2.2.1 RFP Attachment 1- PWS_r1_08022023.docx

DOCX document 187 KB Posted

Attached to
Training Support Services Federal contract opportunity
Solicitation number
70CMSW23R00000020
Issued by
Immigration and Customs Enforcement

About this file

This performance work statement outlines requirements for a training support services contract to be awarded by Immigration and Customs Enforcement. The contractor shall provide personnel to support ICE's Strategic Development Unit, including program management, training administration, logistics, warehouse management, armory operations, and range support operations. Key requirements include supplying personnel in positions such as program manager, curriculum developer, logistics specialist, and gunsmith. The performance period consists of one base year plus four option years. Work will primarily take place at ICE facilities in Fort Moore, Georgia. The contractor must implement quality control procedures and obtain Authority to Operate for any systems processing sensitive information.

View the file

Other files for this federal contract opportunity

Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

IMMIGRATION AND CUSTOMS ENFORCEMENT

PERFORMANCE WORK STATEMENT

Training Support Services

Office of Firearms and Tactical Programs Strategic Operations and Development Division Strategic Development Unit (SDU)

PURPOSE

The U.S. Immigration and Customs Enforcement (ICE), Office of Firearms and Tactical Programs (OFTP), Strategic Development Unit (SDU) requires a contractor to provide service support personnel to support the SDU’s rapidly evolving law enforcement support mission.

1. BACKGROUND

The Strategic Development Unit (SDU) in Fort Moore, Georgia provides a multitude of services to ICE to include acquisition, receiving, issue, storage, and shipping of field equipment, armory services to include inspection, repair, building, maintenance, and disposal of agency owned firearms. The unit also conducts technical testing and evaluation of firearms and law enforcement equipment to ensure that all products issued to the field are the best available. The Strategic Development Unit supports the Strategic Operations & Development Division (SODD) and the Strategic Operations & Analysis Division (SOAD). These divisions are responsible for developing and delivering post-basic, advanced, specialized, use of force related training on-site and at field locations.

2. PERIOD OF PERFORMANCE

Base year plus four option years as follows:

Period
Period of Performance

Base (including one-month transition period)

Option Period 1

Option Period 2

Option Period 3

Option Period 4

3. PLACE OF PERFORMANCE

The primary place of performance will be the Government facilities assigned to the Department of Homeland Security, Immigration and Customs Enforcement, Office of Firearms and Tactical Programs at Fort Moore, Georgia. Primarily, work will be conducted on the ICE campus at 6760 Upton Avenue, Fiske Range Complex at 2927 Sightseeing Road, and the Advanced Training and Operations Center (ATOC) at Alekno Road on Fort Moore, Georgia.

4. HOURS OF OPERATION

Contractor employees shall generally perform all work between the hours of 7 a.m. and 7 p.m. EST, Monday through Friday (except Federal holidays). This range for performance of hours does not mean that the contract employee(s) will work twelve hours shifts. It means that the work performed will occur during a designated shift within these hours of operation. However, there may be occasions when contract employees shall be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this SOW.

5. TASKS

5.1. Program Management / Team Lead: All activities to support successful execution of the contract to include but not limited to:

5.1.1. Supervise and provide professional guidance to all Contract personnel.

5.1.2. Work with OFTP management to identify process improvements.

5.1.3. Produce and provide deliverables as required.

5.1.4. Work with Contract Officer Representative.

5.1.5. Evaluate performance results and recommend changes affecting short-term project growth and success.

5.1.6. Function as a technical expert across multiple project assignments.

5.1.7. Report contract cost data to the COR prior to invoicing.

5.1.8. Arrange and get approvals for contract employee travel.

5.1.9. Plan and lead major assignments.

5.2. Training Administrative Support:

5.2.1. Observing, analyzing, reporting, and making recommendations for improvements.

5.2.2. Develop, format, revise training materials such as lesson plans, curriculum, and other related documents.

5.2.3. Organize and maintain training material for accurate and timely retrieval.

5.2.4. Conduct an annual curriculum review with instructor team leads and stakeholders to incorporate revisions into training documents.

5.2.5. Process course critiques for courses.

5.3. Administrative Task Support

5.3.1. Maintain office logs and files.

5.3.2. Search electronic and hardcopy files and databases for records, supportive data, and historical documents.

5.3.3. Prepare, write, and edit a variety of correspondence including letters and memos.

5.3.4. Prepare, create, format, and edit spreadsheets, presentations, and charts.

5.3.5. Support the development and implementation of a correspondence management process, to include templates and samples for letters, memorandums, directives, manuals, or other similar items.

5.3.6. Recommend the improvement and simplification of reporting requirements through analyses of data reported, analyses of the requirements and methods for preparation of reports and assuring that reporting requirements are met.

5.3.7. Ensure office equipment is maintained and functional, requesting updated or replacement equipment as needed.

5.3.8. Support property management initiatives during inventory actions.

5.3.9. Assist with tracking and maintaining associated files related to purchases.

5.3.10. Serve as a Hazardous Waste Manager for SDU.

5.3.11. Provide suggestions to increase performance efficiency and effectiveness and streamline processes.

5.4. Vehicle Fleet Management:

5.4.1. Support GSA fleet with a working knowledge of federal regulations and ICE policies.

5.4.2. Keep abreast of GSA Fleet regulations and policies.

5.4.3. Draft guidance and standard operating procedures for local vehicle use.

5.4.4. Coordinate maintenance/repairs/modifications to and replacement of vehicles.

5.4.5. Deliver and pick up vehicles to and from maintenance.

5.4.6. Coordinate new vehicle requests.

5.4.7. Track, assign, and monitor vehicles for staff and student use.

5.4.8. Perform monthly GSA on-line mileage report.

5.4.9. Obtain and maintain Federal Fleet Manager Certification.

5.4.10. Perform other duties as assigned.

5.5. Logistics / Warehouse management:

5.5.1. Perform all shipping and receiving functions to include but not limited to receiving and processing incoming mail, documenting proper shipment receipt of operational training supplies and equipment including firearms and ammunition.

5.5.2. Manage inventory of assorted law enforcement equipment and course supplies using ICE’s inventory and tracking system (FACTS).

5.5.3. Transport, unpack, pack, inventory using proper equipment (ex: power machinery, hand truck etc.).

5.5.4. Perform inventory of serialized and non-serialized equipment and supplies.

5.5.5. Reconcile inventory management system with physical inventory.

5.5.6. Report losses of serialized material.

5.5.7. Coordinate new or replacement item requests.

5.5.8. Identify end of life replacement requirements for serialized and non- serialized material.

5.5.9. Provide routine and ad hoc reporting on all items.

5.5.10. Comply with all applicable federal, state, local policies and procedures.

5.5.11. Operate motor vehicles and any specialized equipment necessary to perform warehouse functions (ex: Class C Commercial Driver’s License).

5.5.12. Pull and package equipment and supplies for shipment to field offices.

5.5.13. Generate transfer documents in FACTS.

5.5.14. Obtain and maintain certification to package and ship hazardous materials.

5.6. Armory Operations: All activities to support successful execution of Armory operations to include but not limited to:

5.6.1. Perform firearm maintenance, repair and testing, and complete maintenance record documentation of weapons.

5.6.2. Perform periodic and random inspections of ICE authorized firearm systems including carbines, less lethal shotguns, pistols and other specialty launchers.

5.6.3. Perform inventories of all weapons, equipment and ammunition located at the armory.

5.6.4. Issue agency owned weapons, equipment and ammunition as needed.

5.6.5. Prepare test plans, reports and oversee the development of test protocol; continually seeks improved ways of evaluating accuracy, quality, and overall performance of firearms and ammunition, performing Sporting Arms and Ammunition Institute (SAAMI) pressure and velocity assessments, conducting tests, ensuring tests are valid, and writing comprehensive and detailed reports to support the validity of research findings along with the methodology utilized to meet the objectives of testing procedures.

5.6.6. Conduct tests and evaluations of sample firearms.

5.7. Range Support Operations: All activities to support successful range operations on Fort Moore and off-site training venues to include but not limited to:

5.7.1. Serve as range management point of contact with Fort Moore Range control to schedule, open, and close ranges daily to support training operations.

5.7.2. Maintain communications to Fort Moore Range Control via RIFMIS system or any designated system to schedule the ranges for utilization for safe and orderly range operations.

5.7.3. Manage an inventory of range materials, supplies, and equipment.

5.7.4. Prepare ranges, target systems, and training supplies for daily training missions.

5.7.5. Transport range ammunition and supplies to training locations.

5.7.6. Submit usage or expenditure reports.

5.7.7. Operate and maintain range target systems.

5.7.8. Clean the range lanes of used and unused supplies, expended brass, cotton wads, and other training debris.

6. Recommended Contract Personnel Positions:

Position Title

Program Manager (Team Lead)

Instructional Systems Designer/ Curriculum Developer

Technical Writer II

Logistics Specialist

GSA Fleet Specialist

Administrative Specialist

Parts Clerk

Range Specialist

Ammo Handler

Gunsmith (Level I)

Ballistics Engineer

7. Government Furnished Equipment:

Government will furnish contract employees with Government issued Laptops, Workstations, docks, monitors, printers, scanners, facility key cards, and government PIV cards to complete daily tasks. All government furnished equipment shall be returned upon termination and contract completion.

8. PROGRAM MANAGEMENT

8.1. Provide Effective Program Management

8.1.1. The contractor shall provide all necessary personnel and services to meet the requirements. A program management plan will be provided (see deliverable schedule) that describe how the program will be staffed and managed.

8.1.2. The contactor will maintain adequate staffing to support the requirements above and will demonstrate how the proposed staffing plan will meet the requirements of this SOW.

8.1.3. The contractor shall provide the COR and others as specified upon contract award a monthly list of all employees working on the contract to include title, start date, and clearance status.

8.2. Key Personnel

The following staff are considered Key Personnel and resumes are to be provided within 5 calendar days of contract award:

8.2.1. Program Manager (Team Lead)

· Master’s degree in a related field Business Administration/Management or Professional Certification from National Accredited Organization

· Minimum of 4 years of management experience

· Knowledge of federal and client orders and regulations related to management of government vehicles.

· Demonstrated experience in reading and understanding federal contracts and allocated funding and period of performance of contract line items (CLINs) and task orders (TOs).

8.2.2. Administrative Task Support Personnel/GSA Fleet Manager

· Academic high school diploma or G.E.D

· Minimum of 5 years of office/clerical work experience to include vehicle management and financial management OR associate degree plus 2 years of office/clerical work experience to include vehicle management and financial management.

8.2.3. Instructional Systems Designer/Curriculum Developer

· Bachelor of Arts or Bachelor of Science in Education Curriculum Development or Professional Certification from National Accredited Organization

· Minimum of 5 years of experience working with federal law enforcement to develop performance-based training in firearms and tactics.

· Instructional Systems Design Certification (optional).

· Ability to travel and spend up to 5 days a week each month at offsite SDU locations.

8.2.4. Ballistics Engineer

· Master’s Degree of Science in Engineering or Professional Certification from a National Accredited Organization in a related field.

8.2.5. Technical Writer

· Bachelor of Arts or Bachelor of Science or Professional Certification from National Accredited Organization in related field

· Experience in federal law enforcement training programs.

· Ability to develop, format lesson plans, curriculum, and related documents.

· Ability to travel and spend up to 5 days a week each month at offsite locations.

8.3. The contractor may propose additional key staff positions. The contractor shall obtain written concurrence from the CO for appointment or replacement.

8.4. All staff will be required to complete a DHS background investigation, and other checks as required by state law.

8.5. The Service Provider must require all potential employees to complete and submit to OPR PSU the security application, to include fingerprinting, within 72 hours of eQip Initiation to ensure expedited processing by ICE. Document policies and procedures for all contract activities and provide to COR (see deliverable schedule).

8.6. Contractor Staff Training

8.6.1. The Contractor shall provide ICE with a training plan within 15 calendar days of contract award that will list the required training curriculum for all staff.

8.6.2. The Contractor shall ensure that all staff are trained prior to starting work on the contract.

8.6.3. The Contractor may provide the training or can use an organization approved by the COR to provide training.

9. MAINTAINING STAFFING LEVELS

9.1. At all times, the Service Provider shall maintain appropriate staffing levels to fully satisfy all requirements of this contract.

9.2. Contractor must have the infrastructure to recruit, onboard, train, and retain an adequate workforce to meet the requirements of this contract.

10. PRE-EMPLOYMENT SCREENING

10.1. The contractor shall conduct 100% pre-employment screening on all candidates prior to e-QIP initiation. The contractor shall certify in writing to the CO upon request, prior to commencement of work, that each employee performing under this contract has successfully completed a pre-employment screening that includes, at a minimum:

· citizenship check

· licenses/certifications and any irregularities

· credit worthiness

· criminal background

· education

· employment reference check

11. STANDARDS OF CONDUCT

10.1. The contractor shall obtain written certification from each of its employees agreeing to abide by the standards of conduct outlined below for the duration of their employment:

11.1.1. The contractor shall provide all employees with a copy of the program's standards of conduct.

11.1.2. All employees shall certify in writing that they have read and understand these standards.

11.1.3. A record of this certificate shall be provided to the COR prior to the employee's beginning work under this contract.

11.1.4. If engaging in social media, contractor shall maintain professionalism on and off duty and shall not discuss their duties and information relating to their employment or ICE/ERO.

11.1.5. The contractor shall report to the COR within 24 hours of any violations or attempted violations of the standards of conduct.

11.1.6. Violations may result in employee dismissal by the contractor or removal at the discretion of the CO.

11.1.7. Failure on the part of the contractor to report a known violation or to take appropriate disciplinary action against offending employee or employees shall subject the contractor to appropriate action up to and including termination of the contract for default.

11.1.8. The contractor shall develop procedures for reporting and handling grievances or complaints from participants. All grievances/complaints shall be reported within the next business day to the COR in writing. Any grievances/complaints from participants concerning equal opportunity to the program’s services shall be forwarded to the ICE Office of Diversity and Civil Rights for processing at ICE.Civil.Liberties@ice.dhs.gov.

12. REMOVAL FROM DUTY

11.1 Should a contractor employee need to be removed from duty:

12.1.1. The contractor shall provide all employees with a copy of the program's standards of conduct.

12.1.2. The contractor shall notify the COR within 24 hours upon learning of adverse or disqualifying information regarding any employee. The contractor shall immediately remove the employee from performing duties under this contract, provide written notice to the COR of the employee’s removal and comply with further guidance from the CO upon learning of adverse or disqualifying information.

12.1.3. The contractor shall notify the COR in writing of any employee terminations, suspensions, resignations, or any other adverse personnel actions taken for any reason. Disqualifying information includes, but is not limited to:

12.1.4. Arrest or conviction of a crime (felony or misdemeanor offenses),

12.1.5. A record of arrests for traffic offenses (especially DUI), or

12.1.6. False information entered on suitability forms.

12.1.7. Upon notification, the contractor shall remove any employee from assignment to this contract who has been disqualified for security reasons or is deemed unfit to perform his or her duties.

12.1.8. A determination of being unfit for duty includes, but is not limited to, incidents involving misconduct as set forth below:

a. Neglect of duty or failure to carry out assigned tasks.

b. Falsification or unlawful concealment, removal, mutilation, or destruction of any official documents or records, or concealment of material facts by willful omissions from official documents or records.

c. Possession of or selling, consuming, or being under the influence of intoxicants, drugs, or other mind-altering substances.

d. Unethical or improper use of official authority.

e. Violations of security procedures or regulations.

f. Fraternization with program participants.

g. Failure to maintain or fulfill training requirements; or

h. Inappropriate conduct on social media as defined in the Standards of Conduct

12. MEDIA AND ORGANIZATIONAL INQUIRES

· The contractor shall refer all media inquiries to ICE and/or OFTP for approval.

· The contractor shall not provide any information to the press concerning this contract without prior approval from the ICE PAO.

· The contractor shall immediately notify the ICE PAO of any media or other organizational inquiries.

· There shall be no public disclosures regarding this contract made by the Contractor (or any subcontractors) without review and approval of such disclosure by ICE Public Affairs and express permission granted by the ICE Contracting Officer. The Government considers such information privileged or confidential.

13. PROGRESS MEETINGS

· Weekly Meetings--The Program Manager shall be responsible for keeping the COR informed about contractor progress throughout the performance period of this contract and ensure contractor activities are aligned with ICE objectives. The Program Manager and other staff as needed shall be available to meet with the CO and COR upon request to present deliverables, discuss progress, exchange information, and resolve emergent technical problems and issues.

· Quarterly Review Meetings--The contractor shall coordinate, arrange, and provide a quarterly and/or periodic review meeting at the request of the Government onsite, virtually or a combination of both. The meeting attendance requirement will include all contract key personnel. Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. These meetings may take place virtually or onsite. At these meetings, the COR will notify the contractor of how the Government views the contractor's performance and the contractor will inform the Government of any problems being experienced. Appropriate action shall be taken to resolve outstanding issues. Should additional meetings be required to resolve outstanding issues, these meetings shall be at no additional cost to the Government. The requestor will provide an agenda up to fourteen (14) calendar days prior to the quarterly and/or periodic review meetings that will be approved by the COR. The contractor shall provide an electronic version of the briefing to the Government one (1) week prior to the program review.

· Ad Hoc Meetings--The Government may require ad hoc meetings from time to time to address special circumstances or issues that may arise. The contractor will attend these meetings at date and time that is mutually agreed upon.

14 TRANSITION-IN

The contractor shall be responsible for the transition of all activities identified in this PWS and shall provide a detailed phase in plan, documenting milestones and timeline leading up to program launch. It is expected that transition in will take no more than 30 calendar days. Activities that will occur during the transition in phase include:

· Meet with the COR and other designated ICE staff to review transition in plan and discuss any pertinent or on-going issues. This may be done telephonically.

· Ensure they have all required staffing to begin performance under the contract.

· Onboarding and training of new and incumbent employees in accordance with the PWS to include conducting background investigations.

· Providing all required deliverables as noted in the deliverable table.

15 TRANSITION-OUT

Transition to a new awardee shall occur in a manner that is seamless and causes no disruption to program operations.

· 60 calendar days prior to contract end, the Contractor shall provide a transition out plan, documenting milestones and a schedule for transition activities.

16. QUALITY ASSURANCE

For all areas of responsibility detailed within this PWS, the contractor shall also define and implement quality control review and internal audit procedures in its Quality Control Plan. The contractor shall execute and document the results of such reviews and audits and ensure that all documentation related to them are available to the CO and COR at any time.

ERO has defined and will implement a Quality Assurance Surveillance Plan (QASP) that will evaluate and document the contractor’s performance during the execution and duration of the contract. ERO will conduct audits of multiple locations at random to evaluate the contractor’s quality control review, internal audit procedures, verify the results and ensure contract compliance.

Quality Assurance Reviews--The contractor shall define and implement monthly quality assurance reviews and internal audit procedures in a QCP and review the QASP metrics/performance. The contractor shall execute and document the results of such reviews and audits, implement a corrective action plan on areas found deficient in performance, and ensure that all documentation (e.g., internal audit reports) related to them are available to the COR and the CO at any time during the execution and close-out of this contract.

17. POST AWARD CONFERENCE

The contractor shall participate in a Post Award Conference with the CO and the CORs no later than fifteen (15) calendar days after the date of award. The purpose of the Post Award Conference, which will be chaired by the CO, is to discuss technical and contracting objectives of this contract and review the contractor's overall approach.

18. DELIVERABLES

All are to be approved by the COR or designee.

#
Deliverable
Due Date(s)
Distribution
1
Post Award Conference
To be determined based

upon award date N/A

2
Quality Assurance Plan
Within 15 calendar days of contract award
COR, Contracting

Officer

3
Updated Organizational Chart
Within 15 calendar days of contract award
COR, Contracting

Officer

4
Satisfy Staffing Requirements
Within 15 calendar days of contract award
COR, Contracting

Officer

5
Program Management Plan

for Training Development

30 days from award date
COR, Contracting

Officer, Subject Matter Expert

6
Progress Reports
Reviewed on a quarterly

basis.

COR, Contracting Officer, Subject Matter Expert

7
Instructor and Student

Materials Based on Project Management Plan COR, Contracting Officer, Subject Matter Expert

8
Pilot Report
Based on Project

Management Plan COR, Contracting Officer, Subject Matter Expert

9
Evaluation Report
Two weeks before the

annual curriculum review COR, Contracting Officer, Subject Matter Expert

10
Annual Curriculum

Review Report Two weeks following the annual curriculum review COR, Contracting Officer, Subject Matter Expert

11
Notification of employee termination, transfer, suspension, personnel action relating to disqualifying information or incidents of wrongdoing (criminal or policy violation)
Immediately (immediate verbal report, with written follow-up) upon identification
COR, Contracting

Officer

12
Report of any contract employee misconduct
Immediately (immediate verbal report, with written follow-up) upon identification
COR, Contracting

Officer

13
IT Security Plan
See 3052.204-70 (Section I)
COR, Contracting

Officer

14
Create and Maintain Training Records
Daily or as required
COR
Conduct and Document Internal Quality Assurance Audits
Review and update Quality Control Procedures as required, but no less than annually
COR, Contracting

Officer, Subject Matter Expert

16
Furnish Resumes of Key Personnel
Provide with Proposal and Prior to Entry on Duty (EOD) of any new staff
COR, Contracting

Officer e-QIP Security Process

Weekly report to COR listing employee name, date submitted, date approved/removed from process each Friday
COR
Transition Out Plan
60 calendar days prior to the end of the contract

COR, Contracting Officer

SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause—

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(2) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(3) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system.

The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three

(3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90-day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request.

Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(e) Sensitive Information Incident Reporting Requirements.

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Data Universal Numbering System (DUNS);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email);

(v) Contracting Officer POC (address, telephone, email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the Government PII and/or SPII contained within the system;

(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

(f) Sensitive Information Incident Response Requirements.

(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.

(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:

(i) Inspections,

(ii) Investigations,

(iii) Forensic reviews, and

(iv) Data analyses and processing.

(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

(g) Additional PII and/or SPII Notification Requirements.

(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.

(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:

(i) A brief description of the incident;

(ii) A description of the types of PII and SPII involved;

(iii) A statement as to whether the PII or SPII was encrypted or protected by other means;

(iv) Steps individuals may take to protect themselves;

(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and

(vi) Information identifying who individuals may contact for additional information.

(i) Credit Monitoring Requirements. In the event that a sensitive information incident involves PII or SPII, the Contractor may be required to, as directed by the Contracting Officer:

(1) Provide notification to affected individuals as described above; and/or

(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified. Credit monitoring services shall be provided from a company with which the Contractor has no affiliation. At a minimum, credit monitoring services shall include:

(i) Triple credit bureau monitoring;

(ii) Daily customer service;

(iii) Alerts provided to the individual for changes and fraud; and

(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or

(3) Establish a dedicated call center. Call center services shall include:

(i) A dedicated telephone number to contact customer service within a fixed period;

(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;

(iii) Weekly reports on call center volume,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .