Attachment 9- SST PM Support PWS A00002.pdf

PDF 552 KB Posted

Attached to
Specialized Security Training Federal contract opportunity
Solicitation number
70T01021R7670N004
Issued by
Department of Homeland Security Transportation Security Administration

About this file

This performance work statement outlines requirements for program management support services for the Transportation Security Administration's Specialized Security Training program. Key details include:

  • The contractor shall provide comprehensive program management oversight for all task orders issued under the SST contract to ensure efficiencies and integration across orders. This includes tasks such as scheduling, finance, milestones, deliverables, and overall program performance.

  • The contractor must develop and maintain an integrated master schedule in Microsoft Project to track progress across all training and development task orders. The contractor shall also submit weekly status reports, monthly financial reports, and monthly technical summary reports.

  • The performance period is one base year with four optional one-year periods. Work will be performed at the contractor's facilities but contractor personnel must be available to meet at TSA headquarters.

  • The document establishes numerous reporting and quality assurance requirements and details security requirements for handling personally identifiable information and responding to privacy incidents. Adherence to TSA and DHS security protocols is mandatory.

View the file

Other files for this federal contract opportunity

Other files attached to Specialized Security Training, newest first.
File Type Posted
SST RFP A00003.pdf PDF
RFP SST OTD001 - A00003.pdf PDF
Attachment 15 SST FFDO Range Locations A00003.pdf PDF
Attachment 13 SST Past Performance Sheet A00003.docx DOCX document
Attachment 1- SST TMEI Statement of Work A00002.pdf PDF
Attachment 14 - SST TSA OIT GFE List A00002.pdf PDF
Attachment 4 - SST Pricing A00002.xlsx XLSX spreadsheet
SST RFP A00002.pdf PDF
RFP SST OTD001 - A00002.pdf PDF
Attachment 12- SST FFDO PWS A00002.pdf PDF
Attachment 13 SST Past Performance Sheet A00002.docx DOCX document
Attachment 3- SST RFP Question Answers 3-10-2021.pdf PDF
SST RFP A00001.pdf PDF
Attachment 5- SST Draft Curriculum Development SOW A00001.pdf PDF
SST RFP70T01021R7670N004 Final.pdf PDF
Attachment 2- TMEI SOW Attachment A - Non-SSI Kit Descriptions.pdf PDF
Attachment 3- SST RFP Question Answer Sheet.xlsx XLSX spreadsheet
Attachment 12 Wage Determination List.pdf PDF
Attachment 1- SST TMEI Statement of Work.doc.pdf PDF
Attachment 6- SST Inventory Listing.pdf PDF
Attachment 7- TSA MD 1900.14 Training Standards.pdf PDF
Attachment 9- SST PM Support PWS.pdf PDF
Attachment 10- MFSR_Template.xlsx XLSX spreadsheet
Attachment 11- SST FFDO PWS.pdf PDF
Attachment 8- TSA MD 1900.14 Training Standards Handbook.pdf PDF
Attachment 4 SST Pricing.xlsx XLSX spreadsheet
Show all 26

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Pe rformance Work Statement (PWS)

1 Re quiring Organization

T he Government organization requiring the services described herein is as follows:

Department of Homeland Security T ransportation Security Administration

T raining and Development, TSA-08

6595 Springfield Center Drive, Springfield, VA 20598-6008

601 South 12th Street, 3 rd Floor, East Building Arlington, VA 20598

*Note: TSA headquarters is scheduled to relocate to Springfield, VA in Fall 2020.

2 Background

T he Aviation and Transportation Security Act (ATSA), Public Law 107-71, requires the TSA to develop, implement, and manage training programs for the transportation security workforce. In compliance with

ATSA, the Office of Training & Development (T&D) is responsible for the analysis, design, development, implementation and evaluation of training programs for employees, the transportation industry, and international partners. The focus of all training is to support and increase the TSA workforce technical expertise, professionalism, and engagement effectiveness. TSA’s Risk -Based Security environment must evolve to meet rapidly changing threats. TSA must be prepared to address and meet the demands of an increasingly complex operation within tight timelines and budgetary constraints.

P.L. 107-71 also mandates that Transportation Security Officers (TSO) employed as security screeners may not use any screening device or equipment in the scope of their employment unless they have been trained on that device or equipment and have successfully passed all required assessments for certification or recertification. Additionally, TSOs must be proficient in using the most up-to-date technology in recognizing new threats and weapons, including dual-use items that appear harmless but may be used as weapons.

3 Scope of Work

T SA Training & Development (T&D) requires centralized program management support services to provide seamless program oversight for all T&D task orders issued against the SST 4.0 Indefinite

Delivery Indefinite Quantity (IDIQ).

T he Contractor shall provide comprehensive program management oversight to ensure efficiencies and integration across all T&D task orders to include such tasks as scheduling, finance, milestones, deliverables, and overall program performance in accordance with the IDIQ Performance Work Statement (PWS) and this Task Order.

4 Ke y Personnel http://www.gpo.gov/fdsys/pkg/PLAW-107publ71/pdf/PLAW-107publ71.pdf

4.1 T ask Order Program Manager (Key Personnel)

4.1.1 T he Contractor’s Program Manager is designated as key personnel, and shall act as the central point of contact with the Government for all technical and management issues, and will represent the

Contractor at all Task Order-level post-award status meetings. The Program Manager shall be responsible for all Task Order-level issue resolution, program management, and other contract support including providing comprehensive account support for the SST contract. The Program Manager is responsible for overall PM Support Task Order performance.

5 Place of Performance

Contractor employees will work at the Contractor’s facilities. The contractor’s Program Management

T eam shall be available to meet at TSA Headquarters in Springfield, VA, as required by TSA.

6 Pe riod of Performance

One (1) 12-month base period.

Four (4) 12-month option periods

7 Program Management

7.1 T he Contractor shall provide Program Management oversight of all work performed under all T&D

T ask Orders to include schedule, milestones, cost, finance, products, deliverables and overall program performance as described in the IDIQ PWS and this Task Order.

7.2 T he Contractor shall utilize the TSA system of record and/or the TSA iShare Project Site(s) to update status on overall task management activities, initiate and track Requests for Quotation

(RFQs), WebForms, Program Project/Task/sub-task level reporting and data management.

7.3 Integrated Master Schedule

7.3.1 T he Contractor shall develop and maintain an Integrated Master Schedule (IMS) in Microsoft

Project to track and report progress for each project across all T&D task orders.

7.3.2 T he Contractor shall provide a comprehensive and individual project schedules, which identify efforts that may be performed by partnering Contractors supporting other SST task orders, to the

COR with the submission of the MTSR.

7.3.3 Any significant change equaling an increase of 10% to the approved schedule shall require a re-baselined project schedule.

7.4 T he Contractor shall provide a summary of meetings with TSA, to include a list of all action items, to the COR no later than (NLT) COB three (3) Business Days following each meeting.

7.5 T he Contractor shall conduct one (1) Program Management Review (PMR) per quarter to outline the previous quarter’s activities, issues, and risks in addition to a forecast on all projects across T&D task orders, on a task by task basis, with associated CLINs.

7.5.1 In order to assume cost savings, the Government may use a teleconference and the Contractor is required to possess teleconferencing capability.

7.5.2 Softcopy slides (via e-mail) shall be provided to the COR 72 hours prior to the PMR.

7.6 Post-Award Conference

7.6.1 T he Post-Award conference will cover the terms and conditions of the task order, contract administration, and other administrative concerns.

7.6.2 T he Post-Award Conference is to be held no later than two (2) weeks (10 business days), after the date of Task Order award. The Contractor will be contacted by the Contract Specialist or the

COR to coordinate the Post-Award Conference. Post-Award Conference may be held virtually as directed by the Government.

8 Re porting Requirements

8.1 Unless otherwise specified, the Contractor shall submit deliverables in the format specified in the task order specific deliverable tables. Electronic copies of deliverables must have read/write capability unless otherwise requested. For resultant deliverables that are not identified in the deliverable schedule, the Contractor shall submit an electronic copy of the deliverable in a format agreed upon by both parties. Electronic copies shall be delivered via TSA’s designated system of record, or otherwise as directed by TSA. The electronic copy shall be compatible with TSA computer workstations, requiring, at a minimum, Adobe PDF and Microsoft Office 2010 format application or a format for digital storage mutually agreed to by the parties. The Contractor shall successfully complete and submit products in accordance with the requirements of each task. All source files including individual components such as images, and videos shall be submitted with each deliverable.

8.2 T he Contractor shall develop and maintain program schedules and track/report progress for each separate task performed under all T&D task orders. This shall include a combined Weekly Status

Report (WSR) due by COB Monday of every week.

8.2.1 T he Weekly Status Report shall detail the previous week’s activity and contain the following:

8.2.1.1 Current project schedule for each task

8.2.1.2 W eekly Progress (task specific)

8.2.1.3 W eekly Projected Activity (task specific)

8.2.1.4 Click Count for the week, month, and from inception

8.2.1.5 Risk Reporting – Communication of any risks to TSA operations

8.2.1.6 Instructor Certification/Recertification – Dates and status of instructor certifications, expiration dates, and recertification plans

8.2.1.7 Instructor Utilization – A summary of instructor utilization by training program, including current and planned instructor deployments

8.2.1.8 Logistics Activity – By program, the Contractor shall report on logistics activity to include an

Instructor Deployment Summary and Class Deliveries

8.2.1.9 T ask Specific Travel – The Contractor shall include weekly travel reporting that addresses all planned, forecasted, and completed travel. Forecasted travel shall identify planned travel 30 days prior to travel dates in order to allow for Government approval

8.2.1.10 Schedule Reporting – The Contractor will report progress for each separate project conducted under T&D task orders, identifying scheduled start and end dates, schedule risks and vulnerabilities, status of project milestones, required response timeframes from TSA and general project status

8.2.1.11 Quality Trend Report – This report shall only be included if the contractor has evaluation information to report. Otherwise, it should not be included in the weekly report. As part of the

Kirkpatrick Levels of Evaluation, TSA expects the Contractor to provide this report along with the other evaluation documents listed in T&D Curriculum PWS task order.

8.2.1.12 Naming Convention: The WSR shall be titled using the below naming convention.

Contract_Last_Six-Deliverable_Name-YYYYMMDD

Example: OTD101-WSR-20200812

8.2.2 T he Contractor shall provide a Monthly Financial Summary Report (MFSR) detailing all financial information due fifteen (15) calendar days after month end, or the first business day thereafter, and contain the following:

8.2.2.1 T he MFSR shall include a section to identify contract information, including:

Contract number, Task Order Numbers, and modification number(s), if any;

Reporting period (Month);

Contract period (Base / Option #);

Contract period of performance start and end date.

8.2.3 T he MFSR shall detail all financial information contract-wide and on each T&M project, by invoiced month, as follows:

8.2.3.1 T he MFSR shall include a section reflecting actual monthly and cumulative (by total contract and contract period) expenditures, staffing utilization (labor hours and cost), ODCs, and travel services for the reporting period.

8.2.3.2 A breakout of funds expended on RFQs/Technical Directions (TD) (T&M work) shall be included in this information including cumulative total funds provided to date and a detail of actual monthly/cumulative expenditures and funds remaining to date, inclusive of current period charges.

8.2.3.3 T he Contractor shall detail the cost of expenditures per RFQ/TD, on a per project per task basis, reflecting current and cumulative labor hour costs, ODCs and travel expended.

8.2.3.4 W hen a project/task is submitted, the Contractor shall provide an initial cost estimate of expenditures at completion (EAC).

8.2.3.5 T he Contractor shall also tag the projects by status: ongoing, on hold, terminated, and complete;

8.2.3.6 T he MFSR shall include a variance (%) comparison of planned costs to actuals including labor category costs, a current Estimate at Completion (EAC), funds remaining, and actual cumulative expenditures, per project and rolled up to the TO level;

8.2.3.7 Additional financial data shall be provided to the Government upon request.

8.2.3.8 Naming Convention: The MFSR shall be titled using the below naming convention.

Contract_Last_Six-Deliverable_Name-Month_Covered-YYYYMMDD

Example: OTD101-MFSR-07-20200812

8.2.4 Monthly Technical Summary Report (MTSR)

8.2.4.1 T his deliverable shall be submitted fifteen (15) calendar days after month end, or the first business day thereafter.

8.2.5 T he MTSR shall summarize work accomplished (to align with activity-based cost reporting) during the reporting period. It shall reflect the status of technical services on each task, to include the following:

8.2.5.1 Deliverables submitted or progress achieved on deliverables;

8.2.5.2 A brief summary of status and completion of significant events and milestones and activity planned for the next reporting period; current and anticipated issues, estimate of schedule impacts due to issues (to include a Schedule Performance Index (SPI).

8.2.5.3 Other relevant information, as necessary to convey program status; quality assurance; and/or quality control information.

8.2.5.4 ODCs and Travel Report

8.2.5.4.1 T he Contractor shall be required to support consolidated labor hour, travel, and cost reporting for each T&M effort.

8.2.5.4.2 For each Contractor/subcontract employee, identify the name, labor category/skill level, regular and overtime hours worked per WBS element for each T&M effort.

8.2.5.5 ODC Forecast

8.2.5.5.1 Description of any travel or unique services anticipated to be provided within the next month.

8.2.5.5.2 Description of any other anticipated ODCs within the next month.

8.2.5.6 Naming Convention: The MTSR shall be titled using the below naming convention.

Contract_Last_Six-Deliverable_Name-Month_Covered-YYYYMMDD

Example: OTD101-MTSR-07-20200812

8.2.5.7 Monthly Property Inventory Reports

8.2.5.8 T he Contractor shall provide TSA with a monthly report as an attachment to the Monthly T echnical Status Report submission due on the same date as monthly invoice submission, which includes an inventory list of all assets and a reconciliation of inventory across all Government and Contractor property management systems. Government assessments, reviews, audits, and operations in general, may include physical inventory, document analysis, observations, physical examination, confirmation, interviews, questionnaires, and/or other assessment to obtain an opinion on the effectiveness of controls, accuracy of inventory, and test of design for process efficiency and effectiveness.

9 Q uality Assurance

9.1 Quality Assurance

9.1.1 T he Contractor shall ensure that all T&D task order performance objectives and deliverables are of the highest achievable quality; promote continuous improvement efforts; and ensure industry/enterprise practices are employed at all times. Contractor processes and Standard Operating Procedures (SOPs) shall be followed and are auditable by TSA.

9.1.1.1 T he Contractor shall propose a Quality Control Plan for each task listed in the T&D Threat

Mitigation, Engineering, and Imaging (TME&I) and Curriculum task orders. The due date will be agreed upon by the Government and Contractor.

9.1.2 T he format and content of deliverables shall be agreed upon, in advance, between the COR and

Contractor for T&M work task items. Inspection and acceptance of all deliverables required under this PWS will be performed by the COR. All deliverables are due by 12:00 pm ET on the day specified, unless otherwise stated. If the Government finds that deliverables contain errors, or otherwise do not conform to the requirements stated within this TO, the document will be returned to the Contractor, as soon as the error or other non-conformance becomes known, for correction and re-submission within three (3) business days. Detailed technical records and/or notes should be available to the COR for review of any requirement at any time during the period of performance, and all research material compiled as part of this TO shall be provided to the

Government upon completion of each period of performance. The date, time, method, and location for meetings is to be agreed upon between the Government COR and the Contractor.

9.1.3 T he COR will coordinate the Quality Assurance activities, to include the Quality Assurance Team

(Program Manager, Accountable Property Officer, Property Custodian, and Project Lead) when required.

9.1.4 T he below listed methods may be used to conduct Quality Assurance.

9.1.4.1 Deliverable Review – A review of the deliverables will be conducted based on the following criteria: Delivery, Technical, Content, Management, and Cost Performance.

9.1.4.2 100% Inspection – This level of inspection will be accomplished as designated by TSA. The

100% inspection of GFE/GFP may be broken down into percentages for ease of scheduling and to minimize the impact on operations. The percent should equal 100% for the period designated

(i.e. Period of Performance, annual).

9.1.4.3 Periodic Inspection – Periodic inspections will be scheduled by the COR if and when needed.

Personnel performing the random inspection shall be designated by the COR. The COR, with the Quality Assurance Team when required, will determine the timing of the inspection and the area(s) of Contractor performance to be inspected.

9.1.4.4 Random Inspection – Random monitoring will be directed by the COR if and when required.

Personnel performing the random inspection shall be designated by the COR, to include the

Quality Assurance Team as required.

9.1.4.5 Customer Feedback – Feedback may be obtained either from the results of formal deliverable review or from informal customer statements to ensure that the Contractor has satisfactorily completed tasks as required. Customer feedback shall be solicited by TSA personnel, normally the Project Lead, and reported to the COR. All unsatisfactory reports will be reviewed by the Project Lead for validity for reporting to the COR.

9.1.5 Quality Planning – The Contractor shall conduct a complete review of the detailed requirements to identify all test and inspection resources are necessary for assuring product integrity.

9.1.6 Document Control – The Contractor shall ensure that the latest revisions of drawings, specifications, work instructions, inspection/test instructions, and other documents required to satisfy the requirements herein are utilized in production, inspection, and t est.

9.1.7 Records – The Contractor shall maintain records of all inspections and tests to demonstrate that each quality approach satisfies contract requirements.

9.1.8 Control of Purchases – The Contractor shall ensure that all supplies and services which are contracted and/or purchased from suppliers conform to contract requirements. The Contractor shall require that sub-contractors control the quality for services and supplies provided.

9.1.9 General Acceptance Criteria – General quality measures as set forth below shall be applied to each work product received from the Contractor under this contract.

9.1.9.1 Accuracy – Work products shall be accurate in presentation, technical content, and adherence to accepted elements of style.

9.1.9.2 Clarity – Work products shall be clear and concise. Any/all diagrams shall be easy to understand and be relevant to the supporting narrative.

9.1.9.3 Consistency to Requirements – All work products must satisfy the requirements of this PWS.

9.1.9.4 File Editing – All text and diagrammatic files shall be editable by the Government, unless otherwise directed.

9.1.9.5 Format – Work products shall be submitted in media mutually agreed upon prior to submission.

Hard copy formats shall follow any specified directives or manuals.

9.2 Section 508 of the Rehabilitation Act

9.2.1 See the SST Base IDIQ.

9.3 Non-Disclosure Agreements

9.3.1 Contractor employees, prior to beginning work, shall sign a non-disclosure agreement to be furnished to the CO.

9.4 DHS and TSA Security Requirements

9.4.1 SST Base ID/IQ section C.7.

9.5 Sensitive Security Information (SSI), Personally Identifiable Information (PII), and Incident Response

9.5.1 Contractor access to classified information is not currently required under this effort. However, during performance, it may be necessary for the Contractor to handle sensitive or proprietary information pertinent to TSA’s operations, which must be handled in accordance with TSA’s applicable policies and procedures. Please reference the Base Indefinite Delivery, Indefinite

Quantity (IDIQ) Section C.7.1 and C.7.2. (DHS and TSA Enterprise Architecture Compliance), H.23 5200.224.002 Controlled Unclassified Information Data Privacy and Protection, TSA

Management Directive 2810, and H.30 2500.224.001 Security of Systems Handling Personally

Identifiable Information and Privacy Incident Response.

9.6 Government Service Location Requirements

9.6.1 T his effort requires the Contractor to perform at various TSA sites. While Contractor personnel are at the Government site, they shall comply with all rules and regulations in effect at that site.

9.6.2 T he Contractor shall not connect its privately-owned portable computers to the TSA local area network, nor may it use TSA’s voice over internet protocol telephone system to connect its portable computers to its home office(s).

9.7 Compliance with Service Contract Labor Standards

9.7.1 T his task order is subject to the provisions of 41 U.S.C. chapter 67, Service Contract Labor

Standards (formerly known as the Service Contract Act of 1965). Compliance with the applicable Department of Labor’s Wage Determinations is required.

9.8 Intellectual Property

9.8.1 Intellectual property shall be handled in accordance with the relevant clauses in the Base SST IDIQ contract, including FAR clauses 52.227-3, 52.227-11, 52.227-14, 52.227-16, and 52.227-17. As such, all associated documentation, including reports, curriculum, etc., created by the Contractor under this task order shall become the property of the TSA. No proprietary markings shall be on any deliverables submitted to TSA.

9.9 Government Furnished Information (GFI)

Government Furnished Information shall be handled in accordance with the following:

Aviation and Transportation Security Act, P.L. 107-71, 49 U.S.C. 44940 https://www.gpo.gov/fdsys/pkg/PLAW-107publ71/content-detail.html

T ransportation Security Administration Management Directive No. 3100.1

10 C ontractor Personnel Requirements

10.1 All labor proposed for the requirements defined herein shall meet the labor qualifications described in Attachment 2 to the Specialized Security Training (SST) base IDIQ contract, which is entitled

“ B.2 – Labor Category List and Qualifications”. The Government may request the résumé of any support personnel to verify that personnel meet the qualified personnel requirements described herein. The Contractor shall provide qualified personnel in sufficient numbers to meet the requirements of this Performance Work Statement (PWS). Personnel must be adequately trained to perform the functions necessary to meet the requirements of this PWS.

10.2 Program Manager (PM)

10.2.1 T he Contractor shall provide a Program Manager(s) who shall be responsible for all Contractor work performed under this PWS.

10.2.2 T he Program Manager shall be a single point of contact for the Contracting Officer (CO) and the

Contracting Officer’s Representative (COR). It is anticipated that the PM shall be one of the senior level employees provided by the Contractor for work performed under this PWS. The name of the PM, and the name(s) of any alternate(s) who shall act for the Contractor in the absence of the PM, shall be provided to the Government as part of the Contractor's proposal.

10.2.3 During any absence of the PM, the designated alternate(s) shall have full authority to act for the

Contractor on all oversight matters relating to work performed under this PWS.

10.2.4 T he Contractor shall not replace the PM without prior acknowledgement from the CO.

10.2.5 T he PM shall be available to the COR via telephone between the hours of 0800 and 1700 EST

Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 2 hours of notification.

11 Transition-In

T he contractor shall provide transition-in services that ensure all Contractor personnel are ready to assume work in progress from the outgoing Contractor and assume new work at the start of the task order. The transition in period for this task order must be complete with the Contractor being fully operational within 150 calendar days of Task Order award (includes 60 calendar days for EOD https://www.gpo.gov/fdsys/pkg/PLAW-107publ71/content-detail.html suitability). Two (2) months are allotted for this task, which shall include processing of clearances, shadowing of the outgoing Contractor, and other required services.

12 Transition Out

12.1 T he Contractor shall develop a Transition Out Plan that describes a transition out strategy, and identifies transition data and information, systems, components, documentation, functionality, services, service dependencies, services in terfaces, risks, transition work activities, schedule, staffing down approach, knowledge transfer, and any other information that needs to be considered to ensure a smooth transition.

12.2 T he Contractor shall deliver the Transition Out Plan to the COR within nine (9) business days from the TSA request. Upon acceptance by TSA, the Contractor shall execute the Transition Out Plan and complete within the period of performance designated for the applicable CLIN.

12.3 T he Contractor shall provide an inventory of all operational, procedural, educational, and any other documentation and presentations produced as part of delivering upon the TSA request.

12.4 T he Contractor shall continue to fulfill the current contractual requirement(s) and continue all current work in progress until the successor contractor assumes full operational responsibility as determined by TSA. The Contractor shall not destroy, delete, or otherwise dispose of any files or data upon expiration or termination of the [contract/order], without prior permission from the

COT R.

12.5 T he Contractor shall fully cooperate with the successor contractor and the Government during transition out so as not to interfere with their work or duties.

12.6 T he Contractor shall fully support all TSA requests for information and data required to ensure a seamless transition of services to a new contractor.

12.7 T he Contractor shall deliver to the TSA electronic copies of all TSA data and information developed for TSA in the format requested by TSA within 30 calendar days from the TSA request, including print-ready files and original modifiable source files for all current courses in the National Training

Plan and the Course Catalogue. Any new files developed after the Contractor’s submission shall also be sent to TSA. This shall include but is not limited to the following:

12.7.1 T he final version of all courseware, job aids, guides, etc. This includes Learning Management

System (LMS) and Computer Based Training (CBT) versions of Interactive Multimedia

Instruction (IMIs), instructor guides, participant guides, PowerPoint presentations, test maps, etc.;

12.7.2 All source files for the final products, in an editable format and including components such as images, videos, and any other multimedia;

12.7.3 All Government Furnished Information (GFI) tied to each product;

12.7.4 All Training Curriculum Updates (TCUs);

12.7.5 An index of everything that the contractor provides that includes the file name, file type, and location;

12.7.6 T he files shall be delivered electronically, via a TSA-approved, encrypted external hard drive to the TSA Contracting Officer or their designee;

12.7.7 At the conclusion of the contract, the contractor shall transition information collected or used during the performance period including computer files and databases in Microsoft and Adobe applications.

13 De liverable Table

Section Deliverable Submission Method Due Date Recipient

6.3.2 Integrated Master

Schedule (IMS) Email to COR

As an attachment to

MT SR submission

COR

6.4 Meeting Minutes Email to COR 3 business days COR

6.5

Program

Management

Review

Email to COR

Quarterly, as agreed upon by TSA and the

Contractor

COR

6.6.2 Post-Award

Conference

In person or virtual, as directed by TSA

W ithin 10 business days of award

COR, PM

7.2 W eekly Status

Report (WSR) Email to COR COB Every Monday COR

7.2.2 Monthly Status

Financial Report

(MFSR)

Email to COR

Fifteen (15) calendar days after month end, or the first business day thereafter

COR

7.2.4 Monthly Technical Summary Report

(MTSR)

Email to COR

Fifteen (15) calendar days after month end, or the first business day thereafter

COR

7.2.5.8 Monthly Property

Inventory Report Email to COR

As an attachment to the MTSR submission

COR

8.1.1.1 Quality Control

Plan Email to COR

As agreed upon by

T SA and the Contractor

COR

11.2 T ransition Out Plan Email to COR

W ithin 9 business days of TSA request

COR

11.7 All TSA Data

Upload to TSA system of record, Email, CDs or other as specified

W ithin 30 days of

T SA Request

COR

13.1 Review and acceptance will be conducted in accordance with the SST Base ID/IQ.

13.2 T he COR will review deliverables prior to acceptance and provide the Contractor with email notification of acceptance or rejection.

14 Appendix D - Information Assurance Requirements for TSA Government Acquisitions (April

2016)

A. General Security Requirements

A.1. T he Contractor shall comply with all Federal, Department of Homeland Security (DHS) and

T ransportation Security Administration (TSA) security and privacy guidelines in effect at the time of the award of the contract, as well as those requirements that may be discretely added during the contract.

A.2. T he Contractor shall perform periodic reviews to ensure compliance with all information security and privacy requirements.

A.3. T he Contractor shall comply with all DHS and TSA security controls to ensure that the

Government's security requirements are met. These controls are described in DHS PD 4300A and TSA

MD 1400 series security policy documents and are based on the current National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 standards.

A.4. T he Contractor shall include this guidance in all subcontracts at any tier where the subcontractor is performing the work defined in this statement of work (SOW).

A.5. T he Contractor shall ensure all staff have the required level of security clearance commensurate with the sensitivity of the information being accessed, stored, processed, transmitted or otherwise handled by the System or required to perform the work stipulated by the contract. At a minimum, all Contractor staff shall be subjected to a Public Trust background check and be granted a Public Trust clearance before access to the System or other TSA resources is granted.

A.6. T he Contractor shall sign a DHS Non-Disclosure Agreement (NDA) within (30) calendar days of the contract start date.

A.7. T he Contractor shall not release, publish, or disclose agency information to unauthorized personnel, and shall protect such information in accordance with the provisions of the pertinent laws and regulations governing the confidentiality of sensitive information.

A.8. T he Contractor shall ensure that its staff follow all policies and procedures governing physical, environmental, and information security described in the various TSA regulations pertaining thereto, and the specifications, directives, and manuals for conducting work to generate the products as required by this contract. Personnel shall be responsible for the physical security of their area and government furnished equipment (GFE) issued to the contractor under the terms of the contract.

A.9. T he Contractor shall make all system information and documentation produced in support of the contract available to TSA upon request.

B. Training Requirements

B.1. All Contractor employees, requiring system access, shall receive initial Organizational Security

Fundamentals Training within 60 days of assignment to the contract via the Online Learning Center

(OLC). Refresher training shall be completed annually thereafter.

B.2. T he Contractor shall complete annual online training for Organizational Security Fundamentals https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx and TSA Privacy training.

B.3. Role Based training is required for contract employees with Significant Security Responsibility

(SSR), whose job proficiency is required for overall network security within TSA, and shall be in accordance with DHS and TSA policy. The contractor will be notified if they have a position with significant security responsibility.

B.4. Individuals with SSR shall have a documented individual training and education plan, which shall ensure currency with position skills requirements, with the first course to be accomplished within 90 days of employment or change of position. The individual training plan shall be refreshed annually or immediately after a change in the individual’s position description requirements.

B.5. Information Secuirty and Privacy training supplied by the Contractor shall meet standards established by NIST and set forth in DHS and TSA security policy.

B.6. T he Contractor shall maintain a list of all employees who have completed training and shall submit this list to the contracting officer representative (COR) upon request, or during DHS/TSA onsite validation visits performed on a periodic basis.

B.7. T he contractor shall its employees review and sign the TSA Form 1403 Computer and Wireless

Mobile Device Access Agreement (CAA) prior to accessing IT systems.

C . Configuration Management (hardware/software)

C.1. Hardware or software configuration changes shall be in accordance with the DHS Information

Security Performance Plan (current year and any updates thereafter), the DHS Continuous Diagnostics and Mitigation (CDM) Program to include dashboard reporting requirements and TSA’s Configuration

Management policy. The TSA Chief Information Security Officer (CISO)/Information Assurance and

Cyber Security Division (IAD) shall be informed of and involved in all configuration changes to the TSA

IT environment including systems, software, infrastructure architecture, infrastructure assets, and end user assets. The TSA IAD POC shall approve any request for change prior to any development activity occurring for that change and shall define the security requirements for the requested change. The COR will provide access to the DHS Information Security Performance Plan.

C.2. T he Contractor shall ensure all application or configuration patches and/or Requests for Change

(RFC) have approval by the Technical Discussion Forum (TDF), Systems Configuration Control Board

(SCCB) and lab regression testing prior to controlled change release under the security policy document, T SA Management Directive (MD) 1400.3 Information Technology Security and TSA Information

Assurance (IA) Handbook, unless immediate risk requires immediate intervention. Approval for immediate intervention (emergency change) requires approval of the TSA CISO, SCCB co-chairs, and the appropriate Operations Manager, at a minimum.

C.3. T he Contractor shall ensure all sites impacted by patching are compliant within 14 days of change approval and release.

C.4. T he acquisition of commercial-off-the-shelf (COTS) Information Assurance (IA) and IA-enabled

IT products (to be used on systems entering, processing, storing, displaying, or transmitting “sensitive information”) shall be limited to those products that have been evaluated and validated, as appropriate, in accordance with the following:

T he NIST FIPS validation program.

T he National Security Agency (NSA)/NIST, National Information Assurance Partnership

(NIAP) Evaluation and Validation Program.

T he International Common Criteria for Information Security Technology Evaluation

Mutual Recognition Agreement.

C.5. US Government Configuration Baseline and DHS Configuration Guidance

a) T he provider of information technology shall certify applications are fully functional and operate correctly as intended on systems using the US Government Configuration Baseline (USGCB) and in accordance with DHS and TSA guidance.

1. USGCB Guidelines:

a. http://usgcb.nist.gov/usgcb_content.html

2. DHS Sensitive Systems Configuration Guidance

a. http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx

b) T he standard installation, operation, maintenance, updates and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. The information technology shall also use the Windows Installer Service for installation to the default “program files” directory and shall be able to discretely install and uninstall.

c) Applications designed for general end users shall run in the general user context without elevated system administration privileges.

C.6. T he Contractor shall establish processes and procedures for continuous monitoring of Contractor systems that contain TSA data/information by ensuring all such devices are monitored by, and report to, the TSA Security Operations Center (SOC). The Contractor shall perform monthly security scans on servers that contain TSA data, and shall send monthly scan results to the TSA IAD.

D. Risk Management Framework

D.1. T he Security Authorization and Ongoing Authorization Process in accordance with NIST SP 800-

37 and SP 800-137 (current versions) is a requirement for all TSA IT systems, including General Support

Systems (e.g., standard TSA desktop, general network infrastructure, electronic mail), major applications and development systems (if connected to the operational network or processing, storing, or transmitting government data). These processes are documented in the NIST Risk Management Framework (RMF).

Ongoing Authorization is part of Step 6 “Monitoring” of the RMF. All NIST guidance is publicly available; TSA and DHS security policy is disclosed upon contract award with some exceptions, which are public facing (i.e., DHS Security and Training Requirements for Contractors).

D.2. A written Authorization to Operate (ATO) granted by the TSA Authorizing Official (AO) also known as TSA Chief Information Secuirty Officer (CISO) is required prior to processing operational data or connecting to any TSA network. The contractor shall provide all necessary system information for the security authorization effort.

http://usgcb.nist.gov/usgcb_content.html http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx https://www.dhs.gov/dhs-security-and-training-requirements-contractors

D.3. T SA shall assign a security category to each IT system compliant with the requirements of

Federal Information Processing Standards (FIPS) Pub 199 Standards for Security Categorization of

Federal Information and Information Systems impact levels and assign security controls to those systems consistent with FIPS Pub 200 Minimum Security Requirements for Federal Information and Information

Systems methodology.

D.4. Unless the AO specifically states otherwise for an individual system, the duration of any

Accreditation shall be dependent on the FIPS 199 rating and overall residual risk of the system; the length can span up to 36 months.

D.5. T he Security Authorization (SA)Package contains documentation required for Security

Authorizations and Ongoing Authorization. The package shall contain the following security documentation: 1) Security Assessment Report (SAR), 2) Security Plan (SP) or System Security

Authorization Agreement (SSAA), 3) Contingency Plan, 4) Contingency Plan Test Results, 5) Federal

Information Processing Standards (FIPS) 199 Security Categorization, 6) Privacy Threshold Analysis

(PTA), 7) E-Authentication, 8) Security Assessment Plan (SAP), 9) Authorization to Operate (ATO)

Letter, 10) Plan of Action and Milestones (POA&M), and 11) Ongoing Authorization Artifacts as required by the DHS Ongoing Authorization Methodology (current version). The SA package shall document the specific procedures, training, and accountability measures in place for systems that process personally identifiable information (PII). All security compliance documents shall be reviewed and approved by the CISO and the IAD, and accepted by the CO upon creation and after any subsequent changes, before they go into effect. Ongoing Authorization artifacts include monthly TRigger

Accountability Log (TRAL), monthly operating system scan results, application scans as directed, updated control allocation table (CAT), and associated memos as directed. All steps in the DHS

Information Assurance Compliance Systems (IACS) shall be completed correctly, thoroughly and in a timely manner for all steps of the RMF.

D.6. T he contractor shall support the successful remediation of all identified system weaknesses and vulnerabilities that are identified as a result of the aforementioned security review process.

D.7. T he contractor shall submit and analyze monthly operating system vulnerability scans for the

DHS Information Security Performance Plan FISMA Scorecard. Vulnerabilities not remediated are generated into Plan of Action and Milestone (POA&M)s after 30 days.

E. C ontingency Planning

E.1. T he Contractor shall develop and maintain a Contingency Plan (CP), to include a Continuity of

Operation Plan (COOP), to address circumstances whereby normal operations may be disrupted and thus require activation of the CP and/or COOP. are disrupted. The contractor’s CP/COOP responsibility relates only to the system they provide or operate under contract.

E.2. T he Contractor shall ensure that contingency plans are consistent with template provided in the

DHS IACS Tool. If access has not been provided initially, the contractor shall use the DHS 4300A

Sensitive System Handbook, Attachment K IT Contingency Plan Template.

E.3. T he Contractor shall identify and train all TSA personnel involved with COOP efforts in the procedures and logistics of the disaster recovery and business continuity plans.

E.4. T he Contractor shall ensure the availability of critical resources and facilitate the COOP in an emergency situation.

E.5. T he Contractor shall test their CP annually and retain records of the annual CP testing for review during periodic audits.

E.6. T he Contractor shall record, track, and correct any CP deficiency; any deficiency correction that cannot be accomplished within one month of the annual test shall be elevated to IAD.

E.7. T he Contractor shall ensure the CP addresses emergency response, backup operations, and recovery operations.

E.8. T he Contractor shall have an Emergency Response Plan that includes procedures appropriate to fire, flood, civil disorder, disaster, bomb threat, or any other incident or activity that may endanger lives, property, or the capability to perform essential functions.

E.9. T he Contractor shall have a Backup Operations Plan that includes procedures and responsibilities to ensure that essential operations can be continued if normal processing or data communications are interrupted for any reason.

E.10. T he Contractor shall have a Post-disaster Recovery Plan that includes procedures and responsibilities to facilitate rapid restoration of normal operations at the primary site or, if necessary, at a new facility following the destruction, major damage, or other major interruption at the primary site.

E.11. T he Contractor shall ensure all TSA data (e.g., mail, data servers, etc.) is incrementally backed up on a daily basis.

E.12. T he Contractor shall ensure a full backup of all network data occurs as required by the system’s availability security categorization impact rating per TSA Information Assurance policy.

E.13. T he Contractor shall ensure all network application assets (e.g., application servers, domain controllers, Information Assurance (IA) tools, etc.) shall be incrementally backed up as required to eliminate loss of critical audit data and allow for restoration and resumption of normal operations within one hour.

E.14. T he Contractor shall ensure sufficient backup data to facilitate a full operational recovery within one business day at either the prime operational site or the designated alternate site shall be stored at a secondary location determined by the local element disaster recovery plan.

E.15. T he Contractor shall ensure that data at the secondary location is current as required by the system’s availability security categorization impact rating.

E.16. T he Contractor shall ensure the location of the local backup repository and the secondary backup repository is clearly defined, and access controlled as an Information Security Restricted Area (ISRA).

E.17. T he Contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1: Network and System Infrastructure for the layout of the file systems, or partitions, on a system’s hard disk impacting the security of the data on the resultant system. File system design shall:

Separate generalized data from operating system (OS) files

Compartmentalize differing data types

Restrict dynamic, growing log files or audit trails from crowding other data

E.18. T he contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1: Network and System Infrastructure for the management of mixed data for OS files, user accounts, externally-accesses data files and audit logs.

F. Program Performance

F.1. T he Contractor shall comply with requests to be audited and provide responses within three business days to requests for data, information, and analysis from the TSA IAD and management, as directed by the Contracting Officer (CO).

F.2. T he Contractor shall provide support during the IAD audit activities and efforts. These audit activities shall include, but are not limited to the following: requests for system access for penetration testing, vulnerability scanning, incident response and forensic review.

F.3. Upon completion of monthly security scans, findings shall be documented and categorized as

High, Moderate, or Low based on their potential impact to the System IT Security posture. The

Contractor shall provide TSA with estimates of the total engineering service hours required to support the remediation of open POA&M items. High security findings shall be remediated first in 45 days or less;

Moderate security findings shall be remediated in 60 days or less, and Low security findings shall be remediated in 90 days or less. The Contractor shall work with the TSA System ISSO and the respective

CO and/or Contracting Officer’s Representative (COR), as well as OIT IAD and the System Owner (as required) to prioritize and plan for the remediation of open POA&Ms. The TSA System ISSO shall maintain all security artifacts and perform Ongoing Authorization (per NIST 800-137 and DHS-TSA requirements) and Continuous Diagnostics and Mitigation (CDM) (per OMB M-14-03) activities to ensure active compliance with security requirements. Specific POA&M guidance and information can be found in the SOP 1401 Plan of Action and Milestone (POA&M) Process, as well as the DHS 4300A PD

Attachment H Plan of Action and Milestones (POA&M) Process Guide.

G. Fe deral Risk and Authorization Management Program (FedRAMP)

If a ve ndor is to host a system with a Cloud Service Provider, the following shall apply:

G.1. Fe dRAMP Requirements: Private sector solutions shall be hosted by a Joint

Authorization Board (JAB)-approved Infrastructure as a Service (IaaS) Cloud Service Provider

(CSP) (http://cloud.cio.gov/fedramp/cloud-systems) and shall follow the Federal Risk and

Authorization Management Program (FedRAMP) requirements. The CSP shall adhere to the following in addition to the FedRAMP requirements:

Identity and entitlement access management shall be done through Federated Identity;

SSI and PII shall be encrypted in storage and in transit as it is dispersed across the cloud;

Sanitization of all TSA data shall be done as necessary at the IaaS, PaaS or SaaS levels;

Cloud bursting shall not occur;

http://cloud.cio.gov/fedramp/cloud-systems

T SA data shall be logically separated from other cloud tenants;

All system administrators shall be properly cleared and vetted U.S. citizens;

T SA data shall not leave the United States; and

T he cloud internet connection shall be behind a commercial Trusted Internet Connection

(T IC) that has EINSTEIN 3 Accelerated (E3A) capabilities deployed. These include but are not limited to the analysis of network flow records, detecting and alerting to known or suspected cyber threats, intrusion prevention capabilities and under the direction of DHS detecting and blocking known or suspected cyber threats using indicators. The E3A capability shall use the

Domain Name Server Sinkholing capability and email filtering capability allowing scans to occur destined for .gov networks for malicious attachments, Uniform Resource Locators and other forms of malware before being delivered to .gov end-users.

G.2. Private Sector System Requirements: TSA shall conduct audits at any time on private sector systems, and the system shall be entered into the TSA FISMA Inventory as a system of record using the Control Implementation Summary (CIS) provided by the Cloud Service

Provider. Security artifacts shall be created and maintained in the DHS IACS. The private sector systems are required to go through the Security Authorization Process and the RMF in accordance the Federal Information Systems Management Act (FISMA) and NIST SP 800-37

Rev. 1. The cloud internet connection shall be behind a commercial Trusted Internet Connection

(T IC) that has E3A deployed. Security event logs and application logs shall be sent to the TSA

SOC. Incidents as defined in the TSA Management Directive 1400.3 and its Attachment 1 (TSA

IA Handbook) shall be reported to the TSA SPOC 1-800-253-8571. DHS Information Security

Vulnerability Management Alerts and Bulletins shall be patched within the required time frames as dictated by DHS and communicated by the contracting officer representative (COR) or contract security point of contact (POC).

H. Information Assurance Policy

H.1. All services, hardware and/or software provided under this task order shall be compliant with applicable DHS 4300A Sensitive System Policy Directive, DHS 4300A Sensitive Systems Handbook, T SA MD 1400.3 Information Technology Security, TSA IA Handbook, Technical Standards (TSs) and standard operating procedures (SOPs).

H.2. T he contractor solution shall follow all current versions of TSA and DHS policies, procedures, guidelines, and standards, which shall be provided by the Contracting Officer.

H.3. Authorized access and use of TSA IT systems and resources shall be in accordance with the TSA

IA Handbook.

H.4. T he contractor shall complete TSA Form 251 and TSA Form 251-1 for sensitive or accountable property. The contractor shall email the completed forms to TSA-Property@dhs.gov and include a hard copy with the shipment.

I. Data Stored/Processed at Contractor Site mailto:TSA-Property@dhs.gov

I.1. Unless otherwise directed by TSA, any storage of data shall be contained within the resources allocated by the Contractor to support TSA and may not be on systems that are shared with other commercial or government clients.

J. Remote Access

J.1. T he Contractor remote access connection to TSA networks shall be considered a privileged arrangement for both Contractor and the Government to conduct sanctioned TSA business.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .