Attachment 1 Performance Work Statement.pdf

PDF 221 KB Posted

Attached to
Job Access with Speech (JAWS) Scripting Services Federal contract opportunity
Solicitation number
HQ042322Q0069
Issued by
Defense Finance and Accounting Service

View the file

Other files for this federal contract opportunity

Other files attached to Job Access with Speech (JAWS) Scripting Services, newest first.
File Type Posted
Attachment 2 Pricing Worksheet_Amended.xlsx XLSX spreadsheet
Synopsis Solicitation Amd1.pdf PDF
RFQ Questions and Responses.pdf PDF
Attachment 4 Wage Determination - Cuyahoga Cty.pdf PDF
Attachment 5 Past Performance Information Sheet.docx DOCX document
Attachment 3 Clause Fill-Ins.docx DOCX document
Synopsis Solicitation.pdf PDF
Attachment 4 Wage Determination - Franklin Cty.pdf PDF
Attachment 2 Pricing Worksheet.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS) Defense Finance and Accounting Service (DFAS)

Jobs Access with Speech (JAWS) Scripting Services

1.0 DESCRIPTION OF SERVICES:

The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform JAWS Scripting Services.

2.0 BACKGROUND:

Section 508 of the Rehabilitation Act of 1973 requires Federal agencies to make Electronic and Information Technology (EIT) accessible to people with disabilities. The law (29 USC 794d) applies to all Federal agencies when developing, procuring, maintaining, or using EIT.

JAWS satisfies agency obligations under Section 508 by providing visually impaired employees an alternative means to information and data. Developed by Freedom Scientific, JAWS is a client side software solution that is a screen reader for computer users whose vision loss prevents them from seeing screen content or navigating with a mouse. JAWS provides speech and braille output to enable the visually impaired to hear or read text that is displayed on a computer monitor.

JAWS comes preconfigured and works effectively without any special adjustments for standard commercial software applications. However, for proprietary databases, JAWS must be customized using a scripting language to create a custom speech configuration. JAWS Scripting Language is a proprietary programming language that allows the interoperation of the JAWS screen-reading program with proprietary databases. It acts as an application-programming interface and allows users to combine JAWS scripting, Microsoft Active Accessibility scripting, and document object model scripting. It is a compiled language allowing for source code protection. It allows employees to use content not otherwise accessible with JAWS only.

3.0 SCOPE:

DFAS currently has three visually impaired employees leveraging JAWS scripting language. The number of employees utilizing JAWS may increase or decrease at any time.

The version of JAWS being leveraged within DFAS does not support mission performance due to incompatibility issues with the EDM and AVAYA1X software. This incompatibility has resulted in visually impaired employees not being able to access and/or fully utilize Microsoft Office, Microsoft Edge, Microsoft Outlook, Microsoft Teams, Adobe Connect, Adobe Reader, and Defense Agencies Initiative (DAI) Oracle Time and Labor (OTL) timekeeping system. This list is not all-inclusive.

4.0 OBJECTIVE:

The objective of this PWS is to procure the services of a scripter to customize the JAWS application in order to provide section 508 accessibility standards to all visually impaired employees. The scripter shall customize the JAWS application by configuring required functions based on each employee's job specification and essential tasks. In addition to the customization process, the contractor shall also provide training.

5.0 GENERAL REQUIREMENTS:

The contractor shall:

• Comply with all appropriate Federal and DoD architectures, programs, standards, and guidelines.

• Acquire and maintain all necessary commercial, open source, and third party hardware and software agreements to include licenses, warranties, and commercial maintenance agreements.

• Provide all hardware and software needed to host, manage, and integrate the solution.

• Maintain the licenses and permission from Freedom Scientific to manipulate JAWS software.

• Have a solid understanding of accessibility evaluation tools and methods.

• Have a solid understanding of user requirements for people with visual disabilities requiring nonvisual access, computing support, and JAWS customization.

• Have a solid understanding of accessibility verification tools, assistive technologies, and accessibility standards.

• Have experience with Avaya1X, EDM, and DAI OTL and have a solid understanding of the accessibility benefits and obstacles these systems provide.

• Have knowledge of Web Content Accessibility Guidelines (WCAG) and 508 compliance.

6.0 PERFORMANCE REQUIREMENTS:

6.1 Task 1: Requirements Analysis and Assessment

The Contractor shall:

• Conduct an analysis to identify “as-is” and “to-be” processes.

• Coordinate with the DFAS user and DFAS software Program Managers as necessary.

• Collect the relevant data, information, and documentation to formulate and implement a solution or recommendation for interface between JAWS and Avaya1X, EDM, DAI OTL, and other systems as applicable.

• Perform accessibility audits of the required applications using accessibility testing tools and JAWS/assistive technology products.

• Write audit reports, describing accessibility issues and propose a plan of recommendation to resolve the identified issues.

Deliverable: The contractor shall provide a written assessment report outlining scripting recommendations and any additional customizations. The written assessment report will be based on a level of effort to achieve the DFAS user’s goals. The report shall contain the projected number of hours required to develop, test, and deploy scripts, an evaluation of the DFAS user’s screen reading capabilities, and any recommended training for the DFAS user.

The report shall be provided to the Contracting Officer Representative (COR) and Program Manager (PM) within 5 business days of the completion of the assessment.

6.2 Task 2: Software Development/Scripting

The Contractor shall:

• Gather system requirements, develop, design, integrate and test software/scripting modules and field the software/scripting for use by the DFAS user.

• Ensure that the software/scripting is free from all computer viruses, worms, time-outs, time bombs, back doors, disabling devices and other harmful or malicious code. Notify the COR and PM within 30 minutes of any discovered malicious activity.

• Ensure the JAWS scripting solution is installable and operable.

• Test and evaluate potential software/scripting capabilities and enablers.

• Develop a Software Assurance Validation Document to address the application(s), operational capabilities, functional requirements, system requirements, and Certification and Accreditation (C&A) security requirements. The application(s) source code shall be made available to COR and PM for a code review and analysis as required.

• Provide accessibility support to developer teams, either through consultancy or through contributing code.

• Provide accessibility support/training to DFAS employees for using Microsoft Teams, Adobe Connect, Microsoft Outlook, Microsoft Edge, and other systems as applicable.

Deliverable: The contractor shall provide a Software Assurance Validation Document. The document shall address the application(s), operational capabilities, functional requirements, system requirements, and Certification and Accreditation (C&A) security requirements. The document shall address fully operational capabilities of interface between the current version of JAWS and the current version of Avaya1X, EDM, DAI OTL, and other systems as applicable. The document and application(s) source code shall be provided to the COR and PM within 5 business days of completion of development.

6.3 Task 3: User Acceptance Testing (UAT)

• Conduct User Acceptance Tests to validate that fixes, patches, upgrades or new developments meet functional and system requirements and are ready for production deployment.

• Provide testing to ensure systems proponents are Section 508 compliant as required under the Rehabilitation Act (29 U.S.C. 794d).

Deliverable: The contractor shall provide a report outlining the work performed. The report shall address DFAS user acceptance. The report shall be provided to the COR and PM within 5 business days of completion of UAT.

6.4 Task 4: Maintenance and Sustainment

• Provide maintenance and sustainment for the continued optimal performance of the scripting and any customization to the interface between the current version of JAWS, Avaya1X, DAI OTL, EDM, and other systems as applicable.

• Provide services to allow for modifications to scripts to be made if changes to the offending program break current script functionality.

• Provide telephone consultation service. This service shall be available during regular working hours as listed in this PWS. This communication service shall be managed by a live person and not a recording service. If at the time of the initial call, a live person is not available, the contractor shall provide a voicemail box. The call back response time for all voicemails shall be no longer than two hours.

Deliverable: The contractor shall provide a report for any maintenance or sustainment work performed. The report shall contain full details of all maintenance and sustainment services provided. The report shall be provided to the COR and PM within 5 business days of completion of any maintenance or sustainment services.

7.0 PERIOD AND PLACE OF PERFORMANCE, AND WORK DAYS/HOURS:

7.1 Period of Performance

The period of performance is anticipated to be one base year and four one-year option periods.

7.2 Place of Performance

The contractor is permitted to provide remote services as applicable. If on-site services are required, the contractor shall be available to provide immediate services at the following DFAS sites:

DFAS Cleveland, 1240 E 9th St. Cleveland, OH 44199 DFAS Columbus, 3990 East Broad Street Building 21 Columbus OH 43213

DFAS reserves the right to request services at additional DFAS sites as needed.

Site visits shall be coordinated with the COR at least 48 hours in advance.

7.3 Hours of Operation

The contractor shall perform services during normal business hours. Normal business hours are 0600 to 1800 Eastern Time, Monday through Friday, except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. A full list of Federal Holidays can be found at OPM.gov.

Any labor to be performed outside of normal business hours or during Federal holidays must be approved in advance by the COR and PM. Reimbursement of overtime rates is not authorized.

8.0 PERSONNEL STAFFING APPROACH:

When hiring personnel, the contractor shall keep in mind that the stability and continuity of the work force is essential. The contractor shall at all times maintain an adequate work force for the uninterrupted performance of all tasks defined within this performance work statement.

8.1 Labor Category and Estimated Labor Hours

# of Staff Labor Category Estimated

Labor Hours Base Year

Estimated Labor Hours

Option Periods 1 JAWS Scripter 200 80

The hours listed above are estimated. The Government estimates but does not guarantee these hours. The Government is only responsible to pay for services provided. Unused quantities shall be considered cancelled and will be deobligated at no additional cost to the Government.

8.2 Required Skillset

• Assess websites and applications for accessibility barriers

• Identify, use, and improve tools and techniques for overcoming accessibility barriers

• Develop code for navigation for multiple audiences

• Conduct usability assessments and testing of websites and applications

• Collaborate with agency staff to ensure systems are usable and accessible

• Ability to work in a distributed team environment

• Performs accessibility inspections

• Write technical reports or documentation

• Identify and resolve accessibility barriers

8.3 Systems Information

The contractor shall work within the confines of Government provided software tools as well as within the confines of software distribution via a desktop management service. The contractor’s resources shall include the below identified programming languages as well as similar experience with the DAI. This list is not all-inclusive.

• Oracle

• Microsoft Teams, Edge, Outlook

• Adobe Connect

• HTML

• Proficient in Microsoft SQL Server 2012/2014/2016/2017

• Knowledge of data governance, data management, data modeling, data cleansing, data extraction and transformation, data analysis, data migration, data integration and data mapping

9.0 GOVERNMENT FURNISHED PROPERTY, SPACE, FACILITIES:

10.1 On-site at a DFAS location

All facilities and services (i.e. computer products: PCs, printers, telephones, software and Government provided developmental platforms) will be furnished by DFAS for use within the

DFAS site. The DFAS site location will furnish office space, desks, chairs, and supplies for Contractor personnel working on-site. The office space, supplies and equipment will be of the type ordinarily found at the DFAS site. The furnishings will be of the type used by personnel at in the DFAS site.

9.2 Remote

All computer software required to complete the tasks will be made available to the Contractor.

Defense Information Systems Agency (DISA) is the DFAS Standard for software/hardware. All computers connected at DFAS sites must be configured under DMI. Vendor’s employees may be provided standard issue DFAS laptops. Only property of the Government shall be connected to the DFAS Enterprise Local Area Network (ELAN). For Contractor personnel working at alternate locations agreed upon by DFAS and the Contractor, logon ID’s will be provided to access to the required platforms. The Contractor shall provide the access network connection via the Pulse Secure for any personnel not working at the physical DFAS site.

The contractor shall have an acceptable Property Management System, per DFARS 252.245- 7003 and 52.245-1(f) in place in order to be able to receive GFP. The Contractor shall provide sufficient information as part of their offer in order for the CO to determine the Contractor’s Property Management System is acceptable.

GFP on this contract will be in the form of DFAS formatted laptops in which the contractor will need to remove the laptops from a Government Controlled Facility in order to perform the tasks that are required on the contract at an alternate location. Receipt and return of GFP will be created and tracked through the GFP Tool.

9.3 Configuration Support

Contractor employees shall only connect government owned workstations, laptop computers, software and printers, including computers connected remotely to the DFAS Enterprise Local Area Network (ELAN). This requirement is to protect the ELAN from the spread of malicious logic (viruses and Trojan Horse programs) and to protect sensitive but unclassified (SBU) information from being compromised. Contractors performing duties in a DFAS facility will be provided with DFAS owned workstations and printers.

10.0 TRAVEL

Whenever possible services for JAWS Scripting shall be provided remotely to benefit travel cost.

The contractor may be required to travel to field sites, conferences, and other meetings in performance of this contract. Contractor travel is at the convenience of the Government. All travel shall be performed in accordance with FAR 31.205-46 and reimbursement shall not exceed the amount allowable as specified in FAR 31.205-46. Actual expenses are limited in accordance with FAR 31.205-46. All Contractor travel shall be approved by the COR in advance of actual travel and shall not exceed the funding amount in accordance with the contract. Authorization requests shall be submitted NLT 5 working days prior to the proposed travel start date.

Reimbursement for travel in and about the local area is not authorized. For the purposes of this contract, local travel is defined as within 50 miles of the contractors’ local office, normal duty station, or temporary work site. No travel or subsistence charges for travel time shall be charged for work performed within this 50-mile radius. Under no circumstances will costs be reimbursed for travel performed for personal convenience and daily travel to and from the normal work site, and that includes parking expenses. Travel authorization requests shall include the following:

• Title, purpose/objective of trip

• Itinerary/Date, proceed date, return date (window)

• Location

• Proposed meeting/activities agenda

• Number of contractor participants

• Mode of travel and cost

• Estimated costs

10.1 Travel Arrangements

Performance under this Contract may require travel by Contractor personnel. If travel is required, the Contractor shall be responsible for making all needed arrangements for their personnel.

10.2 Travel Policy

The Government will reimburse the Contractor for allowable travel costs incurred by the Contractor in performance of the contract and determined to be in accordance with FAR subpart 31.2, subject to the following provisions: Travel required for tasks assigned under this contract shall be governed in accordance with rules set forth for temporary duty travel in the FAR 31.205-

46. Overhead profits and other costs are not an allowable travel cost for this requirement. The contractor will only be reimbursed for allowable direct labor costs.

10.3 Travel Accountability

The Contractor shall be responsible to account for travel funds expended and for inclusion of the cost in the monthly report to DFAS indicating travel expenditures for the preceding reporting period with a summary of task-to-date and indicating balances remaining.

10.4 Relocation Costs

Relocation costs and travel costs incident to relocation are not allowable and shall not be reimbursed.

10.5 Government Owned Vehicles

If not restricted by other regulations or policy, contractors will be allowed to travel in government-operated conveyances at their own risk. US Federal Government takes no liability for personnel travelling in government owned vehicles.

11.0 PROPRIETARY INFORMATION

The Contractor shall consider all work performed under this order as proprietary to DFAS and shall not release or divulge any information/data to any other party without explicit written permission from the COR or PM.

12.0 SECURITY REQUIREMENTS:

Personnel Security Investigation (PSI) Requirements. Contractor personnel working on this contract will require a favorably adjudicated Tier 3, or equivalent Noncritical Sensitive (formerly IT-II) level or higher investigation. No access to classified information is required. IAW standard DFAS Personnel Security policy, ALL incoming contractors, regardless of whether they possess a favorably adjudicated Noncritical Sensitive (formerly IT-II) or higher investigation, must submit a Declaration for Federal Employment (OF-306), and a new set of fingerprints* to the COR, who will submit these forms with a Contractor Request for Investigation (CRI) (DFAS Form 9035) to DFAS Personnel Security. DFAS Personnel Security will review all submitted documentation to validate whether contractor personnel meet personnel security requirements to perform work on the contract or if a new background investigation is required.

*New fingerprints are not required if any of the following apply:

The person has been fingerprinted for the Office of Personnel Management (OPM) within the past 30 days;

The person is currently undergoing a background investigation, or reinvestigation, by OPM or any other Federal agency;

The person has a background investigation currently being adjudicated by the Department of Defense Consolidated Adjudications Facility (DoD-CAF) or another CAF;

The person has been favorably adjudicated within the past 30 days by the DoD CAF or a CAF from any other Federal agency; or

The person is coming directly from another DoD agency, with no break in service. This includes any of the military branches as well as the U.S. Coast Guard; however, service members in an inactive reserve status are not included.

The Personnel Security Office otherwise determines that no new fingerprints are required.

Security Requirements. Contractor personnel shall follow the security and training requirements in DFAS 2000.1-I, “Force Protection Mission,” DoDM 5200.01, Volumes 1-3, “DoD Information Security Program,” DoDI, 5200.48, “Controlled Unclassified Information,” DFAS 5200.1-I, “Information Security Program,” DFAS 5200.8-I, “Physical Security Program,” and DFAS 5200.10-I, “Counter Insider Threat Program.” Contractor personnel shall follow all host security requirements in accordance with Part 117 of Title 32, Code of Federal Regulations;

paragraph 117.16. The contractor shall immediately report any occurrences of violation of stated regulations to the Contracting Officer (CO), Contracting Officer Representative (COR) and the Personnel Security Office.

DFAS Personnel Security Incident Reporting Requirements, the National Industrial Security Program and Due Process as it Relates to DFAS Contractor Personnel. The National Industrial Security Program (NISP) is a partnership between the federal government and private industry to safeguard classified information and Controlled Unclassified Information

(CUI).

Executive Order 12829, as amended, "National Industrial Security Program", further amended by Section 6 of E.O. 13691, was established to achieve cost savings and to ensure that industry safeguards the classified information with which it is entrusted while performing work on contracts, programs, bids, or research and development efforts while working for United States Government.

It is important to note that personnel employed as contractors for DFAS are not covered under the National Industrial Security Program (NISP) and are exempt from the provisions of 5 C.F.R.

731. This means that DFAS contractor personnel involved in an incident that potentially violates one or more of the National Security Adjudicative Guidelines found at https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-Adjudicative-Guidelines- U.pdf , are not entitled to Due Process rights normally afforded to federal civilian employees and those personnel covered under NISP; more specifically, Personnel Security may suspend or revoke their access to DFAS IT systems, sensitive information and/or DFAS facilities.

Incident Reporting Requirements.

Whenever a DFAS contractor displays conduct, or is involved in any incident, which is in violation of any of the thirteen National Security Adjudicative Guidelines*, a report shall be made immediately following the incident, or as soon as practicable thereafter, to their DFAS civilian supervisor and the supervisor, if there is one, of the area to which they are assigned, the COR, and in all cases, the Personnel Security Office. Reporting to Personnel Security may be made by phone to (317) 212-7888, by email to dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil, or, in the case of personnel physically located at DFAS Indianapolis Center, in person to the Personnel Security Office located on the third floor center hallway at Column 320T.

All incidents will be investigated by Personnel Security and, depending on the date of the subject’s most recent investigation, may need to have an updated background investigation initiated. Those that do not require a new investigation will have all relevant information regarding the incident forwarded to the Department of Defense, Consolidated Adjudications Facility (DoD-CAF) for review and re-adjudication.

*The thirteen National Security Adjudicative Guidelines are:

1. GUIDELINE A: Allegiance to the United States;

2. GUIDELINE B: Foreign Influence

3. GUIDELINE C: Foreign Preference

4. GUIDELINE D: Sexual Behavior

5. GUIDELINE E: Personal Conduct

6. GUIDELINE F: Financial Considerations

7. GUIDELINE G: Alcohol Consumption

8. GUIDELINE H: Drug Involvement and Substance Misuse https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-Adjudicative-Guidelines-U.pdf https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-Adjudicative-Guidelines-U.pdf mailto:dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil

9. GUIDELINE I: Psychological Conditions

10. GUIDELINE J: Criminal Conduct

11. GUIDELINE K: Handling Protected Information

12. GUIDELINE L: Outside Activities

13. GUIDELINE M: Use of Information Technology

Some Examples of Incidents That Require Reporting to Personnel Security:

a. An arrest for any criminal offense, not including minor traffic violations, by any law enforcement agency. This does include the traffic offenses of Driving Under the Influence of Alcohol or Drugs, and Reckless Driving;

b. Violation of any court order;

c. Delinquencies on any debt for 180 days or longer;

d. Federal, State or Local tax issues or delinquencies;*

e. Delinquencies on any Federal debt;*

f. Child Support delinquencies;

g. Filing for Chapter 7 or Chapter 13 bankruptcy in any Federal Bankruptcy Court;

h. Civil judgements;

i. Having a close personal friendship with a Foreign National (person from a foreign country) with regularly occurring contact;

j. Being approached by a person know to be, or suspected to be, working as an agent of a foreign government or terrorist organization, or any other person, who seeks any information about DFAS, the Department of Defense, or the U.S. Government, especially if the person offers money or something of value to the contractor employee; and

k. Ownership of property or financial accounts in a foreign country.

It should be noted that persons delinquent on Federal debt of any kind may not obtain or maintain favorable personnel security adjudication be considered for a contractor position with DFAS unless they can provide documentary proof that a payment plan has been established with the government agency to whom the debt is owed, and that regularly recurring payments are being made. Contractor personnel who cannot obtain and maintain a favorable personnel security adjudication may not have access to the government data, facility, and equipment required under the contract.

NOTE: This list does not cover every potential incident or offense; any incident in which a contractor is involved and a question exists as to whether it should be reported, should report the incident to Personnel Security, who will then determine if further action is warranted. Failure to report an incident is, in and of itself, an incident involving personal conduct, and may, in some cases, be more serious than the original incident.

Foreign Travel by DFAS Contractor Personnel. Official and Unofficial (Personal) Travel:

Official U.S. Government Business: persons employed as contractor employees with DFAS, to include those with Noncritical Sensitive (formerly IT-II) access, Critical Sensitive (formerly IT- I) access, access to critical program information (related to Research, Development, Test, and Evaluation), sensitive compartmented information, and/or special access program information, in accordance with DoD Directive 5240.06, are required to complete a DFAS Form 9133, Notification of OCONUS Travel, not less than fourteen (14) calendar days prior to the scheduled travel. One copy shall be sent the DFAS Personnel Security group box at dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil and one copy shall be turned into the Site Security/Force Protection Office of the DFAS site where they are stationed.

Upon receipt of the completed Form 9133, the Site Security/Force Protection Office will contact the contractor employee and schedule a Foreign Travel briefing. Immediately prior to travel, contractor employees will check with the State Department at https://travel.state.gov/content/travel/en/traveladvisories/traveladvisories.html.html for any travel advisories for the country or region being traveled to and take the appropriate steps to ensure their safety for any location covered by a travel advisory or warning.

Security Education and Training. Contractor personnel shall receive initial, continuous and refresher security education training in accordance with DFAS 2000.1-I, DoDM 5200.01, Volume 3, “DoD Information Security Program – Protection of Classified Information,” DoDI 5200.48, and DFAS 5200.1-I. Contractor personnel shall also complete all required contractor training requirements identified in this Statement of Work/Performance Work Statement.

Access To, Accountability For, and Safeguarding Of Controlled Unclassified Information (CUI).

The DFAS manager of the requiring office will determine what CUI contractor personnel are given access to. CUI may not be disclosed to contractor personnel unless required for contract performance. Contractor personnel shall safeguard CUI in accordance with DoDI 5200.48 and DFAS 5200.1-I. The sponsoring DFAS activity will provide storage capability for all CUI required for contract performance.

Installation Entry and Common Access Card (CAC) Requirements. The Contractor shall comply with established security procedures for entering government installations and facilities.

Contractor employees shall be required to obtain and wear identification (ID) badges that will permit access into the facility.

All contractors who require unescorted access to DFAS facilities will be required to obtain a DoD CAC. Contractor shall work with the assigned DFAS Contracting Officer Representative (COR)/Trusted Agent (TA) to obtain a CAC using the Trusted Associate Sponsorship System (TASS). Under no circumstances will a CAC be issued to any person unless that person has been cleared by the DFAS Personnel Security Office to work on the contract.

All CACs and badges issued to Contractor personnel are Government property and must be returned to the assigned DFAS COR/TA upon departure from the program or at the conclusion of the contract, whichever comes first. Contractors whose CAC is lost or stolen must report the loss as soon as possible to the assigned DFAS COR/TA and present documentation that the CAC is missing and describing the circumstances under which the loss occurred. The assigned DFAS COR/TA will follow agency CAC procedures in order to issue a new CAC.

https://travel.state.gov/content/travel/en/traveladvisories/traveladvisories.html.html

The CAC contains personally identifiable information (PII) and must be treated as a controlled item. Contractors’ must not share their CACs and passwords with any other staff members. The assigned DFAS COR/TA will report any violation or suspected violation to the Contracting Officer and DFAS Trusted Agent Security Manager (TASM). Any violators will be temporarily or permanently removed from the project. If a Contractor has a CAC issued from a previous engagement with another agency that CAC must be returned to that agency before issuance of a new CAC.

Training. DoD Mandatory Contractor Personnel Training Requirements: The contractor shall direct that its employees performing under this contract complete the annual mandatory training in accordance with the DoD mandate identified for each training module.

Contractor personnel working at a DFAS site who require a Common Access Card (CAC), or contractor personnel working remote via VPN, need to complete the following training modules within 30 days after receipt of CAC, (note for Cyber Awareness Challenge Module 003, completion of this module is required prior to requesting a new DFAS network or VPN account), as a precondition for continued attendance and/or network access.

In addition, these modules shall be completed annually to retain accessibility. Noncompliance will negatively impact contract performance and lead to the loss of CAC and/or network access for contractor personnel.

Continuity of Operations and Crisis Management Organization. Contractor personnel will take the training through the DFAS Portal upon receipt of Network access.

Cyber Awareness Challenge. Completion of this module is required prior to requesting a new DFAS network or VPN account. For contractor personnel unable to access the DFAS Portal, the same training is available at:

https://public.cyber.mil/training/cyber-awareness-challenge/

Upon completion of the training Contractor personnel shall maintain a copy of the training certificate in PDF, submit a copy to the Contracting Officer Representative (COR), attached to the request for network access as proof of completion.

Keeping DFAS Safe: Physical Security, Information Security, and Personnel Security.

Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.

Antiterrorism Level One. All contractor personnel shall take this training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:

https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf https://public.cyber.mil/training/cyber-awareness-challenge/ https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf

All other contractor personnel shall take the training through the DFAS Portal upon receipt of network access.

Privacy Act (PA) and Personally Identifiable Information (PII). Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.

Combating Trafficking in Persons (CTIP) Awareness Training. All contractor personnel shall take this training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:

http://ctip.defense.gov/

All other contractor personnel shall take the training through the DFAS Portal upon receipt of network access.

Records Management. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.

Insider Threat (InT) Awareness Training. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.

DoD Mandatory Controlled Unclassified Information (CUI) Training. All contractor personnel shall take this CUI training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:

https://securityawareness.usalearning.gov/cui/index.html

All other contractor personnel will take the training through the DFAS Portal upon receipt of network access.

NOTE: This list of training requirements is subject to change.

Training Time. The average estimated time for completion of each training module is approximately one hour or less. The Keeping DFAS Safe: Physical Security, Information Security, and Personnel Security training module will take approximately 90 minutes to complete.

Training Methods. Network Training. Network training through the DFAS Portal is the required method for those Contractor personnel who have an existing DFAS network account.

Web-based Training. All contractor personnel are required to take the following web based training: Cyber Awareness Challenge (When system/network access is required), Antiterrorism Level One, Controlled Unclassified Information Training, and Combating Trafficking in Persons http://ctip.defense.gov/ https://securityawareness.usalearning.gov/cui/index.html

(CTIP) Awareness Training. If an individual does not have network access through the DFAS Portal, they can complete the training through a DoD authorized Web source. All other contractor personnel shall take the training through the DFAS Portal upon receipt of DFAS network. The contractor personnel shall retain a PDF copy of the “Certificate of Completion” or a “screen shot” with the date of the completion of the training. The COR will maintain a file for proof of completion.

Contractor personnel who do not require network access but require unescorted access into a DFAS facility shall receive applicable security training through the site Force Protection Office.

To identify Site Force Protection Officers at each DFAS location consult the Agency Force Protection Portal Page:

https://dfasportal.dfas.mil/ddss/force_protection/Pages/SiteSpecificForceProtectionSecurityServi ces.aspx

The prime contractor official representative shall provide the COR with a group list of its personnel requiring completion of the training. The COR will submit the ‘group list’ to the Site Force Protection Officer to schedule training. As a reminder, the prime contractor official representative shall submit this group list of names within 30 days after contract award.

Requests for individual training shall be justified in writing and submitted to the COR for evaluation. Special arrangements will be determined by the Site Force Protection Officer, other training Module POCs and the COR.

Interaction with Contractor Personnel. The COR shall forward questions or concerns directly to the prime contractor official representative who is directly responsible for managing its own employees/subcontractor personnel.

The prime contractor official representative shall coordinate with the COR a training schedule without causing undue delays to contract performance.

The prime contractor official representative (including subcontractor’s personnel when applicable) shall provide the COR, within 30 days after contract award/exercise of an option, a written report identifying:

- Contractor employees required to take the training,

- Contractor employees who have completed the training and

- Contractor employees who are delinquent.

Contractor personnel shall direct their training questions or concerns to their contractor management chain and/or company representative.

https://dfasportal.dfas.mil/ddss/force_protection/Pages/SiteSpecificForceProtectionSecurityServices.aspx https://dfasportal.dfas.mil/ddss/force_protection/Pages/SiteSpecificForceProtectionSecurityServices.aspx

Monthly Training Status Reports. The prime contractor official representative shall submit a monthly status update to the COR, identifying the initial and annual training status of all contractor personnel.

Training Point of Contact (POC). The COR is the POC for the Contractor. The Contractor shall provide regular training updates to the COR, and keep an updated registry to assure employees who come on board at any time in the contract life have completed all required training.

File details come from the government source that posted it. Updated .