Attachment 1-SOW ver2.pdf

PDF 259 KB Posted

Attached to
Online registration tool Federal contract opportunity
Solicitation number
70RCSA20R00000016
Issued by
Department of Homeland Security Office of Procurement Operations

View the file

Other files for this federal contract opportunity

Other files attached to Online registration tool, newest first.
File Type Posted
RFP Terms and Conditions Ver2.pdf PDF
Attachment 2- Pricing Template.xlsx XLSX spreadsheet
RFP 70RCSA20R00000016 SF1449 Ver2.pdf PDF
Attachment 3 Past Perfromance Questionnaire RFP.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF HOMELAND SECURITY (DHS)

CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY (CISA)

INFRASTRUCTURE SECURITY DIVISION (ISD)

STATEMENT OF WORK (SOW)

for

ONLINE MEETING REGISTRATION TOOL, ONARRIVAL360, AND MOBILE EVENT

APPLICATION TOOL

1.0. Background

Within Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA), the Infrastructure Security Division’s (ISD) the Office of Infrastructure Security Compliance Division (ISD) has the unique mission to implement the Chemical Facility Anti- Terrorism Standards (CFATS), the nation’s program to regulate security at high-risk chemical facilities, and a proposed Ammonium Nitrate Security Program.

ISD conducts outreach to identify chemical facilities of interest that may be subject to regulations under CFATS and to make available compliance assistance materials and information on CFATS-related education and training. ISD hosts both virtual and in-person events such as; trainings, conferences, Webinars and teleconferences to accomplish this goal.

Many of these events attract a large number of public and private sector participants with the majority attracting upwards of 200 attendees. In particular, over 600 external stakeholders registered for the annual Chemical Sector Security Summit (“Summit”) in 2019 and more individuals are expected to register for the 2020 Summit. In addition, the first series of three DHSChemSecurityTalks conferences recently held in the summer of 2018 has attracted over 530 registrants. ISD has been using CVENT’s online registration tool to efficiently collect registrant information to reduce the burden of data collection and data security risks at both the Summit and DHSChemSecurityTalks events. ISD is seeking to renew and expand its online registration capabilities with the mobile event application and OnArrival360 tool that will be fully integrated with the current online registration tool to effectively reduce the time and costs of preparing and shipping hardcopy meeting materials, as well as enhance real-time communications with and between attendees before, during, and after the event.

2.0 SCOPE

The online registration tool will allow individuals to self-register for voluntary events offered by ISD. Only selected members of ISD will have access to the registration data, that is housed in a secured password protected database, and that will be archived at the conclusion of the event.

The registration tool will have the capability of producing a variety of statistical reports regarding the composition of the attendees, a feature that will enable ISD to conduct event analysis. Other benefits of using an online self-registering tool include:

• Reserving space at meetings for registrants;

• Managing a wait list;

• Sending out event reminders;

• Ensuring an adequate number of meeting materials for attendees

• Generating session attendee lists (participants must opt-in);

• Assisting with room management of high interest sessions; and

• Generating materials such as conference nametags.

The integrated mobile event application tool with OnArrival360 will improve communications with event participants on many levels. Registrants will have access to information previously available in hardcopy, such the Summit agenda, speaker biographies, and evaluation surveys directly on their smartphones. Registrants will also have access to social sharing opportunities with fellow industry peers, experts, and leaders via the mobile event application tool. It will be possible to push real-time updates to registrants during the event, including room change alerts or session-level survey reminders. The attendee’s experience will be enhanced via live polling, live question & answer sessions, and the session-level surveys will allow speakers to better interact with their audience during and after the session. Additionally, the OnArrival360 tool enables the registration staff to check in attendees, register walk-ins, collect signatures, and print name badges on-demand. Other benefits of integrating with the mobile event application tool include:

• Reducing, or nearly eliminating, the time and costs spent on development, printing and shipping of hardcopy meeting materials such as agendas, speaker biographies, name badges and evaluation forms;

• Reducing the number of staff needed to travel to the event in order to staff a room for question & answer portions of a session (such as, microphone attendants)

• Reduce the number of staff needed to travel to the event in order to staff the registration table;

• Promoting attendee interaction with industry peers, experts, and leaders via social sharing opportunities

• Enhancing the attendee experience via live polling, live question & answer features, and session-level surveys to allow speakers to better interact with their audience during and after the session. Seamless integration with the current online registration tool. Agenda items entered into the online registration tool will automatically populate within the mobile event application.

3.0 OBJECTIVE

ISD is seeking to procure online registration tool that will allow individuals to self- register for DHS voluntary events, reduce the burden of data collection, have the capability of producing event analysis reports and increase the security of the information collected. ISD also seeks to use a mobile event application tool and OnArrival360 that will integrate with the current online registration tool to improve communications with event participants by providing real-time notifications as well as enhance interactions with attendees by offering live polling, live Q&A, and social networking opportunities with industry peers, experts and leaders.

4.0 APPLICABLE DOCUMENTS

Compliance Documents

The following documents provide specifications, standards, or guidelines that must be complied with in order to meet the requirements of this contract:

• ISD Mobile Event Application Tool Requirements

5.0 SPECIFIC REQUIREMENTS/TASKS

The Contractor shall possess the following capabilities and requirements:

• Host multiple concurring events;

• Waitlist function;

• Administrator(s) can manually place individuals on the waitlist instead of registering them;

• Administrator(s) can send emails manually or automated to registrants with hyperlinks or attachments (e.g. invitation, confirmation, reminder thank you and certificates);

• Administrator(s) can create custom reports (e.g. by organization, industry, location, etc);

• Can customize the sender's email address so it is recognizable (i.e. sender is DHS.gov) and to reduce spam;

• Customizable templates are available and able to bring in own graphics;

• Registrants can select optional concurring sessions (i.e. breakouts);

• Optional sessions can have a maximum capacity set ;

• Can create unique and unlimited questions for registrants;

• Administrator(s) can organize registrants and pull reports based on the answers to the questions asked during the registration process;

• Provides a 24 x 7 helpdesk to answer questions and provide assistance;

• Can post custom messages (e.g. privacy statement);

• Can create name tags, tent cards and certificates using templates provided and merged registrant data;

• PCI Level 1 Compliant (for credit card processing);

• Can list the event as public (searchable online) or private;

• Data can be archived and administrators can have access for desired amount of time;

• Restricted, logged access to server room/data center floor;

• Permission-based external firewalls;

• Denial of Service protection;

• Intrusion Detection system;

• Restricted inter-server communication;

• Restrictive administrator permissions and file access controls;

• No shared server authentication;

• Only credentialed users gain access to the system – and then only to permitted resources;

• Enforced strong password policies, including account lockout and password expiration

• 508 compliant Web site;

• Pre-approved through an existing Paper Work Reduction Act and Privacy Impact

Analysis for data collection;

• Administrator can select pre-registration services or onsite event assistance (i.e. can opt to not have and pay for onsite event assistance/services);

• Provides free training for administrators/users;

• Can create name tags, tent cards and certificates for no additional cost;

• Customizable templates are available for free;

• Registrants will receive a personalized summary/schedule of what they registered for;

• Questions can have sub-questions created; and

• Can roll-over unused registrations into new contract.

• Provide information such as the agenda, speaker biographies, and evaluations of the event within the mobile event app

• Provide brief instructions to attendees on how to download and use the mobile event application

• Live polling

• Live Q&A

• Session-Level surveys

• Event-level surveys

• Push instant notifications of event alerts and announcements

• Link social media profiles to event app for easy posting and sharing

• Provide an activity feed of social updates

• In-app messaging capability between event participants

• Provide a 24x7 help desk to answer questions and provide assistance

• Seamless integration with the current online registration tool, CVENT

• Provide training on the use of the mobile event application’s content management system

• Content management system to build content and configure the mobile event app

• Customize event’s security, privacy and social media settings

• Custom branding

• View event content both online and offline on iOS and Android devices

• Provide HTML5 version of the mobile event application for those using Blackberry, Windows devices, or laptop/desktop computer

• Schedule personalization

• Appointment function with other attendees, exhibitors or speakers

• Digital contact information exchange feature for attendees and speakers

• Note-taking capability within the mobile event app

• Sponsor Profiles

• Exhibitor Profiles

• Reporting/measurement function

5.1 Task One - Provide Registrant Slots

Provide a 24 x 7 x 365 capability to create specific event registration website landing pages that contain information relevant to the meeting such as an agenda, other background information;

and lodging options. The landing page will also allow for the gathering of information such as interest in particular sessions; how individuals heard about the event; and select demographic information.

The provider will also ensure a 24 x7 x 365 mobile event application capability to allow individuals to actually submit their information to register for an event. Total registrant slots to be provided each year is 1,250.

Provider will ensure a 24 x 7 x 365 capability to allow the event organizer to correspond with those registered for the event to provide registration confirmations; informational messages via e-mail; and event updates.

5.2 Task Two - Support and Maintenance

Provide annual maintenance of the online registration tool and mobile event application in addition to unlimited online training, unlimited phone/email support, 24 x 7 x 365 helpdesk support; and data storage/security costs.

6.0 CONTRACTOR PERSONNEL

6.1 Qualified Personnel

The Contractor shall provide qualified personnel to perform all requirements specified in this

SOW.

6.2 Continuity of Support

The Contractor shall ensure that the contractually required level of support for this requirement is maintained at all times. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor shall provide e-mail notification to the COR prior to employee absence. Otherwise, the Contractor shall provide a fully qualified replacement.

6.3 Key Personnel

Before replacing any individual designated as Key by the Government, the Contractor shall notify the Contracting Officer no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes shall possess qualifications equal to or superior to those of the Key person being replaced. The Contractor shall not replace Key Contractor personnel without acknowledgment from the Contracting Officer. The following Contractor personnel in Section 3.4 are designated as Key for this requirement. Note: The Government may designate additional Contractor personnel as Key at the time of award.

6.4 Project Manager

The Contractor shall provide a Project Manager who shall be responsible for all Contractor work performed under this SOW. The Project Manager shall be a single point of contact for the Contracting Officer and the Contracting Officer’s Representative (COR). It is anticipated that the Project Manager shall be one of the senior level employees provided by the Contractor for this work effort. The name of the Project Manager, and the name(s) of any alternate(s) who shall act for the Contractor in the absence of the Project Manager, shall be provided to the Government as part of the Contractor's proposal. The Project Manager is further designated as Key by the Government. During any absence of the Project Manager, only one alternate shall have full authority to act for the Contractor on all matters relating to work performed under this contract. The Project Manager and all designated alternates shall be able to read, write, speak and understand English. Additionally, the Contractor shall not replace the Project Manager without prior acknowledgement from the Contracting Officer.

7.0 ISD Contracting Officer’s Reprensentative:

Angela M. Hughes Angela.hughes@cisa.dhs.gov

(703) 235-9309

7.1 Employee Conduct

Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Project Manager shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.

7.2 Removing Employees for Misconduct or Security Reasons

The Government may, at its sole discretion (via the Contracting Officer), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons.

Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.

7.3 SECURITY

All hardware, software, and services provided under this task order must be compliant with DHS 4300A DHS Sensitive System Policy and the DHS 4300A Sensitive Systems Handbook.

Security Review

The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, including the organization of the DHS Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer’s Technical Representative (COTR), and other government oversight organizations, access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract.

The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to the DHS. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of DHS data or the function of computer systems operated on behalf of DHS, and to preserve evidence of computer crime.

DHS 4300A Ver.12.01 3.3 Contractors and Outsourced Operations DHS 4300A Policy - 3.3.b. All Contractor information system services and operations shall adhere to all applicable DHS information security policies.

DHS 4300A Ver.12.01 3.12 Information Security Policy Violation and Disciplinary Action mailto:Angela.hughes@cisa.dhs.gov mailto:Angela.hughes@cisa.dhs.gov

DHS 4300A Policy - 3.12.b. Non-DHS Federal employees, contractors, or others working on behalf of DHS who fail to comply with Department security policies are subject to termination of their access to DHS systems and facilities whether or not the failure results in criminal prosecution.

DHS 4300A Ver.12 4.8.3 Personally Owned Equipment and Software DHS 4300A Policy - 4.8.3.b Equipment that is not owned or leased by the Federal Government, or operated by a contractor on behalf of the Federal Government, shall not be connected to DHS equipment or networks without the written prior approval of the Component CISO/ISSM.

DHS 4300A Ver.12.01 4.8.5 Personal Use of Government Office Equipment and DHS Systems/Computers DHS 4300A Policy - 4.8.5.c Anyone granted user account access to any DHS information system (including DHS employees, contractors, and others working on behalf of DHS) shall have no expectations of privacy associated with its use. By completing the authentication process, the user acknowledges his or her consent to monitoring.

DHS 4300A Policy - 4.8.5.f Contractors, others working on behalf of DHS, or other non-DHS employees are not authorized to use Government office equipment or information systems/computers for personal use, unless limited personal use is specifically permitted by the contract or memorandum of agreement. When so authorized, the limited personal use policies of this section and the provisions of DHS MD 4600.1, DHS MD 4900, DHS MD 4400.1, and DHS MD 4500.1 shall apply

8.0 PERIOD OF PERFORMANCE

The period of performance for this contract is a one-year base period with four one-year option periods as follows:

Base Period September 30, 2020 through September 29, 2021 Option Period One September 30, 2021 through September 29, 2022 Option Period Two September 30, 2022 through September 29, 2023 Option Period Three September 30, 2023 through September 29, 2024 Option Period Four September 30, 2024 through September 29, 2025

9.0 PLACE OF PERFORMANCE

Contractor will perform duties from their primary location of doing business.

10.0 HOURS OF OPERATION

Contractor shall provide a help desk capability on a 24 x 7 x 365 basis. Tool should be accessible for event administrator and interested individuals to register 24 x 7 x 365.

Access to provider account managers 9:00-5:00 Monday through Friday.

11.0 TRAVEL

Contractor travel shall not be required for this requirement.

12.0 POST AWARD CONFERENCE

The Contractor shall attend a Post Award Conference with the Contracting Officer and the COR no later than 10 business days after the date of award. The purpose of the Post Award

Conference, which will be chaired by the Contracting Officer, is to discuss technical and contracting objectives of this contract and review the Contractor's draft project plan. The Post Award Conference will be held at the Government’s facility, located at 2451 Crystal Drive, Arlington, VA or via teleconference.

13.0 PROGRESS REPORTS

The Project Manager shall provide a monthly progress report to the Contracting Officer and COR via electronic mail. This report shall include a summary of all Contractor work performed, including a breakdown of hours of help desk assistance; number of registration slots used by month and cumulative; and any Contractor concerns or recommendations for the previous reporting period.

14.0 PROGRESS MEETINGS

The Project Manager shall be available to meet with the COR upon request, but not less than every six months, to present deliverables, discuss progress, exchange information and resolve emergent technical problems and issues. These meetings shall take place in person or via teleconference.

15.0 GENERAL REPORT REQUIREMENTS

The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows XP and Microsoft Office Applications).

16.0 PROTECTION OF INFORMATION

PRIVACY REQUIREMENTS

16.1 Safeguarding of Sensitive Information (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause –

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual’s identity, such as name, Social Security Number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name.

The definition of PII is not anchored to any single category of information or technology.

Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source— that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security Number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security Numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal history

(7) Medical information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800- 53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://csrc.nist.gov/groups/STM/cmvp/standards.html http://csrc.nist.gov/groups/STM/cmvp/standards.html http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by stature or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty

(30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlines in NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete the PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years.

Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones.

Support in this context includes responding timely to requests for information from the Government about use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

http://www.dhs.gov/privacy-compliance http://www.dhs.gov/privacy-compliance

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls;

or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140- 2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three

(3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any email. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email.

Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Data Universal Numbering System (DUNS);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the System for Award

Management (address, position, telephone, email);

(v) Contracting Officer POC (address, telephone, email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the Government PII and/or SPII contained within the system;

(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

(g) Sensitive Information Incident Response Requirements

(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.

(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:

(i) Inspections,

(ii) Investigations,

(iii) Forensic reviews, and

(iv) Data analyses and processing.

(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

(h) Additional PII and/or SPII Notification Requirements

(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after bring directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.

(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:

(i) A brief description of the incident;

(ii) A description of the types of PII and SPII involved;

(iii) A statement as to whether the PII or SPII was encrypted or protected by other means;

(iv) Steps individuals may take to protect themselves;

(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and

(vi) Information identifying who individuals may contact for additional information.

(i) Credit Monitoring Requirements. In the event that a sensitive information incident involves

PII or SPII, the Contractor may be required to, as directed by the Contracting Officer:

(1) Provide notification to affected individuals as described above; and/or

(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified. Credit monitoring services shall be provided from a company with which the Contractor has no affiliation. At a minimum, credit monitoring services shall include:

(i) Triple credit bureau monitoring;

(ii) Daily customer service;

(iii) Alerts provided to the individual for changes and fraud; and

(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or

(3) Establish a dedicated call center. Call center services shall include:

(i) A dedicated telephone number to contact customer service within a fixed period;

(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;

(iii) Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics;

(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate;

(v) Customized FAQs, approved in writing by the Contracting Officer in coordination with the Headquarters or Component Chief Privacy Officer; and

(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.

(j) Certification of Sanitization of Government and Government-Activity-Related Files and Information. As part of contract closeout, the Contractor shall submit the certification to the COR and the Contracting Officer following the template provided in NIST Special Publication 800-88 Guidelines for Media Sanitization.

16.2 Information Technology Security and Privacy Training (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Security Training Requirements.

(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. The Department of Homeland Security (DHS) requires that Contractor employees take an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via email notification not later than October 31st of each year. The email notification shall state the required training has been completed for all Contractor and subcontractor employees.

(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information.

The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors thirty (30) days of contract award. Any new Contractor employees assigned to the contract shall also sign the DHS Rules of Behavior before accessing DHS systems and sensitive information.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .