RFQ_06C19Q0260_SOW.docx

DOCX document 73 KB Posted

Attached to
Fingerprinting Services Federal contract opportunity
Solicitation number
70B06C19Q00000260
Issued by
Department of Homeland Security Customs and Border Protection

About this file

Statement of Work

View the file

Other files for this federal contract opportunity

Other files attached to Fingerprinting Services, newest first.
File Type Posted
RFQ_06C19Q0260_Amendment_2.docx DOCX document
RFQ_06C19Q0260_Amendment_1.pdf PDF
RFQ_06C19Q0260_Fingerprint_Price_Submission.xls XLS spreadsheet
RFQ_06C19Q0260_CBP_DHS_Aditional_Clauses.docx DOCX document
RFQ_06C19Q0260_Questions_and_Responses.xlsx XLSX spreadsheet
RFQ_06C19Q0260_.pdf PDF
RFQ_06C19Q0260_Clauses.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. DEPARTMENT OF HOMELAND SECURITY

U.S. CUSTOMS and BORDER PROTECTION

Requirements Document

FOR

Office of Human Resources Management

ELECTRONIC FINGERPRINT COLLECTION PROCESS

Table of Contents

1. BACKGROUND2
2. SCOPE2
3. APPLICABLE DOCUMENTS2
4. GENERAL REQUIREMENTS2
4.1. CONTRACTOR FURNISHED EQUIPMENT2
4.2. FINGERPRINT FACILITIES3
5. TASKS3
5.1. TASK 1 – REQUESTS FOR SERVICES3
5.2. TASK 2 – SCHEDULING FINGERPRINTS4
5.3. TASK 4 – PROCESSING AND SUBMITTING FINGERPRINT RESULTS5
5.4. TASK 6 - WEB SERVICES AND DATA REPORTING REQUIREMENTS5
6. DELIVERABLES6
6.1. SECURITY DELIVERABLES6
6.2. QUALITY CONTROL PLAN AND PERFORMANCE MEASURES7
6.3. REPORTS8
6.4. NON-DISCLOSURE AGREEMENT8
6.5. SMALL AND SMALL DISADVANTAGED BUSINESS SUBCONTRACTING PLAN (IF THE CONTRACTOR IS A LARGE BUSINESS)8
7. GOVERNMENT-FURNISHED INFORMATION AND EQUIPMENT (GFE/GFI)8
8. TERM OF CONTRACT9
9. PLACE OF PERFORMANCE9
10. SECURITY9
11. OTHER CONSIDERATIONS12
11.1. TRANSITION PROCESS13
11.2. HOURS OF OPERATION13
11.3. MEETINGS AND TRAVEL13
11.4. CONTRACTOR PERSONNEL13
11.5. INVOICING14

1. BACKGROUND

1.1. As a component of DHS, CBP is responsible for protecting our Nation’s borders in order to prevent terrorists and terrorist weapons from entering the United States, while facilitating the flow of legitimate trade and travel. CBP is also responsible for apprehending individuals attempting to enter the U.S. illegally; stemming the flow of drugs and other contraband; protecting our agricultural and economic interests from harmful pests and diseases; protecting American business from theft of their intellectual property; and regulating and facilitating international trade, collecting import duties, and enforcing U.S. trade laws. The Office of Human Resources Management (HRM) CBP Hiring Center (HC) supports the recruitment, hiring, and retention of qualified employees for various positions within CBP.

1.2. All CBP employees, contractors, consultants, and applicants, are required to undergo a background investigation to include fingerprints that are required for a National Agency Check (NAC).

2. SCOPE

2.1. The purpose of this document is to provide the necessary requirements to procure automated electronic fingerprint services for all CBP employees, contractors, consultants, and applicants.

2.2. The Contractor shall provide all fingerprinting facilities, all fingerprinting personnel, electronic communications of all fingerprint data, and all equipment necessary for completing an automated electronic fingerprint process.

2.3. The Contractor shall provide the following services in compliance with this Statement of Work (SOW):

2.3.1. Schedule of all participants for fingerprinting in coordination with the Hiring Center and the Office of Professional Responsibility (OPR) / Personnel Security Division (PSD) as requested by the Contracting Officer’s Representative (COR).

2.3.2. Capture the electronic fingerprints for all CBP employees, contractors, consultants, and applicants requiring fingerprints as part of their background investigation NAC requirements.

2.3.3. Maintain a web-based data system, accessible remotely by CBP personnel per the Web Services and reporting requirements in this SOW.

2.3.4. Provide all trained personnel to administer fingerprint functions at facilities nationwide as specified in this SOW. The Contractor shall provide the fingerprinting sites in each of the forty-eight (48) continental United States as well as Alaska, Hawaii, Washington, D.C., Puerto Rico, the U.S. Virgin Islands, Guam, and Saipan.

2.3.5. The services under this contract are subject to the needs of the Government and to the availability of funds; the volume of electronic fingerprints ordered is contingent upon the number of new hires approved by Congress, current CBP employees and contractors requiring reinvestigations, and the number of CBP periodic reinvestigations required, and specific hiring requirements. CBP shall make a good faith effort to keep the Contractor informed of anticipated or impending needs for services. The volume of requests sent by CBP to the Contractor shall vary widely by day – CBP may send up to several thousand requests in one day which will need to be completed within the timelines specified in this SOW.

3. APPLICABLE DOCUMENTS

3.1. Electronic fingerprints collected under this Contract shall be consistent with the requirements in this Statement of Work

3.1.1. Compliance with DHS Security Policy

All hardware, software, and services provided under this contract must be compliant with:

DHS 4300A Sensitive Systems Handbook https://www.dhs.gov/publication/dhs-4300a-sensitive-systems- handbook

3.1.1.1. U.S. Customs and Border Protection (CBP) Information Systems Security Policies and Procedures Handbook, CIS HB 1400-05D (This document will be provided after award) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information https://www.dhs.gov/publication/dhs-handbook-safeguarding-sensitive-pii

3.1.1.2. OMB Memorandum 07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007 https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2007/m07-16.pdf

3.1.1.3. U.S. Customs and Border Protection (CBP) Information Security Handbook, Office of Professional Responsibility (OPR), HB 1400-04A (This document will be provided after award)

3.1.1.4. Privacy Act of 1974, 5 U.S.C. § 552a

4. GENERAL REQUIREMENTS

4.1. Contractor Furnished Equipment

4.1.1. To ensure that classified information, entrusted to private industry, is properly safeguarded, CBP requires that contractors who will require access to classified information in the completion of their contractual responsibilities be processed for security clearances in accordance with the requirements stipulated in the National Industrial Security Program Operating Manual (NISPOM).

4.1.2. To ensure consistent collection and submission of electronic fingerprints, the Contractor must coordinate with the sponsoring facility security officer (FSO) to register their equipment with CBP and the Office of Professional Responsibility:

4.1.2.1. Hardware: Console or desk top computer;

4.1.2.2. FBI certified printer;

4.1.2.3. Camera;

4.1.2.4. Flatbed scanner;

4.1.2.5. Driver license reader;

4.1.2.6. Signature pad;

4.2. Fingerprint Facilities

4.2.1. The Contractor shall provide fingerprinting service in each of the forty-eight (48) Continental United States and in Alaska, Hawaii, Washington DC, Puerto Rico, the U.S. Virgin Islands, Guam, and Saipan. The Contractor shall provide fingerprint services within a sixty (60) highway-mile radius of the employee or candidate’s zip code to meet CBP’s background investigation timeline and other requirements addressed in this SOW.

4.2.2. If the Contractor is unable to schedule an appointment within the required timelines because a facility is not available within a 60 (sixty) highway-mile commuting radius, the Contractor shall notify the COR within one (1) business day of the initial request for services from CBP. The Contractor shall then be provided two (2) additional business days to locate an acceptable facility.

4.2.2.1. If the Contractor is unable to locate an acceptable facility within the sixty (60) highway-mile radius, the Contractor shall obtain approval from the COR to:

4.2.2.1.1. Pay at the Contractor’s expense the employee, contractor, potential employee or candidate’s travel expenses to an acceptable facility that is outside of the sixty (60) highway-mile radius.

4.2.3. The Contractor shall ensure that all the fingerprint locations meet the requirements of the Occupational Safety and Health Act (see Applicable Documents in this SOW).

4.2.4. Fingerprint Facility Requirements

4.2.4.1. Any firm or business under contract with CBP that requires access to classified Information must possess a facility security clearance commensurate with the level of access required. This includes any firm or business entity that requires access to classified information to prepare a response to a request for proposal (RFP) or a request for bid and/or in performance of a classified contract.

4.2.4.2. Firms that do not possess a facility security clearance, or the requisite level of facility security clearance, must be sponsored for a DHS facility security clearance when a determination has been made by the CBP program office that the contract effort will require access to classified information. CBP offices must submit relevant sponsorship requests for facility security clearances to OPR/SMD for processing through DSS.

4.2.4.3. Facility security clearances for subcontracts must be sponsored and processed by the prime contract in accordance with the NISPOM. DSS will conduct a risk assessment for all contracts that require contractors to store, process, or access classified CBP information, systems, or property at a contractor facility to identify countermeasures and ensure such countermeasures are implemented prior to the contractor gaining control of CBP material.

5. TASKS

5.1. Task 1 – Requests for Services

5.1.1. On a daily basis, or more frequently when available, CBP shall send via Excel file or via web services information regarding requests for services to be completed. Specific data items included and the format of this file shall be determined by CBP upon award of this contract. The file shall contain the following types of requests:

5.1.1.1. Fingerprint requirements;

5.1.1.2. Employee, Contractor, Consultant, and Applicant contact information changes;

5.1.1.3. Cancellation of requests for employees, contractors, consultants, and applicants who are removed from the process.

5.1.2. Requests shall be rejected by the Contractor and not processed for the following reasons including, but not limited to:

5.1.2.1. Duplicate requirement requests and,

5.1.2.2. Incorrect data formatting.

5.1.3. The Contractor shall provide a summary of requests processed and rejected within two (2) hours of receipt of the request. This summary shall include, at a minimum:

5.1.3.1. Number of fingerprint requests processed (i.e., contact information changes, and cancellation/discontinuation of scheduling);

5.1.3.2. Number of fingerprint requests processed at each location;

5.1.3.3. Number of requests not scheduled or completed; and,

5.1.3.4. For rejected requests only:

5.1.3.4.1. Employee, Contractor and Candidate name and CBP identification number.

5.1.3.4.2. Fingerprint date; and,

5.1.3.4.3. Reason for rejection.

5.2. Task 2 – Scheduling Fingerprints

5.2.1. The Contractor shall provide a standard script of language for use in the scheduling process to the COR within fifteen (15) days of contract award. The script shall be approved by the COR prior to use.

5.2.2. The contractor shall provide scheduling access to a web based system on a 24 hour 7 days per week, 365 days per year basis.

5.2.2.1. In addition to the requirements above, standard script language shall include:

5.2.2.1.1. Instruction to the potential employee, contractor candidate on the necessary items required for the fingerprint process.

5.2.3. The Contractor shall be notified by CBP on a daily basis via vendor provided web-based portal or electronic exchange/web services regarding the fingerprint requests to be scheduled. The following data will be provided:

5.2.3.1. Employee, Contractor, and Candidate name, contact information (including up to three (3) phone numbers and one (1) email address), and current address for scheduling location purposes;

5.2.3.2. CBP’s fingerprint identification numbers, and candidate identification numbers (including CBP-specific candidate ID number and/or social security number);

5.2.3.3. Position; and,

5.2.3.4. Employee, Contractor, and Candidate address changes, and candidates that need to be removed from the scheduling process as they are no longer being considered for the position.

5.2.3.4.1. Employees, contractors, consultants, and applicants that are no longer being considered by, on contract with, or a current employee of CBP shall not be fingerprinted.

5.2.4. Within one (1) business day of receiving the fingerprint request, the Contractor shall identify the potential facility for the applicant, employee, contractor, or consultant to have their fingerprints captured and make the first contact attempt to schedule the process.

5.2.5. The Contractor shall provide the applicant, employee, contractor, or consultant with a unique barcode or ID number that they are expected to provide at their appointment along with two forms of government issued identification.

5.2.6. The Contractor shall use telephone/voicemail, email communication, and SMS text messaging when attempting to contact the candidate to schedule the fingerprint requirement.

5.2.7. Within three (3) business days of the initial request, the Contractor shall schedule the fingerprints with the employee, applicant, or candidate and the facility to be administered as follows:

5.2.7.1. The Contractor shall offer fingerprint appointments a minimum of five (5) days per week between the hours of 7:00 am and 7:00 pm in all time zones.

5.2.7.2. Fingerprinting shall be administered within ten (10) business days of the request from CBP.

5.2.8. If the Contractor is unable to schedule an appointment within the required timeline, the Contractor shall notify the COR within twenty-four (24) hours of making the determination via the Contractor’s web-based portal

5.2.8.1. “Hard to reach” employees, contractors, consultants, or applicants are individuals whom the Contractor has been unable to reach after a minimum of three (3) documented attempts, on three (3) separate days, using all telephone numbers and email addresses available. The Contractor shall not close requests for at least two (2) business days following the third attempt to contact the candidate.

5.2.8.1.1. The Contractor shall make a minimum total of three (3) contact attempts on three (3) separate days using all provided telephone numbers and email addresses. These contact attempts shall be made at different times of the day before identifying a candidate as “Hard to Reach.”

5.2.8.1.2. The Contractor shall make, at a minimum, one (1) contact attempt using each method of communication provided by CBP before identifying a candidate as “Hard to Reach.”

5.2.8.2. The Contractor shall inform the COR via web services when a requested service is unable to be scheduled. Notification shall be sent within twenty-four (24) hours of making the determination that the service cannot be scheduled. The reasons for failure to schedule a service shall be clearly documented. Examples include: refusal to schedule; employee, contractor or candidate is unable to complete fingerprinting within the specified time frame; candidate is “Hard to Reach”; candidate is no longer interested in the position, is on leave, or is on TDY

5.2.9. Within twenty-four (24) hours of scheduling the appointment, the Contractor shall send the employee, contractor or candidate an email providing the appointment information, facility location, and any items the candidate is required to complete and bring to the appointment. The Contractor’s standardized email language shall be provided to the COR within ten (10) business days of award and shall be approved by the COR prior to use.

5.2.10. One (1) business day prior to the appointment date, the Contractor shall send the employee, contractor or candidate a reminder email and SMS text message providing, at a minimum, the scheduled appointment information, facility location, and a reminder to complete and bring the CHHQ to the appointment. The email language/text message shall be provided to the COR during transition in and shall be approved by the COR prior to use.

5.2.11. If the employee, contractor or candidate does not attend the scheduled appointment without prior notification to the Contractor, the candidate is deemed a “No Show.” At the time, the Contractor documents the No Show in the Contractor’s automated system, an email shall be sent to the employee, contractor or candidate providing instructions to contact HC for applicants and OPR for employees, contractors, and consultants due to the No Show. The email language shall be provided to the COR during transition in and shall be approved by the COR prior to use.

5.3. Task 4 – Processing and Submitting Fingerprint Results

5.3.1. The Contractor shall provide CBP with the electronic transfer of fingerprints in a prescribed file format to the delegated system for processing and forwarding to the Office of Personnel Management (OPM):

5.3.1.1. The Contractor shall provide a web service delivered document indicating the number of fingerprints transmitted to the delegated system on a daily basis.

5.3.2. The Contractor will only transfer the file once OPR/PSD has approved their release via vendor web-based portal.

5.3.3. All documentation shall be forwarded electronically to CBP via web services as soon as submitted to the delegated system without error and confirmation of receipt has been received.

5.3.4. Daily transmission of fingerprints shall be provided via the Contractor’s automated system within one (1) business day of the capture date.

5.3.5. The Contractor shall retain electronic copies of all fingerprint files up to and after contract completion to the extent required to comply with this SOW’s document retention requirement.

5.4. Task 6 - Web Services and Data Reporting Requirements

5.4.1. The Contractor shall maintain a web-based data system, accessible remotely by CBP personnel that enable the user to chronicle all attempted and actual communication between the contractor and the candidate, as well as fingerprint status. The data system shall have the capability to allow the Contractor to input candidate information and date of fingerprint capture, and for CBP to retrieve those results. Additionally, the system shall have the capability to produce ad hoc, weekly, and monthly reports for capturing the status of fingerprint capture and scheduling status.

5.4.2. The Contractor shall electronically exchange fingerprint status with CBP. Data sent via web services and in the web portal shall be in real-time. This electronic exchange of fingerprint information includes, but shall not be limited to:

5.4.2.1. All scheduling data;

5.4.2.2. Appointment attendance data;

5.4.2.3. Fingerprint capture data;

5.4.2.4. CBP ability to request an additional scheduling attempt;

5.4.2.5. CBP ability to authorize the release of fingerprints to OPM;

5.4.2.6. Billing information;

5.4.3. The Contractor shall encrypt all Personally Identifiable Information (PII) information prior to sending to CBP via email. CBP shall approve the encryption prior to use according to encryption guidelines.

5.4.4. The Contractor shall maintain an automated database system accessible remotely by the COR and authorized CBP employees which permits access to specific information about each fingerprint request received by the Contractor from CBP. The information available shall include:

5.4.4.1. The current status of a fingerprint requirement at any time and the dates that key events occurred in the process;

5.4.4.2. Date fingerprinting was requested;

5.4.4.3. Employee, Contractor and Candidate contact information used by the Contractor (including phone numbers, email address, zip code, and any other contact information used in the scheduling process);

5.4.4.4. Correspondence with the employee, contractor or candidate (including contact attempts by the contractor to the candidate, date calls were returned by the candidate, date materials/forms were sent to candidate, etc.);

5.4.4.5. Appointment date and time;

5.4.4.6. Verification of appointment attendance;

5.4.4.7. “Hard to Reach” or “No Show” designations as applicable;

5.4.4.8. CBP identification numbers associated with the fingerprint requirement; and,

5.4.4.9. Any other data items that provide information on the status of the request.

5.4.5. The Contractor’s database system shall have the capability of transmitting all fingerprinting information via Web Services and allow all information to be uploaded into CBP’s automated systems daily.

5.4.6. The Contractor's database shall be accessible to the COR or other designated authorized CBP personnel to query as needed.

5.4.7. The technical and security requirements of Web Services are discussed in the Security section of this SOW.

6. DELIVERABLES

6.1. Security Deliverables

6.1.1. See Security section of this SOW for more detail on these documents. The following shall be submitted to the COR within 30 days of contract award (initial report), and throughout the life of the contract as stated in the table below:

Deliverable
Delivery/Frequency
Contingency Plan
Initial and updates when changes to policy occur.
Incident Response Plan
Initial and updates when changes to policy occur.
Security Assessments, Reviews and Reporting
Initial and annual assessments of security controls due at the beginning of each performance period.
Vulnerability Scanning
Monthly scanning of systems and providing resulting audit reports.

6.2. Quality Control Plan (QCP)

6.2.1. Performance measures are based on the services required by this SOW and all attached documents. See below chart that includes but is not limited to the performance measures for this contract:Performance Measures Chart

1. Provide facilities equipped for capturing electronic fingerprints in the 48 contiguous United States as well as Washington, DC; Alaska; Hawaii; Puerto Rico; Virgin Islands; Guam; and, Saipan.

2. Complete fingerprinting requirement within sixty (60) miles of a candidate’s address.

3. Each facility meets minimum specification requirements set forth in the SOW.

4. Process electronic scheduling requests in accordance with the SOW.

5. Schedule a varying volume of requirements within the timeframes required in the SOW.

6. Provide, maintain, and protect from disclosure a data system accessible remotely by CBP to request, track, manage, and deliver electronic fingerprint data in accordance with the SOW.

7. Provide web services according to the data and reporting requirements of the SOW.

8. Ensure appropriate security of IT resources that are developed, processed, or used under this Contract in accordance with the SOW.

9. Adhere to the Contractor’s Transition Plan.

10. Perform all services at the acceptable quality level by the end of the transition period as described in this SOW.

11. Assign key personnel that meet the required qualifications of the SOW.

12. Provide sufficient non-key personnel as required.

13. All personnel perform duties and complete tasks as required in this SOW.

14. Adhere to the Contractor’s Quality Control Plan, meet performance measures and acceptable quality levels as required, and meet or exceed the minimum QCP requirements of the SOW.

15. If applicable, adhere to the plan that has been agreed upon by CBP for subcontracting with small and small disadvantaged businesses, in accordance with the Subcontracting Plan Outline and established procedures to monitor and control the subcontracting effort.

6.2.1.1. The acceptable quality level for this contract is 95% - all contract information and fingerprint administration services from the Contractor shall be at least 95% accurate. The Quality Control Plan shall include measures (see chart above) for the Contractor to achieve all performance goals. The Contractor shall be responsible for the quality and timely completion of all Contract services.

6.2.2. The Contractor’s Quality Control Plan shall include, at a minimum:

6.2.2.1. All items addressed in the Performance Measures Chart in this SOW;

6.2.2.2. Monitoring the performance of all subcontractors, including:

6.2.2.2.1. Process for identifying and correcting errors/ deficiencies and an error rate not to exceed five (5) percent for work completed by subcontractor(s);

6.2.2.2.2. Verifying the qualifications and training of all staff;

6.2.2.2.3. Monitoring pending fingerprint requirements and follow-up to ensure the completion of services within required timeframes; and,

6.2.2.2.4. Verifying candidate attendance at scheduled appointments and ensuring that what is reported back to the Contractor from the subcontractors is accurate.

6.2.2.3. Monitoring the primary Contractor’s performance (including Key Personnel);

6.2.2.4. Contingency plan(s) for emergency operations when the Contractor's and/or subcontractor's services are impacted by natural disasters, severe weather, etc.;

6.2.2.5. Contingency plan(s) for loss of information and security breach;

6.2.2.6. Detailed Plan for adhering to required deadlines; and,

6.2.2.7. The Contractor’s security procedures.

6.2.2.8. Detailed procedures to review and correct data entry errors in automated systems.

6.2.2.9. Systems to review all information for completeness and accuracy prior to submission to CBP.

6.2.3. Monthly teleconference meetings with the Contractor shall be scheduled to discuss quality control and performance issues.

6.2.3.1. The Contractor shall resolve any issues in accordance with this SOW or as directed by the COR.

6.2.3.2. The Contractor’s quality control effectiveness shall be noted in the annual performance evaluations.

6.2.4. The COR may request on occasion that the Contractor query its database for other statistical reporting. If the need for a particular report becomes more frequent, the COR may request that the report be made available on an ongoing basis to either be sent directly from the Contractor’s personnel to the COR or to be accessible on the Contractor’s data system that can be accessed remotely at any time.

6.3. Reports

6.3.1. The Contractor shall submit all reports to the COR within three (3) business days of the request unless otherwise specified in this SOW.

6.3.2. All reports shall be written to CBP's specifications, and shall be provided electronically via the Contractor’s automated database system. The Contractor shall retain electronic copies of all data up to and after contract completion to the extent required to comply with this SOW’s document retention requirement.

6.3.3. The Project Status Report shall be provided no later than the tenth (10) day of each month containing data from the previous month. This report shall also be provided ad hoc with updated data for a given date range as requested by the COR. The report shall include, at a minimum, the following information separated by position for the given reporting period:

6.3.3.1. Status of all fingerprints for all candidates;

6.3.3.2. Total number of fingerprints captured per date, and the cumulative number of requests ordered for the given reporting period;

6.3.3.3. Total number of fingerprints captured per date, and the cumulative number of requests completed for the given reporting period;

6.3.3.4. Number of fingerprints invoiced;

6.3.3.5. Number of fingerprints closed without invoicing due to inability to contact the candidate(s) (“Hard to Reach”);

6.3.3.6. Number of fingerprints closed without invoicing due to the candidate(s) failure to attend their appointment (“No Show”);

6.3.3.7. Number of fingerprints closed without invoicing for other reasons;

6.3.3.8. Complaints received from candidates (include type of complaint and facility) and final resolutions; and,

6.3.3.9. Number of fingerprints (s) that have been ordered but not billed (i.e., “open” requests).

6.3.4. The Contractor shall provide additional ad hoc reports as requested by the COR. If the need for a particular report becomes frequent, the report shall be available on an ongoing basis.

6.4. Other Deliverables

6.4.1. Scheduling scripts; and,

6.4.2. Standardized email.

6.5. Non-Disclosure Agreement

6.5.1. All Contractor employees who will be performing work on this contract shall complete a Non-Disclosure Agreement (NDA) (Attachment TBD) for review and approval by the COR prior to starting work.

6.6. Small and Small Disadvantaged Business Subcontracting Plan (if the Contractor is a Large Business)

6.6.1. The Contractor shall submit:

6.6.1.1. A plan for subcontracting with small and small disadvantaged businesses that meets or exceeds CBP subcontracting goals listed in the Subcontracting Plan Outline (includes all elements of the Subcontracting Plan Outline, Attachment TBD).

6.6.1.2. An outline of procedures to monitor and control the subcontracting effort.

6.6.2. Award will be conditioned upon the Government's ability to reach an agreement with the Contractor on the terms of its subcontracting plan. If the Government accepts the Contractor’s subcontracting plan, it will become a part of this contract. Use of the Subcontracting Plan Outline in Attachment TBD of this SOW is optional; however, the plan shall contain all elements included in the outline. The Contractor's subcontracting plan will be evaluated in the Government's determination of the Contractor’s capability. Past performance against historical goals and the small disadvantaged business participation factor shall also be evaluated.

7. GOVERNMENT-FURNISHED INFORMATION AND EQUIPMENT (GFE/GFI)

7.1. There is no Government Furnished Equipment for this contract. All contractor equipment is subject to the requirements outlined in Section 10, Security.

7.2. The Government shall provide contact information of candidates and location of candidates for scheduling purposes.

8. TERM OF CONTRACT

8.1. The term of the contract shall be 9 months.

9. PLACE OF PERFORMANCE

9.1. The Government shall not provide the Contractor with a work site(s). The Contractor’s administrative/business office may be at any location in the United States; only the facilities performing the examinations shall be located in relation to the employee’s/candidate’s work/home address.

9.2. The Contractor shall provide the fingerprinting sites in each of the forty-eight (48) continental United States as well as Alaska, Hawaii, Washington, D.C., Puerto Rico, the U.S. Virgin Islands, Guam, and Saipan.

10. SECURITY

10.1. Contractors are fully responsible and accountable for ensuring compliance with all Federal Information Security Management Act (FISMA), National Institute of Standards and Technology (NIST) Federal Information Processing Standard (FIPS) and related DHS security control requirements (to include configuration guides, hardening guidance, DHS Security Policy, Procedures, and Architectural guidance).

10.2. Contractors have a responsibility to protect the information they possess and process; and to ensure that security of the information in their charge, contractors must adhere to the same rules and regulations as Government employees.

10.3. All services provided under this contract must be compliant with DHS Information Security Policy, identified in DHS Directive140-01, Information Technology Security Program and 4300A Sensitive Systems Handbook (Attachment TBD).

10.4. Security Clearances: Personnel Security Background Data

10.4.1. Performance under this contract is considered sensitive but unclassified and a security clearance is not required.

10.4.2. All personnel employed by the Contractor for work performed under this contract (including any new personnel hired as replacement(s) during the term of this contract) that have been determined to have access to sensitive information, access to CBP facilities and/or access to government Information Technology (IT) resources must receive a favorable suitability determination for employment by the Office of Professional Responsibility – Personnel Security Division (PSD) following completion of a CBP background investigation. Periodic reinvestigations will be required pursuant to applicable CBP requirements (currently 5 years). Federal investigations completed by other federal entities may be given reciprocal consideration in accordance with CBP policy. A preliminary (A.K.A. provisional) determination may be rendered by PSD thereby authorizing the individual to begin work prior to completion and final adjudication of the investigation (access to systems may be restricted until completion and final adjudication of the investigation). Any individual employed under this contract who is determined unsuitable by PSD will be removed from all work on CBP contracts immediately.

10.5. Security Requirements for Unclassified Information

10.5.1. The Contractor shall ensure that all information obtained in this Contract remains confidential and is not disseminated outside of CBP. All contract documents, records, and Personally Identifiable Information shall be stored in a CBP approved secured locked, fireproof filing cabinets and in a secured room that is not accessible to the public or visitors. The Contractor shall take necessary precautions to ensure that all additional information are properly secured to prevent unauthorized access at all times. The Contractor shall comply with the DHS Handbook for Safeguarding Personally Identifiable Information as amended.

10.5.2. Sensitive Personally Identifiable Information (PII)

Sensitive PII information shall be provided to Contractor by the Government during this contract. The Contractor and subcontractors shall have access to PII such as subject’s names, addresses, telephone numbers, e-mail addresses, , date of birth, etc. Only the Contractor and its subcontractors with authorization and only on a need-to-know basis shall access this information. All Sensitive PII Information shall be stored in accordance with requirements by Office of Professional Responsibility). The Sensitive PII information shall be transmitted electronically and encrypted as required in this SOW.

10.5.3. Security and Privacy Awareness Training

All contractor employees and subcontractors that have access to sensitive DHS/CBP data and to Sensitive Personally Identifiable Information (SPII) are required to complete IT security awareness training on an annual basis. Contractors are required to submit an annual notification to the CBP COR indicating the required training has been completed for all contractor employees and subcontractors. This notification will be in the form of an email titled, “IT Security Awareness Training.” This email must include the Last Name, First Name, and if applicable, the credential number of the individuals completing the training. This initial training and notification will be completed before any contract employee or subcontractor will be allowed to perform work related to this SOW. During the course of this effort, any new contract employees and/or subcontractors must complete this training before they will be allowed to perform work related to this SOW; and documentation of completion of training must be submitted to the COR. After initial training, each contractor employee and subcontractor must annually complete this training within thirty (30) days of implementation of option years. The contractor will submit one email listing all contractor employees and subcontractors who have completed this training. Any contractor employee or subcontractor who did not complete this training will not be allowed to perform work related to this SOW.

10.5.4. Release of Information

All information in this Contract shall comply with the Privacy Act, 5 USC § 552a. The information and records generated, maintained, and received shall be protected and used in compliance with CBP policy and regulations. The Contractor shall not release any information to any unauthorized individuals. All requests for information shall be immediately submitted to the COR.

10.6. Encryption

10.6.1. All contractor owned systems, removable media and storage devices being used to collect, process, disseminate, or maintain privacy and technical information at rest within a non-DHS facility must be encrypted; and the Contractor shall employ at a minimum Advanced Encryption Standard (AES) algorithms with at least 256 bit encryption that have been validated under NIST Federal Information Processing Standard (FIPS) 140-2.

10.7. Physical and Information Security and Monitoring

10.7.1. The Contractor shall provide a facility using appropriate protective measures to provide for physical security. The facility will be located within the United States and its territories. The contractor shall maintain a process to control physical access to DHS/CBP IT assets (which include data). DHS/CBP IT Assets (including data) shall be monitored 24x7x365. A summary of unauthorized access attempts shall be reported to the CBP COR.

10.8. Anti-malware (e.g. virus, spam)

10.8.1. The Contractor shall design, implement, monitor and manage comprehensive anti-malware service. The contractor shall provide all maintenance for the system being used to process and/or store DHS/CBP data, providing the anti-malware capabilities to include configuration, definition updates, and comply with DHS/CBP’s configuration management / release management requirements when changes are required. A summary of alerts shall be reported to the CBP COR in weekly status reports. If an abnormality or anomaly is identified, the contractor shall notify the appropriate CBP point of contact in accordance with the Contractor’s incident response plan.

10.9. Vulnerability Scanning and Patch Management

10.9.1. All contractor and subcontractor owned desktops, laptops, servers or other media storage devices being used to collect, process, disseminate, or maintain privacy and technical information (DHS/CBP data) must be subject to annual vulnerability assessment scans. All contractor and subcontractors are responsible for communicating any security sensitive information such as incident reports, notifications, vulnerability alerts and operational statuses to the CBP Security Operations Center (SOC) via the CBP COR to ensure systems are patched in a timely and expeditious manner.

10.10. Contingency and Incident Response Plans

10.10.1. All plans are created in accordance with the requirements identified in the DHS/CBP Security documentation provided, and the guidelines from the National Institute of Standards and Technology (NIST). NIST documentation can be found at: http://csrc.nist.gov/publications

10.10.2. Contingency Plan

10.10.2.1. Contingency plans provide guidance on the interim measures to recover information system services after a disruption, and may include the relocation of information systems and operations to an alternate site, recovery of information system functions using alternate equipment or the performance of information system functions using manual methods. The contractor shall provide a plan that contains the detailed guidance and procedures for restoring a damaged system based on the impact levels and recovery requirements.

10.10.3. Incident Response Plan

10.10.3.1. Incident Response plans provide guidance on the appropriate procedures and responses to an incident and the capabilities required to successfully, efficiently, and effectively handle an incident. It encompasses all actions taken to quickly restore normal IT service and to minimize impacts on business operations.

10.10.3.2. The contractor shall ensure that all privacy and computer security incidents are identified, reported, and appropriately responded to, in order to mitigate harm to DHS/CBP assets, information, and personnel. Privacy incidents must be reported to the CO and COR as soon as possible, but no later than within one hour of recognition that a privacy incident occurred. All privacy incidents must be reported, whether or not they involve information resources.

10.11. Security Breach

10.11.1. If a security breach occurs, in accordance with the Contractor’s Incident Response Plan, the Contractor shall notify the CO and COR within one business day of recognition that a security breach occurred. Within five (5) additional business days the Contractor shall issue and provide a report to the COR and CO detailing the research conducted by the Contractor, conclusions, and preventive measures that will be taken going forward. The Contractor shall also notify the affected candidates and/or employees, and provide the list of those affected to the COR along with copies of the notification from the Contractor to the affected applicants, contractors, consultants, and/or employees. The Contractor shall provide identity and credit monitoring services to the affected applicants, contractors, consultants, and/or employees

10.12. Document Retention

10.12.1. The Contractor shall maintain electronic copies of the associated documentation for the duration of this agreement. Formal contract closeout shall include the CBP Office of Information Technology overseeing the Contractor destroying all data, as required by CBP regulation, which was obtained and retained per this contract.

10.13. Contractor Representation

10.13.1. In correspondence, all contractor and subcontractor employees must identify themselves as contractors and subcontractors operating on behalf of CBP. E-mail signatures must contain: the contractor name; contractor company; CBP title, program, and organization; CBP program office; CBP identifier, contact number; and fax number if applicable. A sample of the formatting will be provided by the COR.

10.14. Security Assessments, Reviews and Reporting

10.14.1. Security is an integral element in the management of this contract. The Contractor shall conduct assessments, reviews and report the status of the implementation and enforcement of the security requirements contained in this contract.

10.14.2. The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford the Office of the CBP Chief Information Security Officer (CISO) and/or representatives of the CISO, access to the Contractor’s (and subcontractor’s) facilities, installations, operations, documentation, databases, and personnel used in the performance of this contract. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of DHS/CBP data or the function of computer systems operated on behalf of DHS/CBP, and to preserve evidence of computer crime.

10.15. Web Services

10.15.1. The system or application delivered by the Contractor shall provide Web Services functionality (in accordance with Federal security and privacy guidelines) that will allow for the exchange or sharing of functions and data within its system to and from DHS and CBP owned or contracted systems.

10.15.2. Data file transfers will be performed through TLS Secured HTTP downloads from an authenticated website upon award and during the setup and testing of the web services. The file formats will be specified by CBP.

10.15.3. Authorization from CBP shall be granted before sending any miscellaneous documentation that needs to be submitted to CBP outside of a web service interface (i.e. via e-mail).

10.15.4. Data input into Contractor systems are owned by DHS and CBP and must be delivered upon demand or at the termination of the contract, in an electronic file format specified by CBP. Upon the completion or termination of a contract and delivery of DHS’/CBP’s data as described, Contractors are required to destroy their local copies of the data upon approval by CBP.

10.15.5. Web Services Requirements

10.15.5.1. The Contractor shall complete all electronic data transfers using web services. This requirement applies to both data provided to and from CBP.

10.15.6. Technical Requirements of Web Services

10.15.6.1. All Contractor supplied data shall be made available via secure web services, including invoices. This data shall be accessible via a single web service that returns data in an agreed upon XML format. The web service shall accept filter criteria such as an effective date.

10.15.6.2. CBP and the Contractor will define the data needed to be exchanged or shared, the data file formats, the web services exchange mechanism and Application Program Interfaces (APIs) and architecture, as well as the periodicity (up to and including instantaneous, bi-directional data feeds between the Contractor system and CBP systems or databases).

10.15.6.3. Data requirements will change over time, but changes will not exceed four (4) times in a calendar year. The Contractor will be required to modify their systems to be compliant with CBP changes, within thirty (30) calendar days of being notified of the change(s).

10.15.6.4. Data file transfers will be performed through TLS Secured HTTP downloads from an authenticated website upon award and during the setup and testing of the web services. The file formats will be specified by CBP.

10.15.6.5. The Contractor’s web service shall conform to the following technical requirements:

10.15.6.5.1. The web service shall be WS-I Basic Profile 1.1 compliant;

10.15.6.5.2. The web service shall be secured via TLS and AES-256 bit encryption;

10.15.6.5.3. The web service shall provide an authentication mechanism that ensures only authorized requests are processed;

10.15.6.5.4. The web service shall execute requests within one second;

10.15.6.5.5. The web service shall execute against and return current, up to date data;

10.15.6.5.6. The web service shall be available for use at all times, 24 hours per day, seven days per week;

10.15.6.5.7. The Contractor shall submit a detailed description of its web service using a standard WSDL x document;

10.15.6.5.8. The Contractor shall provide an XML schema to describe the result set returned by the web service;

10.15.6.5.9. The Contractor shall provide detailed explanation for any error condition that may be raised as a result of web service operation;

10.15.6.5.10. The Contractor shall provide a list containing all possible error codes and a detailed description of each error; and

10.15.6.5.11. The Contractor shall provide end use documentation for its web service.

10.15.7. Web Services Expectations

10.15.7.1 The Contractor shall obtain and adhere to detailed requirements that define:

10.15.7.1.1. Web Service method signatures

10.15.7.1.2. Input Parameters (filter criteria)

10.15.7.1.3. Output fields

10.15.7.1.4. XML Schema of the results set returned by web service; and

10.15.7.1.5. Any additional business rules

10.15.7.2. CBP shall be given the opportunity for acceptance testing of the Contractor provided web service.

10.15.7.3. The COR shall be notified a minimum of two weeks prior to any modifications made to the web service; final approval by the COR will be required before implementation.

10.15.7.4. All production versions of the deployed web service shall be available in production and removed only upon request from CO or with CBP’s explicit permission.

10.15.7.5. The COR shall be notified at least 24 hours in advance of any web service maintenance that will require web service down time. During downtime, fingerprint results will still be made available to the COR in an agreed method. The method shall be agreed upon after award.

10.15.7.6. The Contractor’s web service support shall have a response time of 24 hours or less; however, the Contractor’s web service support personnel do not need to be available 24 hours per day, seven (7) days per week.

10.15.7.7. Safeguards shall also be put in place to protect the PPII.

11. OTHER CONSIDERATIONS

11.1. Transition Process

11.1.1. Upon award of this contract, the Contractor shall begin the transition process. Once ordering starts, CBP may continually request fingerprints without breaks in ordering, subject to hiring requirements and the availability of funds.

11.1.2. The Contractor shall complete the following during the transition period:

11.1.2.1. Performing personnel security clearances to the extent required by this SOW;

11.1.2.2. Training all facilities and administrators performing the fingerprint process;

11.1.2.3. Testing and modification as necessary of automated database system;

11.1.2.4. Testing and modification as necessary files for web services data transfers;

11.1.2.5. Testing and modification as necessary files for electronic invoices;

11.1.2.6. Review and acceptance of all standardized materials received from authorized CBP staff;

11.1.2.7. An overview of all reports the Contractor has available for the Government; and

11.1.2.8. Access for all authorized CBP personnel to the Contractor’s remotely-accessible automated database system and any secure e-mail systems, etc. The COR shall provide information on CBP personnel that shall be granted this access.

11.1.3. The transition period shall be no more than ninety (90) days. After the transition period, the Contractor shall be fully capable of executing all services required in this SOW.

11.2. Hours of Operation

11.2.1. The Contractor’s key personnel and other personnel that are involved in scheduling fingerprints shall be available from 9:00 am to 5:00 pm EST (unless otherwise instructed), Monday through Friday, except on Federal holidays; however, fingerprinting shall be conducted from 7:00 am to 7:00 pm local time (unless otherwise instructed) a minimum of five (5) days per week in all time zones. The Contractor shall provide the COR with contact information, including the telephone numbers of the Program Manager, and relevant corporate personnel before, during, and after business hours.

11.3. Meetings and Travel

11.3.1. The Contractor shall be responsible for all travel required in completing this Contract. This includes travel costs associated with establishing facilities, training and attending meetings.

11.3.2. Quarterly meetings with the Contractor shall be scheduled to discuss overall contract quality control and performance issues as well as other items deemed appropriate to the Government.

11.3.3. More frequent meetings may be required to address general contract issues, modifications, or other items deemed appropriate by the Government and/or Contractor.

11.3.4. Meetings may occur either by teleconference or in person. Historically, most items have been discussed and resolved via teleconference, so travel for meetings has been infrequent.

11.4. Contractor Personnel

11.4.1. Key Personnel - Program Manager

11.4.1.1. The Contractor shall designate a Program Manager to serve as the main point of contact for…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.