2.1.1 0001 Attachment 1 Statement of Work 9.2.25.pdf
PDF 487 KB Posted
- Attached to
- Flood Catastrophic Modeling Software Federal contract opportunity
- Solicitation number
- 70FA6025R00000021
- Issued by
- Federal Emergency Management Agency
About this file
This is a Statement of Work (SOW) issued by the Federal Emergency Management Agency (FEMA) for Multiple Catastrophe Flood Models. The primary objective is to procure software licenses for storm surge and inland flood catastrophic data modeling, along with supporting services including installation, training, documentation, and remote technical support. FEMA's Actuarial and Catastrophic Modeling (ACM) Branch will be the primary users of these models, which will be housed in the Catastrophe Modeling System (CATZ) to support the National Flood Insurance Program (NFIP) for reinsurance and rate development purposes.
The SOW specifies detailed technical requirements for the catastrophe models, including geographic coverage of the Continental United States, ability to simulate at least 10,000 years of possible outcomes, and capability to produce damage estimates for structures with various characteristics. The contract is structured as a Blanket Purchase Agreement with a one-year base period and four one-year option periods, starting September 1, 2025. Contractors must provide the latest version of model software, install it on CATZ, allow unlimited users within FEMA, and offer ongoing technical support. The models will be used to estimate average annual losses, event losses, and exceedance probabilities to support FEMA's Risk Rating 2.0 initiative, which aims to deliver more equitable and understandable flood insurance rates.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 2.1.2 0001 70FA6025R00000021.pdf | ||
| 2.1.2 0001 70FA6025R00000021 QA 9.2.25.pdf | ||
| 2.1.1 70FA6025R00000021 Solicitation 8.18.25.pdf | ||
| 2.1.1 Attachment 1 Statement of Work 4.28.25.pdf | ||
| 2.2.1 Attachment 3 QASP 8.5.25.pdf | ||
| 2.1.1 Attachment 2 Price Schedule 7.18.25.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FINAL| Version 3.6 | 9/2/25
DEPARTMENT OF HOMELAND SECURITY (DHS)
Federal Emergency Management Agency
Federal Insurance Directorate
Statement of Work (SOW) for
Multiple Catastrophe Models
Bryan Falcone, Contracting Officer
1.0 GENERAL
1.1 BACKGROUND
The Federal Insurance and Mitigation Administration (FIMA) is a component of the Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), which operates the Federal Insurance Directorate and the National Flood Insurance Program (NFIP).
The mission of FIMA is to create safer communities by reducing loss of life and property; enable individuals to recover more rapidly from floods and other disasters; and lessen the financial impact of disasters on the Nation. FIMA accomplishes this mission through by advancing three primary objectives through the NFIP:
• Analyze Risk – Determining the impact of natural hazards that lead to effective strategies for reducing risk.
• Reduce Risk – Reducing or eliminating long-term risk from hazards on the existing built environment and future construction.
• Insure for Flood Risk – Reducing the impact of floods on the Nation by providing flood insurance. The NFIP is the main source for flood insurance in the United States.
FEMA’s NFIP has been offering flood insurance coverage to homeowners, renters and businesses as protection against flood losses for 50 years. In return, local governments commit to sound floodplain management and related flood disaster mitigation efforts. In addition to offering flood insurance, the NFIP’s functions include identifying communities’ flood risks, mapping and publishing Flood Insurance Rate Maps of those risks, helping communities meet floodplain management requirements, and communicating the benefits of flood insurance protection so that more Americans are reimbursed for flood damage through the insurance mechanism, rather than through federal disaster assistance funds.
The Actuarial and Catastrophic Modeling (ACM) Branch sits within FIMA and is responsible for the modeling and pricing of flood risk for the NFIP. The ACM Branch will be the primary users of the catastrophe models procured under this contract. The models will be housed in the Catastrophe Modeling System (CATZ) which was developed to securely host vendor catastrophe models, proprietary actuarial models, as well as other tools to perform reinsurance analytics in support of the NFIP Reinsurance Program and NFIP rate development (Risk Rating 2.0). Currently, CATZ is a Microsoft Azure cloud infrastructure that is owned and operated by FEMA.
1.2 SCOPE
The scope of this acquisition is software licenses for storm surge and inland flood catastrophic data modeling, along with supporting services including installation, training, documentation, and remote technical and troubleshooting support.
1.3 OBJECTIVE
The objective of this acquisition is to procure multiple commercially available off-the-shelf storm surge and inland flood catastrophic data modeling software licenses to support the NFIP for purposes of running models for reinsurance and rate development/pricing, reviewing and validating model output, and, if available, conducting live event tracking. FEMA intends this award to obtain catastrophe model software licenses and associated services to meet these requirements.
FEMA requires catastrophe models because they are widely used in the insurance and reinsurance industry to price flood risk. The model outputs of average annual loss and event/year losses are standard output that the market can consume to understand the NFIP’s flood risk. The average annual loss estimates for a given structure, community, state, or country are used in the insurance industry to set insurance rates and are a basis for the NFIP’s rate-setting methodology. The event and year loss outputs from catastrophe models are used by the insurance industry to estimate the percent probabilities of having losses meet or exceed a certain loss value. This is necessary when incorporating uncertainty into rate setting and when making reinsurance purchase decisions, as the expected losses and exceedance probabilities drive reinsurance strategy.
2.0 WORK AREAS
2.1 OBTAIN UNITED STATES CATASTROPHIC FLOOD MODELING SOFTWARE
2.1.1 Licenses for FEMA Use
The purpose of this Work Area is to obtain commercially available catastrophic flood model software licenses under the following terms and with the following technical capabilities:
License Terms
• Latest version of model software
• Installation on CATZ (vendor cloud platforms will not be accepted)
• No restrictions on the number of users within FEMA
Technical Capabilities
• Geographic coverage shall include:
o At least the Continental United States in the Atlantic Basin and Gulf for storm surge modeling, preference for inclusion of Hawaii.
o At least the Continental United States for inland flood modeling, preference for all 50 states and US territories.
o Additional modeling capabilities for tsunami modeling of the Continental United States is preferred, but not required.
o Inclusion of precipitation modeling as part of the solution for storm surge and inland flood modeling is preferred, but not required.
• Model components shall include a stochastic event set to simulate possible storm surge and inland flood events, a vulnerability component, and a financial component:
o The model shall have at least 10,000 years of possible outcomes in order to have enough sampling for a loss distribution.
o The model shall be able to produce damage estimates for structure data with various building characteristics, including presence of a basement, foundation type, elevation, etc.
o The model shall be able to make assumptions around vulnerability when unknown building characteristics are provided as input.
o The model shall be able to translate damage estimates to a structure into dollar losses through a financial component.
• Model output shall include estimated average annual losses and event losses at various geographic levels including, at the most granular level, at an individual structure/location.
o The model shall be able to produce exceedance probabilities on both an occurrence level, which estimates losses for the maximum possible event in a year, and on an aggregate level, which estimates losses for all events in a year.
2.1.2 Licenses for FEMA Testing
The purpose of this Work Area is to obtain and install catastrophic flood model software licenses on the same terms and with the same technical capabilities as under 2.1.1 above, both only for the purpose of testing. For catastrophe models that FEMA’s ACM Branch has not previously purchased, there will be an initial trial period to test and validate the results of the model using NFIP data. During this trial period, the model results will not be used for rate development or reinsurance. Given the restricted use and purpose of testing, FEMA would expect discounted pricing for the trial period.
2.2 OBTAIN TRAINING AND TECHNICAL SUPPORT FOR THE CATASTROPHIC FLOOD
MODELS
2.2.1 Training and Documentation
The purpose of this Work Area is to obtain training and model documentation to make FEMA personnel proficient in running the catastrophic flood modeling software for reinsurance and risk rating, reviewing and validating model output, and, if available, conducting live event tracking.
2.2.2 Technical and Troubleshooting Support
The purpose of this Work Area is to obtain ongoing remote technical and troubleshooting support for assistance FEMA personnel require arising from technical difficulty in usability or understanding when operating the catastrophic flood modeling software. Contractors will be unable to access NFIP data during technical and troubleshooting support.
3.0 CONTRACTOR PERSONNEL
3.1 Qualified Personnel
The Contractor shall provide qualified personnel to perform all requirements specified in this SOW.
3.2 Continuity of Support
The Contractor shall ensure that the contractually required level of support for Task 2.2.2 is maintained Monday through Friday between the hours of 8 a.m. and 5 p.m. (Eastern Time). The Contractor shall ensure that contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor shall provide e-mail notification to the Contracting Officer’s Representative (COR) prior to employee absence. Otherwise, the Contractor shall provide a fully qualified replacement.
3.3 Employee Identification
Contractor employees visiting government facilities shall wear an identification badge that, at a minimum, displays the contractor name, the employee’s photo, name, clearance-level and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.
3.4 Employee Conduct
Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Contractor shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.
3.5 Removing Employees for Misconduct or Security Reasons
The Government may, at its sole discretion (via the Contracting Officer*), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons. Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.
4.0 Other Applicable Conditions
4.1 Period of Performance
The period of performance for this multiple-award BPA is a one-year base period with four one-year option periods as follows:
Performance Period Dates
Base Period September 1, 2025 through August 30, Option Period One September 1, 2026 through August 30, Option Period Two September 1, 2027 through August 30, Option Period Three September 1, 2028 through August 30, Option Period Four September 1, 2030 through August 30,
4.2 Place of Performance
The primary place of performance will be the Contractor’s facilities with occasional visits to FEMA at 400 C Street Southwest, Washington, D.C. 20024.
4.3 Travel
Contractor travel shall not be required for this requirement.
4.4 Post Award Conference
The Contractor shall attend a Post Award Conference with the Contracting Officer and the COR no later than five business days after the date of award. The purpose of the Post Award Conference, which will be chaired by the Contracting Officer, is to discuss technical and contracting objectives of this contract and review the Contractor's draft Project Plan. The Post Award Conference will be held via teleconference.
4.5 Project Plan
The Contractor shall provide a draft Project Plan at the Post Award Conference for Government review and comment.
The Contractor shall provide a final Project Plan to the COR not later than 10 business days after the Post Award Conference.
4.6 Progress Reports
The Contractor shall provide a quarterly progress report to the Contracting Officer and COR via electronic mail. This report shall include a summary of all Contractor work performed, including a breakdown of labor hours by labor category, all direct costs by line item, an assessment of technical progress, schedule status, any travel conducted and any Contractor concerns or recommendations for the previous reporting period.
4.7 Progress Meetings
A Contractor representative shall be available to meet with the COR upon request to present deliverables, discuss progress, exchange information and resolve emergent technical problems and issues. These meetings shall take place via teleconference.
4.8 General Report Requirements
The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows XP and Microsoft Office Applications).
4.9 Security
4.9.1 Safeguarding of Controlled Unclassified Information (July 2023)
(a) Definitions. As used in this clause— Adequate Security means security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls.
Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:
(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical Facility Anti-Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual “Safeguarding Information Designated as Chemical-Terrorism Vulnerability Information” dated September 2008);
(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (title XXII, subtitle B of the Homeland
Security Act of 2002 as amended through Pub. L. 116–283), PCII’s implementing regulations (6 CFR part 29), the PCII Program Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security, the PCII Program Manager, or a PCII Program Manager Designee;
(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive Security Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or designee), including Department of Homeland Security MD 11056.1, “Sensitive Security Information (SSI)” and, within the Transportation Security Administration, TSA MD 2810.1, “SSI Program”;
(4) Homeland Security Agreement Information means information the Department of Homeland Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement.
The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion Center Initiative and activities for cyber information sharing consistent with the Cybersecurity Information Sharing Act of 2015;
(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;
(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;
(7) Information Systems Vulnerability Information (ISVI) means:
(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release; switching, router, and gateway information;
interconnections and access methods; and mission or business use/need. Examples of ISVI are systems inventories and enterprise architecture models. Information pertaining to national security systems and eligible for classification under Executive Order 13526 will be classified as appropriate; and/or
(ii) Information regarding developing or current technology, the release of which could hinder the objectives of the Department, compromise a technological advantage or countermeasure, cause a denial of service, or provide an adversary with sufficient information to clone, counterfeit, or circumvent a process or system;
(8) Operations Security Information means Department of Homeland Security information that could be collected, analyzed, and exploited by a foreign adversary to identify intentions, capabilities, operations, and vulnerabilities that threaten operational security for the missions of the Department;
(9) Personnel Security Information means information that could result in physical risk to Department of Homeland Security personnel or other individuals whom the Department is responsible for protecting;
(10) Physical Security Information means reviews or reports illustrating or disclosing facility infrastructure or security vulnerabilities related to the protection of Federal buildings, grounds, or property. For example, threat assessments, system security plans, contingency plans, risk management plans, business impact analysis studies, and certification and accreditation documentation;
(11) Privacy Information includes both Personally Identifiable Information (PII) and Sensitive Personally Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual’s identity, either alone, or when combined with other information that is linked or linkable to a specific individual;
and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. To determine whether information is PII, the DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual.
Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.
(i) Examples of stand-alone PII that are particularly sensitive include: Social Security numbers (SSNs), driver’s license or State identification numbers, Alien Registration Numbers (A-numbers), financial account numbers, and biometric identifiers.
(ii) Multiple pieces of information may present an increased risk of harm to the individual when combined, posing an increased risk of harm to the individual.
SPII may also consist of any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
(A) Truncated SSN (such as last 4 digits);
(B) Date of birth (month, day, and year);
(C) Citizenship or immigration status;
(D) Ethnic or religious affiliation;
(E) Sexual orientation;
(F) Criminal history;
(G) Medical information; and
(H) System authentication information, such as mother’s birth name, account passwords, or personal identification numbers (PINs).
(iii) Other PII that may present an increased risk of harm to the individual depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. The context includes the purpose for which the PII was collected, maintained, and used. This assessment is critical because the same information in different contexts can reveal additional information about the impacted individual.
Federal information means information created, collected, processed, maintained, disseminated, disclosed, or disposed of by or for the Federal Government, in any medium or form.
Federal information system means an information system used or operated by an agency or by a Contractor of an agency or by another organization on behalf of an agency.
Handling means any use of controlled unclassified information, including but not limited to marking, safeguarding, transporting, disseminating, re-using, storing, capturing, and disposing of the information.
Incident means an occurrence that—
(1) Actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or
(2) Constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Information Resources means information and related resources, such as personnel, equipment, funds, and information technology.
Information Security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide—
(1) Integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;
(2) Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and
(3) Availability, which means ensuring timely and reliable access to and use of information.
Information System means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
(b) Handling of Controlled Unclassified Information.
(1) Contractors and subcontractors must provide adequate security to protect CUI from unauthorized access and disclosure. Adequate security includes compliance with DHS policies and procedures in effect at the time of contract award. These policies and procedures are accessible at https://www.dhs.gov/dhs-security-and-training-requirements-contractors
(2) The Contractor shall not use or redistribute any CUI handled, collected, processed, stored, or transmitted by the Contractor except as specified in the contract.
https://www.dhs.gov/dhs-security-and-training-requirements-contractors
(3) The Contractor shall not maintain SPII in its invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions. It is acceptable to maintain in these systems the names, titles, and contact information for the Contracting Officer’s Representative (COR) or other government personnel associated with the administration of the contract, as needed.
(4) Any government data provided, developed, or obtained under the contract, or otherwise under the control of the Contractor, shall not become part of the bankruptcy estate in the event a Contractor and/or subcontractor enters bankruptcy proceedings.
(c) Incident Reporting Requirements.
(1) Contractors and subcontractors shall report all known or suspected incidents to the Component Security Operations Center (SOC) in accordance with Attachment F, Incident Response, to DHS Policy Directive 4300A Information Technology System Security Program, Sensitive Systems. If the Component SOC is not available, the Contractor shall report to the DHS Enterprise SOC. Contact information for the DHS Enterprise SOC is accessible https://www.dhs.gov/dhs-security-and-training-requirements-contractors.
Subcontractors are required to notify the prime Contractor that it has reported a known or suspected incident to the Department. Lower tier subcontractors are required to likewise notify their higher tier subcontractor, until the prime contractor is reached. The Contractor shall also notify the Contracting Officer and COR using the contact information identified in the contract. If the report is made by phone, or the email address for the Contracting Officer or COR is not immediately available, the Contractor shall contact the Contracting Officer and COR immediately after reporting to the Component or DHS Enterprise SOC.
(2) All known or suspected incidents involving PII or SPII shall be reported within 1 hour of discovery. All other incidents shall be reported within 8 hours of discovery.
(3) CUI transmitted via email shall be protected by encryption or transmitted within secure communications systems. CUI shall be transmitted using a FIPS 140-2/140-3 Security Requirements for Cryptographic Modules validated cryptographic module identified on https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules. When this is impractical or unavailable, for Federal information systems only, CUI may be transmitted over regular email channels.
When using regular email channels, Contractors and subcontractors shall not include any CUI in the subject or body of any email. The CUI shall be included as a password-protected attachment with the password provided under separate cover, including as a separate email. Recipients of CUI information will comply with any email restrictions imposed by the originator.
(4) An incident shall not, by itself, be interpreted as evidence that the Contractor or Subcontractor has failed to provide adequate information security safeguards for CUI or has otherwise failed to meet the requirements of the contract.
(5) If an incident involves PII or SPII, in addition to the incident reporting guidelines in Attachment F, Incident Response, to DHS Policy Directive 4300A Information Technology System Security Program, Sensitive Systems, Contractors shall also provide as many of the following data elements that are available at the time the https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
(i) Unique Entity Identifier (UEI);
(ii) Contract numbers affected unless all contracts by the company are affected;
(iii) Facility CAGE code if the location of the event is different than the prime Contractor location;
(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, and email);
(v) Contracting Officer POC (address, telephone, and email);
(vi) Contract clearance level;
(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;
(viii) Government programs, platforms, or systems involved;
(ix) Location(s) of incident;
(x) Date and time the incident was discovered;
(xi) Server names where CUI resided at the time of the incident, both at the Contractor and subcontractor level;
(xii) Description of the government PII or SPII contained within the system; and
(xiii) Any additional information relevant to the incident.
(d) Incident Response Requirements.
(1) All determinations by the Department related to incidents, including response activities, will be made in writing by the Contracting Officer.
(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of incidents.
(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:
(i) Inspections;
(ii) Investigations;
(iii) Forensic reviews;
(iv) Data analyses and processing; and
(v) Revocation of the Authority to Operate (ATO), if applicable.
(4) The Contractor shall immediately preserve and protect images of known affected information systems and all available monitoring/packet capture data. The monitoring/packet capture data shall be retained for at least 180 days from submission of the incident report to allow DHS to request the media or decline interest.
(5) The Government, at its sole discretion, may obtain assistance from other Federal agencies and/or third-party firms to aid in incident response activities.
(e) Certificate of Sanitization of Government and Government-Activity-Related Files and Information. Upon the conclusion of the contract by expiration, termination, cancellation, or as otherwise indicated in the contract, the Contractor shall return all CUI to DHS and/or destroy it physically and/or logically as identified in the contract unless the contract states that return and/or destruction of CUI is not required. Destruction shall conform to the guidelines for media sanitization contained in NIST SP 800–88, Guidelines for Media Sanitization. The Contractor shall certify and confirm the sanitization of all government and government-activity related files and information. The Contractor shall submit the certification to the COR and Contracting Officer following the template provided in NIST SP 800–88, Guidelines for Media Sanitization, Appendix G.
(f) Other Reporting Requirements. Incident reporting required by this clause in no way rescinds the Contractor’s responsibility for other incident reporting pertaining to its unclassified information systems under other clauses that may apply to its contract(s), or as a result of other applicable statutory or regulatory requirements, or other U.S.
Government requirements.
(g) Subcontracts. The Contractor shall insert this clause in all subcontracts and require subcontractors to include this clause in all lower tier subcontracts when subcontractor employees will have access to CUI; CUI will be collected or maintained on behalf of the agency by a subcontractor; or a subcontractor information system(s) will be used to process, store, or transmit CUI.
(End of clause)
4.9.2 3052.204-73 NOTIFICATION AND CREDIT MONITORING REQUIREMENTS FOR PERSONALLY
IDENTIFIABLE INFORMATION INCIDENTS (JULY 2023)
(a) Definitions. Privacy Information includes both Personally Identifiable Information (PII) and Sensitive Personally Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual’s identity, either alone, or when combined with other information that is linked or linkable to a specific individual; and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
To determine whether information is PII, the DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual. Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.
(1) Examples of stand-alone PII that are particularly sensitive include: Social Security numbers (SSNs), driver’s license or State identification numbers, Alien Registration Numbers (A-numbers), financial account numbers, and biometric identifiers.
(2) Multiple pieces of information may present an increased risk of harm to the individual when combined, posing an increased risk of harm to the individual. SPII may also consist of any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
(i) Truncated SSN (such as last 4 digits);
(ii) Date of birth (month, day, and year);
(iii) Citizenship or immigration status;
(iv) Ethnic or religious affiliation;
(v) Sexual orientation;
(vi) Criminal history;
(vii) Medical information; and
(viii) System authentication information, such as mother’s birth name, account passwords, or personal identification numbers (PINs).
(3) Other PII that may present an increased risk of harm to the individual depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. The context includes the purpose for which the PII was collected, maintained, and used. This assessment is critical because the same information in different contexts can reveal additional information about the impacted individual.
(b) PII and SPII Notification Requirements.
(1) No later than 5 business days after being directed by the Contracting Officer, or as otherwise required by applicable law, the Contractor shall notify any individual whose PII or SPII was either under the control of the Contractor or resided in an information system under control of the Contractor at the time the incident occurred. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by, the Contracting Officer. The Contractor shall not proceed with notification unless directed in writing by the Contracting Officer.
(2) All determinations by the Department related to notifications to affected individuals and/or Federal agencies and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer.
(3) Subject to government analysis of the incident and direction to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first-class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:
(i) A brief description of the incident;
(ii) A description of the types of PII or SPII involved;
(iii) A statement as to whether the PII or SPII was encrypted or protected by other means;
(iv) Steps individuals may take to protect themselves;
(v) What the Contractor and/or the Government are doing to investigate the incident, mitigate the incident, and protect against any future incidents; and
(vi) Information identifying who individuals may contact for additional information.
(c) Credit Monitoring Requirements. The Contracting Officer may direct the Contractor to:
(1) Provide notification to affected individuals as described in paragraph (b).
(2) Provide credit monitoring services to individuals whose PII or SPII was under the control of the Contractor or resided in the information system at the time of the incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified. Credit monitoring services shall be provided from a company with which the Contractor has no affiliation. At a minimum, credit monitoring services shall include:
(i) Triple credit bureau monitoring;
(ii) Daily customer service;
(iii) Alerts provided to the individual for changes and fraud; and
(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts.
(3) Establish a dedicated call center. Call center services shall include:
(i) A dedicated telephone number to contact customer service within a fixed period;
(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;
(iii) Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics;
(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate;
(v) Customized Frequently Asked Questions, approved in writing by the Contracting Officer in coordination with the Component or Headquarters Privacy Officer; and
(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.
(End of clause)
4.9.3 Privacy Training – Alternate I (DEVIATION)
(a) Definition. As used in this clause, personally identifiable information means information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual. (See Office of Management and Budget (OMB) Circular A–130, Managing Federal Information as a Strategic Resource).
(b) The Contractor shall ensure that initial privacy training, and annual privacy training thereafter, is completed by contractor employees who—
(1) Have access to a system of records;
(2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information on behalf of an agency; or
(3) Design, develop, maintain, or operate a system of records (see also FAR subpart 24.1 and 39.105).
(c) The contracting agency will provide initial privacy training, and annual privacy training thereafter, to Contractor employees for the duration of this contract. Contractor employees shall satisfy this requirement by completing Privacy at DHS: Protecting Personal Information accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Training shall be completed within 30 days of contract award and be completed on an annual basis thereafter not later than October 31st of each year.
(d) The Contractor shall maintain and, upon request, provide documentation of completion of privacy training to the Contracting Officer.
(e) The Contractor shall not allow any employee access to a system of records, or permit any employee to create, collect, use, process, store, maintain, disseminate, disclose, dispose or otherwise handle personally identifiable information, or to design, develop, maintain, or operate a system of records unless the employee has completed privacy training, as required by this clause.
(f) The substance of this clause, including this paragraph (f), shall be included in all subcontracts under this contract, when subcontractor employees will—
(1) Have access to a system of records;
(2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information; or
(3) Design, develop, maintain, or operate a system of records.
4.9.4 Information Technology Security Awareness Training (July 2023)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Security Training Requirements.
(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. The Department of Homeland Security (DHS) requires that Contractor employees take an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance.
Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year. The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.
(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within thirty (30) days of contract award. Any new Contractor employees assigned to the contract shall also sign the DHS Rules of Behavior before accessing DHS systems and sensitive information. The Contractor shall maintain signed copies of the DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, the Contractor shall e-mail copies of the signed DHS Rules of Behavior to the COR not later than thirty (30) days after contract award for each employee. The DHS Rules of Behavior will be reviewed annually, and the COR will provide notification when a review is required.
4.9.5 Information Sharing
While FEMA does not expect contractors under this task order to require access to Personally Identifiable Information (PII), any contractor receiving access to PII will be subject to the following limitations:
Need to Know The contractor will limit access to the PII provided by FEMA under this contract only to the contractor’s authorized personnel who need to know the information to accomplish the tasks outlined in this contract.
Prohibition on Computer Matching The contractor shall ensure no computer matching, as that term is defined in 5 U.S.C. § 552a(o), will occur for the purpose of establishing or verifying eligibility or compliance as it relates to cash or in-kind assistance or payments under federal benefit programs.
Return or Destruction of Data when no longer needed If at any time during the term of this contract any part of FEMA PII, in any form, that the contractor obtains from FEMA ceases to be required by the contractor for the performance of the contract, or upon termination of the contract, whichever occurs first, the contractor shall, within fourteen (14) days thereafter, promptly notify FEMA and securely return PII to FEMA, or, at FEMA’s written request destroy, un-install and/or remove all copies of such PII in the contractor’s possession or control, and certify in writing to FEMA that such tasks have been completed.
4.9.6 3052.204-71 CONTRACTOR EMPLOYEE ACCESS (JULY 2023)
(a) Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:
(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical Facility Anti- Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual “Safeguarding Information Designated as Chemical- Terrorism Vulnerability Information” dated September 2008);
(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (title XXII, subtitle B of the Homeland Security Act of 2002 as amended through Pub. L. 116–283), PCII's implementing regulations (6 CFR part 29), the PCII Program Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security, the PCII Program Manager, or a PCII Program Manager Designee;
(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive Security Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or designee), including Department of Homeland Security MD 11056.1, “Sensitive Security Information (SSI)” and, within the Transportation Security Administration, TSA MD 2810.1, “SSI Program”;
(4) Homeland Security Agreement Information means information the Department of Homeland Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement. The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion Center Initiative and activities for cyber information sharing consistent with the Cybersecurity Information Sharing Act of 2015;
(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;
(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;
(7) Information Systems Vulnerability Information (ISVI) means:
(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release; switching, router, and gateway information;
interconnections and access methods; and mission or business use/need. Examples of ISVI are systems inventories and enterprise architecture models. Information pertaining to national security systems and eligible for classification under Executive Order 13526 will be classified as appropriate; and/or
(ii) Information regarding developing or current technology, the release of which could hinder the objectives of the Department, compromise a technological advantage or countermeasure, cause a denial of service, or provide an adversary with sufficient information to clone, counterfeit, or circumvent a process or system;
(8) Operations Security Information means Department of Homeland Security information that could be collected, analyzed, and exploited by a foreign adversary to identify intentions, capabilities, operations, and vulnerabilities that threaten operational security for the missions of the Department;
(9) Personnel Security Information means information that could result in physical risk to Department of Homeland Security personnel or other individuals whom the Department is responsible for protecting;
(10) Physical Security Information means reviews or reports illustrating or disclosing facility infrastructure or security vulnerabilities related to the protection of Federal buildings, grounds, or property. For example, threat assessments, system security plans, contingency plans, risk management plans, business impact analysis studies, and certification and accreditation documentation;
(11) Privacy Information includes both Personally Identifiable Information (PII) and Sensitive Personally Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual's identity, either alone, or when combined with other information that is linked or linkable to a specific individual; and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. To determine whether information is PII, DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual. Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.
(i) Examples of stand-alone PII that are particularly sensitive include: Social Security numbers (SSNs), driver's license or State identification numbers, Alien Registration Numbers…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .