RFP 70RDAD23R00000011 Amendment 01.pdf

PDF 1 MB Posted

Attached to
EAP and Work-Life Support Services Federal contract opportunity
Solicitation number
70RDAD23R00000011
Issued by
Not on record

About this file

This is a request for proposal for EAP and Work-Life support services. DHS is seeking a contractor to provide a variety of EAP and Work-Life services to all DHS employees and eligible family members located throughout the US and overseas. Services include intake and counseling via a centralized call center available 24/7, short-term counseling, referrals, substance abuse case management, critical incident response, training, and work-life referral services. The contractor will maintain a large affiliate counselor network and provide on-site services when requested. The period of performance is five years with one base year and four option years. Awards will be made as single-award IDIQ contracts with a minimum guarantee of $26,000 and ceiling of $180 million across all task orders.

View the file

Other files for this federal contract opportunity

Other files attached to EAP and Work-Life Support Services, newest first.
File Type Posted
RFP 70RDAD23R00000011 Amendment 05.pdf PDF
70RDAD23R00000011 SF30 Amendment 05.pdf PDF
70RDAD23R00000011 Attachment J.4 (Pricing Template) Amendment 05.xlsx XLSX spreadsheet
70RDAD23R00000011 SF30 Amendment 04.pdf PDF
70RDAD23R00000011 Attachment J.4 (Pricing Template) Amendment 03.xlsx XLSX spreadsheet
70RDAD23R00000011 SF30 Amendment 03.pdf PDF
70RDAD23R00000011 Attachment J.5 (Solicitation Questions and Comments) Amendment 03.xlsx XLSX spreadsheet
70RDAD23R00000011 SF30 Amendment 02.pdf PDF
RFP 70RDAD23R00000011 Amendment 02.pdf PDF
70RDAD23R00000011 Attachment J.5 (Solicitation Questions and Comments) Amendment 02.xlsx XLSX spreadsheet
70RDAD23R00000011 Attachment J.5 (Solicitation Questions and Comments) Amendment 01.xlsx XLSX spreadsheet
70RDAD23R00000011 Attachment J.2 (Representations and Certifications) Amendment 01.docx DOCX document
RFP 70RDAD23R00000011 SF30 Amendment 01.pdf PDF
70RDAD23R00000011 Attachment J.1 (ACORD Form, Certificate of Liability Insurance) Amendment 01.pdf PDF
70RDAD23R00000011 Attachment J.3 (Past Performance Substitute Form) Amendment 01.docx DOCX document
70RDAD23R00000011 Attachment J.4 (Pricing Template) Amendment 01.xlsx XLSX spreadsheet
70RDAD23R00000011 Attachment J.2 (Representations and Certifications).docx DOCX document
70RDAD23R00000011 Attachment J.3 (Past Performance Substitute Form).docx DOCX document
70RDAD23R00000011 Attachment J.4 (Pricing Template).xlsx XLSX spreadsheet
70RDAD23R00000011 Attachment J.5 (Solicitation Questions and Comments).xlsx XLSX spreadsheet
RFP 70RDAD23R00000011.pdf PDF
70RDAD23R00000011 Attachment J.1 (ACORD Form, Certificate of Liability Insurance).pdf PDF
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUMIS CHECKED

CODE 18a. PAYMENT WILL BE MADE BY

CODE

FACILITYCODE

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

OFFEROR

DHS/OPO/DEPT.OPS

245 Murray Lane SW, #0115 Dept. Operations Acquisition Div.

Office of Procurement Operations U.S. Dept. of Homeland Security

CODE 16. ADMINISTERED BYCODE

X

X

624190

SIZE STANDARD:

% FOR:SET ASIDE:UNRESTRICTED OR70RDAD

RFPIFB

10. THIS ACQUISITION ISCODE

RFQ

14. METHOD OF SOLICITATION

13b. RATING

NAICS:

SMALL BUSINESS

09/27/2023

Bjorn Miller (No collect calls)

INFORMATION CALL:

FOR SOLICITATION 8. OFFER DUE DATE/LOCAL TIME

11/17/2023 1200 ES

b. TELEPHONE NUMBERa. NAME

4. ORDER NUMBER3. AWARD/ 6. SOLICITATION

70RDAD23R00000011

5. SOLICITATION NUMBER

1. REQUISITION NUMBER PAGE OF

1 166

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

OFFEROR TO COMPLETE BLOCKS 12, 17, & 30

Washington DC 20528-0115

TELEPHONE NO.

17a. CONTRACTOR/

15. DELIVER TO

Washington DC 20528 245 Murray Lane SW, Mailstop 0115 Dept. Operations Acquisition Div.

Office of Procurement Operations U.S. Dept. of Homeland Security

9. ISSUED BY

7.

2. CONTRACT NO.

EFFECTIVE DATE

$16

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW

ISSUE DATE

DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

11.

SEE SCHEDULE

12. DISCOUNT TERMS

THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13a.

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

8(A)

DEPT OPS ACQ DIV(70RDAD)

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

24.

AMOUNT

23.

UNIT PRICE

22.

UNIT

21.

QUANTITY

20.

SCHEDULE OF SUPPLIES/SERVICES

19.

ITEM NO.

Offerors shall submit one (1) proposal in response to this Request for Proposal (RFP) in accordance with Section L, providing the information prescribed therein. The Government anticipates awarding one (1) single-award contract in response to this RFP to the Offeror providing the Government with the best value.

Offerors shall submit questions to the Contracting Officer, Bjorn Miller, and Contract Specialist, Karen Ma, by the deadline prescribed therein Section L.

(Use Reverse and/or Attach Additional Sheets as Necessary)

HEREIN, IS ACCEPTED AS TO ITEMS:

X

XX

DATED

Bjorn Miller

. YOUR OFFER ON SOLICITATION (BLOCK 5),

INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER

ARE

ARE

31c. DATE SIGNED

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (Type or print)

ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL

SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA 27b.

CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

26. TOTAL AWARD AMOUNT (For Govt. Use Only)

OFFER

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA - FAR (48 CFR) 53.212

ARE NOT ATTACHED.

ARE NOT ATTACHED.

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

30b. NAME AND TITLE OF SIGNER (Type or print)

30a. SIGNATURE OF OFFEROR/CONTRACTOR

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

25. ACCOUNTING AND APPROPRIATION DATA

29. AWARD OF CONTRACT:

REF.

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32c. DATE 32b. SIGNATURE OF AUTHORIZED GOVERNMENT REPRESENTATIVE

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

40. PAID BY39. S/R VOUCHER NUMBER38. S/R ACCOUNT NUMBER

37. CHECK NUMBER

FINALPARTIAL

36. PAYMENT

FINALPARTIAL

35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER33. SHIP NUMBER

COMPLETE

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

42d. TOTAL CONTAINERS42c. DATE REC'D (YY/MM/DD)

42b. RECEIVED AT (Location)

42a. RECEIVED BY (Print)

41c. DATE41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

STANDARD FORM 1449 (REV. 2/2012) BACK

24.

AMOUNT

23.

UNIT PRICE

22.

UNIT

21.

QUANTITY

20.

SCHEDULE OF SUPPLIES/SERVICES

19.

ITEM NO.

32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT REPRESENTATIVE

164 2 of

REQUEST FOR PROPOSAL 70RDAD23R00000011

SECTION A: SOLICITATION/CONTRACT FORM

A.1 NOTICE TO OFFERORS

This is an unrestricted solicitation for the Indefinite-Delivery, Indefinite-Quantity (IDIQ) contract vehicle for Employee Assistance Program (EAP) and Work-Life support services. Offerors shall follow the instructions set forth in Section L of this solicitation to be considered for award.

Any amendment(s) to this solicitation will be posted to https://sam.gov/content/home.

(END OF SECTION A)

https://sam.gov/content/home

SECTION B: SUPPLIES OR SERVICES AND PRICES/COSTS

B.1 AUTHORITY

In accordance with 5 CFR Part 792, Federal agencies must provide employee assistance programs to assist employees with drug and alcohol abuse prevention, treatment, and rehabilitation, and permits Federal agencies to use appropriated funds to improve the affordability of childcare for lower-income employees. Additionally, in accordance with 5 U.S.C. 7901, Federal agencies may establish, within the appropriation limits available, health services programs to promote the physical and mental fitness of employees.

The authority for the award and administration of this IDIQ contract and all task orders thereunder it is defined in Section G.

B.2 BRIEF DESCRIPTION OF SERVICES

The scope of services includes a variety of EAP and Work-Life support services for all Department of Homeland Security (DHS) employees and eligible family members. Services may be provided to civilian, law enforcement, military personnel, or a combination thereof, throughout the Continental United States (CONUS) and Outside the Continental United States (OCONUS).

B.3 IDIQ CONTRACT TYPE

This is a Single-Award IDIQ contract, which is available for use by DHS Headquarters and all DHS Components.

In accordance with Federal Acquisition Regulation (FAR) Section 12.207, the IDIQ contract allows task orders to be awarded on a Firm-Fixed Price (FFP), Time-and-Materials (T&M), Labor- Hour (L-H) basis, or a combination thereof. Additionally, task orders may include optional periods of performance and optional Contract Line Item Numbers (CLIN).

B.4 MINIMUM GUARANTEE AND MAXIMUM CEILING

The Government shall obligate itself at time of contract award in the amount of $26,000.00, which represents the Government’s minimum guarantee. The minimum dollar guarantee applies to the IDIQ contract as a whole and not each ordering period, if exercised. The minimum dollar guarantee will be funded by FY24 funds.

The maximum dollar amount for all task orders awarded thereunder the IDIQ contract is $180,000,000.00. An unlimited number of task orders may be awarded thereunder the IDIQ contract throughout the ordering period, including options, if exercised.

B.5 TASK ORDER PRICING

The IDIQ contract provides DHS Ordering Contracting Officers (OCO) the flexibility to determine fair and reasonable pricing tailored to task order requirements. The OCO has the authority and responsibility to determine price and, if applicable, cost reasonableness for the task order requirement.

The OCO shall identify the applicable contract type for all CLINs in each task order.

The Contractor shall propose and the OCO award all labor rates when performance is conducted at the Contractor’s facility(ies) at the Contractor Site Rate(s). The Contractor shall propose and the OCO award all labor rates at the Government Site Rate(s) when performance is conducted at the Government’s facility(ies) or a site not owned or leased by the Contractor.

B.5.1 FIRM-FIXED PRICE TASK ORDERS

FFP task orders are subject to the definitions prescribed therein FAR Section 16.202, Homeland Security Acquisition Regulation (HSAR) Subpart 3016.2, and any component-specific supplements.

B.5.2 TIME-AND-MATERIALS (T&M) AND LABOR-HOUR (L-H) TASK

ORDERS

T&M and L-H task orders are subject to the definitions prescribed therein FAR Sections 16.601 and 16.602, respectively, and any component-specific supplements.

All labor categories identified therein Attachment J.4 are considered bona fide executive, administrative, and professional labor that are exempt from the Fair Labor Standards Act.

To the extent that any ancillary labor for services are within the scope of this IDIQ contract and subject to the Fair Labor Standards Act, in accordance with FAR Subpart 22.10 and any component-specific supplements, the OCO shall identify such work in the task order solicitation and make a determination as to whether wage determinations are to be applied or not.

This IDIQ contract does not include any provisions or clauses applicable to any Fair Labor Standards Act work that is part of a total solution within the scope of the IDIQ contract. The OCO shall incorporate the appropriate provisions and clauses in each task order solicitation and subsequent award when the Fair Labor Standards Act applies.

B.5.3 LABOR OUTSIDE THE CONTINENTAL UNITED STATES (OCONUS)

Outside the Continental United States (OCONUS) is defined as other than the 48 contiguous states plus the District of Columbia. It is anticipated that there may be task orders for work OCONUS.

The U.S. Department of State’s Bureau of Administration, Office of Allowances, publishes quarterly report indexes of living costs abroad, per-diem rate maximums, quarter’s allowances, hardship differentials, and danger pay allowances.

The Department of State Standardized Regulations (DSSR) is the controlling regulations for allowances and benefits available to all U.S. Government civilians assigned to foreign areas. For task orders issued thereunder this IDIQ contract, Contractor personnel assigned to foreign areas shall not receive allowances and benefits in excess of those identified in the DSSR.

For OCONUS task orders where costs are not specifically addressed in the DSSR, the Government will reimburse the Contractor for all reasonable, allowable, and allocable costs in accordance with FAR Part 31 and any component-specific supplements.

B.5.4 TRAVEL

Travel costs may be included at the task order level. Travel costs may be firm-fixed price or reimbursed at actual cost in accordance with the limitations set forth in FAR Subsection 31.205- 46 and any component-specific supplements. OCOs shall determine all travel costs fair, reasonable, and allowable prior to the Contractor incurring and expensing any travel costs to the Government.

Unless otherwise directed by task order terms and conditions, the Contractor may apply indirect costs to travel consistent with the Contractor’s standard accounting practices.

B.5.5 MATERIALS

Materials may be included at the task order level in accordance with FAR 52.212-4(e)(1)(iii) ALT I (NOV 2021). OCOs shall determine the price(s) to be fair and reasonable and cost(s) to be allowable, allocable, and reasonable prior to task order award.

B.5.6 SUBCONTRACTING

All subcontracting shall follow the procedures prescribed therein FAR Part 12 and FAR Subpart 44.4, and any component-specific supplements.

(END OF SECTION B)

SECTION C: DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK

C.1 BACKGROUND

The Department of Homeland Security (DHS) employs approximately 219,000 employees. Most of these employees work in the Continental United States, but there are DHS employees in Alaska, Hawaii, Puerto Rico, the United States Virgin Islands, Guam and other overseas locations. DHS recognizes that our employees face the same types of personal challenges that all other Americans face and is committed to providing our employees and their families with the right resources, at the right time, to enhance their wellness and increase resilience. Taking care of our workforce and their families is vital to the integrity of operational readiness, reliability, capability, continuity, and mission accomplishment; our success or failure has national security implications. A well and resilient workforce is a ready workforce. The Employee Assistance Program (EAP) is a key tool to providing support for employees and families who may be in need of assistance when faced with day-to-day life challenges requiring professional support to work through those issues.

A breakdown of DHS employees per country, state, and city is included therein Attachment J.6 (DHS Employee Count).

C.2 APPLICABLE GOVERNANCE AND AUTHORITIES

C.2.1 AUTHORITIES

The following laws and authorities established Federal agency responsibility for developing and maintaining prevention, intervention, and rehabilitation programs and services for Federal employees and immediate family members who have alcohol and/or other problems. The Contractor shall comply with all Federal laws, regulations and policies governing Federal EAPs.

Federal EAPs are established in accordance with the following Public Laws (PL): PL 79-658 authorizes the establishment of health programs to promote and maintain the physical and mental fitness of Federal employees; PL 91-616 and PL 92-255 requires Federal agencies to make available alcoholism and drug abuse programs to Federal employees; and PL 96-180 and PL 96- 181 authorizes Federal agencies to provide counseling services, to the extent feasible, to family members of employees who may have alcohol or drug problems, or any other substance abuse problems.

Comptroller General of the U. S. Decision, B-270446, dated February 11, 1997, authorizes the use of operating appropriations to cover the cost of extending its psychological assessment and referral services to its employee’s family members in limited situations, expressly work-related incidents that arise from law enforcement activities or traumatic incidents involving death or serious injury to its employees in the line of duty.

42 U.S.C. 290dd–2, Confidentiality of Substance Use Disorder Patient Records

5 U.S.C. 552a, Records Maintained on Individuals cover confidential requirements in relation to the EAP.

Executive Order 12564, Drug-Free Federal Workplace (DFW), dated September 15, 1986, requires agencies to establish drug-free federal workplace programs, to include drug testing and https://www.ecfr.gov/current/title-42/chapter-I/subchapter-A/part-2 https://www.law.cornell.edu/uscode/text/5/552a https://www.archives.gov/federal-register/codification/executive-order/12564.html substance abuse education for Federal employees and EAP services. As defined by the executive order, EAPs are "agency-based counseling programs that offer assessment, short-term counseling, and referral services to employees for a wide range of drug, alcohol, and mental health programs that affect employee job performance."

DHS Management Directive 254-02, dated May 31, 2007, establishes DHS policy for Employee Assistance Programs, and DHS Management Directive 254-03, dated May 31, 2007, sets procedures for traumatic incident management, including EAP's role.

The Omnibus Transportation Employee Testing Act of 1991, referred as “The Act”, requires drug and alcohol testing of safety-sensitive transportation employees. The Act states “rehabilitation is a critical component of any testing program for abuse of alcohol or use of illegal drugs, and should be made available to individuals, as appropriate.” In accordance with “The Act”, DOT established testing regulations, to include EAP, SAP and rehabilitation requirements.

C.2.2 COMPLIANCE DOCUMENTS

The following documents provide specifications, standards, or guidelines that shall be complied with in order to meet the requirements of the IDIQ contract. The Contractor shall comply with the following documents or any updates thereafter.

• DHS Policy Directive 4300A: Information Technology System Security Program, Sensitive Systems, v13.3

• Department of Defense (DoD) Manual 5200.01 Volumes 1-3, February 24, 2012

• Office of Personnel Management - Enterprise Human Resources Integration (EHRI):

https://www.opm.gov/policy-data-oversight/data-analysis-documentation/enterprise-human-resources-integration/ and https://www.opm.gov/policy-data-oversight/data-analysis-documentation/data-policy-guidance/#url=Data-Reporting-Guidance

• The National Institute of Standards and Technology (NIST) serve as the proponent for cybersecurity guidance and publishes the Cybersecurity Framework for the federal sector.

Within this framework, NIST SP 800-53 Rev. 5, September 2020 is the common document used to reconcile security controls. Federal Information Security Modernization Act (FISMA) mandates the following NIST guidance and standards:

• Federal Information Processing Standard (FIPS) Publication 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004

• FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006

• Special Publication 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, December 2018

• Special Publication 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations, September 2020

• Special Publication 800-53A Rev.5, Assessing Security and Privacy Controls in Information Systems and Organizations, January 2022

• Special Publication 800-59, Guideline for Identifying an Information System as a National Security System, August 2003 https://www.bing.com/ck/a?!&&p=18d9386aa8077690JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0wNTg4NzY0YS0wZmUxLTY1Y2QtMWQ0NS02NTAwMGVmMzY0MDgmaW5zaWQ9NTE5NA&ptn=3&hsh=3&fclid=0588764a-0fe1-65cd-1d45-65000ef36408&psq=DHS+Management+Directive+254-02&u=a1aHR0cHM6Ly93d3cuZGhzLmdvdi9zaXRlcy9kZWZhdWx0L2ZpbGVzL3B1YmxpY2F0aW9ucy9tZ210L2h1bWFuLXJlc291cmNlcy9tZ210LWRpcl8yNTQtMDItZW1wbG95ZWUtYXNzaXN0YW5jZS1wcm9ncmFtX3Jldi0wMC5wZGY&ntb=1 https://dhsconnect.dhs.gov/org/comp/mgmt/policies/Directives/254-03.pdf https://www.bing.com/ck/a?!&&p=a31a53427b696dedJmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0wNTg4NzY0YS0wZmUxLTY1Y2QtMWQ0NS02NTAwMGVmMzY0MDgmaW5zaWQ9NTE5Ng&ptn=3&hsh=3&fclid=0588764a-0fe1-65cd-1d45-65000ef36408&psq=The+Omnibus+Transportation+Employee+Testing+Act+of+1991&u=a1aHR0cHM6Ly93d3cudHJhbnNwb3J0YXRpb24uZ292L29kYXBjL29tbmlidXMtdHJhbnNwb3J0YXRpb24tZW1wbG95ZWUtdGVzdGluZy1hY3QtMTk5MQ&ntb=1 https://www.dhs.gov/publication/dhs-4300a-sensitive-systems-handbook https://www.dhs.gov/publication/dhs-4300a-sensitive-systems-handbook https://www.esd.whs.mil/directives/issuances/dodm/ https://www.opm.gov/policy-data-oversight/data-analysis-documentation/enterprise-human-resources-integration/ https://www.opm.gov/policy-data-oversight/data-analysis-documentation/enterprise-human-resources-integration/ https://www.opm.gov/policy-data-oversight/data-analysis-documentation/data-policy-guidance/#url=Data-Reporting-Guidance https://www.opm.gov/policy-data-oversight/data-analysis-documentation/data-policy-guidance/#url=Data-Reporting-Guidance https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.199.pdf https://csrc.nist.gov/publications/detail/fips/200/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf https://csrc.nist.gov/publications/detail/sp/800-59/final

• Special Publication 800-60 Vol.1 Rev.1, Guide for Mapping Types of Information and Information Systems to Security Categories, August 2008

• NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization, December 2014

• NIST SP 800-144, Guidelines of Security and Privacy in Cloud Computing, December

• NIST SP 800-146, Cloud Computing Synopsis and Recommendations, May 2012

• Federal Information Processing Standard (FIPS) 140-3, Security Requirements for

Cryptographic Modules, March 2019

• DHS Directive 140-01 Rev. 2, Information Technology Security Program, May 2017

• DHS Instruction Guide 040-01-008, Privacy Incident Handling Guidance, December

• DHS Security Authorization Process Guide

• DHS Management Directive 11042.1, Safeguarding Sensitive but Unclassified (For

Official Use Only) Information, January 2015

• DHS Instruction Handbook 121-01-007, Personnel Suitability and Security Program, February 2019

• Coast Guard Cybersecurity Manual, Commandant Instruction (COMDTINST) M5500.13

(series) – FOUO

• DoD Instruction (DODI) 8500.01, Cybersecurity, October 2019

• DODI 8510.01, Risk Management Framework for DoD Systems, July 2022

• DODI 8520.03, Identity Authentication for Information Systems, May 2023

• DODI 8530.01, Cybersecurity Activities Support to DoD Information Network

Operations, July 2017

• DoD Cloud Computing Security Requirements Guide (SRG), Version 1, Release 3, March 6, 2017

• Defense Information Systems Agency (DISA) Cloud Connection Process Guide, Version

2, March 2017

• CJCSM 6510.01B, Cyber Incident Handling Program, Chairman of the Joint Chiefs of

Staff Manual (CJCSM), December 2014

• Information Assurance Vulnerability Management - DOD CJCSI Policy 6510-01F, Assurance (IA) and Computer Network Defense (CND), and CJCSM 6510-01B Cyber Incident Handling Program. National Security systems guidance can be found at https://www.cnss.gov/CNSS/issuances/Policies.cfm.

• Executive Order 13231, Critical Infrastructure Protection in the Information Age, October 2001

• PDD 63, Critical Infrastructure Protection, May 1998

• DoD Memorandum for Cybersecurity Activities Performed for Cloud Service Offerings, November 15, 2017

• DHS Policy Directive 142-04, DHS Reusable and Open Source Software Rev. 01, August 2021

C.2.3 REFERENCE DOCUMENTS

The following documents, or any updates thereafter, may be helpful to the Contractor in managing its solution and performing the services.

• Federal Cloud Computing Strategy, February 2011.

https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-144/final https://csrc.nist.gov/publications/detail/sp/800-146/final https://csrc.nist.gov/publications/detail/fips/140/3/final https://www.bing.com/ck/a?!&&p=3a04fab47b6800a6JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTE5Ng&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DHS+Directive+140-01&u=a1aHR0cHM6Ly93d3cuZGhzLmdvdi9zaXRlcy9kZWZhdWx0L2ZpbGVzL3B1YmxpY2F0aW9ucy9EaXJlY3RpdmUlMjAxNDAtMDElMkMlMjBSZXZpc2lvbiUyMDAyJTJDJTIwSW5mb3JtYXRpb24lMjBUZWNobm9sb2d5JTIwU2VjdXJpdHklMjBQcm9ncmFtJTIwJTI4Li4uLnBkZg&ntb=1 https://www.bing.com/ck/a?!&&p=fa18d83729996a98JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTIxNw&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DHS+Instruction+Guide+040-01-008&u=a1aHR0cHM6Ly93d3cuZGhzLmdvdi9zaXRlcy9kZWZhdWx0L2ZpbGVzL3B1YmxpY2F0aW9ucy8wNDctMDEtMDA4JTIwUElIRyUyMEZJTkFMJTIwMTItNC0yMDE3XzAucGRm&ntb=1 https://www.bing.com/ck/a?!&&p=e96c785ef7328eedJmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTIwMQ&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DHS+Security+Authorization+Process+Guide&u=a1aHR0cHM6Ly93d3cuZGhzLmdvdi9zaXRlcy9kZWZhdWx0L2ZpbGVzL3B1YmxpY2F0aW9ucy9TZWN1cml0eSUyMEF1dGhvcml6YXRpb24lMjBQcm9jZXNzJTIwR3VpZGVfMS5wZGY&ntb=1 https://www.dhs.gov/sites/default/files/publications/Management%20Directive%2011042.1%20Safeguarding%20Sensitive%20But%20Unclassified%20%28For%20Official%20Use%20Only%29%20Information_0.pdf https://www.dhs.gov/sites/default/files/publications/InstructionHandbook121-01-007PersonnelSuitabilityandSecurityProgram.pdf https://www.bing.com/ck/a?!&&p=77b77d23d9c84ed8JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTIwMA&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DoD+Instruction+(DODI)+8500.01&u=a1aHR0cHM6Ly93d3cuZXNkLndocy5taWwvUG9ydGFscy81NC9Eb2N1bWVudHMvREQvaXNzdWFuY2VzL2RvZGkvODUwMDAxXzIwMTQucGRm&ntb=1 https://www.bing.com/ck/a?!&&p=bc5f2a7f844f5477JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTE5MQ&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DODI+8510.01&u=a1aHR0cHM6Ly93d3cuZXNkLndocy5taWwvUG9ydGFscy81NC9Eb2N1bWVudHMvREQvaXNzdWFuY2VzL2RvZGkvODUxMDAxcC5wZGY_dmVyPTIwMTktMDItMjYtMTAxNTIwLTMwMA&ntb=1 https://www.bing.com/ck/a?!&&p=c94977c1567d188cJmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTIwMg&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DODI+8520.03&u=a1aHR0cHM6Ly93d3cuZXNkLndocy5taWwvUG9ydGFscy81NC9Eb2N1bWVudHMvREQvaXNzdWFuY2VzL2RvZGkvODUyMDAzcC5wZGY&ntb=1 https://www.bing.com/ck/a?!&&p=93eccf1bfa7754f4JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTE5Nw&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=dodi+8530.01+&u=a1aHR0cHM6Ly93d3cuZXNkLndocy5taWwvUG9ydGFscy81NC9Eb2N1bWVudHMvREQvaXNzdWFuY2VzL2RvZGkvODUzMDAxcC5wZGY&ntb=1 https://www.bing.com/ck/a?!&&p=e554e892080b0d5fJmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTE4OQ&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DoD+Cloud+Computing+Security+Requirements+Guide+(SRG)%2c+version+1%2c+revision+3&u=a1aHR0cHM6Ly9ybWYub3JnL3dwLWNvbnRlbnQvdXBsb2Fkcy8yMDE4LzA1L0Nsb3VkX0NvbXB1dGluZ19TUkdfdjFyMy5wZGY&ntb=1 https://www.bing.com/ck/a?!&&p=718294eaff843f53JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTE5NQ&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=Defense+Information+Systems+Agency+(DISA)+Cloud+Connection+Process+Guide&u=a1aHR0cHM6Ly93d3cuZGlzYS5taWwvfi9tZWRpYS9GaWxlcy9ESVNBL1NlcnZpY2VzL0RJU04tQ29ubmVjdC9SZWZlcmVuY2VzL0NDUEcucGRm&ntb=1 https://www.cnss.gov/CNSS/issuances/Policies.cfm https://www.bing.com/ck/a?!&&p=8522c85bd339ce7dJmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTIwOA&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=EXECUTIVE+ORDER+13231&u=a1aHR0cHM6Ly93d3cuZGhzLmdvdi94bGlicmFyeS9hc3NldHMvZXhlY3V0aXZlLW9yZGVyLTEzMjMxLWRhdGVkLTIwMDEtMTAtMTYtaW5pdGlhbC5wZGY&ntb=1 https://irp.fas.org/offdocs/pdd/pdd-63.pdf https://www.bing.com/ck/a?!&&p=40c1d08f1ba0a600JmltdHM9MTY4ODk0NzIwMCZpZ3VpZD0xZTEyY2E4OC1jZTZmLTY5YTktM2JlMy1kOWMyY2Y3ZDY4ZjEmaW5zaWQ9NTE5NQ&ptn=3&hsh=3&fclid=1e12ca88-ce6f-69a9-3be3-d9c2cf7d68f1&psq=DoD+Memorandum+for+Cybersecurity+Activities+Performed+for+Cloud+Service+Offerings&u=a1aHR0cHM6Ly9kb2RjaW8uZGVmZW5zZS5nb3YvUG9ydGFscy8wL0RvY3VtZW50cy9DeWJlci9Eb0QlMjBDSU8lMjBTaWduZWQlMjBNZW1vJTIwLSUyMERvRCUyMEN5YmVyc2VjdXJpdHklMjBBY3Rpdml0aWVzJTIwUGVyZm9ybWVkJTIwZm9yJTIwQ2xvdWQlMjBTLi5fLnBkZg&ntb=1 https://www.dhs.gov/scip#PolicyOverview https://cloud.cio.gov/

• Security Authorization of Information Systems in Cloud Computing Environments, December 2011.

• 25 Point Implementation Plan to Reform Federal Information Technology, December 2010.

• HSPD-12 – Policies for a Common Identification Standard for Federal Employees and Contractors.

• OMB M-11-11 "Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors”

• OMB M-06-16 – Acquisition of Products and Services for Implementation of HSPD-12.

• NIST Special Publication 800-171 Revision 2, Protecting Controlled Unclassified

Information in Nonfederal Systems and Organizations

C.3 SCOPE

The scope of this requirement calls for the provision of Employee Assistance and Work-Life Referral Service Program for all DHS employees and their immediate family members.

“Immediate Family Members” is defined as members of the immediate household who are dependents, which may include children, elderly parents, and/or spouses/partners who share financial and family caretaking responsibilities.

DHS HQ intends to place the initial Task Order against the resultant IDIQ contract to procure Information System Security Compliance Services in order to obtain an Authorization Decision (AD). Once DHS grants an AD and DHS agrees the system is available for use in production, DHS and its Components will be able to procure other EAP services as described at the task order level.

The DHS Workforce is widely dispersed, and work in large metropolitan areas (i.e., a recognized area with 50,000 or more inhabitants), remote rural areas, and outside of the continental Unites States, including a number who are stationed in international locations. A large percentage of the DHS workforce is designated as Law Enforcement Officers (LEOs).

The EAP is designed to assist organizations in addressing productivity issues and clients in identifying and resolving personal concerns including, but not limited to, health, marital, family, financial, alcohol, drug, legal, emotional, stress, or other personal issues that may affect job performance. Services shall include, but are not limited to, assessment, short-term counseling, and/or referral services for employees and their family members; management consultation;

organizational development services; training and education awareness; and, traumatic/critical incident support services.

The Contractor shall perform functions grounded in EAP Core Technologies including:

1. A focus on employees’ alcohol and other substance abuse problems;

2. Train management staff in the appropriate use of constructive confrontation techniques;

3. Providing expert consultation and training to supervisors, managers, and union stewards on how to use EAP policy and procedures for both employee problems and for management issues;

https://www.fismacenter.com/fedrampmemo.pdf https://www.dhs.gov/sites/default/files/publications/digital-strategy/25-point-implementation-plan-to-reform-federal-it.pdf https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2011/m11-11.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2011/m11-11.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2011/m11-11.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2006/m06-16.pdf https://www.bing.com/ck/a?!&&p=8b5e28167ee3e733JmltdHM9MTY4OTEyMDAwMCZpZ3VpZD0wMjkyMTI5YS04ZTI5LTZhYWQtMDZjNy0wMWQ2OGYyYjZiNjcmaW5zaWQ9NTIwMw&ptn=3&hsh=3&fclid=0292129a-8e29-6aad-06c7-01d68f2b6b67&psq=NIST+Special+Publication+800-171&u=a1aHR0cHM6Ly9jc3JjLm5pc3QuZ292L3B1YmxpY2F0aW9ucy9kZXRhaWwvc3AvODAwLTE3MS9yZXYtMi9maW5hbA&ntb=1 https://www.bing.com/ck/a?!&&p=8b5e28167ee3e733JmltdHM9MTY4OTEyMDAwMCZpZ3VpZD0wMjkyMTI5YS04ZTI5LTZhYWQtMDZjNy0wMWQ2OGYyYjZiNjcmaW5zaWQ9NTIwMw&ptn=3&hsh=3&fclid=0292129a-8e29-6aad-06c7-01d68f2b6b67&psq=NIST+Special+Publication+800-171&u=a1aHR0cHM6Ly9jc3JjLm5pc3QuZ292L3B1YmxpY2F0aW9ucy9kZXRhaWwvc3AvODAwLTE3MS9yZXYtMi9maW5hbA&ntb=1

4. The creation and maintenance on micro-linkages with counseling, treatment, and other community resources for the successful referral of individual EAP cases (i.e., the Contractor must have knowledge of the availability and quality of resources in order to connect or link a client for appropriate treatment);

5. The creation and maintenance of macro-linkages between the work organization and counseling, treatment and other community resources for appropriate role and use of EAP (i.e., the Contractor must have knowledge of appropriate community resources that are available to the organization or individual);

6. The identification of employees’ behavioral problems including assessment of job performance issues (tardiness, absence, productivity, work relationships, safety, etc.)

The goal of the EAP is to enhance employee and workplace effectiveness through assisting employees with personal problems and productivity issues that may adversely impact their work performance by:

1. Providing high quality services to individuals for assessment and in-person or virtual counseling. This includes clinicians with knowledge of and experience with law enforcement (LE) officers and culture. Ensuring macro and micro linkages for the LE population possess knowledge and experience with the LE culture;

2. Contractor maintaining a training program and methodology to ensure service providers are unbiased to military service, understand military culture, and are aware of the issues facing Servicemen/Servicewomen and their dependents;

3. Ensuring that service providers have an understanding of and empathy for military personnel, civilian employees, and family members and military lifestyles, and ensuring macro and micro linkages for the DHS military population;

4. Providing support for work-life balance issues through a robust resource and referral network;

5. Assisting managers, supervisors, and team leads to improve employee job performance by providing consultative services;

6. Supporting organizational health through consultation with managers, supervisors and special operations groups who request help to address existing workplace issues that affect emotional wellbeing and Work-Life balance;

7. Providing training to employee groups on EAP and Work-Life topics;

8. Collaborating with specialized groups within each DHS Component (i.e. Peer Support, Chaplains, Critical Response teams) to provide consultation and support;

9. Providing professional services in response to critical incidents.

These services are to be provided to all DHS employees and eligible family members that are covered by this IDIQ contract. The Contractor and its subcontractor(s), consultant(s), affiliate(s), and their respective employees shall comply at all times with applicable provisions of federal, state and local law, including the Health Portability and Accountability Act (HIPAA) and National Archives and Records Administration (NARA) records retention schedules.

There is no cost to employees and eligible family members for EAP and Work-Life services. There are times when it is appropriate to refer employees or their family member(s) to outside community resources. When employees accept these referrals, some of their services may continue to be at no cost to them; however, there may be times when fees are assessed by an outside provider due to the nature and number of services required. At those times when services are in excess of the stipulated amounts, employees or their family member(s) will be responsible for any fees charged by the provider. The EAP works with employees or their family members to keep the cost within their financial means and works to ensure that referrals to counselors are coordinated with the employee’s health .

C.4 REQUIREMENTS AND DESCRIPTION OF TASKS

The following task descriptions specify the scope of services that may be acquired under this IDIQ contract. Specific requirements will be delineated at the task order level. DHS employees and eligible family members are permitted to receive EAP and Work-Life services up to the allowable quantity prescribed for that specific service on an annual basis.

C.4.1 TASK 1: INFORMATION SYSTEM SECURITY COMPLIANCE –

AUTHORIZATION DECISION (AD)

The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor information technology system without an Authorization Decision signed by the DHS Headquarter or DHS Component Chief Information Officer (CIO), or designee, in consultation with the DHS Headquarter or DHS Component Privacy Officer. Unless otherwise specified in the Authorization Decision, the Authorization Decision is valid for one (1) year. The Contractor shall adhere to current and updated federal and DHS-specific policies, procedures, and guidance for the Security Authorization (SA) process as defined in https://www.dhs.gov/publication/security-training-contract-policy and NIST Special Publication 800-37, Revision 2, Revision 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, January 2020.

The Contractor’s Information System Security Officer (ISSO) shall coordinate all security activities with the Federal ISSO and/or System Owner. The Portfolio Management Division Information System Security Manager (ISSM) will provide guidance to the Federal ISSO for management with the Contractor ISSO where needed.

All information technology and security compliance documents shall be submitted to the Contracting Officer’s Representative (COR), and reviewed and approved by the DHS Chief Information Security Office Directorate (CISOD) upon creation and after any subsequent changes before they go into effect. All security documentation and artifacts will be uploaded and documented in the DHS system of record.

C.4.1.1 INTELLECTUAL PROPERTY

All intellectual property resulting from activities undertaken in performance of this IDIQ contract and any resultant task order shall be governed under the applicable FAR patent and data rights clauses incorporated therein the IDIQ contract, including FAR 52.227-1, 52.227-2, 52.227-11, FAR 52.227-14, FAR 52.227-16, and FAR 52.227-17, along with any special IDIQ contract requirements prescribed therein Section H that relate to data and patent rights.

https://www.dhs.gov/publication/security-training-contract-policy https://www.dhs.gov/publication/security-training-contract-policy https://www.nist.gov/privacy-framework/nist-sp-800-37 https://www.nist.gov/privacy-framework/nist-sp-800-37 https://www.nist.gov/privacy-framework/nist-sp-800-37

C.4.1.2 SECURITY

Contractor access to unclassified, but security sensitive information, may be required under this IDIQ contract. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination.

C.4.1.3 DHS ENTERPRISE ARCHITECTURE COMPLIANCE

All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the Contractor shall comply with the following HLS EA requirements:

1. All developed solutions and requirements shall be compliant with the HLS EA;

2. All IT hardware and software shall be compliant with the HLS EA Technical Reference

Model (TRM) Standards and Products Profile;

3. Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Mobius;

4. Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines;

5. Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

The Contractor shall utilize and adhere to the DHS Enterprise Security Architecture to the best of its ability and to the satisfaction of the Government. Areas of consideration could include:

1. Use of multi-tier design (separating web, application and data base) with policy enforcement between tiers;

2. Compliance to DHS Identity Credential Access Management (ICAM);

3. Security reporting to DHS central control points (i.e. the DHS Security Operations Center

(SOC) and integration into DHS Security Incident Response;

4. Integration into DHS Change Management (for example, the Infrastructure Change

Control Board (ICCB) process);

5. Performance of activities per continuous monitoring requirements

The Contractor shall participate in DHS’s Continuous Monitoring Strategy and methods, or shall provide a Continuous Monitoring capability that DHS determines acceptable. The DHS Chief Information Security Officer (CISO) issues annual updates to its Continuous Monitoring requirements via the Annual Information Security Performance Plan. At a minimum, the Contractor shall implement and maintain the following processes in accordance with the NIST

Special Publication 800-137 Information Security Continuous Monitoring for Federal Information Systems and Organizations (https://csrc.nist.gov/publications/detail/sp/800-137/final):

1. Asset Management

2. Vulnerability Management

3. Configuration Management

4. Malware Management

5. Log Integration

6. Security Information Event Management (SIEM) Integration

7. Patch Management

8. Provide application event logs to the DHS SOC

9. Near-real-time security status updates to the DHS Security Operations Center (SOC)

The Contractor shall comply with requests to be audited and provide responses within three (3) business days to requests for data, information, and analysis from DHS and any applicable Component COR. The Contractor shall provide support during the audit activities and efforts.

These audit activities may include, but are not limited to, the following: requests for system access for penetration testing, vulnerability scanning, incident response and forensic review.

C.4.1.4 DHS APPLICATION ARCHITECTURE COMPLIANCE

The Contractor shall ensure that the application is designed and developed for browser independence (i.e., the application will generally work with any of the major browsers). DHS HQ currently uses Microsoft Edge (Version 105.0.1343.50 (Official build) (64-bit)) configured with numerous Group Policy Objects (GPOs) as well as Firefox (102.3.0esr (64-bit)), similarly, secured with centrally managed security policies. Browser specific implementations or limitations on browser independence shall be approved in writing by DHS OCIO prior to development. Web Applications should be designed utilizing a responsive web design (RWD) approach, to provide an optimal viewing and interaction experience, independent of that particular platform capabilities the end user is utilizing. If DHS OCIO upgrades to a newer version of Microsoft Edge or Firefox, the Contractor shall ensure the application is compatible with the future version.

C.4.1.5 DHS OPEN-SOURCE COMPLIANCE

The Contractor shall follow the DHS Reusable and Open-Source Software Policy Directive (Policy Directive 142-04) when evaluating any technologies, tools, software, and/or application programmable interfaces (APIs) to support a system.

C.4.1.6 FEDRAMP CERTIFICATION COMPLIANCE

As prescribed therein DHS Policy Directive 4300A, Information Technology System Security Program, Sensitive Systems, the Contractor’s enterprise architecture shall be hosted on a FedRAMP authorized, cloud-based software as a solution (SaaS), or in one of the DHS cloud-based environments. At a minimum, the Contractor’s enterprise architecture shall have a moderate impact level.

C.4.1.7 CYBER-SUPPLY CHAIN RISK MANAGEMENT (C-SCRM)

https://csrc.nist.gov/publications/detail/sp/800-137/final

“Gray-Market” Equipment

i. The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the Contracting Officer (CO). The Contractor shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts shall be OEM parts.

ii. The Contractor shall be excused from using new OEM (i.e., "gray market”, "previously used”) parts only with formal Government approval, in writing, from the IDIQ CO. Such parts shall be procured from their original source and shipped only from the manufacturer’s shipment points.

iii. All equipment and parts obtained by the Contractor on behalf of the Government shall be provided to the DHS COR for DHS OCIO review and approval to validate requirements and approve the manufacturer or provider.

a. Hardware and Software Requests

i. The Contractor supplies the Government with hardware and software and shall provide the manufacturer’s name, address, state, and/or domain of registration, and the DUNS number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNS number of those suppliers shall be provided.

ii. Subcontractors are subject to the same general requirements and standards as the Prime

Contractor. Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.

iii. The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.

1. For software products, the Contractor shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “End of Life (EoL)"). Software updates and patches shall be either: made available to the Government for all products procured under this IDIQ contract, replaced upon End of Support (EoS) is reached, or formally waived (in writing) by the IDIQ CO.

b. Supply-Chain Transport

i. The Contractor shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.

ii. All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the IDIQ contract, the period of performance, or one calendar year from the date the activity occurred.

iii. This transit process shall minimize the number of times enroute components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments. The supplier, at the Government's request, shall be able to provide shipping status at any time during transit.

iv. All records pertaining to the transit, storage, and delivery shall be readily available for inspection by any agent designated by the Government as having the authority to examine them.

v. The Contractor is fully liable for all damage, deterioration, or losses incurred during shipping and handling, unless the damage, deterioration, or loss is due to the Government.

vi. The Contractor shall provide a packing slip, which shall accompany each container or package with the information identifying the contract number, the task order number, a description of the hardware/software enclosed (manufacturer name, model number, serial number), and the customer point of contact.

vii. The Contractor shall send a shipping notification to the intended government recipient;

with a copy transmitted via email to the IDIQ CO, or designated representative. This shipping notification shall be sent electronically and will state the contract number, the task order number, a description of the hardware/software being shipped (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.

c. Notifications

i. The Contractor shall notify the IDIQ PM, IDIQ CO, IDIQ COR, the DHS OCIO, and the DHS Component CIO through the Enterprise Security Operations Center (ESOC) directly of any suspected or potential violations of Section 889 of the National Defense Authorization Act (NDAA) for Information Communications Technology (ICT) at NDAA_Incidents@hq.dhs.gov.

d. Foreign Equities

The Contractor shall immediately notify the IDIQ PM, IDIQ CO, and IDIQ COR, who will report to the Office of the Chief Security Officer (OCSO), or cognizant component personnel security office, regarding any changes to corporate foreign ownership, control, or influence.

C.4.1.8 PROTECTION OF INFORMATION

Contractor access to information protected under the Privacy Act is required thereunder the IDIQ contract. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation.

mailto:NDAA_Incidents@hq.dhs.gov

C.4.2 TASK 2: INTAKE

C.4.2.1 HOURS OF OPERATION/CALL CENTER OPERATIONS

The Contractor shall provide 24-hours a day/7-days a week (24/7) access to EAP and Work-Life staff including master’s level, licensed employee assistance program clinicians via one centralized toll-free, dedicated telephone number issued to DHS. DHS Components may elect to have their own distinct toll-free, dedicated telephone number. Furthermore, DHS Components may port their existing dedicated toll-free phone lines to the Contractor, and the same provisions will remain. At the conclusion of the IDIQ contract, ownership of the toll-free telephone numbers/lines will be transferred to DHS.

The Contractor is responsible for ensuring that services are immediately accessible and responsive to employees. All calls shall be initially answered within fifteen (15) seconds and the Contractor shall manage the volume of calls to keep waiting time to less than one minute. Each call will be answered with a greeting tailored to the Component from which the call originates. The Contractor shall ensure that both OCONUS and CONUS employees can contact the EAP telephonically toll-free. During calls all warm transfer wait times to other counselors shall be kept under sixty (60) seconds.

The Contractor shall also provide access to all services through their website. The website will provide a means for employees and eligible family members to request a callback from the Contractor. The Contractor shall ensure that all requests through the website are responded to on the next business day, or within twenty-four hours of the request, whichever is sooner. The Contractor’s telecommunications infrastructure shall be capable of supporting additional call volume, due to surge in the event of a major disaster.

The Contractor shall make…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .