AR RFP70T04021R7573N004.pdf
PDF 930 KB Posted
- Attached to
- Alarm Resolution Capability Federal contract opportunity
- Solicitation number
- 70T04021R7573N004
About this file
This is a request for proposal issued by the Transportation Security Administration seeking development solutions to support alarm resolution operations. Offerors are requested to provide near-term improvements to current security operations and capabilities, including improved sampling methods for explosives, explosives precursors, and other threat materials. Questions regarding any aspect of the solicitation must be submitted by September 3rd, and proposals in response must be submitted no later than September 13th via email. The purpose of the solicitation is to strengthen alarm resolution and threat detection capabilities.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SF30 AR RFP A3FE1.pdf | ||
| Attachment 6a Price WorksheetRev1.xlsx | XLSX spreadsheet | |
| DD 254 Form_AR RFP.pdf | ||
| SF30 AR RFP A2FE1.pdf | ||
| SF30 AR RFP A1FE1.pdf | ||
| SF1449-12a2.pdf | ||
| AR RFP questionsresponses.pdf | ||
| Attachment 5 Safety Requirements.pdf | ||
| Attachment 1 SOW.pdf | ||
| Attachment 4 DID Workbook.xlsx | XLSX spreadsheet | |
| Attachment 6 Price Worksheet.xlsx | XLSX spreadsheet | |
| Attachment 2 Bailment agreement model template for TSA as Bailee.pdf | ||
| Attachment 3 TRL definitions.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Transportation Security Administration Request for Proposal (RFP)
70T04021R7573N004 Alarm Resolution Capability
CONTENTS
PART I – STANDARD FORM 1449
PART II – Continuation of STANDARD Form 1449
2.1 General
2.2 CONTRACT
Table 1: CLIN Schedule
2.3 Contracting Officer’s Authority
2.4 Place of Performance
2.5 Period of Performance
2.6 Accessibility Requirements
PART IIA – Statement of Work PART III- Contract Clauses
3.1 Clauses Incorporated by Reference
3.2 Clauses Incorporated by Full Text
PART IV Solicitation Documents, Exhibits, or Attachments
4.1 Attachments
Table 3 – List of Attachments
PART V Solicitation Provisions
5.1 Notice to Offerors/Contractors Concerning Trade Agreements Terms Applicability to the TSA 74
5.2 Availability of Internal Appeal Process per FAR 33.103
5.3 Organizational Conflict of Interest
5.4 Annual Representations and Certifications
Part VI Instructions, Conditions, and Notice to Offerors
6.1 Points of Contact
Table 4- Points of Contact
6.2 Questions and Amendments
Table 5- Question Format
6.3 Errors, Omissions or Ambiguities
6.4 Proposal Cost Payment
6.5 Proposal Acceptance Period
6.7 Instructions to Offerors-Commercial Items
6.8 Proposal Preparation
6.9 Proposal Submission Instructions
6.10 Proposal Content
Table 6 - Proposal Content
Part VII Evaluation Factors for Award
7.1 Conformance to RFP
7.2 Basis of Award
7.3 Evaluation Factors and Relative Order of Importance
7.4 Evaluation Factor Ratings
7.5 Responsibility Determination
7.6 Evaluation Approach
PART I – STANDARD FORM 1449
[Fully executed SF1449 shall be provided at time of award]
PART II – CONTINUATION OF STANDARD FORM
2.1 GENERAL
The purpose of this Request for Proposal (RFP) solicitation is to provide the Transportation Security Administration (TSA) with development solutions that support TSA’s mission of ensuring the safety and freedom of movement for people and commerce. To achieve this mission, TSA is seeking development solutions related to Alarm Resolution (AR) operations for potential advancement and improvement in order to strengthen the agency’s ability to respond to shifting adversarial threats, detect emerging and evolving threats concealed on a property, and enable efficient and effective targeting of screening resources. The TSA is specifically interested in development that will provide near-term improvement of current security operations and capabilities, that can provide improved sampling for explosives, non-explosive precursors for Homemade Explosives (HME), and non-explosive threat materials. The proposed solution must present as a confirmatory Transportation Security Equipment (TSE)1 and have a Technical Readiness Level (TRL) of 7 or higher.
Terms and conditions of this RFP and resultant contract(s) are addressed below.
TSA reserves the right not to make an award(s) based on the submissions received.
2.2 CONTRACT
2.2.1 CLIN STRUCTURE
The below table outlines the Firm Fixed Price (FFP) CLIN structure for this Contract: The FFP proposed CLIN unit prices must be inclusive of all service, travel and materials required to meet the SOW requirements.
TABLE 1: CLIN SCHEDULE
Base Period
CLIN Description Type Unit Unit Price
Ext’d Price
0001 System Development FFP JOB
0002 Preliminary Design Review (PDR) FFP JOB
0003 System Development FFP JOB
0004 Critical Design Review (CDR) FFP JOB
0005 Initial Test Readiness Notification (TRN) FFP JOB
0006 Initial Technical Report FFP JOB
0007 Final TRN FFP JOB
1 Confirmatory TSE means screening systems that identify and analyze the alarm material with no further procedures or TSE required to verify whether it is benign and the alarm can be cleared or remains a potential threat that is elevated to Advanced Alarm Resolution (AAR).
0008 Final Technical Report FFP JOB
Option Year (OY) One
1001 OY1:System Development FFP JOB
1002 Preliminary Design Review (PDR) FFP JOB
1003 System Development FFP JOB
1004 Critical Design Review (CDR) FFP JOB
1005 Transportation Security Laboratory (TSL) Submission- Test Readiness
Review (TRR)
FFP JOB
1006 Initial Technical Report FFP JOB
1007 Transportation Security Laboratory (TSL) Submission- Test Readiness
Review (TRR)
FFP JOB
1008 Final Technical Report FFP JOB
Option Year Two
2001 System Development FFP JOB
2002 Preliminary Design Review (PDR) FFP JOB
2003 System Development FFP JOB
2004 Critical Design Review (CDR) FFP JOB
2005 Transportation Security Laboratory (TSL) Submission- Test Readiness
Review (TRR)
FFP JOB
2006 Initial Technical Report FFP JOB
Transportation Security Laboratory (TSL) Submission- Test Readiness
Review (TRR)
FFP JOB
2007 Final Technical Report FFP JOB
2.2.2 CONTRACT TYPE
The Government contemplates award of one or more Firm Fixed Price (FFP) Contract(s) resulting from this solicitation.
The funding for Contracts awarded from this RFP is for the development and data collection as noted in the milestones.2
2 Please note: A Bailment Agreement will be exercised at the time of award for two (2) systems to be utilized for the development. These systems will be bailed at no cost to the Government. (See Attachment 2 for the Bailment Agreement)
2.3 CONTRACTING OFFICER’S AUTHORITY
The CO administering the resulting Contract has responsibility for ensuring the performance of all necessary actions for ensuring compliance with the terms of this Contract, effective contracting, and safeguarding the interests of the United States in its contractual and legally binding agreements. The CO administering the resulting Contract is the only individual who has the authority to enter into, administer, or terminate this Contract and is the only person authorized to approve changes to any of the requirements under the Contract.
2.4 PLACE OF PERFORMANCE
This Contract will consist of multiple places of performance to include, but not limited to the Contractor’s facility, the Transportation Security Laboratory (TSL) located in Atlantic city, NJ, the TSA Systems Integration Facility (TSIF) located in Arlington, VA as well as airport locations (TBD).
2.5 PERIOD OF PERFORMANCE
The period of performance (PoP) of this contract shall be a base period of twelve (12) months from date of award plus two (2) 12 month options periods for a total 36 months if the Government decides to exercise the options.
2.6 ACCESSIBILITY REQUIREMENTS
Section 508 Requirements Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L.
105-220) (codified at 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.
1. All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT or that contain ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps. A, C & D, and available at https://www.gpo.gov/fdsys/pkg/CFR-2017-title36- vol3/pdf/CFR-2017-title36- vol3-part1194.pdf. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards.
Item that contains Information and Communications Technology (ICT): TBD
Applicable Exception: N/A
Authorization #: N/A
Applicable Functional Performance Criteria: All functional performance criteria in Chapter 3 apply to when using an alternative design or technology that results to achieve substantially equivalent or greater accessibility and usability by individuals with disabilities than would be provided by conformance to one or more of the requirements in Chapters 4 and 5 of the Revised 508 Standards, or when Chapters 4 or 5 do not address one or more functions of ICT.
Applicable 508 requirements for electronic content features and components (including Internet and Intranet website; Electronic documents; Electronic forms; Electronic document templates; Electronic reports; Interactive maps): All requirements in E205 apply, including all WCAG Level AA Success Criteria Apply http://www.gpo.gov/fdsys/pkg/CFR-2017-title36-
Applicable 508 requirements for software features and components (including Web, desktop, server, mobile client applications; Electronic content and software authoring tools and platforms;
Software infrastructure): All requirements in Chapter 5 apply, including all WCAG Level AA Success Criteria, 502 Interoperability with Assistive Technology, 503 Application, 504 Authoring Tools Applicable 508 requirements for hardware features and components (including Computers & laptops; Servers; Printers and Copiers; Document scanners; Peripheral Equipment (ex.
keyboards); Information kiosks and transaction machines; Video Displays and Monitors): All requirements in Chapter 4 apply
Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply
2. When providing installation, configuration or integration services for ICT, the contractor shall not reduce the original ICT item’s level of Section 508 conformance prior to the services being performed.
3. When providing maintenance upgrades, substitutions, and replacements to ICT, the contractor shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement. The agency reserves the right to request an Accessibility Conformance Report (ACR) for proposed substitutions and replacements prior to acceptance. The ACR should be created using the on the Voluntary Product Accessibility Template Version 2.2 508 (or later). The template can be located at https://www.itic.org/policy/accessibility/vpat
4. When developing or modifying ICT for the government, the contractor shall ensure the ICT fully conforms to the applicable Section 508 Standards. When modifying a commercially available or government-owned ICT, the contractor shall not reduce the original ICT Item’s level of Section 508 conformance.
5. When developing or modifying web and software ICT, the contractor shall demonstrate Section 508 conformance by providing Section 508 test results based on the versions of the DHS Trusted Tester Methodology currently approved for use, as defined at https://www.dhs.gov/compliance-test-processes. The contractor shall use testers who are certified by DHS on how to use the DHS Trusted Tester Methodology (e.g. “DHS Certified Trusted Testers”) to conduct accessibility testing. Information on how testers can become certified is located at https://www.dhs.gov/publication/trusted-tester- resources.
6. When developing or modifying ICT that are delivered in an electronic Microsoft Office or Adobe PDF format, the contractor shall demonstrate conformance by providing Section 508 test results based on the Accessible Electronic Documents – Community of Practice (AED COP) Harmonized Testing Guidance at https://www.dhs.gov/compliance- test-processes.
7. When developing or modifying software that generates electronic content (e.g., an authoring tool that is used to create html pages, reports, surveys, charts, dashboards, etc.), the contractor shall ensure software can be used to create electronic content that conforms to the Section 508 standards
8. Contractor personnel shall possess the knowledge, skills and abilities necessary to address the applicable revised Section 508 Standards for each ICT.
9. Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated January 29, 2016 and DHS Instruction http://www.itic.org/policy/accessibility/vpat http://www.itic.org/policy/accessibility/vpat http://www.dhs.gov/compliance-test-processes http://www.dhs.gov/compliance-test-processes http://www.dhs.gov/compliance-test-processes http://www.dhs.gov/publication/trusted-tester-http://www.dhs.gov/compliance-
139-05-001, Managing the Accessible Systems and Technology Program, dated January 11, 2017.
10. Where ICT conforming to one or more requirements in the Revised 508 Standards is not commercially available, the agency shall procure the ICT that best meets the Revised 508 Standards consistent with the agency’s business needs, in accordance with 36 CFR E202.7. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated January 29, 2016 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated January 11, 2017 and 36 CFR E202.6.
(End of clause)
INFORMATION ASSURANCE REQUIREMENTS FOR TSA GOVERNMENT
ACQUISITIONS
A. General Security Requirements
A.1. The Contractor shall comply with all Federal, Department of Homeland Security (DHS) and Transportation Security Administration (TSA) security and privacy guidelines in effect at the time of the award of the contract, including, but not limited to ‘DHS National Security Systems Policy Directive 4300B, version 10.1, November 21, 2018’ or current version. As well as those requirements that may be discretely added during the contract.
A.2. The Contractor shall perform periodic reviews to ensure compliance with all information security and privacy requirements.
A.3. The Contractor shall comply with all DHS and TSA security controls to ensure that the Government's security requirements are met. These controls are described in DHS PD 4300A and TSA MD 1400 series security policy documents and are based on the current National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 standards.
A.4. The Contractor shall include this guidance in all subcontracts at any tier where the subcontractor is performing the work defined in this statement of work (SOW).
A.5. The Contractor shall ensure all staff have the required level of security clearance commensurate with the sensitivity of the information being accessed, stored, processed, transmitted or otherwise handled by the System or required to perform the work stipulated by the contract. At a minimum, all Contractor staff shall be subjected to a Public Trust background check and be granted a Public Trust clearance before access to the System or other TSA resources is granted.
A.6. The Contractor shall sign a DHS Non-Disclosure Agreement (NDA) within (30) calendar days of the contract start date.
A.7. The Contractor shall not release, publish, or disclose agency information to unauthorized personnel, and shall protect such information in accordance with the provisions of the pertinent laws and regulations governing the confidentiality of sensitive information.
A.8. The Contractor shall ensure that its staff follow all policies and procedures governing physical, environmental, and information security described in the various TSA regulations pertaining thereto, and the specifications, directives, and manuals for conducting work to generate the products as required by this contract. Personnel shall be responsible for the physical security of their area and government furnished equipment (GFE) issued to the contractor under the terms of the contract.
A.9. The Contractor shall make all system information and documentation produced in support of the contract available to TSA upon request.
B. Training Requirements
B.1. All Contractor employees, requiring system access, shall receive initial Organizational Security Fundamentals Training within 60 days of assignment to the contract via the Online Learning Center (OLC). Refresher training shall be completed annually thereafter.
B.2. The Contractor shall complete annual online training for Organizational Security Fundamentals and TSA Privacy training.
B.3. Role Based training is required for contract employees with Significant Security Responsibility (SSR), whose job proficiency is required for overall network security within TSA, and shall be in accordance with DHS and TSA policy. The contractor will be notified if they have a position with significant security responsibility.
B.4. Individuals with SSR shall have a documented individual training and education plan, which shall ensure currency with position skills requirements, with the first course to be accomplished within 90 days of employment or change of position. The individual training plan shall be refreshed annually or immediately after a change in the individual’s position description requirements.
B.5. Information Security and Privacy training supplied by the Contractor shall meet standards established by NIST and set forth in DHS and TSA security policy.
B.6. The Contractor shall maintain a list of all employees who have completed training and shall submit this list to the contracting officer representative (COR) upon request, or during DHS/TSA onsite validation visits performed on a periodic basis.
B.7. The contractor shall its employees review and sign the TSA Form 1403 Computer and Wireless Mobile Device Access Agreement (CAA) prior to accessing IT systems.
C. Configuration Management (hardware/software) C.1. Hardware or software configuration changes shall be in accordance with the DHS Information Security Performance Plan (current year and any updates thereafter), the DHS Continuous Diagnostics and Mitigation (CDM) Program to include dashboard reporting requirements and TSA’s Configuration Management policy. The TSA Chief Information Security Officer (CISO)/Information Assurance and Cyber Security Division (IAD) shall be informed of and involved in all configuration changes to the TSA IT environment including systems, software, infrastructure architecture, infrastructure assets, and end user assets. The TSA IAD POC shall approve any request for change prior to any development activity occurring for that change and shall define the security requirements for the requested change.
The COR will provide access to the DHS Information Security Performance Plan.
https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx
C.2. The Contractor shall ensure all application or configuration patches and/or Requests for Change (RFC) have approval by the Technical Discussion Forum (TDF), Systems Configuration Control Board (SCCB) and lab regression testing prior to controlled change release under the security policy document, TSA Management Directive (MD) 1400.3 Information Technology Security and TSA Information Assurance (IA) Handbook, unless immediate risk requires immediate intervention. Approval for immediate intervention (emergency change) requires approval of the TSA CISO, SCCB co-chairs, and the appropriate Operations Manager, at a minimum.
C.3. The Contractor shall ensure all sites impacted by patching are compliant within 14 days of change approval and release.
C.4. The acquisition of commercial-off-the-shelf (COTS) Information Assurance (IA) and IA-enabled IT products (to be used on systems entering, processing, storing, displaying, or transmitting “sensitive information”) shall be limited to those products that have been evaluated and validated, as appropriate, in accordance with the following:
• The NIST FIPS validation program.
• The National Security Agency (NSA)/NIST, National Information Assurance
Partnership (NIAP) Evaluation and Validation Program.
• The International Common Criteria for Information Security Technology
Evaluation Mutual Recognition Agreement.
C.5. US Government Configuration Baseline and DHS Configuration Guidance
i. The provider of information technology shall certify applications are fully functional and operate correctly as intended on systems using the US Government Configuration Baseline (USGCB) and in accordance with DHS and TSA guidance.
1. USGCB Guidelines:
a. http://usgcb.nist.gov/usgcb_content.html
2. DHS Sensitive Systems Configuration Guidance
a. http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx
ii. The standard installation, operation, maintenance, updates and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. The information technology shall also use the Windows Installer Service for installation to the default “program files” directory and shall be able to discretely install and uninstall.
iii. Applications designed for general end users shall run in the general user context without elevated system administration privileges.
C.6. The Contractor shall establish processes and procedures for continuous monitoring of Contractor systems that contain TSA data/information by ensuring all such devices are monitored by, and report to, the TSA Security Operations Center (SOC). The Contractor shall perform monthly security scans on servers that contain TSA data, and shall send monthly scan results to the TSA IAD.
D. Risk Management Framework
This section is not applicable if contract has DHS Sensitive Information Required Special Contract Terms (MARCH 2015), SAFEGUARDING OF SENSITIVE INFORMATION
(MAR 2015)
http://usgcb.nist.gov/usgcb_content.html http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx
D.1. The Security Authorization and Ongoing Authorization Process in accordance with NIST SP 800-37 and SP 800-137 (current versions) is a requirement for all TSA IT systems, including General Support Systems (e.g., standard TSA desktop, general network infrastructure, electronic mail), major applications and development systems (if connected to the operational network or processing, storing, or transmitting government data). These processes are documented in the NIST Risk Management Framework (RMF). Ongoing Authorization is part of Step 6 “Monitoring” of the RMF. All NIST guidance is publicly available; TSA and DHS security policy is disclosed upon contract award with some exceptions, which are public facing (i.e., DHS Security and Training Requirements for Contractors).
D.2. A written Authorization to Operate (ATO) granted by the TSA Authorizing Official (AO) also known as TSA Chief Information Security Officer (CISO) is required prior to processing operational data or connecting to any TSA network. The contractor shall provide all necessary system information for the security authorization effort.
D.3. TSA shall assign a security category to each IT system compliant with the requirements of Federal Information Processing Standards (FIPS) Pub 199 Standards for Security Categorization of Federal Information and Information Systems impact levels and assign security controls to those systems consistent with FIPS Pub 200 Minimum Security Requirements for Federal Information and Information Systems methodology.
D.4. Unless the AO specifically states otherwise for an individual system, the duration of any Accreditation shall be dependent on the FIPS 199 rating and overall residual risk of the system; the length can span up to 36 months.
D.5. The Security Authorization (SA)Package contains documentation required for Security Authorizations and Ongoing Authorization. The package shall contain the following security documentation: 1) Security Assessment Report (SAR), 2) Security Plan (SP) or System Security Authorization Agreement (SSAA), 3) Contingency Plan, 4) Contingency Plan Test Results, 5) Federal Information Processing Standards (FIPS) 199 Security Categorization, 6) Privacy Threshold Analysis (PTA), 7) E-Authentication, 8) Security Assessment Plan (SAP),
9) Authorization to Operate (ATO) Letter, 10) Plan of Action and Milestones (POA&M), and
11) Ongoing Authorization Artifacts as required by the DHS Ongoing Authorization Methodology (current version). The SA package shall document the specific procedures, training, and accountability measures in place for systems that process personally identifiable information (PII). All security compliance documents shall be reviewed and approved by the CISO and the IAD, and accepted by the CO upon creation and after any subsequent changes, before they go into effect. Ongoing Authorization artifacts include monthly TRigger Accountability Log (TRAL), monthly operating system scan results, application scans as directed, updated control allocation table (CAT), and associated memos as directed. All steps in the DHS Information Assurance Compliance Systems (IACS) shall be completed correctly, thoroughly and in a timely manner for all steps of the RMF.
D.6. The contractor shall support the successful remediation of all identified system weaknesses and vulnerabilities that are identified as a result of the aforementioned security review process.
D.7. The contractor shall submit and analyze monthly operating system vulnerability scans for the DHS Information Security Performance Plan FISMA Scorecard. Vulnerabilities not remediated are generated into Plan of Action and Milestone (POA&M)s after 30 days.
https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors
E. Contingency Planning
This section is not applicable if contract has DHS Sensitive Information Required Special Contract Terms (MARCH 2015), SAFEGUARDING OF SENSITIVE INFORMATION
(MAR 2015)
E.1. The Contractor shall develop and maintain a Contingency Plan (CP), to include a Continuity of Operation Plan (COOP), to address circumstances whereby normal operations may be disrupted and thus require activation of the CP and/or COOP. are disrupted. The contractor’s CP/COOP responsibility relates only to the system they provide or operate under contract.
E.2. The Contractor shall ensure that contingency plans are consistent with template provided in the DHS IACS Tool. If access has not been provided initially, the contractor shall use the DHS 4300A Sensitive System Handbook, Attachment K IT Contingency Plan Template.
E.3. The Contractor shall identify and train all TSA personnel involved with COOP efforts in the procedures and logistics of the disaster recovery and business continuity plans.
E.4. The Contractor shall ensure the availability of critical resources and facilitate the COOP in an emergency situation.
E.5. The Contractor shall test their CP annually and retain records of the annual CP testing for review during periodic audits.
E.6. The Contractor shall record, track, and correct any CP deficiency; any deficiency correction that cannot be accomplished within one month of the annual test shall be elevated to
IAD.
E.7. The Contractor shall ensure the CP addresses emergency response, backup operations, and recovery operations.
E.8. The Contractor shall have an Emergency Response Plan that includes procedures appropriate to fire, flood, civil disorder, disaster, bomb threat, or any other incident or activity that may endanger lives, property, or the capability to perform essential functions.
E.9. The Contractor shall have a Backup Operations Plan that includes procedures and responsibilities to ensure that essential operations can be continued if normal processing or data communications are interrupted for any reason.
E.10. The Contractor shall have a Post-Disaster Recovery Plan that includes procedures and responsibilities to facilitate rapid restoration of normal operations at the primary site or, if necessary, at a new facility following the destruction, major damage, or other major interruption at the primary site.
E.11. The Contractor shall ensure all TSA data (e.g., mail, data servers, etc.) is incrementally backed up on a daily basis.
E.12. The Contractor shall ensure a full backup of all network data occurs as required by the system’s availability security categorization impact rating per TSA Information Assurance policy.
E.13. The Contractor shall ensure all network application assets (e.g., application servers, domain controllers, Information Assurance (IA) tools, etc.) shall be incrementally backed up as required to eliminate loss of critical audit data and allow for restoration and resumption of normal operations within one hour.
E.14. The Contractor shall ensure sufficient backup data to facilitate a full operational recovery within one business day at either the prime operational site or the designated alternate site shall be stored at a secondary location determined by the local element disaster recovery plan.
E.15. The Contractor shall ensure that data at the secondary location is current as required by the system’s availability security categorization impact rating.
E.16. The Contractor shall ensure the location of the local backup repository and the secondary backup repository is clearly defined, and access controlled as an Information Security Restricted Area (ISRA).
E.17. The Contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1:
Network and System Infrastructure for the layout of the file systems, or partitions, on a system’s hard disk impacting the security of the data on the resultant system. File system design shall:
• Separate generalized data from operating system (OS) files
• Compartmentalize differing data types
• Restrict dynamic, growing log files or audit trails from crowding other data
E.18. The contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1:
Network and System Infrastructure for the management of mixed data for OS files, user accounts, externally-accesses data files and audit logs.
F. Program Performance F.1. The Contractor shall comply with requests to be audited and provide responses within three business days to requests for data, information, and analysis from the TSA IAD and management, as directed by the Contracting Officer (CO).
F.2. The Contractor shall provide support during the IAD audit activities and efforts. These audit activities shall include, but are not limited to the following: requests for system access for penetration testing, vulnerability scanning, incident response and forensic review.
F.3. Upon completion of monthly security scans, findings shall be documented and categorized as High, Moderate, or Low based on their potential impact to the System IT Security posture. The Contractor shall provide TSA with estimates of the total engineering service hours required to support the remediation of open POA&M items. High security findings shall be remediated first in 45 days or less; Moderate security findings shall be remediated in 60 days or less, and Low security findings shall be remediated in 90 days or less.
The Contractor shall work with the TSA System ISSO and the respective CO and/or Contracting Officer’s Representative (COR), as well as OIT IAD and the System Owner (as required) to prioritize and plan for the remediation of open POA&Ms. The TSA System ISSO shall maintain all security artifacts and perform Ongoing Authorization (per NIST 800-137 and DHS-TSA requirements) and Continuous Diagnostics and Mitigation (CDM) (per OMB M-14-
03) activities to ensure active compliance with security requirements. Specific POA&M guidance and information can be found in the SOP 1401 Plan of Action and Milestone (POA&M) Process, as well as the DHS 4300A PD Attachment H Plan of Action and Milestones (POA&M) Process Guide.
G. Federal Risk and Authorization Management Program (FedRAMP)
If a vendor is to host a system with a Cloud Service Provider, the following shall apply:
G.1. FedRAMP Requirements: Private sector solutions shall be hosted by a Joint
Authorization Board (JAB)-approved Infrastructure as a Service (IaaS) Cloud Service Provider (CSP) (http://cloud.cio.gov/fedramp/cloud-systems) and shall follow the Federal Risk and Authorization Management Program (FedRAMP) requirements. The CSP shall adhere to the following in addition to the FedRAMP requirements:
o Identity and entitlement access management shall be done through Federated Identity;
o SSI and PII shall be encrypted in storage and in transit as it is dispersed across the cloud;
o Sanitization of all TSA data shall be done as necessary at the IaaS, PaaS or SaaS levels;
o Cloud bursting shall not occur;
o TSA data shall be logically separated from other cloud tenants;
o All system administrators shall be properly cleared and vetted U.S. citizens;
o TSA data shall not leave the United States; and o The cloud internet connection shall be behind a commercial Trusted Internet
Connection (TIC) that has EINSTEIN 3 Accelerated (E3A) capabilities deployed. These include but are not limited to the analysis of network flow records, detecting and alerting to known or suspected cyber threats, intrusion prevention capabilities and under the direction of DHS detecting and blocking known or suspected cyber threats using indicators. The E3A capability shall use the Domain Name Server Sinkholing capability and email filtering capability allowing scans to occur destined for .gov networks for malicious attachments, Uniform Resource Locators and other forms of malware before being delivered to .gov end-users.
G.2. Private Sector System Requirements: TSA shall conduct audits at any time on private sector systems, and the system shall be entered into the TSA FISMA Inventory as a system of record using the Control Implementation Summary (CIS) provided by the Cloud Service Provider. Security artifacts shall be created and maintained in the DHS IACS. The private sector systems are required to go through the Security Authorization Process and the RMF in accordance the Federal Information Systems Management Act (FISMA) and NIST SP 800-37 Rev. 1. The cloud internet connection shall be behind a commercial Trusted Internet Connection (TIC) that has E3A deployed. Security event logs and application logs shall be sent to the TSA SOC. Incidents as defined in the TSA Management Directive 1400.3 and its Attachment 1 (TSA IA Handbook) shall be reported to the TSA SPOC 1-800-253- 8571. DHS Information Security Vulnerability Management Alerts and Bulletins shall be patched within the required time frames as dictated by DHS and communicated by the contracting officer representative (COR) or contract security point of contact
(POC).
H. Information Assurance Policy H.1. All services, hardware and/or software provided under this task order shall be compliant with applicable DHS 4300A Sensitive System Policy Directive, DHS 4300A Sensitive Systems Handbook, TSA MD 1400.3 Information Technology Security, TSA IA Handbook, Technical Standards (TSs) and standard operating procedures (SOPs).
H.2. The contractor solution shall follow all current versions of TSA and DHS policies, procedures, guidelines, and standards, which shall be provided by the Contracting Officer.
http://cloud.cio.gov/fedramp/cloud-systems
H.3. Authorized access and use of TSA IT systems and resources shall be in accordance with the TSA IA Handbook.
H.4. The contractor shall complete TSA Form 251 and TSA Form 251-1 for sensitive or accountable property. The contractor shall email the completed forms to TSA- Property@dhs.gov and include a hard copy with the shipment.
I. Data Stored/Processed at Contractor Site I.1. Unless otherwise directed by TSA, any storage of data shall be contained within the resources allocated by the Contractor to support TSA and may not be on systems that are shared with other commercial or government clients.
J. Remote Access J.1. The Contractor remote access connection to TSA networks shall be considered a privileged arrangement for both Contractor and the Government to conduct sanctioned TSA business. Therefore, remote access rights shall be expressly granted, in writing, by the TSA
IAD.
J.2. The Contractor employee(s) remote access connection to TSA networks shall be terminated immediately for unauthorized use, at the sole discretion of TSA.
J.3. The Contractor shall use his or her federal issued personal identifiable verification (PIV) badge to access TSA resources to include IT applications and physical facility.
K. Interconnection Security Agreement
If the service being supplied requires a connection to a non-DHS, Contractor system, or DHS system of different sensitivity, the following shall apply:
K.1. Interconnections between DHS and non-DHS IT systems shall be established only through controlled interfaces and via approved service providers. The controlled interfaces shall be accredited at the highest security level of information on the network. Connections with other Federal agencies shall be documented using an interagency agreement;
memoranda of understanding/agreement, service level agreements or interconnection service agreements.
K.2. ISAs shall be reissued every three (3) years or whenever any significant changes have been made to any of the interconnected systems.
K.3. ISAs shall be reviewed and updated as needed as a part of the annual FISMA self-assessment.
L. SBU Data Privacy and Protection
This section is not applicable if contract has DHS Sensitive Information Required Special Contract Terms (MARCH 2015), SAFEGUARDING OF SENSITIVE INFORMATION
(MAR 2015)
mailto:TSA-Property@dhs.gov mailto:TSA-Property@dhs.gov
L.1. The contractor shall satisfy requirements to work with and safeguard Sensitive Security Information (SSI), Personally Identifiable Information (PII) and Sensitive Personally Identifiable Information (Sensitive PII). All support personnel shall understand and rigorously follow DHS and TSA requirements, SSI Policies and Procedures Handbook, and Privacy policies, and procedures for safeguarding SSI, PII and SPII.
L.2. The Contractor shall be responsible for the security of: i) all data that is generated by the contractor on behalf of the TSA, ii) TSA data transmitted by the contractor, and iii) TSA data otherwise stored or processed by the contractor regardless of who owns or controls the underlying systems while that data is under the contractor’s control. All TSA data, including but not limited to PII, SPII, Sensitive Security Information (SSI), Sensitive But Unclassified (SBU), and Critical Infrastructure Information (CII), shall be protected according to DHS and TSA security policies and mandates.
L.3. TSA shall identify IT systems transmitting unclassified/SSI information that shall require protection based on a risk assessment. If encryption is required, the following methods are acceptable for encrypting sensitive information:
1. FIPS 197 (Advanced Encryption Standard (AES)) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2 (current version)
2. National Security Agency (NSA) Type 2 or Type 1 encryption (current version)
3. Public Key Infrastructure (PKI) (see paragraph 5.5.2.1 of the DHS 4300A Sensitive Systems Handbook), current version L.4. The contractor shall maintain data control according to the TSA security level of the data. Data separation shall include the use of discretionary access control methods, VPN encryption methods, data aggregation controls, data tagging, media marking, backup actions, and data disaster planning and recovery. Contractors handling PII shall comply with TSA MD 3700.4, Handling Sensitive Personally Identifiable Information (current version).
L.5. Users of TSA IT assets shall adhere to all system security requirements to ensure the confidentiality, integrity, availability, and non-repudiation of information under their control.
All users accessing TSA IT assets are expected to actively apply the practices specified in the TSA IA Handbook, and applicable IT Security Technical Standards and SOPs.
L.6. The contractor shall comply with Sensitive Personally Identifiable Information (Sensitive PII) disposition requirements stated in the TSA IA Handbook, applicable Technical Standards, SOPs and TSA MD 3700.4, Handling Sensitive Personally Identifiable Information.
L.7. The Contractor shall ensure that source code is protected from unauthorized access or dissemination (see TSA IA Handbook).
L.8. H.5200.224.004 SECURITY REQUIREMENTS FOR HANDLING PERSONALLY
IDENTIFIABLE INFORMATION AND PRIVACY INCIDENT REPONSE (JULY 2017)
a. Definitions
i. “Breach” (may be used interchangeably with “Privacy Incident’) as used in this clause means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to Personally Identifiable Information, in usable form whether physical or electronic
ii. “Personally Identifiable Information (PII)” as used in this clause means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States. Examples of PII include: name, date of birth, mailing address, telephone number, Social Security Number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), Internet protocol addresses, biometric identifiers (e.g., fingerprints), photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
iii. “Sensitive Personally Identifiable Information (Sensitive PII)” as used in this clause is a subset of Personally Identifiable Information, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Complete social security numbers (SSN), alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered Sensitive PII even if they are not coupled with additional PII. Additional examples include any groupings of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
(1) Driver’s license number, passport number, or truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Financial information such as account numbers or Electronic Funds Transfer Information
(5) Medical Information
(6) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) Other Personally Identifiable information may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains Personally Identifiable Information but it is not sensitive.
b. Systems Access. Work to be performed under this contract requires the handling of
Sensitive PII. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The contractor shall provide the Government access to, and information regarding the contractor’s systems, when requested by the Government, as part of its responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the Government in assuring compliance with such requirements. Government access shall include independent validation testing of controls, system penetration testing by the Government, Federal Information Security Management Act (FISMA) data reviews, and access by agency Inspectors General for its reviews.
c. Systems Security.
i. In performing its duties related to management, operation, and/or access of systems containing Sensitive PII under this contract, the contractor, its employees and subcontractors shall comply with applicable security requirements described in the most current versions of DHS Sensitive System Publication 4300A or any replacement publication and rules of conduct as described in TSA Management Directive (MD) 3700.4.
ii. All Contractor-operated systems that input, store, process, output, and/or transmit SPII shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
iii. Use of contractor-owned laptops or other media storage devices to process or store PII is prohibited under this contract until the contractor provides, and the contracting officer in coordination with CISO approves, written certification by the contractor that the following requirements are met:
1. Laptops employ encryption using a NIST Federal Information Processing Standard (FIPS) 140-2 or successor approved product;
2. The contractor has developed and implemented a process to ensure that security and other applications software are kept current;
3. Mobile computing devices utilize anti-viral software and a host-based firewall mechanism;
4. When no longer needed, all removable media and laptop hard drives shall be processed (i.e., sanitized, degaussed, or destroyed) in accordance with DHS security requirements.
5. The contractor shall maintain an accurate inventory of devices used in the performance of this contract;
6. Contractor employee training requirements are covered in FAR 52.224-3.
7. All Sensitive PII obtained under this contract shall be removed from contractor-owned information technology assets upon termination or expiration of contractor work. Removal must be accomplished in accordance with DHS Sensitive System Publication 4300A, which the contracting officer will provide upon request. Certification of data removal will be performed by the contractor’s Project Manager and written notification confirming certification will be delivered to the contracting officer within 15 days of termination/expiration of contractor work.
d. Data Security.
i. Contractor shall limit access to the data covered by this clause to those employees and subcontractors who require the information in order to perform their official duties under this contract.
ii. The contractor, contractor employees, and subcontractors must physically secure Sensitive PII when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss. When Sensitive PII is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed through means that will make the Sensitive PII irretrievable. The contractor shall only use Sensitive PII obtained under this contract for purposes of the contract, and shall not collect or use such information for any other purpose without the prior written approval of the contracting officer. At expiration or termination of this contract, the contractor shall turn over all Sensitive PII obtained under the contract that is in its possession to the Government.
iii. The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain Sensitive PII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
e. Breach Response. The contractor agrees that in the event of any actual or suspected breach of SPII (i.e., loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic), it shall immediately, and in no event later than one hour of discovery, report the breach to the Contracting Officer, the Contracting Officer’s Representative (COR), and the TSA Director of Privacy Policy & Compliance (TSAprivacy@dhs.gov<mailto:TSAprivacy@tsa.dhs.gov>). The contractor is responsible for positively verifying that notification is received and acknowledged by at least one of the foregoing Government parties. The report of a breach shall not, by itself, be interpreted as evidence that the contractor failed to provide adequate safeguards for SPII.
Award fee contracts:
i. For any portions of this contract that involve an award fee, the contractor may be awarded no award fee for any evaluation period in which there is a breach of privacy or security, including any loss of sensitive data or equipment containing sensitive data. Lost award fee due to a breach of privacy or security may not be allocated to future evaluation periods.
ii. For any portions of this contract that involve an award fee, to ensure that the final award fee evaluation at contract completion reflects any breach of privacy or security in an interim period, the overall award fee pool shall be reduced by the amount of the fee available for the period in which the breach occurred if a zero fee determination was made because of a breach of privacy or security.
f. Personally Identifiable Information Notification Requirement.
i. The contractor shall have in place procedures and the capability to promptly notify any individual whose Sensitive PII was, or is reasonably believed to have been, breached, as determined appropriate by the Government.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .