2nd Quarter 2024 Bread Solicitation -C.pdf
PDF 237 KB Posted
- Attached to
- BREAD 2ND QTR FY2024 Federal contract opportunity
- Solicitation number
- 15B31724Q00000006
About this file
This solicitation is for bread products to be delivered to the Federal Correctional Institution in Bennettsville, South Carolina for the second quarter of fiscal year 2024. The solicitation seeks firm fixed pricing for various bread items including enriched finger rolls, sandwich breads made from white, whole wheat or multigrain flour, and sliced bread in 24 ounce loaves. The response due date is November 30, 2023. The solicitation incorporates standard clauses related to small business participation goals, terms and conditions for commercial products and services, and contract provisions implementing statutes and executive orders.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Solicitation Letter Bread.docx | DOCX document | |
| Bread Schedule 2nd Qtr FY2024.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
15B31724Q00000006 Page 1 of 46
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 AND 30.
1. REQUISITION NUMBER PAGE 1 OF
5. SOLICITATION NUMBER
15B31724Q00000006
2. CONTRACT NUMBER 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 6. SOLICITATION ISSUE
DATE
11/07/2023
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
Eric Clyburn eclyburn@bop.gov
b. TELEPHONE NUMBER (No collect calls)
843-454-8225
8. OFFER DUE DATE / LOCAL
TIME
11/30/2023 16:00 ET
CODE 15B317
Federal Bureau of Prisons
FCI Bennettsville
696 Muckerman Road
Bennettsville, SC 29512
9. ISSUED BY UNRESTRICTED OR X SET ASIDE:100.00 % FOR
X SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
(SDVOSB)
WOMEN-OWNED SMALL
BUSINESS (WOSB)
ECONOMICALLY DISADVANTAGED
WOMEN-OWNED SMALL BUSINESS
(EDWOSB)
8(A)
NORTH AMERICAN
INDUSTRY CLASSIFICATION
STANDARD (NAICS):
SIZE STANDARD:
500 Employees
10. THE ACQUISITION IS
SEE SCHEDULE
11. DELIVERY FOR FREE ON BOARD
(FOB) DESTINATION UNLESS
BLOCK IS MARKED
NET 30
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER THE
DEFENSE PRIORITIES AND
ALLOCATIONS SYSTEM -
DPAS (15 CFR 700)
13b. RATING
X REQUEST
FOR QUOTE
(RFQ)
INVITATION
FOR BID
(IFB)
REQUEST
FOR
PROPOSAL
(RFP)
14. METHOD OF SOLICITATION
15B317CODE15. DELIVER TO
Federal Bureau of Prisons FCI Bennettsville 696 Muckerman Road Bennettsville, SC 29512
CODE16. ADMINISTERED BY
FACILITY
CODE
CODE
TELEPHONE NUMBER
17a. CONTRACTOR/
OFFEROR
15B317CODE18a. PAYMENT WILL BE MADE BY
Federal Bureau of Prisons FCI Bennettsville 696 Muckerman Road Bennettsville, SC 29512
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER SEE ADDENDUM
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
19.
ITEM NUMBER
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
FY 2024 1ST QTR. BREAD PRODUCTS FOR FCI
BENNETTSVILLE
PLEASE INCLUDE YOUR:
UNIQUE ENTITY ID
DUNS#______________________________________
PHONE#_____________________________________
FIRM FIXED PRICE
Firm Fixed Price See Continuation Sheet(s)
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)
X 27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4. FAR 52.212-3
AND 52.212-5 ARE ATTACHED. ADDENDA
ARE X ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
X 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN ____ COPIES TO
ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH
OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE
TERMS AND CONDITIONS SPECIFIED.
29. AWARD OF CONTRACT: REFERENCE _____________________________
OFFER DATED _________________ . YOUR OFFER ON SOLICITATION (BLOCK
5) INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH
HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED 31b. NAME OF THE CONTRACTING OFFICER (Type or print)
Eric L Clyburn
31c. DATE SIGNED
11/07/2023
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 11/2021)
Prescribed by GSA - FAR (48 CFR) 53.212
15B31724Q00000006 Page 2 of 46
19.
ITEM NUMBER
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: _________________________________
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
PARTIAL FINAL
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
COMPLETE PARTIAL FINAL
36. PAYMENT 37. CHECK NUMBER
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 11/2021) BACK
15B31724Q00000006 Page 3 of 46
Table of Contents
Section Description Page Number
Solicitation/Contract Form 1 Commodity or Services Schedule 2 Contract Clauses
DOJ-05 Security of Department Information and Systems DOJ-05 (OCT 2023) DOJ-02 Contractor Privacy Requirements (JAN 2022) 52.212-4 Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2023) 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders- Commercial Products and Commercial Services (Nov 2023)
3 List of Attachments 4 Solicitation Provisions
52.212-1 Instructions to Offerors-Commercial Products and Commercial Services (Sep 2023) 52.212-3 Offeror Representations and Certifications-Commercial Products and Commercial Services (Nov 2023)
15B31724Q00000006 Page 4 of 46
Section 1 - Commodity or Services Schedule
SCHEDULE OF SUPPLIES/SERVICES
CONTINUATION SHEET
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 Bread, Roll, Enriched, Finger (Hot Dog), Wheat, Pan Baked, Sliced, Fresh, Seedless. (CID A-A-20053C, Type I, Class of Roll D, Style of Roll 3, Bake Type a, Slice Type i, Product State a, Seed type I, Agricultural practice (i)).
Fresh bread shall be delivered within 48 hours after baking. State package size on bid. 12 pack.
PSC: 8920
Base Period
5,304 EA $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0002 Bread, Roll, Enriched, Sandwich (Hamburger), Whole Wheat, Part Whole Wheat, or Multigrain, Pan Baked, Sliced, Fresh, Seedless.
(CID A-A-20053C, Type I, Class of Roll C, Style of Roll 2, 3, or 4, Bake Type a, Slice Type i, Product State a, Seed type I, Agricultural practice (i)). Fresh bread shall be delivered within 48 hours after baking. State type and package size on bid. 12 pk
PSC: 8920
7,150 EA $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0003 Bread, White, Whole Wheat, White wheat, or Wheat, Unseasoned, Fresh, Any Loaf Size, Pan Baked, Sandwich, Sliced, Enriched, Seedless. (CID A-A-20052C, Type I, Style B, Type II, Type III, or Type IV, Style B, Product State 1, Loaf Size a-e f, Bake Type i I, Shape a) or b), Slice Type I (1), Enrichment Type A (a), Seed Type 2 (ii), Agricultural practice (i)). Fresh bread shall be delivered within 48 hours after baking. State type and loaf size on bid. 24 oz slices
PSC: 8920
8,580 EA $________ $_________________
15B31724Q00000006 Page 5 of 46
Section 2 - Contract Clauses
52.212-4 Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2023)
(a) Inspection/Acceptance. The Contractor shall only tender for acceptance those items that conform to the requirements of this contract. The Government reserves the right to inspect or test any supplies or services that have been tendered for acceptance. The Government may require repair or replacement of nonconforming supplies or reperformance of nonconforming services at no increase in contract price. If repair/replacement or reperformance will not correct the defects or is not possible, the Government may seek an equitable price reduction or adequate consideration for acceptance of nonconforming supplies or services. The Government must exercise its post-acceptance rights--
(1) Within a reasonable time after the defect was discovered or should have been discovered; and
(2) Before any substantial change occurs in the condition of the item, unless the change is due to the defect in the item.
(b) Assignment. The Contractor or its assignee may assign its rights to receive payment due as a result of performance of this contract to a bank, trust company, or other financing institution, including any Federal lending agency in accordance with the Assignment of Claims Act (31 U.S.C. 3727). However, when a third party makes payment (e.g., use of the Governmentwide commercial purchase card), the Contractor may not assign its rights to receive payment under this contract.
(c) Changes. Changes in the terms and conditions of this contract may be made only by written agreement of the parties.
(d) Disputes. This contract is subject to 41 U.S.C. chapter 71, Contract Disputes. Failure of the parties to this contract to reach agreement on any request for equitable adjustment, claim, appeal or action arising under or relating to this contract shall be a dispute to be resolved in accordance with the clause at Federal Acquisition Regulation (FAR) 52.233-1, Disputes, which is incorporated herein by reference. The Contractor shall proceed diligently with performance of this contract, pending final resolution of any dispute arising under the contract.
(e) Definitions. The clause at FAR 52.202-1, Definitions, is incorporated herein by reference.
(f) Excusable delays. The Contractor shall be liable for default unless nonperformance is caused by an occurrence beyond the reasonable control of the Contractor and without its fault or negligence such as, acts of God or the public enemy, acts of the Government in either its sovereign or contractual capacity, fires, floods, epidemics, quarantine restrictions, strikes, unusually severe weather, and delays of common carriers. The Contractor shall notify the Contracting Officer in writing as soon as it is reasonably possible after the commencement of any excusable delay, setting forth the full particulars in connection therewith, shall remedy such occurrence with all reasonable dispatch, and shall promptly give written notice to the Contracting Officer of the cessation of such occurrence.
(g) Invoice.
(1) The Contractor shall submit an original invoice and three copies (or electronic invoice, if authorized) to the address designated in the contract to receive invoices. An invoice must include--
(i) Name and address of the Contractor;
(ii) Invoice date and number;
(iii) Contract number, line item number and, if applicable, the order number;
(iv) Description, quantity, unit of measure, unit price and extended price of the items delivered;
(v) Shipping number and date of shipment, including the bill of lading number and weight of shipment if shipped on Government bill of lading;
(vi) Terms of any discount for prompt payment offered;
15B31724Q00000006 Page 6 of 46
(vii) Name and address of official to whom payment is to be sent;
(viii) Name, title, and phone number of person to notify in event of defective invoice; and
(ix) Taxpayer Identification Number (TIN). The Contractor shall include its TIN on the invoice only if required elsewhere in this contract.
(x) Electronic funds transfer (EFT) banking information.
(A) The Contractor shall include EFT banking information on the invoice only if required elsewhere in this contract.
(B) If EFT banking information is not required to be on the invoice, in order for the invoice to be a proper invoice, the Contractor shall have submitted correct EFT banking information in accordance with the applicable solicitation provision, contract clause (e.g., 52.232-33, Payment by Electronic Funds Transfer--System for Award Management, or 52.232-34, Payment by Electronic Funds Transfer--Other Than System for Award Management), or applicable agency procedures.
(C) EFT banking information is not required if the Government waived the requirement to pay by EFT.
(2) Invoices will be handled in accordance with the Prompt Payment Act (31 U.S.C. 3903) and Office of Management and Budget (OMB) prompt payment regulations at 5 CFR Part 1315.
(h) Patent indemnity. The Contractor shall indemnify the Government and its officers, employees and agents against liability, including costs, for actual or alleged direct or contributory infringement of, or inducement to infringe, any United States or foreign patent, trademark or copyright, arising out of the performance of this contract, provided the Contractor is reasonably notified of such claims and proceedings.
(i) Payment.--
(1) Items accepted. Payment shall be made for items accepted by the Government that have been delivered to the delivery destinations set forth in this contract.
(2) Prompt payment. The Government will make payment in accordance with the Prompt Payment Act (31 U.S.C. 3903) and prompt payment regulations at 5 CFR Part 1315.
(3) Electronic Funds Transfer (EFT). If the Government makes payment by EFT, see 52.212-5(b) for the appropriate EFT clause.
(4) Discount. In connection with any discount offered for early payment, time shall be computed from the date of the invoice. For the purpose of computing the discount earned, payment shall be considered to have been made on the date which appears on the payment check or the specified payment date if an electronic funds transfer payment is made.
(5) Overpayments. If the Contractor becomes aware of a duplicate contract financing or invoice payment or that the Government has otherwise overpaid on a contract financing or invoice payment, the Contractor shall--
(i) Remit the overpayment amount to the payment office cited in the contract along with a description of the overpayment including the--
(A) Circumstances of the overpayment (e.g., duplicate payment, erroneous payment, liquidation errors, date(s) of overpayment);
(B) Affected contract number and delivery order number, if applicable;
(C) Affected line item or subline item, if applicable; and
(D) Contractor point of contact.
(ii) Provide a copy of the remittance and supporting documentation to the Contracting Officer.
(6) Interest.
(i) All amounts that become payable by the Contractor to the Government under this contract shall bear simple interest from the date due until paid unless paid within 30 days of becoming due. The interest rate shall be the interest rate established by the Secretary of
15B31724Q00000006 Page 7 of 46 the Treasury as provided in 41 U.S.C. 7109 , which is applicable to the period in which the amount becomes due, as provided in (i)(6)
(v) of this clause, and then at the rate applicable for each six-month period as fixed by the Secretary until the amount is paid.
(ii) The Government may issue a demand for payment to the Contractor upon finding a debt is due under the contract.
(iii) Final decisions. The Contracting Officer will issue a final decision as required by 33.211 if--
(A) The Contracting Officer and the Contractor are unable to reach agreement on the existence or amount of a debt within 30 days;
(B) The Contractor fails to liquidate a debt previously demanded by the Contracting Officer within the timeline specified in the demand for payment unless the amounts were not repaid because the Contractor has requested an installment payment agreement; or
(C) The Contractor requests a deferment of collection on a debt previously demanded by the Contracting Officer (see 32.607-2).
(iv) If a demand for payment was previously issued for the debt, the demand for payment included in the final decision shall identify the same due date as the original demand for payment.
(v) Amounts shall be due at the earliest of the following dates:
(A) The date fixed under this contract.
(B) The date of the first written demand for payment, including any demand for payment resulting from a default termination.
(vi) The interest charge shall be computed for the actual number of calendar days involved beginning on the due date and ending on--
(A) The date on which the designated office receives payment from the Contractor;
(B) The date of issuance of a Government check to the Contractor from which an amount otherwise payable has been withheld as a credit against the contract debt; or
(C) The date on which an amount withheld and applied to the contract debt would otherwise have become payable to the Contractor.
(vii) The interest charge made under this clause may be reduced under the procedures prescribed in FAR 32.608-2 in effect on the date of this contract.
(j) Risk of loss. Unless the contract specifically provides otherwise, risk of loss or damage to the supplies provided under this contract shall remain with the Contractor until, and shall pass to the Government upon:
(1) Delivery of the supplies to a carrier, if transportation is f.o.b. origin; or
(2) Delivery of the supplies to the Government at the destination specified in the contract, if transportation is f.o.b. destination.
(k) Taxes. The contract price includes all applicable Federal, State, and local taxes and duties.
(l) Termination for the Government's convenience. The Government reserves the right to terminate this contract, or any part hereof, for its sole convenience. In the event of such termination, the Contractor shall immediately stop all work hereunder and shall immediately cause any and all of its suppliers and subcontractors to cease work. Subject to the terms of this contract, the Contractor shall be paid a percentage of the contract price reflecting the percentage of the work performed prior to the notice of termination, plus reasonable charges the Contractor can demonstrate to the satisfaction of the Government using its standard record keeping system, have resulted from the termination. The Contractor shall not be required to comply with the cost accounting standards or contract cost principles for this purpose. This paragraph does not give the Government any right to audit the Contractor's records. The Contractor shall not be paid for any work performed or costs incurred which reasonably could have been avoided.
(m) Termination for cause. The Government may terminate this contract, or any part hereof, for cause in the event of any default by the Contractor, or if the Contractor fails to comply with any contract terms and conditions, or fails to provide the Government, upon request, with adequate assurances of future performance. In the event of termination for cause, the Government shall not be liable to the Contractor for any amount for supplies or services not accepted, and the Contractor shall be liable to the Government for any and all rights and remedies provided by law. If it is determined that the Government improperly terminated this contract for default, such termination shall be deemed a termination for convenience.
15B31724Q00000006 Page 8 of 46
(n) Title. Unless specified elsewhere in this contract, title to items furnished under this contract shall pass to the Government upon acceptance, regardless of when or where the Government takes physical possession.
(o) Warranty. The Contractor warrants and implies that the items delivered hereunder are merchantable and fit for use for the particular purpose described in this contract.
(p) Limitation of liability. Except as otherwise provided by an express warranty, the Contractor will not be liable to the Government for consequential damages resulting from any defect or deficiencies in accepted items.
(q) Other compliances. The Contractor shall comply with all applicable Federal, State and local laws, executive orders, rules and regulations applicable to its performance under this contract.
(r) Compliance with laws unique to Government contracts. The Contractor agrees to comply with 31 U.S.C. 1352 relating to limitations on the use of appropriated funds to influence certain Federal contracts; 18 U.S.C. 431 relating to officials not to benefit; 40 U.S.C. chapter 37, Contract Work Hours and Safety Standards; 41 U.S.C. chapter 87, Kickbacks; 49 U.S.C. 40118, Fly American; and 41 U.S.C. chapter 21 relating to procurement integrity.
(s) Order of precedence. Any inconsistencies in this solicitation or contract shall be resolved by giving precedence in the following order:
(1) The schedule of supplies/services.
(2) The Assignments, Disputes, Payments, Invoice, Other Compliances, Compliance with Laws Unique to Government Contracts, and Unauthorized Obligations paragraphs of this clause;
(3) The clause at 52.212-5.
(4) Addenda to this solicitation or contract, including any license agreements for computer software.
(5) Solicitation provisions if this is a solicitation.
(6) Other paragraphs of this clause.
(7) The Standard Form 1449.
(8) Other documents, exhibits, and attachments.
(9) The specification.
(t) [Reserved]
(u) Unauthorized Obligations
(1) Except as stated in paragraph (u)(2) of this clause, when any supply or service acquired under this contract is subject to any End User License Agreement (EULA), Terms of Service (TOS), or similar legal instrument or agreement, that includes any clause requiring the Government to indemnify the Contractor or any person or entity for damages, costs, fees, or any other loss or liability that would create an Anti-Deficiency Act violation (31 U.S.C. 1341), the following shall govern:
(i) Any such clause is unenforceable against the Government.
(ii) Neither the Government nor any Government authorized end user shall be deemed to have agreed to such clause by virtue of it appearing in the EULA, TOS, or similar legal instrument or agreement. If the EULA, TOS, or similar legal instrument or agreement is invoked through an "I agree" click box or other comparable mechanism (e.g., "click-wrap" or "browse-wrap" agreements), execution does not bind the Government or any Government authorized end user to such clause.
(iii) Any such clause is deemed to be stricken from the EULA, TOS, or similar legal instrument or agreement.
(2) Paragraph (u)(1) of this clause does not apply to indemnification by the Government that is expressly authorized by statute and specifically authorized under applicable agency regulations and procedures.
15B31724Q00000006 Page 9 of 46
(v) Incorporation by reference. The Contractor's representations and certifications, including those completed electronically via the System for Award Management (SAM), are incorporated by reference into the contract.
(End of clause)
A.1 ADDENDUM TO FAR 52.212-4, Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2023)
The terms and conditions for the following clauses are hereby incorporated into this solicitation and resulting contract as an addendum to FAR clause 52.212-4.
Clauses By Full Text
DOJ-05 Security of Department Information and Systems DOJ-05 (OCT 2023)
I. Applicability to Contractors and Subcontractors Section 2839.102 of the Justice Acquisition Regulation (JAR), (48 C.F.R. § 2839.102), applies to this contract.
Accordingly, all contractors are obligated to comply with all applicable DOJ security policies, directives, or guidance documents, including the security requirements in the provisions in this contract clause. This contract clause applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of the contractors and subcontractors (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information. The security requirements set forth herein are in addition to those required by the Federal Acquisition Regulation (“FAR”), and any other applicable laws, mandates, contract clauses, DOJ policies, directives or guidance documents and Executive Orders pertaining to the development and operation of Information Systems and/or the protection of Government Information. This clause does not alter or diminish any existing rights, obligations, or liability under any other civil and/or criminal law, rule, regulation, or mandate.
II. General Definitions The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.
A. Authorization to Operate (“ATO”), as defined in National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-37 Revision 2, is the official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls.
B. Cloud Computing, as defined in DOJ Order 0904 Cybersecurity Program, is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics, three service models, and four deployment models in accordance with NIST SP 800-145.
C. Covered Contract is any contract, order or other agreement under which the contractor, or a subcontractor at any tier, including a cloud service provider, may access, collect, store, process, maintain, 15B31724Q00000006 Page 10 of 46 use, share, retrieve, disseminate, transmit, or dispose of DOJ Information (as defined below) in the course of providing a product or service to the Department, with the exception of acquisitions under the micro-purchase threshold.
D. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information under a Covered Contract.
E. Data means recorded information, regardless of form or the media on which it may be recorded. The term includes technical data, computer software, and personally identifiable information (PII) (defined below). The term does not include information incidental to contract administration, such as financial, administrative, cost or pricing, or management information.
F. DOJ Information, as defined in DOJ Order 0904, means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, information related to DOJ programs or personnel. It includes, without limitation, Information
(1) provided by or generated for the DOJ, (2) managed or acquired by the Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired to perform the contract.
G. Information, as defined in DOJ Order 0904, is any communication or representation of knowledge such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. This includes any communication or representation of knowledge in an electronic format that allows it to be stored, retrieved, or transmitted.
H. Information System, means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502(8)).
I. Personally Identifiable Information (“PII”), as defined in the FAR 24.101, means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. It includes but is not limited to common data elements such as names, addresses, dates of birth, and places of employment, to identity documents, Social Security numbers or other government-issued identifiers, precise location information, medical history, and biometric records. This definition covers all PII that is created by or becomes available to the contractor, including its employees, subcontractors, or affiliates, as a result of performing under this contract. PII, as supplementally defined in DOJ Order 0904, also includes information about an individual maintained by an agency, including, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and information, which can be used to distinguish or trace an individual’s identity.
J. Private Cloud, as defined in NIST SP 800-145, is the deployment model for cloud infrastructure provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units).
It may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off premises.
K. Security Breach means any security incident (as defined below) that directly relates to the loss of control, compromise, exfiltration, manipulation, unauthorized disclosure, unauthorized acquisition, unauthorized exposure or unauthorized access or any similar occurrence of any Covered Information System or any DOJ Information or any PII accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system. This includes incidents where (1) a person other than an authorized user accesses or potentially accesses PII or DOJ Information or (2) an authorized user accesses or potentially accesses PII or DOJ Information for an unauthorized purpose.
a. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed security breach (as defined above).
15B31724Q00000006 Page 11 of 46
b. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed security breach (as defined above).
L. Security Incident means any occurrence that (1) may actually or imminently jeopardize, without lawful authority, the availability, integrity, authentication, confidentiality, or nonrepudiation of DOJ Information or a Covered Information System; or (2) may constitute a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
a. Potential Security Incident means any suspected, but unconfirmed security incident (as defined above).
b. Confirmed Security Incident means any confirmed security incident (as defined above).
M. Vulnerability, as defined in DOJ Vulnerability Management Plan, and the OCIO Information Security Management Procedure, means a weakness or flaw discovered in the design of a system that, when exploited, may result in a loss of confidentially, integrity, or availability of DOJ Information or an Information System.
III. Confidentiality and Non-Disclosure of DOJ Information
A. Preliminary and final contract deliverables and all associated working papers and material generated by the Contractor developed using DOJ Information, product, source code, and/or methods of operations, are the property of the U.S. Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Representative (“COR”) at the conclusion of the contract. The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14 (Rights in Data-General). The Contractor will define a method of monitoring the development activity to include any activity associated with DOJ Information, product, source code, and methods of operations.
The data rights and development details shall be defined within the Contract.
If the Contractor intends to utilize its existing data, for which it has a patent or copyright, to develop a contract deliverable, it is incumbent upon the Contractor to negotiate with the CO the proper FAR Part 27 clauses in the contract to protect its existing data.
B. Pursuant to FAR 52.227-14(d)(2), all documents and data produced in the performance of this contract containing DOJ Information, product code, source code, and/or methods of operations are the property of the U.S. Government and, without the prior written permission of the CO, the Contractor shall neither reproduce nor release such information to any third-party at any time, including during performance or following expiration and/or termination of the contract.
C. Any DOJ Information made available to the Contractor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, the Contractor assumes responsibility for the protection of the confidentiality of all DOJ Information processed, stored, or transmitted by the Contractor. The Contractor shall comply with information security responsibilities and duties throughout the contract and after expiration/termination as appropriate per contract close-out activities. When requested by the CO (typically no more than annually), the Contractor shall provide a report to the CO identifying, to the best of the Contractor’s knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed, stored, or transmitted under the Contract, including an estimate of the number of individuals for whom PII has been processed, stored or transmitted under the Contract and whether such information includes social security numbers (in whole or in part).
IV. Compliance with Information Technology Security Policies, Procedures and Requirements
15B31724Q00000006 Page 12 of 46
A. For all Covered Information Systems, in addition to any other applicable requirements, as set forth in Part I, the Contractor shall comply with the security requirements of the Federal Information Security Modernization Act of 2014 (“FISMA”), Privacy Act of 1974, E-Government Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, 199, and 200, Federal Risk and Authorization Management Program (“FedRAMP”), DOJ IT Security Standards as amended, and OMB Memoranda relating to the security of information and/or Federal Information Systems.
B. In addition, for all Covered Information Systems, the Contractor shall comply with the following requirements, which are listed here only to highlight certain specific applicable requirements from one of the sources identified in the first paragraph of this Section. This is not an exhaustive list of all such requirements with which the Contractor is obligated to comply, and the omission of a requirement from this list should not be construed as negating the materiality of that requirement. These requirements and those in the authorities in the prior paragraph should be read together.
1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise.
2. Providing security awareness training at least annually to all Contractor employees and contractors involved with the Covered Contract. Such training shall include, but not be limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information Systems.
3. Creating, protecting, and retaining, in accordance with applicable requirements but in any event at least until the expiration of the contract, Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information.
4. Maintaining authorizations to operate any Covered Information System.
5. Performing continuous monitoring on all Covered Information Systems, to include but not be limited to, collecting, reviewing, and analyzing appropriate logs and timely investigating security alerts and potential security incidents.
6. Establishing and maintaining baseline configurations and current inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Covered Information Systems.
7. Ensuring appropriate contingency planning has been performed, including DOJ Information and Covered Information System backups.
8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication methods as defined by NIST 800-63-3, Digital Identity Guidelines or current revision.
9. Establishing and maintaining an operational incident handling capability for Covered Information Systems that includes adequate and timely development, logging, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and timely reporting incidents to appropriate officials and authorities within the Contractor’s organization and the DOJ.
15B31724Q00000006 Page 13 of 46
10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms, and personnel used to conduct such maintenance.
11. Protecting Covered Information System media containing DOJ Information, including paper, digital and electronic media, and DOJ assets under Contractor control; protecting them from environmental impacts, access, and equipment positioning requirements defined; limiting access to DOJ Information to authorized users; and sanitizing or destroying Covered Information System media containing DOJ Information before disposal, release or reuse of such media.
12. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Information Systems to authorized personnel according to DOJ 03.
13. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with DOJ Security standards including personnel background checks.
14. Continuously assessing the risk to DOJ Information in Covered Information Systems, including scanning and remediating vulnerabilities, or implementing appropriate mitigation in accordance with DOJ policy, and ensuring the timely removal of assets no longer supported by the Contractor.
15. Continuously monitoring the application of security controls of Covered Information Systems, assessing the efficacy of such controls, and developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in such Covered Information Systems.
16. Monitoring, controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Covered Information Systems, and employing architectural designs, software development techniques, and systems engineering principles that promote effective security.
17. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection from malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate and timely action in response.
18. Ensuring return of Government Furnished Equipment (“GFE”) and/or PIV card assets within 10 business days of notification for end of use (contract end, staff change, etc.).
19. Complying with rights in data (FAR 52.227-14) as to the development, management, and protection of DOJ Information.
20. Reporting on risks or known issues impacting DOJ Services (staffing, hardware, process, changes, etc.) through the Contractor’s CO or COR, DOJ Service Owner (“SO”), and Government Technical Manager (“GTM”) including risk mitigation activities.
21. Reporting through the Contractor’s CO or COR on any projected or planned changes in corporate ownership, covered information system design, and/or any technical changes that could impact the confidentiality, integrity or availability of DOJ Information, data, or systems. Changes to system design must be updated through the authorization process per NIST SP 800-37 Revision 2, Step 6 (‘Continuous Monitoring”) or current NIST revision.
22. When, as part of operating within the DOJ environment, the Contractor’s covered information system is subject to review, audit, or assessment by third parties, facilitating DOJ access to information system resources, facilities, personnel, and documentation in a timely manner as required by the auditors. Should a third-party organization conduct a review of any Covered
15B31724Q00000006 Page 14 of 46
Information System, the Contractor must provide a copy of the report to DOJ, through the CO and
COR.
23. Completing an attestation that meets OMB Memorandum M-22-18 for software procurements following the template attestation form developed by NIST. The attestation form must be returned to the CO and COR for sharing with the component Chief Information Officer (CIO).
24. Reporting on outages impacting DOJ Services through the Contractor’s CO, COR, and DOJ Service Owner (SO) to include event and mitigation details.
C. The Contractor shall not process, store, or transmit DOJ Information using a Covered Information System without first obtaining an ATO for each Covered Information System. The ATO shall be signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under this contract. (For Cloud Computing Systems, see Section V, below.)
D. The Contractor shall ensure compliance with DOJ-03 (Personnel Security Requirements for Contractor Employees) as to all Covered Information Systems.
E. When requested by the DOJ CO or COR as described below, the Contractor shall provide DOJ, including the Office of Inspector General (“OIG”) and Federal law enforcement components, (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and
(2) physical access to the Contractor’s facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by DOJ or agents acting on behalf of DOJ, and such access shall be provided within 72 hours of the request. Additionally, the Contractor shall cooperate with DOJ’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of DOJ Information.
F. The use of Contractor-owned laptops or other portable digital or electronic media to process or store DOJ Information covered by this clause or access a Covered Information System is prohibited unless the CO approves it in writing after the Contractor has provided a letter certifying compliance with the following requirements. For any requirements which include the use or storage of PII, the Senior Component Official for Privacy must also approve. Any additional requirements set forth for the use or storage of PII under DOJ-02, Contractor Privacy Requirements, are in addition to, not superseded by, the requirements set forth here.
1. Media must be encrypted using a NIST FIPS 140-2 approved product.
2. The Contractor must develop and implement a process to ensure that security and other applications software is kept up to date.
3. Where applicable, media must utilize antivirus software and a host-based firewall mechanism.
4. The Contractor must log all computer-readable data extracts from databases holding DOJ Information and verify that each extract including such data has been erased within 90 days of extraction or that its use is still required. All DOJ Information should be treated by the Contractor as sensitive information unless specifically designated as non-sensitive by the DOJ.
5. A Rules of Behavior (ROB) form must be signed and acknowledged annually by users. These rules must address, at a minimum, authorized, and official use, prohibition against unauthorized users and use, and the protection of DOJ Information. The form also must notify the
15B31724Q00000006 Page 15 of 46 users that they have no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contractor-owned laptops or other portable digital or electronic media.
6. Cybersecurity Awareness Training (CSAT) shall be provided annually by Contractor for all users of Covered Information System. This training must be submitted to, and approved by, the CO or COR in advance of being provided to users. Users must complete and acknowledge having received CSAT each year. At a minimum, CSAT provided by contractors must include:
a. Insider Threat Detection and Reporting – Importance of detecting, methodologies, indicators, and reporting
b. Privacy Awareness – Privacy Act and PII
c. General Cybersecurity – Information security, trends in advance persistent threats, social engineering/phishing, appropriate use, mobile devices, remote access, basic security best practices
G. Contractors shall not store DOJ information on Contractor-owned removable IT (e.g., media such as a thumb drive or external hard drive) unless expressly authorized in writing by the DOJ CO or COR in the performance of their contract.
H. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with NIST SP 900-88, Guidelines for Media Sanitization.
I. The Contractor must keep an accurate inventory of digital or electronic media used in the performance of DOJ contracts.
J. The Contractor must remove all DOJ Information from Contractor media and return all such information to the DOJ within 10 days of the expiration or termination of the contract, unless otherwise extended by the CO, or waived (in part or whole) by the CO, and all such information shall be returned in a format and form acceptable to DOJ. The Contractor shall provide a written certification certifying the removal and return of all such information to the CO within 10 business days of the removal and return of all DOJ Information.
K. DOJ, at its discretion, may suspend the Contractor’s access to any DOJ Information, or terminate the contract, when DOJ suspects that the Contractor has failed to comply with any security requirement, or in the event of an Information System Security Incident or Security Breach (see definitions above), where the Department determines that either event gives cause for such action. The suspension of access to DOJ Information may last until such time as DOJ, in its sole discretion, determines that the situation giving rise to such action has been corrected or no longer exists. Any termination action taken because of the Contractor’s suspected failure to comply with any security requirement will be conducted in accordance with the applicable termination clause governing the awarded contract. The Contractor understands that any suspension or termination in accordance with this provision shall be at no cost to DOJ, and that upon request by the CO, the Contractor must immediately return all DOJ Information to DOJ, as well as any media upon which DOJ Information resides, at the Contractor’s expense. The Contractor must comply with FAR 52.227-14 (Rights in Data), FAR 52.245-1 (Government Property), DOJ 2400.3A Chapter 1 (component property procedures), and FAR 4.804-5(a)(6) (Procedures for closing out contract files).
V. Cloud Computing
A. The Contractor may not utilize the Cloud system of any Cloud Service Provider (“CSP”) unless:
1. All of the following has occurred: (a) the Cloud system and CSP have been evaluated by a Third Party Assessing Organization (“3PAO”) certified under FedRAMP; (b) the Cloud system received FedRAMP authorization; (c) the Contractor has provided the most current System Security Plan (“SSP”) and Security Assessment Report (“SAR”) to the DOJ CO for consideration, and provides any subsequent SSPs and SARs within 30 days of issuance; and, (d) the Authorizing Official
15B31724Q00000006 Page 16 of 46 for the DOJ component responsible for maintaining the security confidentiality, integrity, and availability of the DOJ Information under the Covered Contract has issued an ATO; or,
2. In cases where the CSP or its offering is not FedRAMP authorized, the COR approves utilization of the Cloud System after the CSP has worked with the authorizing official, the DOJ OCIO, and the FedRAMP Program Management Office to determine that the CSP is likely to seek and receive Agency/FedRAMP authorization within 1 year, or DOJ has authorized use as a Private Cloud or Contractor Owned, Contractor Operated system.
B. The Contractor must ensure that the CSP allows DOJ to access and retrieve any DOJ Information processed, stored, or transmitted in a Cloud system under this Contract within a reasonable time of any such request, but in no event less than 48 hours from the request. To ensure that the DOJ can fully and appropriately search and retrieve DOJ Information from the Cloud system, access shall include any schemas, meta-data, and other associated data artifacts.
C. The Contractor must ensure that the CSP provides access and information to support and enable DOJ’s cloud security posture management, to include the current inventory of security management configuration data for services and information to confirm the Contractor has been monitoring accounts for compliance with security requirements. The DOJ Justice Security Operations Center (JSOC) must be able to access logs and events to investigate potential security breaches and perform security posture assessments associated with the Security Audit Identity Credential Access Management (ICAM) policies.
D. The Contractor must ensure that the CSP provides evidence of annual recertification of privileged user access management.
E. A Supply Chain Risk Management (SCRM) review is mandatory for specified acquisitions in accordance with established process in EO 14028 and NIST SP 800-161, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, or superseding document.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .