70FB8020R00000007 Amend 2 Attach 1 SOW.docx

DOCX document 58 KB Posted

Attached to
IMAT Leadership Development and Support Contract Federal contract opportunity
Solicitation number
70FB8020R00000007rev
Issued by
Federal Emergency Management Agency

About this file

This document includes a request for proposal and statement of work for leadership curriculum development and training implementation support services for the Federal Emergency Management Agency's Incident Management Assistance Teams. Key details include:

  • The solicitation seeks proposals for an initial 4-week leadership academy to train 25 members of a new National IMAT team, with potential additional curriculum design, development, and training support deliverables over the following year.

  • Proposals are due by June 17, 2020 and the period of performance is one base year plus two option years. The contract is a total small business set-aside for HUBZone firms.

  • Offerors must propose curriculum options built from existing trainings and custom materials, and present a project management plan and staffing approach. Key personnel requirements include a Program Manager and Subject Matter Expert.

  • Evaluation criteria prioritize demonstrated experience, technical/management approach, key personnel capabilities, and past performance over the lowest price. Award will be made based on best value.

  • The contractor must develop pre- and post-training assessments, an after-action report, and support knowledge transfer measurement for the initial academy.

View the file

Other files for this federal contract opportunity

Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

IMAT Leadership Development and Support Contract for the Federal Emergency Management Agency Incident Management Assistance Teams

Statement of Work Amendment 2

Leadership Development and Support for the Federal Emergency Management Agency Incident Management Assistance Teams

A. Project Title

Leadership Development and Support for the Federal Emergency Management Agency (FEMA) Incident Management Assistance Teams (IMAT)

B. Background

The Federal Emergency Management Agency, Operational Coordination Division (OCD), is the program office within the U.S. Department of Homeland Security responsible for overseeing the activities of the Regional and National IMAT Teams, as well as the Field Leaders Cadre. In anticipation of, during, and in the aftermath of a major disaster, FEMA’s mission of coordinating Federal disaster response is carried out by its Incident Management Assistance Teams (IMATs), who support and coordinate local, tribal, state, and Federal response and recovery efforts.

The IMAT program and concept has evolved over many years to progressively adapt to new policy, doctrine, and guidance as a result of lessons-learned and best practices. Most recently, in October 2019, FEMA’s then Acting Administrator, Jeffrey Byard, called for the establishment of a third, full-time National IMAT (N-IMAT) team to meet the challenges posed by 2018-2022’s Strategic Plan Goal 2 focus on catastrophic readiness.

The new N-IMAT team was hired in February of 2020 following a rigorous application process consisting of a review of candidates’ technical qualifications, an online executive leadership assessment, and a day-long in-person hiring assessment center that evaluates candidates’ leadership competencies and abilities. Once all positions have been filled, the team will attend a brand-new IMAT Leadership Academy. In the past, initial IMAT training consisted of some team building exercises, as well as technical training, technical drills and exercises. However, based on observations and feedback from existing team members, this approach has not necessarily equipped the team members with the soft-skills they need to successfully execute their leadership roles and responsibilities while managing the demands of a high-stress, high-impact job. The program intends to engage a contractor who can design, develop, deliver and sustain a leadership academy curriculum that will focus on further developing IMAT members leadership competencies, as well as developing their skills as field leaders.

C. Scope

The IMAT program and concept has evolved over several years to execute new policy, doctrine, and guidance as a result of lessons-learned and best practices. This SOW supports FEMA’s Mission of Helping people, Before, During, and After disasters. It has been written to leverage other functional areas in development at the time of this contract to include curriculum designed to meet the challenges faced by high-performance teams and key field leadership.

The Leadership Development and Support contract for the Federal Emergency Management Agency (FEMA) Incident Management Assistance Teams (IMAT) will first develop and deliver leadership training for the 25 members of the newly established National IMAT (White). The first delivery will be at the IMAT Leadership Academy which will be held from, 29 June 2020 - 24 July 2020. Once this academy has ended, we will seek support for developing and delivering curriculum for additional training and readiness drills, and revision of future academies.

**Due to COVID-19 conditions, the initial curriculum and academy will be delivered as the IMAT Leadership Academy held from 29 June 2020 - 24 July 2020 and will be virtual. This initial delivery has its curriculum resourced by the government and the contractor will not be required to resource it, secure passed-through, required to design or developed any curriculum. Once the June/July 2020 academy delivery has ended, the contractor will be required to provide support for redesigning and redeveloping curriculum for an in-residence delivery.**

The contractor will research existing curriculum to include but not be limited to: leadership development, team building, critical thinking, and decision making to meet the above needs for the IMAT Leadership Academy. The contractor will be expected to present a menu of training options to the project management team. The project management team will review options and select curriculum that best fits the needs of the IMAT program based on the contractor’s recommendations. The contractor will be expected to engage subject matter experts to research and develop curriculum. The contractor will be responsible to provide, develop, or collect for all aspects of the development, planning, organization, conduct, and evaluation of curriculum.

Contractor shall also provide curriculum design, development, sustainment and support as required by the government that includes but is not limited to; case studies, training courses, workshops, seminars, revision of current curricula or the like. These deliverables will be identified by the government either by set schedule, or through as needed requirements. This requirement may include six (6) or more deliverables per year. These deliverables will be identified by the government either by set schedule, or through as needed requirements. Contractor shall provide staffing to perform required deliverable by deadline set by government.

D. Specific Tasks and Deliverables

1) IMAT Academy Design and Development

a. Contractor shall participate in a kick-off meeting with the COR and other members of the project to discuss the scope of the project. The COR will provide the contractor with government furnished materials that may be relevant to the task or provide access to these materials. The materials will be identified, reviewed and discussed during the kick-off meeting. The contractor shall provide a weekly project report detailing accruals to date and tasks completed.

Task
Deliverable
Date after Award
1-a
Attend kick-off meeting
2 days after award
1-b
Weekly progress report
Every Friday

b. Contractor shall develop a project management plan based on the initial project meeting and the project Statement of Work (SOW). The contractor shall manage the project in accordance with the approved project management plan submitted and provide weekly progress reports. The work plan shall include, but is not limited to:

i. Deliverables

ii. Task and methods for accomplishing the project

iii. Staffing plan

iv. Detailed program schedule

Task
Deliverable
Date after Award
1-c
Develop project plan
5 days after award

c. The Contractor shall support the design and development of the IMAT Academy. The work plan shall include, but is not limited to:

i. Operational Support

ii. Logistical Support

iii. Curriculum Design

iv. Curriculum Development and Sub-contracting

Operational Support is defined as activities involved in the execution of all phases of the IMAT Academy to include; ensuring that all events are conducted according to the training schedule and modifying the schedule as required based on real-world events; overseeing the logistics and leadership development sections; maintaining accountability of students and staff members; managing and consolidating all action items and lessons learned; and reporting critical information requirements (CIRs) to command.

Logistical Support is defined as activities associated with assessing space and resource requirements and identifying/coordinating solutions based on operational need. Logistics support includes all coordination with academy site for the provisioning of rooms and managing materials and equipment. Logistical support may include but not limited to; coordinating and troubleshooting travel and lodging for students and IT support.

Curriculum Design is defined as activities associated with the development of IMAT Academy curriculum to include; identifying existing off-the-shelf leadership development curriculum, developing customized training and relevant materials as needed, presenting options for curriculum to program management, and building a comprehensive curriculum delivery plan for the duration of the academy.

Curriculum Development and Sub-Contracting includes the following activities; supporting the execution of all leadership training and ensuring that all staff are available at the appropriate times, instructing specified courses/ blocks of instruction, coordinating for subject matter experts to facilitate and lead courses, and providing all necessary course materials to all participants.

Task
Deliverable
Date after Award
1-d
Develop a menu of curriculum options built from existing trainings and custom trainings for program management to choose from. Options should include but are not limited to:

· Leading dynamic teams

· Decision making in uncertainty

· Team building

· Personal resilience

· Conflict resolution

· Problem solving

· Strategic thinking

· Situational leadership

· Emotional intelligence

· Building trust

· Managing change

· Communicating for impact

· Leading virtual teams

· Coaching and motivating employees for success 2 weeks after award

1-e
Present final curriculum proposal and delivery plan based on feedback from program management
4 weeks after award
1-f
Coordinate scheduling and management of all training staff and ensure all expectations of program management team are communicated clearly and effectively
1-g
Provide onsite logistical and operational support throughout the duration of the IMAT Academy, as needed or requested by the government
1-h
Provide subject matter experts and facilitators to lead all leadership development training courses during the IMAT Academy if required or directed
1-i
Provide subject matter expertise support for continuous revision of the curriculum materials for the duration of the IMAT Academy

1-j Liaise with internal FEMA stakeholders to align leadership development curriculum with technical curriculum

1-k
Provide all printed and digital materials needed for course delivery

d. Design and develop plan to measure and assure knowledge transfer has taken place

i. Pre and Post Assessment for each individual learning module, as well as overall curriculum

Task
Deliverable
Date after Award
1-l
Pre and Post assessments for candidates to assess learning transfer
Pre- Within the first week of the academy, Weekly- throughout duration of academy, Post- the last week of the academy

e. Following the conclusion of the academy, contractor will provide after action report detailing success, shortfalls, and recommendations for improvements in the future

Task
Deliverable
Date after Award
1-m
After Action Report
30 days after end of academy

2) Additional Curriculum Design, Development, and Revision

a. Contractor shall participate in a kick-off meeting for each deliverable with the COR and other members of the project to discuss the scope of the project. The COR will provide the contractor with government furnished materials or provide access to these materials. The materials will be reviewed and discussed during the kick-off meeting. The contractor shall provide a weekly project report detailing accruals to date and tasks completed.

Task
Deliverable
Date after Award
2-a
Attend kick-off meeting
As directed
2-b
Weekly progress report
Every Friday for duration of project

b. Contractor shall develop a project management plan for each additional deliverable based on conversations with The Government following contract award. The contractor shall manage the project in accordance with the approved project management plan submitted and provide weekly progress reports. The work plan shall include, but is not limited to:

i. Deliverables

ii. Task and methods for accomplishing the project

iii. Staffing plan

iv. Detailed program schedule

Task
Deliverable
Date after Award
2-c
Develop project plan
As directed

c. The Contractor shall support the design and development of any additional identified deliverables. The work plan shall include, but is not limited to:

i. Operational Support

ii. Logistical Support

iii. Curriculum Design

iv. Curriculum Development and Sub-Contracting

Operational Support is defined as activities involved in the execution of all phases of the IMAT Academy to include; ensuring that all events are conducted according to the training schedule and modifying the schedule as required based on real-world events; overseeing the logistics and leadership development sections; maintaining accountability of students and staff members; managing and consolidating all action items and lessons learned; and reporting critical information requirements (CIRs) to command.

Logistical Support is defined as activities associated with assessing space and resource requirements and identifying/coordinating solutions based on operational need. Logistics support includes all coordination with academy site for the provisioning of rooms and managing materials and equipment. Logistical support also includes coordinating and troubleshooting travel and lodging for students and IT support.

Curriculum Design is defined as activities associated with the development of IMAT Academy curriculum to include; identifying existing off-the-shelf leadership development curriculum, developing customized training and relevant materials as needed, presenting options for curriculum to program management, and building a comprehensive curriculum delivery plan for the duration of the academy.

Curriculum Development and Sub-Contracting includes the following activities; supporting the execution of all leadership training and ensuring that all staff are available at the appropriate times, instructing specified courses/ blocks of instruction, coordinating for subject matter experts to facilitate and lead courses, and providing all necessary course materials to all participants.

d. Design and develop plan to measure and assure knowledge transfer has taken place if directed by The Government

Task
Deliverable
Date after Award
2-d
Pre and Post assessments for candidates to assess learning transfer
Weekly throughout duration of training delivery

e. Following the conclusion of the academy, contractor will provide after action report detailing success, shortfalls, and recommendations for improvements in the future

Task
Deliverable
Date after Award
2-e
After Action Report
30 days after end of academy

E. Requirements

The execution of tasks under this contract will require continuous coordination and cooperation with all other Operational Coordination Division (OCD) product line contract support personnel. Through the tasking of FEMA/OCD, the contractor shall be required to comply with all directives and tasking issued to the OCD program managers by their superior offices/officers. The contractor shall:

· Provide recommendations and support development of training materials to determine process for prioritizing allocation of OCD resources in support of curriculum, exercises and other preparedness initiatives;

· Develop, maintain, and oversee the implementation of project work plans to include coordination, among various product line vendors and ensure efficiencies and best value for the government;

· Research and develop curriculum progress reporting material for written and oral reports;

· Coordinate with contractors from other functional area contracts to develop and conduct training;

· Prepare correspondence to all training staff;

· Provide regular (bi-weekly) updates in a common format (as determined by the federal program staff) on project/ activity;

· Provide support for program governance and stakeholder management;

· Provide project oversight and life-cycle coordination;

· Coordinate the development, planning, and organization of curriculum;

· Support all OCD affiliated curriculum and exercise building block activities;

· Identify and recommend methods to link separate curriculum and exercise building block activities into thematic groups, especially within the context of the Strategic Plan;

· Assist in identifying facility and schedule requirements for hosting leadership development training;

· Maintain a detailed accounting of all curriculum planning, development, execution, and evaluation benchmarks and milestones;

· Maintain the ability to provide reports for curriculum planning on a just-in-time basis, with the ability to expand or aggregate the data based on the level of detail required for the intended audience;

· Ensure key personnel working on this contract are familiar with national preparedness-related doctrines

· Ensure key personnel working on this contract have experience in project management ensuring solutions in the contract are completed in a timely manner as agreed upon with federal program managers;

· Ensure key personnel working on this contract have extensive experience as technical leaders and project managers;

· Ensure that key personnel working on this contract are subject matter experts in leadership development training;

· Ensure key personnel working on this contract are subject matter experts in adult learning principles;

· Ensure all personnel have experience with Microsoft Outlook, Word, Excel, PowerPoint, Project, and other relevant FEMA approved software tools for to create management efficiencies;

· Facilitate the payment of all outside vendors, as related to this requirement and directed by the COR, as a pass-through cost for The Government

F. Contractor Personnel Qualified Personnel and Labor Categories - It is the responsibility of the Contractor to propose qualified Contractor personnel to perform all requirements specified in the SOW. Qualified personnel should have significant experience in curriculum design and delivery support services.

FEMA anticipates the following labor categories will be designated as Key Personnel to support OCD under this requirement:

1. Program Manager The Program Manager shall serve as a senior leader with experience in project and task management. The Program Manager ensures successful task completion within the scheduled timeframe in accordance with the established scope of work, to include both the technical and financial solutions. The Program Manager shall organize, direct, and coordinate the planning and production of all activities associated with assigned tasks. The Program Manager shall advise, direct and coordinate projects that require practical experience, theoretical understanding, and technical knowledge in emergency management and/or actual experience in FEMA operations and disaster assistance programs. The Program Manager shall be the single point of contact for the CO or COR, and if someone will act in their absence, the CO/COR should be made aware. The Program Manager is further designated as Key by the Government. During any absence of the Program Manager, only one alternate shall have full authority to act for the Contractor on all matters relating to work performed under this contract. The Program Manager and all designated alternates shall be able to read, write, speak and understand English. Additionally, the Contractor shall not replace the Program Manager without prior approval from the Contracting Officer.

· Minimum of 8 years of relevant experience in program management and a Bachelor’s Degree.

2. Subject Matter Expert (SME) Description: Researches, designs, and develops curricula. Determines, in conjunction with management, the scope and sequencing of technical and/or professional development training for staff at various levels of expertise. Determines, in conjunction with management, the scope, content, and objectives required to function successfully in broad job categories. Develops: course materials, presentation materials, workshops, collective terminal objective based training, seminars, exercises, and classroom handouts and manuals and/or other teaching aids. Conducts assessments of present and anticipated training needs.

· Minimum of 7 years of relevant experience and a Bachelor’s Degree. Experience in researching, designing, developing and delivering collective initial and/or advanced training programs.

G. Place of Performance

The majority of the work will be performed at the contractor’s office, with exception of deliverable 1-g which will take place at a location of the governments choosing. The Government reserves the right to change the location as required. The contractor will be responsible for all associated travel and per diem costs for contract staff and all reimbursements will be processed in accordance with FEMA travel policy and Federal Travel Regulations.

H. Travel

All travel shall be preauthorized by the COR.

I. Period of Performance The period of performance for this contract shall be 12-month base year, with two (2) twelve-month option years beginning on June XX, 2020 and will continue through June XX, 2021.

J. Security To accomplish the tasks outlined in this contract, FEMA will share with the contractor the following PII data elements: Names, email address and work phone number for: Randy Warren, randy.warren@fema.dhs.gov, 202.304.5389; Benjamin Butterworth, benjamin.butterworth@fema.dhs.gov, 202.212.2344; Kathleen Mc Coy, kathleen.mccoy@fema.dhs.gov, 202.924.2739.

This information sharing is authorized by The Homeland Security Act of 2002, 6 U.S.C. 313, 314, 317, 320, 321a, and 711; Robert T. Stafford Disaster Relief and Emergency Assistance Act, as amended, 42 U.S.C. 5144, 5149, 5170b, 5192, and 5197; and Routine Use F of the DHS/ALL-014 Department of Homeland Security Personnel Contact Information, March 16, 2018, 83 FR 11780.

All work performed under this SOW is unclassified unless otherwise specified by DHS. All unclassified “For Official Use Only” (FOUO) work is expected to occur at the “medium” level per the NIST 800-60 (FIPS Security Categorization) and the Federal Information Security Management Act (FISMA).

SECURITY: All personnel require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees’ receive a favorably adjudicated public trust suitability prior to entry on duty (EOD). All individuals will be U.S. citizens. The contractor shall follow the standards established within DHS and FEMA policy.

Unauthorized Disclosure of Classified or Unclassified Information:

Contractors and Subcontractors who are working on this contract shall receive Unauthorized Disclosure of Classified or Unclassified Information training.

Access to the training can be obtained at:

https://securityawareness.usalearning.gov/unauthorizedrefresher/index.htm Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

OPSEC Training:

Contractors and Subcontractors who are working on this contract shall receive the OPSEC Awareness Brief.

Access to the briefing can be obtained at http://cdsetrain.dtic.mil/opsec Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

Insider Threat Training:

Insider Threat training for Contractors can be found at: http://cdsetrain.dtic.mil/itawareness/index.htm.

Certificate of training is required for all cleared contractor employees who are working with classified or unclassified information. All certificates must be sent to the assigned FEMA Contracting Officer Representative, before the Contractor or Subcontractor is granted access to classified or unclassified information but no later than 30 calendar days after awarded contract. All cleared contractor personnel are required to recertify Insider Threat training annually thereafter. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

For Official Use Only (FOUO) Information:

In accordance with DHS Management Directive 11042.1 contractors, consultants and others to whom access is granted will abide by 11042.1; DHS policy regarding the identification and safeguarding of sensitive but unclassified information originated within DHS. It also applies to other sensitive but unclassified information received by DHS from other government and non-governmental activities.

The contractor will:

1. Be aware of and comply with the safeguarding requirements for “For Official Use Only” (FOUO) information as outlined in this directive.

2. Participate in formal classroom or computer-based training sessions presented to communicate the requirements for safeguarding FOUO and other sensitive but unclassified information.

3. Be aware that divulging information without proper authority could result in administrative or disciplinary action.

Contractors and Consultants shall execute a DHS Form 11000-6, Sensitive but Unclassified Information Non Disclosure Agreement (NDA), as a condition of access to such information. Other individuals not assigned to or contractually obligated to DHS, but to whom access to information will be granted, may be requested to execute an NDA as determined by the applicable program manager. Execution of the NDA shall be effective upon date of the DHS Policy and not applied retroactively.

Unauthorized Disclosure of Classified or Unclassified Information Contractors and Subcontractors who are working on this contract shall receive the Unauthorized Disclosure of Classified or Unclassified Information training.

Access to the training can be obtained at:

https://securityawareness.usalearning.gov/unauthorizedrefresher/index.htm Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

52.239-1 PRIVACY OR SECURITY SAFEGUARDS (AUG 1996)

(a) The Contractor shall not publish or disclose in any manner, without the Contracting Officer's written consent, the details of any safeguards either designed or developed by the Contractor under this contract or otherwise provided by the Government.

(b) To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor shall afford the Government access to the Contractor's facilities, installations, technical capabilities, operations, documentation, records, and databases.

(c) If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

5.4 HSAR Clauses

SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause— “Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods:

(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements.

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Data Universal Numbering System (DUNS);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email);

(v) Contracting Officer POC (address, telephone, email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the Government PII and/or SPII contained within the system;

(xiii) Number of people potentially affected, and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

(g) Sensitive Information Incident Response Requirements.

(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.

(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:

(i) Inspections,

(ii) Investigations,

(iii) Forensic reviews, and

(iv) Data analyses and processing.

(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

(h) Additional PII and/or SPII Notification Requirements.

(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.

(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:

(i) A brief description of the incident;

(ii) A description of the types of PII and SPII involved;

(iii) A statement as to…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .