Attachment 6 - Contract Terms and Conditions.pdf

PDF 352 KB Posted

Attached to
Technical Surveillance Countermeasure Services Federal contract opportunity
Solicitation number
50310220Q0059
Issued by
Securities and Exchange Commission

View the file

Other files for this federal contract opportunity

Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFQ 50310220Q0059

SEC AGENCY CLAUSES

2001.00 Shipping Instructions (June 2020)

Preservation, packaging, packing, and marking of all deliverables must conform to normal commercial packing standards to assure safe delivery at destination. All deliveries are F.O.B.

Destination. The contractor shall include the SEC contract/delivery order number on all packing slips that accompany items shipped to the SEC.

5003.05 Submission of Invoices - Delphi eInvoicing System (May 2020)

a. The Securities and Exchange Commission (SEC) will only accept electronic invoices submitted through the Delphi eInvoicing system monthly.

b. Contractors are cautioned against submitting an invoice prior to goods and services being received/accepted. Invoices submitted prematurely may be rejected. Software license maintenance and subscriptions may be invoiced at the beginning of the contract period of performance.

c. The SEC's Delphi eInvoicing system is managed by the Enterprise Services Center (ESC). In order to receive payment and in accordance with the Prompt Payment Act, all invoices submitted as attachments in the Delphi eInvoicing web-portal shall contain the following:

(1)Company logo or letterhead

(2)Company name and payment address

(3)Company Point of Contact (POC) for the invoice with phone and e-mail

(4)Invoice number and invoice date

(5) Billing period

(6) SEC Contract number

(7) Task/Delivery Order number (if applicable)

(8) SEC Contracting Officer's Representative (COR name)

(9) Amount billed (by CLIN), current and cumulative

(10) Total amount billed this period

(11) Cumulative total billed to date

(12) Brief Description of Services Performed - General description only

d. If the contract includes allowances for travel, all invoices which include charges pertaining to travel expenses will catalog a breakdown of reimbursable expenses with the appropriate receipts to substantiate the travel expenses.

Attachment 6 Contract Terms and Conditions

e. Payment system registration. All persons accessing the Delphi eInvoicing web-portal will be required to have their own unique user Delphi eInvoicing ID and password and be credentialed through login.gov.

(1) Electronic authentication. See www.login.gov for instructions. Click on the following link for instructions on establishing a login.gov account: https://login.gov/help/creating-an-account/how-do-i-create-an-account-with-logingov/.

(2) To create a login.gov account, the user will need a valid email address and a working phone number. The user will create a password and then login.gov will reply with an email confirming the email address.

(3) In order to make changes to vendor users who will have access to the eInvoicing web-portal for invoice submission and payment tracking purposes, notify iSupplier@sec.gov and include the full name, valid email address, and current phone number of any new vendor users. Vendor users will be notified via e-mail when the account is created. The vendor user will be provided detailed instructions for logging into their Delphi eInvoicing account.

(4) Training on Delphi. To facilitate use of DELPHI, comprehensive user information is available at http://einvoice.esc.gov

(5) Account Management. Vendors are responsible to contact the Delphi Help Desk when their firm's points of contacts will no longer be submitting invoices so they can be removed from the system. Instructions for contacting the Delphi Help Desk can be found at http://einvoice.esc.gov

5004.00 Appointment of Contracting Officer's Representative (COR) (June 2020)

a. TBD, is hereby designated the Securities and Exchange Commission COR for administration and information relating to this contract. TBD is hereby designated as the Alternate COR for this contract. The COR may not re-delegate his or her authority; only the CO has this authority.

b. The COR will manage the contract in coordination with the CO and within the terms of the contract. The COR's responsibilities include reviewing invoices and charges by the Contractor, informing the CO of areas where exceptions are taken, and accepting or rejecting invoices in the SEC's financial system. The COR shall be the primary point of contact responsible for communicating administrative guidance for on-boarding and off-boarding of Contractor Personnel, mandatory trainings, government closures, and other events as necessary. Unless otherwise specified in this contract, inspection and acceptance of supplies and/or services to be furnished under this contract will be performed by the COR.

c. Only the CO has the authority to change the terms and conditions of this contract. The COR may request a contract modification, but the CO will make the final determination. The COR may not agree to or issue a change to the contract terms and conditions. In the event the Contractor effects changes to the contract at the direction of any person other than the CO, the changes will be considered to have been made without any authority and no adjustments will be made to the contract.

6001.00 SEC Non-Disclosure Requirements and Agreements (Feb 2018)

a. Required non-disclosure agreements are attached and must be completed and returned to the Contracting Officer before starting work under this contract. Note: Electronic and digital signatures are prohibited.

b. Provisions of the SEC Regulation Concerning Conduct of Members and Employees and Former Members and Employees of the Commission expressly prohibit unauthorized disclosure and improper use of confidential or non-public information or documents. See 17 C.F .R. § 200.7353(b)(1) & (b)(2). The Contractor, and its employees, agents, subcontractors, and subcontractor personnel who will have access to confidential or non-public information or documents in the performance of the contract, agree to be bound by the provisions of Sections 200.735-3(b)(1) and 200.735-3(b)(2) of the SEC's Regulation Concerning Conduct and the terms set forth in the attached non-disclosure agreements (Attachments 1& 2). For purposes of this clause, "confidential or non-public information," is defined as information generated by or in the possession of the SEC that is commercially valuable, trade secret, market sensitive, proprietary, related to an SEC enforcement or examination matter, subject to privilege, protected by the Privacy Act (5 U.S.C. § 552a), or otherwise deemed confidential or non-public by an SEC division director or office head, and is not otherwise available to the public.

c. An officer or executive authorized to bind the Contractor shall execute the non-disclosure agreement (Attachment 1) on behalf of the Contractor and return it to the Contracting Officer prior to the Contractor commencing work on the contract. The Contractor shall submit to the Contracting Officer a list of its employees, agents, and subcontractors that will be authorized access to SEC information by virtue of performing the requirements set forth in this contract.

Each person identified on the list shall then sign the non-disclosure agreement on behalf of themselves (Attachment 2) and submit it to the Contracting Officer before commencing work on the contract.

d. The Contractor shall also ensure that all of its employees, agents, and subcontractors assigned to perform the requirements set forth in this contract adhere to the terms of the non-disclosure agreement, protecting all confidential or non-public information, and to not divulge to any unauthorized person. Assignment of staff who has not executed the non-disclosure agreement or failure to adhere to this statement shall result in action by the Contracting Officer, as deemed appropriate. Violation of this clause or the attached non-disclosure agreements by the Contractor, its employees, agents, subcontractors, or subcontractor personnel may result in default of the contract and/or civil suits and/or criminal prosecution.

6001.01 Restrictions on Use, Disclosure, and Duplication of Confidential and Non-Public Information (2-Nov-10)

Confidential or non-public information, for purposes of this clause includes but is not limited to, all financial, statistical, personnel and/or technical data which is furnished, produced, generated, or otherwise available to the Contractor, during the performance of this contract. Unless otherwise specified, confidential or non-public information shall not be used for purposes other than performance of work under this contract without the prior written consent of the Contracting

Officer. The Contractor, and its employees, agents, subcontractors, and subcontractor personnel are restricted from duplicating or disclosing confidential or non-public information, in whole or in part, outside the Securities and Exchange Commission (SEC) for purposes other than fulfillment of the requirements set forth in this contract. Any presentation of any confidential or non-public information, or any reports or material derived from confidential or non-public information shall be subject to review of the Contracting Officer prior to publication or dissemination. Any questions about whether information is confidential or non-public shall be referred to the Contracting Officer prior to use disclosure or duplication.

(End of clause)

6002.00 Type of Contract (June 2020)

This is a time and materials and/or firm-fixed price type contract/agreement.

6006.00 Conflicts of Interest (Feb 2019)

(a) General

Subpart 9.5 of the Federal Acquisition Regulation (FAR) 48 C.F.R. 9.5, prescribes responsibilities, general rules, and procedures for identifying, evaluating, and resolving organization conflicts of interest.

(b) Purpose

The purpose of this SEC Instruction (SECI) is to avoid, neutralize, or otherwise mitigate organizational conflicts of interest which might exist related to a Contractor's performance of work required by this contract. Such conflicts may arise in situations including, but not limited to:

(1) A Contractor's participation as an offeror, or representative of an offeror, in a procurement in which it has provided assistance in the preparation of the Government's requirements and specifications;

(2) A Contractor providing advisory assistance to the Government for a procurement in which the Contractor, or a firm which the Contractor represents, is an actual or potential offeror; and

(3) A Contractor's participation as an offeror, or representative of an offeror, in a procurement where the Contractor has obtained confidential or proprietary information relating to competing offers as a result of the Contractor's work on prior contracts.

(c) Definition

For the purposes of this SECI, the term "Contractor" means: the Contractor; any of the Contractor's parents, affiliates, or other entities in which the Contractor or such parents or affiliates have a financial interest; successors in interest to the Contractor or any of its parents or affiliates; proposed consultants or subcontractors at any tier; and employees thereof.

(d) Restrictions

The Contractor agrees:

(1) To remain ineligible to participate in any capacity (including participating as a prime contractor, subcontractor, or as the representative of another party) in offers, contracts, or subcontracts (whether solicited or unsolicited) that directly relate to the Contractor's performance of work under this contract.

(2) To execute, prior to beginning work on a contract, such Confidentiality Agreements, Non- Disclosure Agreements, or other documents which the Contracting Officer may, in their sole discretion, require in order to protect the proprietary nature or confidentiality of information provided by the Government or otherwise received by the Contractor in connection with its work under this contract.

(3) As otherwise provided in this contract, not to accept any compensation or any other form of payment from a broker, potential lessor, or any source other than the Government for services rendered under this contract, and to employ aggressive strategies to minimize the Government's lease costs where the Contractor would be entitled by common business practice to receive a real estate commission or any form of payment from a broker, potential lessor, or other party, for work performed under this contract.

(4) To immediately notify the Contracting Officer of any offer of compensation, other form of payment, or thing of value, made by a broker, potential lessor, or any source other than the Government to the Contractor related to services rendered under this Contract, regardless of whether such offer was made during Contractor's performance of work under a given contract or subsequent to Contractor's completion of work under such contract.

(5) Prior to the acceptance of a contract, request to immediately notify the Contracting Officer of any potential conflict of interest which would prevent or limit the Contractor's ability to perform the work required under the contract.

(6) To immediately notify the Contracting Officer of any conflict of interest discovered during the Contractor's performance of work pursuant to a Government contract; provided that the Contracting Officer shall have the right to impose such restrictions as they deem appropriate on Contractor's performance based on the existence of such a conflict or, if the Contracting Officer determines that such restrictions would not adequately address the conflict of interest at issue, to terminate the Contractor's performance of work under the contract at no cost to the Government.

(7) As otherwise provided in this contract, that if the Contractor declines to accept a task order request and subsequently participates (either directly or as a representative of another party) in a Government procurement action that was the subject of the task order request, then the fee which the Contractor would have been entitled to receive for such task order work or the fee actually paid by the Government for the task order's performance by another contractor, whichever is greater, shall be applied toward the Contractor's minimum order guarantee.

(8) That in the event that the Contractor knowingly withholds the existence of a conflict of interest from the Government, that the Contracting Officer may terminate this contract at no cost to the Government and any minimum guarantee(s) otherwise applicable to the Contractor will be forfeited; provided, that the foregoing shall be in addition to all other remedies and causes of action which the Government may have against the Contractor, including the suspension and/or debarment of the Contractor.

(9) To include this Conflict of Interest SEC Instruction, including this subparagraph, in all of the Contractor's subcontracts at all tiers (appropriately modified to preserve the Government's rights hereunder) which involve the performance of work by subcontractors in support of this contract.

(10) That, in addition to the remedies enumerated above, the Government may terminate this contract for cause in the event of the Contractor's breach of any of the above restrictions.

6007.00 Compliance with Regulations (June 2020)

a. The Contractor shall comply with all statutes, regulations, directives, instructions, and references applicable to the conduct of this acquisition as imposed by the Federal Government and the SEC, including, without limitation, those specified or referred to in this contract.

b. The Contractor and its employees performing work on-site at SEC facilities shall become acquainted with and shall comply with the rules and regulations of the SEC's facilities, including, but not limited to security, controlled access, personnel clearances, and conduct with respect to health and safety at the site, regardless of whether or not title to the facility is vested in the SEC.

6009.05 Contractor Personnel Entry on Duty (June 2020)

a. Included with this award are four forms: Contractor Data Form, Optional Form 306 (OF306) "Declaration of Federal Employment," FBI Fingerprint Privacy Act Form, and a Credit Release Form. The Contractor must ensure that their personnel complete and return these forms to the SEC. Contractor personnel must receive a favorable entry on duty determination rendered by the Personnel Security Branch (PERSEC) of the SEC before they may begin work at the SEC. It is the Contractor's responsibility to ensure that their personnel receive these forms and return them to the contracting officer's representative (COR) for the contract/award as quickly as possible. A delay in completing the forms may delay the SEC start date for the contract/award. Once PERSEC receives the completed forms from the COR, PERSEC will reach out to the Applicant to have their fingerprints enrolled for the FBI criminal history records check and to obtain a completed security questionnaire via the automated system Electronic Questionnaires for Investigations Processing (e-QIP). The applicant is provided 5 days to enroll fingerprints and complete the e-QIP. It is the Contractor's responsibility to ensure that their personnel are in compliance. E-mails about these two processes will be sent to the Contractor's personnel once they are enrolled in USAccess for fingerprints and in e-QIP for completion of the security questionnaire. The COR or contracting officer (CO) may contact the Contractor for assistance if he/she is unable to obtain this information from the Contractor's personnel.

b. Entry on Duty Check

Proposed contractor personnel ("Applicant") shall be subject to a complete entry on duty check, which will be performed by the SEC. The entry on duty check shall include a review of the completed OF-306 Form "Declaration for Federal Employment," e-QIP questionnaire, a credit history check, and a review of the Applicant's criminal history. This entry on duty check will determine the Applicant's ability to begin working on the contract/award. The Government reserves the right of final approval of Applicants.

c. The Applicant shall be given the opportunity to address the items which may have a negative impact on their entry on duty determination prior to that determination being rendered. They will be contacted via email by PERSEC and be offered an opportunity to explain the circumstances and offer mitigating information regarding any adverse information. This information will be considered when rendering the entry on duty determination. Failure to reply to the request for additional information will result in PERSEC utilizing the information available to make the decision.

d. No Applicant shall be assigned to the contract/award prior to contracting officer receiving approval of the entry on duty determination from PERSEC.

e. Background Check

Due to the sensitive nature of the information contained in SEC filings and concerns regarding the security and integrity of this information, the SEC may conduct a background check of an Applicant in addition to an entry on duty check. It shall be the responsibility of the Contractor and individual contractor personnel, throughout the life of this contract/award, to inform the SEC of any information that would change their background or entry on duty checks. The Contractor also agrees to include the substance of this instruction in any of its subcontracts.

f. In addition to the entry on duty checks, a background investigation will be required for an Applicant requiring physical and/or logical access to SEC space and/or technology. Applicants may already have the appropriate level of background investigation prior to onboarding with the SEC. If that is the case and the Applicant receives a favorable entry on duty determination, the Applicant's current favorably adjudicated background investigation will be reciprocally accepted by the SEC and the Applicant will not undergo any additional vetting. However, if a background investigation is needed, it will be scheduled by the SEC with the Department of Defense (DoD) Defense Counterintelligence and Security Agency (DCSA) following the issuance of the entry on duty determination. The background investigation will include additional checks and vetting which may include information on prior employments, education, residences, criminal history, personal references and an interview with the contractor.

g. The Applicant must have a completed background investigation which has been reciprocally accepted or favorably adjudicated by the SEC in order to begin or continue work on an SEC contract/award. In most cases, if negative, derogatory or questionable information is obtained during the background investigation process, the Applicant will be given a chance to provide documentation or an explanation. If an unfavorable determination is rendered, the COR will contact the Contractor and the Applicant will not be allowed to begin or continue work on the contract/award.

6010.00 Personnel and Contractor Responsibilities/Standards of Conduct (June 2020)

a. The Contractor shall provide all management, supervision, and skilled personnel required for the effective and efficient performance of this contract. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of this contract. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce is essential. Contractor employees, agents, and subcontractor personnel (collectively, "Contractor Personnel") are not employees of the Government.

b. The Contractor shall designate a primary POC to communicate with the COR.

c. The SEC has the right to require the removal of any Contractor personnel assigned to this contract, at any time, for any reason.

d. The Contractor shall select, supervise, and exercise control and direction over Contract Personnel under this contract. The SEC will not exercise any supervision over Contractor Personnel, but may, in coordination with Contractor management, provide sufficient direction to contractor personnel to ensure that the purposes of the contract are met and the government's interests are protected.

e. Contractor shall be responsible for:

1. Approving time cards of Contractor Personnel.

2. Approving leave requests of Contractor Personnel.

3. Conducting performance evaluations of Contractor Personnel.

4. Making hiring and firing decisions for Contractor Personnel.

5. Informing Contractor Personnel that they are not employees of the SEC and have not received an appointment in the federal service.

6. Informing Contractor Personnel that they are not to accept direction from employees of the SEC beyond that required to accomplish the purposes of the Contract.

7. Informing Contractor Personnel that deliverables must be marked with employer's logo or other marking legend (as appropriate to the deliverable) and it must be removable if the SEC elects to use the deliverable as SEC materials. This applies to reports, slides, and other documents called out in the contract as deliverables.

8. Informing Contractor Personnel that the Contractor is responsible for approval of their time cards, leave requests and performance evaluations, and for hiring and firing decisions.

9. Directing Contractor Personnel to identify themselves in their communications (and in their work product as appropriate) as contractors rather than SEC or Federal employees, and ensuring that they in fact do so.

10. Directing Contractor Personnel to display their distinguishing badges or other visible identification of their status as contractors at meetings with government or outside personnel.

11. Considering during their performance of the contract whether any actions they are taking would limit the ability of an SEC employee to exercise discretion on an inherently governmental function and bring such actions to the attention of the COR.

f. The Contractor is accountable to the SEC for the actions of its personnel. Contractor Personnel, when on-site at SEC facilities under this contract, shall only engage in duties specified in the statement of work, task order or other work statement, and not in other business, or political, charitable, or other duties. The Contractor shall not recruit on SEC premises or otherwise act to disrupt official SEC business. The Contractor shall be responsible when Contractor Personnel are on site at the SEC for maintaining satisfactory standards of competency, conduct, appearance, and integrity, and shall be responsible for taking such disciplinary action with respect to Contractor Personnel as may be necessary. Contractor Personnel are expected to adhere to standards of conduct that reflect credit on themselves, the contractor, the SEC and the Federal Government.

6010.06 Work Hours and Alternate Work Schedules (June 2020)

a. The core work hours at SEC Headquarters and Regional Offices are Monday - Friday, 10:00 a.m. to 3:00 p.m., in the office's respective time zone. Unless otherwise specified, the Contractor is responsible for conducting business during the core hours, except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings.

b. All contractor personnel assigned to be on-site for this contract shall only occupy SEC workspace during hours that are established by the Contracting Officer's Representative and the Contracting Officer, and when Government personnel will be on-site to oversee contractor personnel.

c. Alternate Work Schedules (AWS) may be requested and approved on a case-by-case basis and in writing by the Contracting Officer's Representative or Contracting Officer, except for contracts subject to the Service Contract Act of 1965 and the Fair Labor Standards Act. The Program Manager will submit all requests for AWS to the COR for review. AWS may be ended at any time at the SEC's sole discretion without any contractual rights being implicated and without affecting cost or performance.

6012.01 Compliance with Security Regulations, Policies, and Procedures (14-Mar-12)

The Contractor shall be responsible for compliance by its employees with SEC security regulations, policies, and procedures. This includes safekeeping, wearing, and visibility of identification badges. The SEC will issue Contractor identification badges to on-site Contractor personnel, and the badges shall be visible at all times while employees are on SEC premises. The Contractor shall provide all requested information (the SEC will provide forms to the Contractor at time of award) required to facilitate issuance of identification badges and shall conform to applicable regulations concerning the use and possession of the badges. The Contractor shall be responsible for ensuring that all identification badges issued to the Contractor employees are returned within forty-eight (48) hours following the completion of the contract, relocation, or termination of an employee and/or request of the Contracting Officer or the Contracting Officer's Representative (COR).

6012.02 SEC 508 Requirements (June 2020)

a. Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, all Information and Communication Technology (ICT) products and services developed, acquired, maintained, and/or used under this contract/order must comply with the Information and Communication Technology Accessibility Provisions set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the "Access Board") in FAR 39.203(a). The complete text of Section 508 Final Provisions can be accessed at Section 508 Law.

b. All ICT products must comply with the following requirements. Descriptions of the requirements are viewable at the link Section 508 Standards.

c. Offerors that fail to demonstrate compliance with the above requirements, may be eliminated from further consideration for award.

d. The offeror shall indicate for each line item in the schedule whether each product or service is compliant or non-compliant with the accessibility requirements at 36 CFR 1194 using a Voluntary Product Accessibility Template (VPAT 2.4). Further, the solicitation response must indicate where full details of compliance can be found (e.g., vendor's website or other exact location).

e. Offerors to this solicitation must provide any additional detailed information necessary for determining applicable Section 508 standards conformance. If an offeror claims its products and/or services, including ICT deliverables such as electronic documents, web content or electronic reports, meet applicable Section 508 standards, and it is later determined by the Government - i.e., after award of a contract/order, that products and/or services delivered do not conform to the described accessibility, remediation of the products and/or services to the level of conformance specified in the contract will be the responsibility of the offeror at its expense.

6012.05 Personally Identifiable Information (PII) in Contracts to Design, Develop, Operate, or Maintain a System of Records (June 2019)

A Contractor that designs, develops, operates or maintains a system of records on behalf of the agency to accomplish an agency function or otherwise maintains Personally Identifiable Information (PII) in the performance of this contract shall, prior to taking such action, comply with the following requirements:

a) The Contractor shall have established policies and procedures in place to safeguard PII. The policies and procedures shall provide the Contractor's processes for identifying, assessing and mitigating privacy risks associated with PII. The policies and procedures shall also cover training of employees on their roles and responsibilities for safeguarding PII and reporting suspected or confirmed compromise of PII.

b) The Contractor shall also ensure that all processes, procedures and equipment associated with PII comply with all laws, regulations, and security mandates as defined by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-61 Revision 2 or the latest revision, and SEC policies developed to safeguard the confidentially, integrity and availability of SEC data that may contain PII. In support of these requirements, the Contractor shall have:

- policies, procedures, and mechanisms designed to restrict access to SEC data on Contractor, subcontractor, or SEC inter/intra agency partner systems exclusively to authorized personnel;

- policies, procedures, and mechanisms that prevent transmission or disclosure of SEC data to an unauthorized party;

- policies, procedures, and mechanisms that ensure SEC data on portable devices are encrypted using methods compliant with Federal Information Processing Standard 140-2; and

- policies, procedures, and mechanisms that ensure SEC data transmitted across public networks (i.e., the Internet) by the Contractor, or its employees, agents or subcontractors, are protected using secure communications, including the use of Transport Layer Security (TLS) protocol and the Advanced Encryption Standard (AES) 256 bit encryption algorithm.

c) The Contractor shall make its privacy policies and procedures that describe administrative, physical, and technical safeguards to protect PII available for review by the SEC Office of Information Security within 10 business days of request.

d) The Contractor shall ensure that those individuals adhere to the Contractor's policies and procedures relating to PII and to SEC-prescribed policies and procedures for the safe handling of SEC PII, including privacy and security training requirements and privacy incident management.

e) The Contractor's employees, agents, and subcontractors shall immediately alert the SEC of any event, including the suspected or confirmed loss of PII. Notification must be made to the SEC of a breach as soon as practicable, but no later than twenty-four (24) hours after the Contractor becomes aware of it by contacting the SEC Service Desk at (202)551-4357. The Contractor shall act in accordance with its policies and procedures in the event of any suspected loss of PII and shall support the SEC's investigation and resolution of reported incidents as requested by the SEC. For purposes of this Instruction, a "suspected loss of PII" shall be interpreted liberally to mean any situation in which the loss of PII or unapproved access to PII is deemed a reasonable possibility.

f) Return or Destruction of PII. At any time during the term of this contract at the SEC's written request or upon the termination or expiration of this contract for any reason, unless otherwise required by law to be retained, the Contractor shall, and shall instruct all authorized personnel to, promptly return to the SEC all copies, whether in written, electronic or other form or media, of PII in its possession or the possession of such authorized personnel, or securely dispose of all such copies, and certify in writing to the SEC that such PII has been returned to SEC or disposed of securely. The destruction of PII shall be performed according to NIST approved methods.

6013.01 Federal Requirements, Security, and Accessibility for Information Systems (8-Jul- 15)

Information Systems Authorization to Operate (ATO): Information systems containing SEC data or operated on behalf of the SEC are required to have an authorization to operate, based on National Institutes of Standards and Technology (NIST) Special Publication (SP) 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach. The security assessment entails a review of minimum security controls, documented in NIST SP 800-53, Revision 4 (and subsequent revisions as finalized by NIST); documentation of a system security plan, based on NIST SP 800-18; and remediation of weaknesses that are documented in a plan of action and milestone (POA&M) document, as required by Office of Management and Budget (OMB) Memorandum 02-01. The ATO will also have to cover any alternate processing facilities or a subcontractor handling SEC information or operating systems on behalf of the SEC. Additional Federal governance includes but is not limited to the following:

-Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d) for system accessibility requirements

-Office of Management and Budget (OMB) Circular A-11, Revised, "Preparation, Submission and Execution of the Budget" (July 2003)

-OMB Circular A-130, Revised, "Management of Federal Information Resources" (November 2000)

-OMB Federal Enterprise Architecture Program Management Office (FEAPMO) Reference Models and Circular A-11 Guidance. www.feapmo.gov.

-Privacy Act of 1974, Public Law 93-579 (5 U.S.C. 552a), as amended

-The E-Government Act of 2002, Public Law 107-347

-OMB Memorandum M-15-01, Fiscal Year 2014-2015 Guidance on Improving Federal Information Security and Privacy Management Practices, October 3, 2014 (and subsequent updates by OMB)

-OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002, September 30, 2003

-OMB Federal Risk and Authorization Management Program (FedRAMP) Policy Memo, December 8, 2011

-Federal Information Processing Standard (FIPS) Publication (PUB) 201, Personal Identity Verification (PIV) of Federal Employees and Contractors, March 2006

-FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006

-FIPS PUB 197, Advanced Encryption Standard, November 2001

-FIPS PUB 140-2, Security Requirements for Cryptographic Modules

National Institute for Standards and Technology (NIST), Special Publication (SP) 800-122, Guide for Protecting the Confidentiality of Personally Identifiable Information (PII), April 2010

-NIST SP 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010

-NIST SP 800-115, Technical Guide to Information Security Testing and Assessment Sept 2008

-NIST SP 800-100, Information Security Handbook: A Guide for Managers, Oct 2006

-NIST SP 800-95, Guide to Secure Web Services, Aug 2007

-NIST SP 800-92, Guide to Computer Security Log Management, Sep 2006

-NIST SP 800-88, Revision 1, Guidelines for Media Sanitization, December 2014

-NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide, August 2012

-NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013

-NIST SP 800-53A, Revision 4, Guide for Assessing the Security Controls in Federal Information Systems, December 2014

-NIST SP 800-44 Version 2, Guidelines on Securing Public Web Servers, Sep 2007

-NIST SP 800-30, Revision 1, Guide for Conducting Risk Assessments, September 2012

-NIST SP 800-34, Revision 1, Contingency Planning Guide for Federal Information Systems, May 2010

-NIST SP 800-18, Revision 1, Guide for Developing Security Plans for Federal Information Systems, February 2006

-NIST SP 800-70, Revision 2, National Checklist Program for IT Products: Guidelines for Checklist Users and Developers, February 2011

-NIST SP 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations, September 2011

Cloud-Based Assessment: Any cloud-based components shall be assessed in accordance with FedRAMP and must have already received a provisional authorization from either the Joint

Authorization Board or another U.S. Federal Executive Branch Agency. Additional Federal requirements for cloud computing are documented in NIST SPs 800-144, 800-145 and 800-146.

Security Issue Review: The Contractor shall remediate problems identified during any security testing activities. All significant issues (typically those rated as HIGH and often those rated as MEDIUM) should be resolved before the system is allowed to go into production and handle SEC information. The Contractor shall resolve as many security audit-related Plan of Action and Milestones (POA&M) items as possible and within a reasonable timeframe, based on risk guidance from the designated authorizing official. The Contractor shall document the resolution and provide supporting evidence of changes. The Contractor shall schedule a conference meeting with the Contracting Officer's Representative (COR), OIT Security Group staff, and relevant SEC staff to review the state of the POA&M resolutions. The Contractor shall provide the SEC with the number and description of resolved POA&M items identified in the security review along with supporting evidence. SEC's OIT Security Group may choose to perform additional technical testing to validate resolution.

Security Assessment: OIT Security Team performs Security Assessment and Authorization (SA&A) for a product to be deployed. This process is designed to allow the SEC to identify any risks associated with the system and either mitigate them or formally accept any residual risk.

This requirement is based on the NIST SP 800 series of documents and includes:

-Enumeration - activity aimed at identifying devices and components and cross-referencing with provided inventory lists;

-Vulnerability Scanning - performs network-based vulnerability assessment of customer's servers, workstations, and any other network device or appliance in scope. The assessment will identify vulnerabilities associated with network services, operating systems, and devices that are un-patched or have out-of-date software security patches;

-Penetration Testing - attempts to exploit weaknesses identified from vulnerability scanning to verify legitimate findings, eliminate false-positives, and determine the extent of the vulnerability and potential remediation steps that may be taken; and

-Functional Testing - Perform specific tests, examinations, and inspections against NIST SP 800- 53 controls not tested by the other activities.

The Contractor shall provide the Security Team with: (1) a system demonstration; (2) test user IDs; (3) Access to the system; and (4) System Security Plan (SSP) (5) additional documents as required under the NIST SP 800 series to support Security Assessment & Authorization activities. The Contractor shall provide ongoing support to update the required SA&A documentation. The OIT Security Team provides the test reports. Any cloud-based components will have to be assessed in accordance with FedRAMP and must have already received a provisional authorization from either the Joint Authorization Board or another U.S. Federal Executive Branch Agency. Additional Federal requirements for cloud computing are documented in NIST SPs 800-144, 800-145 and 800-146.

Documentation Updates: The Contractor shall maintain and update system specifications and/or documentation, including system inventory, to reflect changes made during maintenance or update. The Contractor shall maintain system documentation to reflect the configuration of software releases and commercial off-the shelf (COTS) products. The Contractor shall maintain documents and specifications in compliance with standards for formatting and content and produce standardized documentation, i.e., User Guides, Requirements Documents, On-line Help, Standard Operating Procedures (SOP), system specifications, audit documentation practices and procedures, and other documentation. The documentation shall be available to the COR for review and inspections throughout the system development life cycle (SDLC); updates shall be submitted to the COR for review and approval.

System Development Plan (SDP): The Contractor shall develop, maintain, and execute an SDP which shall include the policies, procedures, standards, instructions, forms, and/or checklists needed to analyze, design, implement, test, and deploy the required application systems. In the SDP, the Contractor shall explain how the Contractor's corporate system development standards and practices will be applied and discuss its development methodology in detail. The SDP shall also describe the development methodology used by the Contractor. The SDP will be benchmarked against NIST SP 800-64, Revision 2, Security Considerations in the System Development Life Cycle, October 2008 and NIST SP 800-160, Systems Security Engineering:

An Integrated Approach to Building Trustworthy Resilient Systems (after becoming final).

Disaster Recovery: Contractor shall create and implement policies, processes and procedures to address the information system security requirements needed for disaster recovery in the event of a disruption of the information service(s) provided. This includes regular review and test of a disaster recovery plan(s) related to recovering the information service(s) provided. Results of all disaster recovery plan tests, exercises or actual events, including but not limited to after-action reports, lessons learned and plan updates will be made available to SEC for review within ten

(10) working days of a request by SEC. Furthermore, SEC will be provided a point of contact for disaster recovery planning and exercise for the information service(s) provided. Contractor shall invite participation from the SEC during tests to ensure SEC is able to access the system(s) and service(s) provided.

Approval of Subcontracts: The Government reserves the right to approve or disapprove any subcontract and any subcontractor selected. Therefore, the Contractor shall obtain the Contracting Officer's approval of all subcontractors and provide copies of subcontracts for any work required by this contract. Subcontractors shall be bound by the same information protection requirements, because they handle the SEC's data. Like the Contractor, the Subcontractor's environment will have to undergo security assessment and authorization, including a facility only used for disaster recovery or alternate processing.

Common Security Configurations: Common security configurations are published on NIST's web site http://checklists.nist.gov. NIST's Computer Security Division website is located at http://csrc.nist.gov. For more information about the security content automation program, see http://nvd.nist.gov/scap.cfm. NIST Special Publication 800-70, Revision 2, National Checklist

Program for IT Products: Guidelines for Checklist Users and Developers, February 2011, is located at http://csrc.nist.gov/publications/nistpubs/800-70-rev2/SP800-70-rev2.pdf.

Non-public Information and Personally Identifiable Information (PII): The Contractor shall have established policies and procedures in place to safeguard any non-public information, including Personally Identifiable Information (PII) and Information in Identifiable Form (IIF) collected on behalf of the SEC. The policies and procedures shall provide the Contractor's processes for identifying, assessing and mitigating privacy risks associated with PII and IIF. The policies and procedures shall also cover training of employees on their roles and responsibilities for safeguarding PII and IIF collected on behalf of the SEC and incident management of suspected or confirmed loss of PII and/or IIF collected on behalf of the SEC in accordance with OMB's Memorandum Recommendations for Identity Theft Related Data Breach Notification, September 20, 2006, and OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007. The Contractor shall provide a copy of its privacy policies to the Contracting Officer for review and comment by SEC's OIT Security Group. The Contractor shall also provide a copy of the policies and procedures (or otherwise make such policies and procedures available) to all of its employees, agents, and subcontractors assigned to perform the requirements set forth in this contract. The Contractor shall ensure that those individuals adhere to the Contractor's policies and procedures relating to PII, IIF and to Federal requirements and SEC-prescribed policies and procedures for the safe handling of PII and IIF collected on behalf of the SEC, including privacy and security training requirements and privacy incident management. Data stored on portable media shall be encrypted using technology compliant with Federal Information Processing Standard 140-2, using NIST validated products.

The Contractor's employees, agents, and subcontractors shall immediately alert the SEC of any event, including the suspected or confirmed loss of non-public information, including PII collected on behalf of the SEC, that could potentially affect the privacy rights of individuals or which violates any federal law, regulation, mandate or requirement as defined in NIST SP 800- 122 by contacting the SEC Information Systems Security point of contact and the SEC Incident Response Team at *CSIRC@sec.gov. The Contractor shall act in accordance with its policies and procedures in the event of any suspected loss of SEC PII and shall support the SEC's investigation and resolution of reported incidents as requested by the SEC. For purposes of this Clause, a "suspected loss of PII" shall be interpreted liberally to mean any situation in which the loss of PII or unapproved access to PII is deemed a reasonable possibility.

Security Requirements for Transmitting Non-public Information, Including PII. Contractors, subcontractors, and SEC inter/intra agency partners handling electronic non-public information, including personally identifiable information (PII) or information in identifiable form (IIF) on behalf of the SEC will be required to meet the following defined Federal requirements when transmitting such data across public networks (i.e., the Internet), storing such data on portable media or transporting data for backup & recovery purposes.

Contractors shall ensure that all processes, procedures and equipment associated with non-public information, including PII or IIF, collected on behalf of the SEC comply with all laws, regulations, and security mandates as defined by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-61 Revision 2 as well as U.S. government and SEC policies developed to safeguard the confidentially, integrity and availability of data collected on behalf of the SEC that may contain non-public information, including PII or IIF. In support of these requirements, the Contractor shall have:

-Policies, procedures, and mechanisms designed to restrict access to SEC data on Contractor, subcontractor, or SEC inter/intra agency partner systems exclusively to authorized personnel;

-Policies, procedures, and mechanisms that prevent transmission or disclosure of SEC data to an unauthorized party;

-Policies, procedures, and mechanisms that ensure SEC data on portable devices are encrypted using methods compliant with Federal Information Processing Standard 140-2 (validated); and

-Policies, procedures, and mechanisms that ensure SEC data transmitted between the Contractor and the SEC are protected using encryption compliant with Federal Information Processing Standard 140-2 (validated).

The Contractor shall provide quarterly assessments to the SEC demonstrating that these policies, procedures, and mechanisms continue to be functional, that the Contractor is compliant with these requirements, and that these requirements are effective. SEC reserves the right to verify stated compliance.

Analysis and Evaluation: The Contractor shall fully cooperate with any risk analysis or other evaluation of the Program conducted by the SEC or its representatives, including any evaluation of the Program under the SEC's SA&A Program. Such cooperation shall include, but is not limited to, undergoing an independent audit or risk analysis by the SEC or by a third-party organization approved by the SEC, with such audits to occur not less than once every three (3) years or when there is a significant change to the system. Such evaluations, risk analyses, or audits shall include security tests on the Contractor's devices and the review of the Contractor's own policies, procedures, security scans, tests, or reviews, which the Contractor agrees to provide to the SEC or its representatives upon request.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .