Attachment C - Information Technology.pdf

PDF 187 KB Posted

Attached to
Civil Surgeon Credential Verification Federal contract opportunity
Solicitation number
70SBUR25Q00000151
Issued by
Department of Homeland Security US Citizen and Immigration Services

About this file

This document is an Information Technology Security Awareness Training attachment (HSAR Class Deviation 15-01, Revision 1) for a federal contract, specifically RFQ# 70SBUR25Q00000151. The attachment outlines mandatory security training requirements for contractors and subcontractors accessing Department of Homeland Security (DHS) systems and sensitive information. Key requirements include completing an annual Information Technology Security Awareness Training course within 30 days of contract award and annually thereafter by October 31st, and signing the DHS Rules of Behavior before accessing DHS systems. Contractors must maintain training certificates and signed Rules of Behavior documents, and submit these to the Contracting Officer's Representative (COR) within 30 days of contract award, with subsequent annual training confirmations due by October 31st each year.

View the file

Other files for this federal contract opportunity

Other files attached to Civil Surgeon Credential Verification, newest first.
File Type Posted
Amendment 0001 - Vendor Q and A.xlsx XLSX spreadsheet
Attachment A - Terms and Conditions .pdf PDF
Attachment B - Security Requirement 5 (March 2025).pdf PDF
Attachment D - Statement of Work.pdf PDF
Attachment E - Wage Determination updated.pdf PDF
Attachment F - Pricing Spreadsheet.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HSAR Class Deviation 15-01, Revision 1 Attachment 1: Information Technology Security Awareness Training (JULY 2023)

INFORMATION TECHNOLOGY SECURITY AWARENESS TRAINING (JULY 2023)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Security Training Requirements.

(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change.

The Department of Homeland Security (DHS) requires that Contractor employees take an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year. Any new Contractor employees assigned to the contract shall complete the training before accessing sensitive information under the contract. The training is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. The Contractor shall maintain copies of training certificates for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, initial training certificates for each Contractor and subcontractor employee shall be provided to the Contracting Officer’s Representative (COR) not later than thirty (30) days after contract award. Subsequent training certificates to satisfy the annual training requirement shall be submitted to the COR via e-mail notification not later than October 31st of each year. The e-mail notification shall state the required training has been completed for all Contractor and subcontractor employees.

(2) The DHS Rules of Behavior apply to every DHS employee, Contractor and subcontractor that will have access to DHS systems and sensitive information. The DHS Rules of Behavior shall be signed before accessing DHS systems and sensitive information. The DHS Rules of Behavior is a document that informs users of their responsibilities when accessing DHS systems and holds users accountable for actions taken while accessing DHS systems and using DHS Information Technology resources capable of inputting, storing, processing, outputting, and/or transmitting sensitive information. The DHS Rules of Behavior is accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors. Unless otherwise specified, the DHS Rules of Behavior shall be signed within thirty (30) days of contract award.

Any new Contractor employees assigned to the contract shall also sign the DHS Rules of Behavior before accessing DHS systems and sensitive information. The Contractor shall maintain signed copies of the DHS Rules of Behavior for all Contractor and subcontractor employees as a record of compliance. Unless otherwise specified, the Contractor shall e-mail copies of the signed DHS Rules of Behavior to the COR not later than thirty (30) days after contract award for each employee. The DHS Rules of Behavior will be reviewed annually, and the COR will provide notification when a review is required.

(End of clause)

RFQ# 70SBUR25Q00000151 - Attachment C http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors

File details come from the government source that posted it. Updated .