2.2.1 ATTACHMENT B- SOW.pdf

PDF 362 KB Posted

Attached to
BUS and VAN Lease Federal contract opportunity
Solicitation number
70B03C23R00000078
Issued by
Department of Homeland Security Customs and Border Protection

About this file

This statement of work describes requirements for a bus and van lease contract to support detainee transportation for U.S. Customs and Border Protection. The contractor shall provide 45 buses across 10 Border Patrol sectors and 28 vans across three field offices to transport detainees from apprehension to processing locations. Buses must seat a minimum of 47 passengers and include security features separating the driver from detainees. Vans must seat 15 passengers and also include security enclosures. The contractor must deliver the vehicles within seven days of award and maintain them according to industry standards. The base period of performance is six months with four six-month option periods allowing for potential award extension. The contractor must comply with security, privacy, and accessibility requirements described for handling sensitive personally identifiable information and detainees.

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work (SOW) For

Southwest Border (SWB)

Detainee Transportation Vehicle Lease

1. BACKGROUND:

The United States Border Patrol (USBP), headed by the Chief, USBP, is the primary federal law enforcement organization responsible for preventing the entry of terrorists and their weapons from entering the United States between official Customs and Border Protection (CBP) ports of entry. The USBP is also responsible for preventing the illicit trafficking of people and contraband between the official ports of entry.

Congress officially established the USBP on May 28, 1924, by passing an act in response to increasing illegal immigration. As mandated by this Act, the small border guard in what was then the Bureau of Immigration reorganized into the USBP. The initial force of 450 officers received the responsibility of combating illegal entries and the growing business of alien smuggling. Today, the USBP has a work force of more than 20,000 agents and 2,000 mission support personnel.

The USBP is specifically responsible for patrolling the 6,000 miles of Mexican and Canadian international land borders and 2,000 miles of coastal waters surrounding the Florida Peninsula and the island of Puerto Rico. Agents work around the clock on assignments, in all types of terrain and weather conditions. Agents also work in many isolated communities throughout the United States. Currently, the USBP is facing a surge in illegal migration along the Southwest border (SWB), straining USBP capabilities including detainee transportation.

In support of its mission, the USBP anticipates increased requirements for detainee transportation vehicle capabilities along the Southwest border. These capabilities must deploy the most efficient mix of detention vehicles capable of adjusting to changes in transportation demand that may vary by shift, day, week, or season. The solution includes the use of detainee transportation vehicles, which strike a proper balance in terms of timeliness and efficiency, to support unique demands of frontline agents and officers.

This solution supports operational mission requirements established by the USBP. Throughout this SOW, use of the term “Government” is interchangeable with USBP and Office of Field Operations (OFO).

2. SCOPE:

The Contractor(s) shall provide and satisfy the leasing requirement transportation vehicles per respective sector for 10 USBP sectors (45 buses ) and 28 vans to Office of Field Operations (OFO) across three different Field Offices. Each sector will be a separate Contract Line Item Number (CLIN). Transportation vehicle requirements will be from location to location (by CLIN). Transportation vehicles will entail over-the-road transport in vehicles of sufficient capacity to meet the performance standards. CBP will use the vehicles to support courtroom transportation, detention facility booking transportation, security services, and other related transportation duties.

Two components of CBP will be supported in this contract: USBP and OFO.

The USBP requires a leasing quantity of 45 vehicles to transport detainees in support of ongoing enforcement and detention actions along the southwest border (SWB.) Detainee transport operations include, but is not limited to, the movement of detainees from the point of apprehension to Border Patrol Stations, Field Offices, Ports of Entry, highway immigration checkpoints, processing centers, hospitals, courts and detention centers.

OFO requires a leasing quantity of 28 vehicles to transport detainees in support of ongoing enforcement and detention actions along the SWB. Detainee transport operations include, but is not limited to, the movement of detainees from the point of apprehension to Border Patrol Stations, Field Offices, Ports of Entry, highway immigration checkpoints, processing centers, hospitals, courts and detention centers.

USBP reserves the right to move any vehicle associated with this agreement to any of the listed Ports of Entry or Sectors due to a surge or an increase in migrant activity.

3. SPECIFIC TASKS:

The specific tasks for this SOW are to provide secure detainee transportation vehicles for detainees in USBP custody in an effective, efficient, and flexible manner to meet the Government’s operational requirements throughout the SWB.

3.1. Operational Requirements

3.1.1. The Contractor(s) shall provide ten (10) buses to the Del Rio Sector (Del Rio

Sector HQ 2401 Dodson Avenue Del Rio, TX 78840). The details regarding the buses are referenced in section 3.2.1.

3.1.2. The Contractor(s) shall provide five (5) buses to the Laredo Sector (207 W. Del Mar Blvd. Laredo, TX 78041). The details regarding the buses are referenced in section 3.2.1.

3.1.3. The Contractor(s) shall provide eight (8) buses to the El Paso Sector (8901 Montana Avenue El Paso, Texas 79925). The details regarding the buses are referenced in section 3.2.1.

3.1.4. The Contractor(s) shall provide eight (8) buses to the Rio Grande Valley Sector (3000 West Military Highway, McAllen TX 78503). The details regarding the buses are referenced in section 3.2.1.

3.1.5. The Contractor(s) shall provide two (2) buses to the Yuma Sector (4035 S. Avenue A, Yuma, AZ 85365). The details regarding the vans are referenced in section 3.2.1.

3.1.6. The Contractor(s) shall provide four (4) buses to the Tucson Sector (2340 S Swan Rd Ste 7, Tucson, AZ 85711).

3.1.7. The Contractor(s) shall provide three (3) buses to the San Diego Sector (7682 Pogo Row, San Diego, CA 92154). The details regarding the buses are referenced in section 3.2.1.

3.1.8. The Contractor(s) shall provide two (2) buses to the El Centro Sector (211 W Aten Rd., Imperial, CA 92251). The details regarding the buses are referenced in section 3.2.1.

3.1.9. The Contractor(s) shall provide one (1) buses to the Miami Sector (15720 Pines Boulevard, Pembroke Pines, FL 33027). The details regarding the buses are referenced in section 3.2.1.

3.1.10. The Contractor(s) shall provide two (2) buses to the Swanton Sector (155 Grand Avenue, Swanton, VT 05488). The details regarding the buses are referenced in section 3.2.1.

3.1.11. The Contractor(s) shall provide 13 vans to the San Diego Field Office. The details regarding the vans and vans are referenced in sections 3.2.2.

a. Four (4) vans to San Ysidro Port of Entry (720 E San Ysidro Blvd, San Diego, CA 92173.)

b. Three (3) vans to Otay Mesa Port of Entry (9777 Via De La Amistad, San Diego, CA 92154.)

c. Six (6) vans to Calexico Port of Entry (200 E 1st St, Calexico, CA 92231.)

3.1.12. The Contractor(s) shall provide up to six (6) vans to the Tucson Field Office:

a. One (1) van to Douglas Port of Entry (First Street and Pan American Ave, Douglas, AZ 85607.)

b. One (1) van to Naco Port of Entry (3867 S. Towner Ave Naco, AZ 85620.)

c. One (1) van to Nogales Port of Entry (9 North Grand Ave Nogales, AZ 85621.)

d. One (1) van to Sasabe Port of Entry (Highway 286 and International Border, Sasabe, AZ 85633.)

e. One (1) van to Lukeville Port of Entry (Highway 85 & Border, Lukeville, AZ

85341.)

f. One (1) van to San Luis Port of Entry (Highway 95 & International Border, San

Luis, AZ 85349.)

3.1.13. The Contractor(s) shall provide nine (9) vans to the El Paso Field Office (1400

Lower Island Rd (FM 3380), Tornillo, TX 79853.) The details regarding the vans are referenced in section 3.2.2.

3.2. Technical Requirements

The Contractor(s) shall comply with the following Technical Requirements:

3.2.1. Vehicle Operability/Interior Security Specifications

Task Requirement for buses:

Vehicles used to transport detainees shall be of adequate design with features and equipment to ensure security:

• All vehicles shall be fully operational upon delivery. Fully operational includes but not limited to being mechanically sound, roadworthy, licensed to operate in all southwest border states (California, Arizona, New Mexico, and Texas), Florida and Vermont. All buses shall be capable of immediate integration into the USBP fleet and retrofitted with a secure detention package (caged compartment) to prevent access to driver and armed guard by detainees and facilitate the immediate movement of USBP detainees.

• Minimum (47) passenger capacity.

• Separate and secure the driver/driving team (two personnel) from the detainees via chain link compartment.

• Front passenger compartment shall segregate at least eight (8) seats, no more than 12 seats, from the rear passenger compartment to enable separation between detained males, females, and unaccompanied juveniles.

• A secure lock box for detainee records via lock and key.

• Detainees shall be unable to open doors and windows from inside of the detainee compartment.

• Detainees shall be unable to open doors and windows from inside of the detainee compartment.

• Audible alarm system to detect tampering with or opening the vehicle’s emergency hatch, if installed in association with Department of Transportation regulations.

• Heating, cooling, and ventilation of the transport vehicle adequate to operate sufficiently in desert and winter environments for the duration of each shift.

• Vehicle navigation and communications systems that are capable of immediately notifying Federal law enforcement officials in the event of a detainee escape.

• Interior and exterior video and audio recording system to document both driver team and detainee status during daytime or nighttime operations.

Video and audio coverage and quality shall be sufficient to allow for post-operation review and audit of any incident. Interior video shall cover the entire secure area within the vehicle, minus restrooms. Exterior video shall provide full picture of both sides and rear of the vehicle. The Contractor(s) shall save recorded video and audio on a minimum two (2) terabyte storage device or saved to a remote storage system (i.e., the cloud) where USBP personnel can gain access. The bus shall have a data capacity for the server to log video recordings. It is currently set at 2 terabyte at a 90 day timeframe.

• On-board rest rooms fitted with stainless steel toilets and hand basins, and hand sanitizer dispenser.

• The Contractor(s) shall outfit rest room with a door that is securable from outside the rest room with a lock. The door must contain a latching mechanism that prevents the door from opening freely. Construction of the door of materials similar in size and dimension to doors separating the cabin compartment. The door must also have hinge(s)/hinge stops that limit the door from opening greater than 90 degrees.

Task Requirement for vans:

• All vehicles shall be fully operational upon delivery. Fully operational includes but not limited to being mechanically sound, roadworthy, licensed to operate in all southwest border states (California, Arizona, New Mexico and Texas). All vans shall be capable of immediate integration into the CBP fleet and retrofitted with a secure detention package (caged compartment) to prevent access to driver and armed guard by detainees and facilitate the immediate movement of CBP detainees.

• (15) passenger capacity.

• Separate and secure the driver/driving team (up to two personnel) from the detainees via chain link compartment.

• A secure lock box for detainee records via lock and key.

• Detainees shall be unable to open doors and windows from inside of the detainee compartment.

• Escape prevention systems (i.e., detention enclosures.)

• Audible alarm system to detect tampering with or opening the vehicle’s emergency hatch, if installed in association with Department of Transportation regulations.

• Heating, cooling, and ventilation of the transport vehicle adequate to operate sufficiently in desert environments for the duration of each shift.

• Vehicle navigation and communications systems that are capable of immediately notifying Federal law enforcement officials in the event of a detainee escape.

• Interior and exterior video and audio recording system to document both driver team and detainee status during daytime or nighttime operations.

Video and audio coverage and quality shall be sufficient to allow for post-operation review and audit of any incident. Interior video shall cover the entire secure area within the vehicle, minus restrooms. Exterior video shall provide full picture of both sides and rear of the vehicle. The Contractor(s) shall save recorded video and audio on a minimum two (2) terabyte storage device or saved to a remote storage system (i.e., the cloud) where CBP personnel can gain access.

• No van shall require a Commercial Driver’s License-Passenger (CDL-P).

• Vans shall be leased on a month-to-month basis.

• Tracking system for buses (geotab, fleetmatics, etc) be activated. The previous used buses have the hardware installed for the G$S bus tracking system.

3.2.2. Vehicle Operating Condition, Security and Cleanliness (Exterior and

Interior) Task Requirement:

The Contractor(s) shall maintain vehicles in good repair to ensure safety and serviceability and shall comply with inspection requirements. Vehicle security features shall remain in good serviceable condition.

Vehicles shall be manufactured no earlier than 2000 due and shall possess capability of telematics installation.

Vehicle interiors must not contain dirt, dust, trash, graffiti, stains, gum, or any kind of residue on any interior surface. Prior to delivery, a bio wash of the interior cleaning event shall occur that uses a concentrated hospital grade liquid detergent, cleaner, sanitizer, fungicide, and mildew stat to aid in the prevention of communicable disease.

The bus drivers seat shall have the ability to be repositionable.

The Contractor(s) shall deliver vehicles fully fueled and inspected prior to delivery.

3.2 Fleet Maintenance

Describe the activities and events required to achieve maintainability goals including explicit definition of the maintainability goals. Include a detailed description of the maintenance concept, the collection of maintenance data, maintenance activities based on level of complexity (to include preventive maintenance), level of effort and availability of assets, and ability to provide uninterrupted vehicle replacement with identical capabilities during periods of inoperability due to maintenance.

• CBP shall bring vehicles requiring service to one of the Contractor(s)’s facilities at industry standard service intervals (e.g., at least every 3,000 miles for inspection and services, never to exceed 3,500 miles.)

• The Contractor(s) shall provide the Government with written instructions on industry standard service intervals (service intervals shall comprise a combination of hours/mileage.)

• Provisioning of roadside assistance shall include transportation to maintenance facilities for major repairs and redelivery of vehicles to the specified USBP Sector following repairs.

• The Contractor(s) will provide like replacement vehicles when it anticipates vehicles to be in repair/maintenance for more than five (5) days.

Removal of vehicles must occur within 30 days of contract expiration/termination.

Locations, Sectors and Ports of Entry are subject to change based on migrant conditions in a specific area.

4. DELIVERY

The Contractor(s) shall deliver detainee transportation vehicles to various Sectors:

SECTOR QUANTITY ADDRESS

Del Rio Sector (10) buses 2401 Dodson Avenue Del Rio, TX 78840

Laredo Sector (5) buses 207 W. Del Mar Blvd. Laredo, TX 78041

El Paso Sector (8) buses 8901 Montana Avenue El Paso, TX 79925

Rio Grande

Valley Sector

(8) buses 3000 West Military Highway, McAllen TX 78503 Yuma Sector (2) buses 4035 S. Avenue A, Yuma, AZ

85365 Tucson Sector (4) buses 2340 S Swan Rd Ste 7, Tucson, AZ 85711

San Diego

Sector

(3) buses 7682 Pogo Row, San Diego, CA

92154 El Centro

Sector

(2) buses 211 W Aten Rd., Imperial, CA

92251 Miami Sector (1) buses 15720 Pines Boulevard, Pembroke Pines, FL 33027 Swanton

Sector

(2) buses 155 Grand Avenue, Swanton, VT 05488

SAN DIEGO

FIELD OFFICE

QUANTITY ADDRESS

San Ysidro Port of Entry

(4) vans 720 E San Ysidro Blvd, San Diego, CA 92173

Otay Mesa Port of Entry

(3) vans 9777 Via De La Amistad, San Diego, CA 92154

Calexico Port of Entry

(6) vans 200 E 1st St, Calexico, CA 92231

TUCSON FIELD

OFFICE

Douglas Port of Entry

(1) van First Street and Pan American Ave, Douglas, AZ 85607

Naco Port of Entry

(1) van 3867 S. Towner Ave, Naco, AZ 85620

Nogales Port of Entry

(1) van 9 North Grand Ave, Nogales, AZ 85621

Sasabe Port of Entry

(1) van Highway 286 and International Border, Sasabe, AZ 85633

Lukeville Port of Entry

(1) van Highway 85 & Border, Lukeville, AZ 85341

San Luis Port of Entry

(1) van Highway 95 & International Border, San Luis, AZ 85349

EL PASO

FIELD OFFICE

El Paso Field Office

(9) vans 1400 Lower Island Rd (FM 3380), Tornillo, TX 79853

5. DELIVERABLES AND DELIVERY SCHEDULE

Contractor(s) must be able to provide a plan of vehicles available and the plan for deployment. The plans must be detailed by Sectors.

Lead time for vehicle delivery is as follows:

• Vehicle requirement must be delivered within seven (7) days after contract award.

• The government reserves the right to add additional buses not to exceed 67, contingent on increased migrant activity at any of the sectors.

• Each period of performance will have 4 optional Clins of 5 units and one Clin of 2 units that can be exercised within the period to add more units.

6. EQUIPMENT

Contractor(s) shall have the capability to deliver the maximum number of vehicles to their respective contracted sites within seven (7) days of receipt of order. Initial quantity of vehicles for each site will be confirmed upon contract award.

7. GOVERNMENT-FURNISHED EQUIPMENT/INFORMATION (GFE/GFI):

The Government anticipates providing and installing GFE in the form of Telematics Equipment to collect real time utilization data. Equipment should, at a minimum capture, odometer reading, engine run hours, engine idle hours, trips per day, and days of use.

8. PERIOD OF PERFORMANCE:

6-month base period and one (1) 6-month option period.

9. SECURITY:

There are no specific security classification level requirements associated with this procurement action. Information is unclassified.

10. SPECIAL CONSIDERATIONS:

10.1. Changes to the SOW

No changes to the SOW or cost increases shall incur without written prior approval of the CO as coordinated by the COR. Any changes or cost increases will not take effect until the CO executes a written modification.

11. POINTS OF CONTACT:

Contracting Officer:

Rosie Zaragoza-Santos Division/Department Border Enforcement Contracting Division-Central Contracting Officer Phone: 830-778-7077 Email: rosie.zaragoza@cbp.dhs.gov

Contracting Officer’s Representative Oscar McCullough U.S. Customs and Border Protection Phone: 808-285-1578 Email: oscar.mccullough@cbp.dhs.gov

SECURITY AND SPECIAL CONSIDERATIONS

CBP Contractor Handling Personally Identifiable Information (PII) Level

“When a contractor, on the behalf of CBP, handles Sensitive PII data, stores and transmits, the contractor will Accredit (ATO) this information system to the (HHM) FIPS level” Department of Homeland Security (DHS) Security Policy Requirement The following terms and conditions should be included in all acquisition documents.

All hardware, software, and services provided under this task order must be compliant with DHS 4300A DHS Sensitive System Handbook and the DHS Management Directive 140-01, Information Security Program.

Encryption Compliance Requirement The following terms and conditions should be included in all acquisition documents.

1. Systems requiring encryption shall comply with FIPS 197 (Advanced Encryption Standard (AES)) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2.

2. Systems requiring encryption shall comply with National Security Agency (NSA) Type 2 or Type 1 encryption.

3. Only cryptographic modules that are FIPS 197 (AES 256) compliant and have received FIPS 140-2 validation at the level appropriate to their intended use may be used in systems requiring encryption.

mailto:rosie.zaragoza@cbp.dhs.gov mailto:oscar.mccullough@cbp.dhs.go

Public Key Infrastructure (PKI) (see paragraph 5.5.2.l of the DHS Sensitive Systems Policy Directive 4300A.).

Security Review

The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, including the organization of the DHS Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer’s Representative (COR), and other government oversight organizations, access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to the DHS. The Contractor shall provide access to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of DHS data or the function of computer systems operated on behalf of DHS, and to preserve evidence of computer crime.

Product Assurance Information Assurance (IA) is considered a requirement for all systems used to input, process, store, display, or transmit sensitive or national security information. IA is achieved through the acquisition and appropriate implementation of evaluated or validated commercial-off-the-shelf (COTS) IA and IA-enabled Information Technology (IT) products. These products provide for the availability of systems. The products also ensure the integrity and confidentiality of information and the authentication and nonrepudiation of parties in electronic transactions.

Supply Chain Risk Management The following requirements should be included in all hardware and software requests to ensure the confidentiality, integrity, and availability of government information.

The Contractors supplying the Government hardware and software shall provide the manufacture’s name, address, state and/or domain of registration, and the Data Universal Numbering System (DUNS) number for all components comprising the hardware and software.

If subcontractors or subcomponents are used, the name, address, state and/or domain of registration and DUNs number of those suppliers must be provided.

Subcontractors are subject to the same general requirements and standards as prime contractors.

Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.

The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.

Contractors shall provide, implement, and maintain a Supply Chain Risk Management Plan that addresses internal and external practices and controls employed to minimize the risk posed by counterfeits and vulnerabilities in systems, components, and software.

The Plan shall describe the processes and procedures that will be followed to ensure appropriate supply chain protection of information system resources developed, processed, or used under this contract. The Plan shall align with the Government’s supply chain risk reduction strategy.

The Supply Chain Risk Management Plan shall address the following elements:

4. How risks from the supply chain will be identified.

5. How commercial-off-the-shelf (COTS) hardware and software products considered for use in moderate and high criticality systems will be assessed for supply chain risk prior to acquisition, upgrade, or integration.

6. What processes and security measures will be adopted to manage these risks to the system or system components

7. How the risks and associated security measures will be updated and monitored.

8. How the Contractor will inform the Government of emerging risks, the status of managed risks, and risks becoming issues.

The Supply Chain Risk Management Plan shall remain current through the life of the contract or period of performance. The Supply Chain Risk Management Plan shall be provided to the Contracting Officer’s Representative (COR) 30 days post award. The Contractor shall review and update the Plan annually and following the identification of emerging risks requiring modification to the Plan. Updates to the Plan shall be provided to the COR within 30 days of the identification of the need for update.

The Contractor acknowledges the Government's requirement to assess the Contractors Supply Chain Risk posture. The Contractor understands and agrees that the Government retains the right to cancel or terminate the contract, if the Government determines that continuing the contract presents an unacceptable risk to national security.

The Contractor shall disclose, and the Government will consider, relevant industry standards certifications, recognitions and awards, and acknowledgments.

The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the Contracting Officer (CO). Contractors shall only provide Original Equipment Manufacturers (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must also be OEM parts.

The Contractor shall be excused from using new OEM (i.e., “grey market,” previously used) components only with formal Government approval. Such components shall be procured from their original genuine source and have the components shipped only from manufacturers authorized shipment points.

For software products, the contractor shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “end of life.”). Software updates and patches must be made available to the government for all products procured under this contract.

Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.

All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lesser of the term of the contract, the period of performance, or one calendar year from the date the activity occurred.

These records must be readily available for inspection by any agent designated by the U.S.

Government as having the authority to examine them.

This transit process shall minimize the number of times en-route components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments. The supplier, at the Government’s request, shall be able to provide shipping status at any time during transit.

The Contractor is fully liable for all damage, deterioration, or losses incurred during shipment and handling, unless the damage, deterioration, or loss is due to the Government. The Contractor shall provide a packing slip which shall accompany each container or package with the information identifying the contract number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact. The contractor shall send a shipping notification to the intended government recipient or contracting officer. This shipping notification shall be sent electronically and will state the contract number, the order number, a description of the hardware/software being shipped (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.

a. The Offeror understands and agrees that the Government retains the right to cancel or terminate the Contract, if the Government determines that continuing this solicitation presents an unacceptable risk to national security.

b. “Gray-Market” Equipment

i. The Offeror shall provide only new equipment unless otherwise expressly approved, in writing, by the DHS Contracting Officer. Offerors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.

ii. The Offeror shall be excused from using new OEM (i.e., "gray market”, "previously used”) components only with formal Government approval, in writing, from the DHS Contracting Officer. Such components shall be procured from their original source and shipped only from the manufacturer’s authorized shipment points.

iii. All equipment obtained by the Offeror on behalf of the Government will need to be provided to OIG OCIO for review to validate requirements and approved Contractors by DHS.

c. Hardware and Software Requests

i. The contractors supply the Government hardware and software will provide the manufacturer’s name, address, state, and/or domain of registration, and the DUNS number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNS number of those suppliers must be provided.

ii. Subcontractors are subject to the same general requirements and standards as prime contractors. Contractors employing subcontractors will perform due diligence to ensure that these standards are met.

iii. The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.

1. For software products, the Offeror shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “End of Life (EoL)"). Software updates and patches shall be either: made available to the government for all products procured under this Contract, replaced upon End of Support (EoS) is reached, or formally waived (in writing) by the DHS Contracting Officer.

d. Supply-Chain Transport

i. Offerors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill Contract obligations with the Government.

ii. All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the Contract, the period of performance, or one calendar year from the date the activity occurred.

iii. This transit process shall minimize the number of times in route components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments.

The supplier, at the Government's request, shall be able to provide shipping status at any time during transit.

iv. All records pertaining to the transit, storage, and delivery shall be readily available for inspection by any agent designated by the U.S. Government as having the authority to examine them.

v. The Offeror is fully liable for all damage, deterioration, or losses incurred during shipping and handling, unless the damage, deterioration, or loss is due to the Government.

vi. The Offeror shall provide a packing slip which shall accompany each container or package with the information identifying this solicitation number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact.

vii. The Offeror shall send a shipping notification to the intended government recipient; with a copy transmitted via email to the Contracting Officer, or designated representative. This shipping notification shall be sent electronically and will state this solicitation number, the order number, a description of the hardware/software being ship (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.

e. Notifications

i. The Offeror shall notify DHS Contracting Officer, COR and the Office of the Chief Information Officer and the DHS component Chief Information Officer through the Enterprise Security Operations Center (ESOC) directly of any suspected or potential violations of Section 889 of the National Defense Authorization Act (NDAA) for Information Communications Technology (ICT) at NDAA_Incidents@hq.dhs.gov.

f. Foreign Equities The Offeror shall immediately notify the DHS Contracting Officer, COR that will report to the Office of the Chief Security Officer (OCSO) or cognizant component personnel security office regarding any changes to corporate foreign ownership, control, or influence.

12. SECURITY REQUIREMENTS FOR UNCLASSIFIED INFORMATION

TECHNOLOGY RESOURCES (JUN 2006)

(a) The Contractor shall be responsible for Information Technology (IT) security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency’s mission.

(b) The Contractor shall provide, implement, and maintain an IT Security Plan. This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.

(1) Within thirty (30) days after contract award, the contractor shall submit for approval its IT Security Plan, which shall be consistent with and further detail the approach contained in the offeror's proposal. The plan, as approved by the Contracting Officer, shall be incorporated into the contract as a compliance document.

(2) The Contractor’s IT Security Plan shall comply with Federal laws that include, but are not limited to, the Computer Security Act of 1987 (40 U.S.C. 1441 et seq.); the Government Information Security Reform Act of 2000; and the Federal Information Security Modernization Act of 2014; and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130.

(3) The security plan shall specifically include instructions regarding handling and protecting sensitive information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.

(c) Examples of tasks that require security provisions include:

(1) Acquisition, transmission, or analysis of data owned by DHS with significant replacement cost should the contractor’s copy be corrupted; and

(2) Access to DHS networks or computers at a level beyond that granted the general public (e.g., such as bypassing a firewall).

(d) At the expiration of the contract, the contractor shall return all sensitive DHS information and IT resources provided to the contractor during the contract and certify that all non-public DHS information has been purged from any contractor-owned system. Components shall conduct reviews to ensure that the security requirements in the contract are implemented and enforced.

(e) Within 6 months after contract award, the contractor shall submit written proof of IT Security authorization to DHS for approval by the DHS Contracting Officer. Security authorization will proceed according to the criteria of the DHS Sensitive System Policy Directive, 4300A (Version 13.1, July 27, 2017) or any replacement publication, which the Contracting Officer will provide upon request. This accreditation will include a final security plan, security assessment plan, security assessment report, and contingency plan, and contingency plan test. This Authorization, when accepted by the Contracting Officer, shall be incorporated into the contract as a compliance document. The contractor shall comply with the approved Security Authorization documentation.

(End of clause)

13. CBP Contractor Handling PII Level

“When a contractor, on the behalf of CBP, handles Sensitive PII data, stores and transmits, the contractor will Accredit (ATO) this information system to the (HHM) FIPS level”

14. DHS Security Policy Requirement

The following terms and conditions should be included in all acquisition documents:

All hardware, software, and services provided under this task order must be compliant with DHS 4300A DHS Sensitive System Handbook and the DHS Management Directive 140-01, Information Security Program.

Alternate I (SEP 2012) When the contract will require Contractor employees to have access to IT resources, add the following paragraphs:

(g) Before receiving access to IT resources under this contract the individual must receive a security briefing, which the Contracting Officer's Technical Representative (COTR) will arrange and complete any nondisclosure agreement furnished by DHS.

(h) The Contractor shall have access only to those areas of DHS information technology resources explicitly stated in this contract or approved by the COTR in writing as necessary for performance of the work under this contract. Any attempts by Contractor personnel to gain access to any information technology resources not expressly authorized by the statement of work, other terms and conditions in this contract, or as approved in writing by the COTR is strictly prohibited. In the event of violation of this provision, DHS will take appropriate actions with regard to the contract and the individual(s) involved.

(i) Contractor access to DHS networks from a remote location is a temporary privilege for mutual convenience while the Contractor performs business for the DHS Component. It is not a right, a guarantee of access, a condition of the contract, or Government Furnished Equipment (GFE).

(j) Contractor access will be terminated for unauthorized use. The Contractor agrees to hold and save DHS harmless from any unauthorized use and agrees not to request additional time or money under the contract for any delays resulting from unauthorized use or access.

(k) Non-U.S. citizens shall not be authorized to access or assist in the development, operation, management or maintenance of Department IT systems under the contract, unless a waiver has been granted by the Head of the Component or designee, with the concurrence of both the Department's Chief Security Officer (CSO) and the Chief Information Officer (CIO) or their designees. Within DHS Headquarters, the waiver may be granted only with the approval of both the CSO and the CIO or their designees. In order for a waiver to be granted:

(1) There must be a compelling reason for using this individual as opposed to a U.S. citizen; and,

(2) The waiver must be in the best interest of the Government.

(l) Contractors shall identify in their proposals the names and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the Contracting Officer.

Alternate II (JUN 2006) When the Department has determined contract employee access to sensitive information or Government facilities must be limited to U.S. citizens and lawful permanent residents, but the contract will not require access to IT resources, add the following paragraphs:

(l) Each individual employed under the contract shall be a citizen of the United States of America, or an alien who has been lawfully admitted for permanent residence as evidenced by a Permanent Resident Card (USCIS I-551). Any exceptions must be approved by the Department's Chief Security Officer or designee.

(m) Contractors shall identify in their proposals, the names and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the Contracting Officer.

15. INFORMATION TECHNOLOGY SECURITY AND PRIVACY TRAINING (MAR

2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Security Training Requirements.

(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. DHS requires that Contractor employees complete an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year.

The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.

(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within thirty (30) days of contract award. Any new Contractor employees assigned to the contract shall also sign the DHS Rules of Behavior before accessing DHS systems and sensitive information. The Contractor shall maintain signed copies of the DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance.

Unless otherwise specified, the Contractor shall e-mail copies of the signed DHS Rules of Behavior to the COR not later than thirty (30) days after contract award for each employee. The

DHS Rules of Behavior will be reviewed annually, and the COR will provide notification when a review is required.

(c) Privacy Training Requirements. All Contractor and subcontractor employees that will have access to Personally Identifiable Information (PII) and/or Sensitive PII (SPII) are required to take Privacy at DHS: Protecting Personal Information before accessing PII and/or SPII. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors.

Training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall also complete the training before accessing PII and/or SPII. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Initial training certificates for each Contractor and subcontractor employee shall be provided to the COR not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year. The email notification shall state the required training has been completed for all Contractor and subcontractor employees.

15. SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause— “Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations;

Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and,

(4) Any information that is designated “sensitive” or subject to other controls, safeguards, or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .