Attachment C - Clauses.docx
DOCX document 89 KB Posted
- Attached to
- Compression Table Procurement Federal contract opportunity
- Solicitation number
- 693JK322Q0011
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment A - RFQ Details.docx | DOCX document | |
| Attachment B - SOW.docx | DOCX document | |
| SF - 18 693JK322Q0011.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
| U.S. Department of Transportation (US DOT) | RFQ # 693JK322Q0011 | |
| Pipeline & Hazardous Materials Safety Administration (PHMSA) | Attachment 3: Clauses |
| U.S. Department of Transportation (US DOT) | RFQ # 693JK319Q0007 | |
| Pipeline & Hazardous Materials Safety Administration (PHMSA) | Attachment 3: Clauses |
Attachment 3: FAR, TAR, and PHMSA Clauses and Special Requirements “Compression Table Procurement”
RFQ # 693JK322Q0011
Any resultant order from this RFQ will incorporate the terms and conditions stated in the SOW and the clauses and special requirements specified in this attachment are applicable to the order.
A. FEDERAL ACQUISITION REGULATIONS (FAR)
A.1 FAR Clauses Incorporated by Reference FAR 52.203-17 Contractor Employee Whistleblower Rights and Requirement To Inform Employees of Whistleblower Rights (JUN 2020) FAR 52.203-19 Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) FAR 52.204-4 Printed or Copies Double-Sided on Postconsumer Fiber Content Paper (MAY 2011) FAR 52.204-7 System for Award Management (OCT 2018) FAR 52.204-10 Reporting Executive Compensation and First-Tier Subcontract Awards (JUN 2020) FAR 52.204-13 System for Award Management Maintenance (OCT 2018) FAR 52.204-16 Commercial and Government Entity Code Reporting (AUG 2020) FAR 52.204-18 Commercial and Government Entity Code Maintenance (AUG 2020) FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems (NOV 2021) FAR 52.204.23 Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) FAR 52.209-6 Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment (NOV 2021) FAR 52.209-9 Updates of Publicly Available Information Regarding Responsibility Matters (OCT 2019) FAR 52.209-10 Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015) FAR 52.212-3 Offeror Representations and Certificatons – Commercial Items (NOV 2021) FAR 52.212-4 Contract Terms and Conditions—Commercial Items (NOV2021) FAR 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders -Commercial Items (JAN 2022) FAR 52.213-4 Terms and Conditions Simplified Acquisitions (Other Than Commercial Items) (JAN 2022) FAR 52.217-8 Option to Extend Services (NOV 1999) FAR 52.217-9 Option to Exend the Term of the Contract (MAR 2000) FAR 52.219-6 Notice of Total Small Business Set-Aside (NOV 2020) FAR 52.219-28 Post-Award Small Business Program Rerepresentation (SEP 2021) FAR 52.222-3 Convict Labor (Jun 2003) FAR 52.223-5 Pollution to Prevention and Right-to-Know Information (MAY 2011) FAR 52.223-6 Drug-Free Workplace (MAY 2001) FAR 52.223-10 Waste Reduction Program (MAY 2011) FAR 52.223-17 Affirmative Procurement of EPA-Designated Items in Service and Construction Contracts (AUG 2018) FAR 52.222-50 Combating Trafficking in Persons (NOV 2021) FAR 52.222-54 Employment Eligibility Verification (NOV 2021) FAR 52.223-18 Encouraging Contractor Policies to Ban Text Messaging While Driving (AUG 2011) FAR 52.237-2 Protection of Government Buildings, Equipment, and Vegetation (APR 1984) FAR 52.232-40 Providing Accelerated Payments to Small Business Subcontractors (DEC 2013) FAR 52.223-18 Encouraging Contractor Policies to Ban Text Messaging When Driving (Aug 2011) FAR 52.232-33 Payment by Electronic Funds Transfer – System for Award Management (Oct 2018) FAR 52.232-40 Providing Accelerated Payments to Small Business Subcontractors (Dec 2013) FAR 52.233-3 Protest after Award (Aug 1996)
A.2 FAR Clause 52.203-98 Prohibition on Contracting with Entities that Require Certain Internal Confidentiality Agreements – Representation (FEB 2015)
(a) In accordance with section 743 of Division E, Title VII, of the Consolidated and Further Continuing Resolution Appropriations Act, 2015 (Pub. L. 113-235), Governmnet agencies are not permitted to use funds appropriated (or otherwise made available) under that or any other Act for contracts with an entity that requires employees or subcontractors of such entity seeking to report fraud, waste, or abuse to sign internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting such waste, fraud, or abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.
(b) The prohibition in paragraph (a) of this provision does not contravene requirements applicable to Standard Form 312, Form 4414, or any other form issued by a Federal department or agency governing the nondisclosure of classified information.
(c) Representation. By submission of its offer, the Offeror represents that it does not require employees or subcontractors of such entity seeking to report fraud, waste, or abuse to sign internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting such waste, fraud, or abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.
A.3 FAR Clause 52.203-99 Prohibition on Contracting with Entities that Require Certain Internal Confidentiality Agreements (MAR 2015)
(a) The Contractor shall not require employees or subcontractors seeking to report fraud, waste, or abuse to sign or comply with internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting such waste, fraud, or abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.
(b) The contractor shall notify employees that the prohibitions and restrictions of any internal confidentiality agreements covered by this clause are no longer in effect.
(c) The prohibition in paragraph (a) of this clause does not contravene requirements applicable to Standard Form 312, Form 4414, or any other form issued by a Federal department or agency governing the nondisclosure of classified information.
(d)
(1) In accordance with 743 of Division E, Title VII, of the Consolidated and Further Continuing Resolution Appropriations Act, 2015 (Pub. L. 113-235), use of funds appropriated (or otherwise made available) under that or any other Act may be prohibited, if the Governent determines that the Contractor is not in compliance with the provisions of this clause.
(2) The Governement may seek any available remedies in the event the contractor fails to comply with the provisions of this clause.
A.4 FAR Clause 52.209-5 Certification Regarding Responsibility Matters (OCT 2015) (a)
(1) The Offeror certifies, to the best of its knowledge and belief, that --
(i) The Offeror and/or any of its Principals --
(A) Are [_] are not [_] presently debarred, suspended, proposed for debarment, or declared ineligible for the award of contracts by any Federal agency;
(B) Have [_] have not [_], within a three-year period preceding this offer, been convicted of or had a civil judgment rendered against them for: commission of fraud or a criminal offense in connection with obtaining, attempting to obtain, or performing a public (Federal, State, or local) contract or subcontract; violation of Federal or State antitrust statutes relating to the submission of offers; or commission of embezzlement, theft, forgery, bribery, falsification or destruction of records, making false statements, tax evasion, violating Federal criminal tax laws, or receiving stolen property (if offeror checks “have”, the offeror shall also see 52.209-7, if included in this solicitation); and
(C) Are [_] are not [_] presently indicted for, or otherwise criminally or civilly charged by a governmental entity with, commission of any of the offenses enumerated in paragraph (a)(1)(i)(B) of this provision; and
(D) Have [_], have not [_], within a three-year period preceding this offer, been notified of any delinquent Federal taxes in an amount that exceeds $3,500 for which the liability remains unsatisfied.
(1) Federal taxes are considered delinquent if both of the following criteria apply:
(i) The tax liability is finally determined. The liability is finally determined if it has been assessed. A liability is not finally determined if there is a pending administrative or judicial challenge. In the case of a judicial challenge to the liability, the liability is not finally determined until all judicial appeal rights have been exhausted.
(ii) The taxpayer is delinquent in making payment. A taxpayer is delinquent if the taxpayer has failed to pay the tax liability when full payment was due and required. A taxpayer is not delinquent in cases where enforced collection action is precluded.
(2) Examples.
(i) The taxpayer has received a statutory notice of deficiency, under I.R.C. §6212, which entitles the taxpayer to seek Tax Court review of a proposed tax deficiency. This is not a delinquent tax because it is not a final tax liability. Should the taxpayer seek Tax Court review, this will not be a final tax liability until the taxpayer has exercised all judicial appeal rights.
(ii) The IRS has filed a notice of Federal tax lien with respect to an assessed tax liability, and the taxpayer has been issued a notice under I.R.C. §6320 entitling the taxpayer to request a hearing with the IRS Office of Appeals contesting the lien filing, and to further appeal to the Tax Court if the IRS determines to sustain the lien filing. In the course of the hearing, the taxpayer is entitled to contest the underlying tax liability because the taxpayer has had no prior opportunity to contest the liability. This is not a delinquent tax because it is not a final tax liability. Should the taxpayer seek tax court review, this will not be a final tax liability until the taxpayer has exercised all judicial appeal rights.
(iii) The taxpayer has entered into an installment agreement pursuant to I.R.C. §6159. The taxpayer is making timely payments and is in full compliance with the agreement terms. The taxpayer is not delinquent because the taxpayer is not currently required to make full payment.
(iv) The taxpayer has filed for bankruptcy protection. The taxpayer is not delinquent because enforced collection action is stayed under 11 U.S.C. 362 (the Bankruptcy Code).
(ii) The Offeror has [[_] has not [_], within a three-year period preceding this offer, had one or more contracts terminated for default by any Federal agency.
(2) “Principal,” for the purposes of this certification, means an officer; director; owner; partner; or a person having primary management or supervisory responsibilities within a business entity (e.g., general manager; plant manager; head of a division or business segment; and similar positions).
This Certification Concerns a Matter Within the Jurisdiction of an Agency of the United States and the Making of a False, Fictitious, or Fraudulent Certification May Render the Maker Subject to Prosecution Under Section 1001, Title 18, United States Code.
(b) The Offeror shall provide immediate written notice to the Contracting Officer if, at any time prior to contract award, the Offeror learns that its certification was erroneous when submitted or has become erroneous by reason of changed circumstances.
(c) A certification that any of the items in paragraph (a) of this provision exists will not necessarily result in withholding of an award under this solicitation. However, the certification will be considered in connection with a determination of the Offeror’s responsibility. Failure of the Offeror to furnish a certification or provide such additional information as requested by the Contracting Officer may render the Offeror nonresponsible.
(d) Nothing contained in the foregoing shall be construed to require establishment of a system of records in order to render, in good faith, the certification required by paragraph (a) of this provision. The knowledge and information of an Offeror is not required to exceed that which is normally possessed by a prudent person in the ordinary course of business dealings.
(e) The certification in paragraph (a) of this provision is a material representation of fact upon which reliance was placed when making award. If it is later determined that the Offeror knowingly rendered an erroneous certification, in addition to other remedies available to the Government, the Contracting Officer may terminate the contract resulting from this solicitation for default.
A.5 FAR Clause 52.209-7 Information Regarding Responsibility Matters (JUL 2013)
(a) Definitions. As used in this provision— “Administrative proceeding” means a non-judicial process that is adjudicatory in nature in order to make a determination of fault or liability (e.g., Securities and Exchange Commission Administrative Proceedings, Civilian Board of Contract Appeals Proceedings, and Armed Services Board of Contract Appeals Proceedings). This includes administrative proceeding at the Federal and State level but only in connection with performance of a Federal contract or grant. It does not include agency actions such as contract audits, site visits, corrective plans, or inspection of deliverables.
“Federal contracts and grants with total value greater than $10,000,000” means—
(1) The total value of all current, active contracts and grants, including all priced options; and
(2) The total value of all current, active orders including all priced options under indefinite-delivery, indefinite-quantity, 8(a), or requirements contracts (including task and delivery and multiple-award Schedules).
“Principal” means an officer, director, owner, partner, or a person having primary management or supervisory responsibilities within a business entity (e.g., general manager; plant manager; head of a division or business segment; and similar positions).
(b) The offeror [_] has [_] does not have current active Federal contracts and grants with total value greater than $10,000,000.
(c) If the offeror checked “has” in paragraph (b) of this provision, the offeror represents, by submission of this offer, that the information it has entered in the Federal Awardee Performance and Integrity Information System (FAPIIS) is current, accurate, and complete as of the date of submission of this offer with regard to the following information:
(1) Whether the offeror, and/or any of its principals, has or has not, within the last five years, in connection with the award to or performance by the offeror of a Federal contract or grant, been the subject of a proceeding, at the Federal or State level that resulted in any of the following dispositions:
(i) In a criminal proceeding, a conviction.
(ii) In a civil proceeding, a finding of fault and liability that results in the payment of a monetary fine, penalty, reimbursement, restitution, or damages of $5,000 or more.
(iii) In an administrative proceeding, a finding of fault and liability that results in—
(A) The payment of a monetary fine or penalty of $5,000 or more; or
(B) The payment of a reimbursement, restitution, or damages in excess of $100,000.
(iv) In a criminal, civil, or administrative proceeding, a disposition of the matter by consent or compromise with an acknowledgment of fault by the Contractor if the proceeding could have led to any of the outcomes specified in paragraphs (c)(1)(i), (c)(1)(ii), or (c)(1)(iii) of this provision.
(2) If the offeror has been involved in the last five years in any of the occurrences listed in (c)(1) of this provision, whether the offeror has provided the requested information with regard to each occurrence.
(d) The offeror shall post the information in paragraphs (c)(1)(i) through (c)(1)(iv) of this provision in FAPIIS as required through maintaining an active registration in the System for Award Management database via https://www.acquisition.gov (see 52.204-7).
B. TRANSPORTATION ACQUISITION REGULATIONS (TAR) CLAUSES
B.1 TAR 1252.223-71 Accident and Fire Reporting (April 2005)
(a) The Contractor shall report to the Contracting Officer any accident or fire occurring at the site of the work which causes:
(1) A fatality or as much as one lost workday on the part of any employee of the Contractor or subcontractor at any tier;
(2) Damage of $1,000 or more to Government-owned or leased property, either real or personal;
(3) Damage of $1,000 or more to Contractor or subcontractor owned or leased motor vehicles or mobile equipment; or
(4) Damage for which a contract time extension may be requested.
(b) Accident and fire reports required by paragraph (a) above shall be accomplished by the following means:
(1) Accidents or fires resulting in a death, hospitalization of five or more persons, or destruction of Government-owned or leased property (either real or personal), the total value of which is estimated at $100,000 or more, shall be reported immediately by telephone to the Contracting Officer or his/her authorized representative and shall be confirmed by telegram or facsimile transmission within 24 hours to the Contracting Officer. Such telegram or facsimile transmission shall state all known facts as to extent of injury and damage and as to cause of the accident or fire.
(2) Other accident and fire reports required by paragraph (a) above may be reported by the Contractor using a state, private insurance carrier, or Contractor accident report form which provides for the statement of:
(i) The extent of injury; and
(ii) The damage and cause of the accident or fire.
Such report shall be mailed or otherwise delivered to the Contracting Officer within 48 hours of the occurrence of the accident or fire.
(c) The Contractor shall assure compliance by subcontractors at all tiers with the requirements of this clause.
B. 2 TAR 1252.223‐73 Seat Belt Use Policies and Programs (APR 2005) In accordance with Executive Order 13043, Increasing Seat Belt Use in the United States, dated April 16, 1997, the contractor is encouraged to adopt and enforce on‐the‐job seat belt use policies and programs for its employees when operating company‐owned, rented, or personally‐owned vehicles. The National Highway Traffic Safety Administration (NHTSA) is responsible for providing leadership and guidance in support of this Presidential initiative. For information on how to implement such a program or for statistics on the potential benefits and cost‐savings to your company or organization, please visit the Buckle Up America section of NHTSA’s website at www.nhtsa.dot.gov. Additional resources are available from the Network of Employers for Traffic Safety (NETS), a public‐private partnership headquartered in the Washington, D.C. metropolitan area, and dedicated to improving the traffic safety practices of employers and employees. NETS is prepared to help with technical assistance, a simple, user friendly program kit, and an award for achieving the President’s goal of 90 percent seat belt use. NETS can be contacted at 1‐888‐221‐0045 or visit its website at www.trafficsafety.org.
B.3 TAR 1252.237‐70 Qualifications of contractor employees (APR 2005)
a. Definitions. As used in this clause‐ Sensitive Information is any information that, if subject to unauthorized access, modification, loss, or misuse, or is proprietary data, could adversely affect the national interest, the conduct of Federal programs, or the privacy of individuals specified in The Privacy Act, 5 U.S.C. 552a, but has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.
b. Work under this contract may involve access to sensitive information which shall not be disclosed, by the contractor unless authorized in writing by the contracting officer. To protect sensitive information, the contractor shall provide training to any contractor employees authorized to access sensitive information, and upon request of the Government, provide information as to an individuals suitability to have authorization.
c. The Contracting Officer may require dismissal from work those employees deemed incompetent, careless, insubordinate, unsuitable, or otherwise objectionable, or whose continued employment is deemed contrary to the public interest or inconsistent with the best interest of national security.
d. Contractor employees working on this contract must complete such forms, as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability. Completed forms shall be submitted as directed by the Contracting Officer. Upon the Contracting Officers request, the Contractor's employees shall be fingerprinted, or subject to other investigations as required.
e. The Contractor shall ensure that contractor employees are:
(1) Citizens of the United States of America or an alien who has been lawfully admitted for permanent residence or employment (indicated by immigration status) as evidenced Bureau of Citizenship and Immigration Services documentation; and
(2) Have background investigations according to DOT Order 1630.2B, Personnel Security Management. f. The Contractor shall immediately notify the contracting officer when an employee no longer requires access to DOT computer systems due to transfer, completion of a project retirement or termination of employment.
g. The Contractor shall include the substance of this clause in all subcontracts at any tier where the subcontractor may have access to Government facilities, sensitive information, or resources.
B.4 TAR 1252.239-70 Cyber-security Requirements for Unclassified and Sensitive Information Technology (IT) Resources (JUN 2012)
(a) Required Policies and Regulations - Compliance with applicable Federal statutes, policies, standards, and guidelines is the responsibility of the Federal government and may not be abdicated to the Contractor. To achieve such compliance, the government requires the Contractor to conform to all U. S. Department of Transportation (DOT) and applicable Federal IT Security statutes, policies, standards, and reporting requirements, including, but not limited to:
(1) Federal Information Security Management Act (FISMA) of 2002, 44 U.S.C § 3541 et seq.
(2) Clinger-Cohen Act of 1996 also known as the “Information Technology Management Reform Act of 1996,” 40 U.S.C § 1401 et seq.
(3) Privacy Act of 1974, 5 U.S.C. § 552a, as amended.
(4) Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information Resources,” and Appendix III, “Security of Federal Automated Information Systems,” as amended.
(5) OMB Memorandum M-04-04, “E-Authentication Guidance for Federal Agencies.”
(6) Homeland Security Presidential Directive (HSPD-12), “Policy for a Common Identification Standard for Federal Employees and Contractors,” August 27, 2004.
(7) DOT Order 1351.37, “Departmental Cybersecurity Policy.”
(8) DOT Departmental Cybersecurity Compendium “Supplement to DOT Order 1351.37: Departmental Cybersecurity Policy.”
(9) DOT Order 1681.1, “Department of Transportation (DOT) Implementation Policy for Identity, Credential, and Access Management (lCAM) and Homeland Security Presidential Directive - 12 (HSPD-12).”
(10) National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) Publication (PUB) 140, “Security Requirements for Cryptographic Modules.”
(11) NIST FIPS PUB 199, “Standards for Security Categorization of Federal Information and Information Systems.”
(12) NIST FIPS PUB 200, “Minimum Security Requirements for Federal Information and Information Systems.”
(13) NIST FIPS PUB 201, “Personal Identity Verification (PIV) of Federal Employees and Contractors” and all related NIST Special Publications.
(14) NIST Special Publication 800-18, “Guide for Developing Security Plans for Federal Information Systems.”
(15) NIST Special Publication 800-30, “Risk Management Guide for Information Technology Security Risk Assessment Procedures for Information Technology Systems.”
(16) NIST Special Publication 800-34, “Contingency Planning Guide for Information Technology Systems.”
(17) NIST Special Publication 800-37, “Guide for the Security Certification and Accreditation of Federal Information Systems.”
(18) NIST Special Publication 800-47, “Security Guide for Interconnecting Information Technology Systems.”
(19) NIST Special Publication 800-53, “Recommended Security Controls for Federal Information Systems.”
(20) NIST Special Publication 800-53A, “Guide for Assessing the Security Controls in Federal Information Systems.”
(21) NIST Special Publication 800-63, “Electronic Authentication Guidance.”
(b) Applicability - The Contractor shall be responsible for Information Technology security for all systems connected to a DOT network operated by the Contractor for DOT, or for Contractor Systems that contains DOT information regardless of location. The term Information Technology, as used in this clause, means any equipment or interconnected system or subsystem of equipment used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information. For purposes of this definition, equipment is used by DOT whether DOT uses the equipment directly or it is used by a contractor under a contract with the agency which (1) requires the use of such equipment or (2) requires the use, to a significant extent, of such equipment in the performance of a service or the furnishing of a product. Information Technology includes computers, ancillary equipment, software, firmware and similar procedures, services (including support services), and related resources. It does not include any equipment acquired by a Federal contractor incidental to a Federal contract.
(c) Security Categorization - In accordance with FIPS 199, “Standards for Security Categorization of Federal Information and Information Systems,” DOT has determined that the security category of the information or information system under this contract is Confidentiality MODERATE, Integrity MODERATE, and Availability MODERATE with an overall security impact level of MODERATE.
(d) Baseline Security Controls and System Security Plan – The Contractor shall develop and maintain the System Security Plan and associated Baseline Security Controls for the system as defined in the DOT Departmental Cybersecurity Compendium. To aid DOT senior officials and Contractors in determining applicable security controls, the Departmental Cybersecurity Compendium assigns security requirements (also referred to as controls and policy) to the DOT Component and Information System levels. The Contractor is responsible for all “System-level” security requirements in accordance with the FIPS PUB 199 Categorization approved for the system unless otherwise indicated in the Statement of Work or Performance Work Statement. The Contractor shall follow DOT policy and guidance specified in DOT Order 1357.31 and the Departmental Cybersecurity Compendium to appropriately tailor the set of baseline security controls and define the implementation owner of each control. The Contractor shall obtain the written approval of the System Security Plan and corresponding Baseline Security Controls from the DOT Authorizing Official or his/her designee.
(e) Information System Contingency Plan (ISCP) and Testing -- The Contractor shall develop and maintain the ISCP for the system as defined in the DOT Departmental Cybersecurity Compendium. The Contractor shall regularly test the ISCP and document test results in accordance with the DOT Departmental Cybersecurity Compendium.
(f) Security Assessment and Authorization – All applicable Contractor systems/applications must support risk management processes, and produce and maintain the documents and artifacts as specified in the DOT Departmental Cybersecurity Policy and the DOT Departmental Cybersecurity Compendium. The Contractor shall prepare and submit the required documents as specified in the Deliverables section of the contract. For systems categorized as High or Moderate security impact per FIPS PUB 199, the Contractor must obtain a qualified independent Security Control Assessor and obtain the approval of this assessor from the DOT Authorizing Official. The Contractor may not begin the processing of DOT information, interconnecting with DOT networks or systems, or any other production operation of the system until the DOT Authorizing Official grants security authorization in accordance with DOT policy and procedures specified in the Departmental Cybersecurity Policy and Compendium.
(g) Continuous Monitoring - Upon attainment of security authorization from the DOT Authorizing Official, the Contractor must implement and perform continuous monitoring of the security state and controls of the information system as specified in the Departmental Cybersecurity Policy and Compendium producing the specified reports and other artifacts to demonstrate ongoing risk management.
(h) Contract Compliance - Upon approval by DOT, the Systems Security Plan, FIPS 199 Categorization, Contingency Plan, Security Assessment Report, Security Authorization, Plan of Action and Milestones (including any required updates), and other documents that are required based on the type of information system in accordance with the Departmental Cybersecurity Policy and Compendium, shall be incorporated into the contract file as compliance documents.
(i) Availability of Data, Documents and Access –
(1) The Contractor shall ensure that all DOT data remains within the United States except as approved in writing by the DOT Authorizing Official or his/her designee.
(2) The Contractor shall provide DOT (or DOT- designated third party contractors) access to the Contractor’s and subcontractors’ facilities, installations, operations, documents, records, databases, and personnel used in performance of the contract. The Contractor shall have the means to support DOT’s request for access 24 hours per day, 7 days per week which may be necessitated due to a security incident, breach or other security matter.
(3) The Contractor shall provide access to the extent required to carry out IT security inspections, investigations, and/or audits to safeguard against threats and hazards to the integrity, availability, and confidentiality of DOT information or to the functions of information technology operated on behalf of DOT, and to preserve evidence of criminal activity.
(4) Upon termination of the contract or earlier, upon request, the Contactor shall provide to the DOT Authorizing Official or his/her designee all DOT data, source code, or database files, in a format specified by the DOT Authorizing Official or his/her designee.
(j) Monthly Deliverables: The Contractor shall provide, on a monthly basis, the following information in NIST Security Content Automation Protocols (SCAP) XML data formats:
(1) Device inventory (type of device and software);
(2) Medium and High Vulnerabilities for each device;
(3) Deviations from approved Configuration Baselines for each device; and
(4) Additional information as required by OMB or the Department of Homeland Security (DHS) as indicated in the Departmental Cybersecurity Compendium.
(k) Quarterly Deliverables: The Contractor shall provide, on a quarterly basis, the following information in a format specified by the COTR:
(1) Plan of Action and Milestones (POA&M) – The Contractor shall prepare a draft of the POA&M associated with known weaknesses at the completion of the initial security assessment. The Contractor shall collaborate with the DOT System Owner, Information System Security Officer/Manager (ISSO/ISSM) and DOT Authorizing Official to obtain necessary information to complete the POA&M to meet DOT guidelines specified in the DOT Departmental Compendium. The POA&M approved by the DOT Authorizing Official shall be included in the initial authorization package. Upon entering Continuous Monitoring phase, the Contractor shall update the POA&M at least quarterly to ensure it contains all known system security weaknesses discovered through security assessment, continuous monitoring, internal and external audits, and related activities that examine security and IT controls of the contractor information system. The POA&M update shall also include progress on corrective actions for weaknesses previously identified.
(l) Annual Deliverables: The Contractor shall provide, on an annual basis, the following documents to the contracting officer and COTR:
1. Updated security risk management documentation:
a. System Security Plan - The Contractor shall review and update the System Security Plan at least annually to ensure the plan is current, accurately describes implemented system controls and reflects changes to the Contractor system and its environment of operation.
b. Security Assessment Report - The Contractor shall provide an update to the Security Assessment Report, based on the results of continuous monitoring performed. For systems categorized as High and Moderate security impact level, the independent Security Control Assessor must issue this report.
c. Information System Contingency Plan (ISCP) - The Contractor shall provide an annual update to the ISCP completed in accordance the Departmental Cybersecurity Compendium.
d. FIPS PUB 199 Categorization – The Contractor shall provide an update to the FIPS PUB 199 Categorization which shall identify any and all information type changes and resulting security impact levels for Confidentiality, Integrity and Availability in accordance with the DOT Departmental Cybersecurity Compendium. The DOT Authorizing Official must approve all changes in FIPS PUB categorization.
(2) Information Security Awareness and Training Records – The Contractor shall ensure its personnel complete both general awareness training and role-based training for personnel that perform roles deemed by DOT to require annual specialized security training (refer to Compendium Appendix D). The Contractor shall comply with awareness and training policy specified in the DOT Departmental Cybersecurity Compendium and evidence of completion of training shall be provided to the COTR upon request by the Government.
(3) Information System Interconnection Agreements – The Contractor shall identify all interconnections between its system and other parties. (Refer to the DOT Departmental Cybersecurity Compendium for definitions and requirements for documentation, security controls and authorization of interconnections).
(4) All Other Applicable Documents as Specified in the Departmental Cybersecurity Compendium.
(m) HSPD-12 / Identity, Credential and Access Management Requirements – The Contractor shall ensure, at a minimum, that all systems that it develops for or operates on behalf of the Government support the use of Personal Identity Verification (PIV) smart cards, and PIV interoperable (PIV-I) smart cards as appropriate, for authentication and access to those systems, for the digital signature of documents and workflows, and for the encryption of documents and information, in accordance with NIST PUB 201 and related special publications. When explicitly required, or by September 30, 2012, whichever occurs earlier, the Contractor shall ensure that all systems it develops for or operates on behalf of the Government meet applicable DOT policy requirements for identity, credential, and access management (ICAM) and require the use of a PIV card or PIV-I for authentication, access, digital signature, and encryption. The Contractor shall ensure that services and products it purchases involving facility or system access control are on the current FIPS 201 Approved Products List, found at http://www.idmanagement.gov/.
(n) US Government Configuration Baseline - The Contractor shall certify applications are fully functional and operate correctly as intended on systems using the US Government Configuration Baseline (USGCB). This includes Internet Explorer configured to operate in Windows. The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. The information technology should also use the Windows Installer Service for installation to the default “program files” directory and should be able to silently install and uninstall. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges. The Contractor shall use Security Content Automation Protocol (SCAP) validated tools with USGCB Scanner capability to certify their products operate correctly with USGCB configurations and do not alter USGCB settings, and shall provide documentation of such validation to the Government as a prerequisite for Government acceptance of the Contractor’s products. The Contractor shall follow guidance in the DOT Departmental Cybersecurity Compendium for tracking and reporting deviations from these baselines.
(o) System Access Notice - The Contractor shall implement DOT- approved warning banners on all DOT systems (both public and private) operated by the Contractor prior to allowing authenticated access to the system(s). The DOT Departmental Cybersecurity Compendium specifies requirements for this warning banner and permitted deviations depending on the end user device.
(p) Privacy Act Notifications - As prescribed in the Federal Acquisition Regulation (FAR) clause 24.104, if the system involves the design, development, or operation of a system of records on individuals, the Contractor shall implement requirements in FAR clause 52.224-1, “Privacy Act Notification” and FAR clause 52.224-2, “Privacy Act.” The Contractor shall ensure that the following banner is displayed on all DOT systems that contain Privacy Act information operated by the Contractor prior to allowing anyone access to the system:
“This system contains information protected under the provisions of the Privacy Act of 1974 (Public Law 93-579). Any privacy information displayed on the screen or printed shall be protected from unauthorized disclosure. Individuals who violate privacy safeguards may be subject to disciplinary actions, a fine of up to $5,000, or both.”
(q) Non-Disclosure Agreements - The Contractor shall cooperate in good faith in defining non-disclosure agreements that other third parties must sign when acting as the Federal government’s agent.
(r) Nondisclosure of Security Safeguards - In accordance with the Federal Acquisitions Regulations (FAR) clause 52.239-1, the Contractor shall be responsible for the following privacy and security safeguards: the Contractor shall not publish or disclose in any manner, without the contracting officer’s written consent, the details of any safeguards either designed or developed by the Contractor under the contract. If new or unanticipated threats or hazards are discovered by either the Government or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.
(s) Subcontracts - The Contractor shall incorporate the substance of this clause in all subcontracts that meet the conditions described in paragraph (b).
B.5 TAR 1252.239-71 Information Technology Security Plan and Accreditation (APR 2005) All offers submitted in response to this solicitation must address the approach for completing the security plan and accreditation requirements in TAR clause 1252.239-70.
B.6 TAR 1252.242‐72 Dissemination of contract information (OCT 1994) The Contractor shall not publish, permit to be published, or distribute for public consumption, any information, oral or written, concerning the results or conclusions made pursuant to the performance of this contract, without the prior written consent of the Contracting Officer. Two copies of any material proposed to be published or distributed shall be submitted to the Contracting Officer.
B.7 TAR 1252.242-73 Contracting Officer’s Technical Representative (OCT 1994)
(a) The Contracting Officer may designate Government personnel to act as the Contracting Officer's Technical Representative (COTR) to perform functions under the contract such as review and/or inspection and acceptance of supplies, services, including construction, and other functions of a technical nature. The Contracting Officer will provide a written notice of such designation to the Contractor within five working days after contract award or for construction, not less than five working days prior to giving the contractor the notice to proceed. The designation letter will set forth the authorities and limitations of the COTR under the contract.
(b) The Contracting Officer cannot authorize the COTR or any other representative to sign documents (i.e., contracts, contract modifications, etc.) that require the signature of the Contracting Officer.
C. DOT/PHMSA SPECIFIC CLAUSES
C.1 Contractor Policy to Ban Text Messaging While Driving
(a) Definitions. The following definitions are intended to be consistent with the definitions in DOT Order 3902.10 and the E.O. For clarification purposes, they may expand upon the definitions in the E.O.
"Driving"-
(1) Means operating a motor vehicle on a roadway, including while temporarily stationary because of traffic, a traffic light, stop sign, or otherwise.
(2) It does not include being in your vehicle (with or without the motor running) in a location off the roadway where it is safe and legal to remain stationary.
"Text messaging" means reading from or entering data into any handheld or other electronic device, including for the purpose of short message service texting, e-mailing, instant messaging, obtaining navigational information, or engaging in any other form of electronic data retrieval or electronic data communication. (See definition in DOT Order 3902.10)
(b) In accordance with Executive Order 13513, Federal Leadership on Reducing Text Messaging While Driving, October 1, 2009, and DOT Order 3902.10, Text Messaging While Driving, December 30, 2009, contractors and subcontractors are encouraged to:
(1) Adopt and enforce workplace safety policies to decrease crashes caused by distracted drivers including policies to ban text messaging while driving--
(i) Company-owned or -rented vehicles or Government-owned, leased or rented vehicles; or
(ii) Privately-owned vehicles when on official Government business or when performing any work for or on behalf of the Government.
(2) Conduct workplace safety initiatives in a manner commensurate with the size of the business, such as-
(i) Establishment of new rules and programs or re-evaluation of existing programs to prohibit text messaging while driving; and
(ii) Education, awareness, and other outreach to employees about the safety risks associated with texting while driving.
(c) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (c), in all subcontracts that exceed the micro-purchase threshold, other than subcontracts for the acquisition of commercially available off-the-shelf items.
C.2 DOT Short‐Term Lending Program (DOT STLP) ATTENTION: Small and Disadvantaged (SDB), Women‐Owned, and Disadvantaged Business Enterprises (DBEs)! The Department of Transportation’s (DOT), Short‐Term Lending Program (STLP) offers working capital financing in the form of lines of credit to finance accounts receivable for transportation related contracts.
The Maximum line of credit is $750,000. The STLP loan has a variable rate, which is connected to the prime rate. The current rate may be found on the OSDBU website http://osdbuweb.dot.gov or call 1‐ (800) 532‐1169.
C.3 Contractor Issued Announcements
1. The recipient of this award must provide, in advance, to the PHMSA Contracting Officer, for review and concurrence, any proposed:
‐ post‐award announcement/press release when the content refers to PHMSA.
‐ article, for publication or presentation, in which PHMSA is mentioned.
2. The recipient of this award must include the following statement in articles for publication or presentation resulting from this award:
“This work was funded in part, under the Department of Transportation, Pipeline and Hazardous Materials Safety Administration. The views and conclusions contained in this document are those of the authors and should not be interpreted as representing the official policies, either expressed or implied, of the Pipeline and Hazardous Materials Safety Administration, the Department of Transportation, or the U.S. Government.”
C.4 Safeguarding Classified Information (PHMSA January 2011) Pipeline and Hazardous Materials Safety Administration (PHMSA) contractor employees are obligated to protect classified information pursuant to all applicable laws, and to use Government information technology systems in accordance with PHMSA and Department of Transportation (DOT) procedures so that the integrity of such systems is not compromised.
Unauthorized disclosure of classified documents (whether in print, on a blog, or on a web site) does not alter the documents’ classified status or automatically result in declassification of the documents. To the contrary, classified information, whether or not already posted on public websites or disclosed to the media, remains classified, and must be treated as such by contractor employees, until it is declassified by an appropriate U.S. Government authority.
PHMSA contractor employees:
1. except as authorized by the Director, Office of Security (M‐40), or other authorized DOT officials, and pursuant to PHMSA/DOT policies and procedures, shall not, while using computers or other devices (such as Blackberries or Smart Phones) that access the Web on non‐classified Government systems, access documents that are marked classified (including classified documents publicly available on WikiLeaks and other web sites), as doing so risks that classified material will be placed onto non‐ classified systems. This requirement applies to access that occurs either through PHMSA/DOT or contractor computers, or through contractors’ personally owned computers that access non‐classified Government systems. This requirement does not restrict PHMSA contractor employee access to non‐ classified, publicly available news reports (and other non‐classified material) that may, in turn, discuss classified material.
2. shall not access classified material unless:
‐ a favorable determination of the person’s eligibility for access has been made by the DOT Director of the Office of Security (M‐40) or another authorized DOT official, ‐ the person has signed an approved non‐disclosure agreement, ‐ the person has a need to know the information, and ‐ the person has received contemporaneous training on the proper safeguarding of classified information and on the criminal, civil, and administrative sanctions that may be imposed on an individual who fails to protect classified information from unauthorized disclosure.
3. shall not remove classified information from official premises or disclose that information without proper authorization.
4. who believe they may have inadvertently accessed or downloaded classified or sensitive information on computers that access the web via non‐classified Government systems, or without prior authorization, should contact their information security offices for assistance.
C.5 Use of Recording Devices at DOT (October 2009) DOT contractor employees must not engage in, attempt to influence any person to engage in, or acquiesce in the clandestine, surreptitious, or other covert use of audio, video, or other electronic recording or monitoring devices or practices, without the prior written approval of the PHMSA Chief of the Contracting Office.
DOT contractor employees have no explicit or implicit expectation of privacy while operating non‐secure Government communications equipment. By using Government communications equipment the user consents to listening‐in, monitoring, or recording of activities on said equipment by DOT employees.
Nothing in this clause is meant to apply to the conduct of video conferences approved by DOT personnel, or to restrict contractor personnel from performing activities necessary to ensure the integrity of DOT’s Information Technology (IT) networking infrastructure or computer systems.
Recordings by DOT contractor employees may not be used by outside entities without the prior written approval of the PHMSA Chief of the Contracting Office.
C.6 U.S. Department of Transportation (DOT) Non-Disclosure Agreement The purpose of this non‐disclosure agreement is to ensure that any information gathered or provided to [TBD], and its consultants/subcontractors under DO # DTPH56[TBD] is not disclosed to unauthorized sources.
This Agreement relates to the disclosure of Government proprietary/sensitive information received in the course of duties under a contract with the U.S. Department of Transportation, Pipeline and Hazardous Materials Safety Administration. As used herein, Government proprietary/sensitive information means information and/or data of a confidential nature including but not limited to sensitive technical, operating, performance, cost, know‐how, or schedule or business information. The information may be disclosed to the contractor in a number of ways, including orally and in writing.
The contractor agrees that receiving Government proprietary/sensitive information subjects them to certain responsibilities and further agrees to the following:
1. To use the information only for the purpose of performance duties, to hold in confidence and protect the information from disclosure and use by anyone without proper authority and need‐to‐ know. No other use of this information is permitted without the express written permission of the Contracting Officer.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .