Attachment A HMTAP Technical Support Services Performance Work Statement dated 1-2-2020.doc

DOC document 393 KB Posted

Attached to
FIMA Hazard Mitigation Technical Assistance Program Support Federal contract opportunity
Solicitation number
70FA2020R00000001
Issued by
Federal Emergency Management Agency Preparedness Section

About this file

This performance work statement outlines requirements for Hazard Mitigation Technical Assistance Program support services. The contract will be awarded to three contractors covering three geographic zones. Contractors must provide personnel, equipment, facilities, and other resources to perform services including program application review, research, analysis, and document development in support of FEMA's pre-disaster, disaster, and post-disaster mitigation and environmental compliance activities. Key details include that the period of performance is one base year plus four option years, contractors must respond to requests within eight hours and be available weekdays from 8:30am to 5:30pm, and work may be required in all ten FEMA regions and territories.

View the file

Other files for this federal contract opportunity

Other files attached to FIMA Hazard Mitigation Technical Assistance Program Support, newest first.
File Type Posted
ATTACHMENT B - QASP_HMTAP Non-AE Services_2-1-2020.docx DOCX document
Attachment C- HMTAP Cost Worksheet Sector A (Part 1).xlsx XLSX spreadsheet
Attachment C - HMTAP Cost Worksheet Sector B (Part 2) .xlsx XLSX spreadsheet
Attachment C - HMTAP Cost Worksheet Sector C- Part 3 .xlsx XLSX spreadsheet
Draft 70FA2020R00000001 Jan 23-2020.rtf RTF text file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT A

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF HOMELAND SECURITY (DHS)

FEDERAL EMERGENCY MANAGEMENT AGENCY (FEMA)

FEDERAL INSURANCE AND MITIGATION ADMINISTRATION (FIMA)

HAZARD MITIGATION TECHNICAL ASSISTANCE PROGRAM (HMTAP)

NON-ARCHITECTURAL AND ENGINEERING (NON-A&E) SERVICES

JANUARY 2, 2020

Part 1 General Information

1.0 General: This is a non-personnel services contract to provide Non-Architectural and Engineering (Non-A&E) Hazard Mitigation Technical Assistance Program (HMTAP) Technical Support Services, including but not limited to program application review/feasibility, research, analysis and document development services in support of FEMA’s pre-disaster, disaster, and post-disaster mitigation and environmental compliance requirements. Performance parameters set forth within this IDIQ Performance Work Statement (PWS) may be refined at the task order level. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.

The purpose of this acquisition is to procure Hazard Mitigation Technical Assistance Program (HMTAP) services in support of the Federal Emergency Management Agency (FEMA)/Federal Insurance and Mitigation Administration (FIMA). Three (3) single-award Indefinite Delivery-Indefinite Quantity (IDIQ) contracts will be issued for three geographic zones covering the United States inclusive of its territories. One contract will be awarded for each zone. This support will provide enhanced capacity in meeting pre-disaster, during disaster, and post-disaster mitigation and environmental responsibilities with respect to HMTAP. This requirement is for $150 million (combined amount for all three contracts). Each contract will each have an IDIQ maximum amount of $50 million.

This acquisition does not involve the procurement of IT products, services, equipment or software. However, the contractor may have access to sensitive information including FEMA’s IT systems. Note: Contractors IT systems will not be used to receive, store, or transmit any sensitive information. Such information will only be electronically sent and stored on Government furnished equipment (GFE) (i.e., laptops) using FEMA’s IT systems.

1.1 Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform HMTAP Technical Support Services as defined in this Performance Work Statement except for those items specified as government furnished property and services. The contractor shall perform to the standards in this contract.

1.2 Background: FEMA’s mission is to support our citizen’s and first responders, to ensure that as a nation, we work together to build, sustain, and improve our capability to prepare for, protect against, respond to, recover from, and mitigate all hazards. The Federal Insurance and Mitigation Administration (FIMA) mission is to work in partnership to support sustainable, disaster resilient communities, to avoid or reduce the loss of life, loss of property, and financial impact from hazards. FIMA created Hazard Mitigation Technical Assistance Program (HMTAP) to aid in reaching this mission. HMTAP. The HMTAP utilizes both large and small businesses through multiple contract vehicles to provide Non-A&E services, Programmatic Technical Assistance services and Training services.

Program areas utilizing the services of the HMTAP include the Office of Environmental Planning and Historic Preservation (OEHP), Floodplain Management (FPM) including the Office of the Flood Insurance Advocate (OFIA), Grants Policy (GP), Grants Data Analytics (GDA), Grants Implementation (GI), and the Mitigation Directorate’s Insurance and Mitigation Readiness Division (IMRD) and the Risk Management Directorate (RMD).

OEHP provides FEMA programs with policy and technical guidance concerning compliance with EHP laws, Executive Orders, and regulations, including but not limited to the National Environmental Policy Act (NEPA), National Historic Preservation Act (NHPA), Endangered Species Act (ESA), Executive 11988, Floodplain Management and Executive Order 12898, Environmental Justice.

The Floodplain Management Branch (FPM) provides technical assistance to other federal agencies, FEMA regional offices, states, tribes and communities in implementing the federal floodplain management requirements and initiatives.

Section 24 of the Homeowner Flood Insurance Affordability Act of 2014 directed FEMA’s Administrator to establish a Flood Insurance Advocate (OFIA) to advocate for the fair treatment of policyholders under the National Flood Insurance Program (NFIP) and for property owners in the mapping of flood hazards, the identification of risks from flood, and the implementation of measures to minimize the risk of flood. Technical support provided may be related to flood insurance, flood hazard mapping, floodplain management, or HMA grants.

The Hazard Mitigation Grant’s Policy Branch provides policy information for Hazard Mitigation Assistance (HMA) grant programs including current HMA policies, as well as policies of other Federal Insurance and Mitigation Administration divisions that affect HMA funding.

The Grants Data and Analytics Branch (GDA) provides HMA grants data analytics, benefit cost analysis and losses avoided type quantitative/analytic tools, technical assistance and trainings; HMA training course development and delivery; analysis and development of system business rules and requirements for sustaining the mitigation grants management systems; and manages the HMTAP program. Through its HMTAP program office, HMTAP CORs support its requiring offices (i.e., Regional Program Offices, HQ Program Offices, etc.) in development of contract documents like the Statement of Objectives (SOO), and the Independent Government Cost Estimate (IGCE). The GDA Branch also serves as the Project Management office for this contract.

The FEMA, FIMA, Hazard Mitigation Assistance (HMA) Division manages and delivers grants for one (1) post disaster mitigation grant program, two (2) pre-disaster mitigation grant programs, and one (1) new post-disaster program (Building Resilient Infrastructure and Communities (BRIC)) being implemented as a result of the Disaster Recovery Reform Act of 2018 (DRRA). The Hazard Mitigation Grant Program (HMGP) is HMA’s largest mitigation program and is made available to states, territories, tribes and districts after a presidentially declared disaster. The Flood Mitigation Assistance (FMA) program and Pre-disaster Mitigation (PDM) program are available to states, territories, tribes and districts pre-disaster to perform mitigation activities.

The Mitigation Directorate’s Insurance and Mitigation Readiness Division (IMRD) works to strengthen the capability and capacity of FEMA’s workforce to ensure the successful delivery of effective mitigation strategies in disaster operations. IMRD achieves these goals through mitigation training, information transfer, coordination of Insurance and Mitigation Disaster Operations, and product development by engaging our stakeholders in a holistic, consensus-based approach.

The Risk Management Directorate (RMD), through collaboration with State, Local, and Tribal entities, delivers quality data that increases public awareness and leads to actions that reduce risk to life and property. It is designed to integrate risk assessment, analysis, and communications by utilizing multi-disciplinary expertise to improve our understanding of the consequences of natural hazard events (including catastrophic) and reduce fatalities, injuries and losses from these events.

Non-A&E service provides a range of services which include studies, analyses, supporting technical review of HMA grants, environmental technical assistance, and providing technical assistance to reduce future losses to homes, businesses, schools, public buildings, and critical facilities from disasters.

The Government intends to award a minimum of three (3) Indefinite-Delivery/Indefinite-Quantity (IDIQ) contracts for the Non-A&E HMTAP support services. All Contractors shall have the capability and capacity to support the requirements as stated within the SOO.

Each contract will cover a distinct geographic sector to facilitate rapid response to declared disasters anywhere within the Unites States and its territories. One contract will be awarded for Sector A, one contract will be awarded for Sector B and one contract will be awarded for Sector C.

The geographical Sectors are defined as follows:

Sector A:

· Region VIII: Colorado, Montana, North Dakota, South Dakota, Utah, Wyoming

· Region IX: Arizona, California, Hawaii, Nevada, Pacific Islands

· Region X: Alaska, Idaho, Oregon, Washington

· FEMA Headquarters – OEHP and RMD

Sector B:

· Region I: Connecticut, Maine, Massachusetts, New Hampshire, Rhode Island, Vermont

· Region II: New Jersey, New York, Puerto Rico, Virgin Islands

· Region III: District of Columbia, Delaware, Maryland, Pennsylvania, Virginia, West Virginia

· Region IV: Alabama, Florida, Georgia, Kentucky, Mississippi, North Carolina, South Carolina, Tennessee

· FEMA Headquarters – HMA to include Grants Policy, Grants Data and Analytics, and Grants Implementation.

Sector C:

· Region V: Illinois, Indiana, Michigan, Minnesota, Ohio, Wisconsin

· Region VI: Arkansas, Louisiana, New Mexico, Oklahoma, Texas

· Region VII: Iowa, Kansas, Missouri, Nebraska

· FEMA Headquarters – FPM including OFIA/IMRD

Note: The intent is to award one IDIQ contract per geographic sector. This requirement will support Readiness and Disaster related activities through the issuance of task orders. Awarded Contractors have the right to solicit support from other HMTAP zoned Contractors to supplement the capabilities of an awarded Contractor.

1.3 Performance Objectives:

The contractor shall perform the following:

1.3.1 Provide assistance to FIMA grant programs including but not limited to the Hazard Mitigation Assistance (HMA) grant programs and the National Dam Safety Program (NDSP). For example, technical assistance to FEMA, States, Tribes, and local communities; research and data collection for guidance consideration; review HMA grant applications to include but not limited to; feasibility, completeness, and eligibility reviews, reviews of benefit cost analysis (BCA), review environmental and historic preservation compliance, and applicable helpline assistance.

1.3.2 Prepare all necessary components of environmental assessments, biological assessments or environmental impact statements including, but not limited to; historic preservation reviews and assessments of historical structures, conducting social science assessments in accordance with the National Environmental Policy Act (NEPA), and conducting surveys and assessments to determine existence of and potential impact to threatened or endangered species, water quality, wetlands delineation, sole or principal drinking aquifers, prime farmlands, and other ecologically significant/geographically unique areas.

1.3.3 Conduct non-Architectural and Engineering (Non-A&E) post-event assessments to identify mitigation opportunities, collect event data, and assess non-engineered structures. For example, non-A&E post-event analysis of damages and damage trends, identify best practices, and perform loss-avoidance studies.

1.3.4 Provide technical assistance and inter-agency coordination in support of analyses of FEMA’s proposed policies and regulations that will assist identifying impact(s) to FEMA programs’ stakeholders and applicants. This could include programmatic agreements, memorandums of agreement/understanding, research and review of documentation for Federal Advisory Council Act (FACA) and other federal agency (DHS, GAO, OMB, Congressional, etc.) requests.

1.3.5 Provide technical assistance in publication development, maintenance, and enhancement of various non-A&E technical and non-technical documents. This could include presentations, graphics support, web-based publications, fact sheets, research-based reports, white papers, guidance, standard operating procedures, streamlining initiatives, strategic planning, performance metrics, technical opinions, public notices, informational flyers, website content, policy analyses, and bulletins.

1.3.6 Provide non-A&E technical assistance to the Floodplain Management Division within the Mitigation Directorate to provide services to assist with implementation of the NFIP. Tasks may include support of community enrollment, eligibility, and compliance, promoting higher regulatory standards, training and transfer of knowledge, support of Community Assistance Program - State Support Services Element (CAP-SSSE) grant program, general NFIP floodplain management programmatic support, etc.

1.3.7 Maintain and enhance Benefit-Cost Analysis (BCA) helpline. Provide responses to programmatic questions related to BCA.

1.3.8 Provide technical support for field operations including but not limited to HMA Community Education and Outreach (CEO) to ensure consistent mitigation messages based upon disaster needs. Aid in providing time-sensitive technical advice to support FEMA efforts in DRCs and other disaster assistance venues.

1.4 Scope: The Contractor shall provide non-architectural and non-engineering (non-A&E) technical assistance, including but not limited to, program application review/feasibility, research, analysis, and document development services in support of FEMA’s pre-disaster, disaster, and post-disaster mitigation and environmental compliance requirements.

1.5 Period of Performance: The period of performance consists of one (1) 12-month base period and four (4) 12-month option periods.

Base Period

Option Period I

Option Period II

Option Period III

Option Period IV

1.6 General Information

1.6.1 Quality Control: The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s quality control program is the means by which he assures himself that his work complies with the requirement of the contract.

The Contractor’s Quality Control Plan (QCP) shall be delivered within 30 days after contract award in electronic format to the CO and COR. A comprehensive written QCP shall be submitted to the CO and COR within 5 working days when changes are made thereafter. After acceptance of the quality control plan the contractor shall receive the contracting officer’s acceptance in writing of any proposed change to his QC system.

1.6.2 Quality Assurance: The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).

1.6.3 Recognized Holidays: Contractor is not required to perform services on the following holidays:

New Year’s Day

Labor Day

Martin Luther King Jr.’s Birthday

Columbus Day

President’s Day

Veteran’s Day

Memorial Day

Thanksgiving Day

Independence Day

Christmas Day

1.6.4 Hours of Operation: The contractor is responsible for conducting business, between the hours of 8:30 AM and 5:30 PM, Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within eight (8) hours of notification during business hours except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings.

For other than firm fixed price contracts, the contractor will not be reimbursed when the government facility is closed for the above reasons. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.

1.6.5 Place of Performance: The work to be performed under this contract will be performed nation-wide including United States territories. The primary place of performance will be at the DHS FEMA Headquarters facility located at 400 C Street SW, Washington, DC.

The Contractor may be required to work at other DHS FEMA facilities in the Washington, DC Metropolitan area as well as other facilities nationwide.

The Contractor may be required to work offsite at Contractor facilities.

Work may be required within all ten FEMA Regions in both the Continental United States (CONUS) and Outside Continental United States (OCONUS) and will be specified at the task order level.

Alternate places of performance shall be coordinated with the Contracting Officer’s Representative (COR) and approved by the Contracting Officer (CO).

1.6.6 Type of Contract: The government will award a hybrid – Firm Fixed Price/Cost Plus Fixed Fee (CPFF)

1.6.7 Security Requirements: All work performed under this PWS is unclassified. All personnel require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees receive a favorably adjudicated public trust suitability prior to entry on duty (EOD) and must maintain the level of security required for the life of the contract.

. All individuals will be U.S. citizens. The contractor shall follow the standards established within DHS and FEMA policy.

[NOTE TO CONTRACTING OFFICER: The CO, in coordination with FEMA’s Personnel Security Division (PSD), shall ensure that all solicitations and contracts comply with the following Federal Acquisition Regulations and Homeland Security Acquisition Regulations by including the requisite clauses, as applicable:

· 48 C.F.R. § 4.1303 (clause at 48 C.F.R. § 52.204-9)

· 48 C.F.R. § 3004.470-3 (clauses at 48 C.F.R. § 3052.204-70 and 48 C.F.R. § 3052.204-71)]

A. BACKGROUND INVESTIGATIONS

All contractor personnel who require access to DHS or FEMA information systems, routine access to DHS or FEMA facilities, or access to sensitive information, including but not limited to Personally Identifiable Information (PII), shall be subject to a full background investigation commensurate with the level of the risk associated with the job function or work being performed. FEMA’s Personnel Security Division (PSD) will determine the risk designation for each contractor position by comparing the functions and duties of the position against those of a same or similar federal position, applying the same standard for evaluating the associated potential for impact on the integrity and efficiency of federal service.

Low Risk without Information System Access

Contractor personnel occupying positions or performing functions with a low risk designation and who do not require access to DHS or FEMA information systems shall undergo a Tier 1 (T1) background investigation which is equivalent to the previously identified National Agency Check with Inquiries (NACI). Either of these investigations must be supported by a separate credit check and must receive a favorable adjudication thereof from FEMA PSD prior to holder performing work under this contract. A favorably adjudicated NACI & C will remain acceptable for the purpose of reciprocity where a T1 investigation is required for a period of 5 years from the date of completion and favorable adjudication provided that all other requirements for the application of reciprocity are met.

Low Risk with Information System Access

Contractor personnel occupying positions or performing functions with a moderate risk designation shall undergo a Tier 2 Suitability (T2S) background investigation which is equivalent to the previously identified Moderate Risk Background Investigation (MBI) and must receive a favorable adjudication thereof from FEMA PSD prior to the holder performing work under this contract. A favorably adjudicated MBI will remain acceptable for the purpose of reciprocity where a T2S investigation is required for a period of 5 years from the date of completion and favorable adjudication provided that all other requirements for the application of reciprocity are met.

Moderate Risk

Contractor personnel occupying positions or performing functions with a moderate risk designation shall undergo a Tier 2 Suitability (T2S) background investigation which is equivalent to the previously identified Moderate Risk Background Investigation (MBI) and must receive a favorable adjudication thereof from FEMA PSD prior to the holder performing work under this contract. A favorably adjudicated MBI will remain acceptable for the purpose of reciprocity where a T2S investigation is required for a period of 5 years from the date of completion and favorable adjudication provided that all other requirements for the application of reciprocity are met.

High Risk

Contractor personnel occupying positions or performing functions with a high-risk designation shall undergo a Tier 4 (T4) background investigation which is equivalent to the previously identified Background Investigation (BI), and must receive a favorable adjudication thereof from FEMA PSD prior to the holder performing work under this contract. A favorably adjudicated BI will remain acceptable for the purpose of reciprocity where a T4 investigation is required for a period of 5 years from the date of completion and favorable adjudication provided that all other requirements for the application of reciprocity are met.

Background Investigation Process

Contractors performing on this contract must be United States Citizens. Contractor applicants must also be 18 years of age or older to allow for the conduct of certain security related queries.

To initiate the request to process contractor personnel, the Contractor shall provide the FEMA Contracting Officer’s Representative (COR) with all required information and comply with all necessary instructions to complete Section II of the FEMA Form 121-3-1-6, “Contract Fitness/Security Screening Request.” The FEMA COR shall ensure that all other applicable sections of the FEMA Form 121-3-1-6 are complete prior to submitting the form to FEMA PSD for processing. The Contractor shall also provide the FEMA COR with completed OF 306, “Declaration for Federal Employment,” forms for all contractor personnel.

Contractor personnel who already have a favorably adjudicated background investigation, may be eligible to perform work under this contract without further processing by FEMA PSD if:

· the investigation was completed within the last five years;

· it meets or exceeds the minimum requirement for the position they will occupy or functions they will perform on this contract;

· the contractor personnel have not had a break in employment since the prior favorable adjudication; and,

· FEMA PSD has verified the investigation and confirmed that no new derogatory information has been disclosed which may require a reinvestigation.

FEMA PSD will notify the COR of the names of the contractor personnel eligible to work based on prior, favorable adjudication. The COR will, in turn, notify the Contractor of the names of the favorably adjudicated contractor personnel, at which time the favorably adjudicated contractor personnel will be eligible to begin work under this contract.

For those contractor personnel who do not have an acceptable, prior, favorable adjudication or who otherwise require reinvestigation, FEMA PSD will issue an electronic notification via email to the contractor personnel that contains the following documents, which are incorporated into this contract by reference, along with a link to the Office of Personnel Management’s Electronic Questionnaires for Investigation Processing (e-QIP) system and instructions for submitting the necessary information:

· Standard Form 85P, “Questionnaire for Public Trust Positions”

· Optional Form 306, “Declaration for Federal Employment”

· SF 87, “Fingerprint Card” (2 copies)

· DHS Form 11000-6, “Non-Disclosure Agreement”

· DHS Form 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act” Applicants born outside the United States will be required to provide proof of citizenship in the form of a Certificate of Naturalization (Form N550 or N570), an unexpired U.S. Passport, or State Department issued Consular Report of Birth Abroad (CRBA) (FS-240)

FEMA PSD will only accept complete packages consisting of all of the above document and Standard Form 85P, which must be completed electronically through the Office of Personnel Management’s e-QIP system. The Contractor is responsible for ensuring that all contractor personnel timely and properly submit all required background information.

Residency requirements apply to the background investigation process. Persons subject to investigation and final adjudication for fitness or suitability must have lived within the United States for no less than 3 of the last 5 years as defined in the DHS Instruction 121-01-007-01, The Department of Homeland Security, Personnel Security, Suitability and Fitness Program (June 14, 2016). DHS has determined this to be the amount of time required to be the sufficient minimum investigative period for the purpose of performing a suitability or fitness adjudication. Both, OPM and OMB require a final adjudicative decision to support the issuance of the HSPD-12 compliant PIV Card that contractors are issued by FEMA Physical Security.

Once contractor personnel have properly submitted the complete package of all required background information, FEMA’s Personnel Security Division, at its sole discretion, may grant contractor personnel temporary eligibility to perform work under this contract prior to completion of the full background investigation if the Personnel Security Division’s initial review of the contractor personnel’s background information reveals no issues of concern. In such cases, FEMA’s Personnel Security Division will provide notice of such temporary eligibility to the COR who will then notify the Prime Contractor, at which time the identified contractor personnel will be temporarily eligible to begin work under this contract. Neither the Prime Contractor nor the contractor personnel have any right to such a grant of temporary eligibility. The grant of such temporary eligibility shall not be considered as assurance that the contactor personnel will remain eligible to perform work under this contract upon completion of and final adjudication of the full background investigation.

Upon favorable adjudication of the full background investigation, FEMA’s Personnel Security Division will update the contractor personnel’s security file and take no further action. In any instance where the final adjudication results in an unfavorable determination FEMA’s Personnel Security Division will notify the contractor personnel directly, in writing, of the decision and will provide the COR with the name(s) of the contractor personnel whose adjudication was unfavorable. The COR will then forward that information to the Contractor. Contractor personnel who receive an unfavorable adjudication shall be ineligible to perform work under this contract. Unfavorable adjudications are final and not subject to review or appeal.

Continued Eligibility and Reinvestigation Eligibility determinations based on a T1, T2S, or T4 (or the equivalent OPM investigation) are valid for five years from the date that the investigation was completed and closed. Contractor personnel required to undergo a background investigation to perform work under this contract shall be ineligible to perform work under this contract upon the expiration the background investigation unless and until the contractor personnel have undergone a reinvestigation and FEMA’s Personnel Security Division has renewed their eligibility to perform w*ork under this contract.

Exclusion by Contracting Officer The Contracting Officer, independent of FEMA’s Personnel Security Division, may direct the Contractor be excluded from working on this contract. Any contractor found or deemed to be unfit or whose continued employment on the contract is deemed contrary to the public interest or inconsistent with the best interest of the agency may be removed.

B. FACILITY ACCESS

The Contractor shall comply with FEMA Directive 121-1 “FEMA Personal Identity Verification Guidance,” FEMA Directive 121-3 “Facility Access,” and FEMA Manual 121-3-1 “FEMA Credentialing Access Manual,” to arrange for contractor personnel’s access to FEMA facilities, which includes, but is not limited to, arrangements to obtain any necessary identity badges for contractor personnel.

Contractor personnel working within any FEMA facility who do not require access to DHS or FEMA IT systems and do not qualify for a PIV Card may be issued a Facility Access Card (FAC). FACs cannot exceed 180 days; all contractors requiring access greater than 180 days will need to qualify for and receive a PIV card before being allowed facility access beyond 180 days.

Contractor personnel shall not receive a FAC until they have submitted a SF 87, “Fingerprint Card,” and an OF306, Declaration for Federal Employment, and receive approval from FEMA PSD. Contractor personnel using a FAC for access to FEMA facilities must be escorted in Critical Infrastructure areas (i.e., server rooms, weapons rooms, mechanical rooms, etc.) at all times.

FEMA may deny facility access to any contractor personnel whom FEMA’s Office of the Chief Security Officer has determined to be a potential security threat.

C. SEPARATION FROM CONTRACT

The Contractor shall notify the FEMA COR of all terminations/resignations within five calendar days of occurrence. The Contractor must account for all forms of Government-provided identification issued to contractor employees under a contract (i.e., the PIV cards or other similar badges) must return such identification to FEMA as soon as any of the following occurs:

· When no longer needed for contract performance.

· Upon completion of a contractor employee’s employment.

· Upon contract completion or termination.

If an identification card or building pass is not available to be returned, the Contractor shall submit a report to the FEMA COR, referencing the pass or card number, name of the individual to whom it was issued, and the last known location and disposition of the pass or card.

The Contractor or contractor personnel’s failure to return all DHS- or FEMA-issued identification cards and building passes upon expiration, upon the contractor personnel’s removal from the contract, or upon demand by DHS or FEMA may subject the contractor personnel and the Contractor to civil and criminal liability.

D. FOR OFFICIAL USE ONLY

In accordance with DHS Management Directive 11042.1 contractors, consultants and others to whom access is granted will abide by 11042.1; DHS policy regarding the identification and safeguarding of sensitive but unclassified information originated within DHS. It also applies to other sensitive but unclassified information received by DHS from other government and non-governmental activities. The contractor will:

1. Be aware of and comply with the safeguarding requirements for “For Official Use Only” (FOUO) information as outlined in this directive.

2. Participate in formal classroom or computer-based training sessions presented to communicate the requirements for safeguarding FOUO and other sensitive but unclassified information.

3. Be aware that divulging information without proper authority could result in administrative or disciplinary action.

Contractors and Consultants shall:

Execute a DHS Form 11000-6, Sensitive but Unclassified Information Non Disclosure Agreement (NDA), as a condition of access to such information. Other individuals not assigned to or contractually obligated to DHS, but to whom access to information will be granted, may be requested to execute an NDA as determined by the applicable program manager. Execution of the NDA shall be effective upon publication of this directive and not applied retroactively.

E. UNAUTHORIZED DISCLOSURE OF CLASSIFIED OR UNCLASSIFIED INFORMATION

Contractors and Subcontractors who are working on this contract shall receive Unauthorized Disclosure of Classified or Unclassified Information training.

Access to the training can be obtained at:

https://securityawareness.usalearning.gov/unauthorizedrefresher/index.htm Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

F. OPSEC TRAINING

Contractors and Subcontractors who are working on this contract shall receive the OPSEC Awareness Brief.

Access to the briefing can be obtained at https://securityawareness.usalearning.gov/opsec/index.htm Send the certificate of completion to the FEMA COR no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

G. INSIDER THREAT TRAINING

Insider Threat training for Contractors can be found at: https://securityawareness.usalearning.gov/itawareness/index.htm Certificate of training is required for all cleared contractor employees who are working with classified or unclassified information. All certificates must be sent to the assigned FEMA Contracting Officer Representative, before the Contractor or Subcontractor is granted access to classified or unclassified information but no later than 30 calendar days after awarded contract. All cleared contractor personnel are required to recertify Insider Threat training annually thereafter. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

1. CYBER HYGIENE AND PRIVACY CLAUSES

SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015):

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause—

“Personally, Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(2) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(3) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive but Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive but Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods:

(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90-day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .