Attachment_1_-_SOW.pdf
PDF 227 KB Posted
- Attached to
- Fiduciary Liability Insurance Federal contract opportunity
- Solicitation number
- 50310219Q0044
- Issued by
- Securities and Exchange Commission
About this file
Attachment 1 - Statement of Work (SOW)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| signed_Amendment_0003_Attachment_-_Q&A.pdf | ||
| signed_AMD_0003_to_RFQ_50310219Q0044.pdf | ||
| Attachment_1_-_SOW.pdf | ||
| revised_RFQ-50310219Q0044.pdf | ||
| signed_AMD0002_-_RFQ_50310219Q0044.pdf | ||
| Attachment_3_-_Pricing_Spreadsheet.xlsx | XLSX spreadsheet | |
| signed_Amendment_0002_Attachment_-_Q&A.pdf | ||
| Amendment_Attachment_1_Question_and_Answers_-_RFQ50310219Q0044.pdf | ||
| AMD0001_-_RFQ_50310219Q0044_signed.pdf | ||
| Attachment_3_-_Pricing_Spreadsheet.xlsx | XLSX spreadsheet | |
| Attachment_2-Past_Performance_Questionnaire.docx | DOCX document | |
| RFQ-50310219Q0044.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Supplemental Retirement Plan (SRP)- Fiduciary Insurance
U.S. Securities and Exchange Commission
OHR – Office of Human Resources Supplemental Retirement Plan (SRP) - Fiduciary Insurance
Statement of Work
1.0 Scope
The Statement of Work (SOW) serves to outline and specify the U.S. Securities and Exchange Commission’s ("SEC" or “Agency”) requirement for Fiduciary Insurance for the Oversight Committee of the Agency’s Supplemental Retirement Plan (referred to herein as the “Plan” or as the “Supplemental Retirement Plan” or “SRP”) and to seek sources that are able to perform these requirements. The Oversight Committee oversees and serves as Plan Administrator of the SRP.
The plan is a defined contribution program that complies with Section 401(a) of the Internal Revenue Code.
The contractor must not be directly regulated by the SEC, but a contractor will not be disqualified solely because it (or one or more partners) is part of a corporate structure that includes one or more entities that are directly regulated by the SEC.
2.0 Background
The mission of the SEC is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation. The SEC oversees the key participants in the securities industry, including securities exchanges, securities brokers and dealers, and investment advisors.
As part of the SEC’s compensation model, the plan was established to offer additional retirement benefits in addition to standard federal retirement programs such as Federal Employees Retirement System (FERS), the Civil Service Retirement System (CSRS), and the Thrift Savings Plan (TSP) for eligible employees. The Plan holds only employer contributions. Currently this plan has over 4500 participants.
The SEC currently contracts with a vendor that provides Trustee and Recordkeeping services for the plan. As the Plan Trustee in accordance with the requirements of Section 401(a) of the Internal Revenue Code, this vendor maintains plan assets in trust, preserves auditable records of all Plan assets, and accepts bi-weekly payroll transfers from the SEC’s payroll provider. As the recordkeeper, this vendor creates and maintains individual participant records containing all pertinent financial data (e.g., account balance, bi-weekly deposits, withdrawals, allocations of interest, vesting amounts), provides a secure web-based platform for participants to manage and verify all aspects of their individual account, and provides call center services to SRP participants throughout the continental U.S. We do not anticipate that the contractor selected for the fiduciary insurance will need to exchange any information with the Trustee and Recordkeeping vendor.
The Oversight Committee, which consists of seven members, was established to oversee and to serve as Plan Administrator of the Plan. In exercising its powers and fulfilling its responsibilities, the Committee’s guiding principle is that it will at all times fulfill its legal and fiduciary responsibilities in a manner that is consistent with the SEC’s mission to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation.
Consistent with that guiding principle, the Committee will not make investments or decisions on behalf of the Plan that would have the effect of creating an actual or apparent conflict of interest between the SEC’s regulatory responsibilities and the Plan.
As Plan Administrator of the SEC’s Supplemental Retirement Plan, the Committee has all the rights and responsibilities of the Plan Administrator as detailed in the Plan Documents and as otherwise granted or required by law. These powers include, but are not limited to:
- Selecting a Plan Trustee and Recordkeeper;
- Carrying out fiduciary responsibilities;
- Selecting the investment vehicle(s) for the Plan assets;
- Determining what optional features the Plan will offer, and on what terms; and
- Resolving claims and disputes between the Plan, participants, and beneficiaries.
The contractor’s expertise must include:
• High level of understanding of the fiduciary responsibilities of qualified retirement plans of a similar size to protect the Commission and the plan’s assets against fiduciary-related claims of mismanagement of the agency’s supplemental retirement plan;
• Comprehensive understanding of qualified defined contribution plans, plan features, and provisions of law related to contribution plans;
• Reliability and ongoing commitment to quality and technology;
• Demonstrated capability of data integrity to ensure maximum security of Personally
Identifiable Information; and,
• Applicable credentials, certifications or accreditations to provide coverage.
3.0 Objectives
The contractor shall provide coverage to the Oversight Committee for associated legal costs and will step in on covered claims to indemnify members of the committee for any reason. To include:
o Allegations of imprudent investing if the plan loses money or does not meet participant growth expectations.
o Errors or delays in responding to requests for investment changes, distributions, and rollovers.
o Not adhering to plan documents.
o Claims by plan beneficiaries.
o Failing to make contributions on a timely basis.
o Engaging in prohibited activities under Section 401(a) of the Internal Revenue
Code.
o Wrongful termination of the plan.
o Conflicts of interest.
The contractor shall protect the Oversight Committee and its members when participants allege violations in connection with collectively bargained agreements.
The contractor shall cover the alleged improper selection of third party service providers, including trustee or custodian.
The Plan is not subject to the Employee Retirement Income Security Act of 1974 (ERISA), however, the contractor shall provide coverage similar to those required when a plan is subject to ERISA as required by the Department of Labor, IRS or other regulatory concerns.
The contractor must respond to telephone and e-mail inquiries by the SEC Contracting Officer (CO) and Contracting Officer’s Representative (COR) and committee members and return calls/messages within one (1) business day.
Travel to the SEC’s headquarters in Washington, DC may be required to support the Agency’s coverage for the committee members.
The contractor must ensure privacy and security of all data, maintaining the Commission’s standards for the handling of sensitive data.
Safeguarding of Information/Maintain Privacy and Security Note the following:
a) Security Requirement for Contract Staff: All individuals working on the effort must have a Moderate Risk Public Trust (MRPT) determination from the Agency to facilitate the protection of sensitive account data.
b) Training. The Federal Acquisition Regulation (FAR) clause 52.224-3, Privacy Training Alternate I, is hereby incorporated in its entirety. In addition, Contractors are responsible for ensuring that all personnel designated by the SEC to take the SEC provided training, complete the training prior to being granted access to SEC information and information systems. The SEC will provide initial privacy training, and annual privacy training thereafter, to the identified personnel for the duration of this contract.
The Contractor shall also ensure that all of its personnel read and agree to abide by the SEC Rules of the Road prior to being granted access to Federal information and information systems and annually thereafter.
c) Breach Response: The Contractor shall have policies, procedures and mechanisms in place for the effective management of breach response and compliance with applicable federal privacy and data protection laws, as well as applicable regulations, directives and security mandates as defined in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-122.
In support of this requirement, the Contractor shall have policies and procedures that implement a breach response and that ensure the Contractor, its employees, agents or subcontractors:
a. Determine the nature and extent of the breach, contain the incident by stopping the unauthorized practice, recover data, shut down the system that was breached, revoke access and/or correct weaknesses in physical security;
b. Provide the SEC with the name and contact information for an employee of the Contractor who shall serve as SEC’s primary breach response contact and shall be available to assist the SEC twenty-four (24) hours per day, seven (7) days per week as a contact in resolving obligations associated with a breach;
c. Notify the SEC of a breach as soon as practicable, but no later than twenty-four
(24) hours after the Contractor becomes aware of it by contacting the SEC Service Desk at (202)551-4357. The Contractor shall not include any sensitive information in the subject or body of any e-mail; and
d. Support the SEC’s investigation and resolution of breach response, if requested by the SEC. For purposes of these instructions, a “suspected breach” shall be interpreted liberally to mean any situation in which the loss of PII or unauthorized access to PII is deemed a reasonable possibility.
Immediately following the Contractor’s notification to SEC of a breach, the parties shall coordinate with each other to investigate the breach. The Contractor agrees to fully cooperate with the SEC in its handling of the matter, including, without limitation: (i) assisting with any investigation; (ii) providing the SEC with physical access to the facilities and operations affected; (iii) facilitating interviews with the Contractor’s employees and others involved in the matter; and (iv) making available all relevant records, logs, files, data reporting and other materials required to comply with applicable law, regulation, industry standards or as otherwise required by the SEC. The Contractor shall reimburse the SEC for actual costs incurred by the SEC in responding to, and mitigating damages for any breach caused by the contractor, including all costs of notice and/or remediation.
In the event of a breach, the Contractor shall use reasonable efforts to prevent a recurrence of such breach.
d) Data Protection/Encryption: Specify security parameters used to exchange information with the Agency including, but not limited to: encryption being used during transport;
whether the data (including passwords) is encrypted in storage; type of connection; etc.
The Contractor shall ensure that its processes, procedures and equipment associated with PII comply with applicable federal privacy and data protection laws, as well as applicable regulations, directives and security mandates as defined by NIST SP 800-61 Revision 2, or the latest revision, and SEC policies and procedures developed to safeguard the confidentially, integrity and availability of SEC data. In support of these requirements, the Contractor shall have
Policies, procedures, and mechanisms designed to restrict access to SEC data on Contractor, subcontractor, or SEC inter/intra agency partner systems exclusively to authorized personnel;
Policies, procedures, and mechanisms that prevent transmission or disclosure of SEC data to an unauthorized party;
Policies, procedures, and mechanisms that ensure SEC data on portable devices are encrypted using methods compliant with Federal Information Processing Standard 140-2;
Policies, procedures, and mechanisms that ensure SEC data transmitted across public networks (i.e., the Internet) by the Contractor, or its employees, agents or subcontractors, are protected using encryption compliant with Federal Information Processing Standard 140-2 and NIST 800-53 Revision 4, or latest revision;
Policies, procedures, and mechanisms that ensure SEC data at rest held by the Contractor, or its employees, agents or subcontractors, are protected using encryption compliant with Federal Information Processing Standard 140-2; and
Policies and procedures to ensure that SEC PII is strictly segregated from information of its other customers.
The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract.
If the Contractor must remove any information from the primary work area, they should protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act information.
e) No data shall be released by the Contractor without the consent of the SEC in writing. All requests for release must be submitted in writing to the Contracting Officer’s Representative and Contracting Officer.
4.0 Federal Requirements & SEC Regulations
4.1 Federal Requirements. The following is a sample list of federal requirements consisting of laws, policies, standards and guidance required for information protection. The contractor will be subject to the same information protection requirements as the SEC under the E-Government Act of 2002. The list that follows is not all-inclusive and the contractor must follow the same requirements as the Commission.
Office of Management and Budget (OMB) Circular A-11, Revised, “Preparation, Submission and Execution of the Budget” (July 2017)
OMB Circular A-130, Revised, “Managing Information as a Strategic Resource” (July 2016)
Privacy Act of 1974, Public Law 93-579 (5 U.S.C. 552a) The E-Government Act of 2002, Public Law 107-347 OMB Federal Enterprise Architecture Program Management Office (FEAPMO) Reference
Models and Circular A-11 Guidance. www.feapmo.gov.
OMB Memorandum M-02-01, Guidance for Preparing and Submitting Security Plans of Action and Milestones, October 17, 2001
OMB Memorandum M-15-01, Fiscal Year 2014-2015 Guidance on Improving Federal Information Security and Privacy Management Practices, October 3, 2014 (and subsequent updates by OMB)
OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002, September 26, 2003
Federal Information Processing Standard (FIPS) Publication (PUB) 201, Personal Identity Verification (PIV) of Federal Employees and Contractors, September 5, 2013
FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems, March 1, 2006
FIPS PUB 197, Advanced Encryption Standard, November 26, 2001
National Institute for Standards and Technology (NIST), Special Publication (SP) 800-122, Guide for Protecting the Confidentiality of Personally Identifiable Information (PII), April 6, 2010
NIST SP 800-37, Revision2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, December 20, NIST SP 800-115, Technical Guide to Information Security Testing and Assessment September 30, 2008
NIST SP 800-100, Information Security Handbook: A Guide for Managers, March 7, 2007
NIST SP 800-95, Guide to Secure Web Services, August 29, 2007
NIST SP 800-92, Guide to Computer Security Log Management, September 13, 2006
NIST SP 800-88, Revision 1, Guidelines for Media Sanitization, December 17, 2014
NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide, August 6, 2012
NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, (most final version)
NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans, (most final version)
NIST SP 800-44 Version 2, Guidelines on Securing Public Web Servers, September 2007
NIST SP 800-30, Revision 1, Guide for Conducting Risk Assessments, September 17, 2012
NIST SP 800-70, Revision 4, National Checklist Program for IT Products: Guidelines for Checklist Users and Developers, February 15, 2018
NIST SP 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations, September 30, 2011
NIST SP 800-144, Guidelines on Security and Privacy in Public Cloud Computing, December 9, 2011
4.2 SEC Regulations
Information Technology Security Program, SECR 24-04 (Rev. 4), November 14, 2018 Safeguarding Non-Public Information, SECR 23-2, September 19, 2018 Enterprise Architecture SECR 24-1.6 (Rev. 2), January 17, 2018 Information Collection Program, SECR 24-09 (Rev. 2), February 15, 2017 Privacy Policy and Compliance, February 15, 2017 Rules of the Road, December 21, 2017
4.3 Security Requirements. The Contractor must meet all the requirements listed below.
4.3.1 Requirements Management. The Contractor will provide all necessary personnel, administrative, financial, and managerial resources necessary to perform all tasks described in this Statement of Work (SOW).
4.3.2 Security Assessment Findings Review. The Contractor must remediate findings identified during any security and privacy testing. All significant findings (typically those rated as HIGH and often those rated as MEDIUM) should be resolved before the system receives an ATO (allowed to go into production and handle SEC Information. The Contractor must remediate as many security and privacy findings documented as Plan of Action and Milestones (POA&M) items as possible and within a reasonable timeframe, based on risk guidance from the designated authorizing official. The Contractor shall document the resolution and provide supporting evidence of changes. The Contractor shall schedule a conference meeting with the COR, OIT Security Group, and relevant SEC staff to review the state of the POA&M resolutions. The Contractor shall provide the SEC with the number and description of resolved POA&M items identified in the security review, along with supporting evidence. The Security Group may choose to perform additional technical testing to validate resolution.
4.3 Security Assessment and Authorization (SA&A): The SEC Office of Information Technology (OIT) Security Team performs a security and privacy assessment for an information system to be deployed and continually updates the authorization based on updates to the information system. This process is designed to allow the SEC to identify any security and privacy risks associated with the system and either mitigate them or formally accept any residual risk. SA&A entails a review of minimum security and privacy controls, documented in the final latest version of NIST SP 800-53 a system privacy plan, privacy impact assessment; system security plan1; and remediation of weaknesses that are documented in a plan of action and milestone (POA&M) document2. SA&A also covers the:
Enumeration - activity aimed at identifying devices and components and cross-referencing with provided inventory lists;
Vulnerability Scanning - automated assessment of system servers, workstations, and any other network device or appliance within the system boundary. The assessment will identify weaknesses associated with network services, operating systems, and devices that are un-patched or have out-of-date software security patches;
Penetration Testing - attempts to exploit weaknesses identified from vulnerability scanning to verify legitimate findings, eliminate false-positives, and determine the extent of the vulnerability and potential remediation steps that may be taken; and
Functional Testing - specific tests, examinations, and inspections against NIST SP 800-53 controls not tested by the other activities;
4.4 Conflicts of Interest.
(a) General. Subpart 9.5 of the Federal Acquisition Regulation 48 C.F.R. 9.5, prescribes responsibilities, general rules, and procedures for identifying, evaluating, and resolving organization conflicts of interest.
(b) Purpose. The purpose of this clause is to avoid, neutralize, or otherwise mitigate organizational conflicts of interest which might exist related to a Contractor’s performance of work required by this contract. Such conflicts may arise in situations including, but not limited to: a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement in which it has provided assistance in the preparation of the Government’s requirements and specifications; a Contractor’s providing advisory assistance to the Government in a procurement in which the Contractor’s firm or one which the Contractor represents is an actual or potential Offeror; and a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement where the Contractor has obtained confidential or proprietary information relating to competing Offerors as a result of the Contractor’s work on prior task orders.
(c) Definition. For purposes of this clause, the term “Contractor” means: The Contractor; any of the Contractor’s parents, affiliates or other entities in which the Contractor or such parents or affiliates have a financial interest; successors in interest to
1 Based on NIST SP 800-18 2 Based on Office of Management and Budget (OMB) Memorandum 02-01 the Contractor or any of its parents or affiliates; proposed consultants or subcontractors at any tier; and employees thereof.
(d) Restrictions. The Contractor agrees:
1. To remain ineligible to participate in any capacity (including participating as a prime Contractor, subcontractor, or as the representative of another party) in contracts, subcontracts, or Proposal (whether solicited or unsolicited) that directly relate to the Contractor’s performance of work under this Contract.
2. Prior to beginning work on a task order, to execute such Confidentiality Agreements, Statements of Non-Disclosure or other documents which the Contracting Officer may, in his/her sole discretion, require in order to protect the proprietary nature or confidentiality of information provided by the Government or otherwise received by the Contractor in connection with its work under this Contract.
3. As otherwise provided in this Contract, not to accept any compensation or any other form of payment from a broker, potential lessor, or any source other than the Government for services rendered under this Contract, and to employ aggressive strategies to minimize the Government’s lease costs where the Contractor would entitled by common business practice to receive a real estate commission or any form of payment from a broker, potential lessor, or other party, for work performed under this Contract.
4. To immediately notify the Contracting Officer of any offer of compensation, other form of payment, or thing of value, made by a broker, potential lessor, or any source other than the Government to the Contractor related to services rendered under this Contract, regardless of whether such offer was made during Contractor’s performance of work under a given task order or subsequent to Contractor’s completion of work under such task order.
5. Prior to the acceptance of a task order request, to immediately notify the Contracting Officer of any potential conflict of interest which would prevent or limit the Contractor’s ability to perform the work requested.
6. To immediately notify the Contracting Officer of any conflict of interest discovered during Contractor’s performance of work pursuant to a Government issued task order; provided that the Contracting Officer shall have the right to impose such restrictions as he/she deems appropriate on Contractor’s performance based on the existence of such a conflict or, if the Contracting Officer determines that such restrictions would not adequately address the conflict of interest at issue, to terminate the Contractor’s performance of work under the task order at no cost to the Government.
7. As otherwise provided in this Contract, that if the Contractor declines to accept a task order request and subsequently participates (either directly or as a representative of another party) in a Government contracting action that was the subject of the task order request, then the fee which the Contractor would have been entitled to receive for such task order work or the fee actually paid by the Government for the task order’s performance by another Contractor, whichever is greater, shall be applied toward the Contractor’s minimum ordering guarantee.
8. That in the event that Contractor knowingly withholds the existence of a conflict of interest from the Government, that the Contracting Officer may terminate this Contract at no cost to the Government and any minimum guarantee(s) otherwise applicable to the Contractor will be forfeited; provided, that the foregoing shall be in addition to all other remedies and causes of action which the Government may have against the Contractor, including the suspension and/or debarment of the Contractor.
9. To include this Conflict of Interest clause, including this subparagraph, in all of the Contractor’s subcontracts at all tiers (appropriately modified to preserve the Government’s rights hereunder) which involve the performance of work by subcontractors in support of this Contract.
10. That, in addition to the remedies enumerated above, the Government may terminate this Contract for cause in the event of the Contractor’s breach of any of the above restrictions.
4.5 Section 508 Requirements. Pursuant to Section 508 of the Rehabilitation Act of 1973
(29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, all electronic and information technology (EIT) products and services developed, acquired, maintained, and/or used under this contract/order must comply with the Electronic and Information Technology Accessibility Provisions set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in FAR 39.2.The complete text of Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/provisions.htm.
All EIT products must comply with the following standards. Descriptions of the standards are viewable at the link Section 508 Standards.
36 CFR 1194 Section 21-Software applications and operating systems 36 CFR 1194 Section 22-Web-based Intranet and Internet Information and
Applications 36 CFR 1194 Section 23-Telecommunication Products 36 CFR 1194 Section 24-Video and Multimedia Products 36 CFR 1194 Section 25-Self-contained, closed products 36 CFR 1194 Section 26-Desktop and Portable Computers 36 CFR 1194 Section 31-Functional Performance Criteria 36 CFR 1194 Section 41-Information, documentation, and support
Offerors that fail to demonstrate compliance with the above standards, or provide equivalent salient characteristics, may be eliminated from further consideration for award.
The Contractor must indicate for each line item in the schedule whether each product or service is compliant or non-compliant with the accessibility standards at 36 CFR 1194 using a Voluntary Product Accessibility Template (VPAT).
Further, the quote must indicate where full details of compliance can be found (e.g., contractor’s website or other exact location). The offeror further represents that all EIT products and services that are less than fully compliant have been reviewed and plans to correct are in place.
Respondents to this solicitation must provide any additional detailed information necessary for determining applicable Section 508 standards conformance, as well as for documenting EIT products and/or services that are incidental to the project, which would constitute an exception to Section 508 requirements. If a contractor claims its products and/or services, including EIT deliverables such as electronic documents and reports, meet applicable Section 508 standards, and it is later determined by the Government – i.e., after award of a contract/order, that products and/or services delivered do not conform to the described accessibility, remediation of the products and/or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.
4.5 Electronic and Information Technology (EIT). In accordance with Section 508 of the
Rehabilitation Act of 1973 (29 U.S.C. 794d), all EIT supplies or services provided under this contract must comply with the applicable accessibility standards issued by the Architectural and Transportation Barriers Compliance Board at 36 CFR Part 1194 (see FAR Subpart 39.2). Electronic and information technology (EIT) is defined at FAR 2.101.
4.6 Electronic and Information Technology Accessibility. Each Electronic and
Information Technology (EIT) product or service furnished under this contract will comply with the Electronic and Information Technology Accessibility Standards (36 CFR 1194 Subpart B-D). If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor will, without charge to the Government, repair or replace the non-compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government will have the following recourses:
• Cancellation of the contract, delivery or task order, purchase or line item without termination liabilities; or,
• In the case of custom Electronic and Information Technology (EIT) being developed for the Government, the Government will have the right to have any necessary changes made or repairs performed by itself or by another firm and the contractor will reimburse the Government for any expenses incurred thereby.
• For every EIT product or service accepted under this contract by the Government that does not comply with 36 CFR 1194, the contractor must, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either the planned refresh cycle of the product or service, or on the contract renewal date, whichever occurs first.
• In the event of a modification(s) to this contract/order, which adds new EIT products and services or revises the type of, or specifications for, products and services the Contractor is to provide, including EIT deliverables such as electronic documents and reports, the Contracting Officer may require that the Contractor provide an update of information provided in the solicitation to identify EIT compliance. Under any maintenance agreement, Contractor agrees to maintain compliance with Section 508 of the Rehabilitation Act of 1973 for all hardware/software.
4.7 Disaster Recovery. Contractor must create and implement policies, processes and procedures to address the information system security requirements needed for disaster recovery in the event of a disruption of the information service(s) provided. This includes regular review and test of a disaster recovery plan(s) related to recovering the information service(s) provided. Results of all disaster recovery plan tests, exercises or actual events, including but not limited to after-action reports, lessons learned and plan updates will be made available to SEC for review within ten (10) working days of a request by SEC. Furthermore, SEC will be provided a point of contact for disaster recovery planning and exercise for the information service(s) provided.
4.8. Return or Destruction of PII. At any time during the term of this contract at the SEC’s written request or upon the termination or expiration of this contract for any reason, the Contractor shall instruct all authorized personnel to promptly return to the SEC all copies, whether in written, electronic or other form or media, of PII in its possession or the possession of such authorized personnel, or securely dispose of all such copies, and certify in writing to the SEC that such PII has been returned to SEC or disposed of securely. The destruction of PII shall be performed according to NIST approved methods.
When Government information is no longer required, the information, data, and/or equipment shall be returned to SEC control, destroyed, or held until otherwise directed.
As part of the contract closeout, the Contractor shall submit a certification of sanitization of Government and Government-activity related files and information to the Contracting Officer’s Representative and Contracting Officer following the template provided in NIST Special Publication 800-88 Guidelines for Media Sanitization.
4.9 RECORDS
The Contractor shall be responsible for creating, maintaining, and disposing of only those government required records that are specifically listed in the Statement of Work. If requested by the Contracting Officer or COR, the Contractor shall provide the original record, or a reproducible copy of such record, within three working days of receipt of the request. This contract specifically incorporates the Rights in Data - Special Works clause contained in FAR 52.227-17, including, but not limited to, paragraph (d), which states:
Except as otherwise specifically provided for in this contract, the Contractor shall not use for purposes other than the performance of this contract, nor shall the Contractor release, reproduce, distribute, or publish any data first produced in the performance of this contract, nor authorize others to do so, without written permission of the Contracting Officer.
All records generated under the contract shall be the SEC’s property and shall be delivered and returned to the SEC upon termination of the contract, unless the SEC instructs otherwise for confidentiality purposes.
Access To and Custody of Records; Effect of Disputes
In addition to the duties specified elsewhere in this Contract the Government may request, and the Contractor shall provide upon such request, full and immediate access to and custody of any and all interview data or other information or data compiled for or generated on behalf of the Government by the Contractor and any of its employees, agents, or sub-Contractors under this contract whether or not performance under the contract has been completed, and regardless of any claim or dispute, if any, arising hereunder.
This general, unilateral right of access and custody is in addition to any other access or custody to records provided for by the Statement of Work described in this contract. The Government shall not be liable for additional costs, if any, that the Contractor may incur in providing records access or custody pursuant to a request under this provision. The Government, however, shall use best efforts to limit the timing and scope of such request so as to cause minimal disruption, if any, to the Contractor’s operations and continued performance under this contract, and to provide reasonable prior notice, where practicable, before making such a request.
Should a person or entity, including any governmental agency other than the SEC, seek or request access, whether through voluntary means or compulsory process, to public comments or other records compiled for, or otherwise relating to, the performance of this contract, the Contractor shall immediately notify, orally and in writing, the COR and the Contracting Officer. The Contractor shall also provide the Government with an opportunity to intervene in any such third-party request for access and/or take other appropriate and necessary measures to assert any applicable privileges, ownership rights, or any other legal or equitable interests of the Government, and, in any event, shall not provide any such third party with access to such records, which shall be treated as the property of the Government, without prior written authorization of the Contracting Officer.
The SEC will obtain and the Contractor will assign and deliver to the SEC all the contractor’s rights, including without limitation all copyrights, in the software first produced in the performance of this contract, all as provided in FAR 52.227-17, Rights in Data – Special Works. The term “software” includes, without limitation, source code listings, design details, algorithms, processes, flow charts, formulas, and related material that would enable the software to be produced, created, or compiled. As to any pre-existing software incorporated into a deliverable under the contract, the Contractor will obtain, assign, and deliver to the SEC intellectual property rights sufficient to permit the SEC to use, disclose, and reproduce such software, to prepare derivative works, to distribute copies to the public, and to perform publicly and display publicly, in any manner and for any purpose, and to have or permit others to do so.
Software contractors in the private and commercial sectors are expected to want the source code as the basis for their SEC Interactive Data applications. The source code will be made publicly available, subject to a permissive licensing scheme that would allow incorporation of the software into other works. The contractor would also have access to the source code on this basis.
File details come from the government source that posted it.