Attachment 12- Background Investigation Requirements.pdf

PDF 739 KB Posted

Attached to
Nationwide Default Management Services (NDMS) Federal contract opportunity
Solicitation number
DRAFT-12SAD222R0001
Issued by
Not on record

View the file

Other files for this federal contract opportunity

Other files attached to Nationwide Default Management Services (NDMS), newest first.
File Type Posted
Draft RFP Questions and Answers_update.pdf PDF
Draft RFP Questions and Answers.pdf PDF
NDMS Program Industry Day March 21 2022.pptx PPTX presentation
Q and A from Industry Day March 21 2022.xlsx XLSX spreadsheet
Attachment 11- Performance Work Statement.docx DOCX document
Attachment B - Subcontracting_Plan_TEMPLATE.docx DOCX document
Attachment 13- System Privacy Baseline Process Requirements.pdf PDF
Attachment 05 - Quality Control Plan.docx DOCX document
Attachment 04 - Vendor Management Plan.docx DOCX document
Draft RFP Question and Comment Template.xlsx XLSX spreadsheet
Attachment 08 - NDMS Task Order Procedures.docx DOCX document
Attachment 07 - Subcontracting Plan.docx DOCX document
Attachment 02 - PMO 20.4-1 USDA RD Visual Identity Guidelines.pdf PDF
Attachment H- Forclosure Unpaid Principal Balance as of June 2021.xlsx XLSX spreadsheet
Attachment F- USDA RD Properties Sold with Average Sale Price by State and UPB.pdf PDF
Attachment D - Oral Presentation Instructions.docx DOCX document
Attachment 10- AD-3030 Representations Regarding Felony Conviction.pdf PDF
Attachment 09 - NDA Rural Development.docx DOCX document
Attachment 03 - Program Management Plan.docx DOCX document
Attachment G- Offeror Questions Template.xlsx XLSX spreadsheet
Attachment 06 - Attorney Approval Request Template.docx DOCX document
Attachment E - DRAFT IDIQ TEP Workbook.xlsx XLSX spreadsheet
NDMS Draft RFP.pdf PDF
NDMS lessons learned.pdf PDF
Attachment C - Cross Reference Matrix.xlsx XLSX spreadsheet
Attachment A - Past Performance Cover Letter and Questionnaire.doc DOC document
Attachment 01 - Network Access Security Policy.docx DOCX document
Show all 27

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BACKGROUND INVESTIGATION REQUIREMENTS

Prior to beginning any work on this PWS, all Contractor employee(s) shall undergo a security screening. All Contractor employees are, at a minimum, subject to a minimum background investigation (MBI) conducted by the Government. Security clearance above the MBI may be required for a specific Work Assignment. Contractor employees who undergo MBI checks which reveal the following may be unacceptable under this acquisition: conviction of a felony, a crime of violence or a serious misdemeanor, or a record of arrests for continuing offenses.

Should the results of any background investigation include any of the above items, the Contractor shall agree to remove the person assigned within one business day of official notification by the Government and provide a replacement within ten business days. New hires or substitution of personnel are subject to the MBI requirement.

a. The software systems under this PWS may contain financial data subject to privacy laws and regulations. The Contractor shall be responsible for assuring that all personnel having access to Privacy Act data have a MBI security clearance prior to access to the data. This includes personnel and technicians on or off-site in which access to the data is possible. Individuals with security clearances shall be responsible for ensuring that sensitive data is not transmitted to unauthorized parties.

b. Upon date of award, the Contractor shall identify to the Contracting Office Representative (COR) those individuals who have security clearances or who shall be in need of security clearances, unless otherwise specified by the OCO. The Government shall provide the necessary background investigation request forms required for each individual identified for clearance. The forms required are:

1. Fingerprint Chart (2 sets required)

2. Standard Form (SF) 171, Personal Qualifications Statement or a Resume

3. OF 306 – Declaration for Federal Employment

4. Fair Credit Reporting Release Form

Online access to SF-85P, Questionnaire for Public Trust Positions, shall be provided by the Government when the COR provides the appropriate request to this office.

c. All forms must be typed, or printed neatly in ink. Once the required documents have been completed, including the online SF-85P, the applicant must take the package to the location specified in the particular Work Assignment or by the COR. The applicant shall be required to setup an appointment to ensure the proper individual is available to receive the completed package. TWO FORMS OF IDENTIFICATION (SOURCE DOCUMENTS) shall BE

REQUIRED FOR VERIFICATION PURPOSES.

Attachment 12 Background Investigation Requirements

Solicitation 12SAD122R0001

If requested, the Contractor shall make any appropriate corrections, and return the corrected forms within 3 working days after the request is received.

The Contractor is responsible for all costs associated with obtaining background investigations and fingerprints.

d. Background investigations conducted by other Federal Government Agencies may be accepted. The Contractor must provide proof of an acceptable background investigation to RD Servicing Personnel Office. Determination of acceptability is at the discretion of RD.

e. The Government has the right to perform periodic on-site inspections of Contractor operations to ensure compliance with information protection requirements outlined in Federal Government regulations.

f. The agency (RD) reserves the right, at any time, to require replacement of Contractor personnel, if the individual does not meet the security requirements.

g. Prior to starting contractual work affected by the Privacy Act, the Contractor is responsible for providing proof of security clearance or submitting all required documents as identified in

(b) above to the agency (RD) Servicing Personnel Office for all affected personnel.

1.1. FACILITY ACCESS REQUIREMENTS

Daily access to facilities shall be required when performing work under this PWS. Specific processes for obtaining required badges for Contractor personnel are discussed below.

Contractor personnel who do not routinely work on the Government site and do not have a Contractor badge shall coordinate with the USDA COR prior to attending onsite meetings at USDA facilities. The following Government specific RD security requirements must be followed to obtain facility access and obtain a Building Pass:

a. The Contractor shall ensure that each Contractor employee has been issued either a temporary or permanent badge (“badge”) from the Government. The Government may issue temporary or visitor badges for Contractor employees who are identified as having an infrequent or temporary legitimate business need for access to the Government site. The badge shall serve to authorize the wearer to enter and leave the security area. The badge must be worn so as to be clearly visible at all time when on the work site. The badge shall be retained by the individual as long as he is required continued admittance to the site.

Attachment 12 Background Investigation Requirements

b. Each Contractor employee shall be subject to Federal laws applicable to Government installations, e.g., a ticket issued by the Federal Protective Officers and possible tow-away of vehicle.

c. The Government reserves the right to exclude or remove from the site or building any employee of the Contractor or Sub-Contractor whose background investigation indicates an undesirable history as discussed in the Background Investigation Requirements section.

d. When the Government directs, the Contractor shall remove from performance on the PWS any person who is identified as a potential threat to the health, safety, security, general well-being, or operational mission of the USDA and its population.

1.2. REMOTE NETWORK ACCESS REQUIREMENTS

The Contractor shall comply with the USDA Office of the Chief Information Officer - Information Technology Network Access Security Policy, (Attachment 3):

a. All remote access shall be through a virtual private network (VPN) or personal WIFI.

b. To protect against loss or theft, sensitive data stored on a laptop should be encrypted. The documents folder is encrypted on USDA issued laptops.

c. It is not normal policy to store sensitive date on portable computers. If the data is being accessed from a system that is secured, then the data should remain on that protected system.

d. Also when transmitting sensitive information through email it should be win-zipped and password protected.

e. If data is compromised, the Contractor shall comply with guidance provided in the Security

Incident Guide (Attachment 4).

1.3. HSPD-12 SECURITY OPERATING PROCEDURES

The Contractor shall comply with agency (RD) personal identity verification procedures that implement Homeland Security Presidential Directive - 12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and Federal Information Processing Standards Publication (FIPS PUB) Number 201.

The Contractor shall insert this clause in all subcontracts when the Subcontractor is required to have physical access to a federally controlled facility or access to a Federal information system.

Attachment 12 Background Investigation Requirements

1.4. PHYSICAL SECURITY

The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of this PWS. The Contractor shall implement procedures to ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of sensitive Government information, data, and/or equipment. The Contractor’s procedures shall be consistent with Government and GSA policies, including GSA Order 2100.1, Information Technology Security Policy (or most current version), OMB Memorandums & Circulars, FISMA, the Computer Security Act of 1987, and the Privacy Act.

In addition, during all activities and operations on Government premises the Contractor shall comply with the policies, rules, procedures and regulations governing the conduct of personnel or protection of Government facilities and data as expressed by GSA, written or oral.

1.5. SENSITIVE INFORMATION STORAGE AND DISCLOSURE

Sensitive But Unclassified (SBU) information, data, and/or equipment shall only be disclosed to authorized personnel on a Need-To-Know basis. The Contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment shall be returned to the Government. The Government shall determine the destiny of such information, data, and/or equipment. If the Government determines that such information, data, and/or equipment is to be destroyed, the destruction shall be accomplished by burning; shredding, or any other method that precludes the reconstruction of the material but only after direction by the Government. All sensitive information contained on Contractor computers shall be either degaussed or shall use the NIST 800-88 (Guidelines for Media Sanitization) but only after coordination with the Government (See Attachment 5, Conditional Access to USDA Sensitive but Unclassified Information Non- Disclosure Agreement).

1.6. PROTECTION OF INFORMATION

The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this SOO. The Contractor shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this PWS should be considered as SBU information. It is anticipated that this information shall be gathered, created and stored within the primary work location. If Contractor personnel must remove any information from the primary work area they shall protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act shall be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.

Attachment 12 Background Investigation Requirements

1.7. UNAUTHORIZED REPRODUCTION

All files, records, papers, or machine-readable materials created or revised using equipment or materials provided under this PWS are the property of the United States Government. The Contractor shall not replicate or reproduce information unless specifically approved in writing by the contracting Officer or the COR. The Contractor shall adhere to all rules, regulations, and procedures relating to security and confidentiality for work performed and any information handled in the course of this work.

1.8. COMPLIANCE WITH SOFTWARE LICENSES AND PROCEDURES

If Contractor-furnished equipment and material are used, the Contractor shall be responsible for ensuring that only commercial, duly licensed software is used. Under no circumstances may "bootleg”, "pirated," or other unofficial copies of software be installed on equipment. Within one working day of any written request from the GSA contracting Officer, the Contractor shall furnish proof of legitimate purchase, or license, of the software used.

1.9. INTELLECTUAL PROPERTY RIGHTS

The existence of any patent, patent application or other intellectual property right that encumbers any deliverable must be disclosed in writing in the cover letter that accompanies the delivery. If no such disclosures are provided, it is assumed that the no intellectual property rights apply.

1.10. ASSESSMENT AND ACCREDITATION (A&A)

The Contractor shall comply with A&A requirements, as required.

1.11. DISASTER RECOVERY PLANNING

The Contractor may be required to work in the arena of disaster recovery and continuity of operation. These duties include complying with NIST 800-34 Contingency Planning Guide for Information Technology Systems, USDA Departmental Manual (DM 3570-001 Disaster Recovery and Business Resumption Plans) and RD or other USDA RD recovery plans for application/system recovery. This includes, but is not limited to the development of application recovery steps; testing, validating, reviewing recovered applications; and maintaining RD or other USDA RD applications in the event of a disaster. Disaster and recovery of applications

Attachment 12 Background Investigation Requirements processes shall be implemented in the event of actual emergencies, i.e. tornados, terrorist attacks, etc. or in simulations; i.e. exercises (tabletops or functional). Personnel assigned these duties shall be listed on a call tree with the potential to be called 24/7.

1.12. LOGICAL ACCESS CONTROL

Prior to accessing USDA information systems Contractor personnel shall review and acknowledge the "User Agreement/Rules of Behavior" and the “Acceptable Use Policy”. Once all the RD or other USDA RD required logical access documents and handbooks have been reviewed, Contractor personnel shall sign the User agreement and have the form filed with the COR (Attachment 6, for copy of the Contractor or Subcontractor Employee Non-Disclosure Agreement).

1.13. INCIDENT RESPONSE

A security incident is classified as any event that violates laws, regulations or security policies.

Contractor and Contractor Partners shall comply and respond in accordance with the USDA Incident Response Procedures DM3505-01.

1.14. COMPUTER SECURITY AWARENESS TRAINING

Prior to accessing USDA information systems PWS personnel shall ensure that the annual Security Awareness Training has been completed or is scheduled to be completed. If applicable, it may be required for Contractor personnel to complete specialized training. This training shall be completed on an annual basis if required.

Attachment 12 Background Investigation Requirements

File details come from the government source that posted it. Updated .