or services furnished for payment.
(c) The COR does not have the authority to alter the contractor's obligations under the contract, and/or modify any of the expressed terms, conditions, specifications, or cost of the agreement. If as a result of technical discussions it is desirable to alter/change contractual obligations or the Scope of Work, the Contracting Officer shall issue such changes.
52.24-403-70 Notice of Contractor Personnel Security Requirements (OCT 2005)
Compliance with Homeland Security Presidential Directive-12 (HSPD-12) and Federal Information Processing Standard Publication
201 (FIPS 201) 1 entitled "Personal Identification Verification (PIV) for Federal Employees and Contractors," Phase I.
1. Long-Term Contractor Personnel:
In order to be compliant with HSPD-12/PIV I, the following investigative requirements must be met for each new long-term 2 contractor employee whose background investigation (BI) process begins on or after October 27, 2005:
a. Contractor Personnel must present two forms of identification in original form prior to badge issuance (acceptable documents are listed in Form I-9, OMB No. 1615-0047, "Employment Eligibility Verification," and at least one document must be a valid State or Federal government-issued picture ID);
b. Contractor Personnel must appear in person at least once before a DOJ official who is responsible for checking the identification documents. This identity proofing must be completed sometime during the clearance process but prior to badge issuance and must be documented by the DOJ official;
c. Contractor Personnel must undergo a BI commensurate with the designated risk level associated with the duties of each position.
Outlined below are the minimum BI requirements for each risk level:
• High Risk - Background Investigation (5 year scope)
• Moderate Risk - Limited Background Investigation (LBI) or Minimum Background Investigation (MBI)
• Low Risk - National Agency Check with Inquiries (NACI) investigation
d. The pre-appointment BI waiver requirements for all position sensitivity levels are a:
1) Favorable review of the security questionnaire form;
2) Favorable fingerprint results;
15B61923Q00000002 Page 10 of 37
3) Favorable credit report, if required;3
4) Waiver request memorandum, including both the Office of Personnel Management schedule date and position sensitivity/risk level;
and
5) Favorable review of the National Agency Check (NAC) 4 portion of the applicable BI that is determined by position sensitivity/risk level.
A badge may be issued following approval of the above waiver requirements.
If the NAC is not received within five days of OPM's scheduling date, the badge can be issued based on a favorable review of the Security Questionnaire and the Federal Bureau of Investigation Criminal History Check (i.e., fingerprint check results).
e. Badge re-validation will occur once the investigation is completed and favorably adjudicated. If the BI results so justify, badges issued under these procedures will be suspended or revoked.
2. Short-Term Contractor Personnel:
It is the policy of the DOJ that short-term contractors having access to DOJ information systems and/or DOJ facilities or space for six months or fewer are subject to the identity proofing requirements listed in items 1a. and 1b. above. The pre-appointment waiver requirements for short-term contractors are:
a. Favorable review of the security questionnaire form;
b. Favorable fingerprint results;
c. Favorable credit report, if required;5 and
d. Waiver request memorandum indicating both the position sensitivity/risk level and the duration of the appointment. The commensurate BI does not need to be initiated.
A badge may be issued following approval of the above waiver requirements and the badge will expire six months from the date of issuance. This process can only be used once for a short-term contractor in a twelve month period. This will ensure that any consecutive short-term appointments are subject to the full PIV-I identity proofing process.
For example, if a contractor employee requires daily access for a three or four-week period, this contractor would be cleared according to the above short-term requirements. However, if a second request is submitted for the same contractor employee within a twelve-month period for the purpose of extending the initial contract or for employment under a totally different contract for another three or four-week period, this contractor would now be considered "long-term" and must be cleared according to the long-term requirements as stated in this interim policy.
3. Intermittent Contractors:
An exception to the above-mentioned short-term requirements would be intermittent contractors.
a. For purposes of this policy, "intermittent" is defined as those contractor employees needing access to DOJ information systems and/or DOJ facilities or space for a maximum of one day per week, regardless of the duration of the required intermittent access. For example, the water delivery contractor that delivers water one time each week and is working on a one-year contract.
b. Contractors requiring intermittent access should follow the Department's escort policy. Please reference the August 11, 2004, and January 29, 2001, Department Security Officer policy memoranda that conveys the requirements for contractor facility escorted access.
c. Due to extenuating circumstances, if a component requests unescorted access or DOJ IT system access for an intermittent contractor, the same pre-employment background investigation waiver requirements that apply to short-term contractors are required.
d. If an intermittent contractor is approved for unescorted access, the contractor will only be issued a daily badge. The daily badge will be issued upon entrance into a DOJ facility or space and must be returned upon exiting the same facility or space.
e. If an intermittent contractor is approved for unescorted access, the approval will not exceed one year. If the intermittent contractor requires unescorted access beyond one year, the contractor will need to be re-approved each year.
4. An individual transferring from another department or agency shall not be re-adjudicated provided the individual has a current (within the last five years), favorably adjudicated BI meeting HSPD-12 and DOJ's BI requirements.
5. The DOJ's current escorted contractor policy remains unchanged by this acquisition notice.
Notes:
1. FIPS 201 is available at: www.csrc.nist.gov/publications/fips/fips201/FIPS-201-022505.pdf
2. Under HSPD-12, long-term contractors are contractors having access to DOJ information systems and/or DOJ facilities or space for six months or longer. The PIV-I identity proofing process, including initiation and adjudication of the required background investigation, is required for all new long-term contractors regardless of whether it is the current practice to issue a badge. The second phase of HSPD-12 implementation (PIV-II) requires badge issuance to all affected long-term contractors.
3. For contractors in position sensitivity/risk levels above level 1, a favorable review of a credit check is required as part of the pre-appointment waiver package.
4. In order to avoid a delay in the hiring process, components should request an Advance NAC Report when initiating investigations to OPM. Per OPM ' s instructions, to obtain an Advance NAC Report, a Code " 3" must be placed in block " B " of the " Agency Use Only " section of the investigative form. This report is available for all case types.
5.For contractors in position sensitivity/risk levels above level 1, a favorable review of a credit check is required as part of the pre-appointment waiver package.
[End of Clause]
15B61923Q00000002 Page 11 of 37
DOJ-02 Contractor Privacy Requirements (JAN 2022)
A. Limiting Access to Privacy Act and Other Sensitive Information
(1) Privacy Act Information
In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.
(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment
Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.
(3) Prior Approval Required to Hire Subcontractors
The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.
(4) Separation Checklist for Contractor Employees
The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.
In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).
Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.
B. Privacy Training, Safeguarding, and Remediation
(1) Required Security and Privacy Training for Contractors
The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract
15B61923Q00000002 Page 12 of 37 and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj. The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-
CS-0005.
The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.
(2) Safeguarding PII Requirements
Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.
(3) Non-Disclosure Agreement Requirement
Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:
(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing;
and
(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.
The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.
(4) Prohibition on Use of PII in Vendor Billing and Administrative Records
The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.
(5) Reporting Actual or Suspected Data Breach
Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.
(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting and Response Procedures for a Breach of Personally Identifiable Information.
15B61923Q00000002 Page 13 of 37
(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and the Contracting Officer within one (1) hour of the initial discovery.
(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:
(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6] Date, time, and location of the incident.
(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.
(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]
(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.
(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]
(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.
(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.
(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.
(6) Victim Remediation
At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach. The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.
C. Government Records Training, Ownership, and Management
(1) Records Management Training and Compliance
(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR. This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.
(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.
(2) Records Creation, Ownership, and Disposition
(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information. The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at
15B61923Q00000002 Page 14 of 37 a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.
(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein.
The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.
(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.
D. Data Privacy and Oversight
(1) Restrictions on Testing or Training Using Real Data Containing PII
The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.
(2) Requirements for Contractor IT Systems Hosting Government Data
The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.
(3) Requirement to Support Privacy Compliance
(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones.
Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.
(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion. The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.
[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control
15B61923Q00000002 Page 15 of 37 of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).
[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.”
Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.
[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.
[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”
[5] https://www.justice.gov/file/4336/download [6] As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used; extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.
[7] As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.
[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.
[9] As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use
(i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product;
includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.
[10] In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .