AMENDMENT.pdf

PDF 227 KB Posted

Attached to
INTERNET BASED THREAT RISK MITIGATION AND MONITORING SERVICES Federal contract opportunity
Solicitation number
70CMSW20R00000002
Issued by
Immigration and Customs Enforcement

About this file

This solicitation requests proposals for internet-based threat risk mitigation and monitoring services. The selected contractor must provide threat monitoring, vulnerability assessments, and reporting for Immigration and Customs Enforcement personnel, facilities, and operations. Key requirements include daily monitoring of open sources and social media in multiple tiers, monthly vulnerability assessments, and ad-hoc reports within 24 hours as requested. The contractor must also implement continuous alerting of imminent threats. The base period of performance is one year with four one-year options. Pricing will be firm fixed price. Proposals are due by March 6, 2020, with award by March 21, 2020. Security screening is required for contractor employees.

View the file

Other files for this federal contract opportunity

Other files attached to INTERNET BASED THREAT RISK MITIGATION AND MONITORING SERVICES, newest first.
File Type Posted
SOLICITATION.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

(x)

70CMSW20R00000002

x x

1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted ; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGEMENT TO BE RECEIVED AT

THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted , such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

x

Washington DC 20536 Attn: Yasmin Atkins

ICE/MS-DC

801 I Street NW, Suite 800 Office of Acquisition Management Immigration and Customs Enforcement ICE/Mission Support-DC

Washington DC 20536

ICE/MS-DC

801 I Street NW, Suite 800 Office of Acquisition Management Immigration and Customs Enforcement ICE/Mission Support-DC

02/28/20200001

13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

12. ACCOUNTING AND APPROPRIATION DATA (If required) is not extended.is extended, Items 8 and 15, and returning

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended , by one of the following methods: (a) By completing

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

FACILITY CODE CODE

10B. DATED (SEE ITEM 13)

10A. MODIFICATION OF CONTRACT/ORDER NO.

9B. DATED (SEE ITEM 11)

9A. AMENDMENT OF SOLICITATION NO.

CODE

8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)

7. ADMINISTERED BY (If other than Item 6)CODE 6. ISSUED BY

PAGE OF PAGES

4. REQUISITION/PURCHASE REQ. NO.3. EFFECTIVE DATE2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO. (If applicable)

1. CONTRACT ID CODE

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

02/28/2020

CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority) appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

E. IMPORTANT: Contractor is not, is required to sign this document and return __________________ copies to the issuing office.

ORDER NO. IN ITEM 10A.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

Amendment 0001 is hereby issued to:

1) Provide answers to questions submitted by industry, and

2) Provide an updated Statement of Objectives (SOO) with updates notated in red.

A signed copy of the original SF 1449 and amendment must be submitted with all proposal submissions.

Period of Performance: 02/28/2020 to 03/06/2020

16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)15A. NAME AND TITLE OF SIGNER (Type or print)

15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 15B. CONTRACTOR/OFFEROR 16C. DATE SIGNED

(Signature of person authorized to sign) (Signature of Contracting Officer)

RYAN MACDONALD

STANDARD FORM 30 (REV. 10-83)

Prescribed by GSA

FAR (48 CFR) 53.243

NSN 7540-01-152-8070

Previous edition unusable

Except as provided herein, all terms and conditions of the document referenced in Item 9 A or 10A, as heretofore changed, remains unchanged and in full force and effect .

Internet Based Threat Risk Mitigation and Monitoring Services

RFP 70CMSW20R00000002

Response to Vendors Questions Amendment 0001

Page # Identifier Question Response

Submission Instructions

(Page 8)

One week to deliver a full technical proposal and product sample is a very truncated timeline. Would the government please provide an extension to next Wednesday (March 11th) to allow offerors adequate time to respond and update technical proposals once questions are answered?

No extensions are granted

3.4 Factor 4 –

Price (Page 12)

Will the government allow an ODC line for technology tools / subscriptions to be used in direct support of this SOW? If so, should that be captured as an ODC CLIN in the pricing volume and also in an offeror’s assumptions as well?

No

3.3 Factor 3 – Past

Performance (Page 12)

Will the government evaluate recent and relevant Past Performance from the commercial sector equally to Past Performance submitted supporting the government?

Yes

5.0 Task

Objectives (Page 17)

Is this requirement for 24/7/365 services? If not, are weekend and holiday reports required as part of the daily reporting?

These services do not require 24-hour support; however, the contractor must have the ability to search required platforms and provide necessary support outside of normal business hours, including weekends and holidays on the next business day.

5.1 Vulnerability

Assessments (Page 17)

Approximately how many ad hoc vulnerability assessments does the government envision per year?

This will be important to help determine Level of Effort for the scope of work.

The government defers to the vendor(s) for a determination on the number of FTE’s needed to fulfill the objectives outlined in the Statement of Objectives.

6 5.1 Vulnerability Assessments

Approximately how many ad hoc threat reports does the

The government has historically requested 50

Response to Vendors Questions Amendment 0001

(Page 17) government envision per year?

This will be important to help determine Level of Effort for the scope of work.

such ad hoc reports.

However, the government cannot accurately predict/anticipate the number of reports it will require as these numbers are determined by several outside factors driving threat activity.

5.2. Proactive

Threat Monitoring

& Report Requirements

(Page 18)

The government requests that offerors “Identify whether a user has deleted messages and provide content from deleted accounts and/or deleted messages.” Some online platforms allow for this, while others do not.

Would the government consider adding “Where applicable, identify whether a user has deleted messages and provide content from deleted accounts and/or deleted messages.” to this clause to ensure it is a reasonable requirement?

Language has been changed to reflect “where applicable.”

5.3 / 5.4 Data Sources and Open

Social Media Sources

(Page 19)

Would the government consider revising the PWS language on Page 19 to the follow: “Data and Sources to include, where applicable:" & Open Social Media to include, where applicable:"?

Language has been changed.

5.3 / 5.4 Data Sources and Open

Social Media Sources

(Page 19)

Would the government consider removal of Vine, a now defunct social media platform, under social media data sources?

Vine has created an app called Vine Camera which allows the positing of video to Twitter and possibly other platforms. Vine can be removed if the contractor can capture this information via other sources. Google+ can be removed.

10 6.0 Deliverables (Page 20)

There are additional Ad Hoc deliverables outlined in Sections

Yes.

Response to Vendors Questions Amendment 0001

5.1 / 5.2 that do not appear in the deliverables found in this table. Should these deliverables be included in the level of effort?

Security

Requirements (Page 26)

Are clearances required for this work beyond the DHS Preliminary Fitness Determination? If so, what level is needed (e.g. Secret, Top Secret, TS/SCI)?

A standard Background Investigation is required as outlined in the SOO.

Otherwise, there is no clearance requirement for this work.

Security

Requirements (Page 27)

Do active DoD clearances count at “adequate, current investigation by another Federal Agency”?

A standard Background Investigation is required as outlined in the SOO.

Otherwise, there is no clearance requirement for this work.

13 N/A Who is the current incumbent on this contract and what is the dollar value of the contract?

Currently this work is not being performed. No current incumbent.

14 Section 5.1, Page

Section 5.1, Page 17, requests "Assessments and/or searches shall involve real-time aggregating open source information using unique identifiers for related association, enhanced data analytics..." Please specify what the Government means by 'enhanced data analytics.’

This language has been changed.

15 Section 5.2, Page

Section 5.2, Page 17, asks that the program offer "automatic alerts." Can the office please offer more details on what it expects from this requirement?

For example, in what circumstances or scenarios are these expected and does the Government expect the contractor to relay these alerts to the Government?

Continuous monitoring and alerting on imminent threats (via email notification ) 24/7). Alerts should include screen rendering of threat and any other information available at the time.

Further analysis will be provided in the next daily report.

16 N/A

Does the Government have clear metrics that they wish to share or would the Government be willing to work with the

The government would be willing to discuss key words and behaviors with the vendor to build out a model.

Response to Vendors Questions Amendment 0001 contractor to identify specific metrics to be used for identifying threatening actors and placing them on a threat scale to maintain standardization? For example, would the Government be willing to identify keywords, behaviors, and other criteria to build out the contractor's models?

17 Section 5.2, Page

Section 5.2, Page 4, requests Psychological Profiles. Does the Government have any more information about what the office wants to include in these deliverables?

The government requires the vendor to have the ability to develop a report outlining person’s on-line social media profile.

18 Section 5.2, Page

Section 5.2, Page 18, requests that the contractor "provide detailed daily, weekly, monthly and end of year/contract reporting, and ADHOC reporting on results with mitigating recommendations..."

Can the Government please define 'mitigating recommendations.’

This language has been changed to remove the requirement for providing “mitigating recommendations.”

19 Section 14.2, Page

Section 14.2, Page 23 states that the contractor will not access restricted sources, however, Section 5.2, Page 18, states that the program requires the “ability to determine which websites were accessed by users prior to making a threat.” Does one of these requirements take precedence over the other? Can the Government explain how they wish to proceed with these requirements?

This language has been changed for clarification:

(via publicly facing information) which social media websites were accessed by users prior to making a threat. In other words, the government is requesting a chronological history of a user’s publicly available social media postings.

20 Section 1.2

Section 1.2, Page Limitations– Please confirm this offeror’s understanding that in accordance with standard

Confirmed

Response to Vendors Questions Amendment 0001 industry practice, cover pages, cover letters, tables of contents, and terms and conditions do not apply toward the total page count.

21 Section 1.3

Section 1.3, Page Size and Format – Does the request for a black and white response only include graphics and headings?

Graphics and headings not included

22 Section 1.3

Section 1.3, Page Size and Format – Please confirm this offeror’s understanding that in accordance with standard industry practice, that the font size for graphics and tables can be smaller than 12 point font.

All font size must be 12 point or greater

23 Section 13.0

Statement of Objectives, Section 13.0, Business Relations – This section requires a Quality Control Plan (QCP) within 15 days of contract award, but the deliverables table in Section 6, Deliverables, does not list the Quality Control Plan. Please confirm our understanding that a QCP shall be delivered within 15 business days of contract award.

QCP shall be delivered within 15 business days of contract award

DEPARTMENT OF HOMELAND SECURITY (DHS)

U.S. IMMIGRATION AND CUSTOMS ENFORCEMENT (ICE)

ICE DIRECTOR’S OFFICE

INTERNET BASED THREAT RISK MITIGATION AND MONITORING SERVICES

STATEMENT OF OBJECTIVES

March 3, 2020

1. Background:

ICE’s mission is to promote homeland security and public safety through the criminal and civil enforcement of approximately 400 federal laws governing border control, customs, trade and immigration.

Over the last two years, ICE has experienced an increased level of external threat activity directed towards its Senior leaders, personnel and facilities. Much of this threat activity originates from social media and online postings and has since expanded to physical attacks on ICE facilities and the homes of ICE employees. In order to prevent adversaries from successfully targeting ICE Senior leaders, personnel and facilities, ICE requires real-time threat mitigation and monitoring services, vulnerability assessments, and proactive threat monitoring services.

2. Point of Contact

The Contractor shall provide a point of contact responsible for coordinating work performance. The point of contact shall have full authority to act on behalf of the Contractor on all matters relating to the daily operation of this contract. The Government point of contact will be the Contracting Officer’s Representative (COR) as later determined and delegated.

3. Description of Services/Introduction:

The Contractor shall provide all necessary personnel, supervision, management, equipment, materials and services, except for those provided by the Government, in support of ICE’s desire to protect ICE Senior Leaders, personnel and facilities, who face threats or harm, via internet-based threat mitigation and monitoring services. These efforts include conducting vulnerability assessments and proactive threat monitoring.

Minimum services include full data aggregation to provide proactive threat monitoring and vulnerability assessments stipulated in the following Tasks Objectives in Section 5. The Contractor will utilize the following Tier Level categories to identify the minimum deliverable and reporting requirements as stipulated in Section 6.

Tier Level Tier Level Coverage Tier Level Description

Tier 1 ICE Senior Leaders (Minimum 12 Targets)

Tier 1 provides detailed and tailored executive open-source Vulnerability Assessments and Proactive Threat Monitoring for ICE Senior Leaders, and, as requested by ICE OPR, their immediate family members.

Tier 2

General ICE Population and Facilities

(Minimum 100 Targets)

Tier 2 provides detailed open-source Vulnerability Assessments and Proactive Threat Monitoring for threats towards ICE employees and facilities in general. Tier 2 will also provide for the assessment and monitoring of threats and/or disruptions to general ICE operations.

Tier 3

Specific ICE Employees, Operations and Facilities as requested by ICE OPR (Minimum 15 Targets)

Tier 3 provides detailed open-source Vulnerability Assessments and Proactive Threat Monitoring for threats against designated ICE employees, their immediate family members and facilities on an AD-HOC basis. Tier 3 will also provide for the assessment and monitoring of threats and/or disruptions to specific ICE operations as requested.

4. Service Provider – Non-Personal Services

DHS retains the authority to make all decisions regarding the DHS mission, and the execution or interpretation of laws of the United States. Contactor Services defined are not considered to be inherently Governmental in nature, as defined by Federal Acquisition Regulation (FAR) Subpart 7.5.

This is a Non-Personal services contract as defined by FAR Subpart 37.101. Contractor personnel rendering services under this order are not subject to supervision or control by Government personnel.

The Contractor will be responsible for the supervision of the Contractor employees at all duty locations. The Contractor is expected to work independently to accomplish the requirements of this order. The Contractor must generate reports and other deliverables as specified in the Statement of Objectives as outlined in Sections 3, 5 and 6. The government will neither supervise contractor employees nor control the method by which the Contractor performs the required tasks. Under no circumstances will the government assign tasks or prepare work schedules for individual contractor employees. It shall be the responsibility of the Contractor to manage its employees and to guard against any actions that are of the nature of personal services or give the perception of personal services. If the Contractor believes that any actions constitute or are perceived to constitute personal services, the Contractor must notify the Contracting Officer (CO) immediately.

5. Task Objectives:

5.1. Vulnerability Assessments

Evaluate and conduct Tier 1 vulnerability assessments using proprietary and publicly available electronic information associated or regarding designated ICE Senior Leaders to identify threats, the exploitation of Protection Plans, and other risk factors. This assessment will be provided within five (5) business days from the award the contract.

Evaluate and conduct Tier 2 vulnerability assessments using proprietary and publicly available electronic information associated or regarding threats to the general ICE population and facilities, as well as threats and/or disruptions to ICE operations. This assessment will be provided within five (5) business days of a request from ICE OPR.

Evaluate and conduct Tier 3 vulnerability assessments using proprietary and publicly available electronic information associated or regarding designated ICE personnel, facilities and operations. These assessments will be provided on an ADHOC basis as requested by

ICE OPR.

Assessments and/or searches shall involve real-time aggregating open source information using unique identifiers for related association, data analytics, and analytic reporting on sentiment and other related factors.

Assessments will include queries to determine what personally identifiable information is publicly available about those in categories Tier 1, 2 and 3 (Phone numbers, addresses, relatives, etc.).

Conduct analytics by utilizing social and behavioral sciences to multiple data sets to locate dangerous individuals posing a possible threat to categories Tier 1, 2 and 3.

Conduct real-time Deep Web and Dark Web searches to identify possible threats against categories Tier 1, 2 and 3.

Conduct open source searches using key-terms and geolocation properties relative or associated with categories Tier 1, 2 and 3.

Immediately notify ICE OPR via electronic means of imminent threats.

Supply ADHOC vulnerability assessments of personnel, locations and facilities as requested by ICE OPR.

5.2. Proactive Threat Monitoring & Report Requirements

Provide a secure and proactive threat monitoring program that contains automatic alerts.

Provide monitoring and analysis of behavioral and social media sentiment (i.e. positive, neutral, and negative) based on a time of day, a week, a month-long period.

Upon system outages, capability to immediately complete searches to recover any lost or potentially lost threat information.

Provide ADHOC searches and reporting when notified by ICE OPR.

Provide secondary and/or follow-on real-time strategic monitoring of previous adverse findings.

Capability to save search criteria post obtaining adverse results, ADHOC queries, or for future queries.

Ensure searches and/or inquires on information and alerting procedures never reveal ICE’s affiliation.

Contractor will analyze individual(s) and/or organization(s) making threats. Analysis should include: 1). Previous social media activity which would indicate any additional threats to ICE; 2). Information which would indicate the individual(s) and/or the organization(s) making threats have a proclivity for violence; and 3). Information indicating a potential for carrying out a threat (such as postings depicting weapons, acts of violence, refences to acts of violence , to include empathy or affiliation with a group which has violent tendencies; references to violent acts; affections with violent acts; eluding to violent acts, etc.).

Monitor and analyze all social media activities (including foreign/dark web/deep web social media networks) in REAL-TIME.

Conduct correlation of users’ social media accounts.

Provides psychological profiles.

Geo-locate individuals beyond standard geo-tagging. The government defines geo-locating as the ability to provide a specific location of the subject/threat actor.

Identify any person or group who has previously identified as having made a threat and individual(s) whose language that would potentially lead to violence directed towards ICE, Facilities, and employees has reached a level of concern.

Identify whether a user has deleted messages and provide content from deleted accounts and/or deleted messages where applicable.

Capability to identify threats by location.

Provide detailed daily, weekly, monthly and end of year/contract reporting, and ADHOC reporting in Adobe PDF or Microsoft Office format.

Provide ADHOC reports as requested by ICE OPR with the capability to adjust date ranges and identify threats by those made against ICE Senior Leaders, ICE employees, and facilities, as well as threat type.

All daily, weekly, monthly and end of year/contract reports will be provided even when there is no reportable activity.

All reports will include threat information in narrative form, including analytical summaries of identified threats and assessments.

All reports will contain statistical data in narrative form and will be depicted in graphs (bar charts, pie charts, etc.).

Statistical data provided in the reports should include information such as: 1). Total number of negative references to ICE found in social media during monitoring; 2). Total number of threats against Senior Leaders; 3). Total number of threats against ICE employees; 4). Total number of threats against ICE facilities/operations; 5). Trend analysis, such as the increase/decrease of threats for each of these categories during the requested period; and 6). Total number of threats by type.

Reports will identify ICE Senior Leaders, ICE employees or and facilities that have been repeatedly targeted.

Reports will provide all relevant information for threats identified by the contractor. This information shall include: 1). Screen renderings of threatening social media posts; 2). The real and social media identity of the threat originator; 2). Time, date and online platform through which the threat was made; and 3). Location and/or the identity of the ICE Senior Leader, ICE employee or facility identified in the threat.

Facial Recognition capabilities that could take a photograph of a subject and search the internet to find all relevant information associated with the subject that will help identify any individual making a threat and help cross reference the individual across multiple platforms.

At the request of OPR, the contractor needs to be able to adjust for the addition and removal of each Tier category from the monitoring list.

Link analysis indicating individual may be associated with other potential threats/threat actors (narrative, charts & graphs).

If threatening information is identified and in a foreign language, the contractor will provide the threat as it appears and provide a translation of the threat in English.

Monitoring capabilities need to include the ability to proactively search for any threatening information and/or information which would suggest a potential disruption in ICE operations by location.

Ability to determine (via publicly facing information) which social media websites were accessed by users prior to making a threat.

5.3. Data Sources (Required where applicable, but not limited to)

Open Source Information Portals Available Proprietary Sources Deep Web Content Dark Web Content IRC/Chat Message Boards

Online Broadcasting Websites Public Email Groups and Discussion Forums Social Media Sites USEnet Data Web Blogs World Wide Web

Public Records (Court records, police reports, DMV records, news reports, etc.)

5.4. Open Social Media Sources (Required where applicable, but not limited to)

Twitter Facebook Foursquare Instagram Snapchat LinkedIn Pinterest Applicable Foreign Social Media

Sites

WordPress StumbleUpon Tagged YouTube Tumblr Vine camera Bitly Flickr

6. Deliverables:

Acceptance by the Government of satisfactory products/services will be made once all the terms and conditions of the contract are fulfilled including the following delivery requirements:

Deliverable Task Frequency Receivers

Tier 1 - Report on findings All Daily (NLT 11:00 AM EST) Gov’t

POC

Tier 2 - Report on findings All Daily (NLT 11:00 AM EST) Gov’t

POC

Tier 3 - Report on findings All Daily (NLT 11:00 AM EST) Gov’t

POC

Vulnerability Assessment as Described in Section 5 Intimal Within 5 business days after award. Gov’t

POC

In-depth Monthly Vulnerability Assessment All Monthly (by the 1st calendar day of each month) Gov’t

POC

Continuous monitoring and alerting on imminent threats (via email notification) 24/7). Alerts should include screen rendering of threat and any other information available at the time. Further analysis will be provided in the next daily report.

All Immediately Gov’t

POC

ADHOC Report All As needed Gov’t

POC

Courtesy Invoice All Monthly (NLT the 15th calendar day of each Month) COR

6.1 Report Submission

The Contractor shall provide a daily report of identified threats. The Contractor shall curate all findings into two sections:

1. Threat Intelligence: This section shall include a daily risk assessment based on the day’s threat activity; a summary of post volume and change from previous period to provide contextual intelligence; a summary of key insights and identified threats, including the user platform, and language of the threat.

2. Social Media Overview: This section shall include a daily risk assessment based on the day’s threat activity; a summary of post volume and change from previous period to provide contextual intelligence; a summary of key insights and identified threats, including the user platform, and language of the threat.

Each report shall include screenshots of threatening posts and a summary of active hyperlinks to the source material. Each finding reports shall be delivered to ICE daily by 11:00 AM EST.

6.2 Monthly Vulnerability Assessment

The Contractor shall provide a monthly Vulnerability Assessment on all key identified ICE Personnel to mitigate threats to high-risk personnel. The Monthly Vulnerability Assessment shall provide a comprehensive understanding of an executive’s online exposure on social media, open source public record aggregators, and other open sources so ICE personnel can limit such exposure and remove vulnerable information adversaries could use to target ICE personnel.

The contractor can collect, analyze, and report on the full collection of openly available information on an identified individual and his immediate family, including spouse and children, in the Monthly Vulnerability Assessment.

All Monthly Vulnerability Assessments shall include:

1. An executive summary of key findings and identified threats.

2. An overview of the executive’s social media presence collected of all social media platforms and open sources. The overview details the social media presence of the executive and includes the publicly available information used to connect the executive to his or her immediate family, including spouse and children, on social media and/or in open sources. Screenshots and hyperlinks (where available) of all relevant findings shall be included.

3. A summary of the open source presence of the executive’s immediate family, including spouse and children. This summary details the analysis of open source public records for identifying information such as relatives, address, and phone number; social media; and open sources for key identifying and/or contextual details on a person’s pattern of life.

4. An overview of any relevant open source a Deep Web and Dark Web exposure identified during research which adversaries could use to target ICE personnel or their families.

5. A comprehensive listing of all identified open source exposures. This listing shall include, but not limited to; type (public records, social media, or open source), an indication of whether the site is active as of the assessment; the URL; details of the available information; details of any links to the executive under review and/or their immediate family; and details of any addresses or phone numbers listed on the source.

6.3 Ad Hoc Reporting

The Contractor shall develop and provide ICE Ad Hoc reports with actionable intelligence on identified threats within 24 hours periods. Once a threat is identified, the Contractor shall review a user’s available open source and social media activity to aid location of the associated individual.

The Ad Hoc reports shall be generated based on ICE guidance and request.

1. The Contractor shall provide public records details on the individual, as available. These details include, but are not limited to: Full legal name, date of birth, any aliases, Social Security Number (SSN), probable address(es), any relevant recent address(es), phone numbers, e-mail, work affiliations, vehicle registration information, and any criminal legal history, The

Contractor shall also provide a summary of the methodology used to determine the subjects identity.

2. The Contractor shall provide all available identifying information to aid ICE in identification when complete information is unavailable. These details can include, but are not limited to:

photograph, partial legal name, partial date of birth, possible city, possible work affiliations, possible school or university affiliation, and any identified possible family members or associates.

7. Government Furnished Information and Support

ICE will provide a list of entity(ies) that require Threat Mitigation and Monitoring Service.

8. Service Provider Furnished Items

8.1. The Contractor shall furnish all other facilities, equipment, and services required in the performance of this contract.

8.2. The Contractor is responsible for taking the actions necessary to protect supplies, material, and equipment and personal property of employees from loss, damage, or theft.

9. Approval Authority

Overall coordination, final approval and authority for this project are the responsibility of the ICE Office of Professional Responsibility. The Contracting Officer will be the administrative point of contact at ICE Office of Acquisition Management – Mission support (MS) for all official correspondence and information concerning this contract. Final acceptability or unacceptability of all deliverables and tasks performed by the Contractor is the responsibility of the OAQ-MS Contracting Officer.

A Contracting Officer’s Representative COR will be identified for this effort. The COR will recommend acceptance of the deliverable products, but only after concurrence from Government on-site Subject Matter Experts (SMEs) that deliverables are complete and correct.

10. Period of Performance

Performance Period Performance Period Dates

Base Period 03/21/2020 – 03/20/2021

Option Period 1 03/21/2021 – 03/20/2022

Option Period 2 03/21/2022 – 03/20/2023

Option Period 3 03/21/2023 – 03/20/2024

Option Period 4 03/24/2024 – 03/20/2025

11. Type of Performance

The contract type will be a Firm Fixed Price Contract.

12. Place of Performance

The Contractor shall accomplish the assigned work by employing and utilizing qualified personnel with appropriate combinations of education, training, and experience. The Contractor shall match personnel skills to the work or task with a minimum of under/over employment of resources. The Contractor shall provide the necessary resources and infrastructure to manage, perform, and administer the contract. Performance will not be at a government location.

13. Business Relations

The Contractor shall successfully integrate and coordinate all activity needed to execute the requirement. The Contractor shall manage the timeliness, completeness, and quality of problem identification. The Contractor shall provide corrective action plans, proposal submittals and timely identification of issues. The Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.

13.1. Quality Control: The Contractor will establish and maintain a complete Quality Control Plan (QCP). This plan will include expected services delivered, contractor procedures for review of delivered services, and other items that may have impact on the performance of this contract. The Contractor will submit their QCP within 15 business days of contract award. When changes are made to the QCP a revised plan will be submitted to the Government.

14. Constraints and Risks

14.1. Obtaining Information from Unrestricted Sources. When conducting social media searches, the Contractor may obtain information from publicly-accessible online sources and facilities under the same conditions they may obtain information from other sources generally open to the public. This principle applies to publicly-accessible sources located in foreign jurisdictions as well as those in the United States.

14.2. Accessing Restricted Sources. When conducting social media searches, the Contractor may not access restricted online sources or facilities.

14.3. Obtaining Identifying Information about Users or Networks. The Contractor may not use software tools, even those generally available as standard operating system software, to circumvent restrictions placed on system users.

14.4. Public Interaction. The Contractor may access publicly-available information only by reviewing posted information and may not interact with the individuals who posted the information.

14.5. Appropriating Online Identity. "Appropriating online identity" occurs when an entity electronically communicates with others by deliberately assuming the known online identity (such as the username) of a real person, without obtaining that person's consent. The Contractor may not use this technique to access information about individuals.

14.6. International Issues. Unless gathering information from online facilities configured for public access, Contractor personnel conducting the required service or deliverables should use reasonable efforts to ascertain whether any pertinent computer system, data, witness, or subject is located in a foreign jurisdiction. Whenever an item or person is located abroad, contractor personnel shall follow ICE's policies and procedures in providing the required service or deliverables.

14.7. PII Safeguards. The contractor will protect personally identifiable information (PII) as required by the Privacy Act and DHS privacy policy.

14.8. Complete ATO and Ongoing security scans and remediation for High Risk Sensitive contracts in accordance with HSAR Deviation 15-01.

15. Contract Management

The Contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned to the requirement. The Contractor must maintain continuity between the support operations at OPR and the Contractor's corporate offices.

16. Contract Administration

The Contractor shall establish processes and assign appropriate resources to effectively administer the requirement. The Contractor shall respond to government requests for contractual actions in a timely fashion. The Contractor shall have a single point of contact between the government and Contractor personnel assigned to support contracts or task orders. The Contractor shall assign work effort and maintaining proper and accurate time keeping records of personnel assigned to work on the requirement.

16.1. Monthly Invoices: The Contractor shall provide monthly invoices to the ICE Invoice Consolidation Office, CO, and COR for services completed within that calendar month. Invoices will separate and note costs per CLIN (Tier Level) for the billed Period of Performance (POP). POP dates for each monthly invoice shall begin with the first and end on the last date of that month.

16.1.1. Invoices shall be submitted no later than the 15th calendar day of the following month. Should the 15th calendar day of the month fall on a Federal holiday or weekend, the invoice shall be delivered to the COR the following business day.

16.1.2. When using Standard Form 1034, Public Voucher for Purchases and Services Other Than Personal, the inclusive dates of delivery of services must only be for the period for which the incurred costs are being claimed.

16.1.3. These invoice requirements are in addition to, not in place of, any invoice submission instructions provided by the CO at the time of award.

17. Acronym List

CO Contracting Officer COR Contracting Officer’s Representative DHS Department of Homeland Security HRI High Risk Indicators ICE Immigration and Customs Enforcement OPR Office of Professional Responsibility PSU Personnel Security Unit SME Subject Matter Expert SOO Statement of Objectives SOW Statement of Work POP Period of Performance

18. Federal Law Enforcement Sensitive

The data provided or processed within the ICE Office of Professional Responsibility shall be considered federal law enforcement sensitive, and, therefore, cannot be used to solicit or benefit other work by the Contractor. All records received, created, used, and maintained by the Contractor for this effort shall be protected as sensitive data, in accordance with government laws, to include the Federal Acquisition Regulation (FAR), Part 24, Protection of Privacy and Freedom of Information, and shall be returned and provided to the government upon contract completion. All reports created by the vendor shall be labeled “Law Enforcement Sensitive” at the top and bottom of each page in red.

All data created for government use and delivered to or falling under the legal control of the government are federal records and shall be managed in accordance with records management legislation as codified at 44 U.S.C. Chapters 21, 29, 31, and 33, the Freedom of Information Act (5 U.S.C. 552), and the Privacy Act (5 U.S.C. 552a), and shall be scheduled for disposition in accordance with 36 CFR 1228.

All contractor employees for this effort will also be required to sign a nondisclosure statement, Acknowledgement and Agreement Handling Sensitive Government Data and Other Government Property and are subject to the security requirements of the SOW/SOO. This form will be signed prior to beginning work for this effort.

19. Security Requirements

19.1 GENERAL

The United States Immigration and Customs Enforcement (ICE) has determined that performance of the tasks as described in Contract requires that the Contractor, subcontractor(s), vendor(s), etc. (herein known as Contractor) have access to sensitive DHS information, and that the Contractor will adhere to the following.

19.2 PRELIMINARY FITNESS DETERMINATION

ICE will exercise full control over granting, denying, withholding or terminating unescorted government facility and/or sensitive Government information access for contractor employees, based upon the results of a Fitness screening process. ICE may, as it deems appropriate, authorize and make a favorable expedited preliminary Fitness determination based on preliminary security checks. The preliminary Fitness determination will allow the contractor employee to commence work temporarily prior to the completion of a Full Field Background Investigation. The granting of a favorable preliminary Fitness shall not be considered as assurance that a favorable final Fitness determination will follow as a result thereof. The granting of preliminary Fitness or final Fitness shall in no way prevent, preclude, or bar the withdrawal or termination of any such access by ICE, at any time during the term of the contract. No employee of the Contractor shall be allowed to enter on duty and/or access sensitive information or systems without a favorable preliminary Fitness determination or final Fitness determination by the Office of Professional Responsibility, Personnel Security Unit (OPR- PSU). No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable preliminary Fitness determination or final Fitness determination by OPR-PSU.

Contract employees are processed under DHS Instruction 121-01-007-001 (Personnel Security, Suitability and Fitness Program), or successor thereto; those having direct contact with Detainees will also have 6 CFR § 115.117 considerations made as part of the Fitness screening process. (Sexual Abuse and Assault Prevention Standards) implemented pursuant to Public Law 108-79 (Prison Rape Elimination Act (PREA) of 2003)

19.3 BACKGROUND INVESTIGATIONS

Contractor employees (to include applicants, temporaries, part-time and replacement employees) under the contract, needing access to sensitive information and/or ICE Detainees, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted.

Background investigations will be processed through the Personnel Security Unit. Contractor employees nominated by a Contracting Officer Representative for consideration to support this contract shall submit the following security vetting documentation to OPR-PSU, through the Contracting Officer Representative (COR), within 10 days of notification by OPR-PSU of nomination by the COR and initiation of an Electronic Questionnaire for Investigation Processing (e-QIP) in the Office of Personnel Management (OPM) automated on-line system.

Standard Form 85P (Standard Form 85PS (With supplement to 85P required for armed positions)), “Questionnaire for Public Trust Positions” Form completed on-line and archived by the contractor employee in their OPM e-QIP account.

Signature Release Forms (Three total) generated by OPM e-QIP upon completion of Questionnaire (e-signature recommended/acceptable – instructions provided to applicant by OPR-PSU). Completed on-line and archived by the contractor employee in their OPM e-QIP account.

Two (2) SF 87 (Rev. December 2017) Fingerprint Cards. (Two Original Cards sent via COR to OPR-PSU)

Foreign National Relatives or Associates Statement. (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

DHS 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act” (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

Optional Form 306 Declaration for Federal Employment (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

If occupying PREA designated position: Questionnaire regarding conduct defined under 6 CFR § 115.117 (Sexual Abuse and Assault Prevention Standards) (This document sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

One additional document may be applicable if contractor employee was born abroad. If applicable, additional form and instructions will be provided to contractor employee.

(If applicable, the document will be sent as an attachment in an e-mail to contractor employee from OPR-PSU – must be signed and archived into contractor employee’s OPM e-QIP account prior to electronic “Release” of data via on-line account)

Contractor employees who have an adequate, current investigation by another Federal Agency may not be required to submit complete security packages; the investigation may be accepted under reciprocity.

The questionnaire related to 6 CFR § 115.117 listed above in item 7 will be required for positions designated under PREA.

An adequate and current investigation is one where the investigation is not more than five years old, meets the contract risk level requirement, and applicant has not had a break in service of more than two years. (Executive Order 13488 amended under Executive Order 13764/DHS Instruction 121-01-007-

01) Required information for submission of security packet will be provided by OPR-PSU at the time of award of the contract. Only complete packages will be accepted by the OPR-PSU as notified by the

COR.

To ensure adequate background investigative coverage, contractor employees must currently reside in the United States or its Territories. Additionally, contractor employees are required to have resided within the Unites States or its Territories for three or more years out of the last five (ICE retains the right to deem a contractor employee ineligible due to insufficient background coverage). This time-line is assessed based on the signature date of the standard form questionnaire submitted for the applied position. Contractor employees falling under the following situations may be exempt from the residency requirement: 1) work or worked for the U.S. Government in foreign countries in federal civilian or military capacities; 2) were or are dependents accompanying a federal civilian or a military employee serving in foreign countries so long as they were or are authorized by the U.S. Government to accompany their federal civilian or military sponsor in the foreign location; 3) worked as a contractor employee, volunteer, consultant or intern on behalf of the federal government overseas, where stateside coverage can be obtained to complete the background investigation; 4) studied abroad at a U.S. affiliated college or university; or 5) have a current and adequate background investigation (commensurate with the position risk/sensitivity levels) completed for a federal or contractor employee position, barring any break in federal employment or federal sponsorship.

Only U.S. Citizens and Legal Permanent Residents are eligible for employment on contracts requiring access to DHS sensitive information unless an exception is granted as outlined under DHS Instruction 121-01-007-001. Per DHS Sensitive Systems Policy Directive 4300A, only U.S. citizens are eligible for positions requiring access to DHS Information Technology (IT) systems or positions that are involved in the development, operation, management, or maintenance of DHS IT systems, unless an exception is granted as outlined under DHS Instruction 121-01-007-001.

19.4 TRANSFERS FROM OTHER DHS CONTRACTS:

Contractor employees may be eligible for transfer from other DHS Component contracts provided they have an adequate and current investigation meeting the new assignment requirement. If the contractor employee does not meet the new assignment requirement a DHS 11000-25 with ICE supplemental page will be submitted to OPR-PSU to initiate a new investigation.

Transfers will be accomplished by submitting a DHS 11000-25 with ICE supplemental page indicating “Contract Change.” The questionnaire related to 6 CFR § 115.117 listed above in item 7 will be required for positions designated under PREA.

19.5 CONTINUED ELIGIBILITY

ICE reserves the right and prerogative to deny and/or restrict facility and information access of any contractor employee whose actions conflict with Fitness standards contained in DHS Instruction 121- 01-007-01, Chapter 3, paragraph 6.B or who violate standards of conduct under 6 CFR § 115.117. The Contracting Officer or their representative can determine if a risk of compromising sensitive Government information exists or if the efficiency of service is at risk and may direct immediate removal of a contractor employee from contract support. The OPR-PSU will conduct periodic reinvestigations every 5 years, or when derogatory information is received, to evaluate continued Fitness of contractor employees.

19.6 REQUIRED REPORTS

The Contractor will notify OPR-PSU, via the COR, of all terminations/resignations of contractor employees under the contract within five days of occurrence. The Contractor will return any expired ICE issued identification cards and building passes of terminated/ resigned employees to the COR. If an identification card or building pass is not available to be returned, a report must be submitted to the COR referencing the pass or card number, name of individual to whom issued, the last known location and disposition of the pass or card. The COR will return the identification cards and building passes to the responsible ID Unit.

The Contractor will report any adverse information coming to their attention concerning contractor employees under the contract to the OPR-PSU, via the COR, as soon as possible. Reports based on rumor or innuendo should not be made. The subsequent termination of employment of an employee does not obviate the requirement to submit this report. The report shall include the contractor employees’ name and social security number, along with the adverse information being reported.

The Contractor will provide, through the COR a Quarterly Report containing the names of contractor employees who are active, pending hire, have departed within the quarter or have had a legal name change (Submitted with documentation). The list shall include the Name, Position and SSN (Last Four) and should be derived from system(s) used for contractor payroll/voucher processing to ensure accuracy.

CORs will submit reports to psu-industrial-security@ice.dhs.gov

Contractors, who are involved with management and/or use of information/data…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .