Attachment 5- SST Draft Curriculum Development SOW A00001.pdf
PDF 424 KB Posted
- Attached to
- Specialized Security Training Federal contract opportunity
- Solicitation number
- 70T01021R7670N004
About this file
This statement of work outlines curriculum development and training support services required by the Transportation Security Administration. Key details include developing and maintaining curricula for the TSA workforce across various topic areas such as screening procedures, leadership training, and regulatory compliance. The contractor must provide subject matter experts, project managers, instructional designers, and classroom instructors to support these efforts. Additional requirements involve maintaining existing curriculum, updating materials for changes to standard operating procedures, and developing new online and in-person courses on an as-needed basis in response to solicitations. The performance period is one base year with four option years. The solicitation number for this opportunity is 70T01021R7670N004.
View the file
Other files for this federal contract opportunity
Show all 26
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section II - Statement of Work (SOW)
1 Requiring Organization
The Government organization requiring the services described herein is as follows:
Department of Homeland Security Transportation Security Administration Training and Development,TSA-08 6595 Springfield Center Drive, Springfield, VA 20598-6008
2 Background
The Aviation and Transportation Security Act (ATSA), Public Law 107-71, requires the TSA to develop, implement, and manage training programs for the transportation security workforce. In compliance with ATSA, the TSA Training & Development (T&D) office is responsible for the analysis, design, development, implementation and evaluation (ADDIE) of training programs for employees, the transportation industry, and international partners. The focus of all training is to support and increase the TSA workforce technical expertise, professionalism, and engagement effectiveness. TSA’s Risk-Based Security environment must evolve to meet rapidly changing threats. TSA must be prepared to address and meet the demands of an increasingly complex operational environment with rapidly advancing technology, tight timelines, and budgetary constraints. TSA requires Contractor-provided curriculum development and maintenance support services for a diverse workforce and industry partners.
3 Scope of Work
The Contractor shall continue to provide curriculum and training support in accordance with the TSA MD
1900.14 Training Standards Handbook for the Transportation Security Administration (TSA) workforce within the Department of Homeland Security (DHS).
The contractor shall maintain, develop, and support the implementation of curricula, both established (planned) and new (driven by emerging threats) for TSA personnel and TSA industry partners. Examples of required training include, but are not limited to the following:
• Screening individuals entering and within the airport’s sterile area;
• Screening baggage and other items destined for an aircraft or airport’s sterile area;
• Checking travel documents in accordance with Standard Operating Procedures (SOP);
• Operating screening equipment, interpreting images and resolving alarms;
• Executing security activities on and off airport grounds;
• Leading and managing the operations/screening workforce;
• Enforcing compliance with Federal transportation security regulations;
• Preventing the introduction of explosive devices into the transportation system;
• Analyzing the behavior of passengers and all persons working and passing through the transportation environment to determine risk;
• Exhibiting professionalism and command presence in the conduct of TSA’s mission;
http://www.gpo.gov/fdsys/pkg/PLAW-107publ71/pdf/PLAW-107publ71.pdf
• Engaging and communicating with the traveling public and each other in a positive and professional manner;
• Conducting compliance investigations and enforcement actions;
• Performing compliance inspections and conducting assessments;
• Engaging in incident management response;
• Executing the TSA mission through teamwork and collaboration.
• General Training support
• Develop curriculum in accordance with the requirements of TSA’s Learning Management System
(e.g. Online Learning Center (OLC) or other designated Learning Management System (LMS), as required by TSA).
4 Place of Performance
Work shall be primarily performed at the Contractor’s facility. Travel to TSA headquarters in Springfield, VA may be required for meetings and briefings.
Performance of this Task Order (TO) may also take place at the TSA-Academy located in Glynco, GA and Charleston, SC, as well as other training locations and airports in the United States and its territories, as required by TSA.
5 Period of Performance
One (1) 12-month base period Four (4) 12-month option periods
6 Performance Requirements
6.1 Post-Award Conference
6.1.1 The Post-Award conference will cover the terms and conditions of the TO, contract administration, and other administrative concerns.
6.1.2 The Post-Award Conference is to be held no later than two (2) weeks (10 business days), after the date of TO award. The Contractor will be contacted by the Contract Specialist (CS) or the Contracting Officer’s Representative (COR) to coordinate the Post-Award Conference.
6.2 Deliverable Requirements
6.2.1 Unless otherwise specified, the Contractor shall submit deliverables in the format specified in the
Deliverable Table, Section 14. Electronic copies of deliverables, including all final versions of courseware, must have read/write capability unless otherwise requested. For resultant deliverables that are not identified in the deliverable schedule, the Contractor shall submit an electronic copy of the deliverable in a format agreed upon by both parties. Electronic copies shall be delivered via TSA’s designated repository for curriculum file development, or as otherwise directed by TSA.
The electronic copy shall be compatible with TSA computer workstations, requiring, at a minimum, Adobe PDF and Microsoft Office Suite application or a format for digital storage mutually agreed upon by TSA and the Contractor. The Contractor shall successfully complete and submit products in accordance with the requirements of each task. All source files including individual components, such as images and videos, shall be submitted with each final deliverable.
Source files for “working” or draft deliverables may be requested by TSA.
6.2.2 Review and acceptance will be conducted in accordance with the Indefinite Delivery, Indefinite
Quantity (IDIQ).
6.2.3 The COR and Government Project Lead will review deliverables prior to acceptance and provide the Contractor with email notification of acceptance, acceptance with comments, or rejection.
6.3 Non-Disclosure Agreements
6.3.1 Contractor employees, prior to beginning work, shall sign a non-disclosure agreement to be furnished to the Contracting Officer (CO) and COR.
6.4 DHS and TSA Security Requirements
6.4.1 See Specialized Security Training (SST) Base IDIQ.
6.5 Sensitive Security Information (SSI), Personally Identifiable Information (PII), and Incident Response
6.5.1 Contractor access to classified information is not currently required under this effort. However, during performance, it may be necessary for the Contractor to handle sensitive or proprietary information pertinent to TSA’s operations, which must be handled in accordance with TSA’s applicable policies and procedures. Please reference the Base IDIQ (DHS and TSA Enterprise Architecture Compliance), H.23 5200.224.002 Controlled Unclassified Information Data Privacy and Protection, TSA Management Directive 2810, and H.30 2500.224.001 Security of Systems Handling PII and Privacy Incident Response.
6.6 Government Service Location Requirements
6.6.1 This effort may require the Contractor to perform at various TSA sites. While Contractor personnel are at the Government site, they shall comply with all rules and regulations in effect at that site.
6.6.2 The Contractor shall not connect its privately-owned portable computers to the TSA local area network, nor may it use TSA’s voice over internet protocol telephone system to connect its portable computers to its home office(s).
6.7 Compliance with Service Contract Labor Standards
6.7.1 This TO is subject to the provisions of 41 U.S.C. chapter 67, Service Contract Labor Standards
(formerly known as the Service Contract Act of 1965). Compliance with the applicable Department of Labor’s Wage Determinations is required.
6.8 Curriculum Development and Maintenance Software Solution
6.8.1 The Contractor shall use approved software in accordance with TSA Office of Information
Technology’s list of approved software.
6.8.2 All Curriculum Development software licenses procured under this contract shall be transferable upon contract close to successor contractors.
6.9 The date, time, method, and location for project meetings is to be agreed upon between the
Government COR and the Contractor. The Contractor shall indicate its proposed preferred method for the meetings as part of its proposal; however, the Government may change the method, day, location or time based on changing mission requirements and schedule constraints.
6.10 Intellectual Property
6.10.1 Intellectual property shall be handled in accordance with the relevant clauses in the Base SST
IDIQ contract, including Federal Acquisition Regulation (FAR) clauses 52.227-3, 52.227-11, 52.227-14, 52.227-16, and 52.227-17. As such, all associated documentation, including reports, curriculum, etc., created by the Contractor under this TO shall become the property of the TSA.
No proprietary markings shall be on any deliverables submitted to TSA.
6.11 Government Furnished Information (GFI)
Government Furnished Information shall be handled in accordance with the following:
• Aviation and Transportation Security Act, P.L. 107-71, 49 U.S.C. 44940 https://www.gpo.gov/fdsys/pkg/PLAW-107publ71/content-detail.html
• Transportation Security Administration Management Directive No. 3100.1
7 Contractor Personnel Requirements
7.1 The Contractor’s Curriculum Project Manager is designated as key personnel, and shall act as the central point of contact (POC) with the Government for all technical and management issues, and will represent the Contractor at all TO-level post award status meetings. The Project Manager shall be responsible for all TO-level issue resolution, project management, and other contract support including providing comprehensive curriculum support for the SST contract. The Curriculum Project Manager is responsible for overall Curriculum TO performance.
7.2 All labor proposed for the requirements defined herein shall meet the labor qualifications described in the SST base IDIQ contract. The Government may request the résumé of any support personnel to verify that personnel meet the qualified personnel requirements described herein. The Contractor shall provide qualified personnel in sufficient numbers to meet the requirements of this Statement of Work (SOW). Personnel must be adequately trained to perform the functions necessary to meet the requirements of this SOW.
7.3 Project Manager
7.3.1 The Contractor shall provide a Project Manager(s) who shall be responsible for all Contractor work performed under this SOW.
7.3.2 The Project Manager shall be a single POC for the CO and the COR. It is anticipated that the
Project Manager shall be one of the senior level employees provided by the Contractor for work performed under this SOW. The name of the Project Manager, and the name(s) of any alternate(s) https://www.gpo.gov/fdsys/pkg/PLAW-107publ71/content-detail.html who shall act for the Contractor in the absence of the Project Manager, shall be provided to the Government as part of the Contractor's proposal.
7.3.3 During any absence of the Project Manager, the designated alternate(s) shall have full authority to act for the Contractor on all oversight matters relating to work performed under this SOW.
7.3.4 The Contractor shall not replace the Project Manager without prior acknowledgement from the CO.
7.3.5 The Project Manager shall be available to the COR via telephone between the hours of 0800 and
1700 EST Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 2 hours of notification.
7.4 Security Training and Integration Analyst (STIA)
7.4.1 Any STIAs proposed shall meet the following requirements: support research, development, operations, and process improvement; provide in-depth knowledge of a specialized field operations (for example: statistics, human factors, data mining, or operations) as it relates to security training and technology; apply unique skills, knowledge, insight and capability to solve complex problems.
7.4.2 Subject Matter Expert (SME) Labor Categories, shall NOT be utilized for any work for this TO.
7.4.3 In addition to the requirements, the following experience shall be collectively represented within the proposed STIA workforce:
• Expertise in Checkpoint Screening Training, including all associated policies and procedures;
• Expertise in Checked Baggage Screening Training, including all associated policies and procedures;
• Expertise in Technology / Equipment and Technology / Equipment Training, including all associated policies, procedures, and Original Equipment Manufacturer (OEM) Training;
• Expertise in conducting investigations and determining enforcement actions;
• Collaborative and professional communications Critical Thinking Skills, Conflict Resolution, Leadership, Teambuilding and Command Presence; Diversity and Inclusion
7.4.4 The Contractor shall incorporate the STIA(s) as approved and appropriate, throughout project planning and at every stage of the Project Plan. STIA(s) shall be included in the curriculum development process and concurrently during each phase of the TSA Training Standards (TS) efforts for each deliverable, as approved by TSA. Level of effort (LOE) for STIA(s) will be approved by the COR for each project.
7.4.5 The Contractor shall be responsible for STIA recurrent training and certification requirements;
7.4.6 STIAs may be utilized as instructors, following completion of the TSA Instructor Development
Course (IDC) and obtaining course instruction qualification/Train-the-Trainer (T3). STIAs are to be used as instructors only when approved by TSA.
7.5 Classroom Instructors
7.5.1 The number of instructors required for each new project will be proposed by the Contractor and approved by the COR. TSA may also prescribe the number of required instructors for training deliveries. All classroom instructors shall meet requirements listed in the SST base IDIQ Contract, TSA Academy SOP 500.4-10 Instructor Certification and Qualification, and/or TSA MD 1900.XX Instructor Standards Quality Assurance Program Handbook (will be provided upon award), as applicable.
8 New Curriculum Design & Development, Maintenance of Existing Curriculum, and T&M
Management
8.1 Curriculum Development requirements will be issued by the COR as Requests for Quote (RFQ) for Time & Materials (T&M) Work.
8.2 For determining the NTE amount of the T&M Contract Line Item Number (CLIN), the
Contractor shall develop an estimate on the basis of new curriculum design and development for 30 courses annually as follows:
• Ten (10) virtual instructor led training
• Ten (10) instructor led in-person highly engaging/interactive training
• Five (5) Level 1 and 2 Interactive Multimedia Instruction (IMI) training
• Five (5) Level 3 IMI training
8.3 For determining the NTE amount of the T&M CLIN, the Contractor shall develop an estimate on the basis of maintenance for 30 courses annually as follows:
• Ten (10) virtual instructor led training
• Ten (10) instructor led in-person highly engaging/interactive training
• Five (5) Level 1 and 2 IMI training
• Five (5) Level 3 IMI training
8.4 The Contractor’s response to an RFQ shall include at a minimum a draft project plan inclusive of schedule, a LOE by proposed labor categories and costs. The Contractor is not authorized T&M labor to respond to TSA’s RFQ (such costs shall be included in the Contractor’s firm fixed price, Program Management Support TO). TSA’s approval of T&M quotes will include a not-to-exceed ceiling (also referred to as a Project Budget) with accepted IDIQ labor categories and their approved IDIQ rates. Quotes will be approved per project. Contractor personnel are permitted to work on multiple T&M projects as long as they meet the labor category requirements for each particular project. Project Plans will be considered ‘Final’ upon TSA’s approval and will be updated as the project proceeds.
8.5 The Contractor shall identify the industry standard development process phase to which each
Work Breakdown Structure (WBS) element pertains, for example, the Analysis, Design, Development, Implementation, or Evaluation phase. If phases are omitted (e.g. Analysis) or completed by the government, the contractor shall identify and document what has been completed and/or waived by the government.
8.6 The Contractor shall develop web based courses in accordance with the Online Learning
Center’s (OLC) Content Integration Guide. (Attachment will be provided upon award)
8.6.1 The OLC is externally hosted by SuccessFactors and utilized by TSA through a perpetual license agreement. SuccessFactors has full ownership over the rights of the application, and the source code is not available to their clients. Online training developed by the Contractor must be fully functional with TSA’s OLC vendor solution and developed in accordance with the OLC Content Integration Guide.
8.7 The Contractor shall only be responsible for Training Standard deliverables specified in project
RFQs.
8.8 This RFQ process follows the established TSA internal process for establishing an appropriate Project Budget or LOE for each T&M-related project.
8.9 Curriculum Development training topics shall include, but are not limited to, the following:
• Technical and procedural training;
• Threat detection;
• Leadership development;
• Professional development training;
• Canine workforce training;
• Regulation authority and their interpretations;
• Transportation regulatory abidance including: aviation, cargo, and surface.
8.10 The Contractor shall provide questions within two (2) business days from receipt of RFQ.
8.10.1 The Contractor shall provide an updated project schedule for each curriculum project following its kick-off meeting, in accordance with any TSA planned or approved changes to the schedule during the meeting. Scheduled milestones shall include all agreed upon TS phase deliverables.
8.10.2 SOP and equipment changes requiring curriculum modification or additional learning objectives
(LOs) will be performed under the Curriculum Development CLIN.
8.10.3 The Contractor shall upload the finalized curricula and all source files to the TSA designated repository for curriculum file development and may be required to provide copies of all developed training in disc format or other approved format, as requested by TSA. TSA may request hard copies via RFQ.
8.11 Curriculum Design, Development and Delivery Personnel Requirements
8.11.1 The Contractor shall provide STIAs to provide the following:
• Technical support to include program documentation (i.e., Guidance Documents, Reference Manuals, etc.), and technical report writing provided to TSA Academy Instructors;
• Impact Analysis and Reporting, special project support (e.g. Measures of Pilot Success, OEM interface, etc.) Uploaded to TSA’s designated repository for curriculum file development and emailed to COR no later than 30 days after receipt of TSA-approved change;
• Support to operational pilot(s) of new curriculum, and/or attending the rollout of new equipment pilots (e.g., OEM training delivery);
• Curriculum Development support to include working with ISDs, instructors, developers, and staff writers to ensure the technical accuracy of course content, presentation materials, Lesson Plans, Instructor and Participant Guides, job aids, handouts, activities/exercises, examinations, and any/all supplemental documents used during the delivery and administration of a course.
• Assist with T3 deliveries, in any capacity deemed appropriate and necessary by TSA.
8.12 Operational Assessments / Pilots
8.12.1 The Contractor shall support technology or operational assessments, pilots, and T3 events with new and/or revised curriculum and technology / screening equipment; these may include field trials, Developmental Test and Evaluation (DT&E), Operational Test and Evaluation (OT&E), and technology and/or capability deployments.
8.12.2 Hours of training and all other requirements, including labor associated with pilot printing and delivery, will be identified in the RFQ process, if known. If Analysis is conducted, the analysis should provide evidence-based recommendation for training hours and curriculum structure.
8.13 Curriculum Maintenance
8.13.1 The Contractor shall provide curriculum maintenance support for the TSA curriculum enterprise in accordance with all requirements identified in the IDIQ SOW and this TO. Maintenance changes may require adding, modifying, or removing LOs (knowledge or performance objectives).
8.13.2 Curriculum maintenance includes updates to existing curriculum, including SOP and equipment changes, and maintaining lessons to ensure currency of content, policy, and procedures.
8.14 SOP Reference Library
8.14.1 The Contractor shall update and maintain the SOP reference library, a baseline library will be provided by the Government upon award. The SOP reference library will be updated as requested by the Government and uploaded into the designated TSA system of record.
8.15 Curriculum Index
8.15.1 The Contractor shall maintain the TSA Curriculum Index weekly and/or as requested by the Government. This index must have the capability to maintain course related information, such as SOP change impacts and dates, regular maintenance impacts and dates, and any regulation changes along with their impacts and dates. Each of these items (SOPs, regular maintenance, and regulation changes) will be provided to the Contractor by TSA.
8.15.2 When the need arises to update curriculum to ensure accuracy and currency following SOP and Security Equipment changes (for example; modifying or adding Learning Objectives), the Contractor shall ensure that the curriculum is delivered to TSA no later than 30 days from the date of the final SOP and/or procedural directive notification.
9 Instructor Training Support Requirements (Optional)
9.1 The Contractor shall provide classroom instruction to TSA instructors and the TSO workforce for demonstration projects, pilot training events, and T3 events. Instructor support provided may take the form of instructor-led training, virtual classroom training, and reviews of the curriculum for which they instruct to support updates to curriculum, as required by TSA. For pricing purposes, the Contractor may use TSA’s instructor training support requirement estimated hours of 42,240 labor hours annually (assuming 1,920-hour work year), with 28,800 annual labor hours required full time at the TSA Academy.
9.2 Instructor training support services shall be provided in the development of the types of training described in Section 8.9.
9.3 The Contractor shall provide instructor support for all courses developed within this TO in addition to each course listed below, as required by TSA.
9.3.1 Innovation Task Force technical equipment training, including but not limited to:
• Computed Tomography (CT) X-ray provided for approximately four vendor types;
• Automatic Screening Lanes (ASL) provided for approximately six different vendor types;
• Other emerging technologies to include Credential Authentication Technology (CAT) and
Enhanced Advanced Imaging Technology (EAIT).
9.3.2 Checked Baggage Explosive Detection System (EDS) deployments to support the following machine manufacturer and model types as well as new technologies as they emerge, including:
• CTX 2500/5500
• CTX 9000/9400
• CTX 9800
• CTX 5800
• CT80 DR+
• L3 6000/6600
• L3 6700
9.3.3 Technical, non-equipment training required to support the release of updated SOPs and/or program updates.
9.4 Instructors shall successfully complete the IDC, a five (5) day certification course conducted at the TSA Academy. Successful completion of the IDC certifies that a person is qualified to instruct at the TSA Academy and associated T3 events. TSA and the Contractor will determine a mutually agreeable timeframe for instructor completion of the IDC.
9.5 Instructors shall adhere to all instructor qualification guidelines to obtain and maintain certification, as described in TSA Academy SOP 500.4-10 Instructor Certification and Qualification.
10 Federal Law Enforcement Training Accreditation (FLETA) (Optional)
10.1 TSA plans to pursue accreditation for the TSA Academy and has already received accreditation for the TSO Basic Training Program (TSO-BTP) Phase II. The Academy manages and delivers many courses and intends to pursue accreditation for other courses, such as Transportation Security Inspector (TSI) and Instructor courses.
10.2 The contractor shall follow the MD 1900.14 Training Standards (ADDIE or other methodologies) and develop all deliverables for any TSA course identified, as required by
TSA.
10.3 The Contractor shall assist with the development of accreditation files.
10.4 The Contractor shall support the maintenance of accredited curricula files.
11 Travel
11.1 Domestic and International Travel may be required for work performed at TSA facilities outside of the vendor’s local commuting area. On an annual basis, TSA estimates the Contractor may be required to travel to up to 80 Hub airports and to TSA Training Centers.
Travel costs for work performed at TSA facilities will be subject to reimbursement as follows:
11.1.1 Contractor travel may be required to support this requirement. The Contractor shall be responsible for obtaining COR approval (electronic mail is acceptable) for all travel 30 days in advance of each travel event. Local travel shall not be authorized. No travel is authorized unless sufficient funds for travel are available on the contract. Travel is reimbursable at cost. Payment of fees or other charges is not applicable to travel. Travel shall be accordance with FAR 31.205-46 and Federal Travel Regulations (FTR). Travel, when in direct and authorized support and execution of an RFQ, shall be allowed without individual requests for approval, up to the authorized individual RFQ NTE Travel amount.
11.1.2 The Contractor shall attend (travel to attend) training, assessments, pilots and/or roll-out events as requested.
11.1.3 The Contractor may be required to travel for training, engaging with TSA experts and becoming familiar with TSA equipment, as agreed upon by TSA and the Contractor.
12 Other Direct Costs (ODCs)
12.1 The Contractor shall adhere to the ODC rules as defined by the terms of the base contract.
12.2 All ODC requests shall contain the following:
• Requirement by SOW Task Number
• CLIN
• Date
• Project / RFQ that it would support, where applicable
12.3 Items purchased by the Contractor using Government funds shall become the property of the
Government.
12.4 The Contractor shall provide written notification to the COR and CO (e-mail is acceptable) when 75% of the funds authorized have been expended for ODC CLINs, T&M CLINs, and Cost Reimbursable (CR) CLINs. The notice shall also include whether or not the Contractor anticipates a need for more funds than the remaining 25% of the CLIN.
12.5 The Contractor shall provide ODC expenditures and forecasts as outlined in the Program Management Support TO.
12.6 All purchases must adhere to FAR, DHS, and TSA guidelines.
12.7 The Contractor shall procure ODCs in support of TSA pilots, as directed.
12.8 The Contractor may be required to acquire Commercial off-the-shelf (COTS) licenses to conduct curriculum development services.
12.9 The Contractor may be required to provide logistics support to include printing of course and pilot curriculum and shipment of kits/materials. Materials may include, but are not limited to the following: Instructor Guides, Participant Guides, T3 Guides, Curriculum CDs, and COTS items/training supplies for new developments, as requested by TSA.
12.10 Pilots will generally consist of two (2) instructors and 24 students, and may require binders for each student and instructor guides for each instructor.
13 Transition Out
13.1 The Contractor shall perform Transition Out activities if Optional CLIN is exercised at any point during the Period of Performance (PoP) of the TO, including the Base Period and all Option Periods.
13.2 The Contractor shall develop a Transition Out Plan that describes a transition out strategy, and identifies transition data and information, systems, components, documentation, functionality, services, service dependencies, services interfaces, risks, transition work activities, schedule, staffing down approach, knowledge transfer, and any other information that needs to be considered to ensure a smooth transition.
13.3 The Contractor shall deliver the Transition Out Plan to the COR within nine (9) business days from the TSA request. Upon acceptance by TSA, the Contractor shall execute the Transition Out Plan and complete within the PoP for the applicable CLIN.
13.4 The Contractor shall provide an inventory of all operational, procedural, educational, and any other documentation and presentations using a TSA approved delivery method.
13.5 The Contractor shall continue to fulfill the current contractual requirement(s) and continue all current work in progress until the succeeding contractor assumes full operational responsibility as determined by TSA. The Contractor shall not destroy, delete, or otherwise dispose of any files or data upon expiration or termination of the TO, without prior permission from the COR.
13.6 The Contractor shall fully cooperate with the successor contractor and the Government during transition out so as not to interfere with their work or duties.
13.7 The Contractor shall fully support all TSA requests for information and data required to ensure a seamless transition of services to a new contractor.
13.8 The Contractor shall deliver to the TSA electronic and/or hard copies, if requested, of all TSA data and information developed for TSA using delivery format approved by COR within 30 calendar days from the TSA request, including print-ready files and original modifiable source files for all current courses. Any new files developed after the Contractor’s submission shall also be sent to TSA. This shall include but is not limited to the following:
13.8.1 The final version of all courseware, job aids, guides, etc., this includes LMS and Computer Based
Training (CBT) versions of IMI, instructor guides, participant guides, PowerPoint presentations, test maps, training aids, etc.;
13.8.2 All source files for the final products, in an editable format and including components such as images, videos, and any other multimedia;
13.8.3 All Government Furnished Information (GFI) tied to each product;
13.8.4 All Training Curriculum Updates (TCUs);
13.8.5 An index of everything the contractor provides that includes the file name, file type, and location;
13.8.6 The files shall be delivered electronically, using a TSA approved delivery method to the TSA CO or their designee;
13.8.7 At the conclusion of the contract, the contractor shall transition information collected or used during the performance period including computer files and databases in Microsoft and Adobe applications.
14 Deliverable Table
Section Deliverable Submission Method Due Date Recipient
8.10.3
Finalized Curriculum and
Associated Deliverables
Upload to TSA’s designated repository for curriculum file development and/or as requested by TSA
Upon Curriculum completion and approval
COR, PL
8.11.1, 8.15.2
Curriculum updates following Impact
Analysis and/or due to TSA
SOP/Technology changes Updates
Upload to TSA’s designated repository for curriculum file development and email
No later than 30 days after receipt of TSA-approved change
COR, PL
8.14 SOP Reference
Library
Upload to TSA’s designated system of record and email As requested COR, PL
8.15 Curriculum Index
Upload to TSA’s designated system of record and email
Update weekly COR, PL
13.3 Transition Out Plan Email Within 9 business days
of TSA request COR
13.8 All TSA Data
Submit electronic and/or hard copies, if requested, using delivery format approved by TSA
Within 30 days of TSA Request COR
15 Appendix B - Instructional Design Model
15.1 This section is included as a reference for the standard requirements, deliverables, and artifacts for each phase. These requirements apply to the entire TO. Specific efforts will require some or all of the Training Standard deliverables (based on RFQ). For estimation purposes, assume all Analysis, Design, Development, Pilot, Implementation, and Evaluation deliverables will be required, unless otherwise directed by the Government. The Contractor shall utilize artifacts noted in the TSA MD 1900.14 Training Standards Handbook and/or as requested by TSA.
15.2 The Contractor shall provide all curriculum deliverables established at kickoff prior to each corresponding Technical Review, as applicable. Deliverables shall be reviewed in draft format only. Dates of the reviews shall be built into the Project Plan.
15.3 The Contractor shall participate in Technical Reviews staged throughout a training development project, during which designated personnel review key deliverables to authorize the project to advance.
16 Appendix C - Definition of Acronyms
ADDIE Analysis, Design, Development, Implementation, and Evaluation ASL Automatic Screening Lanes CAA Computer and Wireless Mobile Device Access Agreement CAT Credential Authentication Technology CDG Course Design Guide CLIN Contract Line Item Number CO Contracting Officer COR Contracting Officer’s Representative CS Contract Specialist CT Computed Tomography DHS Department of Homeland Security DT&E Developmental Test and Evaluation EAIT Enhanced Advanced Imaging Technology EDS Explosive Detection System FAR Federal Acquisition Regulation FLETA Federal Law Enforcement Training Accreditation FTR Federal Travel Regulations GFE Government Furnished Equipment GFI Government Furnished Information IDC Instructor Development Course IDIQ Indefinite Delivery, Indefinite Quantity ILT Instructor Led Training IMI Interactive Multimedia Instruction LMS Learning Management System LOE Level of Effort NLT No Later Than OEM Original Equipment Manufacturer OLC Online Learning Center OT&E Operational Test and Evaluation PL Project Lead RFQ Request for Quote SME Subject Matter Expert
SOP Standard Operating Procedure SOW Statement of Work SST Specialized Security Training STIA Security Training and Integration Analyst T3 Train-the-Trainer T&D Training and Development T&M Time and Materials TCU Training Curriculum Update TSI Transportation Security Inspector TSO-BTP TSO Basic Training Program TSO Transportation Security Officer
17 Appendix D - Information Assurance Requirements for TSA Government Acquisitions (April
2016)
A. General Security Requirements
A.1. The Contractor shall comply with all Federal, Department of Homeland Security (DHS) and Transportation Security Administration (TSA) security and privacy guidelines in effect at the time of the award of the contract, as well as those requirements that may be discretely added during the contract.
A.2. The Contractor shall perform periodic reviews to ensure compliance with all information security and privacy requirements.
A.3. The Contractor shall comply with all DHS and TSA security controls to ensure that the Government's security requirements are met. These controls are described in DHS PD 4300A and TSA MD 1400 series security policy documents and are based on the current National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 standards.
A.4. The Contractor shall include this guidance in all subcontracts at any tier where the subcontractor is performing the work defined in this statement of work (SOW).
A.5. The Contractor shall ensure all staff have the required level of security clearance commensurate with the sensitivity of the information being accessed, stored, processed, transmitted or otherwise handled by the System or required to perform the work stipulated by the contract. At a minimum, all Contractor staff shall be subjected to a Public Trust background check and be granted a Public Trust clearance before access to the System or other TSA resources is granted.
A.6. The Contractor shall sign a DHS Non-Disclosure Agreement (NDA) within (30) calendar days of the contract start date.
A.7. The Contractor shall not release, publish, or disclose agency information to unauthorized personnel, and shall protect such information in accordance with the provisions of the pertinent laws and regulations governing the confidentiality of sensitive information.
A.8. The Contractor shall ensure that its staff follow all policies and procedures governing physical, environmental, and information security described in the various TSA regulations pertaining thereto, and the specifications, directives, and manuals for conducting work to generate the products as required by this contract. Personnel shall be responsible for the physical security of their area and government furnished equipment (GFE) issued to the contractor under the terms of the contract.
A.9. The Contractor shall make all system information and documentation produced in support of the contract available to TSA upon request.
B. Training Requirements
B.1. All Contractor employees, requiring system access, shall receive initial Organizational Security Fundamentals Training within 60 days of assignment to the contract via the Online Learning Center (OLC). Refresher training shall be completed annually thereafter.
B.2. The Contractor shall complete annual online training for Organizational Security Fundamentals and TSA Privacy training.
B.3. Role Based training is required for contract employees with Significant Security Responsibility (SSR), whose job proficiency is required for overall network security within TSA, and shall be in accordance with DHS and TSA policy. The contractor will be notified if they have a position with significant security responsibility.
B.4. Individuals with SSR shall have a documented individual training and education plan, which shall ensure currency with position skills requirements, with the first course to be accomplished within 90 days of employment or change of position. The individual training plan shall be refreshed annually or immediately after a change in the individual’s position description requirements.
B.5. Information Secuirty and Privacy training supplied by the Contractor shall meet standards established by NIST and set forth in DHS and TSA security policy.
B.6. The Contractor shall maintain a list of all employees who have completed training and shall submit this list to the contracting officer representative (COR) upon request, or during DHS/TSA onsite validation visits performed on a periodic basis.
B.7. The contractor shall its employees review and sign the TSA Form 1403 Computer and Wireless Mobile Device Access Agreement (CAA) prior to accessing IT systems.
C. Configuration Management (hardware/software)
C.1. Hardware or software configuration changes shall be in accordance with the DHS Information Security Performance Plan (current year and any updates thereafter), the DHS Continuous Diagnostics and Mitigation (CDM) Program to include dashboard reporting requirements and TSA’s Configuration Management policy. The TSA Chief Information Security Officer (CISO)/Information Assurance and Cyber Security Division (IAD) shall be informed of and involved in all configuration changes to the TSA IT environment including systems, software, infrastructure architecture, infrastructure assets, and end user assets. The TSA IAD POC shall approve any request for change prior to any development activity occurring for that change and shall define the security requirements for the requested change. The COR will provide access to the DHS Information Security Performance Plan.
C.2. The Contractor shall ensure all application or configuration patches and/or Requests for Change (RFC) have approval by the Technical Discussion Forum (TDF), Systems Configuration Control Board (SCCB) and lab regression testing prior to controlled change release under the security policy document, https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx
TSA Management Directive (MD) 1400.3 Information Technology Security and TSA Information Assurance (IA) Handbook, unless immediate risk requires immediate intervention. Approval for immediate intervention (emergency change) requires approval of the TSA CISO, SCCB co-chairs, and the appropriate Operations Manager, at a minimum.
C.3. The Contractor shall ensure all sites impacted by patching are compliant within 14 days of change approval and release.
C.4. The acquisition of commercial-off-the-shelf (COTS) Information Assurance (IA) and IA-enabled IT products (to be used on systems entering, processing, storing, displaying, or transmitting “sensitive information”) shall be limited to those products that have been evaluated and validated, as appropriate, in accordance with the following:
• The NIST FIPS validation program.
• The National Security Agency (NSA)/NIST, National Information Assurance Partnership (NIAP) Evaluation and Validation Program.
• The International Common Criteria for Information Security Technology Evaluation Mutual Recognition Agreement.
C.5. US Government Configuration Baseline and DHS Configuration Guidance
a) The provider of information technology shall certify applications are fully functional and operate correctly as intended on systems using the US Government Configuration Baseline (USGCB) and in accordance with DHS and TSA guidance.
1. USGCB Guidelines:
a. http://usgcb.nist.gov/usgcb_content.html
2. DHS Sensitive Systems Configuration Guidance
a. http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx
b) The standard installation, operation, maintenance, updates and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. The information technology shall also use the Windows Installer Service for installation to the default “program files” directory and shall be able to discretely install and uninstall.
c) Applications designed for general end users shall run in the general user context without elevated system administration privileges.
C.6. The Contractor shall establish processes and procedures for continuous monitoring of Contractor systems that contain TSA data/information by ensuring all such devices are monitored by, and report to, the TSA Security Operations Center (SOC). The Contractor shall perform monthly security scans on servers that contain TSA data, and shall send monthly scan results to the TSA IAD.
D. Risk Management Framework
D.1. The Security Authorization and Ongoing Authorization Process in accordance with NIST SP 800- 37 and SP 800-137 (current versions) is a requirement for all TSA IT systems, including General Support Systems (e.g., standard TSA desktop, general network infrastructure, electronic mail), major applications http://usgcb.nist.gov/usgcb_content.html http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx and development systems (if connected to the operational network or processing, storing, or transmitting government data). These processes are documented in the NIST Risk Management Framework (RMF).
Ongoing Authorization is part of Step 6 “Monitoring” of the RMF. All NIST guidance is publicly available; TSA and DHS security policy is disclosed upon contract award with some exceptions, which are public facing (i.e., DHS Security and Training Requirements for Contractors).
D.2. A written Authorization to Operate (ATO) granted by the TSA Authorizing Official (AO) also known as TSA Chief Information Secuirty Officer (CISO) is required prior to processing operational data or connecting to any TSA network. The contractor shall provide all necessary system information for the security authorization effort.
D.3. TSA shall assign a security category to each IT system compliant with the requirements of Federal Information Processing Standards (FIPS) Pub 199 Standards for Security Categorization of Federal Information and Information Systems impact levels and assign security controls to those systems consistent with FIPS Pub 200 Minimum Security Requirements for Federal Information and Information Systems methodology.
D.4. Unless the AO specifically states otherwise for an individual system, the duration of any Accreditation shall be dependent on the FIPS 199 rating and overall residual risk of the system; the length can span up to 36 months.
D.5. The Security Authorization (SA)Package contains documentation required for Security Authorizations and Ongoing Authorization. The package shall contain the following security documentation: 1) Security Assessment Report (SAR), 2) Security Plan (SP) or System Security Authorization Agreement (SSAA), 3) Contingency Plan, 4) Contingency Plan Test Results, 5) Federal Information Processing Standards (FIPS) 199 Security Categorization, 6) Privacy Threshold Analysis (PTA), 7) E-Authentication, 8) Security Assessment Plan (SAP), 9) Authorization to Operate (ATO) Letter, 10) Plan of Action and Milestones (POA&M), and 11) Ongoing Authorization Artifacts as required by the DHS Ongoing Authorization Methodology (current version). The SA package shall document the specific procedures, training, and accountability measures in place for systems that process personally identifiable information (PII). All security compliance documents shall be reviewed and approved by the CISO and the IAD, and accepted by the CO upon creation and after any subsequent changes, before they go into effect. Ongoing Authorization artifacts include monthly TRigger Accountability Log (TRAL), monthly operating system scan results, application scans as directed, updated control allocation table (CAT), and associated memos as directed. All steps in the DHS Information Assurance Compliance Systems (IACS) shall be completed correctly, thoroughly and in a timely manner for all steps of the RMF.
D.6. The contractor shall support the successful remediation of all identified system weaknesses and vulnerabilities that are identified as a result of the aforementioned security review process.
D.7. The contractor shall submit and analyze monthly operating system vulnerability scans for the DHS Information Security Performance Plan FISMA Scorecard. Vulnerabilities not remediated are generated into Plan of Action and Milestone (POA&M)s after 30 days.
E. Contingency Planning https://www.dhs.gov/dhs-security-and-training-requirements-contractors
E.1. The Contractor shall develop and maintain a Contingency Plan (CP), to include a Continuity of Operation Plan (COOP), to address circumstances whereby normal operations may be disrupted and thus require activation of the CP and/or COOP. are disrupted. The contractor’s CP/COOP responsibility relates only to the system they provide or operate under contract.
E.2. The Contractor shall ensure that contingency plans are consistent with template provided in the DHS IACS Tool. If access has not been provided initially, the contractor shall use the DHS 4300A Sensitive System Handbook, Attachment K IT Contingency Plan Template.
E.3. The Contractor shall identify and train all TSA personnel involved with COOP efforts in the procedures and logistics of the disaster recovery and business continuity plans.
E.4. The Contractor shall ensure the availability of critical resources and facilitate the COOP in an emergency situation.
E.5. The Contractor shall test their CP annually and retain records of the annual CP testing for review during periodic audits.
E.6. The Contractor shall record, track, and correct any CP deficiency; any deficiency correction that cannot be accomplished within one month of the annual test shall be elevated to IAD.
E.7. The Contractor shall ensure the CP addresses emergency response, backup operations, and recovery operations.
E.8. The Contractor shall have an Emergency Response Plan that includes procedures appropriate to fire, flood, civil disorder, disaster, bomb threat, or any other incident or activity that may endanger lives, property, or the capability to perform essential functions.
E.9. The Contractor shall have a Backup Operations Plan that includes procedures and responsibilities to ensure that essential operations can be continued if normal processing or data communications are interrupted for any reason.
E.10. The Contractor shall have a Post-disaster Recovery Plan that includes procedures and responsibilities to facilitate rapid restoration of normal operations at the primary site or, if necessary, at a new facility following the destruction, major damage, or other major interruption at the primary site.
E.11. The Contractor shall ensure all TSA data (e.g., mail, data servers, etc.) is incrementally backed up on a daily basis.
E.12. The Contractor shall ensure a full backup of all network data occurs as required by the system’s availability security categorization impact rating per TSA Information Assurance policy.
E.13. The Contractor shall ensure all network application assets (e.g., application servers, domain controllers, Information Assurance (IA) tools, etc.) shall be incrementally backed up as required to eliminate loss of critical audit data and allow for restoration and resumption of normal operations within one hour.
E.14. The Contractor shall ensure sufficient backup data to facilitate a full operational recovery within one business day at either the prime operational site or the designated alternate site shall be stored at a secondary location determined by the local element disaster recovery plan.
E.15. The Contractor shall ensure that data at the secondary location is current as required by the system’s availability security categorization impact rating.
E.16. The Contractor shall ensure the location of the local backup repository and the secondary backup repository is clearly defined, and access controlled as an Information Security Restricted Area (ISRA).
E.17. The Contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1: Network and System Infrastructure for the layout of the file systems, or partitions, on a system’s hard disk impacting the security of the data on the resultant system. File system design shall:
• Separate generalized data from operating system (OS) files
• Compartmentalize differing data types
• Restrict dynamic, growing log files or audit trails from crowding other data
E.18. The contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1: Network and System…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .