Attachment 1- PWS.pdf

PDF 540 KB Posted

Attached to
Training Support Services Federal contract opportunity
Solicitation number
70CMSW23R00000020
Issued by
Immigration and Customs Enforcement

About this file

This document outlines requirements for a performance work statement for training support services with the U.S. Immigration and Customs Enforcement. Key details include:

  • The contractor shall provide service support personnel to support the Strategic Development Unit's law enforcement support mission, including acquisition, receiving, issue, storage, and shipping of field equipment; armory services; and technical testing and evaluation of firearms and law enforcement equipment.

  • Tasks required include program management, training administrative support, administrative task support, vehicle fleet management, logistics and warehouse management, armory operations, and range support operations. Recommended contract personnel positions include a program manager, instructional designer, technical writer, logistics specialist, and administrative specialist.

  • The period of performance is a one-year base period plus four one-year option periods. The primary place of performance is government facilities at Fort Moore, Georgia.

  • The contractor must implement quality control procedures and participate in meetings, reviews, and audits. Several reports and deliverables are required on topics such as progress, instructor materials, and an annual curriculum review.

View the file

Other files for this federal contract opportunity

Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Office of Acquisition Management U.S. Department of Homeland Security 500 12th Street, NW Washington, DC 20536

IMMIGRATION AND CUSTOMS ENFORCEMENT

PERFORMANCE WORK STATEMENT

Training Support Services

Office of Firearms and Tactical Programs

Strategic Operations and Development Division Strategic Development Unit (SDU)

PURPOSE

The U.S. Immigration and Customs Enforcement (ICE), Office of Firearms and Tactical Programs (OFTP), Strategic Development Unit (SDU) requires a contractor to provide service support personnel to support the SDU’s rapidly evolving law enforcement support mission.

1. BACKGROUND

The Strategic Development Unit (SDU) in Fort Moore (formerly Benning), GA. provides a multitude of services to ICE to include acquisition, receiving, issue, storage, and shipping of field equipment, armory services to include inspection, repair, building, maintenance, and disposal of agency owned firearms. The unit also conducts technical testing and evaluation of firearms and law enforcement equipment to ensure that all products issued to the field are the best available. The Strategic Development Unit located at Fort Moore supports the Homeland Security Investigations Strategic Operations & Development Division (SODD), and the Enforcement and Removal Operations Strategic Operations & Analysis Division (SOAD). These units are responsible for developing and delivering post-basic, advanced, specialized, and use of force related training on-site at Fort Moore or the field.

The units also provide subject matter expertise in use of force related queries. The training provided by these units certifies instructors for firearms, defensive tactics, special response team leaders, and members, and field.

2. PERIOD OF PERFORMANCE

Base year plus four option years as follows:

Period Period of Performance

Base (including one-month transition period) 1 August 2023 – 31 July 2024 Option Period 1 1 August 2024 – 31 July 2025 Option Period 2 1 August 2025 – 31 July 2026 Option Period 3 1 August 2026 – 31 July 2027 Option Period 4 1 August 2027 – 31 July 2028

3. PLACE OF PERFORMANCE

The primary place of performance will be the Government facilities assigned to the Department of Homeland Security, Immigration and Customs Enforcement, Tactical Operations Unit at U.S. Army Garrison, MCoE, Fort Moore, Georgia. Primarily, work will be conducted on Fiske Range Complex at Sightseeing Road in Fort Moore, Georgia. However, there will be required visits at the ICE Campus, U.S. Department of Homeland Security specifically the administration building #234, at 6760 Upton Avenue, Fort Moore, Georgia.

4. HOURS OF OPERATION

Contractor employees shall generally perform all work between the hours of 7 a.m. and 7 p.m. EST, Monday through Friday (except Federal holidays). This range for performance of hours does not mean that the contractor employee(s) will work twelve hours shifts. It just means that the work performed would occur during a designated shift within these hours of operation. However, there may be occasions when Contractor employees shall be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this SOW.

5. TASKS

5.1. Program Management / Team Lead: All activities to support successful execution of the contract to include but not limited to:

5.1.1. Supervise and provide professional guidance to all Contract personnel.

5.1.2. Work with OFTP management to identify process improvements.

5.1.3. Produce and provide deliverables as required.

5.1.4. Work with Contract Officer Representative.

5.1.5. Evaluate performance results and recommend changes affecting short-term project growth and success.

5.1.6. Function as a technical expert across multiple project assignments.

5.1.7. Report contract cost data to the COR prior to invoicing.

5.1.8. Arrange and get approvals for contract employee travel.

5.1.9. Plan and lead major assignments.

5.2. Training Administrative Support:

5.2.1. Evaluate training by observing, analyzing, reporting, and making recommendations for improvements.

5.2.2. Develop, format, revise training materials such as lesson plans, curriculum, and other related documents.

5.2.3. Organize and maintain training material for accurate and timely retrieval.

5.2.4. Conduct an annual curriculum review with instructor team leads and stakeholders to incorporate revisions into training documents.

5.2.5. Process course critiques for courses.

5.3. Administrative Task Support

5.3.1. Maintain office logs and files.

5.3.2. Search electronic and hardcopy files and databases for records, supportive data, and historical documents.

5.3.3. Prepare, write, and edit a variety of correspondence including letters and memos.

5.3.4. Prepare, create, format, and edit spreadsheets, presentations, and charts.

5.3.5. Support the development and implementation of a correspondence management process, to include templates and samples for letters, memorandums, directives, manuals, or other similar items.

5.3.6. Recommend the improvement and simplification of reporting requirements through analyses of data reported, analyses of the requirements and methods for preparation of reports and assuring that reporting requirements are met.

5.3.7. Ensure office equipment is maintained and functional, requesting updated or replacement

U.S. Department of Homeland Security equipment as needed.

5.3.8. Support property management initiatives during inventory actions.

5.3.9. Assist with tracking and maintaining associated files related to purchases.

5.3.10. Serve as a Hazardous Waste Manager for SDU.

5.3.11. Provide suggestions to increase performance efficiency and effectiveness and streamline processes.

5.4. Vehicle Fleet Management:

5.4.1. Support GSA fleet with a working knowledge of federal regulations and ICE policies.

5.4.2. Keep abreast of GSA Fleet regulations and policies.

5.4.3. Draft guidance and standard operating procedures for local vehicle use.

5.4.4. Coordinate maintenance/repairs/modifications to and replacement of vehicles.

5.4.5. Deliver and Pick up vehicles to and from maintenance.

5.4.6. Coordinate new vehicle requests.

5.4.7. Track, assign, and monitor vehicles for staff and student use.

5.4.8. Perform monthly GSA on-line mileage report.

5.4.9. Obtain and maintain Federal Fleet Manager Certification.

5.4.10. Perform other duties as assigned.

5.5. Logistics / Warehouse management:

5.5.1. Perform all shipping and receiving functions to include but not limited to receiving and processing incoming mail, documenting proper shipment receipt of operational training supplies and equipment including firearms and ammunition.

5.5.2. Manage inventory of assorted law enforcement equipment and course supplies using ICE’s inventory and tracking system (FACTS).

5.5.3. Transport, unpack, pack, inventory using proper equipment (ex: power machinery, hand truck etc.).

5.5.4. Perform inventory of serialized and non-serialized equipment and supplies.

5.5.5. Reconcile inventory management system with physical inventory.

5.5.6. Report losses of serialized material.

5.5.7. Coordinate new or replacement item requests.

5.5.8. Identify end of life replacement requirements for serialized and non- serialized material.

5.5.9. Provide routine and ad hoc reporting on all items.

5.5.10. Comply with all applicable federal, state, local policies and procedures.

5.5.11. Operate motor vehicles and any specialized equipment necessary to perform warehouse functions (ex: Class C Commercial Driver’s License).

5.5.12. Pull and package equipment and supplies for shipment to field offices.

5.5.13. Generate transfer documents in FACTS.

5.5.14. Obtain and maintain certification to package and ship hazardous materials.

5.6. Armory Operations: All activities to support successful execution of Armory operations to include but not limited to:

5.6.1. Perform firearm maintenance, repair and testing, and complete maintenance record documentation of weapons.

5.6.2. Perform periodic and random inspections of ICE authorized firearm systems including carbines, less lethal shotguns, pistols and other specialty launchers.

U.S. Department of Homeland Security

5.6.3. Perform inventories of all weapons, equipment and ammunition located at the armory.

5.6.4. Issue agency owned weapons, equipment and ammunition as needed.

5.6.5. Design and implement research programs regarding ammunition and related products for possible future law enforcement application.

5.6.6. Prepare test plans, reports and oversee the development of test protocol; continually seeks improved ways of evaluating accuracy, quality, and overall performance of firearms and ammunition, performing Sporting Arms and Ammunition Institute (SAAMI) pressure and velocity assessments, conducting tests, ensuring tests are valid, and writing comprehensive and detailed reports to support the validity of research findings along with the methodology utilized to meet the objectives of testing procedures.

5.6.7. Conduct tests and evaluations of sample firearms.

5.6.8. Recommend changes in design, mechanical operations, and serviceability based on extensive testing and research.

5.6.9. Evaluate new ammunition for ICE use.

5.6.10. Direct ballistic testing using conventional and unconventional firearms i and terminal ballistics.

5.6.11. Conduct tests and evaluations using industry standard 10% ballistic gelatin and high-speed imaging cameras and video recorders to measure kinetic energy distribution of projectiles and penetrating potential.

5.6.12. Conduct comprehensive technical evaluations of ammunition malfunctions.

5.6.13. Determine the most effective projectile using performance measures linked to terminal ballistics.

5.7. Range Support Operations: All activities to support successful range operations on Fort Moore and off-site training venues to include but not limited to:

5.7.1. Serve as range management point of contact with Fort Moore Range control to schedule, open, and close ranges daily to support training operations.

5.7.2. Maintain communications to Fort Moore Range Control via RIFMIS system or any designated system to schedule the ranges for utilization for safe and orderly range operations.

5.7.3. Manage an inventory of range materials, supplies, and equipment.

5.7.4. Prepare ranges, target systems, and training supplies for daily training missions.

5.7.5. Transport range ammunition and supplies to training locations.

5.7.6. Submit usage or expenditure reports.

5.7.7. Operate and Maintain range target systems.

5.7.8. Cleaning the range lanes of used and unused supplies, expended brass, cotton wads, and other training debris.

6. Recommended Contract Personnel Positions:

Position Title Program Manager (Team Lead) Instructional Systems Designer/ Curriculum Developer Technical Writer II Logistics Specialist GSA Fleet Specialist

U.S. Department of Homeland Security

Administrative specialist Parts Clerk Range Specialist Ammo Handler Gunsmith (Level I) Ballistic Engineer

7. PROGRAM MANAGEMENT

7.1. Provide Effective Program Management

7.1.1. The contractor shall provide all necessary personnel and services to meet the requirements.

A program management plan will be provided (see deliverable schedule) that describe how the program will be staffed and managed.

7.1.2. The contactor will maintain adequate staffing to support the requirements above and will demonstrate how the proposed staffing plan will meet the requirements of this SOW.

7.1.3. The contractor shall provide the COR and others as specified upon contract award a monthly list of all employees working on the contract to include title, start date, and clearance status.

7.2. Key Personnel

The following staff are considered Key Personnel and resumes are to be provided within 5 calendar days of contract award:

7.2.1. Program Manager (Team Lead)

• Master’s degree in a related field Business Administration/Management

• Minimum of 4 years of management experience

• Knowledge of federal and client orders and regulations related to management of government vehicles.

• Demonstrated experience in reading and understanding federal contracts and allocated funding and period of performance of contract line items (CLINs).

7.2.2. Administrative Task Support Personnel/GSA Fleet Manager

• Academic high school diploma or G.E.D

• Minimum of 5 years of office/clerical work experience to include vehicle management and financial management OR Associates degree plus 2 years of office/clerical work experience to include vehicle management and financial management.

7.2.3. Instructional Systems Designer/Curriculum Developer

• Bachelor of Arts or Bachelor of Science in Education Curriculum Development

• Minimum of 5 years of experience working with federal law enforcement to develop performance-based training in firearms and tactics.

• Instructional Systems Design Certification (optional).

• Ability to travel and spend up to 5 days a week each month at offsite SDU locations.

7.2.4. Technical Writer

• Bachelor of Arts or Bachelor of Science

• Experience in federal law enforcement training programs.

U.S. Department of Homeland Security

• Ability to develop, format lesson plans, curriculum, and related documents.

• Ability to travel and spend up to 5 days a week each month at offsite SDU locations.

7.3. The contractor may propose additional key staff positions. The contractor shall obtain written concurrence from the CO for appointment or replacement.

7.4. All staff will be required to complete a DHS background investigation, and other checks as required by state law.

7.5. The Service Provider must require all potential employees to complete and submit to OPR PSU the security application, to include fingerprinting, within 72 hours of eQip Initiation to ensure expedited processing by ICE. Document policies and procedures for all contract activities and provide to COR (see deliverable schedule).

7.6. Contractor Staff Training

7.6.1. The Contractor shall provide ICE with a training plan within 15 calendar days of contract award that will list the required training curriculum for all staff.

7.6.2. The Contractor shall ensure that all staff are trained prior to starting work on the contract.

7.6.3. The Contractor may provide the training or can use an organization approved by the COR to provide training.

8. MAINTAINING STAFFING LEVELS

8.1. At all times, the Service Provider shall maintain appropriate staffing levels to fully satisfy all requirements of this contract.

8.2. Contractor must have the infrastructure to recruit, onboard, train, and retain an adequate workforce to meet the requirements of this contract.

9. PRE-EMPLOYMENT SCREENING

9.1. The contractor shall conduct 100% pre-employment screening on all candidates prior to e-QIP initiation. The contractor shall certify in writing to the CO upon request, prior to commencement of work, that each employee performing under this contract has successfully completed a pre-employment screening that includes, at a minimum:

• citizenship check

• licenses/certifications and any irregularities

• credit worthiness

• criminal background

• education

• employment reference check

10. STANDARDS OF CONDUCT

10.1. The contractor shall obtain written certification from each of its employees agreeing to abide by the standards of conduct outlined below for the duration of their employment:

U.S. Department of Homeland Security

10.1.1. The contractor shall provide all employees with a copy of the program's standards of conduct.

10.1.2. All employees shall certify in writing that they have read and understand these standards.

10.1.3. A record of this certificate shall be provided to the COR prior to the employee's beginning work under this contract.

10.1.4. If engaging in social media, contractor shall maintain professionalism on and off duty and shall not discuss their duties and information relating to their employment or ICE/ERO.

10.1.5. The contractor shall report to the COR within 24 hours of any violations or attempted violations of the standards of conduct.

10.1.6. Violations may result in employee dismissal by the contractor or removal at the discretion of the CO.

10.1.7. Failure on the part of the contractor to report a known violation or to take appropriate disciplinary action against offending employee or employees shall subject the contractor to appropriate action up to and including termination of the contract for default.

10.1.8. The contractor shall develop procedures for reporting and handling grievances or complaints from participants. All grievances/complaints shall be reported within the next business day to the COR in writing. Any grievances/complaints from participants concerning equal opportunity to the program’s services shall be forwarded to the ICE Office of Diversity and Civil Rights for processing at ICE.Civil.Liberties@ice.dhs.gov.

11. REMOVAL FROM DUTY

11.1 Should a contractor employee need to be removed from duty:

11.1.1. The contractor shall provide all employees with a copy of the program's standards of conduct.

11.1.2. The contractor shall notify the COR within 24 hours upon learning of adverse or disqualifying information regarding any employee. The contractor shall immediately remove the employee from performing duties under this contract, provide written notice to the COR of the employee’s removal and comply with further guidance from the CO upon learning of adverse or disqualifying information.

11.1.3. The contractor shall notify the COR in writing of any employee terminations, suspensions, resignations, or any other adverse personnel actions taken for any reason. Disqualifying information includes, but is not limited to:

11.1.4. Arrest or conviction of a crime (felony or misdemeanor offenses),

11.1.5. A record of arrests for traffic offenses (especially DUI), or

11.1.6. False information entered on suitability forms.

11.1.7. Upon notification, the contractor shall remove any employee from assignment to this contract who has been disqualified for security reasons or is deemed unfit to perform his or her duties.

11.1.8. A determination of being unfit for duty includes, but is not limited to, incidents involving misconduct as set forth below:

a. Neglect of duty or failure to carry out assigned tasks.

b. Falsification or unlawful concealment, removal, mutilation, or destruction of any official documents or records, or concealment of material facts by willful omissions from official documents or records.

c. Possession of or selling, consuming, or being under the influence of intoxicants, drugs, U.S. Department of Homeland Security or other mind-altering substances.

d. Unethical or improper use of official authority.

e. Violations of security procedures or regulations.

f. Fraternization with program participants.

g. Failure to maintain or fulfill training requirements; or

h. Inappropriate conduct on social media as defined in the Standards of Conduct

12. MEDIA AND ORGANIZATIONAL INQUIRES

• The contractor shall refer all media inquiries to ICE and/or OFTP for approval.

• The contractor shall not provide any information to the press concerning this contract without prior approval from the ICE PAO.

• The contractor shall immediately notify the ICE PAO of any media or other organizational inquiries.

• There shall be no public disclosures regarding this contract made by the Contractor (or any subcontractors) without review and approval of such disclosure by ICE Public Affairs and express permission granted by the ICE Contracting Officer. The Government considers such information privileged or confidential.

13. PROGRESS MEETINGS

• Weekly Meetings--The Project Manager shall be responsible for keeping the COR informed about contractor progress throughout the performance period of this contract and ensure contractor activities are aligned with ICE objectives. The Project Manager and other staff as needed shall be available to meet with the CO and COR upon request to present deliverables, discuss progress, exchange information, and resolve emergent technical problems and issues.

• Quarterly Review Meetings--The contractor shall coordinate, arrange, and provide a quarterly and/or periodic review meeting at the request of the Government onsite, virtually or a combination of both. The meeting attendance requirement will include all contract key personnel. Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. These meetings may take place virtually or onsite. At these meetings, the COR will notify the contractor of how the Government views the contractor's performance and the contractor will inform the Government of any problems being experienced. Appropriate action shall be taken to resolve outstanding issues. Should additional meetings be required to resolve outstanding issues, these meetings shall be at no additional cost to the Government. The requestor will provide an agenda up to fourteen (14) calendar days prior to the quarterly and/or periodic review meetings that will be approved by the COR. The contractor shall provide an electronic version of the briefing to the Government one (1) week prior to the program review.

• Ad Hoc Meetings--The Government may require ad hoc meetings from time to time to address special circumstances or issues that may arise. The contractor will attend these meetings at date and time that is mutually agreed upon.

14 TRANSITION-IN

The contractor shall be responsible for the transition of all activities identified in this PWS and shall provide a detailed phase in plan, documenting milestones and timeline leading up to program launch.

It is expected that transition in will take no more than 30 calendar days. Activities that will occur during the transition in phase include:

• Meet with the COR and other designated ICE staff to review transition in plan and discuss any pertinent or on-going issues. This may be done telephonically.

U.S. Department of Homeland Security

• Ensure they have all required staffing to begin performance under the contract.

• Onboarding and training of new and incumbent employees in accordance with the PWS to include conducting background investigations.

• Providing all required deliverables as noted in the deliverable table.

15 TRANSITION-OUT

Transition to a new awardee shall occur in a manner that is seamless and causes no disruption to program operations.

• 60 calendar days prior to contract end, the Contractor shall provide a transition out plan, documenting milestones and a schedule for transition activities.

16. QUALITY ASSURANCE

For all areas of responsibility detailed within this PWS, the contractor shall also define and implement quality control review and internal audit procedures in its Quality Control Plan (QCP). The contractor shall execute and document the results of such reviews and audits and ensure that all documentation related to them are available to the CO and COR at any time.

ERO has defined and will implement a Quality Assurance Surveillance Plan (QASP) that will evaluate and document the contractor’s performance during the execution and duration of the contract. ERO will conduct audits of multiple locations at random to evaluate the contractor’s quality control review, internal audit procedures, verify the results and ensure contract compliance.

Quality Assurance Reviews--The contractor shall define and implement monthly quality assurance reviews and internal audit procedures in a QCP and review the QASP metrics/performance. The contractor shall execute and document the results of such reviews and audits, implement a corrective action plan on areas found deficient in performance, and ensure that all documentation (e.g., internal audit reports) related to them are available to the COR and the CO at any time during the execution and close-out of this contract.

17. POST AWARD CONFERENCE

The contractor shall participate in a Post Award Conference with the CO and the CORs no later than fifteen (15) calendar days after the date of award. The purpose of the Post Award Conference, which will be chaired by the CO, is to discuss technical and contracting objectives of this contract and review the contractor's overall approach.

18. DELIVERABLES

All are to be approved by the COR or designee.

# Deliverable Due Date(s) Distribution 1 Post Award Conference To be determined based upon award date N/A

2 Quality Control Plan Within 15 calendar days of contract award COR, Contracting Officer

3 Updated Organizational Chart Within 15 calendar days of contract award COR, Contracting Officer

4 Satisfy Staffing Requirements Within 15 calendar days of contract award COR, Contracting Officer

U.S. Department of Homeland Security

5 Project Management Plan for Training Development

30 days from award date COR, Contracting Officer, Subject Matter Expert

6 Progress Reports Reviewed on a quarterly basis.

COR, Contracting Officer, Subject Matter Expert

7 Instructor and Student Materials

Based on Project Management Plan

COR, Contracting Officer, Subject Matter Expert

8 Pilot Report Based on Project Management Plan

COR, Contracting Officer, Subject Matter Expert

9 Evaluation Report Two weeks before the annual curriculum review

COR, Contracting Officer, Subject Matter Expert

10 Annual Curriculum Review Report

Two weeks following the annual curriculum review

COR, Contracting Officer, Subject Matter Expert

11 Notification of employee termination, transfer, suspension, personnel action relating to disqualifying information or incidents of wrongdoing (criminal or policy violation)

Immediately (immediate verbal report, with written follow-up) upon identification

COR, Contracting Officer

12 Report of any contract employee misconduct

Immediately (immediate verbal report, with written follow-up) upon identification

COR, Contracting Officer

13 IT Security Plan See 3052.204-70 (Section I) COR, Contracting Officer

14 Create and Maintain Training Records

Daily or as required COR

Conduct and Document Internal Quality Assurance Audits

Review and update Quality Control Procedures as required, but no less than annually

COR, Contracting Officer, Subject Matter Expert

16 Furnish Resumes of Key Personnel

Provide with Proposal and Prior to Entry on Duty (EOD) of any new staff

COR, Contracting Officer e-QIP Security Process

Weekly report to COR listing employee name, date submitted, date approved/removed from process each Friday

COR

Transition Out Plan 60 calendar days prior to the end of the contract

COR, Contracting Officer

U.S. Department of Homeland Security

HSAR DEVIATION 15-02 INFORMATION TECHNOLOGY SECURITY AND

PRIVACY TRAINING (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Security Training Requirements.

(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. The Department of Homeland Security (DHS) requires that Contractor employees take an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year.

The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.

(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within thirty (30) days of contract award. Any new Contractor employees assigned to the contract shall also sign the DHS Rules of Behavior before accessing DHS systems and sensitive information. The Contractor shall maintain signed copies of the DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance.

Unless otherwise specified, the Contractor shall e-mail copies of the signed DHS http://www.dhs.gov/dhs-security-and-training-requirements-contractors

U.S. Department of Homeland Security

Rules of Behavior to the COR not later than thirty (30) days after contract award for each employee. The DHS Rules of Behavior will be reviewed annually and the COR will provide notification when a review is required.

(c) Privacy Training Requirements. All Contractor and subcontractor employees that will have access to Personally Identifiable Information (PII) and/or Sensitive PII (SPII) are required to take Privacy at DHS: Protecting Personal Information before accessing PII and/or SPII. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors . Training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall also complete the training before accessing PII and/or SPII. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Initial training certificates for each Contractor and subcontractor employee shall be provided to the COR not later than thirty (30) days after contract award.

Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year.

The email notification shall state the required training has been completed for all Contractor and subcontractor employees.

(End of clause)

PRIVACY REQUIREMENTS FOR CONTRACTOR AND PERSONNEL

In addition to FAR 52.224-1 Privacy Act Notification (APR 1984), 52.224-2 Privacy Act (APR 1984), FAR 52.224-3 Privacy Training (JAN 2017), and HSAR Clauses, the following instructions must be included in their entirety in all contracts.

Limiting Access to Privacy Act and Other Sensitive Information In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984), and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DHS system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.dhs.gov/system-records-notices- sorns. Applicable SORNS of other agencies may be accessed through the agencies’ websites or by searching GovInfo, available at https://www.govinfo.gov that replaced the FDsys website in December 2018. SORNs may be updated at any time.

Prohibition on Performing Work Outside a Government Facility/Network/Equipment The Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or Workplace as a Service (WaaS) if WaaS is authorized by the statement of work. Government information shall remain within the confines of authorized Government networks at all times. Except where telework is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/system-records-notices-sorns https://www.dhs.gov/system-records-notices-sorns https://www.govinfo.gov/

U.S. Department of Homeland Security removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of telework authorizations.

Prior Approval Required to Hire Subcontractors The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract.

The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

Separation Checklist for Contractor Employees Contractor shall complete a separation checklist before any employee or Subcontractor employee terminates working on the contract. The separation checklist must verify: (1) return of any Government- furnished equipment; (2) return or proper disposal of sensitive personally identifiable information (PII), in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to sensitive PII.

In the event of adverse job actions resulting in the dismissal of an employee or Subcontractor employee, the Contractor shall notify the Contracting Officer’s Representative (COR) within 24 hours. For normal separations, the Contractor shall submit the checklist on the last day of employment or work on the contract.

As requested, contractors shall assist the ICE Point of Contact (ICE/POC), Contracting Officer, or COR with completing ICE Form 50-005/Contractor Employee Separation Clearance Checklist by returning all Government-furnished property including but not limited to computer equipment, media, credentials and passports, smart cards, mobile devices, PIV cards, calling cards, and keys and terminating access to all user accounts and systems.

Contractor’s Commercial License Agreement and Government Electronic Information Rights Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases) and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S.

Government and are considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

Privacy Lead Requirements If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy documentation, the Contractor shall assign or procure a Privacy

U.S. Department of Homeland Security

Lead, to be listed under the SOW or PWS’s required Contractor Personnel section. The Privacy Lead shall be responsible for providing adequate support to DHS to ensure DHS can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance. The Privacy Lead shall work with personnel from the program office, the ICE Privacy Unit, the Office of the Chief Information Officer, and the Records and Data Management Unit to ensure that the privacy documentation is kept on schedule, that the answers to questions in the PIA are thorough and complete, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.

The Privacy Lead:

• Must have excellent writing skills, the ability to explain technology clearly for a non-technical audience, and the ability to synthesize information from a variety of sources.

• Must have excellent verbal communication and organizational skills.

• Must have experience writing PIAs. Ideally the candidate would have experience writing PIAs for DHS.

• Must be knowledgeable about the Privacy Act of 1974 and the E-

Government Act of 2002.

• Must be able to work well with others.

If a Privacy Lead is already in place with the program office and the contract involves IT system builds or substantial changes that may require privacy documentation, the requirement for a separate Private Lead specifically assigned under this contract may be waived provided the Contractor agrees to have the existing Privacy Lead coordinate with and support the ICE Privacy POC to ensure privacy concerns are proactively reviewed and so ICE can complete any required PTA, PIA, SORN, or other supporting documentation to support privacy compliance if required.

The Contractor shall work with personnel from the program office, the ICE Office of Information Governance and Privacy, and the Office of the Chief Information Officer to ensure that the privacy documentation is kept on schedule, that the answers to questions in any privacy documents are thorough and complete, that all records management requirements are met, and that questions asked by the ICE Privacy Unit and other offices are answered in a timely fashion.

U.S. Department of Homeland Security

General Cybersecurity Contract Requirements

A.1 In accordance with ITAR 4.5.4.1 – Compliance with DHS Security Policy

Terms and Conditions.

Not Applicable.

A.2 In accordance with ITAR 4.5.3.1 – Compliance with DHS Security Policy Terms and Conditions.

Compliance with DHS Security Policy Terms and Conditions:

All hardware, software, and services provided under this contract must be compliant with DHS 4300A DHS Sensitive System Policy and DHS 4300A Sensitive Systems Handbook.

A.3 In accordance with ITAR 4.5.3.4 and ITAR 4.5.4.4 – Security

Review Security Review Terms and Conditions

The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford ICE, including the organization of ICE Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer Technical Representative (COTR), and other government oversight organizations, access to the Contractor's facilities, installations, operations, documentation, databases and personnel used in the performance of this contract.

The Contractor will contact ICE Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to ICE. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of ICE data or the function of computer system operated on behalf of ICE, and to preserve evidence of computer crime.

A.4 In accordance with ITAR 4.5.3.7 – Supply Chain Risk

Management Supply Chain Risk Management Terms and

Conditions

The Contractors supplying the Government hardware and software shall provide the manufacturer's name, address, state and/or domain of registration, and the Data Universal Numbering System (DUNS) number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state, and/or

IMPORTANT CAUTION

Reference to contract requirements and clauses is current as of the date of publication. Due diligence should be exercised by all stakeholders in the process to confirm accuracy and applicability of the requirements identified in this Appendix.

U.S. Department of Homeland Security domain of registration and DUNs number of those suppliers must also be provided.

Subcontractors are subject to the same general requirements and standards as prime contractors. Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.

The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.

Contractors shall provide, implement, and maintain a Supply Chain Risk Management Plan that addresses internal and external practices and controls employed to minimize the risk posed by counterfeits and vulnerabilities in systems, components, and software.

The Plan shall describe the processes and procedures that will be followed to ensure appropriate supply chain protection of information system resources developed, processed, or used under this contract.

The Supply Chain Risk Management Plan shall address the following elements:

(i) How risks from the supply chain will be identified;

(ii) What processes and security measures will be adopted to manage these risks to the system or system components; and

(iii) How the risks and associated security measures will be updated and monitored.

The Supply Chain Risk Management Plan shall remain current through the life of the contract or period of performance. The Supply Chain Risk Management Plan shall be provided to the Contracting Officer Representative (COR/CO) 30 days post award.

The Contractor acknowledges the Government's requirement to assess the Contractors Supply Chain Risk posture. The Contractor understands and agrees that the Government retains the right to cancel or terminate the contract, if the Government determines that continuing the contract presents a risk to national security.

The Contractor shall disclose, and the Government will consider, relevant industry standard certifications, recognitions and awards, and acknowledgments.

The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the CO. Contractors shall provide only Original Equipment Manufacturer (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.

The Contractor shall be excused from using new OEM (i.e. "grey market, "previously used) components only with formal Government approval. Such components shall be procured from their original source and have them shipped only from manufacturers authorized shipment points.

For software products, the contractor shall provide all OEM software updates to correct defects for the life of the product (i.e., until the “end of life"). Software updates and patches must be made available to the government for all products procured under this contract.

Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.

U.S. Department of Homeland Security

All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the contract, the period of performance, or one calendar year from the date the activity occurred.

These records must be readily available for inspection by any agent designated by the U.S.

Government as having the authority to examine them.

This transit process shall minimize the number of times en route components undergo a change of custody and make use of tamper-proof or tamper-evident packaging for all shipments. The supplier, at the Government's request, shall be able to provide shipping status at any time during transit.

The Contractor is fully liable for all damage, deterioration, or losses incurred during shipping and handling, unless the damage, deterioration, or loss is due to the Government. The Contractor shall provide a packing slip which shall accompany each container or package with the information identifying the contract number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact. The contractor shall send a shipping notification to the intended government recipient or contracting officer. This shipping notification shall be sent electronically and will state the contract number, the order number, a description of the hardware/software being ship (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.

A.5 In accordance with HSAR 3052.204-70 - Security requirements for unclassified IT resources, with ITAR 4.5.3.3 – Access to Unclassified Facilities, IT Resources, and Sensitive Information Requirement Clause Inclusion Instruction, with ITAR 4.5.3.9 – Security Requirements for Unclassified Information Technology Resources Clause, with ITAR 4.5.4.6 – Required Protections for DHS Systems Hosted in Non-DHS Data Centers, and with ITAR 4.5.4.7 – Contractor Employee Access Clause. As prescribed in (HSAR) 48 CFR 3004.470-3 Contract clauses:

Security Requirements For Unclassified Information Technology Resources

(JUN 2006)

The Contractor shall be responsible for IT security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency’s mission.

The Contractor shall provide, implement, and maintain an IT Security Plan. This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.

Within 60 days after contract award, the contractor shall submit for approval its IT Security Plan, which shall be consistent with and further detail the approach contained in the offeror's proposal. The plan, as approved by the Contracting Officer (CO), shall be incorporated into the contract as a compliance document.

The Contractor’s IT Security Plan shall comply with Federal laws that include, but are not limited to, the Computer Security Act of 1987 (40 U.S.C. 1441 et seq.); the http://farsite.hill.af.mil/reghtml/regs/other/hsar/3004.htm#P27_2040

U.S. Department of Homeland Security

Government Information Security Reform Act of 2000; and the FISMA of 2002; and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130.

The security plan shall specifically include instructions regarding handling and protecting sensitive information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.

Examples of tasks that require security provisions include:

a) Acquisition, transmission or analysis of data owned by DHS with significant replacement cost should the contractor’s copy be corrupted; and

b) Access to DHS networks or computers at a level beyond that granted the public (e.g., such as bypassing a firewall).

At the expiration of the contract, the contractor shall return all sensitive DHS information and IT resources provided to the contractor during the contract and certify that all non-public DHS information has been purged from any contractor-owned system.

Components shall conduct reviews to ensure that the security requirements in the contract are implemented and enforced.

A.5.1 Contractor IT Security

Accreditation Contractor IT Security

Accreditation

Within 6 months after contract, the contractor shall submit written proof of IT Security accreditation to DHS for approval by DHS CO. Accreditation will proceed according to the criteria of DHS Sensitive System Policy Publication, 4300A (most current version) or any replacement publication, which the CO will provide upon request. This accreditation will include a final security plan, risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan. This accreditation, when accepted by the CO, shall be incorporated into the contract as a compliance document. The contractor shall comply with the approved accreditation documentation.

A.6 In accordance with HSAR 3052.204-71 - Contractor Employee Access Contractor Employee Access (Sep 2012) Sensitive Information, as used in this clause, means any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of title 5,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .