36C24626B0024_2.docx

DOCX document 148 KB Posted

Attached to
Y1BG--652-23-105 Campus Wide Camera (Construction) Federal contract opportunity
Solicitation number
36C24626B0024
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 6

About this file

This is an Invitation for Bid (IFB) for a Campus Wide Camera System Replacement construction project at Richmond VA Medical Center in Richmond, Virginia. The solicitation number is 36C24626B0024, issued on May 5, 2026, with an estimated construction magnitude between $2,000,000 and $5,000,000. This is a 100% Total Service-Disabled Veteran-Owned Small Business (SDVOSB) set-aside with NAICS code 236220 and a small business size standard of $45.0 million. Sealed bids are due by 2:00 PM EDT on June 4, 2026, with public bid opening scheduled for June 5, 2026, at 1:00 PM EDT via Microsoft Teams. A mandatory pre-bid site visit will be conducted on May 14, 2026, at 10:00 AM EDT. Questions must be submitted by May 20, 2026, at 3:00 PM EDT. Award will be made to the lowest responsible bidder based on price alone, with contract performance required within 365 days from Notice to Proceed.

The scope of work includes complete demolition and removal of existing cameras and installation of a modernized security camera system with analytics across 13 buildings at the medical center, requiring coordination with VA IT for compliance with VA cybersecurity directives and integration with VA Police body-worn camera solutions. Work includes multiple construction divisions covering electrical, communications, earthwork, site improvements, and finishing trades. Bidders must submit detailed cost breakdowns covering labor, materials, equipment, transportation, supervision, and disposal. Three bid options are offered: Base Bid for full system installation (365 days), Bid Deduct Alternate 1 removing 30% of exterior fixtures (300 days), and Bid Deduct Alternate 2 removing an additional 30% of interior fixtures (255 days). Contractors must be registered in the System for Award Management (SAM) and verified in the SBA's VetCert database. A bid guarantee of 20% of bid price or $3,000,000 (whichever is less) is required, along with performance and payment bonds. The solicitation incorporates extensive federal acquisition regulations, VA-specific clauses, and security requirements including personnel vetting, information security compliance, liquidated damages for data breaches ($1,000 per affected individual), and comprehensive cybersecurity standards aligned with FISMA, NIST, and executive orders on federal cybersecurity.

View the file

Other files for this federal contract opportunity

Other files attached to Y1BG--652-23-105 Campus Wide Camera (Construction), newest first.
File Type Posted
MARKET SURVEY CONSTRUCTION MATERIALS TEMPLATE.xlsx XLSX spreadsheet
S02 - 36C24626B0024-Campus_02.pdf PDF
SITE VISIT ATTENDANCE LOG OF_05-14-2026-CAMPUS CAMERA_Redacted.pdf PDF
ATTACHMENT D - WAGE DETERMINATION_revised.pdf PDF
Response to Solicitation RFIs Tracker-Campus Wide-0002.xlsx XLSX spreadsheet
36C24626B0024 0002.docx DOCX document
36C24626B0024 0001.docx DOCX document
ATTACHMENT D - WAGE DETERMINATION.pdf PDF
ATTACHMENT C - BID ITEMS COST BREAKDOWN.xlsx XLSX spreadsheet
ATTACHMENT B - DRAWINGS.pdf PDF
ATTACHMENT A - SPECIFICATIONS.docx DOCX document
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C24626B0024

1. SOLICITATION NUMBER

2. TYPE OF SOLICITATION

3. DATE ISSUED

PAGE OF PAGES

4. CONTRACT NUMBER

5. REQUISITION/PURCHASE REQUEST NUMBER

6. PROJECT NUMBER

7. ISSUED BY

CODE

8. ADDRESS OFFER TO

a. NAME

b. TELEPHONE NUMBER (Include area code) (NO COLLECT CALLS)

10. THE GOVERNMENT REQUIRES PERFORMANCE OF THE WORK DESCRIBED IN THESE DOCUMENTS (Title, identifying number, date) 12a. THE CONTRACTOR MUST FURNISH ANY REQUIRED PERFORMANCE AND PAYMENT BONDS?

(If "YES," indicate within how many calendar days after award in Item 12B.)

12b. CALENDAR DAYS

13. ADDITIONAL SOLICITATION REQUIREMENTS:

STANDARD FORM 1442 (REV. 8/2014)

STANDARD FORM 1442

Prescribed by GSA-FAR (48 CFR) 52.236-1(d)

SOLICITATION, OFFER,

AND AWARD

(Construction, Alteration, or Repair)

SOLICITATION

SOLICITATION

IMPORTANT - The "offer" section on the reverse must be fully completed by offeror.

9. FOR INFORMATION

CALL:

NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".

SEALED BID (IFB)

NEGOTIATED (RFP)

11. The Contractor shall begin performance within ____________ calendar days and complete it within calendar days after receiving award, notice to proceed. This performance period is mandatory negotiable. (See _____________________________).

YES

NO

a.

Sealed offers in original and ___________________copies to perform the work required are due at the place specified in Item 8 by _____________ (hour) local time _____________________ (date). If this is a sealed bid solicitation, offers must be publicly opened at that time. Sealed envelopes containing offers shall be marked to show the offeror's name and address, the solicitation number, the date and time offers are due.

b.

An offer guarantee is, is not required.

c.

All offers are subject to the (1) work requirements, and (2) other provisions and clauses incorporated in the solicitation in full text or by reference.

d.

Offers providing less than _______________________ calendar days for Government acceptance after the date offers are due will not be considered and will be rejected.

36C24626B0024 X 05-05-2026 652-23-105 36C246 Email: vangie.miller@va.gov Department of Veterans Affairs Network Contracting Office 6 201 Hay Street, Suite 305 Fayetteville

NC

28301 Contract Specialist, Moses Deng Email: moses.deng2@va.gov Contract Officer, Vangie Miller

Moses Deng 910-475-6807 Invitation for Bid for Project: Campus Wide Camera System (Construction)Project# 652-23-105.

Location: Richmond V.A. Medical Center 1201 Broad Rock Blvd. Richmond, Virginia 23249 See Statement of Work (SOW), Specifications and Drawings attached for details of this requirement.

Pursuant to VAAR 836-204 (f) (2), the estimated magnitude of construction is between $2,000,000 and $5,000,000.

This is a 100% Total Service-Disabled Veteran Owned Small Business (SDVOSB) Set-Aside The North American Industry Classification System (NAICS) code for this action is 236220 with a size standard of $45.0M

Contractors must be registered in the System for Award Management (SAM) at https://www.sam.gov and verified in the Small Business Administration’s (VetCert) database at https://veterans.certify.sba.gov/ to be eligible for award.

A Pre-Bid Site Visit will be conducted on May 14, 2026 at 10:00 AM EDT.

Location: Meet outside of the Engineering Suite, 2K-137, on the catwalk of the Richmond VA Medical Center Campus.

Request for Information (Questions) are due no later than: May 20, 2026 by 3:00 PM EDT.

The Government affords no guarantee that questions (RFI's) submitted after the aforementioned date and time will be answered.

Bids are due the day prior to the date and time indicated on Block 13 below.

Bid Opening Location: Microsoft Teams (online): https://teams.microsoft.com/meet/288727272735232?p=arvNtEsqv873fRRlaR Bids will NOT be accepted in paper form. See General Instructions beginning on page 6 for details.

All bids shall be submitted by the prime contractor. Bids must be submitted by electronics means through email to the Contract Specialist, Moses Deng at moses.deng2@va.gov and Cc Contract Officer, Vangie Miller at vangie.miller@va.gov.

X X X see page 26

1:00 PM

EDT

06-05-2026 X

14. NAME AND ADDRESS OF OFFEROR

15. TELEPHONE NUMBER

16. REMITTANCE ADDRESS

CODE

FACILITY CODE

17. The offeror agrees to perform the work required at the prices specified below in strict accordance with the terms of the solicitation, if this offer is accepted by the Government in writing within __________ calendar days after the date offers are due.

AMOUNTS

18. The offeror agrees to furnish any required performance and payment bonds.

19. ACKNOWLEDGMENT OF AMENDMENTS

AMENDMENT

NUMBER

DATE.

20a. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN OFFER 20b. SIGNATURE 20c. OFFER DATE

21. ITEMS ACCEPTED:

22. AMOUNT

23. ACCOUNTING AND APPROPRIATION DATA

24. SUBMIT INVOICES TO ADDRESS SHOWN IN

ITEM

25. OTHER THAN FULL AND OPEN COMPETITION PURSUANT TO

10 U.S.C. 2304(c)( 41 U.S.C. 3304(a) (

26. ADMINISTERED BY

27. PAYMENT WILL BE MADE BY

PHONE:

FAX:

28. NEGOTIATED AGREEMENT

29. AWARD

Your Contractor agrees offer on this solicitation is hereby accepted as to the items listed. This to furnish and deliver all items or perform all work requirements identified award consummates the contract, which consists of (a) the Government on this form and any continuation sheets for the consideration stated in solicitation and your offer, and (b) this contract award. No further cont-this contract. The rights and obligations of the parties to this contract ractual document is necessary.

shall be governed by (a) this contract award, (b) the solicitation, and (c) the clauses, representations, certifications, and specifications incorporated by reference in or attached to this contract.

30a. NAME AND TITLE OF CONTRACTOR OR PERSON AUTHORIZED 31a. NAME OF CONTRACTING OFFICER

TO SIGN

30b. SIGNATURE 30c. DATE 31b. UNITED STATES OF AMERICA 31c. AWARD DATE

BY

OFFER

AWARD

STANDARD FORM 1442 (REV. 8/2014) BACK

(Include ZIP Code) (Include area code) (Include only if different than Item 14.)

(Insert any number equal to or greater than the minimum requirement stated in Item 13d. Failure to insert any number means the offeror accepts the minimum in Item 13d.)

(The offeror acknowledges receipt of amendments to the solicitation -- give number and date of each) (Type or print) (4 copies unless otherwise specified) (Type or print) (Type or print) (Contractor is required to sign this document and return _______ copies to issuing office.)

(Contractor is not required to sign this document.)

(Must be fully completed by offeror) (To be completed by Government)

CONTRACTING OFFICER WILL COMPLETE ITEM 28 OR 29 AS APPLICABLE

BID ITEM (BASE BID): $

BID ITEM I (DEDUCT NO. 1): $

BID ITEM II (DEDUCT NO. 2): $

Department of Veterans Affairs Network Contracting Office 6 201 Hay Street, Suite 305 Fayetteville

NC

28301 http://www.fsc.va.gov/einvoice.asp Department of Veterans Affairs Financial Services Center P.O. Box 149971 Austin

TX

78714-9971 512-460-5049 512-460-5221

Table of Contents

PART I - THE SCHEDULE1
SECTION A - SOLICITATION/CONTRACT FORM1
A.1 SF 1442 SOLICITATION, OFFER, AND AWARD (Construction, Alteration, or Repair)1
A.2 SF 1442 SOLICITATION, OFFER, AND AWARD (CONSTRUCTION, ALTERATION, OR REPAIR)– BACK2
A.3 PRICE/COST SCHEDULE5
ITEM INFORMATION5
A.4 DELIVERY SCHEDULE6
INFORMATION REGARDING BIDDING MATERIAL, BID GUARANTEE AND BONDS27
INSTRUCTIONS, CONDITIONS AND OTHER STATEMENTS TO BIDDERS/OFFERORS28
2.1 52.216-1 TYPE OF CONTRACT (NOV 2025) (DEVIATION)31
2.2 52.222-5 CONSTRUCTION WAGE RATE REQUIREMENTS—SECONDARY SITE OF THE WORK (NOV 2025) (DEVIATION)31
2.3 52.225-10 NOTICE OF BUY AMERICAN REQUIREMENT—CONSTRUCTION MATERIALS (MAY 2014)32
2.4 52.228-1 BID GUARANTEE (SEP 1996)33
2.5 52.233-2 SERVICE OF PROTEST (SEP 2006)33
2.6 52.240-90 SECURITY PROHIBITIONS AND EXCLUSIONS REPRESENTATIONS AND CERTIFICATIONS (NOV 2025) (DEVIATION)34
2.7 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)38
REPRESENTATIONS AND CERTIFICATIONS40
3.1 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018)40
3.2 52.209-13 VIOLATION OF ARMS CONTROL TREATIES OR AGREEMENTS—CERTIFICATION (NOV 2021)41
GENERAL CONDITIONS44
4.1 52.211-12 LIQUIDATED DAMAGES—CONSTRUCTION (SEPT 2000)44
4.2 52.219-28 POSTAWARD SMALL BUSINESS PROGRAM REREPRESENTATION (NOV 2025) (DEVIATION)44
4.3 52.222-40 NOTIFICATION OF EMPLOYEE RIGHTS UNDER THE NATIONAL LABOR RELATIONS ACT (NOV 2025) (DEVIATION)46
4.4 52.222-42 STATEMENT OF EQUIVALENT RATES FOR FEDERAL HIRES (MAY 2014)48
4.5 52.225-2 BUY AMERICAN CERTIFICATE (OCT 2022)48
4.6 52.228-14 IRREVOCABLE LETTER OF CREDIT (NOV 2014)49
4.7 52.225-9 BUY AMERICAN—CONSTRUCTION MATERIALS (DEVIATION) (NOV 2025)53
4.8 SUPPLEMENTAL INSURANCE REQUIREMENTS58
4.9 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025) (DEVIATION)58
4.10 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)67
4.11 52.214-26 AUDIT AND RECORDS—SEALED BIDDING (JUN 2020)68
4.12 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020)71
4.13 VAAR 852.219-73 VA NOTICE OF TOTAL SET-ASIDE FOR CERTIFIED SERVICE-DISABLED VETERAN-OWNED SMALL BUSINESSES (JAN 2023) (DEVIATION)72
4.14 VAAR 852.219-75 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING—CERTIFICATE OF COMPLIANCE FOR SERVICES AND CONSTRUCTION (JAN 2023) (DEVIATION)75
4.15 VAAR 852.236-71 SPECIFICATIONS AND DRAWINGS FOR CONSTRUCTION (APR 2019)77
4.16 VAAR 852.242-70 GOVERNMENT CONSTRUCTION CONTRACT ADMINISTRATION (OCT 2020)78
4.17 VAAR 852.204-72, PERSONNEL VETTING AND CREDENTIALING (MAR 2026) (DEVIATION)79
4.18 IT CONTRACT SECURITY82

A.3 PRICE/COST SCHEDULE

ITEM INFORMATION

ITEM NUMBER
DESCRIPTION OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
1.00
JB
__________________
__________________

Base Bid - All work in accordance with this scope of work, design drawings and specifications.

Contract Period: Base (Period of Performance is 365 days from Notice to Proceed (NTP)

Contract Period: Base POP Begin:

POP End:

1.00
JB
__________________
__________________

Bid Deduct Alternate 1 – All work in Base Bid but remove 30% of the exterior fixtures. (300 calendar days to complete all work) – Reducing “Fish Eye” fixtures from a quantity of 252 to 170 & “Multisensor” fixtures from a quantity of 173 to 121.

(Period of Performance is 300 days from Notice to Proceed (NTP)

Contract Period: Option 1

1.00
JB
__________________
__________________

Bid Deduct Alternate 2 – All work in Bid Deduct Alternate 1 but remove an additional 30% of the interior fixtures. (255 calendar days to complete all work) – Reducing “Dome Cameras” from 215 to 150.

(Period of Performance is 255 days from Notice to Proceed (NTP)

Contract Period: Option 2

GRAND TOTAL
__________________

A.4 DELIVERY SCHEDULE

ITEM NUMBER
SHIPPING INFORMATION
QUANTITY
DELIVERY DATE
0001
SHIP TO:
Department of Veterans Affairs

Richmond VA Medical Center 1201 Broad Rock Boulevard Richmond, VA 23249 4915

USA

1.00
365 Days from NTP
0002
SHIP TO:
Department of Veterans Affairs

Richmond VA Medical Center 1201 Broad Rock Boulevard Richmond, VA 23249 4915

USA

1.00
300 Days from NTP
0003
SHIP TO:
Department of Veterans Affairs

Richmond VA Medical Center 1201 Broad Rock Boulevard Richmond, VA 23249 4915

USA

1.00
255 Days from NTP

SCOPE OF WORK

Central Virginia VA Health Care System Richmond V.A. Medical Center 1201 Broad Rock Blvd.

Richmond, Virginia 23249

SCOPE OF WORK

Project: 652-23-105 Project Title: Campus Wide Camera System Replacement

1. Background The Department of Veterans Affairs (VA) Office of the Senior Security Office/Physical Security and Infrastructure Office, along with the Richmond VA Medical Center (VAMC) VA Police Department requires a modernized security camera system with analytics in order to comply with the VA 0730 Handbook, Security and Law Enforcement, and the Office of Information and Technology (OIT) VA Directive 6517, 6518, 6500 (6500.6 and 6500.11), 6008 along with the OIT Strategic Plan and Veterans Affairs Enterprise Architecture Principles, in addition to:

· Presidential Executive Order 14111, dated November 27, 2023, aims to enhance the quality and effectiveness of security measures and protections in Federal facilities while modernizing these programs and technologies to meet current industry standards.

In addition to security measures, the VA has been charged by the U.S. Office of Management and Budget and the White House with the following:

· Presidential Executive Order 14028, titled “Improving the Nation’s Cybersecurity,” was issued on May 12, 2021. This order focuses on advancing agencies toward a Zero Trust architecture and accelerating the transition to secure cloud services.

· Presidential Executive Order 12997/13286 established the Interagency Security Committee, which aims to enhance the security and protection of federal facilities across the United States.

· Presidential Executive Order 13800, titled "Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure," was issued on May 11, 2017. The order aims to enhance the nation's cybersecurity posture and capabilities by focusing on the modernization of federal IT infrastructure and the protection of critical infrastructure.

· Guidance issued on February 26, 2025, aims to implement technological solutions that automate routine tasks, allowing staff to concentrate on higher-value activities. This guide also outlines plans to reduce costs and promote efficiency by adopting new software systems and eliminating duplicate systems.

Due to these orders, the Richmond VAMC requires a modernized security system that will enhance security, provide an easy-to-use system, minimize on-premises infrastructure, minimal network (Local Area Network (LAN)/Wide Area Network (WAN)) traffic, and increase the VA’s cybersecurity posture while meeting National Defense Authorization and Trade Agreements Act manufacturing rules according to current FAR clauses while complying with Federal Information Security Management Act (FISMA). The VA Police require that the new system to be able to integrate with the current VA Police’s Body Worn Camera Solution (Axon) and other VA Police Enterprise VA Police Solutions as a Service product with Camera’s and software itself. The solution will need to be outfitted for the Richmond VAMC located at 1201 Broad Rock Blvd, Richmond VA 23249.

APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Statement of Work, the Contractor shall comply with the following:

1. “Federal Information Security Modernization Act of 2014”

2. Federal Information Processing Standards (FIPS) Publication 140-3, “Security Requirements for Cryptographic Modules”, March 22, 2019

3. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004

4. FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006

5. FIPS Pub 201-3, “Personal Identity Verification of Federal Employees and Contractors,” January 2022

6. 10 U.S.C. § 2224, "Defense Information Assurance Program", as amended

7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

8. Public Law 109-461 (P.L. 109-461), Veterans Benefits, Health Care, and Information Technology Act of 2006, as amended, Title IX, Information Security Matters

9. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”, as amended

10. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm

11. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm

12. VA Directive 6102, “Internet/Intranet Services,” August 5, 2019

13. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” as amended

14. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

15. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”, as amended

16. NIST SP 800-66 Rev. 2, “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” February 2024

17. 45 C.F.R Parts 160 and 164, Subparts A and E, the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”); and 45 C.F.R. Parts 160 and 164, Subparts A and C, the Security Standard (“Security Rule”); as amended

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021 (see VA NOTICE 24-18, dated September 27, 2024, “Update to VA Directive 6500 Cybersecurity Program”, and VA Notice 25-07, dated 3/18/25, “Amending VA Directive 6500 to incorporate M-24-15”)

21. VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021 (see VA Notice 25-01, dated October 15, 2024, “Update to VA Handbook 6500 Risk Management Framework for VA Information Systems VA Information Security Program”, and VA Notice 25-06, dated 3/18/25, “Amending VA Directive 6500 to incorporate M-24-15”)

22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” June 30, 2023

23. VA Handbook 6500.6, “Contract Security,” March 12, 2010 (see VA Notice 24-12, dated April 22, 2024, “Update to VA Handbook 6500.6, Contract Security, Appendix C VA Information and Information System Security/Privacy Language For Inclusion Into Contracts, As Appropriate”)

24. VA Handbook 6500.8, “Information System Contingency Planning,” March 25, 2025

25. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018

26. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

27. OIT Process Asset Library (PAL), OIT Process Asset Library.

28. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

29. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

30. VA Directive 6510, “VA Identity, Credential and Access Management,” September 3, 2024

31. VA Handbook 6510, “VA Identity, Credential and Access Management,” September 27, 2024

32. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017

33. VA Directive 6300, “Records and Information Management,” September 21, 2018

34. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010

35. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

36. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

37. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015

38. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014

39. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

40. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

41. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

42. Federal Identity, Credential, and Access Management (FICAM) Architecture, June 30, 2023 (FICAM Architecture (idmanagement.gov))

43. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018

44. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020

45. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

46. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

47. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

48. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

49. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

50. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

51. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

52. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (P.L. 110–140), December 19, 2007

53. Section 104 of the Energy Policy Act of 2005, (P.L. 109–58), August 8, 2005

54. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

55. VA Directive 0057, “VA Environmental Management Program,” October 25, 2022

56. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

57. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

58. “Veteran Focused Integration Process (VIP) Guide 4.0,” March 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

59. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

60. “Product Line Management Transformation Playbook” version 3.1, August 2023, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

61. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

62. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),” November 19, 2020

63. Social Security Number (SSN) Fraud Prevention Act of 2017

64. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018

65. C.F.R Title 15 Part 7, “Securing the Information and Communications Technology and Services (ICTS) Supply Chain”, as amended

66. Executive Order 14028, “Executive Order on Improving the Nation's Cybersecurity,” May 12, 2021, https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/

67. OMB Memorandum M-22-09, “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles”, January 26, 2022, https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf.

68. NIST SP 800-52 Revision 2, “Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations

69. OMB M-22-18, “Enhancing the Security of the Software Supply Chain through Secure Software Development Practices,” September 14, 2022

70. OMB M-23-16, “Update to Memorandum M-22-18,” June 9, 2023

71. OMB M-21-31, “Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents,” August 27, 2021

72. NIST SP 800-88 Revision 1 “Guidelines for Media Sanitization,” December 2014

73. CISA Binding Operational Directive (BOD) 19-02: “Vulnerability Remediation Requirements of Internet-Accessible Systems,” April 29, 2019, BOD 19-02: Vulnerability Remediation Requirements for Internet-Accessible Systems | CISA

74. CISA BOD 22-01: “Reducing the Significant Risk of Known Exploited Vulnerabilities,” November 3, 2021, BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities | CISA

75. CISA BOD 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks.” Cybersecurity & Infrastructure Security Agency (CISA), BOD 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks | CISA

76. VA Directive 6550, Pre-Procurement Assessment and Implementation of Medical Devices/Systems, June 03, 2019

77. VA Memorandum, “VA Security Controls,” January 17, 2025, https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010

WORK STATEMENT

The Contractor shall completely prepare the site for building operations, including demolition and removal of existing cameras, and furnish labor and materials and perform work for Campus Wide Security Camera Replacement as required by drawings and specifications.

Work required is for the installation and performance of cameras and cabling, however additional construction trades are required to facilitate the installation of the cameras. These trades are largely limited to performing cutting and patching required to remove and replace cameras and install new cameras, cabling, and new conduit work, and provide a complete passive camera system as delineated in the project construction documents.

The following construction Divisions/Trades will be required:

Division 2 – Existing Conditions (Trades: General Laborers, Carpenters) Division 7 – Thermal and Moisture Protection (Trades: Carpenters) Division 9 – Finishes (Trades: Carpenters, Painters, Drywall Installers) Division 27 – Communications (Trades: Electricians) Division 28 – Electronic Safety and Security (Trades: Electricians, Communication Technicians) Division 31 – Earthwork (Trades: Surveyors, Heavy Equipment Operators, Concrete Masons) Division 32 – Site Improvements (Trades: Landscapers) Work performed occurs both indoors and outdoors. Buildings included in the scope of work are as follows: Buildings 500, 501, 507, 509, 511, 512, 513, 514, 515, 518, 519, 520, and 521 and additional site work indicated on contract drawings. To perform the camera replacement work inside the buildings requires information technology systems work and camera testing, selective demolition, general carpentry, painting, electrical work, firestopping and fireproofing. Work for an abatement contractor is required. (See Bid Drawings) Work being performed outside the buildings to install cameras and cabling requires site survey engineers to conduct underground site investigations. The contractor and site subcontractors will also be required to install new underground cabling, create handholes, and perform earthwork removal, including the removal of concrete sidewalks, asphalt paving, as well as repair of the same and reseeding and new markings.

Additionally, camerawork outside buildings is required to patch and repair existing buildings in such a way as to leave no trace of construction or repair. This includes roof repair, which requires warranted roof work, repair of existing metal panels, brick repair, caulking, concrete foundation coring, and waterproofing.

2. Contract Specification/Drawings The following contract drawings are included in their entirety by reference in this Scope of Work:

SHEET #
TITLE
GI001
COVER SHEET
GI002
DEMOLITION INFORMATION AND SHEET INDEX
GI003
GENERAL - ICRA GUIDLINES
GI004
FIRE/SMOKE BARRIER LEGEND
GI-1-500-00A
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-500-00B
INFECTION CONTROL PLAN LEVEL 01 - OVERALL- BG-107
GI-1-500-01A
INFECTION CONTROL PLAN LEVEL 01 - OVERALL
GI-1-500-01B
INFECTION CONTROL PLAN LEVEL 01 - OVERALL CONT.
GI-1-500-02A
INFECTION CONTROL PLAN LEVEL 02 - OVERALL
GI-1-500-02B
INFECTION CONTROL PLAN LEVEL 02 - OVERALL CONT.
GI-1-500-03A
INFECTION CONTROL PLAN LEVEL 03 - PART A
GI-1-500-03D
INFECTION CONTROL PLAN LEVEL 03 - PART D
GI-1-500-04
INFECTION CONTROL PLAN LEVEL 04
GI-1-500-05
INFECTION CONTROL PLAN LEVEL 05
GI-1-501-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-507-00
GENERAL - INFECTION CONTROL PLAN
GI-1-509-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-509-01
INFECTION CONTROL PLAN LEVEL 01 - OVERALL
GI-1-511-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-512-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-512-01
INFECTION CONTROL PLAN LEVEL 01 - OVERALL
GI-1-513-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-514-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-515-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-515-01
INFECTION CONTROL PLAN LEVEL 01 - OVERALL
AE-1-518-00
OVERALL FLOOR PLAN - LICENSE PLATE CAMERA MOUNTDETAILS
GI-1-518-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-519-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-519-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-520-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-521-00
INFECTION CONTROL PLAN LEVEL 00 - OVERALL
GI-1-521-01
INFECTION CONTROL PLAN LEVEL 01 - OVERALL
CD-1-S01
CAMPUS SITE PLAN - DEMOLITION
CU-1-S01
CAMPUS SITE PLAN - NEW WORK
TD-1-500-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00 - OVERALL
TD-1-500-00A
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00 - PART A
TD-1-500-00B
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00 - PART B
TD-1-500-00C
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00 - PART C
TD-1-500-00D
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00 - PART D
TD-1-500-00E
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00 - PART E
TD-1-500-01
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01 - OVERALL
TD-1-500-01A
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01 - PART A
TD-1-500-01B
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01 - PART B
TD-1-500-01C
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01 - PART C
TD-1-500-01D
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01 - PART D
TD-1-500-01E
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01 - PART E
TD-1-500-02
SECURITY FLOOR PLAN - DEMOLITION LEVEL 02 - OVERALL
TD-1-500-02A
SECURITY FLOOR PLAN - DEMOLITION LEVEL 02 - PART A
TD-1-500-02B
SECURITY FLOOR PLAN - DEMOLITION LEVEL 02 - PART B
TD-1-500-02C
SECURITY FLOOR PLAN - DEMOLITION LEVEL 02 - PART C
TD-1-500-02D
SECURITY FLOOR PLAN - DEMOLITION LEVEL 02 - PART D
TD-1-500-03A
SECURITY FLOOR PLAN - DEMOLITION LEVEL 03 - PART A
TD-1-500-03D
SECURITY FLOOR PLAN - DEMOLITION LEVEL 03 - PART D
TD-1-500-04A
SECURITY FLOOR PLAN - DEMOLITION LEVEL 04 - PART A
TD-1-500-04D
SECURITY FLOOR PLAN - DEMOLITION LEVEL 04 - PART D
TD-1-500-05A
SECURITY FLOOR PLAN - DEMOLITION LEVEL 05 - PART A
TD-1-500-05D
SECURITY FLOOR PLAN - DEMOLITION LEVEL 05 - PART D
TY-0-01
SECURITY COVER SHEET
TY-1-500-00
SECURITY FLOOR PLAN LEVEL 00 - OVERALL
TY-1-500-00A
SECURITY FLOOR PLAN LEVEL 00 - PART A
TY-1-500-00B
SECURITY FLOOR PLAN LEVEL 00 - PART B
TY-1-500-00C
SECURITY FLOOR PLAN LEVEL 00 - PART C
TY-1-500-00D
SECURITY FLOOR PLAN LEVEL 00 - PART D
TY-1-500-00E
SECURITY FLOOR PLAN LEVEL 00 - PART E
TY-1-500-01
SECURITY FLOOR PLAN LEVEL 01 - OVERALL
TY-1-500-01A
SECURITY FLOOR PLAN LEVEL 01 - PART A
TY-1-500-01B
SECURITY FLOOR PLAN LEVEL 01 - PART B
TY-1-500-01C
SECURITY FLOOR PLAN LEVEL 01 - PART C
TY-1-500-01D
SECURITY FLOOR PLAN LEVEL 01 - PART D
TY-1-500-01E
SECURITY FLOOR PLAN LEVEL 01 - PART E
TY-1-500-02
SECURITY FLOOR PLAN LEVEL 02 - OVERALL
TY-1-500-02A
SECURITY FLOOR PLAN LEVEL 02 - PART A
TY-1-500-02B
SECURITY FLOOR PLAN LEVEL 02 - PART B
TY-1-500-02C
SECURITY FLOOR PLAN LEVEL 02 - PART C
TY-1-500-02D
SECURITY FLOOR PLAN LEVEL 02 - PART D
TY-1-500-03A
SECURITY FLOOR PLAN LEVEL 03 - PART A
TY-1-500-03D
SECURITY FLOOR PLAN LEVEL 03 - PART D
TY-1-500-04
SECURITY FLOOR PLAN LEVEL 04
TY-1-500-05
SECURITY FLOOR PLAN LEVEL 05
TY-1-S01
SECURITY SITE PLAN - DEMOLITION
TY-1-S02
SECURITY SITE PLAN - NEW WORK
TY-5-01
SECURITY DETAILS
TY-5-02
SECURITY DETAILS
TY-5-03
SECURITY DETAILS
TY-5-04
SECURITY DETAILS
TY-6-500-01
SECURITY CCTV RISER DIAGRAM
TY-6-500-02
SECURITY CCTV RISER DIAGRAM
TY-6-500-03
SECURITY CCTV RISER DIAGRAM
TY-6-500-04
SECURITY CCTV RISER DIAGRAM
TY-7-01
CAMERA SCHEDULE
TY-7-02
CAMERA SCHEDULE
TD-1-501-01
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01
TY-1-501-01
SECURITY FLOOR PLAN LEVEL 01
TY-6-501-01
SECURITY CCTV RISER DIAGRAM
TD-1-507-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TY-1-507-00
SECURITY FLOOR PLAN LEVEL 00
TY-6-507-00
SECURITY CCTV RISER DIAGRAM
TD-1-509-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TD-1-509-01
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01
TY-1-509-00
SECURITY FLOOR PLAN LEVEL 00
TY-1-509-01
SECURITY FLOOR PLAN LEVEL 01
TY-6-509-01
SECURITY CCTV RISER DIAGRAM
TD-1-511-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TY-1-511-00
SECURITY FLOOR PLAN LEVEL 00
TY-6-511-00
SECURITY CCTV RISER DIAGRAM
TD-1-512-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TD-1-512-01
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01
TY-1-512-00
SECURITY FLOOR PLAN LEVEL 00
TY-1-512-01
SECURITY FLOOR PLAN LEVEL 01
TY-6-512-01
SECURITY CCTV RISER DIAGRAM
TD-1-513-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TY-1-513-00
SECURITY FLOOR PLAN LEVEL 00
TY-6-513-00
SECURITY CCTV RISER DIAGRAM
TD-1-514-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TY-1-514-00
SECURITY FLOOR PLAN LEVEL 00
TY-6-514-00
SECURITY CCTV RISER DIAGRAM
TD-1-515-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TD-1-515-01
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01
TY-1-515-00
SECURITY FLOOR PLAN LEVEL 00
TY-1-515-01
SECURITY FLOOR PLAN LEVEL 01
TY-6-515-00
SECURITY CCTV RISER DIAGRAM
TD-1-518-01
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01
TD-1-518-02
SECURITY FLOOR PLAN - DEMOLITION LEVEL 02
TD-1-518-03
SECURITY FLOOR PLAN - DEMOLITION LEVEL 03
TD-1-518-04
SECURITY FLOOR PLAN - DEMOLITION LEVEL 04
TY-1-518-01
SECURITY FLOOR PLAN LEVEL 01
TY-1-518-02
SECURITY FLOOR PLAN LEVEL 02
TY-1-518-03
SECURITY FLOOR PLAN LEVEL 03
TY-1-518-04
SECURITY FLOOR PLAN LEVEL 04
TY-6-518-00
SECURITY CCTV RISER DIAGRAM
TD-1-519-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TY-1-519-01
SECURITY FLOOR PLAN LEVEL 00
TY-6-519-00
SECURITY CCTV RISER DIAGRAM
TD-1-520-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TY-1-520-00
SECURITY FLOOR PLAN LEVEL 00
TY-6-520-00
SECURITY CCTV RISER DIAGRAM
TD-1-521-00
SECURITY FLOOR PLAN - DEMOLITION LEVEL 00
TD-1-521-01
SECURITY FLOOR PLAN - DEMOLITION LEVEL 01
TY-1-521-00
SECURITY FLOOR PLAN LEVEL 00
TY-1-521-01
SECURITY FLOOR PLAN LEVEL 01
TY-6-521-00
SECURITY CCTV RISER DIAGRAM

The following contract specifications are included in their entirety by reference in this Scope of Work:

SECTION #
TITLE
00 01 00
TABLE OF CONTENTS
01 00 00
GENERAL REQUIRMENTS
01 10 00
SUMMARY OF WORK
01 22 00
UNIT PRICES
01 32 16.15
PROJECT SCHEDULES
01 33 23
SHOP DRAWINGS, PRODUCT DATA, AND SAMPLES
01 35 26
SAFETY REQUIREMENTS
01 42 19
REFERENCE STANDARDS
01 45 00
QUALITY CONTROL
01 45 29
TESTING LABORATORY SERVICES
01 57 19
TEMPORARY ENVIRONMENTAL CONTROLS
01 58 16
TEMPORARY INTERIOR SIGNAGE
01 73 29
CUTTING AND PATCHING
01 74 19
CONSTRUCTION WASTE MANAGEMENT
01 91 00
GENERAL COMMISSIONING REQUIREMENTS
02 21 13
SITE SURVEYS
02 41 10
DEMOLITION AND SITE CLEANING
02 82 13.13
GLOVEBAG ASBESTOS ABATEMENT
07 84 00
FIRESTOPPING
07 92 00
JOINT SEALANTS
09 91 00
PAINTING
27 05 11
REQUIREMENTS FOR COMMUNICATIONS INSTALLATIONS
27 05 26
GROUNDING AND BONDING FOR COMMUNICATIONS SYSTEMS
27 05 33
CONDUITS AND BACKBOXES FOR COMMUNICATIONS SYSTEMS
27 05 36
CABLE TRAYS FOR COMMUNICATIONS SYSTEMS
27 05 53
IDENTIFICATION FOR COMMUNICATIONS SYSTEMS
27 10 00
STRUCTURED CABLING
27 11 19
COMMUNICATIONS TERMINATION BLICKS AND PATCH PANELS
27 13 13.13
COMMUNICATIONS COPPER CABLE SPLICING AND TERMINATIONS
27 15 13
COMMUNICATIONS COPPER HORIZONTAL CABLING
27 16 19
COMMUNICATIONS PATCH CORDS, STATION CORDS, AND CROSS CONNECT WIRE
28 05 00
COMMON WORK RESULTS FOR ELECTRONIC SAFETY AND SECURITY
28 05 01
STATEMENT OF WORK FOR ELECTRONIC SAFETY AND SECURITY CAMPUS VIDEO SURVEILLANCE SYSTEM REPLACEMENT
28 05 13
CONDUCTORS AND CABLES FOR ELECTRONIC SAFETY AND SECURITY
28 05 26
GROUNDING AND BONDING FOR ELECTRONIC SAFETY AND SECURITY
28 23 00
VIDEO SURVEILLANCE
31 20 00
EARTHWORK
32 12 16
ASPHALT PAVING
32 17 23
PAVEMENT MARKINGS
32 90 00
PLANTING

In the instance that information on the contract drawings should conflict with the information in the specification, the specifications shall always take precedence over the drawings.

3. Bid Schedule

· Base Bid - All work in accordance with this scope of work, design drawings and specifications.

· Bid Deduct Alternate 1 – All work in Base Bid but remove 30% of the exterior fixtures. (300 calendar days to complete all work) – Reducing “Fish Eye” fixtures from a quantity of 252 to 170 & “Multisensor” fixtures from a quantity of 173 to 121.

· Bid Deduct Alternate 2 – All work in Bid Deduct Alternate 1 but remove an additional 30% of the interior fixtures. (255 calendar days to complete all work) – Reducing “Dome Cameras” from 215 to 150.

· Most of the work shall be performed during the hours of 7:00 am to 4:00 pm, unless otherwise approved by the VA. Work provided after hours is listed in the ICRA drawings as required to minimize interruptions in the main building. (14 days’ notice required) The contractor shall have 365 days from the Notice to Proceed to complete all work associated with the Base Bid Scope of Work.

4. VA Information Security Requirements

5.1 GENERAL

Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security. The contractor shall have the proper “Authority to Operate” credentials to be awarded this contract.

Work performed will require coordination with the VA IT department in order ensure compliance with VA guidelines.

5.2 ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.

d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employment. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

5.3 VA INFORMATION CUSTODIAL LANGUAGE

a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

b. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

c. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.

d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

g. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.

h. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

i. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.

k. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above-mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.

l. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COTR.

5.4 NOT USED

5.5 INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE

a. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerablity scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COTR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA’s network involving VA information must be reviewed and approved by VA prior to implementation.

b. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.

c. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor’s systems in accordance with VA Handbook 6500.3, Certification and Accreditation and/or the VA OCS Certification Program Office. Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.

d. The contractor/subcontractor’s system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA’s POA&M management process. The contractor/subcontractor must use VA’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500.3. This may require reviewing and updating all of the documentation (PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.

e. The contractor/subcontractor must conduct an annual self-assessment on all systems and outsourced services as required. Both hard copies and electronic copies of the assessment must be provided to the COTR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor must take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.

f. VA prohibits the installation and use of personally owned or contractor/subcontractor owned equipment or software on VA’s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.

g. All electronic storage media used on non-VA leased or non-VA owned IT equipment…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .