36C10B25R0003 0005.pdf

PDF 408 KB Posted

Attached to
DA01--Independent Enterprise Testing and Support Services (IETSS) Federal contract opportunity
Solicitation number
36C10B25R0003
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This is Amendment 0005 to Request for Proposal (RFP) 36C10B25R0003 for "Independent Enterprise Testing and Support Services (IETSS)" issued by the Department of Veterans Affairs Technology Acquisition Center. The amendment makes revisions to Section C - Contract Clauses and updates organizational conflict of interest requirements.

Key changes include modifications regarding conflict of interest provisions for contractors performing VA IT project management or software development services, specifying that contractors currently performing these services for projects that will be tested under this contract may be precluded from award. The amendment requires contractors to submit mitigation plans if organizational conflicts arise and includes requirements for protecting proprietary data, employee training, and notification procedures. The amendment maintains strict data rights provisions giving VA unlimited rights to technical data produced under the contract. Small business participation requirements are included but specific percentage goals are marked as TBD (to be determined). The amendment is effective December 6, 2024, and all other terms and conditions remain unchanged.

View the file

Other files for this federal contract opportunity

Other files attached to DA01--Independent Enterprise Testing and Support Services (IETSS), newest first.
File Type Posted
Attachment 001 - IETSS Price Evaluation Spreadsheet_v3.xlsx XLSX spreadsheet
36C10B25R0003 0004.pdf PDF
Attachment 001 - IETSS Price Evaluation Spreadsheet_v2.xlsx XLSX spreadsheet
36C10B25R0003 0003.pdf PDF
Amendment 36C10B25R0003 0002.pdf PDF
Attachment 004 - Memorandum of Independence Confirmation 11-21-24.docx DOCX document
36C10B25R0003_4.docx DOCX document
36C10B25R0003 0001.pdf PDF
Questions and Answers IETSS 36C10B25R0003.pdf PDF
Attachment 001 - IETSS Price Evaluation Spreadsheet_v1.xlsx XLSX spreadsheet
Draft RFP Q_A.pdf PDF
Attachment 004 - Memorandum of Independence Confirmation.docx DOCX document
Attachment 002 - IETSS Infrastructure and Processes_b.zip ZIP file
Attachment 002 - IETSS Infrastructure and Processes_a.zip ZIP file
Attachment 001 - IETSS Price Evaluation Spreadsheet.xlsx XLSX spreadsheet
36C10B25R0003_3.docx DOCX document
Attachment 003 - Small Business Participation Report.xls XLS spreadsheet
36C10B25R0003 IETSS RFP.pdf PDF
Attachment 005 - Business Associate Agreement BAA.doc DOC document
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

5. PROJECT NUMBER (if applicable)

CODE 7. ADMINISTERED BY

2. AMENDMENT/MODIFICATION NUMBER

CODE

6. ISSUED BY

8. NAME AND ADDRESS OF CONTRACTOR

4. REQUISITION/PURCHASE REQ. NUMBER 3. EFFECTIVE DATE

9A. AMENDMENT OF SOLICITATION NUMBER

9B. DATED

PAGE OF PAGES

10A. MODIFICATION OF CONTRACT/ORDER NUMBER

10B. DATED

BPA NO. 1. CONTRACT ID CODE

FACILITY CODE CODE

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

E. IMPORTANT:

is extended,

(a) By completing Items 8 and 15, and returning __________ copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY is not extended.

12. ACCOUNTING AND APPROPRIATION DATA

(REV. 11/2016)

is required to sign this document and return ___________ copies to the issuing office. is not, A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN ITEM 10A.

15C. DATE SIGNED

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER

Contractor

16C. DATE SIGNED

14. DESCRIPTION OF AMENDMENT/MODIFICATION

16B. UNITED STATES OF AMERICA

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER 16A. NAME AND TITLE OF CONTRACTING OFFICER

15B. CONTRACTOR/OFFEROR

STANDARD FORM 30 PREVIOUS EDITION NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.243

(Type or print) (Type or print)

(Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

(Number, street, county, State and ZIP Code)

(If other than Item 6)

(Specify type of modification and authority)

(such as changes in paying office, appropriation date, etc.)

(If required)

(SEE ITEM 11)

(SEE ITEM 13)

(X)

CHECK

ONE

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

(Signature of person authorized to sign) (Signature of Contracting Officer)

1 23

0005 12-6-2024

VA-24-00050415

Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

To all Offerors/Bidders

36C10B25R0003

X

X X

X 1

***Please see Continuation Page

Jason King Contracting Officer

36C10B25R0003 0005

Continuation Page:

The purpose of Amendment 0005 to Request for Proposal (RFP) 36C10B25R0003 entitled “Independent Enterprise Testing and Support Services (IETSS)” is as follows:

1. To revise Section C – Contract Causes. Updates in track changes below.

2. All other terms and conditions remain in full force and effect.

SECTION C - CONTRACT CLAUSES

C.1 FEDERAL ACQUISITION REGULATION (FAR) 52.252-2 CLAUSES

INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

http://www.acquisition.gov/far/index.html http://www.va.gov/oal/library/vaar/

FAR

Number

Title

Date

52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE

CERTAIN FEDERAL TRANSACTIONS

JUN 2020

52.203-16 PREVENTING PERSONAL CONFLICTS OF INTEREST JUN 2020

52.204-9 PERSONAL IDENTITY VERIFICATION OF

CONTRACTOR PERSONNEL

JAN 2011

52.204-13 SYSTEM FOR AWARD MANAGEMENT

MAINTENANCE

OCT 2018

52.204-18

COMMERCIAL AND GOVERNMENT ENTITY CODE

MAINTENANCE

AUG 2020

52.204-23 PROHIBITION ON CONTRACTING FOR HARDWARE,

SOFTWARE, AND SERVICES DEVELOPED OR

PROVIDED BY KASPERSKY LAB AND OTHER

COVERED ENTITIES

NOV 2021

52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN

TELECOMMUNICATIONS AND VIDEO

SURVEILLANCE SERVICES OR EQUIPMENT

NOV 2021

52.212-4 CONTRACT TERMS AND CONDITIONS –

COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES

NOV 2023

52.212-4 CONTRACT TERMS AND CONDITIONS –

COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES ALTERNATE I

NOV 2021

52.227-1 AUTHORIZATION AND CONSENT JUN 2020

52.227-2 NOTICE AND ASSISTANCE REGARDING PATENT

AND COPYRIGHT INFRINGEMENT

JUN 2020

52.227-14 RIGHTS IN DATA – GENERAL MAY 2014

52.227-16 ADDITIONAL DATA REQUIREMENTS JUN 1987

52.232-39 UNENFORCEABILITY OF UNAUTHORIZED

OBLIGATIONS

JUN 2013

52.242-13 BANKRUPTCY JUL 1995

52.245-1 GOVERNMENT PROPERTY SEP 2021

852.201-70 CONTRACTING OFFICER'S REPRESENTATIVE

DEC 2022

852.203-70 COMMERCIAL ADVERTISING MAY 2018

http://www.acquisition.gov/far/index.html http://www.va.gov/oal/library/vaar/

852.204-71 INFORMATION AND INFORMATION SYSTEMS

SECURITY

FEB 2023

852.215-70 SERVICE-DISABLED VETERAN-OWNED AND

VETERAN-OWNED SMALL BUSINESS EVALUATION

FACTORS

JAN 2023

852.215-71 EVALUATION FACTOR COMMITMENTS OCT 2019

852.219-70 VA SMALL BUSINESS SUBCONTRACTING PLAN

MINIMUM REQUIREMENTS

JAN 2023

852.233-70

PROTEST CONTENT/ALTERNATIVE DISPUTE

RESOLUTION

SEP 2018

852.233-71 ALTERNATE PROTEST PROCEDURE SEP 2018

(End of Clause)

C.2 52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR

INFORMATION SYSTEMS (NOV 2021)

(a) Definitions. As used in this clause—

Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.

Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.

Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).

Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information ( 44 U.S.C. 3502).

Safeguarding means measures or controls that are prescribed to protect information systems.

(b) Safeguarding requirements and procedures.

(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:

(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

(iii) Verify and control/limit connections to and use of external information systems.

(iv) Control information posted or processed on publicly accessible information systems.

(v) Identify information system users, processes acting on behalf of users, or devices.

(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

(vii) Sanitize or destroy information system media containing Federal Contract

Information before disposal or release for reuse.

http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3

(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

(xii) Identify, report, and correct information and information system flaws in a timely manner.

(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.

(xiv) Update malicious code protection mechanisms when new releases are available.

(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.

(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (c), in subcontracts under this contract (including subcontracts for the acquisition of commercial products or commercial services, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.

(End of clause)

C.3 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT

STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (MAY 2024)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204–23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities (DEC 2023) (Section 1634 of Pub. L. 115–91).

(3) 52.204–25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115–232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015).

(5) 52.232–40, Providing Accelerated Payments to Small Business Subcontractors (MAR 2023) (31 U.S.C. 3903 and 10 U.S.C. 3801).

(6) 52.233-3, Protest After Award (AUG 1996) (31 U.S.C. 3553).

(7) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and 108-78 (19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

[] (1) 52.203–6, Restrictions on Subcontractor Sales to the Government (JUN 2020), with Alternate I (NOV 2021) (41 U.S.C. 4704 and 10 U.S.C. 4655).

[] (2) 52.203–13, Contractor Code of Business Ethics and Conduct (NOV 2021) (41 U.S.C.

3509).

[] (3) 52.203–15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (JUN 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)

[X] (4) 52.203–17, Contractor Employee Whistleblower Rights (NOV 2023) (41 U.S.C.

4712); this clause does not apply to contracts of DoD, NASA, the Coast Guard, or applicable elements of the intelligence community—see FAR 3.900(a).

[X] (5) 52.204–10, Reporting Executive Compensation and First-Tier Subcontract Awards (JUN 2020) (Pub. L. 109–282) (31 U.S.C. 6101 note).

[] (6) [Reserved] [X] (7) 52.204–14, Service Contract Reporting Requirements (OCT 2016) (Pub. L. 111–117, section 743 of Div. C).

[] (8) 52.204–15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (OCT 2016) (Pub. L. 111–117, section 743 of Div. C).

[X] (9) 52.204–27, Prohibition on a ByteDance Covered Application (JUN 2023) (Section 102 of Division R of Pub. L. 117–328).

[] (10) 52.204–28, Federal Acquisition Supply Chain Security Act Orders—Federal Supply Schedules, Governmentwide Acquisition Contracts, and Multi-Agency Contracts. (DEC 2023) (Pub. L. 115–390, title II).

[] (11)(i) 52.204–30, Federal Acquisition Supply Chain Security Act Orders— Prohibition.

(DEC 2023) (Pub. L. 115–390, title II).

[] (ii) Alternate I (DEC 2023) of 52.204–30.

[X] (12) 52.209–6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (NOV 2021) (31 U.S.C. 6101 note).

[X] (13) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (OCT 2018) (41 U.S.C. 2313).

[] (14) [Reserved] [] (15) 52.219–3, Notice of HUBZone Set-Aside or Sole-Source Award (OCT 2022) (15 U.S.C. 657a).

[X] (16) 52.219–4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (OCT 2022) (if the offeror elects to waive the preference, it shall so indicate in its offer) (15 U.S.C. 657a).

[] (17) [Reserved] [] (18)(i) 52.219-6, Notice of Total Small Business Set-Aside (NOV 2020) (15 U.S.C. 644).

[] (ii) Alternate I (MAR 2020) of 52.219-6.

[] (19)(i) 52.219-7, Notice of Partial Small Business Set-Aside (NOV 2020) (15 U.S.C. 644).

[] (ii) Alternate I (MAR 2020) of 52.219-7.

[X] (20) 52.219-8, Utilization of Small Business Concerns (FEB 2024) (15 U.S.C. 637(d)(2) and (3)).

[X] (21)(i) 52.219–9, Small Business Subcontracting Plan (SEP 2023) (15 U.S.C. 637(d)(4)).

[] (ii) Alternate I (NOV 2016) of 52.219-9.

[] (iii) Alternate II (NOV 2016) of 52.219-9.

[] (iv) Alternate III (JUN 2020) of 52.219–9.

[] (v) Alternate IV (SEP 2023) of 52.219–9.

[] (22)(i) 52.219-13, Notice of Set-Aside of Orders (MAR 2020) (15 U.S.C. 644(r)).

[] (ii) Alternate I (MAR 2020) of 52.219-13.

[] (23) 52.219–14, Limitations on Subcontracting (OCT 2022) (15 U.S.C. 657s).

[X] (24) 52.219-16, Liquidated Damages—Subcontracting Plan (SEP 2021) (15 U.S.C.

637(d)(4)(F)(i)).

[] (25) 52.219–27, Notice of Set-Aside for, or Sole-Source Award to, Service-Disabled Veteran-Owned Small Business (SDVOSB) Concerns Eligible Under the SDVOSB Program (FEB 2024) (15 U.S.C. 657f).

[X] (26) (i) 52.219–28, Post-Award Small Business Program Representation (FEB 2024) (15 U.S.C. 632(a)(2)).

[] (ii) Alternate I (MAR 2020) of 52.219–28.

[] (27) 52.219–29, Notice of Set-Aside for, or Sole-Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (OCT 2022) (15 U.S.C. 637(m)).

[] (28) 52.219–30, Notice of Set-Aside for, or Sole-Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (OCT 2022) (15 U.S.C. 637(m)).

[] (29) 52.219-32, Orders Issued Directly Under Small Business Reserves (MAR 2020) (15 U.S.C. 644(r)).

[] (30) 52.219–33, Nonmanufacturer Rule (SEP 2021) (15 U.S.C. 657s).

[X] (31) 52.222-3, Convict Labor (JUN 2003) (E.O. 11755).

[X] (32) 52.222–19, Child Labor—Cooperation with Authorities and Remedies (FEB 2024) (E.O. 13126).

[X] (33) 52.222-21, Prohibition of Segregated Facilities (APR 2015).

[X] (34)(i) 52.222–26, Equal Opportunity (SEP 2016) (E.O. 11246).

[] (ii) Alternate I (FEB 1999) of 52.222-26.

[X] (35)(i) 52.222–35, Equal Opportunity for Veterans (JUN 2020) (38 U.S.C. 4212).

[] (ii) Alternate I (JUL 2014) of 52.222-35.

[X] (36)(i) 52.222–36, Equal Opportunity for Workers with Disabilities (JUN 2020) (29 U.S.C. 793).

[] (ii) Alternate I (JUL 2014) of 52.222-36.

[X] (37) 52.222–37, Employment Reports on Veterans (JUN 2020) (38 U.S.C. 4212).

[X] (38) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act

(DEC 2010) (E.O. 13496).

[X] (39)(i) 52.222-50, Combating Trafficking in Persons (NOV 2021) (22 U.S.C. chapter 78 and E.O. 13627).

[] (ii) Alternate I (MAR 2015) of 52.222-50 (22 U.S.C. chapter 78 and E.O. 13627).

[X] (40) 52.222-54, Employment Eligibility Verification (MAY 2022). (E. O. 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial products or commercial services as prescribed in FAR 22.1803.)

[] (41)(i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA- Designated Items (MAY 2008) (42 U.S.C.6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

[] (ii) Alternate I (MAY 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

[] (42) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (MAY 2024) (42 U.S.C. 7671, et seq.).

[] (43) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (MAY 2024) (42 U.S.C. 7671, et seq.).

[] (44) 52.223-20, Aerosols. (MAY 2024) (42 U.S.C. 7671, et seq.).

[] (45) 52.223-21, Foams (MAY 2024). (42 U.S.C. 7671, et seq.).

[] (46) 52.223-23, Sustainable Products and Services (MAY 2024) (E.O. 14057, 7 U.S.C.

8102, 42 U.S.C. 6962, 42 U.S.C. 8259b, and 42 U.S.C. 7671I).

[X] (47)(i) 52.224-3, Privacy Training (JAN 2017) (5 U.S.C. 552a).

[] (ii) Alternate I (JAN 2017) of 52.224-3.

[] (48)(i) 52.225-1, Buy American—Supplies (OCT 2022) (41 U.S.C. chapter 83).

[] (ii) Alternate I (OCT 2022) of 52.225-1.

[] (49)(i) 52.225-3, Buy American—Free Trade Agreements—Israeli Trade Act (NOV 2023) (19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, 19 U.S.C.

chapter 29 (sections 4501-4732), Public Law 103-182, 108-77, 108-78, 108-286, 108-302, 109- 53, 109-169, 109-283, 110-138, 112-41, 112-42, and 112-43.

[] (ii) Alternate I [Reserved].

[] (iii) Alternate II (DEC 2022) of 52.225-3.

[] (iv) Alternate III (FEB 2024) of 52.225-3.

[] (v) Alternate IV (OCT 2022) of 52.225-3.

[] (50) 52.225–5, Trade Agreements (NOV 2023) (19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note [X] (51) 52.225-13, Restrictions on Certain Foreign Purchases (FEB 2021) (E.O.'s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).

[] (52) 52.225–26, Contractors Performing Private Security Functions Outside the United States (OCT 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. Subtitle A, Part V, Subpart G Note).

[] (53) 52.226-4, Notice of Disaster or Emergency Area Set-Aside (NOV 2007) (42 U.S.C.

5150).

[] (54) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (NOV 2007) (42 U.S.C. 5150).

[] (55) 52.226-8, Encouraging Contractor Policies to Ban Text Messaging While Driving

(MAY 2024) (E.O. 13513)

[X] (56) 52.229–12, Tax on Certain Foreign Procurements (FEB 2021).

[] (57) 52.232-29, Terms for Financing of Purchases of Commercial Products and Commercial Services (NOV 2021) (41 U.S.C. 4505, 10 U.S.C. 3805).

[] (58) 52.232-30, Installment Payments for Commercial Products and Commercial Services

(NOV 2021) (41 U.S.C. 4505, 10 U.S.C. 3805).

[X] (59) 52.232-33, Payment by Electronic Funds Transfer—System for Award Management

(OCT 2018) (31 U.S.C. 3332).

[] (60) 52.232-34, Payment by Electronic Funds Transfer—Other than System for Award Management (JUL 2013) (31 U.S.C. 3332).

[] (61) 52.232-36, Payment by Third Party (MAY 2014) (31 U.S.C. 3332).

[X] (62) 52.239-1, Privacy or Security Safeguards (AUG 1996) (5 U.S.C. 552a).

[X] (63) 52.242-5, Payments to Small Business Subcontractors (JAN 2017)(15 U.S.C.

637(d)(13)).

[] (64)(i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (NOV 2021) (46 U.S.C. 55305 and 10 U.S.C. 2631).

[] (ii) Alternate I (APR 2003) of 52.247-64.

[] (iii) Alternate II (NOV 2021) of 52.247-64.

(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

[X] (1) 52.222-41, Service Contract Labor Standards (AUG 2018) (41 U.S.C. chapter 67).

[X] (2) 52.222-42, Statement of Equivalent Rates for Federal Hires (MAY 2014) (29 U.S.C.

206 and 41 U.S.C. chapter 67).

[X] (3) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards—Price Adjustment (Multiple Year and Option Contracts) (AUG 2018) (29 U.S.C. 206 and 41 U.S.C.

chapter 67).

[X] (4) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards—Price Adjustment (MAY 2014) (29 U.S.C 206 and 41 U.S.C. chapter 67).

[] (5) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment—Requirements (MAY 2014) (41 U.S.C. chapter 67).

[] (6) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services—Requirements (MAY 2014) (41 U.S.C. chapter 67).

[X] (7) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026

(JAN 2022).

[X] (8) 52.222-62, Paid Sick Leave Under Executive Order 13706 (JAN 2022) (E.O. 13706).

[] (9) 52.226–6, Promoting Excess Food Donation to Nonprofit Organizations (JUN 2020) (42 U.S.C. 1792).

(d) Comptroller General Examination of Record. The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, as defined in FAR 2.101, on the date of award of this contract, and does not contain the clause at 52.215-2, Audit and Records—Negotiation.

(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor's directly pertinent records involving transactions related to this contract.

(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR Subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.

(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.

(e)(1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c), and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial products or commercial services. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause—

(i) 52.203–13, Contractor Code of Business Ethics and Conduct (NOV 2021) (41 U.S.C.

3509).

(ii) 52.203–17, Contractor Employee Whistleblower Rights (NOV 2023) (41 U.S.C. 4712).

(iii) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(iv) 52.204–23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities (DEC 2023) (Section 1634 of Pub. L. 115–91).

(v) 52.204–25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115–232).

(vi) 52.204–27, Prohibition on a ByteDance Covered Application (JUN 2023) (Section 102 of Division R of Pub. L. 117–328).

(vii) (A) 52.204–30, Federal Acquisition Supply Chain Security Act Orders— Prohibition.

(DEC 2023) (Pub. L. 115–390, title II).

(B) Alternate I (DEC 2023) of 52.204–30.

(viii) 52.219–8, Utilization of Small Business Concerns (FEB 2024) (15 U.S.C. 637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds the applicable threshold specified in FAR 19.702(a) on the date of subcontract award, the subcontractor must include 52.219–8 in lower tier subcontracts that offer subcontracting opportunities.

(ix) 52.222-21, Prohibition of Segregated Facilities (APR 2015).

(x) 52.222–26, Equal Opportunity (SEP 2016) (E.O. 11246).

(xi) 52.222–35, Equal Opportunity for Veterans (JUN 2020) (38 U.S.C. 4212).

(xii) 52.222–36, Equal Opportunity for Workers with Disabilities (JUN 2020) (29 U.S.C.

793).

(xiii) 52.222–37, Employment Reports on Veterans (JUN 2020) (38 U.S.C. 4212).

(xiv) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (DEC 2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.

(xv) 52.222-41, Service Contract Labor Standards (AUG 2018) (41 U.S.C. chapter 67).

(xvi)(A) 52.222-50, Combating Trafficking in Persons (NOV 2021) (22 U.S.C. chapter 78 and E.O. 13627).

(B) Alternate I (MAR 2015) of 52.222-50 (22 U.S.C. chapter 78 and E.O. 13627).

(xvii) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment—Requirements (MAY 2014) (41 U.S.C. chapter 67).

(xviii) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services—Requirements (MAY 2014) (41 U.S.C. chapter 67).

(xix) 52.222-54, Employment Eligibility Verification (MAY 2022) (E. O. 12989).

(xx) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026

(JAN 2022).

(xxi) 52.222-62 Paid Sick Leave Under Executive Order 13706 (JAN 2022) (E.O. 13706).

(xxii)(A) 52.224-3, Privacy Training (JAN 2017) (5 U.S.C. 552a).

(B) Alternate I (JAN 2017) of 52.224-3.

(xxiii) 52.225–26, Contractors Performing Private Security Functions Outside the United States (OCT 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. Subtitle A, Part V, Subpart G Note).

(xxiv) 52.226–6, Promoting Excess Food Donation to Nonprofit Organizations (JUN 2020) (42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.

(xxv) 52.232–40, Providing Accelerated Payments to Small Business Subcontractors (MAR 2023) (31 U.S.C. 3903 and 10 U.S.C. 3801). Flow down required in accordance with paragraph

(c) of 52.232–40.

(xxvi) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (NOV 2021) (46 U.S.C. 55305 and 10 U.S.C. 2631). Flow down required in accordance with paragraph

(d) of FAR clause 52.247-64.

(2) While not required, the Contractor may include in its subcontracts for commercial products and commercial services a minimal number of additional clauses necessary to satisfy its contractual obligations.

C.4 FAR 52.217-7 OPTION FOR INCREASED QUANTITY – SEPARATELY PRICED

LINE ITEM (MAR 1989)

The Government may require the delivery of the numbered line items 5001, 5001AA, and 5001AB, identified in the Price Schedule as an option item, in the quantity and at the price stated in the Price Schedule. The Contracting Officer may exercise the option by written notice to the Contractor anytime within the contract period of performance. Delivery of added items shall continue at the same rate that like items are called for under the contract unless the parties otherwise agree.

(End of Clause)

C.5 FAR 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR

2000)

(a) The Government may extend the term of this contract by written notice to the Contractor provided that the Government gives the Contractor a preliminary written notice of its intent to extend prior to the contract expiring. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 66 months.

(End of clause)

C.6 52.227-19 COMMERCIAL COMPUTER SOFTWARE LICENSE (DEC 2007)

(a) Notwithstanding any contrary provisions contained in the Contractor's standard commercial license or lease agreement, the Contractor agrees that the Government will have the rights that are set forth in paragraph (b) of this clause to use, duplicate or disclose any commercial computer software delivered under this contract. The terms and provisions of this contract shall comply with Federal laws and the Federal Acquisition Regulation.

(b)(1) The commercial computer software delivered under this contract may not be used, reproduced, or disclosed by the Government except as provided in paragraph (b)(2) of this clause or as expressly stated otherwise in this contract.

(2) The commercial computer software may be—

(i) Used or copied for use with the computer(s) for which it was acquired, including use at any Government installation to which the computer(s) may be transferred;

(ii) Used or copied for use with a backup computer if any computer for which it was acquired is inoperative;

(iii) Reproduced for safekeeping (archives) or backup purposes;

(iv) Modified, adapted, or combined with other computer software, provided that the modified, adapted, or combined portions of the derivative software incorporating any of the delivered, commercial computer software shall be subject to same restrictions set forth in this contract;

(v) Disclosed to and reproduced for use by support service Contractors or their subcontractors, subject to the same restrictions set forth in this contract; and

(vi) Used or copied for use with a replacement computer.

(3) If the commercial computer software is otherwise available without disclosure restrictions, the Contractor licenses it to the Government without disclosure restrictions.

(c) The Contractor shall affix a notice substantially as follows to any commercial computer software delivered under this contract:

Notice—Notwithstanding any other lease or license agreement that may pertain to, or accompany the delivery of, this computer software, the rights of the Government regarding its use, reproduction and disclosure are as set forth in Government Contract No.

______TBD____________.

C.7 Reserved

C.8 VAAR 852.211-76 LIQUIDATED DAMAGES – REIMBURSEMENT FOR DATA

BREACH COSTS (FEB 2023)

(a) Definition. As used in this clause, “contract” means any contract, agreement, order or other instrument and encompasses the definition set forth in FAR 2.101.

(b) Non-disclosure requirements. As a condition of performance under a contract, order, agreement, or other instrument that requires access to sensitive personal information as defined in VAAR 802.101, the following is expressly required— https://www.acquisition.gov/far/part-2#FAR_2_101 https://www.va.gov/oal/library/vaar/vaar802.asp#802101

(1) The Contractor, subcontractor, their employees or business associates shall not, directly or through an affiliate or employee of the Contractor, subcontractor, or business associate, disclose sensitive personal information to any other person unless the disclosure is lawful and is expressly permitted under the contract; and

(2) The Contractor, subcontractor, their employees or business associates shall immediately notify the Contracting Officer and the Contracting Officer’s Representative (COR) of any security incident that occurs involving sensitive personal information.

(c) Liquidated damages. If the Contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach, the Contractor shall, in place of actual damages, pay to the Government liquidated damages of $37.50 per affected individual in order to cover costs related to the notification, data breach analysis and credit monitoring. In the event the Contractor provides payment of actual damages in an amount determined to be adequate by the Contracting Officer, the Contracting Officer may forgo collection of liquidated damages.

(d) Purpose of liquidated damages. Based on the results from VA’s determination that there was a data breach caused by Contractor’s or any of its agents’ failure to protect or otherwise engaging in conduct to cause a data breach of VA sensitive personal information, and as directed by the Contracting Officer, the Contractor shall be responsible for paying to the VA liquidated damages in the amount of $37.50 per affected individual to cover the cost of the following:

(1) Notification related costs.

(2) Credit monitoring reports.

(3) Data breach analysis and impact.

(4) Fraud alerts.

(5) Identity theft insurance.

(e) Relationship to termination clause, if applicable. If the Government terminates this contract, purchase order, or agreement, in whole or in part under clause 52.249-8, Default—Fixed-Price Supply and Service, or any other related FAR or VAAR clause included in the contract, in addition to the required liquidated damages for data breach-related expenses specified in paragraph (c) above, the Contractor is liable for excess costs for those supplies and services for repurchase as may be required under the Termination clause.

(End of clause)

C.9 VAAR 852.239-70 SECURITY REQUIREMENTS FOR INFORMATION

TECHNOLOGY RESOURCES (FEB 2023)

(a) Definitions. As used in this clause— Information technology has the same meaning in FAR 2.101 and also means Information and Communication Technology (ICT).

Information system security plan means a formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements.

https://www.acquisition.gov/far/part-52#FAR_52_249_8 https://www.acquisition.gov/far/2.101

(b) Responsibilities. The Contractor shall be responsible for information system security for all systems connected to a Department of Veterans Affairs (VA) network or operated by the Contractor for VA, regardless of location. This clause is applicable to all or any part of the contract that includes information technology resources or services in which the Contractor has physical or other system access to VA information that directly supports the mission of VA. Examples of tasks that require security provisions include—

(1) Hosting of VA e-Government sites or other information technology operations;

(2) Acquisition, transmission, or analysis of data owned by VA with significant replacement cost should the contractor's copy be corrupted; and

(3) Access to VA general support systems/major applications at a level beyond that granted the general public, e.g., bypassing a firewall.

(c) Information system security plan. The Contractor shall develop, provide, implement, and maintain an Information System Security Plan. VA information systems must have an information system security plan that provides an overview of the security requirements for the system and describes the security controls in place or the plan for meeting those requirements. This plan shall describe the processes and procedures that the Contractor will follow to ensure appropriate security of information system resources developed, processed, or used under this contract. The information system security plan should include implementation status, responsible entities, resources, and estimated completion dates. Information system security plans may also include, but are not limited to, a compiled list of system characteristics, and key security-related documents such as a risk assessment, PIA, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan. The plan shall address the specific contract requirements regarding information systems related support or services included in the contract, to include the performance work statement (PWS) or statement of work (SOW). The Contractor's Information System Security Plan shall comply with applicable Federal Laws that include, but are not limited to, 40 U.S.C.

11331, the Federal Information Security Modernization Act (FISMA) of 2014 and the E- Government Act of 2002. The plan shall meet information system security requirements in accordance with Federal and VA policies and procedures, and as amended during the term of this contract, and include, but are not limited to the following.

(1) OMB Circular A-130, Managing Information as a Strategic Resource;

(2) National Institute of Standards and Technology (NIST) Guidelines; and

(3) VA Directive 6500, VA Cybersecurity Program, and the directives and handbooks in the VA 6500 series related to VA information (including VA sensitive information and sensitive personal information and information systems security and privacy), as well as those set forth in the contract specifications, statement of work, or performance work statement. These include, but are not limited to, VA Handbook 6500.6, Contract Security; and VA Directive and Handbook 0710, Personnel Security and Suitability Program, which establishes VA’s procedures, responsibilities, and processes for complying with current Federal law, Executive Orders, policies, regulations, standards and guidance for protecting VA information, information systems (see 802.101, Definitions) security and privacy, and adhering to personnel security requirements when accessing VA information or information systems.

(d) Submittal of plan. Within 90 days after contract award, the Contractor shall submit the Information System Security Plan to the Contracting Officer for review and approval.

(e) Security accreditation. As required by current VA policy, the Contractor shall submit written proof of information system security accreditation to the Contracting Officer for https://www.govinfo.gov/content/pkg/USCODE-2021-title40/pdf/USCODE-2021-title40-subtitleIII-chap113-subchapIII-sec11331.pdf https://www.govinfo.gov/content/pkg/USCODE-2021-title40/pdf/USCODE-2021-title40-subtitleIII-chap113-subchapIII-sec11331.pdf https://www.va.gov/oal/library/vaar/vaar802.asp#802101 non-VA owned systems. Such written proof may be furnished either by the Contractor or by a third party. Accreditation shall be in accordance with VA policy available from the Contracting Officer upon request. The Contractor shall submit for acceptance by the Contracting Officer along with this accreditation a final information system security plan, such as a risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan. The accreditation and the final information system security plan and the accompanying documents, such as a risk assessment, security test and evaluation, and disaster recovery/continuity of operations plan.

(f) Annual validation. On an annual basis, the Contractor shall verify in writing to the Contracting Officer that the Information System Security Plan remains valid.

(g) Banners. The Contractor shall ensure that the official VA banners are displayed on all VA systems (both public and private) operated by the Contractor that contain Privacy Act information before allowing anyone access to the system. The Office of Information Technology will make official VA banners available to the Contractor.

(h) Screening and access. The Contractor shall screen all personnel requiring privileged access or limited privileged access to systems operated by the Contractor for VA or interconnected to a VA network in accordance with VA Directives and Handbooks referenced in paragraph (c) of this clause.

(i) Training. The Contractor shall ensure that its employees performing services under this contract complete VA security awareness training on an annual basis. This includes signing an acknowledgment that they have read, understand, and agree to abide by the VA Information Security Rules of Behavior (VA National Rules of Behavior) as required by 38 U.S.C. 5723; FAR 39.105, Privacy; clause 852.204-71, Information and Information Systems Security, and this clause on an annual basis.

(j) Government access. The Contractor shall provide the Government access to the Contractor's and subcontractors' facilities, installations, operations, documentation, databases, and personnel used in performance of the contract. The Contractor shall provide access to enable a program of information system inspection (to include vulnerability testing), investigation and audit (to safeguard against threats and hazards to the integrity, availability and confidentiality of VA data or to the function of information systems operated on behalf of VA), and to preserve evidence of computer crime.

(k) Notification of termination of employees. The Contractor shall immediately notify the Contracting Officer when an employee who has access to VA information systems or data terminates employment.

(l) Subcontractor flow down requirement. The Contractor shall incorporate and flow down the substance of this clause to all subcontracts that meet the conditions in paragraph (a) of this clause.

C.10 VAAR 852.239-71 INFORMATION SYSTEM SECURITY PLAN AND

ACCREDITATION (FEB 2023)

(a) Design or development at non-VA facilities. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with the Federal Information Security Modernization Act (FISMA), Health Insurance Portability and Accountability Act (HIPAA) regulations, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic protected health information (PHI), outlined in 45 CFR https://www.govinfo.gov/content/pkg/USCODE-2021-title38/pdf/USCODE-2021-title38-partIV-chap57-subchapIII-sec5723.pdf https://www.acquisition.gov/far/39.105 https://www.va.gov/oal/library/vaar/vaar852.asp#85220471 https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C part 164, subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization and the Trusted Internet Connections (TIC) Reference Architecture).

(b) Privacy Impact Assessment. During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COR, and approved by the VA Privacy Service in accordance with VA Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact Assessment.

(c) Security of procured or developed systems and technologies. The Contractor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as "Systems"), throughout the life of the contract and any extension, warranty, or maintenance periods. This includes, but is not limited to, workarounds, patches, hotfixes, upgrades, and any physical components (hereafter referred to as Security Fixes) which may be necessary to fix all security vulnerabilities published or known to the Contractor anywhere in the Systems, including Operating Systems and firmware. The Contractor shall ensure that Security Fixes shall not negatively impact the Systems.

(d) Subcontract flow down requirements. The Contractor shall include the clause at 52.224-1, Privacy Act Notification, in every solicitation and/or subcontract awarded by the Contractor when the clause 52.224-1 is included in its contract.

C.11 VAAR 852.239-72 INFORMATION SYSTEM DESIGN AND DEVELOPMENT

(FEB 2023)

(a) Design or development at non-VA facilities. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with the Federal Information Security Modernization Act (FISMA), Health Insurance Portability and Accountability Act (HIPAA) regulations, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic protected health information (PHI), outlined in 45 CFR part 164, subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization and the Trusted Internet Connections (TIC) Reference Architecture).

(b) Privacy Impact Assessment. During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COR, and approved by the VA Privacy Service in accordance with VA Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact Assessment.

(c) Security of procured or developed systems and technologies. The Contractor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as ‘‘Systems’’), throughout the life of the contract and any extension, warranty, or maintenance periods. This includes, but is not limited to, workarounds, patches, hotfixes, upgrades, and any physical components (hereafter referred to as Security Fixes) which https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=767&FType=2 https://www.acquisition.gov/far/part-52#FAR_52_224_1 https://www.acquisition.gov/far/part-52#FAR_52_224_1 may be necessary to fix all security vulnerabilities published or known to the Contractor anywhere in the Systems, including Operating Systems and firmware. The Contractor shall ensure that Security Fixes shall not negatively impact the Systems.

(d) Subcontract flow down requirements. The Contractor shall include the clause at 52.224–1, Privacy Act Notification, in every solicitation and/or subcontract awarded by the Contractor when the clause FAR 52.224– 1 is included in its contract.

(End of clause)

C.12 VAAR 852.239-73 INFORMATION SYSTEM HOSTING, OPERATION,

MAINTENANCE, OR USE (FEB 2023)

(a) Definitions. As used in this clause— Assessment and Authorization (A&A) means the process used to ensure information systems including Major Applications and General Support Systems have effective security safeguards which have been implemented, planned for, and documented in an Information Technology Security Plan. The A&A process per applicable VA policies and procedures is the mechanism by which VA provides an Authorization to Operate (ATO), the official management decision given by the VA to authorize operation of an information system (see VA Handbook 6500 for additional details). Information system security plan means a formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements.

(b) Hosting, operation, maintenance, or use at non-VA facilities. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, Contractors/subcontractors are fully responsible and accountable for ensuring compliance with the applicable Health Insurance Portability and Accountability (HIPAA) Act of 1996 (HIPAA) Privacy and Security Rules, the Privacy Act and other required VA confidentiality statutes included in VA’s mandatory yearly training and privacy handbooks, Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology (NIST), Federal Information Processing Standards (FIPS), and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The Contractor’s security control procedures must be equivalent to or exceed, those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to approval to operate.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .