Attachment_1__Terms_and_Conditions_70FA3018R00000007_Amendment_1.pdf
PDF 434 KB Posted
- Attached to
- To procure telecommunications services and equipment. Federal contract opportunity
- Solicitation number
- 70FA3018R00000007
About this file
This document is a solicitation for a wireline telecommunications services contract. FEMA intends to award an IDIQ contract with a base period of one year and four one-year options. The contractor must provide wireline equipment, services, and maintenance to support disaster and non-disaster operations for FEMA in the continental US and overseas. Deliverables include voice, data, audio/video conferencing, cables, and other ancillary equipment. The contractor must have a Top Secret facility clearance and all personnel must be cleared at the TS level. Proposals are due by June 11, 2018 and submitted electronically in four volumes: technical approach, management approach, past performance, and pricing. Evaluation criteria include technical approach, management approach, past performance, and price.
Attachment 1: Terms and Conditions Amendment
View the file
Other files for this federal contract opportunity
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 1
TERMS AND CONDITIONS
70FA3018R00000007
52.212-4 Contract Terms and Conditions - Commercial Items. (JAN 2017)
Addendum to 52.212-4
The work may be performed in the Continental United States (CONUS) or Outside the Continental United States (OCONUS).
The Place of Performance for Administration Services will be located at Mt. Weather, VA. All other delivery addresses will be specified at the individual Order level.
Contract Administration: The U.S. Department of Homeland Security, Federal Emergency Management Agency will perform all contract administration. Communications pertaining to contractual administrative matters shall be addressed to the Contracting Officer (CO) listed below. Changes in, or deviations from, the Performance Work Statement or terms and conditions of the contract shall not be effected without written modification to the order as executed by a FEMA Contracting Officer.
The Government Officials assigned to this contract are as follows:
Administrative Contracting Officer:
Name: Sharrye Favron Email: Sharrye.Favron@fema.dhs.gov
Primary Contracting Officer’s Representative:
Name: TBD Phone:
Email:
Alternate Contracting Officer’s Representative:
Name: TBD Phone:
CONTRACTING OFFICERS REPRESENTATIVE
The Contracting Officer may designate a Contracting Officers Representative (COR) to assist in monitoring the work under this contract. The COR is responsible for the technical administration of the contract and technical liaison with the Contractor. The COR IS NOT authorized to change the scope of work or specifications as stated in the contract and in any Task Order, to make any commitments or otherwise obligate the Government or authorize any changes which affect the contract price, delivery schedule, period of performance, or other terms or conditions.
The Contracting Officer is the only individual who can legally commit or obligate the Government for the expenditure of public funds. The technical administration of this contract shall not be construed to authorize the revision of the terms and conditions of this contract and any Task Orders issued. The Contracting Officer shall authorize any such revision in writing.
(End)
TECHNICAL DIRECTION AND SURVEILLANCE
mailto:Sharrye.Favron@fema.dhs.gov
(a) Performance of the work under this contract shall be subject to the surveillance and written technical direction of the Contracting Officer's Representative (COR) who shall be specifically appointed by the
(b) Contracting Officer in writing. Technical direction is defined as a directive to the Contractor which approves approaches, solutions, designs, or refinements; fills in details or otherwise completes the general description of work of documentation items; shifts emphasis among work areas or tasks; or otherwise furnishes guidance to the Contractor. Technical direction includes the process of conducting inquiries, requesting studies, or transmitting information or advice by the COR, regarding matters within the general tasks and requirements in the statement of work for this contract.
(c) The COR does not have the authority to, and shall not, issue any technical direction which:
(1) Constitutes an assignment of additional work outside the Statement of Work;
(2) Constitutes a change as defined in the contract clause entitled "Changes";
(3) In any manner causes an increase or decrease in the total estimated contract cost, the fixed fee (if any), or the time required for contract performance;
(4) Changes any of the expressed terms, conditions, or specifications of the contract; or
(5) Interferes with the Contractor's right to perform the specifications of the contract.
(d) All technical directions shall be issued in writing by the COR.
(e) The Contractor shall proceed promptly with the performance of technical directions duly issued by the COR in the manner prescribed by this clause and within his/her authority under the provisions of this clause. Any instruction or direction by the COR which falls within one, or more, of the categories defined in (b)(1) through (5) above, shall cause the Contractor to notify the Contracting Officer in writing within five (5) working days after receipt of any such instruction or direction and shall request the Contracting Officer to modify the contract accordingly. Upon receiving the notification from the Contractor, the Contracting Officer shall either issue an appropriate contract modification within a reasonable time or advise the Contractor in writing within thirty (30) days after receipt of the Contractor's Letter that:
(1) the technical direction is rescinded in its entirety
(2) the technical direction is within the scope of the contract, does not constitute a change under the "Changes" clause of the contract and that the Contractor should continue with the performance of the technical direction.
(f) A failure of the Contractor and Contracting Officer to agree that the technical direction is within scope of the contract, or a failure to agree upon the contract action to be taken with respect thereto shall be subject to the provisions of the "Disputes" clause of this contract.
(g) Any action(s) taken by the Contractor in response to any direction given by any person other than the Contracting Officer or the COR shall be at the Contractor's risk.
(End)
Invoice Procedures
The contractor shall submit an invoice(s) upon delivery and acceptance of all supplies or services as specified in the Price/Cost Schedule.
Contractors shall submit vouchers electronically in pdf format to the FEMA Finance Center at FEMA- Finance-Vendor-Payments@fema.dhs.gov, AND
Contractors shall also submit an electronic pdf copy to FEMA COR or program person if a COR is not designated at their email address.
The submission of vouchers electronically will reduce correspondence and other causes for delay to a minimum and will facilitate prompt payment to the Contractor. Paper vouchers mailed to the finance center will not be processed for payment. If the Contractor is unable to submit a payment request in electronic form, the contractor shall submit the payment request using a method mutually agreed to by the Contractor, the Contracting Officer, and the payment office.
Invoices shall be submitted as follows: Contractors shall use Standard Form (SF) 1034 (Public Voucher for Purchases and Services Other Than Personal) and SF 1035 (Continuation Sheet) when requesting payment for supplies or services rendered. Both forms are located at http://www.gsa.gov/portal/forms/type/SF. Suitable self-designed forms (contractor invoice forms) may be submitted instead of the SF 1035 as long as they contain the information required.
The voucher must provide a description of the supplies or services, by line item (if applicable), quantity, unit price, and total amount. The item description, unit of measure, and unit price must match those specified in the contract. Invoices that do not match the line item pricing in the contract will be considered improper and will be returned to the Contractor. The Contractor shall not be paid more frequently than on a monthly basis.
SF 1034 and 1035 instructions:
SF 1034 – Public Voucher for Purchases and Services Other than Personal
The information which a contractor is required to submit in its Standard Form1034 is set forth as follows:
(1) U.S. Department, Bureau, or establishment and location insert the names and address of the servicing finance office unless the contract specifically provides otherwise.
(2) Date Voucher Prepared - insert date on which the public voucher is prepared and submitted.
(3) Contract/Delivery Order Number and Date - insert the number and date of the contract and delivery order, if applicable, under which reimbursement is claimed.
(4) Requisition Number and Date - leave blank.
(5) Voucher Number - insert the appropriate serial number of the voucher. A separate series of consecutive numbers, beginning with Number 1, shall be used by the contractor for each new contract. When an original voucher was submitted, but not paid in full because of suspended costs, resubmission vouchers should be submitted in a separate invoice showing the original voucher number and designated with the letter "R" as the last character of the number. If there is more than one resubmission, use the appropriate suffix (R2, R3, etc.)
(6) Schedule Number; Paid By; Date Invoice Received - leave blank.
(7) Discount Terms - enter terms of discount, if applicable.
(8) Payee's Account Number - this space may be used by the contractor to record the account or job number(s) assigned to the contract or maybe left blank.
(9) Payee's Name and Address – show the name of the contractor exactly as it appears in the contract and its correct address, except when an assignment has been made by the contractor, or the right to receive payment has been restricted, as in the case of an advance account. When the right to receive payment is restricted, the type of information to be shown in this space shall be furnished by the Contracting Officer.
(10) Shipped From; To; Weight Government B/L Number - insert for supply contracts.
(11) Date of Delivery or Service - show the month, day and year, beginning and ending dates of supplies or services delivered.
(12) Articles and Services - insert the following: "For detail, see Standard Form 1035" OR “For detail, see contractor invoice form”.
(13) Type the following certification, signed by an authorized official, on the face of the Standard Form 1034.
mailto:Finance-Vendor-Payments@fema.dhs.gov http://www.gsa.gov/portal/forms/type/SF http://www.gsa.gov/portal/forms/type/SF
"I certify that all payments requested are for appropriate purposes and in accordance with the agreements set forth in the contract."
(Name of Official) (Title)
(14) Amount - insert the amount claimed for the period indicated in (11) above. This amount should be transferred from the total per the SF 1035 Continuation Sheet or contractor invoice form.
(15) SF 1035 – Continuation Sheet
The SF 1035 will be used to identify the specific item description, quantities, unit of measure, and prices for each category of deliverable item or service. Suitable self-designed forms (contractor invoice form) may be submitted instead of the SF 1035 as long as they contain the information required.
The information which a contractor is required to submit in its Standard Form1035 is set forth as follows:
U.S. Department, Bureau, or Establishment - insert the name and address of the servicing finance office.
Voucher Number - insert the voucher number as shown on the Standard Form 1034.
Schedule Number – leave blank.
Sheet Number - insert the sheet number if more than one sheet is used in numerical sequence. Use as many sheets as necessary to show the information required.
Number and Date of Order - insert payee's name and address as in the Standard Form 1034.
Articles or Services - insert the contract number as in the Standard Form 1034, and description.
Quantity; Unit Price – insert for supply contracts.
Amount - insert the total quantities contract value, and amount and type of fee payable (as applicable). A summary of claimed current and cumulative goods and services delivered and accepted to date. - Invoices shall include an itemization of all goods and services delivered and accepted for the period by item and by CLIN. Each invoice shall include sufficient detail to identify goods and services as compared
ELECTRONIC FUNDS TRANSFER (EFT) INFORMATION
1. To receive payment, the contractor shall submit their EFT information to the Government. EFT information maybe submitted by EFT form, through System for Award Management (SAM), or on invoice.
Failure to provide the EFT information or failure to notify the Government of changes to this EFT information may result in delays in payments and/or rejection of the invoice in accordance with the Prompt Payment clause of this contract. EFT forms may be submitted directly the FEMA Finance Center at FEMA- Finance-RecordsMaintenance@fema.dhs.gov,ortotheContractingOffice.
2. If submitting EFT information on invoice/voucher, the following EFT information should be submitted:
(a) Routing Transit Number (RTN) – The contractor shall provide the current 9-digit RTN of the payee's bank
(b) Payee's account number
(c) Contractor's Tax Identification Number(TIN)
(The EFT information submitted must be that of the contractor unless there is an official Assignment of Claims on file with the payment office.)
If at anytime during the term of this contract, the contractor changes any EFT information, (i.e. financial agent, RTN, account number, etc.) the new EFT information must replace the old EFT information on subsequent invoices submitted under this contract, through SAM, or by submission of a new EFT form.
mailto:Finance-RecordsMaintenance@fema.dhs.gov mailto:Finance-RecordsMaintenance@fema.dhs.gov
Pricing Overview
The Contractor agrees that during the life of this contract, the prices set forth herein shall not exceed the lower of the following:
(a) The lowest tariff price at which the Contractor offers the service or equipment to its commercial customers (including discounts)
(b) The price the Contractor has established for the service or equipment on its GSA multiple award schedules, if any
(c) The price the Contractor offers to state, local, or other Federal agencies (except for those accounts for which the Contractor can provide documented justification)
(d) The Contractor’s tariff price, less the same discount applied to the unit price for same or similar service/feature under this contract For the purpose of this clause, the phrase “commercial customers” refers to any and all buyers who acquire supplies and services from the Contractor, except those buyers who are the Contractor’s affiliate.
If, at any time during the IDIQ period, the Contractor’s prices in (a) or (b) above are reduced below those that are shown on the price schedules in this Section, the Contractor shall notify the FEMA Contracting Officer and the COR and provide a list of the IDIQ Line Item Numbers (CLINs), item descriptions, unit prices, and supporting documentation (applicable tariff pages or commercial prices). The FEMA Contracting Officer will then modify the price schedules to show the lower prices.
The Government will then begin paying the lower price on the first day of the monthly billing cycle following the month in which the Contractor’s price decreased.
Minimum Guarantee & Maximum Contract Limitation Minimum Guarantee: $100,000.00 Maximum Contract Limitation: TBD
Tariffs Tariffs required to be filed in connection with any resultant service or delivery order shall be provided to and certified by the FEMA Contracting Officer, within 45 days prior to the filing by the Contractor, that there are no terms and conditions in the filing that are inconsistent with or supplemental to the service or delivery order terms and conditions.
Permits The Contractor shall, without additional expense to the Government, be responsible for obtaining any necessary licenses, certifications, and permits, and for complying with any applicable federal, state, county, and municipal laws, codes, and regulations, in connection with the performance of the contract.
52.204-4 Printed or Copied Double-Sided on Postconsumer Fiber Content Paper. (MAY
2011) 52.216-18Ordering. (OCT1995)
(a) Any supplies and services to be furnished under this contract shall be ordered by issuance of delivery orders or task orders by the individuals or activities designated in the Schedule. Such orders may be issued from Date of Award through 12 Months.
(b) All delivery orders or task orders are subject to the terms and conditions of this contract. In the event of conflict between a delivery order or task order and this contract, the contract shall control.
(c) If mailed, a delivery order or task order is considered "issued" when the Government deposits the order in the mail. Orders may be issued orally, by facsimile, or by electronic commerce methods only if authorized in the Schedule.
(End of clause)
52.216-19 Order Limitations. (OCT 1995)
(a) Minimum order. When the Government requires supplies or services covered by this contract in an amount of less than $100.00, the Government is not obligated to purchase, nor is the Contractor obligated to furnish, those supplies or services under the contract.
(b) Maximum order. The Contractor is not obligated to honor-
(1) Any order for a single item in excess of $500,000.00;
(2) Any order for a combination of items in excess of TBD; or
(3) A series of orders from the same ordering office within 30 days that together call for quantities exceeding the limitation in subparagraph (b)(1) or (2) of this section.
(c) If this is a requirements contract (i.e., includes the Requirements clause at subsection 52.216- 21 of the Federal Acquisition Regulation (FAR)), the Government is not required to order apart of anyone requirement from the Contractor if that requirement exceeds the maximum-order limitations in paragraph (b) of this section.
(d) Notwithstanding paragraphs (b) and (c) of this section, the Contractor shall honor any order exceeding the maximum order limitations in paragraph (b), unless that order (or orders) is returned to the ordering office within 30 days after issuance, with written notice stating the Contractor's intent not to ship the item (or items) called for and the reasons. Upon receiving this notice, the Government may acquire the supplies or services from another source.
52.216-22 Indefinite Quantity. (OCT 1995)
(a) This is an indefinite-quantity contract for the supplies or services specified, and effective for the period stated, in the Schedule. The quantities of supplies and services specified in the Schedule are estimates only and are not purchased by this contract.
(b) Delivery or performance shall be made only as authorized by orders issued in accordance with the Ordering clause. The Contractor shall furnish to the Government, when and if ordered, the supplies or services specified in the Schedule up to and including the quantity designated in the Schedule as the "maximum." The Government shall order at least the quantity of supplies or services designated in the Schedule as the "minimum."
(c) Except for any limitations on quantities in the Order Limitations clause or in the Schedule, there is no limit on the number of orders that may be issued. The Government may issue orders requiring delivery to multiple destinations or performance at multiple locations.
(d) Any order issued during the effective period of this contract and not completed within that period shall be completed by the Contractor within the time specified in the order. The contract shall govern the Contractor's and Government's rights and obligations with respect to that order to the same extent as if the order were completed during the contract's effective period; provided, that the Contractor shall not be required to make any deliveries under this contract after 12 months after order date.
52.217-6 Option for Increased Quantity. (MAR 1989)
The Government may increase the quantity of supplies called for in the Schedule at the unit price specified.
The Contracting Officer may exercise the option by written notice to the Contractor within 30 Days.
Delivery of the added items shall continue at the same rate as the like items called for under the contract, unless the parties otherwise agree.
52.217-8 Option to Extend Services. (NOV 1999)
The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 60 Days.
52.217-9 Option to Extend the Term of the Contract. (MAR 2000)
(a) The Government may extend the term of this contract by written notice to the Contractor within 30 Days; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 60days (60 days unless a different number of days is inserted) before the contract expires. The preliminary notice does not commit the Government to an extension.
(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.
(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed One (1) 12 Month Base Ordering Period and Four (4) Twelve Month Option Ordering Periods(months)(years).
52.223-5 Pollution Prevention and Right-to-Know Information (May 2011)
52.223-6Drug-FreeWorkplace.(MAY2001)
52.223-10 Waste Reduction Program. (MAY 2011)
52.227-1 Authorization and Consent. (DEC 2007)
52.227-14 Rights in Data--General. (MAY 2014)
52.227-2 Notice and Assistance Regarding Patent and Copyright Infringement. (DEC
2007) 52.229-3 Federal, State, and Local Taxes. (FEB 2013)
52.233-2 Service of Protest. (SEP 2006)
(a) Protests, as defined in section 33.101 of the Federal Acquisition Regulation, that are filed directly with an agency, and copies of any protests that are filed with the Government Accountability Office (GAO), shall be served on the Contracting Officer (addressed as follows) by obtaining written and dated acknowledgment of receipt from 500 C Street Washington, DC 20742
(b) The copy of any protest shall be received in the office designated above within one day of filing a protest with the GAO.
(End of provision)
52.233-3 Protest after Award. (AUG 1996) 52.242-13 Bankruptcy. (JUL 1995) 52.246-2 Inspection of Supplies - Fixed-Price. (AUG 1996)
52.246-4 Inspection of Services - Fixed-Price. (AUG1996) 52.246-16 Responsibility for Supplies. (APR 1984) 52.247-34 F.o.b. Destination.(NOV 1991)
52.252-2 Clauses Incorporated by Reference.(FEB 1998) This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause maybe accessed electronically at this/these address(es): http://farsite.hill.af.mil/.
SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII http://farsite.hill.af.mil/
Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss 11 of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers(PIN)
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessibleathttp://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information
HSAR Class Deviation 15-01 Attachment 1: Safeguarding of Sensitive Information (MAR 2015)
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and http://www.dhs.gov/dhs-security-and-training-requirements-contractors
Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc.
The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the http://csrc.nist.gov/groups/STM/cmvp/standards.html http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html
Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years.
Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process.
The Contractor shall update its SA package by one of the following methods:
(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of http://www.dhs.gov/privacy-compliance computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request.
Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.
(f) Sensitive Information Incident Reporting Requirements.
(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.
(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
(i) Data Universal Numbering System (DUNS);
(ii) Contract numbers affected unless all contracts by the company are affected;
(iii) Facility CAGE code if the location of the event is different than the prime contractor location;
(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email);
(v) Contracting Officer POC (address, telephone, email);
(vi) Contract clearance level;
(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;
(viii) Government programs, platforms or systems involved;
(ix) Location(s) of incident;
(x) Date and time the incident was discovered;
(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;
(xii) Description of the Government PII and/or SPII contained within the system;
(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and
(xiv) Any additional information relevant to the incident.
(g) Sensitive Information Incident Response Requirements.
(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.
(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:
(i) Inspections,
(ii) Investigations,
(iii) Forensic reviews, and
(iv) Data analyses and processing.
(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.
(h) Additional PII and/or SPII Notification Requirements.
(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.
(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:
(i) A brief description of the incident;
(ii) A description of the types of PII and SPII involved;
(iii) A statement as to whether the PII or SPII was encrypted or protected by other means;
(iv) Steps individuals may take to protect themselves;
(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and
(vi) Information identifying who individuals may contact for additional information.
(i) Credit Monitoring Requirements. In the event that a sensitive information incident involves PII or SPII, the Contractor may be required to, as directed by the Contracting Officer:
(1) Provide notification to affected individuals as described above; and/or
(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified.
Credit monitoring services shall be provided from a company with which the Contractor has no affiliation.
At a minimum, credit monitoring services shall include:
(i) Triple credit bureau monitoring;
(ii) Daily customer service;
(iii) Alerts provided to the individual for changes and fraud; and
(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or
(3) Establish a dedicated call center. Call center services shall include:
(i) A dedicated telephone number to contact customer service within a fixed period;
(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;
(iii) Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics;
(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate;
(v) Customized FAQs, approved in writing by the Contracting Officer in coordination with the Headquarters or Component Chief Privacy Officer; and
(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.
(j) Certification of Sanitization of Government and Government-Activity-Related Files and Information.
As part of contract closeout, the Contractor shall submit the certification to the COR and the Contracting Officer following the template provided in NIST Special Publication 800-88 Guidelines for Media Sanitization.
3052.204-71 Contractor employee access. (SEP 2012)
(a) "Sensitive Information", as used in this clause, means any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Pub. L. 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security
(including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, part 1520, as amended, "Policies and Procedures of Safeguarding and Control of SSI," as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .