Attachment 1 - PERFORMANCE WORK STATEMENT - 70US0921R70090014 - 8-10-21.docx
DOCX document 102 KB Posted
- Attached to
- Credentialing Services Federal contract opportunity
- Solicitation number
- 70US0921R70090014
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 70US0921R70090014-0001.pdf | ||
| Attachment 3 - RFP INSTRUCTIONS AND EVALUATION FOR AWARD - 70US0921R70090014 8-10-21.docx | DOCX document | |
| Attachment 4 - SAMPLE TASK ORDER - LARGE EVENT - 70US0921R70090014.docx | DOCX document | |
| Attachment 5 - SAMPLE TASK ORDER-SMALLER EVENT - 70US0921R70090014.docx | DOCX document | |
| Attachment 9-Pricing Sheet.xlsx | XLSX spreadsheet | |
| Attachment 7 - Past performance questionnaire - 70US0921R70090014.docx | DOCX document | |
| Attachment 6 - Quality Assurance Surveillance Plan- 70US0921R70090014.docx | DOCX document | |
| Attachment 8 Solicitation Clarification Question Request Form.xlsx | XLSX spreadsheet | |
| Attachment 2 - ADDITIONAL PROVISIONS AND CLAUSES - 70US0921R70090014.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 1 - PERFORMANCE WORK STATEMENT
70US0921R70090014
PERFORMANCE WORK STATEMENT
DPD CREDENTIALING / ACCESS CONTROL SERVICES
Part 1
GENERAL INFORMATION
1. INTRODUCTION: The United States Secret Service (USSS) Office of Protective Operations (OPO) / Dignitary Protective Division (DPD) assumes the lead role in the coordination of operational security plans for all events in which Foreign Heads of State / Government are in attendance and events designated as National Special Security Events (NSSEs). This is a non-personal services contract to provide production of temporary special events credentials in support of access control for such events. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the contractor who, in turn is responsible to the Government.
1.1 Background: When USSS DPD assumes the lead role in the coordination of operational security plans for events in which Foreign Heads of State/Government are in attendance and events designated as NSSEs, advance planning and coordination must occur. Among the areas of advance planning and coordination is event access control. The DPD Credentialing Section is responsible for the design and procurement/production of temporary special event credentials in support of access control for all events possessing national and/or international significance that represent highly symbolic targets for terrorism that include designated NSSEs.
1.2 Objectives: The following are the objectives of this acquisition:
· Provide pre-event and onsite consultation of best practices
· Provide advance planning services related to credentialing
· Produce physical credentials, with specified security features, for NSSEs and other protective events
· Provide access control solutions that integrate with physical credentials
· Provide secure data management services for credential operations
· Provide tracking of real-time event attendance and participation
· Meet USSS security requirements for contractor facility access and personnel security
· Provide on-site training to USSS personnel at credentialing checkpoints
1.2.1 Authority:
The Contracting Officer (CO) is responsible for the general administration of this Indefinite delivery Indefinite Quantity (IDIQ). The Contracting Officer’s Representative (COR) is responsible for the review/acceptance of all deliverables, and technical direction. The CO shall serve as the Government point of contact for contractual direction. The COR shall serve as the Government point of contact concerning information exchange, submission review and payment. Nothing said by the COR shall be construed to change the order requirements unless supported in writing in advance by the CO.
Each order shall have an appropriate Contracting Officer and COR, as identified.
The USSS points of contact responsible for overall administration of this order is:
Keisha Pender Contract Specialist 202-406-9759 Keisha.Pender@usss.dhs.gov
Danielle Donaldson Contracting Officer 202-380-7689 Danielle.Donaldson@usss.dhs.gov.
COR Point of Contact:
Amanda Brown Parks Senior Business Acquisition Analyst 202-870-6229 amanda.brownparks@usss.dhs.gov
1.3 Scope: DPD Credentialing / Access Control Services: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Credentialing / Access Control Services as defined in this Performance Work Statement except for those items specified as Government furnished property and services. The contractor shall accomplish:
· Provide physical credentials and underlays as well as access control solutions for National Special Security Events (NSSEs) and other major events.
· These events included and are not limited to: United Nations General Assembly (UNGA); state funerals, National Conventions, Summits, Presidential Inauguration and any major event that could be designated as National Special Security Event.
· Implement all required access control personnel, services, equipment, and supplies for a major event within a specific, and at times, limited time (possibly twenty-four hours’ notice); and
· Effectively operate at temporary To Be Determined (TBD) “on-site” location(s) for an approximate 15 to 30-day period.
· Provide event management services in the form of access control equipment and authorized personnel to operate access control equipment
1.4. Specific Tasks:
1.4.1. Event Management:
Event Management shall incorporate all aspects of credentialing services. This includes access control equipment and personnel services, secure data management and consultative services for an event. The planning and development, execution, and production and distribution shall be provided by the Contractor in a written plan on pre-designated date(s) determined by the USSS Project Manager (PM) prior to each event.
1.4.1.1 Project Management
The contractor shall accomplish all aspects of event management to include industry-standard data collection as well as facilitation of design, production and distribution of credentials for events of national significance.
This includes and is not limited to the following:
· Pre-event, on-site strategic consultation and best practice system strategies;
· Pre-planning for potential events to include on-site project management and access control solutions for hardware and software and installation of access control equipment at all designated check points;
· Participate in video teleconferences and/or provide presentations with event coordinators;
· The Contractor shall act as credential liaison and expedite reporting between internal and external organizations/agencies that may be collecting data for specific groups and the PM to facilitate access control solutions for the purpose of enabling credential management.
· The Contractor shall facilitate credential communication methods with organization/agencies, manage all incoming data, prepare and ensure data accuracy, establish and maintain a data change management process, and prepare credential information for production and distribution;
· Written plan on pre-designated date(s) determined by the PM, and specified on the order prior to each event.
1.4.1.2 Secure Data Management
· The data management process is the main phase of credential operations. The USSS shall provide an estimated number of participants for each event that shall require credentials and collaborate with the Contractor to determine a data submission deadline for all applicants.
· Additional requirements related to Secure Data Management are listed in Section 1.4.4 – Additional Software
1.4.1.3 Planning
· The Contractor shall coordinate with the USSS to develop a communication procedure, basic elements for information management, basic data planning, credential design, venue, event and security requirements and staffing. The Government shall provide the USSS official logo and approve credential design.
· The Contractor shall collaborate with the Government on how to handle card modifications and/or additional cards if and when necessary.
1.4.1.4 Design / Development
Contractor shall provide:
· All elements of information management to include identifying and confirming all constituent groups, registration procedures, approval/denial procedures, processing, change management, deadlines and policies.
· All elements of basic data planning to include, establishing data field, photo format and size, access scheme, category/badge types, venue/event/zone code designation.
· All elements of credential design to include, elements of the badge, look, stock type, amount, templates, proofs and legal disclaimers.
· All elements of advances printing and distribution center process to include advanced printing criteria, center locations, lay-out, process flow, schedule of installation, policies and procedures, crisis management plans, staffing and communication procedures.
1.4.1.5 Execution
Contractor shall perform:
· Execution of plans created during Development.
· Adjust to iterations and changes based on the response and acceptance of various agencies.
· Extensive data collection and processing.
· Data procedures must be clarified in order to ensure proper production and distribution of the physical badge.
1.4.1.6 Production, Distribution and Reference
Contractor shall perform the following services:
· All elements of data management, design, technology operational to produce accurate access control devices.
· Facilitate / Produce secure badge design on secure card stock. The contractor shall modify the design to fit on the card.
· The contractor shall be responsible for facilitating/ producing the cards and providing all material associated to print.
· Maintain consistent delivery of credentials based on agreed deadlines.
· Maintain accuracy and print quality of credentials.
· Maintain secure process for reconciling printed credentials. In the event a card is lost, the person shall report it appropriately. Prior to printing a new card or underlay, the contractor shall receive approval first from the PM.
· Once the data is received, the contractor shall print the cards and keep them until authorized by the USSS to distribute.
· Distribution, all established methods, access control is set to record/reference based on requirements.
· Crisis management and trouble-shooting procedures and required modifications implemented.
1.4.2 Access Control Equipment and System Management
Prior to each event the USSS shall determine required security features to include within devices: barcodes, micro printing, holograms, Radio Frequency Identification biometrics, etc. The access control devices and equipment readers shall comply with the following:
· Incorporation of TBD security feature technology.
· Technology should have the capability to be used simultaneously with other government and USSS systems.
· Assigned readers/ monitors at each designated check point.
· Full reader/scanning easy view functions.
· Tracking of system and device modifications and distribution information (examples: name of person the cards were distributed to, date, time, location and copy of receiving person’s electronic signature).
· Tracking of real-time attendance and participation.
1.4.3 Radio Frequency (RF) Equipment
The Contractor shall be provided the opportunity to de-conflict the radio frequency (RF) signal with USSS protective equipment such as magnetometers and /or to test function equipment at access control checkpoints to ensure Contractor access control equipment operations does not interfere with other Government utilized technology or established security plan timetables.
· The Contractor shall incorporate industry-standard security technologies, such as RF transmitters
· Supply associated RF equipment and fully encrypted connections as required in the Data Management and Security Section. The Contractor shall be an in-house fully production capable contractor for supplemental identification and shall supply and/or produce USSS approved access control devices and equipment that incorporate industry-standard security technologies and data collection and design that operate with fully encrypted connections. When required, the Contractor shall provide software, hardware and equipment that allows for each access device to be deactivated if and when necessary.
1.4.4 Additional Software
· The contractor shall provide software to manage all data related to applicant / credential submissions including: credentialing appointments, engagements, and deadlines; as a communications platform; to obtain applicant / credential information; and to communicate with the USSS on credential access levels and requirements.
· Configure commercial web application software, modified for USSS use and for users to interact and create engagements or appointments that build databases and custom web forms while allowing for the sharing of documents.
· Software should be specific to each event to automate the collection, management, and communication of applicant/credential information while complying with government prerequisite privacy and data security requirements.
· The Contractor shall provide continual access and technical support of the software for the USSS to utilize when managing smaller events that do not require the full extent of contractor support. The Contractor shall provide an experienced technician capable of software update installation, system maintenance and software solutions throughout the duration of the contract.
· The Contractor must have the ability to store and format personal identifying information (PII) and allow for the secure sharing of such information with the Government. The Contractor must have the ability to receive, compile, store, view, and implement applicant photos within web based software and on all access control devices. The Contractor shall, as necessary, persistently upgrade software, hardware, devices and equipment for additional biometric implementation for future events.
· The Contractor shall have the ability to track data changes through Internet Protoccol (IP) tracking and login by each user and administrator and the ability to create URL for data collection from end users.
· All physical access devices shall be deactivated and/or properly disposed of upon completion of the event. Physical devices shall only be active for the duration of the event and shall not be utilized for access to future events. The Contractor should be capable of purging records upon completion of each event or NSSE.
1.4.5 Memorandum of Understanding / Memorandum of Agreement
A memorandum of understanding (MOU)/memorandum of agreement (MOA) shall be executed between the USSS and the Contractor within 30 days of contract award. The MOU/MOA shall serve to confirm the Contractor’s system boundary, USSS system boundary, data breach notification procedures, as well as roles and responsibilities in the event of a data breach.
1.4.6 Training
Event checkpoints shall be manned by USSS personnel and Contractor personnel. The Contractor shall provide a minimum level of training to USSS personnel with regard to monitor assessment and response to help determine whether or not the individual(s) should be granted access to a particular area. The exact number of checkpoints shall be determined prior to each event.
· When required, the Contractor shall provide vetted personnel to staff the TBD on-site credentialing/ distribution center(s) prior to the event and venue checkpoints for the duration of the event or as required by the USSS PM.
1.4.7 Labor Categories
The contractor shall provide the labor categories associated with each action. The proposed categories shall be priced under this contract.
The suggested labor categories are listed below. This list is intended to be anticipated and in no way is all inclusive, nor is the list required for each and every technical approach to a given requirement or order. Each order shall have the appropriate type and number of labor categories based upon the scope of the order.
Program Manager Project Manager / Deputy Program Manager Project Coordinator Operations / Production Manager Training Specialist Technical Developer Programmer Network Operations Information Systems Security Manager Information System Security Engineer Information System Security Officer Graphic Designer
Further listed below are sample duties for each of the suggested labor categories as well as typical, minimum experience for each type of labor category.
PROGRAM MANAGER
| Functional Responsibilities: |
| Program Manager II |
The Program Manager oversees the entire initiatives. They are ultimately responsible for the success of all interconnected projects within that program.
| • | Initiates kick off activities based on SOW |
| • | Implement project plan and assigns task |
| • | Maintains planned budget |
| • | Works with client to ensure policies and procedures |
| • | Reviews and creates initial outreach and communication strategy for internal and external stockholders |
| • | Recruitment of Labor Graphic, Systems Build out & launch, responsible organization and customer service |
| Minimum General Experience: |
| 8+ Years of Program Management experience handling large and small major events |
| Minimum Education: |
| BS/BA |
PROJECT MANAGER
| Functional Responsibilities: |
| Project Manager / Deputy Program Manager II |
The Project Manager oversees a specific aspect within the project. It can be a specific aspect within the whole project. They ensure the timely delivery of a specific project
| • | Becomes the main point of contact and troubleshoots internal and external issues |
| • | Oversees the technical and operational task as it pertains to assigned responsibility |
| • | Directly uses, monitors and manages technology tools |
| • | Provides direct customer service and account management |
| • | Organizes and implements all operational equipment, set up and staffing |
| • | Reports to Program manager on daily basis. |
| • | Oversees onboarding of (RO) Responsible Organization points of contact (including Training and customer service and trouble shooting |
| • | Compiles after action reports |
| Minimum General Experience: |
| 4+ Years of Project Management experience handling large and small major events |
| OR |
| 8+ Years of Project Management experience handling large and small major events |
| Minimum Education: |
| BS/BA |
PROJECT COORDINATOR
| Functional Responsibilities: |
| Project Coordinator II |
As directed by Project Manager coordinates execution of SOW objectives. Assesses current business situation and analyzes and develops business rules based on management plan. Maintains costs vs. budget, plans vs. performance and staffing requirements
| Minimum General Experience: |
| 3+ Years Project Coordination experience handling major events |
| Minimum Education: |
| HS |
OPERATIONS MANAGER/PRODUCTION MANAGER
| Functional Responsibilities: |
| Operations Manager / Production Manager I & II |
Under direction of technical management, monitors and controls all computer terminals, kiosks, printers, readers etc. Continually observes equipment and reports any deviations from standard and implements solutions to maintain continuous operations.
| Minimum General Experience: |
| 1+ Years managing continuous operations of I.T systems |
| OR |
| 3+ Years managing continuous operations of I.T systems |
| Minimum Education: |
| BS |
BS
TRAINING SPECIALIST
| Functional Responsibilities: |
| Training Specialist I & II |
Provides overall training of software/hardware tools for overall operation. Prepares training guides, programs and tutorials. Ensures concepts and operations are understood and effectively adopted by all personnel and stakeholders
| Minimum General Experience: |
| 3+ Years training on software/hardware tools |
| OR |
| 5+ Years training on software/hardware tools |
| Minimum Education: |
| BS/BA |
BS/BA
TECHNICAL DEVELOPER
| Functional Responsibilities: |
| Technical Developer I & II |
Designs, modifies, develops, writes and implements software programming applications. Supports and/or installs software applications. Performs and manages tests, reviews and analysis. Knowledgeable of full cycle software development and relational database concepts
| Minimum General Experience: |
| 4+ Years Designing, modifying, developing, writing and implementing software programming applications |
| OR |
| 7+ Years Designing, modifying, developing, writing and implementing software programming applications |
| Minimum Education: |
| BS/BA |
BS/BA
PROGRAMMER
| Functional Responsibilities: |
| Programmer I, II, III |
The Programmer is part of an overall engineering team that includes development, deployment and maintenance of software and hardware solutions, launches the specific install required for the event
| • | The Programmer is required by CISO office |
| • | The programmer monitors and alerts CISO in the event of potential security threats based on site traffic and logs scans from continuous monitoring |
| • | The programmer performs any required updates and changes to the system |
| • | Identify, test and writes code for correction or performance updates |
| • | Perform fixes to bugs, error based on user needs |
| • | Assist system and networking engineer foe software issues with hardware |
| Minimum General Experience: |
| 2+ Years monitoring security threats and notifying leadership |
| OR |
| 4+ Years monitoring security threats and notifying leadership |
| OR |
| 6+ Years monitoring security threats and notifying leadership |
| Minimum Education: |
| BS/BA |
BS/BA
BS/BA
NETWORK OPERATIONS
| Functional Responsibilities: |
| Network Operations I & II |
Plans, analyzes, and maintains network infrastructure for software and hardware integration and uses. Performs testing and ensures security, connectivity and best practices for network implementation
| Minimum General Experience: |
| 3+ Years Performing testing and ensures security, connectivity and best practices for network implementation |
| OR |
| 5+ Years Performing testing and ensures security, connectivity and best practices for network implementation. |
| Minimum Education: |
| BS/BA |
BS/BA
INFORMATION SYSTEM SECURITY MANAGER
| Functional Responsibilities: |
| Information System Security Manager I |
Responsible for the overall cybersecurity plans and oversees and maintains network infrastructure for software and hardware integration and uses.
| Minimum General Experience: |
| 5+ Years of maintain network infrastructure for software and hardware integration |
| Minimum Education: |
| BS/BA |
INFORMAITON SYSTEM SECURITY ENGINEER
| Functional Responsibilities: |
| Information System Security Engineer I |
Engineering, implementing and monitoring security measures for the protection of computer systems, networks and information. Identifying and defining system security requirements. Designing computer security architecture and developing detailed cyber security designs.
| Minimum General Experience: |
| 5+ Years monitoring security measures for computer system protections. |
| Minimum Education: |
| BS/BA |
INFORMATION SYSTEM SECURITY OFFICER
| Functional Responsibilities: |
| Information System Security Officer I |
Protects the IT infrastructure and monitors networks, databases, and computer systems and create a risk management plan. Perform security updates and build firewalls and other security features
| Minimum General Experience: |
| 5+ Years protecting I.T infrastructure and monitoring computer systems. |
| Minimum Education: |
| BS/BA |
GRAPHIC DESIGNER
| Functional Responsibilities: |
| Graphic Designer I & II |
Designs the layout and graphical presentation of security access badges / credentials. Presents proofs / exemplars to the government for production approval.
| Minimum General Experience: |
| 3+ Years graphic design |
| OR |
| 6+ Years graphic design |
| Minimum Education: |
| BS/BA |
BS/BA
Alternate Degree Experience Equivalency These above requirements are a guide to the types of experience and educational background of typical personnel in each labor category. Education and experience may be substituted for each other. Each year of relevant experience may be substituted for 1 year of education, and vice versa. In addition, certifications, professional licenses, and vocational technical training may be substituted for experience or education with the written approval of the ordering activity.
On occasion, there may be a need to waive the requirements in order to use the best individual for the task. The task order Contracting Officer and/or the Contracting Officer’s Representative (COR) may waive the minimum education / experience requirements at the sole discretion of the government.
1.5 General Information
1.5.1 Period of Performance: This IDIQ contract is anticipated to be from date of award for 5 years. This IDIQ is not funded. Funds are obligated via task/delivery orders to this contract.
1.5.2 Place of Performance: The majority of the performance shall be at the Contractor’s Facility. Based on the task order there may be on-site locations as applicable. Those locations shall be spelled out in each of the task orders.
During ‘on-site’ locations operation must continue to perform for an approximate 15 to 30-day duration for each event as applicable.
1.5.3 Hours of Operation: The contractor is responsible for conducting business as specified herein. The hours of operations will be at Task Order Level
1.5.4 Type of Contract: The contract is anticipated to be an Indefinite Delivery, Indefinite Quantity (IDIQ). Each task order placed from this contract shall be Firm Fixed Price and Cost (Travel), as applicable. Each individual task order shall be evaluated for the services required at the time of the task order award.
1.5.5 Privacy Act: Personnel who have access to Privacy Information shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations. This effort has been determined by the USSS Office of the Chief Information Officer (OCIO) to be “high risk”.
1.5.5.1 Cyber-Supply Chain Risk Management (C-SCRM):
0. The Offeror understands and agrees that the Government retains the right to cancel or terminate the Contract, if the Government determines that continuing this solicitation presents an unacceptable risk to national security.
0. “Gray-Market” Equipment
1. The Offeror shall provide only new equipment unless otherwise expressly approved, in writing, by the DHS Contracting Officer. Offerors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.
1. The Offeror shall be excused from using new OEM (i.e., "gray market”, "previously used”) components only with formal Government approval, in writing, from the DHS Contracting Officer. Such components shall be procured from their original source and shipped only from the manufacturer’s authorized shipment points.
1. All equipment obtained by the Offeror on behalf of the Government will need to be provided to OIG OCIO for review to validate requirements and approved Contractors by DHS.
0. Hardware and Software Requests
2. The contractors supply the Government hardware and software will provide the manufacturer’s name, address, state, and/or domain of registration, and the DUNS number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state, and/or domain of registration and DUNS number of those suppliers must be provided.
2. Subcontractors are subject to the same general requirements and standards as prime contractors. Contractors employing subcontractors will perform due diligence to ensure that these standards are met.
2. The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.
2. For software products, the Offeror shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “End of Life (EoL)"). Software updates and patches shall be either: made available to the government for all products procured under this Contract, replaced upon End of Support (EoS) is reached, or formally waived (in writing) by the DHS Contracting Officer.
0. Supply-Chain Transport
3. Offerors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill Contract obligations with the Government.
3. All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the Contract, the period of performance, or one calendar year from the date the activity occurred.
3. This transit process shall minimize the number of times in route components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments. The supplier, at the Government's request, shall be able to provide shipping status at any time during transit.
3. All records pertaining to the transit, storage, and delivery shall be readily available for inspection by any agent designated by the U.S. Government as having the authority to examine them.
3. The Offeror is fully liable for all damage, deterioration, or losses incurred during shipping and handling, unless the damage, deterioration, or loss is due to the Government.
3. The Offeror shall provide a packing slip which shall accompany each container or package with the information identifying this solicitation number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact.
3. The Offeror shall send a shipping notification to the intended government recipient; with a copy transmitted via email to the Contracting Officer, or designated representative. This shipping notification shall be sent electronically and will state this solicitation number, the order number, a description of the hardware/software being ship (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.
0. Notifications
4. The Offeror shall notify DHS Contracting Officer, COR and the Office of the Chief Information Officer and the DHS component Chief Information Officer through the Enterprise Security Operations Center (ESOC) directly of any suspected or potential violations of Section 889 of the National Defense Authorization Act (NDAA) for Information Communications Technology (ICT) at NDAA_Incidents@hq.dhs.gov.
0. Foreign Equities
The Offeror shall immediately notify the DHS Contracting Officer, COR that will report to the Office of the Chief Security Officer (OCSO) or cognizant component personnel security office regarding any changes to corporate foreign ownership, control, or influence.
1.5.5.2 Physical Security: The contractor shall be responsible for safeguarding all Government equipment, information and property provided for contractor use. At the close of each work period, Government facilities, equipment, and materials shall be secured.
The Contractor’s facility shall also be equipped with physical security measures to safeguard generated hardware, equipment and/or devices utilized by the Government for imminent events. Physical security involves the use of multiple layers of interdependent systems which include CCTV, security guards, protective barriers, locks, alarms, motion detectors, access control protocols, and many other techniques. Once access device production for the Government has begun, the facility should be equipped with a safe, vault and/or secure area to protect produced credentials, underlays and /or additional devices. After award of contract, USSS representatives shall periodically perform on-site survey(s) of Contractor facilities for compliance. The Contractor shall be briefed on the results of the on-site facility survey and given two weeks to mitigate any identified security risks. In addition, the USSS shall routinely require for USSS personnel to be on-site at the Contractor’s facility upon production of Government access devices to ensure access control accountability and help manage pre-event correspondence and planning efforts.
1.5.5.3 Contractor Facility Access: All non-classified USSS information is considered “Sensitive But Unclassified” (SBU) and must be protected as such. The clearance level for this contract is unclassified, however all personnel, both prime and subcontractor, working under this requirement must be a U.S. citizen. All Contractor personnel involved, including on-site support shall undergo a security background check by the USSS. The Contractor shall provide only personnel who can successfully pass the background investigation.
The selected offeror is required to provide the following information about both the Contractor’s employees and subcontractors who may have direct or incidental (whether logical or physical) access to USSS information:
1. Employee’s full name
1. Employee’s gender
1. Employee’s date and place of birth
1. Employee’s social security number
On-site event contractor and subcontractor personnel may need access into USSS controlled facilities and therefore must truthfully complete and submit a USSS Facility Access Request (SSF 3237) as a minimum Category 1 Applicant, which expires a year from approval date or date indicated on the form, and a Conditional Access to Sensitive But Unclassified Information Non-Disclosure Agreement (SSF 4024).
The USSS shall conduct a limited background investigation of all named personnel. The results of these checks shall be used solely by the USSS in evaluating personnel. The USSS has the right to request exclusion of any Contractor personnel from government projects and/or events for any reason. Employees with warrants, numerous felony arrests, or a felony conviction shall be excluded. Due to required confidentiality laws and privacy issues, the Contractor shall not be provided an explanation if an employee is denied.
1.5.5.4 Key Personnel: The contractor shall propose the following personnel as key personnel:
· Program Manager (PM): The PM shall have the full authority to act for the contractor on all matters. The PM shall be ultimately responsible for all credentialing services as specified herein.
· Project Manager / Deputy Project Manager (DPM): The Project Manager / DPM shall act in the absence of the PM and shall have all authority for the PM in his/her absence.
· The contractor shall obtain approval from the contracting officer and the contracting officer’s representative for changes to and/or replacement of contract key personnel.
At the discretion of the Government, all Key Personnel shall be required to be interviewed by the Government prior to be selected to start any work.
1.5.5.5 Identification of Contractor Employees: All contract personnel attending meetings, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. Contractor personnel shall wear appropriate contractor credentials while performing services under this contract.
1.5.6. Contractor Travel: The Contractor shall be required to travel to perform services under this contract. Duration, frequency and location of travel are dependent upon each individual task order. Contractor shall be authorized travel expenses consistent with FAR 31.205-46, the terms and conditions of the Federal Travel Regulation (FTR), and the limitation of funds specified in the resultant contract. All travel requires Government approval/authorization and notification to the COR. The Contractor is required to provide a proposed cost estimate as early as possible and on a TBD date determined by the PM prior to the final security planning of each event.
1.5.7 Other Direct Costs: This category includes contractor travel (outlined in 1.5.7) to government facilities and/or while performing services for the government and shipping expenses associated with production of credentials.
1.5.8 Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.5.9 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan shall be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.
PART 2
DEFINITIONS & ACRONYMS
2. Definitions and Acronyms:
2.1. DEFINITIONS
2.1.1 CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the Government. The term used in this contract refers to the prime.
2.1.2 CONTRACTING OFFICER (CO). A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the Government. Note: The only individual who can legally bind the Government.
2.1.3 CONTRACTING OFFICERS REPRESENTATIVE (COR). A person designated and authorized in writing by the contracting officer to perform specific technical or administrative functions.
2.1.4 DELIVERABLE. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.
2.1.5 KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
2.1.6 PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
2.1.7 ACCESS CONTROL. Actions which limit the physical entrance into a given space, area or property. An Access control system is one that grants or denies access based on the identity of the individual attempting to gain access in combination with the area they are attempting to gain access to.
2.1.8 CREDENTIAL. A method of identifying authorized individuals by something they have.
2.1.9 SENSITIVE INFORMATION. Any information or proprietary data which if subject to unauthorized access, modification, loss, or misuse could adversely affect the national interest, the conduct of Federal programs, or the privacy to which individuals are entitled under 5 U.S.C. 552a (The Privacy Act), but that has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept classified in the interest of national defense or foreign policy.
2.1.10 QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). A Government document that specifies how the contractor will verify and document that the government is receiving quality of services called for under the contract. The QASP identifies that each performance objective is linked to a method of inspection incorporated in the QASP. The QASP identifies what is going to be inspected, the inspection process, and who will do the inspecting. and pays only for the acceptable level of services resulting in the successful accomplishment of the Governments desired outcomes.
2.2. ACRONYMS
| CFR | Code of Federal Regulations | |
| CO | Contracting Officer | |
| CONUS | Continental United States (excludes Alaska and Hawaii) | |
| COR | Contracting Officer Representative | |
| COTS | Commercial-Off-the-Shelf | |
| CPFF | Cost Plus Fixed Fee | |
| FAR | Federal Acquisition Regulation | |
| FFP | Firm Fixed Price | |
| GFP | Government Furnished Property | |
| HSAR | Homeland Security Acquisition Regulation | |
| LH | Labor Hour | |
| NCR | National Capital Region | |
| NSSE | National Special Security Event | |
| OCI | Organizational Conflict of Interest | |
| OCONUS | Outside Continental United States (includes Alaska and Hawaii) | |
| ODC | Other Direct Costs | |
| PIPO | Phase In/Phase Out | |
| POC | Point of Contact | |
| PM | Program Manager | |
| PWS | Performance Work Statement | |
| QASP | Quality Assurance Surveillance Plan | |
| RF | Radio Frequency | |
| TE | Technical Exhibit | |
| TM | Time and Material | |
| TPOC | Technical Point of Contact |
PART 3
GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
3. GOVERNMENT FURNISHED ITEMS AND SERVICES:
3.1. Services: The Government shall coordinate data collection for the credentials.
3.2 Facilities: The Government shall secure commercial space for the Contractor to perform “on-site” operations.
3.3 Utilities: In addition, the Government shall provide internet connectivity within the credentialing center and at all designated access control checkpoints. The internet connection speed at all locations will be a minimum of 1.544 Mbps. When wired internet connectivity is not available, the government will provide a wireless connection at a minimum of 4G speed. The contractor shall instruct employees in utilities conservation practices. The contractor shall be responsible for operating under conditions that preclude the waste of utilities, which include turning off the water faucets or valves after using the required amount to accomplish cleaning vehicles and equipment.
3.4 Equipment: Prior to and during “on-site” required events, the Government shall provide all furniture and fixtures to include telephones for contractor work stations.
3.5 Materials: The Government shall also provide the Logo and the estimated number of participants for each event, as applicable.
PART 4
DELIVERABLES
4.0 DELIVERABLES:
4.1 Deliverable Table
| Item |
| Medium/Format and Submit To |
| Contract Level (IDIQ/ Order) |
| Frequency |
| Due Date / Response Time |
| PWS Location |
Initial platform configuration, account setup, and in-person *kick-off meeting at USSS HQ
N/A
IDIQ
Once
| Within 10 business days of award or at kickoff meeting |
| 4.1.1 |
| Pre-event Consultation/ Best Practices Written Plan |
| Email to COR/PM/CO |
| Task Order |
| Once per event |
| TBD for each Task Order |
| 4.1.8 |
| Communication Procedures |
| Email to COR/PM/CO |
| Task Order |
| Once per event |
| 10 days after task order |
| 4.1.8 |
| Badge Design |
| Email to COR/PM/CO |
| Task order |
| Once Per event |
| As specified in task order |
| 4.1.4 |
| Application Software |
| Web Services |
| IDIQ - to be approved |
| TBD |
| TBD |
| 4.1.5 |
| Memorandum of Understanding (MOU)/ Memorandum of Agreement (MOA) |
| *Government provides via Email |
| IDIQ |
| Upon Kickoff Meeting |
| Within 30 days of award. |
| 4.1.6 |
| Meeting Minutes |
| Email to COR/PM/CO |
| As Applicable |
| As Applicable |
| Within 3 business days of meeting |
| 4.1.1 |
| Quality Control Plan (QCP) |
| Email to COR/PM/CO |
| IDIQ |
| Once |
| Delivered within 30 days after contract award |
| 4.1.7 |
4.1.1 Meetings
· Kick- Off- The contractor shall coordinate with the Government POCs for a kick off meeting. During the meeting the contractor and Government shall clarify and address any ambiguous information.
· The contractor shall act as a Liaison for the USSS and provide information to the Government POC as reference.
· Meeting Minutes shall be required for all meetings and shall need to be submitted to the Government PO, with 3 business days of meeting.
4.1.2 Pre-Event Consultation / Best Practices Written Plan
The Contractor shall provide a written plan on pre-event planning document within 15 business days prior to the event or as specified in the Task Order. Written plan shall be submitted to the USSS COR/PM CO for pre-approval.
4.1.3 Communication Procedures
The contractor shall develop communication procedures. These procedures shall include basic elements for information management, basic data planning, credential design, venue, event and security requirements and staffing. The procedures should address how the Government and the Contractors shall collaborate on handling card modifications and/or additional cards if and when necessary. Communication procedures shall be submitted to the USSS COR/PM CO for pre-approval.
4.1.4 Badge Design: The badge designs shall be on secure card stock and shall be modified to fit the card. Additional information provided under 1.4.1.6. Badge designs shall be submitted to the USSS COR/PM CO for pre-approval.
4.1.5 Application Software: See Section 8 “Special Contract Requirements” herein.
4.1.6 Memorandum of Understanding / Memorandum of Agreement (MOU/MOA): The MOU/MOA shall serve to confirm the Contractor’s system boundary, USSS system boundary, data breach notification procedures, as well as roles and responsibilities in the event of a data breach.
4.1.7 Quality Control Plan: The contractor shall develop and maintain an effective quality control program (QCP) to ensure services are performed in accordance with this PWS. The contractor shall implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s QCP is the means to assure that work complies with the requirement of the contract. The QCP is to be delivered within 30 days after contract award and submitted to the Contracting Officer (CO), Program Manager (PM) and Contracting Officer’s Representative (COR) within five working days when changes are made thereafter. After acceptance of the QCP, the contractor shall receive the CO’s acceptance in writing of any proposed change to their quality control system. The contractor shall ensure that all deliverables have gone through the QCP as evidenced by submission of deliverables to the CO and COR.
4.1.8 Quality Assurance Surveillance Plan (QASP): The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards shall be applied, the frequency of surveillance, and the minimum acceptable defect rate(s). Please see Part 9 of PWS for performance metrics.
PART 5
INSPECTION AND ACCEPTANCE
5.0 INSPECTION AND ACCEPTANCE PROCESS
5.1 All written deliverables, including training materials, shall be quality products that are complete and thorough; structured in a clear, logical fashion; and in a proper, accepted writing style.
5.2 Written deliverables shall be accompanied by a cover letter, signed by an authorized representative of the company such as Leadership (CEO, PM, etc) to affirm that the deliverable has been through necessary review and quality control procedures.
5.3 If, for any reason, a deliverable cannot be delivered within the scheduled time frame: The contractor shall notify the COR/CO with cause of delay, the proposed revised schedule, and the impact on the overall program. The CO shall approve as to if the delay is acceptable and shall modify the contract.
5.4 The Contractor shall submit the documentation to the Government. This will be addressed at the task order level so the Government can review and the CO can approve. Without the approval, the deliverable is considered not delivered.
PART 6
OPERATING ENVIRONMENT (TECHNOLOGY)
6.0 OPERATING ENVIRONMENT (TECHNOLOGY)
The government shall not be providing any hardware or software for this project / program. The software is a web-based application. As this is an online resource, it is imperative that the provider be prepared to demonstrate compliance with the Risk Management Framework (RMF) as detailed by the National Institute for Standards in Technology (NIST), Department of Homeland Security (DHS) and USSS Policy. Specifically, all providers must be FedRAMP certified for baseline control baselines and vetted by the USSS Office of the Chief Information Security Officer (OCISO). The provider must be able to share all associated security plans and certification documents appropriate to the FedRAMP requirement. Baseline controls for all external information systems minimally includes:
| AC – 1 |
| 7.0 Access Control Policy and Procedures |
| 8.0 AC – 2 |
| 9.0 Account Management |
| 10.0 AC – 3 |
| 11.0 Access Enforcement |
| 12.0 AC – 5 |
| 13.0 Separation of Duties |
| 14.0 AC – 6 |
| 15.0 Least Privilege |
| 16.0 IA – 1 |
| 17.0 Identification and Authentication Policy and Procedures |
| 18.0 IA – 2 |
| 19.0 Identification and Authentication (Organization Users) |
| 20.0 IA – 4 |
| 21.0 Identifier Management |
| 22.0 IA – 8 |
| 23.0 Identification and Authentication (Non-Organizational Users) |
| 24.0 PS – 4 |
| 25.0 Personnel Termination |
| 26.0 PS – 5 |
| 27.0 Personnel Transfer |
| 28.0 SA – 9 |
| 29.0 External Information System Services |
The government requires that all systems utilize strong, multifactor authentication. This solution must therefore be HSPD – 12 compliant.
The government requires that along with satisfying the requirements listed in the above paragraph, the vendor must adhere to all privacy matters as dictated by the DHS and USSS Privacy Officers. As this capability shall collect PII data from the public adherence to DHS and USSS policy regarding privacy matters is paramount.
PART 7
ORDERING INSTRUCTIONS
7.0 TASK ORDER ORDERING INSTRUCTIONS
7.1 Task Order Instructions
Each Request for Task Order Proposal (RTOP) shall be requested from the Contractor. The contractor shall provide the pricing and statement of requirements for each task order. This shall be done in a timely manner, no longer than 3 business days. The Contractor shall provide any assumptions. The pricing shall be in accordance with the IDIQ pricing.
The Government has a template for the task order form when requesting quotes. See Attachments 4 and 5.
Each response shall have the following information provided by the Contractor:
1. Date of response and period of effective date for the quote
1. A quote that is in accordance with the pricing in the IDIQ.
1. Itemized listing of services/supplies to facilitate the task order.
1. Any assumptions and/or risks the Contractor sees with the task order.
1. Ensure that all travel, if required, is in accordance with the FTR.
PART 8
S…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .