Sol_75N92018Q0109.pdf

PDF 244 KB Posted

Attached to
Combined Synopsis/Solicitation Federal contract opportunity
Solicitation number
75N92018Q0109
Issued by
Department of Health and Human Services National Institutes of Health

About this file

75N92018Q0109

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUMIS CHECKED

CODE 18a. PAYMENT WILL BE MADE BY

CODE

FACILITYCODE

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

OFFEROR

ADM-NIBIB

Bethesda MD 20892-7511

N/A Imaging and Bioengineering National Institute of Biomedical National Institutes of Health

TDP, BTHOFF CODE 16. ADMINISTERED BYCODE

X

X

541990

SIZE STANDARD:

% FOR:SET ASIDE:UNRESTRICTED ORIO-NIBIB

RFPIFB

10. THIS ACQUISITION ISCODE

RFQ

14. METHOD OF SOLICITATION

13b. RATING

NAICS:

SMALL BUSINESS

04/11/2018 1400 ES

03/30/2018

301-827-7549Michael Gemmill (No collect calls)

INFORMATION CALL:

FOR SOLICITATION 8. OFFER DUE DATE/LOCAL TIMEb. TELEPHONE NUMBER a. NAME

4. ORDER NUMBER3. AWARD/ 6. SOLICITATION

75N92018Q0109

5. SOLICITATION NUMBER

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS 1. REQUISITION NUMBER PAGE OF

1 17 4897632OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

N/A

TELEPHONE NO.

17a. CONTRACTOR/

Bethesda MD 20817 N/A N/A 6707 Democracy Blvd 2 Democracy Plaza, TDP, BTHOFF

15. DELIVER TO

Bethesda MD 20892-7511 N/A N/A Imaging and Bioengineering National Institute of Biomedical

9. ISSUED BY

7.

2. CONTRACT NO.

EFFECTIVE DATE

$15.00

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW

ISSUE DATE

DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

11.

SEE SCHEDULEX

12. DISCOUNT TERMS

THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13a.

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

8(A)

National Institutes of Health

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

X

24.

AMOUNT

23.

UNIT PRICE

22.

UNIT

21.

QUANTITY

20.

SCHEDULE OF SUPPLIES/SERVICES

19.

ITEM NO.

Delivery: 05/03/2019 Period of Performance: 05/04/2018 to 05/03/2019

1 Base year of Professional services to assist with creating a modern, navigable, mobile responsive website

Continued ...

(Use Reverse and/or Attach Additional Sheets as Necessary)

HEREIN, IS ACCEPTED AS TO ITEMS:

XX

DATED

Jennifer E. Swift

. YOUR OFFER ON SOLICITATION (BLOCK 5),

INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER

ARE

ARE

31c. DATE SIGNED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (Type or print)

ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL

SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

26. TOTAL AWARD AMOUNT (For Govt. Use Only)

OFFER

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA - FAR (48 CFR) 53.212

ARE NOT ATTACHED.

ARE NOT ATTACHED.

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

30b. NAME AND TITLE OF SIGNER (Type or print)

30a. SIGNATURE OF OFFEROR/CONTRACTOR

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

25. ACCOUNTING AND APPROPRIATION DATA

29. AWARD OF CONTRACT:

REF.

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32c. DATE 32b. SIGNATURE OF AUTHORIZED GOVERNMENT REPRESENTATIVE

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

40. PAID BY39. S/R VOUCHER NUMBER38. S/R ACCOUNT NUMBER

37. CHECK NUMBER

FINALPARTIAL

36. PAYMENT

FINALPARTIAL

35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER33. SHIP NUMBER

COMPLETE

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

42d. TOTAL CONTAINERS42c. DATE REC'D (YY/MM/DD)

42b. RECEIVED AT (Location)

42a. RECEIVED BY (Print)

41c. DATE41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

STANDARD FORM 1449 (REV. 2/2012) BACK

24.

AMOUNT

23.

UNIT PRICE

22.

UNIT

21.

QUANTITY

20.

SCHEDULE OF SUPPLIES/SERVICES

19.

ITEM NO.

2 Option Year 1 of Professional services to assist with creating a modern, navigable, mobile responsive website

(Option Line Item)

05/03/2019

Period of Performance: 05/04/2019 to 05/03/2020

3 Option Year 2 of Professional services to assist with creating a modern, navigable, mobile responsive website

(Option Line Item)

05/03/2020

Period of Performance: 05/04/2020 to 05/03/2021

4 Option Year 3 of Professional services to assist with creating a modern, navigable, mobile responsive website

(Option Line Item)

05/03/2021

Period of Performance: 05/04/2021 to 05/03/2022

32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT REPRESENTATIVE

17 2 of

COMBINED SYNOPSIS / SOLICITATION

WORKFORM

(1) Action Code: Combined Synopsis/Solicitation

(2) Date: 03/30/2018

(3) Year: 2018

(4) Contracting Office Zip Code: 20892

(5) Classification Code: R499

(6) Contracting Office Address:

6701 Rockledge Drive Rockledge II Bethesda, MD 20892

(7) Subject/Title: Professional services to assist with creating a modern, navigable, mobile-responsive website

(8) Proposed Solicitation Number:

(9) Closing Response Date: 4/11/2018

(10) Contact Point(s): Michael Gemmill, Contract Specialist

(11) Contract Award and Solicitation Number: TBD

(12) Contract Award Dollar Amount: TBD

(13) Contract Line Item Number(s): TBD

(14) Contractor Award Date: TBD

(15) Contractor Name: TBD

(16) Description:

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6 as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation will not be issued.

Solicitation number 75N92018Q0109 is issued as a request for quotation (RFQ).

The incorporated provisions and clauses are those in effect through Federal Acquisition Circular FAC 2005-97 effective 1/24/2018.

This order is being set aside for a Woman Owned Small Business. The associated NAICS code is 541990 and the small business size standard is $15,000,000. The acquisition is being conducted in accordance with the procedures of FAR Part 12 and FAR Part 13

Statement of Work (SOW) Agency/Institute: National Institutes of Health (NIH)/ National Institute of Biomedical Imaging and Bioengineering (NIBIB)/ NIBIB Office of Science Policy and Communications (OSPC)

Purpose NIBIB is seeking professional services to assist with creating a modern, navigable, mobile-responsive website

Background

The National Institutes of Health (NIH) is the nation’s leading medical research agency and the primary Federal agency conducting and supporting medical discoveries that improve people’s health. The National Institute of Biomedical Imaging and Bioengineering (NIBIB) is one of 27 Institutes and Centers that comprise NIH. The NIBIB Office of Science Policy and Communications (OSPC) plays a critical role in carrying out the mission of the Institute as the singular office that disseminates information about research supported by NIBIB to Congress, researchers, and the public. OSPC activities include the preparation and dissemination of press releases, science highlights, designing and maintaining the Institute website, developing content for the web site and social media, developing apps for educating the public, maintaining the research funding information on the website for researchers, preparing remarks and presentations for the Director and senior leadership at the Institute, preparing minutes of the Advisory Council meetings, and drafting the Institute’s Strategic Plan, among other responsibilities.

OSPC is tasked with creating a modern, navigable, mobile-responsive website for the Institute.

The website is the primary means for NIBIB to describe its mission, its scientific and programmatic goals and scientific advances. As the NIH Institute at the forefront of technology development, the website needs to be on the leading edge in content, usability and style.

Vendor Required Experience

NIBIB requires a senior web designer and developer with the following expertise:

- understanding of the existing NIBIB website, as well as the institute’s mission, programs and goals

- expert skill and experience in web design, layout, navigation, site map creation, data mining and conducting competitive assessments

- adept at creating and managing digital content guidelines, tools, style guides and processes, as well as auditing and conducting inventory of online content to identify gaps in quality and compliance

- ability to continually evaluate metrics and information architecture to optimize design and usability

- working in/for a medical or scientific communications office and handling medical/scientific/health writing, editing, and social media content creation and strategizing,

- writing and auditing content for Plain Language, Clear Communication and 508 compliance

- on various platforms including Adobe Creative Suite and Drupal 8, and others. NIBIB’s website was developed using the Drupal platform. The institute will be moving to Drupal 8 with this new website

- in search engine optimization (SEO), which is the process of improving the visibility of our web site in a search engine’s unpaid results

- an understanding of communications principles and standards. Digital writing, editing, design and development samples will be required

Requirements Specific Tasks to be performed by Contractor:

The Contractor will redesign and aid in deployment of the NIBIB website

The Contractor will create a style guide for the NIBIB website.

The Contractor will address responsivity concerns for the website.

The Contractor will review the current and revised websites for errors, broken links, faulty navigation, gaps in quality and compliance.

The Contractor will assist in developing, formatting, and tagging documents to meet 508 requirements The Contractor will review NIBIB website content and make recommendations for improving search engine optimization The Contractor will consult with senior OSPC staff on assignments and specific task requirements.

The contractor will help conduct testing to gauge user experience, 508 accessibility and compliance. 508 compliance is required for every item posted on the NIBIB website, according to NIH policy

The website must be redesigned to fit modern mobile-responsivity and usability standards. Since the lion’s share of website users are now on mobile devices, NIBIB must accommodate this consistent trend

Deliverables/Delivery Schedule:

The contractor shall provide documented evidence of any and/or all work product, including, but not limited to, the following tasks:

Work products and documents related to all assignments.

Written recommendations and suggestions for search engine optimization and other website performance and design.

Final documents that meet 508 compliance requirements as assigned.

Final written documents (such as e-newsletters, news releases) that highlight NIBIB science advances to a scientific and lay audience.

Documents that track the open rate/analytics of these written products Monthly Status Report to include a brief synopsis of task efforts, major accomplishments and identified issues, risks, contingency plans going forward.

It is anticipated that award will be made with a (12) month Base Period of Performance with three (3), twelve (12) month Option periods.

Interested parties should submit a tailored quotation for this requirement.

Evaluation Criteria is as follows:

FAR clause 52.212-2, Evaluation – Commercial Items is applicable to this acquisition. The Government will award a contract resulting from this solicitation to the responsible offeror whose quote (inclusive of options) conforms to and meets the specifications identified in the solicitation and provides the best value to the Government.

Evaluation of Quotations

The technical approach is the most important item in the evaluation of the contractor’s capability to perform the desired services. Therefore, the approach must present sufficient information to reflect a thorough understanding of the work requirements and a detailed technical approach for achieving project objectives as set forth in the SOW.

The technical approach may NOT contain any references to price-cost. However, resource information, such as data concerning proposed other direct costs, must be contained in the technical approach so that contractor’s understanding of the scope of work may be evaluated.

The award will be made on a competitive best value basis, using the “tradeoff’ approach among price-cost and non-price-cost factors. The Government may elect to award to other than the lowest priced offeror, or other than the highest rated non-price quote. In either case, a tradeoff will be conducted. The government reserves such right of flexibility in conducting the evaluation as necessary to assure an award with the contractor providing the best value to the government.

Understanding the requirements (Weight: 35%) Contractor shows a general understanding of the Institute’s mission Contractor shows a general understanding of Institute’s need to communicate its research to a broad audience through its website and creative tools Contractor shows a clear understanding of the work products, deliverables, and tasks associated with this position Contractor shows a clear understanding of the elements needed for a modern, navigable, mobile-responsive website Contractor shows a clear understanding of the broad range of activities within the Office of Science Policy and Communications including preparing, editing, and maintaining content for the website.

Qualifications/Experience and Capability on Similar Tasks (Weight: 40%) Contractor shows knowledge and experience developing designs, style guides, and features of a user-friendly, responsive website Contractor shows knowledge and skill in search engine optimization Contractor shows knowledge and skill in website navigation, site map creation, data mining and conducting competitive assessments Contractor shows knowledge and skill in conducting testing to gauge user experience Contractor shows knowledge of website platforms and software including Adobe

Creative Suite and Drupal Contractor shows knowledge and experience in the processes and steps for redesigning and developing a modern, responsive website, optimized for mobile devices Contractor shows knowledge and understanding of federal policies for websites including 508 accessibility and compliance Contractor shows knowledge and skills in developing and editing web content

Procedures for Assuring Quality of Work, Products, and Deliverables (Weight: 15%) Contractor describes internal review of materials for quality and meeting of requirements prior to sending to Institute Contractor clearly describes procedure for making corrections or edits requested by the

Institute.

References to Evaluate Past Performance (Weight: 10%) Contractor provides examples of previous work on similar tasks Contractor provides 2 references that may be contacted by the Institute

Applicable FAR Clauses

FAR clause 52.212-1, Instructions to Offerors – Commercial Items, applies to this acquisition.

FAR clause 52.212-3, Offeror Representations and Certifications – Commercial Items, is applicable. An offeror shall complete only paragraphs (b) of this provision if the offeror has completed the annual representations and certificates electronically via http://www.acquisition.gov. If an offeror has not completed the annual representations and certifications electronically at the System for Award Management (SAM) website, the offeror shall complete only paragraphs (c) through (p) of this provision.

FAR clause at 52.212-4, Contract Terms and Conditions – Commercial Items, applies to this acquisition.

FAR clause at 52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders – Commercial Items, applies to this acquisition. Including the following clauses:

• 52.217-4, Evaluation of Options Exercised at Time of Contract Award

• 52.217-9 Option to Extend the Term of the Contract.

• 52.219-6, Notice of Total Small Business Set-Aside (NOV 2011) (15 U.S.C. 644)

• 52.219-13, Notice of Set-Aside of Orders (NOV 2011) (15 U.S.C. 644(r))

• 52.219-14, Limitations on Subcontracting (JAN 2017) (15 U.S.C. 637(a)(14))

• 52.219-28, Post Award Small Business Program Representation

• 52.219-30 Notice of Set-Aside for, or Sole Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (DEC 2015) (15 U.S.C. 637(m)).

• 52.232-19, Availability of Funds for the Next Fiscal Year (APR 1984)

• 52.222-3, Convict Labor (June 2003) (E.O. 11755)

• 52.222-21, Prohibition of Segregated Facilities (APR 2015)

• 52.222-26, Equal Opportunity (APR 2015) (E.O. 11246)

• 52.222-35, Equal Opportunity for Veterans (OCT 2015) (38 U.S.C. 4212)

• 52.222-36, Equal Opportunity for Workers with Disabilities (JUL 2014) (29 U.S.C. 793)

• 52.222-37, Employment Reports on Veterans (OCT 2015) (38 U.S.C. 4212)

• 52.222-50, Combating Trafficking in Persons (MAR 2015). (22 U.S.C. chapter 78 and E.O. 13627)

• 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements

• (i) 52.222-54 Employment Eligibility Verification (OCT 2015) (Executive Order 12989).

• 52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving (AUG 2011) (E.O. 13513)

• 52.225-13, Restrictions on Certain Foreign Purchases (JUN 2008)

• 52.232-33, Payment by Electronic

• 52.204-9, Personal Identity Verification of Contractor Personnel

• 52.224-1 Privacy Act Notification.

• 52.224-2 Privacy Act.

• HHSAR 352.224-70, Privacy Act

It has been determined that this contract is subject to the Privacy Act of 1974, because this contract provides for the design, development, or operation of a system of records on individuals. The design, development, or operation work the Contractor is to perform is: Web portal for receiving applications

• 52.239-1, Privacy or Security Safeguards

• 52.204-21, Basic Safeguarding of Covered Contractor Information Systems

• FAR 39.101(c), Acquisition of Information Technology

• FAR 4.5, Electronic Commerce in Contracting

Additional Contract Requirements:

1. Post Award Evaluation of Contractor Performance

Contractor Performance Evaluations

Interim and final evaluations of Contractor performance will be prepared on this contract in accordance with FAR Subpart 42.15. The final performance evaluation will be prepared at the time of completion of work. In addition to the final evaluation, interim evaluations will be prepared annually prior to the exercise of options. Interim evaluations will not be prepared for awards with a period of performance of less than 18-months. Interim evaluations will be prepared annually for awards greater than 18-months.

Interim and final evaluations will be provided to the Contractor as soon as practicable after completion of the evaluation. The Contractor will be permitted thirty days to review the document and to submit additional information or a rebutting statement. If agreement cannot be reached between the parties, the matter will be referred to an individual one level above the Contracting Officer, whose decision will be final.

Copies of the evaluations, Contractor responses, and review comments, if any, will be retained as part of the contract file, and may be used to support future award decisions.

Electronic Access to Contractor Performance Evaluations

Contractors may access evaluations through a secure Web site for review and comment at the following address: http://www.cpars.gov.

2. Confidentiality of Information Confidential information, as used in this article, means information or data of a personal nature about an individual or proprietary information or data submitted by, or pertaining to, an institution or organization.

The Contracting Officer and the Contractor may, by mutual consent, identify elsewhere in this contract specific information and/or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential. Similarly, the Contracting Officer and the Contractor may, by mutual consent, identify such confidential information from time to time during the performance of the contract. Failure to agree will be settled pursuant to the "Disputes" clause.

If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, the Contractor will follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

Confidential information, as defined in paragraph (a) of this article, shall not be disclosed without the prior written consent of the individual, institution, or organization.

Whenever the Contractor is uncertain with regard to the proper handling of material under the contract, or if the material in question is subject to the Privacy Act or is confidential information subject to the provisions of this article, the Contractor should obtain a written determination from the Contracting Officer prior to any release, disclosure, dissemination, or publication.

Contracting Officer’s determination will reflect the result of internal coordination with appropriate program and legal officials.

The provisions of paragraph (d) of this article shall not apply to conflicting or overlapping provisions in other Federal, State or local laws.

The following information is covered by this article: [TBD]

3. Non-Personal Services and Inherently Government Functions

a. Pursuant to FAR 37.1, no personal services shall be performed under this contract. All work requirements shall flow only from the Contracting Officer’s Representative (COR) to the Contractor’s Project Manager. No Contractor employee will be directly supervised by the Government. All individual employee assignments, and daily work direction, shall be given by the applicable employee supervisor. If the Contractor believes any Government action or communication has been given that would create a personal services relationship between the Government and any Contractor employee, the Contractor shall promptly notify the Contracting Officer of this communication or action.

b. Pursuant to FAR 7.5, the Contractor shall not perform any inherently governmental actions under this contract. No Contractor employee shall hold him or herself out to be a Government employee, agent, or representative. No Contractor employee shall state orally or in writing at any time that he or she is acting on behalf of the Government. In all communications with third parties in connection with this contract, Contractor employees shall identify themselves as Contractor employees and specify the name of the company for which they work.

In all communications with other Government contractors in connection with this contract, the Contractor employee shall state that they have no authority to in any way change the contract and that if the other contractor believes this communication to be a direction to change their contract, they should notify the Contracting Officer for that contract and not carry out the direction until a clarification has been issued by the Contracting Officer

4. Non-Disclosure / Non-Use Agreement

The contractor shall ensure that a Non-Disclosure Statement is signed by all staff assigned to or performing on this contract before performing any work, including all subcontractors and consultants. The contractor shall also ensure that all staff understand and adhere to the terms of the non-disclosure statement protecting the procurement sensitive information of the government and the proprietary information of other contractors.

5. Information System Security Requirements

HHS Security and Privacy Language for Information and Information Technology Procurements is applicable to this solicitation and the following information is provided to assist in proposal preparation.

IMPORTANT NOTE TO OFFERORS: The following information shall be addressed in a separate section of the Proposal entitled "Information Security."

The Homeland Security Presidential Directive (HSPD)-12 and the Federal Information Security Management Act of 2002 (P.L. 107-347) (FISMA) requires each agency to develop, document, and implement an agency-wide information security program to safeguard information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor (including subcontractor), or other source.

INFORMATION SECURITY AND/OR PHYSICAL ACCESS SECURITY

A. POSITION SENSITIVITY DESIGNATIONS

All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract:

[ ] Level 6: Public Trust - High Risk. Contractor/subcontractor employees assigned to Level 6 positions shall undergo a Suitability Determination and Background Investigation (MBI).

[ ] Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

[X] Level 1: Non-Sensitive. Contractor/subcontractor employees assigned to Level 1 positions shall undergo a Suitability Determination and National Check and Inquiry Investigation (NACI).

1. HOMELAND SECURITY PRESIDENTIAL DIRECTIVE (HSPD)-12

The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors;

HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.

For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12)

Roster-

a. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO within fourteen (14) calendar days after the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within seven (7) calendar days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at:

https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityR oster_10-15-12.xlsx .

b. If the Contractor is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.

Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

c. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

d. The Contractor shall notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the contract and if they have previously been the subject of national agency checks or background investigations.

e. All contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract. Contractors may begin work after the fingerprint check has been completed.

f. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-14. Accordingly, the Contractor shall ensure that any additional employees whose names it submits for work under this contract have a reasonable chance for approval.

g. Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the contract price of no more that the cost of the additional investigation(s).

h. The Contractor shall include language similar to this "HHS Controlled Facilities and Information Systems Security" language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

i. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.

Within 7 calendar days after the Government's final acceptance of the work under this contract, or upon termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.

B Standard for Encryption- The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.

c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and NIH-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the Contracting Officer and the Contracting Officer's Technical Representative within 15 days of the validation.

e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to the COR upon request and at the conclusion of the contract.

C Applicability- The requirements herein apply whether the entire contract or order (hereafter "contract"), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor)will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

D Safeguarding Information and Information Systems- In accordance with the Federal

Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

Integrity , which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

Availability , which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less , bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov .

d. Comply with the Privacy Act requirements.

E Information Security Categorization- In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II:

Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Contractor Non-Disclosure Agreement and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [ X ] Low [ ] Moderate [ ] High Integrity: [ X ] Low [ ] Moderate [ ] High Availability: [ X ] Low [ ] Moderate [ ] High Overall Risk Level: [ X ] Low [ ] Moderate [ ] High Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[ ] No PII [ X ] Yes PII

F Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB) Circular A-130, "PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual." Examples of PII include, but are not limited to the following:

social security number, date and place of birth, mother's maiden name, biometric records, etc.

PII Confidentiality Impact Level has been determined to be: [ X] Low [ ] Moderate [ ] High

G CONTRACT INITIATION AND EXPIRATION

1. General Security Requirements- The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology or and in accordance with the

HHS Contract Closeout Guide (2012).

HHS EA requirements may be located here:

https://www.hhs.gov/ocio/ea/documents/proplans.html

2. System Documentation- Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.

3. Sanitization of Government Files and Information- As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation in accordance with the NIH Media Sanitization and Disposal Policy to the CO and/or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

4. Notification- The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO within fifteen days before an employee stops working under this contract.

5. Contractor Responsibilities Upon Physical Completion of the Contract- The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR.

Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or NIH policies.

6. The Contractor (and/or any subcontractor) shall perform and document the actions identified in the NIH Contractor Employee Separation Checklist https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf when an employee terminates work under this contract within 2 days of the employee's exit from the contract. All documentation shall be made available to the CO and/or COR upon request.

H TRAINING

1. Mandatory Training for All Contractor Staff- All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/NIH Contractor Information Security Awareness, Privacy, and Records Management training course at http://irtsectraining.nih.gov/ before performing any work under this contract.

Thereafter, the employees shall complete NIH Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.

2. Role-based Training- All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum. Read further guidance about the NIH Role-based Training https://ocio.nih.gov/aboutus/publicinfosecurity/securitytraining/Pages/rolebasedtraining.a spx https://www.hhs.gov/ocio/ea/documents/proplans.html https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf

3. Training Records- The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy.

A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

I RULES OF BEHAVIOR

1. The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, and comply with the NIH Information Technology General Rules of Behavior https://ocio.nih.gov/InfoSecurity/training/Pages/nihitrob.aspx , which are contained in the NIH Information Security Awareness Training Course http://irtsectraining.nih.gov

2. All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual NIH Information Security Awareness Training. If the training is provided by the contractor, the signed Rules of Behavior must be provided as a separate deliverable to the CO and/or COR per defined timelines above.

J INCIDENT RESPONSE

The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/NIH IRT teams within 24 hours, whether the response is positive or negative.

FISMA defines an incident as "an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cyber security and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as "a suspected or confirmed incident involving PII".

1. Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.

2. NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send NIH approved notifications to affected individuals individuals in accordance with https://ocio.nih.gov/InfoSecurity/IncidentResponse/Pages/ir_guidelines.aspx http://irtsectraining.nih.gov/ https://ocio.nih.gov/InfoSecurity/IncidentResponse/Pages/ir_guidelines.aspx https://ocio.nih.gov/InfoSecurity/IncidentResponse/Pages/ir_guidelines.aspx

3. Report all suspected and confirmed information security and privacy incidents and breaches to the NIH Incident Response Team (IRT) via email at IRT@mail.nih.gov, COR, CO, the NIH Office of the SOP (or his or her designee), and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour, and consistent with the applicable NIH and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:

a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;

b. not include any sensitive information in the subject or body of any reporting e-mail; and

c. encrypt sensitive information in attachments to email, media, etc.

Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information HHS and NIH incident response policies when handling PII breaches.

4. Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally

Identifiable Information HHS and NIH incident response policies when handling PII breaches.

5. Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

This may also involve physical access to contractor facilities during a breach/incident investigation within an hour of discovery.

K Confidentiality and Nondisclosure of Information- Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified inwriting by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and NIH policies. Unauthorized disclosure of information will be subject to the HHS/NIH sanction policies and/or governed by the following laws and regulations:

18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

Each employee, including subcontractors, having access to non-public Department information under this acquisition shall complete the "Commitment to Protect Non-Public Information - Contractor Employee Agreement" located at:

https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Nondisclosure.pdf . A copy of each signed and witnessed Non-Disclosure agreement shall be submitted to the Project Officer/COR prior to performing any work under this acquisition.

All responses must be received by April 11, 2018 at 2PM EDT. Responses must be submitted via the FedConnect webportal (www.fedconnect.net). Potential Offerors do not need to register to view a notice; however, in order to submit questions and/or response to this Notice, an account will need to be established.

Place of Contract Performance: Contractor’s site Set-aside Status: Woman Owned Small Business https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Nondisclosure.pdf https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Nondisclosure.pdf

File details come from the government source that posted it.