Att 1 PWS.pdf
PDF 166 KB Posted
- Attached to
- Shredding Services Federal contract opportunity
- Solicitation number
- HQ042323Q0002
- Issued by
- Defense Finance and Accounting Service
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Synopsis Solicitation - Amd 1.pdf | ||
| RFQ Questions and Responses.pdf | ||
| Att 5 Past Performance Info Sheet.docx | DOCX document | |
| Att 4 Wage Determination - Franklin Cty.pdf | ||
| Synopsis Solicitation.pdf | ||
| Att 3 Clause Fill-Ins.docx | DOCX document | |
| Att 2 Pricing Worksheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement Defense Finance and Accounting Service Columbus, OH
Shredding and Destruction Services
1.0 INTRODUCTION: The purpose of this requirement is to provide the Defense Finance and
Accounting Service, Columbus, OH (DFAS-CO) with contractor services for collection, shredding/destruction and disposal of sensitive Government papers/materials while maintaining confidentiality to protect from identity theft, in accordance with the following Federal Laws and Regulations:
The Privacy Act of 1974 The Gramm-Leach-Bliley Act of 1999 The Data Protection Act of 1998 DFAS Regulation 5200.1-R (Information Security) DFAS Regulation 5205.1 (Operations Security)
2.0 SCOPE: The contractor shall provide all personnel, equipment, tools, materials, supervision, and other items and services necessary to perform all services identified herein from the following DFAS Facilities/Sites:
Defense Finance & Accounting Service – Columbus Center Building 21 3990 E. Broad Street Columbus, OH 43213-1152 DoDAAC: HQ0363
A loading area and designated shredding area shall be utilized by the Contractor and shall be made available at DFAS-CO. The bins will be collected by onsite personnel and staged/placed at the loading area prior to the contractor’s arrival.
Equipment provided by the contractor shall include forty (40) lockable 64-gallon collection bins with metal locks and hinges on all containers, which shall be left on site in their designated areas throughout the entire period of performance. A master key for the shred bin locks shall be provided to the Contracting Officer Representative (COR) for internal use.
2.1 Period of Performance: The period of performance is estimated to be a one-year base period and four one-year option periods
3.0 GENERAL REQUIREMENTS: The Contractor shall provide services for the collection of paper and other materials for shredding, destruction, and disposal.
3.1 Materials to be shredded or destroyed: Materials to be shredded or destroyed include but are not limited to photo impressions, computer tape, printouts, carbon paper, carbon typewriter ribbons, notes, envelops, work papers, staples, clips, or any other material containing names, addresses, SSN, credit information, and any confidential information which has served its purpose.
3.2 Shredding: Shredding shall produce residue partial sized not exceeding 5/8 inch cross cut shred in width or smaller strips of all paper grades (un-separated) for shredding. This includes staples, clips, bindings and folders. The contractor shall provide for the convenient, safe and secure destruction of a variety of media which may include but not be limited to paper, photo impressions, computer tape, printouts, carbon paper, carbon typewriter ribbons, notes, envelops, work papers, staples, clips, or any other material containing names, addresses, SSN, credit information, and any confidential information which has served its purpose.
Only appropriately cleared employees of the contractor shall shred/destroy material. These individuals shall have a full understanding of their responsibilities.
After specified destruction is accomplished, shredded material shall be transported and properly disposed in accordance with all applicable local, state, and federal laws and regulations. All fees associated with disposal shall be paid by the Contractor.
3.3 Collection Requirements: The Contractor shall provide on-site shredding services to handle a variety of unclassified materials. The contractor shall shred and dispose of paper/material awaiting removal. All problem/issues regarding paper/material collection, shredding or disposal shall be reported to the COR.
Shredding shall be performed as scheduled during periods of inclement weather unless specific approval to delay collections is requested by the Contractor and approved by the COR. Such approval will normally be granted only in cases of particularly severe weather, such snow storms or tornados, etc.
When approval to reschedule collections is granted, the contractor shall accomplish all missed collections within 24 hours after the severe weather has terminated, at no additional cost to the Government.
The contractor shall be responsible for cleaning up any spillage of paper/material that occurs as a result of the contractor’s actions during the shredding process. The contractor shall consider all material designated for destruction under this order as proprietary to DFAS and shall safeguard all material designated for removal and destruction until such time as destruction of material is certified as complete.
3.4 Transportation of Material: Vehicles used for collection by the contractor shall have watertight bodies which do not permit loss of paper/material. Open-box trucks, with or without canvas cover, shall not be used. Collection vehicles shall be operated in accordance with activity rules and regulations while in the activity area, and shall be kept closed when moving or when not actually engaged in shredding paper/material.
4.0 SERVICE SCHEDULE: The contractor shall pick-up paper/materials every four weeks on the days mutually agreed upon by the COR and Contractor. The estimated quantity is 40 bins. The time of destruction is to be completed between the hours of 9:00 a.m. and 3:00 p.m., unless an adjusted time period is mutually agreed upon by the COR.
Frequency and quantity are estimates and may increase or decrease based upon mission requirements.
Either party may request a change in frequency or quantity. This request shall be made in writing. The receiving party shall respond to the request within five business days. Upon mutual agreement of both parties, a contract modification may be issued if necessary.
5.0 DELIVERABLES
5.1 Disposal Permits: Within 7 calendar days after contract award, the Contractor shall submit copies of disposal permits or other written documentation of approval and suitability of landfill or other final disposal methods.
5.2 Certificate of Destruction: No later than 24 hours after shredding, a signed certificate for shredding/destruction shall be issued upon completion of each job. The certificate shall be submitted to the COR and indicate the date of shredding/destruction, identify the material destroyed, method of destruction, number of pounds/bins shredded and disposed and shall be signed by the individuals (contractor and Government) designated to destroy and witness the shredding. Destruction officials shall be required to know, through their personal knowledge, that such material was shredded/destroyed.
6.0 PRIVACY ACT REQUIREMENTS: In accordance with Security and Privacy Act Requirements, all work performed relative to the tasking identified in the PWS are unclassified or carry a Privacy Act Classification. System security shall be in accordance with DoD Directive 8500.1, Security Requirements for AIS. The contractor shall meet all Government security requirements and be agreeable to site inspections. After paper/material has been shredded/destroyed and disposed of by the contractor as specified herein, there are no further restrictions on the material. All persons, their vehicles and other property entering, leaving and while within the confines of Government property are be subject to searches and inspections.
7.0 SECURITY INVESTIGATION REQUIREMENTS: In accordance with Security Investigation Requirements, no classified work will be required. However, the contractor will be working with sensitive information which is covered by the Privacy Act and category ADP/IT II. Contractor shall ensure sensitive (privacy act) information is properly safeguarded at the work site and not removed from the work site. Also, the contractor shall be required to comply with security requirements associated with access to the DFAS enterprise network.
8.0 CONTRACTING OFFICER REPRESENTATIVE (COR): The COR will act as the on-site and off-site technical point of the contract for the Government. The COR will initiate request and monitor performance. The COR’s authority is limited to technical issues and he/she is not authorized to make contractual decisions. The authority to resolve monetary issues and contractual interpretation is the responsibility of the Contracting Officer.
9.0 SECURITY REQUIREMENTS:
Personnel Security Investigation (PSI) Requirements. Contractor personnel working on this contract will require a favorably adjudicated Tier 3, or equivalent Noncritical Sensitive (formerly IT-II) level or higher investigation. No access to classified information is required. IAW standard DFAS Personnel Security policy, ALL incoming contractors, regardless of whether they possess a favorably adjudicated Noncritical Sensitive (formerly IT-II) or higher investigation, must submit a Declaration for Federal Employment (OF-306), and a new set of fingerprints* to the COR, who will submit these forms with a Contractor Request for Investigation (CRI) (DFAS Form 9035) to DFAS Personnel Security. DFAS Personnel Security will review all submitted documentation to validate whether contractor personnel meet personnel security requirements to perform work on the contract or if a new background investigation is required.
*New fingerprints are not required if any of the following apply:
The person has been fingerprinted for the Office of Personnel Management (OPM) within the past 120 days;
The person is currently undergoing a background investigation, or reinvestigation, by OPM or any other Federal agency;
The person has a background investigation currently being adjudicated by the Department of Defense Consolidated Adjudications Facility (DoD-CAF) or another CAF;
The person has been favorably adjudicated within the past 30 days by the DoD CAF or a CAF from any other Federal agency; or The person is coming directly from another DoD agency, with no break in service. This includes any of the military branches as well as the U.S. Coast Guard; however, service members in an inactive reserve status are not included.
The Personnel Security Office otherwise determines that no new fingerprints are required.
Security Requirements. Contractor personnel shall follow the security and training requirements in DFAS 2000.1-I, “Force Protection Mission,” DoDM 5200.01, Volumes 1-3, “DoD Information Security Program,” DoDI, 5200.48, “Controlled Unclassified Information,” DFAS 5200.1-I, “Information Security Program,” DFAS 5200.8-I, “Physical Security Program,” and DFAS 5200.10, “Insider Threat Program.”
Contractor personnel shall follow all host security requirements in accordance with DoD 5220.22-M, paragraph 6-105. The contractor shall immediately report any occurrences of violation of stated regulations to the Contracting Officer (CO), Contracting Officer Representative (COR) and the Personnel Security Office. (Paragraph has been stricken as unnecessary or redundant).
DFAS Personnel Security Incident Reporting Requirements, the National Industrial Security Program and Due Process as it Relates to DFAS Contractor Personnel. The National Industrial Security Program (NISP) is a partnership between the federal government and private industry to safeguard classified information.
Executive Order 12829, as amended, "National Industrial Security Program", further amended by Section 6 of E.O. 13691, was established to achieve cost savings and to ensure that industry safeguards the classified information with which it is entrusted while performing work on contracts, programs, bids, or research and development efforts while working for United States Government.
It is important to note that personnel employed as contractors for DFAS are not covered under the National Industrial Security Program (NISP) and are exempt from the provisions of 5 C.F.R. 731. This means that DFAS contractor personnel involved in an incident that potentially violates one or more of the National Security Adjudicative Guidelines found at https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-Adjudicative-Guidelines-U.pdf, are not entitled to Due Process rights normally afforded to federal civilian employees and those personnel covered under NISP; more specifically, Personnel Security may suspend or revoke their access to DFAS IT systems, sensitive information and/or DFAS facilities.
Incident Reporting Requirements.
Whenever a DFAS contractor displays conduct, or is involved in any incident, which is in violation of any of the thirteen National Security Adjudicative Guidelines*, a report shall be made immediately following the incident, or as soon as practicable thereafter, to their DFAS civilian supervisor and the supervisor, if there is one, of the area to which they are assigned, the COR, and in all cases, the Personnel Security Office. Reporting to Personnel Security may be made by phone to (317) 212-7888, by email to dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil, or, in the case of personnel physically located at
DFAS Indianapolis Center, in person to the Personnel Security Office located on the third floor center hallway at Column 320T.
All incidents will be investigated by Personnel Security and, depending on the date of the subject’s most recent investigation, may need to have an updated background investigation initiated. Those that do not require a new investigation will have all relevant information regarding the incident forwarded to the Department of Defense, Consolidated Adjudications Facility (DoD-CAF) for review and re-adjudication.
*The thirteen National Security Adjudicative Guidelines are:
1. GUIDELINE A: Allegiance to the United States;
2. GUIDELINE B: Foreign Influence
3. GUIDELINE C: Foreign Preference
4. GUIDELINE D: Sexual Behavior
5. GUIDELINE E: Personal Conduct
6. GUIDELINE F: Financial Considerations
7. GUIDELINE G: Alcohol Consumption
8. GUIDELINE H: Drug Involvement and Substance Misuse
9. GUIDELINE I: Psychological Conditions
10. GUIDELINE J: Criminal Conduct
11. GUIDELINE K: Handling Protected Information
12. GUIDELINE L: Outside Activities
13. GUIDELINE M: Use of Information Technology
Some Examples of Incidents That Require Reporting to Personnel Security:
a. An arrest for any criminal offense, not including minor traffic violations, by any law enforcement agency. This does include the traffic offenses of Driving Under the Influence of Alcohol or Drugs, and Reckless Driving;
b. Violation of any court order;
c. Delinquencies on any debt for 180 days or longer;
d. Federal, State or Local tax issues or delinquencies;*
e. Delinquencies on any Federal debt;*
f. Child Support delinquencies;
g. Filing for Chapter 7 or Chapter 13 bankruptcy in any Federal Bankruptcy Court;
h. Civil judgements;
i. Having a close personal friendship with a Foreign National (person from a foreign country) with regularly occurring contact;
j. Being approached by a person know to be, or suspected to be, working as an agent of a foreign government or terrorist organization, or any other person, who seeks any information about DFAS, the Department of Defense, or the U.S. Government, especially if the person offers money or something of value to the contractor employee; and
k. Ownership of property or financial accounts in a foreign country.
It should be noted that persons delinquent on Federal debt of any kind may not obtain or maintain favorable personnel security adjudication be considered for a contractor position with DFAS unless they can provide documentary proof that a payment plan has been established with the government agency to whom the debt is owed, and that regularly recurring payments are being made. Contractor personnel who cannot obtain and maintain a favorable personnel security adjudication may not have access to the government data, facility, and equipment required under the contract.
NOTE: This list does not cover every potential incident or offense; any incident in which a contractor is involved and a question exists as to whether it should be reported, should report the incident to Personnel
Security, who will then determine if further action is warranted. Failure to report an incident is, in and of itself, an incident involving personal conduct, and may, in some cases, be more serious than the original incident.
Foreign Travel by DFAS Contractor Personnel Official and Unofficial (Personal) Travel: Official U.S. Government Business: persons employed as contractor employees with DFAS, to include those with Noncritical Sensitive (formerly IT-II) access, Critical Sensitive (formerly IT-I) access, access to critical program information (related to Research, Development, Test, and Evaluation), sensitive compartmented information, and/or special access program information, in accordance with DoD Directive 5240.06, are required to complete a DFAS Form 9133, Notification of OCONUS Travel, not less than fourteen (14) calendar days prior to the scheduled travel. One copy shall be sent the DFAS Personnel Security group box at dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil and one copy shall be turned into the Site Security/Force Protection Office of the DFAS site where they are stationed.
Upon receipt of the completed Form 9133, the Site Security/Force Protection Office will contact the contractor employee and schedule a Foreign Travel briefing. Immediately prior to travel, contractor employees will check with the State Department at https://travel.state.gov/content/travel/en/traveladvisories/traveladvisories.html.html for any travel advisories for the country or region being traveled to and take the appropriate steps to ensure their safety for any location covered by a travel advisory or warning.
Security Education and Training. Contractor personnel shall receive initial, continuous and refresher security education training in accordance with DFAS 2000.1-I, DoDM 5200.01, Volume 3, “DoD Information Security Program – Protection of Classified Information,” DoDI 5200.48, and DFAS 5200.1- I. Contractor personnel shall also complete all required contractor training requirements identified in this Statement of Work.
Access To, Accountability For, and Safeguarding Of Controlled Unclassified Information (CUI).
The DFAS manager of the requiring office will determine what CUI contractor personnel are given access to. CUI may not be disclosed to contractor personnel unless required for contract performance.
Contractor personnel shall safeguard CUI in accordance with DoDI 5200.48 and DFAS 5200.1-I. The sponsoring DFAS activity will provide storage capability for all CUI required for contract performance.
Installation Entry and Common Access Card (CAC) Requirements.
The Contractor shall comply with established security procedures for entering government installations and facilities. Contractor employees shall be required to obtain and wear identification (ID) badges that will permit access into the facility.
All contractors who require unescorted access to DFAS facilities will be required to obtain a DoD CAC.
Contractor shall work with the assigned DFAS Contracting Officer Representative (COR)/Trusted Agent (TA) to obtain a CAC using the Trusted Associate Sponsorship System (TASS). Under no circumstances will a CAC be issued to any person unless that person has been cleared by the DFAS Personnel Security Office to work on the contract.
All CACs and badges issued to Contractor personnel are Government property and must be returned to the assigned DFAS COR/TA upon departure from the program or at the conclusion of the contract, whichever comes first. Contractors whose CAC is lost or stolen must report the loss as soon as possible to the assigned DFAS COR/TA and present documentation that the CAC is missing and describing the circumstances under which the loss occurred. The assigned DFAS COR/TA will follow agency CAC procedures in order to issue a new CAC.
The CAC contains personally identifiable information (PII) and must be treated as a controlled item.
Contractors’ must not share their CACs and passwords with any other staff members. The assigned DFAS COR/TA will report any violation or suspected violation to the Contracting Officer and DFAS Trusted Agent Security Manager (TASM). Any violators will be temporarily or permanently removed from the project. If a Contractor has a CAC issued from a previous engagement with another agency that CAC must be returned to that agency before issuance of a new CAC.
Training.
DoD Mandatory Contractor Personnel Training Requirements: The contractor shall direct that its employees performing under this contract complete the annual mandatory training in accordance with the DoD mandate identified for each training module.
Contractor personnel working at a DFAS site who require a Common Access Card (CAC), or contractor personnel working remote via VPN, need to complete the following training modules within 30 days after receipt of CAC, (note for Cyber Awareness Challenge Module 003, completion of this module is required prior to requesting a new DFAS network or VPN account), as a precondition for continued attendance and/or network access.
In addition, these modules shall be completed annually to retain accessibility. Noncompliance will negatively impact contract performance and lead to the loss of CAC and/or network access for contractor personnel.
Continuity of Operations and Crisis Management Organization. Contractor personnel will take the training through the DFAS Portal upon receipt of Network access.
Cyber Awareness Challenge. Completion of this module is required prior to requesting a new DFAS network or VPN account. For contractor personnel unable to access the DFAS Portal, the same training is available at:
https://public.cyber.mil/training/cyber-awareness-challenge/
Upon completion of the training Contractor personnel shall maintain a copy of the training certificate in PDF, submit a copy to the Contracting Officer Representative (COR), attached to the request for network access as proof of completion.
Keeping DFAS Safe: Physical Security, Information Security, and Personnel Security. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
Antiterrorism Level One. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:
https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf
All other contractor personnel shall take the training through the DFAS Portal upon receipt of network access.
Privacy Act (PA) and Personally Identifiable Information (PII). Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
Combating Trafficking in Persons (CTIP) Awareness Training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:
http://ctip.defense.gov/
All other contractor personnel shall take the training through the DFAS Portal upon receipt of network access.
Records Management. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
Insider Threat (InT) Awareness Training. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
DoD Mandatory Controlled Unclassified Information (CUI) Training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:
https://securityawareness.usalearning.gov/cui/index.html. All other contractor personnel will take the training through the DFAS Portal upon receipt of network access.
NOTE: This list of training requirements is subject to change.
Training Time. The average estimated time for completion of each training module is approximately one hour or less. The Keeping DFAS Safe: Physical Security, Information Security, and Personnel Security training module will take approximately 90 minutes to complete.
Training Methods.
Network Training. Network training through the DFAS Portal is the required method for those Contractor personnel who have an existing DFAS network account.
Web-based Training. For Cyber Awareness Challenge, Antiterrorism Level One, and Combating Trafficking in Persons (CTIP) Awareness Training: If an individual does not have network access through the DFAS Portal, they can complete the training through a DoD authorized Web source. All other contractor personnel shall take the training through the DFAS Portal upon receipt of DFAS network. The contractor personnel shall retain a PDF copy of the “Certificate of Completion” or a “screen shot” with the date of the completion of the training. The COR will maintain a file for proof of completion.
Contractor personnel who do not require network access but require unescorted access into a DFAS facility shall receive applicable security training through the site Force Protection Office. To identify Site Force Protection Officers at each DFAS location consult the Agency Force Protection Portal Page:
https://dfasportal.dfas.mil/ddss/force_protection/Pages/SiteSpecificForceProtectionSecurityServices.aspx
The prime contractor official representative shall provide the COR with a group list of its personnel requiring completion of the training. The COR will submit the ‘group list’ to the Site Force Protection Officer to schedule training. As a reminder, the prime contractor official representative shall submit this group list of names within 30 days after contract award. Requests for individual training shall be justified in writing and submitted to the COR for evaluation. Special arrangements will be determined by the Site Force Protection Officer, other training Module POCs and the COR.
Interaction with Contractor Personnel. The COR shall forward questions or concerns directly to the prime contractor official representative who is directly responsible for managing its own employees/subcontractor personnel.
The prime contractor official representative shall coordinate with the COR a training schedule without causing undue delays to contract performance.
The prime contractor official representative (including subcontractor’s personnel when applicable) shall provide the COR, within 30 days after contract award/exercise of an option, a written report identifying:
- Contractor employees required to take the training,
- Contractor employees who have completed the training and
- Contractor employees who are delinquent.
Contractor personnel shall direct their training questions or concerns to their contractor management chain and/or company representative.
Monthly Training Status Reports. The prime contractor official representative shall submit a monthly status update to the COR, identifying the initial and annual training status of all contractor personnel.
Training Point of Contact (POC). The COR is the POC for the Contractor. The Contractor shall provide regular training updates to the COR, and keep an updated registry to assure employees who come on board at any time in the contract life have completed all required training.
File details come from the government source that posted it. Updated .