Attachment B - Sample Task Order SOW.pdf
PDF 393 KB Posted
- Attached to
- FDA Security Installation and Maintenance Federal contract opportunity
- Solicitation number
- 75F40121R00039
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment B Solicitation No. 75F40121R00039
FDA Security Installation and Maintenance
U.S. FOOD AND DRUG ADMINISTRATION
Office of Operations
OSSCM/OSO
Security Maintenance Sample Task Order 1 Statement of Work (SOW)
1. Background
The U S. Food and Drug Administration (FDA) is a scientific, regulatory, and public health Government agency. Its jurisdiction encompasses food products (other than meat and poultry), human and animal drugs, therapeutic agents of biological origin, medical devices, radiation-emitting products for consumer, medical, and occupational use, cosmetics, and animal feed. Approximately one-third of the agency's employees are stationed outside of the Washington, D. C. area, staffing over 150 field offices and laboratories, including 20 district offices, across the US conterminous, non-conterminous states and US territories.
The Office of Security Operations, through the Physical Security Office, is charged with securing all FDA facilities nationwide for the protection of people and property. Systems utilized by the Physical Security Office include access control systems (ACS), video imaging systems, closed circuit television (CCTV), various security detection and initiating devices, perimeter detection, and others. All Electronic Security Systems utilized by the Physical Security Office need to be maintained to 100% efficiency 24 hours a day, 365 days a year. As the FDA mission grows, new installations and modifications to existing facilities will be required to meet the FDA’s security needs.
2. Objectives
The purpose of this requirement (Task Order 01) is to service and Maintain the FDA National Security System.
As a result of this Task Order, the FDA expects to achieve the following outcomes:
Enhance FDA’s ability to continually maintain and monitor the performance of all physical security systems listed below in Section 4 to be known as “PSS”.
Enable FDA to remain at a state of readiness to ensure that all physical security assets are inspected and one hundred percent operational.
Enable FDA to rapidly and effectively respond to urgent physical security related programing, maintenance, and installation situations.
Enhance FDA’s ability to accurately retain data pertaining to all PSS.
Maintain all hardware and software associated with the PSS throughout the United States and U.S territories.
3. Scope of Work
FDA Security Systems Operations and Maintenance
The Contractor shall provide all necessary parts and labor to maintain all PSS. All systems utilized by the Physical Security Office are required to be maintained to 100% efficiency 24 hours a day 365 days a year. Representative activities include: Dealer License - The contractor shall provide factory certified technicians for all systems listed in this contract. The contractor shall also provide support personnel, equipment, tools, transportation, diagnostic equipment, parts, materials, supervision and any other services, material and personnel not specifically mentioned necessary to perform all aspects of
Statement of Work. The contractor shall be a dealer in good standing with all PSS.
Software/Network Maintenance: The Contractor shall work closely with FDA Physical Security Team, White Oak Command Center and other stakeholders to maintain the FDA security systems network and software in accordance with the specifics of this task order. Representative activities include:
• Maintain manufacture updates and licenses to all PSS.
• Resolve network issues that can affect the PSS on standalone networks.
• Maintain a journal logbook for all server logins with time date and system, including a complete description of reason for login.
File Server and Database Maintenance/Service: The Contractor shall maintain and administer specific head end file servers and databases. The duties performed by the Contractor shall include:
• Provide MDI and Software House SQL Server Database backups, in addition to those backups performed by FDA IT personnel; ensuring that backups are of sufficient quality, frequency and integrity to restore the system to full operation in event of a crash or catastrophic failure;
• Install SQL Server updates and patches; providing recovery and restoration of system applications and data in the event of loss or catastrophic system failure;
• Provide support to field personnel when head end adjustments are necessary to support proper system communication or to optimize performance of field equipment;
• Coordinate, as required, with FDA Physical Security Branch and FDA IT personnel in order to facilitate troubleshooting system software, hardware and network problems; responding to system outage incidents when server or database problems are suspected; and maintaining a journal logbook of any file server/database changes and updates.
System Administration: The Contractor shall provide system administration for all security systems identified in Section 4 (FDA Technology) listed below. The activities performed by the Contractor shall include:
• Perform daily system checks and log the status of all physical security systems, network and field devices on MDI, Software House, and Bosch Servers and workstations
• Program the configuration of all field hardware modifications in the Electronic Security System;
• Input all repairs and work performed in the FDA Service Maintenance Database;
• Administer and maintain a Configuration Management Database for all MDI, Software House, and
Bosch Servers and workstations
• Report and log all configuration management changes and updates in the configuration management database.
• Provide technical support for the Physical Security Electronic Systems and performing routine repairs
• Manage and direct all technicians responding to service and maintenance calls.
Preventative Maintenance: The Contractor shall perform preventive maintenance. The Contractor shall develop a preventive maintenance schedule and shall report on all tasks performed using the service maintenance database, which must be approved by FDA Physical Security.
Technical Support (Service Calls): The Contractor shall respond to service calls, as described herein.
• Service/trouble calls - Service/trouble calls will be initiated by the designated security representative at each field location to the FDA Physical Security Branch on 301-796-2408 or the FDA White Oak Command Center located at 10903 New Hampshire Avenue, Silver Spring, Maryland on 301-796-2414, 24 hours a day, 7 days per week. FDA White Oak Command Center operators will contact the contractor by phone and by a contractor provided online web portal connected to maintenance database to initiate a service/trouble call.
• The Contractor shall respond via telephone to the White Oak Command Center within one (1) hour of receiving the service request.
• The Contractor shall contact the local security representative before arriving at any FDA location.
All service calls, once started, shall be worked until equipment is back in serviceable condition. Status of the service performed shall be logged into the appropriate web-portal reporting database based on the service performed before leaving the site, unless work is performed after core hours (7am-5pm) or weekends; in those cases, the status shall be logged the next business day before 12:00 PM, Eastern Time. The status update shall include information such as, but not limited to: System affected, device information, any malfunctions found, and corrective action(s) taken for each service call; parts required;
any upgrade suggestions to improve operation of the security system, if warranted; and duration of performance.
• The Contractor shall be responsible for moving and protecting and replacing furnishings in the work area when the work is complete. Any damages resulting from the Contractor's operations shall be repaired or replaced by the Contractor at no additional expense to the Government.
• Working in secured areas is required under this task order, and the Contractor will not be granted unlimited access to these areas. The Contractor shall contact a Physical Security Specialist to liaison with the site in question prior to the start of work to arrange for security escorts into the secured area.
• Under no circumstances shall the Contractor (or any of its subcontractors, if applicable) enter an FDA Bio Safety Level 3 Lab (BSL3) suite, Office of Criminal Investigations (OCI) Spaces or Sensitive Compartment Information Facility (SCIF) without a Government escort.
• The Contractor shall notify the on-site Physical Security Specialist to ensure that the affected area is properly secured, if the Contractor determines that the repairs cannot be accomplished with the parts on hand.
• The Contractor shall not leave the building unsecured at any time.
Representative activities performed by the Contractor shall include:
• Investigate all trouble tickets presented and take corrective actions.
• Provide after-hours remote access support or phone support in the event of a system failure.
• Take actions to prevent or mitigate redundant service requests by scrutinizing all system trouble tickets presented.
• Update the appropriate web-portal Service Database to reflect the status of pending and completed service calls.
Non-Emergency Repairs: The Contractor shall respond to non-emergency repair service calls, as required herein.
• The Contractor shall have all labor, materials, and equipment to perform the necessary repairs.
• The Contractor shall provide non-emergency repair service within (24) hours to the requested maintenance site at Headquarters locations and (48) hours to the requested maintenance site at Field locations, from the time of receipt of call, day or night.
• For maintenance requests originating after core hours on Fridays, the response shall be required the next business day.
• It shall be the responsibility of the Contractor to keep the FDA Contracting Officer Representative (COR) informed of the telephone numbers at which the Contractor can be contacted.
Emergency Repairs: Emergency repairs are defined as those that are life threatening or allow breach of any perimeter security. The Contractor shall respond to non-emergency repair service calls, as required herein.
• The Contractor shall provide emergency repair service within (4) hours to the requested maintenance site at Headquarters locations, and within 24 hours to the requested field site from the time of receipt of call, day or night.
• The Contractor shall respond to emergency repair service calls, as required herein.
• The Contractor shall have all labor, materials, and equipment to perform the necessary repairs.
• It shall be the responsibility of the Contractor to keep the FDA informed of the telephone numbers at which the responding technician(s) can be contacted.
Spare Parts:
• The Contractor shall provide Original Equipment Manufacturer (OEM) spare equipment and parts to ensure that the system remains fully operational.
• The Contractor shall maintain a spare equipment inventory to ensure that the system remains completely operational.
• The Contractor shall repair or replace defective equipment per maintenance request within 24 hours.
4. FDA Technology
The FDA security systems, in whole, is comprised of multiple integrated systems installed at individual locations nationwide, to include, but not limited to:
Accutech, Aiphone and Commend equipment, BOSCH / Pelco CCTV (Dealer Certification), Building Intelligence SV3 Visitor management systems, Commend International, Delta Scientific Barriers Foundry/Barcade network devices, CEIA /GARRET Magnetometer Walk thru Metal Detector, Mantrap Interlock doors with PLC boards, Monitor Dynamics Inc 6.2.6 SP4/5 (MDI) (Dealer Certification), Motorola and Acela radio equipment, NetApp storage, Nortel, SALTO Security systems, Smith Detection X-Ray scanners, Software House CCURE 9000(Dealer Certification), Vehicle barriers installed in the NCR National Capitol Region.
5. Quality Assurance Plan
The purpose of this Quality Assurance Plan (QAP) is to provide a mutually agreed upon mechanism to assess the Contractor’s performance throughout the course of the initiative. The Contractor shall meet with FDA project leadership at contract initiation to review this plan and agree upon deliverables and areas to be measured, monitoring mechanisms and target standards, and surveillance methods and frequency of surveillance.
The QAP details how the performance metrics and compliance criteria are captured and reported, providing FDA leadership with an understanding of how measures and metrics will be applied based on the proposed technical solution.
6. Warranty
Manufacturer Equipment The Contractor shall honor manufacturers’ warranty/guarantees on all installed hardware/software starting, at the time of installation and usage. The Contractor shall provide the description, model number, serial number and date of hardware/software installed where a manufacturers’ warranty/guarantees apply. The Contractor shall replace and make operational any defective warranty/guarantee items within 24 hours.
Labor
The Contractor shall warrant all labor and non-manufacturer warranty/guarantees for a period of one (1) year.
Documentation
Warranty periods shall be tracked in the Service Maintenance Database under the Inventory section. This shall include manufacturer and labor warranty/guarantees.
7. Testing
All equipment must be fully tested by a certified Technician prior to FDA’s inspection and acceptance of the system. A performance verification test will be performed and presented to the FDA Physical Security Staff before scheduling final acceptance testing. Equipment will not be added to the maintenance portion of the contract until the system has been fully accepted by the Government in writing.
8. Documentation
• Monthly Preventive Maintenance Reports
• Weekly Service Request/Trouble Tickets Reports
• Daily Systems check results
9. Deliverables
• Project Integration Packet/Configuration Sheets
• Preventive Maintenance Reports
• Service Request/Trouble Tickets
• Daily Systems check results
Be advised that the FDA does not accept documents which contain the use of macros. Document submissions required throughout the period of performance of this Order must not have macro-enabled functionality, and any document delivered having that functionality will be deemed delinquent, if not corrected prior to the due date.
10. Place of Performance
The place of performance for this task order for the Project Manager, System Administrator and Technicians is the FDA’s White Oak Campus, located in Silver Spring, MD. A list of all FDA Physical Security Sites to be maintained r is listed in Item #14 below.
11. Period of Performance
The period of performance for this task order consists of 12 months, anticipated to be January 3, 2022 through January 2, 2023.
12. Task Order Type
The task order type is anticipated to be Firm-Fixed-Price.
13. Security and Privacy
A. Baseline Security Requirements
1. Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR)
Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2. Safeguarding Information and Information Systems. In accordance with the Federal
Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an FDA network or operated by the Contractor on behalf of FDA regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party. This includes notifying the FDA Systems Management Center (SMC) within one (1) hour of discovery/detection in the event of an information security incident.
c. Adopt and implement the policies, procedures, controls, and standards required by the
HHS/FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the FDA Information Security Program security requirements, outlined in the FDA Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing your ISSO.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
3. Information Security Categorization. In accordance with FIPS 199 and National Institute of
Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf
Security Categorization Level:
Information Type (Number and Title)
Confidentiality (Low, Moderate, High)
Integrity (Low, Moderate, High)
Availability (Low, Moderate, High)
Help Desk Services Low Low Low Security Management Mod Mod Low IT Infrastructure Maintenance Low Mod High Lifecycle/Change Management Low Mod Low Record Retention Mod Mod Low System and Network Monitoring
Mod Mod Low
Information System Security Low Mod Low Service Recovery Low Low Low
Information/System Categorization:
Project/System Name Confidentiality
(Low, Moderate, High) Integrity (Low, Moderate, High)
Availability (Low, Moderate, High)
Overall Risk:
(Low, Moderate, High)
Moderate Moderate Moderate
E-AUTHENTICATION RISK ASSESSMENT
Conduct an E-Authentication Threshold Analysis (E-Auth TA) to determine if a full E- Authentication Risk Assessment (E-Auth RA) is necessary by following the OMB 04-04, E- Authentication Guidance for Federal Agencies (https://www.whitehouse.gov/sites/default/files/omb/memoranda/fy04/m04- 04.pdf) and NIST SP 800-63, Electronic Authentication Guideline. If a full E-Auth RA is required, determine the level of assurance. The potential levels of assurance are:
• Level 1: Little or no confidence in the asserted identity’s validity;
• Level 2: Some confidence in the asserted identity’s validity;
• Level 3: High confidence in the asserted identity’s validity; or
• Level 4: Very high confidence in the asserted identity’s validity.
Based on the required level of assurance determined by the E-Auth RA, select the appropriate authentication level of assurance and authentication method required to access the information system, including remote authentication.
Level of Assurance: [ X ] N/A [ ] Level 1 [ ] Level 2 [ ] Level 3 [ ] Level 4
Authentication Method: [ X ] N/A [ ] Single-Factor [ ] Two-Factor [ ] Multi-Factor
Based on information provided by the Privacy Office, system/data owner, or other privacy https://www.whitehouse.gov/sites/default/files/omb/memoranda/fy04/m04-04.pdf https://www.whitehouse.gov/sites/default/files/omb/memoranda/fy04/m04-04.pdf representative, it has been determined that this solicitation/contract involves:
[ X ] No PII [ ] Yes PII
Personally Identifiable Information (PII). Per the OMB Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother’s maiden name, biometric records, etc.
PII Confidentiality Impact Level has been determined to be: [ X] Low [ ] Moderate [ ] High
PROSPECTIVE OFFEROR NON-DISCLOSURE AGREEMENT
[ X ] Offerors WILL NOT require access to sensitive information in order to prepare an offer.
[ ] Offerors WILL require access to sensitive information in order to prepare an offer. A Non- Disclosure Agreement (NDA) is necessary for a prospective offeror who will require access to Government information in order to prepare an offer (i.e., a prospective offeror must access an FDA computer room floor plan). [See Appendix B for Non-Disclosure Agreement form.]
DESCRIPTION OF SENSITIVE INFORMATION:
Select appropriate position sensitivity designation below.
[ ] Tier 4: Sensitive - High Risk
[ X ] Tier 2: Sensitive - Moderate Risk
INFORMATION PRIVACY CERTIFICATION
[ ] No privacy requirements apply to this solicitation. Proceed to the signature page.
[ X ] Privacy requirements27 apply to this solicitation. Complete the checklist and sign below.
[ ] Privacy Act applies to this solicitation. Complete the information below and sign the checklist. The following tailored information is required for RFP preparation.
PERSONALLY IDENTIFIABLE INFORMATION (PII)
Select the PII Confidentiality Impact Level. For additional information, see NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (http://csrc.nist.gov/publications/PubsSPs.html).
http://csrc.nist.gov/publications/PubsSPs.html)
PII28 Overall Level: [ ] No PII [ X ] Yes PII
If yes for PII, insert language from the following sections/sub-sections a . Section 2: All
b. Section 3: Applicable language as determined by the
FDA Senior Official for Privacy c . PRIVACY ACT
If Privacy Act requirements apply, complete the following:
TAILORED PRIVACY ACT INFORMATION: Provide the following information if the Privacy Act applies to this solicitation (this is needed to tailor the SOW as required by the HHSAR “Privacy Act” clause, 352.224-70):
• Applicable SORN number(s), or statement that a SORN will be developed:
• Description of design, development, or operation work:
• Records disposition instructions:
PROSPECTIVE OFFEROR NON-DISCLOSURE AGREEMENT
[X] Offerors WILL NOT require access to sensitive information to prepare an offer.
[ ] Offerors WILL require access to sensitive information in order to prepare an offer. A Non- Disclosure Agreement (NDA) is necessary for a prospective offeror who will require access to government information in order to prepare an offer (i.e., a prospective offer must access an FDA computer room, floor plan).
4. Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa). As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re- using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
i. marked appropriately;
ii. disclosed to authorized personnel on a Need-To-Know basis;
iii. protected in accordance with NIST SP 800-53, Security and Privacy Controls for
Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
iv. returned to FDA control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization and the FDA IS2P Appendix T: Sanitization of Computer-Related Storage Media.
b. Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06- 16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of FDA shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and FDA policies. Unauthorized disclosure of information will be subject to the HHS/FDA sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
c. Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
d. Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
e. Contract Documentation. The Contractor shall use FDA-provided templates, policies, forms and other agency documents to comply with contract deliverables, as appropriate.
f. Standard for Encryption. The Contractor (and/or any subcontractor) shall:
i. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
ii. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
iii. All devices (i.e.: desktops, laptops, mobile devices, etc.) that store, transmit, or process non-public FDA information should utilize FDA-provided or FDA information security authorized devices that meet HHS and FDA-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
iv. Verify that the encryption solutions in use are compliant with FIPS 140-2. The
Contractor shall provide a written copy of the validation documentation to the
COR.
v. Use the Key Management system on the HHS Personal Identification
Verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys (PIV card) shall be provided to the COR upon request and at the conclusion of the contract. Upon completion of contract, contractor ensures that COR is able to access and read any encrypted data.
g. Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the FDA non-disclosure agreement (3398 Form), as applicable. A copy of each signed and witnessed NDA shall be submitted to the CO and/or COR prior to performing any work under this acquisition.
h. Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a full PIA needs to be completed.
i. If the results of the PTA show that a full PIA is needed, the Contractor shall assist procuring activity representative, program office and the FDA SOP or designee http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf http://inside.fda.gov:9003/downloads/administrative/forms/fda/ucm013733.pdf with completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002. The PTA/PIA must be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).
ii. The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee in reviewing and updating the PIA at least every three years throughout the Enterprise Performance Life Cycle (EPLC) /information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.
5. Training
1. Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable FDA Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete FDA Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS and FDA training policies.
2. Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy and FDA Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Standard Operating Procedures (SOP).
3. Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
6. Rules of Behavior
1. The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
2. All Contractor employees performing on the contract must read and adhere to the Rules of Behavior (ROB) before accessing HHS and FDA data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines.
7. Incident Response
The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/FDA SMC /Incident Response Team (IRT) teams within 24 hours, whether the response is positive or negative.
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.” The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by FISMA as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII.”
In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:
1. Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
2. NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send FDA approved notifications to affected individuals as directed by FDA’s SOP.
3. Report all suspected and confirmed information security and privacy incidents and breaches to the FDA Systems Management Center, COR, CO, and other stakeholders, (Recommend adding the FDA Senior Official for Privacy with contact information and either defining or deleting “other stakeholders.”) including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour of discovery/detection, and consistent with the applicable FDA and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:
a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
b. not include any sensitive information in the subject or body of any reporting e-mail; and
c. encrypt sensitive information in attachments to email, media, etc.
4. Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable
Information and HHS and FDA incident response policies when handling PII breaches.
5. Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation demand.
8. Position Sensitivity Designations
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract: [See the FDA Security Article, entitled Contractor Personnel Security Clearance Standards and Residency Requirements for the Position Risk Designation Tier(s) (i.e., 1, 2, and/or 4) that apply to this award.] Position Risk Designations will be mentioned at the task order level.
9. Homeland Security Presidential Directive (HSPD)-12
The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster and any revisions to the roster as a result of staffing changes shall be submitted to the COR and/or CO per the COR or CO’s direction. Any revisions to the roster as a result of staffing changes shall be submitted within a timeline as directed by the COR and/or CO. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
10. Contract Initiation and Expiration
1. General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the FDA EPLC framework and methodology in accordance with the FDA EPLC Project documentation, located here:
http://sharepoint.fda.gov/orgs/DelMgmtSupport/IntakeProc/EPLCv2/SitePages/v2/EPLCHome.as px
2. HHS EA requirements may be located here:
https://www.hhs.gov/about/agencies/asa/ocio/index.html
3. System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
4. Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation in accordance with FDA OAGS SMGs to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization and FDA IS2P Appendix T: Sanitization of Computer-Related Storage Media.
5. Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR as soon as it is known that an employee will stop working under this contract.
6. Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or FDA policies.
7. The Contractor (and/or any subcontractor) shall coordinate with the COR via email, copying the
Contract Specialist, to ensure that the appropriate person performs and documents the actions identified in the FDA eDepart system http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/defau lt.htm as soon as it is known that an employee will terminate work under this contract within days of the employee’s exit from the contract. All documentation shall be made available to the CO and/or COR upon request.
11. Records Management and Retention
The Contractor (and/or any subcontractor) shall maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS/FDA policies and shall not dispose of any records unless authorized by HHS/FDA.
http://sharepoint.fda.gov/orgs/DelMgmtSupport/IntakeProc/EPLCv2/SitePages/v2/EPLCHome.aspx http://sharepoint.fda.gov/orgs/DelMgmtSupport/IntakeProc/EPLCv2/SitePages/v2/EPLCHome.aspx https://www.hhs.gov/about/agencies/asa/ocio/index.html http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/default.htm http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/default.htm
In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS/FDA policies.
A. Privacy Act
It has been determined that this contract is subject to the Privacy Act of 1974, because this contract provides for the design, development, or operation of a system of records about individuals.
The System of Records Notice (SORN) that is applicable to this contract is: 09-10-0010 (Bioresearch Monitoring Information System, HHS/FDA).
The design, development, or operation work the Contractor is to perform is: The contracted support services personnel will access data subject to the Privacy Act of 1974.
The disposition to be made of the Privacy Act records upon completion of contract performance is: The records are maintained in accordance with FDA's Records Control Schedule, applicable General Records Schedule (accessions), and disposition schedule approved by the National Archives and Records Administration (cases).
| 1. Background |
| 2. Objectives |
| 3. Scope of Work |
| FDA Security Systems Operations and Maintenance |
| All service calls, once started, shall be worked until equipment is back in serviceable condition. Status of the service performed shall be logged into the appropriate web-portal reporting database based on the service performed before leaving the sit... |
| 4. FDA Technology |
| 6. Warranty |
| 7. Testing |
| 8. Documentation |
| 9. Deliverables |
| 10. Place of Performance |
| The place of performance for this task order for the Project Manager, System Administrator and Technicians is the FDA’s White Oak Campus, located in Silver Spring, MD. A list of all FDA Physical Security Sites to be maintained r is listed in Item #14... |
| 11. Period of Performance |
| The period of performance for this task order consists of 12 months, anticipated to be January 3, 2022 through January 2, 2023. |
| 12. Task Order Type |
| The task order type is anticipated to be Firm-Fixed-Price. |
| 13. Security and Privacy |
| A. Baseline Security Requirements |
| Security Categorization Level: |
| Level of Assurance: [ X ] N/A [ ] Level 1 [ ] Level 2 [ ] Level 3 [ ] Level 4 |
| [ ] Tier 4: Sensitive - High Risk |
| PII28 Overall Level: [ ] No PII [ X ] Yes PII |
| 5. Training |
| 6. Rules of Behavior |
| 7. Incident Response |
| 8. Position Sensitivity Designations |
| 9. Homeland Security Presidential Directive (HSPD)-12 |
| 10. Contract Initiation and Expiration |
| 11. Records Management and Retention |
| A. Privacy Act |
File details come from the government source that posted it. Updated .