A1 SOW.pdf

PDF 285 KB Posted

Attached to
Battery UPS Replacement Federal contract opportunity
Solicitation number
75D301-20-R-67980
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

This is a solicitation for battery uninterruptible power supply (UPS) replacement services at multiple Centers for Disease Control and Prevention facilities. The solicitation seeks replacement of Life Safety and Laboratory UPS units that have reached end of service life at buildings located on the Roybal Campus. Services required include removal and disposal of existing wet-cell and VRLA batteries, installation of new UL 1778 and UL 924/UL 1778 compliant UPS units, and performance testing. The estimated price range for the firm fixed price contract is between $1 million to $5 million, with a period of performance of 365 days from notice to proceed. This is a woman-owned small business set-aside, with a small business size standard of $16.5 million for NAICS 238990. A pre-proposal meeting is scheduled for June 18, 2020 and single award anticipated. Questions may be addressed to the contact by June 30, 2020, referencing solicitation 75D301-20-R-67980.

View the file

Other files for this federal contract opportunity

Other files attached to Battery UPS Replacement, newest first.
File Type Posted
Amendment 00002.pdf PDF
Amendment 00001.pdf PDF
Drawings.pdf PDF
Site Photos 1.zip ZIP file
A12 General References.docx DOCX document
A9 Past Performance.docx DOCX document
A10 HazMat.docx DOCX document
A11 Bid Bond.pdf PDF
75D301 20 R 67980.pdf PDF
A8 Wage Determination GA20200126.pdf PDF
A14 Project Experience.docx DOCX document
A13 Deliverables_LmtOnSubconRpt_REQD.xlsx XLSX spreadsheet
A15 _Contractor_Visit_Form.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

04 ARPRIL 2020

STATEMENT OF WORK

FY20: REPLACE LIFE SAFETY AND LABORATORY

UNINTERRUPTIBLE POWER SUPPLIES

ROYBAL CAMPUS

SECTION 1 – BACKGROUND

There are several locations at the Centers for Disease Control and Prevention (CDC), Roybal Campus, that require replacement of Life Safety and Laboratory uninterruptible power supplies (UPSs). These systems are at or nearing the end of service life as indicated by quarterly preventative maintenance testing reports and market research performed for replacement parts. Several UPS units are considered to be Life Safety, but do not conform to UL 924 or NFPA 101 requirements. These systems will require replacements, as they serve critical data, emergency, life safety, laboratory and general-purpose loads within the facility. Having an inappropriate UPS will directly affect the expected runtime and the ability to serve facility loads during an unplanned power outage.

SECTION 2 – GENERAL PROJECT REQUIREMENTS

A. GENERAL REQUIREMENTS

A.1 DEFINITIONS

Contracting Officer

(CO)

The individual designated to administer the contract. Throughout this contract this individual will be responsible and possess the authority to act on behalf of the Government with respect to the specific contract.

Contracting Officer Representative (COR)

The individual designated by the Contracting Officer as the authorized representative of the Contracting Officer. The COR is responsible for monitoring performance and technical management of the effort required and should be contacted regarding questions or problems of a technical nature.

Contract Contract or task order.

Contractor The term Contractor refers to both the prime Contractor and all subcontractors, whether in contract with the Prime Contractor or other subcontractors at any tier, including the Designer of Record.

Quality Control (QC) Contractor's system to control the quality of design, material, equipment and construction.

Quality Assurance

(QA)

Government's program to evaluate the effectiveness of the Contractor's quality control. The Government's QA Program is not a substitute for the Contractor's QC Program.

Federal Holidays New Year's Day, Martin Luther King Jr. Day, President's Day, Memorial Day, Independence Day; Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, and Christmas Day.

A.2 CHANGES

No oral statement by any person other than the Contracting Officer, as provided in FAR 52.243-4 Changes, will in any manner or degree modify or otherwise affect the terms of this contract. The contractor must provide the Contracting Officer written document for changes to the contract.

A.3 NO WAIVER BY THE GOVERNMENT

The failure of the Government in any one or more instances to insist upon strict performance to any of the terms of this contract or to exercise any option herein conferred is not to be construed as a wavier or relinquishment to any extent of the right to assert or rely upon such terms or options on any future occasion.

A.4 WARRANTY

Warrant all materials and work for not less than one year after final acceptance of the work, except as otherwise indicated in this Statement of Work. If required to provide remedial repair of previously installed work due to latent defect or unacceptable work performance, warrant the repaired work for one year after the completion and acceptance of the repair. For warranted items, furnish the manufacturer’s original written warranty accompanied by a copy of the supplier's receipt showing place of purchase, telephone number of suppliers, address, delivery order number if applicable, and ticket number.

B. SUMMARY OF WORK

B.1 PROTECTION OF GOVERNMENT PROPERTY

Take special care to protect CDC property. Return areas damaged as a result of construction under this contract to their original condition. In addition to FAR 52.236-9, Protection of Existing Vegetation, Structures, Equipment, Utilities, and Improvements, perform the following:

a. Remove or alter existing work or facilities in such a manner as to prevent injury or damage to any portion of the existing work or facilities that remain.

b. Repair or replace portions of existing work altered during construction operations to match existing or adjoining work, as approved by the Contracting Officer. At the completion of operations, existing work must be in a condition equal to or better than that which existed before new work started.

c. Provide dust covers or protective enclosures to protect existing work that remains and CDC material and equipment located in the vicinity during the construction period.

d. Preserve the natural resources as required. Coordinate with CDC Environmental Office.

B.2 GOVERNMENT FURNISHED MATERIAL AND EQUIPMENT

If applicable, the Government will furnish the materials and equipment for installation by the Contractor pursuant to contract clause FAR 52.245-2, Government Property (Fixed Price Contracts). Notify the Contracting Officer in writing at least 15 calendar days before the materials and equipment are required.

Pick up materials and equipment no later than 30 calendar days after such date. When materials and equipment are not picked up by the 30th day, the Contractor will be charged for storage at the prevailing rate. The Contracting Officer will specify the location of materials and equipment and the delivery location.

C. WORK RESTRICTIONS

C.1 SCHEDULE OF WORK

“Non-critical” work must be scheduled during normal business hours from 6:00 am to 6:00 pm, Monday through Friday, excluding Government holidays. “Critical” work must be scheduled outside normal business hours, Saturdays, Sundays, and Government holidays. The contractor must coordinate with the Contracting Officer Representative and provide a minimum two week notice to inform building occupants of upcoming work. The contractor must phase all work as necessary to minimize downtime and disruption to CDC. The contractor must deliver material and equipment to the site. The contractor must coordinate laydown area with Contracting Officer Representative for material and equipment.

C.2 SECURITY, BADGES AND ACCESS

Obtain badges, passes, accesses, and etc., as necessary for entrance to construction site, buildings, and rooms. All security requirements apply to all subcontractors and suppliers associated with this contract. Follow security requirements as set forth by CDC.

D. PRICE AND PAYMENT PROCEDURES

Contractor requests for payment must conform and will be processed in accordance with the requirements of FAR 52.232-5 Payments under Fixed-Price Construction Contracts and FAR 52.232-27 Prompt Payment for Construction Contracts.

D.1 SCHEDULE OF PRICES

Within 15 calendar days of notice of award, prepare and deliver to the Contracting Officer a Schedule of Prices (construction contract) as directed by the Contracting Officer. Provide a detailed breakdown of the contract price, giving quantities for each of the various kinds of work, unit prices, and extended prices.

Costs must be summarized, and totals provided for each construction category. The Contractor may invoice for bonds once the Government has approved the bonds, however, no other requests for payment will be processed without an approved Schedule of Prices.

E. ADMINISTRATIVE REQUIREMENTS

E.1 SUPERVISION

The Contractor must have a superintendent fluent in English on the job site during working hours. The Superintendent must have a minimum of 5 years of experience as a Superintendent on previous projects of similar size and complexity. The Superintendent may serve as the Site Safety and Health Officer.

Provide a Superintendent Resume for the proposed on-site Project Superintendent describing experience with references and qualifications to the Contracting Officer for approval. The Contracting Officer reserves the right to interview the proposed on-site Project Superintendent at any time in order to verify the submitted qualifications.

F. POST AWARD MEETINGS

F.1 PRE-CONSTRUCTION CONFERENCE

Prior to construction or demolition, meet with representatives of the Contracting Officer to discuss and develop mutual understanding relative to administration of the safety programs, environmental issues, safety of building occupants and surrounding area, hazardous materials, waste disposal, construction QC procedures, construction schedule, labor provisions and other construction phase contract procedures.

F.2 CONSTRUCTION MEETINGS

Conduct construction meetings and/or conference calls with appropriate CDC personnel on an as needed basis. The contractor’s key personnel must attend the construction meetings and/or conference calls.

The construction meetings and/or conference calls is an effort to discuss project schedule, safety, quality control, phasing plans, and etc. The contractor must provide a written record of the construction meetings and/or conference calls to the Contracting Officer for documentation.

G. CONSTRUCTION SCHEDULE

Prior to the start of work, prepare and submit to the Contracting Officer for acceptance of a construction schedule in the form of a bar chart schedule in accordance with the terms in FAR 52.236-15 Schedules for Construction Contracts.

G.1 BAR CHART SCHEDULE

Provide a construction schedule in the form of a bar chart in accordance with FAR 52.236-15 Schedules for Construction Contracts. The bar chart schedule, must at a minimum, show work activities, submittals, CDC review periods, material and equipment delivery, utility outages, on-site construction, inspection, testing, and close out activities. The bar chart schedule must be time scaled and generated using an electronic spreadsheet program. Submit Schedules and updates in hard copy and on electronic media that is acceptable to the Contracting Officer. Submit an electronic back-up of the project schedule in an import format compatible with the Government's scheduling program.

G.2 SCHEDULE MONTHLY UPDATES

Update the Construction Schedule at monthly intervals or when the schedule has been revised. Keep the updated schedule current, reflecting actual activity progress and plan for completing the remaining work. Submit copies of purchase orders and confirmation of delivery dates as directed by the Contracting Officer.

H. CONSTRUCTION SUBMITTAL PROCEDURES

The CDC will be responsible for the approval of all required submittals in accordance with Statement of Work.

Refer SECTION 10 REFERENCE MATERIAL AND ATTACHMENTS “Design Package” for submittal register and its submittal items. CDC approvals, in accordance with FAR 52.236-23 Responsibility of the Architect- Engineer Contractor, must not to be construed as a complete check, and only indicates that the general method of construction, materials, detailing and other information are satisfactory. CDC approvals will not relieve the contractor of the responsibility for any errors which may exist.

H.1 SUBMITTAL REGISTER

Prepare and maintain a submittal register, as construction work progresses. The submittal register should provide or show items of equipment and materials for which submittals are required by specifications and Statement of Work. The submittal register must have, at a minimum, the action code (“A” – Approved, “AN” – Approved as Noted, “D” – Disapproved, “R” – Resubmit, and etc.), transmittal number, specification section number, paragraph number, description of the items of equipment and materials to be submitted, received on and sent on dates. Submit the submittal register once a month.

H.2 TRANSMITTAL FORM

Transmit each submittal to the Contracting Officer and Contracting Officer Representative. Transmit submittals with transmittal form prescribed by Contracting Officer Representative and standard for project. On the transmittal form identify Contractor, indicate date of submittal, and include information prescribed by transmittal form and required in paragraph entitled, "Identifying Submittals," of this section.

If required, process transmittal forms to record actions regarding samples, installations, and panels provided. File transmittal per attached instructions.

H.3 VARIATIONS

Variations from contract requirements will require CDC approval in accordance with FAR 52.236-21 Specifications and Drawings for Construction and will be considered where it is advantageous to CDC.

H.4 AS-BUILT DRAWINGS

In accordance with FAR 52.236-21 Specifications and Drawings for Construction, the contractor is required to keep a hard copy of the contract drawings at the construction site at all times. The contractor is required to mark-up the contract drawings to represent approved changes to the contract drawings.

Make comments and mark-up the drawings complete without reference to letters, memos, or materials that are not part of the as-built drawing. Show what was changed, how it was changed, where items are relocated and change related details. Mark-up in base colors red (deletions), green (additions), and blue (special items). As-built prints must be neat, legible and accurate. The contractor must provide a copy of the as-built drawings 30 days prior to completion of the construction project. The as-built drawings must be submitted in electronic format (i.e. Adobe Acrobat - pdf).

H.5 OPERATIONS AND MAINTENANCE DATA

The contractor must provide two hard copies and an electronic copy of Operations and Maintenance (O&M) Manuals 30 days prior to completion of the construction project. The O&M Manuals must include the project provided equipment, product, or system, defining the importance of system interactions, troubleshooting, and long-term preventive operation and maintenance. O&M Manuals must be organized and present information in sufficient detail to clearly explain O&M requirements at the system, equipment, component, and subassembly level. Include an index proceeding each submittal.

H.6 TRAINING PLAN

Prior to acceptance of the all work by the Contracting Officer, provide a comprehensive training for the systems and equipment provided. The training must be targeted for building maintenance personnel and applicable building occupants. The instructor(s) must be well versed in the particular system being presented. Training must include classroom or field lectures based on the system operating requirements. The location of classroom training requires approval by the Contracting Officer.

I. FIRE PROTECTION AND LIFE SAFETY

Work must comply with applicable criteria identified herein. Any project including work on means of egress, fire rated elements, Fire Suppression, Mass Notification, or Fire Alarm Systems must require the services of a Registered Fire Protection Engineer.

I.1 FIRE PROTECTION AND LIFE SAFETY CERTIFICATION

Unless otherwise specified herein, provide certification that all life safety and fire protection feature and systems have been installed in accordance with applicable criteria, the contract documents, approved submittals, and manufacturer's requirements. This certification must summarize all fire protection and life safety features.

J. HEALTH, SAFETY, AND ENVIROMENT

J.1 This section is applicable to all work covered by this contract including on-site work, i.e., services performed within the boundaries of CDC, including transportation on roads—whether CDC, public, or quasi-public roads— within the gross, overall perimeter of CDC facilities and assigned CDC operations.

J.2 GENERAL REQUIREMENTS

J.2.1 The Contractor must comply with all applicable health, safety, and environmental regulations (including recordkeeping, notification and reporting requirements), orders, permits, and policies of the Federal State, and local government, and any other safety, health, and environmental requirements or consensus standards applicable to the execution of work under this Contract.

J.2.2 Applicable regulations. The specific regulations listed below form a part of this specification to the extent referenced. The regulations are referred to in the text by basic designation only. The list below should not be considered exhaustive or to supplant any other applicable federal, state, or local laws, regulations, orders, permits and/or policies.

a. Code of Federal Regulations (CFR)

b. Occupational Safety and Health Administration (OSHA) General Industry Safety and Health Standards (29 CFR 1910); OSHA Construction Industry Standards (29 CFR 1926).

Both publications are available for sale by the Superintendent of Documents, U.S.

Government Printing Office, Washington, D. C. 20402, or OSHA’s website at http://www.osha.gov.

i. National Emission Standards for Hazardous Air Pollutants (40 CFR, Part 61-63)

ii. State Air Quality Control (Rule 391-3-1)

iii. Hazardous Materials (49 CFR, Parts 171, 172)

iv. Hazardous Waste Management System (40 CFR, Part 260-265)

v. Emergency Planning and Community Right-to-Know Act (EPCRA) (40 CFR, Parts 68, 350, 355, 370, and 372)

vi. National Pollutant Discharge Elimination System (40 CFR, Parts 9, 122-124)

vii. Oil Pollution Prevention (40 CFR, Part 112)

J.2.3 The Contractor is notified that CDC uses an Environmental Management System process to achieve the sustainability goals identified in the HHS, and tiered CDC (2012), Strategic Sustainability Performance Plan (SSPP). The Contractor must work with the appropriate CDC business support offices to achieve these goals.

J.2.4 In this section, safety encompasses environment, safety, and health—including pollution prevention and waste minimization; employees include subcontractor employees; and line management includes those Contractor and subcontractor employees managing or supervising employees performing work.

J.3 Contractor's Responsibility for Health, Safety and Environment (HSE). The Contractor must bear the sole responsibility and full liability for compliance with all applicable federal, state and local regulations pertaining to the environment and the health and safety of Contract personnel during the execution of work under this contract. There will be no reimbursement made by the Government for payment of monetary penalties resulting from citations issued to the Contractor by regulatory agencies for violation of health and safety standards, including OSHA citations and penalties. The Contractor must hold the Government harmless for any action of the Contractor, or Contractor or Sub-contractor personnel, which may result in injury, illness or death.

CDC’s Health and Safety office must be notified of any atypical subcontract work and must have access to, and the right to examine HSE programs of the subcontractor.

J.4 COMPREHENSIVE HEALTH AND SAFETY PLAN (CHSP)

Within 7 days of contract award, the Contractor must submit a draft Comprehensive Health and Safety Plan (CHSP) for implementing a site-specific overall safety program.

The submittal will be reviewed by the Contracting Officer, COR, and representatives from the government’s Health and Safety Office within 14 days of receipt and a meeting will be scheduled to discuss and develop a mutual understanding relative to the administration of the overall safety program, to review a list of all hazardous operations and other major or key operations required or planned in the performance of the Contract, as well as review revisions, if any to the draft CHSP.

The finalized CHSP, ready for review and approval by the COR, must be submitted within 14 working days after the meeting with the Contracting Officer, COR, and representatives from the CDC Health and Safety Office.

http://www.osha.gov/

J.5 ENVIRONMENTAL STEWARDSHIP AND SUSTAINABILITY

Within 45 days of award, Contractor must provide written plans defining their procedures that will support CDC’s compliance with applicable environmental regulations and achievement of the goals set forth in the SSPP. Contractor is encouraged to provide copies of their Company Environmental Policy or acknowledgement of an Environmental Management System, as applicable.

Within 45 days of written request from CDC, Contractor must provide plan updates and develop new plans necessary to support CDC’s continuous improvement in stewardship and sustainability, consistent with CDC’s EMS.

K. INFORMATION TECHNOLOGY

K.1 BASELINE SECURITY REQUIREMENTS

1. Applicability. The requirements herein apply whether the entire contract or order (hereafter

“contract”), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart

2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

2. Safeguarding Information and Information Systems. In accordance with the Federal Information

Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) must:

a. Protect government information and information systems in order to ensure:

i. Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

ii. Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

iii. Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location.

In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer must immediately, within one (1) hour or less, bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.

3. Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [x ] Low [ ] Moderate [ ] High

Integrity: [ x] Low [ ] Moderate [ ] High

Availability: [x ] Low [ ] Moderate [ ] High

Overall Risk Level: [x ] Low [ ] Moderate [ ] High

Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[ x] No PII [ ] Yes PII

4. Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.”

Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.

PII Confidentiality Impact Level has been determined to be: [x] Low [ ] Moderate [ ] High

5. Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI.

32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, must be:

a. marked appropriately;

b. disclosed to authorized personnel on a Need-To-Know basis;

c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and

d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.

Destruction of information and/or data must be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

6. Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) must protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.

7. Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS must be used only for the purpose of carrying out the provisions of this contract and must not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract.

The Contractor assumes responsibility for protection of the confidentiality of Government records and must ensure that all work performed by its employees and subcontractors must be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed must be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information must be protected in accordance with HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:

a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

8. Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol must comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6). .

9. Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS must enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP.

For internal-facing websites, the HTTPS is not required, but it is highly recommended.

10. Contract Documentation. The Contractor must use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.

11. Standard for Encryption. The Contractor (and/or any subcontractor) must:

a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.

c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use have been validated under the Cryptographic

Module Validation Program to confirm compliance with FIPS 140-2. The Contractor must provide a written copy of the validation documentation to the COR.

e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys must be provided to CDC Office of Chief Information Security Officer (OCISO).

12. Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract must complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA must be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.

13. Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor must assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.

a. The Contractor must assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.

K.2 TRAINING

1. Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract must complete the applicable HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees must complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training must be compliant with HHS training policies.

2. Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they must complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.

All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes must have their user accounts disabled until they have met their RBT requirement.

3. Training Records. The Contractor (and/or any subcontractor) must maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records must be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

K.3 RULES OF BEHAVIOR

1. The Contractor (and/or any subcontractor) must ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.

2. All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.

K.4 INCIDENT RESPONSE

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information” (03 January 2017) states:

Definition of an Incident:

An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

Definition of a Breach:

The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

It further adds:

A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.

The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.

Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC must include the following requirements:

1. The contractor must cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.

2. All contractors and subcontractors must properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors must protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.

3. All contractors and subcontractors must participate in regular training on how to identify and report a breach.

4. All contractors and subcontractors must report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) must respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC) or CDC Computer Incident Response Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655- 2245, whether the response is positive or negative.

5. All contractors and subcontractors must be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.

6. All contractors and subcontractors must allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with HHS/CDC Policy and the HHS/CDC Breach Response Plan and to assist with responding to a breach.

7. Cloud service providers must use guidance provided in the FedRAMP Incident Communications Procedures when deciding when to report directly to US-CERT first or notify CDC first.

8. Identify roles and responsibilities, in accordance with HHS/CDC Breach Response Policy and the HHS/CDC Breach Response Plan. To this end, the Contractor must NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative.

If so instructed by the Contracting Officer or representative, all notifications must be pre-approved by the appropriate CDC officials, consistent with HHS/CDC Breach Response Plan, and the Contractor must then send CDC- approved notifications to affected individuals; and,

9. Acknowledge that CDC will not interpret report of a breach, by itself, as conclusive evidence that the contractor or its subcontractor failed to provide adequate safeguards for PII.

K.5 POSITION SENSITIVITY DESIGNATIONS

All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR).

The requiring activity representative, in conjunction with Personnel Security, must use the OPM Position Sensitivity Designation automated tool (https://www.opm.gov/investigations/) to determine the sensitivity designation for background investigations. After making those determinations, include all applicable position sensitivity designations.

K.6 HOMELAND SECURITY PRESIDENTIAL DIRECTIVE (HSPD)-12

The Contractor (and/or any subcontractor) and its employees must comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.

For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12)

Roster. The Contractor (and/or any subcontractor) must submit a roster by name, position, e-mail address, phone number and responsibility of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster must be submitted to the COR and/or CO by the effective date of this contract. Any revisions to the roster as a result of staffing changes must be submitted immediately upon change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.

If the employee is filling a new position, the Contractor must provide a position description and the

Government will determine the appropriate suitability level.

K.7 CONTRACT INITIATIN AND EXPIRATION

1. General Security Requirements. The Contractor (and/or any subcontractor) must comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor must follow the HHS EPLC framework and methodology and in accordance with the HHS Contract Closeout Guide (2012).

HHS EA requirements may be located here: https://www.hhs.gov/ocio/ea/documents/proplans.html CDC EPC Requirements: https://www2a.CDC.gov/CDCup/library/other/eplc.htm

2. System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.

3. Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) must provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

4. Notification. The Contractor (and/or any subcontractor) must notify the CO and/or COR and system

ISSO before an employee stops working under this contract.

5. Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) must return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor must provide a certification that all government information has been properly sanitized and purged from Contractor-owned https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.hhs.gov/ocio/ea/documents/proplans.html https://www2a.cdc.gov/CDCup/library/other/eplc.htm systems, including backup systems and media used during contract performance, in accordance with HHS and/or CDC policies.

6. The Contractor (and/or any subcontractor) must perform and document the actions identified in the

CDC Out Processing Checklist (http://intranet.cdc.gov/od/hcrmo/pdfs/hr/Out_Processing_Checklist.pdf) when an employee terminates work under this contract. All documentation must be made available to the CO and/or COR upon request.

K.8 RECORDS MANAGEMENT RETENTION

The Contractor (and/or any subcontractor) must maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS policies and must not dispose of any records unless authorized by HHS.

In the event a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it must be documented and reported as an incident in accordance with HHS policies.

L. QUALITY ASSURANCE

L.1 QUALIFIED TESTING ORGANIZATION

The contractor must engage the services of a qualified testing organization to provide inspection, testing, calibration, and adjustments to electrical distribution system and generation equipment. The testing organization must be independent of the supplier, manufacturer, and installer of the equipment. The testing organization must be a first-tier subcontractor. Work must not be performed by a second-tier subcontractor.

a. Submit name and qualifications of the testing organization. The testing organization must be regularly engaged in the testing of electrical materials, devices, installations, and systems for a minimum of five years. The testing organization must have a calibration program and test instruments used must be calibrated in accordance with NETA ATS and NETA MTS, as applicable.

b. Submit name and qualifications of the lead engineering technician performing the required testing service. Include a list of three comparable jobs performed by the technician with the specific names and telephone numbers for reference. Testing, inspection, calibration, and adjustments must be performed by an engineering technician, certified by NETA or the National Institute for Certification in Engineering Technologies (NICET) with a minimum of 5 years’ experience inspecting, testing, and calibrating electrical distribution and generation equipment, systems, and devices.

L.2 INSPECTION AND TEST REPORTS

Submit certified copies of inspection and test reports. Reports must include certification of compliance with specified requirements, identify deficiencies, and recommend corrective action when appropriate.

Type and neatly bind test reports to form a part of the final record. Submit test reports documenting the results of each test not more than 14 days after test is completed.

L.3 TEST AND INSPECTION PROCEDURES

Submit test procedures for each item of equipment to be field tested at least 21 days prior to planned testing date. Do not perform testing until after test procedure has been approved. The test procedure must indicate how tests are to be conducted. A statement of the tests that are to be performed without indicating how the tests are to be performed is not acceptable.

http://intranet.cdc.gov/od/hcrmo/pdfs/hr/Out_Processing_Checklist.pdf

L.4 NEC QUALIFIED WORKER

Provide in accordance with NFPA 70. Qualified workers must be allowed to be assisted by helpers on a 1 to 1 ratio, provided such helpers are registered in recognized apprenticeship programs. Submit a certification confirming NEC Qualified worker requirements.

L.5 START-UP ENGINEER SERVICES

Provide the services of a qualified factory trained start-up engineer, regularly employed by the uninterruptible power supply manufacturer. The start-up services include conducting preliminary operations and functional acceptance tests. The start-up engineer must be present at the installation site, full-time, while preliminary operations and functional acceptance tests are being conducted.

M. QUALITY CONTROL

M.1 QUALITY CONTROL MANAGER

Appoint a Quality Control Manager responsible for the QC program. The Project Superintendent may serve as the Quality Control Manager on this project. The QC Manager must have a minimum 5 years of experience as a Quality Control Manager on previous projects of similar size and complexity.

M.1.1 RESPONSIBILITIES

a. Participate in post award kick-off coordination and production meetings.

b. Ensure that no construction begins before receiving notice to proceed and construction submittals are approved as required by the QC Plan.

c. Immediately stop any work that does not comply with contract plans and specifications and direct the removal and replacement of any defective work.

d. Prepare QC Reports.

e. Hold construction meetings with Project Superintendent and CDC; participation must be suitable for the phase of work.

f. Ensure that safety inspections are performed. Attend weekly Toolbox meetings.

g. Maintain submittal log.

h. Maintain updated as-built drawings on site.

i. Maintain testing plan and log. Ensure that all testing is performed per contract.

j. Maintain deficiency log on site, noting dates deficiency identified, and date corrected.

k. Certify and sign statement on each invoice that all work to be paid under the invoice has been completed in accordance with contract requirements.

l. Perform Punch-out and Pre-final inspections and participate in Final Inspections. Establish list of deficiencies; correct prior to the Final inspection.

m. Ensure that all required keys, operation and maintenance manuals, warranty certificates, and the As-built drawings are submitted to the Contracting Officer.

M.2 QUALITY CONTROL PLAN

Submit a QC Plan for Government review and acceptance prior to the start of construction. Submit the QC Manager's resume for approval prior to all other administrative submittals with the exception of bonds and insurance. The QC plan must include the following:

L.1.1. NAMES, QUALIFICATIONS and RESPONSIBILITIES

For each person in the QC…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .