70CMSD22R00000003_RFP AMD 1 - Redline.pdf
PDF 820 KB Posted
- Attached to
- DHS ICE OPLA PLAnet Administrative Support Services Federal contract opportunity
- Solicitation number
- 70CMSD22R00000003
- Issued by
- Immigration and Customs Enforcement
About this file
This request for proposal (RFP) solicits administrative support services across the United States, including Puerto Rico. The Department of Homeland Security (DHS), Immigration and Customs Enforcement (ICE) intends to issue a single award under FAR Part 12 to a certified 8(a) program participant. The estimated total value of the requirement is between $50-60 million over five years. Interested parties must have a Unique Entity Identifier and be registered in SAM. The submission deadline for Phase I questions is June 1, 2022, with Phase II questions to follow. Proposals are due by June 8, 2022. The NAICS code is 561110 for office administrative services with a $8 million size standard. This is a 100% small business set-aside approved by the SBA.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 5 - QASP dtd 6.1.22 - Clean.pdf | ||
| 70CMSD22R00000003_RFP AMD 1 - Clean.pdf | ||
| RFP Questions and Answers.pdf | ||
| Attachment 5 - QASP dtd 6.1.22 - Redline.pdf | ||
| 70CMSD22R00000003 A00001 SF30.pdf | ||
| Attachment 3 - All Wage Determinations dtd 3.15.22.pdf | ||
| RFP 70CMSD22R00000003 dtd 5.25.22.pdf | ||
| Attachment 1 - PWS dtd 5.25.22.pdf | ||
| Attachment 6 - Corporate Experience Cover Page.docx | DOCX document | |
| Attachment 2 - Pricing Template.xlsx | XLSX spreadsheet | |
| Attachment 5 - QASP dtd 4.13.22.pdf | ||
| Attachment 4 - Questions Comments Template.xlsx | XLSX spreadsheet |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section B
SECTION B:
SUPPLIES OR SERVICES AND
PRICES/COSTS
B.1 GENERAL
The U.S. Department of Homeland Security, U.S. Immigration and Customs Enforcement (DHS/ICE) is issuing a competitive RFP as an 8(a) small business set aside. The North American Industry Classification System (NAICS) code is 561110 Office Administrative Services, and the small business size standard is $8.0 million.
DHS/ICE intends to award a single contract from this solicitation for commercial items under Federal Acquisition Regulations (FAR) Part 12 (Acquisition of Commercial Items) using the source selection procedures of FAR (15) (Contracting by Negotiation).
B.2 CONTRACT PRICING
The SF33 represents the Contract Line-Item Number (CLIN) structure expected upon award.
However, Offerors are instructed to fill in Attachment 2 - Pricing Template. All base and option period pricing shall be incorporated into this contract upon award. The rates provided by the Contractor will be utilized to bill against the applicable CLIN.
B.3 CONTRACT TYPE
This solicitation intends to establish a Hybrid Contract, Labor Hour (with a fixed price CLIN for Project Management). The contractor shall maintain and approved accounting system to permit timely and accurate development of all necessary cost data in the format required by the proposed contract type.
B.4 TRAVEL
Contractor personnel may be required to travel to support the requirements of this contract. The Contractor shall, to the maximum extent practicable, minimize overall travel costs by taking advantage of discounted airfare rates available through advance purchase. Charges associated with itinerary changes, and cancellations under nonrefundable airline tickets may be reimbursable as long as the changes are driven by the work requirement.
All travel will be reimbursed at cost in accordance with the Federal Travel Regulations (FTR).
The Contractor shall seek written Government approval (Contracting Officer (CO) or Contracting Officer Representative (COR)) at least two weeks in advance, prior to incurring any costs associated with non-local travel.
The Contractor shall use the federal lodging and per diem allowances in accordance with FAR
Section B subpart 31.205-46 and the applicable FTR governing the travel performed directly referable to this contract. The Government will not reimburse transportation costs in excess of coach class commercially scheduled air or ground transportation by the most expeditious route.
[THE BALANCE OF THIS PAGE IS INTENTIONALLY LEFT BLANK]
[END OF SECTION B]
Section C
SECTION C:
DESCRIPTION/SPECIFICATIONS/
PERFORMANCE WORK STATEMENT
C.1 Contractor shall provide all requirements within the contract’s Performance Work Statement (PWS), and within the terms and conditions of the resultant contract
C.2 See Attachment 1 for the contract’s PWS.
[END OF SECTION C]
Section D
SECTION D:
PACKAGING & MARKING
[THIS SECTION IS INTENTIONALLY LEFT BLANK]
[END OF SECTION D]
Section E
SECTION E:
INSPECTION AND ACCEPTANCE
E.1 CLAUSES INCORPORATED BY REFERENCE (FAR 52.252-2) (FEB 1998)
This contract incorporates the following clauses by reference with the same force and effect as if they were given in full text. Upon request, the Contracting Officer (CO) will make their full text available. Also, the full text can be accessed electronically at this internet address:
https://www.acquisition.gov/far/.
FAR TITLE DATE
52.212-4 Contract Terms and Conditions-Commercial Products and Commercial Services (Alt I) Nov 2021
52.246-4 Inspection of Services – Fixed Price Aug 1996 52.246-6 Inspection of Services – Time and Material and Labor
Hour May 2001
E.2 INSPECTION REQUIREMENTS
Review of Deliverables ---
a. The Contractor shall provide the deliverables to the Contracting Officer Representative
(COR) and Contracting Officer (CO). The COR may reject or require correction of any deficiencies found in the deliverables. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejections.
For all deliverable due dates that fall on a weekend or federal holiday, the deliverable will be due the following working day. “Days” refers to calendar days unless otherwise specified.
b. In the event the contractor anticipates difficulty in complying with any delivery schedule, the contractor shall immediately provide written notice to the CO and COR. Each notification shall give pertinent details, including the date by which the contractor expects to make delivery; provided that this data shall be informational only in character and that receipt thereof shall not be construed as a waiver by the Government of any contract delivery schedule, or any rights or remedies provided by law or under this contract.
c. The CO or COR will provide written acceptance, comments and/or change requests, if any, within twenty (20) days from receipt by the Government of the initial deliverable.
d. Upon receipt of the Government comments, the contractor shall incorporate the comments and/or change requests and to resubmit the deliverable in its final form.
http://acquisition.gov/far/index.html http://acquisition.gov/far/index.html
e. If written acceptance, comments and/or change requests are not issued by the Government within twenty (20) calendar days of submission, the draft deliverable shall be deemed acceptable as written, and the contractor may proceed with the submission of the final deliverable product.
f. If a contractor is non-compliant in submission of deliverables, the Government will document the non-compliance in any requested contractor’s past performance report and may draft a Contractor Discrepancy Report (CDR).
E.3 DELIVERABLES CHART
Deliverable Title Delivery Time/Frequency Format PWS
Reference Acceptable Quality
Level Non-Disclosure Agreement (NDA) The Contractor shall provide all NDAs to the COR
No later than 5 days after contract award or 5 days after entry on duty (EOD) of each new hire
PDF 1.18 Received timely
Monthly recruiting/retention report
10th day of the following month
PDF or MS Office Product
1.7 (d)(2) Received timely
Monthly contract status report
10th day of the following month
PDF or MS Office Product
1.7 (d)(3) Received timely
Bi-weekly Communication Dashboard Report
Every two weeks
Teams Meeting 1.7 (d)(4) Received timely
Quality Control Plan (QCP)
No later than 30 days after the contract award. Final version due within 5 calendar days of Government’s review of draft.
Draft – Word, Final -
1.8.2
Draft – received on time. Final Version - Accurate, complete, received on time.
Monthly Invoice Due by the 10th calendar day of each Month.
Electronic 1.21 Received on time
Ad Hoc Reports Due within 5 working days of request Electronic 2.1 Accurate, complete, and received on time
Post Award Conference (Kick-off Meeting) Minutes
Draft due within 7 calendar days after meeting. Final version due within 5 calendar days of Government’s review of Draft.
Draft – Word, Final -
2.2
Draft – received on time. Final Version - Accurate, complete, received on time.
Transition Plan
Draft due within 7 calendar days after the award of the contract.
Final version due
Draft – Word, Final -
1.23.
Draft – received on time. Final Version - Accurate, complete, received on time.
Deliverable Title Delivery Time/Frequency Format PWS
Reference Acceptable Quality
Level within 5 days after Government’s review of draft.
Project Manager(s) Resume
Draft due 14 calendar days after contract award. Personnel change due 14 calendar days after notification.
Draft – Word, Final -
1.24. Received on time
E.4 ACCEPTANCE CRITERIA
Deliverables will be deemed acceptable if the document adequately covers all required topics;
meets general quality measures; is professionally prepared in terms of format, clarity, and readability; and is delivered on time via a government approved site. General quality measures, as set forth below, will be applied to each work product received from the Contractor under this performance work statement.
• Accuracy - Work products shall be accurate in presentation, technical content, and adherence to accepted elements of style.
• Clarity - Work products shall be clear and concise. The wording should adhere to the simple language requirements to the extent possible. Any/all diagrams and graphics shall be easy to understand and be relevant to the supporting narrative.
• Consistency to Requirements - All work products must satisfy the requirements of this performance work statement.
• Editable file formats - All text and diagrammatic files shall be editable by the Government, if requested.
• Format - All work products should adhere to any format/template requirements provided by the Government.
• Medium - Work products shall be submitted on media mutually agreed upon prior to submission.
• Timeliness - Work products shall be submitted on or before the due date specified in this performance work statement or submitted in accordance with a later scheduled date determined by the Government.
E.5 QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
Services will be evaluated in accordance with the metrics outlined in the QASP (see Attachment 5).
[END OF SECTION E]
Section F
SECTION F:
DELIVERIES OR PERFORMANCE
F.1 CLAUSES INCORPORATED BY REFERENCE (FAR 52.252-2) (FEB 1998)
This contract incorporates the following clauses by reference with the same force and effect as if they were given in full text. Upon request, the CO will make their full text available.
Also, the full text can be accessed electronically at this internet address: https://www.acquisition.gov/far
52.242-15 Stop Work Order Aug 1989
F.2 PERIOD OF PERFORMANCE
The contract’s anticipated period of performance, when awarded, has an anticipated period of performance which will include a base period of one (1) year and four (4) one-year options in accordance with FAR 17.2. Included in the base period will be a one-month transition period and 11-month operational period. The option to extend services for up to six (6) months, in accordance with FAR 52.217-8, is being evaluated but will not be listed as a separate CLIN. The associated cost will not be included in the overall price of the contract.
The anticipated period of performance is as follows:
Note: Actual dates will be incorporated in the specific CLIN once the award date is finalized.
Until then general periods are included for planning purposes.
Period of Performance Dates Base Period (inclusive of 30-day transition period) 12 months
Option 1 12 months Option 2 12 months Option 3 12 months Option 4 12 months
F.3 OPTION PERIOD OF PERFORMANCE AND PRICING
The period of performance of the option periods issued under the contract shall not exceed twelve months and shall be priced using the rates provided Attachment 2 – Pricing Template, that will be applicable to the option periods anticipated period of performance.
https://www.acquisition.gov/far
Section F
F.4 PLACE OF PERFORMANCE
The Contractor shall perform the services at Government facilities, including Government leased facilities, located in the United States, including Puerto Rico. See PWS Section 1.16.1 for a list of locations and addresses.
F.5 NOTICE OF DELAYS
In the event the contractor encounters difficulty in meeting performance requirements, or when it anticipates difficulty in complying with the contract delivery schedule, or as soon as the contractor has knowledge that any actual or potential situation is delaying or threatens to delay the timely performance of this contract, the contractor shall immediately notify the CO, PM and the COR in writing. This notification shall give pertinent details and this data shall be informational only in character; this provision shall not be construed as a waiver by the Government of any delivery schedule or date, or any rights or remedies provided by law or under this contract.
F.6 CONTRACTOR EVALUATING PROCEDURES:
The Government will issue contractor performance ratings for each awarded requirement from this solicitation via the Contractor Performance Assessment Reporting System (CPARS) in accordance with FAR 42.1502. The CPARS website is located: http://www.cpars.gov.
[END OF SECTION F]
http://www.cpars.gov/
Section G
SECTION G:
CONTRACT ADMINISTRATION DATA
G.1 CONTRACT ADMINISTRATION
Notwithstanding the contractor’s responsibility for total management responsibility during the performance of this contract, the administration of the contract will require maximum coordination between the ICE and the contractor.
The following will describe the roles and responsibilities of individuals and/or authorized users who will be the primary Points of Contact (POC) for the Government on matters regarding contract administration as well as other administrative information. The Government reserves the right to unilaterally change any of these individual assignments at any time.
Contracting Officer’s Representative (COR) The COR within the Office of Principal Legal Advisor (OPLA), is responsible for the receipt and acceptance of the contract-level deliverables and reports and past performance reporting for the contract. The COR supports the CO in the general management of the acquisition. The CORs for OPLA Administrative Support Services are:
Contracting Officer Representative (COR):
West locations Marilyn Doty 214-293-6977 marilyn.l.doty@ice.dhs.gov
Contracting Officer Representative (COR):
East locations Mark Gonzales 678-943-0270 mark.r.gonzales@ice.dhs.gov
The COR for this contract will be identified by the CO through a written designation. A copy of the letter of designation with specific duties and responsibilities will be provided to the contractor.
The COR will represent the CO in the administration of technical details within the scope of the task order. The COR is also responsible for the final inspection and acceptance of all contract deliverables and reports. The COR is not otherwise authorized to make any representations or commitments of any kind on behalf of the CO or the Government. The COR does not have authority to alter the contractor’s obligations or to change the contract specifications, price, terms or conditions. If, as a result of technical discussions, it is desirable to modify contract obligations or the specification, changes will be issued in writing and signed by the CO.
Contracting Officer (CO) The ICE Office of Acquisition Management has the overall responsibility for administration of the OPLA Administrative Support Services contract. The CO, without right of delegation, mailto:marilyn.l.doty@ice.dhs.gov mailto:mark.r.gonzales@ice.dhs.gov is the only authorized individual to take actions on behalf of the Government to amend, modify or deviate from the contract terms, conditions, requirements, specifications, details and/or delivery schedules. The CO for this contract is:
Name: Tasha Wang Email: Tasha.Wang@ice.dhs.gov Telephone Number: 682-308-7915
G.2 MINIMUM CONTRACTOR KEY PERSONNEL
The minimum contractor key personnel are described in the PWS. Please see attached PWS.
G.3 UNILATERAL ORDERS
Modifications under this contract may be issued unilaterally. If the parties fail to agree, the CO may require the contractor to perform, and any disagreement shall be deemed a dispute within the framework of the "Disputes" clause at FAR 52.233-1.
G.4 INVOICE REQUIREMENTS
1. The contractor shall be active in the System for Award Management (www.SAM.gov) for invoice processing. Besides the information identified below, a proper invoice shall also include; contractor’s Unique Entity Identifier (UEI); the ICE Program Office; and state whether the invoice is “INTERIM” or “FINAL”.
2. In accordance with Contract Clauses, FAR 52.212-4 (g) (1), Contract Terms and
Conditions - Commercial Items, or FAR 52.232-25 (a) (3), Prompt Payment, as applicable, the information required with each invoice submission is as follows:
"...An invoice must include-
(i) Name and address of the contractor. The name, address and UEI on the invoice MUST match the information in both the Contract/Agreement and the information in SAM;
(ii) Unique Entity Identifier (UEI);
(iii) Invoice date and number;
(iv) Contract number, line items and, if applicable, the order number;
(v) Description, quantity, unit of measure, unit price and extended price of the items delivered;
(vi) Shipping number and date of shipment, including the bill of lading number and weight of shipment if shipped on Government bill of lading;
(vii) Terms of any discount for prompt payment offered;
(viii) Remit to Address;
(ix) Name, title, and phone number of persons to notify in event of defective invoice;
(x) ICE Program Office designated on the order/contract/agreement; and
(xi) Whether the invoice is “Interim” or “Final” mailto:Tasha.Wang@ice.dhs.gov
3. Invoice submission: shall be submitted via one of the following two methods. Improper invoices or those submitted by means other than these two methods will be returned.
Email is the preferred method.
(i) Primary method of submission is email. The contractor shall submit one (1) invoice in PDF format per e-mail and the subject line of the e-mail will reference the invoice number of the attached invoice to: Invoice.Consolidation@ice.dhs.gov
Attn: ICE-OPLA Invoice
(ii) Mail:
DHS, ICE
Financial Service Center Burlington
Attn: ICE-OPLA Invoice P.O. Box 1620 Williston, VT 05495-1620
(iii)Electronic Funds Transfer (EFT) banking information in accordance with 52.232- 33 Payment by Electronic Funds Transfer – System for Award Management or 52-232-34, Payment by Electronic Funds Transfer – Other than System for Award Management.
4. Invoice Supporting Documentation. To ensure payment, the vendor must submit supporting documentation which provides substantiation for the invoiced costs to the Contracting Officer Representative (COR) or Point of Contact (POC) identified in the contract. Invoice charges must align with the contract CLINs. Supporting documentation is required when guaranteed minimums are exceeded and when allowable costs are incurred. Details are as follows:
(i) Other Direct Costs. Costs associated with Contractor travel shall be in accordance with FAR Part 31.205-46, Travel Costs and Federal Travel Regulations, prescribed by the General Services Administration, for travel in the contiguous United States. The contractor is required to submit invoice supporting documentation for all travel during the invoice period which provides the information described below:
1) The invoice shall include appropriate supporting documentation for any direct charge billed for reimbursement. For travel, contain the names of individuals traveling, dates, destination, purpose, and costs of the travel.
2) The contractor shall submit receipts or other documents supporting other direct costs billed to the contract, such as the purchase of personal protective equipment (PPE).
(ii) Firm Fixed-Price CLINs. Supporting documentation is not required for charges for FFP CLINs.
5. Safeguarding Information: As a contractor or vendor conducting business with Immigration and Customs Enforcement (ICE), you are required to comply with DHS Policy regarding the safeguarding of Sensitive Personally Identifiable Information (PII).
Sensitive PII is information that identifies an individual, including an alien, and could result in harm, embarrassment, inconvenience or unfairness. Examples of Sensitive PII include information such as: Social Security Numbers, Alien Registration Numbers (A- Numbers), or combinations of information such as the individuals name or other unique identifier and full date of birth, citizenship, or immigration status.
As part of your obligation to safeguard information, the follow precautions are required:
(i) Email supporting documents containing Sensitive PII in an encrypted attachment with password sent separately to the Contracting Officer Representative (COR) assigned to the contract.
(ii) Never leave paper documents containing Sensitive PII unattended and unsecure.
When not in use, these documents will be locked in drawers, cabinets, desks, etc.
so the information is not accessible to those without a need to know.
(iii) Use shredders when discarding paper documents containing Sensitive PII.
(iv) Refer to the DHS Handbook for Safeguarding Sensitive Personally Identifiable
Information (March 2012) found at http://www.dhs.gov/xlibrary/assets/privacy/dhs-privacy-safeguardingsensitivepiihandbook-march2012.pdf for more information on and/or examples of Sensitive PII.
6. Payment Inquiries: Questions regarding invoice submission or payment, please contact
Financial Service Center Burlington at 1-877-491-6521, Option # 3 or by e-mail at OCFO.CustomerService@ice.dhs.gov
Invoices without the above information may be returned for resubmission.
[END OF SECTION G]
Section H
SECTION H:
SPECIAL CONTRACT REQUIREMENTS
H.1. SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to:
name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the CO, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various management directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01- 007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://csrc.nist.gov/publications/PubsSPs.html
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the COR no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (most current version), or any successor publication, DHS 4300A Sensitive Systems Handbook (most current version), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the CO shall incorporate the
ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed.
As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90-day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the CO and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS.
Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis.
The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the CO may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.
f) Sensitive Information Incident Reporting Requirements.
(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the CO, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the CO’s email address is not immediately available, the contractor shall contact the CO immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email.
Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information or has otherwise failed to meet the requirements of the contract.
(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
(i) Unique Entity Identifier (UEI);
(ii) Contract numbers affected unless all contracts by the company are affected;
(iii) Facility CAGE code if the location of the event is different than the prime contractor location;
(iv) Point of contact (POC) if different than the POC recorded in the System for
Award Management (address, position, telephone, email);
(v) CO POC (address, telephone, email);
(vi) Contract clearance level;
(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;
(viii) Government programs, platforms or systems involved;
(ix) Location(s) of incident;
(x) Date and time the incident was discovered;
(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;
(xii) Description of the Government PII and/or SPII contained within the system;
(xiii) Number of people potentially affected, and the estimate or actual number of records exposed and/or contained within the system; and
(xiv) Any additional information relevant to the incident.
g) Sensitive Information Incident Response Requirements.
(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the CO in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.
(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:
(i) Inspections,
(ii) Investigations,
(iii) Forensic reviews, and
(iv) Data analyses and processing.
(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.
h) Additional PII and/or SPII Notification Requirements.
(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the CO. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the CO, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the CO, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.
(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:
(i) A brief description of the incident;
(ii) A description of the types of PII and SPII involved;
(iii)A statement as to whether the PII or SPII was encrypted or protected by other means;
(iv) Steps individuals may take to protect themselves;
(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and
(vi) Information identifying who individuals may contact for additional information.
i) Credit Monitoring Requirements. In the event that a sensitive information incident involves PII or SPII, the Contractor may be required to, as directed by the CO:
(1) Provide notification to affected individuals as described above; and/or
(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified. Credit monitoring services shall be provided from a company with which the Contractor has no affiliation. At a minimum, credit monitoring services shall include:
(i) Triple credit bureau monitoring;
(ii) Daily customer service;
(iii)Alerts provided to the individual for changes and fraud; and
(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or
(3) Establish a dedicated call center. Call center services shall include:
(i) A dedicated telephone number to contact customer service within a fixed period;
(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;
(iii)Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics;
(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate;
(v) Customized FAQs, approved in writing by the CO in coordination with the Headquarters or Component Chief Privacy Officer; and
(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.
j) Certification of Sanitization of Government and Government-Activity-Related
Files and Information. As part of contract closeout, the Contractor shall submit the certification to the COR and the CO following the template provided in NIST Special Publication 800-88 Guidelines for Media Sanitization.
H.2. INFORMATION TECHNOLOGY SECURITY AND PRIVACY TRAINING
(MAR 2015)
(a) Applicability. This clause applies to the contractor, its subcontractors, and contractor employees (hereafter referred to collectively as “contractor”). The contractor shall insert the substance of this clause in all subcontracts.
(b) Security Training Requirements.
(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change.
The Department of Homeland Security (DHS) requires that Contractor employees take an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors.
The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year. The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.
(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within thirty (30) days of contract award.
Any new Contractor employees assigned to the contract shall also sign the DHS Rules of Behavior before accessing DHS systems and sensitive information. The Contractor shall maintain signed copies of the DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, the Contractor shall e-mail copies of the signed DHS Rules of Behavior to the COR not later than thirty (30) days after contract award for each employee. The DHS Rules of Behavior will be reviewed annually, and the COR will provide notification when a review is required.
(c) Privacy Training Requirements. All Contractor and subcontractor employees that will have access to Personally Identifiable Information (PII) and/or Sensitive PII (SPII) are required to take Privacy at DHS: Protecting Personal Information before accessing PII and/or SPII. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors.
Training shall be…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .