2.2.1 Attach 1.pdf

PDF 392 KB Posted

Attached to
COMMUNITY RATING SYSTEM (CRS) PROGRAM Federal contract opportunity
Solicitation number
70FA6023R00000011
Issued by
Federal Emergency Management Agency

About this file

This document outlines a performance work statement for a firm-fixed price contract to provide Community Rating System program services to the Federal Emergency Management Agency. Key details include that the contractor shall conduct verification of community floodplain management activities and recommend CRS classifications; assist with CRS applications and modifications; provide training and technical assistance to stakeholders; and prepare communications materials. The contractor must follow all applicable FEMA policies and procedures, handle controlled unclassified information appropriately, and obtain favorable background investigations for applicable personnel.

View the file

Other files for this federal contract opportunity

Other files attached to COMMUNITY RATING SYSTEM (CRS) PROGRAM, newest first.
File Type Posted
70FA6023R00000011 A0004.pdf PDF
70FA6023R00000011 A0003.pdf PDF
2.4.1 - 70FA6023R00000011 A0002.pdf PDF
70FA6023R00000011 A0001.pdf PDF
2.2.1 Attach 3 Past Performance Questionnaire.doc DOC document
2.2.1 Attach 2.pdf PDF
2.2.1 - 70FA6023R00000011 9.12.23 Alt.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 1 – Performance Work Statement

FEDERAL EMERGENCY MANAGEMENT AGENCY

COMMUNITY RATING SYSTEM (CRS) PROGRAM

PERFORMANCE WORK STATEMENT (PWS)

September 7, 2023

1.0 GENERAL

This is non-personal services contract to provide Community Rating System services. The Government will not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.

1.1 Background: The FEMA National Flood Insurance Program’s (NFIP) Community Rating System (CRS) is administered by the U.S. Department of Homeland Security’s (DHS), Federal Emergency Management Agency (FEMA). The CRS is a voluntary insurance rating program implemented in 1990 to recognize community floodplain management activities that exceed the minimum floodplain management standards of the NFIP. The National Flood Insurance Reform Act of 1994 codified the CRS within the NFIP.

The CRS directly supports Goal 1 of FEMA’s 2018–2022 Strategic Plan. This goal, to Build a Culture of Preparedness, is implemented throughout the CRS.

(a) Objective 1.1: Incentivize Investments that Reduce Risk, Including Pre-Disaster

Mitigation, and Reduce Disaster Costs at All Levels is achieved through numerous floodplain management practices recognized by the CRS.

(b) Objective 1.2: Close the Insurance Gap is fostered through the CRS’s credit for flood insurance promotion and the series of credits for public information.

The CRS is implemented to enable the nationwide reduction of disaster risk through a multidisciplinary, collaborative approach involving federal, state, and local officials; professionals with expertise in floodplain management; insurance industry and underwriting experts; and academic researchers. The CRS leverages a whole-community approach to advancing risk management capability.

1.2 Objectives: Under CRS, flood insurance premiums for policyholders in a CRS-participating community are reduced to reflect the added flood risk protection that results from community activities that meet the three goals of CRS:

(1) reduce and avoid flood damage to insurable property;

(2) strengthen and support the insurance aspects of the NFIP; and

(3) encourage a comprehensive approach to floodplain management.

1.3 Scope: The Contractor shall furnish all personnel, supervision, equipment, supplies, facilities, materials, and services (except as may be expressly set forth in the contract as furnished by the Government) to fulfill the requirements of this PWS dated 09/07/2023 and the QASP dated 01/12/2023.

1.4 Period of Performance: The period of performance shall be for one (1), 6-month base period, two (2), additional 6-month option periods. three (3), 12-month option periods, and concluding with one (1), 6-month option period. The total duration of the contract is 5 years. The period of performance will be as follows:

Base Period: 6-months after contract award Option Period-1: 6-months Option Period-2: 6-months Option Period-3: 12-months Option Period-4: 12-months Option Period-5: 12-months Option Period-6: 6-months

1.5 Quality Assurance: The Government will evaluate the Contractor’s performance under this contract in accordance with the terms of the contract, Quality Assurance Surveillance Plan (QASP) and the requirements of this PWS.

1.6 Recognized Holidays: The Contractor is not required to perform service on holidays:

New Year’s Day Labor Day Martin Luther King Jr.’s Birthday Columbus Day President’s Day Veteran’s Day Memorial Day Thanksgiving Day Juneteenth Day Christmas Day Independence Day

1.7 Hours of Operation: The Contractor shall conduct business for the full duration of FEMA core hours of 9:00

AM to 5:30PM Eastern time, Monday thru Friday, except Federal holidays. Contractor staff may be required to conduct business beyond the core hours referenced above including after hour and weekend support. The Contractor may permit flexible working schedules for its employees and the employees of its subcontractors;

provided, however, the Contractor must maintain, at all times, an adequate workforce for the uninterrupted performance of all tasks defined within this PWS during FEMA core business hours. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.

1.8 Place of Performance: This contract is for nationwide CRS support including U.S. Territories and Tribal

Nations. This includes but is not limited to Contractor Facilities and approved telework locations, FEMA Headquarters located in Washington, DC, FEMA Regional Offices, and participating communities. All telework must be pre-approved by the Contracting Officer Representative (COR).

1.9 Type of Contract: This is a firm-fixed price contract.

1.10 Remote Post Award Conference/Periodic Progress Meetings: The Contractor shall attend, remotely, all required post award conferences and progress meetings, to be held no more than once per quarter. Attendance at all meetings shall be at no additional cost to the government.

1.11 Key Personnel: Key Personnel are considered essential to the work being performed under this contract.

The Contractor’s Project Manager/Program Director is designated as a Key Personnel. The desired qualifications for the Project Manager/Program Director are 10 years of CRS or comparable program delivery experience;

experience with annual program review and continuous improvement; budget formulation and financial controls;

and post-secondary education with a degree or degrees in any of the following: planning, business administration, public policy, environmental sciences, or quantitative analytics such as math or insurance actuary studies. This is the only position designated as a Key Personnel.

Before replacing any individual designated as Key Personnel by the Government, the Contractor shall notify the Contracting Officer no less than 30 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes shall possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor shall not replace Key Personnel without approval from the Contracting Officer.

1.12 Identification of Contractor Employees: All Contractor personnel attending meetings and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. Contractor personnel will be required to obtain, use, and display a Personal Identity Verification (PIV) card in government facilities and a contractor identification badge in performance of their service in the field.

1.13 Contractor Travel: Contractor travel may be required to support this requirement and included in the fixed price of each CLIN. Travel expenses shall not exceed those in the prevailing per diem rates in accordance with GSA Joint Travel Regulation.

1.14 Organizational Conflict of Interest: As defined in FAR Subpart 9.5, the Contractor shall notify the Contracting Officer immediately whenever it becomes aware of any actual or potential Organizational Conflict of Interests (OCI) and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such

OCI.

The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer. In the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements (limitation of future contracting), which may be affected by the OCI. The Contractor will not have any access to source selection sensitive information and/or proprietary data under this contract.

2.0 GOVERNMENT FURNISHED ITEMS AND SERVICES:

2.1. Services: The Government will provide basic services for Government furnished equipment such as phones, desks, utilities, information technology, and general office supplies while working in Government facilities.

2.2 Facilities: Basic facilities such as workspace and its associated operating requirements (i.e., phones, desks, utilities, information technology, and general office supplies) will be provided while working in Government facilities. Teleworkers will only use government-furnished equipment to remotely access the Government network.

2.3 FEMA CRS Website: The Government shall be solely responsible for FEMA’s CRS program website. The Government shall ensure that FEMA’s CRS program website is maintained with current information and resources including, but not limited to, training videos, forms, guides, checklists, and other CRS-related materials.

2.4 Equipment: The Government will provide basic services to phones, desks, utilities, information technology, and general office supplies while working in Government facilities. Teleworkers will only use government furnished equipment to remotely access the Government network.

2.4.1 The Government will provide laptops and facilitate any required background checks and security approvals in order to allow the Contractor to access the Government network remotely to meet this requirement. However, the Contractor’s information system will be used to gather and analyze data and generate findings relative to community verifications and data analytics subject to the conditions set forth in Homeland Security Acquisition Regulation (HSAR) Class Deviation 15-01, Revision 1: Safeguarding of Controlled Unclassified Information.

3.0 SPECIFIC TASKS / REQUIREMENTS

3.1 Task 1: Community Activities Verification Process and Internal Stakeholder Training: Conduct verification of community activities to reduce flood damage and recommend CRS classification. The firm-fixed price includes travel for approximately 20 round trips per month in support of this task/CLIN.

The Contractor shall:

3.1.1 Conduct periodic verifications of community floodplain management activities to reduce flood damage and recommend CRS classification.

3.1.1.1 Assist in updating and preparing the CRS application and forms, including materials for a simplified Class 9 participation process. The simplified Class 9 process is based upon the CRS application as related to each state.

3.1.1.2 Review approximately 25 community applications submitted for CRS classification.

3.1.1.3 Conduct approximately 175 community cycle and modification applications.

3.1.1.4 Review and analyze data collected in Tasks 3.1.1.1 and 3.1.1.2.

3.1.1.5 Process compiled credit components of the CRS classification recommendations from Task

3.1.1.3 to recommend community activity scores and classifications (for final approval by FEMA).

3.1.1.6 Prepare and submit, to FEMA, a verification report for each community processed in Task 3.1.1.4.

3.1.1.7 Deliver a spreadsheet containing CRS credit activity, element, and other rating components of the CRS classification recommendations and verification recommendations using a format as prescribed by FEMA. FEMA may agree to an alternate format based on collaboration with the Contractor. The precise delivery date will be determined by the FEMA Program Manager and relayed to Contractor at least 10 business working days in advance of the delivery date need.

3.1.1.8 Assemble and provide to FEMA a spreadsheet containing community official contact information identifying community Chief Executive Officer and/or CRS Coordinator to include name, title, business address (property or mailing), phone number(s) (facsimile, telephone, or cellular), and email address. The Contractor shall fully comply with FAR 52.224-1, Privacy Act Notification; FAR 52.224-2, Privacy Act; Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act; FAR 52.224-3, Privacy Act Training; Information Technology Security Awareness Training (July 2023) as referenced in this PWS or contract clauses.

3.1.2 Conduct community eligibility and program participation recommendations to support Government determinations.

3.1.2.1 Receive and review approximately 600 community recertification documents for participating

CRS communities who are not scheduled to undergo a CRS cycle verification visit review during the calendar year and are scheduled to recertify during the applicable quarter of the year.

3.1.2.2 Receive, scan and review construction certificates for approximately 800 communities and prepare and distribute findings to the FEMA Regional Offices the CRS Elevation Certificate Evaluation Report for each community upon completion of the certificate review and provide to FEMA HQ in a prescribed National Violations Tracker format as a document that identifies buildings with possible floodplain management violations.

3.1.2.3 Upon request by FEMA Regional offices, with concurrence from FEMA/COR, complete community floodplain management program assessments, which may be used for CRS participation eligibility assessments, for up to 10 communities. Assessment reports with the findings for each community shall be sent to the FEMA Regional office.

3.1.3 Review and verify new community activities that are implemented for potential CRS credit and revised CRS Classification modifications for up to 25 participating CRS communities. This task is contingent upon community request; however, the Contractor shall notify communities should Contractor staff become aware of potential CRS Classification modification opportunities.

3.1.4 Conduct 100% quality review of all completed gradings. Concurrent with task 3.1.1.5 and provide a CRS Class Change Report and a CRS participation master list of all CRS communities in a Microsoft Excel spreadsheet or other format as approved by FEMA. The Contractor shall manage and store the data in a non-proprietary format to be available upon request by FEMA.

3.1.5 Conduct data management and analytics to monitor CRS program trends, including impact on flood insurance rates that will include use of the NFIP PIVOT data system.

3.1.5.1 Provide routine reports on verified activity scores for current and past CRS program data sets as requested by the Government.

3.1.5.2 Manage data to provide reports as necessary that reflect program trends as requested by the Government.

3.1.6 Prepare a description of CRS community verification and element documentation and data exchanges between communities and FEMA that would allow validation and verification of CRS activities and elements. This description is intended to provide a comprehensive reference source, such as a handbook/manual, of all workflows associated information exchange between FEMA and the community to assess and verify implementation of all CRS activities. These workflow descriptions would support and compliment the NFIP CRS Coordinator’s Manual. Draft documents will be coordinated with the COR on a quarterly basis to show progress toward a final document that would be completed within twelve months.

3.1.7 Special Note: Currently, the Government uses the Community Information System (CIS) as a repository to maintain historical records of key actions or events, such as verifications visits, for each CRS community. A CIS modernization/change initiative is planned at some stage during the period of performance for this contract. As a result, there could be changes that impact this contract, such as the type of CRS data collected and entered into CIS or added functionality to expand the capability of CIS to support the CRS program. It is anticipated that a priced, bilateral modification would be negotiated to accommodate the additional scope of work, as appropriate.

3.2 Task 2: CRS Continuous Improvement Process: Recommend improvements to the CRS Program for implementation during the performance period of the contract.

3.2.1 Anticipate natural changes to floodplains and changes in floodplain management practices and recommend actions to mitigate adverse impacts.

3.2.2 Assist FEMA in refining and simplifying CRS operating procedures for implementation of the current program during the performance period of the contract.

3.2.3 Monitor and seek continuous performance improvement of Contractor’s field work activities for implementation of the current program during the performance period of the contract.

3.2.4 Recommend and execute FEMA approved enhancements to processes, tools, and templates for implementation of the current program during the performance period of the contract.

3.2.5 Updated and revise the CRS Coordinator’s Manual when FEMA implements changes to the CRS program for use during the performance period of the contract.

3.2.6 Organize plan, attend, and facilitate three (3) in-person meetings of the Community Rating System Task Force (CRSTF), intended to be conducted in the January timeframe, and to be conducted with the assistance of a designated facilitator for implementation of the current program during the performance period of the contract.

3.3 Task 3: Training and Technical Assistance to External Stakeholders: Conduct training and technical assistance in implementing credited flood protection activities. The firm-fixed price includes travel for approximately 6 round trips per month in support of this Task/CLIN.

3.3.1 Provide training to CRS stakeholders, including local and state government officials, Federal agency officials, non-governmental organizations, and others in CRS activities, operations, and procedures.

Annually, this includes approximately three 4-day courses at EMI, three field deployed 4-day courses, and five 2-day courses to be conducted at various locations nationwide, to be determined in consult with FEMA headquarters, FEMA Regional Offices and the Contractor (with flexibility to conduct such sessions virtually).

3.3.2 Assist local officials in preparing CRS applications for newly participating communities and modifications for existing CRS communities.

3.3.3 Support stakeholder outreach and communications to promote awareness of the CRS program.

3.3.4 Participate in planning and strategy discussions to provide consistent communications and message delivery across stakeholders and related documentation as mutually agreed upon.

3.3.5 Conduct 4-day CRS formal training and coordination meetings - to include face-to-face classroom venues, with the flexibility to conduct such meetings virtually , up to 2 times annually. These are to include HQ office staff and FEMA regional, Contractor central office staff, field staff, and specialized subcontractor staff.

3.3.6 Provide facilitation between FEMA and CRS communities and technical support to CRS communities to monitor, assess and deliver data to FEMA related to repetitive loss properties in CRS communities.

3.4 Task 4: Communications: Prepare and provide a range of communications materials pertaining to the

CRS program and its operations.

3.4.1 Provide CRS program materials for broad stakeholder use to include bimonthly newsletters and fact sheets, presentations and program guidance manuals as mutually agreed to in writing by FEMA and the Contractor. The Contractor shall get COR approval of such program materials before release to the public if it has any appearance of representation of FEMA.

3.4.2 Prepare and provide draft program materials for FEMA use such as papers, reports, briefing materials, draft responses for information oversight agency strategic planning and multi-year program assessments and email responses of a complex nature, as reasonably requested by FEMA and agreed to in writing by the Contractor.

3.4.3 Prepare and provide to FEMA the spreadsheet and synopsis containing certain compiled credit components referenced in 3.1.1.6 above, containing the compiled components of the CRS classification recommendations that is used to support community CRS classifications recommendations.

3.4.4 Update FEMA CRS website using GFE in coordination with the COR. This may include posting new documents, replacing outdated documents, and adding useful links.

3.4.5 Assist with the updating and preparation NFIP CRS Coordinator’s Manual. The CRS Coordinator’s Manual provides the comprehensive technical explanation of the CRS program for communities and other CRS program stakeholders.

3.4.6 Participate in 2 to 4 national conferences and tending a CRS exhibit/booth, to include suitable branding exhibit materials and display, in coordination with the COR.

3.4.7 Update, revise, and print the CRS Local Officials Guide to be made available at conferences, events, and other CRS stakeholders forums.

4.0 DELIVERABLES SCHEDULE

Deliverable Frequency Medium/Format Submit To Biweekly Meeting Every two week Determined by COR COR

Written Quarterly Status Report

Last calendar day every three months

Determined by COR COR

Quarterly Meetings Every three months Determined by COR COR

Verification Reports / Community Notification Letters

Monthly Determined by COR COR

Spreadsheet Containing Compiled Credit Components as Described in the NFIP CRS Coordinator’s Manual, of the CRS Classification Recommendation

Every six months Determined by COR COR

National Tracker Potential Violations Report

Quarterly Determined by COR COR

CRS Class Change Report Every six months Determined by COR COR

Spreadsheet of participating CRS community official contact information of CEO and CRS Coordinator.

Every six months Determined by COR COR

Comprehensive reference source of CRS activities and elements workflow description

Final draft due within one year

Determined by COR COR

CRS Task Force Meeting agendas, agenda packets and summary minutes of meetings.

3x per year as per date mutually agreed upon by FEMA and the Contractor

Determined by COR COR

CRS Training materials for 4-day EMI and field deployed CRS courses and 2-day field deployed courses

Per Course 4-day course material is maintained in FEMA’s LCMS. Additional course hand out material and student exercise material

COR

will be in MS Word format.

Contractor/FEMA Coordination meetings (Task

3) Agenda, all training material, meeting summary minutes.

2X per year Determined by COR Determined by COR

CRS Newsletter Bi- Monthly Digital for posting on FEMA website

COR

CRS Fact Sheets, presentations, and program guidance as determined necessary and as mutually agreed upon by FEMA and the Contractor

Ad-Hoc Determined by COR Determined by COR

5.0 APPLICABLE PUBLICATIONS/REFERENCES: The Contractor must abide by all statutes, applicable regulations, publications, manuals, and federal policies, and procedures referenced herein.

• CRS Coordinator’s Manual

• CRS Biennial Report to Congress

• CRS Communities Credit Files (Community Rating System | FEMA.gov)

6.0 OTHER TERMS, CONDITIONS, AND PROVISIONS

I. RECORDS MANAGEMENT OBLIGATIONS

A. Applicability

This clause applies to all Contractors whose employees create, work with, or otherwise handle Federal https://www.fema.gov/floodplain-management/community-rating-system records, as defined in Section B, regardless of the medium in which the record exists.

B. Definitions

“Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

The term Federal record:

• includes FEMA records;

• does not include personal materials;

• applies to records created, received, or maintained by Contractors pursuant to their FEMA contract; and

• may include deliverables and documentation associated with deliverables.

C. Requirements

1. Contractor shall comply with all applicable records management laws and regulations, as well as National

Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C.

552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C.

chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

4. FEMA and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of FEMA or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to FEMA. The agency must report promptly to NARA in accordance with 36 CFR 1230.

5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records, or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the PWS. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to FEMA control, or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the SOW. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).

6. The Contractor (and any sub-contractor) is required to abide by Government and FEMA guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with FEMA policy.

8. The Contractor shall not create or maintain any records containing any non-public FEMA information that are not specifically tied to or authorized by the contract.

9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.

II. DHS ENTERPRISE ARCHITECTURE COMPLIANCE

All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures.

Specifically, the Contractor shall comply with the following Homeland Security Enterprise Architecture (HLS EA) requirements:

(a) All developed solutions and requirements shall be compliant with the HLS/FEMA EA.

(b) All IT hardware and/or software shall be compliant with the HLS/FEMA EA Technical Reference Model (TRM) Standards and Products Profile.

(c) Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.

(d) Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-011 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

(e) Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S.

Government Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

52.224-3 Privacy Training – Alternate I (DEVIATION)

(a) Definition. As used in this clause, personally identifiable information means information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual. (See Office of Management and Budget (OMB) Circular A–130, Managing Federal Information as a Strategic Resource).

(b) The Contractor shall ensure that initial privacy training, and annual privacy training thereafter, is completed by contractor employees who—

(1) Have access to a system of records;

(2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information on behalf of an agency; or

(3) Design, develop, maintain, or operate a system of records (see also FAR subpart 24.1 and 39.105).

(c) The contracting agency will provide initial privacy training, and annual privacy training thereafter, to Contractor employees for the duration of this contract. Contractor employees shall satisfy this requirement by completing Privacy at DHS: Protecting Personal Information accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Training shall be completed within 30 days of contract award and be completed on an annual basis thereafter not later than October 31st of each year.

(d) The Contractor shall maintain and, upon request, provide documentation of completion of privacy training to the Contracting Officer.

(e) The Contractor shall not allow any employee access to a system of records, or permit any employee to create, https://www.dhs.gov/sites/default/files/publications/mgmt_directive_103_01_enterprise_data_management_policy.pdf https://www.dhs.gov/sites/default/files/publications/mgmt_directive_103_01_enterprise_data_management_policy.pdf collect, use, process, store, maintain, disseminate, disclose, dispose or otherwise handle personally identifiable information, or to design, develop, maintain, or operate a system of records unless the employee has completed privacy training, as required by this clause.

(f) The substance of this clause, including this paragraph (f), shall be included in all subcontracts under this contract, when subcontractor employees will—

(1) Have access to a system of records;

(2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information; or

(3) Design, develop, maintain, or operate a system of records.

(End of clause)

3052.204-71 Contractor employee access (JULY 2023).

(a) Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:

(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical Facility Anti-Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual “Safeguarding Information Designated as Chemical-Terrorism Vulnerability Information” dated September 2008);

(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (title XXII, subtitle B of the Homeland Security Act of 2002 as amended through Pub. L. 116– 283), PCII’s implementing regulations (6 CFR part 29), the PCII Program Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security, the PCII Program Manager, or a PCII Program Manager Designee;

(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive Security Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or designee), including Department of Homeland Security MD 11056.1, “Sensitive Security Information (SSI)” and, within the Transportation Security Administration, TSA MD 2810.1, “SSI Program”;

(4) Homeland Security Agreement Information means information the Department of Homeland Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement. The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion Center Initiative and activities for cyber information sharing consistent with the Cybersecurity Information Sharing Act of 2015;

(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;

(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;

(7) Information Systems Vulnerability Information (ISVI) means:

(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release; switching, router, and gateway information; interconnections and access methods; and mission or business use/need. Examples of ISVI are systems inventories and enterprise architecture models. Information pertaining to national security systems and eligible for classification under Executive Order 13526 will be classified as appropriate; and/or

(ii) Information regarding developing or current technology, the release of which could hinder the objectives of the Department, compromise a technological advantage or countermeasure, cause a denial of service, or provide an adversary with sufficient information to clone, counterfeit, or circumvent a process or system;

(8) Operations Security Information means Department of Homeland Security information that could be collected, analyzed, and exploited by a foreign adversary to identify intentions, capabilities, operations, and vulnerabilities that threaten operational security for the missions of the Department;

(9) Personnel Security Information means information that could result in physical risk to Department of Homeland Security personnel or other individuals whom the Department is responsible for protecting;

(10) Physical Security Information means reviews or reports illustrating or disclosing facility infrastructure or security vulnerabilities related to the protection of Federal buildings, grounds, or property. For example, threat assessments, system security plans, contingency plans, risk management plans, business impact analysis studies, and certification and accreditation documentation;

(11) Privacy Information includes both Personally Identifiable Information (PII) and Sensitive Personally Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual’s identity, either alone, or when combined with other information that is linked or linkable to a specific individual; and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. To determine whether information is PII, DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual. Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.

(i) Examples of stand-alone PII that are particularly sensitive include: Social Security numbers (SSNs), driver’s license or State identification numbers, Alien Registration Numbers (A-numbers), financial account numbers, and biometric identifiers.

(ii) Multiple pieces of information may present an increased risk of harm to the individual when combined, posing an increased risk of harm to the individual. SPII may also consist of any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:

(A) Truncated SSN (such as last 4 digits);

(B) Date of birth (month, day, and year);

(C) Citizenship or immigration status;

(D) Ethnic or religious affiliation;

(E) Sexual orientation;

(F) Criminal history;

(G) Medical information; and

(H) System authentication information, such as mother’s birth name, account passwords, or personal identification numbers (PINs).

(iii) Other PII that may present an increased risk of harm to the individual depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number.

The context includes the purpose for which the PII was collected, maintained, and used. This assessment is critical because the same information in different contexts can reveal additional information about the impacted individual.

(b) Information Resources means information and related resources, such as personnel, equipment, funds, and information technology.

(c) Contractor employees working on this contract must complete such forms as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability. Completed forms shall be submitted as directed by the Contracting Officer. Upon the Contracting Officer’s request, the Contractor’s employees shall be fingerprinted or subject to other investigations as required. All Contractor employees requiring recurring access to government facilities or access to CUI or information resources are required to have a favorably adjudicated background investigation prior to commencing work on this contract unless this requirement is waived under Departmental procedures.

(d) The Contracting Officer may require the Contractor to prohibit individuals from working on the contract if the Government deems their initial or continued employment contrary to the public interest for any reason, including, but not limited to, carelessness, insubordination, incompetence, or security concerns.

(e) Work under this contract may involve access to CUI. The Contractor shall access and use CUI only for the purpose of furnishing advice or assistance directly to the Government in support of the Government’s activities, and shall not disclose, orally or in writing, CUI for any other purpose to any person unless authorized in writing by the Contracting Officer. For those Contractor employees authorized to access CUI, the Contractor shall ensure that these persons receive initial and refresher training concerning the protection and disclosure of CUI.

Initial training shall be completed within 60 days of contract award and refresher training shall be completed every 2 years thereafter.

(f) The Contractor shall include this clause in all subcontracts at any tier where the subcontractor may have access to government facilities, CUI, or information resources.

ALTERNATE I (JULY 2023)

When the contract will require Contractor employees to have access to information resources, add the following paragraphs:

(g) Before receiving access to information resources under this contract, the individual must complete a security briefing; additional training for specific categories of CUI, if identified in the contract; and any nondisclosure agreement furnished by DHS. The Contracting Officer’s Representative (COR) will arrange the security briefing and any additional training required for specific categories of CUI.

(h) The Contractor shall have access only to those areas of DHS information resources explicitly stated in this contract or approved by the COR in writing as necessary for performance of the work under this contract. Any attempts by Contractor personnel to gain access to any information resources not expressly authorized by the terms and conditions in this contract, or as approved in writing by the COR, are strictly prohibited. In the event of violation of this provision, DHS will take appropriate actions with regard to the contract and the individual(s) involved.

(i) Contractor access to DHS networks from a remote location is a temporary privilege for mutual convenience while the Contractor performs business for DHS. It is not a right, a guarantee of access, a condition of the contract, or government-furnished equipment (GFE).

(j) Contractor access will be terminated for unauthorized use. The Contractor agrees to hold and save DHS harmless from any unauthorized use and agrees not to request additional time or money under the contract for any delays resulting from unauthorized use or access.

(k) Non-U.S. citizens shall not be authorized to access or assist in the development, operation, management, or maintenance of Department IT systems under the contract, unless a waiver has been granted by the Head of the Component or designee, with the concurrence of both the Department’s Chief Security Officer (CSO) and the Chief Information Officer (CIO) or their designees. Within DHS Headquarters, the waiver may be granted only with the approval of both the CSO and the CIO or their designees. In order for a waiver to be granted:

(1) There must be a compelling reason for using this individual as opposed to a U.S. citizen; and

(2) The waiver must be in the best interest of the Government.

(l) Contractors shall identify in their proposals the names and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the Contracting Officer.

Alternate II (JULY 2023)

When the Department has determined contract employee access to controlled unclassified information or Government facilities must be limited to U.S. citizens and lawful permanent residents, but the contract will not require access to information resources, add the following paragraphs:

(g) Each individual employed under the contract shall be a citizen of the United States of America, or an alien who has been lawfully admitted for permanent residence as evidenced by a Permanent Resident Card (USCIS I- 551). Any exceptions must be approved by the Department's Chief Security Officer or designee.

(h) Contractors shall identify in their proposals, the names and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the Contracting Officer.

3052.204-72 Safeguarding of Controlled Unclassified Information (JULY 2023)

(a) Definitions. As used in this clause—

Adequate Security means security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls.

Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:

(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical Facility Anti-Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual “Safeguarding Information Designated as Chemical-Terrorism Vulnerability Information” dated September 2008);

(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (title XXII, subtitle B of the Homeland Security Act of 2002 as amended through Pub. L. 116– 283), PCII’s implementing regulations (6 CFR part 29), the PCII Program Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security, the PCII Program Manager, or a PCII Program Manager Designee;

(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive Security Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or designee), including Department of Homeland Security MD 11056.1, “Sensitive Security Information (SSI)” and, within the Transportation Security Administration, TSA MD 2810.1, “SSI Program”;

(4) Homeland Security Agreement Information means information the Department of Homeland Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement. The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion Center Initiative and activities for cyber information sharing consistent with the Cybersecurity Information Sharing Act of 2015;

(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;

(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;

(7) Information Systems Vulnerability Information (ISVI) means:

(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release; switching, router, and gateway information; interconnections and access methods; and mission or business use/need. Examples of ISVI are systems inventories and enterprise architecture models. Information pertaining to national security systems and eligible for classification under Executive Order 13526 will be classified as appropriate; and/or

(ii) Information regarding developing or current technology, the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .