Attachment 1 - PWS - Amend 01.pdf
PDF 1 MB Posted
- Attached to
- FDA NCTR On-Site Animal Care and Technical Procedures Federal contract opportunity
- Solicitation number
- 75F40123R00001
About this file
This is a performance work statement (PWS) for animal care and technical procedures support services for the U.S. Food and Drug Administration's National Center for Toxicological Research (NCTR). The contractor will provide animal husbandry, technical procedures, sanitation, diet formulation, and data management to support NCTR's IACUC-approved research protocols. Services include care of mice, rats, nonhuman primates such as rhesus macaques, zebrafish, and potentially mini-pigs housed in NCTR facilities. The contractor must maintain AAALAC accreditation standards and comply with regulations such as the Animal Welfare Act. The PWS outlines requirements for personnel, quality control, safety, training, facilities, equipment, and estimated annual workloads. A five-year contract base period and five one-year options are available for award.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 - Pricing Worksheet Labor Categories_Amend 01.xls | XLS spreadsheet | |
| Attachment 7 - Sample Client Authorization Letter Amend 01.pdf | ||
| FDA 75F40123R00001 Amendment 01.pdf | ||
| 75F40123R00001 Amendment 01 - Q and A.pdf | ||
| Attachment 8 - SCA Incumbents - Length of Service.pdf | ||
| Attachment 5 - Form 3398.pdf | ||
| Attachment 6 - PPEQ.pdf | ||
| Attachment 4 - Wage Det No. 2015-5121 rev.20.pdf | ||
| Attachment 2 - Pricing Worksheet Labor Cats_rev2.xls | XLS spreadsheet | |
| Attachment 7 - Sample Client Authorization Letter.pdf | ||
| Attachment 1 - PWS and Appendices 1-4.pdf | ||
| FDA Solicitation 75F40123R00001.pdf | ||
| Attachment 3 - CBA.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
Animal Care and Technical Procedures
November 2022March 2023
Table of Contents
1. SCOPE
1.1. Background
1.2. Objective
1.3. List of Appendices
2. APPLICABLE DOCUMENTS
3. DEFINITIONS
4. REQUIREMENTS
4.1. General Requirements
4.2. Specific Requirements
4.3. Large Animal Specific Requirements
4.4. Technical Procedures
5. DELIVERABLES
6. 6.0. GOVERNMENT FUNDED TRAINING
7. 7.0. OPTIONAL ITEM – DOSED DIET FORMULATION SERVICES
Performance Work Statement (PWS) Animal Care and Technical Procedures
1. SCOPE. Independently and not as an agent of the Government, the Contractor shall furnish the necessary personnel, materials, services, and otherwise do all things necessary for or incident to provide animal care and technical procedures equivalent to or exceeding the accepted standards and practices of the Laboratory Animal Care industry to NCTR, as described herein.
1.1. Background. The National Center for Toxicological Research (NCTR) is located at the Jefferson Laboratories of the U.S. Food and Drug Administration (FDA) in Jefferson, Arkansas, approximately 35 miles south of Little Rock and 28 miles north of Pine Bluff. NCTR is an internationally recognized FDA research center that conducts toxicological research studies and other research activities designed to support the FDA’s mission to protect the public’s health. NCTR investigators partner with researchers elsewhere in the FDA as well as other government agencies, industry, and academia. NCTR is comprised of six research divisions and has facilities including: 132 general or special purpose research laboratories; AAALAC-accredited animal facilities, including rodent facilities accommodating conventional housing, a small pathogen-free rodent breeding colony, a small immunocompromised rodent facility; a nonhuman primate (NHP) facility; a zebrafish production facility; a phototoxicology research center; an imaging center including microPET, MRI, and CT scanner; a nanotechnology core facility; and an inhalation toxicology facility. On-site support services for animal studies performed at NCTR have been obtained through contracts since the Center’s inception in 1972.
1.2. Objective. The purpose of this contract is to provide support services to NCTR’s animal research program, specifically the provision of quality care to all research animals, sanitation of all animal care, provision of protocol-specified technical procedures, and provision of chain of custody for test articles formulated into the water or diet.
Ancillary tasks necessary to accomplish these services are included (e.g., quality control, occupational safety and health, inventory control, equipment maintenance, development, and maintenance of standard operating procedures, as well as maintaining a comprehensive employee training program). The need for these services is paramount as a significant component of NCTR’s research mission can only be accomplished through animal research. Animal-based research projects are highly regulated and demand exemplary execution.
1.3. List of Appendices. The attached Appendices are included to assist in providing a complete record of the services that have been previously provided, as well as to outline the expected level of services required under this contract. Appendices are attached immediately following this PWS.
Appendix 1: Historical Workload Appendix 2: Government Furnished Property Appendix 3: Facility Floor Plans Appendix 4: Quality Assurance Surveillance Plan (QASP)
2. APPLICABLE DOCUMENTS. To ensure the successful accomplishments of NCTR’s research mission, animal care services, at a minimum, shall comply with regulations and guidelines below, as well as any amendments or revisions thereto.
2.1. Federal Regulations, Policies and Procedures.
a. Animal Welfare Act as Amended (7 USC, 2131-2159).
https://www.aphis.usda.gov/animal_welfare/downloads/awa/awa.pdf
b. Animal Welfare Act Regulations (Code of Federal Regulations, Title 9, Chapter 1, Subchapter A - Animal Welfare) (2020).
CFR-2020-title9-vol1-chapI-subchapA.pdf (govinfo.gov)
c. Guide for the Care and Use of Laboratory Animals, Eighth Edition, Institute of Laboratory Animal Resources (ILAR), Division of Earth and Life Sciences, National Research Council, 2011.
http://grants.nih.gov/grants/olaw/Guide-for-the-Care-and-Use-of-Laboratory-Animals.pdf
d. Public Health Service Policy on Humane Care and Use of Laboratory Animals, Office of Laboratory Animal Welfare, National Institutes of Health, 2015.
http://grants.nih.gov/grants/olaw/references/phspol.htm
e. American Veterinary Medical Association (AVMA) Guidelines for the Euthanasia of Animals, 2020 https://www.avma.org/KB/Policies/Documents/euthanasia.pdf
f. Occupational Safety and Health Administration Regulations (Standards – 29 CFR) including the Hazard Communication Standard (OSHA Standards, 29 CFR 1910.1200) and the Occupational Exposure to Hazardous Chemicals in Laboratories (29 CFR 1910.1450).
http://www.osha.gov/pls/oshaweb/owastand.display_standard_group?p_toc_level=1&p_part_number=1910 http://www.osha.gov/pls/oshaweb/owadisp.show_document?p_table=standards&p_id=10099 http://www.osha.gov/pls/oshaweb/owadisp.show_document?p_table=standards&p_id=10106
g. Biosafety in Microbiological and Biomedical Laboratories (CDC-NIH, 2007); Biological Safety Level-2 (BSL-2) Manual and Biological Safety Level-3 (BSL-3) Manual.
http://www.cdc.gov/biosafety/publications/bmbl5/index.htm
h. Environmental Protection Agency (EPA) Resource Conservation and Recovery Act Regulations.
https://www.epa.gov/rcra/resource-conservation-and-recovery-act-rcra-regulations
2.2. Availability of Federal Regulations, Policies and Procedures. Unless otherwise indicated, copies of the aforementioned documents are available for free distribution online.
2.3. Center-Specific Policies and Procedures.
a. NCTR Environment, Safety, and Health Manual.
b. NCTR Occupant Emergency Plan.
c. NCTR Animal Care Standard Operating Procedures.
d. NCTR Disaster Plan
2.4. Availability of Center-Specific Policies and Procedures. Center-specific documents can be accessed at NCTR’s on-site library.
3. DEFINITIONS. As used throughout this Performance Work Statement (PWS), the following terms shall have the meaning set forth below and specified as applicable to this contract.
3.1. AAALAC Accreditation. AAALAC, International is a private, nonprofit organization that evaluates institutions that use animals in research, teaching, or testing and awards accreditation to those that meet or exceed the standards for humane treatment of animals outlined in the Guide for the Care and Use of Laboratory Animals (National Research Council, 2011), the Guide for the Care and Use of Agricultural Animals in Research and Teaching (Federation of Animal Science Societies, 2010), and the European Convention for the Protection of Vertebrate Animals Used for Experimental and Other Scientific Purpose (Council of Europe, ETS 123).
3.2. Animal Care and Use Form (ACUF). The ACUF is a standalone document and is part of the protocol. The ACUF details all procedures approved to be performed on or for the animal during the conduct of the study. The ACUF describes the intervention actions in case of unexpected or adverse effects. The ACUF must be approved by the Institutional Animal Care and Use Committee before animals can be obtained and animal work can begin. All animal activities must comply with the approved ACUF.
3.3. American Association for Laboratory Animal Science (AALAS). AALAS is an association of professionals that advances responsible laboratory animal care and use to benefit people and animals. The association provides educational materials to laboratory animal care professionals and researchers, administers certification programs for laboratory animal technicians and managers, publishes scholarly journals, supports laboratory animal science research, and serves as the premier forum for the exchange of information and expertise in the care and use of laboratory animals.
3.4. Center for Tobacco Products (CTP). CTP, a part of the FDA, oversees the implementation of the Family Smoking Prevention and Tobacco Control Act.
3.5. Contracting Officer (CO). A Government employee with the authority to enter into and administer contracts and make determinations and findings with respect thereto, or with part of such authority.
3.6. Contract Specialist (CS). A Government employee, acting as a representative of and operating under the authority of the CO, who performs contract-related administration activities.
3.7. Contracting Officer’s Representative (COR). A Government employee who provides technical clarification and guidance with respect to the PWS and serves as the technical liaison between the Contractor and the CO.
3.8. Contractor. Refers to both the Prime Contractor and all Subcontractors. The Prime Contractor shall be responsible for ensuring that its Subcontractors comply with the requirements of this PWS.
3.9. Cooperative Research and Development Agreement (CRADA). A CRADA is an agreement between one or more FDA laboratories and one or more non-Federal parties under which the FDA laboratory provides personnel, services, facilities, equipment, or other resources toward the conduct of specified research or development efforts. The CRADA partner contributes all of the above and funding to the project.
3.10. Environmental, Safety, and Health Committee (ESHC). The Jefferson Laboratories ESHC is organized and maintained to monitor and support the campus environmental, health, and safety programs. The ESHC meets quarterly to assist in maintaining an open channel of communication between employees and management concerning issues related to these programs on the campus.
3.11. Government Furnished Property (GFP). All Government facilities, property, and supplies provided to the Contractor to be used by the Contractor in carrying out responsibilities set forth in this PWS. Ownership of GFP remains that of the Government at all times (unless and until consumed or expended in the normal course of business) and all GFP shall be returned and/or accounted for upon completion of the contract.
3.12. Interagency Agreement (IAA). A document between government agencies and departments that defines cooperative work between the agencies. The IAA between FDA/NCTR and NIEHS/NTP has been in place since 1992.
The IAA supports the design and execution of toxicological studies that are consistent with the goals and needs of both the FDA and NTP.
3.13. Multi-Generation Support System (MGSS). An in-house data management system similar to commercial animal data tracking systems, e.g. Provantis.
3.14. NCTR Experiment Activity Tracking (NEAT). A computerized system to track time spent on individual experiments and other activities. Each experiment or activity in the system is capable of being broken down into a number of milestones with individual tasks to accurately track how time was spent on the experiment or activity.
3.15. National Institute of Environmental Health Sciences (NIEHS). Located in Research Triangle Park, North Carolina, NIEHS is a part of the National Institutes of Health (NIH), and has a mission to discover how the environment affects people in order to promote healthier lives.
3.16. National Toxicology Program (NTP). The NTP is an interagency program whose mission is to evaluate agents of public health concern by developing and applying tools of modern toxicology and molecular biology.
3.17. NCTR Quality Management Team. The NCTR Quality Management Team in the Regulatory Compliance and Risk Management office conducts audits, inspections, and reviews to assess compliance with approved study protocols, established Standard Operating Procedures (SOPs), and the Best Data Quality and Integrity Practices.
NCTR Quality Management Team observations are reported to the responsible laboratory personnel, study director, investigators, and management. Corrective action responses as a result of a QAU observation include: protocol amendments; protocol/data/report/SOP clarifications and/or revisions; and protocol/SOP deviation documentation.
3.18. Occupational Safety and Health Administration (OSHA). As part of the U.S. Department of Labor, OSHA sets and enforces standards to assure safe and healthful working conditions for working men and women.
OSHA Standards, 29 CFR 1910 and 1925:
http://www.osha.gov/pls/oshaweb/owasrch.search_form?p_doc_type=STANDARDS&p_toc_level=0
3.19. Office of Scientific Coordination (OSC). This office provides and coordinates support for the conduct of research at NCTR, and is the location of the Veterinary Services Staff, Microbiology Surveillance Staff, and experimental support staff. OSC manages the IAA with the CTP, and the COR is part of this organization.
3.20. Principal Investigator (PI). The PI is the ultimate customer; the lead scientist with ultimate responsibility for a research protocol. The terms “PI” and “study director” are used interchangeably.
3.21. Pristima. A commercial off the shelf data management system similar to the existing MGSS animal data tracking systems.
3.22. Protocol. Protocols are experimental designs written by Principal Investigators, approved through NCTR management, and performed at NCTR. The terms “protocol” and “study” are used interchangeably.
3.23. Quality Assurance Surveillance Plan (QASP). The plan developed specifically for the PWS, to assure compliance with the requirements. This should not be confused with the Contractor’s Internal Quality Assurance (IQA).
3.24. Quality Control Plan (QCP). A document that includes all measures the Contractor will take to ensure that the quality of an end item or service meets the contract requirements regarding timeliness, accuracy, appearance, completeness, consistency, and conformity to appropriate standards and/or specifications. It includes but is not limited to a written set of self-inspection checklists developed by the Contractor that comprehensively detect variations from the contract requirements; recording of work data; trend analysis; feedback and control systems for correcting deficiencies; and the necessary documentation to record findings.
3.25. Regulatory Compliance and Risk Management (RCRM). RCRM is the office responsible for NCTR’s Safety, Security, Archives, and Quality Management Team. Federal employees in this office conduct laboratory safety training and inspections, as well as Quality Management inspections.
3.26. Restricted Areas. Special clearance procedures are required for access to the Nonhuman Primate (NHP) facility. Access to the NHP facility may be obtained when the following criteria are met: 1) legitimate need to enter the facility; 2) completion of NCTR NHP safety training; 3) negative tuberculosis test, positive measles titer (or proof of vaccination), and respirator fit test; 4) NHP Facility Supervisor briefing; and 5) approval from the Director of Veterinary Services. In addition, access to the rodent breeding colony (a Specified Pathogen Free [SPF] area) is restricted so that no one may enter after previously having been in a conventional rodent facility on the same day. (Exceptions may be granted but will require a shower (including cleaning all skin and hair) and clothing change into clean clothing.)
While in these areas, Contractor personnel are subject to applicable NCTR SOPs, which will be made available to those who are permitted access.
3.27. Specific Pathogen Free (SPF). A designation given to animals that are raised, housed, and handled in a manner to keep them from being infected with specific pathogens defined by internal SOPs.
3.28. Standard Operating Procedures (SOPs). A formally documented specific set of procedures to be followed in carrying out a given operation or in a given situation.
3.29. Study. Studies are experimental designs written by PIs, approved through NCTR management and performed at NCTR. The terms “protocol” and “study” are used interchangeably.
3.30. Study Director. The study director is the lead scientist with ultimate responsibility for a research protocol.
The terms “PI” and “study director” are used interchangeably.
4. REQUIREMENTS.
4.1. General Requirements. Services shall include collaboration with NCTR PIs and other NCTR contractors during planning and development of research protocols, provision of animal care and technical procedures to conduct Institutional Animal Care and Use Committee (IACUC)-approved research protocols, and provision of data for preparation of scientific manuscripts. As requested by the COR, the Contractor shall serve on committees (e.g., Safety, etc.) and participate in seminars, workshops, and training programs on topics appropriate to fulfill NCTR’s goals.
The primary services requested by this PWS are for the Contractor to: 1) provide animal husbandry services including, but not limited to feeding, watering, maintaining a clean environment, operating cage processing areas, making and recording observations, and breeding laboratory animals; 2) provide extensive technical research support procedures in support of animal research protocols including, but not limited to, dosing by gavage, intravenous (IV), intraperitoneal (IP), and topical routes; 3) conduct blood collection from all species on-site as defined in research protocols; 4) provide support for research on behavioral testing of rodents, mini-swine and NHP; 5) provide psychological well-being programs for the NHP colony primarily, and for other species secondarily; 6) provide diet and bedding storage services including, but not limited to receiving, storing, processing, and distributing a) produce for NHP enrichment programs,
b) animal diets, and c) chain of custody for PI, NCTR Chemistry department or externally procured test articles. Other important aspects of this contract requiring Contractor resources include Quality Assurance, Quality Control, Occupational Safety and Health, Employee Training, Inventory Control, Equipment Management, and Data Management. In addition, the Contractor shall provide management and administrative support to ensure effective and efficient utilization of staff, participate in NCTR’s time keeping system (NEAT), provide for planning and scheduling of work, ensure the highest quality of work, and effectively carry out the business aspects of this contract.
A Memorandum of Agreement (MOA) has been established between NCTR and the on-site Arkansas Regional Laboratory (ARL) to provide ARL with animal facility space and specified animal care services under this contract in support of Clostridium toxin bioassays. If other MOAs are established, the Contractor will be expected to assume additional animal care services as set forth in the MOAs.
Facilities, equipment, and expendable supplies required for performance of work under this contract are provided by the NCTR. The Contractor is required to acquire, maintain, and ensure adequate inventory of personnel support items as described in the NCTR Disaster Plan (e.g., supplies for contract employees to stay onsite during a disaster.)
The NCTR is a part of the U.S. FDA; therefore, the immediate needs of the contract may change as other FDA Centers require research services. This may occur through a modification to this contract or, on a limited basis, under this contract through the request of the NCTR COR and following approval by the CO.
Mice, rats, NHPs (rhesus macaque [Macaca mulatta]) and zebrafish constitute the current animal care population at NCTR. The addition of mini-swine is expected during this contract. Additional animal species may be utilized during this contract period and the Contractor shall have or quickly develop the expertise necessary to provide animal care and technical procedures required of these species.
It is the responsibility of every person (contract, government, visitor) working with animals at NCTR to ensure their care and welfare. Mistreatment or neglect of any animal requires immediate removal from the animal area and may include termination.
4.1.1. Hours of Operation. The Contractor will be responsible for providing 24/7/365 animal care and technical procedures services. Core hours are Monday through Friday 6:00 a.m. to 6:00 p.m. Central Time. Continuous service shall be provided as required during the core hours by using staggered start times with the normal animal facility workday scheduled from 7am – 3:30pm and the normal non-animal facility workday scheduled from 8:00 a.m. to 4:30 p.m. Occasionally, scheduled protocol-directed technical procedures will occur outside the core hours.
The Contractor shall also provide essential animal care and technical procedures services including scheduled protocol-specific tasks on Saturdays, Sundays, Holidays, and during inclement weather. Weekend/Holiday hours are typically, 7:00 a.m. to 3:30 p.m., but are dependent on animal and/or study needs.
4.1.2. Observance of Federal Holidays & Other Government Closings. The federal holidays are as below unless otherwise identified by the Contracting Officer (CO):
New Year’s Day January 1st Martin Luther King Day Third Monday in January President’s Day Third Monday in February Memorial Day Last Monday in May Juneteeth June 19th Independence Day July 4th Labor Day First Monday in Sept.
Columbus Day Second Monday in Oct.
Veteran’s Day November 11th Thanksgiving Day Fourth Thursday in November Christmas Day December 25th
In the event there is a Holiday or administrative leave announced other than those recognized federal holidays, the Contractor shall provide sufficient staff to provide essential services including scheduled protocol-specific tasks as identified above. Occasionally, the Contractor may be required to provide animal care /technical procedures support between the hours of 6:00 p.m. and 6:00 a.m.
The Contractor’s management and professional personnel shall be on-site Mon-Fri from 8:00 a.m. to 4:30 p.m unless staggered to be congruent with technician schedules. If not on-site, they or qualified designees shall be available by telephone within 30 minutes for any emergency which may arise in the animal facilities. In addition, the contractor shall provide their contract management staff with designated cell phones to permit telephone access during emergencies that arise during non-core hours. (Exceptions can be made if contractor staff prefers the use of personal cell phones, but contractor provided must be offered.) If there is an emergency, the COR will notify the Contractor’s Project Director verbally, and within 24 hours, will provide a written authorization to cover additional work requirements. As with all contracts, only the CO is authorized to issue change orders or any directive that creates a cost implication.
Appendix 1, Table 5 shows the Holidays worked under the previous contract. This table documents past overtime and Holidays worked but does not necessarily reflect the overtime and Holidays that will be required in the future.
4.1.3. Place of Performance. The primary place of performance will be at NCTR in Jefferson, AR. Some administrative matters pertaining to the contract may be performed at the contractor’s facility; however, the day-to-day animal-related services will take place at NCTR, 3900 NCTR Road, Jefferson, AR 72079. Since the majority of the contract work must occur at NCTR in Jefferson, AR; telework activities by contract employees based at NCTR can be requested for emergency situations only and must be requested from the COR in advance. A written telework agreement must include the supervisor monitoring an employee’s plan for performance of tasks as well as task completion as per the employee’s plan and tasks must provide a benefit to the government and must be tasks that can only occur during working hours.
4.1.4. Baseline Security Requirements
Applicability. The requirements herein apply whether the entire contract or modification (hereafter "contract"), or portion thereof, includes either or both of the following:
Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the FDA mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
Safeguarding Information and Information Systems. All government information and information systems must be protected in accordance with FDA policies and level of risk. At a minimum, the Contractor (and/or any subcontractor) must:
Protect the:
Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
Availability, which means ensuring timely and reliable access to and use of information.
Categorize all information owned and/or collected/managed on behalf of FDA and information systems that store, process, and/or transmit FDA information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories. Based on information provided by the System/Data Owner, ISSO, privacy representative, or other POC, the impact level for each Security Objective (Confidentiality, Integrity, and Availability) and the Overall Impact Level, which is the highest watermark of the three factors of the information or information system are the following:
Confidentiality: [X ] Low [ ] Moderate [ ] High Integrity: [ ] Low [X ] Moderate [ ] High
Availability: [X ] Low [ ] Moderate [ ] High Overall Impact Level: [ ] Low [ ] Moderate [ ] High
Based on the agreed-upon level of impact, implement the necessary safeguards to protect all information systems and information collected and/or managed on behalf of FDA regardless of location or purpose.
Report any discovered or unanticipated threats or hazards by either the agency or contractor, or if existing safeguards have ceased to function immediately after discovery, within one (1) hour or less, to the government representative(s).
This includes notifying the FDA Cybersecurity and Infrastructure Operations Coordination Center (CIOCC) within one
(1) hour of discovery/detection in the event of a cybersecurity or privacy incident.
Adopt and implement all applicable policies, procedures, controls, and standards required by the FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the FDA Information Security Program security requirements, outlined in the FDA Information Security and Privacy Protection (IS2P) policy, by contacting the CO/COR or emailing your ISSO.
Privacy Compliance. Comply with the E-Government Act of 2002, NIST SP 800-53, and applicable FDA privacy policies and complete all the requirements below:
Per the Office of Management and Budget (OMB) Circular A-130, Personally Identifiable Information (PII), is "information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual." Examples of PII include, but are not limited to the following:
Social Security number, date and place of birth, mother's maiden name, biometric records, etc.
Based on information provided by the ISSO, System/Data Owner, or other security or privacy representative, it has been determined that this solicitation/contract involves: [ ] No PII [X] PII
The Contractor must support the agency with conducting a Privacy Threshold Analysis (PTA) for the information system and/or information handled under this contract to determine whether or not a full Privacy Impact Assessment (PIA) needs to be completed.
If the results of the PTA show that a full PIA is needed, the Contractor must support the agency with completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03- 22, Guidance for Implementing the Privacy Provisions of the FDA Information Technology Procurements - Security and Privacy Language E-Government Act of 2002. The PTA/PIA must be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).
The Contractor must support the agency in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.
Controlled Unclassified Information (CUI). Executive Order 13556 defines CUI as "information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information."
The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term "handling" refers to "…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information." 81 Fed. Reg. 63323. The requirements below apply only to nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, must be:
Marked appropriately;
Disclosed to authorized personnel on a Need-To-Know basis;
Protected in accordance with NIST SP 800-53, Security and Privacy Controls for Information Systems and
Organizations applicable baseline if handled by a contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
Returned to FDA control, destroyed when no longer needed, or held until otherwise directed. Information and/or data must be disposed of in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) must protect all government information that is or may be sensitive by securing it with a solution that is validated with current FIPS 140 validation certificate from the NIST CMVP.
Government Furnished Equipment (GFE) for Foreign Travel. FDA personnel are prohibited from taking GFE when participating in personal, unofficial travel to foreign countries. FDA personnel are strictly prohibited from teleworking using GFE in foreign countries. FDA personnel must also request loaner GFE from the FDA Foreign Travel program for official travel to any foreign country. Please see the FDA IS2P, Appendix T Government Furnished Equipment for Foreign Travel.
Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of FDA must be used only for the purpose of carrying out the provisions of this contract and must not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and must ensure that all work performed by its employees and subcontractors must be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed must be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein. The confidentiality, integrity, and availability of such information must be protected in accordance with HHS and FDA policies. Unauthorized disclosure of information will be subject to the HHS and FDA sanction policies and/or governed by the following laws and regulations:
18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol must comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
Information and Communications Technology (ICT). ICT products and services from prohibited entities/sources must not be used/acquired in compliance with Public Law 115-232, Section 889 Parts A and B, FAR 4.21, FAR 52.204.23, FAR 52.204.24, and FAR 52.204.25. The contractor (and/or any subcontractor) must notify the government if they identify prohibited ICT products and/or services are used during the contract performance.
Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS must enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, HTTPS is not required, but it is highly recommended. Consult the HHS Policy for Internet and Email Security for additional information.
Contract Documentation. The Contractor must use provided templates, policies, forms, and other agency documents to comply with contract deliverables as appropriate.
Standard for Encryption. The Contractor (and/or any subcontractor) must:
Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with an encryption solution that is validated with current FIPS 140 validation certificates from the NIST CMVP.
Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and FDA-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with current FIPS 140 validation certificates from the NIST CMVP. The Contractor must provide a written copy of the validation documentation to the COR.
Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys http://csrc.nist.gov/publications/. Encryption keys must be provided to the COR upon request and at the conclusion of the contract.
Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract must complete the FDA non-disclosure agreement (3398 Form)], as applicable. Contractors (and/or subcontractors) must submit a copy of each signed and witnessed NDA to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
Training Requirements
Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract must complete the applicable FDA information security awareness, privacy, and records management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees must complete FDA information security awareness, privacy, and records management training at least annually, during the life of this contract. All provided training must be compliant with HHS training policies.
Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy.
Training Records. The Contractor (and/or any subcontractor) must maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records must be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
Rules of Behavior
The Contractor (and/or any subcontractor) must ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, HHS Rules of Behavior for Privileged Users, and FDA policies and standards.
All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Agency data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
Incident Response
The Contractor (and/or any subcontractor) must respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/FDA CIOCC /Incident Response Team teams within 24 hours, whether the response is positive or negative. FISMA defines an incident as "an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. In accordance with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information (PII), an incident is "an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies" and a privacy breach is "the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose." For additional information on the HHS breach response process, please see the FDA IS2P Appendix F: Incident Response and the HHS Policy and Plan for Preparing for and Responding to a Breach of Personally Identifiable Information (PII)."
In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) must:
Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract, with encryption solution that is validated with current FIPS 140 validation certificates from the NIST
CMVP.
NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative.
If so, instructed by the Contracting Officer or representative, the Contractor must send FDA approved notifications to affected individuals as directed by FDA’s SOP.
Report all suspected and confirmed information security and privacy incidents and breaches to the FDA CIOCC, COR, CO, FDA SOP (or his or her designee), and other stakeholders, including breaches involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour, and consistent with the applicable FDA and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contact information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor must:
o Cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
o Not include any sensitive information in the subject or body of any reporting e-mail; and o Encrypt sensitive information in attachments to email, media, etc.
Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, and HHS and FDA breach response policies when handling PII breaches.
Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation on demand.
Position Sensitivity Designations All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract Tier 2.
Homeland Security Presidential Directive (HSPD)-12 The Contractor (and/or any subcontractor) and its employees must comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; OMB M-19-17; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
Roster The Contractor (and/or any subcontractor) must submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster must be submitted to the COR and/or CO per the COR or CO’s direction. Any revisions to the roster as a result of staffing changes must be submitted within a timeline as directed by the COR and/or CO. The COR will notify the Contractor of the appropriate level of investigation required for each staff member. If the employee is filling a new position, the Contractor must provide a position description and the Government will determine the appropriate suitability level.
Contract Initiation and Expiration
General Security Requirements. The Contractor (and/or any subcontractor) must comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor must follow the FDA EPLC framework and methodology in accordance with the FDA EPLC Project documentation, located here:
http://sharepoint.fda.gov/orgs/DelMgmtSupport/IntakeProc/EPLCv2/SitePages/v2/EPLCHome.aspx and in accordance with the HHS Contract Closeout Guide (2012).
System Documentation. Contractors (and/or any subcontractors) must follow and adhere to HHS System Development Life Cycle requirements, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) must provide all required documentation in accordance with SMGs published by FDA’s Office of Acquisitions and Grant Services (OAGS) to the CO and/or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
Notification. The Contractor (and/or any subcontractor) must notify the CO and/or COR and system ISSO as soon as it is known that a contract employee will stop working under this contract.
Contractor Responsibilities upon Physical Completion of the Contract. The contractor (and/or any subcontractors) must return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor must provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and FDA policies.
The Contractor (and/or any subcontractor) must perform and document the actions identified in the FDA eDepart system http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/default.htm as soon as it is known that a contract an employee will terminate work under this contract. The Contractor (and/or any subcontractor) shall coordinate with the COR via email, copying the Contract Specialist, to ensure that the appropriate person performs and documents the actions identified in the FDA eDepart system. All documentation must be available to the CO and/or COR upon request.
Records Management and Retention
The Contractor (and/or any subcontractor) must maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS Policy for Records Management and HHS and FDA policies and must not dispose of any records unless authorized by HHSFDA.
In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, he/she must document and report the incident in accordance with HHS and FDA policies.
High Value Asset (HVA) If a system is identified as HVA, the contractor must comply with the FDA IS2P Appendix AB:
High Value Asset (HVA) Program, the HHS Policy for the High Value Asset (HVA) Program, and the DHS HVA Control Overlay in addition to the above requirements.
4.1.4 Key and Access Card Control. The Contractor shall insure that keys and/or PIV badges issued to the Contractor are not lost or misplaced and are not used by unauthorized persons. Only designated Government personnel shall duplicate keys issued to the Contractor. The Government will provide PIV badges to all Contractor personnel. The Contractor shall immediately report the occurrence of a lost key or PIV badges to the COR and RCRM Security.
Contractor employees shall not grant access to any controlled/restricted areas to persons that have not been cleared by the COR to be in those areas i.e., animal rooms.
4.1.5 Privacy Act. It has been determined that this contract is subject to the Privacy Act of 1974, because this contract provides for the design, development, or operation of a system of records about individuals from which records are retrieved by name or other identifying particular.
The System of Records Notice(s) (SORN(s)) that is applicable to this contract is: OPM/GOVT-1 (General Personnel Records), December 11, 2012, 77 FR 79694; modification published November 30, 2015, 80 FR 74815. Gov-wide SORNs are available here: https://www.fpc.gov/resources/SORNs/
The system of records design, development, or operation work the Contractor is to perform is: The contractor will have access to human resources, occupational health, and learning management records about HHS personnel.
The disposition to be made of the Privacy Act records upon completion of contract performance…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .