Clauses rev 4 updated.docx
DOCX document 97 KB Posted
- Attached to
- Doctrine Support Federal contract opportunity
- Solicitation number
- 70FB7019R00000019
- Issued by
- Federal Emergency Management Agency
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 4 Past Performance.docx | DOCX document | |
| Attachment 1 Doctrine Support Price CLIN Sheet updated 02.05.20.xlsx | XLSX spreadsheet | |
| Attachment 3 - Resume Template.docx | DOCX document | |
| Questions and Answers Consolidated.xlsx | XLSX spreadsheet | |
| Amendment 00001 Signed.pdf | ||
| Request for Proposal 70FB7019R00000019 v2.pdf | ||
| Attachment 2 Statement of Work.pdf | ||
| Attachment 4 Past Performance.pdf | ||
| QA Template.xlsx | XLSX spreadsheet | |
| Attachment 3 - Resume Template.pdf | ||
| Attachment 1 Doctrine Support Price CLIN Sheet.xlsx | XLSX spreadsheet | |
| Request for Proposal 70FB7019R00000019.pdf | ||
| Draft SOW - Doctrine Support updated.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
70FB7019R00000019
70FB7019R00000019
SECTION B – SUPPLIES, SERVICES, AND PRICES
B.1 ITEMS TO BE ACQUIRED
The contractor shall provide technical support to:
1. Develop doctrinal documents in accordance with NRF, CFR 44, NIMS, NDRF, Stafford Act and other authoritative documents relevant to FEMA’s legal responsibilities. Documents must incorporate working group input.
2. Develop draft doctrine text based on validated, value-added ideas from training exercise and working group results.
3. Support the comment adjudication process by consolidating inputs from stakeholders into a single comment matrix and incorporate approved changes into documents.
4. Conduct working groups to validate draft doctrine through facilitation, identification of issues and gaps within the draft and subject related documents for discussion, preliminary outline, draft invites and concepts of operation.
5. Ensure that documents developed meet the following specifications:
a. In accordance with applicable Government policies, including proper formatting in line with Government Printing Office (GPO) and DHS house style guidance.
b. Documents shall be based on FEMA, ORR validated research and analysis conducted by the Contractor.
c. Documents content shall incorporate working group results, validated concepts, proven joint capabilities, lessons learned, and established best practices.
Review lessons learned, best practices, and insights. In addition to the routine research of lessons learned during doctrine assessment and development, the Contractor shall review and comment on specific draft and final “lessons learned,” “best practices,” and “insights” reports and/or documents as directed by the ORR Doctrine Section to determine their potential impact on doctrine.
B.2 PRICE SCHEDULE
Offerors shall provide a detail breakdown for each contract line item numbers (CLINs) listed above. Contractor must use format in Attachment 1. If Attachment 1 format is not utilized, the proposal is deemed UNACCEPTABLE.
B.3 MINIMUM AND MAXIMUM QUANTITIES FOR MULTIPLE SINGLE AWARD CONTRACTS
The guaranteed contract minimum is $1,000.00. The contract ceiling amount shall not exceed $20,640,626.98.
B.4 CONTRACT TYPE
The Department Homeland Security (DHS) - Federal Emergency Management Agency (FEMA) intends to award a single award Indefinite Delivery-Indefinite Quantity (IDIQ) contracts. Task orders will be hybrid Firm-Fixed-Price (FFP) and Time and Materials Labor Hours CLINs.
B.5 IDENTIFICATION OF GOVERNMENT OFFICIALS
The Government Officials assigned to this contract are as follows:
Contracting Officer:
Name: Isaac L. Chapple, Contracting Officer Phone: 202-212-3924 Email: Isaac.Chapple@fema.dhs.gov
Contracting Specialist:
Name: Kristyl Grier, Contracting Specialist Phone: 202-212-4637 Email: Kristyl. Grier@fema.dhs.gov
Contracting Officer Representative:
Name: To Be Determined at time of Award Phone:
Email:
B.6 PERIOD OF PERFORMANCE
The contract shall be effective as of the execution date and shall continue through five years one base plus four (4) option periods, except that delivery orders placed prior to the expiration date shall remain in full force and effect until deliveries have been completed and payments, therefore, have been made.
1. The Period of Performance shall be from the date of contract award through 12 months.
2. If Option 1 is exercised, the Period of Performance shall be from the effective date of the option through 12 months.
3. If Option 2 is exercised, the Period of Performance shall be from the effective date of the option through 12 months.
4. If Option 3 is exercised, the Period of Performance shall be from the effective date of the option through 12 months.
5. If Option 4 is exercised, the Period of Performance shall be from the effective date of the option through 12 months.
B.7 PLACE OF PERFORMANCE
The primary place of performance will be at the Contractor’s own facility. There will be instances where the Contractors are required to be at FEMA Headquarters (meetings, workshops, etc.). The Contractor will be required to attend frequent meetings and planning sessions for coordination and planning purposes at:
Federal Emergency Management Agency Headquarters Office of Response and Recovery Doctrine and Policy Office 500 C Street SW Washington DC 20472
B.8 BILLING INSTRUCTIONS
Contractors will use Standard Form 1034 (Public Voucher for Purchases and Services Other Than Personal) located at http://www.gsa.gov/portal/forms/type/SF when submitting a payment request. A payment request means any invoice or request for contract financing payment requesting reimbursement for supplies or services rendered. The Contractor shall not be paid more frequently than on a monthly basis.
Contractors must submit vouchers electronically in pdf format to the FEMA Finance Center at FEMA-Finance-Vendor-Payments@fema.dhs.gov. A copy of the voucher must be submitted electronically to the contracting officer identified within this contract. The submission of vouchers electronically will reduce correspondence and other causes for delay to a minimum and will facilitate prompt payment to the Contractor. Paper vouchers mailed to the finance center will not be processed for payment. If the Contractor is unable to submit a payment request in electronic form, the contractor shall submit the payment request using a method mutually agreed to by the Contractor, the Contracting Officer, and the payment office.
B.9 INVOICE INSTRUCTIONS
The contractor shall submit a monthly invoice upon delivery and acceptance of all supplies or services as specified in the Section B clause, “Consideration and Payment”. Invoices shall be submitted as follows:
Contractors will use Standard Form 1034 (Public Voucher for Purchases and Services Other Than Personal) and SF 1035 Continuation sheet when requesting payment for supplies or services rendered. The voucher must provide a description of the supplies or services, by line item (if applicable), quantity, unit price, and total amount. The item description, unit of measure, and unit price must match those specified in the contract. Invoices that do not match the line item pricing in the contract will be considered improper and will be returned to the Contractor.
SF 1034 and 1035 instructions: SF 1034 – Fixed Price The information which a contractor is required to submit in its Standard Form 1034 is set forth as follows:
(1) U.S. Department, Bureau, or establishment and location insert the names and address of the servicing finance office unless the contract specifically provides otherwise.
(2) Date Voucher Prepared - insert date on which the public voucher is prepared and submitted.
(3) Contract/Delivery Order Number and Date - insert the number and date of the contract and delivery order, if applicable, under which reimbursement is claimed.
(4) Requisition Number and Date - leave blank.
(5) Voucher Number - insert the appropriate serial number of the voucher. A separate series of consecutive numbers, beginning with Number 1, shall be used by the contractor for each new contract. When an original voucher was submitted, but not paid in full because of suspended costs, resubmission vouchers should be submitted in a separate invoice showing the original voucher number and designated with the letter "R" as the last character of the number. If there is more than one resubmission, use the appropriate suffix (R2, R3, etc.)
(6) Schedule Number; Paid By; Date Invoice Received - leave blank.
(7) Discount Terms - enter terms of discount, if applicable.
(8) Payee's Account Number - this space may be used by the contractor to record the account or job number(s) assigned to the contract or may be left blank.
(9) Payee's Name and Address - show the name of the contractor exactly as it appears in the contract and its correct address, except when an assignment has been made by the contractor, or the right to receive payment has been restricted, as in the case of an advance account. When the right to receive payment is restricted, the type of information to be shown in this space shall be furnished by the Contracting Officer.
(10) Shipped From; To; Weight Government B/L Number - insert for supply contracts.
(11) Date of Delivery or Service - show the month, day and year, beginning and ending dates of supplies or services delivered.
(12) Articles and Services - insert the following: "For detail, see Standard Form 1035 total amount claimed transferred from Page of Standard Form 1035.”
B.10 DEFECTIVE OR IMPROPER INVOICES (JUN 2014)
Name, title, phone number, and email of officials of the business concern who are to be notified when the Government receives an improper invoice.
| __TBD______________________________________________________________________ |
| ____________________________________________________________________________ |
| ____________________________________________________________________________ |
B.11 PAYMENT FOR UNAUTHORIZED WORK
No payments will be made for any unauthorized supplies and/or services or for any unauthorized changes to the work governed under a particular task order. This includes any services performed by the contractor of their own volition or at the request of an individual other than a
B.12 TASK ORDERS
All task orders will be initiated by the Contracting Officer via a request for task order proposals with specific information and instructions for supplies required. The Contractor will be required to perform the services in accordance with issued task orders. The task order proposal request is not a commitment that the FEMA will issue a task order, nor will any Contractor incurred proposal cost become reimbursable. In addition, the Contractor shall not initiate any performance efforts until a written task order has been signed and issued by the Contracting Officer or issued orally by the Contracting Officer.
B.13 TASK ORDER PROCEDURES
The Government (CO/CS) will issue task order proposal requests with documents and information to include (but not limited to): the statement of work, pricing schedule, period of performance, and place of performance. The contractor must submit its technical and price proposals to CO and CS only. The government will evaluate both the technical and price proposals for contract award and issue Task Order.
B.14 TASK ORDER ISSUANCE
A Task Order may be issued without negotiations based on acceptability of the Task Order Proposal. If negotiations are required, the Contract Specialist will arrange a meeting or a conference call among the appropriate Government and Contractor personnel. The Government may request submission of a Revised Proposal and/or Final Work Plan, if required. If an agreement cannot be reached on any aspect of the delivery, the Government has the right to unilaterally issue the Task Order, and the Contractor is required to perform; however, while performance is taking place, the Contractor has the right to pursue applicable remedies under the Disputes clause of the Contract.
Upon signature by the Contracting Officer, each Task Order is considered fully executed, binding and ready for implementation. Each Task Order will be forwarded promptly to the Contractor and shall conform to all terms and conditions of the contract. Orders may be issued electronically.
B.15 MODIFICATIONS
Under this contract, and subsequent Task Orders, the Contracting Officer is the only Government official authorized to make changes via a Standard Form 30. Only a duly appointed FEMA Contracting Officer is authorized to change the specifications, terms, and conditions of this contract and subsequent task order(s).
SECTION C – CONTRACT CLAUSES
C.1 - 52.212-4 Contract Terms and Conditions - Commercial Items. (OCT 2018) by reference (see SF 1449 block 27a) - 52.212-4 Alternate I (Jan 2017) C.2 - Addendum to FAR 52.212-4 In addition to the FAR 52.212-4 “Contract Terms and Conditions—Commercial Items” the following FAR, HSAR and FEMA Clauses are incorporated as an addendum to this solicitation. The full text can be accessed at https://www.acquisition.gov/ FAR 52.252-2 Clauses Incorporated by Reference This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): http://www.acquisition.gov/far/index.html
| Clause Database |
| Clause Number |
| Clause Title |
| FAR |
| 52.202-1 |
| Definitions (NOV 2013) |
| FAR |
| 52.203-3 |
| Gratuities (APR 1984) |
| FAR |
| 52.203-5 |
| Covenant Against Contingent Fees (MAY 2014) |
| FAR |
| 52.203-6 |
| Restrictions on Subcontractor Sales to the Government (SEPT 2006) - Alternate I (OCT 1995) |
| FAR |
| 52.203-7 |
| Anti-Kickback Procedures. (MAY 2014) |
| FAR |
| 52.203-12 |
| Limitation on Payments to Influence Certain Federal Transactions. (OCT 2010) |
| FAR |
| 52.203-17 |
| Contractor Employee Whistleblower Rights and Requirement To Inform Employees of Whistleblower Rights (APR 2014) |
| FAR |
| 52.216-22 |
| Indefinite Quantity (OCT 1995) |
| FAR |
| 52.216-25 |
| Contract Definitization (OCT 2010) |
| FAR |
| 52.516-25 |
| Alternate 1 (APR 1984) |
| FAR |
| 52.223-17 |
| Affirmative Procurement of EPA-designated Items in Service and Construction Contracts (AUG 2018) |
| FAR |
| 52.223-18 |
| Encouraging Contractor Policies to Ban Text Messaging While Driving. (AUG 2011) |
| FAR |
| 52.224-3 |
| Privacy Training (JAN 2017) |
| FAR |
| 52.228-5 |
| Insurance - Work on a Government Installation. (JAN 1997) |
| FAR |
| 52-232-1 |
| Payments (APR 1984) |
| FAR |
| 52.232-17 |
| Interest (MAY 2014) |
| FAR |
| 52.232-18 |
| Availability of Funds (APR 1984) |
| FAR |
| 52.232-39 |
| Unenforceability of Unauthorized Obligations (JUN 2013) |
| FAR |
| 52.233-1 |
| Disputes (MAY 2014) - Alternate I (DEC 1991) |
| FAR |
| 52.239-1 |
| Privacy or Security Safeguards (AUG 1996) |
| FAR |
| 52.244-6 |
| Subcontracts for Commercial Items (AUG 2019) |
| FAR |
| 52.246-4 |
| Inspection of Services – Fixed Price (AUG 1996) |
| FAR |
| 52.246-6 |
| Inspection – Time and Material and L/H (MAY 2001) |
| FAR |
| 52.246-15 |
| Certificate of Conformance (APR1984) |
| HSAR |
| 3052.219-70 |
| Small business subcontracting plan reporting. (JUN 2006) |
| HSAR |
| 3052.222-70 |
| Strikes or picketing affecting timely completion of the contract work. (DEC 2003) |
| HSAR |
| 3052.245-70 |
| Government Property Reports. (AUG 2008) [Deviation] |
C 2.1 52.215-19 Notification of Ownership Changes. (OCT 1997)
(a) The Contractor shall make the following notifications in writing:
(1) When the Contractor becomes aware that a change in its ownership has occurred, or is certain to occur, that could result in changes in the valuation of its capitalized assets in the accounting records, the Contractor shall notify the Administrative Contracting Officer (ACO) within 30 days.
(2) The Contractor shall also notify the ACO within 30 days whenever changes to asset valuations or any other cost changes have occurred or are certain to occur as a result of a change in ownership.
(b) The Contractor shall -
(1) Maintain current, accurate, and complete inventory records of assets and their costs;
(2) Provide the ACO or designated representative ready access to the records upon request;
(3) Ensure that all individual and grouped assets, their capitalized values, accumulated depreciation or amortization, and remaining useful lives are identified accurately before and after each of the Contractor's ownership changes; and
(4) Retain and continue to maintain depreciation and amortization schedules based on the asset records maintained before each Contractor ownership change.
(c) The Contractor shall include the substance of this clause in all subcontracts under this contract that meet the applicability requirement of FAR 15.408(k).
C 2.3 52.216-24 Limitation of Government Liability. (APR 1984)
(a) In performing this contract, the Contractor is not authorized to make expenditures or incur obligations exceeding [ ] $500.00 dollars.
(b) The maximum amount for which the Government shall be liable if this contract is terminated is [ $500.00]dollars.
C 2.4 52.217-8 Option to Extend Services.
The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 30 days.
C 2.5 52.217-9 Option to Extend the Term of the Contract. (MAR 2000)
(a) The Government may extend the term of this contract by written notice to the Contractor within 30 days; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 60 days before the contract expires. The preliminary notice does not commit the Government to an extension.
(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.
(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed sixty (60) (months) or five (5) (years).
C 3. 3052.212-70 Contract Terms and Conditions Applicable to DHS Acquisition of Commercial Items. (SEP 2012) The Contractor agrees to comply with any provision or clause that is incorporated herein by reference to implement agency policy applicable to acquisition of commercial items or components. The provision or clause in effect based on the applicable regulation cited on the date the solicitation is issued applies unless otherwise stated herein. The following provisions and clauses are incorporated by reference: http://farsite.hill.af.mil/VFHSARA.HTM
(a) Provisions.
_X__ 3052.209-72 Organizational Conflicts of Interest.
_____ 3052.216-70 Evaluation of Offers Subject to An Economic Price Adjustment Clause.
_____ 3052.219-72 Evaluation of Prime Contractor Participation in the DHS Mentor Protege Program.
(b) Clauses.
_____ 3052.203-70 Instructions for Contractor Disclosure of Violations.
_____ 3052.204-70 Security Requirements for Unclassified Information Technology Resources.
__X_ 3052.204-71 Contractor Employee Access.
_____ Alternate I _____ 3052.205-70 Advertisement, Publicizing Awards, and Releases.
_____ 3052.209-73 Limitation on Future Contracting.
__X__ 3052.215-70 Key Personnel or Facilities.
_____ 3052.216-71 Determination of Award Fee.
_____ 3052.216-72 Performance Evaluation Plan.
_____ 3052.216-73 Distribution of Award Fee.
_____ 3052.217-91 Performance. (USCG) _____ 3052.217-92 Inspection and Manner of Doing Work. (USCG) _____ 3052.217-93 Subcontracts. (USCG) _____ 3052.217-94 Lay Days. (USCG) _____ 3052.217-95 Liability and Insurance. (USCG) _____ 3052.217-96 Title. (USCG) _____ 3052.217-97 Discharge of Liens. (USCG) _____ 3052.217-98 Delays. (USCG) _____ 3052.217-99 Department of Labor Safety and Health Regulations for Ship Repair. (USCG) _____ 3052.217-100 Guarantee. (USCG) __X__ 3052.219-70 Small Business Subcontracting Plan Reporting.
_____ 3052.219-71 DHS Mentor Protege Program.
__X_ 3052.228-70 Insurance.
_____ 3052.228-90 Notification of Miller Act Payment Bond Protection. (USCG) _____ 3052.228-91 Loss of or Damage to Leased Aircraft. (USCG) _____ 3052.228-92 Fair Market Value of Aircraft. (USCG) _____ 3052.228-93 Risk and Indemnities. (USCG) _____ 3052.236-70 Special Provisions for Work at Operating Airports.
__X_ 3052.242-72 Contracting Officer's Technical Representative.
_____ 3052.247-70 F.o.B. Origin Information.
_____ Alternate I _____ Alternate II _____ 3052.247-71 F.o.B. Origin Only.
__X_ 3052.247-72 F.o.B. Destination Only.
C.4 PACKAGING AND MARKING
A project execution plan will be required for all assignment and other specific deliverable descriptions and due dates will be detailed in each task order.
Unless otherwise specified, the Contractor must be able to provide written documents in electronic (i.e., source and pdf formats). Electronic copies provided must be compatible with Microsoft Project, Word, Excel, Access, PowerPoint, or other (FEMA, ORR) Microsoft Office software applications. The Contractor must be able to accept and send document files electronically.
For deliverables, the Contractor shall ensure that all reports are written in clear, concise English without typographical or grammatical errors. The Contractor shall meet all of the report writing guidelines in the United States Government Printing Office Style Manual and the Department of Homeland Security Guidelines.
Any and all electronic and information technology (EIT) procured through this effort must meet the applicable accessibility standards at 36 CFR 1194. 36 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at: http://www.section508.gov .
All information relating to the items to be delivered or services to be performed under this contract may not be disclosed by any means without prior approval of the CO. Dissemination of public disclosures includes but is not limited to: permitting access of such information by foreign national or by any other person, entity, and publication of technical or scientific papers, advertising, or any other proposed public release. The Contractor shall provide adequate physical protection to such information so as to preclude access by any person or entity not authorized such access by the Government.
C.5 Section 508 Compliance Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology (EIT), they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.
All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable EIT accessibility standards have been identified:
Section 508 Applicable EIT Accessibility Standards
a. 36 CFR 1194.21 Software Applications and Operating Systems applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.
b. 36 CFR 1194.22 Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous JavaScript and XML (AJAX) then 1194.21 Software standards also apply to fulfill functional performance criteria.
c. 36 CFR 1194.24 Video and Multimedia Products applies to all video and multimedia products that are procured or developed under this work statement. Any video or multimedia presentation shall also comply with the software standards (1194.21) when the presentation is through the use of a Web or Software application interface having user controls available.
d. 36 CFR 1194.25 Self Contained, Closed Products, applies to all EIT products such as printers, copiers, fax machines, kiosks, etc. that are procured or developed under this work statement.
e. 36 CFR 1194.31 Functional Performance Criteria applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.
f. 36 CFR 1194.41 Information Documentation and Support applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required 1194.31 Functional Performance Criteria, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.
Section 508 Applicable Exceptions Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COTR and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply: 36 CFR 1194.3(b) Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.
Section 508 Compliance Requirements 36 CFR 1194.2(b) (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meet some but not all of the standards, the agency must procure the product that best meets the standards. When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.
All delivery’s for testing of functional and/or technical requirements must include specific testing for Section 508 compliance and must use DHS Office of Accessible Systems and Technology approved testing methods and tools. For information about approved testing methods and tools send an email to accessibility@dhs.gov.
C.6 SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause— “Personally, Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
| (1) | Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee); |
| (2) | (2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee); |
| (3) | (3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and |
| (4) | (4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures. |
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.
(f) Sensitive Information Incident Reporting Requirements.
(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information or has otherwise failed to meet the requirements of the contract.
(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
(i) Data Universal Numbering System (DUNS);
(ii) Contract numbers affected unless all contracts by the company are affected;
(iii) Facility CAGE code if the location of the event is different than the prime contractor location;
(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email);
(v) Contracting Officer POC (address, telephone, email);
(vi) Contract clearance level;
(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;
(viii) Government programs, platforms or systems involved;
(ix) Location(s) of incident;
(x) Date and time the incident was discovered;
(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;
(xii) Description of the Government PII and/or SPII contained within the system;
(xiii) Number of people potentially affected, and the estimate or actual number of records exposed and/or contained within the system; and
(xiv) Any additional information relevant to the incident.
(g) Sensitive Information Incident Response Requirements.
(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.
(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:
(i) Inspections,
(ii) Investigations,
(iii) Forensic reviews, and
(iv) Data analyses and processing.
(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.
(h) Additional PII and/or SPII Notification Requirements.
(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.
(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:
(i) A brief description of the incident;
(ii) A description of the types of PII…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .