D Attachments.pdf

PDF 25 MB Posted

Attached to
Protective Services Federal contract opportunity
Solicitation number
80KSC020NPSC-SR-SS
Issued by
National Aeronautics and Space Administration Kennedy Space Center

View the file

Other files for this federal contract opportunity

Other files attached to Protective Services, newest first.
File Type Posted
NPSC-SR Pre Solicitation Conference Slides May 13 2021.pdf PDF
NPSC-SR Draft_RFP_Industry_Comment_Form.xlsx XLSX spreadsheet
Attachment F2 NPSC-SR Price Proposal Template.xlsx XLSX spreadsheet
Attachment D14 - JSC WSTF WSC Government Property.xlsx XLSX spreadsheet
Attachment D14 - MSFC MAF Government Property.xlsx XLSX spreadsheet
Attachment D14 - KSC Government Property.xlsx XLSX spreadsheet
Attachment D14 - SSC Government Property.xlsx XLSX spreadsheet
Attachment F3 NPSC-SR Subcontractor Price Template.xlsx XLSX spreadsheet
80KSC021R0009-DRAFT.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

For the best experience, open this PDF portfolio in

Acrobat X or Adobe Reader X, or later.

Get Adobe Reader Now!

http://www.adobe.com/go/reader

80KSC021R0009-DRAFT

NASA Protective Services Contract - South Region

(NPSC-SR)

Attachment D13

Safety and Health Plan

The approved Safety and Health Plan will be incorporated into the contract after award as Attachment D13.

Contract-South Region

Attachment D14

Government Property

See Excel Attachment D14 KSC Government Property See Excel Attachment D14 JSC WSTF WSC Government Property See Excel Attachment D14 MSFC MAF Government Property See Excel Attachment D14 SSC Government Property

Attachment D15

Government Furnished IT Seats

NPSC-SR

Attachment D15 – Government Furnished IT Seats 80KSC021R0009-DRAFT

The Government will provide the following not-to exceed (NTE) IT seats to the Contractor. Any requests above the NTE IT seats will require justification and approval by the Contracting Officer.

IT Seats Description

NTE

KSC JSC WSTF WSC MSFC MAF SSC

Standard Computing Seat Desktop

The Standard Computing seat is intended for overall general-purpose computing in support of Center and Agency activities and is packaged with a pre-defined set of services and service options.

Typical usage includes e-mail, Web browsing, standard office automation and desktop productivity enhancement software, including report preparation, presentation creation, meeting scheduling, spreadsheet generation, as well as general science and engineering application development and execution. Desktops are computer platforms in an enclosure that allow for expansion and that can be placed on a desk or on the floor. It includes a single monitor, keyboard, mouse, and external speakers with each Desktop seat.

71 19 11 5 15 7 28

Standard Computing Seat Laptop

The Standard Computing seat is intended for overall general-purpose computing in support of Center and Agency activities and is packaged with a pre-defined set of services and service options. Typical usage includes e-mail, Web browsing, standard office automation and desktop productivity enhancement software, including report preparation, presentation creation, meeting scheduling, spreadsheet generation, as well as general science and engineering application development and execution.

Laptops are provided with a docking station solution for end-users who require seat mobility, performance, and lighter weight. It includes a laptop carrying case with each Laptop seat.

24 15 6 0 30 15 10

Engineering/Scientific Workstation Seat

The Workstation is a multi-processor system intended for application development and execution of higher performance scientific and engineering programs. Workstations offer additional expansion options utilizing high-speed peripherals, system expansion slots, and additional processor sockets.

Includes a single monitor, keyboard, mouse, and external speakers with each Workstation seat.

0 0 0 0 2 0 0

Smartphone

Smartphone device such as Apple iPhone or Blackberry. Includes battery, wall and car chargers, sync cable, carrying case (holster), hands-free headset and all required software licenses for the devices.

500 voice minutes domestic calling plan (overages will be funded by the Government) Free nights and weekend minutes.

Unlimited text messaging International calling/texting capability.

10 0 7 0 1

Cell Phones

Cellular phone seats have the following minimum set of services: Voicemail, Camera, and Speaker Phone. In addition, it includes the battery, wall charger, hands-free headset, and required software licenses for the devices.

500 voice minutes domestic calling plan (overages will be funded by the Government) Free nights and weekend minutes.

Unlimited text messaging International calling/texting capability.

18 0 0 0 0 0 0

Pagers Pagers are numeric, alphanumeric one way, and alphanumeric two-way, statewide and nationwide coverage areas, featuring Voice Mail notification, local and toll-free number services, Return to Service features, and Octel Message Notification (Out calling).

0 0 0 0 0 0 0

Cellular Data Devices (Wireless Hot Spots or Air Cards)

Wireless Mobile Hotspot/MiFi devices provide portable connectivity for up to five devices and include unlimited domestic data plan. Air Cards provide cellular connectivity to a single device

0 0 0 0 0 0 0

Machine to Machine data plans

Machine-to-Machine (M2M) data plans support device communication such as remote telemetry or data output using cellular networks.

10 0 0 0 0 0 0

Black and White Network Printer

Speed: 52 pages/minute

▪ Recommended use: 5,000 pages per month

▪ Other Functions: None

▪ Paper Capacity: Minimum of 2 adjustable paper trays with a minimum of 250-sheet capacity each for various paper sizes (minimally letter and legal)

2 0 0 0 1

Color Network Printer

Speed: 20 color or 35 B&W pages/minute

▪ Recommended use: 2,000 color or 5,000 B&W pages per month

▪ Other Functions: None

▪ Paper Capacity: Minimum of 2 adjustable paper trays with a minimum of 250-sheet capacity each for various paper sizes (minimally letter and legal)

1 0 2 0 0 1

Black and White Multi- Function Device Network Printer

Speed: 36 pages/minute

▪ Recommended use: 7,500 pages per month

▪ Other Functions: Fax and Scan

▪ Paper Capacity: Minimum of 2 adjustable paper trays with a minimum of 500-sheet capacity each for various paper sizes (minimally letter and legal)

▪ 11x17 supported Note – These are Center Baseline strategically placed location

0 0 0 0 2 1

Color Multi-Function Device Color Network Printer

Speed: 36 pages/minute

▪ Recommended use: 2,000 color or 5,000 B&W pages per month

▪ Other Functions: Fax and Scan

▪ Paper Capacity: Minimum of 2 adjustable paper trays with a minimum of 500-sheet capacity each for various paper sizes (minimally letter and legal)

▪ 11x17 supported

0 0 0 0 2 0 0

Attachment D2

Reserved

Attachment D17

DD Form 254

Attachment D3

Data Requirements List (DRL) and Data Requirement Description (DRD)

DATA REQUIREMENTS LIST

DRL Number Revision

Project/System NASA Protective Services Contract-South Region (NPSC-SR)

Contract Number 80KSC021R0009-DRAFT Preparation Date 03/28/2021

Contractor Technical Approval

Attachment Number D3 Exhibit Number

Item DRD Title Change Status 01 1.0-1 Semi-annual Program Senior Management Status Review 02 1.1-1 Advanced Notification of Workforce Reductions Report 03 1.1-2 Vehicle Utilization Plan 04 1.2-1 Safety and Health Plan 05 1.2-2 Safety Statistics and Mishap Reporting 06 1.3-1 Quality Management Plan 07 1.5-1 IT Security Management Program Plan 08 1.7-1 Records Management Program Plan 09 1.7-2 File Plan 10 1.7-3 Contract Records Close-out Plan 11 3.0-1 Emergency Management Program Plan 12 5.2-1 Physical Security Assessment Plan 13 6.6-1 Internal Security and Education and Training Program Plan 14 1.6-1 Contract Phase-in Plan 15 1.1-3 Strike Contingency Plan K1 K1.1-1 Monthly Program Management Status Review K2 K1.1-2 Institutional Protective Services Report K3 K1.1-3 Contractor Performance Metrics and Workload Indicator Report K4 K1.1-4 Quarterly Summary of 3rd Step Labor Grievances and Arbitrations Report K5 K1.1-5 Replacement of Government Furnished Equipment Report K6 K1.1-6 Headcount Report K7 K4.0-1 PSCC Management Plan K8 K6.0-1 Security Operations Program Plan K9 K10.1-1 NPSTA Program Plan

K10 K6.1-2 Security Police Daily Summary Report J1 J1.1-1 Security Services Education Training Program Plan J2 J2.5-1 Critical Infrastructure Protection Program Plan (CIPP) J3 J3.5-1 Annual Physical Security Plan & Assessment J4 J4.1-1 Standard Operating Procedure JSC, EF and SCTF J5 J5.1-1 Protective Services Security Reports J6 J6.4-1 Emergency Dispatch Center Response Metric Requirements J7 J7.1-1 Quarterly Self-Assessment Metrics Reports J8 J8.1-1 Armory Report J9 J9.1-1 Security Services Training Report

J10 J10.1-1 Government Property Management Plan M1 M6.1-1 Security Police Daily Summary Report M2 M1.1-1 Monthly Status Report M3 M1.1-2 On-Site Employee Location Listing M4 M1.1-3 Government Property Management Plan M5 M1.1-4 Training Plan M6 M1.1-5 OPS Quarterly Activity Report M7 M1.6-1 Standard Operating Procedures S1 S1.1-1 Employee Separation Report S2 S1.4-1 Hazardous Materials Chemical Inventory S3 S1.6-1 Standard Operating Procedures S4 S3.3-1 Continuity of Operations Plan (COOP) S5 S4.0-1 SSC Incident, Complaint, and M-V Accident Report S6 S5.1-1 Government Property Management Plan S7 S6.1-1 Center Law Enforcement and Security Activities Report S8 S6.3-1 SSC Investigative Report S9 S6.4-1 Quarterly Activity Report

Regional Data Requirement Description (DRDs) https://businessworld.ksc.nasa.gov/ https://nef.nasa.gov/

KSC FORM 16-246 NS 06/13 (1.0) PREVIOUS EDITIONS ARE OBSOLETE. Validate prior to use. NRRS 5/13.A Instruction Page 1 of 1

Data Requirement Contract Application Information for DRL

NASA Protective Services Contract – South Region (NPSC-SR) A. Item Number

B. Line Item Title

Quality Management Plan (QMP)

C. OPR

SA-E

D. Type

E. Inspect / Accept

F. Frequency

RT

G. Initial Sub.

See Block I H. As of Date

I. Remarks

The Contractor shall provide the initial QMP within 60 calendar days after the contract performance start date for Government review. The Contractor shall revise the plan as required and submit to the Government within 30 calendar days. The Contractor shall revise the QMP as required when organizational changes occur that change the organization executing the quality requirements, change the quality management functions (e.g., the process through which management decisions are made, or change the organizational responsibility, authority or accountability).

Type “D” electronic versions shall be compatible with Microsoft Office.

J. Distribution

The Contractor shall upload the QMP to a central electronic repository at KSC.

Totals

No. Type

1 D

Data Requirement Description

1. Title

Quality Management Plan (QMP)

2. Number

1.3-1

3. Use

To ensure quality management requirements are implemented and satisfied throughout all phases of contract performance.

4. Date

5. Organization

7. Interrelationship 6. References

8. Preparation Information The Contractor's QMP shall describe the processes of the QMS that ensures compliance with ISO 9001:2015, Quality Management Systems - Requirements and shall include:

a. Organizational charts which illustrate the functional relationship and lines of communication (including alternate opinions) between the organizations implementing the requirements, Contractor Program Manager, and other organizational elements including all subcontracts, Government and other relevant interfaces.

b. An internal evaluation process to continually evaluate the effectiveness of Contractor’s application of the ISO elements, document non-conformance findings, and implement corrective actions,

c. Verification methods to confirm that corrective actions were successfully implemented.

d. Descriptions of the quality management functions within the contract team including the process through which management decisions will be made.

e. Description of the responsibility, authority and accountability of personnel who will perform a quality function.

f. Description of the management controls that will used to ensure the compliance with requirements.

g. Description of the organization's boards, panels and committees used in the implementation.

h. Description of methodologies, metrics and leading indicators used to measure the effectiveness of the QMS throughout the Contractor organization.

i. Description of the quality audit processes that identifies and prioritizes audits and assessments to be performed annually and a summary report of the prior year audits and results.

j. Description of the continuous improvement methodology, implementation and risk assessments of proposed improvements.

k. Description of the certification and qualification training approach, including listing all processes, tasks and positions that require certification or qualifications and the requirements for achieving the certification or qualifications.

l. Describe the flow down of requirements to Contractor Quality Management System documents and organizational elements, including verification methods to ensure requirements have been met.

Product shall be compatible with the Microsoft Office products or future versions as specified by the Government. The final QMP shall be scanned into PDF format and published electronically into the KSC Business World (Tech Doc) at https://businessworld.ksc.nasa.gov.

Information Technology (IT) Security Management Program Plan (ITSMPP)

NASA-KSC IT-B

AN

Upon receipt of the initial or revised ITSMPP, the OPR will contact location (see Box J) IT representatives to establish a timeline and point-of-contact for comment submittal. The OPR will work with the contractor, CO, and commenter to resolve comments prior to approving the Plan. Type “D” electronic versions shall be compatible with Microsoft Office.

The initial submittal shall be within 30 Days of Contract Start Date.

The Contractor shall review the ITSMPP at least annually and shall revise the Plan as required (See Block 8).

The Federal Information Processing Standards (FIPS) Publication Series of the National Institute of Standards and Technology (NIST) is the official series of publications relating to standards and guidelines adopted and promulgated under the provisions of the Federal Information Security Management Act (FISMA) of 2002. FIPS Pub 200, Minimum Security Requirements for Federal Information and Information Systems, specifies minimum security requirements for information and information systems supporting the executive agencies of the federal government and a risk-based process for selecting the security controls necessary to satisfy at minimum these security requirements.

NIST has identified seventeen security-related areas that represent a broad-based, balanced information technology security program that addresses the management, operational, and technical aspects of protecting information and information technology systems.

These seventeen security-related areas were used as the model for the content identified to be addressed in the Contractor IT Security Program Description document. For contractors not familiar with these seventeen security-related areas, additional information can be found in FIPS Pub 200. Keep in mind that the FIPS 200 is a document that contains requirements for the federal government.

For the purposes of this Contractor IT Security Program Description document the FIPS 200 is a reference document only, it is not to be considered a requirement.

The following document is a reference document unless specified otherwise within this DRD or the contract: FIPS 200, Minimum Security Requirements for Federal Information and Information Systems.

J. Distr bution The Contractor shall upload the ITSMPP to a central electronic repository at KSC for review and approval.

After approval the submitted, modified, or updated document shall be scanned into PDF format and published electronically into the KSC Business World (Tech Doc) at https://businessworld.ksc.nasa.gov. See Block 8 for format and updating.

Information Technology (IT) Security Management Program (ITSMPP)

1.5-1

To provide Government insight into the Contractor’s methodology for managing all aspects of information security and to ensure appropriate security of IT resources are addressed.

7. Interrelationship An IT Systems Security Document Plan is not required due to the Contractor not being responsible for any IT systems.

6. References See Block 8

References for Block 6:

FAR 52.204-21: Basic Safeguarding of Covered Contractor Information Systems NFS 1852.204-76: Security Requirements for Unclassified IT Resources NFS 1852.223-75: Major Breach of Safety or Security NFS 1852.237-72: Access to Sensitive Information NFS 1852.237-73L: Release of Sensitive Information NFS 1852.239.73: Review of the Offeror’s Information Technology Systems Supply Chain NFS 1852.239.74: Deviation Clause NPD 2800.1, Managing Information Technology NPR 2810.1, Security of Information Technology (Revalidated with Change 1, dated May 19, 2011)

The Contractor shall submit an ITSMPP for its unclassified technology information resources. The ITSMPP shall describe the policies, processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. The Contractor’s ITSMPP shall be compliant with the IT security requirements in accordance with Federal and NASA policies as referenced in OMB Circular A-130 (Management of Federal Information Resources), and NPR 2810.1. The ITSMPP should not confused with the IT System Security Plan and is a separate IT plan that defines how IT Security will be managed on the contract.

The ITSMPP shall comply with NPD 2810.1 and NPR 2810.1 and include, at a minimum, the following:

a. Cognizant Personnel and Roles and Responsibilities. The contractor shall identify the roles and responsibilities within its team responsible for achieving and maintaining cybersecurity during contract performance, as well as the names and titles of the specific individuals assigned to these roles (e.g., the information system owner, the information system security officer, and the chief information security officer).

b. Process for meeting security authorization requirements, including development and maintenance of IT security plans, implementation and validation of controls, security assessments, remediation, authorization, and continuous monitoring for any corporate owned system processing National Aeronautics and Space Administration (NASA) data, including but not limited to ITAR, EAR, and PII sensitive information.

c. Process for meeting security authorization requirements, including development and maintenance of IT security plans, implementation and validation of controls, security assessments, remediation, authorization, and continuous monitoring for any system interfacing with NASA IT systems or for systems provided to NASA.

d. Process for documenting an end-to-end cyber architecture of the entire system up to contractually responsible boundaries and reporting that information to the location/Agency program.

e. Process for ensuring the supply chain risk mitigation.

f. Process for information security incident management and response, including coordination with NASA Security

Operations Center (SOC) and location/Agency civil service interfaces.

g. Process for ensuring all software, operational technology (sensors, controllers), and information technology for the location/Agency program are cyber-hardened through cybersecurity engineering processes.

h. Process for ensuring personnel screening include the steps for performing appropriate verifications through background checks commensurate with the sensitivity of work being performed on behalf of the location/Agency program.

i. Process for addressing foreign national access to company-owned or NASA-owned location/Agency data.

j. Process for sharing executive summaries resulting from audits of corporate owned IT Systems.

k. Process for the use of mobile devices, mobile media, the encryption at rest, marking of media, and sanitization methods employed to protect location/Agency data.

l. Physical measures in place to protect location/Agency hardware, designs, and IT systems used in support of the location/Agency program.

m. Process for informing location/Agency Program cyber security subject matter experts as to the state of the program’s cyber vulnerabilities threats, and mitigations, to include cyber related threat information.

n. Process for ensuring all subcontractors abide by the IT/OT security management approaches proposed through this DRD.

Format and Update: Use Microsoft Word. After approval the submitted, modified, or updated document shall be scanned into PDF format and published electronically into the KSC Business World (Tech Doc) at https://businessworld.ksc.nasa.gov. Revise the ITSMPP when changes occur in items a – n above. Changes to the document shall be identified with revision marks. When an update occurs the revision number of the Plan will be updated.

Records Management Program Plan (RMPP)

NPSC-SR COR

AR

Upon receipt of the initial or revised RMPP, the OPR will contact the Records Managers at JSC, KSC, MSFC, SSC, WSC and WSTF to establish a timeline for comment resolution. The OPR will work with the contractor, CO, and Records Managers to resolve comments prior to approving the Plan.

The Contractor shall submit one RMPP for the entire NPSC-SR within 90 days after contract start. The RMPP will be outlined in accordance with Block 8 below. The Plan shall be revised as required.

The RMPP shall be reviewed annually, and revisions submitted for approval by December 31st each year.

Type D means electronic submission. The Contractor shall upload the RMPP to a central electronic repository at KSC for review. The Contractor shall notify the OPR and each location’s Records Manager that it has been uploaded. After approval the submitted, modified, or updated Plan shall be scanned into PDF format and published electronically into the KSC Business World (Tech Doc) at https://businessworld.ksc.nasa.gov. See Block 8 for format and updating.

Records Management Program (RMPP)

1.7-1

Establishes the requirement for a RMPP covering the contractor’s policies and objectives for the organization, implementation and control of documentation required for support of NASA.

The RMPP shall identify all elements of the program function including organizational pattern (i.e. relationship to line and staff), implementation policy and procedures, the subcontractor interface and the reporting and control system for functions outlined in the RMPP, describe the implementation of a records management program in accordance with the documents referenced in this DRD, and provide sufficient detail to demonstrate an understanding of the compliance requirements including the following areas:

The RMPP shall outline the contractor's proposed controls and processes, as necessary to define the documentation distribution control system. The RMPP shall define, but not be limited to, the following:

A. Requirements, including implementation and operational methods.

B. List all acronyms used.

C. Depict a hierarchy of documents from contracts requirements through implementing and operational documents.

D. Describe all documents processes used and shall include flow charts.

E. Depict the process of documentation initiation; approval; implementation; methods of revision; reporting and submittal;

and modifications or changes.

F. Address a system for management of records and disposition of files.

The RMPP shall use the following format:

I. Program Management

a. Program authorization and organization

b. Guidance and training

c. Internal Evaluations

d. Procedures and Processes

II. Records Creation/Recordkeeping Requirements

a. Creation of records/adequacy of documentation

b. Contractor Records

III. Records Maintenance (General)

a. General

b. Paper-based Records

c. Electronic Records

d. Legacy Records

IV. Maintenance of Special Records

a. Electronic Records

b. Audiovisual Records

c. Cartographic and Architectural Records

d. Micrographic Records

V. Records Disposition

a. Records Disposition Schedule Implementation

VI. Vital Records

Note: The RMPP must include a plan that ensures compliance with Memorandum For Heads Of Executive Departments and Agencies (M-19-21) “Transition to Electronic Records” (see Compliance Documents) and future guidance concerning the transition to electronic records that may be released by the Government. This memo addresses the transition federal agencies' business processes and recordkeeping to an electronic environment to the fullest extent possible by December 31, 2022.”, or as revised.

References:

a. NASA Records Management, NPD 1440.6 (latest version)

b. NASA Records Management Program Requirements, NPR 1441.1 (latest version)

c. Export Control Program NPD 2190.1 (latest version)

d. 44 U.S.C. Chapters 29, 31, 33

e. 44 U.S.C. 3501 et seq., Paperwork Reduction Act

f. 36 CFR Parts 1220-1238

g. Executive Order 12656, Assignment of Emergency Preparedness Responsibilities, Sections 201, 202, 1901, and

2001 (November 18, 1988), as amended.

h. FAR 52.227-14/52.2227-16

i. Memorandum For Heads Of Executive Departments and Agencies (M-19-21) “Transition to Electronic Records”

Update and Format: Revise the RMPP when changes occur. Changes to the document shall be identified with revision marks.

When an update occurs the revision number of the Plan will be updated. Microsoft Word compatible.

File Plan

AN (See Block I)

Each location’s Record Manager will serve as the OPR for their location.

Type “D” means electronic. Format shall be Microsoft Office compatible.

The Contractor shall submit an initial location specific File Plan to each location’s Records Manager by 120 days after contract start, designating the Plan as follows:

- JSC = D1-JSC - SSC = D1-SSC

- KSC = D1-KSC - WSC = D1-WSC

- MSFC = D1-MSFC - WSTF = D1-WSTF

Example: File Plan for Kennedy Space Center (D1-KSC)

The Contractor shall maintain and update each location’s File Plan in accordance with the NASA references in Block 8 below. The revised plan shall be submitted by December 31st each year.

The Contractor shall upload each File Plan to a central electronic repository at KSC for review and approval by the location’s Records Manager. The Contractor shall notify the location’s Records Manager the Plan has been uploaded. After approval the submitted, modified, or updated document the Contractor will work with each location’s Records Manager to determine where the approved Plan will reside. See Block 8 for format and updating.

6 D

File Plan

1.7-2

The File Plan shall provide identity of all NASA records being generated in the performance of the contract and shall include code number, the description of NASA records maintained, the records disposition, and the authority per NPR 1441.1.

See 8 below

The File Plan shall include at a minimum, the following data:

a) Code#: NRRS 1441.1.

b) Record Title: Record Series description, a description of the record and its function.

c) Office of Record: Office responsible for retiring the record at the end of lifecycle.

d) Location: Physical location of records.

e) Retention/Disposition: Period of time the record shall be kept, and how it is treated at the end of its active lifecycle.

f) Permanent verses Temporary: Designation of permanent status or temporary status of records.

g) Vital Status: Records identified as necessary for continuing operations immediately following an emergency.

h) Volume: Amount of records.

NASA Records Management, NPD 1440.6 (latest version) NASA Records Management Program Requirements, NPR 1441.1 (latest version) NASA Record Retention Schedules, NRRS 1441.1 (latest version) NASA Export Control Program, NPD 2190.1 (latest version)

Update and Format: Revise the File Plan when changes occur. Changes to the document shall be identified with comments indicating where the changes have occurred. When an update occurs the revision number of the Plan will be updated. Microsoft Excel.

Contract Records Close-Out Plan

OT

Each location’s Record Manager will serve as the OPR for their respective location. Type “D” means electronic and shall be compatible with Microsoft Office.

The Contractor shall turn over inactive records to each location’s Record Manager (see Block J) and transition all active records to the next Contractor by the end of the Contract.

The Contractor shall develop a Contract Records Close-Out Plan for each location, and submit 120 days prior to end-of-contract (see Block J), designating the Plan as follows:

- JSC = D1-JSC - SSC = D1-SSC

- KSC = D1-KSC - WSC = D1-WSC

- MSFC = D1-MSFC - WSTF = D1-WSFT

Example: Contract Records Close-Out Plan for Kennedy Space Center (D1-KSC)

The Contractor shall upload each Contract Records Close-Out Plan to a central electronic repository at KSC for review and approval by each location’s Records Manager. The Contractor shall notify the location’s Records Manager that the Plan has been uploaded. After approval of the submitted, modified, or updated Plan the Contractor will work with each location’s Records Manager to determine where the approved Plan will reside. See Block 8 for format.

6 D

Contract Records Close-Out Plan

1.7-3

To determine the amount of Government-owned records at each NASA location that will be turned over to the follow-on contract or stored at the NASA Archives. This DRD establishes the requirement for a complete and final record inventory at contract close-out.

The Contractor shall submit a final inventory of records with volumes updated. The volumes shall be listed in megabytes for records in electronic formats, and in cubic feet for hard copy records. The inventory shall include sufficient technical documentation of all electronic records to permit the agency access and use. The inventory shall include sufficient details and locations documentation of all hard-copy records to permit the Government access and use.

a. NASA Records Management Program Requirements, NPR 1441.1.

b. NASA Record Retention Schedules, NRRS 1441.1.

Format:

Microsoft Excel.

mailto:ksc-dl-op-industrialrelations@mail.nasa.gov

Description (DRDs)-KSC

NASA Protective Services Contract – South Region (NPSC-SR), Kennedy Space Center (KSC)

K2

Institutional Protective Services Report

SI-B1

AN

See Block 1

365/15

G. Initial Sub: Within 15 days of KSC Annex start.

Type "D": Electronic submittal. Product shall be compatible with Microsoft Office suite of software. Reports shall be distributed via e-mail. The Contractor shall provide this report no later than 15 calendar days after April 30, 2023 and 15 calendar days after the close of each government fiscal year.

KPSC-SR COR: SI-P

NPSC-SR (KSC) CO: OP-OS

NPSC-SR CO: OP-OS

3 D

Institutional Protective Services Report

K1.1-2

To provide actual cost and workforce data used to respond to NASA HQ requests to compare costs across Centers.

NPSC-SR (KSC)

N/A

The Contractor shall provide the requested information per this DRD in the sample format shown below. Actual cost shall be provided on all cost reimbursable contract line item numbers (CLIN). Billable costs shall be provided on all fixed price CLINs.

The contractor shall report on baseline IDIQ costs and WYEs in separate charts and by Center Annex.

An example of the chart and mapping is provided below for KSC:

OPS

PROGRAM

REIM

GRAND

TOTAL

Project

WBS #

FYXX $K

(No decimals)

FYXX

WYEs (one decimal)

WYE

Security and Program Protection Emergency Management

PSCC

Resources Protection

Security Services

NPSTA

Training Requirements & Mandatory Skill & Performance Levels

Security and Program Protection Security and Program Protection 0 0 0 0 0 0 0 0

K3

Contract Performance Metrics and Workload Indicator Report

SI-P

MO

30/12

Initial Submit: Type "D" Electronic submittal. Product shall be compatible with Microsoft Office suite or Adobe software. Reports shall be distributed via e-mail. Coordinate with the KSC Protective Services Office (PSO) to obtain pertinent data and any additional items to report.

G. Initial Sub: Within 6 months of Contract start. Provided a continuous cumulative role-up at the end of each contract year.

NPSC-SR (KSC) Contracting Officer: OP-OS

NPSC-SR COR: SI-P

D = Electronic submission. The Contractor shall upload the Contract Performance Metrics and Workload Indicator Report to a central electronic repository at KSC for review and approval. After approval the submitted, modified, or updated Plan shall be scanned into PDF format and uploaded into KSC Business World (Tech Doc) at https://businessworld.ksc.nasa.gov.

2 D

Contract Performance Metrics and Workload Indicator Report

K1.1-3

To provide Government insight into Contractor performance in all areas of the contract. Delve into existing or potential problem areas as well as insight into the Contractors productivity and work performed against Government expectations.

See Block 8 below

Metrics:

The Contractor shall develop, maintain, analyze, and report performance in all areas of the contract and KSC Annex. The metrics shall include meaningful demonstration of work performance, quality, responsiveness, and long-term effectiveness of the work or services. Every Performance Standard (PS), reference attachment D2, shall have an associated metric(s).

The Contractor shall develop metrics jointly with the Government. The Contractor shall provide a self-evaluation of the metric and report existing or potential problem areas with recommended solutions. The report shall identify contract title and contract number. At a minimum, metrics shall be meaningful, customer oriented, linked to goals/objectives(performance standards), process/action oriented, developed from readily collectible and verifiable data, trendable, visually and simply displayed, measurable, repeatable, capable of distinguishing desirable from undesirable results.

Workload Indicators:

The Contractor shall track and trend actual workload performance for major work activities and tasks. A major work activity or task is defined as a workload indicator that would take a minimum of 100 man-hours per year to complete. The Contractor shall identify major work activities and tasks and coordinate changes to the suggested Workload Indicators below with the Contracting Officer’s Representative (COR). The Workload Indicator report shall convey as a minimum the major work activity/task and the number count of how many times that activity/task occurred in the current reporting period.

These are the minimum reporting requirements for the workload indicators.

WORKREQ# TITLE

1.2-1 Safety Meetings 1.2-2 Safety Working Groups 2.0-1 Number of secure phones and keys inventoried 2.0-2 Number of employees trained (Security Awareness) 3.2-1 EOC Activation excluding first shift weekdays (hours) 3.2-2 Responses to emergencies not requiring EOC activation, excluding first shifts (hours) 3.2-3 Damage Assessment and Recovery Operations (events) 3.2-4 Personnel trained annually in Emergency Support Functions (ESF) 3.2-5 Personnel, government, contractor and partners, trained annually as Hurricane Coordinators

3.2.6 EOC Launch Operations, 1st, 2nd and 3rd shifts.

3.2-6 EOC operations extending beyond 8hours 4.0-1 Security Alarms resulting in a Security response 4.0-2 Security Alarms points acknowledged 4.0-3 Fire alarm points acknowledged 4.0-4 Fire alarms resulting in a fire response 4.0-5 Security responses 4.0-6 ENS inquiries 4.0-7 PSCC Fire incidents processed 4.0-8 Radio transmissions 4.0-9 Phone calls processed 4.0-10 Request for Security Responses to KSC Visitor’s Center 4.0-11 Fire and EMS responses to KSC Visitor’s Center 4.0-12 NCIS/FCIC inquires 5.1-1 Facilities requiring risk analyses 5.1-2 Physical Security Design reviews 5.1-3 Final Acceptance tests (Security) 5.2-1 Cores purchased 5.2-2 Cores constructed 5.2-3 Cores installed 5.2-4 Keys cut 5.2-5 Keys issued (exclude lost key replacements) 5.2-6 Work orders received 5.2-7 Work Orders completed (exclude safe trouble calls) 5.2-8 Safe and vault Trouble calls 5.2-9 Lost key replacements 5..2-10 Lock repairs 5.2-11 Key audits with Physical Security personnel and Key Custodians 6.0-1 Security Police Incident reports (exclude Vehicle Crashes) 6.0-2 Vehicle Crash reports 6.0-3 Magistrate citations

NASA Protective Services Contract- South Region (NPSC-SR)

K7

Protective Services Communication Center (PSCC) Management Program Plan

SI-P0

RT updated AN

RT updated AN

Initial Sub: Within 90 days of contract start.

The Plan shall be the Center's prescribing directive for managing the PSCC. Type "D": Electronic submittal. Product shall be compatible with Microsoft Office suite of software. Reports shall be distributed via e-mail. The Contractor shall review annually and provide revisions to the NPSC-SR (KSC) Contracting Officer’s Representative (COR) for review and approval. If annually no changes are made, a letter from the Contract Manager stating there are changes to the plan will be routed to the KSC COR and Contract for review and approval after which the letter shall be uploaded to KSC Business World (Tech Doc) at https://businessworld.ksc.nasa.gov.

NPSC-SR (KSC) COR

NPSC-SR (KSC) CO

NPSC-SR CO

4 D

PSCC Management Program Plan

K4.0-1

The Contractor shall develop a Plan that incorporates at a minimum all of the following instructions and procedures. The contractor shall submit for approval the Plan to NASA Protective Services Office (PSO) within 90 days of contract award for review and approval.

The Plan shall address the Contractor's approach to PSCC Operations including checklists.

The Plan shall include at a minimum the following sections:

Standard Operating Procedures:

PSCC Operations PSCC Training Program PSCC Updating Marquee

Checklists:

Aircraft/Missile Crash Aircraft In-flight Emergency Paging/email Notification Process Robbery/Alarm Response ESS Alarm Response Vehicle Gate Penetration Aircraft/UAS Penetration Watercraft Penetration Bomb Threat Phone Protocol/Nuisance/Prank/Malicious Traffic Stops NCIC/FCIC ENS • Emergency Notification System Hostage Situation PSCC Evacuation Process Tornado Area Warning System (TAWS) Fire Console Alarm System Activity Force Protection Conditions Spill/Leak Haz-Mat Response Suspicious Packages, Substances (WMD) Response EMS Response Elevator Response PSCC Equipment/Call Out Process Duress Responses/Radio Duress Man-Down Duress Response (security gates) DNPS Bus Duress Response

K8

Security Operations Program Plan

SI-P0

2/5

AD

G. Initial Sub: 60 days after KSC Annex start.

Type "D": Electronic submittal. Product shall be compatible with Microsoft Office suite of software. Reports shall be distributed via e-mail. The Contractor shall review annually.

KPSC-SR COR: SI-P

KSC Chief of Protective Services

NPSC-SR (KSC) CO: OP-OS

NPSC-SR CO: OP-OS

Security Operations Program Plan

K6.0-1

The Contractor shall develop a Plan that incorporates at a minimum, all of the following forms, checklists, plans, and procedures to be developed. The Contractor shall submit for approval the Plan to KSC Protective Services Office (PSO) within 60 days of contract award for review and approval.

Standard Operating Procedures (SOPs) at minimum Handling and Control of SP Admin Documents Helicopter Support Guidelines Security Police Armories Security Police Dress and Appearance Standards Duties and Responsibilities Of Security Police Supervisors ERT Operations SEC-P-0013, Shift Formation Communications and Senior Management Notification Procedures SEC-P-0017, Weapons Handling/ Clearing Security Simulations / Exercises SEC-P-0027 Responding To Weapons Of Mass Destruction Threats SEC-P-0031, Injured Animals Pets Locked In Vehicles (KSCVC) SEC-P-0038, Random Vehicle Inspections Safeguarding, Care and Use of Government Equipment K-9 Support Law Enforcement Procedures Oleoresin Capsicum Spray Bomb Threat Procedures Police Procedures, Records, Forms and Checklist Non-Lethal Training Training Standard Operating Procedure Use of Force Photographic Lineup Control of Evidence and Found Property NPSTA and Facility Use Policy NPST Academy Security Police Personnel Standards Electronic Control Devices (ECD) Vehicle Pursuits and Apprehension Alarm/Duress Procedures NPSTA Instructor Development/CERTS KSC Federal Magistrate Program Administration Crisis Negotiation Team Operations Lock Shop Procedure Body Camera usage

Special Security Instructions (Post Orders) (at a minimum provide the following for supporting PWS 6.0):

KSC ERT Supervisor KSC ERT Lead - 240 KSC ERT (LC-39 Area) - 241 KSC ERT (Pad A/B) - 242 KSC ERT (Industrial Area) - 243 KSC ERT (Industrial Area) - 244 KSC Gate 2 - 903/903a KSC Gate 3 - 907/907a KSC Gate 4 - 908/908a Industrial Area Rover - 200

K10

Security Police Daily Summary Report (DSR)

KSC PSO/SIP0

DA; See Block I

D. Electronic submittal. Report shall be distributed via e-mail using distribution list provided by the Government.

F. Disseminated Monday through Sunday no later than 7:00am nominally.

G. Initial Submission is annex start date.

KSC PSO

Security Police Daily Summary Report (DSR)

K6.1-2

To disseminate security information to Center leadership and key personnel.

A DSR shall provide a summary of Report of Incidents (ROIs) that have occurred the day prior. The DSR is a synopsis of the previous day’s ROIs developed from information that is readily available within each ROI.

Attachments are not necessary with the DSR. Recipients shall be identified by Protective Services Office (PSO).

The DSR shall be generated using information from the Government provided electronic reporting system. Contractor initial submission shall be reviewed by the KSC PSO prior to submitted to management. Format shall be coordinated with PSO prior to use.

Description (DRDs)-JSC

Johnson Space Center (JSC)

J2

Critical Infrastructure Protection Program Plan (CIPP)

JSC CO & COR

AR/AN

MATERIAL PROTECTION: All material developed on behalf of this program should be protected as Sensitive but Unclassified Information (SBU), future Controlled Unclassified Information (CUI) at minimum.

Format: NASA Form 1805, Facility Security Level (FSL) Determination Matrix, Plans & Report formats shall be directed by the Contracting Officer’s Representative (COR) at JSC.

Receipt: 180 days after contract start. Frequency of Plans, Reports, Forms and Letters described in this DRD are as they occur or detailed in the "Contents" Section below.

JSC CO

JSC COR

JSC Deputy Center Chief of Protective Services

Submission Electronic, MS Office or a searchable portable document format (pdf).

Critical Infrastructure Protection Program Plan (CIPP)

J2.5-1

To develop, document, maintain and manage the Critical Infrastructure Protection Program (CIPP) at JSC, EF, SCTF and WSTF/WSC.

NPSC-SR (JSC)

Annex Section 5.3

8.1 SCOPE: The Contractor shall establish a program to identify critical essential infrastructures and key resources, evaluate these assets for vulnerabilities and implement appropriate security enhancements (procedural and physical) to mitigate vulnerabilities.

8.2 CONTENTS:

8.2.1 NASA Form 1805, Facility Security Level (FSL) Determination Matrix

The Contractor shall ensure the overall Center and all JSC, Ellington Field (EF) and Sonny Carter Training Facility (SCTF) facilities/buildings are assessed using the guidance in NPR 1620.2, Facility Security Assessments. Facility Security Level (FSL) Initially the contractor shall perform this assessment within 180 days of contract start, and as required. Thereafter, determinations will be reviewed and adjusted, if necessary, at least every five years for level (I) and (II) facilities and every three years for levels (III) and (IV) facilities from the facility’s previous assessment date. In addition to the guidance in NPR 1620.2, the Contractor shall clearly identify specific non-compliance areas, by specific NPR 1620.3 reference, on the Facility Security Level (FSL) Determination Matrix.

8.2.2 Formal Letters to Centers' Chief Information Officer and Center Director

The Center Chiefs of Protective Services, may decline to include buildings in the program that are determined not to have any Center operational or mission support value (e.g., abandoned or decommissioned facilities, vacant sheds, and vacant trailers). A written proposal to remove these facilities/buildings is required to the Center’s Chief Information Office and Center Director for approval. The Contractor shall produce this letter as needed.

8.2.3 Formal Letters to Assistant Administrator for Protective Services

All Center NCI assets must be included on the NASA Headquarters NCI Inventory. All proposed changes to the NCI list shall be coordinated by the Center with the responsible Headquarters Mission Directorate Associate Administrator, the Center’s Chief Information Officer (CIO), Center Chief of Protective Services (CCPS)/Center Chief of Security (CCS) and Critical Infrastructure Assurance Officer (CIAO). Upon approval of the asset as a NCI the CCPS/CCS and Center CIAO ensures a physical security vulnerability risk assessment is completed and implement appropriate mitigation plans to address all vulnerabilities. NPR 1600.1, NASA Security Program Procedural Requirements. The Contractor shall provide formal letters to the Center Chief of Protective Services when facilities are added or removed from the JSC NCI Inventory.

8.2.4 Physical Security Risk Vulnerability Assessment Reports

The Contractor shall create or update Physical Security Risk Vulnerability Assessments when the facilities NASA Form 1805, Facility Security Level (FSL) Determination Matrix is created or updated. These reports are the documentation of the risk assessment process to include the identification of undesirable events, consequences, and vulnerabilities and the recommendation of specific security measures commensurate with the level of risk. These reports shall be conducted on the overall Center and every facility/building that the Center Chief of Protective Services, determines has Center operational or mission support value.

J4

Standard Operating Procedures JSC, EF and SCTF

AD

Format: All procedures shall be written in the International Standard Organization (ISO) format.

Frequency of Submission: Initial Standard Operating Procedures (SOP's) within 60 days of contract start. All SOPs shall be reviewed and updated annually or more frequently if changes in procedures are required.

Additional Remarks: SOPs shall be standardized for JSC and are subject to review and JSC CCS.

Standard Operating Procedures JSC, EF and SCTF

J4.1-1

To document the contractor’s standard operating procedures for tasks performed under the contract and as required by NASA Procedural Requirements.

8.1 SCOPE: Specific SOPs shall address those recurring tasks performed by the Protective Services Contractor personnel at JSC, WSTF, & WSC.

8.2 APPLICABLE DOCUMENT: NPR 1600.1A, NASA Security Program Procedural Requirements; NPR 1600.3, NASA Personnel Security; NPR 1620.2, Facility Security Assessments; NPR 1620.3, Physical Security Requirements for NASA Facilities and Property;

and NPR 8000.4A, Agency Risk Management Procedural Requirements.

8.3 CONTENTS: SOPs shall address actual duties, responsibilities, and special instructions that relate to but are not limited to the following areas of interest: Management General Orders; Administrative Services Badging; Emergency Dispatch Center Procedures (JSC Only); Locksmith Administrative, Operations and Procedures; Security Operation, Post Orders; Physical Security Specialist Operations and Procedures (JSC Only); NASA Critical Infrastructure Protection Program (NCIPP) Procedures; Training Operations and any other security task performed in support of the contract. The SOPs shall, at minimum, include the below list. The Contractor shall add procedures, as needed, so support the requirements of the JSCPSC II.

8.4 Standard Operating Procedures Requirements JSC: (Example)

8.4.1 Management

Supervisor General Orders

SGO-01 Supervisors Duties, Responsibilities & Management Expectations

General Orders GO-01 Standards of Conduct GO-02 Appearance Standards GO-03 Patrol Units GO-04 Armory Access Inventory Turn-In Procedures GO-05 Radio Procedures (Not Used) GO-06 Civil Disorder GO-07 Vehicle Use GO-08 Vehicle Inspection GO-09 Firearms Training and Certification GO-11 Workplace Violence GO-12 Duress Alarm – Building 110 Badge Office GO-13 Duress Alarm - Building 211 Child Care Center GO-14 Hazardous Material Response GO-15 Fire and Explosion Plan GO-16 Hostage and Barricade Situation GO-17 Flag Protocol GO-18 Storage of Weapons GO-19 Unauthorized Gate Entry

GO-20 Terrain Vehicle Usage Perimeter Checks GO-21 PSS Law Enforcement Assistance GO-22 Vehicle Crash Investigation GO-23 Ballistic Vest Policy GO-24 Active Shooter Response GO-25 Bomb Threat Assessment GO-26 Incident Reports GO-27 Digital In-Car Video System GO-28 Hurricane / Severe Weather Support Plan GO-29 Emergency Response Building 37 Room 1233 GO-30 Suspicious Activity Reporting

Subject Matter not covered in current SOPs.

Acceptable Union Activity on JSC Property (if applicable) Property Management Procedures Scheduled Barrier and Bollard Maintenance Procedures

8.4.2 Administrative Services, Badging

GO-01 JSC Security Visitor Badging GO-02 Technical Support Specialists (TSS) Metrics Reporting GO-03 Termination Procedures GO-04 Denied Access List Procedures GO-05 Processing A Foreign National (FN) GO-06 Processing Suspended Drivers GO-07 Electronic Controlled Access Area (CAA) Process GO-08 ID Networks Fingerprint Roll-FBI Fingerprint Review Procedures GO-09 Specialty Badges (Currently being reviewed) GO-11 Issue of non-Access Tenant Badge (Currently being reviewed)

Post Orders

PO-03 Post Order Sonny Carter Training Facility Post 19 Badge Office Desk PO-04 Post Order Building 267 Ellington Field Badge Office Desk PO-05 Building 111 Contract Extensions and Terminations PO-06 Building 111 Advanced NAC List PO-07 Building 111 Scheduling the e-QIP Lab PO-09 Badge Procedures for Former Astronauts PO-10 Official Escort Badges (Currently being reviewed)

HSPD 12 Procedures (Currently being reviewed) JSC Reserved Parking Desk Procedures, (Working on revisions) Building 110 Desk Procedures (Working on revision)

8.4.3 Emergency Dispatch Center (EDC) Operations

EDC-01 General Dispatch Operating Procedure EDC-02 Alarmed Door Access Requests EDC-03 Escort Procedure EDC-04 Fireworks Alarm Status EDC-05 Door Openings and Closings EDC-06 Backup Dispatch Center EDC-07 Suspicious Materials (Biological & Chemical) Threat Procedure EDC-08 Alarm Response for Buildings 1 and 420 EDC-09 JSC Medical Officer of the Day EDC-10 Aircraft Incident Response EDC-11 Ambulance Run Procedure EDC-12 Response to Alarm in the Astro-materials Curation Facilities Bldgs. 31 & 31N EDC-13 Bomb Threat Procedure EDC-14 Duress Alarms Bldgs. 1, 4S, 45, 110 111, 211 EDC-15 Monaco Alarm System EDC-16 Radio Tower Lighting EDC-17 Emergency Response Team Notification EDC-18 Roof Access (Vent/Fume Hoods) EDC-19 Banner Procedure EDC-20 Site Wide Emergency Warning System EDC-21 Radio Off-Line Procedure EDC-22 Incident Command/Perimeter Control EDC-23 Addresses for JSC, SCTF & Ellington Field EDC-24 Work Order Processing and Tracking

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .