70RDAD20R00000007 Attachment 1.pdf
PDF 520 KB Posted
- Attached to
- Employment Verification and Unemployment Compensation Services Federal contract opportunity
- Solicitation number
- 70RDAD20R00000007
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 1 - CLINS and SOW-002.pdf | ||
| 70RDAD20R00000007-002 Questions-Responses.pdf | ||
| 70RDAD20R00000007 Attachment 2.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
70RDAD20R00000007 Attachment 1 - SCHEDULE OF CLINS AND STATEMENT OF WORK
70RDAD20R00000007 Attachment 1 Page 1 of 34
CONTRACT LINE ITEM NUMBER (CLIN) 0001
Base Period
Estimated Time Period for ATO Approval: Twelve (12) Months
SUPPLIES/SERVICES CLIN
TYPE
UNIT QUANTITY UNIT
PRICE
TOTAL
PRICE
Authority to Operate (ATO) FIRM
FIXED
PRICE
LO 1
CLIN 0002
Base Period
Estimated Time Period for ATO Approval: Twelve (12) Months
SUPPLIES/SERVICES CLIN
TYPE
UNIT QUANTITY UNIT
PRICE
TOTAL
PRICE
Travel
Not to Exceed Ceiling Price:
$5,000.00.
Contractor exceeds the ceiling price at their own risk. Travel to be paid in accordance with the Federal Travel Regulations
(FTR).
Time and Materials
LO 1
Please note: The Authority to Operate approval process is estimated to take approximately 12 months for completion. However, that process could take less than or more than that estimated period. Accordingly, the Base period of performance may extend beyond the estimated 12 months or shortened less than the estimated 12 months in coordination with the completion of the ATO Approval Process. Option Period One (1) and all subsequent Option periods of performance may be revised upon issuance of the ATO and the exercise of Option Period One. The overall contract period of performance shall not exceed five (5) years.
70RDAD20R00000007 Attachment 1 Page 2 of 34
CLIN 1001
Option Period One
Period of Performance: Twelve (12) Months
SUPPLIES/SERVICES CLIN
TYPE
UNIT QUANTITY UNIT
PRICE
TOTAL
PRICE
Full Employment Verification and Unemployment Compensation Support Services in accordance with the SOW.
FIRM
FIXED
MO 12
CLIN 2001
Option Period Two
Period of Performance: Twelve (12) Months
SUPPLIES/SERVICES CLIN
TYPE
UNIT QUANTITY UNIT
PRICE
TOTAL
PRICE
Full Employment Verification and Unemployment Compensation Support Services in accordance with the SOW.
FIRM
FIXED
CLIN 3001
Option Period Three
Period of Performance: Twelve (12) Months
SUPPLIES/SERVICES CLIN
TYPE
UNIT QUANTITY UNIT
PRICE
TOTAL
PRICE
Full Employment Verification and Unemployment Compensation Support Services in accordance with the SOW.
FIRM
FIXED
CLIN 4001
Option Period Four
Period of Performance: Twelve (12) Months
SUPPLIES/SERVICES CLIN
TYPE
UNIT QUANTITY UNIT
PRICE
TOTAL
PRICE
Full Employment Verification and Unemployment Compensation Support Services in accordance with the SOW.
FIRM
FIXED
70RDAD20R00000007 Attachment 1 Page 3 of 34
DEPARTMENT OF HOMELAND SECURITY (DHS)
STATEMENT OF WORK (SOW)
Employment Verification (EV) and Unemployment Compensation (UC) Administration for Federal Employees
1 General
The United States Department of Homeland Security (DHS) intends to award an enterprise-wide contract to procure full-service Employment Verification (EV) and Unemployment Compensation (UC) Administration, including, but not limited to, records management, claims review, defense, mitigation, and processing at a state by state level for DHS and its Components. The DHS federal workforce is approximately 185,000 employees. The DHS includes the following Components:
• Department of Homeland Security Headquarters (DHS HQ)
• U.S. Citizenship and Immigration Services (USCIS)
• U.S. Customs and Border Protection (CBP)
• Cybersecurity and Infrastructure Security Agency (CISA)
• Federal Emergency Management Agency (FEMA)
• Federal Law Enforcement Training Center (FLETC)
• Immigration and Customs Enforcement (ICE)
• Transportation Security Administration (TSA)
• United States Coast Guard (USCG)
• United States Secret Service (USSS)
1.1 Background
Due to the large number of current and former employees, DHS outsources Employment Verification (EV) to streamline services and ensure effective and efficient processing. Mortgage companies, consumer finance companies, auto lenders, credit card issuers, prospective employers, and government social services are among those who may seek verification of current and former employment.
Since 1955, Government civilian employees have had unemployment insurance protection under US Code Title 5, Chapter 85. The Omnibus Reconciliation Act of 1980 (P.L. 96-499, December 5, 1980) amended the Unemployment Compensation (UC) for Federal Employees (UCFE) law by establishing the requirement for each Government Agency to contribute to State unemployment benefits for former Government employees, effective January 1, 1981. 20 CFR, Part 609 sets forth the Secretary of the Department of Labor (DOL) regulations to implement the UCFE program.
State UC laws and policies are not uniform and vary significantly with regards to eligibility requirements, payment amounts, and period of eligibility. This makes it difficult for Government agency personnel who are not familiar with detailed State requirements to track unemployment benefit payments, ensure payments have been properly applied; and verify, review, and appeal claims within prescribed time limits.
Therefore, a Contractor is required to support administrative functions of Government agency Civilian Personnel Offices (CPO) and Human Resource Offices (HRO) UC requirements.
70RDAD20R00000007 Attachment 1 Page 4 of 34
1.2 Scope
A Contractor will be recquired to fulfill the Components’ responsibility for responding to EV requests and UC management. The Contractor shall perform all administrative functions in managing UC claims and have a mastery of UC statutes and regulations in all fifty states, US territories and protectorates, and the District of Columbia. However, Government officials will retain responsibility for reviewing all claims that the Contractor deems protestable and determine which claims will be challenged.
In FY21, DHS expects about 185,000 civilian federal employees. In FY19, DHS, across all Components, had 6,049 unemployment compensation cases. Please reference Attachment A for DHS-wide Historical Data. The Contractor shall provide the following services:
• Employment History Storage and Maintenance
• Employment Verification
• Social Services Verification
• UC Claims Processing
• UC Hearing and Appeals Administration
• UC State Detail Processing
• UC Reconciliation
• UC Training
• Management Reports and Reviews
1.3 Objective
The objective of this acquisition is to:
• Make available to DHS and its Components the most effective and efficient process for responding to EV requests
• Make available to DHS and its Components the most effective and efficient process for handling UC claims
• Provide department-wide metrics on UC claims
• Improve overall management of the DHS UC claims process
1.4 Compliance Documents
• The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681, as amended
• State-specific, including Puerto Rico, District of Columbia, and US Territories and protectorates, Unemployment Compensation claims guidelines, timelines, and requirements
• DHS Instruction Manual 047-01-007, Revision #03, Handbook for Safeguarding Sensitive
Personally Identifiable Information (PII), as amended
• DHS Sensitive Systems Policy Directive 4300A, including handbook and attachments
• National Institute of Standards and Technology (NIST) 800 Series
• NIST Special Publication 800-53 Security and Privacy Controls for Federal Information
Systems and Organizations
• NIST Special Publication 800-88 Guidelines for Media Sanitization
70RDAD20R00000007 Attachment 1 Page 5 of 34
2 Tasks
2.1 Task 1- Authority to Operate (ATO)
The Contractor shall develop security compliance documentation and perform engineering activities to ensure the solution is available for the DHS security assessment. The Contractor shall ensure the solution is ready to achieve a DHS-issued Authority to Operate (ATO) in accordance with:
• DHS 4300A Sensitive Systems Handbook
• NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations
The Contractor Information System Security Officer (ISSO) shall coordinate all security activities with the Federal ISSO and/or System Owner. The Risk Management Division Information System Security Manager (ISSM) will provide guidance to the Federal ISSO for management with the Contractor ISSO where needed.
All security compliance documents will be reviewed and approved by the DHS Chief Information Security Officer (CISO) and accepted by the DHS Contracting Officer (CO), or CO designee, upon creation and after any subsequent changes, before they go into effect.
2.2 Task 2- Full Employment Verification and Unemployment Compensation Support Services
2.2.1 Sub-task 1- Employment History Storage and Maintenance Services
The Contractor shall provide the following in support of the Employment History Storage and Maintenance Services:
• The Contractor shall maintain a secure electronic interface, database, and system for receipt, input, and confirmation of the payroll and separation data transmitted from the USDA National Finance Center (NFC), the DHS shared service payroll provider. Attachment B and C outline the file structure.
• The Contractor ISSO shall maintain, and update as required, all security documentation and comply with ongoing security activities in accordance with DHS 4300A Sensitive Systems Handbook and NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations; the Contractor ISSO shall manage any remediation plan of actions and milestones (POA&M) resulting from the ATO assessment; the Contractor ISSO shall comply with any required ATO renewal or ongoing assessment requirements.
• The Contractor shall provide a mechanism to notify the DHS Components when supporting separation documentation is required. The Contractor shall accept separation data directly from DHS Components in multiple formats. The separation data provided by DHS Components augments the payroll data received from NFC.
• The Contractor shall provide for receipt, input, and storage of expanded comments/remarks from Components when additional separation information is available.
• The Contractor shall securely maintain all payroll and separation data that may be submitted by various payroll and personnel systems in multiple formats.
70RDAD20R00000007 Attachment 1 Page 6 of 34
• The Contractor shall provide for receipt and input of the payroll and separation data in the format submitted by the Components. This includes the incorporation of the required Government location identifiers – Agency Identification Code (AIC) – to at least the 5th level into the contractor’s system. NFC data may be transmitted to the 8th level.
• Level 1- Agency Code (aka Department, e.g. DHS)
• Level 2- Bureau Code (aka Component, e.g. TSA)
• Level 3- Office (e.g. OCHCO)
• Level 4- Division
• Level 5- Branch
• The Contractor shall create and/or modify and maintain a database that masks and/or truncates social security numbers (SSN) unless essential to personnel duties. The Contractor shall establish role-based permissions to limit access to SSN.
• The Contractor shall provide a feature to attach documents to each individual case file as designated by AIC identifier.
• The Contractor shall provide a secure data storage feature that can receive up to two years of historical payroll and separation data and storage; and maintenance of all historical data collected.
DHS will provide at least two years of historical payroll and separation data at contract award. DHS or Components will provide pay schedules to the Contractor at the beginning of each fiscal year and as required for any mid-year modifications to their pay schedules. DHS will provide payroll and separation information to the Contractor on a bi-weekly basis concurrent with scheduled payroll.
2.2.2 Sub-task 2- Employment Verification (EV) Services
The Contractor shall provide the following in support of EV Services:
• The Contractor shall respond to requests for employment and wage information on any individuals employed, presently or formerly, by DHS or its Components that may be generated by mortgage, lending, or credit institutions, verifiers of employment, and social/ family service government agencies via an online portal.
• The Contractor shall ensure the most up-to-date employment and wage information available is leveraged in the EV process.
• The Contractor shall provide a mechanism to obtain a verifier’s reason or permissible purpose for requesting the information, as defined by the Fair Credit Reporting Act (FCRA). The Contractor shall ensure the employee’s consent before providing income or salary information.
• The Contractor shall provide a mechanism for employees to block the release of salary information.
• The Contractor shall provide a 1-page electronic promotional brochure to advise DHS employees how to access EV services within 10 business days of award.
70RDAD20R00000007 Attachment 1 Page 7 of 34
• The Contractor shall provide 100,000 print wallet cards to advise DHS employees how to access EV services. The Contractor shall submit an electronic proof for COR approval before printing within 10 business days of award. The Contractor shall deliver printed wallet cards within 30 business days of COR approval.
2.2.2.1 Basic employment verification
The Contractor shall provide the following information to lenders, verifiers, and agencies in support of basic employment verification inquiries:
• Employee Name
• Employee SSN
• Employer Name
• Initial Hire Date
• Most recent Hire Date (if applicable)
• Current employment status (active or inactive)
• Total employment time with employer in years or months
• Position/Title
2.2.2.2 Basic employment verification with salary information
The Contractor shall provide the following information to lenders, verifiers, and agencies in support of basic employment verification with salary information inquiries:
• All information in Section 2.2.1
• Current rate-of-pay and most recent period earnings
2.2.2.3 Basic employment verification, salary information, and salary history
The Contractor shall provide the following information to lenders, verifiers, and agencies in support of basic employment verification, salary information, and salary history inquiries:
• All information in Sections 2.2.1 and 2.2.2
• Year to date gross wages
• Two previous years’ total gross wages (when available)
2.2.2.4 Social services verification
The Contractor shall be able to provide verification for issuance of benefits related to social programs (e.g., Supplemental Nutrition Assistance Program [SNAP], Temporary Assistance for Needy Families [TANF], WIC, ACA, etc.).
2.2.3 Sub-task 3- Unemployment Compensation (UC) Administration Services
2.2.3.1 Claims Processing
The Contractor shall provide the following in support of UC Administration Claims Processing:
70RDAD20R00000007 Attachment 1 Page 8 of 34
• The Contractor will be designated as the addressee of record for the receipt of Request for Wage and Separation Information – UCFE Form ES·931 and other related inquiries as appropriate from the 50 states, Puerto Rico, District of Columbia, and US Territories and protectorates. The Contractor shall return ES-931 forms to the state UC office in accordance with state-specific deadlines.
• The Contractor shall determine whether the claimant is a former employee of a respective
DHS Component. If so, the Contractor shall determine which sub-unit within the Component the claimant was employed. Upon receipt of a claim or appeal, the Contractor shall contact the appropriate Component POC within 24 hours to request and coordinate separation documentation.
• The Contractor shall review employee separation documents to ensure that needed employment information is provided. When processing a claim, the Contractor shall ensure that the employee’s Form SF-50 provides a decision or resignation cause, and (if it includes a decision), attach:
• A copy of all witnesses' statements supporting the decision
• Guidance on conduct or performance
• Any other documents that supported the action
• The Contractor shall review claimants' circumstances of separation, availability for work, and allocation or severance or other special payments.
• The Contractor shall complete claims forms and return them to the State agency within four days but no later than the last calendar day authorized by the state date of request.
• The Contractor shall interface with the Federal Interstate Connection (ICON) System to electronically receive inquiries from the various state unemployment offices and respond electronically. The Contractor must have the hardware / software necessary and agrees to work with the ICON administrator regarding procedural matters.
• The Contractor shall establish and maintain a methodology for electronic tracking of all claims-related documentation and correspondence to ensure that timely responses are made to all claims or appeals. The Contractor shall record and be able to report on type of documentation received, date of receipt, date of request for information to agency, and date of agency response.
• The Contractor shall notify the appropriate Component POCs for the case in writing (includes email) within five days of the State’s Unemployment Compensation Case determination.
2.2.3.2 Hearing and Appeals Administration
The Contractor shall provide the following in support of UC Administration Hearing and Appeals Administration:
• The Contractor shall notify the appropriate Component POCs for the case in writing within five days of the State’s Unemployment Compensation Case determination. The Component officials will determine whether to appeal or accept State’s Unemployment Compensation Case determinations within 48 hours of receipt of the determination.
70RDAD20R00000007 Attachment 1 Page 9 of 34
• The Contractor shall prepare the Component to attend all hearings to provide responses to procedural questions and issues.
• The Contractor shall ensure that all claim and appeal documentation is complete, accurate, timely, and complies with the specific states' guidelines and laws when filing an appeals case.
• The Contractor shall provide the necessary review, witness preparation, and consultation throughout the appeal process as set-forth by the respective State laws.
2.2.3.3 State Detail Processing
The Contractor shall provide the following in support of UC Administration State Detail Processing:
• The Contractor shall be the addressee of record for receipt of the paid data from the 50 states, Puerto Rico, District of Columbia, and US Territories and protectorates.
• The Contractor shall monitor receipt and review the benefit paid data to determine whether any claimant is a former employee of a respective Component and accuracy of the charges.
Any discrepancies which cannot be solved informally must be reported to the appropriate Component POC so that an appeal can be filed with the State/ Territory unemployment office. The Contractor shall report to the Component POC when and how the discrepancies have been adjudicated by the State/Territory.
• The Contractor shall interface with the ICON System to electronically receive and, if necessary, dispute quarterly benefit statements from the various state unemployment offices and respond electronically.
• When an appeal is filed, the Contractor will follow-up with the State to ensure that credits are received and properly accounted. See Section 2.3.2.
2.2.3.4 Reconciliation
The Contractor shall provide the following in support of UC Administration Reconciliation:
• The Contractor shall reconcile State benefit paid data with the amounts DOL bills to participating Components within 30 days of receipt of data. This includes follow up with the State unemployment offices for any missing benefit paid data or benefit paid in error. The Contractor shall notify the Component POC when there is missing benefit paid data and when and how the issue will be resolved. The Contractor shall coordinate with state agency POCs to encourage timely reporting.
• The Contractor shall conduct audits of all UC payments to claimants to evaluate the validity of payments and determine the possibility of fraudulent activity.
• The Contractor shall deliver a comprehensive quarterly reconciliation for each Component at the employee level. The monthly reconciliation report shall include employee name, SSN, Component, type of documentation received, date of receipt, date of request for information to agency, date of agency response, claim effective date, claim paid date, claim amount, and any other relevant data elements.
70RDAD20R00000007 Attachment 1 Page 10 of 34
2.2.3.5 Training
The Contractor shall provide the following in support of UC Administration Training:
• The Contractor shall provide quarterly training to UC processors and managers on procedures for day-to-day management. The Contractor shall conduct workshops geared to the responsibilities of Government personnel and uniqueness of each DHS Component in the areas of, but not limited to:
• Procedures for day-to-day UC management
• Hearings and appeals training
• Cost of unemployment claims
• Hiring practices
• Part-time employment
• Use of probationary periods
• Separation terminology
• Documentation
• UC law
• Employee eligibility
• Training may be virtual instructor led or online recordings.
2.2.4 Sub-task 4- Management Reporting Services
The Contractor shall provide the following in support of Management Reporting Services:
• The Contractor shall provide EV and UC Management Reports quarterly at Level 2- Bureau Code (aka Component, e.g. TSA), with cumulative quarterly and annual data. The Management Reports shall include both summary and detailed information for:
• EV inquiries
• UC claims, hearings, and appeals
• Disposition of claims determinations and appeals
• Charges and credits
• Notification of Benefit Integrity Violations
• Reconciliation and audit findings
• Using the AICs, the Contractor shall present the required information by Component. The
Contractor shall summarize information at Level 1- Agency Code (aka Department, e.g.
DHS). The Contractor shall also have the capability to drill down quarterly metrics to Level 5- Branch.
• The Contractor shall participate in quarterly Program Management Review (PMR) meetings to provide Component status on current activities, review performance metrics, discuss risks and issues, submit problems, and make recommendations. The quarterly PMR meetings will be scheduled by the Contracting Officer’s Representative (COR) or government Program Manager (PM) and occur via conference call or video-teleconference.
70RDAD20R00000007 Attachment 1 Page 11 of 34
• The Contractor shall provide detailed meeting materials 72-hours in advance of each PMR.
3 Contractor Personnel
3.1 Qualified Personnel
The Contractor shall provide qualified personnel to perform all requirements specified in this SOW.
3.2 Continuity of Support
The Contractor shall ensure that the contractually required level of support for this requirement is maintained at all times. The Contractor shall ensure that all contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor shall provide e-mail notification to the COR and PM prior to employee absence. Otherwise, the Contractor shall provide a fully qualified replacement.
3.2.1 Program Manager (Non-Billable)
The Contractor shall provide a Program Manager who shall be responsible for all Contractor work performed under this contract. The Program Manager shall be a single point of contact for the Contracting Officer, COR, and PM. It is anticipated that the Program Manager shall be one of the senior level employees provided by the Contractor for this work effort. The name of the Program Manager, and any alternate(s) who shall act for the Contractor in the absence of the Program Manager, shall be provided to the Government as part of the Post Award Conference. During any absence of the Program Manager, only one alternate shall have full authority to act for the Contractor on all matters relating to work performed under this contract. The Program Manager and all designated alternates shall be able to read, write, speak and understand English.
The Program Manager shall be available to the COR and PM via telephone between the hours of 8:00AM and 5:00PM EST, Monday through Friday.
The Program Manager is not billable nor required to be full-time dedicated to this contract.
3.2.2 Information System Security Officer (ISSO) (Non-Billable)
The Contractor shall provide an Information Systems Security Officer (ISSO) who shall be responsible for all Contractor systems security work performed under this SOW. The ISSO shall be a single point of contact for systems security related issues. The name of the ISSO, and the name(s) of any alternate(s) who shall act for the Contractor in the absence of the ISSO, shall be provided to the Government as part of the Contractor's proposal. During any absence of the ISSO, only one alternate shall have full authority to act for the Contractor on all matters relating to systems security work performed under this contract.
The ISSO and all designated alternates shall be able to read, write, speak and understand English.
The ISSO shall be available to the COR and PM via telephone between the hours of 8:00AM and 5:00PM EST, Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 4 business hours of notification.
The ISSO is not billable nor required to be full-time dedicated to this contract.
70RDAD20R00000007 Attachment 1 Page 12 of 34
3.3 Employee Identification
Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.
Contractor employees working on-site at Government facilities shall wear a Government issued identification badge. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent (in meetings, when answering Government telephones, in e-mail messages, etc.)
and display the Government issued badge in plain view above the waist at all times.
3.4 Employee Conduct
Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Program Manager shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.
3.5 Removing Employees for Misconduct or Security Reasons
The Government may, at the discretion of the Contracting Officer and/or COR, direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons. Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.
4 Other Applicable Conditions
4.1 Personnel Security
4.1.1 Post-Award Instructions Regarding Security Requirements for Contract/ Orders
The procedures outlined below shall be followed for the DHS Security Office to process background investigations and suitability determinations, as required, in a timely and efficient manner.
Carefully read the security clauses in the Order. Compliance with the security clauses in the contract is not optional.
Contract employees (to include applicants, temporaries, part-time and replacement employees) under the contract, requiring access to sensitive information, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. All background investigation s will be processed through the DHS Security Office.
Prospective Contractor employees shall submit the following completed forms to the DHS Security Office. The Standard Form 85P will be completed electronically, through the Office of Personnel Management's e-QIP SYSTEM. The completed forms must be given to the DHS
70RDAD20R00000007 Attachment 1 Page 13 of 34
Security Office no less than thirty (30) days before the start date of the contract or thirty (30) days prior to entry on duty of any employees, whether a replacement, addition, subcontractor employee, or vendor:
a. Standard Form 85P, "Questionnaire for Public Trust Positions"
b. FD Form 258, "Fingerprint Card" (2 copies)
c. DHS Form 11000-6 "Conditional Access To Sensitive But Unclassified Information Non-Disclosure Agreement"
d. DHS Form 11000-9, "Disclosure and Authorization Pertaining to Consumer Report is Pursuant to the Fair Credit Reporting Act"
Only complete packages will be accepted by the DHS Security Office. Specific instructions on submission of packages will be provided upon award of the contract.
DHS may, as it deems appropriate, authorize and grant a favorable entry on duty (EOD) decision based on preliminary suitability checks. The favorable EOD decision would allow the employees to commence work temporarily prior to the completion of the full investigation.
The granting of a favorable EOD decision shall not be considered as assurance that a full employment suitability authorization will follow. A favorable EOD decision or a full employment suitability determination shall in no way prevent, preclude, or bar DHS from withdrawing or terminating access to government facilities or information, at any time during the term of the contract. No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable EOD decision or suitability determination by the Security Office.
Limited access to Government buildings is allowable prior to the EOD decision if the Contractor is escorted by a Government employee. This limited access is to allow Contractors to attend briefings and non-recurring meetings in order to begin transition work.
The DHS Security Office shall be notified of all terminations /resignations within five (5) days of occurrence. The Contractor shall return to the Contracting Officer Technical Representative (COR) all DHS issued identification cards and building passes that have either expired or have been collected from terminated employees. If an identification card or building pass is not available to be returned, a report shall be submitted to the COR, referencing the pass or card number, name of individual to who it was issued and the last known location and disposition of the pass or card.
When sensitive Government information is processed on Department telecommunications and automated information systems, the Contractor shall provide for the administrative control of sensitive data being processed. Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level. Contractors who fail to comply with Depa1iment security policy are subject to having their access to Department IT systems and facilities terminated, whether or not the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g., Privacy Act).
70RDAD20R00000007 Attachment 1 Page 14 of 34
Failure to follow these instructions may delay the completion of suitability determinations and background checks. Note that any delays in this process that are not caused by the government do not relieve a contractor from performing under the terms of the contract.
4.1.2 Requests for Exception to U.S. Citizenship Requirement
Special procedures apply for exception to the requirement that persons accessing DHS systems be U.S.
citizens. Under normal circumstances, only U.S. citizens are allowed access to DHS systems and networks; but there is a need at times to grant access to foreign nationals. Access for foreign nationals is normally a long-term commitment, and exceptions to citizenship requirements are treated differently from security policy waivers. Exceptions to the U.S. citizenship requirement should be requested by completing a Foreign National Visitor Access Request, DHS Form 11052-1, which is available online or through the DHS Office of the Chief Security Officer (OCSO). Components who have access may file their request via the Foreign National Vetting Management System (FNVMS), a part of the DHS OCSO Integrated Security Management System’s (ISMS). For further information regarding the citizenship exception process, contact the DHS OCSO.
4.2 Security Clauses
Contractor access to unclassified, but Security Sensitive Information may be required under this SOW.
Contractor employees shall safeguard this information against unauthorized disclosure or dissemination.
HSAR Class Deviation 15-01: SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the
70RDAD20R00000007 Attachment 1 Page 15 of 34 privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
70RDAD20R00000007 Attachment 1 Page 16 of 34
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources.
The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://csrc.nist.gov/publications/PubsSPs.html
70RDAD20R00000007 Attachment 1 Page 17 of 34 names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s).
During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system.
The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA.
The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the
70RDAD20R00000007 Attachment 1 Page 18 of 34
DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three
(3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .