SOW_eWFM_MXS__27_Mar_18.docx
DOCX document 358 KB Posted
- Attached to
- Aspect eWFM Maintenance Federal contract opportunity
- Solicitation number
- 70FB7018R00000022
- Issued by
- Federal Emergency Management Agency
About this file
SOW
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP_70FB7018R00000022_3_Apr_18.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. Department of Homeland Security Federal Emergency Management Agency Recovery Technology Programs Division Disaster Data Technologies Program Management Office
(DDT PMO)
Statement of Work (SOW) v1.0 eWorkForce Management (eWFM) System Maintenance
27 March 2018
Table of Contents
| 1. | Background | 3 |
| 2. | Scope and Objectives | 3 |
| 3. | Administration | 5 |
| 4. | Government Furnished Equipment (GFE): | 5 |
| 5. | Invoices | 6 |
| 6. | Place of Performance | 7 |
| 7. | Period of Performance | 7 |
| 8. | Employment Eligibility Verification (E-Verify) | 7 |
| 9. | Information Technology Security Requirements | 7 |
| Appendix I – Records Management Compliance | 10 |
| Appendix II – DHS Enterprise Architecture Compliance | 13 |
| Appendix III – 508 Compliance Accessibility Requirements | 14 |
| Appendix IV – Security | 16 |
| Background Investigations | 16 |
| Facility Access | 18 |
| Security Training | 19 |
| Unauthorized Disclosure of Classified or Unclassified Information | 19 |
| OPSEC Training | 19 |
| Insider Threat Training | 19 |
| For Official Use Only (FOUO) Information | 20 |
| Appendix VI – Safeguarding of Sensitive Information (March 2015) | 21 |
| Appendix VII – Information Technology Security and Privacy Training (March 2015) | 30 |
| Appendix VII – Contractor Employee Access | 32 |
1.
Background This eWorkForce Management (eWFM) maintenance contract is in support of the Federal Emergency Management Agency (FEMA) and is managed by the Recovery Technology Programs Division and supports the Individual Assistance Division’s enterprise-wide staffing requirements. The software provides advanced multi-center networking, enterprise staff management, and monitoring capability. The eWFM modules enable the streamlining and automation for schedule changes and notification to agents and supervisors. Inherent enterprise business rules eliminate redundant paperwork for schedule changes, time off, overtime and posted schedule information. Maintenance services are required to ensure eWFM modules are fully operational and any troubles or issues are minimal and do not impact the mission of the National Processing Service Center (NPSC).
2. Scope and Objectives eWFM Maintenance Currently FEMA utilizes Aspect Software eWFM v7.5 which was last upgraded in 2015. The Contractor shall provide maintenance, troubleshooting, repair and diagnosis on the following Aspect eWFM modules and/or hardware:
· eWFM CORE FST (Licenses: 2,500)
· eWFM Agent Productivity Agent (Licenses: 2,500)
· eWFM Real-Time Adherence Agent (Licenses: 2,500)
· eWFM Allocate Agent (Licenses: 2,500)
· eWFM Empower Agent (Licenses: 1,600)
· eWFM eSchedule Planner IVR Port (Licenses: 24)
· eWFM Administrator (Licenses: 20)
· Virtual Schedule Attendant (VSA)
· CXP Pro System (8 Port Production VSA Server)
· AudioCodes Gateway Hardware for the CXP Pro (1)
The Contractor shall perform the maintenance remotely via VPN access 10 hours a day, 8 AM-6 PM central time, Monday through Friday, excluding recognized public holidays in the Texas NPSC (TXNPSC) locale.
The Contractor shall provide technical support by providing a toll free Helpdesk number. This number shall be provided to the Contracting Officer Representative (COR) within seven (7) business days of contract award. Aspect’s Helpdesk must be available to FEMA end users to assist them in schedule changes, accessing the system, and general questions and assistance. The Helpdesk shall be available to all licensed end-users. In addition, problems may be reported by FEMA utilizing Aspect’s website (www.aspect.com).
The Contractor shall provide a point-of contact, within seven (7) business days of contract award, for all maintenance related issues.
The maintenance shall include software upgrades and update releases which may contain bug fixes, improvements, and enhancements. At no additional cost the Contractor shall provide FEMA a CD of the applicable updates within five (5) business days of the releases. FEMA will install the upgrades, update releases, etc.
The Contractor shall provide a minimum notice of twelve (12) months on any End of Service Life Support for any software product supported on this contract.
The following severity/response time matrix shall apply to all contractor groups that perform maintenance on the eWFM Core Software or any implemented Modules.
| Severity of Issue |
| Definition |
| Response Time |
Severity 1 Critical System Down
| Failure in the production operation of Aspect equipment or program that causes cessation of operation with no acceptable workaround. |
| Immediate |
Severity 1 Critical
| Failure in the production operation of Aspect equipment or program causing severe impact on the customer’s ability to route calls or run business critical reports with no acceptable workaround. |
| 60 minutes |
Severity 2 High Intermittent failure in the production operation of Aspect equipment or program that causes moderate degradation in performance or functionality, resulting in a major operation impact to the customer’s ability to conduct business with not acceptable workaround.
– or – Failure in the lab environment of Aspect equipment, hardware, or program that causes the solution to materially cease operation and impacts Customer’s ability to implement new functionality with no acceptable workaround.
2 hours
Severity 3 Medium
| Minor impact in the production operation of Aspect equipment where the solution is operational but a technical issue exists that may need resolution. Includes reported issues with documentation. Workaround is usually available |
| 4 hours |
Severity 4 Low
| Low or no impact in the production operation of Aspect program where the issues do not impede service and are limited to user questions and enhancement requests. |
| 8 hours or next business day. |
The Contractor shall provide FEMA with access within seven (7) business days of contract award to Contractor’s online Case Management system, which will enable FEMA to generate reports at any time to obtain performance measurements of maintenance support activity, including but not limited to: date reported, name of who reported issue, issue reported, severity level, response time, what the resolution was, date issue resolved, and how long it took to resolve.
Training The Contractor shall provide subscription based training for the eWorkforce Management. The subscription services provide for unlimited training through Aspect’s Active Learning web-based portal, virtual instructor led training, and regularly scheduled onsite training courses at any Aspect facilities. The Contractor shall provide access and directions to the subscription training services within fourteen (14) calendar days of contract award. Workforce Management Education Agents Annual Subscription is for up to 1,800 users.
3. Administration Notwithstanding the Contractor’s responsibility for total management during the performance of the contract, the administration of the contract will require maximum coordination between FEMA and the Contractor. The following government personnel will administer the contract.
Contracting Officer’s Representative (COR) The COR will monitor contract performance to ensure the goals and requirements of this contract are met. The COR will oversee the Contractor’s performance of services and provide coordination on issues affecting all involved entities and the Contractor. The COR will coordinate with the Contractor to ensure proper resources are available to perform the services and to interface with the Contractor with information exchange, direction, decisions, documentation and other issues affecting this contract. All issues uncovered during the execution of the contract shall be reported to the CO and COR.
Contracting Officer (CO) All contract administration will be effected by the CO. Communications pertaining to contract administration matters will be addressed to the CO. No changes in or deviation from the scope of work shall be effected without a modification executed by the CO authorizing such changes.
4. Government Furnished Equipment (GFE):
FEMA Government Property (Laptops and PIV Badges) will be provided to the Contractor, in accordance with FAR 45.102(b), under the following conditions:
(i) Providing the property is in the Government’s best interest due to directives established by the Information Technology Security Branch (ITSB) for cyber security management;
(ii) The overall benefit to the acquisition significantly outweighs the increase cost of administration, including ultimate property disposal;
(iii) Providing the property does not substantially increase the Government’s assumption of risk;
(iv) Government requirements cannot otherwise be met.
The Contractor shall pick up the laptops from a FEMA facility at no additional cost to the Government. The equipment and components shall be returned to the CORs at the designated location at the Contractor’s expense. All of the security controls for GFE must be adhered to by the Contractor and subcontractor to fulfill the requirements of the contract.
The Contractor shall login with the FEMA laptop and connect to the FEMA network at least once every two (2) weeks for a minimum of four (4) hours to ensure the download of appropriate patches. Therefore, the Contractor shall bring their laptop to a FEMA office every two (2) weeks and attach it directly to the FEMA Local Area Network (LAN) or log in remotely and connect to the FEMA Virtual Private Network (VPN) once every two (2) weeks. If a Contractor employee logs in remotely, they shall use a high-speed internet connection and leave the laptop logged in for a minimum of four (4) hours to allow all patches and updates to properly load as downloads will not occur properly via a dial-up connection.
If this mandatory requirement is not adhered to then the Contractor employees shall travel to the local/nearest FEMA office to reset their credentials at no additional cost to the Government.
Any Government equipment provided for FEMA’s contract shall be used exclusively for official FEMA business and are subject to FEMA and DHS rules of behavior regarding access and use of DHS sensitive information technology resources.
5. Invoices The Contractor shall e-mail an electronic copy of the invoice for the previous month’s activity to the FEMA Finance Vendor Payments email address below, and the COR and Alternate COR shall be copied on all invoice submissions. If email is unavailable, the Contractor shall notify the COR and Alternate COR and mail the invoice to the FEMA Finance Center. Invoices shall be presented to:
Federal Emergency Management Agency FEMA Finance Center PO Box 9001 Winchester, VA 22604
(540) 540-1900 FEMA-Finance-Vendor-Payments@fema.dhs.gov
Invoices will be paid net 30 days after receipt from the Contractor of a proper invoice. The invoice shall be supported by data for all work accomplished during the previous month of performance. Supporting documentation for the invoice shall include, but is not limited to:
a. Contractor name and address
b. Invoice date and number
c. Contract number and contract line item number (CLIN)
d. Description, quantity, unit of measure, unit price and extended price
e. Taxpayer ID Number
f. Payment terms including discounts for prompt payment
a. Name and address of Contractor official to whom payment is being sent (must be the same as that in the contract or in a proper notice of assignment)
b. Name (where practicable), title, phone number, and mailing address of person to notify in the event of a defective invoice
g. Any other information or documentation required by the contract
h. See contract clauses for further invoicing instruction
6. Place of Performance The Contractor shall perform the maintenance remotely via VPN access 10 hours a day, 8 AM-6 PM CST, Monday through Friday, excluding recognized public holidays in the TXNPSC locale.
7. Period of Performance The period of performance is twelve (12) months from the date of award.
8. Employment Eligibility Verification (E-Verify) Executive Order 12989 mandates the electronic verification of all employees working on any federal contract. The Contractor shall agree that each employee working on this contract shall successfully pass the DHS Employment Eligibility Verification (E-Verify) program, which is operated by the Department of Homeland Security in partnership with the Social Security Administration to establish work authorization.
The Contractor shall ensure that each employee working on this contract has a Social Security Card issued and approved by the Social Security Administration. The Contractor shall be responsible to the Government for acts and omissions of its own employees and for any subcontractor(s) and their employees.
Subject to existing law, regulations, and/or other provisions of this contract, illegal or undocumented aliens shall not be employed by the Contractor and only United States Citizens shall be employed under with this contract. The Contractor shall ensure that this provision is expressly incorporated into any and all subcontracts or subordinate agreements issued in support of this contract.
9. Information Technology Security Requirements
Security Management Upon award the Contractor shall appoint a senior official to act as the Corporate Security Officer. The Corporate Security Officer will interface with FEMA’s Security Office through the COR on all security matters to include physical, personnel, and protection of all Government information and data accessed by the Contractor.
The COR and the FEMA Security Office shall have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements under this contract. Should the COR determine that the Contractor is not complying with the security requirements of this contract; the Contractor shall be informed in writing by the Contracting Officer of the proper action to be taken in order to effect compliance with such requirements.
Information Technology Security Clearance When sensitive Government information is processed on Agency telecommunications and automated information systems, the Contractor agrees to provide for the administrative control of sensitive data being processed and to adhere to the procedures governing such data as outlined in the DHS Sensitive Systems Policy Directive 4300A and DHS National Security Systems Policy Directive 4300B. Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level.
Contractors who fail to comply with DHS/FEMA security policy are subject to having their access to DHS/FEMA IT systems and facilities terminated, whether or not the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g., Privacy Act).
Information Technology Security Training and Oversight All Contractor personnel using DHS/FEMA automated systems or processing DHS/FEMA sensitive data will be required to receive Security Education and Awareness Training (SEAT). This training will be provided by FEMA.
Security Considerations (Data) The Contractor shall maintain, transmit, retain in the strictest confidence, and prevent the unauthorized duplication, use, and disclosure of information. The Contractor shall provide information only to personnel, Contractors, and subcontractors having a need to know such information in the performance of their duties for this project.
Information made available to the Contractor by the Government for the performance or administration of this effort shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer (CO).
If public information is provided to the Contractor for use in performance or administration of this effort, the Contractor, except with the written permission of the CO, may not use such information for any other purpose. If the Contractor is uncertain about the availability or proposed use of information provided or the performance or administration, the Contractor shall first consult with the CO regarding use of that information for other purposes.
The Contractor agrees to assume responsibility for protecting the confidentiality of Government records, which are not public information. All personnel or subcontractor of the Contractor to whom information may be made available or disclosed, may use the information only for a purpose and to the extent authorized herein. Penalties may ensue upon non-approved release of privacy data.
Performance of this effort may require the Contractor to access and use data and information proprietary to a Government agency or Government Contractor, which is of such a nature that its dissemination or use, other than in performance of this effort, would be adverse to the interests of the Government and/or others. Therefore, Contractor and/or Contractor personnel shall not divulge or release data or information developed or obtained in performance of this effort, until made public by the Government, except to authorize Government personnel or upon written approval of the CO. The Contractor shall not use, disclose, or reproduce proprietary data that bears a restrictive legend, other than as required in the performance of this effort. Nothing herein shall preclude the use of any data independently acquired by the Contractor without such limitations or prohibit an agreement at no cost to the Government between the Contractor and the data owner that provides for greater rights to the Contractor.
All deliverables, source code, and data received, processed, evaluated, loaded, and/or created as a result of this contract shall remain the sole property of the Government unless specific exception is granted by the CO.
Appendix I – Records Management Compliance A. Applicability This clause applies to all Contractors whose employees create, work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.
B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.
The term Federal record:
1. includes FEMA records.
1. does not include personal materials.
1. applies to records created, received, or maintained by Contractors pursuant to their FEMA contract.
1. may include deliverables and documentation associated with deliverables.
C. Requirements
1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
1. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.
1. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
1. FEMA and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of FEMA or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to FEMA. The agency must report promptly to NARA in accordance with 36 CFR 1230.
1. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to FEMA control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the SOO. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).
1. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and FEMA guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.
1. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with FEMA policy.
1. The Contractor shall not create or maintain any records containing any non-public FEMA information that are not specifically tied to or authorized by the contract.
1. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.
1. The FEMA owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which FEMA shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.
1. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take FEMA-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.
[Note: To the extent an agency requires contractors to complete records management training, the agency must provide the training to the contractor.]
D. Flowdown of requirements to subcontractors
1. The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph, in all subcontracts under this SOO, and require written subcontractor acknowledgment of same.
1. Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.
Appendix II – DHS Enterprise Architecture Compliance All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the Contractor shall comply with the following Homeland Security Enterprise Architecture (HLS EA) requirements:
(a) All developed solutions and requirements shall be compliant with the HLS/FEMA EA.
(b) All IT hardware and/or software shall be compliant with the HLS/FEMA EA Technical Reference Model (TRM) Standards and Products Profile.
(c) Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.
(d) Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01[footnoteRef:1][1] and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines. [1: [1] Department of Homeland Security (DHS) Directives System, Enterprise Data Management Policy, 2008. https://www.dhs.gov/sites/default/files/publications/mgmt_directive_103_01_enterprise_data_management_policy.pdf]
(e) Applicability of IPv6 to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA related component acquisitions shall be IPv6 compliant as defined in the USGv6 Profile (NIST Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.
Appendix III – 508 Compliance Accessibility Requirements Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology (EIT), they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.
All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable EIT accessibility standards have been identified:
Section 508 Applicable EIT Accessibility Standards 36 CFR 1194.21 Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.
36 CFR 1194.22 Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous Javascript and XML (AJAX) then 1194.21 Software standards also apply to fulfill functional performance criteria.
36 CFR 1194.23 Telecommunications Products, applies to all telecommunications products including end-user interfaces such as telephones and non end-user interfaces such as switches, circuits, etc. that are procured, developed or used by the Federal Government.
36 CFR 1194.26 Desktop and Portable Computers, applies to all desktop and portable computers, including but not limited to laptops and personal data assistants (PDA) that are procured or developed under this work statement.
36 CFR 1194.31 Functional Performance Criteria, applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.
36 CFR 1194.41 Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required 1194.31 Functional Performance Criteria, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.
Section 508 Applicable Exceptions Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COTR and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply: 36 CFR 1194.3(b) Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.
Section 508 Compliance Requirements 36 CFR 1194.2(b) (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meet some but not all of the standards, the agency must procure the product that best meets the standards. When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.
All tasks for testing of functional and/or technical requirements must include specific testing for Section 508 compliance, and must use DHS Office of Accessible Systems and Technology approved testing methods and tools. For information about approved testing methods and tools send an email to accessibility@dhs.gov.
Appendix IV – Security
Background Investigations All contractor personnel who require access to DHS or FEMA information systems, routine access to DHS or FEMA facilities, or access to sensitive information, including but not limited to Personally Identifiable Information (PII), shall be subject to a full background investigation commensurate with the level of the risk associated with the job function or work being performed. FEMA’s Personnel Security Division (PSD) will determine the risk designation for each contractor position by comparing the functions and duties of the position against those of a same or similar federal position, applying the same standard for evaluating the associated potential for impact on the integrity and efficiency of federal service.
Low Risk without Information System Access Contractor personnel occupying positions or performing functions with a Low Risk designation and who do not require access to DHS or FEMA information systems shall undergo a National Agency Check with Inquiries (NACI) Tier 1 and a credit check and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
Low Risk with Information System Access Contractor personnel occupying positions or performing functions with a Low Risk designation and who require access to DHS or FEMA information systems shall undergo a Tier 2 Suitability Background Investigation (T2) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
Moderate Risk Contractor personnel occupying positions or performing functions with a Moderate Risk designation shall undergo a Tier 2 Suitability Background Investigation (T2) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
High Risk Contractor personnel occupying positions or performing functions with a High Risk designation shall undergo a Tier 4 Background Investigation (BI) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
Background Investigation Process To initiate the request to process contractor personnel, the Contractor shall provide the FEMA Contracting Officer’s Representative (COR) with all required information and comply with all necessary instructions to complete Section II of the FEMA Form 121-3-1-6, “Contract Fitness/Security Screening Request.” The FEMA COR shall ensure that all other applicable sections of the FEMA Form 121-3-1-6 are complete prior to submitting the form to FEMA PSD for processing. The Contractor shall also provide the FEMA COR with completed OF 306, “Declaration for Federal Employment,” forms for all contractor personnel.
Contractor personnel who already have a favorably adjudicated background investigation, may be eligible to perform work under this contract without further processing by FEMA PSD if
· the investigation was completed within the last five years,
· it meets or exceeds the minimum requirement for the position they will occupy or functions they will perform on this contract,
· the contractor personnel have not had a break in employment since the prior favorable adjudication, and
· FEMA PSD has verified the investigation and confirmed that no new derogatory information has been disclosed which may require a reinvestigation.
FEMA PSD will notify the COR of the names of the contractor personnel eligible to work based on prior, favorable adjudication. The COR will, in turn, notify the Contractor of the names of the favorably adjudicated contractor personnel, at which time the favorably adjudicated contractor personnel will be eligible to begin work under this contract.
For those contractor personnel who do not have an acceptable, prior, favorable adjudication or who otherwise require reinvestigation, FEMA PSD will issue an electronic notification via email to the contractor personnel that contains the following documents, which are incorporated into this contract by reference, along with a link to the Office of Personnel Management’s Electronic Questionnaires for Investigation Processing (e-QIP) system and instructions for submitting the necessary information:
· Standard Form 85P, “Questionnaire for Public Trust Positions”
· Optional Form 306, “Declaration for Federal Employment”
· SF 87, “Fingerprint Card” (2 copies)
· DHS Form 11000-6, “Non-Disclosure Agreement”
· DHS Form 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act”
FEMA PSD will only accept complete packages consisting of all of the above document and Standard Form 85P, which must be completed electronically through the Office of Personnel Management’s e-QIP system. The Contractor is responsible for ensuring that all contractor personnel timely and properly submit all required background information.
Once contractor personnel have properly submitted the complete package of all required background information, FEMA’s Personnel Security Division, at its sole discretion, may grant contractor personnel temporary eligibility to perform work under this contract prior to completion of the full background investigation if the Personnel Security Division’s initial review of the contractor personnel’s background information reveals no issues of concern. In such cases, FEMA’s Personnel Security Division will provide notice of such temporary eligibility to the COR who will then notify the Prime Contractor, at which time the identified contractor personnel will be temporarily eligible to begin work under this contract. Neither the Prime Contractor nor the contractor personnel has any right to such a grant of temporary eligibility. The grant of such temporary eligibility shall not be considered as assurance that the contactor personnel will remain eligible to perform work under this contract upon completion of and final adjudication of the full background investigation.
Upon favorable adjudication of the full background investigation, FEMA’s Personnel Security Division will update the contractor personnel’s security file and take no further action. In any instance where the final adjudication results in an unfavorable determination FEMA’s Personnel Security Division will notify the contractor personnel directly, in writing, of the decision and will provide the COR with the name(s) of the contractor personnel whose adjudication was unfavorable. The COR will then forward that information to the Contractor. Contractor personnel who receive an unfavorable adjudication shall be ineligible to perform work under this contract. Unfavorable adjudications are final and not subject to review or appeal.
Continued Eligibility and Reinvestigation Eligibility determinations based on a Low Risk (NACI w/Credit or T1), Moderate Risk (MBI or T2S or High Risk (BI or T4) are valid for five years from the date that the investigation was completed and closed. Contractor personnel required to undergo a background investigation to perform work under this contract shall be ineligible to perform work under this contract upon the expiration the background investigation unless and until the contractor personnel have undergone a reinvestigation and FEMA’s Personnel Security Division has renewed their eligibility to perform work under this contract.
Exclusion by Contracting Officer The Contracting Officer, independent of FEMA’s Personnel Security Division, may direct the Contractor be excluded from working on this contract. Any contractor found or deemed to be unfit or whose continued employment on the contract is deemed contrary to the public interest or inconsistent with the best interest of the agency may be removed.
Facility Access The Contractor shall comply with FEMA Directive 121-1 “FEMA Personal Identity Verification Guidance,” FEMA Directive 121-3 “Facility Access,” and FEMA Manual 121-3-1 “FEMA Credentialing Access Manual,” to arrange for contractor personnel’s access to FEMA facilities, which includes, but is not limited to, arrangements to obtain any necessary identity badges for contractor personnel.
Contractor personnel working within any FEMA facility who do not require access to DHS or FEMA IT systems and do not qualify for a PIV Card may be issued a Facility Access Card (FAC). FACs cannot exceed 180 days; all contractors requiring access greater than 180 days will need to qualify for and receive a PIV card before being allowed facility access beyond 180 days.
Contractor personnel shall not receive a FAC until they have submitted a SF 87, “Fingerprint Card,” and receive approval from FEMA PSD. Contractor personnel using a FAC for access to FEMA facilities must be escorted in Critical Infrastructure areas (i.e., server rooms, weapons rooms, mechanical rooms, etc.) at all times.
FEMA may deny facility access to any contractor personnel whom FEMA’s Office of the Chief Security Officer has determined to be a potential security threat.
The Contractor shall notify the FEMA COR of all terminations/resignations within five calendar days of occurrence. The Contractor must account for all forms of Government-provided identification issued to contractor employees under a contract (i.e., the PIV cards or other similar badges) must return such identification to FEMA as soon as any of the following occurs:
· When no longer needed for contract performance.
· Upon completion of a contractor employee’s employment.
· Upon contract completion or termination.
If an identification card or building pass is not available to be returned, the Contractor shall submit a report to the FEMA COR, referencing the pass or card number, name of the individual to whom it was issued, and the last known location and disposition of the pass or card.
The Contractor or contractor personnel’s failure to return all DHS- or FEMA-issued identification cards and building passes upon expiration, upon the contractor personnel’s removal from the contract, or upon demand by DHS or FEMA may subject the contractor personnel and the Contractor to civil and criminal liability.
Security Training
SECURITY: All personnel require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees’ receive a favorably adjudicated public trust suitability prior to entry on duty (EOD). All individuals will be U.S. citizens. The contractor shall follow the standards established within DHS and FEMA policy.
Unauthorized Disclosure of Classified or Unclassified Information Contractors and Subcontractors who are working on this contract shall receive Unauthorized Disclosure of Classified or Unclassified Information training.
Access to the training can be obtained at:
https://securityawareness.usalearning.gov/unauthorizedrefresher/index.htm
Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
OPSEC Training Contractors and Subcontractors who are working on this contract shall receive the OPSEC Awareness Brief.
Access to the briefing can be obtained at http://cdsetrain.dtic.mil/opsec
Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
Insider Threat Training Insider Threat training for Contractors can be found at: http://cdsetrain.dtic.mil/itawareness/index.htm.
Certificate of training is required for all cleared contractor employees who are working with classified or unclassified information. All certificates must be sent to the assigned FEMA Contracting Officer Representative, before the Contractor or Subcontractor is granted access to classified or unclassified information but no later than 30 calendar days after awarded contract. All cleared contractor personnel are required to recertify Insider Threat training annually thereafter. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
For Official Use Only (FOUO) Information In accordance with DHS Management Directive 11042.1 contractors, consultants and others to whom access is granted will abide by 11042.1; DHS policy regarding the identification and safeguarding of sensitive but unclassified information originated within DHS. It also applies to other sensitive but unclassified information received by DHS from other government and non-governmental activities.
The contractor will:
1. Be aware of and comply with the safeguarding requirements for “For Official Use Only” (FOUO) information as outlined in this directive.
2. Participate in formal classroom or computer based training sessions presented to communicate the requirements for safeguarding FOUO and other sensitive but unclassified information.
3. Be aware that divulging information without proper authority could result in administrative or disciplinary action.
Contractors and Consultants shall execute a DHS Form 11000-6, Sensitive but Unclassified Information Non Disclosure Agreement (NDA), as a condition of access to such information. Other individuals not assigned to or contractually obligated to DHS, but to whom access to information will be granted, may be requested to execute an NDA as determined by the applicable program manager. Execution of the NDA shall be effective upon date of the DHS Policy and not applied retroactively.
Unauthorized Disclosure of Classified or Unclassified Information Contractors and Subcontractors who are working on this contract shall receive the Unauthorized Disclosure of Classified or Unclassified Information training.
Access to the training can be obtained at:
https://securityawareness.usalearning.gov/unauthorizedrefresher/index.htm
Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
Appendix VI – HSAR Class Deviation 15-01: Safeguarding of Sensitive Information (March 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(2) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(3)…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.