7309r1221102_SCADA.docx

DOCX document 115 KB Posted

Attached to
URGENT Emergency Call Outs SCADA Systems Federal contract opportunity
Solicitation number
7309r1221102
Issued by
International Boundary and Water Commission U.S.-Mexico

View the file

Other files for this federal contract opportunity

Other files attached to URGENT Emergency Call Outs SCADA Systems, newest first.
File Type Posted
7309r1221102_Emergency_Call_outs_SCADA_Systems.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

for The U.S. International Boundary and Water Commission

SCADA Systems Maintenance and Emergency Call out Services

July 2017

1. BACKGROUND

The U.S. Section of the International Boundary and Water Commission (USIBWC) is a federal government agency and the U.S. component of the International Boundary and Water Commission (IBWC), which applies the boundary and water treaties of the United States and Mexico and settles differences that may arise in their application. Established in 1889, the USIBWC is an international body composed of the United States Section and the Mexican Section, each headed by an Engineer-Commissioner appointed by his/her respective president. Each Section is administered independently of the other. The USIBWC is headquartered in El Paso, Texas and supports thirteen field offices throughout the U.S./Mexico border with a single General Support System (GSS). Two field offices, located in San Ysidro, CA and Nogales, AZ have as their primary mission, the treatment of wastewater from Mexico and the surrounding areas through International Wastewater Treatment Plants (IWTP) with Supervisory Control and Data Acquisitions (SCADA) Systems that are completely independent from the HQ, El Paso, General Support System (GSS) System. These systems (SBIWTP SCADA and NIWTP SCADA) are in need of predictive, preventive and timely maintenance. The required services include the application of software and firmware patching and remediation, existing software upgrades and possibly the supply of materials (replacement parts, updated hardware) that may not already be in stock at these sites and any other work deemed necessary the USIBWC within the scope of available contractor services. The Information Management Division (IMD) under the Administrative Department of the Agency, manages and supports all Information Technology (IT) resources and services for the USIBWC. The IMD is responsible for overseeing and assisting agency-specific efforts to provide adequate, risk-based, and cost-effective cybersecurity for all USIBWC Systems, per Office of Management and Budget (OMB) Memorandum 10-28 and The Federal Information Security Modernization Act of 2014.

The SCADA Systems located in San Ysidro, CA and Nogales, AZ are integral parts of the USIBWC’s critical infrastructure and are essential to facilitating our mission operations. The growing issue of cybersecurity and its impact on Industrial Control Systems (ICS) or SCADA systems highlights fundamental risks to our Nation’s critical infrastructure and the USIBWC is in need to implement a Defense-in-Depth and maintenance strategy to our SCADA Systems to ensure they continue to evolve and operate in a secure, multi-layered environment that can adjust to the marked increase in cyber-based attacks on critical infrastructure systems. The USIBWC seeks a contractor that understands the relationship of threats and vulnerabilities to controls, standards and countermeasures put in place to protect the operations, personnel and technologies that make up our SCADA systems. Existing software at both sites include but are not limited to Rockwell Rslogix, Ignition, VMWare ESX, Kaptus Solutions KaptusMobile, ThinManager and Factorytalk ME and both Windows and Linux operating systems. The tools, maintenance enhancements and services required through this PWS will provide the USIBWC with the ability to enhance/automate our capabilities, correlate, analyze critical security-related information, and enhance risk-based decision making at the agency and Federal enterprise level.

2. OBJECTIVES

The USIBWC’s IMD has a mission to safeguard and secure our SCADA environments where the cyber-attack threat is continuously growing and evolving. This acquisition is intended to assist the USIBWC utilize managed services for functions that require highly specialized skills and technologies to include incident response forensics, cyber vulnerability mitigation, risk management, continuity of operations and incident response training, and assist in implementing an effective maintenance and emergency call-out program. The services acquired by this PWS should help to defend USIBWC SCADA Systems from cybersecurity threats by providing discovery efforts and documentation of existing Systems and establishing a progressive maintenance program that will provide the necessary controls and IT security requirements specific to SCADA systems.

The USIBWC’s vision is to achieve a full understanding and documentation of site operations, and validation of all the needs, equipment usages and procedures implemented as part of the recent SCADA System upgrades. The outcome of this contract is to have all System and operations processes identified in a Sequence of Operations (SOO) or Process Narrative. The SOO will define the processes in the content of the supporting documentation and system programing which makes for a triangulation of information for any future support needs. Keeping existing software/firmware up to date and implementing an aggressive patching and remediation and backup program for each of the sites is also an objective requirement.

3. CONTRACTOR REQUIREMENTS

The contractor must provide documentation and/or a summary of experience that shows they possess the following credentials, skills and knowledge necessary to provide the specialized services the USIBWC requires at both SCADA System sites:

(a) The contractor should provide documentation or a summary on the level of knowledge and experience they have in working with SCADA Systems within wastewater treatment plants and their familiarity with wastewater treatment processes and operations.

(b) One of more contractor staff must have passed a minimum of Ignition Core Training. Ignition is the main software used within our SCADA environments and is essential to work with existing HMI’s and System components. Provide basic training certificate of completion or other credentials for training completion.

(c) The contractor must possess Cisco switchgear experience. Both SCADA System network equipment consists of Cisco hardware and is essential for the USIBWC to achieve the level of network efficiency our SCADA networks require. Provide training or certification certificates and summary of experience to include the level of expertise managing, patching and configuring Cisco networking equipment.

(d) The contractor must be a Rockwell solutions provider with extensive Rockwell experience. Contractor should possess or have the ability to obtain a solutions provider agreement with Rockwell in order to provide sufficient support and ensure appropriate licenses required for support will be available. Contractor is required to provide solutions provider credentials.

(e) The contractor must have VMWAre ESX environment experience to work with, manage, update and configure virtual System components and use as part of a patch testing and deployment process. Experience should include the ability and knowledge on how to allocate resources and monitor for issues within a virtual environment. Experience in disaster recovery and backup of virtual environments should also be submitted.

(f) Networking experience including but not limited to firewall management and configuration, fiber networks, and VLans in order to document, diagnose, update, configure and maintain USIBWC SCADA System networks

(g) Programming knowledge and experience with Java.

(h) Programming knowledge and experience with Python.

(i) Experience in using ThinManager Platinum is essential to ensure System growth, automation and the integration of new clients or replacements as necessary.

(j) Experience and knowledge in working with Kaptus Solutions Kaptus Mobile Experience for alarming and alerting purposes.

(k) The contractor will provide remote support by using established remote access procedures and telephone support to on-site employees to assess, troubleshoot or improve plant operations. The expectations for remote support is that it will be on-call during daytime hours Monday through Friday and available for emergency call-outs as necessary and approved by the IMD.

Some examples of required remote support include:

1) Accessing the System remotely to diagnose SCADA System issues and identify root causes and solutions to issues or delays with Plant processes.

2) Adjusting plant control parameters through a combination of mechanical and PLC changes.

3) Troubleshooting equipment problems that affect the plant’s efficiency or long-term operability.

4) Remotely troubleshooting Network Issues for determining root cause issues and resolutions.

5) Walk on-site personnel through the application of solutions that cannot be physically performed remotely.

4. REGULATIONS COMPLIANCE

The contractor shall be required to comply and utilize the following laws and guidance to conduct quality control of the work and services provided. Applying the best practices described within the following guidance will ensure our SCADA Systems are sufficiently protected and that the work and services provided align with NIST’s Federal Cybersecurity Framework, industry best practices and USIBWC business practices.

(a) The Federal Information Security Modernization Act of 2014

(b) NIST SP-800-82, Revision 2, Guide to Industrial Control Systems (ICS) Security

(c) DHS-Homeland Security’s Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies, September 2016

(d) DHS-Homeland Security’s Configuring and Managing Remote Access for Industrial Control Systems, November 2010

(e) DHS-Homeland Security’s Recommended Practice for Patch Management of Control Systems, December 2008

(f) The contractor and USIBWC will agree within a Service Level Agreement (SLA), MOU or ISA, to specific management and technical requirements for the provided services.

5. DELIVERABLES

For South Bay International Wastewater Treatment Plant (SBIWTP) and Nogales International Wastewater Treatment Plant (NIWTP). Each site has a lack of site documentation and a need to discover, identify and document the plant’s current operations as necessary by completing the following tasks:

(a) Plant operations shall be detailed and documented in a SOO document that will need to be reviewed and verified by Plant personnel.

(b) The initial discovery process of both sites will take place with cooperation of onsite personnel and within 45 days from date of award of this contract. The contractor will visit each site to familiarize itself with existing site locations, meet on-site personnel and conduct an initial assessment on how to best initiate and complete the SOO documentation and work described within this contract.

(c) Completed work will fully document detailed plant operations. It will be segmented by plant process and will document each of the sub-processes, their components, the SCADA references and the interconnectivity of all devices and their processes. The SOO will outline the process path so the facility can be further automated to minimize operator intervention, while also identifying any preventive and predictive maintenance suggestions if they require additional work to be of value.

(d) Identify network design issues and provide a plan (including time and materials) required to improve internal System performance, remote access management and the implementation of IT Security controls. Improvements to the System shall include:

1) Troubleshooting and providing a solution for any bandwidth issues required for remote backup capabilities

2) Disable unnecessary service, ports, protocols, applications and functions to prevent vectors for malicious parties to gain access to the System.

3) Configure the system to provide only essential services and capabilities for operational and testing requirements.

4) Work with the IMD to establish multi-factor authentication for local and remote access using government issued PIV cards.

5) Restrict SCADA System user privileges to only those that are required to perform each job or task. The employment of least privilege principles should be applied allowing only authorized access for users, which are necessary to accomplish assigned tasks in accordance with organizational mission and business functions.

6) Evaluate existing centralized patch management application to efficiently control the distribution of patches and upgrades where applicable. Work with USIBWC staff to improve and make more efficient, the existing procedures to test patches to identify potential incompatibilities with network gear before deployment.

(e) SOO documentation will outline all the existing coding, instrumentation, license information and all equipment that would help alleviate networking costs on future projects and allow for better management of the Systems’ network. It shall include recommendations required to get the System to a fully automated state. The documentation shall include an Asset Inventory based on existing documentation to validate what is physically on site and determine a Risk Characterization of each asset. This assessment will include the following:

1) Identify each asset that exists within the existing SCADA System

2) Identify the level of protection each asset requires (physical or INFOSEC)

3) Identify the level of threat each asset would have if compromised; what realistic worst-case scenario would result if compromised?

4) Determine the asset value in the overall SCADA System process. How important is this asset and does it have a priority over others to recover in case of recovery efforts.

5) What is the criticality of the process or information to the process mission

6) What interconnections are required for the System to perform

7) What methods are currently available for use access of each asset

8) What dependencies are present for System functionality

9) How does the information flow through the System and through what mechanisms?

10) Validate from existing inventory, make model and other necessary information from assets to include in inventory documentation.

11) Determine/institute historical recording of any of these assets for:

a) Current data being recorded

b) Value date to be recorded

c) Available on-board diagnostics via comms or relays

d) Establish viability of incorporating those signals into existing SCADA application

12) Implement identified points needed to be brought into SCADA

13) Establish all relevant maintenance cycles from vendor/site knowledge

14) Establish historical failure cycles from vendor

15) Determine critical components and establish on-site spares needs

16) Establish lead-lag and load balance approach for all such subsystems.

17) Establish common run-time correlations for service alarms in SCADA with recorded acknowledgement when maintenance is performed

18) Create necessary reports through Ignition required by USIBWC staff for compliance or business operations

(f) The purpose of this documentation is to identify the thread that defines assets from its mission (purpose) to the asset itself to supporting infrastructure to SCADA dependencies. This will reveal which SCADA components are more critical when applying necessary security controls. Based on this information, the contractor shall rate the security categorizations based on the potential impact (low, moderate, or high) on plant operations should an event occur that jeopardizes its ability to accomplish its mission, protect its assets, fulfill its legal responsibilities and maintain its day to day functions.

(g) The contractor will provide the SOO in a draft version within 120 days of award of this contract for USIBWC review. The USIBWC will have a 30-day period for markups, concurrence and approval. Upon approval, the contractor shall incorporate any changes/modifications and provide the final product to the IMD. The final SOO will help plan support operations, prioritize maintenance and identify SCADA system improvements that can be applied as part of this contract by the end of the period of performance

(h) Monthly reports on the progress of the SOO documentation is required by the first Friday of each month from the award of this contract. The report shall specify progress on ongoing work and a plan with deadlines for remaining work to be completed.

(i) The contractor shall be able to provide pertinent, detailed information and required comprehensive predictive analysis of Ignition SCADA software, to include performing upgrades/updates to the application and update operational screens as needed.

(j) Operator screens within Ignition shall be updated/upgraded based on site improvements and automation needs identified and implemented by the contractor.

(k) The contractor shall be required to provide training to on site staff on the SCADA System and Ignition application not limited to and including:

1) Required maintenance procedures

2) Continuity of Operations tasks such as backups and system recovery

3) Incident Response training

4) Backup and recovery operations of Systems data

5) General use and operations of Ignition software and automated procedures to make their operations of the plant more efficient

6) Assistance in updating existing policies and procedures

(l) The contractor shall provide all software/firmware upgrades, patching and remediation work necessary to keep the System up to date and protected from existing and future vulnerabilities and threats identified through Microsoft, Ignition, US-CERT and ICS-CERT vulnerability reports and bulletins within the required timeframes.

(m) The contractor will develop and implement within 60 days of award of this contract, a patching plan to keep software patches and upgrades up to date within the specified time period after release, based on criticality. The contractor will follow the established USIBWC Configuration Management Policy to initiate change control and patching processes to either System and will recommend approval only after each patch has been tested within a test environment. Deployment of patches or upgrades must first be approved prior to deployment on the production system. The contractor shall follow all best practices referenced in the guidance provided in DHS’s “Recommended Practice for Patch Management of Control Systems” of December 2008

(n) The contractor shall test all patches in established virtual environments that contain the same model and type of SCADA system software to determine whether the patch has unintended consequences. Only after patches are successfully tested and approved by the IMD can patching proceed on the live SCADA System environment.

(o) The contractor will provide on-site resources within 8 hours of the need being identified to address issues and operational concerns that cannot be handled over the phone by on-site staff.

(p) The contractor will receive guidance from USIBWC IMD personnel on which patches or remediation procedures to initiate based on reports and recommendations from an existing Continuous Monitoring service provider.

(q) The contractor will work with USIBWC personnel and established guidelines to produce an effective and efficient Incident Response and Disaster Recovery plan.

(r) The contractor shall implement security controls approved by the USIBWC in accordance with priority. The most critical (high impact) and most vulnerable (high likelihood) system assets shall be the first priority for risk reduction and mitigation activities.

(s) For the SBIWTP, provide a path to upgrade the aged legacy PLC systems and document any associated decline in the older hardware. Identify the most likely areas of failure due to age of software and electronics

6. SCOPE

The Contractor shall provide the following System maintenance and services describe above to both SCADA Systems (SBIWTP SCADA and NIWTP SCADA).

CLIN
SERVICES
DESCRIPTION
001
Site Documentation and Discovery Operations
The contractor will complete tasks described in Deliverables paragraph 5 to validate existing assets and document a Sequence of Operations (SOO) documentation of all components and functionality of the SCADA Systems. This work will be used to plan support operations, prioritize maintenance and identify SCADA system improvements that can be applied as part of this contract by the end of the period of performance. Support in validating and compiling System inventory’s.
002
Maintenance and Improvements of SCADA Systems Hardware and Software
Maintenance and Improvements of System hardware and software as recommended in final SOO from CLIN 001. Perform necessary patching and software upgrades as approved by USIBWC remotely and/or onsite, to include assessments, testing, implementation of patching and repairs. System components updates/upgrades to latest version, patches and firmware. Perform programming and product upgrades needed to keep the System in optimal working order. Perform System security and maintenance improvements as described within SOO. Perform operations screens modifications to enhance functionality as required. This CLIN will be billed monthly for actual work hours performed.
003
Emergency Response to Incidents and Operations Issues
Emergency response to resolve any emergency repair or continuity of operation tasks on existing software and all network components (Servers, routers, switches, backup software/hardware) performed on-site or remotely at either SCADA System site. This CLIN will be billed monthly for actual work hours performed.
004
Training on SCADA Systems Operations
Contractor will create and maintain all training manuals and documentation on the proper use and functionality of all SCADA System components at both IWTP sites. Annual disaster recovery training will be provided to all operators and administrators by the end of this period of performance. This CLIN will be billed monthly for actual work hours performed.
005
Travel
Two Quarterly trips (8 trips x 2 sites = 16)
006
Provide Project Management
The contractor shall provide all necessary personnel, administrative, financial, and managerial resources necessary for the support of contract accomplishment. This includes the management and oversight of its performance of the contract and work performed by contractor personnel, including subcontractors and teaming arrangements/partners, to satisfy the requirements identified in the contract. The contractor shall provide this support in accordance with the terms and requirements of this BPA and the specific requirements of the order.

Examples of support:

a. Convene technical status meetings.

b. Prepare project management documentation such as a project management plan (PMP), staffing plan, and project schedules

c. Manage contractor personnel assigned to the order.

d. Prepare trip reports.

e. Prepare problem notification reports.

7. Patching Level Expectations Vulnerability scan results and reports will be made available by the USIBWC to the contractor for action per the time frames in table 7-1. Identified patches, software and firmware updates of all System components shall be completed in accordance with the established patching process (testing, validation, documentation and scheduling of production patching) and within the following timeframes: Critical patches = 30 days, High level patches = 60 days, Low level patches = 90 days. Reports on hours spent performing patch management and remediation tasks will be documented and reported monthly to reconcile against monthly invoices.

Table 7-1: Patching and Remediation Response Times

Category
Response Time
Critical Vulnerabilities
Within 30 days of notification
High Vulnerabilities
Within 60 days of notification
Low Vulnerabilities
Within 90 days of notification
Response to Emergency Response requirements
Within 8 hours

8. USIBWC Points of Contact The following Points of Contact are provided for the contractor to help perform the scope of requirements under this contract and report activities towards each CLIN completion. If the contacted personnel are unavailable, the notification will be raised to the next contact listed.

Table 4-1: Primary Points of Contact for USIBWC

USIBWC Headquarters

Contact
Phone
Email
Maritza Dominguez, Network Admin
915-832-4130 (work)

Maritza.Dominguez@ibwc.gov

Z. Mora, Supervisor, ISSM
(915) 832-4755 (work)

(915) 929-7727 (cell) z.mora@ibwc.gov

Nogales, IWTP

John Light, USIBWC Area Operations Mngr.

(520) 281-5814 (work)

(520) 470-9029 (cell) John.light@ibwc.gov

Lorenzo Ortiz, AAOM
(520) 281-5814 (work)

(520) 262-2494 (cell) Lorenzo.ortiz@ibwc.gov

Shannon Jackson, Operator
(520) 281-1832 (work)
Shannon.jackson@ibwc.gov

South Bay, IWTP

Steve Smullen, USIBWC Area Operations Mngr.
(619) 662-7601 (work)

(619) 405-4224 (cell) Steve.Smullen@ibwc.gov

Robert Nienhuis, SBIWTP Superintendent
(619) 662-7690 (work)

(909) 994-7507 (cell) Robert.Nienhuis@veolia.com

Victor Gurule, SCADA System Analyst
(619) 662-7684 (work)

(619) 207-9101 (cell) Victor.Gurule@veolia.com

9. REQUIRED PERFORMANCE METRICS (RPM) TABLE

Required Service
Performance

Standards Acceptable Quality Levels (AQL) Method Of Surveillance Incentive (Negative) (Impact on Contractor Payments)

The contractor will provide the SOO in draft within 120 days of award for USIBWC review.
Section 5 Deliverables, (g)
100%
Report review
$100 shall be deducted from the monthly payment amount for each day passed 120 days that the USIBWC does not receive the draft SOO.

Site Documentation (SOO) & Discovery Operations

Section 5 Deliverables, (h)

100%

Monthly reports review, periodic/random inspection, submissions for review

$100 shall be deducted from the monthly payment amount for each instance where documentation on SOO development progress is not provided for review by the first Friday of each month.

Regular Maintenance of SCADA Hardware & Software (Patching & Upgrades)
Section 5 Deliverables, 7 Patching Level Expectations

Monthly reports review, IMD staff reports, inspection, complaints

$200 shall be deducted from the monthly payment amount for each instance (each reported patch or upgrade) where criticality/category were not met within it respective timeframe.

Initial site familiarization visit
Section 5 Deliverables, (b)
100%
On site report, USIBWC personnel reporting
$100 shall be deducted from the monthly payment amount for each day passed the 45-day requirement that it takes to complete both site visits.
Training on SCADA Systems Operations
Section 5 Deliverables, (k)

100%

Certificates of completion for each student for each course.

$1000 shall be deducted from the final payment if required training has not been provided as required by the end of the period of performance of this contract.

The contractor will develop and implement a patching plan
Section 5. Deliverables (m)
100%
Receipt of Plan
$100 for every day passed the 60-day requirement shall be deducted from the monthly payment amount for each day it takes to receive an implemented patching and upgrade plan for both sites.

Emergency Response to Incidents and Operations Issues Section 5. Deliverables (o)

Emergency response documentation, inspection, complaints

$100 shall be deducted from the monthly payment amount for each incident response time not in compliance within the required 8-hour time frame.

Provide Project Management

Section 2.0, Scope

Timeliness of reporting, status meetings, inspection, verification of data provided

$100 shall be deducted from the monthly payment amount for each instance the USIBWC does not receive monthly meeting minutes or project progress /management plans

10. INCREMENTAL FUNDING LIMITATION OF GOVERNMENT’S OBLIGATION

If an order is incrementally funded, it shall specify the total amount of the order, the amount obligated, the estimated performance period based on the amount of obligated funds, and a statement that the contractor is not required to perform work nor is the Government obligated to reimburse the contractor for work performed in excess of the amount obligated.

11. AVAILABILITY OF FUNDS

The Government's obligation on orders placed under this contract is contingent upon the availability of appropriated funds from which payment for ordering purposes can be made. No legal liability on the part of the Government for any payment may arise until funds are available and until there is written notice to the contractor from the Contracting Officer.

12. FFP “AS A SERVICE” PRICING IN ORDERS

It is the Government’s intent to implement “as a service” pricing for some orders when appropriate to the Government’s requirements. This will be one or more FFP CLINs that will bundle software, ancillary hardware, and services requirements for a defined contract period into one FFP price. The contractor shall then propose one FFP based on hardware, tools, and services as available on contractor’s IT Schedule 70 and this BPA. If required, details instructing the contractor to provide pricing for these CLINs will be in the order.

13. TITLE

This acquisition will provide the USIBWC with specialized information technology (IT) services and tools necessary to comply with DHS’ Continuous Diagnostic and Mitigation (CDM) program requirements. The CDM program seeks to defend Federal and other government IT networks from cyber-security threats by providing continuous monitoring sensors (tools), diagnosis, mitigation tools and Continuous Monitoring as a Service (CMaaS) to strengthen the security posture of Government networks.

Within the scope of this contract, the contractor shall provide tools and services required by the USIBWC to implement an effective CDM program. The scope for Tools and CMaaS includes the tool functional and task areas, as well as providing ancillary hardware as listed in Section 2.0.

For this procurement, the Government uses the term “as a service” within the acronym “CMaaS” to represent the IT professional services required to implement, maintain, and operate CM tools. At the order level, there are two options: Tools and services may be purchased individually or “as a service.” However, for the purpose of price evaluation and award of this contract, the pricing requested is traditional FFP for tools and LH for services. Therefore, this CONTRACTuses the term “CMaaS” to represent all CM IT services regardless of how they are priced or deployed.

14. PERIOD OF PERFORMANCE

The period of this contract is for one-year from the time of award.

15. CONTRACTING OFFICER’S REPRESENTATIVE (COR)

The CO will appoint a COR in writing using a COR Appointment Letter that will be provided to the contractor upon award.

CORs are not authorized to change any of the terms and conditions, scope, schedule, and price of the contract. Changes in the scope of work will be made only by the Ordering CO by properly executed modifications to the order or by modification to the contract.

16. CONTRACT ADMINISTRATION

Contracting Officer:

To be determined
Contracting Officer
U.S. International Boundary and Water Commission
4171 N. Mesa, C-100
El Paso, TX 79902
Telephone: (915) 832-4120
Email:

Contracting Officer’s Representative:

Zenon Mora Supervisory, IT Specialist / ISSM U.S. International Boundary and Water Commission 4171 N. Mesa, C-100 El Paso, TX 79902 Telephone: (915) 832-4755 Cell: (915) 929-7727 Email: z.mora@ibwc.gov

17. ORDER QUOTE SUBMISSION

At a minimum, the quote shall include:

(a) Price: The quote may include a detailed cost per hour of all labor required to accomplish the tasks as set forth in this PWS, or be a fixed-price quote with sufficient information to substantiate the price quoted. Prime contractor shall provide off-site or on-site rates as required by the order. The discounts offered do not preclude the prime contractor from offering or the Government requesting, further price reductions in accordance with commercial practices, market forces, and volume buying at the time of placing orders.

(b) Statement disclosing any known or expected conflicts of interest pursuant to FAR 9.5: The quote may also require the submission of the following information (the Government is not limited to the below list and may require other information):

1) Technical information (e.g., technical approach, including team partners and experience as required by the PWS).

2) Technical data, computer software, and computer software documentation, if applicable, as required in reference to meeting the needs of the statement of work in the PWS.

3) Corporate Experience (as it relates to the specific requirements of an order).

4) Proposed Key Personnel and Staffing.

5) Price Quote and any additional discounts against the schedule labor rates.

(c) Evaluation: The Government will evaluate responses against evaluation criteria contained in the order PWS.

18. ORDER ISSUANCE

The SOW, labor mix, and hours (if applicable), as well as a proposed ceiling price for the PWS, may be incorporated into the order. The proposed technical solution may also be incorporated in the order. Each order shall, as appropriate:

(a) Set forth a pricing schedule.

(b) Set forth the specific level of effort and/or performance outcomes desired to be fulfilled under the order based on the estimated dollar value and complexity of the proposed order.

(c) Designate the Ordering COR who will perform inspection and acceptance.

(d) Set forth any payment options.

(e) Be dated.

(f) Set forth the property, if any, to be furnished by the Government and the date(s) such property is to be delivered to the contractor.

(g) Set forth the disbursing office where payment is to be made.

(h) Set forth administration data.

(i) Set forth the contractor’s and Government’s respective technical data rights.

(j) Set forth any other pertinent information

19. INVOICE REQUIREMENTS

Invoices shall be submitted in accordance with FAR Clause 52.212-4(g). Invoices shall be submitted to invoices@ibwc.gov with a courtesy copy sent to the CO and COR.

20. FIRM-FIXED-PRICE (FFP) CLINs If no payment schedule is specified in the order, the contractor may invoice on a monthly basis, the amount obtained by dividing the FFP amount for the order period, by the number of months of performance in the period. For FFP CLINs, the invoice shall include the period of performance period covered by the invoice, and the CLIN number and title. All amounts invoiced shall be reported by CLIN element (as shown in Section 1 – Supplies or Services and Price of the order) and shall be provided for the current invoice and in total from project inception to date. The contractor shall provide the invoice data in spreadsheet form with the following detailed information. The listing shall include separate columns and totals for the current invoice period and the project to date.

(a) FFP period of performance period

(b) Amount invoiced

21. TRAVEL

The contractor may invoice monthly on the basis of cost incurred for cost of travel comparable with the Joint Travel Regulation (JTR)/Federal Travel Regulation (FTR). The invoice shall include the period of performance covered by the invoice, the CLIN number and title, and the GSA Schedule number. Separate worksheets, in MS Excel format, shall be submitted for travel.

CLIN/Task Total Travel: This invoice information shall identify all cumulative travel costs billed by CLIN/Task. The current invoice period’s travel details shall include separate columns and totals and include the following:

(a) Travel Authorization Request identifier, approver name, and approval date

(b) Current invoice period

(c) Names of persons traveling

(d) Number of travel calendar days

(e) Dates of travel

(f) Number of calendar days per diem charged

(g) Per diem rate used

(h) Total per diem charged

(i) Transportation costs (rental car, air fare, etc.)

(j) Total charges

(k) Explanation of variances exceeding 10% of the approved versus actual costs

(l) Indirect handling rate

22. GOVERNMENT-FURNISHED PROPERTY (GFP) AND

GOVERNMENT FURNISHED INFORMATION (GFI)

The USIBWC may provide the contractor with some of the necessary information, and/or office space required to perform the services outlined in this contract. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract.

In addition, the contractor shall protect all Government data, etc., by treating the information as sensitive. Sensitive but unclassified information, data, and/or equipment will only be disclosed to authorized-personnel as described in the order. The contractor shall keep the information confidential, use appropriate safeguards to maintain its security in accordance with minimum Federal standards.

When no longer required, this information, data, and/or equipment shall be returned to Government control, destroyed, or held until otherwise directed by the CO. The contractor shall destroy unneeded items by burning, shredding, or any other method that precludes the reconstruction of the material.

Work under this contract may require that the contractor’s personnel have access to information covered under the Privacy Act. Contractor personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, section 552a and applicable agency rules and regulations.

23. ACCESS TO FACILITIES, SYSTEMS AND SECURITY CLEARANCE REQUIREMENTS

The USIBWC does have specific personnel security and background check requirements in order for contractor personnel to access the facilities and SBU systems necessary to perform the work. When these requirements exist, they will be detailed in the PWS, along with any special instructions. Top secret clearance or equivalent background investigation (SSBI). All personnel touching these systems, whether the primary contractor or any sub-contractor, must have U.S citizenship.

24. SECURITY REQUIREMENTS

The contractor is advised to review the NIST documents to determine the level of effort that will be necessary to complete the requirements.

25. USIBWC SYSTEM SECURITY COMPLIANCE REQUIREMENT

The data that will be processed by the information systems being requested in support of contract requirements will be classified by the Office of the Chief Information Officer (OCIO), or equivalent for impact in the PWS, in all three categories (confidentiality, integrity, and availability) as defined in Federal Information Processing Standards (FIPS) Pub 199, “Standards for Security Categorization of Federal Information and Information Systems.” The three categories are defined as follows:

Definitions:

(a) CONFIDENTIALITY: “Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information…” [44 U.S.C, Sec 3542] A loss of confidentiality is the unauthorized disclosure of information.

(b) INTEGRITY: “Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity…” [44 U.S.C., Sec 3542] A loss of integrity is the unauthorized modification or destruction of information.

(c) AVAILABILITY: “Ensuring timely and reliable access to and use of information…” [44 U.S.C., Sec 3542] A loss of availability is the disruption of access to or use of information or an information system.

NIST Special Publication 800-53 Revision 3, “Recommended Security Controls for Federal Information Systems” (hereafter described as NIST SP 800-53) defines requirements for compliance to meet the minimum-security requirements. NIST SP 800-53 requirements are viewed as mandatory requirements for which some risks are acceptable, but generally most requirements pertaining to the impact level must be incorporated into the infrastructure. The controls requiring organizational defined parameter will be provided by the ordering activity within the individual PWS.

The contractor shall implement the controls from NIST SP 800-53 for the appropriate impact level (as defined in FIPS 199). The Government has determined that the appropriate impact level for CDM systems is “high” for confidentiality and integrity and “moderate” for availability.

The contractor shall generally and substantially and in good faith follow NIST guidelines and any security guidance provided by the ordering activity, or activity being supported by the order, as appropriate. Where there are no procedural guides, the contractor shall use generally accepted industry best practices for IT security.

26. REQUIRED SECURITY POLICIES AND REGULATIONS

To perform work on orders under this contract, the contractor shall be subject to all ordering activity IT security standards, policies, reporting requirements, and Government-wide laws or regulations applicable to the protection of Government-wide information security.

Contractors are also required to comply with FIPS, the “Special Publications 800 series” guidelines published by NIST, and the requirements of FISMA.

· Federal Information Security Management Act (FISMA) of 2002.

· Clinger-Cohen Act of 1996 also known as the “Information Technology Management Reform Act of 1996.”

· Privacy Act of 1974 (5 U.S.C. § 552a).

· Homeland Security Presidential Directive (HSPD-12), “Policy for a Common Identification Standard for Federal Employees and Contractors,” August 27, 2004.

· Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information Resources,” and Appendix III, “Security of Federal Automated Information Systems,” as amended.

· OMB Memorandum M-04-04, “E-Authentication Guidance for Federal Agencies.”

· FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information Systems.”

· FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information Systems.”

· FIPS PUB 140-2, “Security Requirements for Cryptographic Modules.”

· NIST Special Publication 800-18 Rev 1, “Guide for Developing Security Plans for Federal Information Systems.”

· NIST Special Publication 800-30, “Risk Management Guide for Information Technology Security Risk Assessment Procedures for Information Technology Systems.”

· NIST Special Publication 800-34, “Contingency Planning Guide for Information Technology Systems.”

· NIST SP 800-37, Revision 1, “Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach.”

· NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology Systems.”

· NIST Special Publication 800-53 Revision 4, “Recommended Security Controls for Federal Information Systems.”

· NIST Special Publication 800-53A, “Guide for Assessing the Security Controls in Federal Information Systems.”

· NIST Special Publication 800-82r2, “Guide to Industrial Control Systems (ICS) Security (May 2015)

· Department of Homeland Security: Cyber Security Procurement Language for Control Systems (Sept 2009)

· Recommended Practice for Patch Management of Control Systems (Dec 2008)

· Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies

· Configuring and Managing Remote Access for Industrial Control Systems

27. ADDITIONAL SECURITY STIPULATIONS

Under this contract, deliverables designated in the PWS shall be labeled “FOR OFFICIAL USE ONLY” (FOUO) or SENSITIVE BUT UNCLASSIFIED (SBU) designation per document sensitivity. External transmission/dissemination of SBU to or from a Government computer must be encrypted. Certified encryption modules must be used in accordance with FIPS PUB 140-2, “Security requirements for Cryptographic Modules.”

As prescribed in the Federal Acquisition Regulation (FAR) 24.104, if the system involves the design, development, or operation of a system of records on individuals, the contractor shall implement requirements in FAR clause 52.224-1, “Privacy Act Notification” and FAR clause 52.224-2, “Privacy Act.”

The Government has the right to perform manual or automated audits, scans, reviews, or other inspections of the vendor’s IT environment being used to provide or facilitate services for the Government. The contractor shall be responsible for privacy and security safeguard provisions in accordance with FAR clause 52.239-1 “Privacy and Security Safeguards.”

The contractor shall not publish or disclose in any manner, including responding to press inquiries, without the Ordering CO’s written consent, the details of any security safeguards either designed or developed by the contractor in support of this contract or otherwise provided by the Government.

To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of any non-public Government data collected and stored by the contractor, the contractor shall afford the Government logical and physical access to the contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases within 72 hours of the request. Automated audits shall include, but are not limited to, the following methods:

(a) Authenticated and unauthenticated operating system/network vulnerability scans.

(b) Authenticated and unauthenticated web application vulnerability scans.

(c) Authenticated and unauthenticated database application vulnerability scans.

Automated scans may be performed by Government personnel, or agents acting on behalf of the Government, using Government-operated equipment, and Government-specified tools. If the contractor chooses to run its own automated scans or audits, results from these scans may, at the Government’s discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by the Government. In addition, the results of vendor-conducted scans shall be provided, in full, to the Government.

If new or unanticipated threats or hazards are discovered by either the Government or the contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

28. ORGANIZATIONAL CONFLICT OF INTEREST

For work to be performed in support of this contract, if the contractor has or is currently providing support or anticipates providing support to the department or agency, for whom order work is being performed, that creates or represents an actual or potential organizational conflict of interest (COI), the contractor shall immediately disclose this actual or potential COI in accordance with FAR Subpart 9.5. The contractor is also required to complete and sign an Organizational Conflict of Interest Statement in which the contractor (and any subcontractors, consultants or teaming partners) agrees to disclose information concerning the actual or potential conflict with any quote for any solicitation relating to any work in the order. All actual or potential COI situations shall be handled in accordance with FAR Subpart 9.5.

29. NON-DISCLOSURE REQUIREMENTS

If the contractor acts on behalf of, or provides advice with respect to any phase of an agency procurement, as defined in FAR 3.104-4, then the contractor shall ensure that all its personnel (to include subcontractors, teaming partners, and consultants) who will be personally and substantially involved in the performance of the order:

(a) Execute and submit a Corporate Non-Disclosure Agreement (NDA), using procedures outlined in the order PWS, prior to the commencement of any work on the order, and Are instructed in the FAR 3.104 requirements for disclosure, protection, and marking of contractor bid or quote information, or source selection information.

All proposed replacement contractor personnel also must submit a Non-Disclosure Agreement and be instructed in the requirements of FAR 3.104. Any information provided by contractors in the performance of order work under this BPA, or obtained by the Government, is only to be used in the performance of the order. The contractor shall put in place appropriate procedures for the protection of such information and shall be liable to the Government for any misuse or unauthorized disclosure of such information by its personnel, as defined above.

30. INTELLECTUAL PROPERTY RIGHTS

The existence of any patent, patent application, or other intellectual property right that encumbers any deliverable must be disclosed in writing on the cover letter that accompanies the delivery. If no such disclosures are provided, the data rights provisions in FAR 52.227-14, Rights in Data – General, Alt. II and III apply. The Software Agreements referenced in Section 7.9, amended as contemplated therein, shall be deemed to constitute such disclosure with regard to their associated commercial software tools and shall prevail over any inconsistent provision in FAR 52.227-14, Rights in Data – General, Alt. II and III to the extent of such inconsistency.

31. U.S. GOVERNMENT CONFIGURATION BASELINE (USGCB)

The contractor shall certify that software applications and tools are fully functional and operate correctly as intended on systems using the USGCB. The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved USGCB configuration.

Applications designed for normal end users shall run in the standard user context without elevated system administration privileges. The contractor shall use Security Content Automation Protocol (SCAP) validated tools with USGCB Scanner capability to certify their products operate correctly with USGCB configurations and do not alter USGCB settings.

image1.jpeg

File details come from the government source that posted it. Updated .