AWE_SOW - Final - Track Changes.docx
DOCX document 3 MB Posted
- Attached to
- R499-- AWE & PSA Assessments Federal contract opportunity
- Solicitation number
- 36C10D24Q0065
- Issued by
- Department of Veterans Affairs
About this file
This statement of work outlines annual workplace evaluation and physical security assessment services required by the Department of Veterans Affairs. The contractor will conduct safety inspections and security reviews at 57 regional offices and over 150 outbased offices across multiple states and territories. Services include developing evaluation protocols, performing on-site checks, and submitting preliminary and final reports. The base period of performance is the date of award through December 2024 with two optional one-year extensions. Pricing will be provided on a per-location basis.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Vendor Q_A Final.xlsx | XLSX spreadsheet | |
| 36C10D24Q0065 0006.docx | DOCX document | |
| AWE_SOW_ Final_Track changes.docx | DOCX document | |
| 36C10D24Q0065 0005.docx | DOCX document | |
| 36C10D24Q0065 0004.docx | DOCX document | |
| 36C10D24Q0065_vendor_Q_A.xlsx | XLSX spreadsheet | |
| Instructions Sections.docx | DOCX document | |
| 36C10D24Q0065 0003.docx | DOCX document | |
| 36C10D24Q0065 0002.docx | DOCX document | |
| 36C10D24Q0065 0001.docx | DOCX document | |
| VA Handbook 6500.6 Contract Security Appendix C.pdf | ||
| solicitation vendor q and a format.xlsx | XLSX spreadsheet | |
| past performance questionnaire.docx | DOCX document | |
| AWE_SOW - Final.docx | DOCX document | |
| 36C10D24Q0065.docx | DOCX document |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Annual Workplace Evaluation and Physical Security Assessments Statement of Work (SOW)
Introduction/Background As one of the administrations within the Department of Veterans Affairs (VA), the Veterans Benefits Administration (VBA) provides a variety of benefits and services to service members, veterans, and their families. These benefits and services include but are not limited to education benefits, home loans, life insurance, and disability compensation or pension benefits. Award of these benefits often requires information gathering from a multitude of third parties, government agencies, and digital repositories as well as the application of complex rules.
VBA owns and operates a substantial infrastructure portfolio within the National Capital Region (NCR) and Regional Offices throughout the nation. VBA is committed to protecting its workers by conducting annual workplace inspections consistent with direction from the VBA Office of Mission Support - Occupational Safety and Health Division and Physical Security Assessments consistent with the Office of Safety, Security, and Preparedness. The inspections and assessments focus on two major task categories:
1) Annual Workplace Evaluations (AWE) are inspections for workplace hazards by evaluating the Occupational Safety and Health programs/elements/requirements. AWE’s shall be conducted by the contractor annually at both Regional Offices and Out based Offices.
2) Physical Security Assessments are security assessments for the implementation of best practices to mitigate vulnerabilities and threats and countermeasures for specific aspects in the following areas:
a. Facility Overview
b. Facility Security Background
c. Security Force Profile
d. Physical Security Profile
e. Comprehensive Security Systems.
Contractor shall complete PSAs only at all out based offices and the contractor shall complete PSAs only during he base year of the contract.
VBA will accomplish these inspections and assessments through the services of a contractor with the necessary safety expertise and physical security expertise. This approach ensures that VBA receives expert and third-party feedback on safety and physical security.
The purpose of this procurement is to engage a highly skilled contractor with expert knowledge and extensive experience as well as credibility in these critical areas of safety and physical security. This document outlines the scope and steps to be taken to create a methodology that promotes consistency, ensures thoroughness, and enhances the quality of the assessment process.
Scope The VBA Office of Mission Support (OMS) – Occupational Safety and Health (OSH) Division and the Office of Safety Security and Preparedness (OSSP) seeks the support of a highly experienced Contractor with broad and extensive technical expertise in two Task Areas 1) Annual Workplace Evaluation and 2) Physical Security Assessments to provide an array of support for numerous VBA Regional Offices and Out-Based Office sites. The following Table of Deliverables is described in more detail in Section 5.
List of Deliverables
Project Kick-off Meeting and meeting minutes
Project Plan (w/ major actions, key milestones, etc.)
Work Plan for AWE with deployment schedule
Integrated Master Schedule (IMS)
Table format schedule (AWEs) derived from IMS
Table format schedule (PSAs) derived from IMS
Work Plan for Physical Security Assessments with deployment schedule
Preliminary AWE Completed Checklist (1-per site prior to departure)
Final AWE Completed Checklist (1-per site 15 days after site visit)
Inspector’s Supplemental Information/Observation Report (1-per site 15 days after site visit)
Preliminary PSA AWE Completed Checklists (1-per site prior to departure)
Final PSA AWE Completed Checklist (1-per site 15 days after site visit)
Inspector’s Supplemental Information/Observation Report (1-per site 15 days after site visit)
Transition-In Plan
Detailed Transition-Out Plan
Personnel assigned to the Task Areas shall be specialized and certified in their respective skill areas. Required service areas include:
Task Area 1: Annual Workplace Evaluations Annual Workplace Evaluations (AWE) encompass inspections and the completion of checklists and reports for the Occupational Safety and Health (OSH) Programs, which include but are not limited to the following safety programs/elements/requirements:
· Life Safety
· Electrical Safety
· Lock Out/Tag Out,
· Construction Safety,
· General Work Environment
· Housekeeping
· Medical Services and First Aid
· Personal Protective Equipment (PPE),
· Hazard Communication (Global Harmonization System),
· Federal Agency Requirements, and
· OSH Training Task Area 2: Physical Security Assessments Physical Security Assessments (PSAs) encompass three-year assessment cycles, however, PSAs will be conducted at all Out-Based offices in the base year of the contract, and ensure the completion of checklists and reports for the Office of Safety, Security, and Preparedness (OSSP), which include but are not limited to the following areas of security assessments:
· Facility Overview
· Security Force Profile
· Entry Controls Employees/Visitors (Badging)
· Parking Delivery Standoff
· Barriers, Locks, and Keys
· Building Envelope
· Intrusion Detection and Assessment
· Communications
· Testing and Maintenance
· Support Systems, and
· Systems Management Applicable Criteria Documents The Contractor shall comply with the criteria documents listed below in three categories: 3.1) General Applicable Criteria Documents; 3.2) Annual Workplace Evaluation Criteria Documents; and 3.3) Physical Security Assessment Criteria Documents.
General Applicable Criteria Documents
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. 44 U.S.C. § 3551-3558, “Federal Information Security Modernization Act (FISMA) of 2014.”
3. Health Insurance Portability and Accountability Act (HIPAA); 45 CFR Part 160, 162, and 164; Health Insurance Reform: Security Standards; Final Rule dated February 20, 2003
4. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017
5. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007.
6. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005.
7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974.”
8. Public Law 109-461, “Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters.”
9. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998.
10. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards.”
11. Section 701 of the Promise to Address Comprehensive Toxics (PACT) Act of 2022 (Public Law 117-168), August 2, 2022
12. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
13. Social Security Number (SSN) Fraud Prevention Act of 2017
14. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018
15. Federal Travel Regulation (FTR) (www.gsa.gov/federaltravelregulation)
16. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade,” dated March 19, 2015.
17. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001.
18. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018
19. Executive Order 13960, “Promoting the Use of Trustworthy Artificial Intelligence in the Federal Government,” dated December 3, 2020.
20. Executive Order 14026, “Increasing the Minimum Wage for Federal Contractors,” dated April 27, 2021.
21. Executive Order 14028, “Improving the Nation's Cybersecurity,” dated May 12, 2021.
22. Executive Order 14034, “Protecting Americans' Sensitive Data from Foreign Adversaries,” dated June 9, 2021.
23. Executive Order 14058, “Transforming Federal Customer Experience and Service Delivery to Rebuild Trust in Government,” dated December 13, 2021.
24. “Homeland Security Presidential Directive (12) (HSPD-12)”, August 27, 2004.
25. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016.
26. OMB Memorandum “Security Authorization of Information Systems in Cloud Computing Environments,” December 8, 2011 (FedRAMP Policy Memorandum)
27. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005
28. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC),” November 20, 2007.
29. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008.
30. OMB Memorandum M-04-04, “E-Authentication Guidance for Federal Agencies,” December 16, 2003.
31. OMB Memorandum M-05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005.
32. OMB Memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” February 3, 2011.
33. OMB Memorandum M-19-17, “Enabling Mission Delivery through Improved Identity, Credential, and Access Management,” May 21, 2019.
34. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019
35. OMB Memo M-21-06, “Guidance for Regulation of Artificial Intelligence Applications,” dated November 17, 2020.
36. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol version 6 (IPv6),” November 19, 2020.
37. OMB Memo M-21-30, “Protecting Critical Software Through Enhanced Security Measures,” dated August 10, 2021.
38. OMB Memo M-22-01, “Improving Detection of Cybersecurity Vulnerabilities and Incidents on Federal Government Systems through Endpoint Detection and Response,” dated October 8, 2021.
39. OMB Memorandum M-22-09, “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles,” January 26, 2022.
40. OMB Memorandum for Chief Information Officers, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008.
41. “Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.2, Federal Interagency Technical Reference Architectures, Department of Homeland Security,” June 19, 2017.
42. “Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance,” V2.0, December 2, 2011.
43. “Draft National Institute of Standards and Technology Interagency Report (NISTIR) 798, “Mobile, PIV, and Authentication,” March 2014.
44. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules,” May 25, 2001.
45. FIPS 186-5, “Digital Signature Standard (DSS),” dated February 3, 2023.
46. FIPS Publication 199, “Standards for Security Categorization of Federal Information and Information Systems,” February 2004.
47. FIPS Publication 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006.
48. FIPS Publication 201-3, “Personal Identity Verification of Federal Employees and Contractors,” January 2022.
49. FIPS Special Publication 800-172, “Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIS Special Publication 800-171,” February 2021.
50. NIST SP 500-267B Revision 1, ”USGv6 Profile,” November 2020
51. NIST SP 800-37, “Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, Rev. 2,” December 20, 2018.
52. NIST SP 800-53, “Security and Privacy Controls for Federal Information Systems and Organizations,” dated May 26, 2022.
53. NIST SP 800-57, “Recommendation for Key Management,” dated May 4, 2020.
54. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” December 1, 2017.
55. NIST Special Publication (SP) 800-66 Rev 2 (Draft): “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” July 2022.
56. NIST SP 800-116 Rev. 1, “Guidelines for the Use of PIV Credentials in Facility Access,” June 29, 2018.
57. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 19, 2014.
58. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013 (https://www.va.gov/vapubs/index.cfm)
59. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013 (https://www.va.gov/vapubs/index.cfm)
60. VA Handbook 0710, “Personnel Suitability and Security Program” dated May 2, 2016
61. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, (https://www.va.gov/vapubs/index.cfm)
62. VHA Directive 1605.05, Business Associate Agreements, November 17, 2020, (https://www.va.gov/vhapublications/ViewPublication.asp?pub_ID=9178)
63. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5, 2019 (https://www.va.gov/vapubs/index.cfm)
64. VA Directive 6102 (Internet/Intranet Services), August 5, 2019 (https://www.va.gov/vapubs/index.cfm)
65. VA Handbook 6102 (Internet/Intranet Services), August 5, 2019 (https://www.va.gov/vapubs/index.cfm
66. VA Directive 6300, “Records and Information Management,” September 21, 2018 (https://www.va.gov/vapubs/index.cfm)
67. VA Handbook, 6300.1, “Records Management Procedures,” March 24, 2010 (https://www.va.gov/vapubs/index.cfm)
68. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021 (https://www.va.gov/vapubs/index.cfm)
69. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” February 24, 2021 (https://www.va.gov/vapubs/index.cfm)
70. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019 (https://www.va.gov/vapubs/index.cfm)
71. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle,” March 22, 2010 (https://www.va.gov/vapubs/index.cfm)
72. VA Handbook 6500.6, “Contract Security,” March 12, 2010 (https://www.va.gov/vapubs/index.cfm)
73. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011 (https://www.va.gov/vapubs/index.cfm)
74. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018.
75. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017.
76. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014.
77. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015.
78. VA Directive and Handbook 6510, “VA Identity and Access Management,” January 15, 2016.
79. A Directive and Handbook 6513, “Secure External Connections,” October 12, 2017
80. VA Directive and Handbook 6517, “Risk Management Framework for Cloud Computing,” November 15, 2016.
81. VA Directive 6609, “Mailing of Sensitive Personal Information,” May 20, 2011 (https://www.va.gov/vapubs/index.cfm)
82. VA Handbook 0730, “Security and Law Enforcement,” dated August 11, 2000. (https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=93&FType=2)
83. VA Handbook 0730/1, “Security and Law Enforcement,” dated August 20, 2004. (https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=96&FType=2)
84. VA Handbook 0730/4, “Security and Law Enforcement,” dated March 29, 2013. (https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=700&FType=2)
85. VA Directive 6066, “Protected Health Information (PHI) and Business Associate Agreements Management,” dated September 2, 2014.
86. VA Regulation 2022-13312, “Individuals Using the Department of Veterans Affairs’ Information Technology Systems to Access Records Relevant to a Benefit Claim,” dated June 24, 2022.
87. “Authorization Requirements Standard Operating Procedures, v1.35,” dated April 13, 2022.
88. “BTS Emergency Notification SOP, v2.0, dated July 22, 2021
89. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
90. “One-VA Technical Reference Model (TRM)” - (reference at https://www.va.gov/trm/TRMHomePage.aspx)
91. VA Enterprise Cloud Technical Reference Guide, v2.0, dated November 2022.
92. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015.
93. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014.
94. VA Enterprise Cloud (VAEC) Technical Reference Guide, July 2018 version 1.
95. “IAM Identity Management Business Requirements Guidance Document”, May 2013. https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514
96. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011
97. VA Memorandum, VAIQ #7712300, “Mandate to meet PIV Requirements for New and Existing Systems,” June 30, 2015.
98. VA Memorandum, VAIQ #7660995, “Continuous Diagnostics and Monitoring of all VA Information Systems,” dated January 29, 2016.
99. VA Memorandum, VAIQ #7497987, “Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment,” August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section. https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552
100. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014. https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
101. VA Memorandum, VAIQ #7614373, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems,” July 9, 2015. https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
102. VA Memorandum, VAIQ #7613595, “Mandatory Use of PIV Multifactor Authentication to VA Information System,” June 30, 2015. https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
103. VA Memorandum, VAIQ #7613597, “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges,” June 30, 2015. https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
104. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896
105. VA Memorandum, VAIQ #7581492, “Use of Personal Email,” April 24, 2015. https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
106. VA Memorandum VAIQ #7823189, “Updated VA Information Security Rules of Behavior,” September 15, 2017. https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
107. “Records Control Schedule VB-1,” dated January 31, 2014.
Annual Workplace Evaluation Criteria Documents
108. 29 CFR 1904 “Recording and Reporting Occupational Injuries and Illnesses”, latest version
109. 29 CFR 1910 “Occupational Safety and Health Standards,” latest version
110. 29 CFR 1926 “Safety and Health Regulations for Construction,” latest version
111. 29 CFR 1960 “Basic Program Elements for Federal Employee Occupational Safety and Health Programs and Related Matters”, latest version
112. 41 CFR Subtitle C “Federal Property Management Regulations System”
113. National Fire Protection Association (NFPA) Standards, latest version
114. General Services Administration (GSA) Lease Criteria
115. American National Standards Institute (ANSI)
116. VA Directive 7700 OSH Program
117. VBA Directive 7700 OSH Program Physical Security Assessment Criteria Documents
118. VA Handbooks 0730
119. Physical Security Design Manual (PDRSM)
120. Interagency Security Committee (ISC) Risk Management Process for Federal Facilities Performance Details Performance Period The Base Period is date of award through December 31, 2024.
Option Period 1 is January 1, 2025 through December 31, 2025.
Option Period 2 is January 1, 2026 through December 31, 2026.
Hours of Work Work at a Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO). Hours of work will be established at the contract level. The Contractor may also be required to support 24/7 operations 365 days per year as identified in the contract.
There are 11 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, five are set by date:
| New Year's Day | January 1 |
| Juneteenth Day | June 19 |
| Independence Day | July 4 |
| Veterans Day | November 11 |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six (6) are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January | |
| Washington's Birthday | Third Monday in February | |
| Memorial Day | Last Monday in May | |
| Labor Day | First Monday in September | |
| Columbus Day | Second Monday in October | |
| Thanksgiving | Fourth Thursday in November |
Place of Performance Locations of the work shall be at Government and Contractor sites within the Continental United States (CONUS), the Philippines, Puerto Rico, St. Thomas, and St. Croix. No work at Contractor site(s) shall be performed outside of the Continental United States (OCONUS). The primary work performed at the Government locations is identified in Section 10 Regional Office Locations List and Section 11 Out-Based Office Locations List.
Travel Most of the work shall require travel by the Contractor, anticipated requirements for travel include Contractor or combined Contractor/VBA staff teams performing facility assessment, visits, inspections, or training. The contractor is responsible for all travel cost and shall be in accordance with the GSA Federal Travel Regulations, Federal Acquisition Regulation (FAR) 31.205-46. All travel cost shall be inclusive of the contractor’s price quote for each inspection. Therefore, the government will not provide a separate reimbursement for any contractor travel cost incurred. In addition, all travel must be pre-approved by the Contracting Officer’s Representative (COR).
For AWE travel, the Contractor shall conduct on-site inspections at 100% of the Regional Offices (ROs) and at 100% of the Out-Based Offices (OBOs) during each period of performance (see list at Section 10 and 11). Preparation for each on-site visit shall include a Pre-Visit Conference Call, Opening Conference, and Closing Conference with the VBA identified point-of-contact(s). These may include the facility Director, Assistant Director, Collateral Duty Safety Officer (CDSO), Security Officer, union representatives, and other personnel identified by VBA.
For PSA travel, the Contractor shall conduct PSAs at all out based offices in the base year of the contract. (See list at Section 12). The list shall be coordinated with and determined by the VBA point-of-contact for the PSAs. Preparation for and each visit shall include a Pre-Visit Conference Call, Opening Conference, and Closing Conference with the VBA identified point-of-contact(s). These may include the facility Director, Assistant Director, Collateral Duty Safety Officer (CDSO), Security Officer, union representatives, and other personnel identified by VBA.
Most VBA facilities shall require a one-day visit plus travel to and from the facility. Some of the larger facilities may require 1.5 to 2 days depending on size and complexity. The Contractor shall coordinate with the facilities point-of-contact (POC) will provide the Contractor with a schedule. The Contractor shall make every effort to minimize travel and combine individual visits within a normal work week.
Upon award of the contract, the Contractor shall work with the government points-of-contract to develop and provide separate projected travel schedules for AWEs and PSAs no later than 20 days after the contract award. The Contractor shall develop separate travel schedules for the AWEs and PSAs, respectively, in a simple table format derived from an Integrated Master Schedule (IMS) for overall management of the contract award. The Contractor shall prepare to travel within the first 30 days of the contract and may be required to travel before submittal of the travel schedule. The Contractor shall work with the government to determine priority of site-visits to ensure any government expectations, priorities, and sequencing for AWEs or PSAs are accomplished. For the Contractor’s proposal, the Contractor shall provide to the government a proposed IMS and simple table format (separate for AWEs and PSAs) with the appropriate headings, proposed lead times for site visits, prospective groupings for the efficiency of travel, any other heading categories the Contractor considers key or critical, and other documentation that may benefit the effectiveness of the teams.
Deliverable(s):
A. Integrated Master Schedule (IMS) B. Table format schedule (AWEs) derived from IMS C. Table format schedule (PSAs) derived from IMS Non-Government Facilities Personnel performing at Contractor facilities shall comply with VA and/or Federal Authorization and Accreditation (A&A) requirements. The Contractor shall disclose specific facility information during the solicitation process as part of the Contractor proposal. All facilities shall be approved by VA and in compliance with VA Security and Privacy. All facilities containing VA source materials shall be compliant with 36 CFR Part 1234, Subpart B, with no exceptions made for the waivers discussed within 36 CFR Part 1234, Subpart B.
Contractor Acquired Equipment The Contractor shall acquire and/or provide any hardware and/or software required to accomplish the contract that is not provided as Government Furnished Property (GFP). All hardware/software must adhere to VA information technology (IT) requirements, including the requirement for an Authority to Operate (ATO). Software integrity shall be maintained by the Contractor within the licensing agreement of the producer.
Task Description The sections below provide details.
Project Management, Task Management, and Work Plan The purpose of this task is to manage and coordinate support for overall project management, ensure ongoing communications, integration and collaboration, quality, status reporting, and staff allocations; and identify and address risks and issues.
This task includes overall management of the project. The Contractor shall perform the following activities:
· Conduct a kick-off meeting no later than 15 business days after contract award to define a common understanding of project plan, major actions, key milestones, and schedules as well as deliverables. The Contractor shall provide meeting minutes 3 business days after the meeting.
· Introduce Contractor personnel and describe the roles of individuals.
· Provide the staff experience profile that accomplishes the tasks in this contract.
· Identify the periodic meetings to discuss progress, plans, risks, and issues.
Deliverable(s):
A. Project Kick-off Meeting and meeting minutes B. Project Plan (w/ major actions, key milestones, etc.)
Work Plan for AWE
· Develop a Work Plan for AWE inspections no later than 20 business days after contract award that serves as a living document throughout the contract and will cover the following general areas:
· Develop AWE best practices for inspections.
· Execute AWE Inspection Deployment Schedule.
· One-year cycle for Regional Offices and Out-Based Offices (OBOs)
· Document risks, issues, and root causes of deficiencies.
· Make recommendations for corrective actions and preventive measures.
· Ensure continual improvement of AWE inspection process using information gathered from past and ongoing inspections.
Deliverable(s):
Work Plan for AWE with deployment schedule Work Plan for Physical Security Assessments Develop a Work Plan for Physical Security Assessments no later than 20 business days after contract award that serves as a living document throughout the contract and will cover the following general areas:
· Document risks, issues, and make recommendations for execution of the Physical Security Assessments inspections.
· Develop Physical Security Assessment best practices for inspections, and
· Develop Physical Security Assessment Deployment Schedule
· Update the Physical Security Assessment information as required.
The deployment schedule, whether AWE Physical Security Assessment, shall be coordinated with and approved by a VBA identified point-of-contact. The deployment schedule will consider accessibility, proximity, and complexity to streamline logistics requirements. The VBA COR will work with the Contractor to develop the schedule in consideration of priorities and travel efficiency. The schedule shall reflect how the Contractor’s plan will implement an efficient methodology for conducting all the required site visits (e.g., group two to three VBA facilities in a single trip so that grouped AWE Inspections or Physical Security Assessments shall be completed in a single week based on geography, proximity, and other travel considerations).
Deliverable(s):
A. Work Plan for Physical Security Assessments with deployment schedule
Work Plan for Physical Security Assessments with deployment schedule Overall Managerial Activities for the Conduct of AWE Inspections and Physical Security Assessments Planning/Preparation The Contractor team shall review applicable regulations for the facility based on the answers to any pre-visit Questionnaire (developed as part of the protocol), review and prepare required forms for the visit, prepare a Contractor Team Plan for each facility visit to minimize time impacts to VBA facilities operations, and review the protocol so that all the steps will be followed to complete the evaluation or assessment. The Contractor will create the Opening Conference Guide and Facility Schedule. The VBA identified point-of-contact(s) will coordinate with the Contractor for any visits attended by additional observers beyond the expected personnel.
AWE – Planning and Preparation During the planning and preparation activities, AWE inspectors shall review the checklist provide by VBA requiring on-site completion (listed below and in Appendix B):
· OMS Checklist for Annual Workplace Safety and Health Inspections
· Other site-specific AWE documents
At a minimum, the assessor(s) shall review the site mission and related documents to include, but not limited to organization charts, OSH operational criteria for the site, site plans and procedures, past site office AWE checklist/surveys, facility plans and lists, housekeeping and custodial operations/procedures, personal protective equipment policy/procedures, alarm procedures, site maps, and architectural/engineering drawings. Architectural/engineering drawings shall include, but not be limited to:
· Floor plans for all floors including emergency egress
· Interior plans to include special room layouts and workstations.
· HVAC plans
· Electrical and lighting floor plans
· Plumbing plans
· Fire Safety floor plans
· Site plans including sidewalks, parking, loading dock, etc.
· Other site-specific documents, as may be defined and shall be requested by the Contractor.
Physical Security Planning and Preparation During the planning and preparation activities, physical security assessors shall review the checklist documents requiring on-site completion (listed below and in Appendices C, D and E):
· Facility Security Assessment: Building Engineer Questionnaire
· Facility Security Assessment: Cybersecurity Questionnaire
· Facility Security Assessment: Tenant Agency Questionnaire
· PACS Assessment Toolkit (Physical Access Control Systems)
· Other site-specific documents, as may be defined and shall be requested by the Contractor.
At a minimum, the assessor(s) shall review the site mission and related documents to include, but not limited to, organization charts, site security plans and procedures, past site office assessment checklist/surveys, site/facility asset lists, alarm procedures, and site maps/drawings.
Site maps/drawings may include, but not be limited to:
· Security areas (property protection areas, security areas, vaults, vault type rooms, etc.)
· Critical facilities
· Controlled areas
· Building definitions
· Location of security posts
· Classified matter areas
· Vital equipment areas
· Lighting diagrams
· Sensors (types, locations, controls, etc.)
· Alarms (types, locations, controls, etc.)
· Data transmission systems
· Console equipment, and
· Miscellaneous security items
The assessor shall plan and prepare for interviews of personnel to gain insight into facility operations. The assessor shall determine the organizational levels of personnel to interview to include, but not be limited to security managers (government and contractor), facility managers and staff, vault/vault-type room custodians, security police officers (SPOs), security technicians/specialists, systems engineers and programmers, central alarm station (CAS), secondary alarm station (SAS) operators and other personnel as determined by the contractor and coordinated with the government representative. Interviews may be formal or informal and may take the form of discussions during facility tours or performance testing.
Facility Visit The Contractor will conduct the visit. Contractors must be escorted by a VA employee. In conducting the facility visit, the Contractor will gather information that will be used to confirm compliance with applicable internal and external standards as well as the specific Checklist prepared for the facility. The facility visit will begin with an Opening Conference, review of any pre-visit Questionnaire and required checklist(s), and verification of the Facility Visit Schedule. The team will conduct interviews with staff, observe operations, and review records to gather required data and develop findings. Preliminary findings will be discussed with facility management to ensure that the information gathered is correct and the Contractor will conduct a Closing Conference to review all findings at the conclusion of the visit.
AWE Actions and Conduct During On-Site Visit During the on-site visit, the AWE Inspector(s) shall conduct themselves in a professional manner as the agenda and materials prepared during the planning and preparation phase are used to guide interviews and tours in concert and coordination with on-site representatives. The Inspectors may collect information as necessary and complete the required OMS AWE Checklist, as well as collect additional information as deemed necessary for the specific site and provide a supplemental information/observation report. The Inspector’s supplemental information/observation report shall discuss observed deficiencies, potential concerns and previous findings that may have required attention/resolution and that were not addressed by the AWE checklist. The Inspectors shall work with on-site representative(s) on an action plan and timeline, if necessary, to resolve deficiencies and consider establishing a prioritized list for actions.
Set-up/schedule follow-up meetings as appropriate for communication and resolution of open items. Identify and verify actions and/or documents planned to be addressed as part of the follow-up meetings.
Deliverables:
A. Preliminary AWE Checklist (1-per site prior to departure) B. Final AWE Completed Checklist (1-per site 15 days after site visit) C. Inspector’s Supplemental Information/Observation Report (1-per site 15 days after site visit) Physical Security Assessment Actions and Conduct During On-Site Visit During the on-site visit, the Physical Security Assessors shall use detailed information prepared during the planning and preparation phase to guide interviews and tours of the physical security aspects of the facility, collecting and documenting information as necessary and as appropriate.
The Assessor(s) shall review common deficiencies, potential concerns, and previous findings after completing each data collection activity to determine whether any of the identified deficiencies are apparent at the facility. If so, assessors shall then determine whether subsequent activities should be reprioritized.
Set-up/schedule follow-up meetings as appropriate for communication and resolution of open items. Identify and verify actions and/or documents planned to be addressed as part of the follow-up meetings.
Deliverables:
D. Preliminary PSA Checklists (1-per site prior to departure) E. Final PSA Completed Checklist (1-per site 15 days after site visit) F. Assessor’s Preliminary Supplemental Information/Observation Report (1-per site prior to departure) G. Assessor’s Final Supplemental Information/Observation Report (1-per site 15 days after site visit) Data Synthesis / Forms/ Reports In addition to required forms and checklist, the Contractor shall create and provide a site visit report, preliminary before departure from the site and final report no later than 10 days after the site visit. The Contractor shall work with the government to propose a format for approval by the VBA Program Officer to report findings of the visit conducted, listing of the findings, any standard not being met, the location of the finding, the actual observation, and recommended corrective action to be taken. The reports shall also highlight good practices discovered during the site visits and identify those practices recommended for implementation. The reports shall also consist of year-end reports as noted.
AWE Reports The Contractor shall provide a summary report at the conclusion of each calendar year, including the completed checklist for each site within the time frame as noted above. For standards not being met, the Contractor shall identify the specific OSH rule that has not been met and time frame recommended for when the corrective action should be completed, as well as ensure that any critical items are specifically flagged for special attention and urgent recommendation for correction.
The Contractor shall also provide and an end of year report that summarizes VBA, highlighting positives from the inspections in each of the report including identification of consistent good practices that should be recognized and considered for implementation across VBA.
Deliverable(s):
A. Draft AWE End of Year Report (30 days before end of POP) B. Final AWE End of Year Report (5 days before end of POP) Physical Security Assessment Reports The Contractor shall provide a summary report ensuring that the specific checklist being addressed for each site is provided within the time frame as noted above. For standards not being met, the Contractor shall identify the specific security criteria that has not been met, any security practices that should be adapted (if needed) as a stop gap, and a time frame recommended for when the corrective action should be completed to ensure consistent security practices. The Contractor shall identify any critical items specifically flagged for special attention and urgent recommendation for correction.
The Contractor shall also provide and an end of year report that summarizes VBA, highlighting positive security practices from the assessments in each of the reports including identification of consistent good practices that should be recognized and considered for implementation across VBA.
Deliverable(s):
A. Draft PSA End of Year Report (30 days before end of POP) B. Final PSA End of Year Report (5 days before end of POP) AWE Specialization Areas Occupational Safety and Health Administration Programs The Contractor shall be knowledgeable and experienced with the federal, agency, directives, and consensus standards/criteria on Occupational Safety and Health to ensure that VBA Regional Offices (ROs) maintain and operate with the appropriate safety and health protocols. The Annual Workplace Evaluation criteria documents listed in Section 3.2 include specific regulations that apply to the following assessments within this Section. Occupational Safety and Health Administration (OSHA) Standard 29 CFR 1926 and 1910 discuss life safety, electrical safety, general work environment, personal protective equipment, lockout/tagout, medical services and first aid, and hazard communication program as discussed in the following sections. Standard 1926 covers safety and health regulations for construction while 1910 covers OSHA standards that are promoted from national consensus standards or any established Federal standard. Standards 29 CFR 1904 and 1960 provide guidance for OSHA programs in general. Standard 1904 requires the employer to track and report any work-related deaths, injuries, or illnesses while Standard 1960 discusses standards related to OSHA programs for Federal employees. The Contractor shall coordinate with the respective Collateral Duty Safety Officers (CDSOs) on the plan for completing the Annual Workplace Evaluation.
Life Safety (Fire and Egress):
During the life safety assessment, the Contractor will conduct a thorough on-site review of the facility, assess compliance with the Life Safety Code and VBA criteria. Standard 1910 Subpart E Exit Routes and Emergency Planning cover the requirements for exit routes in the workplace and Subpart L contains overall fire protection requirements. Standard 1926 Subpart F contains requirements for fire prevention and protection through all phases of construction. This includes but not limited to examining egress paths, doors, stairways, and above-the-ceiling areas; noting the presence of smoke and fire dampers, escutcheons, smoke detectors, fire extinguishers, exit signs, and egress illumination devices; and reviewing fire resistance ratings of doors and partitions. The Contractor shall also ensure that monthly fire extinguisher inspections are annotated. As part of the process, the Contractor shall be working with the CDSO, the Contractor shall gather building information from previously prepared Life Safety plans, VBA’s record drawings, field assessments, and consult with applicable building codes as determined by the facility’s year of construction.
Electrical Safety During the electrical safety inspection/assessment, the Contractor shall employ qualified electrical inspectors and provide all technical supervision, equipment, labor, and materials to conduct a thorough on-site review of the facility’s periodic electrical inspection and assess compliance with the electrical code and VBA/OSH criteria. 1910 Subpart S include protection requirements for electrical but for construction, requirements related to electrical safety are found in 1926 Subpart K. This includes but is not limited to examining electrical panel clearance, code compliance for use of electrical power, proper use of appliances and equipment, ensuring no damage to cords, switches, and junction boxes and ensuring proper use of any connections to electrical. The Contractor shall also investigate and document whether unauthorized small appliances are present. The Contractor shall complete all required forms and checklist and provide an overall report consistent with best practices on the overall state of the facility’s electrical system and any recommendations for improvement.
General Work Environment The Contractor shall assess the general work environment in accordance with standards 1910 or 1926 (for construction) to ensure clear egress/access paths, aisles, passageways, and emergency egress aspects to include proper egress and exit through doors and (if applicable) emergency windows. The Contractor shall ensure the stability and safety of office equipment including bookcase, cabinets, and other heavy items. The Contractor shall also assess the proper levels of illumination of work areas and proper ventilation levels and operation for the work being performed. The Contractor shall also assess the cleanliness of the work environment to ensure proper housekeeping and best practices for operating in a clean and safe work environment.
Personal Protective Equipment The Contractor shall provide workplace hazard assessments for the proper quantity and placement of required personal protective equipment (PPE) for the type of work being performed to include the need for protective gloves, aprons, shields, or other means to prevent cuts and injuries. In addition, provide emergency materials for corrosive liquids or chemical splash injuries as well as training practices for the proper use, care, and limitations for personnel use. Standard 1910 Subpart I describe the general requirements for personal protective equipment. Requirements for construction are detailed within Standard 1926 Subpart C, General Safety and Health Provisions.
Lock Out / Tag Out The Contractor shall assess existing practices for lockout/tagout procedures in facilities needing such and ensure that affected employees have been notified of procedures required for the respective facility. 1910 Subpart J has requirements on controlling hazardous energy with lockout/tagout as well as an example of typical lockout procedures. 1926 Subpart G details the requirements for using tags to prevent accidents and Subpart K specifically details locking and tagging out electrical circuits.
Medical Services and First Aid The Contractor shall assess the adequacy of medical services and first aid requirements sufficiently stocked and readily available at locations appropriate for the site and facility that allows for ready access by personnel. Requirements for medical and first aid are in 1910 Subpart K or 1926.151 Subpart D.
Hazard Communication Program The Contractor shall assess existing and needed hazard communication programs (HAZCOM) and whether workers have been trained in the proper practices for hazard controls, safe use, handling, and emergency procedures for work environments using hazardous materials as a normal part of the work environment. Hazard communication requirements can be found in 1910 Subpart Z or 1926 Subpart D.
AWE Training The Contractor shall develop, implement, and execute processes for initial training of personnel on maintaining compliance with AWE requirements. The Contractor shall develop and submit to the Government for review training plans, manuals, and other training documentation or training aids. Electronic training tools such as video teleconferencing and computer-based training shall be employed to enhance the effectiveness of training materials and courses. Training delivery may be recorded during live delivery to VA; pre-recorded initial training is not acceptable. The Contractor shall submit a detailed training plan with timelines and schedules, sufficiently detailed to identify user training plans for respective facility or facilities as coordinated with the Government. The Contractor shall create and submit completion certificates for all training attendees.
The Contractor shall develop accompanying electronic user manuals that VA will subsequently make available to new users. The electronic user manuals shall be delivered along with the training manuals. During the period of performance, the Contractor shall revise all user manuals as substantial changes are made to the service.
Deliverable(s):
A. Training plans, manuals, training documentation/aids B. Live training (electronic training tools for support – see 5.4) C. Completion Certificates Physical Security Assessments The Contractor shall be knowledgeable and experienced in the assessment of Physical Security Systems and Operations and best practices to mitigate vulnerabilities and threats. The knowledge areas required include assessments consistent with VA Handbook 0730, the Physical Security Resilience Design Manual (PDRSM), and the Interagency Security Committee (ISC) Risk Management Process for Federal Facilities. The Contractor shall conduct security assessments at identified Regional Offices (RO)s and Out-Based Offices throughout the nation in coordination with the Program Manager and respective Security Officer for the facility identified. The areas of assessment shall include but not be limited to 5.5.1 through 5.5.6.
Facility Overview Facility Operations and Building Management Systems: the Contractor shall characterize and document the overall dimensional size of the facility, acreage, parking, tenants, floor plans, building information, and update/document the overall dimensions of the facility, neighboring tenants, site property, floors, elevators, loading docks, mailrooms, and other factors determined by the Contractor to capture the character of the facility, as well as any changes that may have occurred since the previous assessment.
The Contractor shall assess and provide an overview of operational hours, personnel (government or contractor), work shifts, quantity counts of personnel and visitors, as well as related characteristics that may influence physical security criteria.
Elevators and Escalators: The Contractor shall assess elevator and escalator operations along with respective controls and monitoring and whether a system owner is identified and if a system security plan is in-place along with associated management documentation, updates, owners, points of contacts. The Contractor shall determine if the system security plan is consistent with current industry practices and, if applicable, provide recommendations for improvement. The Contractor shall identify and/or validate the quantity of elevators/escalators and their respective operational condition and whether they serve the public, building services, or other specific/dedicated function. The Contractor shall assess whether elevator/escalator operations are connected to computer or an enterprise network and whether access controls (username, password, etc.) are in-place and whether controls and monitoring are internal or external to the facility.
Heating, Ventilating, Air Conditioning (HVAC) System The Contractor shall assess the HVAC system(s) along with controls and monitoring and whether a system owner is identified and if a system security plan is in-place along with associated management documentation, updates, owners, points of contracts.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .