70RDAD21R00000001 Amendment 0001 to RFP.pdf

PDF 1 MB Posted

Attached to
Cybersecurity Compensation System Support Services Federal contract opportunity
Solicitation number
70RDAD21R00000001
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This is a request for proposal for cybersecurity compensation system support services. The Department of Homeland Security seeks a contractor to assist with designing and operating a Cybersecurity Compensation System, which will be part of a new Cybersecurity Talent Management System. The objective is to enable DHS to offer competitive compensation to recruit and retain cybersecurity talent while balancing internal and external equity. The contractor will provide support including ongoing assessments of the compensation system design, assisting with analysis of compensation data and surveys, and supporting ongoing operation of salary structures and incentives. The base period of performance is one year with four one-year option periods. The solicitation requests proposals due by March 22, 2021 and anticipates awarding a single time and materials contract.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity Compensation System Support Services, newest first.
File Type Posted
Question and Answers to Solicitation.xlsx XLSX spreadsheet
Pre Proposal Conference Recording.mp4 MP4 file
70RDAD21R00000001 Attachment 3 Non-Disclosure Agreement.pdf PDF
70RDAD21R00000001 Final Solicitation RFP.pdf PDF
70RDAD21R00000001 Attachment 2 Pricing Table.xlsx XLSX spreadsheet
70RDAD21R00000001 Attachment 1 Labor Categories and Qualifications.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

(x)

70RDAD21R00000001

x x

1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted ; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGEMENT TO BE RECEIVED AT

THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted , such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

x

Washington DC 20528-0115

DHS/OPO/DEPT.OPS

245 Murray Lane SW, #0115 Dept. Operations Acquisition Div.

Office of Procurement Operations U.S. Dept. of Homeland Security

Washington DC 20528 245 Murray Lane SW, Mailstop 0115

70RDAD

Dept. Operations Acquisition Div.

Office of Procurement Operations U.S. Dept. of Homeland Security

DEPT OPS ACQ DIV(70RDAD)

CTMS Compens03/19/20210001

13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

12. ACCOUNTING AND APPROPRIATION DATA (If required) is not extended.is extended, Items 8 and 15, and returning

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended , by one of the following methods: (a) By completing

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

FACILITY CODE CODE

10B. DATED (SEE ITEM 13)

10A. MODIFICATION OF CONTRACT/ORDER NO.

9B. DATED (SEE ITEM 11)

9A. AMENDMENT OF SOLICITATION NO.

CODE

8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)

7. ADMINISTERED BY (If other than Item 6)CODE 6. ISSUED BY

PAGE OF PAGES

4. REQUISITION/PURCHASE REQ. NO.3. EFFECTIVE DATE2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO. (If applicable)

1. CONTRACT ID CODE

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

03/16/2021

CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority) appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

E. IMPORTANT: Contractor is not, is required to sign this document and return __________________ copies to the issuing office.

ORDER NO. IN ITEM 10A.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

The purpose of this amendment is to provide responses to questions received from contractors regarding the solicitation.

All changes to the solicitation have been highlighted in yellow.

16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)15A. NAME AND TITLE OF SIGNER (Type or print)

15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 15B. CONTRACTOR/OFFEROR 16C. DATE SIGNED

(Signature of person authorized to sign) (Signature of Contracting Officer)

Phorsha R. Peel

STANDARD FORM 30 (REV. 10-83)

Prescribed by GSA

FAR (48 CFR) 53.243

NSN 7540-01-152-8070

Previous edition unusable

Except as provided herein, all terms and conditions of the document referenced in Item 9 A or 10A, as heretofore changed, remains unchanged and in full force and effect .

TEL: EMAIL: 202-447-5224 phorsha.peel@hq.dhs.gov

AMENDMENT 0001

FEDERAL ACQUISITION REGULATION (FAR) Subpart 12.6

COMBINED SYNOPSIS/SOLICITATION NOTICE

In accordance with (IAW) Federal Acquisition Regulation (FAR) subpart 12.603, Streamlined Solicitation for Commercial Items, Combined Synopsis/Solicitation Procedures, shall be utilized in support of the subject solicitation. As such the following synopsis information as required by FAR subpart 5.207 Preparation and transmittal of synopses is hereby provided to include detail required by aforementioned FAR subpart 12.603.

(1) Action Code: Not Applicable

(2) Date: March 19, 2021

(3) Year: 2021

(4) Contracting Office ZIP Code: 20528-0115

(5) Product or Service Code: R431

(6) Contracting Office Address: U.S. Dept. of Homeland Security Office of Procurement Operations 245 Murray Lane, SW, Mailstop 0115 Washington DC 20528-0115

(7) Subject: Department of Homeland Security (DHS), Cybersecurity Compensation System Support Services

(8) Proposed Solicitation Number: 70RDAD21R00000001

(9) Closing Response Date: Phase I Proposal – March 22, 2021

(10) Contact Point or Contracting Officer: Daniel Weingarten Email: Daniel.Weingarten@hq.dhs.gov

Phorsha Peel Email: Phorsha.Peel@hq.dhs.gov

(11) Contract Award and Solicitation Number: Solicitation Number: 70RDAD21R00000001 Award Number: TBD

(12) Line Item Number: A schedule of supplies and services is represented within the solicitation document reference Section B, to include solicitation Attachment 2, Pricing Schedule Template.

AMENDMENT 0001

mailto:Daniel.Weingarten@hq.dhs.gov mailto:Phorsha.Peel@hq.dhs.gov

(14) Contract Award Date: TBD

(15) Contractor: TBD

(16) Description: This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in FAR subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation is hereby issued as a part of this notice.

Solicitation 70RDAD21R00000001 is issued as a Request for Proposal (RFP) where provisions 52.212-1, , 52.212-3, 52.212-4, and 52.212-5 applies.

Award will be made on a best value/tradeoff basis as described in Section M of the RFP.

(17) Place of Contract Performance: Section F

(18) Set-aside Status: Full and Open

SECTION A: SOLICITATION/CONTRACT FORM

See solicitation Standard Form 1449

SECTION B – SUPPLIES OR SERVICE/PRICE OR COST

1 AWARD TYPE

The Government intends to award a Time and Materials type single award contract.

2 GENERAL DESCRIPTION

This Department of Homeland Security (DHS), Cybersecurity Compensation System Support Services acquisition is a single award contract. The objective of this contract is to assist DHS with the design and ongoing operation of a Cybersecurity Compensation System, which will be one key element of the Department’s new Cybersecurity Talent Management System (CTMS) (note: CTMS is a Federal civilian personnel system—not an information technology system.

Similarly, the Cybersecurity Compensation System is not an information technology system; it is a set of business rules, processes, and policies for administering compensation). The Strategic Cybersecurity Compensation System should enable DHS to offer sufficiently competitive compensation to recruit and retain required cybersecurity talent, while remaining responsive to changes in the cybersecurity labor/talent market and the cybersecurity work necessary to execute the DHS mission. The Cybersecurity Compensation System should balance internal and external equity, while integrating leading compensation methods, including those proven effective in cybersecurity-focused organizations and those reflecting a focus on skills/competencies/capabilities.

SECTION C: DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK

1 BACKGROUND

The DHS Office of the Chief Human Capital Officer (OCHCO) leads a cross-Component effort to implement a new cybersecurity-focused Federal civilian personnel system, the Cybersecurity Talent Management System (CTMS), as authorized by the Border Patrol Agent Pay Reform Act of 2014 (P.L. 113-277), which added a new section (codified at 6 U.S.C. § 658) to the Homeland Security Act of 2002. The Secretary’s authority allows for a variety of talent management changes, including alternative methods for describing jobs, conducting hiring, and compensating employees.

In designing CTMS, DHS has revisited some of the foundational theories and structures that underlie how the Federal Government has managed talent for a decade. In order to modernize the civil service for cybersecurity work, DHS has specifically revisited the following aspects of compensation: traditional Federal position classification, multi-field salary structures, tenure-based salary progression, and occupation-focused compensation flexibilities. In completing the design of CTMS and preparing for launch, DHS is pursuing new compensation practices to enhance the Department’s capacity to compete for top cybersecurity talent in a competitive market.

The objective of this contract is to assist DHS with the design and ongoing operation of a Cybersecurity Compensation System, which will be one key element of the Department’s new

CTMS (note: CTMS is a Federal civilian personnel system—not an information technology system. Similarly, the Cybersecurity Compensation System is not an information technology system; it is a set of business rules, processes, and policies for administering compensation). The Strategic Cybersecurity Compensation System should enable DHS to offer sufficiently competitive compensation to recruit and retain required cybersecurity talent, while remaining responsive to changes in the cybersecurity labor/talent market and the cybersecurity work necessary to execute the DHS mission. The Cybersecurity Compensation System should balance internal and external equity, while integrating leading compensation methods, including those proven effective in cybersecurity-focused organizations and those reflecting a focus on skills/competencies/capabilities.

2 SCOPE

Contractor support is needed for ongoing design and operation of the Cybersecurity Compensation System based on existing DHS work, including some completed with the support of a prior contractor. Existing work includes proposed designs for: a national broadband salary structure, including geographic differentials/supplements, and a streamlined menu of recruitment and retention incentives, including cash bonuses, time-off, and student loan repayments. Support for the Cybersecurity Compensation System will include: Design, Analysis, Operation, and Surge.

The contractor shall perform the task identified as “MANDATORY” on a continual basis upon award. If the need arises, the contractor shall perform the tasks identified as “OPTIONAL.”. If the need arises, the contractor shall perform Task Four – Surge, which is to enable DHS to increase the number of support staff and/or adjust the level of expertise provided across other tasks to address unexpected circumstances.

3 SPECIFIC REQUIREMENT/TASKS

3.1 TASK ONE: Design (MANDATORY):

1. Review and remain knowledgeable of the latest versions of foundational documentation related to CTMS and the Cybersecurity Compensation System, including: CTMS regulations, Government-wide compensation regulations that apply under CTMS, CTMS policies, and CTMS standard operating procedures (SOPs).

2. Produce ongoing assessments of the design and current state of the Cybersecurity Compensation System, including information about cybersecurity compensation best practices and options for enhancing System operation and effectiveness. Each assessment should be scoped with DHS to clarify format (e.g., issue paper, draft policy language, executive summary, slide deck, chart/graph, action plan); to ensure appropriate specialized expertise is available to assist (in some cases, there may be a need for multiple contractor experts with specific specializations/professional experiences to provide input); and to define focus areas to be comprehensively covered. Such focus areas may include:

a. Work/job value hierarchy (or architecture of work);

b. National salary structure(s), including geographic differentials, informed by market analysis (note: structures(s) cover all career levels and multiple cybersecurity specializations, including those associated with increasingly deep technical expertise in specific competencies and increasingly deep cybersecurity management/leadership expertise);

c. Objective, competency-focused salary setting processes using cybersecurity technical and professional/leadership competencies as well as other compensable factors;

d. Processes for managing salary progression based on performance/impact on the DHS cybersecurity mission, including through competency enhancement;

e. Cash bonuses and other recruitment and retention incentives provided based on eligibility criteria and amount/frequency limitations;

f. Relationship to market of specific aspects of the Cybersecurity Compensation System based on specific sources of data, such as particular compensation surveys; and

g. Composition and strength of total reward offering, including benefits, at all career and expertise levels, from the entry-level through the national expert or executive level.

3.2 TASK TWO. Analysis (OPTIONAL):

1. Assist with identifying, obtaining, and using a compensation data analysis platform(s)/solution(s) to compile, maintain, and report compensation data, including that obtained from or prepared for compensation surveys. If necessary, highlight potential costs, licenses, or subscriptions for review and decision by DHS, including contractor purchase through other direct costs. Effort could include identifying and using existing contactor platform(s)/solution(s) as best approach to complete work.

2. Assist with identifying, obtaining, and analyzing relevant compensation survey data. If necessary, highlight potential costs, licenses, or subscriptions for review and decision by DHS, including contractor purchase through other direct costs. Effort could include identifying and using existing contactor data sources/data gathering methods as best approach to complete work.

3. Prepare DHS compensation data to enable participation in compensation surveys. Such assistance may include - facilitating job matching, compiling and sanitizing data, and monitoring deadlines and associated project schedules.

4. At least annually, produce a comprehensive analysis of the state of the cybersecurity labor/talent market to include - trend summaries; straightforward comparisons of current CTMS employee compensation to compensation in the market; and issues to be addressed by potential Cybersecurity Compensation System design adjustments.

5. Assist in refining current compensation cost models, including estimation factors and projections in future years, to increase accuracy and utility for DHS in estimating and planning for employee compensation under CTMS.

3.3 TASK THREE. Operation (OPTIONAL):

1. Assist with maintenance and planning associated with salary structures and recruitment and retention incentives, including cash bonuses. Specific assistance will include;

a. Supporting annual salary planning, including through analysis of projected budget for salary increases based on merit (defined in terms of performance/mission impact, including competency enhancement, under CTMS), development of merit increase matrices, management of salary progression, and interaction with review boards and calibration panels;

b. Supporting annual cash bonus planning, including through analysis of projected budget for recognition awards (based primarily on performance/mission impact, including competency enhancement, under CTMS), development of templates and tools to assist with the allocation and calculation of awards to ensure distribution based on differentiated performance/mission impact, and interaction with review boards and calibration panels;

c. Developing and maintaining compensation training and communication materials, including, guidance, tools, and templates for managers and other leadership stakeholders as well as employees to understand annual and ad hoc compensation processes and provide required input; and

d. Preparing reports on employees and groups of employees assessing competitiveness of compensation against the market and presenting data related to Cybersecurity Compensation System performance metrics defined with DHS.

2. Assist with ongoing operation of salary structures and recruitment and retention incentives, including cash bonuses. Specific assistance will include:

a. Developing and maintaining guidance, including templates, decision trees, matrices, and calculators, to support compensation decisions affecting individuals or groups of individuals;

b. Assisting with and recommending modifications to salary setting, salary adjustment, and retention and recruitment incentive request/approval processes;

c. Preparing compensation packages for review/approval;

d. Developing and maintaining compensation communication and negotiation procedures, including guidance for explaining compensation package strength to applicants, employees, hiring officials, managers, and other leadership stakeholders;

and

e. Preparing reports on employees and groups of employees assessing current compensation in relationship to any applicable laws, regulations, policies, and SOPs, including compensation limitations or caps under the Cybersecurity Compensation System.

3.4 TASK FOUR. Surge Support (Optional):

If the need arises, output associated with other Tasks would be expanded under Task Four to address unexpected increases in workload volume or complexity. The Tasks would be performed as identified above with an expectation of either more detailed or complex work products, an increase in the volume or rapidity of work product production, or both. If exercised, the support under the Task Four Optional CLIN will be expanded incrementally—and as needed, up to the ceiling level—by bringing on additional contractor staff to perform the work.”

3.5 Other Direct Costs

Other direct costs will be set as Not to Exceed $130,000 for the base year, $140,000 per each option year to include compensation surveys, compensation management software (e.g., PayFactors, Payscale, MarketPay), and Compensation Allocation tools (e.g., Curo).

4 CONTRACTOR PERSONNEL

4.1 Qualified Personnel

The Contractor shall provide qualified personnel to perform all requirements specified in this RFP. Please refer to Attachment 1 - Labor Categories and Qualifications.

4.2 Continuity of Support

The Contractor shall ensure that the contractually required level of support for this requirement is maintained at all times. The Contractor shall ensure that all contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor shall provide e-mail notification to the Contracting Officer’s Representative (COR) prior to employee absence. Otherwise, the Contractor shall provide a fully qualified replacement.

4.3 Key Personnel

Before replacing any individual designated as Key by the Government, the Contractor shall notify the Contracting Officer no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes shall possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor shall not replace Key Contractor personnel without approval from the Contracting Officer. The following Contractor personnel are designated as Key for this requirement:

1. Project Manager

2. Lead Compensation - Subject Matter Expert

3. Lead Compensation Consultant

4.4 Project Manager

The Contractor shall identify a Project Manager (PM) to provide centralized administration and management. The PM is required to correspond and meet with the DHS OCHCO Program Manager and COR as necessary. The PM is responsible for hands-on project management and coordination of day-to-day support across tasks. The PM shall also be available to participate in ad hoc meetings throughout the term of the contract.

The Contractor shall provide a Project Manager who shall be responsible for all Contractor work performed under this SOW. The PM shall be a single point of contact for the Contracting Officer and the COR. The name of the PM shall be provided to the Government as part of the Contractor's proposal. The PM is further designated as Key by the Government. During any absence of the PM, only one alternate shall have full authority to act for the Contractor on all matters relating to work performed under this contract. Any alternate(s) who shall act for the Contractor in the absence of the PM shall be as qualified as the PM. The PM and all designated alternates shall be able to read, write, speak and understand English. Additionally, the Contractor shall not replace the PM without prior approval from the Contracting Officer.

4.5 Lead Compensation Subject Matter Expert

The Contractor shall identify a Lead Compensation Subject Matter Expert (SME) to provide centralized strategic vision and technical leadership across all Tasks. The Lead Compensation SME shall provide significant technical experience, including thought leadership. The Lead Compensation SME must have experience designing compensation programs for IT/cybersecurity professionals as well as a strong understanding of the current leading compensation practices for cybersecurity professionals. The name of the Lead Compensation SME shall be provided to the Government as part of the Contractor's proposal.

4.6 Lead Compensation Consultant

The Contractor shall identify a Lead Compensation Consultant to provide day-to-day compensation analysis and input across Tasks, as well as collaborating with DHS to address to ad hoc requests and challenges. The Lead Compensation Consultant shall have in-depth client experience, preferably with organizations focused on IT/cybersecurity. The Lead Compensation Consultant shall possess strong technical compensation skills and project management skills.

Additionally, the Lead Compensation Consultant should be an expert in market-based pay/compensation and have a strong understanding of cybersecurity roles and the labor market for cybersecurity professionals. The name of the Lead Compensation Consultant shall be provided to the Government as part of the Contractor's proposal.

4.7 Replacement of Key Personnel

Before replacing any individual designated as Key by the Government, the Contractor must notify the Contracting Officer no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes must possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor must not replace Key Contractor personnel without approval by the Contracting Officer.

4.8 Key Personnel Availability

All Key Personnel shall be available to the COR via telephone between the hours of 8:00 a.m.

and 5:00 p.m. ET, Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 2 hours of notification.

The Project Manager shall be available to engage in on-site ad hoc meetings as required with a 24-hour notification within the Washington D.C. Metro area.

4.9 Employee Identification

Contractor Employees Visiting Government Facilities Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not apparent and display all identification and visitor badges in plain view above the waist at all times.

Contractor Employees Working On-Site at Government Facilities Contractor employees working on-site at Government facilities shall wear a Government issued identification badge. All Contractor employees shall identify themselves as Contractors when their status is not apparent (in meetings, when answering Government telephones, in e-mail messages, etc.) and display the Government issued badge in plain view above the waist at all times.

4.10 Employee Conduct

Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Project Manager shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.

4.11 Removing Employees for Misconduct or Security Reasons

The Government may, at its sole discretion (via the Contracting Officer), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons.

Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.

5 OTHER APPLICABLE CONDITIONS

5.1 General Report Requirements

The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows 7 and Microsoft Office 2010 Applications).

5.2 Protection of Information

Contractor access to information protected under the Privacy Act is required under this RFP.

Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation.

Review and certify understanding of provided DHS policies and guidelines governing the handling of sensitive information, including personally identifiable information (PII), ethical conduct, use and communication of DHS branded materials, and proper identification of relationship to DHS in applicant and stakeholder interactions.

5.3 Data Stored/Processed at Contractor Site

Unless otherwise directed by DHS, any storage of data must be contained within the resources allocated by the Contractor to support DHS and may not be shared with other commercial or government clients.

The Contractor remote access connection to DHS networks may be terminated for unauthorized use, at the sole discretion of DHS.

5.4 Sensitive But Unclassified (SBU) Data Privacy and Protection

The Contractor must satisfy requirements to work with and safeguard Sensitive Security Information (SSI), and Personally Identifiable Information (PII). All support personnel must understand and rigorously follow DHS and DHS requirements, policies, and procedures for safeguarding SSI and PII. Contractor personnel will be required to complete online training for SSI and Informational Security, which take one hour each, as well as DHS online Privacy training. Failure by the Contractor to comply with these requirements may result in termination of this agreement.

The Contractor shall be responsible for the security and prevention of data breaches of: i) all data that is generated by the contractor on behalf of the DHS, ii) DHS data transmitted by the contractor, and iii) DHS data otherwise stored or processed by the contractor regardless of who owns or controls the underlying systems while that data is under the contractor’s control.

The Contractor shall maintain data control according to the DHS security level of the data. Data separation shall include the use of discretionary access control methods, VPN encryption methods, data aggregation controls, data tagging, media marking, backup actions, and data disaster planning and recovery. Contractors handling PII must comply with DHS MD 3700.4, Handling Sensitive Personally Identifiable Information (current version).

Users of DHS IT assets shall adhere to all system security requirements to ensure the confidentiality, integrity, availability, and non-repudiation of information under their control. All users accessing DHS IT assets are expected to actively apply the practices specified in the DHS Information Technology Security Policy (ITSP) Handbook and applicable IT Security Technical Standards.

The Contractor shall comply with all data disposition requirements stated in the DHS IT Security Policy Handbook, applicable Technical Standards and DHS MD 3700.4, Handling Sensitive Personally Identifiable Information.

In the event of a breach or suspected breach, the Contractor shall immediately notify the Contracting Officer and Contracting Officer’s Representative to describe the incident, identity all information that has potentially been compromised due to the breach, and corrective action being taken to mitigate the breach. See HSAR Clause Safeguarding of Sensitive Information (Mar 2015) for notification timelines and additional requirements. Failure by the Contractor to comply with these requirements may result in termination for cause of this agreement in accordance with FAR 52.212-4(m).

5.5 Disposition of Government Resources

At the expiration of the Award, the contractor shall deliver to the government to the following:

a. All DHS information provided to or collected by the contractor along with detailed descriptor information (i.e. document catalogue, data dictionary, etc.)

b. IT resources provided to the contractor during the Award

c. Certification that all assets that contained or were used to process DHS information have been sanitized in accordance with the DHS MD 1400.3, DHS IT Security Policy Handbook and Technical Standards. Proof of sanitization shall be emailed to the COR

d. Master asset inventory list that reflects all assets, government furnished equipment (GFE) or non-GFE that were used to process DHS information.

5.6 Access to Unclassified Facilities, IT Resources, and Sensitive Information

The assurance of the security of unclassified facilities, Information Technology (IT) resources, and sensitive information during the acquisition process and contract performance are essential to the DHS mission. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive but Unclassified (For Official Use Only) Information https://www.dhs.gov/xlibrary/assets/foia/mgmt_directive_110421_safeguarding_sensitive_but_u nclassified_information.pdf, describes how contractors must handle sensitive but unclassified information. DHS MD 4300.1 Information Technology Systems Security and the DHS Sensitive Systems Handbook prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering contractors specifically for the award that require access to DHS facilities, IT resources or sensitive information. Contractor shall not use or redistribute any DHS information processed, stored, or transmitted by the contractor except as specified in the award.

5.7 Compliance with DHS IT Security Policy Terms and Conditions

All hardware, software, and services provided under this contract must be compliant with DHS 4300A DHS Sensitive System Policy and the DHS 4300A Sensitive Systems Handbook.

The IT solution shall meet all US Federal and DHS specific Systems and Security and Privacy requirements criteria.

5.9 PROTECTION OF INFORMATION NON-DISCLOSURE AGREEMENT

Contractor access to sensitive but unclassified information is required under this SOW. The Contractor shall ensure that all Contractor personnel having access to business or procurement sensitive information sign and submit an executed Attachment 3 – Contractor Non-Disclosure Agreement Form (DHS Form 11000-6) (3 Pages).

5.10 GOVERNMENT FURNISHED RESOURCES

The Government shall furnish the Contractor with the following for all onsite contractor personnel: enough workspace, computers, telephones, access to printers, access to photocopiers, and access to scanners.

The Contractor shall use Government furnished facilities, property, equipment and supplies only for the performance of work under this contract and shall be responsible for returning all Government furnished facilities, property, and equipment in good working condition, subject to normal wear and tear.

The Government will provide the Contractor with the available data necessary to complete the requirements of this award.

5.11 DISCLOSURE OF INFORMATION

The services required under the award constitute professional and management services, which are essential to the mission but not otherwise available within. The Government will neither supervise Contractor employees nor control the method by which the Contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual Contractor employees. It shall be the responsibility of the Contractor to manage their employees and to guard against any actions that have the nature of personal services or give the perception of personal services. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor’s further responsibility to notify the Contracting Officer immediately.

These services shall not be used to perform work of a policy/decision making or management nature. All decisions relative to programs supported by the Contractor will be the sole responsibility of the Government. Support services will not be ordered to circumvent personnel ceilings, pay limitations, or competitive employment procedures.

5.12 SECURITY

Contractor access to unclassified, but Security Sensitive Information may be required under this SOW. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination.

Requests for Exception to U.S. Citizenship Requirement

Special procedures apply for exception to the requirement that persons accessing DHS systems be U.S. citizens. Under normal circumstances, only U.S. citizens are allowed access to DHS systems and networks; but there is a need at times to grant access to foreign nationals. Access for foreign nationals is normally a long-term commitment, and exceptions to citizenship requirements are treated differently from security policy waivers. Exceptions to the U.S.

citizenship requirement should be requested by completing a Foreign National Visitor Access Request, DHS Form 11052-1, which is available online or through the DHS Office of the Chief Security Officer (OCSO). Components who have access may file their request via the Foreign National Vetting Management System (FNVMS), a part of the DHS OCSO Integrated Security Management System’s (ISMS). For further information regarding the citizenship exception process, contact the DHS OCSO This Policy Directive and the DHS 4300A Sensitive Systems Handbook apply to all DHS employees, contractors, detailees, others working on behalf of DHS, and users of DHS information systems that collect, generate, process, store, display, transmit, or receive DHS information unless an approved waiver has been granted. This includes prototypes, telecommunications systems, and all systems in all phases of the Systems Engineering Life Cycle (SELC).

POST-AWARD INSTRUCTIONS REGARDING SECURITY REQUIREMENTS FOR

CONTRACTS/ORDERS

The procedures outlined below shall be followed for the DHS Security Office to process background investigations and suitability determinations, as required, in a timely and efficient manner.

• Carefully read the security clauses in the Order. Compliance with the security clauses in the contract is not optional.

• Contract employees (to include applicants, temporaries, part-time and replacement employees) under the contract, requiring access to sensitive information, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. All background investigation s will be processed through the DHS Security Office. Prospective Contractor employees shall submit the following completed forms to the DHS Security Office. The Standard Form 85P will be completed electronically, through the Office of Personnel Management's e- QIP SYSTEM. The completed forms must be given to the DHS Security Office no less than thirty (30) days before the start date of the contract or thirty (30) days prior to entry on duty of any employees, whether a replacement , addition, subcontractor employee, or vendor:

A. Standard Form 85P, "Questionnaire for Public Trust Positions"

B. Standard Form 85P Certification

C. Standard Form 85P Authorization for Release of Information

D. FD Form 258, "Fingerprint Card" (2 copies)

E. DHS Form 11000-6 "Conditional Access To Sensitive But

Unclassified Information Non-Disclosure Agreement"

F. DHS Form 11000-9, "Disclosure and Authorization Pertaining to

Consumer Rep is Pursuant to the Fair Credit Reporting Act"

Only complete packages will be accepted by the DHS Security Office. Specific instructions on submission of packages will be provided upon award of the contract.

DHS may, as it deems appropriate, authorize and grant a favorable entry on duty (EOD) decision based on preliminary suitability checks. The favorable EOD decision would allow the employees to commence work temporarily prior to the completion of the full investigation. The granting of a favorable EOD decision shall not be considered as assurance that a full employment suitability authorization will follow. A favorable EOD decision or a full employment suitability determination shall in no way prevent, preclude, or bar DHS from withdrawing or terminating access to government facilities or information, at any time during the term of the contract. No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable EOD decision or suitability determination by the Security Office. No employee of the

Contractor shall be allowed to access sensitive information or systems without a favorable EOD decision or suitability determination.

Limited access to Government buildings is allowable prior to the EOD decision if the

Contractor is escorted by a Government employee. This limited access is to allow

Contractors to attend briefings and non-recurring meetings in order to begin transition work.

The DHS Security Office shall be notified of all terminations /resignations within five (5) days of occurrence. The Contractor shall return to the Contracting Officer Technical

Representative (COR) all DHS issued identification cards and building passes that have either expired or have been collected from terminated employees. If an identification card or building pass is not available to be returned, a report shall be submitted to the

COR, referencing the pass or card number, name of individual to who it was issued and the last known location and disposition of the pass or card.

When sensitive Government information is processed on Department telecommunications and automated information systems, the Contractor shall provide for the administrative control of sensitive data being processed. Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level.

Contractors who fail to comply with Depa1iment security policy are subject to having their access to Department IT systems and facilities terminated, whether or not the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws

(e.g., Privacy Act).

Failure to follow these instructions may delay the completion of suitability determinations and background checks. Note that any delays in this process that are not caused by the government do not relieve a contractor from performing under the terms of the contract.

Your POC at the Security Office is:

o DHS OCSO/PSD Security Customer Service Center Telephone: (202) 447-5010 o E-mailbox: officeofsecurity@dhs.gov.

Personal Identification Verification (PIV) Credential Compliance Authorities:

• HSPD-12 “Policies for a Common Identification Standard for Federal Employees and Contractors”

• OMB M-11-11 "Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors"

• OMB M-06-16 “Acquisition of Products and Services for Implementation of HSPD-12”

• NIST FIPS 201 “Personal Identity Verification (PIV) of Federal Employees and Contractors”

• NIST SP 800-63 “Electronic Authentication Guideline”

• OMB M-10-15 “FY 2010 Reporting Instructions for the Federal Information Security

Management Act and Agency Privacy Management”

Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting HSPD-12 PIV credentials as a method of identity verification and authentication.

SECTION D: PACKAGING AND MARKING

1 Packing, Packaging, Marking and Storage of Equipment

Unless otherwise specified, all items to be delivered under this contract shall be preserved, packaged, and packed in accordance with normal commercial practices to meet the packing requirements of the carrier and ensure safe delivery at destination at the most economical rate(s).

The Contractor shall use (where possible) packing materials which have the least impact on the environment when manufactured or discarded, including, brown cardboard in lieu of cardboard which has been bleached white and/or dyed, and materials which both decompose and are recyclable in lieu of recycle-only products such as plastic or Styrofoam.

All initial packing, marking and storage incidental to shipping of equipment to be provided under this contract shall be at the Contractor’s expense. The Contractor shall supervise the packing of all acquired equipment furnished by the Contractor and shall supervise the unpacking of equipment to be installed. The Contractor is fully liable for all damage, deterioration, or losses incurred during shipment and handling, unless the damage, deterioration, or losses are due to the fault of the Government.

mailto:officeofsecurity@dhs.gov

2 Markings

As applicable, all deliverables submitted to the contract’s Contracting Officer (CO) and contract’s Contracting Officer’s Representative (COR) shall be accompanied by a packing list or other suitable shipping document that shall clearly indicate the following:

• Contract number;

• Name and address of the consignor;

• Name and address of the consignee;

• Government bill of lading number covering the shipment (if any); and

• Description of the item/material shipped, including item number, quantity, number of containers, and package number (if any).

The Contractor shall comply with the security requirements for packaging, marking, mailing, and shipping classified materials as prescribed by current Department of Homeland Security (DHS) directives.

3 Advertisements, Publicizing Awards and News Releases

Under no circumstances shall the Contractor, or anyone acting on behalf of the Contractor, refer to the supplies, services, or equipment furnished pursuant to the provisions of this contract in any publicity/news release or commercial advertising without first obtaining explicit written consent to do so from the contract’s Contracting Officer.

4 Branding

Use of Department of Homeland Security Seal:

In accordance with DHS Management Directive 123-06, 18 U.S.C. § 506, 18 U.S.C. § 701, 18 U.S.C. § 1017 and 28 U.S.C. § 1733(b), the usage of the DHS seal shall be requested by completing DHS Form 0030 (12/08).

Request shall be submitted to the Contracting Officer, who will be responsible for submitting the form for review by the DHS Office of Public Affairs.

DHS must be acknowledged in any presentation (oral or written) of work that is a direct result of contractor’s support work to DHS. Any presentation that contractor makes that relates to work conducted by or funded by or for DHS must be provided to the COR with a courtesy copy to the CO for review prior to presentation. Contractor must obtain COR or CO guidance and permission prior to development of presentation or acceptance of invitation to make presentation.

Contractor is not permitted to present DHS work or their participation in DHS work for business promotional purposes, prior to COR and CO permission.

Any questions, comments, or concerns on presentations shall be addressed to the respective COR and CO.

SECTION E: INSPECATION AND ACCEPTANCE

1 Clauses Incorporated by Reference (FAR 52.252-2) (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at www.acquisition.gov/far.

FAR Clause Title Date 52.212-4 Contract Terms and Conditions-Commercial Items (Oct 2018) (Alt I)

2 Inspection

(a) Inspection of all items under this contract shall be accomplished by the cognizant DHS Contracting Officer’s Representative (COR), or any other duly authorized Government representative in accordance with the applicable FAR clauses and Section C of this contract.

(b) All deliverables will be inspected for content, completeness, and accuracy and conformance to contract requirements. Inspection may include validation of information or software through the use of automated tools and/or testing of the deliverables, as specified in Section C. The scope and nature of this testing will be sufficiently comprehensive to ensure the completeness, quality and adequacy of all deliverables and services.

(c) The Government requires a period not to exceed thirty (30) business days after receipt of services and final deliverable items for inspection and acceptance or rejection unless otherwise specified in Section C. The Government shall provide written notification of acceptance or rejection of all final deliverables within 30 business days of receipt of services or deliverables. Absent written notification within 30 business days of receipt, final deliverables shall be construed as accepted. All notifications of rejection will be accompanied with an explanation of the specific deficiencies causing the rejection.

3 Acceptance

(a) Acceptance of all work and effort shall be accomplished in writing by the Contracting Officer or their duly designated representative.

AMENDMENT 0001

http://www.acquisition.gov/far http://www.acquisition.gov/far

(b) The basis for acceptance shall be in compliance with the requirements set forth in Section C, the terms and conditions of this contract, and other terms and conditions. Services and/or deliverable items rejected shall be corrected in accordance with the applicable clauses.

(c) Reports, documents and narrative type deliverables will be accepted when all discrepancies, errors or other deficiencies identified in writing by the government have been corrected.

(d) Non-conforming products or services will be rejected or revised as directed by the CO or COR as specified in Section C. Unless otherwise agreed by the parties, deficiencies will be corrected within ten (10) business days of the rejection notice. If the deficiencies cannot be corrected within the specified period, the Contractor will immediately notify the Contracting Officer of the reason for the delay and provide a proposed corrective action plan within ten

(10) business days.

SECTION F: DELIVERIES/PERFORMANCE

1 PERIOD OF PERFORMANCE

The period of performance for this contract is:

• One twelve-month base period of performance, and

• Four twelve-month option periods.

2 PLACES OF PERFORMANCE

The primary place of performance for this work will be Contractor facilities - including remote/virtual environments - within the United States. Some work may be completed at DHS facilities in the Washington, DC area; onsite arrangements and available hoteling space and schedules would be discussed with the Contractor at the time DHS exercised such support. If necessary, Key Personnel or should be able to attend virtual meetings within 48 hours’ notice. If necessary, Contract team personnel should be able to attend critical in-person meetings within 5 business days’ notice.

3 HOURS OF OPERATION

Contractor employees shall generally perform all work between the hours of 08:30am and 05:00pm ET, Monday through Friday (except Federal holidays). However, there may be occasions when Contractor employees shall be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this SOW.

Services will generally not be required on the following Federal holidays (or any other holidays declared by the Government); however, the Contractor may be required to provide services on these days in support of mission critical situations.

• New Year's Day - 1 January

• Martin Luther King's Birthday - Third Monday in January

• Inauguration Day – January 20 (or 21st if the 20th is a Sunday)

• Washington’s Birthday - Third Monday in February

• Memorial Day - Last Monday in May

• Independence Day - 4 July

• Labor Day - First Monday in September

• Columbus Day - Second Monday in October

• Veterans Day - 11 November (or as observed)

• Thanksgiving Day - 4th Thursday in November

• Christmas Day - 25 December

No work shall be performed by Contractor personnel on Government facilities on Federal holidays or other non-workdays without prior written approval of the COR.

4 DELIVERABLES AND DELIVERY SCHEDULE

For each deliverable, the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .