Attachment A- AWARE Additional Terms and Conditions 11142024.pdf
PDF 354 KB Posted
- Attached to
- Aware CaptureSuite License and Maintenance Federal contract opportunity
- Solicitation number
- 70B04C25Q00000004
About this file
This document is a combined synopsis/solicitation for a sole source procurement by the Department of Homeland Security, Customs and Border Protection (CBP) for software maintenance and support for the Aware CaptureSuite software.
The solicitation is for the provision of support and maintenance for 4,904 Aware CaptureSuite licenses over a 1-year period. The Aware CaptureSuite software is used by CBP for fingerprint capture, processing, and validation at U.S. ports of entry. The maintenance includes priority technical support, bug fixes, and software upgrades. The contracting officer has determined that Aware, Inc. is the only reasonably available source to meet this requirement, as Aware possesses unique customized capabilities that would be too costly and time-consuming for CBP to replicate with a new provider. Responses to this notice will be considered, but the contracting officer has the discretion to make a sole source award to Aware, Inc.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 1 for 70B04C25Q00000004.pdf | ||
| Amendment 1- Attachment B- Statement of WorkRequirement (20146989) 11142024.pdf | ||
| Amendment1 - 2.2.1 Terms and Conditions 11142024.pdf | ||
| Amendment 1 -2.2.1 Solicitation 70B04C25Q00000004 Aware 11142024.pdf | ||
| 2.2.1 Terms and Conditions 11142024.pdf | ||
| Attachment B- Statement of WorkRequirement (20146989) 11142024.pdf | ||
| 2.2.1 Solicitation 70B04C25Q00000004 Aware 11142024.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work Aware CaptureSuite Program Software
Additional DHS Terms & Conditions
Enterprise Architecture Compliance
The Offeror shall ensure that the design conforms to the Department of Homeland Security (DHS) and Customs and Border Protection (CBP) Enterprise Architecture (EA), the DHS and CBP Technical Reference Models (TRM), and all DHS and CBP policies and guidelines (such as the CBP Information Technology Enterprise Principles and the DHS Service Oriented Architecture - Technical Framework), as promulgated by the DHS and CBP Chief Information Officers (CIO), Chief Technology Officers (CTO) and Chief Architects (CA).
The Offeror shall conform to the Federal Enterprise Architecture (FEA) model and the DHS and CBP versions of the FEA model, as described in their respective EAs. All models will be submitted using Business Process Modeling Notation (BPMN 1.1 or BPMN 2.0 when available) and the CBP Architectural Modeling Standards. Universal Modeling Language (UML2) may be used for infrastructure only. Data semantics shall be in conformance with the National Information Exchange Model (NIEM). Development solutions will also ensure compliance with the current version of the DHS and CBP target architectures.
Where possible, the Offeror shall use DHS/CBP approved products, standards, services, and profiles, as reflected by the hardware, software, application, and infrastructure components of the DHS/CBP TRM/standards profile. If new hardware, software, or infrastructure components are required to develop, test, or implement the program, these products will be coordinated through the DHS and CBP formal Technology Insertion (TI) process (to include a trade study with no less than four alternatives, one of which reflecting the status quo and another reflecting multi-agency collaboration). The DHS/CBP TRM/standards profile will be updated as TIs are resolved.
All developed solutions shall be compliant with the Homeland Security (HLS) EA.
All IT hardware and software shall be compliant with the HLS EA.
Compliance with the HLS EA shall be derived from and aligned through the CBP EA.
Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval, and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.
Development of data assets, information exchanges, and data standards will comply with the DHS Data Management Policy MD 103-01. All data-related artifacts will be developed and validated according to DHS Data Management Architectural Guidelines.
Applicability of Internet Protocol version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS EA (per OMB Memorandum M-05-22, August 2, 2005), regardless of whether the acquisition is for modification, upgrade, or replacement. All EA related component acquisitions shall be IPv6 compliant, as defined in the USGv6 Profile (NIST Special Publication 500-267) and the corresponding declarations of conformance, defined in the USGv6 Test Program.
DHS Security Policy Requirement
All hardware, software, and services provided under this order must be compliant with DHS Information Security Systems Directive 4300A (version 13.3, Feb 13, 2023).
DHS Geospatial Information System Terms and Conditions
All implementations including geospatial data, information, and services shall comply with the policies and requirements set forth in the DHS Geospatial Information Infrastructure (GII), including (but not limited to) the following:
• All data built to the GII, whether adopted or developed, shall be submitted to the government for review and insertion into the DHS Data Reference Model.
• All software built to the GII, whether adopted or developed, shall be submitted to the government for http://cbpnet.cbp.dhs.gov/linkhandler/cbpnet/oit/edme/soa.ctt/soa.pdf review and insertion into the DHS Technical Reference Model.
ISO Terms and Conditions for Sensitive but Unclassified Requests DHS Security Policy Requirement
The following terms and conditions should be included in all acquisition documents.
All hardware, software, and services provided under this task order must be compliant with DHS Information Security Systems Directive 4300A (version 13.3, Feb 13, 2023).
Encryption Compliance Requirement
The following terms and conditions should be included in all acquisition documents.
1. FIPS 197 (Advanced Encryption Standard (AES)) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2.
2. National Security Agency (NSA) Type 2 or Type 1 encryption.
3. Public Key Infrastructure (PKI) (please see DHS Information Security Systems Directive 4300A version 13.3, Feb 13, 2023 - attachment U).
Security Review Requirement
The following requirements should be included in all acquisition documents.
Security Review
The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, including the organization of the DHS Office of the Chief Information Officer, the Office of the Inspector General, authorized Contracting Officer’s Technical Representative (COTR), and other government oversight organizations, access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to the DHS. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of DHS data or the function of computer systems operated on behalf of DHS, and to preserve evidence of computer crime.
Interconnection Security Agreement (ISA)
The following requirements should be included in the acquisition document if the service being supplied requires a connection to a non-DHS, Contractor system, or DHS system of different sensitivity.
Interconnection Security Agreement Requirements
Interconnections between DHS and non-DHS IT systems shall be established only through controlled interfaces and via approved service providers. Connections with other Federal agencies shall be documented based on interagency agreements; memoranda of understanding, service level agreements or interconnect service agreements.
Required Protections for DHS Systems Hosted in Non-DHS Data Centers
The following requirements should be included in acquisition documents for information systems which are hosted, operated, maintained, and used on behalf of DHS at non-DHS facilities. Contractors are fully responsible and accountable for ensuring compliance with all Federal Information Security Management Act (FISMA), National Institute of Standards and Technology (NIST) Federal Information Processing Standard (FIPS) and related DHS security control requirements (to include configuration guides, hardening guidance, DHS Security Policy, Procedures, and Architectural guidance). The contractor security procedures shall be the same or greater than those that are provided by DHS Enterprise Data Center(s). Please note that all of the subsections from Security Authorization to Log Retention are included in this requirement.
Security Authorization
A Security Authorization of any infrastructure directly in support of the DHS information system shall be performed as a general support system (GSS) prior to DHS occupancy to characterize the network, identify threats, identify vulnerabilities, analyze existing and planned security controls, determine likelihood of threat, analyze impact, determine risk, recommend controls, perform remediation on identified deficiencies, and document the results. The Security Authorization shall be performed in accordance with the DHS Security Policy and the controls provided by the hosting provider shall be equal to or stronger than the FIPS 199 security categorization of the DHS information system.
At the beginning of the contract, and annually thereafter, the contractor shall provide the results of an independent assessment and verification of security controls. The independent assessment and verification shall apply the same standards that DHS applies in the Security Authorization Process of its information systems. Any deficiencies noted during this assessment shall be provided to the COTR for entry into the DHS’ Plan of Action and Milestone (POA&M) Management Process. The contractor shall use the DHS’ POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies shall be corrected within the timeframes dictated by the DHS POA&M Management Process. Contractor procedures shall be subject to periodic, unannounced assessments by DHS officials. The physical aspects associated with contractor activities shall also be subject to such assessments.
On a periodic basis, the DHS and its Components, including the DHS Office of Inspector General, may choose to evaluate any or all of the security controls implemented by the contractor under these requirements. Evaluation could include, but it not limited to vulnerability scanning. The DHS and its Components reserve the right to conduct audits at their discretion. With ten working days’ notice, at the request of the Government, the contractor shall fully cooperate and facilitate in a Government-sponsored security control assessment at each location wherein DHS information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of DHS, including those initiated by the Office of the Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) determined by DHS in the event of a security incident.
Enterprise Security Architecture
The contractor shall utilize and adhere to the DHS Enterprise Security Architecture in accordance with applicable laws and DHS policies to the satisfaction of the DHS COTR. Areas of consideration could include:
4. Use of multi-tier design (separating web, application and data base) with policy enforcement between tiers
5. Compliance to DHS Identity Credential Access Management (ICAM)
6. Security reporting to DHS central control points (i.e. the DHS Security Operations Center (SOC) and integration into DHS Security Incident Response
7. Integration into DHS Change Management (for example, the Infrastructure Change Control Board
(ICCB) process)
8. Performance of activities per continuous monitoring requirements
Continuous Monitoring
The contractor shall participate in DHS’ Continuous Monitoring Strategy and methods or shall provide a Continuous Monitoring capability that the DHS determines acceptable. The DHS Chief Information Security Officer (CISO) issues annual updates to its Continuous Monitoring requirements via the Annual Information Security Performance Plan. At a minimum, the contractor shall implement the following processes:
9. Asset Management
10. Vulnerability Management
11. Configuration Management
12. Malware Management
13. Log Integration
14. Security Information Event Management (SIEM) Integration
15. Patch Management
16. Providing near-real-time security status information to the DHS SOC
Specific Protections
Specific protections that shall be provided by the contractor include, but are not limited to the following:
Security Operations
The Contractor shall operate a SOC to provide the security services described below. The Contractor shall support regular reviews with the DHS Information Security Office to coordinate and synchronize the security posture of the contractor hosting facility with that of the DHS Data Centers. The SOC personnel shall provide 24x7x365 staff to monitor the network and all of its devices. The contractor staff shall also analyze the information generated by the devices for security events, respond to real-time events, correlate security device events, and perform continuous monitoring. It is recommended that the contractor staff shall also maintain a trouble ticket system in which incidents and outages are recorded. In the event of an incident, the contractor facility SOC shall adhere to the incident response plan.
Computer Incident Response Services
The Contractor shall provide Computer Incident Response Team (CIRT) services. The contractor shall adhere to the standard Incident Reporting process as determined by the Component and is defined by a DHS-specific incident response plan that adheres to DHS policy and procedure for reporting incidents. The contractor shall conduct Incident Response Exercises to ensure all personnel are familiar with the plan. The contractor shall notify the DHS SOC of any incident in accordance with the Incident Response Plan and work with DHS throughout the incident duration.
Firewall Management and Monitoring
The Contractor shall provide firewall management services that include the design, configuration, implementation, maintenance, and operation of all firewalls within the hosted DHS infrastructure in accordance with DHS architecture and security policy. The contractor shall provide all maintenance to include configuration, patching, rule maintenance (add, modify, delete), and comply with DHS’ configuration management / release management requirements when changes are required. Firewalls shall operate 24x7x365. Analysis of the firewall logs shall be reported to DHS COTR in weekly status reports. If an abnormality or anomaly is identified, the contractor shall notify the appropriate DHS point of contact in accordance with the incident response plan.
Intrusion Detection Systems and Monitoring
The Contractor shall provide the design, configuration, implementation, and maintenance of the sensors and hardware that are required to support the NIDS solution. The contractor is responsible for creating and maintaining the NIDS rule sets. The NIDS solution should provide real-time alerts. These alerts and other relevant information shall be located in a central repository. The NIDS shall operate 24x7x365. A summary of alerts shall be reported to DHS COTR in weekly status reports. If an abnormality or anomaly is identified, the contractor shall notify the appropriate DHS point of contact in accordance with the incident response plan.
Physical and Information Security and Monitoring
The Contractor shall provide a facility using appropriate protective measures to provide for physical security. The facility will be located within the United States and its territories. The contractor shall maintain a process to control physical access to DHS IT assets. DHS IT Assets shall be monitored 24x7x365. A summary of unauthorized access attempts shall be reported to the appropriate DHS security office.
Vulnerability Assessments
The Contractor shall provide all information from any managed device to DHS, as requested, and shall assist, as needed, to perform periodic vulnerability assessments of the network, operating systems, and applications to identify vulnerabilities and propose mitigations. Vulnerability assessments shall be included as part of compliance with the continuous monitoring of the system.
Anti-malware (e.g., virus, spam)
The Contractor shall design, implement, monitor and manage to provide comprehensive anti-malware service. The contractor shall provide all maintenance for the system providing the anti-malware capabilities to include configuration, definition updates, and comply with DHS’ configuration management / release management requirements when changes are required. A summary of alerts shall be reported to DHS COTR in weekly status reports. If an abnormality or anomaly is identified, the contractor shall notify the appropriate DHS point of contact in accordance with the incident response plan.
Patch Management
The Contractor shall perform provide patch management services. The contractor shall push patches that are required by vendors and the DHS system owner. This is to ensure that the infrastructure and applications that directly support the DHS information system are current in their release and that all security patches are applied. The contractor shall be informed by DHS which patches that are required by DHS through the Information Security Vulnerability Management bulletins and advisories. Core applications, the ones DHS utilizes to fulfill their mission, shall be tested by DHS. However, the contractor shall be responsible for deploying patches as directed by DHS. It is recommended that all other applications (host-based intrusion detection system (HIDS), network intrusion detection system (NIDS), Anti-malware, and Firewall) shall be tested by the contractor prior to deployment in a test environment.
Log Retention
Log files for all infrastructure devices, physical access, and anti-malware should be retained online for 180 days and offline for three years.
Supply Chain Risk Management Requirement
Supply Chain risks result from adversarial exploitation of the organizations, people, activities, information, resources, or facilities that provide hardware, software, or services. These risks can result in a loss of confidentiality, integrity, or availability of information or information systems. A compromise to even minor system components can lead to adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.
Authorities:
• Comprehensive National Cybersecurity Initiative (CNCI) Initiative 11, Develop Multi-Pronged Approach for Global Supply Chain Risk Management
• DHS Information Security Systems Directive 4300A version 13.3, Feb 13, 2023
• Homeland Security Presidential Directive 23, Cyber Security and Monitoring, 8 January 2008
• Office of Budget and Management Circulation A-130, Appendix III
• National Institute of Standards and Technology, Special Publication 800-53, Revision 4, Security and
Privacy Controls for Federal Information Systems and Organizations, April 2013
Supply Chain Risk Management
The following requirements should be included in all hardware and software requests to ensure the confidentiality, integrity, and availability of government information.
The Contractors supplying the Government hardware and software shall provide the manufacture’s name, address, state and/or domain of registration, and the Data Universal Numbering System (DUNS) number for all components comprising the hardware and software. If subcontractors or subcomponents are used, the name, address, state and/or domain of registration and DUNs number of those suppliers must also be provided.
Subcontractors are subject to the same general requirements and standards as prime contractors.
Contractors employing subcontractors shall perform due diligence to ensure that these standards are met.
The Government shall be notified when a new contractor/subcontractor/service provider is introduced to the supply chain, or when suppliers of parts or subcomponents are changed.
Contractors shall provide, implement, and maintain a Supply Chain Risk Management Plan that addresses internal and external practices and controls employed to minimize the risk posed by counterfeits and vulnerabilities in systems, components, and software.
The Plan shall describe the processes and procedures that will be followed to ensure appropriate supply chain protection of information system resources developed, processed, or used under this contract.
The Supply Chain Risk Management Plan shall address the following elements:
1. How risks from the supply chain will be identified,
2. What processes and security measures will be adopted to manage these risks to the system or system components, and
3. How the risks and associated security measures will be updated and monitored.
The Supply Chain Risk Management Plan shall remain current through the life of the contract or period of performance. The Supply Chain Risk Management Plan shall be provided to the Contracting Officer Technical Representative (COTR) 30 days post award.
The Contractor acknowledges the Government's requirement to assess the Contractors Supply Chain Risk posture. The Contractor understands and agrees that the Government retains the right to cancel or terminate the contract, if the Government determines that continuing the contract presents an unacceptable risk to national security.
The Contractor shall disclose, and the Government will consider, relevant industry standards certifications, recognitions and awards, and acknowledgments.
The Contractor shall provide only new equipment unless otherwise expressly approved, in writing, by the Contracting Officer (CO). Contractors shall only provide Original Equipment Manufacturers (OEM) parts to the Government. In the event that a shipped OEM part fails, all replacement parts must be OEM parts.
The Contractor shall be excused from using new OEM (i.e. “grey market,” previously used) components only with formal Government approval. Such components shall be procured from their original genuine source and have the components shipped only from manufacturers authorized shipment points.
For software products, the contractor shall provide all OEM software updates to correct defects for the life of the product (i.e. until the “end of life.”). Software updates and patches must be made available to the government for all products procured under this contract.
Contractors shall employ formal and accountable transit, storage, and delivery procedures (i.e., the possession of the component is documented at all times from initial shipping point to final destination, and every transfer of the component from one custodian to another is fully documented and accountable) for all shipments to fulfill contract obligations with the Government.
All records pertaining to the transit, storage, and delivery will be maintained and available for inspection for the lessor of the term of the contract, the period of performance, or one calendar year from the date the activity occurred.
These records must be readily available for inspection by any agent designated by the US Government as having the authority to examine them.
This transit process shall minimize the number of times en route components undergo a change of custody and make use tamper-proof or tamper-evident packaging for all shipments. The supplier, at the Government’s request, shall be able to provide shipping status at any time during transit.
The Contractor is fully liable for all damage, deterioration, or losses incurred during shipment and handling, unless the damage, deterioration, or loss is due to the Government. The Contractor shall provide a packing slip which shall accompany each container or package with the information identifying the contract number, the order number, a description of the hardware/software enclosed (Manufacturer name, model number, serial number), and the customer point of contact. The contractor shall send a shipping notification to the intended government recipient or contracting officer. This shipping notification shall be sent electronically and will state the contract number, the order number, a description of the hardware/software being shipped (manufacturer name, model number, serial number), initial shipper, shipping date and identifying (tracking) number.
4.1.3.8 Personal Identification Verification (PIV) Credential Compliance
If the ITAR request is for products, systems, services, hardware, or software that enables access to controlled facilities and information systems, please include the PIV Credential Compliance requirement below.
Examples of when to use this requirement:
• The ITAR request is for a commercial-off-the-shelf (COTS) product that the Component requires to fulfill its mission requirements. The COTS product must be enabled to use PIV credential, in accordance with NIST guidelines including Federal Information Processing Standard Publication (FIPS) 201 (Demonstrated progress toward integration with AppAuth would be considered a confirmation to PIV enablement).
• The ITAR request is for the procurement of 1500 desktops as part of a technology refresh. The desktops must have a PIV card reader.
• The Component is requesting a custom software product to be developed. The custom software product must be able to use PIV credential for authentication purpose.
Personal Identification Verification (PIV) Credential Compliance
Authorities:
• HSPD-12 “Policies for a Common Identification Standard for Federal Employees and Contractors”
• OMB M-11-11 "Continued Implementation of Homeland Security Presidential Directive (HSPD) 12–
Policy for a Common Identification Standard for Federal Employees and Contractors"
• OMB M-06-16 “Acquisition of Products and Services for Implementation of HSPD-12”
• NIST FIPS 201 “Personal Identity Verification (PIV) of Federal Employees and Contractors”
• NIST SP 800-63 “Electronic Authentication Guideline”
• OMB M-10-15 “FY 2010 Reporting Instructions for the Federal Information Security Management
Act and Agency Privacy Management”
Personal Identification Verification (PIV) Credential Compliance Requirement
Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting HSPD-12 PIV credentials as a method of identity verification and authentication.
Procurements for software products or software developments shall be compliant by PIV by accepting PIV credentials as the common means of authentication for access for federal employees and contractors.
PIV-enabled information systems must demonstrate that they can correctly work with PIV credentials by responding to the cryptographic challenge in the authentication protocol before granting access.
If a system is identified to be non-compliant with HSPD-12 for PIV credential enablement, a remediation plan for achieving HSPD-12 compliance shall be required for review, evaluation, and approval by the
CISO.
CBP Contractor Handling PII Level
When a contractor, on the behalf of CBP, handles Sensitive PII data, stores and transmits, the contractor will Accredit (ATO) this information system to the (HHM) FIPS level
Security Requirements for Unclassified Information Technology Resources Requirement
If the contractor will be working on DHS sensitive data either at a contractor facility or on contractor equipment, a Contractor IT Security Plan is required.
(END)
As prescribed in (HSAR) 48 CFR 3004.470-3(b):
Homeland Security Presidential Directive (HSPD-12)
The Homeland Security Presidential Directive 12 (HSPD-12) requires the use of the Personal Identity Verification (PIV) credentials as the common means of authentication for access to DHS facilities, networks, and information systems. Personal Identity Verification (PIV) credentials shall be used as the primary means of logical authentication for DHS sensitive systems. The Contractor must use his or her federal issued Personal Identity Verification (PIV) credentials to access DHS resources to include IT applications and physical facility.
The DHS Office of the Chief Security Officer shall be notified of all terminations/resignations within five
(5) days of occurrence. The Contractor shall return to the Contracting Officer Representative (COR) all DHS issued Personal Identity Verification (PIV) credentials/identification cards and building passes that have either expired or have been collected from terminated employees. If a PIV credential/identification card or building pass is not available to be returned, a report shall be submitted to the COR, referencing the PIV credential, pass or card number, name of individual to who it was issued and the last known location and disposition of the PIV credential, pass or card. The Contractor or contractor personnel's failure to return all DHS- or FEMA-issued identification cards and building passes upon expiration, upon the contractor personnel's removal from the contract, or upon demand by DHS or FEMA may subject the contractor personnel and the Contractor to civil and criminal liability.
Information Security Office Compliance for National Security Systems Requests
Compliance with DHS Security Policy Requirements for National Security Systems
All hardware, software, and services provided under this contract must be compliant with DHS National Security Systems Policy Directive 4300B, and/or the 4300C series for Sensitive Compartmented Information SCI systems.
Encryption Compliance Terms and Conditions
National Security Systems, requiring encryption shall comply with the following standards:
1. Products using FIPS 197 Advanced Encryption Standard (AES) algorithms with at least 256 bit encryption that has been validated under FIPS 140-2 (Note: The use of triple DES [3DES] and FIPS 140-1 is no longer permitted. A waiver or exception is required for systems where AES cannot currently be used.)
2. NSA Type 2 or Type 1 encryption
3. Public Key Infrastructure (PKI) (see paragraph 5.5.2.1 of the Department of Homeland Security
(DHS) Information Security Systems Directive 4300A (version 13.3, Feb 13, 2023).
ITP Compliance Terms and Conditions
All back-end system hardware and software shall be hosted in the DHS Enterprise Data Center unless Component provides a migration plan or obtains an approved waiver from DHS CIO.”
All DHS Wide Area Network circuits must be part of the OneNet architecture unless a waiver is approved by DHS CIO.
Office of Accessible Systems & Technology (OAST) (Section 508)
1. Section 508 Requirements
Section 508 of the Rehabilitation Act (classified to 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.
All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Appendixes A, C & D, and available at https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards. ICT includes IT and other equipment.
Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018, or any successor publication.
1.1 Section 508 Requirements for Technology Products
Section 508 applicability to Information and Communications Technology (ICT): Aware CaptureSuite Program Software
Applicable Exception: N/A Authorization #: N/A
Applicable Functional Performance Criteria: All functional performance criteria in Chapter 3 apply to when using an alternative design or technology that results substantially equivalent or greater accessibility and usability by individuals with disabilities than would be provided by conformance to one or more of the requirements in Chapters 4 and 5 of the Revised 508 Standards, or when Chapters 4 or 5 do not address one or more functions of ICT.
Applicable 508 requirements for electronic content features and components (including but not limited to Internet or Intranet website): Does not apply
Applicable 508 requirements for software features and components (including but not limited to Software infrastructure): All requirements in Chapter 5 apply, including all WCAG 2.0 Level A and AA Success Criteria Apply except 2.4.1 Bypass Blocks, 2.4.5 Multiple Ways, 3.2.3 Consistent Navigation, 3.2.4 Consistent Identification, 502 Interoperability with Assistive Technology, 503 Application
Applicable 508 requirements for hardware features and components: Does not apply
Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply
1.2 Section 508 Requirements for Technology Products
Section 508 applicability to Information and Communications Technology (ICT): Licenses
Applicable Exception: N/A Authorization #: N/A https://uscode.house.gov/view.xhtml?req=(title:29%20section:794d%20edition:prelim)%20OR%20(granuleid:USC-prelim-title29-section794d)&f=treesort&edition=prelim&num=0&jumpTo=true https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5 https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5
Applicable Functional Performance Criteria: All functional performance criteria in Chapter 3 apply to when using an alternative design or technology that results substantially equivalent or greater accessibility and usability by individuals with disabilities than would be provided by conformance to one or more of the requirements in Chapters 4 and 5 of the Revised 508 Standards, or when Chapters 4 or 5 do not address one or more functions of ICT.
Applicable 508 requirements for electronic content features and components: Does not apply
Applicable 508 requirements for software features and components (including but not limited to Software infrastructure)
Applicable 508 requirements for hardware features and components: Does not apply
Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply
1.4 Section 508 Deliverables
1. Section 508 Accessibility Conformance Reports: For each ICT item offered through this contract (including commercially available products, and solutions consisting of ICT that are developed or modified pursuant to this contract), the Offeror shall provide an Accessibility Conformance Report (ACR) to document conformance claims against the applicable Section 508 standards. The ACR shall be based on the Voluntary Product Accessibility Template Version 2.0 508 (or successor versions). The template can be found at https://www.itic.org/policy/accessibility/vpat. Each ACR shall be completed by following all of the instructions provided in the template, including an explanation of the validation method used as a basis for the conformance claims in the report.
ISO (Information Security) Compliance System Security documentation appropriate for the SELC status.
Security Certification/Accreditation
CBP Program Offices shall provide personnel (System Owner and Information System Security Officers) with the appropriate clearance levels to support the security certification/accreditation processes under this Agreement in accordance with the current version of the DHS Information Security Systems Directive 4300A (version 13.3, Feb 13, 2023), CBP Information Systems Security Policies and Procedures Handbook HB-1400-05, and all applicable National Institute of Standards and Technology (NIST) Special Publications (800 Series). During all SELC phases of CBP systems, CBP personnel shall develop documentation and provide any required information for all levels of classification in support of the certification/accreditation process. In addition, all security certification/accreditation will be performed using the DHS certification/accreditation process, methodology and tools. An ISSO performs security actions for an information system. There is only one ISSO designated to a system, but multiple Alternate ISSOs may be designated to assist the ISSO. While the ISSO performs security functions, the System Owner is always responsible for information system security (4300A). System owners shall include information security requirements in their capital planning and investment control (CPIC) business cases for the current budget year and for the Future Years Homeland Security Program (FYHSP) for each DHS information system. System owners or AOs shall ensure that information security requirements and POA&Ms are adequately funded, resourced and documented in accordance with current OMB budgetary guidance.
Disaster Recovery Planning & Testing – Hardware
If the system owner requires a robust DR solution (full redundancy and failover capabilities (for near zero downtime) then the funded DR solution must match the production environment like-for-like. This solution https://www.itic.org/policy/accessibility/vpat would also include additional software licenses, hardware, firmware and storage for the DR environment.
The system owner or program office must also include travel, per diem and approximately 16 over the core hours for travel to recovery facilities twice per fiscal year for system administrators, DBA’s, end users or testers If the system owner requires a moderate DR solution that would provide a working environment that is capable of handling their mission essential functions then they can fund a scaled down solution which should still take into consideration additional hardware, software licenses, and storage for the DR environment.
The system owner or program office is still responsible for the costs associated with testing their DR solution; however, for a scaled down solution, it may be possible to leverage or share staff already designated to participate in DR activities.
If the system owner only requires a low DR solution then the system owner or program office can use internal resources to perform a table-top exercise, which generally does not require travel, additional hardware or software licenses.
Monitoring/reviewing contractor security requirements
Security Review and Reporting
(a) The Contractor shall include security as an integral element in the management of this contract. The Contractor shall conduct reviews and report the status of the implementation and enforcement of the security requirements contained in this contract and identified references.
(b) The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS including the organization of the DHS Office of the Chief Information Officer, Office of Inspector General, the CBP Chief Information Security Officer, authorized Contracting Officer’s Technical Representative (COTR), and other government oversight organizations, access to the Contractor's and subcontractors' facilities, installations, operations, documentation, databases, and personnel used in the performance of this contract. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to the DHS. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of DHS/CBP data or the function of computer systems operated on behalf of DHS/CBP, and to preserve evidence of computer crime.
Access to Unclassified Facilities, Information Technology Resources, and Sensitive Information
The assurance of the security of unclassified facilities, Information Technology (IT) resources, and sensitive information during the acquisition process and contract performance are essential to the DHS mission. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive But Unclassified (For Official Use Only) Information, describes how contractors must handle sensitive but unclassified information. DHS MD 4300.1 Information Technology Systems Security and the DHS Sensitive Systems Handbook prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering contractors specifically for all contracts that require access to DHS facilities, IT resources or sensitive information.
Contractors shall not use or redistribute any DHS information processed, stored, or transmitted by the contractor except as specified in the contract.
OMB-M-07-18 FDCC/Common Security Configuration Clause
In acquiring information technology, agencies shall include the appropriate information technology security policies and requirements, including use of common security configurations available from the National
Institute of Standards and Technology’s website at http://checklists.nist.gov. Agency contracting officers should consult with the requiring official to ensure the appropriate standards are incorporated.
Engineering Platforms
Common Enterprise Services (CES) – Deliver the systems, infrastructure, and operational capabilities to fully implement the three service levels defined as part of the DHS/CBP Common Enterprise Services and support DHS Component use of those services. This includes the build out and integration of all required services and infrastructure, which must include the Single Sign-on Portal and CBP Enterprise Services Bus (ESB), required for the CES. Capabilities shall be designed to the DHS standard operating architecture (SOA), transportable between DHS data centers (CBP National Data Center, Stennis, and DHS 2nd data center). CBP is consolidating all its development, testing, production, and disaster recovery environments to the two DHS Enterprise Data Centers. The Contractor shall continue to meet the requirements of this SOW regardless of the location of these environments.
Single Sign-on Portal – Design, build, and operate a single sign-on Portal - consistent with DHS’ enterprise portal solution (for which ICE is the steward) - to provide a common point of access, with a single sign-on capability to existing applications and to provide the infrastructure for integrating diverse internal and/or external information and transactional resources. This includes the migration of the current ACE Portal to the Single Sign-on Portal as rapidly as feasible.
ITP (Infrastructure Transformation Program)
All applications under this contract will follow the CBP/DHS approved Migration Plan and be transportable between DHS data centers (CBP National Data Center, Stennis, and DHS 2nd data center).
Help Desk and Operations Support
The contractor shall provide third tier reporting for trouble calls received from the Help Desk, the DHS Task Manager, or the users. The Contractor shall respond to the initiators of trouble calls as by receiving telephonic notifications of problems, resolving them, or directing them to the proper technical personnel for resolution. Problems that cannot be resolved immediately or with the requirements of the performance standards are to be brought to the attention of the DHS Task Manager. The Contractor shall document notification and resolution of problems in Service Now .
Interfacing
As requested by the COR, assistance in consolidating all systems with the DHS Consolidated Data Center.
Resources are to be consolidated with the DHS Consolidated Data Center for each system to be determined by the COR.
Transition Plan (if applicable)
The DHS CIO has established portfolio targets for the IT infrastructure that include production system consolidation at a DHS data center and transition to OneNet. The contractor must be prepared to support CBP government leads, within the purview of this contract, to provide any required transition planning or program execution, associated with meeting the agreed to transition timeline, as directed by Government personnel. This includes the following types of tasks:
• Coordination with Government representatives
• Review, evaluation and transition of current support services
• Transition of historic data to new contractor system
• Government-approved training and certification process http://checklists.nist.gov/
• Transfer of all necessary business and/or technical documentation
• Orientation phase and program to introduce Government personnel, programs, and users to the
Contractor's team, tools, methodologies, and business processes, equipment, furniture, phone lines, computer equipment, etc.
• Transfer of Government Furnished Equipment (GFE) and Government Furnished Information (GFI), and GFE inventory management assistance
• Applicable debriefing and personnel out-processing procedures
Cloud Computing
(a) Cloud computing. All use of cloud computing products or services that process unclassified information must comply with the FedRAMP Authorization Act, 44 U.S.C. Section 3607 et. seq. The following requirements apply when using cloud computing to provide information systems or services in the performance of the contract.
i. Cloud computing security requirements. The Contractor shall implement and maintain administrative, technical, and physical safeguards and controls with the security level and services required in accordance with FedRAMP Security Authorization Requirements unless notified by the Contracting Officer that this requirement has been waived by the Agency Chief Information Officer.
ii. Cloud computing continuous monitoring. The Contractor shall maintain an adequate continuous monitoring capability based on the FedRAMP Security Authorization Requirements including processes described in the NIST Special Publication (SP) 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations and governed by the FedRAMP Continuous Monitoring Strategy Guide.
ii. Cloud computing services cyber incident reporting. The Contractor shall report all cybersecurity incidents that are related to the cloud computing service provided under this contract. Reports shall be submitted according to FedRAMP Security Authorization Requirements, published FedRAMP Incident Communications Procedures, and Federal Incident Notification Guidelines for submitting incident notifications to CISA using the CISA incident reporting form (https://us-cert.cisa.gov/report).
Artificial Intelligence / Machine Learning Requirements
Definitions:
Artificial Intelligence (AI) includes the following:
(1) Any artificial system that performs tasks under varying and unpredictable circumstances without significant human oversight, or that can learn from experience and improve performance when exposed to data sets.
(2) An artificial system developed in computer software, physical hardware, or other context that solves tasks requiring human-like perception, cognition, planning, learning, communication, or physical action.
(3) An artificial system designed to think or act like a human, including cognitive architectures and neural networks.
(4) A set of techniques, including machine learning, that is designed to approximate a cognitive task.
(5) An artificial system designed to act rationally, including an intelligent software agent or embodied robot that achieves goals using perception, planning, reasoning, learning, communicating, decision making, and acting.
Requirements:
The 2019 National Defense Authorization Act (NDAA) and Executive Order (EO) 13960 require that AI used in the Federal Government foster public trust and confidence while protecting privacy, civil rights, civil liberties, and American values. All federal employees, contractors, and subcontractors, when designing, developing, acquiring, and/or using AI for or within DHS, will adhere to the following 9 principles.
https://us-cert.cisa.gov/report https://us-cert.cisa.gov/report
1. Lawful and respectful of our Nation's values:
Agencies shall design, develop, acquire, and use AI in a manner that exhibits due respect for our Nation's values and is consistent with the Constitution and all other applicable laws and policies, including those addressing privacy, civil rights, and civil liberties.
2. Purposeful and performance-driven:
Agencies shall seek opportunities for designing, developing, acquiring, and using AI, where the benefits of doing so significantly outweigh the risks, and the risks can be assessed and managed.
3. Accurate, reliable, and effective:
Agencies shall ensure that their application of AI is consistent with the use cases for which that AI was trained, and such use is accurate, reliable, and effective.
4. Safe, secure, and resilient:
Agencies shall ensure the safety, security, and resiliency of their AI applications, including resilience when confronted with systematic vulnerabilities, adversarial manipulation, and other malicious exploitation.
5. Understandable:
Agencies shall ensure that the operations and outcomes of their AI applications are sufficiently understandable by subject matter experts, users, and others, as appropriate.
6. Responsible and traceable:
Agencies shall ensure that human roles and responsibilities are clearly defined, understood, and appropriately assigned for the design, development, acquisition, and use of AI. Agencies shall ensure that AI is used in a manner consistent with these Principles and the purposes for which each use of AI is intended.
The design, development, acquisition, and use of AI, as well as relevant inputs and outputs of particular AI applications, should be well documented and traceable, as appropriate and to the extent practicable.
7. Regularly monitored:
Agencies shall ensure that their AI applications are regularly tested against these Principles. Mechanisms should be maintained to supersede, disengage, or deactivate existing applications of AI…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .