2.2.1_Attachment A_SOW for Hosting Services_04.28.2021_FINAL.pdf
PDF 322 KB Posted
- Attached to
- ICE/HSI Hosting Services Federal contract opportunity
- Solicitation number
- 70CTD021Q00000096
- Issued by
- Immigration and Customs Enforcement
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 2.2.1_Attachment B_Terms and Conditions_FINAL 04.28.2021.pdf | ||
| 2.2.1_Combined Synopsis and RFQ Letter_FINAL_04.28.2021.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment A
STATEMENT OF WORK (SOW)
FOR
U.S. Department of Homeland Security Immigration and Customs Enforcement, Homeland Security Investigations, Global Trade Investigations Division, Intellectual Property Rights Center
1.0 GENERAL
1.1 BACKGROUND
This SOW outlines the support and hosting services required for initiatives at the U.S. Department of Homeland Security (DHS)/Immigration and Customs Enforcement (ICE)/Homeland Security Investigations (HSI)/Global Trade Investigations Division (GTID)/ Intellectual Property Rights Center (IPR Center). The IPR Center stands at the forefront of the U.S. Government’s response to global intellectual property (IP) theft. The IPR Center uses the expertise of its 25 member agencies to share information, develop initiatives, coordinate enforcement actions, and conduct investigations related to IP theft and trade enforcement. Through this strategic interagency partnership, the IPR Center protects the public’s health and safety, the U.S. economy, and the war fighters. The IPR Center employs a strategic approach to combat IP theft. This approach includes:
• Investigation – Identifying, disrupting, prosecuting and dismantling criminal organizations involved in the manufacture and distribution of counterfeit products.
• Interdiction - Using focused targeting and inspections to keep counterfeit and pirated goods out of the U.S. supply chains, markets and streets.
• Outreach and Training - Providing training for domestic and international law enforcement to build stronger enforcement capabilities worldwide.
The IPR Center also manages and supports the ICE/HSI/GTID commercial fraud program, focusing on commercial imports that are based on false statements and deceptive business practices. By combining the IP theft and commercial fraud programs at the IPR Center, ICE/HSI is able to take a comprehensive approach to addressing these vulnerabilities.
Through Operation In Our Sites (IOS), the IPR Center addresses intellectual property theft vulnerabilities present through the internet, which counterfeiters use to facilitate the sale of counterfeit and pirated merchandise. The IPR Center launched IOS in June 2010 and under this operation, ICE/HSI identifies and targets internet website domain names that were distributing and selling only infringing goods.
ICE/HSI then uses the criminal process to seize the infringing domain names. When a domain is seized criminally under IOS, viewers are redirected to a criminal seizure banner which provides information regarding the reason for the seizure. Viewers can also be redirected to a public service announcement regarding the dangers of counterfeiting. As of October 1, 2020, the IPR Center’s seizure banner had been visited by over 181 million internet users.
Criminal organizations, however, have adapted to this methodology and now have inactive and/or dormant domain names ready to be activated when their active domain names are seized, requiring the IPR Center to shift its approach. Therefore, in addition to seizing domains through the criminal process, the IPR Center has partnered with industry because the IPR Center has found that industry’s use of the civil or legal administrative process is more efficient at shutting down infringing websites than the criminal process. As an example of this, in fiscal year 2020, eight (8) rights holders and two (2) industry organizations, working in coordination with the IPR Center, shut down 79,026 websites.
Because the criminal seizure banners cannot be utilized in the civil/administrative process, the IPR Center has created an Anti-Counterfeiting and Piracy (ACP) banner which can be used by the rights holders when they seize a website through the civil or administrative process. The ACP banner is an informational banner which provides a conduit for the public to provide information on IPR violations to the IPR Center. It is anticipated that like the criminal seizure banners, the ACP banner will also be an effective method of educating the public about the serious problem of IP theft and will be viewed by even more internet users than the IPR Center’s criminal seizure banner.
Historically, when ICE/HSI criminally seized a website domain, the court order directed the Registry to redirect hits to the domain to a specific IP Address that was affiliated with the hosting service’s server.
Depending upon what the IPR Center instructs, the hosting service would then show one of the criminal seizure banners or redirect again to a Public Service Announcement regarding the dangers of counterfeiting.
The redirection of the seized and/or shut-down domains is a critical component to the IPR Center’s outreach and public education. It also serves as a deterrent for those considering selling counterfeit goods in the future.
1.2 SCOPE
The Contractor shall provide technical support, to include retrieval of data regarding visitors to the seized domain names, as well as maintenance pertaining to seized websites and/or shutdown websites. The contractor shall also provide technical support for the utilization of the criminal seizure banners, the ACP banner, and Public Service Announcement(s).
1.3 OBJECTIVE
The ICE/HSI/Global Trade Investigations Division (GTID)/IPR Center will have its criminal seizure banners and ACP banner hosted by an independent server, separate of any Government computer systems. The server host will collect data regarding the domain names and banners, as well as on the visitors to the domain names.
1.4 APPLICABLE DOCUMENTS
1.4.1 Compliance Documents
• N/A
1.4.2 Reference Documents
• N/A
2.0 SPECIFIC REQUIREMENTS/TASKS
The Contractor will provide an independent server to host the criminal seizure banners and ACP banner separate of any Government computer system. The dedicated server minimally will have a bandwidth of 100MB, dedicated server web server memory of 1TB, dedicated server SFTP server memory of 2TB, Dual Core, 12GB of RAM with 2 Quad Core and take over domain name www.seizedservers.com which contains the websites seized by ICE, HSI, the IPR Center’s seizure banners, ACP banner and list of websites seized by rights holders. This includes the following:
2.1 Criminal seizure banners
• Host the criminal seizure banners on an independent server.
file://hqnas/SHARED/G-A/G-ACS/CAAT%20Team/TOOLBOX/SCOPE%20PARAGRAPHS.doc http://www.seizedservers.com/ o Includes creating and maintaining the banner as needed;
o Includes name server;
o Includes web server; and o Includes Secure File Transfer Protocol (SFTP) server (secured by user name and password).
• Ensure that the lists of seized domain names are directed to this banner, as directed by the IPR
Center.
• This includes domain names that have been seized in past, as well as ones that may be seized in the future.
2.2 Anti-Counterfeiting and Piracy (ACP) banner
• Host the ACP banner on an independent server.
• Includes creating and maintaining the banner as needed;
• Includes name server;
• Includes web server,
• Includes SFTP server.
• Includes Secure File Transfer Protocol (SFTP) server (secured by user name and password).
• Ensure that the current lists of shutdown domain names are directed to this banner, as directed by the IPR Center.
• This includes domain names that have been shut down in the past, as well as ones that may be shut down in the future.
2.3 Public Service Announcement (PSA)
• Host the PSA on an independent server.
• Ensure that the current lists of seized domain names and/or shutdown domain names are directed to the PSA, as directed by the IPR Center.
2.4 Registries and Registrars
• Interact with Registries (e.g. VeriSign) and other registrars as originally outlined by the IPR
Center in delineated format;
2.5 Data
• Collect data regarding domain names, banner hits, PSA hits and capture the visitor’s IP address with time stamp, referring URL and user agent information, as instructed by the IPR Center
• Provide statistics as requested of hits to the respective banners (broken down by individual website) and the PSA
• When a problem arises in the collection of data on the seized websites, the Contractor will identify the problem and takes appropriate steps to correct the problem. The Contractor will notify the IPR Center within 24 hours of the issue and the corrective measure taken.
• Contractor will provide monthly statistical reports, and supplemental statistical reports as requested, to the IPR Center by creating programs to retrieve the hits information for each seized website from the Contractor’s server and transfer the statistic to an Excel spreadsheet listing the name of the seized website and the number of hits to each website for the past month. Contractor shall update the list of seized websites on the Excel spreadsheet as needed or as requested by the IPR Center. The monthly statistical report will contain a running count of the total number of hits to the IPR Center’s seizure banner since the operation’s inception in 2010. The Contractor shall coordinate with the previous Contractor in transfer of data from the previous contractor’s server to the new contractor’s server. New programs created by the contractor in fulfillment of this contract along with the source codes will become property of ICE, HSI and the IPR Center. The contractor shall provide instructions to ICE, HSI, GTID, and IPR Center personnel in the operation, maintenance and updating of the programs.
• Contractor shall provide a monthly report, or as needed, to the IPR Center, ensuring that the seized websites are directed to the correct seizure banner. The Contractor shall create a program that will provide a report that lists each website directed to the IPR Center’s seizure banner. New programs created by the Contractor in fulfillment of this Purchase Order along with the source codes will become property of ICE, HSI and the IPR Center. The Contractor shall provide instructions to ICE, HSI and IPR Center personnel in the operation, maintenance and updating of the programs.
• Contractor shall create specific rules to ensure that overlapping domain names (e.g.
FakeGucci.com and Fake_Gucci.com) are properly separated so the data pertaining to each domain name is properly captured.
• Provide data on the visitor’s IP address with time stamp, referring URL and user agent information collected by the dedicated server for the seized websites as needed by the IPR Center.
2.6 Support
• The IPR Center can pose questions and/or requests for data via email or telephone between the hours of 9:00am and 5:30pm EST, Monday through Friday (except Federal holidays).
• The Contractor shall respond via email or telephone to questions and/or requests for data within 24 hours.
• Questions posed on Fridays will be answered the following Monday.
• Questions posed the day before a Federal holiday will be answered the next business day after the
Federal holiday.
• If there is going to be a delay in response, the contractor shall notify the requestor within 24 hours.
• Contractor shall complete the necessary action or request according to the IPR Center’s instructions.
3.0 CONTRACTOR PERSONNEL
It is the responsibility of the Contractor to propose qualified contractor personnel to perform all requirements specified in the SOW.
3.1 Qualified Personnel
The Contractor shall provide qualified personnel to perform all requirements specified in this SOW.
3.2 Continuity of Support
The Contractor shall ensure that the contractually required level of support for this requirement is maintained at all times.
3.3 Project Manager
A project manager is not required.
3.4 Employee Identification
3.4.1 Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.
3.5 Employee Conduct
Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Contractor shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.
3.6 Removing Employees for Misconduct or Security Reasons
The Government may, at its sole discretion (via the Contracting Officer*), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons. Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract.
The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.
4.0 OTHER APPLICABLE CONDITIONS
N/A
4.1 SECURITY
Contractor access to classified information is not currently required under this SOW. However, the Government at a later date may require all Contractor personnel to have Secret Clearances. Accordingly, all Contractor employees provided for this requirement must be eligible for a Secret Clearance.
4.2 PERIOD OF PERFORMANCE
The period of performance is a one (1) month transition-in, eleven (11) month base period, one (1) 12-month option period, one (1) 11-month option period, and one (1) month transition-out.
Transition-In June 1, 2021 through June 30, 2021 Base Period July 1, 2021 through May 31, 2022 Option Period One June 1, 2022 through May 31, 2023 Option Period Two June 1, 2023 through April 30, 2024 Transition-Out May 1, 2024 through May 31, 2024
4.3 PLACE OF PERFORMANCE
The primary place of performance will be the Contractor’s facilities.
4.4 HOURS OF OPERATION
As outlined in Section 2.6, the Contractor shall respond to telephone calls and emails.
4.5 TRAVEL
Contractor travel shall not be required for this requirement.
4.6 POST AWARD CONFERENCE
The Contractor shall attend a Post Award Conference with the Contracting Officer and the COR no later than 14 business days after the date of award. The purpose of the Post Award Conference, which will be chaired by the Contracting Officer, is to discuss technical and contracting objectives of this requirement.
4.7 PROGRESS REPORTS
The Contractor shall provide statistical reports as requested to the COR and copy the Contracting Officer via email. This report shall include a summary of all Contractor work performed, and any Contractor concerns or recommendations for the previous reporting period.
4.8 PROGRESS MEETINGS
The Contractor shall be available meet virtually with the COR, upon request, to present deliverables, discuss progress, exchange information, and resolve emergent technical problems and issues.
4.9 GENERAL REPORT REQUIREMENTS
The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows and Microsoft Office Applications).
4.10 INTELLECTUAL PROPERTY
Any and all programs created by the contractor to fulfill this Purchase Order will belong to ICE, HSI and the IPR Center. The contractor will make available all source codes for the programs and provide instructions on the use, maintenance, and update to ICE, HSI and/or IPR Center personnel to continue operations when the service of the contractor is no longer needed.
4.11 PROTECTION OF INFORMATION
It is possible that the Contractor may have access to information protected under the Privacy Act under this SOW to include Personally Identifiable Information (PII). Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation. The Contractor will provide documentation of what steps have been taken to ensure that the data collected on the dedicated server is protected against intrusion attacks or “hacks,” and will notify the IPR Center within 24 hours of any detected intrusion attempts. At the end of the Purchase Order, the Contractor will provide the IPR Center with a copy all information storage on the dedicated server and shall certify in writing the destruction of all PII, including visitor’s IP addresses.
It is possible that the Contractor may have access to proprietary information under this SOW. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation.
4.12 SECTION 508 COMPLIANCE
Accessibility Requirements (Section 508)
4.12.1 Section 508 Requirements
Section 508 of the Rehabilitation Act (classified to 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.
All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Appendixes A, C & D, and available at https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards. ICT includes IT and other equipment.
https://uscode.house.gov/view.xhtml?req=(title:29%20section:794d%20edition:prelim)%20OR%20(granuleid:USC-prelim-title29-section794d)&f=treesort&edition=prelim&num=0&jumpTo=true https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5 https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5
Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018, or any successor publication.
4.12.1.1 Section 508 Requirements for Technology Services
When providing maintenance upgrades, substitutions, and replacements to ICT, the contractor shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement.
The agency reserves the right to request an Accessibility Conformance Report (ACR) for proposed upgrades, substitutions and replacements prior to acceptance. The ACR should be created using the on the Voluntary Product Accessibility Template Version 2.2 508 (or successor versions). The template can be located at https://www.itic.org/policy/accessibility/vpat
1. When developing or modifying ICT, the Contractor is required to validate ICT deliverables for conformance to the applicable Section 508 requirements. Validation shall occur on a frequency that ensures Section 508 requirements is evaluated within each iteration and release that contains user interface functionality.
2. When modifying, installing, configuring or integrating commercially available or Government-owned ICT, the Contractor shall not reduce the original ICT Item’s level of Section 508 conformance.
3. When developing or modifying web based and electronic content components, except for electronic documents and non-fillable forms provided in a Microsoft Office or Adobe PDF format, the Contractor shall demonstrate conformance to the applicable Section 508 standards (including WCAG 2.0 Level A and AA Success Criteria) by conducting testing using the DHS Trusted Tester for Web Methodology Version 5.0 or successor versions, and shall ensure testing is conducted by individuals who are certified by DHS on version 5.0 or successor versions (e.g.
“DHS Certified Trusted Testers”). The Contractor shall provide the Trusted Tester Certification IDs to DHS upon request. Information on the DHS Trusted Tester for Web Methodology Version 5.0, related test tools, test reporting, training, and tester certification requirements is published at https://www.dhs.gov/trusted-tester.
4. When developing or modifying software functions of ICT, the Contractor shall demonstrate conformance to the applicable Section 508 standards (including the requirements in Chapter 5 and WCAG 2.0 Level A and AA Success Criteria). When the requirements in Chapter 5 do not address one or more software functions, the Contractor shall demonstrate conformance to the Functional Performance Criteria specified in Chapter 3. The Contractor shall use a test process capable of validating conformance to all applicable Section 508 standards for software functionality delivered pursuant to this contract. The Contractor may utilize the DHS Trusted Tester Methodology for Web and Software Version 4.0 as a component of the overall test process used. This version of the test process provides partial test coverage of the Section 508 standards that apply to software. If the Contractor uses this test process, the Contractor shall address the test coverage gaps through additional test procedures. Information on the DHS Trusted Tester Methodology for Web and Software Version 4.0, including coverage against the applicable Section 508 standards for software as well as gaps that need to be addressed through other test methods, related test tools, and training is published at https://www.dhs.gov/trusted-tester.
https://www.itic.org/policy/accessibility/vpat https://www.dhs.gov/trusted-tester https://www.dhs.gov/trusted-tester
5. Contractor personnel shall possess the knowledge, skills and abilities necessary to address the accessibility requirements in this work statement.
4.12.1.2 Section 508 Deliverables
Section 508 Test Plans: When developing or modifying ICT pursuant to this contract, the Contractor shall provide a detailed Section 508 Conformance Test Plan. The Test Plan shall describe the scope of components that will be tested, an explanation of the test process that will be used, when testing will be conducted during the project development life cycle, who will conduct the testing, how test results will be reported, and any key assumptions.
1. Section 508 Test Results: When developing or modifying ICT pursuant to this contract, the Contractor shall provide test results in accordance with the Section 508 Requirements for Technology Services provided in this solicitation.
2. Section 508 Accessibility Conformance Reports: For each ICT item offered through this contract (including commercially available products, and solutions consisting of ICT that are developed or modified pursuant to this contract), the Offeror shall provide an Accessibility Conformance Report (ACR) to document conformance claims against the applicable Section 508 standards. The ACR shall be based on the Voluntary Product Accessibility Template Version 2.0 508 (or successor versions). The template can be found at https://www.itic.org/policy/accessibility/vpat. Each ACR shall be completed by following all of the instructions provided in the template, including an explanation of the validation method used as a basis for the conformance claims in the report.
3. Other Section 508 Documentation: The following documentation shall be provided upon request for ICT items offered through this contract:
o Documentation of features provided to help achieve accessibility and usability for people with disabilities.
o Documentation on how to configure and install the ICT Item to support accessibility.
o Documentation of core functions that cannot be accessed by persons with disabilities.
o Documentation of remediation plans to address non-conformance to the Section 508 standards
5.0 GOVERNMENT TERMS & DEFINITIONS
5.1 COR – Contracting Officer’s Representative
5.2 DHS − Department of Homeland Security
5.3 Criminal Seizure Banners - This displayed banner cites a Federal statute violated by the seized website. These banners will be modified, and the number of banners will increase as situation dictates.
5.4 Anti-Piracy and Counterfeiting Banner –This is an informational banner that alerts the viewers that counterfeiting and piracy are crimes.
https://www.itic.org/policy/accessibility/vpat
5.5 Public Service Announcement - Message that highlights the danger of counterfeiting and piracy and its harm on society.
5.6 Seized Domain Names – Domain names that are seized based on an order issued by a criminal or civil court.
5.7 Shutdown Domain Names – Domain names that are removed administratively and can no longer be searchable or found on the internet.
6.0 GOVERNMENT FURNISHED PROPERTY
6.1 GOVERNMENT FURNISHED EQUIPMENT
The Government will not furnish any equipment to the Contractor in support of this Purchase Order.
6.2 GOVERNMENT FURNISHED INFORMATION
The Government will provide all necessary information, data and documents to the Contractor for work required under this Purchase Order. The Contractor shall use Government furnished information, data and documents only for the performance of work under this Purchase Order, and shall be responsible for returning all Government furnished information, data and documents to the Government at the end of the performance period. The Contractor shall not release Government furnished information, data and documents to outside parties without the prior and explicit consent of the Contracting Officer.
7.0 CONTRACTOR FURNISHED PROPERTY
The Contractor shall furnish all facilities, materials, equipment, and services necessary to fulfill the requirements of this Purchase Order.
8.0 GOVERNMENT ACCEPTANCE PERIOD
The COR will review deliverables prior to acceptance and provide the contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor stating that the deliverable has been accepted.
8.1 The COR will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted quote. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor shall have an opportunity to correct the rejected deliverable and return it per delivery instructions.
8.2 The COR will have 10 business days to review deliverables and make comments. The Contractor shall have 5 business days to make corrections and redeliver.
8.3 All other review times and schedules for deliverables shall be agreed upon by the parties based on the final approved Project Plan. The Contractor shall be responsible for timely delivery to Government personnel in the agreed upon review chain, at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to ensure that the established schedule is maintained.
9.0 DELIVERABLES
ITEM SOW
REFERENCE DELIVERABLE / EVENT DUE BY
DISTRIBUTION
1 2.5 Statistical Reports Monthly
IPR Center
2 2.5 Supplemental Statistical Reports As Requested
IPR Center
3 2.5 Seized Websites Directed to Correct Seizure Banner Report
Monthly IPR Center
2 4.6 Post Award Conference Within 14 days of award
N/A
3 4.7 Progress Reports As Requested
COR, CO
4 4.8 Virtual Progress Meetings As Requested
COR
Architecture and Agile
DHS Enterprise Architecture Compliance All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures.
Specifically, the Contractor shall comply with the following Homeland Security (HLS) EA requirements:
• All developed solutions and requirements shall be compliant with the HLS EA.
• All IT hardware and software shall be compliant with the HLS EA Technical Reference Model (TRM) Standards and Products Profile.
• Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.
• Development of data assets, information exchanges and data standards will comply with the DHS Enterprise Data Management Policy Directive 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.
• Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile
(National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.
ICE Application Architecture Compliance
• The Contractor shall ensure that the application is designed and developed for browser independence;
i.e., the application will generally work with any of the major browsers. ICE currently uses Internet Explorer (IE) version 11 configured with numerous Group Policy Objects (GPOs) as well as Chrome for Work, similarly secured with centrally managed security policies. Browser specific implementations or limitations on browser independence must be approved in writing by ICE OCIO prior to development. Web Applications should be designed utilizing a responsive web design (RWD) approach, to provide an optimal viewing and interaction experience, independent of the particular platform capabilities the end user is utilizing. If ICE OCIO upgrades to a newer version of IE or Chrome for Work, the contractor shall ensure the application is compatible with the future version.
Open Source Compliance
• The Contractor shall follow the ICE Open Source Manifesto when evaluating any technologies, tools, software, and/or application programmable interfaces (API’s) to support a system.
• The Contractor shall prioritize the adoption of, and migration to, Open Source technologies over proprietary or “closed” technologies.
Required IT Contract Language
Security Review Terms and Conditions
The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford ICE, including the organization of ICE Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer Technical Representative (COTR), and other Government oversight organizations, access to the Contractor's facilities, installations, operations, documentation, databases and personnel used in the performance of this contract.
The Contractor will contact ICE Chief Information Security Officer to coordinate and participate in the review and inspection activity of Government oversight organizations external to ICE. Access shall be provided to the extent necessary for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of ICE data or the function of computer system operated on behalf of ICE, and to preserve evidence of computer crime.
Security Requirements For Unclassified Information Technology Resources (JUN 2006)
The Contractor shall be responsible for IT security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency’s mission.
The Contractor shall provide, implement, and maintain an IT Security Plan. This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.
Within 60 days after contract award, the contractor shall submit for approval its IT Security Plan, which shall be consistent with and further detail the approach contained in the offeror's proposal. The plan, as approved by the Contracting Officer (CO), shall be incorporated into the contract as a compliance document.
The Contractor’s IT Security Plan shall comply with Federal laws that include, but are not limited to, the Computer Security Act of 1987 (40 U.S.C. 1441 et seq.); the Government Information Security Reform Act of 2000; and the FISMA of 2002; and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130.
The security plan shall specifically include instructions regarding handling and protecting sensitive information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.
Examples of tasks that require security provisions include:
a) Acquisition, transmission or analysis of data owned by DHS with significant replacement cost should the contractor’s copy be corrupted; and
b) Access to DHS networks or computers at a level beyond that granted the public (e.g., such as bypassing a firewall).
At the expiration of the contract, the contractor shall return all sensitive DHS information and IT resources provided to the contractor during the contract and certify that all non-public DHS information has been purged from any contractor-owned system. Components shall conduct reviews to ensure that the security requirements in the contract are implemented and enforced.
Contractor Employee Access (Sep 2012) Sensitive Information, as used in this clause, means any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy.
This definition includes the following categories of information:
a) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
b) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
c) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
d) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
e) “Information Technology Resources” include, but are not limited to, computer equipment, networking equipment, telecommunications equipment, cabling, network drives, computer drives, network software, computer software, software programs, intranet sites, and internet sites.
Contractor employees working on this contract must complete such forms as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability. Completed forms shall be submitted as directed by the CO. Upon the CO's request, the Contractor's employees shall be fingerprinted, or subject to other investigations as required.
All Contractor employees requiring recurring access to Government facilities or access to sensitive information or IT resources are required to have a favorably adjudicated background investigation prior to commencing work on this contract unless this requirement is waived under Departmental procedures.
The CO may require the Contractor to prohibit individuals from working on the contract if the Government deems their initial or continued employment contrary to the public interest for any reason. Including, but not limited to, carelessness, insubordination, incompetence, or security concerns.
Work under this contract may involve access to sensitive information. Therefore, the Contractor shall not disclose, orally or in writing, any sensitive information to any person unless authorized in writing by the CO. For those Contractor employees authorized access to sensitive information, the Contractor shall ensure that these persons receive training concerning the protection and disclosure of sensitive information both during and after contract performance.
The Contractor shall include the substance of this clause in all subcontracts at any tier where the subcontractor may have access to Government facilities, sensitive information, or resources.
Privacy Expectations
Government contractor employees do not have a right, nor should they have an expectation, of privacy while using Government provided devices at any time, including accessing the Internet and using e-mail and voice communications. To the extent that employees wish that their private activities remain private, they should avoid using the Government provided device for limited personal use. By acceptance of the Government provided device, employees imply their consent to disclosing and/or monitoring of device usage, including the contents of any files or information maintained or passed -through that device.
Personal Identification Verification (PIV) Credential Compliance Terms and Conditions
a) Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting HSPD-12 PIV credentials as a method of identity verification and authentication.
b) Procurements for software products or software developments shall be compliant by accepting PIV credentials as the common means of authentication for access for federal employees and contractors.
c) PIV-enabled information systems must demonstrate that they can correctly work with PIV credentials by responding to the cryptographic challenge in the authentication protocol before granting access.
d) If a system is identified to be non-compliant with HSPD-12 for PIV credential enablement, a remediation plan for achieving HSPD-12 compliance shall be required for review, evaluation, and approval by the CISO.
Personal Identification Verification (PIV) Credential Compliance Terms and Conditions
a) Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting HSPD-12 PIV credentials as a method of identity verification and authentication.
b) Procurements for software products or software developments shall be compliant by accepting PIV credentials as the common means of authentication for access for federal employees and contractors.
c) PIV-enabled information systems must demonstrate that they can correctly work with PIV credentials by responding to the cryptographic challenge in the authentication protocol before granting access.
d) If a system is identified to be non-compliant with HSPD-12 for PIV credential enablement, a remediation plan for achieving HSPD-12 compliance shall be required for review, evaluation, and approval by the CISO.
| STATEMENT OF WORK (SOW) |
| FOR |
| 1.4 APPLICABLE DOCUMENTS |
| 2.0 SPECIFIC REQUIREMENTS/TASKS |
| 2.5 Data |
| Collect data regarding domain names, banner hits, PSA hits and capture the visitor’s IP address with time stamp, referring URL and user agent information, as instructed by the IPR Center |
| Provide statistics as requested of hits to the respective banners (broken down by individual website) and the PSA |
| 2.6 Support |
| The IPR Center can pose questions and/or requests for data via email or telephone between the hours of 9:00am and 5:30pm EST, Monday through Friday (except Federal holidays). |
| The Contractor shall respond via email or telephone to questions and/or requests for data within 24 hours. |
| Questions posed on Fridays will be answered the following Monday. |
| Questions posed the day before a Federal holiday will be answered the next business day after the Federal holiday. |
| If there is going to be a delay in response, the contractor shall notify the requestor within 24 hours. |
3.0 CONTRACTOR PERSONNEL
| 4.12.1 Section 508 Requirements |
| 4.12.1.1 Section 508 Requirements for Technology Services |
| When providing maintenance upgrades, substitutions, and replacements to ICT, the contractor shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement. The agency reserves the right to request an... |
| 4.12.1.2 Section 508 Deliverables |
| Section 508 Test Plans: When developing or modifying ICT pursuant to this contract, the Contractor shall provide a detailed Section 508 Conformance Test Plan. The Test Plan shall describe the scope of components that will be tested, an explanation of ... |
| 5.0 GOVERNMENT TERMS & DEFINITIONS |
| 6.0 GOVERNMENT FURNISHED PROPERTY |
| 6.1 GOVERNMENT FURNISHED EQUIPMENT |
| 7.0 CONTRACTOR FURNISHED PROPERTY |
File details come from the government source that posted it. Updated .