FBI and DOJ Full Text Clauses.pdf
PDF 150 KB Posted
- Attached to
- RFP - Medical Evaluations and Services Federal contract opportunity
- Solicitation number
- 15F06725R0000538
About this file
This document contains the contract clauses and special requirements for a federal contract (Solicitation 15F06726F0000107) with the Federal Bureau of Investigation (FBI). Key highlights include strict security and personnel requirements, with multiple specialized clauses addressing cybersecurity, information technology, and personnel access. Notable requirements include:
The contract mandates rigorous security protocols, including mandatory background investigations for all contractor personnel, prohibition of non-U.S. citizens accessing DOJ IT systems, and comprehensive cybersecurity measures. Contractors must comply with extensive requirements around protecting DOJ information, managing potential security incidents, and maintaining strict confidentiality. Personnel must undergo thorough security screenings, including citizenship verification, background checks, and annual cybersecurity training. The contract also includes provisions for holiday and government closure procedures, supply chain risk management, and specific restrictions on post-government employment for intelligence community personnel.
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
15F06726F0000107 Page 5 of 48
Section 3 - Special Contract Requirements
Clauses By Full Text
FBI-0006 Contractor Access to FBI facilities and information (OCT 2024)
Access to FBI facilities and information is subject to specific security and suitability requirements. The FBI reserves the right and prerogative to deny and/or restrict facility and information access of any contractor employee determined by the FBI, at any time prior to or during performance, to be unsuitable for access and/or present a risk of compromising sensitive government information to which he or she would have access to under this contract. Contractors will be allotted a reasonable amount of time, determined by the government, to replace the employee found not suitable for contract performance. Failure to replace the employee may result in a no cost termination by the government.
End of Clause
FBI-0020 Schedule of Values (Nov 2023)
Schedules for Construction Contracts
(a) Purpose. The project schedule shall be a rational, reasonable, and realistic plan for completing the work, and conform to the requirements specified in this clause and elsewhere in the contract. The Contractor understands and acknowledges that the preparation and proper management of the project schedule is a material component of the contract.
(b) Use of the schedule. The Contracting Officer shall be entitled, but not required, to rely upon the project schedule to evaluate the Contractor's progress, evaluate entitlement to extensions of time, and determine the criticality or float of any activities described in such project schedule.
(c) Submission. Prior to notice to proceed, or such other time as may be specified in the contract, the Contractor shall submit the project schedule.
(d) Milestones. The project schedule shall incorporate milestone events specified in the contract, including, as applicable, notice to proceed, substantial completion, and milestones related to specified work phases and site restrictions. The project schedule shall also include Contractor-defined milestones to identify target dates for critical events, based upon the Contractor's chosen sequence of work.
(e) Activities. The project schedule shall depict all major activities necessary to complete the work.
(f) Schedule of values:
1. The Contractor shall prepare and submit for approval a cost breakdown of the Contract price, to be referred to as the “schedule of values”, assigning values to each major activity necessary to complete the work.
2. Values must include all direct and indirect costs, although a separate value for bond costs may be established.
3. The schedule of values must contain sufficient detail to enable the Contracting Officer to evaluate applications for payment.
(g) Conflicting terms:
1. If at any time the Contracting Officer finds that the project schedule does not comply with any contract requirement, the Contracting Officer will provide written notice to the Contractor.
15F06726F0000107 Page 6 of 48
2. Within 30 calendar days of written notice, or such other time as may be specified, from the Contracting Officer, the Contractor shall take one of the following actions:
i. Revise the project schedule.
ii. Adjust activity progress.
iii. Provide sufficient information demonstrating compliance.
3. If the Contractor fails to sufficiently address the Contracting Officer's exceptions to the project schedule, the Contracting Officer may-
i. Withhold retainage until the project is substantially complete or until such time as the Contractor has complied with project schedule requirements; or
ii. Terminate the contract for default.
(h) Revisions to the schedule. If the Contractor revises the project schedule after initial approved submission, the Contractor shall provide in writing a narrative describing the substance of the revision, the rationale for the revision, and the impact of the revision on the projected substantial completion date and the available float for all activities. The addition of detail to prospective activities shall not be deemed a revision if the overall duration of the detailed activity does not change.
(i) Updates. Unless a different period for updates is specified elsewhere, the Contractor shall update the project schedule weekly to reflect actual progress in completing the work, and submit the updated project schedule by the following Monday.
(End of Clause)
FBI-0022 Information and Communication Technology Compliance in accordance with Section 508 of the Rehabilitation Act (Nov 2023)
In accordance with Section 508 of the Rehabilitation Act of 1973 and the Architectural and Transportation Barriers Compliance Board, Information Communication Technology (ICT) Accessibility Standards, all ICT supplies and services supplied as part of this contract shall meet the applicable accessibility standards at 36 CFR Part 1194.
Before acceptance, the contractor shall provide an Accessibility Conformance Report (ACR) for each ICT item that is developed, updated, configured for the agency, and when product substitutions are offered. The ACR should be based on the latest version of the Voluntary Product Accessibility Template provided by the Industry Technology Industry Council (ITIC). To be considered for award, an ACR must be submitted for each ICT Item, and must be completed according to the instructions provided by ITIC.
Before acceptance, when the contractor is required to perform testing to validate conformance to the agency's accessibility requirements, the vendor shall provide a Supplemental Accessibility Conformance Report (SAR) that contains the following information:
• Accessibility test results based on the required test methods.
• Documentation of features provided to help achieve accessibility and usability for people with disabilities.
• Documentation of core functions that cannot be accessed by persons with disabilities.
• Documentation on how to configure and install the ICT item to support accessibility.
• When an ICT item is an authoring tool that generates content (including documents, reports, videos, multimedia productions, web content, etc.), provide information on how the ICT item enables the creation of accessible electronic content that conforms to the Revised 508 Standards, including the range of accessible user interface elements the tool can create.
15F06726F0000107 Page 7 of 48
• Before final acceptance, the contractor shall provide a fully working demonstration of the completed ICT Item to demonstrate conformance to the agency's accessibility requirements. The demonstration shall expose where such conformance is and is not achieved.
• Before acceptance, the agency reserves the right to perform independent testing to validate that the ICT solution provided by the contractor conforms to the applicable Revised 508 Standards.
(End of Clause)
FBI-0025 Taxpayer First Act, Section 2004 Safeguarding (JAN 2023)
I. PERFORMANCE
In performance of this contract, the Contractor agrees to comply with and assume responsibility for compliance by officers or employees with the following requirements:
(1) All work will be performed under the supervision of the contractor.
(2) The contractor and contractor’s officers or employees to be authorized access to Federal Tax Information (FTI) must meet background check requirements defined in IRS Publication 1075. The contractor will maintain a list of officers or employees authorized access to FTI. Such list will be provided to the agency and, upon request, to the IRS.
(3) FTI in hardcopy or electronic format shall be used only for the purpose of carrying out the provisions of this contract.
FTI in any format shall be treated as confidential and shall not be divulged or made known in any manner to any person except as may be necessary in the performance of this contract. Inspection or disclosure of FTI to anyone other than the contractor or the contractor’s officers or employees authorized is prohibited.
(4) FTI will be accounted for upon receipt and properly stored before, during, and after processing. In addition, any related output and products require the same level of protection as required for the source material.
(5) The contractor will certify that FTI processed during the performance of this contract will be completely purged from all physical and electronic data storage with no output to be retained by the contractor at the time the work is completed.
If immediate purging of physical and electronic data storage is not possible, the contractor will certify that any FTI in physical or electronic storage will remain safeguarded to prevent unauthorized disclosures.
(6) Any spoilage or any intermediate hard copy printout that may result during the processing of FTI will be given to the agency. When this is not possible, the contractor will be responsible for the destruction of the spoilage or any intermediate hard copy printouts and will provide the agency with a statement containing the date of destruction, description of material destroyed, and the destruction method.
(7) All computer systems receiving, processing, storing, or transmitting FTI must meet the requirements in IRS Publication 1075. To meet functional and assurance requirements, the security features of the environment must provide for the managerial, operational, and technical controls. All security features must be available and activated to protect against unauthorized use of and access to FTI.
(8) No work involving FTI furnished under this contract will be subcontracted without the prior written approval of the IRS.
(9) Contractor will ensure that the terms of FTI safeguards described herein are included, without modification, in any approved subcontract for work involving FTI.
(10) To the extent the terms, provisions, duties, requirements, and obligations of this contract apply to performing services with FTI, the contractor shall assume toward the subcontractor all obligations, duties and responsibilities that the agency
15F06726F0000107 Page 8 of 48 under this contract assumes toward the contractor, and the subcontractor shall assume toward the contractor all the same obligations, duties and responsibilities which the contractor assumes toward the agency under this contract.
(11) In addition to the subcontractor’s obligations and duties under an approved subcontract, the terms and conditions of this contract apply to the subcontractor, and the subcontractor is bound and obligated to the contractor hereunder by the same terms and conditions by which the contractor is bound and 202 obligated to the agency under this contract.
(12) For purposes of this contract, the term “contractor” includes any officer or employee of the contractor with access to or who uses FTI, and the term “subcontractor” includes any officer or employee of the subcontractor with access to or who uses FTI.
(13) The agency will have the right to void the contract if the contractor fails to meet the terms of FTI safeguards described herein.
II. CRIMINAL/CIVIL SANCTIONS
(1) Each officer or employee of a contractor to whom FTI is or may be disclosed shall be notified in writing that FTI disclosed to such officer or employee can be used only for a purpose and to the extent authorized herein, and that further disclosure of any FTI for a purpose not authorized herein constitutes a felony punishable upon conviction by a fine of as much as $5,000 or imprisonment for as long as 5 years, or both, together with the costs of prosecution.
(2) Each officer or employee of a contractor to whom FTI is or may be accessible shall be notified in writing that FTI accessible to such officer or employee may be accessed only for a purpose and to the extent authorized herein, and that access/inspection of FTI without an official need-to-know for a purpose not authorized herein constitutes a criminal misdemeanor punishable upon conviction by a fine of as much as $1,000 or imprisonment for as long as 1 year, or both, together with the costs of prosecution.
(3) Each officer or employee of a contractor to whom FTI is or may be disclosed shall be notified in writing that any such unauthorized access, inspection or disclosure of FTI may also result in an award of civil damages against the officer or employee in an amount equal to the sum of the greater of $1,000 for each unauthorized access, inspection, or disclosure, or the sum of actual damages sustained as a result of such unauthorized access, inspection, or disclosure, plus in the case of a willful unauthorized access, inspection, or disclosure or an unauthorized access/inspection or disclosure which is the result of gross negligence, punitive damages, plus the cost of the action. These penalties are prescribed by IRC sections 7213, 7213A and 7431 and set forth at 26 CFR 301.6103(n)-1. (3) Additionally, it is incumbent upon the contractor to inform its officers and employees of the penalties for improper disclosure imposed by the Privacy Act of 1974, 5 U.S.C. 552a. Specifically, 5 U.S.C. 552a(i)(1), which is made applicable to contractors by 5 U.S.C. 552a(m) (1), provides that any officer or employee of a contractor, who by virtue of his/her employment or official position, has possession of or access to agency records which contain individually identifiable information, the disclosure of which is prohibited by the Privacy Act or regulations established thereunder, and who knowing that disclosure of the specific material is so prohibited, willfully discloses the material in any manner to any person or agency not entitled to receive it, shall be guilty of a misdemeanor and fined not more than $5,000.
(4) Granting a contractor access to FTI must be preceded by certifying that each officer or employee understands the agency’s security policy and procedures for safeguarding FTI. A contractor and each officer or employee must maintain their authorization to access FTI through annual recertification of their understanding of the agency’s security policy and procedures for safeguarding FTI. The initial certification and recertifications must be documented and placed in the agency's files for review. As part of the certification and at least annually afterwards, a contractor and each officer or employee must be advised of the provisions of IRC sections 7213, 7213A, and 7431 (see Exhibit 4, Sanctions for Unauthorized Disclosure, and Exhibit 5, Civil Damages for Unauthorized Disclosure). The training on the agency’s security policy and procedures provided before the initial certification and annually thereafter must also cover the incident response policy and procedure for reporting unauthorized disclosures and data breaches. (See Section 10) For the initial
15F06726F0000107 Page 9 of 48 certification and the annual recertifications, the contractor and each officer or employee must sign, either with ink or electronic signature, a confidentiality statement certifying their understanding of the security requirements. 203
III. INSPECTION
The IRS and the Agency, with 24-hour notice, shall have the right to send its inspectors into the offices and plants of the contractor to inspect facilities and operations performing any work with FTI under this contract for compliance with requirements defined in IRS Publication 1075. The IRS’ right of inspection shall include the use of manual and/or automated scanning tools to perform compliance and vulnerability assessments of information technology (IT) assets that access, store, process or transmit FTI. Based on the inspection, corrective actions may be required in cases where the contractor is found to be noncompliant with FTI safeguard requirements.
(End of clause)
FBI-0026 Personal Protective Equipment Clause (MAR 2023)
a. General
The Company will make provisions for the health and safety of Employees during their hours of employment in accordance with the US Army Corps of Engineers EM 385 Manual. https://www.publications.usace.army.mil/portals/76/ publications/engineermanuals/em_385-1-1.pdf. The Company will provide protective equipment, including personal protective equipment (PPE) for eyes, face, head, and extremities, protective clothing, respiratory devices, and protective shields and barriers. All PPE will be used and maintained in a sanitary and reliable condition. PPE will be used wherever it is necessary, to protect from injury or impairment of any part of the body, ant to protect the body through absorption, inhalation or physical contact from the hazards of processes or environment, chemical hazards, radiological hazards, or mechanical irritants encountered. It is each Employee’s responsibility to abide by established safety rules and policies. If a condition arises that presents a danger to an Employee’s health or safety, the Employee will report the hazard to his/her Supervisor, who will promptly investigate and take whatever action is necessary to correct the condition.
b. Cost
At no cost to Employees, the Company will furnish protective devices, protective apparel, and other equipment necessary to properly protect Employees in sufficient quantities and proper sizes of such protective clothing.
c. PPE Program Plan
This program should address in writing the hazards present; the selection, maintenance, and use of PPE; the training of employees; and monitoring of the program to ensure its ongoing effectiveness. The written program plan shall be submitted to the Government 15 days after award or modification of the existing contract and approved by the Contracting Officer or Contracting Officer Representative.
d. Training
Each worker required to use personal protective equipment is required to know:
i. i. When it is necessary
ii. What kind is necessary
iii. How to properly put it on, adjust, wear and take it off
iv. The limitations of the equipment
v. Proper care, maintenance, useful life, and disposal of the equipment
(End of clause)
15F06726F0000107 Page 10 of 48
FBI-0029 Public Release of Information (OCT 2024)
The FBI requires that contractors shall not divulge, publish, or disclose information or produce material related to the contract award, or acquired in or derived from the performance of their duties without prior written consent of the FBI.
For purposes of this Clause, "Information" shall include but not be limited to any or all written or spoken language or recordings made public, including: web sites or social media platforms, including X (formerly Twitter), Instagram, TikTok, etc.; publications, studies, books, and theses; photographs and videos/films; and public announcements and press releases describing any part of the subject matter of this contract or any phase of any program hereunder, except to the extent such information is:
1) already known to the Contractor prior to the commencement of the contract; or
2) required by law, regulation, subpoena or government or judicial order to be disclosed, including the Freedom of Information Act.
No release of information shall be made without the prior written consent of the Office of Public Affairs and/or the Contracting Officer of the FBI. Information should be sent to:[Contracting Officer's Email]. The FBI will make every effort to review proposed publications in a timely manner. Public disclosure of information without prior FBI approval could result in financial penalties or a termination for default of the contract.
Where appropriate, in accordance with established academic publishing practices, the FBI reserves the right to author/co-author any publication derived from this contract.
These obligations do not cease upon completion of the contract.
(End of clause)
FBI-0030 Organizational Conflict of Interest (OCT 2024)
a. Purpose: The purpose of this clause is to ensure that:
i. The Contractor is rendering impartial assistance and advice to the Government at all times under this contract and related Government contracts;
ii. The Contractor’s objectivity in performing work under this contract or related Government contracts is not impaired; and
iii. The Contractor does not obtain an unfair competitive advantage by virtue of its access to non-public Government information, or by virtue of its access to proprietary information belonging to others.
b.Scope: The Organizational Conflict of Interest (OCI) rules, procedures and responsibilities described in FAR 9.5 “Organizational and Consultant Conflicts of Interest”, FAR 3.101-1 “Standards of Conduct – General, and in this clause are applicable to the prime Contractor (including any affiliates and successors-in-interest), as well as any co-sponsor, joint-venture partner, consultant, subcontractor or other entity participating in the performance of this contract. The Contractor shall flow this clause down to all subcontracts, consulting agreements, teaming agreements, or other such arrangements which have OCI concerns, while modifying the terms "contract", "Contractor", and "Contracting Officer" as appropriate to preserve the Government's rights.
c. Access to and Use of Nonpublic Information: If in performance of this contract the contractor obtains access to nonpublic information such as plans, policies, reports, studies, financial plans, or data which has not been released or otherwise made available to the public, the Contractor agrees it shall not use such information for any private purpose or release such information without prior written approval from the Contracting Officer.
15F06726F0000107 Page 11 of 48
d. Access to and Protection of Proprietary Information: The Contractor agrees to exercise due diligence to protect proprietary information from misuse or unauthorized disclosure in accordance with FAR 9.505-4. The Contractor may be requested to enter into a written non-disclosure agreement with a third party asserting proprietary restrictions, if required in the performance of the contract.
e. In accordance with FAR 3.101-1, the Contractor shall also take all appropriate measures to prevent the existence of conflicting roles that might bias the Contractor’s judgement, give the Contractor an unfair competitive advantage, and deprive the FBI of objective advice or assistance that can result from hiring former Government employees. (See Health Net Fed. Svcs, B-401652.3).
f. OCI Disclosures: The Contractor shall disclose to the Contracting Officer all facts relevant to the existence of an actual or potential OCI, prior to award and any time after award. In the proposal submission, contractors must certify that they have not participated in the development of the solicitation in any capacity and must provide a list of any former FBI employees. OCI Disclosures after award must address any listed in this clause or FAR 9.5. This disclosure shall include a description of the OCI and the action the Contractor has taken or plans to take to avoid, neutralize or mitigate the OCI.
g. Remedies and Waiver:
i. If the contractor fails to comply with any requirements of FAR 9.5, FAR 3.101-1, or this clause, the Government may terminate this contract for default, disqualify the Contractor from subsequent related contractual efforts if necessary to neutralize a resulting organizational conflict of interest, and/or pursue other remedies permitted by law or this contract. If the Contractor discovers and promptly reports an actual or potential OCI subsequent to contract award, the Contracting Officer may terminate this contract for convenience if such termination is deemed to be in the best interest of the Government or take other appropriate actions.
ii. The parties recognize that the requirements of this clause may continue to impact the contractor after contract performance is completed, and that it is impossible to foresee all future impacts. Accordingly, the Contractor may at any time seek an OCI waiver from the FBI Head of Contracting by submitting a written waiver request to the Contracting Officer. Any such request shall include a full description of the OCI and detailed rationale for the OCI waiver.
(End of clause)
15F06726F0000107 Page 12 of 48
Section 4 - Contract Clauses
Clauses By Full Text
FBI-0023 Federal Bureau of Investigation Electronic Invoicing Requirement (JUL 2024)
The Federal Bureau of Investigation (FBI) requires vendors to submit a proper invoice and supporting documentation electronically through the Invoice Processing Platform (IPP). IPP is a secure, web-based electronic invoicing system provided by the U.S. Department of the Treasury’s Bureau of the Fiscal Service (Treasury) in partnership with the Federal Reserve Bank of St. Louis (FRSTL). IPP is available at no cost to any commercial vendor or independent contractor doing business with a participating government agency.
Invoice Submission
Vendors are required to create and submit electronic invoices using the IPP system. All supporting documentation shall be uploaded into the IPP system.
Invoices must be submitted at least monthly but no more than bi-weekly. Final invoices must be submitted 30 days after the end date of the period of performance.
Invoices submitted by email will not be accepted. This requirement applies immediately upon contract award. For contract-specific questions, please contact the contracting officer.
Obtaining IPP Access
If your company has already enrolled in IPP: You will not be required to re-register. Please contact your company's IPP account administrator so that he/she may add you as an additional user to your company's IPP collector account.
If your company has NOT enrolled in IPP: Your company will be auto enrolled for IPP using information from your SAM account. Your company's Primary Electronic Business Point of Contact (POC) will be designated as an IPP administrator.
This POC will be contacted by email to register when the FBI initiates the enrollment process through IPP. To prevent enrollment delays, please ensure your designated Electronic Business POC in sam.gov is up to date. Your company's IPP administrator will be responsible for initial account registration as well as creating and managing your company's IPP users and permissions. Please note that due to U.S. Department of the Treasury guidelines, IPP cannot set up User IDs using a shared email address.
How to register for IPP:
1. Once FBI Initiates the enrollment process, your company's designated Electronic Business POC in sam.gov will receive two emails from IPP Customer Support (noreply@mail.eroc.twai.gov). The first email contains the initial administrative IPP User ID. The second email, sent with 24 hours of receipt of the first email, contains a temporary password. You must log in with the temporary password within 30 days.
2. Registration is complete when the initial administrative user logs into the IPP web site with the User ID and password provided and accepts the IPP rules of behavior. Additional user accounts, including administrators, can be created after initial login.
15F06726F0000107 Page 13 of 48
Training
Vendor training materials, including a first-time login tutorial, are available on the IPP.gov website. Once you have logged in to the IPP application, you will have access to user guides that provide step-by-step instructions for all IPP capabilities ranging from creating and submitting an invoice to setting up email notifications.
Additional Support
IPP Customer Support Team is available Monday through Friday from 8:00 am to 6:00 pm EST. Phone: (866) 973-3131 or email: IPPCustomerSupport@fiscal.treasury.gov For answers to frequently asked questions, visit the Vendor FAQ page on the gov web site.
(End of clause)
DOJ-01 Whistleblower Information Distribution (Nov 2023)
Within 30 days of contract award, the contractor and its subcontractors must distribute the “Whistleblower Information for Employees of DOJ Contractors, Subcontractors, Grantees, or Sub-Grantees or Personal Services Contractors” (“Whistleblower Information”) document to their employees performing work in support of the products and services delivered under this contract (https://oig.justice.gov/sites/default/files/2020-04/NDAA-brochure.pdf).
By agreeing to the terms and conditions of this contract, the prime contractor acknowledges receipt of this requirement, in accordance with 41 U.S.C. § 4712 and FAR 3.908 & 52.203-17, and commits to distribution. Within 45 days of award, the contractor must provide confirmation to the contracting officer verifying that it has distributed the whistleblower information as required.
(End of Clause)
DOJ-01 AltII Whistleblower Information Distribution (Nov 2023)
Within 30 days of contract award, the contractor and its subcontractors must distribute the “Whistleblower Information for Employees of DOJ Contractors, Subcontractors, Grantees, or Sub-Grantees or Personal Services Contractors” (“Whistleblower Information”) document to their employees performing work in support of the products and services delivered under this contract (https://oig.justice.gov/sites/default/files/2020-04/NDAA-brochure.pdf).
By agreeing to the terms and conditions of this contract, the prime contractor acknowledges receipt of this requirement, in accordance with 41 U.S.C. § 4712 and FAR 3.908 & 52.203-17, and commits to distribution. Within 45 days of award, the contractor must provide confirmation to the contracting officer verifying that it has distributed the whistleblower information as required.
(End of Clause)
DOJ-02 Contractor Privacy Requirements (Nov 2023)
A. Limiting Access to Privacy Act and Other Sensitive Information
(1) Privacy Act Information
In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor
15F06726F0000107 Page 14 of 48 is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http:// www.gpo.gov/fdsys/. SORNs may be updated at any time.
(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment
Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract.
Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.
(3) Prior Approval Required to Hire Subcontractors
The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.
(4) Separation Checklist for Contractor Employees
The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify:
(1) return of any Government-furnished equipment;
(2) return or proper disposition of personally identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and
(3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.
In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).
Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user
15F06726F0000107 Page 15 of 48 accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.
B. Privacy Training, Safeguarding, and Remediation
(1) Required Security and Privacy Training for Contractors
The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj. The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.
The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.
(2) Safeguarding PII Requirements
Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.
(3) Non-Disclosure Agreement Requirement
Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:
(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and
(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.
The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.
(4) Prohibition on Use of PII in Vendor Billing and Administrative Records
15F06726F0000107 Page 16 of 48
The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.
(5) Reporting Actual or Suspected Data Breach
Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where:
(1) a person other than an authorized user accesses or potentially accesses PII or
(2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.
(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting and Response Procedures for a Breach of Personally Identifiable Information.
(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and the Contracting Officer within one (1) hour of the initial
(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:
(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.
[6] Date, time, and location of the incident.
(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.
(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]
(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.
(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]
(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.
15F06726F0000107 Page 17 of 48
(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.
(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.
(6) Victim Remediation
At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach. The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.
C. Government Records Training, Ownership, and Management
(1) Records Management Training and Compliance
(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR. This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.
(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of
(2) Records Creation, Ownership, and Disposition
(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information. The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.
(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information
15F06726F0000107 Page 18 of 48 systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.
(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records
D. Data Privacy and Oversight
(1) Restrictions on Testing or Training Using Real Data Containing PII
The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.
(2) Requirements for Contractor IT Systems Hosting Government Data
The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.
(3) Requirement to Support Privacy Compliance
(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel.
An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required.
The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.
(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion. The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST
15F06726F0000107 Page 19 of 48
800-53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.
[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).
[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.
[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.
[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .