2.2.1 Attachment A SOW Hosting Support Services .pdf

PDF 372 KB Posted

Attached to
ICE/HSI Hosting Support Services Federal contract opportunity
Solicitation number
70CTD024Q00000107
Issued by
Immigration and Customs Enforcement

About this file

This document is a Statement of Work (SOW) for a federal contract opportunity issued by the U.S. Department of Homeland Security's Immigration and Customs Enforcement, Homeland Security Investigations, Global Trade Investigations Division, Intellectual Property Rights Center.

The SOW outlines the requirements for technical support and hosting services needed to host the Intellectual Property Rights Center's criminal seizure banners, Anti-Counterfeiting and Piracy banner, and Public Service Announcement on an independent server separate from any government systems. The services include creating and maintaining the banners, hosting the domain name www.seizedservers.com, collecting visitor data and providing periodic statistical reports, and interacting with domain registries and registrars as directed by the IPR Center. The contract has a one-year base period with two one-year option periods. The primary place of performance will be the contractor's facilities. Contractor personnel will require Secret security clearances. The government will not provide any resources to the contractor, who must furnish all necessary facilities, materials, equipment, and services.

View the file

Other files for this federal contract opportunity

Other files attached to ICE/HSI Hosting Support Services, newest first.
File Type Posted
2.10.1 Sep17 Questions and Answers RFQ 70CTD024Q00000107.xlsx XLSX spreadsheet
Amendment0001.pdf PDF
2.10.1 Questions and Answers RFQ 70CTD024Q00000107.xlsx XLSX spreadsheet
2.2.1 Combined Synopsis and RFQ Letter.pdf PDF
2.2.1_Attachment B Terms and Conditions.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Page 1 of 21 RFQ# 70CTD024Q00000107

STATEMENT OF WORK (SOW)

FOR

Immigration and Customs Enforcement, Homeland Security Investigations, Global Trade Investigations Division, Intellectual Property Rights Center

1.0 GENERAL

1.1 Background

This SOW outlines the support and hosting services required for initiatives at the U.S.

Department of Homeland Security (DHS)/Immigration and Customs Enforcement (ICE)/Homeland Security Investigations (HSI)/Global Trade Investigations Division (GTID)/ Intellectual Property Rights Center (IPR Center). The IPR Center stands at the forefront of the U.S. government’s response to global intellectual property (IP) theft. The IPR Center uses the expertise of its 25 member agencies to share information, develop initiatives, coordinate enforcement actions, and conduct investigations related to IP theft and trade enforcement.

Through this strategic interagency partnership, the IPR Center protects the public’s health and safety, the U.S. economy, and the war fighters. The IPR Center employs a strategic approach to combat IP theft. This approach includes:

• Investigation – Identifying, disrupting, prosecuting and dismantling criminal organizations involved in the manufacture and distribution of counterfeit products.

• Interdiction - Using focused targeting and inspections to keep counterfeit and pirated goods out of the U.S. supply chains, markets and streets.

• Outreach and Training - Providing training for domestic and international law enforcement to build stronger enforcement capabilities worldwide.

The IPR Center also manages and supports the ICE/HSI/GTID Commercial Fraud program, focusing on commercial imports that are based in false statements and deceptive business practices. By combining the IP theft and commercial fraud programs at the IPR Center, ICE/HSI is able to take a comprehensive approach to addressing these vulnerabilities.

Through Operation In Our Sites (IOS), the IPR Center addresses intellectual property theft vulnerabilities present through the internet, which counterfeiters use to facilitate the sale of counterfeit and pirated merchandise. The IPR Center launched IOS in June 2010 and under this operation, ICE/HSI identifies and targets internet website domain names that were distributing and selling only infringing goods. ICE/HSI then uses the criminal process to seize the infringing domain names. When a domain is seized criminally under IOS, viewers are redirected to a criminal seizure banner which provides information regarding the reason for the seizure. Viewers can also be redirected to a public service announcement regarding the dangers of counterfeiting.

The IPR Center’s seizure banner has been visited by millions of internet users.

Page 2 of 21 RFQ# 70CTD024Q00000107

Criminal organizations, however, have adapted to this methodology and now have inactive and/or dormant domain names ready to be activated when their active domain names are seized, requiring the IPR Center to shift its approach. Therefore, in addition to seizing domains through the criminal process, the IPR Center has partnered with industry because the IPR Center has found that industry’s use of the civil or legal administrative process is more efficient at shutting down infringing websites than the criminal process.

Because the criminal seizure banners cannot be utilized in the civil/administrative process, the IPR Center has created an Anti-Counterfeiting and Piracy (ACP) banner which can be used by the rights holders when they seize a website through the civil or administrative process. The ACP banner is an informational banner which provides a conduit for the public to provide information on IPR violations to the IPR Center. It is anticipated that like the criminal seizure banners, the ACP banner will also be an effective method of educating the public about the serious problem of IP theft and will be viewed by even more internet users than the IPR Center’s criminal seizure banner.

Historically, when ICE/HSI criminally seized a website domain, the court order directed the Registry to redirect hits to the domain to a specific IP Address that was affiliated with the hosting service’s server. Following the instructions from the IPR Center, the hosting service would then show one of the criminal seizure banners or redirect again to a Public Service Announcement regarding the dangers of counterfeiting.

The redirection of the seized and/or shut-down domains is a critical component to the IPR Center’s outreach and public education. It also serves as a deterrent for those considering selling counterfeit goods in the future.

1.2 Scope

The Contractor shall provide technical support, to include retrieval of data regarding visitors to the seized domain names, as well as maintenance pertaining to seized websites and/or shutdown websites. The contractor shall also provide technical support for the utilization of the criminal seizure banners, the ACP banner, and Public Service Announcement(s).

1.3 OBJECTIVE

The ICE/HSI/Global Trade Investigations Division (GTID)/IPR Center will have its criminal seizure banners and ACP banner hosted by an independent server, separate of any Government computer systems. The server host will collect data regarding the domain names and banners, as well as on the visitors to the domain names.

1.4 APPLICABLE DOCUMENTS

1.4.1 Compliance Documents

• N/A

1.4.2 Reference Documents

• N/A https://icegov-my.sharepoint.com/personal/0816439275_ice_dhs_gov/Documents/Documents/SCOPE%20PARAGRAPHS.doc

Page 3 of 21 RFQ# 70CTD024Q00000107

2.0 SPECIFIC REQUIREMENTS/TASKS

The contractor will provide an independent server to host the criminal seizure banners and ACP banner separate of any Government computer system. The dedicated server minimally will have a bandwidth of 100MB, dedicated server web server memory of 1TB, dedicated server SFTP server memory of 2TB, Dual Core, 12GB of RAM with 2 Quad Core (or greater) and take over domain name www.seizedservers.com which contains the websites seized by ICE, HSI, the IPR Center’s seizure banners, ACP banner and list of websites seized by rights holders. This includes the following:

2.1 Criminal seizure banners

• Host the criminal seizure banners on an independent server.

o include creating and maintaining the banner as needed;

o Includes name server;

o Includes web server; and o Includes Secure File Transfer Protocol (SFTP) server (secured by user name and password).

• Ensure that the lists of seized domain names are directed to this banner, as directed by the IPR Center.

• This includes domain names that have been seized in past, as well as ones that may be seized in the future

2.2 Anti-Counterfeiting and Piracy (ACP) banner

• Host the ACP banner on an independent server.

• Include creating and maintaining the banner as needed;

• includes name server;

• includes web server,

• Includes SFTP server.

• Includes Secure File Transfer Protocol (SFTP) server (secured by user name and password).

• Ensure that the current lists of shutdown domain names are directed to this banner, as directed by the IPR Center.

• This includes domain names that have been shut down in the past, as well as ones that may be shut down in the future.

2.4 Public Service Announcement (PSA)

http://www.seizedservers.com/

Page 4 of 21 RFQ# 70CTD024Q00000107

• Host the PSA on an independent server.

• Ensure that the current lists of seized domain names and/or shutdown domain names are directed to the PSA, as directed by the IPR Center.

2.5 Registries and Registrars

• Interact with Registries (e.g. VeriSign) and other registrars as originally outlined by the IPR Center in delineated format;

2.6 Data

• Collect data regarding domain names, banner hits, PSA hits and capture the visitor’s IP address with time stamp, referring URL and user agent information, as instructed by the IPR Center

• Provide statistics on a periodic basis of hits to the respective banners (broken down by individual website) and the PSA

• When a problem arises in the collection of data on the seized websites, the contractor will identify the problem and takes appropriate steps to correct the problem. The contractor will notify the IPR Center within 24 hours of the issue and the corrective measure taken.

• Contractor will provide periodic statistical reports, or as needed, to the IPR Center by creating programs to retrieve the hits information for each seized website from the contractor’s server and transfer the statistic to an Excel spreadsheet listing the name of the seized website and the number of hits to each website for the past month. Contractor will update the list of seized websites on the Excel spreadsheet as needed or as requested by the IPR Center. The monthly statistical report will contain a running count of the total number of hits to the IPR Center’s seizure banner since the operation’s inception in 2010.

The contractor will coordinate with the previous contractor in transfer of data from the previous contractor’s server to the new contractor’s server. New programs created by the contractor in fulfillment of this contract along with the source codes will become property of ICE, HSI and the IPR Center. The contractor will provide instruction to ICE, HSI, GTID, and IPR Center personnel in the operation, maintenance and updating of the programs.

• Contractor will provide a monthly report, or as needed, to the IPR Center, ensuring that the seized websites are directed to the correct seizure banner. The contractor will create a program that will provide a report that lists each website directed to the IPR Center’s seizure banner. New programs created by the contractor in fulfillment of this contract along with the source codes will become property of ICE, HSI and the IPR Center. The contractor will provide instructions to ICE, HSI and IPR Center personnel in the operation, maintenance and updating of the programs.

Page 5 of 21 RFQ# 70CTD024Q00000107

• Contractor will create specific rules to ensure that overlapping domain names (e.g.

FakeGucci.com and Fake_Gucci.com) are properly separated so the data pertaining to each domain name are properly captured.

• Provide data on the visitor’s IP address with time stamp, referring URL and user agent information collected by the dedicated server for the seized websites as needed by the IPR Center.

2.7 Support

• The IPR Center can pose questions and/or requests for data via email or telephone between the hours of 9:00am and 5:30pm EST, Monday through Friday (except Federal holidays).

• The contractor shall respond via email or telephone to questions and/or requests for data within 24 hours.

• Questions posed on Fridays will be answered the following Monday.

• Questions posed the day before a Federal holiday will be answered the next business day after the Federal holiday.

• If there is going to be a delay in response, the contractor will notify the requestor within 24 hours.

• Contractor will complete the necessary action or request according to the IPR Center’s instructions.

3.0 CONTRACTOR PERSONNEL

It is the responsibility of the contractor to propose qualified contractor personnel to perform all requirements specified in the SOW.

3.1 Qualified Personnel

The Contractor shall provide qualified personnel to perform all requirements specified in this

SOW.

3.2 Continuity of Support

The Contractor shall ensure that the contractually required level of support for this requirement is maintained at all times.

3.3 Key Personnel

Before replacing any individual designated as Key by the Government, the Contractor shall notify the Contracting Officer no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes shall possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The

Page 6 of 21 RFQ# 70CTD024Q00000107

Contractor shall not replace Key Contractor personnel without approval from the Contracting Officer. The following Contractor personnel are designated as Key for this requirement. Note:

The Government may designate additional Contractor personnel as Key at the time of award.

The System Administrator managing the independent server(s) is considered to be a Key Personnel. The System Administrator will provide support for implementation, troubleshooting and maintenance of IT systems. Manages IT system infrastructure and any processes related to these systems. Provide support to IT systems including: day-to-day operations, monitoring and problems resolution for all of the client problems. Provide second level problem identification, diagnosis and resolution of problems. Provide support for the dispatch system and hardware problems and remain involved in the resolution process. Provide support for the escalation and communication of status to agency management and internal customers. Must possess experience in one or more systems and architectures and associated hardware: mainframe, mini, or client/server based.

Contractor personnel designated as “Key Personnel” by the Government require Government acknowledgement prior to replacement. The Contractor shall submit a written notice of intent to replace the Key Personnel along with the resume of the proposed replacement(s) to the Contracting Officer (CO) a minimum of ten (10) business days prior to the proposed date of change. All proposed replacement(s) shall possess qualifications equal to or superior to those of the Key Personnel being replaced. The Government may designate additional contractor personnel as Key in specific calls.

3.4 Project Manager

A project manager is not required.

3.5 Employee Identification

3.5.1 Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.

3.6 Employee Conduct

Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Contractor shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.

Page 7 of 21 RFQ# 70CTD024Q00000107

3.7 Removing Employees for Misconduct or Security Reasons

The Government may, at its sole discretion (via the Contracting Officer*), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons.

Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.

4.0 OTHER APPLICABLE CONDITIONS

N/A

4.1 SECURITY

Contractor access to classified information is not currently required under this SOW. However, the Government at a later date may require all Contractor personnel to have Secret clearances.

Accordingly, all Contractor employees provided for this requirement must be eligible for a Secret Clearance.

4.2 PERIOD OF PERFORMANCE

The period of performance for this contract is a one-year base period with two one-year option periods as follows:

Base Period September 23, 2024 through September 22, 2025

Option Period One September 23, 2025 through September 22, 2026

Option Period Two September 23, 2026 through September 22, 2027

4.3 PLACE OF PERFORMANCE

The primary place of performance will be the Contractor’s facilities.

4.4 HOURS OF OPERATION

As outlined in section 2.7, the Contractor shall respond to telephone calls and emails.

4.5 TRAVEL

Contractor travel shall not be required for this requirement.

4.6 POST AWARD CONFERENCE

The Contractor shall attend a Post Award Conference with the Contracting Officer and the COR no later than 14 business days after the date of award. The purpose of the Post Award Conference, which will be chaired by the Contracting Officer, is to discuss technical and contracting objectives of this contract and review the Contractor's draft project plan

Page 8 of 21 RFQ# 70CTD024Q00000107

4.7 PROJECT PLAN

The Contractor is to provide a project plan to the Government to assist the COR in contract administration. The Contractor shall provide a draft Project Plan at the Post Award Conference for Government review and comment. The Contractor shall provide a final Project Plan to the COR not later than 14 business days after the Post Award Conference.

4.8 BUSINESS CONTINUITY PLAN

The Contractor is not required to provide continuous operations to the Government during emergencies, including natural disasters and acts of terrorism.

4.9 PROGRESS REPORTS

The Contractor shall provide periodic statistical reports to the Contracting Officer and COR via electronic mail. This report shall include a summary of all Contractor work performed, including a breakdown of labor hours by labor category, all direct costs by line item, and any Contractor concerns or recommendations for the previous reporting period.

4.10 PROGRESS MEETINGS

The Contractor shall be available to (virtually) meet with the COR upon request to present deliverables, discuss progress, exchange information and resolve emergent technical problems and issues.

4.11 GENERAL REPORT REQUIREMENTS

The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows and Microsoft Office Applications).

4.12 INTELLECTUAL PROPERTY

Any and all programs created by the contractor to fulfill this contract will belong to ICE, HSI and the IPR Center. The contractor will make available all source codes for the programs and provide instructions on the use, maintenance, and update to ICE, HSI and/or IPR Center personnel to continue operations when the service of the contractor is no longer needed.

4.13 PROTECTION OF INFORMATION

It is possible that the Contractor may have access to information protected under the Privacy Act under this SOW to include Personally Identifiable Information (PII). Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation. The contractor will provide documentation of what steps have been taken to ensure that the data collected on dedicated server is protected against intrusion attacks or “hacks,” and will notify the IPR Center within 24 hours of any detected intrusion attempts. At the end of the contract, the contractor will provide the IPR Center with a copy all information storage on the dedicated server and shall certify in writing the destruction of all PII, including visitor’s IP addresses.

Page 9 of 21 RFQ# 70CTD024Q00000107

It is possible that the Contractor may have access to proprietary information under this SOW.

Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation.

4.14 SECTION 508 COMPLIANCE

Accessibility Requirements (Section 508)

1. Section 508 Requirements

Section 508 of the Rehabilitation Act (classified to 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.

All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Appendixes A, C & D, and available at https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards. ICT includes IT and other equipment.

Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018, or any successor publication.

1.1 Section 508 Requirements for Technology Services

When providing maintenance upgrades, substitutions, and replacements to ICT, the contractor shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement. The agency reserves the right to request an Accessibility Conformance Report (ACR) for proposed upgrades, substitutions and replacements prior to acceptance. The ACR should be created using the on the Voluntary Product Accessibility Template Version 2.2 508 (or successor versions). The template can be located at https://www.itic.org/policy/accessibility/vpat

1. When developing or modifying ICT, the Contractor is required to validate ICT deliverables for conformance to the applicable Section 508 requirements. Validation shall occur on a frequency that ensures Section 508 requirements is evaluated within each iteration and release that contains user interface functionality.

https://uscode.house.gov/view.xhtml?req=(title:29%20section:794d%20edition:prelim)%20OR%20(granuleid:USC-prelim-title29-section794d)&f=treesort&edition=prelim&num=0&jumpTo=true https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5 https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5 https://www.itic.org/policy/accessibility/vpat

Page 10 of 21 RFQ# 70CTD024Q00000107

2. When modifying, installing, configuring or integrating commercially available or government-owned ICT, the Contractor shall not reduce the original ICT Item’s level of Section 508 conformance.

3. When developing or modifying web based and electronic content components, except for electronic documents and non-fillable forms provided in a Microsoft Office or Adobe PDF format, the Contractor shall demonstrate conformance to the applicable Section 508 standards (including WCAG 2.0 Level A and AA Success Criteria) by conducting testing using the DHS Trusted Tester for Web Methodology Version 5.0 or successor versions, and shall ensure testing is conducted by individuals who are certified by DHS on version

5.0 or successor versions (e.g. “DHS Certified Trusted Testers”). The Contractor shall provide the Trusted Tester Certification IDs to DHS upon request. Information on the DHS Trusted Tester for Web Methodology Version 5.0, related test tools, test reporting, training, and tester certification requirements is published at https://www.dhs.gov/trusted-tester.

4. When developing or modifying software functions of ICT, the Contractor shall demonstrate conformance to the applicable Section 508 standards (including the requirements in Chapter 5 and WCAG 2.0 Level A and AA Success Criteria). When the requirements in Chapter 5 do not address one or more software functions, the Contractor shall demonstrate conformance to the Functional Performance Criteria specified in Chapter 3. The Contractor shall use a test process capable of validating conformance to all applicable Section 508 standards for software functionality delivered pursuant to this contract. The Contractor may utilize the DHS Trusted Tester Methodology for Web and Software Version 4.0 as a component of the overall test process used. This version of the test process provides partial test coverage of the Section 508 standards that apply to software. If the Contractor uses this test process, the Contractor shall address the test coverage gaps through additional test procedures. Information on the DHS Trusted Tester Methodology for Web and Software Version 4.0, including coverage against the applicable Section 508 standards for software as well as gaps that need to be addressed through other test methods, related test tools, and training is published at https://www.dhs.gov/trusted-tester.

5. Contractor personnel shall possess the knowledge, skills and abilities necessary to address the accessibility requirements in this work statement.

1.2 Section 508 Deliverables

Section 508 Test Plans: When developing or modifying ICT pursuant to this contract, the Contractor shall provide a detailed Section 508 Conformance Test Plan. The Test Plan shall describe the scope of components that will be tested, an explanation of the test process that will be used, when testing will be conducted during the project development life cycle, who will conduct the testing, how test results will be reported, and any key assumptions.

https://www.dhs.gov/trusted-tester https://www.dhs.gov/trusted-tester https://www.dhs.gov/trusted-tester

Page 11 of 21 RFQ# 70CTD024Q00000107

1. Section 508 Test Results: When developing or modifying ICT pursuant to this contract, the Contractor shall provide test results in accordance with the Section 508 Requirements for Technology Services provided in this solicitation.

2. Section 508 Accessibility Conformance Reports: For each ICT item offered through this contract (including commercially available products, and solutions consisting of ICT that are developed or modified pursuant to this contract), the Offeror shall provide an Accessibility Conformance Report (ACR) to document conformance claims against the applicable Section 508 standards. The ACR shall be based on the Voluntary Product Accessibility Template Version 2.0 508 (or successor versions). The template can be found at https://www.itic.org/policy/accessibility/vpat. Each ACR shall be completed by following all of the instructions provided in the template, including an explanation of the validation method used as a basis for the conformance claims in the report.

3. Other Section 508 Documentation: The following documentation shall be provided upon request for ICT items offered through this contract:

o Documentation of features provided to help achieve accessibility and usability for people with disabilities.

o Documentation on how to configure and install the ICT Item to support accessibility.

o Documentation of core functions that cannot be accessed by persons with disabilities.

o Documentation of remediation plans to address non-conformance to the Section 508 standards

5.0 GOVERNMENT TERMS & DEFINITIONS

5.1 COR – Contracting Officer’s Representative

5.2 DHS − Department of Homeland Security

5.3 Criminal Seizure Banners - This displayed banner cites a Federal statute violated by the seized website. These banners will be modified and the number of banners will increase as situation dictates.

5.4 Anti-Piracy and Counterfeiting Banner –This is an informational banner that alerts the viewers that counterfeiting and piracy are crimes.

5.5 Public Service Announcement - Message that highlights the danger of counterfeiting and piracy and its harm on society.

5.6 Seized Domain Names – Domain names that are seized based on an order issued by a criminal or civil court.

5.7 Shutdown Domain Names – Domain names that are removed administratively and can no longer be searchable or found on the internet.

https://www.itic.org/policy/accessibility/vpat

Page 12 of 21 RFQ# 70CTD024Q00000107

6.0 GOVERNMENT FURNISHED RESOURCES

The Government will not furnish any resources to the Contractor in support of this contract.

The Government will provide all necessary information, data and documents to the Contractor for work required under this contract. The Contractor shall use Government furnished information, data and documents only for the performance of work under this contract, and shall be responsible for returning all Government furnished information, data and documents to the Government at the end of the performance period. The Contractor shall not release Government furnished information, data and documents to outside parties without the prior and explicit consent of the Contracting Officer.

7.0 CONTRACTOR FURNISHED PROPERTY

The Contractor shall furnish all facilities, materials, equipment, and services necessary to fulfill the requirements of this contract.

8.0 GOVERNMENT ACCEPTANCE PERIOD

The COR will review deliverables prior to acceptance and provide the contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.

8.1 The COR will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted proposal.

In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions.

8.2 The COR will have 10 business days to review deliverables and make comments. The Contractor shall have 5 business days to make corrections and redeliver.

8.3 All other review times and schedules for deliverables shall be agreed upon by the parties based on the final approved Project Plan. The Contractor shall be responsible for timely delivery to Government personnel in the agreed upon review chain, at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to assure that the established schedule is maintained.

9.0 DELIVERABLES

ITEM SOW

REFERENCE

DELIVERABLE /

EVENT DUE BY

DISTRIBUTION

1 2.6 Statistical Reports Periodically/as requested

IPR Center

Page 13 of 21 RFQ# 70CTD024Q00000107

ITEM SOW

REFERENCE

DELIVERABLE /

EVENT DUE BY

DISTRIBUTION

2 4.6 Post Award Conference Within 14 days of award

N/A

3 4.6, 4.7 Draft Contractor Project Plan

TBD

COR, Contracting Officer

4 4.7 Final Contractor Project Plan

Within 14 days of award

COR, Contracting Officer

5 4.8 Business Continuity Plan TBD COR, Contracting

Officer

Architecture and Agile

DHS Enterprise Architecture Compliance

All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the contractor shall comply with the following Homeland Security (HLS) EA requirements:

• All developed solutions and requirements shall be compliant with the HLS EA.

• All IT hardware and software shall be compliant with the HLS EA Technical Reference Model (TRM) Standards and Products Profile.

• Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.

• Development of data assets, information exchanges and data standards will comply with the DHS Enterprise Data Management Policy Directive 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

• Applicability of Internet Protocol to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special Publication

Page 14 of 21 RFQ# 70CTD024Q00000107

500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

ICE Application Architecture Compliance

• The Contractor shall ensure that the application is designed and developed for browser independence; i.e., the application will generally work with any of the major browsers.

Browser specific implementations or limitations on browser independence must be approved in writing by ICE OCIO prior to development. Web Applications should be designed utilizing a responsive web design (RWD) approach, to provide an optimal viewing and interaction experience, independent of the particular platform capabilities the end user is utilizing. If ICE OCIO upgrades to a newer version the contractor shall ensure the application is compatible with the future version.

Open Source Compliance

• The Contractor shall follow the ICE Open Source Manifesto when evaluating any technologies, tools, software, and/or application programmable interfaces (API’s) to support a system.

• The Contractor shall prioritize the adoption of, and migration to, Open Source technologies over proprietary or “closed” technologies.

OCIO/ Data Management Unit (DMU) - Data Ownership Contract Requirements Language

1. Accessibility of Government-owned Data All stored program data associated with this acquisition shall be owned by the Government.

As such, it shall be made accessible to the Government in accordance with the Minimum Data Access Capability described below. This accessibility is required to allow full data transparency, flexibility in performing data analytics, and integration with data from other government programs.

In addition to the Minimum Data Access Capability, the Government prefers, but does not require, that program data be accessible via Enhanced Access Capabilities as described below.

Definition of “program data”: Program Data refers to any data resulting from ICE and DHS organizational activity. Examples of such data include but are not limited to administrative data resulting from human resource, management, and financial actions, as well as operational data resulting from performance of the ICE mission.

Definition of “associated with this acquisition”: Program Data is associated with an acquisition if it is created by DHS organizational activity that is facilitated by the contractor.

Examples of how a contractor might facilitate organizational activity follow:

Page 15 of 21 RFQ# 70CTD024Q00000107 o Program data is stored by contractor personnel o Program data is stored by software that is managed, developed, or used by the contractor o Program data is stored in a repository that is managed, developed, or used by the contractor

2. Minimum Data Access Capability

• The current version of all Program Data is accessible to the Government within 24 hours of request, as well as on any pre-defined schedule as required by the Government.

Data access can occur by various means, provided that Government security requirements are met, and data is accessible in a format that is acceptable to the Government. Examples include but are not limited to APIs that are consumable by the Government, files made available for Government download (e.g., Excel Spreadsheets), or direct database query by federal or contractor personnel.

• The contractor shall format program data accessed by the Government to anticipate the maximum file size of any data to be accessed. File size shall be small enough to assure rapid processing by government applications.

• The contractor shall provide the means for the Government to interpret accessible Program Data as follows:

o Data elements and groupings of data elements shall be clearly identifiable by labels embedded in the data itself, or by a separate schema or file layout which allows such elements and groupings to be identified.

In the case of a relational database schema defined through Data Definition Language (DDL), data elements would be represented as columns, and groupings of data would be represented as tables. In addition, relationships between tables would be described as foreign key relations.

o Labels or names used to identify data elements and groupings of data elements shall be approved by the Government. In addition, each label or name shall be associated with a government approved definition which describes the content of data held therein.

o Program data delivered to the Government shall conform to the Government approved definition for each data element and grouping of data elements.

o All data accessible by the Government shall be both machine readable and human-readable in plain text.

o All reference data associated with Program Data also needs to be accessible to the Government. Such reference data is required to provide complete understanding of a record.

Reference Data Example: Program data may include a city code which uniquely identifies a city. Reference data associated with a city code may include its name, geographic boundaries, population, median income, etc. This example is provided for clarification of the meaning of reference data and may or may not apply to this specific

Page 16 of 21 RFQ# 70CTD024Q00000107 acquisition. Examples of other reference data codes would include codes representing eye color, gender, country of origin, etc.

3. Enhanced Access Capabilities

The Government prefers that sharing of program data take place via an Application Programming Interface (API) or multiple APIs. APIs allow the Government to efficiently consume data via a widely recognized standard where the data has been completely abstracted from the technology platform that produces it.

In addition, the Government prefers that sharing of program data take place using techniques that enhance efficiency, such as Change Data Capture (CDC). CDC enhances efficiency of data transfer by providing only incremental updates to program data as opposed to providing all program data each time data is shared.

SECURITY REQUIREMENTS

GENERAL

The United States Immigration and Customs Enforcement (ICE) has determined that performance of the tasks as described in this contract requires that the Contractor, subcontractor(s), vendor(s), etc. (herein known as Contractor) have access to sensitive DHS information, and that the Contractor will adhere to the following.

PRELIMINARY FITNESS DETERMINATION

ICE will exercise full control over granting, denying, withholding or terminating unescorted government facility and/or sensitive Government information access for Contractor applicants/employees, based upon the results of a Fitness screening process. ICE may, as it deems appropriate, authorize and make a favorable expedited preliminary Fitness determination based on preliminary security checks. The preliminary Fitness determination will allow the Contractor employee to commence work temporarily prior to the completion of a Full Field Background Investigation. The granting of a favorable preliminary Fitness shall not be considered as assurance that a favorable final Fitness determination will follow as a result thereof. The granting of preliminary Fitness or final Fitness shall in no way prevent, preclude, or bar the withdrawal or termination of any such access by ICE, at any time during the term of the contract. No employee of the Contractor shall be allowed to enter on duty and/or access sensitive information or systems without a favorable Fitness determination by the Office of Professional Responsibility (OPR), Personnel Security Division (PSD). No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable Fitness determination by OPR PSD. Contract employees are processed under DHS Instruction 121-01-007-001, Personnel Security, Suitability and Fitness Program, dated June 14, 2017, or successor thereto;

those having direct contact with Detainees will also have 6 CFR § 115.117 considerations made as part of the Fitness screening process. Sexual Abuse and Assault Prevention Standards implemented pursuant to Public Law 108-79 (Prison Rape Elimination Act (PREA) of 2003)).

Page 17 of 21 RFQ# 70CTD024Q00000107

BACKGROUND INVESTIGATIONS

Contractor employees (to include applicants, temporary, part-time and replacement employees) under the contract, needing access to sensitive information and/or ICE Detainees, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. Background investigations will be processed through OPR PSD. Contractor applicant/employees are nominated by a Contracting Officer Representative (COR) for consideration to support this contract via submission of the DHS Form 11000-25 and ICE Supplement to the DHS Form 11000-25 to the PSD. This contract shall submit the following security vetting documentation to OPR PSD, through the COR, within 10 days of notification of initiation of an Electronic Questionnaire for Investigation Processing (e-QIP), or successor thereto, in the Office of Personnel Management (OPM) automated on-line system:

1. Standard Form 85P (Standard Form 85PS (with supplement to 85P required for those with direct contact with detainees or armed positions)), “Questionnaire for Public Trust Positions” form completed online and archived by the Contractor applicant/employee in their OPM e-QIP account.

2. Signature Release Forms (Three total) generated by OPM e-QIP upon completion of Questionnaire (e-signature recommended/acceptable). Completed online and archived by the Contractor applicant/employee in their OPM e-QIP account.

3. Electronic fingerprints taken at an approved facility OR two (2) SF 87 Fingerprint

Cards (current revision) sent to OPR PSD. Additional information regarding fingerprints will be sent to the Contractor applicant/employee from OPR PSD.

4. Optional Form 306 Declaration for Federal Employment. This document is sent as an attachment in an e-mail to the Contractor applicant/employee from OPR PSD.

Completed online and archived by the Contractor applicant/employee in their OPM e-QIP account.

5. If occupying PREA designated position: Questionnaire regarding conduct defined under 6 CFR § 115.117 (Sexual Abuse and Assault Prevention Standards). This document is sent as an attachment in an e-mail to the Contractor applicant/employee from OPR PSD. Completed online and archived by the Contractor applicant/employee in their OPM e-QIP account.

6. One additional document may be applicable if the Contractor applicant/employee was born abroad. If applicable, the document will be sent as an attachment in an e-mail to the Contractor applicant/employee from OPR PSD. Completed online and archived by the Contractor applicant/employee in their OPM e-QIP account.

Contractor employees who have an adequate, current investigation by another Federal Agency may not be required to submit complete security packages; the investigation may be accepted under reciprocity. The questionnaire related to 6 CFR § 115.117 listed above in item 5 will be required for positions designated under PREA.

Page 18 of 21 RFQ# 70CTD024Q00000107

An adequate and current investigation is one where the investigation was favorably adjudicated within 5 years and not to exceed 7 years, meets the contract risk level requirement, and applicant has not had a break in service of more than two years. (Executive Order 13488 amended under Executive Order 13764/DHS Instruction 121-01-007-01)

Required information for submission of security packet will be provided by OPR PSD at the time of award of the contract. Only complete packages will be accepted by OPR PSD as notified by the COR.

To ensure adequate background investigative coverage, Contractor applicants/employees must currently reside in the United States or its Territories. Additionally, Contractor applicants/employees are required to have resided within the United States or its Territories for three or more years out of the last five (ICE retains the right to deem a Contractor applicant/employee ineligible due to insufficient background coverage). This timeline is assessed based on the signature date of the standard form questionnaire submitted for the applied position.

Contractor employees falling under the following situations may be exempt from the residency requirement: 1) work or worked for the U.S. Government in foreign countries in federal civilian or military capacities; 2) were or are dependents accompanying a federal civilian or a military employee serving in foreign countries so long as they were or are authorized by the U.S.

Government to accompany their federal civilian or military sponsor in the foreign location; 3) worked as a Contractor employee, volunteer, consultant or intern on behalf of the federal government overseas, where stateside coverage can be obtained to complete the background investigation; 4) studied abroad at a U.S. affiliated college or university; or 5) have a current and adequate background investigation (commensurate with the position risk/sensitivity levels) completed for a Federal or Contractor employee position, barring any break in federal employment or federal sponsorship.

Only U.S. citizens and Legal Permanent Residents are eligible for employment on contracts requiring access to DHS sensitive information unless an exception is granted as outlined under DHS Instruction 121-01-007-001. Per DHS Sensitive Systems Policy Directive 4300A, only U.S.

citizens are eligible for positions requiring access to DHS Information Technology (IT) systems or positions that are involved in the development, operation, management, or maintenance of DHS IT systems, unless an exception is granted as outlined under DHS Instruction 121-01-007- 001.

CONTINUED ELIGIBILITY

ICE reserves the right and prerogative to deny and/or restrict facility and information access of any Contractor employee whose actions conflict with Fitness standards contained in DHS Instruction 121-01-007-01, Chapter 3, paragraph 6.B or who violate standards of conduct under 6 CFR § 115.117. The Contracting Officer or their representative can determine if a risk of compromising sensitive Government information exists or if the efficiency of service is at risk and may direct immediate removal of a Contractor employee from contract support.

OPR PSD will conduct periodic reinvestigations every 5 years, or when derogatory information is received, to evaluate continued Fitness of Contractor employees.

Page 19 of 21 RFQ# 70CTD024Q00000107

The Federal Government is transitioning to Trusted Workforce (TW) 2.0. TW 2.0 is a whole-of-government background investigation reform effort overhauling the personnel vetting process by creating a government-wide system that allows transfer of trust across organizations. All contractor employees will be subjected to the transition and will be enrolled into continuous vetting at a date to be determined and via a to be determined continuous vetting system.

Enrollment will include multiple requirements from all personnel and potential changes to processes, procedures, and systems. This contract will comply with all requirements that facilitate the mandated transition to TW 2.0.

REQUIRED REPORTS

The Contractor will notify OPR PSD, via the COR providing an ICE Form 50-005, Contractor Employee Separation Clearance Checklist, of all terminations/resignations of Contractor employees under the contract within five days of occurrence to the ICEDepartureNotification@ice.dhs.gov group box. The Contractor will return any expired ICE issued identification cards and building passes of terminated/resigned employees to the COR. If an identification card or building pass is not available to be returned, a report must be submitted to the COR referencing the pass or card number, name of individual to whom issued, the last known location and disposition of the pass or card. The COR will return the identification cards and building passes to the responsible ID Unit.

The Contractor will report any adverse information coming to their attention concerning Contractor employees under the contract to OPR PSD, via the COR, as soon as possible. Reports based on rumor or innuendo should not be made. The subsequent termination of employment of an employee does not obviate the requirement to submit this report. The report shall include the Contractor employees’ name and social security number, along with the adverse information being reported.

The Contractor will provide, through the COR, a Quarterly Report (on a Microsoft Excel Spreadsheet) containing the names of Contractor employees who are actively serving on their contract. The list shall include the Name, Position and SSN (Last Four) and should be derived from system(s) used for Contractor payroll/voucher processing to ensure accuracy. This list is what ICE Industrial Security uses to reconcile the contract quarterly. CORs will submit reports to PSD-Industrial-Security@ice.dhs.gov no later than the 10th day of each January, April, July and October.

Contractors, who are involved with management and/or use of information/data deemed “sensitive” to include ‘law enforcement sensitive” are required to complete the DHS Form 11000-6-Sensitive but Unclassified Information Non-Disclosure Agreement (NDA) for Contractor employee access to sensitive information. The NDA will be administered by the COR to all contract personnel within 10 calendar days of the entry on duty date.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .