Combined_Synopsis_update_Sept_12_-_Final.pdf

PDF 278 KB Posted

Attached to
Tsunami Model Federal contract opportunity
Solicitation number
70FA6018Q00000006
Issued by
Federal Emergency Management Agency Information Technology Section

About this file

Combined Synopsis Solicitation 70FA6018Q00000006

View the file

Other files for this federal contract opportunity

Other files attached to Tsunami Model, newest first.
File Type Posted
A2_Tsunami_SOW_-_Sept_12_-_Final.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1 | P a g e

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation will not be issued.

Solicitation number 70FA6018Q00000006 is issued as a request for quote (RFQ).

This solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2005-66.

This solicitation is un-restricted. NAICS: 511210

DESCRIPTION OF REQUIREMENTS FOR THE SERVICES TO BE ACQUIRED

The purpose of the acquisition is to procure a tsunami data modeling capabilities for the purposes of running models for reinsurance and risk rating, reviewing and validating model output in accordance with Attachment A, Statement of Work (SOW).

PERIOD AND PLACE OF PERFORMANCE

The period of performance will be a 12-month base period and four 12 month option period.

The place of performance will be primarily remote and at FEMA Headquarters located in Washington, DC.

**** LEFT BLANK INTENTIONALLY***

http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/12.htm#P282_47557

2 | P a g e

Base Period (12 Months) CLIN Description Quantity Unit Price

0001 Tsunami Catastrophe Model w/Training

1 FFP

Option Year One (12 Months) CLIN Description Quantity Unit Price

1001 Tsunami Catastrophe Model w/Training 1 FFP

Option Year Two (12 Months) CLIN Description Quantity Unit Price

2001 Tsunami Catastrophe Model w/Training 1 FFP

Option Year Three (12 Months) CLIN Description Quantity Unit Price

3001 Tsunami Catastrophe Model w/Training 1 FFP

Option Year Four (12 Months) CLIN Description Quantity Unit Price

4001 Tsunami Catastrophe Model w/Training 1 FFP

PROVISION AT 52.212-1, INSTRUCTIONS TO OFFERORS -- COMMERCIAL, APPLIES TO

THIS ACQUISITION.

ADDENDUM TO 52.212-1 INSTRUCTIONS TO OFFERORS --COMMERCIAL ITEMS (Aug 2018)

In addition to the FAR 52.212-1 "Instructions to Offerors-Commercial Items," the following is requested:

http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/52_000.htm#P1391_191748

3 | P a g e

Offerors are required to submit their proposals in two separate volumes as follows:

Volume I – Technical Proposal

Volume II – Price

Title of the Requirement: Tsunami Model

The content of the Technical Proposal must not exceed 20 single spaced pages (10 pages when printed front and back) exclusive of functional spreadsheet using a font size of 12. Each “page” is one sheet, 8 ½” x 11”, with at least one inch margins on all sides, using Times New Roman font. Pages shall be consecutively numbered i. Page numbers, notation of proprietary information, and any other identifying information printed on each page are excluded from the margin requirements. Any foldout pages shall not exceed either 8 1/2" x 22" or 17" x 11", which when folded in half will be no larger than 8 1/2" by 11".

The foldout will count as two pages. The Government may not review content exceeding the 20 page limitation. The Technical Proposal must not contain cost/price information.

In addition to 52.212-1 Instructions to Offerors – Commercial Items (b), each proposal shall include the following:

Cover page - shall indicate the following:

• Proposal category (Technical or Business)

• Volume Number

Table of Contents - Sufficient details that will allow the important elements to be easily located. The Table of Contents does not count against the 20-page limitation.

EVALUATION PROCEDURES

This is a Lowest Price Technically Acceptable (LPTA) procurement. The Government intends to award a purchase order resulting from this RFQ to the responsible offeror whose offer is the lowest price technically acceptable for this requirement, which shall represent best value to the Government. Award shall be made on the basis of the lowest evaluated price of the quotation meeting or exceeding the acceptability standards for non-cost factors (i.e. Technical conformance to the requirements of the RFQ). Evaluation of price will be based on the offerors total price. Past performance is not an evaluation factor for this acquisition.

The following factors shall be used to evaluate offers:

a) Price

b) Technically acceptable in conformance to the requirements of the RFQ.

c) Quotation shall have to meet or exceed the acceptability standards for non-cost factors

The offerors initial quotation shall contain the offerors best terms from a price and technical standpoint, offerors should submit software model numbers and their brochures to prove capabilities and any proposed commercial license terms and conditions which must be in compliance with FAR Clause 52.227-19 – Commercial Computer Software License - Dec 2007, (Brochures and terms and conditions

4 | P a g e will not count against the 20 page limit). The Government intends to evaluate offers and award a purchase order without discussions, but reserves the right to conduct discussions if later determined by the Contracting Officer to be necessary.

FACTOR RATINGS FOR TECHNICAL APPROACH

Adjectival Overall and Technical Approach Acceptable Software meets the following requirements:

• United States probabilistic and stochastic tsunami model with the following requirements:

o The ability to calculate Average Annual Loss (AAL) and other return metrics such as different decile exceedance probability levels o Minimum number of events: 50,000 earthquake events or 10,000 tsunami events o One license for commercially available tsunami modelling software with no restrictions on the number of users within FEMA

• Installation:

o The contractor shall provide all application files, drivers, libraries, and any other necessary software necessary via secure physical storage media; along with instructions for FEMA to install such software; and o Contractor shall provide remote installation support as needed

Training and technical support meets requirements defined in Work Area 2 of the SOW.

Unacceptable Quotation fails to meet requirements in the SOW and one or more deficiencies exist for which correction would require a major revision or redirection of the quotation. A contract cannot be awarded with this quotation.

Factor 1: Technical Approach

The offeror’s proposal will be evaluated for technical acceptability to ensure their approach and deliverables support and ensure achievement of the goals, phases and objectives identified in the SOW.

The offeror will be evaluated on how well their model demonstrates the following requirements:

Work Area 1: Obtain tsunami modeling software

The purpose of this work area is to obtain the latest version of tsunami modeling software with the following capabilities:

• United States probabilistic and stochastic tsunami model with the following requirements:

o The ability to calculate AAL and other return metrics such as different decile exceedance probability levels o Minimum number of events: 50,000 earthquake events or 10,000 tsunami events o One license for commercially available tsunami modelling software with no restrictions on the number of users within FEMA

• Installation:

5 | P a g e o The contractor shall provide all application files, drivers, libraries, and any other necessary software necessary via secure physical storage media; along with instructions for FEMA to install such software;

and Contractor shall provide remote installation support as needed

Work Area 2: Obtain training and technical support for the tsunami flood model

The purpose of this work area is to obtain training for up to five (5) FIMA personnel to gain proficiency in running models for reinsurance and risk rating, reviewing and validating model output. The vendor will provide model documentation.

In addition, the vendor will provide ongoing remote technical and troubleshooting support for assistance required arising from technical difficulty in usability or understanding, Monday through Friday between the hours of 8 a.m. and 5 p.m. (EST). The vendor will be unable to access NFIP data during technical and troubleshooting support.

Factor 2: Price

The offeror shall quote a firm-fixed price for the contract based on the requirements of the SOW, dated April 2018.

Price will be evaluated for completeness and reasonableness (inclusive of options 1001, 2001, 3001, and 4001). Please provide your commercial rates or redacted comparable commercial contract records for similar purchases.

(a) Options. The Government will evaluate the fixed price for options 1001, 2001, 3001, and 4001 by adding them to the proposed price for CLIN 0001. Evaluation of options shall not obligate the Government to exercise the option(s).

(b) A written notice of award or acceptance of an offer, mailed or otherwise furnished to the successful offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer's specified expiration time, the Government may accept an offer (or part of an offer).

Offerors shall include a completed copy of the provision at 52.212-3, Offeror Representations and Certifications -- Commercial Items (Aug 2018), with its offer.

FAR Clause at 52.212-4, Contract Terms and Conditions -- Commercial Items (Jan 2017), applies to this acquisition.

FAR Clause at 52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders -- Commercial Items (Aug 2018)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial items:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/52_000.htm#P1467_205602 http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/52_000.htm#P1749_245556 http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/52_000.htm#P1749_245556

6 | P a g e

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and

Other Covered Entities (Jul 2018) (Section 1634 of Pub. L. 115-91).

(3) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015)

(4) 52.233-3, Protest After Award (AUG 1996) (31 U.S.C. 3553).

(5) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77, 108-78 (19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the contracting officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:

[Contracting Officer check as appropriate.]

_X_ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Sept 2006), with Alternate I (Oct 1995) (41 U.S.C. 4704 and 10 U.S.C. 2402).

___ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (Oct 2015) (41 U.S.C. 3509).

___ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (Jun 2010) (Section 1553 of Pub L. 111-5) (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009).

___ (4) 52.204-10, Reporting Executive compensation and First-Tier Subcontract Awards (Oct 2016) (Pub. L. 109-282) (31 U.S.C. 6101 note).

___ (5) [Reserved]

___ (6) 52.204-14, Service Contract Reporting Requirements (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).

___ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).

___ (8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment (Oct 2015) (31 U.S.C. 6101 note).

___ (9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Jul 2013) (41 U.S.C. 2313).

___ (10) [Reserved]

7 | P a g e

___ (11) (i) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Nov 2011) (15 U.S.C.

657a).

___ (ii) Alternate I (Nov 2011) of 52.219-3.

___ (12) (i) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Oct 2014) (if the offeror elects to waive the preference, it shall so indicate in its offer)(15 U.S.C.

657a).

___ (ii) Alternate I (Jan 2011) of 52.219-4.

___ (13) [Reserved]

___ (14) (i) 52.219-6, Notice of Total Small Business Aside (Nov 2011) (15 U.S.C. 644).

___ (ii) Alternate I (Nov 2011).

___ (iii) Alternate II (Nov 2011).

___ (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (June 2003) (15 U.S.C. 644).

___ (ii) Alternate I (Oct 1995) of 52.219-7.

___ (iii) Alternate II (Mar 2004) of 52.219-7.

___ (16) 52.219-8, Utilization of Small Business Concerns (Nov 2016) (15 U.S.C. 637(d)(2) and (3)).

___ (17) (i) 52.219-9, Small Business Subcontracting Plan (Aug 2018) (15 U.S.C. 637 (d)(4)).

___ (ii) Alternate I (Nov 2016) of 52.219-9.

___ (iii) Alternate II (Nov 2016) of 52.219-9.

___ (iv) Alternate III (Nov 2016) of 52.219-9.

___ (v) Alternate IV (Aug 2018) of 52.219-9.

___ (18) 52.219-13, Notice of Set-Aside of Orders (Nov 2011) (15 U.S.C. 644(r)).

___ (19) 52.219-14, Limitations on Subcontracting (Jan 2017) (15 U.S.C. 637(a)(14)).

___ (20) 52.219-16, Liquidated Damages—Subcontracting Plan (Jan 1999) (15 U.S.C.

637(d)(4)(F)(i)).

___ (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (Nov 2011) (15 U.S.C. 657f).

8 | P a g e

___ (22) 52.219-28, Post Award Small Business Program Rerepresentation (Jul 2013) (15 U.S.C.

632(a)(2)).

___ (23) 52.219-29, Notice of Set-Aside for, or Sole Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (Dec 2015) (15 U.S.C. 637(m)).

___ (24) 52.219-30, Notice of Set-Aside for, or Sole Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (Dec 2015) (15 U.S.C. 637(m)).

___ (25) 52.222-3, Convict Labor (June 2003) (E.O. 11755).

___ (26) 52.222-19, Child Labor—Cooperation with Authorities and Remedies (Jan 2018) (E.O.

13126).

___ (27) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).

___ (28) (i) 52.222-26, Equal Opportunity (Sep 2016) (E.O. 11246).

___ (ii) Alternate I (Feb 1999) of 52.222-26.

___ (29) (i) 52.222-35, Equal Opportunity for Veterans (Oct 2015) (38 U.S.C. 4212).

___ (ii) Alternate I (July 2014) of 52.222-35.

___ (30) (i) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) (29 U.S.C. 793).

___ (ii) Alternate I (July 2014) of 52.222-36.

___ (31) 52.222-37, Employment Reports on Veterans (Feb 2016) (38 U.S.C. 4212).

___ (32) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496).

_ X_ (33) (i) 52.222-50, Combating Trafficking in Persons (Mar 2015) (22 U.S.C. chapter 78 and E.O.

13627).

___ (ii) Alternate I (Mar 2015) of 52.222-50, (22 U.S.C. chapter 78 and E.O. 13627).

___ (34) 52.222-54, Employment Eligibility Verification (Oct 2015). (E. O. 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial items as prescribed in 22.1803.)

___ (35) (i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA-Designated Items (May 2008) (42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

9 | P a g e

___ (ii) Alternate I (May 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

___ (36) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (Jun 2016) (E.O.13693).

___ (37) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (Jun 2016) (E.O. 13693).

___ (38) (i) 52.223-13, Acquisition of EPEAT® -Registered Imaging Equipment (Jun 2014) (E.O.s 13423 and 13514

___ (ii) Alternate I (Oct 2015) of 52.223-13.

___ (39) (i) 52.223-14, Acquisition of EPEAT® -Registered Television (Jun 2014) (E.O.s 13423 and 13514).

___ (ii) Alternate I (Jun 2014) of 52.223-14.

___ (40) 52.223-15, Energy Efficiency in Energy-Consuming Products (Dec 2007) (42 U.S.C. 8259b).

___ (41) (i) 52.223-16, Acquisition of EPEAT® -Registered Personal Computer Products (Oct 2015) (E.O.s 13423 and 13514).

___ (ii) Alternate I (Jun 2014) of 52.223-16.

_ X_ (42) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging while Driving (Aug 2011) (E.O. 13513).

___ (43) 52.223-20, Aerosols (Jun 2016) (E.O. 13693).

___ (44) 52.223-21, Foams (Jun 2016) (E.O. 13696).

___ (45) (i) 52.224-3, Privacy Training (Jan 2017) (5 U.S.C. 552a).

___ (ii) Alternate I (Jan 2017) of 52.224-3.

___ (46) 52.225-1, Buy American--Supplies (May 2014) (41 U.S.C. chapter 83).

___ (47) (i) 52.225-3, Buy American--Free Trade Agreements--Israeli Trade Act (May 2014) (41 U.S.C. chapter 83, 19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, Pub. L. 103-182, 108-77, 108-78, 108-286, 108-302, 109-53, 109-169, 109-283, 110-138, 112- 41, 112-42, and 112-43).

___ (ii) Alternate I (May 2014) of 52.225-3.

___ (iii) Alternate II (May 2014) of 52.225-3.

10 | P a g e

___ (iv) Alternate III (May 2014) of 52.225-3.

___ (48) 52.225-5, Trade Agreements (Aug 2018) (19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note).

_ X_ (49) 52.225-13, Restrictions on Certain Foreign Purchases (June 2008) (E.O.’s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).

___ (50) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).

___ (51) 52.226-4, Notice of Disaster or Emergency Area Set-Aside (Nov 2007) (42 U.S.C. 5150).

___ (52) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (Nov 2007) (42 U.S.C. 5150).

___ (53) 52.232-29, Terms for Financing of Purchases of Commercial Items (Feb 2002) (41 U.S.C.

4505), 10 U.S.C. 2307(f)).

___ (54) 52.232-30, Installment Payments for Commercial Items (Jan 2017) (41 U.S.C. 4505, 10 U.S.C. 2307(f)).

___ (55) 52.232-33, Payment by Electronic Funds Transfer— System for Award Management (Jul 2013) (31 U.S.C. 3332).

___ (56) 52.232-34, Payment by Electronic Funds Transfer—Other Than System for Award Management (Jul 2013) (31 U.S.C. 3332).

___ (57) 52.232-36, Payment by Third Party (May 2014) (31 U.S.C. 3332).

___ (58) 52.239-1, Privacy or Security Safeguards (Aug 1996) (5 U.S.C. 552a).

___ (59) 52.242-5, Payments to Small Business Subcontractors (Jan 2017) (15 U.S.C. 637(d)(12)).

___ (60) (i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (Feb 2006) (46 U.S.C. Appx 1241(b) and 10 U.S.C. 2631).

___ (ii) Alternate I (Apr 2003) of 52.247-64.

___ (iii) Alternate II (Feb 2006) of 52.247-64.

(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or executive orders applicable to acquisitions of commercial items:

[Contracting Officer check as appropriate.]

11 | P a g e

___ (1) 52.222-17, Nondisplacement of Qualified Workers (May 2014) (E.O. 13495)

___ (2) 52.222-41, Service Contract Labor Standards (Aug 2018) (41 U.S.C. chapter 67.).

___ (3) 52.222-42, Statement of Equivalent Rates for Federal Hires (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).

___ (4) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards -- Price Adjustment (Multiple Year and Option Contracts) (Aug 2018) (29 U.S.C.206 and 41 U.S.C. chapter 67).

___ (5) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards -- Price Adjustment (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).

___ (6) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment--Requirements (May 2014) (41 U.S.C.

chapter 67).

___ (7) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services--Requirements (May 2014) (41 U.S.C. chapter 67).

___ (8) 52.222-55, Minimum Wages Under Executive Order 13658 (Dec 2015) (E.O. 13658).

___ (9) 52.222-62, Paid Sick Leave Under Executive Order 13706 (JAN 2017) (E.O. 13706).

___ (10) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations. (May 2014) (42 U.S.C. 1792).

___ (11) 52.237-11, Accepting and Dispensing of $1 Coin (Sep 2008) (31 U.S.C. 5112(p)(1)).

(d) Comptroller General Examination of Record The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, and does not contain the clause at 52.215-2, Audit and Records -- Negotiation.

(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor’s directly pertinent records involving transactions related to this contract.

(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR Subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.

12 | P a g e

(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.

(e)

(1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c) and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial items. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause—

(i) 52.203-13, Contractor Code of Business Ethics and Conduct (Oct 2015) (41 U.S.C. 3509).

(ii) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(iii) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and

Other Covered Entities (Jul 2018) (Section 1634 of Pub. L. 115-91).

(iv) 52.219-8, Utilization of Small Business Concerns (Nov 2016) (15 U.S.C. 637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds $700,000 ($1.5 million for construction of any public facility), the subcontractor must include 52.219-8 in lower tier subcontracts that offer subcontracting opportunities.

(v) 52.222-17, Nondisplacement of Qualified Workers (May 2014) (E.O. 13495). Flow down required in accordance with paragraph (1) of FAR clause 52.222-17.

(vi) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).

(vii) 52.222-26, Equal Opportunity (Sep 2016) (E.O. 11246).

(viii) 52.222-35, Equal Opportunity for Veterans (Oct 2015) (38 U.S.C. 4212).

(ix) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) (29 U.S.C. 793).

(x) 52.222-37, Employment Reports on Veterans (Feb 2016) (38 U.S.C. 4212).

(xi) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.

13 | P a g e

(xii) 52.222-41, Service Contract Labor Standards (Aug 2018), (41 U.S.C. chapter 67).

(xiii) (A) 52.222-50, Combating Trafficking in Persons (Mar 2015) (22 U.S.C. chapter 78 and E.O. 13627).

(B) Alternate I (Mar 2015) of 52.222-50 (22 U.S.C. chapter 78 E.O. 13627).

(xiv) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment--Requirements (May 2014) (41 U.S.C. chapter 67.)

(xv) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services--Requirements (May 2014) (41 U.S.C. chapter 67)

(xvi) 52.222-54, Employment Eligibility Verification (Oct 2015) (E. O. 12989).

(xvii) 52.222-55, Minimum Wages Under Executive Order 13658 (Dec 2015).

(xviii) 52.222-62, Paid sick Leave Under Executive Order 13706 (JAN 2017) (E.O. 13706).

(xix) (A) 52.224-3, Privacy Training (Jan 2017) (5 U.S.C. 552a).

(B) Alternate I (Jan 2017) of 52.224-3.

(xx) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).

(xxi) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations. (May 2014) (42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.

(xxii) 52.247-64, Preference for Privately-Owned U.S. Flag Commercial Vessels (Feb 2006) (46 U.S.C. Appx 1241(b) and 10 U.S.C. 2631). Flow down required in accordance with paragraph (d) of FAR clause 52.247-64.

(2) While not required, the Contractor may include in its subcontracts for commercial items a minimal number of additional clauses necessary to satisfy its contractual obligations.

The additional FAR clauses and/or provisions are incorporated by reference as an addendum to this solicitation:

FAR 52.203-6

Alternate I

Restrictions on Subcontractor Sales to the Government (Sep 2006)

FAR 52.204-4 Printed or Copied Double-Sided on Postconsumer Fiber Content Paper (May 2011)

14 | P a g e

FAR 52.204-6 Unique Entity Identifier (Oct 2016) FAR 52.204-9 Personal Identity Verification of Contractor Personnel (Jan

2011) FAR 52.209-7 Information Regarding Responsibility Matters (Jul 2013) FAR 52.209-9 Updates of Publicly Available Information Regarding

Responsibility Matters (Jul 2013) FAR 52.222-40 Notification of Employee Rights Under the National Labor

Relations Act (Dec 2010) FAR 52.224-1 Privacy Act Notification (Apr 1984) FAR 52.224-2 Privacy Act (Apr 1984) FAR 52.225-13 Restriction on Certain Foreign Purchases (Jun 2008) FAR 52.225-25 Prohibition on Contracting with Entities Engaging in Certain

Activities or Transactions Relating to Iran—Representation and Certification (Aug 2018)

FAR 52.233-4 Applicable Law For Breach Of Contract Claim (Oct 2004) FAR 52.217-5 Evaluation of Options (Jul 1990) FAR 52.227-14 Rights in Data (Dec 2007) FAR 52.227-19 Commercial Computer Software Licenses (Dec 2007) FAR 52.237-3 Continuity of Services (Jan 1991)

15 | P a g e

The additional clauses and/or provisions are incorporated in full text as an addendum to this solicitation:

FAR 52.217-9 Option To Extend The Term Of The Contract (Mar 2000) FEMA Nara Records Management Language For Contracts HSAR 3052.242-72 Contracting Officer's Technical Representative (Dec 2003)

52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 30 days; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 45 days before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 66 months.

SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause—

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as

16 | P a g e any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as the Department of Homeland Security (including the Assistant Secretary for the Transportation

Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan.

Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

17 | P a g e

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official

Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(5) DHS 4300A Sensitive Systems Handbook and Attachments

(6) DHS Security Authorization Process Guide

(7) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(8) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(9) DHS Information Security Performance Plan (current fiscal year)

(10) DHS Privacy Incident Handling Guidance

(11) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(12) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(13) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(9) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

• Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information.

DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://csrc.nist.gov/groups/STM/cmvp/standards.html http://csrc.nist.gov/groups/STM/cmvp/standards.html http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html

18 | P a g e

Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01- 007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

• The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

• All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(14) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

• Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

• Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has

19 | P a g e been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

• Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

• Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required.

The shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones.

Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy.

Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods:

(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

• Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the http://www.dhs.gov/privacy-compliance

20 | P a g e

Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(3) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(4) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may includerestricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(5) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements.

21 | P a g e

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.

22 | P a g e

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

Data Universal Numbering System (DUNS);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email);

(v) Contracting Officer POC (address, telephone, email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the Government PII and/or SPII contained within the system;

(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

Sensitive Information Incident Response Requirements.

(1) All determinations related to sensitive information incidents, including response activities,notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.