FY19 Enhanced Webinar SOW-7-10-19.docx

DOCX document 63 KB Posted

Attached to
Enhanced Webinar Federal contract opportunity
Solicitation number
70RNPP19Q00000043
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

SOW

View the file

Other files for this federal contract opportunity

Other files attached to Enhanced Webinar, newest first.
File Type Posted
Questions_and_Answers-__70RNPP19Q00000043-Enhanced_Webinar_Platform.pdf PDF
70RNPP19Q00000043.pdf PDF
Provisions and Clauses TM.docx DOCX document
RFQ_Enhanced Webinar Platform-Reissued-7-9-19.docx DOCX document
Price Template.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF HOMELAND SECURITY (DHS)

CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY (CISA)

STAKEHOLDER ENGAGEMENT AND CYBER INFRASTRUCTURE RESILIENCE (SECIR)

PARTNERSHIP AND ENGAGEMENT (P&E) BRANCH

STATEMENT OF WORK (SOW)

FOR

ENHANCED WEBINAR PLATFORM

1.0 GENERAL

1.1 BACKGROUND

The Stakeholder Engagement and Cyber Infrastructure Resilience (SECIR) Division, falls under Cybersecurity Division (CSD) within Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security (DHS). CISA provides cybersecurity resources to federal departments and agencies, owners and operators of critical infrastructure to include small and midsize businesses; and state, local, tribal, and territorial (SLTT) governments. Activities include a webinar series on various cybersecurity topics. The current webinar service available within DHS is provided by the Homeland Security Information Network (HSIN) via Adobe Connect. While this is a valuable resource for small scale webinars, the service is not currently scalable for a large sum of participants (over 500 attendees). A more robust enterprise service will need to be provided for SECIR Partnership and Engagement Branch (P&E) to minimize latency issues and other overarching capability gaps.

1.2 OBJECTIVE

The objective of this contract is to obtain consulting support services to execute and provide a webinar capability for SECIR/P&E that will meet or exceed the requirements listed in the specific tasks and requirements section of this statement of work (SOW).

1.4 APPLICABLE DOCUMENTS

There are no notable additional applicable documents associated with this procurement effort.

2.0 SPECIFIC REQUIREMENTS/TASKS

2.1 TASK ONE: Webinar Platform

The contractor shall provide webinar capability that will meet the requirements listed below:

· Ability to support 5,000+ simultaneous attendees for up to 3 webinars a month.

· 50,000-100,000 user hours per year required (scalable dependent upon webinars scheduled per Fiscal Year). Per consumption licensing requirements.

· Screen Sharing Capability

· Ability to add documents and content (logistical information, background materials, etc.) to display during the webinar.

· Host, presenter, and participant segregation and permissions.

· Ability to seamlessly support hosts at multiple locations

· Tech support to address issues that arise during presentations

· Close Captioning (CC) or transcription (Close Captioning Preferred)

· Participant list provided post webinar to the government

· The ability to create a customizable unique link for each webinar event.

· The ability to hide the participant list during the webinar but still have a host able to view the attendee count through the back end.

· Customizable survey polling of participants at the end of the webinar and easy extraction of polling results for analysis.

· The ability to duplicate the logistics of an existing webinar room.

· Ability of participants to “raise hand” and ask questions or provide comments, via either text or voice (chat feature).

2.2 TASK TWO: Recording Webinar

The contractor shall provide recording services for webinar platform as described in the requirements listed below:

· Delivery of compressed file post webinar to the government for re-play and re-use.

· Ability to record webinar with close captioning

· Ability to capture video recording of webinar

· Advanced Registration Capabilities

· Ability to create a custom link for the event and promotion of the event for marketing purposes.

· Ability to modify (add/edit/delete) specific field input types for registration as needed.

· Ability to add documents and content to the registration page for event attendees (logistical information, background materials, etc.).

· Event capacity management during registration

· Overflow/waitlist creation, if registration exceeds attendee cap.

· Ability to export registration data.

· Ability to perform surveys pre/post event.

· Ability to send registration confirmation emails, reminders, and calendar invites.

2.3 TASK THREE: Technical Support

The contractor shall provide remote tiered technical support for webinar platform as described in the requirements listed below:

· Provide support services related to technical issues running the webinar platform such as, but not limited to the following:

· Provide answers to technical questions related to the webinar platform.

· Provide guidance to webinar administrators as required for report generation, statistics, recording, event setup, authentication, Q&A, and transcripts.

· Ability to alternate to different streaming mechanisms in instances of event disruption.

· Remote professional services engineer to monitor events.

· Production/operator to provide introduction and closing, coordinate between panelists and participants, ensure event runs smoothly.

3.0 CONTRACTOR PERSONNEL

This procurement does not require contractor personnel support.

4.0 OTHER APPLICABLE CONDITIONS

4.1 SECURITY REQUIREMENTS

Webinar capability operates at the unclassified level. All users will be individually authenticated for each session. All personnel managing/operating the system shall be vetted by SECIR/P&E Manager.

4.2 PERIOD OF PERFORMANCE

The period of performance (POP) for this contract is a one-year base period with one (1) one-year option period as follows:

Base PeriodAugust 15, 2019 through August 14, 2020
Option Period OneAugust 15, 2020 through August 14, 2021

4.3 PLACE OF PERFORMANCE

The maintenance of the work will be conducted on-site at the DHS Wilson Blvd Facility. Maintenance of the server will be conducted offsite at a central maintenance facility or over the network from vendor’s network operations.

4.4 SECTION 508 COMPLIANCE

4.4.1 Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology (EIT), they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.

All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable EIT accessibility standards have been identified:

36 Code of Federal Regulations (CFR) 1194.21 Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.

36 CFR 1194.22 Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous JavaScript and XML (AJAX) then 1194.21 Software standards also apply to fulfill functional performance criteria.

36 CFR 1194.41 Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required 1194.31 Functional Performance Criteria, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.

4.4.2 Section 508 Applicable Exceptions

Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COR and a determination will be made in accordance with DHS Management Directives (MD) 4010.2. DHS has identified the following exceptions that may apply: 36 CFR 1194.3(b) Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.

4.4.3 Section 508 Compliance Requirements

36 CFR 1194.2(b) (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meets some but not all of the standards, the agency must procure the product that best meets the standards. When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.

All tasks for testing of functional and/or technical requirements must include specific testing for Section 508 compliance, and must use DHS Office of Accessible Systems and Technology approved testing methods and tools. For information about approved testing methods and tools send an email to accessibility@dhs.gov.

4.4.4 Section 508 Compliance Requirements

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) (codified at 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.

1. All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT or that contain ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps. A, C & D, and available at https://www.gpo.gov/fdsys/pkg/CFR-2017-title36-vol3/pdf/CFR-2017-title36-vol3-part1194.pdf. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards.

· Item that contains Information and Communications Technology (ICT): Enhanced Webinar Platform

· Applicable Exception: N/A Authorization #: N/A

· Applicable Functional Performance Criteria: All functional performance criteria in Chapter 3 apply to when using an alternative design or technology that results to achieve substantially equivalent or greater accessibility and usability by individuals with disabilities than would be provided by conformance to one or more of the requirements in Chapters 4 and 5 of the Revised 508 Standards, or when Chapters 4 or 5 do not address one or more functions of ICT.

· Applicable 508 requirements for software features and components (including Software infrastructure): All requirements in Chapter 5 apply, including all WCAG Level AA Success Criteria, 502 Interoperability with Assistive Technology, 503 Application

· Applicable 508 requirements for hardware features and components: Does not apply

· Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply

2. When providing installation, configuration or integration services for ICT, the contractor shall not reduce the original ICT item’s level of Section 508 conformance prior to the services being performed.

3. When providing maintenance upgrades, substitutions, and replacements to ICT, the contractor shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement. The agency reserves the right to request an Accessibility Conformance Report (ACR) for proposed substitutions and replacements prior to acceptance. The ACR should be created using the on the Voluntary Product Accessibility Template Version 2.2 508 (or later). The template can be located at https://www.itic.org/policy/accessibility/vpat

4. Contractor personnel shall possess the knowledge, skills and abilities necessary to address the applicable revised Section 508 Standards for each ICT.

5. Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated January 29, 2016 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated January 11, 2017.

6. Where ICT conforming to one or more requirements in the Revised 508 Standards is not commercially available, the agency shall procure the ICT that best meets the Revised 508 Standards consistent with the agency’s business needs, in accordance with 36 CFR E202.7. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated January 29, 2016 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated January 11, 2017 and 36 CFR E202.6.

5.0 GOVERNMENT TERMS & DEFINITIONS

ACRONYM
DEFINITION
CISA
Cybersecurity and Infrastructure Security Agency
CO
Contracting Officer
COR
Contracting Officer’s Representative
CSD
Cybersecurity Division
DHS
Department of Homeland Security
NS/EP
National Security and Emergency Preparedness
P&E
Partnership and Engagement
SECIR
Stakeholder Engagement
SOW
Statement of Work

6.0 GOVERNMENT FURNISHED RESOURCES

The Government will in support of this contract will provide all hardware, software, labor and other direct cost activities related to the maintenance and upkeep of the webinar platform.

7.0 CONTRACTOR FURNISHED PROPERTY

Not applicable. The Contractor shall furnish all facilities, materials, equipment and services necessary to fulfill the requirements of this contract, except for the Government Furnished Resources specified in SOW 2.0 and SOW 6.0.

8.0 GOVERNMENT ACCEPTANCE PERIOD

The COR will review deliverables prior to acceptance and provide the contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.

The following is the acceptance criteria:

1. Before accepting items that contain Information and Communications Technology (ICT) that are developed, modified, or configured according to this contract, the government reserves the right to require the contractor to provide the following:

· Accessibility test results based on the required test methods.

· Documentation of features provided to help achieve accessibility and usability for people with disabilities.

· Documentation of core functions that cannot be accessed by persons with disabilities.

· Documentation on how to configure and install the ICT Item to support accessibility.

· Demonstration of the ICT Item’s conformance to the applicable Section 508 Standards, (including the ability of the ICT Item to create electronic content – where applicable).

2. Before accepting ICT required under the contract, the government reserves the right to perform testing on required ICT items to validate the offeror’s Section 508 conformance claims. If the government determines that Section 508 conformance claims provided by the offeror represent a higher level of conformance than what is actually provided to the agency, the government shall, at its option, require the offeror to remediate the item to align with the offeror’s original Section 508 conformance claims prior to acceptance.

9.0 DELIVERABLES

The Contractor shall consider items in BOLD as having mandatory due dates.

ITEM
SOW REFERENCE
DELIVERABLE / EVENT
DUE BY

DISTRIBUTION

1
Section 2.1
Webinar Service
15 days after contract award
COR and Contracting Officer
2
Section 2.2
Webinar Recording
Performed as required
COR and Contracting Officer

10.0 INVOICING AND PAYMENT

All invoices must reflect the following mandatory information:

· Contract Number (Block 2 on OF-347)

· Order Number (Block 3 on OF-347 if applicable)

· Requisition Number (Block 4 on OF-347)

· CLIN(S)

· Description of Services for each CLIN

· Period of Performance

· Line(s) of Accounting and Funding Amount for each CLIN

· Total Invoice Amount Invoices can be mailed, emailed or faxed:

MAIL:

Department of Homeland Security 245 Murray Lane SW Bldg, 410 Attn: Toya Reynolds Washington, DC 20598

EMAIL:

Invoices can be emailed to the following email address. You must ensure you receive a dated confirmation of receipt that your email was received and the dated confirmation is the start of your clock for payment purposes.

Email address: NPPDInvoice.Consolidation@ice.dhs.gov

A copy of the invoice must also be sent to the CO and COR identified in Section 5 of this Order.

DHS POINTS OF CONTACT

Contracting Officer (CO) Toya Reynolds, Toya.reynolds@hq.dhs.gov;

Contract Specialist (CS) Elizabeth Entien, Elizabeth.entien@hq.dhs.gov;

Contracting Officer’s Representative (COR) Vandai Luong, Vandai.luong@hq.dhs.gov;

11.0 ENTERPRISE ARCHITECTURE COMPLIANCE TERMS and CONDITIONS

All solutions and services shall meet DHS Enterprise Architecture (EA) policies, standards, and procedures. Specifically, the contractor shall comply with the following Homeland Security (HLS) EA requirements:

· All developed solutions and requirements shall be compliant with the HLS EA.

· All IT hardware and software shall be compliant with the HLS EA Technical Reference Model (TRM) Standards and Products Profile.

· Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.

· Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

· Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

12.0 DHS IT SECURITY LANGUAGE

DHS 4300A Ver.12.01 Contractors and Outsourced Operations DHS 4300A Policy 3.3.a. - All Statements of Work (SOW) and contract vehicles shall identify and document the specific security requirements for information system services and operations required of the contractor.

DHS 4300A Policy 3.3.b. - All Contractor information system services and operations shall adhere to all applicable DHS information security policies.

DHS 4300A Policy 3.3.c. - Requirements shall address how sensitive information is to be handled and protected at contractor sites, including any information stored, processed, or transmitted using contractor information systems. Requirements shall also include requirements for personnel background I investigations and clearances, and facility security.

DHS 4300A Policy 3.3.d. SOWs and contracts shall include a provision stating that, when the contract ends, the contractor shall return all information and information resources provided during the life of the contract and certify that all DHS information has been purged from any contractor-owned system(s) that have been used to process DHS information.

DHS 4300A Policy 3.3.e. - Components shall conduct reviews to ensure that information security requirements are included in contract language and that the requirements are met throughout the life of the contract.

DHS 4300A Ver.12.01 3.12 Information Security Policy Violation and Disciplinary Action Individual accountability is a cornerstone of an effective security policy. Component Heads are responsible for taking corrective actions whenever security incidents or violations occur and for holding personnel accountable for intentional violations. Each Component must determine how to best address each individual case.

DHS 4300A Policy 3.12.a - Violations related to information security are addressed in Standards of Ethical Conduct for Employees of the Executive Branch; DHS employees may be subject to disciplinary action for failure to comply with DHS security policy whether or not the failure results in criminal prosecution.

DHS 4300A Policy 3.12.b. - Non-DHS Federal employees, contractors, or others working on behalf of DHS who fail to comply with Department security policies are subject to termination of their access to DHS systems and facilities whether or not the failure results in criminal prosecution.

DHS 4300A Policy 3.12.c - Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions.

DHS 4300A Ver. 12.01 4.1.2 Rules of Behavior DHS 4300A Policy 4.1.2.a - Components shall ensure that rules of behavior contain acknowledgement that the user has no expectation of privacy (a “Consent to Monitor” provision) and that disciplinary actions may result from violations.

DHS 4300A Policy 4.1.2.b - Components shall ensure that DHS users are trained regarding rules of behavior and that each user signs a copy prior to being granted user accounts or access to information systems or data.

DHS 4300A Ver.12.01 4.1.5 Information Security and Privacy Awareness, Training, and Education DHS 4300A Policy 4.1.5.a - Components shall establish an information security training program for users of DHS information systems.

DHS 4300A Policy 4.1.5.b - DHS personnel, contractors, or others working on behalf of DHS (i.e. employees, detailees, military) accessing DHS systems shall receive initial training and annual refresher training in security awareness and accepted security practices. Personnel shall complete security awareness training within twenty-four (24) hours of being granted a user account. If a user fails to meet this training requirement, user access shall be suspended.

DHS 4300A Policy 4.1.5.c - DHS personnel, contractors, or others working on behalf of DHS (i.e. employees, detailees, military) with significant security responsibilities (e.g., Information Systems Security Officers (ISSO), system administrators) shall receive initial specialized training and thereafter annual refresher training specific to their security responsibilities.

DHS 4300A Ver.12 4.2.1 General Physical Access DHS 4300A Policy 4.2.1.d - Visitors shall sign in upon entering DHS facilities that house information systems, equipment, and data. They shall be escorted during their stay and sign out upon leaving. Access by non-DHS contractors or vendors shall be limited to those work areas requiring their presence. Visitor logs shall be maintained and available for review for one (1) year.

DHS 4300A Ver.12.01 4.3.1 Media Protection DHS 4300A Policy 4.3.1.c - DHS personnel, contractors, and others working on behalf of DHS are prohibited from using any non-Government-issued removable media (USB drives and from connecting them to DHS equipment or networks or using them to store DHS sensitive information.

DHS 4300A Ver.12.01 4.8.5 Personal Use of Government Office Equipment and DHS Systems/Computers DHS 4300A Policy 4.8.5.c - Anyone granted user account access to any DHS information system (including DHS employees, contractors, and others working on behalf of DHS) shall have no expectations of privacy associated with its use. By completing the authentication process, the user acknowledges his or her consent to monitoring.

13.0. ACCOUNTABLE PROPERTY (There is no accountable property for this requirement.)

No Contractor Acquired Property (CAP) or Government Furnished Property (GFP) is to be procured or utilized in support of this procurement.

a.Contract property - All property, both real and personal, that is used in the performance of a contract, and includes facilities, material, special tooling, special test equipment, and agency-peculiar property. Contract property refers to both Contractor-Acquired Property (CAP) and GFP, in the possession of contractors.
b.Contractor Acquired Property (CAP) - Property acquired, fabricated, or otherwise provided by the contractor for performing a contract and to which the Government has title.
c.Government Furnished Property (GFP) - Property in the possession of, or directly acquired by, the Government and subsequently furnished to the contractor for performance of a contract. Government-furnished property includes, but is not limited to, spares and property furnished for repair, maintenance, overhaul, or modification. Government-furnished property also includes contractor-acquired property if the contractor-acquired property is a deliverable under a cost contract when accepted by the Government for continued use under the contract. NOTE: GFP may also be referred to as Government Furnished Equipment (GFE), the two terms are interchangeable.

14.0. OTHER REQUIREMENTS

14.1 For each commercially available Information and Communications Technology (ICT) item offered through this contract, the Offeror shall provide an Accessibility Conformance Report (ACR). The ACR shall be created using the Voluntary Product Accessibility Template Version 2.2 508 (or later). The template can be found at https://www.itic.org/policy/accessibility/vpat. Each ACR shall be completed in accordance with all the instructions provided in the VPAT template. Each ACR must address the applicable Section 508 requirements referenced in the Work Statement. Each ACR shall state exactly how the ICT meets the applicable standards in the remarks/explanations column, or through additional narrative. All “Supports”, “Supports with Exceptions”, “Does Not Support”, and “Not Applicable” (N/A) responses must be explained in the remarks/explanations column or through additional narrative. The offeror is cautioned to address each standard individually and with specificity, and to be clear whether conformance is achieved throughout the entire ICT Item (for example - user functionality, administrator functionality, and reporting), or only in limited areas of the ICT Item. The ACR shall provide a description of the evaluation methods used to support Section 508 conformance claims. The agency reserves the right, prior to making an award decision, to perform testing on some or all of the Offeror’s proposed ICT items to validate Section 508 conformance claims made in the ACR.

14.2 For each ICT Item that will be developed, modified, installed, configured, integrated, or hosted by the contractor pursuant to this contract, the offeror shall provide an acknowledgement of the Section 508 requirements and a detailed explanation of the Offerors plan to ensure conformance with the requirements. The Offeror shall also describe the evaluation methods that will be used to validate for conformance to the Section 508 Standards.

14.3 The offeror shall describe plans for features that do not fully conform to the Section 508 Standards.

15.0 SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause –

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual’s identity, such as name, Social Security Number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security Number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security Numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal history

(7) Medical information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by stature or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlines in NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete the PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any email. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Data Universal Numbering System (DUNS);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email);

(v) Contracting Officer POC (address, telephone, email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the Government PII and/or SPII contained within the system;

(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

(g) Sensitive Information Incident Response Requirements

(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.

(2)…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.