Attachment_1_SOW_Biorisk_Managment_Framework.pdf
PDF 362 KB Posted
- Attached to
- CDC Biorisk management system framework Federal contract opportunity
- Solicitation number
- 140D0426R0119
About this file
Statement of Work Summary
This is a Statement of Work (SOW) for RFP 140D0426R0119 issued by the Centers for Disease Control and Prevention (CDC), Office of Readiness and Response, for the U.S. National Authority for Containment of Poliovirus (NAC). The contract is for development of a U.S. NAC Biorisk Management Framework for Poliovirus Containment, including training, technical services support, and access to ISO standards and licensing. The base period runs from September 18, 2026 through September 17, 2027, with four optional one-year extension periods through September 17, 2031. The contractor must deliver a publication-quality biorisk management framework integrating ISO 35001, ISO/IEC 17021, ISO 9001, ISO 31000, ISO 45001, NIH Design Requirements Manual, and WHO Global Action Plan for Poliovirus Containment. ANSI is identified as the only vendor capable of providing the specific ISO-aligned licenses and technical services required.
Key deliverables include: a working draft U.S. NAC Biorisk Management Framework (4 months), standards mapping and integration matrix (5 months), documentation of all licenses and permissions (2 months), identification and convening of stakeholders with expert review (6 months), two best-practice briefs (4 and 9 months), practical implementation resources including roadmaps and assessment tools (6 months), comprehensive competency-based training programs (5 months), train-the-trainer workshops (6 months), establishment of standards-based collaboratives (6 months), directories of technical experts (4 months), and a secure digital platform for hosting frameworks and training resources (8 months). Monthly status reports and work plans are required throughout the contract period. The contractor must provide workforce training, stakeholder engagement, and implementation tools supporting NAC's transition to a U.S.-led poliovirus containment program aligned with international standards following Executive Order 14155, which directed U.S. withdrawal from the WHO.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| B08_SOL_-_RFP_CDC_Biorisk_final.pdf | ||
| Attachment_2_Pricing_Spreadsheet.zip | ZIP file |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
U.S. National Authority for Containment of Poliovirus, (NAC) Office of Readiness and Response (ORR)
RFP 140D0426R0119
TITLE: DEVELOPMENT OF A U.S. NATIONAL AUTHORITY FOR CONTAINMENT OF POLIOVIRUS
(NAC) BIORISK MANAGEMENT FRAMEWORK FOR POLIOVIRUS CONTAINMENT, TRAINING, AND
TECHNICAL SERVICES SUPPORT
SECTION 1 – BACKGROUND
The Office of Readiness and Response in the Centers for Disease Control and Prevention (CDC) was established to support and coordinate public health preparedness and emergency response activities across the agency. As the nation’s disease control and prevention agency, CDC provides leadership to the national public health community to prepare for and respond to urgent threats to the public’s health. ORR has oversight and responsibility for all programs that comprise CDC’s emergency response portfolio. The U.S.
National Authority for Containment of Poliovirus (U.S. NAC) located in ORR’s Division of Regulatory Science and Compliance is responsible for oversight and advancement of poliovirus containment activities within the United States. Throughout the United States, there are many facilities, including academic institutions, federal laboratories, and companies, with poliovirus and materials potentially infectious for poliovirus. Implementing containment measures will minimize the risk of the virus getting into the environment and causing harm to our communities.
In January 2025, Executive Order (EO) 14155 directed the United States to withdraw from the World Health Organization (WHO). As a result, the U.S. NAC ended its participation in WHO’s poliovirus containment certification program and established a U.S.-led approach. The U.S. NAC fully aligned its program documents and processes with federal directives while continuing to meet the highest standards of safety and oversight.
Following EO14155, the U.S. NAC revised its containment certification program. The U.S. NAC poliovirus containment certification program is now in alignment with national guidelines and recognized standards for certification bodies, including, but not limited to, International Organization of Standardization (ISO) 17021-1:2015 Conformity assessment – Requirements for bodies providing auditing and certification of management systems, ISO 35001:2019 Biorisk management for laboratories and other related organizations, NIH Design Requirements Manual, and U.S. NAC technical specifications. U.S.
NAC created a biorisk management systems framework for poliovirus designated facilities that outlines the expectations for poliovirus containment certification and are in alignment with the current version of ISO35001 Biorisk Management, NIH Design Requirements Manual, and additional U.S. NAC technical specifications.
The U.S. NAC intends to build upon the existing NAC Biorisk Management Framework and conduct a critical analysis of international and national standards as it relates to poliovirus containment. The U.S.
NAC is seeking to procure international laboratory and safety standards services to help inform and further develop a biorisk management system framework for the United States. The updated framework shall integrate principles and requirements from nationally and internationally recognized standards and technical guidance including but not limited to ISO35001, ISO17021, NIH Design Requirements Manual (DRM), WHO Global Action Plan for Poliovirus Containment, 4th edition and NAC-specific technical guidance and containment requirements. U.S. NAC requires the procurement of International Organization for Standardization (ISO) standards and technical services. The procurement of ISO standard services would help the U.S NAC to enhance the development, coordination and management of its poliovirus containment certification program. The U.S. NAC is seeking to procure ISO standards, licenses, trainings, and technical support to ensure access to the following standards and other standards not mentioned below that follow within a poliovirus certification containment program:
• ISO/IEC 17021-1 — Conformity assessment requirements for bodies providing audit and certification of management systems
• ISO 45001 — Occupational health and safety management systems
• ISO 35001 — Biorisk management systems for laboratories and related organizations
• ISO 9001 — Quality management systems
• ISO 31000 — Risk management principles and guidelines
• TS7446 — ISO35001 implementation
The U.S. NAC is working to create an independent containment program aligned with global eradication and containment efforts. The resulting proposed, new framework shall be a U.S. government-owned product designed to support a sustainable, risk-based, and auditable containment framework tailored to U.S.
requirements. The contractor would provide technical services and license standards to further develop the proposed U.S. NAC domestic biorisk framework. The framework will fulfill U.S. public health needs and continue to establish the U.S. NAC as a global leader in poliovirus containment and oversight. The effort supports Administration priorities related to public health preparedness, biosafety, biosecurity, and strengthen long-term capability. The contractor would work with the U.S. NAC and stakeholders to help integrate, communicate and coordinate the implementation of the new framework.
SECTION 2 – PURPOSE
The purpose of the contract is to procure technical services, framework development support, stakeholder engagement, workforce training, and implementation tools necessary to establish a U.S. led- biorisk management framework for poliovirus containment and associated implementation framework. The contract will also procure licenses for access to ISO framework. The American National Standards Institute (ANSI) is the only vendor who has created these specific licenses and technical services required to accurately implement an ISO aligned certification program. The ISO standards and technical services will ensure consistent and high-quality performance across all operational areas within the U.S. NAC poliovirus containment certification program.
The contract will provide services which support technical biosafety and biosecurity services standards which are unique only to ANSI. The contractor shall help mold existing framework to create a new government framework for US NAC’s poliovirus containment certification program. The contractor shall negotiate and change licensing agreements for relevant biosafety and biorisk framework.
SECTION 3 – SCOPE OF WORK
The contractor shall provide the following services which will help to advance the U.S. NAC’s mission to protect the nation from poliovirus risks and reinforce the United States’ position as a global leader in poliovirus containment. The U.S. NAC is committed to protecting the American public and advancing poliovirus containment systems that reflect national priorities and accelerate progress toward international standards.
The contractor shall provide services in the following areas:
1. Develop, pilot, disseminate and roll out a NAC Biorisk Management Framework for Poliovirus Containment integrating relevant requirements such as ISO 35001, ISO/IEC 17021, ISO 9001, ISO 19011, NIH DRM, WHO GAP IV, and NAC technical guidance.
2. Facilitate stakeholder engagement and technical consensus development.
3. Support review by domestic and international subject matter experts.
4. Develop training, implementation guidance, and competency-based learning programs.
5. Provide access to a virtual portal which houses the necessary standards, training, tools and resources needed to stand up a biorisk management system for a poliovirus containment program.
6. Build NAC and stakeholder workforce capability to support implementation and oversight of the new framework.
7. Provide technical assistance in certifying a NAC Biorisk Management Framework for Poliovirus
Containment. Provide the U.S. NAC with access to ISO 35001 — Biorisk management systems for laboratories and related organizations
8. Consider providing the following ISO standards and licenses but the below may be viewed as optional:
• ISO/IEC 17021‑1 — Conformity assessment requirements for bodies providing audit and certification of management systems
• ISO 45001 — Occupational health and safety management systems
• ISO 9001 — Quality management systems
• ISO 31000 — Risk management principles and guidelines
• TS 7446 — ISO 35001 implementation guidance
SECTION 4 – TASKS TO BE PERFORMED
The contractor shall perform the following tasks to include but not limited to the following:
Task 4.1: Project Management
The contractor shall perform the following services:
4.1.2 A kickoff meeting shall be held no later than 7 workdays after the initial award is made to review statement of work, establish work plans, introduce staff, establish timelines, and define roles and responsibilities.
4.1.3 Following the kickoff meeting, the contractor shall develop a written work plan, minimally including all essential interim and final deliverables, key staff responsible for tasks (including contractor, CDC or other partners), and schedule of key deadlines (including review cycles and absolute No Later Than (NLT) dates for key activities and deliverables) for COR and CDC Project Officer review and correct before acceptance. The work plan must contain:
• A series of specific reports and activities proposed and developed by the contractor following the kick-off meeting and amended as directed during the duration of the contract. The work plan will include the contractor’s plan for ongoing monitoring and evaluation of services to ensure high quality performance and customer satisfaction.
• The work plan will be disseminated to key CDC management, staff, and external stakeholders impacted by this project, as needed. The work plan is due no later than 30 workdays following the kickoff meeting. The work plan (and any schedule of interim deliverables) may be revised according to CDC acceptance of the updated work plan by the COR and the CDC Project Officer during the period of performance of the contract.
4.1.4 The contractor shall provide a monthly report including updates on deliverables as described in the work plan. The monthly report shall be considered a substantial delivery of the project, for review by the NAC staff, COR and CDC Project Officer. It will be used as 1) a tracking tool for success with the contract, 2) documentation of effort, services and completed deliverables as invoiced in the monthly invoice. The contractor shall develop the monthly report format for review and approval by the COR and the CDC Project Officer. The monthly report is due NLT than the 5th calendar day of each month.
4.1.5 The contactor shall set up weekly and daily meetings with CDC COR and the CDC Project Officer. The meetings are initiated and led by the contractor. The purpose of this meeting is to review ongoing contract performance. The meeting minutes must be documented in the following monthly report. Any required performance improvements must be documented and reported in the monthly reports. Daily check-in points would occur via email or phone communication.
4.1.6 Ensure work products are completed in a timely manner, often with quick turnaround times for drafts.
4.1.7 Coordinate communications projects from the planning stage; providing additional or missing materials; and editing for content format, flow, and integrity.
Task 4.2: Development of NAC Biorisk Management Framework and Licensing
The contractor shall perform the following services:
4.2.1 Develop a working draft of U.S. NAC Biorkisk Management Framework for Poliovirus Containment based upon the existing NAC Biorisk Management Framework. Activities include conducting a clause-by-clause analysis of ISO35001, WHO GAP-4, NIH DRM to identify overlapping, unique, and supplemental requirements. Based on analysis, produced a standards mapping and integration matrix.
4.2.2 Develop a publication quality document incorporating organizational context, leadership and governance/top management, biorisk and risk assessment, worker health and immunizations, training and competency, quality management for biorisk management systems, security, infrastructure and operational management, equipment, inventory, storage outside containment perimeter, good microbiological practices, clothing and personal protective equipment, decontamination and waste management, inactivation for future use, emergency response and contingency planning, and transport topic areas. The framework shall include normative requirements, informative annexes, implementation guidance, references, and definitions and terminology. Final document shall meet Section 508 accessibility requirements.
4.2.3 Provide technical support to NAC in operationalizing ISO-aligned standard in real‑world environments, including audit workflows, compliance structures, corrective action systems, performance measurement, and continuous improvement mechanisms.
4.2.4 Identify, obtain, and document all licenses, permissions, and usage rights necessary to incorporate requirements from applicable standards, guidance documents, and technical references used in the development of the U.S. NAC Biorisk Management Framework for Poliovirus Containment and related database for the creation of audit reports and checklists.This includes, but is not limited to: ISO35001, ISO/IEC 17021, ISO9001, WHO GAP, ISO19011, NIH DRM, any additional ISO standards references during standard development.
4.2.5 Ensure that all use of copyrighted standards and reference materials complies with applicable intellectual property, copyright, licensing, and fair-use requirements.
Task 3: Stakeholder Engagement and Consensus Development The contractor shall perform the following services:
4.3.1 Identify, convene, and facilitate participation of relevant stakeholders and subject matter experts to review the newly developed U.S. NAC framework. Activities include conducting technical working groups, expert panels, and establishing a structured review process of the standard and resolution of technical comments. Contractor will provide U.S. NAC a report of the technical comments.
4.3.2 Develop two best‑practice briefs, technical summaries, and knowledge‑sharing products.
4.3.3 Convene and host workshops, connect NAC with stakeholder organizations (virtual exchanges), and stakeholder briefings to present options, risks, recommendations and keep federal, industry and lab partners aligned.
4.3.4 Provide technical assistance to support coordinated dissemination and collaborative learning of guidance and lessons learned through organized communities of practice.
Task 4: Framework Implementation Tools and Guidance The contractor shall perform the following services:
4.4.2 Develop practical implementation resources supporting adoption of the new U.S. NAC framework. Tools may include, but are not limited to: implementation roadmap, readiness assessment tools, audit preparation guides, self-assessment checklists.
4.4.3 Provide technical assistance to develop and maintain the operational framework for NAC program, ensuring that governance, accreditation, certification, and conformity assessment structures align with international best practices.
4.4.4 Appoint SME for the integration of ANAB‑aligned accreditation structures into the NAC containment and certification system, ensuring alignment with ISO/IEC 17021‑1 and related management system requirements.
4.4.5 Provide specialized biosafety and biosecurity technical expertise that will assist with the development, refinement, and maintenance of the U.S. NAC’s new bio risk management framework.
4.4.6
Task 5: Advance the U.S. Biorisk Management System (BMS) framework and Facilitate Acceptance Across Industry and ISO Partners The contractor shall perform the following services:
4.5.1 Design and deliver a comprehensive competency-based education and training program for U.S. NAC/DRSC staff and stakeholders (i.e., designated facility personnel, leadership, biosafety professionals). Training topics include NAC Biorisk Management Framework, ISO19011, ISO 35001, ISO/IEC 17021, management systems implementation, risk-based decision making. Learning products include instructor-led courses, virtual instructor-led training, self-paced on demand e-Learning, competency assessments.
4.5.2 Conduct train-the-trainer workshops for NAC staff on the new standard.
4.5.3 Establish and support standards-based collaboratives that convene federal agencies, laboratories, accreditation bodies, industry partners, and technical experts to create coordinated national poliovirus containment and bio risk execution ecosystems.
4.5.4 Design and maintain directories and registries of technical experts, and accredited organizations to support transparency, tracking, and national-scale coordination.
Task 6: Digital Learning and Resource Platform Management The contractor shall provide the following services:
4.6.1 Provide access to national and international standards necessary for U.S. NAC containment, bio risk management, and certification system development. This includes ISO 35001, ISO/IEC 17021, ISO 9001, ISO 31000, TRS7446, ISO45001, and
4.6.2 Provide a secure, accessible platform to host US NAC framework and training resources.
Capabilities include but are not limited to: user access management, training delivery, resource library, knowledge repository, resources and on-demand available.
SECTION 5 – GOVERNMENT FURNISHED MATERIALS
Adequate workspace, other materials equivalent to that used by government personnel, desk, chair, cabinet space, telephone, and similar items, will be provided, when the contract personnel are onsite to conduct their activities. Government property including CDC computer equipment if deemed necessary will be provided by NAC to perform assigned duties.
All such items utilized by the contractor remain the property of the Government. If performance of this contract is within and on Government facilities, and the Government furnished property or contractor-acquired property is for use only within or on the Government facilities, the control and accountable record keeping for such property shall be retained by the Government (see FAR 52,245-1, Property Records).
The Contractor shall remain accountable for loss or damage but will not be required to submit an annual inventory or place its own bar codes on the items. The Government will provide property labels and other identification for contractor-acquired Government property under this paragraph.
OFFICE SPACE AND EQUIPMENT
• The Government will provide office space as well as access to the following: telephone, fax, and computers.
• The Government will provide all office supplies such as paper, pencils, and staplers.
• Telework, Hybrid and Remote
Contractors may telework, may have access to hybrid or may have access to remote work flexibilities at the discretion of the government. The government has the authority to require the contractor to work on CDC Atlanta, Georgia campuses on a full time or part-time basis and may be requested work in the office at anytime. It is at the discretion of the government to remove telework, hybrid and remote options of any contractor on this requirement.
SECTION 6 – PERIOD OF PERFORMANCE and Contractor Effort Proposed
The period of performance will consist of one 12-month base period and 4 one year options periods.
Base Period 9/18/2026 – 9/17/2027
Option Period 1 9/18/2027 – 9/17/2028
Option Period 2 9/18/2028 – 9/17/2029
Option Period 3 9/18/2029 – 9/17/2030
Option Period 4 9/18/2030 – 9/17/2031
SECTION 7 – DELIVERABLES/REPORTING SCHEDULE FOR THE BASE and OPTION PERIOD
Item/Tasks Description Quantity Format Delivery Date Deliver To 0 Kickoff meeting agenda 1 Electronicall y via E-mail and Microsoft Suite
Within one week of contract start
COR and Technical Monitor
0 Minutes from kickoff meeting including revised deliverable schedule
1 Electronicall y via E-mail and Microsoft Suite
Within one week following kickoff meeting
COR and Technical Monitor
1 Work Plan 5 (per year)
Electronicall y via E-mail and Microsoft Suite
Initial Work Plan Version 1, 30 working Days from Start of Contract, Version 2, 3 ,4 and 5 at quarter interval of the calendar year
COR and
1 Monthly Reporting 12 (per year)
Electronicall y via E-mail and
Monthly by the 5th calendar day following the end of the month
COR and Technical Monitor
Develop a U.S. NAC Biorkisk Management Standard
1 Electronicall y via E-mail and
4 months after contract award
COR and Technical Monitor
Develop a standards mapping and integration matrix and
5 months after contract
COR and
Identify, obtain, and document all licenses, permissions, and usage rights and
2 months after contract
COR and
Identify, convene, and facilitate participation of relevant stakeholders and subject matter experts to review the newly developed U.S.
NAC standard.
1 Virtually using respective training platforms
6 months after contract award
COR,
Technical monitor, Auditors and Participating facilities
Develop two best‑practice briefs, technical summaries, and knowledge‑sharing products.
2 Electronicall and
4 months and 9 months after contract award
COR and
Facilitate workshops, connect NAC with stakeholder organizations (virtual exchanges), and stakeholder briefings to present options, risks, recommendations and
2 Virtually using respective training platforms
4 months after contract award
COR,
Technical monitor, Auditors and Participating facilities keep federal, industry and lab partners aligned.
Develop practical implementation resources (i.e.
implementation roadmap, readiness assessment tools, audit preparation guides, self-assessment checklists.
4 Electronicall and
6 months after contract
COR and
Design and deliver a comprehensive competency-based education and training program for U.S.
NAC/DRSC staff and stakeholders (i.e., designated facility personnel, leadership, biosafety professionals).
1 Virtually using respective training platforms
5 months after contract award
COR,
Technical monitor, Auditors and Participating facilities
Conduct train-the-trainer workshops for NAC staff on the new standard.
2 Virtually respective training platforms
6 months after contract award
COR,
Technical monitor, Auditors
Establish and support standards-based collaboratives that convene federal agencies, laboratories, accreditation bodies, industry partners, and technical experts respective training platforms
6 months after contract
Design and maintain directories and registries of technical experts, and accredited organizations y via email and Microsoft Suite
4 months after contract award
COR,
Technical monitor
Provide a secure, accessible platform to host US NAC standard and training resources.
respective platforms
8 months after contract
COR and Technical Monitor, Auditors
SECTION 8 -- PERFORMANCE MATRIX
The Contractor’s performance, in addition to specifics listed below, will be evaluated in terms of timeliness, completeness, and error rate. At the initiation of each defined task, a best estimate of time of completion will be identified by the project manager. The actual length of time needed to produce a finished product meeting quality standards will be compared to this estimate in order to evaluate the Contractor’s performance.
Unless otherwise noted, for all tasks “normal operational hours” used to define timeframes listed below are based off of a work schedule of Monday through Friday, 9:00 a.m. to 5:00 p.m., excluding federal government holidays and building closures related to weather, utilities, and other issues. Contractor staff is required to work Monday through Friday and may begin working any time between 7:00 a.m. and 9:30 a.m. and must complete their tour of duty by 6:00 p.m.
Contractor output will be judged on completeness relative to the specifications identified at the onset of the specific activity. The extent to which the end product is error-free will also be measured.
1. Contractor must provide work products that require minimal technical corrections as identified by an internal review.
PERFORMANCE
OBJECTIVE
STANDARD PERFORMANCE
THRESHOLD
ACCEPTABLE
QUALITY LEVELS
(AQLs)
METHOD OF
SURVEILLANCE
Develop quality work in accordance with the Statement of Work
Work products are relatively free of errors
90%, 10% deviation from standard
Inspection by COR and Technical Monitor
Timely response to and resolution of requests for customer support
Respond to customer service requests within 4 hours, provide resolution or communicate a plan for resolution within 24 hours
95%, 5% deviation from standard
Inspection by COR and Technical Monitor
Ensure timely receipt of projects and deliverables
Deliver products within Government’s standard turnaround time or request proxy assistance for completing assignments before deadline
100%, 0% deviation from standard
Inspection by COR and Technical Monitor
SECTION 8 – REFERENCE MATERIALS
U.S. National Authority for Containment of Poliovirus | CDC
SECTION 9- ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY
(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998 and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Standards (36 CFR part 1194), require that when Federal agencies https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cdc.gov%2Fcpr%2Fpolioviruscontainment%2Findex.htm&data=05%7C01%7Ckelly.wroblewski%40aphl.org%7C92a725fc41524522d89708da762d40d4%7C434e0aedef824568a0493b17adc08ddd%7C1%7C0%7C637952234002574466%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=NB2Sd6DM5koFEkAaEAiTDUazYv0kZyHYWOTAQOGS39w%3D&reserved=0 develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.
(b) Accordingly, any offeror responding to this solicitation must comply with established HHS EIT accessibility standards. Information about Section 508 is available at http://www.hhs.gov/web/508. The complete text of the Section 508 Final Provisions can be accessed at http://www.access-aboard.gov/sec508/standards.htm.
(c) The Section 508 accessibility standards applicable to this contract are: 1194.
205 WCAG 2.0 Level A & AA Success Criteria 302 Functional Performance Criteria 502 Inoperability with Assistive Technology 504 Authoring Tools 602 Support Documentation 603 Support Services
In order to facilitate the Government's determination whether proposed EIT supplies meet applicable Section 508 accessibility standards, offerors must submit an HHS Section 508 Product Assessment Template, in accordance with its completion instructions. The purpose of the template is to assist HHS acquisition and program officials in determining whether proposed EIT supplies conform to applicable Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and documentation detail - whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the HHS Section 508 Evaluation Template are available under Section 508 policy on the HHS Web site http://hhs.gov/web/508.
In order to facilitate the Government's determination whether proposed EIT services meet applicable Section 508 accessibility standards, offerors must provide enough information to assist the Government in determining that the EIT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.
(d) Respondents to this solicitation must identify any exception to Section 508 requirements. If a offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.
(e) Electronic content must be accessible to HHS acceptance criteria. Checklist for various formats are available at http://508.hhs.gov/, or from the Section 508 Coordinator listed at https://www.hhs.gov/web/section- 508/additional-resources/section-508-contacts/index.html. Materials that are final items for delivery should be accompanied by the appropriate checklist, except upon approval of the Contracting Officer or Representative.
SECTION 10-OMB Paperwork Reduction Act of 1995 (PRA)
Offerors are advised that any activities involving information collections (i.e., surveys, questionnaires, applications, audits, data requests, reporting, recordkeeping and disclosure requirements, etc.) from 10 or more non-Federal entities, including State and local governmental agencies, are subject to the conditions of the http://www.hhs.gov/web/508 http://www.access-aboard.gov/sec508/standards.htm http://www.access-aboard.gov/sec508/standards.htm http://hhs.gov/web/508 http://508.hhs.gov/ https://www.hhs.gov/web/section-508/additional-resources/section-508-contacts/index.html https://www.hhs.gov/web/section-508/additional-resources/section-508-contacts/index.html
PRA. Under the PRA, a federal agency sponsoring a standardized data collection or directly obtaining standardized or substantially similar information from ten or more persons or entities (other than Federal employees within the scope of their employment) in any 12-month period must obtain advance written approval from the Office of Management and Budget (OMB). Regardless of form or format (oral, written, or electronically transmitted), responses of opinion or fact requested or required by or for CDC, except those specifically exempted or excluded, are subject to the provisions of the PRA and its implementing regulation, 5 CFR 1320 (Controlling Paperwork Burdens on the Public).
SECTION 11-OMB Security Requirements
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2) Safeguarding Information and Information Systems. In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the
Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
3) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality: [X] Low [ ] Moderate [ ] High
Integrity: [X] Low [ ] Moderate [ ] High
Availability: [X] Low [ ] Moderate [ ] High
Overall Risk Level: [X] Low [ ] Moderate [ ] High
Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:
[ ] No PII [X] Yes PII
Complete this section using the information obtained from the Security and Privacy Checklist in Appendix A, parts A and B.
4) Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother’s maiden name, biometric records, etc.
PII Confidentiality Impact Level has been determined to be: [X] Low [ ] Moderate [ ] High
5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
b. disclosed to authorized personnel on a Need-To-Know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
7) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
8) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6). .
9) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
10) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
See Appendix D for baseline deliverables.
11) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
d. Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR.
E. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to CDC Office of Chief Information Security Officer
(OCISO).
12) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
See Appendix C for the Contractor Non-Disclosure Agreement.
13) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.
a. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.
All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
D. Incident Response
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for another than authorized purpose.
OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information” (03 January 2017) states:
Definition of an Incident:
An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Definition of a Breach:
The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
It further adds:
A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.
Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:
1) The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.
2) All contractors and subcontractors shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
3) All contractors and subcontractors shall participate in regular training on how to identify and report a breach.
4) All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US- CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC) or CDC Computer Incident Response Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655-2245, whether the response is positive or negative.
5) All contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.
6) All contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with HHS/CDC Policy and the HHS/CDC Breach Response Plan and to assist with responding to a breach.
7) Cloud service providers shall use guidance provided in the FedRAMP Incident Communications Procedures when deciding when to report directly to US-CERT first or notify CDC first.
8) Identify roles and responsibilities, in accordance with HHS/CDC Breach Response Policy and the HHS/CDC Breach Response Plan. To this end, the Contractor shall NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .