Attachment 1- SST TMEI Statement of Work.doc.pdf

PDF 698 KB Posted

Attached to
Specialized Security Training Federal contract opportunity
Solicitation number
70T01021R7670N004
Issued by
Department of Homeland Security Transportation Security Administration

About this file

This statement of work outlines products and services required for the Transportation Security Administration's Specialized Security Training requirement. Key details include:

  • The contractor shall provide global threat mitigation, engineering, and imaging support including threat image library development and management, image capture and delivery for screening technologies, curriculum development, and simulator support.

  • Additional requirements involve help desk support, threat kit management, curriculum logistics, simulator logistics, check-in baggage and checkpoint image delivery, and transition services.

  • The contractor must adhere to project management principles, quality assurance standards, and TSA security requirements. Work may involve handling inert explosive simulants and other weapons.

  • The solicitation period closes on an upcoming date provided in Amendment 5 to the solicitation. The statement of work provides context for the Specialized Security Training requirement but does not include pricing or award details.

View the file

Other files for this federal contract opportunity

Other files attached to Specialized Security Training, newest first.
File Type Posted
SST RFP A00003.pdf PDF
RFP SST OTD001 - A00003.pdf PDF
Attachment 15 SST FFDO Range Locations A00003.pdf PDF
Attachment 13 SST Past Performance Sheet A00003.docx DOCX document
Attachment 1- SST TMEI Statement of Work A00002.pdf PDF
Attachment 14 - SST TSA OIT GFE List A00002.pdf PDF
Attachment 4 - SST Pricing A00002.xlsx XLSX spreadsheet
Attachment 9- SST PM Support PWS A00002.pdf PDF
SST RFP A00002.pdf PDF
RFP SST OTD001 - A00002.pdf PDF
Attachment 12- SST FFDO PWS A00002.pdf PDF
Attachment 13 SST Past Performance Sheet A00002.docx DOCX document
Attachment 3- SST RFP Question Answers 3-10-2021.pdf PDF
SST RFP A00001.pdf PDF
Attachment 5- SST Draft Curriculum Development SOW A00001.pdf PDF
SST RFP70T01021R7670N004 Final.pdf PDF
Attachment 2- TMEI SOW Attachment A - Non-SSI Kit Descriptions.pdf PDF
Attachment 3- SST RFP Question Answer Sheet.xlsx XLSX spreadsheet
Attachment 12 Wage Determination List.pdf PDF
Attachment 6- SST Inventory Listing.pdf PDF
Attachment 7- TSA MD 1900.14 Training Standards.pdf PDF
Attachment 9- SST PM Support PWS.pdf PDF
Attachment 10- MFSR_Template.xlsx XLSX spreadsheet
Attachment 11- SST FFDO PWS.pdf PDF
Attachment 8- TSA MD 1900.14 Training Standards Handbook.pdf PDF
Attachment 4 SST Pricing.xlsx XLSX spreadsheet
Show all 26

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP Attachment 1 – Statement of Work (SOW)

Table of Contents 1 Requiring Office(s) 2 Scope of Product, Service, or Outcome 3 Key Personnel 4 Task A - Global Threat Mitigation, Engineering, and Image (TME&I) Support 5 Task B - Help Desk Support 6 Task C - Threat Image Library (TIL) 7 Task D - Rapid Response / Threat in the Spotlight (Optional) 8 Task E - Checkpoint Image Delivery 9 Task F - Checked Baggage Image Delivery 10 10 Task G - Simulator Support 11 Task H - Kit Management 12 Task I - Curriculum Logistics Support 13 Task J - Transition In 14 Task K - Transition Out 15 Period of Performance 16 Place of Performance 17 Travel 18 Other Direct Costs (ODCs) 19 Appendix A - SOW Attachments 20 Appendix B - Definition of Terms

Threat Mitigation, Engineering, and Imaging

TME&I

STATEMENT OF WORK

1 Requiring Office(s)

In support of this task order, the contractor shall provide support services to the Office of Training and Development (T&D).

2 Scope of Product, Service, or Outcome

The Contractor shall provide a broad range of services to assist and support the Department of Homeland Security’s (DHS), Transportation Security Administration (TSA). They include but are not limited to the following:

• Adherence to Project Management Principles (as regulated by the Project Management Institute)

• Quality Assurance of all work and deliverables completed

• Management of Contractor Acquired Property, Government Furnished Equipment, Information, and Property (CAP / GFE / GFI / GFP)

• Adherence to TSA Security Requirements for Contractors and facilities

• Expertise in OEM technology, engineering, software development, instructional design, explosives and chemicals

• Proper management and storage of industrial chemicals and materials

• Help Desk and Field Support Services

• Logistics Support Services

• Threat Kit Program life cycle management and logistics support

• Curriculum logistics support

• Simulator logistics support

• Global Threat and Image Support for TSA learning technology products:

• Threat Image Library (TIL) development and management

• Capture/deliver images to support curriculum development, as well as training and tests for deployed checkpoint and checked baggage technologies

• Load/store images into libraries for use on TRX Simulators, Original Equipment

Manufacturer (OEM) simulators as needed, or as training image curricula

• Review/update image libraries as needed to comply with changes to TSA Standing

Operating Procedures (SOPs), Prohibited Items List (PIL) and other TSA guidance

• Develop ad-hoc images as needed to support emerging requirements

• Design, develop, analyze, pilot, and maintain screening training and testing/certification images and tests

• Product support, software development, requirements management, and helpdesk support for image based simulation products

3 Key Personnel

3.1 Task Order TME&I Program Manager (Key Personnel)

3.1.1 The Contractor’s TME&I Program Manager is designated as key personnel, and shall act as the central point of contact with the Government for all technical and management issues, and will represent the Contractor at all Task Order-level post-award status meetings. The Program Manager shall be responsible for all Task Order-level issue resolution, program management, and other contract support including providing comprehensive account support for the SST contract.

The TME&I Program Manager is responsible for overall TME&I Task Order performance.

4 Task A - Global Threat Mitigation, Engineering, and Image (TME&I) Support

4.1 Contractor Acquired Property, Government Furnished Equipment, Information, and Property

(CAP/GFE/GFI/GFP) Management

4.1.1 All CAP / GFE / GFI / GFP in the custody, control, possession, and management responsibility of the Contractor shall be managed, tracked, and reported IAW all federal regulations, government standards, and Contractor’s management controls. This includes comprehensive record keeping in the Government-provided Inventory Management System (IMS), to include all acquisition, identification, shipping and receiving, storage and warehousing, movement, maintenance, consumption, and disposition activities. The IMS shall provide a web-based, single and centralized repository for asset, inventory, and life-cycle management data. The Contractor shall conduct inventories and other asset management functions, with automated identification technology capable of address-acquired/identification events, day-to-day activities/major events, and retirement events within the IMS. The Contractor’s use of the Government provided IMS shall be compliant with federal regulations and government standards. Further, the Contractor will ensure asset management functions are compliant with the Joint Financial Management Improvement Program’s (JFMIP) Inventory, Supplies and Materials System Requirements (JFMIP-SR-03-02) and GAO Property Management System Requirements’ Checklist for Reviewing Systems, Under the Federal Financial Management Improvement Act, dated December 2001 (GAO-02-171G), specifically relating to the type of assets being managed by the Contractor (excepting any direct integration with the Government’s property management system, real property, heritage management, and lease management policies, unless specifically directed to do so in other guidance.

4.1.1.1 All CAP, GFE, and other Government assets and property in the custody, control, possession, and management responsibility of the Contractor shall be managed within the IMS to ensure:

4.1.1.1.1 Continuous control

4.1.1.1.2 Continuous monitoring while property and components are mobile

4.1.1.1.3 Event tracking of assets within the Government’s systems

This ensures Government property is tracked for physical internal controls, data stewardship, system integration, and the efficient management of Government assets, materials, and supplies. The Contractor shall ensure that the process of monitoring, controlling, and accounting for assets throughout their lifecycle is completed. This includes from the time funds are obligated for an asset, procurement, transfers of custodial and organizational accountability, physical inventory reviews, financial accounting and depreciation, capture of maintenance events, calculation of the cost of ownership, excess material, retirement/disposal of property with Government guidance and approval, as required.

4.1.1.2 The Contractor’s use of the Government provided IMS shall electronically manage and track property records of transfers for the gaining and losing property custodians.

4.1.1.3 The Contractor’s management controls shall ensure use of an approved data upload process for the Government’s Accountable Property System of Record (APSR) only when significant workload or level of authorization precludes individual entries into the APSR.

4.1.1.4 Only the CO can provide the following resolutions for inventory, with PA recommendations:

4.1.1.4.1 Declared unaccounted for

4.1.1.4.2 Confirmed unaccounted for

4.1.1.4.3 Inventory assets final event approved in Contractor’s system of record

For these states, the Contractor shall submit a completed Report of Survey (ROS) and SF-120 for assets being disposed of/dropped from accountability and will provide detailed circumstances, and justification in the asset’s history (whether lost, damaged, destroyed (LDD) or other). Along with all ROS documents, the Contractor shall provide asset timeline and detailed asset history, to include an auditable trail of who was involved in the activity and detailed description of the events surrounding the LDD, within the DHS and TSA-prescribed timeframes for reporting.

4.1.1.5 In coordination with the TSA Accountable Property Manager, the Contractor shall manage TSA accountable property in the TSA designated APSR and all firearms in the Federal Air Marshall Information System (FAMIS), and other systems as designated by TSA.

4.1.2 Key Property Management Standards

4.1.2.1 As appropriate, the below standards in 4.1.2.3 highlight basic property management perspectives of performance standards, practices, metrics, and methods of effectiveness for the conduct of management and administration activities for durable and movable assets beyond the FAR 45, FAR 46, and related clauses/regulations for conducting business according to industry standards and with the Government.

4.1.2.2 Specific areas highlighted below reflect aspects of personal property management from determination of needs and initial acquisition through final disposition, including receipt, identification and marking, record keeping, custodial and administrative accountability, reporting, consumption, maintenance, movement, storage, inventory, control, utilization, and disposition that should be considered in both establishment and daily operations. Other programmatic, project, financial, and life-cycle management requirements, measures, standards and maturity model requirements for management of assets, activities, services, and day-to-day operations must be coupled with these standards to achieve task expectations and/or requirements of laws, regulations, directives, manuals, etc.

4.1.2.3 Standards:

1. E2131-09 Standard Practice for Assessing Loss, Damage, or Destruction of Property

2. E2132-01(2007) Standard Practice for Physical Inventory of Durable, Moveable Property

3. E2135-10a Standard Terminology for Property and Asset Management

4. E2279-09 Standard Practice for Establishing the Guiding Principles of Property

Management

5. E2306-11 Standard Practice for Disposal of Personal Property

6. E2379-09 Standard Practice for Property Management for Career Development and

Training

7. E2452-10 Standard Practice for Equipment Management Process Maturity (EMPM) Model

8. E2453-05 Standard Practice for Determining the Life-Cycle Cost of Ownership of Personal

Property

9. E2495-07 Standard Practice for Prioritizing Asset Resources in Acquisition, Utilization, and Disposition

10. E2497-06 Standard Practice for Calculation of Equipment Movement Velocity (EMV)

11. E2499-06 Standard Practice for Classification of Equipment Physical Location

Information

12. E2604-09 Standard Practice for Data Characteristics of Equipment Records

13. E2605-08 Standard Practice for Receiving Property

14. E2606-08 Standard Practice for Receipt Notification as a Result of Tangible Property

Movement

15. E2607-08 Standard Practice for Cannibalization/Reclamation of Serviceable Equipment

Components to Support Demand Requirements

16. E2608-08 Standard Practice for Equipment Control Matrix (ECM)

17. E2631-09 Standard Practice for Physical Placement of an Entity-Controlled Supplemental

Identification Label

18. E2671-10 Standard Practice for Defining Movements, Shipments, and Transfers of

Tangible Property

19. E2672-09 Standard Practice for Identification and Categorization of Tooling

20. E2674-09 Standard Practice for Assessment of Impact of Mobile Data Storage Device

(MDSD) Loss

21. E2675-09 Standard Practice for Property Management System Outcomes

22. E2676-09 Standard Practice for Tangible Property Mobility Index (MI)

23. E2715-09 Standard Practice for Moveable Property Storage

24. E2811-11 Standard Practice for Management of Low Risk Property (LRP)

25. E2812-11 Standard Practice for Uniform Data Management in Asset Management

Records Systems

26. Executive Guide: Best Practices in Achieving Consistent, Accurate Physical Counts of

Inventories and Related Property (GAO-02-447G, March 2002)

27. Property Management System Requirements: Checklist for Reviewing Systems Under the

Federal Financial Management Improvement Act, December 2001, GAO-02-171G

28. Standards for Internal Control in the Federal Government, GAO/AIMD-00-21.3.1, November 1999

29. Internal Control Management and Evaluation Tool, GAO-01-1008G, August 2001.

30. Inventory System Checklist, GAO/AIMD-98-21.2.4, May 1998

31. JFMIP Property Management Systems Requirements (SR-00-4)

32. JFMIP Inventory, Supplies and Materials System Requirements (SR-03-02)

33. 41 CFR, Parts 100-128, Subtitle C, Federal Property Management Regulations System

34. 41 CFR, Parts 101-127, Inventory Management

35. OMB Circular A-123, Management Accountability and Control

4.1.3 The Contractor shall define the product(s) to be developed and/or produced in a Bill of Materials

(BOM) that describes all work and related elements of work to be accomplished or that will yield an end product and/or depicts the services to be provided. These BOMs shall serve as a starting point for the creation of a technical approach. These will reflect the most current approach or cost savings and include all the elements for the product(s) including hardware, software, data, or services. The custody of these elements, noted above, is the Contractor’s responsibility. These BOMs shall provide a comprehensive framework allowing for the Contractor’s management controls to be implemented, managed, assessed and/or audited. Some programs may have several contract BOMs, so that the BOM is useable both internally and externally, especially for the test of design for the assessment, by program, and/or other Government review/auditing entities. The Contractor shall submit the BOM to the COR within three (3) business days of completion of the

BOM.

4.1.4 The configuration of any TSE systems shall be the same as fielded units operating at the TSA specification for U.S. airports unless otherwise directed by the Government. Should a deviation (Request for Deviation (RFD)) to configuration be required, the Contractor shall submit the request to the Government for approval.

4.1.5 TSA will supply TSA property tags as needed.

4.1.6 Property records shall be managed by the Contractor with all acquisition, identification, receipt, storage and warehousing, movement, maintenance, consumption, and requests for disposal maintained current in the IMS. Contractor shall provide property records to the PA / COR NLT the 5th business day after the activity/transaction for bulk upload into the TSA APSR when Contractor’s access or level of access will not, in a timely fashion, accomplish the maintenance of currency of assets, inventory, and accountability or as otherwise mutually agreed upon by the Contractor and TSA. Disposition requests and recordation shall be coordinated with the PA and shall include the disposition of data, software, equipment, and documentation related to the asset, kit, and/or system. Property records, as well as assets and inventory, are subject to cyclic, selected items, special, spot, and wall to wall inventories. The accuracy, reliability, and reproducibly of counts and processes for inventories shall be testable for segregation of duties as well as clear auditable trails of data for assets and inventory. Property records shall provide comprehensive and clear order request, designation, and fulfillment details illustrating logistical reliability, documentation accuracy, delivery status, and segregation of duties for accountability purposes.

4.1.7 The Contractor shall include in the monthly report, an inventory list of all assets and a reconciliation of inventory across all Government and Contractor property management systems.

Government assessments, reviews, audits, and operations in general, may include physical inventory, document analysis, observations, physical examination, confirmation, interviews, questionnaires, and/or other assessment to obtain an opinion on the effectiveness of controls, accuracy of inventory, and test of design for process efficiency and effectiveness.

4.1.8 Maintenance of TSE Original Equipment Manufacturer (OEM) equipment is provided through the

TSA Office of Acquisition Program Management (APM). The Contractor shall be required to coordinate with TSA via the COR to reach APM. TSA will direct any OEM Contractor deliveries, but the Contractor may coordinate delivery schedules with the OEM Contractor personnel once directed by CO/COR.

4.1.9 The Contractor shall establish and maintain a comprehensive Reliability, Availability, and Maintainability (RAM) system that includes configuration and logistical management data points that optimize the utilization of assets and inventory. The maintenance history shall be maintained in the Government’s inventory management system with capability of reporting to data calls upon request of the Government at asset and major component levels.

4.1.10 The Contractor shall establish and maintain a life-cycle management program for both assets and inventory, which includes raw material, waste, prototype, first article, and standard’s management.

4.1.11 The Contractor shall ensure that asset, inventory, and life-cycle management efforts are designed to be able to provide utilization data upon request and historical data for both assets and inventory. The Contractor shall provide, upon request of the Government, for both periodic reporting and utilization in “what if” logistical scenario decision-making; and shall incorporate asset, inventory, and property management quality control and quality assurance reporting, documents, assessments, improvement validation records, findings, and recommendations, along with any quality initiation efforts that significantly benefited operations.

4.1.12 The Contractor shall maintain a log of all Reports of Survey (ROS), and assets in a lost, damaged, or destroyed status. This log shall be submitted to the COR whenever a sensitive item is added to the log and upon end of period of performance.

4.1.13 The Contractor shall maintain and track a log of all software and hardware licenses required for the TME&I program. This log shall be submitted to the COR whenever a new license is acquired or an old license is renewed.

4.1.14 Although periodic, data calls or requests to export data from systems/databases may be of a notice or no notice nature. Principally, these requests should be responded to when the request is made, within at most 24 hours, unless a timeframe has already been established in the paragraphs above specifically related to that report or data call. Request to correlate data that is not part of a requested report will be negotiated at the time of the request and based upon prioritization and importance of the request against current workload.

4.2 Security Requirements

4.2.1 Access to classified information up to the SECRET level is required to support this task order. All personnel supplied for tasks must have a current, interim or active U.S. Government Secret or higher clearance before they are submitted for clearance to TSA. The Contractor shall have a Secret facility clearance, active the date of proposal submission. The Contractor shall comply with all Federal, DHS and TSA security and privacy guidelines in effect at the time of the award of the contract, as well as those requirements that may be discretely added during the contract.

4.2.1.1 The Contractor shall comply with all Federal, Department of Homeland Security (DHS) and

Transportation Security Administration (TSA) security and privacy guidelines in effect at the time of the award of the contract, as well as those requirements that may be discretely added during the contract.

4.2.1.2 The Contractor shall perform periodic reviews to ensure compliance with all information security and privacy requirements.

4.2.1.3 The Contractor shall comply with all DHS and TSA security controls to ensure that the Government's security requirements are met. These controls are described in DHS PD 4300A and TSA MD 1400 series security policy documents and are based on the current National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 standards.

4.2.1.4 The Contractor shall include this guidance in all subcontracts at any tier where the subcontractor is performing the work defined in this statement of work (SOW).

4.2.1.5 The Contractor shall sign a DHS Non-Disclosure Agreement (NDA) within (30) calendar days of the contract start date.

4.2.1.6 The Contractor shall not release, publish, or disclose agency information to unauthorized personnel, and shall protect such information in accordance with the provisions of the pertinent laws and regulations governing the confidentiality of sensitive information.

4.2.1.7 The Contractor shall ensure that its staff follow all policies and procedures governing physical, environmental, and information security described in the various TSA regulations pertaining thereto, and the specifications, directives, and manuals for conducting work to generate the products as required by this contract. Personnel shall be responsible for the physical security of their area and government furnished equipment (GFE) issued to the contractor under the terms of the contract.

4.2.1.8 The Contractor shall make all system information and documentation produced in support of the contract available to TSA upon request.

4.2.2 The Contractor shall ensure all staff have the required level of security clearance commensurate with the sensitivity of the information being accessed, stored, processed, transmitted or otherwise handled by the System or required to perform the work stipulated by the contract. At a minimum, all Contractor staff shall be subjected to a Public Trust background check and be granted a Public Trust clearance before access to the System or other TSA resources is granted.

4.2.3 The Contractor shall be able to deliver to, work with, and provide and/or procure lab-developed chemically-based inert explosive simulants; threat mitigation X-ray images, and other threat mitigation developed materials, for testing, to Transportation Security Integration Facility (TSIF);

DHS Transportation Security Laboratory (DHS-TSL), and OEM Facilities; as required and approved by TSA; to TSA-HQ for program management and at U.S. airports, for approved deployment. The DHS-TSL is located in Egg Harbor, NJ, at the Federal Aviation Administration (FAA) Technical Center. Visitor requests are required consistent with the National Industrial Security Program Operating Manual (NISPOM) and need to know must be approved and certified by TSA prior to any access. The Contractor shall submit all requests for TSA approval.

4.2.4 The Contractor shall require a DD Form 254, Department of Defense Contract Security Classification Specification, based on the following specifications:

4.2.4.1 Access to SECRET Information.

4.2.5 The Contractor shall procure and maintain security and classified storage containers/cabinets to securely house materials rating a minimum classification of Sensitive Security Information (SSI) and firearms.

4.2.6 The Contractor shall store/safeguard SSI documents.

4.2.7 Select contract and sub-contract personnel shall require courier credentials issued by DHS/TSA to allow for the transport of classified information. The Contractor shall provide a list of trained classified couriers to the COR NLT 15 days after award to facilitate issuance of the appropriate credentials.

4.2.8 Select contract and sub-contract employees assigned to this TO shall require credentials that indicate that they work in support of TSA and frequently transport inert explosive simulants that appear real without lab testing, and other weapons including real and inert replicas.

4.2.9 Select contract and sub-contract employees assigned to this TO shall require TSA badges that will allow them to be issued TSA white package computers. Physical access to TSA headquarters is not required. The white package computers are required to allow these select contract and sub-contract employees access to the TSA iShare and the On-line Learning Center (OLC) via Virtual Private Network (VPN) or the TSA network.

4.2.10 In accordance with the Department of Defense (DOD) Manual 5220.22-M, “National Industrial Security Program Operating Manual (NISPOM) for Safeguarding Classified Information,” Chapter 5, Section 5-502, the Contractor is authorized to disclose TSA classified information to cleared sub-contractors when access is necessary to perform tasks or services for fulfillment of a prime or sub-contract.

4.2.11 In accordance with the Department of Defense (DOD) Manual 5220.22-M, “National Industrial Security Program Operating Manual (NISPOM) for Safeguarding Classified Information,” Chapter 5, Section 5-506, the Contractor shall not disclose classified information received or generated under this TSA contract to any other Federal agency unless specifically authorized in writing by the TSA Program Office that has classification management jurisdiction over the information and the TSA COR.

4.2.12 In accordance with the Department of Defense (DOD) Manual 5220.22-M, “National Industrial Security Program Operating Manual (NISPOM) for Safeguarding Classified Information,”, Chapter 5, Section 5-509, the Contractor shall not disclose classified information to another Contractor except to support a contract, sub-contract or other TSA purpose.

4.2.13 Contractor must safeguard classified material in accordance with Executive Order 13526, Classified National Security Information and DHS Instruction 121-01-011, DHS Administrative Security Program, at the SECRET level in support of program office requirements. Additionally, in accordance with the Department of Defense (DOD) Manual 5220.22-M, National Industrial Security Program Operating Manual (NISPOM) for Safeguarding Classified Information, Chapter 5, Section 5-502, the Contractor is authorized to disclose TSA classified information to cleared sub-contractors when access is necessary to perform tasks or services for fulfillment of a prime or sub-contract. However, prior written approval by the CO or his/her designee is required. Additionally, pursuant to NISPOM, Chapter 5, Section 5-506, the Contractor shall not disclose classified information received or generated under this TSA contract to any other Federal agencies unless specifically authorized in writing by the TSA Program Office that has classification management jurisdiction over the information and the TSA COR. In accordance with the NISPOM, Chapter 5, Section 5-509, the Contractor shall not disclose classified information to another Contractor except to support a contract, sub-contract or other TSA purpose. The Contractor must first obtain written approval from the responsible CO or his/her designee before it exercises any actions authorized by NISPOM Chapter 5, Sections 5-502, 5-506, and 5-509.

4.2.13.1FAR Clause 52.204-2 applies to the extent that this contract involves access to information classified “Confidential” and/or “Secret”

The Contractor shall comply with—

(1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M); and

(2) Any revisions to that manual, notice of which has been furnished to the Contractor

(3) If, subsequent to the date of this contract, the security classification or security requirements under this contract are changed by the Government and if the changes cause an increase or decrease in security costs or otherwise affect any other term or condition of this contract, the contract shall be subject to an equitable adjustment as if the changes were directed under the Changes clause of this contract.

(4) The Contractor agrees to insert terms that conform substantially to the language of this clause, including this paragraph (4) but excluding any reference to the Changes clause of this contract, in all sub-contracts under this contract that involve access to classified information.

4.2.14 Security Requirements for Handling Personally Identifiable Information and Privacy Incident

Response (July 2017) of Systems handling personally identifiable information and privacy incident response.

1. Definitions.

(a) “Breach” (may be used interchangeably with “Privacy Incident’) as used in this clause means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to Personally Identifiable Information, in usable form whether physical or electronic.

(b) “Personally Identifiable Information (PII)” as used in this clause means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States. Examples of PII include: name, date of birth, mailing address, telephone number, Social Security Number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), Internet protocol addresses, biometric identifiers (e.g., fingerprints), photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

(c) “Sensitive Personally Identifiable Information (Sensitive PII)” as used in this clause is a subset of Personally Identifiable Information, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Complete social security numbers (SSN), alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered Sensitive PII even if they are not coupled with additional PII. Additional examples include any groupings of information that contains an individual’s name or other unique identifier plus one or more of the following elements:

(1) Driver’s license number, passport number, or truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Financial information such as account numbers or Electronic Funds Transfer Information

(5) Medical Information

(6) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other Personally Identifiable information may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains Personally Identifiable Information but it is not sensitive.

2. Systems Access. Work to be performed under this contract requires the handling of Sensitive PII.

The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The contractor shall provide the Government access to, and information regarding the contractor’s systems, when requested by the Government, as part of its responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the Government in assuring compliance with such requirements. Government access shall include independent validation testing of controls, system penetration testing by the Government, Federal Information Security Management Act (FISMA) data reviews, and access by agency Inspectors General for its reviews.

3. Systems Security.

(a) In performing its duties related to management, operation, and/or access of systems containing

Sensitive PII under this contract, the contractor, its employees and subcontractors shall comply with applicable security requirements described in the most current versions of DHS Sensitive System Publication 4300A or any replacement publication and rules of conduct as described in TSA Management Directive (MD) 3700.4.

(b) All Contractor-operated systems that input, store, process, output, and/or transmit SPII shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(c) Use of contractor-owned laptops or other media storage devices to process or store PII is prohibited under this contract until the contractor provides, and the contracting officer in coordination with CISO approves, written certification by the contractor that the following requirements are met:

(i) Laptops employ encryption using a NIST Federal Information Processing Standard (FIPS) 140- 2 or successor approved product;

(ii) The contractor has developed and implemented a process to ensure that security and other applications software are kept current;

(iii) Mobile computing devices utilize anti-viral software and a host-based firewall mechanism;

(iv) When no longer needed, all removable media and laptop hard drives shall be processed (i.e., sanitized, degaussed, or destroyed) in accordance with DHS security requirements.

(v) The contractor shall maintain an accurate inventory of devices used in the performance of this contract;

(vi) Contractor employee training requirements are covered in FAR 52.224-3.

(vii) All Sensitive PII obtained under this contract shall be removed from contractor-owned information technology assets upon termination or expiration of contractor work. Removal must be accomplished in accordance with DHS Sensitive System Publication 4300A, which the contracting officer will provide upon request. Certification of data removal will be performed by the contractor’s Project Manager and written notification confirming certification will be delivered to the contracting officer within 15 days of termination/expiration of contractor work.

4. Data Security.

(a) Contractor shall limit access to the data covered by this clause to those employees and subcontractors who require the information in order to perform their official duties under this contract.

(b) The contractor, contractor employees, and subcontractors must physically secure Sensitive PII when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss. When Sensitive PII is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed through means that will make the Sensitive PII irretrievable. The contractor shall only use Sensitive PII obtained under this contract for purposes of the contract, and shall not collect or use such information for any other purpose without the prior written approval of the contracting officer. At expiration or termination of this contract, the contractor shall turn over all Sensitive PII obtained under the contract that is in its possession to the Government.

(c) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain Sensitive PII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

5. Breach Response. The contractor agrees that in the event of any actual or suspected breach of SPII

(i.e., loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic), it shall immediately, and in no event later than one hour of discovery, report the breach to the Contracting Officer, the Contracting Officer’s Representative (COR), and the TSA Director of Privacy Policy & Compliance (TSAprivacy@dhs.gov<mailto:TSAprivacy@tsa.dhs.gov>). The contractor is responsible for positively verifying that notification is received and acknowledged by at least one of the foregoing Government parties. The report of a breach shall not, by itself, be interpreted as evidence that the contractor failed to provide adequate safeguards for SPII.

Award fee contracts:

(a) For any portions of this contract that involve an award fee, the contractor may be awarded no award fee for any evaluation period in which there is a breach of privacy or security, including any loss of mailto:TSAprivacy@dhs.gov%3cmailto:TSAprivacy@tsa.dhs.gov sensitive data or equipment containing sensitive data. Lost award fee due to a breach of privacy or security may not be allocated to future evaluation periods.

(b) For any portions of this contract that involve an award fee, to ensure that the final award fee evaluation at contract completion reflects any breach of privacy or security in an interim period, the overall award fee pool shall be reduced by the amount of the fee available for the period in which the breach occurred if a zero fee determination was made because of a breach of privacy or security.

6. Personally Identifiable Information Notification Requirement.

(a) The contractor shall have in place procedures and the capability to promptly notify any individual whose Sensitive PII was, or is reasonably believed to have been, breached, as determined appropriate by the Government. The method and content of any notification by the contractor shall be coordinated with, and subject to the prior approval of the Government, based upon a risk-based analysis conducted by the Government in accordance with DHS Privacy Incident Handling Guidance. Notification shall not proceed unless the Government has determined that: (i) notification is appropriate; and (ii) would not impede a law enforcement investigation or jeopardize national security.

Subject to Government analysis of the breach and the terms of its instructions to the contractor regarding any resulting breach notification, a method of notification may include letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. At minimum, a notification should include: (i) a brief description of how the breach occurred; (ii) a description of the types of personal information involved in the breach; (iii) a statement as to whether the information was encrypted or protected by other means; (iv) steps an individual may take to protect themselves; (v) what the agency is doing, if anything, to investigate the breach, to mitigate losses, and to protect against any further breaches; and (vi) point of contact information identifying who affected individuals may contact for further information.

(b) In the event that a PII breach occurs as a result of the violation of a term of this contract by the contractor or its employees, the contractor shall, as directed by the contracting officer and at no cost to the Government, take timely action to correct or mitigate the violation, which may include providing notification and/or other identity protection services to affected individuals for a period not less than18 months from discovery of the breach. Should the Government elect to provide and/or procure notification or identity protection services in response to a breach, the contractor will be responsible for reimbursing the Government for those expenses.

7. Pass-Through of Security Requirements to Subcontractors. The contractor agrees to incorporate the substance of this clause, its terms and requirements, in all subcontracts under this contract, and to require written subcontractor acknowledgement of same. Violation by a subcontractor of any provision set forth in this clause will be attributed to the contractor.

4.2.15 Authorities

The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

4.2.16 Handling of Sensitive Information

Contractor compliance with this clause, as well as the policies and procedures described below, is required.

4.2.16.1Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation.

Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

4.2.16.2The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

4.2.16.3All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

4.2.16.4The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to http://csrc.nist.gov/publications/PubsSPs.html maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

4.2.17 Authority to Operate

4.2.17.1The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

4.2.17.2Complete the Security Authorization process. The SA process shall proceed according to the

DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

4.2.17.2.1 (Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty

(30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

4.2.17.2.2 Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations.

The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

4.2.17.2.3 Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years.

Upon review of the PTA, the DHS Privacy Office determines whether a Privacy

Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones.

Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

4.2.17.3Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90-day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

4.2.17.4Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90-day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

4.2.17.5Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .