70CDCR19R00000002_Sections_D_-_M_Amendment_0001.pdf
PDF 719 KB Posted
- Attached to
- Intensive Supervision Appearance Program IV (ISAP IV) Support Services Federal contract opportunity
- Solicitation number
- 70CDCR19R00000002
- Issued by
- Immigration and Customs Enforcement
About this file
This solicitation is for Intensive Supervision Appearance Program IV (ISAP IV) support services. The solicitation seeks to provide case management and monitoring services for participants in the ISAP program through a single award indefinite delivery/indefinite quantity contract with a one year base period and four one-year options. Services will include intake, case management, GPS monitoring, drug and alcohol testing, transportation, and reporting. Pricing will be evaluated for the transition period, base year and option years. The contractor must be able to provide services nationwide at existing and new sites with less than 90 days notice. The contractor will be responsible for staffing each site and providing all required equipment and facilities.
Amendment 0001 Sections D-M
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
70CDCR19R00000002
SECTION D - PACKAGING AND MARKING
D.1 Packaging and Marking
All information and/or correspondence submitted to the Contracting Officer or the COR shall be clearly marked and indicate the contract number.
D.2 Report Cover Sheet
Each report submitted by the Contractor via hard copy shall have a cover sheet containing the following information:
1. Name and Address of the COR
2. Contract Number
3. Name and Address of the Contractor
4. Title of Report
5. Report Number and Type
6. Period Covered by the Report
No report cover sheet is required for reports submitted via e-mail.
[THE BALANCE OF THIS PAGE IS LEFT INTENTIONALLY BLANK]
[END OF SECTION D]
SECTION E – INSPECTION AND ACCEPTANCE
E.1 CLAUSES INCORPORATED BY REFERENCE (FAR 52.252-2) (FEB 1998)
This contract incorporates the following clauses by reference with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text can be accessed electronically at this internet address: https://acquisition.gov/browse/index/far.
Clause Number Clause Title Date
52.246-4 Inspection of Services – Fixed Price Aug 1996
[THE BALANCE OF THIS PAGE IS LEFT INTENTIONALLY BLANK]
[END OF SECTION E]
http://acquisition.gov/far/index.html
SECTION F - DELIVERIES OR PERFORMANCE
F.1 CLAUSES INCORPORATED BY REFERENCE (FAR 52.252-2) (FEB 1998)
This contract incorporates the following clauses by reference with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text can be accessed electronically at this internet
Clause Number Clause Title Date
52.242-15 Stop Work Order Aug 1989
52.242-17 Government Delay of Work Apr 1984
F.2 Term of Contract
The initial term of this contract shall be for a twelve (12)-month base period, consisting of a six (6)-month transition period and a six (6)-month operational period.
The six (6)-month transition-in period shall ensure an orderly transition from the existing contract with no degradation of service. The transition-in period shall also provide the awardee adequate time to obtain the required contractor personnel security clearances, Entry on Duty (EOD) determination, facility space, staff that space and outfit applicable active participants with GPS devices in advance of day one of the start of contract performance. Contractor personnel shall be able to start work no sooner than the base period contract start date or the date the security clearance is granted (EOD), whichever is later.
This contract shall also contain four (4) one-year option periods. Offerors are required only to price the transition, base and option periods. Offerors shall not submit a price for the optional extension of services period in accordance with FAR 52.217-8. For evaluation purposes, FAR 52.217-8, Option to
Extend Services, will use the last option period’s pricing to determine its fairness and reasonableness.
The entire contract term including options shall not exceed 66 months (five years and six months) in duration.
F.3 Period of Performance
The estimated period of performance of this contract is as follows:
Transition - TBD
Base Operational Period – TBD
Option Year 1 – TBD
Option Year 2 – TBD
Option Year 3 – TBD
Option Year 4 – TBD
The period of performance dates shall be provided at the time of contract award. Option periods of performance shall remain as twelve (12) months.
F.4 Place of Performance
Work shall be performed (service shall be provided) at the sites listed in Attachment 7 - Location
Overview. See Section H.1. for procedure to open additional ISAP IV sites.
F.5 Contractor Evaluating Procedures
The Government will issue Contractor performance ratings via the Contractor Performance
Assessment Reporting System (CPARS) in accordance with FAR 42.1502. The CPARS website is located: http://www.cpars.gov.
[THE BALANCE OF THIS PAGE IS INTENTIONALLY LEFT BLANK]
[END OF SECTION F]
http://www.cpars.gov/
SECTION G - CONTRACT ADMINISTRATION DATA
G.1 CONTRACT ADMINISTRATION
The administration of the contract will require maximum coordination between the ICE and the
Contractor.
The individuals outlined in Section G will be the Government points of contact during the performance of this contract for their respective roles as identified herein:
To Be Designated at Time of Award
G.2 CONTRACTING OFFICER’S REPRESENTATIVE
The following individual is designated and authorized by the Contracting Officer (CO) to perform contract administration functions related to the technical performance of this contract.
To Be Designated at Time of Award
(a) The CO may designate Government personnel to act as the Contracting Officer's Representative
(COR) to perform functions under the contract such as review or inspection and acceptance of supplies, services, including construction, and other functions of a technical nature. The CO will provide a written notice of such designation to the Contractor within five working days after contract award or for construction, not less than five working days prior to giving the contractor the notice to proceed. The designation letter will set forth the authorities and limitations of the COR under the contract.
(b) The CO cannot authorize the COR or any other representative to sign documents, such as contracts, contract modifications, etc., that require the signature of the CO.
G.3 ORDERING PROCEDURES
No funding will be obligated on the ISAP IV base contract. Funding will be provided via issuance of task orders as requirements arise.
The contractor shall not invoice outside of the transition services until contractor personnel have received an EOD clearance and begin work under this contact. The contractor may begin billing for participant services as soon as they are incurred, even if services are incurred during the transition period.
G.4 INVOICE REQUIREMENTS
In accordance with Section G, Contract Administration Data, invoices shall be submitted as follows:
Service Providers/Contractors shall use these procedures when submitting an invoice.
1. Invoice Submission: Invoices shall be submitted in a “.pdf” format in accordance with the contract terms and conditions [Contract Specialist and Contracting Officer to disclose if on a monthly basis or other agreed to terms"] via email, United States Postal Service (USPS) or facsimile as follows:
a) Email:
• Invoice.Consolidation@ice.dhs.gov
• Contracting Officer Representative (COR) or Government Point of Contact (GPOC)
• Contract Specialist/Contracting Officer
Each email shall contain only (1) invoice and the invoice number shall be indicated on the subject line of the email.
b) USPS:
DHS, ICE
Financial Operations - Burlington
P.O. Box 1620
Williston, VT 05495-1620
ATTN: ICE-ERO/HQ CED
The Contractors Data Universal Numbering System (DUNS) Number must be registered and active in the System for Award Management (SAM) at https://www.sam.gov prior to award and shall be notated on every invoice submitted to ensure prompt payment provisions are met. The ICE program office identified in the task order/contract shall also be notated on every invoice.
c) Facsimile:
Alternative Invoices shall be submitted to: (802)-288-7658
Submissions by facsimile shall include a cover sheet, point of contact and the number of total pages.
Note: The Service Provider’s or Contractor’s Dunn and Bradstreet (D&B) DUNS Number must be registered in the System for Award Management (SAM) at https://www.sam.gov prior to award and shall be notated on every invoice submitted to ensure prompt payment provisions are met. The ICE program office identified in the task order/contract shall also be notated on every invoice.
2. Content of Invoices: Each invoice shall contain the following information as applicable:
(i). Name and address of the Service Provider/Contractor. Note: the name, address and DUNS number on the invoice MUST match the information in both the Contract/Agreement and the information in the SAM. If payment is remitted to another entity, the name, address and DUNS information of that entity must also be provided which will require Government verification before payment can be processed;
(ii). Dunn and Bradstreet (D&B) DUNS Number;
(iii). Invoice date and invoice number;
(iv). Agreement/Contract number, contract line item number and, if applicable, the order number;
(v). Description, quantity, unit of measure, unit price, extended price and period of performance of the items or services delivered;
(vi). If applicable, shipping number and date of shipment, including the bill of lading number and weight of shipment if shipped on Government bill of lading;
(vii). Terms of any discount for prompt payment offered;
(viii). Remit to Address;
(ix). Name, title, and phone number of person to resolve invoicing issues;
(x). ICE program office designated on order/contract/agreement and
(xi). Mark invoice as “Interim” (Ongoing performance and additional billing expected) and “Final”
(performance complete and no additional billing)
(xii). Electronic Funds Transfer (EFT) banking information in accordance with 52.232-33 Payment by Electronic Funds Transfer – System for Award Management or 52-232-34, Payment by Electronic
Funds Transfer – Other than System for Award Management.
3. Invoice Supporting Documentation. To ensure payment, the vendor must submit supporting documentation which provides substantiation for the invoiced costs to the Contracting Officer
Representative (COR) or Point of Contact (POC) identified in the contract. Invoice charges must align with the contract CLINs. Supporting documentation is required when guaranteed minimums are exceeded and when allowable costs are incurred.
(i) Firm Fixed-Price CLINs. Supporting documentation is not required for charges for FFP CLINs.
4. Safeguarding Information: As a contractor or vendor conducting business with Immigration and
Customs Enforcement (ICE), you are required to comply with DHS Policy regarding the safeguarding of Sensitive Personally Identifiable Information (PII). Sensitive PII is information that identifies an individual, including an alien, and could result in harm, embarrassment, inconvenience or unfairness.
Examples of Sensitive PII include information such as: Social Security Numbers, Alien Registration
Numbers (A-Numbers), or combinations of information such as the individuals name or other unique identifier and full date of birth, citizenship, or immigration status.
As part of your obligation to safeguard information, the follow precautions are required:
(i) Email supporting documents containing Sensitive PII in an encrypted attachment with password sent separately to the Contracting Officer Representative assigned to the contract.
(ii) Never leave paper documents containing Sensitive PII unattended and unsecure. When not in use, these documents will be locked in drawers, cabinets, desks, etc. so the information is not accessible to those without a need to know.
(iii) Use shredders when discarding paper documents containing Sensitive PII.
(iv) Refer to the DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(March 2012) found at http://www.dhs.gov/xlibrary/assets/privacy/dhs-privacy-safeguardingsensitivepiihandbook-march2012.pdf for more information on and/or examples of
Sensitive PII.
5. Invoice Inquiries. If you have questions regarding payment, please contact ICE Financial
Operations at 1-877-491-6521 or by e-mail at OCFO.CustomerService@ice.dhs.gov.
[END OF SECTION G]
mailto:OCFO.CustomerService@ice.dhs.gov
SECTION H - SPECIAL CONTRACT REQUIREMENTS
H.1. PROCEDURE FOR OPENING ADDITIONAL ISAP IV LOCATIONS
In accordance with the ISAP IV Statement of Work as well as Attachment 7 - Location Overview, the
Government intends to expand its ISAP coverage to additional Enforcement and Removal Operations
(ERO) Field Office and Sub-Office locations under the ISAP IV contract through the establishment of new contractor facilities and assignment of contractor personnel working on-site at government facilities as required by need and mission priorities. The contractor shall be notified in writing, via bilateral contract modification, of the Government’s intent to open a new ISAP IV Field Office or
Sub-Office location(s). The modification shall be signed by the ISAP IV Contracting Officer and issued to the ISAP IV Program Director and/or Deputy Program Director. The designated ERO field office and/or sub-office location(s) may require C-, G-, S- or T-site services. The contractor shall have no more than thirty (30) calendar days for G-, S- and T-site locations and no more than ninety
(90) calendar days for C-site locations (contingent upon adequate real estate availability) from receipt of the written notice to commence ISAP IV services and fulfill all SOW requirements at the specific location(s) identified herein. The contractor shall be prepared with sufficient staff and equipment to provide ISAP IV services for the full (i.e., maximum) number of anticipated ISAP IV participant slots for that location.
Offerors are encouraged to review Attachment 11 – Expansion History by Contract Year as well as
Attachment 12 – FY18 ISAP III Statistics.
H.2. REQUIRED SECURITY LANGUAGE FOR SENSITIVE /BUT UNCLASSIFED (SBU)
CONTRACTS
SECURITY REQUIREMENTS
H.2.1. General
The United States Immigration and Customs Enforcement (ICE) has determined that performance of the tasks as described in Contract requires that the
Contractor, subcontractor(s), vendor(s), etc. (herein known as Contractor) have access to sensitive DHS information, and that the Contractor will adhere to the following.
H.2.2. Preliminary Fitness Determination
ICE will exercise full control over granting, denying, withholding or terminating unescorted government facility and/or sensitive Government information access for contractor employees, based upon the results of a Fitness screening process.
ICE may, as it deems appropriate, authorize and make a favorable expedited preliminary Fitness determination based on preliminary security checks. The preliminary Fitness determination will allow the contractor employee to commence work temporarily prior to the completion of a Full Field Background
Investigation. The granting of a favorable preliminary Fitness shall not be considered as assurance that a favorable final Fitness determination will follow as a result thereof. The granting of preliminary Fitness or final Fitness shall in no way prevent, preclude, or bar the withdrawal or termination of any such access by
ICE, at any time during the term of the contract. No employee of the Contractor shall be allowed to enter on duty and/or access sensitive information or systems without a favorable preliminary Fitness determination or final Fitness determination by the Office of Professional Responsibility, Personnel Security
Unit (OPR-PSU). No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable preliminary Fitness determination or final Fitness determination by OPR-PSU. Contract employees are processed under DHS Instruction 121-01-007-001 (Personnel Security, Suitability and Fitness Program), or successor thereto; those having direct contact with Detainees will also have 6 CFR § 115.117 considerations made as part of the
Fitness screening process. (Sexual Abuse and Assault Prevention Standards) implemented pursuant to Public Law 108-79 (Prison Rape Elimination Act
(PREA) of 2003).
H.2.3. Background Investigations
Contractor employees (to include applicants, temporaries, part-time and replacement employees) under the contract, needing access to sensitive information and/or ICE
Detainees, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. Background investigations will be processed through the Personnel Security Unit. Contractor employees nominated by a Contracting Officer Representative for consideration to support this contract shall submit the following security vetting documentation to OPR-
PSU, through the Contracting Officer Representative (COR), within 10 days of notification by OPR-PSU of nomination by the COR and initiation of an Electronic
Questionnaire for Investigation Processing (e-QIP) in the Office of Personnel
Management (OPM) automated on-line system.
1. Standard Form 85P (Standard Form 85PS (With supplement to 85P required for armed positions)), “Questionnaire for Public Trust Positions” Form completed on-line and archived by the contractor employee in their OPM e-
QIP account.
2. Signature Release Forms (Three total) generated by OPM e-QIP upon completion of Questionnaire (e-signature recommended/acceptable – instructions provided to applicant by OPR-PSU). Completed on-line and archived by the contractor employee in their OPM e-QIP account.
3. Two (2) SF 87 (Rev. December 2017) Fingerprint Cards. (Two Original
Cards sent via COR to OPR-PSU)
4. Foreign National Relatives or Associates Statement. (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)
5. DHS 11000-9, “Disclosure and Authorization Pertaining to Consumer
Reports Pursuant to the Fair Credit Reporting Act” (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be
6. Optional Form 306 Declaration for Federal Employment (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)
7. If occupying PREA designated position: Questionnaire regarding conduct defined under 6 CFR § 115.117 (Sexual Abuse and Assault Prevention
Standards) (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)
8. One additional document may be applicable if contractor employee was born abroad. If applicable, additional form and instructions will be provided to contractor employee. (If applicable, the document will be sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be
Contractor employees who have an adequate, current investigation by another Federal
Agency may not be required to submit complete security packages; the investigation may be accepted under reciprocity. The questionnaire related to 6 CFR § 115.117 listed above in item 7 will be required for positions designated under PREA.
An adequate and current investigation is one where the investigation is not more than five years old, meets the contract risk level requirement, and applicant has not had a break in service of more than two years. (Executive Order 13488 amended under
Executive Order 13764/DHS Instruction 121-01-007-01)
Required information for submission of security packet will be provided by OPR-PSU at the time of award of the contract. Only complete packages will be accepted by the
OPR-PSU as notified by the COR.
To ensure adequate background investigative coverage, contractor employees must currently reside in the United States or its Territories. Additionally, contractor employees are required to have resided within the Unites States or its Territories for three or more years out of the last five (ICE retains the right to deem a contractor employee ineligible due to insufficient background coverage). This time-line is assessed based on the signature date of the standard form questionnaire submitted for the applied position. Contractor employees falling under the following situations may be exempt from the residency requirement: 1) work or worked for the U.S. Government in foreign countries in federal civilian or military capacities; 2) were or are dependents accompanying a federal civilian or a military employee serving in foreign countries so long as they were or are authorized by the U.S. Government to accompany their federal civilian or military sponsor in the foreign location; 3) worked as a contractor employee, volunteer, consultant or intern on behalf of the federal government overseas, where stateside coverage can be obtained to complete the background investigation; 4) studied abroad at a U.S. affiliated college or university; or 5) have a current and adequate background investigation (commensurate with the position risk/sensitivity levels) completed for a federal or contractor employee position, barring any break in federal employment or federal sponsorship.
Only U.S. Citizens and Legal Permanent Residents are eligible for employment on contracts requiring access to DHS sensitive information unless an exception is granted as outlined under DHS Instruction 121-01-007-001. Per DHS Sensitive Systems Policy
Directive 4300A, only U.S. citizens are eligible for positions requiring access to DHS
Information Technology (IT) systems or positions that are involved in the development, operation, management, or maintenance of DHS IT systems, unless an exception is granted as outlined under DHS Instruction 121-01-007-001.
H.2.4. Transfers from Other DHS Contracts
Contractor employees may be eligible for transfer from other DHS Component contracts provided they have an adequate and current investigation meeting the new assignment requirement. If the contractor employee does not meet the new assignment requirement a DHS 11000-25 with ICE supplemental page will be submitted to OPR-
PSU to initiate a new investigation.
Transfers will be accomplished by submitting a DHS 11000-25 with ICE supplemental page indicating “Contract Change.” The questionnaire related to 6 CFR § 115.117 listed above in item 7 will be required for positions designated under PREA.
H.2.5. Continued Eligibility
ICE reserves the right and prerogative to deny and/or restrict facility and information access of any contractor employee whose actions conflict with Fitness standards contained in DHS Instruction 121-01-007-01, Chapter 3, paragraph 6.B or who violate standards of conduct under 6 CFR § 115.117. The Contracting Officer or their representative can determine if a risk of compromising sensitive Government information exists or if the efficiency of service is at risk and may direct immediate removal of a contractor employee from contract support. The OPR-PSU will conduct periodic reinvestigations every 5 years, or when derogatory information is received, to evaluate continued Fitness of contractor employees.
H.2.6. Required Reports
The Contractor will notify OPR-PSU, via the COR, of all terminations/resignations of contractor employees under the contract within five days of occurrence. The Contractor will return any expired ICE issued identification cards and building passes of terminated/ resigned employees to the COR. If an identification card or building pass is not available to be returned, a report must be submitted to the COR referencing the pass or card number, name of individual to whom issued, the last known location and disposition of the pass or card. The COR will return the identification cards and building passes to the responsible ID Unit.
The Contractor will report any adverse information coming to their attention concerning contractor employees under the contract to the OPR-PSU, via the COR, as soon as possible. Reports based on rumor or innuendo should not be made. The subsequent termination of employment of an employee does not obviate the requirement to submit this report. The report shall include the contractor employees’ name and social security number, along with the adverse information being reported.
The Contractor will provide, through the COR a Quarterly Report containing the names of contractor employees who are active, pending hire, have departed within the quarter or have had a legal name change (Submitted with documentation). The list shall include the Name, Position and SSN (Last Four) and should be derived from system(s) used for contractor payroll/voucher processing to ensure accuracy.
CORs will submit reports to psu-industrial-security@ice.dhs.gov
Contractors, who are involved with management and/or use of information/data deemed
“sensitive” to include ‘law enforcement sensitive” are required to complete the DHS
Form 11000-6-Sensitive but Unclassified Information NDA for contractor access to sensitive information. The NDA will be administered by the COR to the all contract personnel within 10 calendar days of the entry on duty date. The completed form shall remain on file with the COR for purpose of administration and inspection.
Sensitive information as defined under the Computer Security Act of 1987, Public Law
100-235 is information not otherwise categorized by statute or regulation that if disclosed could have an adverse impact on the welfare or privacy of individuals or on the welfare or conduct of Federal programs or other programs or operations essential to the national interest. Examples of sensitive information include personal data such as
Social Security numbers; trade secrets; system vulnerability information; pre-solicitation procurement documents, such as statements of work; and information pertaining to law enforcement investigative methods; similarly, detailed reports related to computer security deficiencies in internal controls are also sensitive information because of the potential damage that could be caused by the misuse of this information.
All sensitive information must be protected from loss, misuse, modification, and unauthorized access in accordance with DHS Management Directive 11042.1, DHS
Policy for Sensitive Information and ICE Policy 4003, Safeguarding Law Enforcement
Sensitive Information.”
Any unauthorized disclosure of information should be reported to
ICE.ADSEC@ICE.dhs.gov.
H.2.7. Security Management
The Contractor shall appoint a senior official to act as the Corporate Security Officer.
The individual will interface with the OPR-PSU through the COR on all security matters, to include physical, personnel, and protection of all Government information and data accessed by the Contractor.
The COR and the OPR-PSU shall have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements under this contract. Should the COR determine that the Contractor is not complying with the security requirements of this contract, the Contractor will be informed in writing by the
Contracting Officer of the proper action to be taken in order to effect compliance with such requirements.
H.2.8. Information Technology Security Clearance
When sensitive government information is processed on Department telecommunications and automated information systems, the Contractor agrees to provide for the administrative control of sensitive data being processed and to adhere to the procedures governing such data as outlined in DHS MD 4300.1, Information
Technology Systems Security. or its replacement. Contractor employees must have favorably adjudicated background investigations commensurate with the defined sensitivity level.
Contractor employees who fail to comply with Department security policy are subject to having their access to Department IT systems and facilities terminated, whether or not the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g., Privacy Act).
H.2.9 Information Technology Security Training and Oversight
In accordance with Chief Information Office requirements and provisions, all contractor employees accessing Department IT systems or processing DHS sensitive data via an IT system will require an ICE issued/provisioned Personal Identity Verification (PIV) card.
Additionally, Information Assurance Awareness Training (IAAT) will be required upon initial access and annually thereafter. IAAT training will be provided by the appropriate component agency of DHS.
Contractor employees, who are involved with management, use, or operation of any IT systems that handle sensitive information within or under the supervision of the
Department, shall receive periodic training at least annually in security awareness and accepted security practices, systems rules of behavior, to include Unauthorized
Disclosure Training, available on PALMS or by contacting ICE.ADSEC@ICE.dhs.gov.
Department contractor employees, with significant security responsibilities, shall receive specialized training specific to their security responsibilities annually. The level of training shall be commensurate with the individual’s duties and responsibilities and is intended to promote a consistent understanding of the principles and concepts of telecommunications and IT systems security.
All personnel who access Department information systems will be continually evaluated while performing these duties. System Administrators should be aware of any unusual or inappropriate behavior by personnel accessing systems. Any unauthorized access, sharing of passwords, or other questionable security procedures should be reported to the local Security Office or Information System Security Officer (ISSO).
H.3 ICE INFORMATION GOVERNANCE AND PRIVACY REQUIREMENTS CLAUSE
(JUL 2017)
No section of this clause may be read as self-deleting unless the terms of the contract meet the requirements for self-deletion as specified in this clause.
H.3.1. Limiting Access to Privacy Act and Other Sensitive Information
(1) Privacy Act Information
In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984), and FAR 52.224-2
Privacy Act (APR 1984), if this contract requires contractor personnel to have access to information protected by the Privacy Act of 1974 the contractor is advised that the relevant
DHS system of records notices (SORNs) applicable to this Privacy Act information may be found at www.dhs.gov/privacy. Applicable SORNS of other agencies may be accessed through the agencies’ websites or by searching FDsys, the Federal Digital System, available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.
(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment
The Contractor shall perform all tasks on authorized Government networks, using
Government-furnished IT and other equipment and/or Workplace as a Service (WaaS) if
WaaS is authorized by the statement of work. Government information shall remain within the confines of authorized Government networks at all times. Except where telework is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized
Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of telework authorizations.
(3) Prior Approval Required to Hire Subcontractors
The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and
Agency guidance for protecting sensitive and proprietary information.
(4) Separation Checklist for Contractor Employees
Contractor shall complete a separation checklist before any employee or Subcontractor employee terminates working on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposal of sensitive personally identifiable information (PII), in paper or electronic form, in the custody of the employee or
Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to sensitive PII.
In the event of adverse job actions resulting in the dismissal of an employee or Subcontractor employee, the Contractor shall notify the Contracting Officer’s Representative (COR) within
24 hours. For normal separations, the Contractor shall submit the checklist on the last day of employment or work on the contract.
As requested, contractors shall assist the ICE Point of Contact (ICE/POC), Contracting
Officer, or COR with completing ICE Form 50-005/Contractor Employee Separation
Clearance Checklist by returning all Government-furnished property including but not limited to computer equipment, media, credentials and passports, smart cards, mobile devices, PIV cards, calling cards, and keys and terminating access to all user accounts and systems.
H.3.2. Privacy Training, Safeguarding, and Remediation
If the Safeguarding of Sensitive Information (MAR 2015) and Information Technology
Security and Privacy Training (MAR 2015) clauses are included in this contract, section
H.3.2 is deemed self- deleting.
(1) Required Security and Privacy Training for Contractors
Contractor shall provide training for all employees, including Subcontractors and independent contractors who have access to sensitive personally identifiable information (PII) as well as the creation, use, dissemination and/or destruction of sensitive PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle sensitive PII, including security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of sensitive PII. All Contractor employees are required to take the Privacy at DHS: Protecting
Personal Information training course. This course, along with more information about DHS security and training requirements for Contractors, is available at www.dhs.gov/dhs-security-and-training-requirements-contractors. The Federal Information Security Management Act
(FISMA) requires all individuals accessing ICE information to take the annual Information
Assurance Awareness Training course. These courses are available through the ICE intranet site or the Agency may also make the training available through hypertext links or CD. The
Contractor shall maintain copies of employees’ certificates of completion as a record of compliance and must submit an annual e-mail notification to the ICE Contracting Officer’s
Representative that the required training has been completed for all the Contractor’s employees.
(2) Safeguarding Sensitive PII Requirement
Contractor employees shall comply with the Handbook for Safeguarding sensitive PII at DHS at all times when handling sensitive PII, including the encryption of sensitive PII as required in the Handbook. This requirement will be flowed down to all subcontracts and lower tiered subcontracts as well.
(3) Non-Disclosure Agreement Requirement
All Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (DHS Form 11000-6) prior to commencing work. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting
Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) Prohibition on Use of PII in Vendor Billing and Administrative Records
The Contractor’s invoicing, billing, and other financial/administrative records/databases may not store or include any sensitive Government information, such as PII that is created, obtained, or provided during the performance of the contract. It is acceptable to list the names, titles and contact information for the Contracting Officer, Contracting Officer’s
Representative, or other ICE personnel associated with the administration of the contract in the invoices as needed.
(5) Reporting Suspected Loss of Sensitive PII
Contractors must report the suspected loss or compromise of sensitive PII to ICE in a timely manner and cooperate with ICE’s inquiry into the incident and efforts to remediate any harm to potential victims.
1. The Contractor must develop and include in its security plan (which is submitted to
ICE) an internal system by which its employees and Subcontractors are trained to identify and report the potential loss or compromise of sensitive PII.
2. The Contractor must report the suspected loss or compromise of sensitive PII by its employees or Subcontractors to the ICE Security Operations Center (480-496-6627), the Contracting Officer’s Representative (COR), and the Contracting Officer within one (1) hour of the initial discovery.
3. The Contractor must provide a written report to ICE within 24 hours of the suspected loss or compromise of sensitive PII by its employees or Subcontractors. The report must contain the following information:
a. Narrative or detailed description of the events surrounding the suspected loss or compromise of information.
b. Date, time, and location of the incident.
c. Type of information lost or compromised.
d. Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.
e. Names of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.
f. Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.
g. Actions that have been or will be taken to minimize damage and/or mitigate further compromise.
h. Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.
4. The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
5. At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access sensitive PII or to work on that contract based on their actions related to the loss or compromise of sensitive PII.
(6) Victim Remediation
The Contractor is responsible for notifying victims and providing victim remediation services in the event of a loss or compromise of sensitive PII held by the Contractor, its agents, or its
Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the
Government, call center help desk services for the individuals whose sensitive PII was lost or compromised. The Contractor and ICE will collaborate and agree on the method and content of any notification that may be required to be sent to individuals whose sensitive PII was lost or compromised.
H.3.3. Government Records Training, Ownership, and Management
(1) Records Management Training and Compliance
(a) The Contractor shall provide DHS basic records management training for all employees and Subcontractors that have access to sensitive PII as well as to those involved in the creation, use, dissemination and/or destruction of sensitive PII. This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. This training can be obtained via links on the ICE intranet site or it may be made available through other means (e.g., CD or online). The
Contractor shall maintain copies of certificates as a record of compliance and must submit an e-mail notification annually to the Contracting Officer’s Representative verifying that all employees working under this contract have completed the required records management training.
(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.
(2) Records Creation, Ownership, and Disposition
(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency data. The Contractor shall certify in writing the destruction or return of all Government data at the conclusion of the contract or at a time otherwise specified in the contract.
(b) Except as stated in the Performance Work Statement and, where applicable, the
Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases) and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and are considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.
(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the
Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C.
§ 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.
H.3.4. Data Privacy and Oversight
Section H.3.4 applies to information technology (IT) contracts. If this is not an IT contract, section H.3.4 may read as self-deleting. ISAP IV has not been deemed an IT contract.
(1) Restrictions on Testing or Training Using Real Data Containing PII
The use of real data containing sensitive PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible. ICE policy requires that any proposal to use of real data or de-identified data for IT system testing or training be approved by the ICE Privacy Officer and
Chief Information Security Officer (CISO) in advance. In the event performance of the contract requires or necessitates the use of real data for system-testing or training purposes, the Contractor in coordination with the Contracting Officer or Contracting Officer’s
Representative and Government program manager shall obtain approval from the ICE Privacy
Office and CISO and complete any required documentation.
If this IT contract contains the Safeguarding of Sensitive Information (MAR 2015) and
Information Technology Security and Privacy Training (MAR 2015) clauses, section
H.3.4.2 of this clause is deemed self-deleting.
(2) Requirements for Contractor IT Systems Hosting Government Data
The Contractor is required to obtain a Certification and Accreditation for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.
(3) Requirement to Support Privacy Compliance
(a) The Contractor shall support the completion of the Privacy Threshold Analysis
(PTA) document when it is required. PTAs are triggered by the creation, modification, upgrade, or disposition of an IT system, and must be renewed at least every three years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy
Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide adequate support to complete the PIA in a timely manner and shall ensure that project management plans and schedules include the PTA, PIA, and SORN (to the extent required) as milestones.
Additional information on the privacy compliance process at DHS, including PTAs, PIAs, and SORNs, is located on the DHS Privacy Office website
(www.dhs.gov/privacy) under “Compliance.” DHS Privacy Policy Guidance
Memorandum 2008-02 sets forth when a PIA will be required at DHS, and the Privacy
Impact Assessment Guidance and Template outline the requirements and format for the PIA.
(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy documentation, the Contractor shall assign or procure a Privacy Lead, to be listed under “Key Personnel.” The Privacy Lead shall be responsible for providing adequate support to DHS to ensure DHS can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance. The Privacy Lead shall work with personnel from the program office, the
ICE Privacy Office, the Office of the Chief Information Officer, and the Records
Management Branch to ensure that the privacy documentation is kept on schedule, that the answers to questions in the PIA are thorough and complete, and that questions asked by the ICE Privacy Office and other offices are answered in a timely fashion.
The Privacy Lead:
• Must have excellent writing skills, the ability to explain technology clearly for a non-technical audience, and the ability to synthesize information from a variety of sources.
• Must have excellent verbal communication and organizational skills.
• Must have experience writing PIAs. Ideally the candidate would have experience writing PIAs for DHS.
• Must be knowledgeable about the Privacy Act of 1974 and the E-Government
Act of 2002.
• Must be able to work well with others.
(c) If a Privacy Lead is already in place with the program office and the contract involves IT system builds or substantial changes that may require privacy documentation, the requirement for a separate Private Lead specifically assigned under this contract may be waived provided the Contractor agrees to have the existing
Privacy Lead coordinate with and support the ICE Privacy POC to ensure privacy concerns are proactively reviewed and so ICE can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance if required.
The Contractor shall work with personnel from the program office, the ICE Office of
Information Governance and Privacy, and the Office of the Chief Information Officer to ensure that the privacy documentation is kept on schedule, that the answers to questions in any privacy documents are thorough and complete, that all records management requirements are met, and that questions asked by the ICE Privacy Office and other offices are answered in a timely fashion.
H.4. INFORMATION TECHNOLOGY SECURITY AND PRIVACY TRAINING (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Security Training Requirements.
(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. The
Department of Homeland Security (DHS) requires that Contractor employees take an annual
Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than
October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October
31st of each year. The e-mail notification shall state the required training has been completed for all
Contractor and subcontractor employees.
(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information
Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .