TE 10 Mandatory Training DRAFT.docx
DOCX document 111 KB Posted
- Attached to
- FEMA Housing Inspection Services Programs Federal contract opportunity
- Solicitation number
- 70FB8022I0FEMAHIS
About this file
This document is a Technical Exhibit (TE 10) that outlines the mandatory training requirements for contractors under the 2024 IHP Field Services Contract. The required training includes Information Technology Security Awareness, Privacy, DHS Rules of Behavior, Unauthorized Disclosure of Classified or Unclassified Information, OPSEC, Insider Threat, and Unconscious Bias. All contractor personnel must complete the applicable training within 30 days of contract award and annually thereafter by October 31st. Contractors must maintain training records and provide certificates to the Contracting Officer's Representatives (CORs) within 30 days of completion. The document also includes the applicable HSAR clause on Information Technology Security and Privacy Training, which governs the security and privacy training requirements for DHS contractors.
The document is related to a pre-solicitation for FEMA's Housing Inspection Services Programs, Solicitation Number 70FB8022I0FEMAHIS. This is a Request for Information (RFI) only, and no proposals are being requested at this time. FEMA is seeking vendor feedback on the attached RFI document and the associated Performance Work Statement (PWS) for its Housing Inspection Services Program. Responses to the RFI are due by Friday, May 13, 2022 at 5 pm.
View the file
Other files for this federal contract opportunity
Show all 41
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
2024 IHP Field Services Contract Technical Exhibit #10 Mandatory Training for Contractors
The Department of Homeland Security and FEMA requires the following courses and attestation be completed by Contracted personnel within the established timelines and job positions:
| • | Information Technology Security Awareness Training |
| • | Privacy Training |
| • | DHS Rules of Behavior |
| • | Unauthorized Disclosure of Classified or Unclassified Information |
| • | OPSEC Training |
| • | Insider Threat Training |
| • | Unconscious Bias Training |
2024 IHP Field Services Contract Technical Exhibit #10
TE 10 Mandatory Training.docx 1 12/5/2023 Information Technology Security Awareness Training:
Content: Provides guidance for online conduct and proper use of information technology. The Challenge presents cybersecurity and information systems security awareness instructional topics through first-person simulations and mini-game challenges that allow the user to practice and review cybersecurity concepts in an interactive manner. The training takes approximately one (1) hour to complete. Completion of the training is required before access to DHS systems can be provided.
Required Personnel to complete the Training: All Contract personnel accessing DHS / FEMA Systems
Training Location: https://public.cyber.mil/training/cyber-awareness-challenge Training Timeline: Prior to accessing DHS/FEMA Systems and or within 30-days of contract award.
Training Frequency: Annually by October 31st
Training Duration: 1-hour
Contractor Requirements: The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance, provide CORs with training certificates within 30-days of completion or contract award.
Privacy Training:
Content: Defines Personally Identifiable Information (PII); identifies the required methods for collecting, using, sharing, and safeguarding PII; lists the potential consequences of not protecting PII; and requirements for reporting suspected or confirmed privacy incidents. The training takes approximately one (1) hour to complete. Completion of the training is required before access to PII can be provided.
Required Personnel to complete the Training: All Contract personnel with access to Personal Identifying Information.
Training Location: https://www.dhs.gov/course/privacy-dhs Training Timeline: Prior to accessing DHS/FEMA Systems with PII or SPII and or within 30 days of contract award.
Training Frequency: Annually by October 31st
Training Duration: 1-hour
Contractor Requirements: The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance, provide CORs with training certificates within 30-days of completion or contract award.
DHS Rules of Behavior:
Content: The purpose of DHS Rules of Behavior is to inform users of their responsibilities and let them know they will be held accountable for their actions while they are accessing DHS systems and using DHS IT resources capable of accessing, storing, receiving, or transmitting sensitive information. The DHS Rules of Behavior apply to every DHS employee and DHS support contractor.
In addition to having to read, accept, and sign the general Rules of Behavior that apply to DHS systems and IT resources, users also are required to read, accept, and sign Rules of Behavior that apply specifically to systems to which they will have access.
Required Personnel to sign the Rules of Behavior: All Contract personnel with access to Personal Identifying Information or Sensitive Information will sign the Rules of Behavior.
Certification Location: DHS 4300A Sensitive Systems Handbook Attachment G Rules of Behavior Certification Timeline: Prior to accessing DHS/FEMA Systems with PII or SPII and or within 30 days of contract award.
Certification Frequency: Annually, FEMA CORs will provide notification when a review is necessary.
Certification Duration: 1-hour
Contractor Requirements: The Contractor shall maintain signed copies of DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance, provide the FEMA CORs with training certificates within 30-days of signing the form.
Unauthorized Disclosure of Classified or Unclassified Information
Content: This course provides an overview of what unauthorized disclosure is, including specific types of unauthorized disclosure and some common misconceptions about unauthorized disclosure. This course will also discuss the types of damage caused by unauthorized disclosure and the various sanctions one could face if caught engaging in unauthorized disclosure
Required Personnel to complete the Training: All Contract personnel with access to Personal Identifying Information.
Training Location: https://securityawareness.usalearning.gov/disclosure/index.html Training Timeline: Prior to accessing DHS/FEMA Systems with PII or SPII, within 30 days of contract award or within 10-days of new personnel being onboarded.
Training Frequency: Annually
Training Duration: 1-hour
Contractor Requirements: The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance, provide CORs with training certificates within 30-days of completion or contract award.
OPSEC Training
Content: This web-based course provides OPSEC awareness for military members, government employees, and contractors. The course provides information on the basic need to protect unclassified information about operations and personal information to ensure safe and successful operations and personal safety.
Required Personnel to complete the Training: All Contract personnel with access to Personal Identifying Information.
Training Location: https://securityawareness.usalearning.gov/opsec/index.htm Training Timeline: Prior to accessing DHS/FEMA Systems with PII or SPII, within 30 days of contract award or within 10-days of new personnel being onboarded.
Training Frequency: Annually
Training Duration: 1-hour
Contractor Requirements: The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance, provide CORs with training certificates within 30-days of completion or contract award.
Insider Threat Training
Content: This course provides a thorough understanding of how Insider Threat Awareness is an essential component of a comprehensive security program. With a theme of, "If you see something, say something" the course promotes the reporting of suspicious activities observed within the place of duty. Using a few case study scenarios, the course teaches the common indicators which highlight actions and behaviors that can signify an insider threat. The instruction promotes a proactive approach to reporting the suspicious activities.
Required Personnel to complete the Training: All Contract personnel with access to Personal Identifying Information.
Training Location: https://securityawareness.usalearning.gov/itawareness/index.htm# Training Timeline: Prior to accessing DHS/FEMA Systems with PII or SPII, within 30 days of contract award or within 10-days of new personnel being onboarded.
Training Frequency: Annually
Training Duration: 1-hour
Contractor Requirements: The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance, provide CORs with training certificates within 30-days of completion or contract award.
Unconscious Bias Training
Content: No matter who you are, you are prey to unconscious biases. To be part of a complex, diverse team you must take steps to overcome implicit and explicit biases and reject social stereotypes. Understanding you own bias, whether conscious or unconscious, is the key.
Throughout this course you'll learn about the characteristics of unconscious bias and the nature of buried prejudice. You'll discover how they can inadvertently affect your thinking and decision-making. And you'll learn about the positive things that can happen when you take an anti-biased approach to people and situations in the workplace.
Required Personnel to complete the Training: All Contract personnel tasked to this contract.
Training Location: Contractors are to secure appropriate unconscious bias training coursework through a credentialed program. Currently, FEMA utilizes the training vendor Skillsoft and noted curriculum through this link: Understanding Unconscious Bias - EVERYONE - Skillsoft Training Timeline: Within 30 days of contract award or prior to field assessors meeting with the disaster survivor.
Training Frequency: One-time requirement.
Training Time: 30 minutes
Contractor Requirements: The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance, provide CORs with training certificates within 30-days of completion or contract award.
Information Technology Security and Privacy Training (March 2015) Reference: Homeland Security Acquisition Regulation (HSAR) training requirements for DHS contracts include special clauses for Safeguarding of Sensitive Information (March 2015) – disclosed in the Data Sharing Technical Exhibit, and the Information Technology Security and Privacy Training (March 20215) disclosed here.
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Security Training Requirements.
(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. The Department of Homeland Security (DHS) requires that Contractor employees take an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year. The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.
(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within thirty (30) days of contract award. Any new Contractor employees assigned to the contract shall also sign the DHS Rules of Behavior before accessing DHS systems and sensitive information. The Contractor shall maintain signed copies of the DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, the Contractor shall e-mail copies of the signed DHS Rules of Behavior to the COR not later than thirty (30) days after contract award for each employee. The DHS Rules of Behavior will be reviewed annually, and the COR will provide notification when a review is required.
(c) Privacy Training Requirements. All Contractor and subcontractor employees that will have access to Personally Identifiable Information (PII) and/or Sensitive PII (SPII) are required to take Privacy at DHS: Protecting Personal Information before accessing PII and/or SPII. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors.
Training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall also complete the training before accessing PII and/or SPII. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Initial training certificates for each Contractor and subcontractor employee shall be provided to the COR not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year. The e- mail notification shall state the required training has been completed for all Contractor and subcontractor employees.
(end of clause) image1.png
File details come from the government source that posted it. Updated .