36C10X18Q0085-00005001.pdf
PDF 698 KB Posted
- Attached to
- SAC Armed Security (VA-18-00009053) Federal contract opportunity
- Solicitation number
- 36C10X18Q0085
About this file
36C10X18Q0085 00005 36C10X18Q0085 Amended.pdf
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10X18C0033-000.docx | DOCX document | |
| 36C10X18Q0085-00005000.docx | DOCX document | |
| 36C10X18Q0085-00002001.docx | DOCX document | |
| 36C10X18Q0085-00002000.docx | DOCX document | |
| 36C10X18Q0085-00001000.docx | DOCX document | |
| 36C10X18Q0085-000.docx | DOCX document | |
| 36C10X18Q0085-002.docx | DOCX document | |
| 36C10X18Q0085-004.docx | DOCX document | |
| 36C10X18Q0085-003.docx | DOCX document | |
| 36C10X18Q0085-005.docx | DOCX document | |
| 36C10X18Q0085-001.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 1. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. DUNS: DUNS+4:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. 2/2012)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS 64
119-18-2-219-0032
TBD 36C10X18Q0085 02-23-2018
Derek Devine 240-215-1628 03-23-2018
4:00 PM EST
Strategic Acquisition Center - Frederick
Department of Veterans Affairs
321 Ballenger Center Drive, Suite 125
Frederick MD 21703
X 100
X
561612
$20.5 Million
X
N/A
X
36C10X
See PWS Section 2.1
36C10X
Frederick MD 21703
36C10X
See Contract Administration Data, Section B.1
See CONTINUATION Page
The Department of Veterans Affairs (VA) Strategic
Acquisition Center Frederick (SAC-F) and Strategic
Acquisition Center Fredericksburg (SAC-V) requires the services of two (2) armed security guards for each of its facilities in Frederick, MD and Fredericksburg, VA.
This will be a Firm Fixed Price Contract
Provide pricing information on the schedule in section B2
The deadline for questions is 4:00 PM EST 02/28/2018
See CONTINUATION Page
X X
36C10X18Q0085
Table of Contents
SECTION A
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
B.2 LIMITATIONS ON SUBCONTRACTING-- MONITORING AND COMPLIANCE (JUN
2011)
B.3 PERFORMANCE WORK STATEMENT
B.4 PRICE/COST SCHEDULE
SECTION C - CONTRACT CLAUSES
C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL ITEMS (JAN
2017)
C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT
STATUTES OR EXECUTIVE ORDERS—COMMERCIAL ITEMS (NOV 2017)
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS .... Error! Bookmark not defined.
SECTION E - SOLICITATION PROVISIONS
E.1 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (JUL 2013)
E.2 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL ITEMS (JAN 2017)
E.3 52.216-1 TYPE OF CONTRACT (APR 1984)
E.4 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL
ITEMS (NOV 2017)
E.5 52.233-2 SERVICE OF PROTEST (SEP 2006)
E.6 VAAR 852.233-70 PROTEST CONTENT/ALTERNATIVE DISPUTE RESOLUTION
(JAN 2008)
E.7 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (JAN 1998)
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
(continuation from Standard Form 1449, block 18A.)
1. ADMINISTRATION:
All administration matters will be handled by the following individuals:
CONTRACTOR: TBD
GOVERNMENT: Contracting Officer 36C10X
Department of Veterans Affairs
Frederick, MD 21703
2. CONTRACTOR REMITTANCE ADDRESS:
All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer - System for Award Management
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly [ ]
b. Semi-Annually [ ]
c. Other [X ] Monthly, upon delivery and acceptance of
Government.
4. CONTRACTOR INSTRUCTIONS:
All invoices from the contractor shall be submitted electronically, in accordance with VAAR Clause
852.232-72 Electronic Submission of Payment Requests.
*** The IFCAP Purchase Order number: TBD MUST be included on all invoices.
*** The Contract/Order number: TBD MUST be included on all invoices.
Contracting POC: TBD
Contracting Officer’s Representative (COR) POC: TBD
TUNGSTEN (f/k/a OB10) ELECTRONIC INVOICE SUBMISSION
FSC e-INVOICE PROGRAM THRU AUSTIN PORTAL
FSC MANDATORY ELECTRONIC INVOICE SUBMISSION FOR AUSTIN PAYMENTS
Vendor Electronic Invoice Submission Methods:
Fax, email and scanned documents are not acceptable forms of submission for payment requests.
Electronic form means an automated system transmitting information electronically according to the accepted data transmissions below.
VA’s Electronic Invoice Presentment and Payment System – The Financial Services Center
(FSC) in Austin, TX uses a third-party contractor, Tungsten, to transition vendors from paper to electronic invoice submission. Please go to this website: http://www.tungsten-network.com/US/en/veterans-affairs/ to begin submitting electronic invoices, free of charge.
http://www.tungsten-network.com/US/en/veterans-affairs/ http://www.tungsten-network.com/US/en/veterans-affairs/
A system that conforms to the X12 electronic data interchange (EDI) formats established by the
Accredited Standards Center (ASC) chartered by the American National Standards Institute
(ANSI). The X12 EDI Web site is http://www.x12.org.
Vendor e-invoice Set-up information:
Please contact Tungsten at the phone number or email address listed below to begin submitting your electronic invoices to the VA Financial Services Center in Austin, TX for payment processing. If you have questions about the payment status of a properly submitted invoice, the e-invoicing program, or
Tungsten, please contact the FSC at the phone number or email address listed below.
Tungsten e-Invoice setup information: 1-877-489-6135
Tungsten e-Invoice email: VA.Registration@tungsten-network.com
VA TUNGSTEN Number: AAA544240062
FSC e-Invoice contact information: 1-877-353-9791
FSC e-Invoice email: vafsccshd@va.gov http://www.fsc.va.gov/einvoice.asp
COMMUNICATIONS:
https://www.federalregister.gov/articles/2012/11/27/2012-28612/va-acquisition-regulation-electronic-submission-of-payment-requests http://fcw.com/articles/2012/11/27/va-epayments.aspx?s=fcwdaily
5. ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
AMENDMENT NO DATE
B.2 LIMITATIONS ON SUBCONTRACTING-- MONITORING AND COMPLIANCE (JUN
2011)
This solicitation includes VAAR 852.219-10, Notice of Total Service-Disabled Veteran-Owned Small
Business Set-Aside. Accordingly, any contract resulting from this solicitation will include this clause. The contractor is advised in performing contract administration functions, the CO may use the services of a support contractor(s) retained by VA to assist in assessing the contractor's compliance with the limitations on subcontracting or percentage of work performance requirements specified in the clause. To that end, the support contractor(s) may require access to contractor's offices where the contractor's business records or other proprietary data are retained and to review such business records regarding the contractor's compliance with this requirement. All support contractors conducting this review on behalf of VA will be required to sign an “Information Protection and Non-Disclosure and Disclosure of Conflicts of Interest
Agreement” to ensure the contractor's business records or other proprietary data reviewed or obtained in the course of assisting the CO in assessing the contractor for compliance are protected to ensure information or data is not improperly disclosed or other impropriety occurs. Furthermore, if VA determines any services the support contractor(s) will perform in assessing compliance are advisory and assistance services as defined in FAR 2.101, Definitions, the support contractor(s) must also enter into an agreement with the contractor to protect proprietary information as required by FAR 9.505-4, obtaining access to proprietary information, paragraph (b). The contractor is required to cooperate fully and make http://www.x12.org/ mailto:VA.Registration@tungsten-network.com mailto:vafsccshd@va.gov http://www.fsc.va.gov/einvoice.asp https://www.federalregister.gov/articles/2012/11/27/2012-28612/va-acquisition-regulation-electronic-submission-of-payment-requests https://www.federalregister.gov/articles/2012/11/27/2012-28612/va-acquisition-regulation-electronic-submission-of-payment-requests http://fcw.com/articles/2012/11/27/va-epayments.aspx?s=fcwdaily available any records as may be required to enable the CO to assess the contractor's compliance with the limitations on subcontracting or percentage of work performance requirement.
B.3 PERFORMANCE WORK STATEMENT
1. GENERAL INFORMATION
1.1 The Department of Veterans Affairs (VA) Strategic Acquisition Center Frederick (SAC-F) and Strategic Acquisition Center Fredericksburg (SAC-V) requires the services of two (2) armed security guards for each of its facilities in Frederick, MD and Fredericksburg, VA.
The requirement shall include, per location; one (1) control desk guard, fixed, Post1, who is assigned to the Main lobby and, one (1) rover guard, Post 2, who is responsible for patrolling the entire building. The guards will provide protection for: the tenant agency employees, the general public visiting the facility, as well as personal and U.S.
Government property within the confines of post assignment area of responsibility.
Services will be provided Monday through Friday, excluding weekends and holidays, from
6:00 AM to 6:00 PM. Additional hours may be requested due to special events (i.e. open houses, recruitment fairs, etc.). The guards shall perform duties in a polite and courteous manner reflecting the highest degree of professionalism expected on all VA Federal
Protective Service (FPS) posts.
1.2 Guards shall remain alert and observe and report immediately to the Contracting Officer
Representative (COR) all violations of federal, state, or local law, or Building Rules and
Regulations, or safety hazards, facility problems, or unusual incidents occurring on
Federally owned or controlled property by telephoning the COR at 202-568-1200.
2. PLACE OF PERFORMANCE
2.1 The armed security guard services will be provided at the following locations: 321
Ballenger Center Drive, Suite 125, Frederick, MD 21703 and 10300 Spotsylvania Avenue, Suite 400, Fredericksburg, VA 22408.
3. PERIOD OF PERFORMANCE
3.1 The period of performance for the base contract will be twelve (12) months starting on April
25, 2018, running through April 24, 2019. In addition to the base period, the Government will have four (4), one (1) year option periods.
4. GENERAL INSTRUCTIONS
4.1 Purpose: To describe the basic duties, responsibilities, and expectations for FPS guards assigned to support Department of Veterans Affairs’ requirement, at 321 Ballenger Center Drive, Suite 125, Frederick, MD 21703 and 10300 Spotsylvania Avenue, Suite 400, Fredericksburg, VA 22408.
4.2 Post Orders: These Post Orders are intended to serve as a guide for the guards. Post Orders are also intended to serve as a quick reference and resource for information describing the procedures and requirements for performing general duties and specific tasks. They are established for the Security
Posts and include detailed information supporting and defining the authority, organization, duties, tasks and expectations of all guards assigned to protect the Department of Veterans Affairs SAC-F and SAC-V.
5. GENERAL REQUIREMENTS AND RESPONSIBILITIES
5.1 General - This section contains the requirements that pertain to all guards and guard posts.
5.1.1 All guards will read and be familiar with the duties of the Post. The following is a list of the
Posts for FPS guards supporting Department of Veterans Affairs:
5.1.1.1 Post 1: Control Desk guard; and
5.1.1.2 Post 2: Rover guard.
5.1.2 All orders are subject to revision under emergency conditions.
5.2 Qualifications - This section contains the requirements that pertain to the guards. It is contractors’ responsibility to ensure that their officers are qualified by undergoing background checks.
Contractors must also ensure that the guards possess the required licenses, certification and permits.
Contracted security guards are required to undergo training and pass FPS administered written examinations. The required training, licenses, certification and permits include but are not limited to the following tasks and skills:
Background investigation
Contractor provided basic training
Contractor provided refresher training
Cardiopulmonary Resuscitation (CPR) training and certification
Domestic violence prevention certification
Contractor provided firearms training
Firearms qualification
Annual firearms re qualification
Medical screening
First Aid certification
Drug screening
Written exam
State weapon permit
Expandable baton certification
The contractor must submit a copy of all required training certification before beginning work.
5.3 Professionalism - The guards are the first impression visitors receive at the Department of Veterans
Affairs –SAC-F and SAC-V. Guards are expected to be professional, alert, and courteous at all times.
5.4 Performance and Behavior
5.4.1 Reviewing Standard Operating Procedures (SOP) - Guards are expected to routinely review any and all Department of Veterans Affairs Security Post instructions, procedures and security plans. Guards shall not read newspapers or private reading material while on post.
5.4.2 Guards shall not sleep on duty.
5.4.3 Writing checks, typing or writing personal letters, or conducting other other personal affairs while on duty is prohibited.
5.4.4 Personal Entertainment - Guards will not listen to personal radios, tape players, TV sets, or similar devices while on duty. Items of this nature are not to be possessed or stored on post.
Possession or use of personal Cellular Phones is prohibited while on post.
5.4.5 Diversions and Distractions - Guards shall avoid diversions and distractions that could interfere with duties.
5.4.6 Personal Visitors - Guards shall not receive personal visitors while on duty. Brief, discreet personal interactions may take place if they do not interrupt normal appropriate attention to duty.
5.4.7 Conversations - Guards shall refrain from extended conversations of a personal nature, which distract from systems monitoring and security duties.
5.4.8 Telephone Use - Security telephone lines shall not be used by guards or other personnel for unofficial or personal calls. Personal cellular phones shall not be used or stored on post.
5.4.9 Duties of the Post - All guards assigned to a Post shall be thoroughly familiar with the duties of that specific post.
5.4.10 End of the shift - When the tour of duty has ended the guard shall sign out on the duty log.
The guard shall thoroughly brief their relief (if applicable) regarding information pertinent to the effective performance of duties and the events of the last 24 hours. Written reports and sheets of completed records, documents, and forms shall be neatly kept in a safe place for pick up by the Federal Police Service (FPS) Inspector.
5.5 Appearance
5.5.1 Uniforms - Uniforms shall be kept clean and pressed, shoes/boots shall be shined or polished, and headgear (if any) shall be clean and in good repair.
5.5.2 Facial Hair – Men’s faces must be clean-shaven, except for mustaches and sideburns. Men’s sideburns must be neatly trimmed, extending no lower than the bottom of the ear, constant in width (not flared), and end with a clean-shaven, horizontal line.
5.5.3 Jewelry – Shall be limited to a wrist watch, a single band on the wedding finger, post earrings
(females only), a single chain or bracelet that identifies medical alert information or
POW/MIA/KIA bracelets.
5.5.4 Hair - Female Officers hair should be worn in such a manner that prevents the hair from falling below the collar, or cause interference with the wear of headgear. The height of male officer’s hair is not to exceed 2 inches from the scalp to the coiffure.
5.5.5 Badges – Guards shall wear their identification badges above the waist and in plain view and facing forward at all times.
5.6 Courtesy
5.6.1 Professional Manner - All personnel and visitors shall be greeted courteously and in a polite, professional manner.
5.6.2 Standard of Behavior - Guards shall adhere to commonly accepted standards of behavior and protocol while on duty.
5.6.3 Slang and Terms of Endearment - The use of inappropriate slang or personal terms of endearment is not authorized.
5.6.4 Demeanor - Professional demeanor will be maintained at all times
5.7 Business Hours (Non-Security Hours): 0600-1800 Monday through Friday.
5.7.1 Authorized Department of Veterans Affairs Center SAC-F employees and contractors shall be able to enter the facility upon presenting a valid Department of Veterans Affairs identification card. Those employees and contractors seated within the SAC-F and SAC-V facility are issued access badges for entry to the facility from exterior doors. Employees or contractors who do not possess a valid agency identification card will report to the security desk prior to being admitted into the facility. The guard assigned to this post, must verify employees or contractors who are unable to produce an authorized Identification Card. The employee or contractor’s first line supervisor must come to the front desk with a valid ID to verify that the individual is allowed into the facility. The individual must sign in on a GSA
Form 139 and be issued a temporary visitors pass. ANYONE REFUSING TO SHOW
VALID IDENTIFICATION OR SIGN IN UPON REQUEST WILL BE DENIED
ENTRY INTO THE FACILITY.
5.7.2 All visitors desiring entry into the Department of Veterans Affairs SAC-F and SAC-V space shall be directed to the lobby security desk for proper identification and check in procedures.
All visitors’ information will be entered into the GSA Form 139.
5.7.3 Guard shall make contact with the individual point of contact being visited to verify the visit.
Visitors shall be issued a Visitor’s pass after the Point of Contact (POC) has confirmed the appointment of the visitor. Visitors shall present a valid driver’s license or other form of government identification. Visitors shall also sign the Visitors Register Log.
5.3.1 Visitors must be escorted by the POC prior to leaving the lobby area.
5.7.4 All personnel shall display ID badges in plain view above the waist so they are visible to guards.
5.7.5 Person(s) wishing to enter the building during Security Hours must:
(a) Use a valid picture Government Identification Card/Access card, issued by the
Department of Veterans Affairs to unlock the main handicapped door, or display a
GSA government identification card. Unless on an approved list; all visitors to
Department of Veterans Affairs space must be verified by a VA employee. Only the following representatives are authorized to sign admittance letters for the Building:
I. Director;
II. Deputy Director; or
III. Their designees.
(b) All personnel being processed through the Lobby Access Control Area shall present a valid identification (ID) consisting of one of the following:
(c) Valid federal picture ID.
(d) State issued driver’s license.
5.8 RESERVED
5.9 Reporting Incidents
5.9.1 Guards shall immediately report incidents to the COR, telephone number: 202-568-1200. For additional information and instructions contact the FPS Compliance Section, telephone number: (202) 461-0769.
5.10 Emergency Procedures
5.10.1 Review the Department of Veterans Affairs Emergency Action Plan for instructions involving
FIRES, BOMB THREATS, MEDICAL EMERGENCIES, EMERGENCY EVACUATION
PROCDURES, and UTILITY EMERGENCIES AND THE LOCATION OF UTILITY CUT-
OFFS.
5.11 Key Control
5.11.1 All guards are responsible for the security of the occupied space and lock box keys.
5.11.2 Persons receiving special keys shall present satisfactory identification and complete Record of
Keys Issued (GSA Form 138) prior to receiving the keys.
5.11.3 The receiving guard on a GSA Form shall sign for patrol keys 1051 (Firearms and Guard
Equipment Register), each time they are issued and the number of keys must be indicated.
5.11.4 Emergency keys shall be stored inside two envelopes and kept separate in the key cabinet or appropriate container. The outer envelope shall:
(a) Identify the key.
(b) Be marked “TO BE OPENED IN THE EVENT OF AN EMERGENCY ONLY”.
(c) Show the signature of the person sealing the envelope.
(d) Show date the envelope was sealed.
5.12 Communications
5.12.1 Communication is essential to the efficient performance of routine duties and critical to emergency response situations.
5.12.2 At a minimum, guards are responsible for conducting radio communications checks at the beginning of each shift. The vendor should provide radios for communication for the guards as well as the Director and Deputy Director of SAC-F and SAC-V.
5.12.3 Malfunctions and/or technical difficulties shall be reported to the Security Supervisor and replacements or repairs made available prior to the next shift.
5.13 Telephone
5.13.1 Guards may receive phone calls that need to be transferred to a facility employee. Guards may transfer calls as requested. Guards shall ask callers to identify themselves prior to transferring the call.
5.13.2 Guards shall NOT divulge telephone numbers or other personal information about facility employees.
5.13.3 Guards shall NOT accept collect calls.
5.13.4 Guards shall NOT make long distance calls from the office phone.
5.13.5 Guards shall NOT use the office phone for personal calls.
5.14 Logs and Records
5.14.1 Logs and reports are archives available to document events and actions of the GUARDs and operations, and therefore, are extremely important from a management, legal and operational perspective.
5.14.2 Logs are official government documents and shall be kept in a professional manner, be legible at all times, and recorded accurately.
5.14.3 All log entries shall be made in ink. Mistakes shall be corrected by placing one line through the error and initialing the correction in the adjacent margin.
5.15 Lighting
5.15.1 Lighting is critical to the security of the facility and safety of personnel. Guards shall periodically check the lighting in and around main entrances and walkways, hallways and corridors, and work areas.
5.15.2 Guards shall log and report any non-functioning fixtures as a Work Order Request to the COR.
6. SPECIFIC REQUIREMENTS/ DELIVERABLES
6.1 Deliverable one: Post 1 (Main Lobby)
6.1.1 Objective
6.1.1.1 This is a Fixed Post. This post is located in the main lobby where the guard screens visitors entering the building.
6.1.1.2 This post shall be manned Monday through Friday. The duty hours are 0600-1800. The guard shall NOT leave this post until properly relieved.
6.1.2 Primary Duties
6.1.2.1 The guard shall learn the identities of the Director and the Deputy Director of SAC- F and SAC-V.
6.1.2.2 The guard shall screen all visitors and check for proper identification.
6.1.2.3 The guard assigned to this post verifies visitor’s ID is valid.
6.1.2.4 The guard assigned to this post shall ensure the unimpeded ingress and egress of building employees during specific hours of operation.
6.1.2.5 The guard shall direct all visitors to the front desk for sign in procedures.
6.1.3 Time specific duties
6.1.3.1 First Relief
6.1.3.1.1 0600 – 1800 – Monday through Friday, Excluding Federal Holidays.
6.1.3.1.2 The guard will ensure that all of the required items are at the post. Sign in logs, post orders and any items requiring a pass on of information.
6.1.4 Special Instructions
6.1.4.1 Emergency Evacuation Procedures;
6.1.4.1.1 Whenever the fire alarm sounds during non-security hours the guard should immediately contact the Frederick County Sherriff’s Department at (301) -
600-1046 or Spotsylvania County Sherriff’s Department at (540) – 507-
7200.
6.1.4.1.2 Whenever a guard receives a phone call or personal visit reporting a fire: (a) determine the floor, (b) sound the alarm for the floor, and (c) follow the phone procedures in item “I”.
6.1.4.1.3 In the event that the individuals called cannot be reached, the guard should sound the alarm to evacuate the entire building.
6.1.4.1.4 Use the elevator key to recall all passenger elevators to the lobby and shut them off. However, in order to evacuate the handicapped, the key to the freight elevators should be in the appropriate wall box in the freight elevators authorized occupant emergency personnel.
6.1.4.1.5 Clear the lobby to for evacuation
6.1.4.2 Bomb Threats; whenever a guard receives a report of a bomb treat, or suspicious package, he/she should first call the Frederick County Sherriff’s Department at (301)
600-1046 or Spotsylvania County Sherriff’s Department at (540) 507-7200, then the
Federal Protective Service (202) 708-1111 and then the Department of Veterans
Affairs Security Office on (202) 273-5555.
6.1.4.3 Deliveries or pick up: The guard will notify the Staff Assistants that a package is to be delivered or picked up to report to the lobby. Guards shall follow all post orders in their entirety. Modification or amendments to post orders will not be accepted unless they have been pre approved by the assigned FPS Inspector. Temporary modifications in the event of an emergency situation, to protect life and property will be accepted from the FPS Inspector, COR, or other designated official will be followed solely during that specific emergency.
6.2 Deliverable two: Post 2 (Entire Building)
6.2.1 Objective
6.2.1.1 This is a roving Post. This post covers the entire building.
6.2.1.2This post shall be manned Monday through Friday. NO FEDERAL HOLIDAYS. The duty hours are 0600–1800. The guard shall NOT leave this post until properly relieved.
6.2.2 Primary Duties
6.2.2.1 The guard shall conduct walking patrols of the entire building.
6.2.2.2 The guard shall make his/herself visible during walking patrols.
6.2.2.2 The guard shall conduct walk thru inspections of the stairways.
6.2.2.3 The guard shall conduct a walk thru of the vending area located on the 1 st floor.
6.2.2.5 The guard shall respond to emergencies and request for assistance calls from the operations office.
7 Time specific duties
7.1 0600 – 1800 – Monday through Friday excluding weekends and federal holidays.
7.1.2 The guard shall conduct staggered patrols and door checks. The door checks will consist of the guard physically checking the door to ensure that it is closed and locked.
7.1.3 Any doors found unsecured will be secured. The guard will contact the Security Operation
Office by radio and an entry made in the guards’ patrol log (1103).
7.1.4 The guard shall use the access card provided by the Department of Veterans Affairs Security and Law Enforcement when on patrol. The guard shall present the card at all checkpoints that have a card reader.
7.1.5 The guard shall challenge anyone in the building who does not have a valid VA issued access/ID card on their person.
7.1.6 The guard shall provide stand by assistance as requested by the Director and the Deputy
Director when matters such as employee returns to claim property.
7.1.7 The guard may provide escort assistance to Visitors of the facility. The guards shall contact the COR for discretion in providing escort assistance.
8. Government Furnished Property and Facilities
8.1 VA will provide the Contractor’s on-site staff, property that is incidental to the place of performance per FAR 45.000(a)(5): workspace, furniture, supplies, telephone and automation equipment as is reasonable to fulfill the requirements of this PWS. Special ergonomic furniture such as chairs or stand up desks will not be furnished by the Government and if needed, must be supplied by the Contractor
8.2 Desk space including a computer shall be provided for Contractor use while working at both the
Frederick, MD and Fredericksburg, VA locations.
8.3 The Contractor will be provided access to all available Government furnished information, facilities, material, equipment, or services as required to accomplish the efforts in the contract.
This shall include office space, desk, telephone, chair, computer, shared printer, laptop (if applicable). The Contractor shall be responsible for securing all GFP that is assigned to them.
Therefore, should any property be lost or destroyed due to Contractor’s negligence, the
Contractor is responsible for replacing the property. The Contractor may be provided keys or codes for access to the Government facility. These keys and codes shall be controlled, tracked, and protected. Upon completion of the period of performance, all keys and/or access badges to the Government facility shall be turned in to the Contracting Officer’s Representative (COR). VA will provide the following GFP to contracted personnel as needed: 1) Computing system, 2)
Telephone, and 3) Mobile Device.
8.4 All persons requiring access to VA information systems shall sign a System Rules of Behavior
Notice for those systems before being given access, and annually thereafter. Each employee requiring access to a VA system shall be required to submit the information necessary to prepare
VA form 9957.
8.5 All computer systems residing on VA premises or under VA control will be administered by VA
System Administration staff. Contractor personnel will be granted only the least access required to accomplish activities associated with this TO.
8.6 All employees of the Contractor must sign a non-disclosure agreement regarding release of data and information pertaining to the contract and publication of data and information of material related to the project.
9. Physical Security & Safety Requirements
9.1 The Contractor and its personnel shall follow all VA policies, standard operating procedures, applicable laws and regulations while on VA property. Violations of VA regulations and policies may result in citation and disciplinary measures for persons violating the law.
9.2 The Contractor and their personnel shall wear visible identification at all times while they are on the premises.
9.3 It is the responsibility of the Contractor to park in the appropriate designated parking areas. VA will not invalidate or make reimbursement for parking violations of the Contractor under any conditions.
9.4 Smoking is prohibited inside/outside any building other than the designated smoking areas.
9.5 The Contractor shall obtain all necessary licenses and/or permits required to perform the work, with the exception of software licenses that need to be procured from a Contractor or vendor in accordance with the requirements document.
9.6. The Contractor shall take all reasonable precautions necessary to protect persons and property from injury or damage during the performance of this contract.
10. Position/ Task Risk Designation Level(s) and Contractor Personnel Security Requirements
10.1 Background Investigation
10.1.1 The level of background security investigation will be in accordance with VA Directive
0710 dated June 4, 2010 and is available at:
http://www.va.gov/vapubs/viewPublication.asp?Pub_ID=487&FType=2.
10.1.2 The contract employee level of background investigation required for this effort is: NACI
10.2 Contractor Personnel Security
10.2.1 All contract employees who require access to the VA site(s) and/or access to VA local area network (LAN) systems shall be the subject of a background investigation and must receive a favorable adjudication from the VA Security and Investigations Center (SIC).
These requirements are applicable to all sub-contractor personnel requiring the same
NACI Background Investigation.
10.2.2 Position Sensitivity
10.2.2.1 Position Sensitivity Background Investigation (in accordance with Department of
Veterans Affairs 0710 Handbook, “Personnel Suitability and Security Program,”
Appendix A)
10.2.2.2 Tier 1 / National Agency Check with Written Inquiries (NACI) A Tier 1/NACI is conducted by OPM and covers a 5-year period. It consists of a review of http://www.va.gov/vapubs/viewPublication.asp?Pub_ID=487&FType=2 records contained in the OPM Security Investigations Index (SII) and the DOD
Defense Central Investigations Index (DCII), FBI name check, FBI fingerprint check, and written inquiries to previous employers and references listed on the application for employment. In VA it is
11. VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY
LANGUAGE
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or call order.
b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with the latest version of the VA
Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for
Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with
Defense Security Service (DSS). Verification of a Security Clearance must be processed through the
Special Security Officer located in the Planning and National Security Service within the Office of
Operations, Security, and Preparedness.
d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-
U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth.
Location within the U.S. may be an evaluation factor.
e. The contractor or subcontractor must notify the Contracting Officer immediately via email when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
2. INFORMATION SYSTEM DESIGN AND DEVELOPMENT
a. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related
VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference the latest version of Appendix D of VA Handbook 6500, VA Information
Security Program). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COR, and approved by the VA Privacy Service in accordance with
Directive 6507, VA Privacy Impact Assessment.
b. The contractor/subcontractor shall certify to the COR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration (FDCC), and the common security configuration guidelines provided by NIST or the VA. This includes
Internet Explorer 7 configured to operate on Windows XP and Vista (in Protected Mode on Vista) and future versions, as required.
c. The standard installation, operation, maintenance, updating, and patching of software shall not alter the configuration settings from the VA approved and FDCC configuration. Information technology staff must also use the Windows Installer Service for installation to the default “program files” directory and silently install and uninstall.
d. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
e. The security controls must be designed, developed, approved by VA, and implemented in accordance with the provisions of VA security system development life cycle as outlined in NIST
Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal
Information Systems, the latest version of VA Handbook 6500, Information Security Program and the latest version of VA Handbook 6500.5, Incorporating Security and Privacy in System Development
Lifecycle.
f. The contractor/subcontractor is required to design, develop, or operate a System of Records Notice
(SOR) on individuals to accomplish an agency function subject to the Privacy Act of 1974, (as amended), Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Privacy Act may involve the imposition of criminal and civil penalties.
g. The contractor/subcontractor agrees to:
(1) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:
(a) The Systems of Records (SOR); and
(b) The design, development, or operation work that the contractor/subcontractor is to perform;
(2) Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a SOR on individuals that is subject to the Privacy Act; and (3) Include this Privacy Act clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a SOR.
h. In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a SOR on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a
SOR on individuals to accomplish an agency function, the contractor/subcontractor is considered to be an employee of the agency.
(1) “Operation of a System of Records” means performance of any of the activities associated with maintaining the SOR, including the collection, use, maintenance, and dissemination of records.
(2) “Record” means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and contains the person’s name, or identifying number, symbol, or any other identifying particular assigned to the individual, such as a fingerprint or voiceprint, or a photograph.
(3) “System of Records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
i. The vendor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as “Systems”), throughout the life of this contract and any extension, warranty, or maintenance periods. This includes, but is not limited to workarounds, patches, hotfixes, upgrades, and any physical components (hereafter referred to as
Security Fixes) which may be necessary to fix all security vulnerabilities published or known to the vendor anywhere in the Systems, including Operating Systems and firmware. The vendor shall ensure that Security Fixes shall not negatively impact the Systems.
j. The vendor shall notify the COR and any other people the COR requests via email within 1 hour of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system). Such issues shall be remediated as quickly as is practical, but in no event longer than 1day, unless otherwise stated by the COR.
k. When the Security Fixes involve installing third party patches (such as Microsoft OS patches or
Adobe Acrobat), the vendor will provide written notice to the VA that the patch has been validated as not affecting the Systems within 5 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within 1 day after the Security Fix has been validated as not affecting the System.
l. All other vulnerabilities shall be remediated as specified in this paragraph in a timely manner based on risk, but within 60 days of discovery or disclosure. Exceptions to this paragraph (e.g. for the convenience of VA) shall only be granted with approval of the contracting officer and the VA
Assistant Secretary for Office of Information and Technology.
3. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE
a. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-\VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to operational approval. All external
Internet connections to VA’s network involving VA information must be reviewed and approved by
VA prior to implementation. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of
Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.
b. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor’s systems in accordance with the latest version of VA Handbook 6500.3, Certification and Accreditation and/or the VA OCS Certification Program
Office.
Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.
c. The contractor/subcontractor’s system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA’s POA&M management process. The contractor/subcontractor must use VA’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of
Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per the latest version of VA Handbook 6500.3. This may require reviewing and updating all of the documentation (PIA, System Security Plan, Contingency Plan). The
Certification Program Office can provide guidance on whether a new C&A would be necessary.
d. The contractor/subcontractor must conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment must be provided to the COR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor must take appropriate and timely action to correct or mitigate any weaknesses discovered during such testing, at no additional cost.
e. VA prohibits the installation and use of personally-owned or contractor/subcontractor-owned equipment or software on VA’s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA-approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.
f. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information must be handled in adherence with the latest version of VA
Handbook 6500.1, Electronic Media Sanitization upon: (i) completion or termination of the contract or (ii) disposal or return of the IT equipment by the contractor/subcontractor or any person acting on behalf of the contractor/subcontractor, whichever is earlier. Media (hard drives, optical disks, CDs, back-up tapes, etc.) used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per 6500.1 requirements. This must be completed within 30 days of termination of the contract.
4. SECURITY INCIDENT INVESTIGATION
a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify via email the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.
b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.
c. With…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.