HE Rail Statement of Work.pdf
PDF 1 MB Posted
- Attached to
- High Energy Rail Inspection Systems Federal contract opportunity
- Solicitation number
- 70B03C20R00000011
About this file
This request for proposal solicits bids for high energy rail inspection systems for U.S. Customs and Border Protection. The indefinite delivery, indefinite quantity contract has a total ceiling of $379 million over a five year ordering period with potential options extending up to ten years. The acquisition is subject to the Trade Agreements Act and includes sustainability requirements. Vendors must submit proposals by September 30, 2020, and CBP intends to award one or more contracts by that same date. The systems must include production, installation, and maintenance of rail inspection equipment as well as warranty and training provisions. Multiple awards are anticipated from this full and open competitive solicitation open to all responsible vendors.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A0002.pdf | ||
| Questions and Answers.pdf | ||
| A0001.pdf | ||
| Past Performance Questionnaire.pdf | ||
| Technology Readiness Questionnaire.pdf | ||
| HE Rail SOW Appendix D-CAVSS Guide.pdf | ||
| HE Rail SOW Appendix A - FRD.pdf | ||
| HE Rail SOW Appendix C - Tech Worksheet.pdf | ||
| RFP 70B03C20R00000011.pdf | ||
| HE Rail SOW Appendix B - RDE.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work
High Energy Rail Inspection System i
THIS PAGE INTENTIONALLY LEFT BLANK
ii
Table of Contents Table of Contents .......................................................................................................... ii High Energy Rail Inspection System Statement of Work
1. Scope of Effort
1.1 Program Organization
Government Management Organization
1.2 Purpose
1.3 Background
2. Program Objectives
2.1 Operational Objectives
3. Applicable Documents
3.1 Federal Regulations and Publications·
3.2 National Standards
3.3 DHS/CBP Documents
4. Requirements
4.1 Requirement Definitions:
4.2 General Requirements
Performance Requirements for HE Rail Systems
Imaging System Equipment and Equipment Installation
Sources & Detectors
5. Computers
5.1 Adherence to DHS and CBP IT Security Policies
5.2 Computer Security
Identification and Authentication (Levels of Access)
Identification and Authentication (Passwords)
Access Control
Auditing
6. Information Technology Security
6.1 Basic Requirements
6.2 Security Authorization
6.3 DHS Security Policy Requirement
6.4 Compliance with DHS Binding Operational Directive 17-01
6.5 Encryption Compliance Requirement
6.6 Security Review
6.7 Access to Unclassified Facilities, Information Technology (IT) iii
Resources, and Sensitive Information
6.8 Personal Identity Verification of Contractor Personnel
6.9 Security Requirements for Unclassified Information Technology Resources
6.10 Contractor Employee Access
6.11 Enterprise Architecture (EA) Compliance
6.12 Supply Chain Risk Management Terms and Conditions
6.13 IPv6
6.14 CBP Contractor Handling PII Level
6.15 Personal Identification Verification (PIV) Credential Compliance
6.16 DHS Information Technology Portfolio Alignment
7. Accessibility Requirements (Section 508 Compliance)
8. Warranty
9. Reliability, Availability and Maintainability Requirements
9.1 Basic System Reliability Requirements – Inherent Availability (Ai)
Mean Time Between Failures (MTBF)
Mean Time to Repair (MTTR)
Life Cycle Expectation
9.2 Predictive Reliability, Availability, and Maintainability Analysis
9.3 Classification of Reliability Critical Items
9.4 Corrosion Control
9.5 Quality Assurance/Quality Control Plan
10. Sustainment and Maintenance
10.1 Service Support Availability Requirements – Operational Availability (Ao) 43
10.2 Service Calls and Work Orders
Work Completion Form (WCF)
Work Site Cleanliness
Conditional but Operational Status
10.3 Maintenance
Preventive Maintenance
Corrective Maintenance
Monthly Preventive Maintenance Schedule
Corrosion Control Maintenance
10.4 On-Demand Services (Technology Refresh, Other Maintenance, and iv
Other Support Services)
Engineering Services
Ad Hoc Reports
Site Surveys
Provisioning Support
Retrofit/Replacement Support
10.5 Systems Integration Support and Services
10.6 Relocation Services
10.7 Site Work
10.8 Disposal Services
10.9 Emergency Services
10.10 Corrective and Replacement Services
10.11 On Demand Training
10.12 Remote Maintenance Monitoring
10.13 Configuration Management
10.14 Configuration Baseline
10.15 Technical Documentation
10.16 Management of the Technical Documentation
10.17 Engineering Change Proposals
10.18 Configuration Changes
10.19 Configuration Control Reports
10.20 Interchangeability
10.21 Accessibility
10.22 System Safety Program
Radiation Safety
Radiation Safety Design Review
Radiological Survey Report
Annual Radiation Survey and Report
Safety Plan
Hazardous Materials
11. System Training and Manuals
11.1 Operator Training and Analyst Training
11.2 Train the Trainer
11.3 Technical Manuals
v
11.4 System User’s Manual
11.5 Operational/Storage Checklist
11.6 Service and Maintenance Manual
11.7 Ownership
12. Site Preparation, Engineering Services and Support
12.1 Site Surveys
12.2 Engineering Assessment
12.3 Construction Drawings
12.4 Engineering Assessment and Construction Drawings Approval Process
Table 1: Engineering Assessment and Drawings Approval Process
12.5 Site Preparation
13. System Installation
13.1 Power Requirements and Conditioning
13.2 As-Built Drawings
13.3 Construction Manager Log
13.4 Operator Booth
Prefabricated Booths
Operator Booth Quality Control Documentation (e.g. Fabrication Inspection Plan)
DATA/LAN and Voice Connectivity
Work Center
Workstation Integration and Interface
13.5 Lighting
Exterior Booth Lighting
Operating Area Lighting
Inspection Area Lighting
Other Area Lighting
13.6 Fencing
13.7 Junction Boxes and Other Enclosures
13.8 Walls
14. Testing
14.1 Site Accepting Testing
14.2 First Article Testing
Documentation Deliverables vi
Project Management Plan
Reliability Prediction Report
Hazardous Materials List
Equipment Installation Data
Monthly Progress Report
Training Materials
System User’s Manual
Service and Maintenance Manual
Contractor Technical Reference Documentation
Quality Assurance Plan
Acceptance Test Plan
Radiological Survey, Radiation Survey and Leak Test Reports
Annual Configuration Report (Configuration List)
Technical Documentation Package
Certified (As-Built) Construction Drawings
Construction Manager’s Log
Warranty
Safety Plan
Site Survey Report / Engineering Assessment / Construction Drawings / Installation Plan and Checklist
IT Security Plan
Interface Control Document for Radiation Detection Equipment Integration
15. RAIL ENVIRONMENT
16. INSPECTION OPERATIONS
Figure1: Notional Example of an Operator’s GUI
Figure 2: Notional Example of an Analyst’s GUI with integrated RDE
Figure 3: Nominal HE Rail Inspection System Diagram vii
Version Date Comments
V1 V1.1 V1.2
07/01/19 07/17/19
07/18/19
1st Draft Incorporated 1st round of comments
Incorporated 2nd round of comments
High Energy Rail Inspection System Statement of Work
1. Scope of Effort
The contractor shall deploy a fleet of High Energy (HE) Rail Systems, which include radiographic imaging, radio frequency identification (RFID), and other ancillary capabilities that operate concurrently via a command and display interface, to inspect the rail cargo at CBP designated locations. The HE Rail Inspection System shall include provisions to integrate, interface with, and operate within close proximity, a government tested and approved passive Radiation Portal Monitor (RPM). The contractor shall provide program management, materials (e.g. hardware, software, consumables, and documentation), facilities (e.g. architectural and engineering designs, site civil works, infrastructure preparations, and administrative/work spaces), and life-cycle sustainment services (e.g. warranty, pre-planned product improvement/technology enhancements, training services and materials, and performance-based maintenance).
1.1 Program Organization
This program is under the technical direction of the LS-NII Contracting Officer Representative (COR) assigned to the CBP Office of Information and Technology (OIT) Laboratories and Scientific Services Directorate (LSSD), Interdiction Technology Branch (ITB) in coordination with CBP Enterprise Network and Technology Support (ENTS) Integrated Logistics Division (ILD).
Government Management Organization
CBP management of this program will be accomplished through the CBP Non- Intrusive Inspection Program Management Office (NII PMO) for system acquisition, delivery, and acceptance. CBP Enterprise Network and Technology Support (ENTS) Integrated Logistics Division (ILD) will manage Warranty, Operations and Maintenance (O&M), and On-Demand Services. CBP will coordinate with the Contractor to ensure successful system integration. CBP Office of Training Development (OTD) will approve training development. CBP OTD and ENTS Technology Training Support Branch (TTSB) will coordinate operator training presentations. CBP Human Resources Management (HRM) will approve radiation safety.
1.2 Purpose
For the contractor to produce, deliver, and deploy a High Energy (HE) Rail Inspection System fleet and provide life-cycle sustainment, maintenance, and training for U.S. Customs and Border Protection (CBP).
1.3 Background
As part of the CBP layered enforcement strategy, rail cargo is examined by Law enforcement personnel via Non-Intrusive Inspection (NII) systems for contraband, illegal narcotics, weapons of mass destruction, and instruments of terror. The NII systems currently in use are nearing the end of their useful life. CBP’s long-term goal is to improve the effectiveness and efficiency of NII operations by increasing system performance, expanding the use of automated tools and processes, and integrating multiple sensors, technologies, and data platforms. CBP’s HE Rail system concept of operations (CONOPS) is included in this SOW. CBP intends to replace existing rail NII systems with integrated systems comprised of radiographic imaging, railcar identification, site security, provisions to integrate passive Radiation Detection Equipment (RDE), and display and control subsystems that improves CBP inspection and interdiction operations near U.S.
rail border crossings.
2. Program Objectives
a. Deploy a mature HE Rail solution to up to 50 CBP designated locations.
b. Sustain HE Rail operations for at least ten (10) years after deployment.
c. Develop separate training course materials and provide training services for CBP training personnel, and HE Rail operators, and analysts.
d. Provide a flexible and scalable HE Rail solution with modular, independent components and the ability to support multiple operating configurations (e.g., multiple analysts, and combined and distributed functions and operations).
e. Enable pre-planned and ad hoc product improvement by deploying CBP OIT compliant hardware, operating systems, and data formats (e.g., ANSI N42.42, NIEM N.25, .tiff files, UFF) that will allow for:
(1) Future integration and interoperability with the CBP Data Network and CBP law enforcement databases.
(2) Future remote system operations, health monitoring, maintenance diagnostics, and IT security updates.
(3) Continuous evolution of hardware (e.g., components, sensors, and IT equipment) and software (e.g., operating systems, graphical user interfaces (GUI), algorithms) to easily adopt new and emerging technologies and capabilities.
f. Integrate passive RDE subsystems in the future that are government tested and approved solutions.
g. If desired, acquire technical data rights so that the Government can maintain and modify the procured systems using Government personnel and third party contractors as desired.
2.1 Operational Objectives
The CBP Rail CONOPs demands rail-specific system capabilities for the NII Radiographic imaging, conveyance cameras, display and control subsystems (see Appendix B). The HE Rail Inspection System shall employ radiographic imaging, security cameras, conveyance cameras, railcar identification, display and control, and provisions to integrate government tested and approved passive RDE subsystems.
a. Radiographic Imaging Subsystem: Provide NII Radiographic imaging capabilities to inspect every cargo container and railcar with high-penetration photons that meet the all performance parameters, generate scans quickly, produce images with high contrast sensitivity and spatial resolution, and discriminate organic and heavy metal materials (e.g. low-Z and high-Z).
b. Railcar Identification Subsystem: Provide railcar identification capabilities via high-resolution cameras and RFID technology to capture unique identifiers on the exterior of railcars and containers and RFID tag information and to link to the image and future radiation scan data by railcar or cargo container.
c. Conveyance Cameras Subsystem: Provide cameras to monitor the sides of the railcars (top, left, right, and bottom) and to capture a still image of each conveyance in the inspection record.
d. Display/Control Subsystem: Provides operator controls and tailored GUIs for system operation, to include the following:
(1) An operator GUI to control and monitor all subsystems (Radiographic
Imaging, Conveyance Cameras, Railcar Identification).
(2) An analyst GUI to review and analyze NII Radiographic images with the corresponding RFID and conveyance camera images for each conveyance.
(3) Future advanced image analysis capabilities (e.g., algorithms and sensors) to assist operators in identifying potential contraband and anomalies present in cargo and distinguishing laden and empty railcars/containers.
(4) Consolidated reports of inspection data, queried by data element (e.g. train, railcar, date and time, CBP operator or analyst, importer, etc.).
(5) Customizable autonomous data management.
e. The system, including subsystems, shall be fully operational in the extreme weather conditions present on the U.S-Canadian and U.S.-Mexican border (e.g.
extreme hot or cold, arid or condensing air conditions, night and day time use, etc.)—customized modifications based on deployment location are acceptable.
f. The contractor shall ensure the system is operationally available at low sustainment costs throughout the 10-year system sustainment period.
g. The contractor shall ensure CBP operators, analysts, and trainers are trained to operate the system, to analyze images and data to interdict contraband, and to train other CBP operators and analysts.
h. The contractor shall provide sufficient day, and thermal IR cameras, that are compliant with CBP Border Security Deployment Program (BSDP) requirements (See Appendix D CAVSS Design Guide standards), separate from those used for railcar ID to provide 360 degree coverage of the safety control area, including the portion under the train, and both sides of the approach and departure zones for northbound or southbound train movement to detect humans in the safety control area or on the sides or top of railcars.
3. Applicable Documents Documents cited shall be referenced and used as called for in this Statement of Work, Appendix A, B, C, and D and the Data Item Descriptions.
3.1 Federal Regulations and Publications·
a. Code of Federal Regulations, 10 CFR 20, Standards for
Protection against Radiation, 2012, (NRC).
b. Code of Federal Regulations, 10 CFR 39.35, Leak Testing of
Sealed Sources, 2012, (NRC).
c. Code of Federal Regulations, 10 CFR 71, Packaging and Transportation of Radioactive Materials, 2012, (NRC).
d. Code of Federal Regulations, 21 CFR 179, Irradiation in the Production, Processing and Handling of Food, 2012, (FDA).
e. Code of Federal Regulations, 29 CFR 1910, Occupational Safety and Health Standards, 2012, (OSHA).
f. Code of Federal Regulations, 49 CFR 172, Hazardous Materials, Etc., 2012, (DOT)
g. U. S. Department of Transportation Federal Highway Administration Bridge Formula Weights August 2006 FHWA-
HOP-06-105
(http://www.ops.fhwa.dot.gov/publications/publications.htm#f a).
Note: The regulations can be accessed by going to: http://ecfr.gpoaccess.gov.
3.2 National Standards
a. American National Standards Institute, ANSI/IEEE N42.41, Minimum Performance Criteria for Active Interrogation Systems Used for Homeland Security, 2007.
b. American National Standards Institute, ANSI/IEEE N42.46, Determination of the Imaging Performance of X-Ray and Gamma-Ray Systems for Cargo and Vehicle Security Screening, 2008.
http://www.ops.fhwa.dot.gov/publications/publications.htm#fa) http://www.ops.fhwa.dot.gov/publications/publications.htm#fa) http://ecfr.gpoaccess.gov/
c. American National Standards Institute, ANSl/HPS N43.3, General Radiation Safety - Installations Using Non-Medical X- Ray and Sealed Gamma-Ray Sources, Energies up to 10 MeV, 2008.
d. American National Standards Institute, ANSl/HPS N43.14, Radiation Safety for Active Interrogation Systems for Security Screening of Cargo, Energies up to 100 MeV, 2011.
e. National Fire Protection Association, NFPA 79, Electrical Standards for Industrial Machinery, 2007.
f. Federal Information Processing Standards Publication (FIPS PUB), Number 140-2, Security Requirements for Cryptographic Modules,
g. National Fire Protection Association, NFPA 70, Recommended Practice for Electrical Equipment Maintenance, 2010.
3.3 DHS/CBP Documents
a. CBP HB 1400-05D Information Systems Security Policies and Procedures
Handbook Version 7.0, November 16, 2017 (or latest update)
b. DHS-CBP N.25, Standard Messaging Protocol, Version 1.5.0.6, 2010
c. CBP Interface Control Document, Version 5, Jan 2013.
d. DHS Sensitive Systems Policy Directive 4300A, Version 13.1, July 27, 2017
(or latest update).
e. CBP Training Development Standards, 2008.
f. CBP Instructor-Led Training (ILT) Style Guide, 2009.
g. CBP Instructor-Led Training (ILT) Process Guide, 2008.
4. Requirements
The Contractor shall perform all tasks within this SOW. The Contractor shall abide by all applicable Federal regulations, national standards, and U.S.
Department of Homeland Security (DHS) and CBP documents in performing all tasks. Requirements for this effort shall include the fabrication, integration, test, delivery, training, logistics, and on-demand support of HE Rail Systems. CBP will deploy these systems at various CBP POEs (land border crossings along the Southwest/Northern borders, seaports and airports) within the United States as designated by CBP. CBP may identify specific deployment sites and schedules within the Request for Proposal (RFP).
4.1 Requirement Definitions:
1. Threshold: The minimum level of operational performance that the
Government is willing to accept is considered a threshold value.
2. Objective: A level of performance that significantly improves mission performance, safety, or supportability beyond that of the threshold value, and represents the desired yield for system performance is considered an objective.
3. Objective values are not required, but can be defined to provide guidance to the Contractor with respect to areas where increased capability is of interest to the government. If Objectives are defined, the interval between the Objective and Threshold values for a given parameter is the government program manager's (PM) trade-space.
4. Single Requirement: Some requirements will have only a single parameter value and, when this is the case, these values are thresholds.
4.2 General Requirements
Each HE Rail System shall meet the requirements defined in this SOW. The Contractor shall perform the work necessary to develop, test and deliver the procured equipment. The Contractor shall also provide warranty, logistics, on-demand services and training in support of these LS-NII systems as identified in this SOW.
Performance Requirements for HE Rail Systems
Appendix A Functional Requirements Document (FRD) contains requirements for HE Rail.
Imaging System Equipment and Equipment Installation
In accordance with this Statement of Work, the Contractor shall deliver HE Rail Systems incorporating radiographic imaging technology. The Contractor shall deliver HE Rail Systems designed to best commercial practices designed to highest industry standards.
Sources & Detectors
As part of the HE Rail System, the Contractor shall deliver an imaging source or sources, which shall incorporate X-Ray transmission that are capable of meeting the Performance Specifications as described in Appendix A.
5. Computers
As part of the system, the Contractor shall provide computers and server(s) to meet the SOW.
5.1 Adherence to DHS and CBP IT Security Policies
The computer and ancillary IT systems that comprise the Non-Intrusive Inspection system are required to adhere to DHS and CBP IT security policies, procedures, and requirements detailed in the below documents or any subsequent, replacement or revised publication.
• U.S. Customs and Border Protection HB 1400-05D Information Systems Security Policies and Procedures Version 6.01 May 17, 2016
• U.S. Department of Homeland Security DHS Sensitive Systems Policy Directive 4300A Version 13.1 July 27, 2017
U.S. Department of Homeland Security DHS Sensitive Systems Handbook Version 12.0 November 15, 2015.
5.2 Computer Security
All system computers and software programs in the system shall have the following security features incorporated. Computers shall be equipped with Operating Systems of Windows 10 64bit; capable of upgrade to latest version.
The system shall have a wireless technology that can be encrypted in accordance with DHS 4300A policy. The wireless capability shall have the ability to be disabled when not in use.
Identification and Authentication (Levels of Access) The Contractor shall provide three levels of CBP User access (Operator Level 1, Operator Level 2, and Administrator). Operator Level 1 shall be able to perform all system functions except copying and deleting images or Data Sets. Operator Level 1 shall not have access to User Accounts. Operator Level 2 (Supervisor) shall be able to perform all Operator Level 1 functions plus be able to create and delete Operator Level 1 accounts, copy and delete images and data set files, and reset Level 1 and Level 2 passwords. Operator Level 2 shall have access to Operator Level 1 Accounts. The Administrator shall be able to perform all Operator Level 1 and Level 2 functions plus have access to all Accounts. The Administrator shall be able to create, edit and delete all Accounts. The Contractor shall create a simplified procedure for the Administrator and Operator Level 2 to create, edit and delete User Accounts. Operator Level 1 and Level 2 shall not have access to Windows except for those hard drives that have IDS stored on them or the external drives from which an image may be imported or an image or IDS may be exported or copied. The CBP Administrator Account shall have access to Windows Operating System.
Identification and Authentication (Passwords) A. All passwords used to access the HE Rail system for operation are required to be Strong Passwords. Strong passwords have the following requirements:
1. Are at least 16 characters (Unicode and ASCII) in length
2. Comply with the DHS hardening guides for operating systems and the configuration guides for applications. In the absence of guidance, the ISSO will determine the appropriate password complexity based on the level of risk.
3. The system will force all passwords to contain three of the four following types of characters
• Uppercase Alphabetic characters
• Lowercase Alphabetic characters
• Special characters
• Numbers
4. The system will check the user account passwords are not the same as any of the user’s previous 8 passwords
5. Strong pass phrases, if used in addition to or instead of passwords, follow the same guidelines as above.
6. The system will check the strong passwords is not the same as the
User identification (ID) and if it is will force the user to change the password.
B. The HE Rail system must have the ability to:
1. The system shall automatically disable user accounts that have not been used in 45 days.
2. Passwords shall not be set to the null string.
3. Automatically require the user to change their password every 90 days.
4. Password Storage – The system shall store all user account passwords in encrypted form in accordance to DHS/CBP encryption requirements
Access Control
A. Unique User Accounts – The system shall enable all users to have unique account identifiers, including separate identifiers for operator accounts and administrator accounts.
B. Automatic Account Lockout – The system shall lock a user account for twenty (20) minutes after three consecutive failed logon attempts.
C. Automatic Session Termination – The system shall lock the user login session after twenty (20) minutes of inactivity. The system shall require the user to authenticate with the user account password to regain system access after the system lock. After 60 minutes of inactivity, the system shall log the user account out of the system.
D. Warning Banner – The DHS Chief Information Security Officer (CISO) stipulates that a warning banner statement be displayed on all DHS systems during user account logon. The system shall prompt the user to accept the current language before they can authenticate with the user id and user password to access the system. The current language required follows:
• You are accessing a U.S. Government information system, which includes
(1) this computer, (2) this computer network, (3) all computers connected to this network and (4) all devices and storage media attached to this network or to a computer on this network. This information system is provided for U.S. Government-authorized use only.
• Unauthorized or improper use or access of this system may result in disciplinary action, as well as civil and criminal penalties.
• By using this information system, you understand and consent to the following:
o You have no reasonable expectation of privacy when you use this information system; this includes any communications or data transiting, stored on, originated from or directed to this information system. At any time, and for any lawful government purpose, the government may monitor, intercept, search and seize any communication or data transiting, stored on, originated from or directed to or from this information system.
o The government may disclose or use any communications or data transiting, stored on, originated from or directed to or from this information system for any lawful government purpose.
o You are NOT authorized to process classified information on this information system.
Auditing
A. Audit Records – System will retain audit records sufficient in detail to facilitate the reconstruction of events if compromise or malfunction occurs. Audit records shall contain at least the following information:
1. Identity of each user and device accessing or attempting to access the system
2. Time and date of the access and the logoff
3. Activities that might modify, bypass, or negate information security safeguards
4. Security – relevant actions associated with processing
5. All activities performed using an administrator account/identity B. Audit Record Access – Audit records and audit logs shall be protected from unauthorized access, modification, or destruction.
C. Audit Record Retention – Audit records shall be maintained on the system for a minimum of ninety (90) days. Audit records shall be preserved for a period of 7 years as part of managing records for each system to allow audit information to be placed online for analysis with reasonable ease.
D. Audit Reduction / Report Generation – The system will provide an audit reduction and report generation capability that:
1. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents
2. Without altering the original content or time ordering of audit records
E. The system will have the capability to tag each scan with the user name who conducted it. The user name and time shall be displayed with the image and the IDS.
6. Information Technology Security
The Contractor shall adhere to all DHS and CBP IT security policies and the basic requirements, security authorization, encryption compliance, and pass security review.
HSAR Special clauses shall apply; Safeguarding of Sensitive Information (MAR 2015) and Information Technology Security and Privacy Training (MAR 2015).
Applicability of requirements will be determined by Government.
6.1 Basic Requirements
The Contractor shall adhere to all DHS and CBP IT security policies, including the guidelines and policies stated in the DHS Sensitive Systems Policy Directive 4300A Version 13.1, or any subsequent, replacement or revised publication. This policy mandates DHS organizational elements, including Contractors, follow guidelines outlined in the DHS MD 4300A, DHS Sensitive Systems Handbook, version 12.01, with attachments or any subsequent, replacement or revised publication.
DHS Directive 4300A, Section 3.2., Basic Requirements outlines the management, operational and technical baseline security requirements (BLSR) for DHS Components to ensure confidentiality, integrity, availability, authenticity and non-repudiation of sensitive information systems. The 4300A Handbook provides greater detail of the BLSRs, including the roles and responsibilities associated with each.
CBP will provide personnel with the appropriate clearance levels to support the security certification/accreditation processes under this Contract in accordance with DHS MD 4300A, DHS Sensitive Systems Policy and Handbook, paragraph 4.1.1.d. During all systems development life cycle (SDLC) phases of CBP systems, CBP personnel will develop documentation and provide any required information for all levels of classification in support of the certification/accreditation process. In addition, all security certification/accreditation will be performed using the DHS certification/accreditation process, methodology and tools.
6.2 Security Authorization
a. A Security Authorization of any infrastructure directly in support of the DHS information system shall be performed by the Contractor as a general support system (GSS) ‘prior to DHS occupancy to characterize the network, identify threats, identify vulnerabilities, analyze existing and planned security controls, determine likelihood of threat, analyze impact, determine risk, recommend controls, perform remediation on identified deficiencies, and document the results. The Security Authorization shall be performed in accordance with the DHS Security Policy and the controls provided by the hosting provider shall be equal to or stronger than the Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, Section 3, security categorization of the DHS information system.
b. At the beginning of the contract, and annually thereafter, the Contractor shall provide the results of an independent assessment and verification of security controls in the Contractor’s format. The independent assessment and verification shall apply the same standards that DHS applies in the Security Authorization Process of its information systems. Any deficiencies noted during this assessment shall be provided to the COR for entry into the DHS’ Plan of Action and Milestone (POA&M) Management Process. The Contractor shall use the DHS’ POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies shall be corrected within the timeframes dictated by the DHS POA&M Management Process. Contractor procedures shall be subject to periodic, unannounced assessments by DHS officials. The physical aspects associated with Contractor activities shall also be subject to such assessments.
On a periodic basis, the DHS and its Components, including the DHS Office of Inspector General, may choose to evaluate any or all of the security controls implemented by the Contractor under these clauses. Evaluation could include, but is not limited to vulnerability scanning. The DHS and its Components reserve the right to conduct audits at their discretion. With ten working days’ notice, at the request of the Government, the Contractor shall fully cooperate and facilitate in a
Government-sponsored security control assessment at each location wherein DHS information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of DHS, including those initiated by the Office of the Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) determined by DHS in the event of a security incident.
6.3 DHS Security Policy Requirement
All hardware, software, and services provided under this task order must be compliant with DHS 4300A DHS Sensitive System Policy, and the DHS 4300A Sensitive Systems Handbook, and the CBP HB1400-05d.
6.4 Compliance with DHS Binding Operational Directive 17-01
All hardware, software, and services provided under this procurement must be compliant with the Department of Homeland Security National Protection and Programs Directorate Binding Operational Directive 17-01.
The full text of the operational directive can be found at:
https://www.gpo.gov/fdsys/pkg/FR-2017-09-19/pdf/2017-19838.pdf All hardware, software, and services provided under this procurement must not use any information security products, solutions, and services supplied, directly or indirectly, by AO Kaspersky Lab or affiliated companies.
6.5 Encryption Compliance Requirement
All systems drives provided under this task must be DHS encryption compliant. The following methods are acceptable for encrypting sensitive information:
• Products using FIPS 197 Advanced Encryption Standard (AES), Chapter 5, algorithms with at least 256 bit encryption that has been validated under FIPS 140-2 Standards for Security Requirements for Cryptographic Modules.
• National Security Agency (NSA) Type 2 or Type 1 encryption
• Public Key Infrastructure (PKI) (see paragraph 5.5.2.1 of the Department of Homeland Security (DHS) IT Security Program Handbook (DHS Management Directive (MD) 4300A) for Sensitive Systems).
6.6 Security Review
The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS including the organization of the DHS Office of the Chief Information Officer, Office of Inspector General, the CBP Chief Information Security Officer, authorized Contracting Officer’s Representative (COR), and other Government oversight organizations, access to the Contractor’s and https://www.gpo.gov/fdsys/pkg/FR-2017-09-19/pdf/2017-19838.pdf subcontractor’s facilities, installations, operations, documentation, databases, and personnel used in the performance of this contract. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of Government oversight organizations external to the DHS. The Contractor shall provide access to the extent necessary for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of DHS/CBP data or the function of computer systems operated on behalf of DHS/CBP, and to preserve evidence of computer crime.
6.7 Access to Unclassified Facilities, Information Technology (IT)
Resources, and Sensitive Information IT resources, and sensitive information during the acquisition process and contract performance are essential to the DHS mission. DHS Management Directive (MD)
11042.1 Safeguarding Sensitive But Unclassified (For Official Use Only) Information paragraph 6, describes how Contractors must handle sensitive but unclassified information. DHS Sensitive Systems Policy Directive 4300A, paragraph 3.4, and DHS Sensitive Systems Handbook, MD 4300.A Information Technology Security Program, Chapter 4, prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering Contractors specifically for all Task Orders that require access to DHS facilities, IT resources or sensitive information. Contractors shall not use or redistribute any DHS information processed, stored, or transmitted by the Contractor except as specified in the task order.
Contractors who require access to the DHS network, such as when conducting remote maintenance, require a background investigation in accordance with DHS Sensitive Systems Handbook, MD 4300.A, paragraph 4.1.1.d.
6.8 Personal Identity Verification of Contractor Personnel
a. The Contractor shall comply with agency personal identity verification procedures identified in the contract that implement Homeland Security Presidential Directive-12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors, paragraph 3, Office of Management and Budget (OMB) guidance M-05-24, Appendix A, chapters 3 and 4, and Federal Information Processing Standards Publication (FIPS PUB) Number 201-2, Personnel Identity Verification of Federal Employees and Contractors, Section 2.
b. The Contractor shall insert this clause in all subcontracts when the subcontractor is required to have routine physical access to a federally -controlled facility or routine access to a Federally-controlled information system.
6.9 Security Requirements for Unclassified Information Technology
Resources
a. The Contractor shall be responsible for Information Technology (IT) security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency’s mission.
b. The Contractor shall provide, implement, and maintain an IT Security Plan (see DID A025). This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.
(b.1) Within 30 days after contract award, the Contractor shall submit for approval its IT Security Plan in the Contractor’s format, which shall be consistent with and further detail the approach contained in the officer’s proposal. The plan, as approved by the Contracting Officer, shall be incorporated into the contract as a compliance document.
(b.2) The Contractor’s IT Security Plan shall comply with Federal laws that include, but are not limited to, the Computer Security Act of 1987 (40 USC 1441 et seq.), sections 5 and 6; the Federal Information Security Management Act (44 USC 3554 (b)) of 2014;
and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130, Appendix III, A.3.b(2).
(b.3) The security plan shall specifically include instructions regarding handling and protecting sensitive information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.
c. Examples of tasks that require security provisions include— (c.1) Acquisition, transmission or analysis of data owned by DHS with significant replacement cost should the Contractor’s copy be corrupted; and (c.2) Access to DHS networks or computers at a level beyond that granted the general public (e.g., such as bypassing a firewall).
d. At the expiration of the contract, the Contractor shall return all sensitive DHS information and IT resources provided to the Contractor during the contract, and certify that all non-public DHS information has been purged from any Contractor- owned system. Components shall conduct reviews to ensure that the security requirements in the contract are implemented and enforced.
e. Within 6 months after contract award, the Contractor shall submit written proof, in the Contractor’s format, of IT Security accreditation to DHS for approval by the DHS Contracting Officer. Accreditation will proceed according to the criteria of the DHS Sensitive System Policy Publication, 4300A, Section 3.9, or any replacement publication, which the Contracting Officer will provide upon request. This accreditation will include a final security plan, risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan. This accreditation, when accepted by the Contracting Officer, shall be incorporated into the contract as a compliance document. The Contractor shall comply with the approved accreditation documentation.
6.10 Contractor Employee Access
a. Sensitive Information, as used in this Chapter, means any information, the loss, misuse, disclosure, or unauthorized access to or modification of which could adversely affect the national or homeland security interest, or the conduct of Federal programs, or the privacy to which individuals are entitled under the Privacy Act (5 USC 552A (b)) but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(a.1) Protected Critical Infrastructure Information (PCll) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), 6 USC 133 (a) (1) as amended, the implementing regulations thereto (6 CFR Part 29) Protected Critical Infrastructure Information, as amended, the applicable PCll Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCll Program Manager or his/her designee);
(a.2) Sensitive Security Information (SSI), as defined in 49 CFR 1520(5)(b), Protection of Sensitive Security Information, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(a.3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest;
and, (a.4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
b. “Information Technology Resources” include, but are not limited to, computer equipment, networking equipment, telecommunications equipment, cabling, network drives, computer drives, network software, computer software, software programs, intranet sites, and internet sites.
c. Contractor employees working on this contract must complete such forms as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability in accordance with DHS Sensitive Systems Handbook, MD 4300.A, paragraph 4.1.1.d. The Contractor shall submit the completed forms as directed by the Contracting Officer. Upon the Contracting Officer’s request, the Contractor’s employees shall be fingerprinted, or subject to other investigations as required. All Contractor employees requiring recurring access to Government facilities or access to sensitive information or IT resources are required to have a favorably adjudicated background investigation prior to commencing work on this contract unless this requirement is waived under Departmental procedures.
d. The Contracting Officer may require the Contractor to prohibit individuals from working on the contract if the government deems their initial or continued employment contrary to the public interest for any reason, including, but not limited to, carelessness, insubordination, incompetence, or security concerns.
e. Work under this contract may involve access to sensitive information.
Therefore, the Contractor shall not disclose, orally or in writing, any sensitive information to any person unless authorized in writing by the Contracting Officer. For those Contractor employees authorized access to sensitive information, the Contractor shall ensure that these persons receive training concerning the protection and disclosure of sensitive information both during and after contract performance.
f. The Contractor shall include the substance of this clause in all subcontracts at any tier where the subcontractor may have access to Government facilities, sensitive information, or resources.
Alternate I (SEP 2012) When the contract will require Contractor employees to have access to Information Technology (IT) resources, add the following paragraphs:
(g) Before receiving access to IT resources under this contract the individual must receive a security briefing, which the Contracting Officer's Technical Representative (COTR) will arrange, and complete any nondisclosure agreement furnished by DHS.
(h) The Contractor shall have access only to those areas of DHS information technology resources explicitly stated in this contract or approved by the COTR in writing as necessary for performance of the work under this contract. Any attempts by Contractor personnel to gain access to any information technology resources not expressly authorized by the statement of work, other terms and conditions in this contract, or as approved in writing by the COTR, is strictly prohibited. In the event of violation of this provision, DHS will take appropriate actions with regard to the contract and the individual(s) involved.
(i) Contractor access to DHS networks from a remote location is a temporary privilege for mutual convenience while the Contractor performs business for the DHS Component. It is not a right, a guarantee of access, a condition of the contract, or Government Furnished Equipment (GFE).
(j) Contractor access will be terminated for unauthorized use. The Contractor agrees to hold and save DHS harmless from any unauthorized use and agrees not to request additional time or money under the contract for any delays resulting from unauthorized use or access.
(k) Non-U.S. citizens shall not be authorized to access or assist in the development, operation, management or maintenance of Department IT systems under the contract, unless a waiver has been granted by the Head of the Component or designee, with the concurrence of both the Department's Chief Security Officer (CSO) and the Chief Information Officer (CIO) or their designees. Within DHS Headquarters, the waiver may be granted only with the approval of both the CSO and the CIO or their designees. In order for a waiver to be granted:
(1) There must be a compelling reason for using this individual as opposed to a U.S.
citizen; and
(2) The waiver must be in the best interest of the Government.
(l) Contractors shall identify in their proposals the names and citizenship of all non-U.S.
citizens proposed to work under the contract. Any additions or deletions of non-U.S.
citizens after contract award shall also be reported to the Contracting Officer.
SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to:
name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .