Attachment 4 - SAMPLE TASK ORDER - LARGE EVENT - 70US0921R70090014.docx
DOCX document 39 KB Posted
- Attached to
- Credentialing Services Federal contract opportunity
- Solicitation number
- 70US0921R70090014
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 70US0921R70090014-0001.pdf | ||
| Attachment 1 - PERFORMANCE WORK STATEMENT - 70US0921R70090014 - 8-10-21.docx | DOCX document | |
| Attachment 3 - RFP INSTRUCTIONS AND EVALUATION FOR AWARD - 70US0921R70090014 8-10-21.docx | DOCX document | |
| Attachment 7 - Past performance questionnaire - 70US0921R70090014.docx | DOCX document | |
| Attachment 6 - Quality Assurance Surveillance Plan- 70US0921R70090014.docx | DOCX document | |
| Attachment 8 Solicitation Clarification Question Request Form.xlsx | XLSX spreadsheet | |
| Attachment 2 - ADDITIONAL PROVISIONS AND CLAUSES - 70US0921R70090014.docx | DOCX document | |
| Attachment 5 - SAMPLE TASK ORDER-SMALLER EVENT - 70US0921R70090014.docx | DOCX document | |
| Attachment 9-Pricing Sheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 4 – SAMPLE TASK ORDER (LARGE EVENT)
70US0921R70090014
SAMPLE TASK ORDER (LARGE EVENT)
DPD CREDENTIALING / ACCESS CONTROL SERVICES
GENERAL INFORMATION
1. INTRODUCTION: The United States Secret Service (USSS) Office of Protective Operations (OPO) / Dignitary Protective Division (DPD) assumes the lead role in the coordination of operational security plans for all events in which Foreign Heads of State / Government are in attendance and events designated as National Special Security Events (NSSEs). This is a non-personal services contract to provide production of temporary special events credentials in support of access control for such events. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the contractor who, in turn is responsible to the Government.
1.1 Background: The USSS DPD has assumed the lead role in the coordination of operational security plans for a large event in Washington, DC which has been designated a NSSE. Among the areas of advance planning and coordination is event access control. The DPD Credentialing Section is responsible for the design and procurement/production of temporary special event credentials in support of access control for this NSSE. The Assistant to the Special Agent in Charge (ATSAIC) of the USSS DPD Credentialing & Identification Section shall be the government Program Manager (PM). The government shall from time to time designate a deputy PM from the USSS DPD Credentialing & Identification section.
1.2 Objectives:
The USSS DPD Credentialing Section is requires the contractor to provide a credentialing and access control solution for the “2025 Inauguration” held in Washington DC on Monday, January 20, 2025. This event has been designated a NSSE. The contractor shall be available to be on site approximately 14-21 days prior to event, as notified by the government PM. The contractor shall produce credentials and underlays in support of this event.
The following are the objectives of this acquisition:
· Provide pre-event and onsite consultation of best practices
· Provide advance planning services related to credentialing
· Produce physical credentials, with specified security features, for NSSEs and other protective events
· Provide access control solutions that integrate with physical credentials
· Provide secure data management services for credential operations
· Provide tracking of real-time event attendance and participation
· Meet USSS security requirements for contractor facility access and personnel security
· Provide on-site training to USSS personnel at credentialing checkpoints
1.2.1 Authority:
The Contracting Officer (CO) is responsible for the general administration of this Task Order. The Contracting Officer’s Representative (COR) is responsible for the review/acceptance of all deliverables, and technical direction. The CO shall serve as the Government point of contact for contractual direction. The COR shall serve as the Government point of contact concerning information exchange, submission review and payment. Nothing said by the COR shall be construed to change the order requirements unless supported in writing in advance by the CO.
The USSS points of contact responsible for overall administration of this Task Order are:
Mrs. Danielle Donaldson Contracting Officer 202-380-7689 Danielle.Donaldson@usss.dhs.gov.
COR Point of Contact:
Amanda Brown Parks Senior Business Acquisition Analyst 202-870-6229 amanda.brownparks@usss.dhs.gov
USSS DPD Credentialing PM:
Mark Brandenburg Assistant to the Special Agent in Charge (ATSAIC) 202-870-0676 mark.brandenburg@usss.dhs.gov
USSS DPD Credentialing DPM:
William Nelson Credentialing Events Coordinating Coordinator 202-538-5097 william.t.nelson@usss.dhs.gov
1.3 Scope: DPD Credentialing / Access Control Services: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Credentialing / Access Control Services as defined in this Performance Work Statement except for those items specified as Government furnished property and services. The contractor shall accomplish:
· Provide physical credentials and underlays as well as access control solutions for the “2025 Inauguration” NSSE.
· Implement all required access control personnel, services, equipment, and supplies for the “2025 Inauguration” NSSE, including short notice (less than 24 hours) assignments.
· Effectively operate at temporary “on-site” location(s) in the Washington, DC area for an approximate 14 to 21-day period, as notified by the government.
· Provide event management services in the form of access control equipment and authorized personnel to operate access control equipment
1.4. Specific Tasks:
1.4.1. Event Management:
Event Management shall incorporate all aspects of credentialing services. This includes access control equipment and personnel services, secure data management and consultative services for an event. The planning and development, execution, and production and distribution shall be provided by the Contractor in a written plan to the government PM and deputy PM within 14 days of Task Order Award.
1.4.1.1 Project Management
The contractor shall accomplish all aspects of event management to include industry-standard data collection as well as facilitation of design, production and distribution of credentials for events of national significance.
This includes and is not limited to the following:
· Pre-event, on-site strategic consultation and best practice system strategies;
· Pre-planning for potential events to include on-site project management and access control solutions for hardware and software and installation of access control equipment at all designated check points;
· Participate in video teleconferences and/or provide presentations with event coordinators;
· The Contractor shall act as credential liaison and expedite reporting between internal and external organizations/agencies that may be collecting data for specific groups and the PM to facilitate access control solutions for the purpose of enabling credential management.
· The Contractor shall facilitate credential communication methods with organization/agencies, manage all incoming data, prepare and ensure data accuracy, establish and maintain a data change management process, and prepare credential information for production and distribution;
· Written plan on pre-designated date(s) determined by the PM, and specified on the order prior to each event.
1.4.1.2 Secure Data Management
· The data management process is the main phase of credential operations. The USSS estimates approximately 75,000 or more individuals for this event that shall require credentials. The USSS shall collaborate with the Contractor to determine a data submission deadline for all applicants.
· Additional requirements related to Secure Data Management are listed in Section 1.4.4 – Additional Software
1.4.1.3 Planning
· The Contractor shall coordinate with the USSS to develop a communication procedure, basic elements for information management, basic data planning, credential design, venue, event and security requirements and staffing. The Government shall provide the USSS official logo and approve credential design with the Contractor.
· The Contractor and the Government shall collaborate on how to handle card modifications and/or additional cards if and when necessary.
1.4.1.4 Design / Development
Contractor shall provide:
· All elements of information management to include identifying and confirming all constituent groups, registration procedures, approval/denial procedures, processing, change management, deadlines and policies.
· All elements of basic data planning to include, establishing data field, photo format and size, access scheme, category/badge types, venue/event/zone code designation.
· All elements of credential design to include, elements of the badge, look, stock type, amount, templates, proofs and legal disclaimers.
· All elements of advances printing and distribution center process to include advanced printing criteria, center locations, lay-out, process flow, schedule of installation, policies and procedures, crisis management plans, staffing and communication procedures.
1.4.1.5 Execution
Contractor shall perform:
· Execution of plans created during Development.
· Adjust to iterations and changes based on the response and acceptance of various agencies.
· Extensive data collection and processing.
· Data procedures must be clarified in order to ensure proper production and distribution of the physical badge.
1.4.1.6 Production, Distribution and Reference
Contractor shall perform the following services:
· All elements of data management, design, technology operational to produce accurate access control devices.
· Facilitate / Produce secure badge design on secure card stock. The contractor shall modify the design to fit on the card.
· The contractor shall be responsible for facilitating/ producing the cards and providing all material associated to print.
· Maintain consistent delivery of credentials based on agreed deadlines.
· Maintain accuracy and print quality of credentials.
· Maintain secure process for reconciling printed credentials. In the event a card is lost, the person shall report it appropriately. Prior to printing a new card or underlay, the contractor shall receive approval first from the PM.
· Once the data is received, the contractor shall print the cards and keep them until authorized by the USSS to distribute.
· Distribution, all established methods, access control is set to record/reference based on requirements.
· Crisis management and trouble-shooting procedures and required modifications implemented.
1.4.2 Access Control Equipment and System Management
Prior to each event the USSS shall determine required security features to include within devices: barcodes, micro printing, holograms, Radio Frequency Identification biometrics, etc. The access control devices and equipment readers shall comply with the following:
· Incorporation of security feature technology.
· Technology should have the capability to be used simultaneously with other government and USSS systems.
· Assigned readers/ monitors at each designated check point.
· Full reader/scanning easy view functions.
· Tracking of system and device modifications and distribution information (examples: name of person the cards were distributed to, date, time, location and copy of receiving person’s electronic signature).
· Tracking of real-time attendance and participation.
1.4.3 Radio Frequency (RF) Equipment
The Contractor shall be provided the opportunity to de-conflict the radio frequency (RF) signal with USSS protective equipment such as magnetometers and /or to test function equipment at access control checkpoints to ensure Contractor access control equipment operations does not interfere with other Government utilized technology or established security plan timetables.
· The Contractor shall incorporate industry-standard security technologies, such as RF transmitters
· Supply associated RF equipment and fully encrypted connections as required in the Data Management and Security Section. The Contractor shall be an in-house fully production capable contractor for supplemental identification and shall supply and/or produce USSS approved access control devices and equipment that incorporate industry-standard security technologies and data collection and design that operate with fully encrypted connections. When required, the Contractor shall provide software, hardware and equipment that allows for each access device to be deactivated if and when necessary.
1.4.4 Additional Software
· The contractor shall provide software to manage all data related to applicant / credential submissions including: credentialing appointments, engagements, and deadlines; as a communications platform; to obtain applicant / credential information; and to communicate with the USSS on credential access levels and requirements.
· Configure commercial web application software, modified for USSS use and for users to interact and create engagements or appointments that build databases and custom web forms while allowing for the sharing of documents.
· Software should be specific to each event to automate the collection, management, and communication of applicant/credential information while complying with government prerequisite privacy and data security requirements.
· The Contractor shall provide continual access and technical support of the software for the USSS to utilize when managing smaller events that do not require the full extent of contractor support. The Contractor shall provide an experienced technician capable of software update installation, system maintenance and software solutions throughout the duration of the contract.
· The Contractor must have the ability to store and format personal identifying information (PII) and allow for the secure sharing of such information with the Government. The Contractor must have the ability to receive, compile, store, view, and implement applicant photos within web based software and on all access control devices. The Contractor shall, as necessary, persistently upgrade software, hardware, devices and equipment for additional biometric implementation for future events.
· The Contractor shall have the ability to track data changes through IP tracking and login by each user and administrator and the ability to create URL for data collection from end users.
· All physical access devices shall be deactivated and/or properly disposed of upon completion of the event. Physical devices shall only be active for the duration of the event and shall not be utilized for access to future events. The Contractor should be capable of purging records upon completion of each event or NSSE.
1.4.5 Memorandum of Understanding / Memorandum of Agreement
The memorandum of understanding (MOU)/memorandum of agreement (MOA) executed between the USSS and the Contractor at the time of IDIQ Contract Award remains in effect for this Task Order.
1.4.6 Training
Event checkpoints shall be manned by USSS personnel and Contractor personnel. The Contractor shall provide a minimum level of training to USSS personnel with regard to monitor assessment and response to help determine whether or not the individual(s) should be granted access to a particular area. The exact number of checkpoints shall be communicated by the USSS PM to the Contractor.
· When required, the Contractor shall provide vetted personnel to staff the “2025 Inauguration” NSSE on-site credentialing/ distribution center(s) prior to the event and venue checkpoints for the duration of the event or as required by the USSS PM.
1.4.7 Labor Categories
The contractor shall propose, pursuant to this Task Order, a sufficient number of contract labor personnel under the labor categories awarded under the IDIQ Contract.
1.5 General Information
1.5.1 Date of Delivery: The period of performance shall be from the date of award through April 25, 2025.
1.5.2 Place of Delivery: The majority of the performance shall be at the Contractor’s Facility. However, the contractor shall be required to perform work at a temporary “on- site” facility in Washington, DC approximately 14-21 days prior to the NSSE beginning. The USSS PM shall provide the location of the “on site” facility in Washington, DC to the contractor.
1.5.3 Hours of Operation: The contractor is responsible for conducting business as specified herein, and for this event including hours of operation during the evening time. Approximate work hours are from 6 AM – 10 PM as notified by the USSS PM during event “on site” support.
1.5.4 Type of Contract: The contract is a Task Order against the IDIQ Contract. This Order is a Hybrid Firm Fixed Price (Services) / Time and Materials and Cost (Travel). The proposal shall be evaluated for the services required at the time of the order award.
1.5.6.1 Privacy Act: Personnel who have access to Privacy Information shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations. This effort has been determined by the USSS Office of the Chief Information Officer (OCIO) to be “high risk”.
1.5.6.2 Physical Security: The contractor shall be responsible for safeguarding all Government equipment, information and property provided for contractor use. At the close of each work period, Government facilities, equipment, and materials shall be secured.
The Contractor’s facility shall also be equipped with physical security measures to safeguard generated hardware, equipment and/or devices utilized by the Government for imminent events. Physical security involves the use of multiple layers of interdependent systems which include CCTV, security guards, protective barriers, locks, alarms, motion detectors, access control protocols, and many other techniques. Once access device production for the Government has begun, the facility should be equipped with a safe, vault and/or secure area to protect produced credentials, underlays and /or additional devices. After award of contract, USSS representatives shall periodically perform on-site survey(s) of Contractor facilities for compliance. The Contractor shall be briefed on the results of the on-site facility survey and given two weeks to mitigate any identified security risks. In addition, the USSS shall routinely require for USSS personnel to be on-site at the Contractor’s facility upon production of Government access devices to ensure access control accountability and help manage pre-event correspondence and planning efforts.
1.5.6.2.1 Contractor Facility Access: All non-classified USSS information is considered “Sensitive But Unclassified” (SBU) and must be protected as such. The clearance level for this contract is unclassified, however all personnel, both prime and subcontractor, working under this requirement must be a U.S. citizen. All Contractor personnel involved, including on-site support shall undergo a security background check by the USSS. The Contractor shall provide only personnel who can successfully pass the background investigation.
The selected offeror is required to provide the following information about both the Contractor’s employees and subcontractors who may have direct or incidental (whether logical or physical) access to USSS information:
1. Employee’s full name
1. Employee’s gender
1. Employee’s date and place of birth
1. Employee’s social security number
On-site event contractor and subcontractor personnel may need access into USSS controlled facilities and therefore must truthfully complete and submit a USSS Facility Access Request (SSF 3237) as a minimum Category 1 Applicant, which expires a year from approval date or date indicated on the form, and a Conditional Access to Sensitive But Unclassified Information Non-Disclosure Agreement (SSF 4024).
The USSS shall conduct a limited background investigation of all named personnel. The results of these checks shall be used solely by the USSS in evaluating personnel. The USSS has the right to request exclusion of any Contractor personnel from government projects and/or events for any reason. Employees with warrants, numerous felony arrests, or a felony conviction shall be excluded. Due to required confidentiality laws and privacy issues, the Contractor shall not be provided an explanation if an employee is denied.
1.5.6.3 Key Personnel: The contractor shall propose the following personnel as key personnel:
· Project Manager (PM): The PM shall have the full authority to act for the contractor on all matters. The PM shall be ultimately responsible for all credentialing services as specified herein.
· Deputy Project Manager (DPM): The DPM shall act in the absence of the PM and shall have all authority for the PM in his/her absence.
· The contractor shall obtain approval from the government for changes to and/or replacement of contract key personnel.
1.5.6.4 Identification of Contractor Employees All contract personnel attending meetings, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. Contractor personnel shall be required to wear appropriate credentials while performing services under this contract.
1.5.7. Contractor Travel The Contractor shall be required to travel to perform services under this contract. Duration, frequency and location of travel are dependent upon each individual task order. Contractor shall be authorized travel expenses consistent with FAR 31.205-46, the substantive provisions of the Federal Travel Regulation (FTR), and the limitation of funds specified in this contract. All travel requires Government approval/authorization and notification to the COR. . The Contractor is required to provide a proposed cost estimate as early as possible and on a TBD date determined by the PM prior to the final security planning of each event. Payments are presented at the conclusion of each event.
1.5.8 Other Direct Costs This category includes contractor travel (outlined in 1.5.6) to government facilities and/or while performing services for the government and shipping expenses associated with production of credentials.
1.5.9 Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.5.10 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan shall be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.
PART 2
DEFINITIONS & ACRONYMS
2. Definitions and Acronyms:
Refer to the USSS Credentialing IDIQ Part 2. The definitions and acronyms for the IDIQ remain in effect for this Task Order.
PART 3
GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
3. GOVERNMENT FURNISHED ITEMS AND SERVICES:
Refer to the USSS Credentialing IDIQ Part 3. All terms of the IDIQ Contract pertaining to government furnished property remain in effect for this Task Order.
PART 4
DELIVERABLES
4.0 DELIVERABLES:
All deliverables as specified in the USSS Credentialing IDIQ Contract Part 4 remain in effect for this Task Order. In addition, the following additional deliverables and / or deliverable specifications apply:
4.1 Deliverable Table
Item
Mode Contract Level (IDIQ/ Order)
Frequency
Due Date / Response Time
Initial event platform configuration, account setup, and in-person *kick-off meeting at USSS HQ
In Person or Virtual platform meeting
Order
Upon Award
Within 5 business days of Task Order award.
| Communication Procedures |
| Email to COR/PM/CO |
| Order |
| Per event |
| 10 days after order |
| Best Practices Written Plan |
| Email to COR/PM/CO |
| Order |
| Per Event |
| 15 days prior to event beginning. |
| Badge Design |
| Email to COR/PM/CO |
| Order |
| Per event |
| As specified in order |
| Meeting Minutes |
| Email to COR/PM/CO |
| As Applicable |
| As Applicable |
| Within 3 business days of meeting |
4.1.1 Meetings
· Kick- Off- The contractor shall coordinate with the Government POCs for a kick off meeting. During the meeting the contractor and Government shall clarify and address any ambiguous information.
· The contractor shall act as a Liaison for the USSS and provide information to the Government POC as reference.
· Meeting Minutes shall be required for all meetings and shall be submitted to the Government PM, within 3 business days of meeting.
4.1.2 Pre-Event Consultation / Best Practices Written Plan
The Contractor shall provide a written plan on pre-event planning document within 15 business days prior to the event. The information that this plan contains is in accordance with Section 1.4.1 of this Performance Work Statement (PWS). Written plan shall be submitted to the USSS COR/PM CO for pre-approval.
4.1.3 Communication Procedures
The contractor shall develop communication procedures. These procedures shall include basic elements for information management, basic data planning, credential design, venue, event and security requirements and staffing. The procedures should address how the Government and the Contractors shall collaborate on handling card modifications and/or additional cards if and when necessary. Communication procedures shall be submitted to the USSS COR/PM and CO for pre-approval.
4.1.4 Badge Design
The badge designs shall be on secure card stock and shall be modify to fit the card. Additional information provided under 1.4.1.4. Badge designs shall be submitted to the USSS COR/PM and CO for pre-approval.
4.1.5 Application Software
See Section 8.0 “Special Contract Requirements” herein.
4.1.6 Memorandum of Understanding / Memorandum of Agreement (MOU/MOA) The MOU/MOA shall serve to confirm the Contractor’s system boundary, USSS system boundary, data breach notification procedures, as well as roles and responsibilities in the event of a data breach. This MOU/MOA was executed at the time of IDIQ Contract award and remains in effect.
4.1.7 Quality Control Plan
Contractor Deliverables as specified in its proposed Quality Control Plan at the time of IDIQ contract award shall be adhered to.
4.1.8 Quality Assurance Surveillance Plan (QASP)
The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards shall be applied, the frequency of surveillance, and the minimum acceptable defect rate(s). Please see section 9 for metrics related to the QASP.
PART 5
INSPECTION AND ACCEPTANCE
5.0 INSPECTION AND ACCEPTANCE PROCESS
| 5.1 | All written deliverables, including training materials, shall be quality products that are complete and thorough; structured in a clear, logical fashion; and in a proper, accepted writing style. |
| 5.2 | Written deliverables shall be accompanied by a cover letter, signed by an authorized representative of the company, affirming that the deliverable has been through necessary review and quality control procedures. |
| 5.3 | If, for any reason, a deliverable cannot be delivered within the scheduled time frame: The contractor shall notify the COR/CO with cause of delay, the proposed revised schedule, and the impact on the overall program. The CO shall approve as to if the delay is acceptable and shall modify the contract. |
| 5.4 | The Contractor shall submit the documentation to the Government within reasonable timeframe so the Government can review and the CO can approve. Contractor must receive approval before the deliverable is considered accepted. |
PART 6
OPERATING ENVIRONMENT (TECHNOLOGY)
6.0 OPERATING ENVIRONMENT (TECHNOLOGY)
The government will not be providing any hardware or software for this project / program. The software is a web-based application. As this is an online resource, it is imperative that the contractor be prepared to demonstrate compliance with the Risk Management Framework (RMF) as detailed by the National Institute for Standards in Technology (NIST), Department of Homeland Security (DHS) and USSS Policy. Specifically, all contractors must be FedRAMP certified for baseline control baselines and vetted by the USSS Office of the Chief Information Security Officer (OCISO). The contractor must be able to share all associated security plans and certification documents appropriate to the FedRAMP requirement. Baseline controls for all external information systems minimally includes:
| 1. AC – 1 |
| 5.0 Access Control Policy and Procedures |
| 6.0 AC – 2 |
| 7.0 Account Management |
| 8.0 AC – 3 |
| 9.0 Access Enforcement |
| 10.0 AC – 5 |
| 11.0 Separation of Duties |
| 12.0 AC – 6 |
| 13.0 Least Privilege |
| 14.0 IA – 1 |
| 15.0 Identification and Authentication Policy and Procedures |
| 16.0 IA – 2 |
| 17.0 Identification and Authentication (Organization Users) |
| 18.0 IA – 4 |
| 19.0 Identifier Management |
| 20.0 IA – 8 |
| 21.0 Identification and Authentication (Non-Organizational Users) |
| 22.0 PS – 4 |
| 23.0 Personnel Termination |
| 24.0 PS – 5 |
| 25.0 Personnel Transfer |
| 26.0 SA – 9 |
| 27.0 External Information System Services |
The government requires that all systems utilize strong, multifactor authentication. This solution must therefore be HSPD – 12 compliant.
The government requires that along with satisfying the requirements listed in the above paragraph, the contractor must adhere to all privacy matters as dictated by the DHS and USSS Privacy Officers. As this capability will collect PII data from the public, adherence to DHS and USSS policy regarding privacy matters is paramount.
PART 7
ORDERING INSTRUCTIONS
7.0 TASK ORDER ORDERING INSTRUCTIONS
7.1 Order Instructions
A Request for Task Order Proposal (RTOP) will be requested from the Contractor. The contractor shall provide the pricing and statement of requirements for this order within 3 business days. The Contractor shall provide any assumptions. The pricing shall be in accordance with the IDIQ pricing.
Each response shall have the following information provided by the Contractor:
1. Date of response and period of effective date for the quote
2. A quote that is in accordance with the pricing in the IDIQ.
3. Itemized listing of services/supplies to facilitate the order.
4. Any assumptions and/or risks the Contractor sees with the order.
5. Ensure that all travel, if required, is in accordance with the FTR.
PART 8
SPECIAL CONTRACT REQUIREMENTS
8.0 SPECIAL CONTRACT REQUIREMENTS
27. Order of Precedence In the event of an inconsistency between the Special Contract Requirements and the FAR clauses and provisions in the RFP or the IDIQ or subsequent Task Order, the inconsistency will be resolved by giving precedence in the following order:
1. Special Contract Requirements (Section 8.0 of the IDIQ)
2. FAR Clauses
27. Adherence to Policy
All contractor personnel shall adhere to the following Federal and Agency policies and regulations:
· OMB Circular A-130, "Measuring of Federal Information Resources",
· Appendix III;
· Public Law 100-235, "Computer Security Act of 1987;"
· Federal Information Security Management Act (FISMA);
· Federal Information Processing Standards;
· National Institute for Standards in Technology (NIST) Special Publication 800-37, "Guide for the Security Certification and Accreditation of Federal Information Systems;"
· NIST Special Publication 800-18, "Guide for Developing Security Plans for Information Technology Systems;"
· NIST Special Publication 800-26, "Self-Assessment Guide for Information
· Technology Systems;"
· DHS Management Directive (MD) 4300A IT Security Program;
· DHS MD 4300A IT Security Program Handbook;
· Windows 2008 R2 Server Configuration Baseline Guide
· U.S. Secret Service, Protective Research Manual, Sections IRM-9, 10, 11 and 12 Information Assurance - general, management, operational and technical controls;
· U.S. Secret Service Oracle Security Implementation Guide.
8.3 Confidentiality of Data
8.3.1 "Sensitive Information" is any information or proprietary data which if subject to unauthorized access, modification, loss, or misuse could adversely affect the national interest, the conduct of Federal programs, or the privacy to which individuals are entitled under 5 U.S.C. 552a (The Privacy Act), but that has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept classified in the interest of national defense or foreign policy.
8.3.2 Duplication or disclosure of the data and other information to which the contractor will have access as a result of this contract is prohibited. The contractor and his/her subcontractor(s) (if any) shall not disclose said data, any interpretations and/or translations thereof, or data derivative there from, to unauthorized parties in contravention of these provisions, without the prior written approval of the Contracting Officer or the party in which title thereto is wholly vested. Subcontractors shall be subject to the same stipulations and may be held responsible for any violations of confidentiality.
8.3.3 The contractor shall not transmit or remove any USSS or DHS material from USSS facilities. The contractor shall label and classify all documents produced in conjunction with this contract as appropriate, and as directed by the USSS COR. The contractor shall not remove any documents supplied by the USSS, including sensitive but unclassified documents, working papers, briefings and reports as well as classified documents, from Information Resources Management Division (IRMD) work space. The contractor shall maintain all electronic documents, briefings and reports in IRMD provided computers, and shall not transfer or store data outside of USSS control. Additionally, the contractor shall maintain accountability and shall return to the USSS all documents and data upon completion of this contract.
8.3.4 The contractor shall have access only to those areas of USSS Information Technology resources explicitly stated in this contract or approved by the USSS COR in writing as necessary for performance of the work under this contract. Information Technology assets includes computer equipment, networking equipment, telecommunications equipment, cabling, network drives, computer drives, network software, computer software, software programs, intranet sites, and Internet sites. Any attempts by contractor personnel to gain access to any Information Technology resources not expressly authorized by the performance work statement, other terms and conditions in this contract, or as approved in writing by the USSS COR, is strictly prohibited. In the event of violation of this provision, USSS will take appropriate actions with regard to the contract.
8.3.5 The Contracting Officer may require dismissal from this contract those contractor employees deemed incompetent, careless, insubordinate, or otherwise objectionable, or whose continued employment is deemed contrary to the public interest or inconsistent with the best interest of national security.
8.3.6 The contractor shall include the substance of this clause in all subcontracts at any tier where the subcontractor may have access to Government facilities, sensitive information, or resources.
8.4 Privacy Act
Work on this project may require that contractor personnel have access to Privacy Information and shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations.
8.5 Dissemination of Contract Information
The Contractor shall not publish, permit to be published, or distribute for public consumption, any information, oral or written, concerning the results or conclusions made pursuant to the performance of this contract, without the prior written consent of the CO. The contractor shall submit an electronic or printed copy of any material proposed to be published or distributed to the Contracting Officer for approval.
8.6 SECTION 508 REQUIREMENTS
The USSS has determined that the following accessibility standards (36 CFR Part 1194) apply to this procurement under Section 508 of the Rehabilitation Act of 1973.
1194.21 Software applications and operating systems.
1194.22 Web-based intranet and internet information and applications.
1194.24 Video and multimedia products.
1194.26 Desktop and portable computers.
1194.31 Functional performance criteria.
1194.41 Information, documentation, and support.
The contractor shall deliver products and/or services that provide the features described in the above standards, or equivalent salient characteristics.
PART 9
SECURITY TERMS AND CONDITIONS
9.0 SECURITY TERMS AND CONDITIONS
Refer to the USSS Credentialing IDIQ Part 10. The Terms and Conditions for the IDIQ remain in effect for this Task Order.
File details come from the government source that posted it. Updated .