2.2.1- 70CDCR26R00000021.pdf

PDF 2 MB Posted

Attached to
TRANSPORTATION_SUPPORT_FOR_TEXAS Federal contract opportunity
Solicitation number
70CDCR26R00000021
Issued by
Immigration and Customs Enforcement

About this file

This is a Request for Proposal (RFP) for commercial services issued by Immigration and Customs Enforcement (ICE) for statewide armed ground transportation and dispatch operations supporting the 287(g) Program throughout Texas. Solicitation number 70CDCR26R00000021 seeks a contractor to provide safe, secure, and humane armed ground transportation for individuals arrested under the 287(g) Program, including transport to ICE-designated locations in Texas, Oklahoma, and New Mexico. The contractor must also operate a centralized 24/7/365 dispatch center located within the ICE 287(g) National Coordination Center in the greater Nashville, Tennessee area and maintain a contractor-hosted secure web portal. This is a Firm-Fixed-Price (FFP) contract with a base period of 12 months (inclusive of a 120-day transition-in period) and one optional 36-month extension period, for a total potential duration of 48 months. The primary place of performance is all 254 counties in Texas, with delivery locations at ICE facilities in Texas, Oklahoma, and New Mexico as directed by ICE Enforcement and Removal Operations (ERO).

The contractor must provide all necessary management, supervision, personnel, training, certifications, vehicles, facilities, equipment, materials, and quality control. Required qualifications include general liability insurance of at least $500,000 per occurrence, automobile liability insurance of at least $200,000 per person and $500,000 per occurrence, and workers' compensation insurance of not less than $3,000,000. The contract incorporates extensive security and compliance requirements, including FedRAMP Cloud Computing Security Requirements Baseline compliance, NIST SP 800-53 controls, DHS security policies, Privacy Act compliance with contractor employee training, and supply chain risk management protocols. The contractor must conduct reasonable inquiries to identify prohibited products or services under FASCSA orders and report any non-compliant items within 72 hours. Responses must include pricing using the provided pricing template with CLINs for transportation services and dispatch services. This acquisition is not set aside for small business concerns, and large businesses must submit an individual subcontracting plan. The solicitation does not indicate a specific response deadline or award date in the primary sections reviewed.

View the file

Other files for this federal contract opportunity

Other files attached to TRANSPORTATION_SUPPORT_FOR_TEXAS, newest first.
File Type Posted
2.2.1- 70CDCR26R00000021 A0003.pdf PDF
A0002 70CDCR26R00000021.pdf PDF
2.2.1- Attachment 02- Pricing Template A0002.xlsx XLSX spreadsheet
2.2.1- Attachment 02- Pricing Template A0001.xlsx XLSX spreadsheet
2.2.1- Attachment 01-PWS A0001.pdf PDF
Attachment 04- Government Response to Questions A0001.xlsx XLSX spreadsheet
2.1.1-Attachment 06– ICE Firearms Policy.pdf PDF
A0001 70CDCR26R00000021.pdf PDF
2.1.1-Attachment 05– G-391 Upload Template.xlsx XLSX spreadsheet
2.2.1- Attachment 04- Solicitation Question Template (1).xlsx XLSX spreadsheet
2.2.1- Attachment 03- Consolidated Wage Determinations (1).xlsx XLSX spreadsheet
2.2.1- Attachment 02- Pricing Template (1).xlsx XLSX spreadsheet
2.2.1- Attachment 01-PWS.pdf PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION

15A. NAME AND

ADDRESS

OF OFFEROR

SOLICITATION, OFFER, AND AWARD 1. This Contract is a Rated Order under the Defense Priorities and Allocations System (DPAS) - Code of Federal Regulations - at 15 CFR 700.

RATING PAGE

2. CONTRACT NUMBER 3. SOLICITATION NUMBER 4. TYPE OF SOLICITATION 5. DATE ISSUED 6. REQUISITION/PURCHASE NUMBER

CODE7. ISSUED BY 8. ADDRESS OFFER TO (If other than item 7)

NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".

SOLICITATION

9. Sealed offers in original and copies for furnishings the supplies or services in the Schedule will be received at the place specified in item 8, or if hand carried, in the depository located in until local time

CAUTION - LATE Submissions, Modifications, and Withdrawals: See Section L, Provision Number 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.

10. FOR

INFORMATION

CALL:

A. NAME B. TELEPHONE (NO COLLECT CALLS)

AREA CODE NUMBER EXTENSION

C. EMAIL ADDRESS

11. TABLE OF CONTENTS

(X) DESCRIPTION PAGE(S) (X) SECTION PAGE(S)DESCRIPTION

A B

C D E F G H

I

J

K

L

M EVALUATION FACTORS FOR AWARD

INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS

REPRESENTATIONS, CERTIFICATIONS AND OTHER

STATEMENTS OF OFFERORS

PART IV - REPRESENTATIONS AND INSTRUCTIONS

LIST OF ATTACHMENTS

PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACHMENTS

CONTRACT CLAUSESSOLICITATION/CONTRACT FORM

SUPPLIES OR SERVICES AND PRICES/COSTS

DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

PACKAGING AND MARKING

INSPECTION AND ACCEPTANCE

DELIVERIES OR PERFORMANCE

CONTRACT ADMINISTRATION DATA

SPECIAL CONTRACT REQUIREMENTS

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

OFFER (Must be fully completed by offeror)

12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause Number 52.232-8)

14. ACKNOWLEDGMENT OF AMENDMENTS

(The offeror acknowledges receipt of amendments to the SOLICITATION for offerors and related documents numbered and dated):

10 CALENDAR DAYS (%) 20 CALENDAR DAYS (%) 30 CALENDAR DAYS (%) CALENDAR DAYS (%)

DATEAMENDMENT NUMBERAMENDMENT NUMBER DATE

CODE FACILITY 16. NAME AND THE TITLE OF PERSON AUTHORIZED TO SIGN OFFER

(Type or print)

AREA CODE NUMBER EXTENSION

15C. CHECK IF REMITTANCE ADDRESS IS

DIFFERENT FROM ABOVE - ENTER

SUCH ADDRESS IN SCHEDULE.

17. SIGNATURE 18. OFFER DATE

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION

22. AUTHORITY FOR USING OTHER THAN FULL OPEN COMPETITION UNDER THE

UNITED STATES CODE AT:

10 U.S.C. 3204(a) ( )41 U.S.C. 3304(a) (

24. ADMINISTERED BY (If other than Item 7)

26. NAME OF CONTRACTING OFFICER (Type or print)

IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.

AUTHORIZED FOR LOCAL REPRODUCTION

Previous edition is unusable

23. SUBMIT INVOICES TO ADDRESS SHOWN IN

(4 copies unless otherwise specified)

25. PAYMENT WILL BE MADE BY

27. UNITED STATES OF AMERICA

(Signature of Contracting Officer)

28. AWARD DATE

CODE

ITEM

STANDARD FORM 33 (REV. 12/2022)

Prescribed by GSA - FAR (48 CFR) 53.214 (c)

SEALED BID (IFB) INVITATION FOR BID

NEGOTIATED (RFP) REQUEST FOR

PROPOSAL

(Hour) (Date)

PART I - THE SCHEDULE PART II - CONTRACT CLAUSES

15B. TELEPHONE NUMBER

CODE

OF PAGES

Shane.Crowl@ice.dhs.gov CC: Brittany.Tobias@ice.dhs.gov

70CDCR26R00000021

shane.crowl@ice.dhs.gov

SHANE CROWL

DETENTION COMPLIANCE AND REMOVALS

ICE Office of Acquisition Management 500 12th St SW

WASHINGTON DC 20024

70CDCR

1700 ES

SHANE CROWL

08/10/2026

07/27/2026

1 121

CONTINUATION SHEET

REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGES

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C)

NSN 7540-01-152-8067

70CDCR26R00000021

Solicitation for 287(g) Texas Transportation in accordance with sections A-M of this Request for Proposal (RFP), including Attachments (See

Section J).

SECTION B:

SUPPLIES OR SERVICES AND PRICES/COSTS

B.1. GENERAL

The contractor shall provide all management, supervision, personnel, training, certifications, vehicles, facilities, equipment, materials, supplies, and quality control necessary to perform the safe, secure, humane, and expeditious armed ground transportation services identified in the Performance Work Statement (PWS) for individuals arrested under the 287(g) Program throughout the State of Texas, including transport to ICE designated locations in Texas, Oklahoma and New Mexico and operation of a centralized dispatch center and secure web portal.

B.2. CONTRACT TYPE

This is a Firm-Fixed-Price (FFP) contract.

B.3. CLIN STRUCTURE

See Attachment-02 Pricing Template for anticipated CLIN structure.

Note: The government may establish a single CLIN for transportation services (X001), and a single CLIN for dispatch services (X002), given the number of locations required. In this event, the government will incorporate the offerors price sheet as an attachment to the resultant contract award.

[END OF SECTION B]

[THE REMAINDER OF THIS PAGE IS INTENTIONALLY LEFT BLANK]

REQUEST FOR PROPOSAL 70CDCR26R00000021

SECTION C:

DESCRIPTION/SPECIFICATIONS

C.1. PERFORMANCE WORK STATEMENT (PWS)

The PWS is attached to this solicitation; see Attachment 01 – Performance Work Statement.

[END OF SECTION C]

[THE REMAINDER OF THIS PAGE IS INTENTIONALLY LEFT BLANK]

SECTION D:

PACKING AND MARKING

D.1. PACKING AND MARKING

No packing or marking requirements are applicable to this requirement.

[END OF SECTION D]

SECTION E:

INSPECTION AND ACCEPTANCE

E.1. CLAUSES AND/OR PROVISIONS INCORPORATED BY REFERENCE

The following clauses are incorporated by reference:

Number Title Date 52.204-7 System for Award Management Nov 2024 52.212-4 Contract Terms and Conditions – Commercial Products and

Commercial Services (DEVIATION 25-21)

E.2. INSPECTION AND ACCEPTANCE

The government will conduct inspection and acceptance for all rendered services including deliverables in accordance with FAR 52.212-4 (DEVIATION 25-21). See:

Attachment 01 – Performance Work Statement

E.3. CONTRACTOR PERFORMANCE ASSESSMENT REPORTING SYSTEM (CPARS)

In accordance with Federal Acquisition Regulation (FAR) Subpart 42.15, it is anticipated that past performance evaluations will be entered into CPARS, the governmentwide evaluation reporting tool for all past performance reports on contracts and orders. For more information regarding CPARS, please visit http://www.cpars.gov/.

E.4. QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)

Services will be evaluated in accordance with the metrics outlined in the QASP contained within Attachment 01- Performance Work Statement.

[END OF SECTION E]

http://www.cpars.gov/

SECTION F:

DELIVERIES OR PERFORMANCE

F.1. CLAUSES AND/OR PROVISIONS INCORPORATED BY REFERENCE

The following clauses are incorporated by reference:

52.242-15 Stop-Work Order Aug 1989

F.2. PERIOD OF PERFORMANCE

The anticipated period of performance will include a single base period of 12- months inclusive of a 120 day transition-in period; and Option Period One: 36 months, if exercised by the Government.

F.3. PLACE OF PERFORMANCE

Primary place of performance:

• State of Texas (all 254 counties)

Delivery locations:

• ICE facilities in Texas, Oklahoma, and New Mexico, as directed by ICE ERO.

Dispatch Center

• Contractor dispatch operations shall be located within the ICE 287(g) National Coordination Center in the greater Nashville, Tennessee area, as described in the PWS. The Government will provide space; the contractor will furnish and operate all equipment within that space.

F.4. LIST OF DELIVERABLES

For a complete list of contract deliverables and associated due dates, see:

• Attachment 01 – Performance Work Statement (PWS)

[END OF SECTION F]

SECTION G:

CONTRACT ADMINISTRATION DATA

G.1. CONTRACT ADMINISTRATION

Notwithstanding the contractor’s responsibility for management of daily of operations of the facility during the contract performance, the administration of the contract will require coordination between ICE and the contractor.

G.2. CONTRACTING OFFICER’S REPRESENTATIVE (COR)

The following individual is designated as the COR for this requirement and is authorized by the contracting officer (CO) to perform specific contract administration functions such as inspection and acceptance of services and other functions of a technical nature:

The CORs will represent the CO in the administration of technical details within the scope of the Contract. The CORs are also responsible for the final inspection and acceptance of all Contract deliverables and reports. The CORs are not otherwise authorized to make any representations or commitments of any kind on behalf of the CO or the Government. The CORs do not have authority to alter the contractor’s obligations or to change the contract specifications, price, terms or conditions. If, as a result of technical discussions, it is desirable to modify contract obligations or the specification, changes will be issued in writing and signed by the CO.

The COR will monitor contractor performance using the Quality Assurance Surveillance Plan (QASP), and will verify compliance with the performance standards, Acceptable Quality Levels (AQLs), and deliverable requirements set forth in the PWS.

G.3. INVOICE INSTRUCTIONS

The Contractor shall invoice in accordance with the PWS and any additional instructions provided in the award document (including the designated electronic invoicing system). At a minimum, invoices shall be supported by the monthly performance and reporting documentation.

[END OF SECTION G]

SECTION H:

SPECIAL CONTRACT REQUIREMENTS

H.1. PERFORMANCE-BASED SERVICES CONTRACTING (PBSC)

Through the direction of the Office of Management and Budget (OMB), Office of Federal Procurement Policy (OFPP), performance-based contracting techniques will be applied to this contract to the “maximum extent practicable.” For information about PBSC, refer to RFO 37.101.

Performance-based contracts for service must include:

a) Performance requirements that define the work in measurable, mission-related terms;

b) Performance standards (i.e., quality, quantity, timeliness) tied to the performance requirements;

and

c) A Government QASP or other suitable plan that describes how the contractor’s performance will be measured against the performance standards or service level agreements (SLAs).

H.2. DISCLOSURE OF INFORMATION – OFFICIAL USE ONLY

Each officer or employee of the contractor or subcontractor at any tier to whom “Official Use Only” information may be made available or disclosed, shall be notified in writing by the contractor that “Official Use Only” information disclosed to that individual can be used only for a purpose, and to the extent authorized herein, and that further disclosure of any such “Official Use Only” information, by any means, for a purpose or to an extent unauthorized herein, may subject the offender to criminal sanctions imposed by 18 U.S.C. Sections 641 and 3571. Section 641 of 18 U.S.C. provides, in pertinent part, that whoever knowingly converts to his use or the use of another, or without authority sells, conveys, or disposes of any record of the United States or whoever receives the same with the intent to convert it to his use or gain, knowing it to have been converted, shall be guilty of a crime punishable by a fine or imprisoned up to 10 years, or both.

H.3. CONTRACTOR’S INSURANCE AND FAR 52.228-10

The contractor shall maintain insurance in an amount not less than $3,000,000 to protect the contractor from claims under workman compensation acts and from any other claims for damages for personal injury, including death which may arise from operations under this contract whether such operations by the contractor itself or by any subcontractor or anyone directly or indirectly employed by either business entity. The contractor shall maintain general liability insurance: bodily injury liability coverage written on a comprehensive form of policy of at least $500,000 per occurrence is required.

Additionally, an automobile liability insurance policy providing for bodily injury and property damage liability covering automobiles operated in the United States (U.S.) shall provide coverage of at least $200,000 per person and $500,000 per occurrence for bodily injury and $20,000 per occurrence for property coverage. Certificates of such insurance shall be subject to the approval of the CO for adequacy of protection. All insurance certificates required under this contract shall provide 30 days’ notice to the government of any contemplated cancellation. The contractor shall ensure that all staff having access to alien monies and valuables are bonded in an amount sufficient to ensure reimbursement to the alien by the contractor in case of loss.

H.4. ICE INFORMATION GOVERNANCE AND PRIVACY REQUIREMENTS (JUL 2017)

In addition to FAR 52.224-1 Privacy Act Notification (APR 1984), 52.224-2 Privacy Act (APR 1984), 52.224-3 Privacy Training – Alternate I (DEVIATION), and HSAR Clauses, the following instructions must be included in their entirety in all contracts.

Limiting Access to Privacy Act and Other Sensitive Information In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984), and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DHS system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.dhs.gov/system-records-notices-sorns. Applicable SORNS of other agencies may be accessed through the agencies’ websites or by searching GovInfo, available at https://www.govinfo.gov that replaced the FDsys website in December 2018. SORNs may be updated at any time.

Prohibition on Performing Work Outside a Government Facility/Network/Equipment The contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or Workplace as a Service (WaaS) if WaaS is authorized by the Performance Work Statement Government information shall remain within the confines of authorized Government networks at all times. Except where telework is specifically authorized within this contract, the contractor shall perform all tasks described in this document at authorized Government facilities; the contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of telework authorizations.

Prior Approval Required to Hire Subcontractors The Contractor is required to obtain the CO’s approval prior to engaging in any contractual relationship (subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

Separation Checklist for Contractor Employees Contractor shall complete a separation checklist before any employee or subcontractor employee terminates working on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposal of sensitive personally identifiable information (PII), in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and

(3) termination of any technological access to the contractor’s facilities or systems that would permit the terminated employee’s access to sensitive PII.

REQUEST FOR PROPOSAL 70CDCR26R00000021

https://www.dhs.gov/system-records-notices-sorns https://www.govinfo.gov/

In the event of adverse job actions resulting in the dismissal of an employee or subcontractor employee, the contractor shall notify the Contracting Officer’s Representative (COR) within 24 hours. For normal separations, the Contractor shall submit the checklist on the last day of employment or work on the contract.

As requested, contractors shall assist the ICE Point of Contact (ICE/POC), CO, or COR with completing ICE Form 50-005/Contractor Employee Separation Clearance Checklist by returning all Government-furnished property including but not limited to computer equipment, media, credentials and passports, smart cards, mobile devices, PIV cards, calling cards, and keys and terminating access to all user accounts and systems.

Contractor’s Commercial License Agreement and Government Electronic Information Rights Except as stated in the PWS and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases) and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and are considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

Privacy Lead Requirements If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy documentation, the contractor shall assign or procure a privacy lead, to be listed under the PWS’s required contractor personnel section. The privacy lead shall be responsible for providing adequate support to DHS to ensure DHS can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance. The Privacy Lead shall work with personnel from the program office, the ICE Privacy Unit, the Office of the Chief Information Officer, and the Records and Data Management Unit to ensure that the privacy documentation is kept on schedule, that the answers to questions in the PIA are thorough and complete, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.

The Privacy Lead:

• Must have excellent writing skills, the ability to explain technology clearly for a non-technical audience, and the ability to synthesize information from a variety of sources.

• Must have excellent verbal communication and organizational skills.

• Must have experience writing PIAs. Ideally the candidate would have experience writing PIAs for DHS.

• Must be knowledgeable about the Privacy Act of 1974 and the E-Government

Act of 2002.

• Must be able to work well with others.

If a Privacy Lead is already in place with the program office and the contract involves IT system builds or substantial changes that may require privacy documentation, the requirement for a separate

Private Lead specifically assigned under this contract may be waived provided the contractor agrees to have the existing Privacy Lead coordinate with and support the ICE Privacy POC to ensure privacy concerns are proactively reviewed and so ICE can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance if required. The contractor shall work with personnel from the program office, the ICE Office of Information Governance and Privacy, and the Office of the Chief Information Officer to ensure that the privacy documentation is kept on schedule, that the answers to questions in any privacy documents are thorough and complete, that all records management requirements are met, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.

H.5. COMPLIANCE WITH DHS SECURITY POLICY TERMS AND CONDITIONS

All hardware, software, and services provided under this task order must be compliant with DHS National Security Systems Policy Directive 4300B, Version 10.1, November 21, 2018' for NSS Collateral (Unclass, Secret or Top Secret Collateral).

H.6. ENCRYPTION COMPLIANCE TERMS AND CONDITIONS

If encryption is required, the following methods are acceptable for encrypting sensitive information:

a) FIPS 197 (Advanced Encryption Standard (AES)) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2.

b) National Security Agency (NSA) Type 2 or Type 1 encryption.

c) Public Key Infrastructure (PKI) (see paragraph 5.5.2.1 of the Department of Homeland

Security (DHS) IT Security Program Handbook (DHS Management Directive (MD) 4300A) for Sensitive Systems).

H.7. SECURITY REVIEW TERMS AND CONDITIONS

The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The contractor shall afford ICE, including the organization of ICE Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer Representative (COR), and other government oversight organizations, access to the contractor's facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The contractor will contact ICE Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to ICE. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of ICE data or the function of computer system operated on behalf of ICE, and to preserve evidence of computer crime.

H.8. INTERCONNECTION SECURITY AGREEMENT (ISA) TERMS AND CONDITIONS

Interconnections between DHS/ICE and non-DHS/ICE IT systems shall be established only through controlled interfaces and via approved service providers. The controlled interfaces shall be authorized at the highest security level of information on the network. Connections with other Federal agencies shall be documented based on interagency agreements, memoranda of understanding, service level agreements or interconnection security agreements.

H.9. PERSONAL IDENTIFICATION VERIFICATION (PIV) CREDENTIAL COMPLIANCE

TERMS AND CONDITIONS

a) Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting HSPD-12 PIV credentials as a method of identity verification and authentication.

b) Procurements for software products or software developments shall be compliant by accepting PIV credentials as the common means of authentication for access for federal employees and contractors.

c) PIV-enabled information systems must demonstrate that they can correctly work with PIV credentials by responding to the cryptographic challenge in the authentication protocol before granting access.

d) If a system is identified to be non-compliant with HSPD-12 for PIV credential enablement, a remediation plan for achieving HSPD-12 compliance shall be required for review, evaluation, and approval by the CISO.

H.10. IN ACCORDANCE WITH FEDRAMP

1) FedRAMP IT Systems Security Requirements

a) The Federal agency will determine the security category for the cloud system in accordance with Federal Information Processing Standard 199; then, the contractor/Cloud Service Provider (CSP) shall apply the appropriate set of impact baseline controls as required in the FedRAMP Cloud Computing Security Requirements Baseline document to ensure compliance to security standards. The FedRAMP baseline controls are based on the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations (as amended), and also includes a set of additional controls for use within systems providing cloud services to the federal government.

b) The CSP shall maintain a security management continuous monitoring environment that meets or exceeds the requirements outlined in the latest edition of FedRAMP Cloud Computing Security Requirements Baseline and FedRAMP Continuous Monitoring Requirements.

2) FedRAMP Privacy Requirements

Contractor shall be responsible for the following privacy and security safeguards:

a) To the extent required to carry out the FedRAMP assessment and authorization process and FedRAMP continuous monitoring, to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public Government data collected and stored by the contractor, the contractor shall afford the Government access to the contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases.

b) If new or unanticipated threats or hazards are discovered by either the Government or the contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

c) The contractor shall also comply with any additional FedRAMP privacy requirements.

d) The Government has the right to perform manual or automated audits, scans, reviews, or other inspections of the vendor’s IT environment being used to provide or facilitate services for the Government. In accordance with the Federal Acquisitions Regulations (FAR) clause 52.239-1, contractor shall be responsible for the following privacy and security safeguards:

i. The contractor shall not publish or disclose in any manner, without the CO’s written consent, the details of any safeguards either designed or developed by the Contractor under this contract or otherwise provided by the Government.

Exception—Disclosure to a Consumer Agency for purposes of C&A verification.

ii. To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the contractor shall afford the Government access to the contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases within 72 hours. The program of inspection shall include, but is not limited to: Authenticated and unauthenticated operating system/network vulnerability scans Authenticated and unauthenticated we b application vulnerability scans Authenticated and unauthenticated database application vulnerability scans Automated scans can be performed by Government personnel, or agents acting on behalf of the Government, using Government operated equipment, and Government specified tools.

iii. If new or unanticipated threats or hazards are discovered by either the Government or the contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

iv. If the vendor chooses to run its own automated scans or audits, results from these scans may, at the Government’s discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by the Government. In addition, the results of vendor-conducted scans shall be provided, in full, to the Government.

3) Sensitive Information Storage

Controlled Unclassified information (CUI), data, and/or equipment will only be disclosed to authorize personnel on a need-to-know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to Government control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following NIST SP 800-88, Guidelines for Media Sanitization.

The disposition of all data will be at the written direction of the COR; this may include documents returned to Government control; destroyed; or held as specified until otherwise directed. Items returned to the Government shall be hand carried or sent by certified mail to the

COR.

4) Protection of Information

The contractor shall be responsible for properly protecting all information used, gathered, or developed because of work under this contract. The contractor shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this contract should be considered as CUI information. It is anticipated that this information will be gathered, created, and stored within the primary work location. If contractor personnel must remove any information from the primary work area they should protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.

The government will retain unrestricted rights to government data. The government retains ownership of any user created/loaded data and applications hosted on vendor’s infrastructure, as well as maintains the right to request full copies of these at any time.

The data that is processed and stored by the various applications within the network infrastructure contains financial data as well as personally identifiable information (PII). This data and PII shall be protected against unauthorized access, disclosure or modification, theft, or destruction. The contractor shall ensure that the facilities that house the network infrastructure are physically secure.

The government-owned data must be available to the Government upon request within one business day or within the timeframe specified otherwise and shall not be used for any other purpose other than that specified herein. The contractor shall provide requested data at no additional cost to the government.

No data shall be released by the contractor without the consent of the Government in writing.

All requests for release must be submitted in writing to the COR/CO.

5) Security Classification

The preparation of the deliverables in this contract will be completed at a Sensitive but Unclassified level unless a higher level is specified.

6) Confidentiality and Nondisclosure

The preliminary and final deliverables and all associated working papers and other material deemed relevant by the agency that have been generated by the contractor in the performance of this contract, are the property of the U.S. Government, and must be submitted to the COR at the conclusion of the contract. The U.S. Government has unlimited data rights to all deliverables and associated working papers and materials in accordance with FAR 52.227-1, 52.227-2, 52.227-3, 52.227-11, 52.227-14, 52.227-16.

All documents produced for this project are the property of the U.S. Government and cannot be reproduced or retained by the contractor. All appropriate project documentation will be given to the agency during and at the end of this contract. The contractor shall not release any information without the written consent of the CO.

Personnel working on any of the tasks described may, at Government request, be required to sign formal non-disclosure and/or conflict of interest agreements to guarantee the protection and integrity of Government information and documents.

7) Disclosure of Information

Any information made available to the contractor by the Government shall be used only for carrying out the provisions of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of the contract. In performance of this contract, the contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its subcontractors shall be under the supervision of the contractor or the contractor’s responsible employees. Each officer or employee of the contractor or any of its subcontractors to whom any Government record may be made available or disclosed shall be notified in writing by the contractor that information disclosed to such officer or employee can be used only for that purpose and to the extent authorized herein. Further disclosure of any such information, by any means, for a purpose or to an extent unauthorized herein, may subject the offender to criminal sanctions imposed by 18 U.S.C. §§ 1030.

8) FedRAMP Security Requirements Overview:

a) The minimum requirements for low and moderate impact cloud systems are contained within the FedRAMP Cloud Computing Security Requirements Baseline. The contractor and Federal Government Agency share responsibility to ensure compliance with security requirements.

b) The implementation of a new Federal Government cloud system requires a formal process, known as Assessment and Authorization, which provides guidelines for performing the assessment.

c) FedRAMP requires cloud service providers to utilize a Third-Party Assessment Organization (3PAO) to perform an assessment of the cloud service provider’s security controls to determine the extent to which security controls are implemented correctly, operate as intended, and produce the desired outcome with respect to meeting security requirements.

d) The FedRAMP PMO security staff will be available for consultation during the process.

Both the FedRAMP PMO staff and JAB will review the results before issuing a Provisional Authorization decision. The Government reserves the right to verify the infrastructure and security test results before issuing an Authorization decision.

e) Federal agencies will be able to leverage the provisional Authorization granted by FedRAMP and any documentation prepared by the contractor to issue their own authority to operate.

f) The vendor is advised to review the FedRAMP guidance documents (see References below) to determine the level of effort that will be necessary to complete the requirements. All FedRAMP documents and templates are available at http://FedRAMP.gov.

9) FedRAMP Security Compliance Requirements

The contractor shall implement the controls contained within the FedRAMP Cloud Computing Security Requirements Baseline and FedRAMP Continuous Monitoring Requirements for low and moderate impact system (as defined in FIPS 199). These documents define requirements for compliance to meet minimum Federal information security and privacy requirements for both low and moderate impact systems. While the FedRAMP baseline controls are based on NIST SP 800-53, Revision 4. The contractor shall generally, substantially, and in good faith follow FedRAMP guidelines and Security guidance. In situations where there are no procedural guides, the contractor shall use generally accepted industry best practices for IT security.

10) Required FedRAMP Policies and Regulations

The contractor shall comply with FedRAMP Security Assessment Framework – describing a general security Assessment Framework for the Federal Risk and Authorization Management Program (FedRAMP). This document details the security assessment process which must be used to achieve FedRAMP compliance. Download here:

https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Assessment_ Framework.pdf

11) Assessment and Authorization

DHS/ICE may choose to cancel the contract/award and terminate any outstanding orders if the contractor has its provisional authorization revoked and the deficiencies are greater than agency risk tolerance thresholds.

12) Assessment of the System

a) The contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement. The Level of Effort for the A&A is based on

REQUEST FOR PROPOSAL 70CDCR26R00000021

http://fedramp.gov/ https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Assessment_Framework.pdf https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Assessment_Framework.pdf the System’s NIST Federal Information Processing Standard (FIPS) Publication 199 categorization. The contractor shall create, maintain and update the following documentation using FedRAMP requirements and templates, which are available at http://FedRAMP.gov :

Privacy Impact Assessment (PIA) FedRAMP Test Procedures and Results Security Assessment Report (SAR) System Security Plan (SSP) IT System Contingency Plan (CP) IT System Contingency Plan (CP) Test Results POA&M Continuous Monitoring Plan (CMP) FedRAMP Control Tailoring Workbook Control Implementation Summary Table Results of Penetration Testing Software Code Review Interconnection Agreements/Service Level Agreements/Memorandum of

Agreements.

b) Information systems must be assessed by an accredited 3PAO whenever there is a significant change to the system’s security posture in accordance with the FedRAMP Continuous Monitoring Plan.

c) The Government reserves the right to perform penetration testing. If the Government exercises this right, the contractor shall allow Government employees (or designated third parties) to conduct security assessment activities to include control reviews in accordance with FedRAMP requirements (https://www.fedramp.gov/assets/resources/documents/CSP_Penetration_Test_Guidance.

pdf). Review activities include but are not limited to scanning operating systems, web applications, wireless scanning; network device scanning to include routers, switches, and firewall, and IDS/IPS; databases and other applicable systems, including general support structure, that support the processing, transportation, storage, or security of Government information for vulnerabilities.

d) Identified gaps between required FedRAMP Security Control Baselines and Continuous Monitoring controls and the contractor's implementation as documented in the Security Assessment Report shall be tracked by the contractor for mitigation in a POA&M document. Depending on the severity of the gaps, the Government may require them to be remediated before a provisional authorization is issued.

e) The contractor is responsible for mitigating all security risks found during A&A and continuous monitoring activities. All high-risk vulnerabilities must be mitigated within 30 days and all moderate risk vulnerabilities must be mitigated within 30 days from the date vulnerabilities are formally identified. The Government will determine the risk rating of vulnerabilities.

13) Authorization of System

The contractor shall provide access to the Federal Government, or their designee acting as their https://www.fedramp.gov/assets/resources/documents/CSP_Penetration_Test_Guidance.pdf https://www.fedramp.gov/assets/resources/documents/CSP_Penetration_Test_Guidance.pdf agent, when requested, in order to verify compliance with the requirements for an Information Technology security program. The Government reserves the right to conduct onsite inspections.

The contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review.

14) Reporting and Continuous Monitoring

Maintenance of the FedRAMP Provisional Authorization will be through continuous monitoring and periodic audit of the operational controls within a contractor’s system, environment, and processes to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to the FedRAMP PMO as required by FedRAMP Requirements. The submitted deliverables (or lack thereof) provide a current understanding of the security state and risk posture of the information systems. The deliverables will allow the FedRAMP JAB to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur. Contractors will be required to provide updated deliverables and automated data feeds as defined in the FedRAMP Continuous Monitoring Plan.

All deliverables shall be labeled appropriately (such as “Controlled Unclassified Information” (CUI)). External transmission/dissemination of labeled deliverables to or from a Government computer must be encrypted. Certified encryption modules must be used in accordance with FIPS PUB 140 (as amended), “Security requirements for Cryptographic Modules.”

15) Non-Repudiation

The Cloud Service Provider vendor shall provide a system that is capable of implementing NIST SP 800-53 Control AU-10 approved controls, which provides for origin authentication, data integrity, and signer non-repudiation. This binds the identity of the information producer with the information to and provides the means for authorized individuals to determine the identity of the producer of the information.

16) Identification and Authentication (Organizational Users)

The vendor shall support a secure, multi-factor method of remote authentication and authorization to identified Government Administrators that will allow Government designated personnel the ability to perform management duties on the system.

The vendor shall support multi-factor authentication including user ID and Password, digital certificate, PIV or smart card, PIN, tokens, etc.

17) Identification and Authentication (Non-Organizational Users)

The vendor shall support a secure, dual factor method of remote authentication and authorization to identified Vendor Administrators that will allow vendor-designated personnel the ability to perform management duties on the system.

18) Incident Reporting Timeframes

Cloud Service Providers are required to report all computer security incidents to the United States Computer Emergency Readiness Team (U.S.-CERT) in accordance with U.S.-CERT “Incident Categories and Reporting Timeframes” in, Appendix J, Table J-1 of NIST SP 800-61 (as amended), “Computer Security Incident Handling Guide.” Any Category (CAT) 1, CAT 2, or CAT 3 incident, must be reported immediately to their Information Systems Security Officer (ISSO) and the Senior Agency Information Security Officer (SAISO). Any incident that involves compromised Personally Identifiable Information (PII) must be reported to U.S.-CERT within 1 hour of detection regardless of the incident category reporting timeframe.

19) Media Transport

The vendor shall document activities associated with the transport of Federal agency information stored on digital and non-digital media and employ cryptographic mechanisms to protect the confidentiality and integrity of this information during transport outside of controlled areas.

Digital media, containing Federal agency information, that is transported outside of controlled areas must be encrypted using an approved encryption mode; non-digital media including but not limited to CD-ROM, floppy disks, etc., must be secured using the same policies and procedures as paper.

Media, containing Federal Agency information that is transported outside of controlled areas must ensure accountability. This can be accomplished through appropriate actions such as logging and a documented chain of custody form.

Federal Agency data that resides on mobile/portable devices (e.g., USB flash drives, external hard 12 drives, and SD cards) must be encrypted using an approved encryption mode. All Federal Agency data residing on laptop computing devices must be protected with approved encryption software.

20) Boundary Protection

The CSP/Reseller shall route all external connections through a Trusted Internet Connection

(TIC).

21) Protection of Information At Rest

The CSP shall provide security mechanisms for handling data at rest and in transit in accordance with FIPS 140-2.

22) Security Alerts, Advisories, and Directives

The CSP/Reseller shall provide a list of their personnel, identified by name and role, with system 1 administration, monitoring, and/or security responsibilities that are to receive security alerts, two advisories, and directives. This list shall include ICE SOC.

H.11. PRIVACY EXPECTATIONS

Government contractor employees do not have a right, nor should they have an expectation, of privacy while using Government provided devices at any time, including accessing the Internet and using e-mail and voice communications. To the extent that employees wish that their private activities remain private, they should avoid using the Government provided device for limited personal use. By acceptance of the government provided device, employees imply their consent to disclosing and/or monitoring of device usage, including the contents of any files or information maintained or passed -through that device.

H.12. CONTRACTOR IT SECURITY ACCREDITATION

Within 6 months after contract, the contractor shall submit written proof of IT Security accreditation to DHS for approval by DHS CO. Accreditation will proceed according to the criteria of DHS Sensitive System Policy Publication, 4300A (most current version) or any replacement publication, which the CO will provide upon request. This accreditation will include a final security plan, risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan.

This accreditation, when accepted by the CO, shall be incorporated into the contract as a compliance document. The contractor shall comply with the approved accreditation documentation.

H.13. SUPPLY CHAIN RISK MANAGEMENT TERMS AND CONDITIONS

The contractors supplying the Government hardware and software shall provide the manufacturer's name, address, state and/or domain of registration, and the Data Universal Numbering System (DUNS) number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNs number of those suppliers must also be provided.

Subcontractors are subject to the same general requirements and standards as prime contractors.

Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.

The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.

Contractors shall provide, implement, and maintain a Supply Chain Risk Management Plan that addresses internal and external practices and controls employed to minimize the risk posed by counterfeits and vulnerabilities in systems, components, and software.

The Plan shall describe the processes and procedures that will be followed to ensure appropriate supply chain protection of information system resources developed, processed, or used under this contract.

The Supply Chain Risk Management Plan shall address the following elements:

(i) How risks from the supply chain will be identified;

(ii) What processes and security measures will be adopted to manage these risks to the system or system components; and

(iii) How the risks and associated security measures will be updated and monitored.

The Supply Chain Risk Management Plan shall remain current through the life of the contract or period of performance. The Supply Chain Risk Management Plan shall be provided to the Contracting Officer Representative (COR/CO) 30 days post award.

The contractor acknowledges the Government's requirement to assess the Contractors Supply Chain Risk posture. The Contractor understands and agrees that the Government retains the right to cancel or terminate the contract, if the Government determines that continuing the contract presents a risk to national security.

The contractor shall disclose, and the Government will consider, relevant industry standard certifications, recognitions and awards, and acknowledgments.

The contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the CO. Contractors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.

The contractor shall be excused from using new OEM (i.e. "grey market, "previously used) components only with formal Government approval. Such components shall be procured from their original source and have them shipped only from manufacturers authorized shipment points.

For software products, the contractor shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “end of life"). Software updates and patches must be made available to the government for all products procured under this contract.

Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.

All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the contract, the period of performance, or one calendar year from the date the activity occurred.

These records must be readily available for inspection by any agent designated by the U.S.

Government as having the authority to examine them.

This transit…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .