SOR-AWS-DHS-MTS Antenna Upgrade-20230822 RUIO-23-JW032 wc.docx
DOCX document 72 KB Posted
- Attached to
- AWARD - DHS Data Center 1 Support Services Federal contract opportunity
- Solicitation number
- 70RTAC21D00000002
About this file
This document is a Statement of Requirements (SOR) from the Department of Homeland Security for the repair and upgrade of a mobile tracking system antenna. The SOR establishes the minimum requirements for diagnosis, repair, and upgrade of the existing antenna to enable critical firmware updates, including replacement of hardware and renewal of the warranty. The scope includes repairing and upgrading the antenna to the MTS 2.0 standard by replacing major components and adding a new wiring harness compatible with a Silvus SC4200 mesh radio provided by the government. Delivery is required within 90 days of award, with products to be shipped to the Technology Service Corporation facility for repair and upgrade. The successful bidder must meet technical requirements for the repair and upgrade, and provide documentation including start and stop warranty dates, points of contact, and a quick reference guide. Invoicing and payment terms are also outlined.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sole Source Justification- MTS Antenna Upgrade-20230512 RUIO-23-JW032.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEPARTMENT OF HOMELAND SECURITY (DHS)
STATEMENT OF REQUIREMENTS (SOR)
FOR
MTS ANTENNA REPAIR AND UPGRADE
September 1, 2023
GENERAL
BACKGROUND
This requirement is for the repair and upgrade of a Technology Service Corporation (TSC) Mobile Tracking System (MTS) antenna. The government purchased the MTS tracking antenna in 2020. The MTS has been in operational use since with Customs and Border Protection – Air and Marine Operations (CBP-AMO) Manassas Air Branch. The MTS requires an upgrade and replacement of hardware to be able to accept critical firmware updates. The manufacturer will perform diagnosis, repair, and upgrade to allow for required updates.
This document establishes the minimum requirements for the equipment.
SCOPE
The scope of this requirement is the diagnosis of MTS and replacement of hardware to enable critical firmware updates. These items will assist CBP-AMO investigative and protective missions in the National Capital Region.
OBJECTIVE
The purpose of this effort is to deploy a fully functional mobile tracking antenna to extend the range of wirless video transmissions from CBP-AMO air assets. This document establishes the minimum requirements for the repair and upgrade and will result in a single award.
TASK OBJECTIVE/SCOPE OF WORK
The JWPMO AWS Program has a requirement for the following equipment:
| CLIN |
| Section |
| Description |
| Quantity |
MTS Antenna Repair and Upgrade
| 0001 |
| 3.1. |
| MTS Antenna Repair and Upgrade |
| 1 |
TECHNICAL REQUIREMENTS
The equipment requirements in this section define the minimum requirements for the equipment repair and upgrade to be procured under this delivery order.
MTS Antenna Repair and Upgrade
This requirement is to repair and upgrade an existing MTS antenna into an MTS 2.0 by repairing and saving major components from the original MTS antenna. The upgrade will include a new wiring harness for the Silvus SC4200 mesh radio. The upgrade will include a renewal of the TSC standard one-year factory warranty from the date of delivery of the upgraded unit. The government shall provide the Silvus SC4200 radio and the MTS antenna to the manufacturer for repair and upgrades..
OTHER APPLICABLE CONDITIONS
PLACE OF PERFORMANCE
The vendor shall perform the repair and upgrade at:
Technology Service Corporation 246 S. Meadow Rd.
Gate 6, Bldg. S-1 Plymouth, MA 02360
CONTRACTING OFFICER’S REPRESENTATIVE (COR)
The Contracting Officer has designated a COR to assist in monitoring the work under this Contract. The COR is responsible for the technical administration of the Contract and technical liaison with the successful vendor. The COR IS NOT authorized to change the scope of work or specifications as stated in the Contract, to make any commitments or otherwise obligate the Government or authorize any changes which affect the Contract price, delivery schedule, delivery period or other terms or conditions.
The Contracting Officer is the only individual who can legally commit or obligate the Government for the expenditure of public funds. The technical administration of this Contract shall not be construed to authorize the revision of the terms and conditions of this Contract. Any such revision shall be authorized in writing by the Contracting Officer.
Contracting Officer’s Representative (COR)
The following COR is designated as the Primary COR for this Contract and is responsible for the day-to-day coordination of the Contract.
| Name: Ashley Gorham |
| Office: 771-200-6299 |
| Email: ashley.gorham@hq.dhs.gov |
CONTRACTING OFFICER’S (CO) AUTHORITY
A warranted Contracting Officer is the only person authorized to issue modifications to the Contract, approve changes in any of the requirements, or obligate funds. Notwithstanding any clause/provision contained elsewhere in this SOR, the authority to modify the Contract remains solely with the Contracting Officer. If the Contractor makes any Contract changes at the direction of any person other than the Contracting Officer, the change will be considered to have been made without authority and no adjustment will be made in the Contract to cover any increases in charges that may result. The Contracting Officer has the authority to perform any and all post-award functions in administering and enforcing the proposed Contract in accordance with its terms and conditions.
Name: Randy Dreyer Office: 202-967-1682 Email: Randy.Dreyer@hq.dhs.gov
This Contract will be administered on a day-to-basis by the following Contract Specialist:
Name: Antionette Walker Office: 202-796-1682 Email: Antionette.Walker@hq.dhs.gov
DELIVERY
Delivery shall not exceed ninety (90) days after the date of Contract award. Any lead times for equipment that may affect the ability of the vendor to comply with this delivery must clearly be defined in vendor proposal packages with dates of delivery. The vendor shall provide the equipment appropriately packaged and delivered to the following address:
Department of Homeland Security Attn:
Ashley Gorham 10501 Furnace Rd Mail Stop 5125 Lorton, VA 22709
771-200-6299 Ashley.gorham@hq.dhs.gov
GOVERNMENT ACCEPTANCE PERIOD
The COR will review deliverables prior to acceptance and provide the Contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.
The COR will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted proposal. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions.
The COR will have 15 business days to review deliverables and make comments. The Contractor shall have 10 business days to make corrections and redeliver.
All other review times and schedules for deliverables shall be agreed upon by the parties. The Contractor shall be responsible for timely delivery to Government personnel in the agreed upon review chain, at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to assure that the established schedule is maintained.
TERMS AND CONDITIONS
Certification by the Government of satisfactory products shall be contingent upon the vendor performing in accordance with the terms and conditions of the Contract. Acceptance by the Government of satisfactory products will be made once all the terms and conditions of the order are fulfilled including the following requirements:
INSPECTION AND ACCEPTANCE
For payment purposes, inspection and acceptance of all deliverables will be deemed to have been performed within 30 days of receipt of shipment documentation or other confirmation of receipt of delivery by the ordering entity. Acceptance of equipment from the vendor is only complete when all items are delivered and received by DHS AWS Joint JWPMO.
SHIPPING AND HANDLING
Delivery hours are from 8:00 a.m. – 3:00 p.m. Eastern Time Monday – Friday.
Pallet height may not exceed 60 inches, must be palletized, and arrive in shrink wrap to maintain the integrity of the pallet and ensure it has not been tampered with in-transit.
Product must contain adequate cushioning material to properly protect equipment during shipping. For odd-shaped items, wrap and tape all sharp edges or protrusions. The Contractor is fully liable for all damage, deterioration, or losses incurred during shipment and handling, unless the damage, deterioration, or losses are due to the fault of the Government.
All items must be stacked in an orderly fashion on the pallet organizing them into like-items.
Pallets utilized for shipping must be structurally sound and free of damage to the deck boards. Improper stacking of cartons on a pallet and utilization of degraded wood pallets will reduce the compression strength of the cartons loaded on the pallet and cause possible damage to the product.
A legible copy of the packing slip must accompany the shipment.
The vendor shall provide an inventory list with each item that identifies components, part number/serial number of items, and barcodes applied. A master inventory list will also be provided to the Government in electronic and paper form (Excel is preferred) for the completed shipment.
PRODUCT MARKING
The vendor shall provide a generic alphanumeric scheme (serial number) for marking. These markings shall be sufficient to track all devices for inventory and invoicing purposes. In no event shall devices be identifiable, regarding purpose or agency, through these markings to anyone but authorized users. A unique, identifiable, and visible serial number shall be permanently affixed to each device.
TECHNICAL
The vendor shall provide all necessary cables to power the device including AC power supplies.
Vendor shall ensure all items have been thoroughly inventoried, set up and tested prior to shipment.
Vendor shall provide the start and stop warranty dates and specific Points of Contact for service and maintenance (technical and warranty call center support contact numbers).
A quick reference guide or user manual will be provided with each system describing the unique functionality and quick setup instructions.
INVOICES AND PAYMENT PROVISIONS
Certification by the Government of satisfactory products and services shall be contingent upon the Contractor performing in accordance with the terms and conditions of the Contract. Acceptance by the Government of satisfactory services will be made once all the terms and conditions of the order are fulfilled.
The Contractor shall submit invoices. Contract Line Item Number (CLIN) and description for each billed item. Any additional backup information as required by this Contract. The Contractor shall send electronic invoices to MGTInvoice.Consolidation@ice.dhs.gov with a courtesy copy to the designated COR. Payment will be based on receipt of a proper invoice and satisfactory Delivery Order (DO) performance. The invoice is a “proper invoice” as defined under Federal Acquisition Regulations Clause 52.212-4.
A proper invoice must include the following items:
i. Name and address of the Contractor;
ii. Invoice date and number;
iii. Contract number, Contract line-item number and, if applicable, the order number;
iv. Description, quantity, unit of measure, unit price and extended price of the items delivered, if applicable;
v. Shipping number and date of shipment, including the bill of lading number and weight of shipment if shipped on Government bill of lading, if applicable;
vi. Terms of any discount for prompt payment offered;
vii. Name and address of official to whom payment is to be sent;
viii. Name, title, and phone number of people to notify in event of defective invoice; and
ix. Taxpayer Identification Number (TIN). The Contractor shall include its TIN on the invoice only if required elsewhere in this Contract.
x. Electronic funds transfer (EFT) banking information.
All invoices shall be submitted by the Contractor in electronic format via email. No other form of invoice submission will be accepted. Invoices shall be electronically submitted to the following addresses:
To: MGTInvoice.Consolidation@ice.dhs.gov
Cc: ashley.gorham@hq.dhs.gov
The subject line of the electronic mail message shall contain the following information:
Contractor Name, Contract/Task Order Number, and the Contractor’s Invoice Number.
Failure to comply with the procedures outlined may result in payment being delayed at no additional cost to the Government.
The Contractor shall submit invoices to the email addresses above. Additionally, the Contractor shall prepare and submit a sufficient and procurement regulatory compliant invoice and receiving report for technical certification of inspection/acceptance of services and approval for payment. The Contractor shall attach back up information to the invoices and receiving reports substantiating all costs for services performed. The receiving agency’s written or electronic acceptance by the COR and date of acceptance shall be included as part of the backup documentation.
If the invoice is submitted without all required back up documentation, the invoice shall be rejected. The Government reserves the right to have all invoices and backup documentation reviewed by the Contracting Officer prior to payment approval.
DISCLOSURE OF INFORMATION
Information furnished by the Contractor under this Contract may be subject to disclosure under the Freedom of Information Act (FOIA). Therefore, all items that are confidential to business, or contain trade secrets, proprietary, or personally-identifiable information must be clearly marked. Any information made available to the Contractor by the Government must be used only for the purpose of carrying out the requirements of this Contract and must not be divulged or made known in any manner to any person except as may be necessary in the performance of the Contract.
ADVERTISEMENTS, PUBLICIZING AWARDS, AND NEWS RELEASES
All press releases or announcements about agency programs, projects, and Contract awards need to be cleared by the Program Office and the Contracting Officer. Under no circumstances shall the Contractor, or anyone acting on behalf of the Contractor, refer to the supplies, services, or equipment furnished pursuant to the provisions of this Contract in any publicity newsrelease or commercial advertising without first obtaining explicit written consent to do so from the Program Office and the Contracting Officer.
GENERAL REPORT REQUIREMENTS
The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations/laptops (Microsoft Office 365 Applications).
SECTION 508 COMPLIANCE
Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. § 794d) as amended by P.L. 105-220 under Title IV (Rehabilitation Act Amendments of 1998) all Electronic and Information Technology (EIT) developed, procured, maintained and/or used under this Contract shall be in compliance with the “Electronic and Information Technology Accessibility Standards” set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in 36 CFR Part 1194. The complete text of Section 508 Standards can be accessed at http://www.access-board.gov/ or at http://www.section508.gov.
All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable EIT accessibility standards have been identified:
36 Code of Federal Regulations (CFR) 1194.21 Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.
36 CFR 1194.22 Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous JavaScript and XML (AJAX) then 1194.21 Software standards also apply to fulfill functional performance criteria.
36 CFR 1194.41 Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required 1194.31 Functional Performance Criteria, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.
Section 508 of the Rehabilitation Act (classified to 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use Information and Communications Technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.
All products, platforms and services delivered as part of this SOR that, by definition, are deemed ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Appendixes A, C & D, and available at https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5.
In the revised regulation, ICT replaced the term EIT used in the original 508 standards. ICT includes IT and other equipment.
SECTION 508 APPLICABLE EXCEPTIONS
Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COR and a determination will be made in accordance with DHS Management Directives (MD) 4010.2, DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018, and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018, or any successor publication. DHS has identified the following exceptions that may apply: 36 CFR 1194.3(b) Incidental to Contract, all EIT that is exclusively owned and used by the Contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those Contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.
SECTION 508 COMPLIANCE REQUIREMENTS
36 CFR 1194.2(b) (COTS/GOTS products), when procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meet some but not all of the standards, the agency must procure the product that best meets the standards. When applying this standard, all procurements of EIT shall have documentation of market research that identifies a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.
All tasks for testing of functional and/or technical requirements must include specific testing for Section 508 compliance, and must use DHS Office of Accessible Systems and Technology approved testing methods and tools. For information about approved testing methods and toolssend an email to accessibility@dhs.gov.
SECTION 508 REQUIREMENTS FOR TECHNOLOGY SERVICES
When developing or modifying ICT, the Contractor is required to validate ICT deliverables for conformance to the applicable Section 508 requirements. Validation shall occur on a frequency that ensures Section 508 requirements is evaluated within each iteration and release that contains user interface functionality.
When modifying, installing, configuring or integrating commercially available or government-owned ICT, the Contractor shall not reduce the original ICT Item’s level of Section 508 conformance.
When developing or modifying electronic documents and forms provided in a Microsoft Office or Adobe PDF format, the Contractor shall demonstrate conformance to the applicable to the applicable Section 508 standards (including WCAG Level A and AA Level 2.0 Success Criteria) by conducting testing using the test methods published under “Accessibility Tests for Documents” at https://www.dhs.gov/compliance-test-processes.
Contractor personnel shall possess the knowledge, skills, and abilities necessary to address the accessibility requirements in this SOR.
SECTION 508 DELIVERABLES
Section 508 Test Plans: When developing or modifying ICT pursuant to this Contract, the Contractor shall provide a detailed Section 508 Conformance Test Plan. The Test Plan shall describe the scope of components that will be tested, an explanation of the test process that will be used, when testing will be conducted during the project development life cycle, who will conduct the testing, how test results will be reported, and any key assumptions.
Section 508 Test Results: When developing or modifying ICT pursuant to this Contract, the Contractor shall provide test results in accordance with the Section 508 Requirements for Technology Services provided in this solicitation.
Section 508 Accessibility Conformance Reports: For each ICT item offered through this Contract (including commercially available products, and solutions consisting of ICT that are developed or modified pursuant to this Contract), the Contractor shall provide an Accessibility Conformance Report (ACR) to document conformance claims against the applicable Section 508 standards. The ACR shall be based on the Voluntary Product Accessibility Template Version 2.0 508 (or successor versions). The template can be found at https://www.itic.org/policy/accessibility/vpat. Each ACR shall be completed by following all of the instructions provided in the template, including an explanation of the validation method used as a basis for the conformance claims in the report.
OTHER SECTION 508 DOCUMENTATION: THE FOLLOWING DOCUMENTATION SHALL BE PROVIDED UPON REQUEST FOR ICT ITEMS OFFERED THROUGH THIS CONTRACT:
(1) Documentation of features provided to help achieve accessibility and usability for people with disabilities.
(2) Documentation on how to configure and install the ICT Item to support accessibility.
(3) Documentation of core functions that cannot be accessed by persons with disabilities.
(4) Documentation of remediation plans to address non-conformance to the Section 508 standards
DHS Enterprise Architecture Compliance
All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the Contractor shall comply with the following Homeland Security (HLS) Enterprise Architecture (EA) requirements:
(1) All developed solutions and requirements shall be compliant with the Homeland Security (HLS) (EA).
(2) All IT hardware and software shall be compliant with the HLS EA Technical Reference Model (TRM) Standards and Products Profile.
(3) Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Architecture Division (EAD) for review, approval and insertion into the DHS Data Reference Model and Mobius.
(4) Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.
(5) Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement.
(6) All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.
Cyber-Supply Chain Risk Management (C-SCRM)
The Contractor understands and agrees that the Government retains the right to cancel or terminate the Contract, if the Government determines that continuing this solicitation presents an unacceptable risk to national security.
GRAY-MARKET EQUIPMENT
The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the DHS Contracting Officer. Contractors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.
The Contractor shall be excused from using new OEM (i.e., "gray market”, "previously used”) components only with formal Government approval, in writing, from the DHS Contracting Officer. Such components shall be procured from their original source and shipped only from the manufacturer’s authorized shipment points.
All equipment obtained by the Contractor on behalf of the Government will need to be provided to Office of the Inspector General (OIG) Office Chief Information Officer (CIO) for review to validate requirements and approved Contractors by DHS.
HARDWARE AND SOFTWARE REQUESTS
The Contractors supply the Government hardware and software will provide the manufacturer’s name, address, state, and/or domain of registration, and the DUNS number for all components comprising the hardware and software. If Sub-Contractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNS number of those suppliers must be provided.
Sub-Contractors are subject to the same general requirements and standards as prime Contractors. Contractors employing Sub-Contractors will perform due diligence to ensure that these standards are met.
The Government shall be notified when a new Contractor/Sub-Contractor/Service Provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.
For software products, the Contractor shall provide all Original Equipmnet Manufacturer (OEM) software updates to correct defects for the life of the product (i.e., until the “End of Life (EoL)"). Software updates and patches shall be either: made available to the government for all products procured under this Contract, replaced upon End of Support (EoS) is reached, or formally waived (in writing) by the DHS Contracting Officer.
SUPPLY-CHAIN TRANSPORT
Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill Contract obligations with the Government.
All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the Contract, the Period of Performance, or one calendar year from the date the activity occurred.
This transit process shall minimize the number of times in route components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments. The supplier, at the Government's request, shall be able to provide shipping status at any time during transit.
All records pertaining to the transit, storage, and delivery shall be readily available for inspection by any agent designated by the U.S. Government as having the authority to examine them.
The Contractor is fully liable for all damage, deterioration, or losses incurred during shipping and handling, unless the damage, deterioration, or loss is due to the Government.
The Contractor shall provide a packing slip which shall accompany each container or package with the information identifying this solicitation number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact.
The Contractor shall send a shipping notification to the intended government recipient; with a copy transmitted via email to the Contracting Officer, or designated representative. This shipping notification shall be sent electronically and will state this solicitation number, the order number, a description of the hardware/software being ship (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.
NOTIFICATIONS
The Contractor shall notify DHS Contracting Officer, COR and the Office of the Chief Information Officer and the DHS component Chief Information Officer through the Enterprise Security Operations Center (ESOC) directly of any suspected or potential violations of Section 889 of the National Defense Authorization Act (NDAA) for Information Communications Technology (ICT) at NDAA_Incidents@hq.dhs.gov.
FOREIGN EQUITIES
The Contractor shall immediately notify the DHS Contracting Officer, COR that will report to the Office of the Chief Security Officer (OCSO) or cognizant component personnel security office regarding any changes to corporate foreign ownership, control, or influence.
PROTECTION OF INFORMATION
Contractor access to information protected under the Privacy Act may be required under this Contract. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and government policy and regulation.
Contractor access to proprietary information is required under this Contract. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with DHS MD 11042.1, Safeguarding Sensitive but Unclassified (For Official Use Only) Information. The Contractor shall ensure that all Contractor personnel having access to business or procurement sensitive information sign a non-disclosure agreement (DHS Form 11000-6).
SECURITY
COMPLIANCE WITH DHS SECURITY POLICY
All hardware, software, and services provided under this task order must be compliant with DHS Sensitive Systems Directive 4300A version 13.2 20 September, 2022.
If encryption is required, the following methods are acceptable for encrypting sensitive information:
· FIPS 197 (Advanced Encryption Standard (AES)) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2.
· National Security Agency (NSA) Type 2 or Type 1 encryption.
· Public Key Infrastructure (PKI) (see paragraph 5.5.2.1 of the Department of Homeland Security IT Security Program Handbook (DHS Management Directive (MD) 4300A for Sensitive Systems).
SECURITY MANAGEMENT
The Contractor shall appoint a senior official to act as the Corporate Security Officer. The individual will interface with the Security Office through the COR on all security matters, to include physical, personnel and protection of all government information and data accessed by the Contractor.
The COR and the Security Office shall have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements under this Contract. Should the COR determine that the Contractor is not complying with the security requirements of this Contract; the Contractor will be informed in writing by the Contracting Officer of the proper action to be taken in order to effect compliance with such requirements.
NON-DISCLOSURE OF PROTECTED CRITICAL INFRASTRUCTURE INFORMATION
The parties agree to implement an interim rule promulgating new regulations at Title 6 Code of Federal Regulations Section 29.8 (c) to govern procedures for handling critical infrastructure information. The regulations detailed in the interim rule, which was effective upon publication pursuant to Section 808 of the Congressional Review Act, were promulgated pursuant to Title II, Section 214 of the Homeland Security Act of 2002, known as the Critical Infrastructure Information Act of 2002 (CII Act).
The Contractor shall comply with all requirements of the Protected Critical Infrastructure Information (PCII) Program set out in the CII Act, in the implementing regulations published in the Interim Rule, and in the PCII Procedures Manual as they may be amended from time to time and shall safeguard Protected CII in accordance with the procedures contained therein.
The Contractor shall ensure that each of its employees, consultants and Sub-Contractors who work on the PCII Program have executed NDAs in a form prescribed by the PCII Program Manager. The Contractor shall ensure that each of its employees, consultants and Sub-Contractors has executed an NDA and agrees that none of its employees, consultants or Sub-Contractors will be given access to Protected CII without having previously executed an NDA.
SECURITY REVIEW
The government may elect to conduct periodic reviews to ensure that the security requirements contained in this Contract are being implemented and enforced. The Contractor shall afford DHS, including the organization of the DHS Office of the Chief Information Officer (OCIO), the Office of the Inspector General (OIG), authorized COR, and other government oversight organizations, access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this Contract. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to the DHS. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of DHS data or the function of computer systems operated on behalf of DHS, and to preserve evidence of computer crime.
ACCESS TO UNCLASSIFIED FACILITIES, INFORMATION TECHNOLOGY RESOURCES, AND SENSITIVE INFORMATION
Contractor access to unclassified but Security Sensitive Information may be required under this SOR. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination.
The assurance of the security of unclassified facilities, Information Technology (IT) resources, and sensitive information during the acquisition process and Contract performance are essential to the DHS mission. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive But Unclassified (For Official Use Only) Information, describes how Contractors must handle sensitive but unclassified information. DHS MD 4300.1 Information Technology Systems Security and the DHS Sensitive Systems Directive 4300A version 13.2 20 September, 2022 prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering Contractors specifically for all Task Orders that require access to DHS facilities, IT resources or sensitive information. Contractors shall not use or redistribute any DHS information processed, stored, or transmitted by the Contractor except as specified in the Task Order.
PROMOTING THE USE OF TRUSTWORTHY ARTIFICIAL INTELLIGENCE IN THE FEDERAL GOVERNMENT
Principles for Use of Artificial Intelligence (AI) in Government. When designing, developing, acquiring, and using AI in the Federal Government, agencies shall adhere to the following Principles:
(a) Lawful and respectful of our Nation's values. Agencies shall design, develop, acquire, and use AI in a manner that exhibits due respect for our Nation's values and is consistent with the Constitution and all other applicable laws and policies, including those addressing privacy, civil rights, and civil liberties.
(b) Purposeful and performance-driven. Agencies shall seek opportunities for designing, developing, acquiring, and using AI, where the benefits of doing so significantly outweigh the risks, and the risks can be assessed and managed.
(c) Accurate, reliable, and effective. Agencies shall ensure that their application of AI is consistent with the use cases for which that AI was trained, and such use is accurate, reliable, and effective.
(d) Safe, secure, and resilient. Agencies shall ensure the safety, security, and resiliency of their AI applications, including resilience when confronted with systematic vulnerabilities, adversarial manipulation, and other malicious exploitation.
(e) Understandable. Agencies shall ensure that the operations and outcomes of their AI applications are sufficiently understandable by subject matter experts, users, and others, as appropriate.
(f) Responsible and traceable. Agencies shall ensure that human roles and responsibilities are clearly defined, understood, and appropriately assigned for the design, development, acquisition, and use of AI. Agencies shall ensure that AI is used in a manner consistent with these Principles and the purposes for which each use of AI is intended. The design, development, acquisition, and use of AI, as well as relevant inputs and outputs of particular AI applications, should be well documented and traceable, as appropriate and to the extent practicable.
(g) Regularly monitored. Agencies shall ensure that their AI applications are regularly tested against these Principles. Mechanisms should be maintained to supersede, disengage, or deactivate existing applications of AI that demonstrate performance or outcomes that are inconsistent with their intended use or this order.
(h) Transparent. Agencies shall be transparent in disclosing relevant information regarding their use of AI to appropriate stakeholders, including the Congress and the public, to the extent practicable and in accordance with applicable laws and policies, including with respect to the protection of privacy and of sensitive law enforcement, national security, and other protected information.
(i) Accountable. Agencies shall be accountable for implementing and enforcing appropriate safeguards for the proper use and functioning of their applications of AI, and shall monitor, audit, and document compliance with those safeguards. Agencies shall provide appropriate training to all agency personnel responsible for the design, development, acquisition, and use of AI.
File details come from the government source that posted it. Updated .