88310321Q00056 ADAMS.pdf
PDF 678 KB Posted
- Attached to
- Agency Digital Asset Management System Federal contract opportunity
- Solicitation number
- 88310321Q00056
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Appendix F - Configuration Management Database (CMDB) Template.pdf | ||
| Appendix E - System Security Plan Requirements.pdf | ||
| Appendix C - Incident Response Plan Template.pdf | ||
| 88310321Q00056 ADAMS.docx | DOCX document | |
| Appendix D - Quality_Assurance_Cloud_CMDB_Template.xlsx | XLSX spreadsheet | |
| Appendix G - Interface Control Document (ICD) Template.pdf | ||
| Appendix B - Contingency Plan Template.pdf | ||
| Amendment 002.docx | DOCX document | |
| Amendment 001 Extension.docx | DOCX document | |
| Appendix A - IT Security Requirements.pdf | ||
| Volume 1 Requirements Matrix.xlsx | XLSX spreadsheet |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in FAR Subpart 12.6, Streamlined Procedures for Evaluation and Solicitation for Commercial Items as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotations are being requested and a written solicitation will not be issued. The solicitation number is 88310321Q00056 and is issued as a Request for Quotation (RFQ). The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2021-05 effective March 10, 2021. This is a total small business set-aside RFQ under NAICS code 541511, Custom Computer Programming Services. CONTRACT LINE ITEM NUMBER(S): See Attachment 1, Schedule of Prices. REQUIREMENT: The National Archives and Records Administration (NARA) has a requirement to obtain an Agency Digital Asset Management System (ADAMS). See Attachment 2, Performance Work Statement. PERIOD OF PERFORMANCE: The period of performance will consist of a base year and four (4) option years. The following Federal Acquisition Regulation (FAR) clauses are incorporated and are to remain in full force in any resultant contract. FAR provisions will be removed prior to award. FAR provision 52.212-1, Instructions to Offerors - Commercial Items (Jun 2020). Addenda: (1) Change paragraph (c) to read: Period for acceptance of offers. The offeror agrees to hold the prices in its offer firm for 90 calendar days from the date specified for receipt of offers. (2) Delete paragraph (h), Multiple Awards. - see below for additional quotation submission instructions. EVALUATION (In lieu of FAR provision 52.212-2): Evaluation and award will be in accordance with Simplified Acquisition Procedures at FAR 13.106, Soliciting Competition, Evaluation of Quotations or Offers, Award and Documentation authorized by FAR Subpart 13.5, Simplified Procedures for Certain Commercial Items as prescribed by FAR 12.301(c)(2). Selection of the Contractor for this contract will be based on NARA’s assessment of the best overall value to the Government.
Best value for this contract will be obtained in accordance with Attachment 10, Evaluation Factors for Award. Exceptions taken to any terms and conditions stated in the RFQ must be clearly outlined on a separate page of the Contractor’s quotation entitled “Exceptions”.
The Contractor must also include a justification and the cost impact of each exception noted.
The Government reserves the right to make an award on the initial quotation without communicating with contractors. For evaluation purposes, the total price for each fixed-price CLIN will be determined by multiplying the quantity by the firm-fixed unit price. The evaluated total contract price will be determined by summing the total prices of all performance years (base year and all option years). FAR provision 52.212-3, Offeror Representations and Certifications
- Commercial Items (Feb 2021) - The Offeror shall complete only paragraph (b) of this provision if the Offeror has completed the annual representations and certification electronically in the System for Award Management (SAM) accessed through https://www.sam.gov. If the Offeror has not completed the annual representations and certifications electronically, the Offeror shall complete only paragraphs (c) through (v) of this provision. FAR clause 52.212-4, Contract Terms and Conditions - Commercial Items (Oct 2018) – see Attachment 7, Additional NARA Terms and Conditions (Addenda to FAR clause 52.212-4). FAR clause 52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders - Commercial Items (Jan 2021) - see Attachment 6, FAR Clauses for the full text of this clause and for additional applicable FAR clauses. FAR provision 52.217-5, Evaluation of Options (Jul 1990). The Contractor is required to be registered in the System for Award Management (SAM) and maintain registration until final payment in accordance with FAR provision 52.204-7, System for Award Management (Oct 2018). Full text provisions and clauses can be found at http://www.acquisition.gov. QUESTIONS: Questions regarding this RFQ must be submitted in writing to the Contract Specialist, Shawn Xiong (Contractor) at shawn.xiong@nara.gov no later than 12:00 PM ET on June 11. 2021 to be considered. Questions submitted in any other manner will not be answered. Contractors are requested to group and submit questions in the same order found in the RFQ while making reference to the particular paragraph number. The Government will answer questions or requests for clarification via a written RFQ amendment. QUOTATION DUE DATE: Phase I Submissions must be received by 12:00 PM ET on June 23, 2021. Phase II submissions are tentatively scheduled to be received by 12:00 PM ET on July 9, 2021.
Failure to submit quotations by the due date and time may result in rejection of the quotation as untimely. Contractors submitting via e-mail are cautioned to allow one extra business day for delivery and confirm receipt of quotation as the e-mail will need to pass through IT security.
Contractors must also submit, with its quotation, representations required by FAR provision 52.204-24, Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment, FAR provision 52.204-26, Covered Telecommunications Equipment or Services-Representation, or FAR provision 52.212-3(v), Covered Telecommunications Equipment or Services-Representation. Please indicate in the quotation if the representations are complete in the contractor’s SAM profile.QUOTATION SUBMISSION INSTRUCTIONS:
NARA requests that contractors email one (1) copy of the quotation in accordance with Attachment 9, Quotation Submission Instructions (Volumes 1 through 4) to:
shawn.xiong@nara.gov.
8831032021Q00056 - ADAMS
ATTACHMENT 1
SCHEDULE OF PRICES
Base Year: Months 1 - 12
CLIN Description Qty Unit Firm-Fixed Unit Price
Total Price
Digital Asset Management System in accordance with Enclosure 2, Performance Work Statement
MO
Installation in accordance with Enclosure 2, Performance Work Statement
LO
Operations and Maintenance in
RESERVED
TOTAL BASE YEAR PRICE: $__________
Option Year I: Months 13 - 24
TOTAL OPTION YEAR I PRICE: $__________
Option Year II: Months 25 - 36
CLIN Description Qty Unit
TOTAL OPTION YEAR II PRICE: $__________
Option Year III: Months 37 - 48
TOTAL OPTION YEAR III PRICE: $__________
Option Year IV: Months 49-60
CLIN Description Qty Unit
TOTAL OPTION YEAR IV PRICE: $__________
TOTAL CONTRACT PRICE: $__________
ATTACHMENT 2
PERFORMANCE WORK STATEMENT
AGENCY DIGITAL ASSET MANAGEMENT SYSTEM
1.0 BACKGROUND
1.1 The National Archives and Records Administration (NARA) serves American democracy by safeguarding and preserving the records of our Government, ensuring that people can discover, use, and learn from this documentary heritage. NARA ensures ready access to the essential evidence that documents the rights of American citizens, the actions of Federal officials, and the national experience. The agency meets thousands of information needs daily, ensuring access to records on which the entitlements of citizens, the credibility of government, and the accuracy of history depend.
1.2 NARA is an independent federal agency responsible for the permanent records of the entire Federal Government. In the course of providing guidance to other agencies, preserving records, and making records accessible to the public, the nearly 3,000 staff at over 40 facilities across the country create photographs, graphics, and video recordings that need to be organized and maintained for use, reuse, and, in some cases, eventual transfer to NARA as permanent records.
1.3 NARA is seeking an Agency Digital Asset Management System (ADAMS) for managing NARA’s digital special media materials. During this implementation, the ADAMS will be used as a library for completed work and managing works-in-progress. The objective for ADAMS is for any staff from around the agency (or for NARA support contractors from outside the agency) to have the capability to upload files or access the system from any desktop, laptop, or mobile device. NARA may have over 100TB of content to populate ADAMS during the first year and will add approximately 33TB per year during operations. Over a five-year span, the content is projecting 320TB of total storage needed in the fifth year.
2.0 SCOPE OF WORK
The Contractor shall be responsible for delivering a fully functional and operational ADAMS solution using a team of qualified experts. The Contractor shall provide a Commercial Off-the-Shelf (COTS) ADAMS solution where the data will be hosted on the NARA Enterprise Cloud, Amazon Web Services (AWS). The solution shall have role-based administration, workflow, and search and download ability. However, some assets will have access limitations to specific users based on administrative rights and privileges. The technical solution will allow the capability to gather assets into personal collections and share collections with other staff and people outside the agency.
3.0 REQUIREMENTS
3.1 ADAMS Stakeholder Business Requirements
3.1.1 NARA authorized users will have access to an ADAMS web-based system based on user roles and permissions assigned by a system administrator who can assign and create all the roles and functions of account management: permissions, roles, user groups, permissions, and restrictions.
3.1.2 Authorized users will be able to bulk upload digital media (photos, videos, audio, graphic images) with required metadata fields populated manually at ingest, embedded in the IPTC, or uploaded with an associated csv or xml file. Users will be able to sort and collect assets in galleries or groups for exporting to their desktops, phones, internally and externally.
3.1.3 Authorized users shall be able to manage digital special media assets via workflow.
The solution should provide the capability for an authorized user to define and manage the workflow process through reporting on an audit trail that records all activity in the system, configuring and defining alerts, and through version control of digital assets.
3.1.4 Authorized users shall be able to approve digital special media assets for use by the general public. The system should have a workflow that includes the email notification of assets awaiting approval and the email notification of assets that have been approved. Assets should be held in a queue only visible to the user and approver until the asset has been approved for release.
3.1.5 Users will be able to perform searches for assets using and specifying all IPTC and custom metadata fields, parametric (advanced) searches, keywords. Search results will have the capability to be sorted, filtered, saved and exported.
3.1.6 Users will be able to singularly and bulk export and crop asset derivatives in several resolutions/sizes. For example, still image as a high res tif or jpg, medium and low res jpg, and video exported in low and high res. Metadata is exported embedded in the file and as a sidecar extract alongside the derivative asset renditions.
3.1.7 Authorized users will be able to securely share asset(s) to internal and external (non- NARA) users (without authentication) via notification through email with a link to the selected assets.
3.1.8 The System Administrator will be able to manage assets by associating an alert that will notify the System Administrator to initiate a scheduled records transfer on a certain date through the employment of a proprietary metadata field designated, populated, and capable of being edited by the System Administrator.
3.1.9 The system will provide canned (built-in) reports and custom reports showing approvals/rejections for any asset or user workflow. Canned and custom reports can be generated using rejection/approval or other pre-defined outcomes.
3.1.10 Users will have access to online training which must be included with the system.
3.1.11 The solution should be browser agnostic and accessible at a minimum through Microsoft Edge and Google Chrome.
3.1.12 The solution shall support Internet Protocol version 6 (IPv6).
3.1.13 The solution user interface shall comply with Section 508 Standards for Electronic and Information Technology.
3.1.14 The solution shall be in compliance with NARA IT Security requirements by keeping an exportable, searchable audit log for modifications to digital content, have the capability for system administrator to run file integrity checks, and authenticate users using NARA's identity management and authentication services.
3.1.15 The Contractor’s solution shall use existing NARAnet credentials and 2-factor authentication (via Security Assertion Markup Language (SAML) or NARA’s SecureAuth), when authenticating known NARA users. The Contractor’s solution may use means other than authentication for granting temporary access to external (non-NARA) users (e.g. a temporary unique link to an upload or download interface that can expire after a set amount of time). The Contractor shall describe how the methodology ensures that only the appropriate user(s) can access the link, and how a NARA user can restrict or terminate access to that link after a given time interval has expired.
3.2 Additional Functionality. The ADAMS solution may perform these functions:
3.2.1 Authorized users will be able to publish assets directly to social media channels including: YouTube, Instagram, Facebook, and Twitter from approved mobile and desktop devices.
3.2.2 The solution will interoperate with multimedia editing and desktop publishing applications (Adobe Creative Suite) for editing photos, videos, and graphic images.
3.2.3 The solution will support a folder-based library structure.
3.3 Operations and Maintenance and Installation
The Contractor shall install, operate, maintain, and support the ADAMS software application to ensure that services are provided without interruption to the production environment. The Contractor shall support the operation and maintenance of the ADAMS system, keeping the system operating with supported Contractor releases or off-the-shelf software upgrades. This will include both major and minor product releases, i.e. upgrading from version 4.0 to 5.0, as well as from 4.0 to 4.1. All upgrades, updates and patches shall be installed by the Vendor with support from the NARA IT staff.
3.3.1 Installation. The Contractor shall install and configure all system software requirements for the ADAMS solution. The Contractor shall work in coordination with the COR to deploy a fully functional ADAMS on NARA’s AWS environment.
3.3.2 Software maintenance and support shall include the following:
3.3.2.1 Software Support. Contractor phone support should be provided during standard working hours. NARA’s standard hours are defined as weekdays, not including statutory holidays, Monday through Friday between 6:30 AM and 6:00 PM ET.
3.3.2.2 Software - Application Patches. All incremental application patches should be included and installed by the Contractor. Patches shall be installed with the support of the COR.
3.3.2.3 Operating System Patches. All operating systems (OS) patches will be tested for potential impact to the system, if any. The results will be published within 30 calendar days after being issued by the OS contractor. NARA will have access to this list. NARA personnel will install all OS patches after verifying operation from the Contractor.
3.3.2.4 System Database Patches. All system database patches will be tested for potential impact to the system, if any. The results will be published within 30 calendar days after being issued by the system database manufacturer. NARA will have access to this list. NARA personnel will install all System Database patches after verifying operation from the manufacturer.
3.4 NARA IT Security Requirements
The Contractor must comply with the NARA IT Security Requirements for Cloud-based systems in accordance with Appendix A. These requirements apply to all contractors and subcontractors, including cloud service providers ("CSPs"), and personnel of contractors, subcontractors, and CSPs that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of NARA Information. These requirements implement specific NARA security requirements applicable to this contract.
4.0 PROJECT MANAGEMENT
The Contractor shall develop and deliver a Project Management Plan (PMP) to describe the Contractor’s overall strategy and approach to managing the services under this requirement. It shall also detail management processes, organization design, and roles and responsibilities of key personnel and subcontractors. In addition, the PMP shall describe the communication channels to be used internally and externally, and the approaches for subcontractor management, risk management, planning and scheduling. The Contractor shall submit updates as required to document changes in the PMP. The PMP shall address, at a minimum, the following specific topics:
4.1 Contractor’s approach to overall project management and administration;
4.2 Contractor’s approach to configuration management; and
4.3 Contractor’s proposed lines of responsibility, authority, and communication through which IT tasks and related sub-tasks are managed.
5.0 GOVERNMENT FURNISHED INFORMATION (GFI)
The Government will provide the Contractor the data and information required in the performance of this contract. This will include applicable background information and NARA’s directives, policies, and regulations. The Contractor shall safeguard information and records from being compromised, altered, destroyed, mutilated, damaged, or lost.
APPENDIX TITLE DATE
A IT Security Requirements_v6 September 12, 2019 B Contingency Plan Template No Date C Incident Response Plan Template April 3, 2019 D Quality_Assurance_Cloud_CMDB_Template August 21, 2017 E System Security Plan Requirements No Date F Configuration Management Database
(CMDB) Template April 3, 2018
G Interface Control Document (ICD) Template No Date
6.0 DELIVERABLES
All contract deliverables must be submitted to the COR for review and approval, as specified below. The Government will have ten (10) business days to review after which the COR may return the deliverable to the Contractor for rework or accept the deliverable as completed. The Contractor shall have five (5) days to review, rework, and provide revisions to the COR, unless specified otherwise by the COR.
DELIVERABLE
TITLE
FORMAT DUE DATE
Project Management Plan, Project Schedule and Timeline
Microsoft (MS) Project or Clarity
Within 30 days of award
Bi-weekly Status Meetings and Notes
MS Word or Google Bi-weekly
Architecture design, data migration plan, data mapping, interface control document, logical data model, and physical data model
MS Word or Google As requested
Server Configurations and Settings
On servers and routers; MS Word or Google
As requested, per NIST and NARA guidelines
Final architecture design and implementation design documents
MS Word or Google As requested
Configuration and Implementation of NIST 800-53 Security Controls
On applicable platform
As requested, per NARA Security Benchmark Guides and NIST 800-53
Support for updates to System Security Plan (SSP) (application controls only)
MS Excel, Google, or Xacta format
As requested, per
NIST 800-53
Support for updates to Contingency Plan (CP)
MS Word, Google, or Xacta format
As requested, per
NIST SP 800-53
Support for Authorization to Operate
(ATO)
In person; MS Word, Google, or Xacta format
As requested
Operations and Maintenance Manuals
Paper and electronic format
As requested
System Plans and Specifications
Paper and electronic format
As requested
Software Licenses and Agreements
Paper and electronic format
As requested
APPENDIX A
IT SECURITY REQUIREMENTS
(ATTACHED)
ATTACHMENT 3
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
1.0 INTRODUCTION:
This Quality Assurance Surveillance Plan (QASP) has been developed to provide the Quality Assurance Evaluator / Contracting Officer’s Representative (COR) and other Government evaluators a summary of the key performance standards required in the contract, performance levels, and method of surveillance normally used for that performance standard. These are listed in Attachment 4, Performance Requirements Summary (PRS).
The QASP describes a systematic method to evaluate receipt by the Government of acceptable services the Contractor is required to furnish. The Contractor is required to provide satisfactory performance in all areas of the contract. Before invoices can be paid, a determination by the COR must first be made that satisfactory services have been received.
Any non-conformance with contract requirements is a “defect”. A defect may be recorded for each item evaluated that failed to meet the standards as required by the subject Performance Work Statement (PWS) paragraph(s). Examples of defects that will be recorded include, but are not limited to:
a. Failure to perform a required task;
b. Failure to take corrective action to prevent reoccurrence of less than satisfactory performance; or
c. Performance of less than satisfactory work (quality work consists of completing the work in accordance with the appropriate PWS specifications, manufacturer’s recommendations, Government regulations, or best industry practices).
Quality Assurance is based on the premise that the Contractor, and not the Government, is responsible for management and quality control actions to meet the terms of the contract. The Government will follow the guidance in FAR 52.212-4, Contract Terms and Conditions - Commercial Items when performance is other than satisfactory.
Good management and use of an adequate quality control (QC) plan will allow the Contractor to operate within specified performance requirements. The COR and Government evaluators shall be objective, fair, and consistent in evaluating Contractor performance against contract requirements and standards. The main emphasis is on quality performance.
2.0 ACTUAL SURVEILLANCE:
Actual surveillance will be performed on a periodic basis, 100% surveillance, or as otherwise specified in the PRS in conjunction with the PWS.
If satisfactory performance is not achieved, the COR will determine the possible cause of the less than satisfactory performance. The COR will initiate a Contract Discrepancy Report (CDR) for all defects that could not be re-performed and for all defects not corrected by the Contractor in a timely or satisfactory manner when requested by the Government. The COR will submit the
CDR documentation recording the less than satisfactory performance and stating a recommended action to the Contracting Officer (CO) including any proposed contract deductions.
3.0 SURVEILLANCE METHODS:
Services shall have the results of the surveillance documented. The surveillance methods the Government will use to evaluate the Contractor’s performance for the listed tasks are specified in the PRS. Customer complaints may be used in conjunction with the above surveillance methods as an indicator of performance or as areas to emphasize further for future surveillance.
4.0 INFORM CONTRACTOR:
a. Regardless of the surveillance method, the Contractor should be kept informed of performance status. The COR will notify the Contractor of any defect(s) to be corrected. The time to re-perform and correct defects after notification will vary depending on the type of defect, the item being inspected, the level of the item (i.e., routine, urgent, or emergency), etc.
The COR will inspect re-performed or corrected discrepancies. If corrected properly and timely, the defect(s) will not result in a payment deduction. However, the COR will maintain all documentation for file maintenance and turn this information over to the CO upon completion of the contract. Performance issues should also be an item of discussion during contract status meetings.
b. CDRs should be used to officially notify the Contractor of a performance problem.
CDR use includes notifying the Contractor of:
(i) Non-performance or less than satisfactory performance when the Government elects not to have the Contractor re-perform the service;
(ii) Failure of the Contractor to re-perform non-performed or less than satisfactory performed services;
(iii) Non-performed or less than satisfactory services that cannot be re-performed due to the nature or the timing of the required services; and
(iv) Continuous, less than satisfactory service whether the service is re-performed or not.
c. Critical performance problems should be immediately communicated with a follow-up written CDR. The COR will complete the CDR and forward it to the CO for review and approval. The COR will sign and forward the CDR to the Contractor for the Contractor’s response and comments. The Contractor will have seven (7) calendar days (or such lesser time that the COR stipulates) to complete a response. After evaluating the Contractor’s response, the COR will forward the CO any CDR requiring further action (contract interpretation, problem resolution, reduced payments, deficiency letter notification, cure notice, etc.). The COR will provide the CO recommended actions with supporting rationale.
5.0 REVISIONS TO QASP:
Revisions to this surveillance plan are the responsibility of the COR and the CO.
ATTACHMENT 4
PERFORMANCE REQUIREMENTS SUMMARY (PRS)
1.0 PERFORMANCE REQUIREMENTS SUMMARY (PRS). The PRS captures key requirements of the Performance Work Statement (PWS) at an outcome level (performance standard) and states the performance level and method of surveillance for the requirement. The absence of any contract requirement from the PRS does not limit the rights or remedies of the Government within the contract.
2.0 METHOD OF SURVEILLANCE. The PRS provides the surveillance method(s) the Government will use to evaluate the Contractor’s performance for the listed tasks. The primary surveillance methods used will be 100% surveillance, periodic surveillance, or customer complaints.
3.0 GOVERNMENT QUALITY ASSURANCE. The Quality Assurance Surveillance Plan, Attachment 3, describes how the Government will inspect, in conjunction with this PRS, and how the COR, other performance evaluators, the Contractor, and the Contracting Officer will communicate to ensure satisfactory performance of contract requirements.
NARA – 88310321Q00056, ADAMS
PERFORMANCE REQUIREMENTS SUMMARY
REQUIREMENT
SUMMARY ITEM
(RS)
PERFORMANCE STANDARD PERFORMANCE
LEVEL
METHOD OF
SURVEILLANCE
(RS-1) Services PWS paragraph 3.0
The Contractor must provide the required services and ensure that services are performed in accordance with the requirements and are of the highest quality.
Satisfactory Periodic Surveillance
(RS-2) Government Furnished Items PWS paragraph 5.0
The Contractor maintains and utilizes equipment is accordance with the requirements outlined in the PWS.
Satisfactory Periodic Surveillance
(RS-3) Deliverables PWS paragraph 6.0
The Contractor should provide required deliverables as listed in the contract. The deliverables should be timely, accurate, complete, and provide the required information.
Satisfactory Periodic Surveillance
(RS-4) Project Management PWS paragraph 4.0
The Contractor provides PMP in timely manner and ensures ADAMS solution is successfully implemented.
Satisfactory 100% Surveillance
ATTACHMENT 5
CONTRACT ADMINISTRATION
I. GOVERNMENT CONTRACT ADMINISTRATION
a. This Contract will be administered by:
National Archives and Records Administration Office of the Chief Acquisition Officer (Z) 8601 Adelphi Road, Room 3340 College Park, MD 20740-6001
b. Contract Specialist (CS):
See award document.
c. Contracting Officer (CO):
Any warranted Z CO.
The CO has the overall responsibility for the administration of this Contract. Written communication to the Contract Specialist must reference the contract number and must either be emailed or mailed, postage prepaid, to the above address.
The CO alone, without delegation, is authorized to take actions on behalf of the Government to amend, modify, or deviate from the contract terms, conditions, requirements, specifications, details and/or delivery schedules; make final decisions on disputed deductions from contract payments for non-performance or unsatisfactory performance; terminate the contract for convenience or default; and issue final decision contract questions or matters under dispute. However, the CO may delegate certain other responsibilities to authorized representatives.
II. CONTRACTING OFFICER’S REPRESENTATIVE (COR) LEVEL 1:
a. COR: See award document
b. The individual named above is designated as the Contracting Officer’s Representative (COR) to assist the CO in the discharge of the CO’s responsibilities. The COR serves as the point of contact through which the Contractor can relay questions or problems of a technical nature to the CS and the CO. The COR is responsible for the inspection and acceptance of the contract requirements and for the review and certification of invoices for the contract requirements.
c. In no event will any understanding or agreement, modification, change order, or other matter deviating from the terms of the contract between the Contractor and any person other than the CO be effective or binding upon the Government.
d. When, in the opinion of the Contractor, the COR requests effort outside the existing scope of the contract, the Contractor must promptly notify the CO in writing.
e. No action will be taken by the Contractor under such technical instruction unless the CO has issued a contractual change.
III. ELECTRONIC INVOICING AND PAYMENT REQUIREMENTS – INVOICE
PROCESSING PLATFORM (IPP) (JANUARY 2020)
Payment requests must be submitted electronically through the U. S. Department of the Treasury's Invoice Processing Platform System (IPP).
"Payment request" means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in the applicable Prompt Payment clause included in the contract, or the clause 52.212-4 Contract Terms and Conditions – Commercial Items included in commercial item contracts. The IPP website address is: https://www.ipp.gov.
Under this contract, the following documents are required to be submitted as an attachment to the IPP invoice: Invoices shall be submitted after Government’s acceptance of all deliverables. The invoice shall contain information required by FAR 52.212-4(g).
Contractor Invoice to include:
1. Award number
2. CLIN/Item number of deliverable
3. Description of deliverable
4. Price of deliverable
5. Quantity of deliverable
6. Date deliverable was provided to the Government for inspection if applicable
7. Serial number/part number if applicable
The Contractor must use the IPP website to register, access and use IPP for submitting requests for payment. Assistance with enrollment can be obtained by contacting the IPP Customer Support Helpdesk by sending an email to IPPCustomerSupport@fiscal.treasury.gov or phone (866) 973-3131.
If the Contractor is unable to comply with the requirement to use IPP for submitting invoices for payment, the Contractor must submit a waiver request in writing to the Contracting Officer with its proposal or quotation.
IV. FINAL PAYMENT
Before final NARA payment is made, the Contractor must furnish to the CO a written release of all claims against the Government arising by virtue of the contract, other than claims in stated amounts as may be specifically excluded by the Contractor from the operation of the release. If the Contractor’s claim to amounts payable under the contract has been assigned under the
Assignment of Claims Act of 1940, as amended (31 U.S.C. § 203, 41 U.S.C. § 15), a release may also be requested of the assignee. To ensure that all necessary adjustments for non-performance or unsatisfactory performance have been made and a release of claims has been submitted before the contract is closed out, the final NARA payment will be made in thirty (30) calendar days after receipt of a proper invoice, date of completion of performance, or receipt of release of claims by the CO, whichever is later.
ATTACHMENT 6
ADDITIONAL NARA TERMS AND CONDITIONS
I. SECURITY OF INFORMATION AND PROTECTION OF CONTROLLED
UNCLASSIFIED INFORMATION, INCLUDING PERSONALLY IDENTIFIABLE
INFORMATION (APRIL 2017)
(a) Applicability
This clause applies to all controlled unclassified information, which may include personally identifiable information, as defined in Section B, regardless of the medium in which it is found and includes paper records.
(b) Definitions. As used in this clause:
“Breach” means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to personally identifiable information, in usable form whether physical or electronic.
“Controlled Unclassified Information” means information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or Government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic;
requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.
“Personally identifiable information (PII)” means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States. Examples of PII include the following:
(1) Name.
(2) Date of birth.
(3) Mailing address.
(4) Telephone number.
(5) Social Security Number.
(6) Email address.
(7) Zip code.
(8) Account numbers.
(9) Certificate/license numbers.
(10) Vehicle identifiers including license plates.
(11) Uniform resource locators (URLs).
(12) Internet protocol addresses.
(13) Biometric identifiers (e.g., fingerprints).
(14) Photographic facial images.
(15) Any other unique identifying number or characteristic.
(16) Any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive personally identifiable information (sensitive PII)” means a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
(1) Complete social security numbers, alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered sensitive PII even if they are not coupled with additional PII.
(2) Additional examples include any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
(i) Driver’s license number, passport number, or truncated social security number (such as last 4 digits);
(ii) Date of birth (month, day, and year);
(iii) Citizenship or immigration status;
(iv) Financial information such as account numbers or electronic funds transfer information;
(v) Medical information; and/or
(vi) System authentication information such as mother’s maiden name, account passwords or personal identification numbers.
(3) Other PII may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but it is not sensitive.
(c) Data Security.
(1) The Contractor shall limit access to the data covered by this clause to those employees and subcontractor who require the information in order to perform their official duties under this contract.
(2) The Contractor employees, and subcontractors must physically or electronically secure CUI, which may include sensitive PII, when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss.
(3) When CUI is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed in accordance with NIST 800-88 standards.
(4) The Contractor shall only use CUI obtained under this contract for purposes of the Contractor; it shall not be disclosed, released, disseminated, or published without the prior written consent of the Contracting Officer.
(5) If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, The Contractor shall follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.
(6) At expiration or termination of this contract, the Contractor shall turn over all CUI obtained under the Contractor that is in its possession.
(d) Systems Access. Work to be performed under this contract may require the handling of CUI, including PII. The Contractor shall provide the Government access to, and information regarding those systems handling CUI, including sensitive PII for the Government under the Contractor, when requested by the Government, as part of the Contractor’s responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the Government in assuring compliance with such requirements. Government access shall include independent testing of controls, system penetration testing by the Government, Federal Information Security Management Act data reviews, and access by agency Inspectors General (IG) for IG reviews.
When requested by the NARA CO or COR or other NARA official as described herein, in connection with NARA’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of NARA Information, Contractor shall provide NARA, including the NARA OIG,
(1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Contractor's facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by NARA or agents acting on behalf of NARA, and such access shall be provided within 72 hours of the request. Additionally, the Contractor shall cooperate with NARA’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of NARA information.
(e) Systems Security.
(1) In performing its duties related to management, operation, and/or access of systems containing PII under this contract, the Contractor, its employees and subcontractors shall comply with all applicable security requirements and rules of conduct applicable to the agency’s systems as described in:
a) NARA Directive 1608 http://www.archives.gov/foia/directives/nara1608.pdf
b) NARA Notice 2010-045;
c) NARA Penalty Guide (Personnel 300, Appendix 752A - Penalty Guide); and
d) NARA’s Media Protection Methodology.
(2) In addition, the use of Contractor-Owned laptops or other portable storage devices to process or store sensitive PII is prohibited under this contract until the Contractor provides, and the Contracting Officer, in coordination with the Senior Agency Official for Privacy (SAOP) or the SAOP’s designee, approves the Contractor’s written acknowledgment that the following requirements are met:
(i) Laptops and other portable storage devices must employ encryption that is NIST Federal Information Processing Standard (FIPS) 140-2 validated (or its successor) http://csrc.nist.gov/publications/PubsFIPS.html, and approved.
(ii) The Contractor has developed and implemented a process to ensure that security and other applications software are kept current.
(iii) Mobile computing devices utilize anti-virus software and a host-based firewall mechanism.
(iv) Removable media, such as hard drives, flash drives, devices with flash memory, CDs and floppy disks containing CUI, which may include sensitive PII shall not be removed from a Government facility unless they are encrypted using a NIST FIPS 140-2 or successor approved product.
(v) When no longer needed, all removable media, hard drives, and flash memory shall be destroyed in accordance with Government security requirements identified in NARA’s Media Protection Methodology.
(vi) The Contractor shall maintain an accurate inventory of devices used in the performance of this contract.
(3) All NARA information obtained under this contract shall be removed from Contractor- Owned information technology assets at the direction of the Contracting Officer or Contracting Officer’s Representative. Removal must be accomplished in accordance with standard FedRAMP controls for media protection in moderate IT systems and NIST 800-88 standards.
Certification of data removal will be performed by the Contractor’s Project Manager and written notification confirming acknowledgment will be delivered to the Contracting Officer within 30 days of the direction to remove the information.
(4) Back up or mirrors of any systems or files containing CUI shall be treated in the same manner as the original data containing CUI, with the same protections and obligations.
http://www.archives.gov/foia/directives/nara1608.pdf http://csrc.nist.gov/publications/PubsFIPS.html http://csrc.nist.gov/publications/PubsFIPS.html
(5) The Contractor shall require FIPS 140-2 (or successor) encryption of any sensitive PII when transmitted electronically across the Internet or other public works.
(f) Breach Notification to Government.
(1) The Contractor has been provided with: NARA Directive 1608, and is aware of its roles, responsibilities, and relationship with the Government in case of data breach.
(2) In the event of any actual or suspected breach of sensitive PII, the Contractor shall immediately, and in no event later than one hour of discovery, report the breach to the Contracting Officer, the COR, the Senior Agency Official for Privacy (currently NARA’s General Counsel garymstern@nara.gov) and the Chief Information Officer (only for IT requirements) in accordance with NARA Directive 1608.
(3) The Contractor is responsible for positively verifying that notification is received and acknowledged by appropriate Government parties identified in subparagraph (2) above.
(4) In the event of a confirmed, potential or suspected Security Breach, involving unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any NARA Information accessed by, retrievable from, processed by stored on, or transmitted within, to or from any such system, Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the NARA CO and the CO's Representative (''COR").
(5) NARA, at its sole discretion, may obtain, and Contractor will permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any security incident, PII or Security Breach. Additionally. NARA, at its sole discretion, may require Contractor to retain, at Contractor's expense, a Third Party Assessing Organization (3PAO) acceptable to NARA, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.
(6) Any report submitted in accordance with paragraphs (1), (2) and (3) above, shall identify (I) both the Information Systems and NARA Information involved or at risk, including the type, amount, and level of sensitivity of the NARA Information and, if the NARA Information contains PII, the estimated number of unique instances of Pll, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the USCERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by the NARA. Contractor shall continue to provide written updates to the NARA CO regarding the status of the Security incident at least every three (3) calendar days until informed otherwise by the NARA CO.
(7) Response activities related to any security incident or PII or Security Breach undertaken by NARA, including activities undertaken by Contractor, other federal agencies, and any third-party contractors or firms at the request or direction of NARA, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Security Incident and/or liability for any additional response activities. Contractor shall be responsible for all costs and related resource a locations required for all such response activities related to any Security Incident or Breach, including the cost of any penetration testing.
(g) Personally Identifiable Information Notification Requirement
Contractor certifies that it has a security policy in place that contains procedures to promptly notify any individual whose Personally Identifiable Information ("Pll") was, or is reasonably determined by NARA to have been, compromised. Any notification shall be coordinated with the NARA CO and shall not proceed until NARA has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by Contractor shall be coordinated with, and subject to the approval of, NARA. Contractor shall be responsible for taking corrective action consistent with NARA Data Breach Notification Procedures and as directed by the NARA CO, including all costs and expenses associated already covered by above clauses added in PII clause with such corrective action, which may include providing credit monitoring to any individuals whose Pll was actually or potentially compromised. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident, Breach, or PII Breach will be made by NARA senior officials at NARA’s discretion.
(h) Flowdown of security requirements to subcontractors.
(1) The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph (g), in all subcontracts under this contract, and require written subcontractor acknowledgement of same.
(2) Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.
II. CONFIDENTIALITY OF INFORMATION
(a) Confidential information is any information that, if subject to unauthorized access, modification, loss, or misuse could adversely affect the national interest, the conduct of Federal programs, or the privacy of individuals, but has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy. Confidential information also includes proprietary data and information for which other restrictions on access apply.
(b) The Contracting Officer and the Contractor may, by mutual consent, identify elsewhere in this contract specific information and/or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential.
Similarly, the Contracting Officer and the Contractor may, by mutual consent, identify such confidential information from time to time during the performance of the contract. Failure to agree will be settled pursuant to the “Disputes” clause.
(c) While in the course of performance of this contract, the Contractor may have access to confidential information and communications, including but not limited to Personally Identifiable Information (PII). Confidential information may be contained in printed material or on electronic media. The Contractor will preserve the confidentiality of all such information and communications and agrees not to disclose, release, disseminate, or publish any such information or communications for any purposes whatsoever without the prior approval of the Contracting Officer. Failure to comply with the provisions of this paragraph will be grounds for Termination for Cause and the Contractor may be liable for damages. This provision shall survive the expiration or termination of the period of performance of this contract.
(d) If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, the Contractor will follow…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .