Attachment I - SOW_70RCSA20Q00000041.pdf

PDF 287 KB Posted

Attached to
CCTV Equipment and Installation Services - DHS/CISA/CSD Federal contract opportunity
Solicitation number
70RCSA20Q00000041
Issued by
Department of Homeland Security Office of Procurement Operations

View the file

Other files for this federal contract opportunity

Other files attached to CCTV Equipment and Installation Services - DHS/CISA/CSD, newest first.
File Type Posted
VendorQuestions_70RCSA20Q00000041_070920.pdf PDF
VendorQuestions_70RCSA20Q00000041_070120.pdf PDF
Attachment I - SOW_70RCSA20Q00000041_Updated060320.pdf PDF
Attachment III- VendorQuestions_70RCSA20Q00000041.pdf PDF
Attachment II - Clauses_70RCSA20Q00000041.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT I: Statement of Work

70RCSA20Q00000041

STATEMENT OF WORK (SOW)

CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY (CISA)

CLOSED-CIRCUIT TELEVISION (CCTV) SYSTEM UPGRADE

1.0 GENERAL

1.1 Background

The Cybersecurity Division (CSD) of the Cybersecurity and Infrastructure Security Agency (CISA) is responsible for enhancing the security, resiliency, and reliability of the nation's cyber and communications infrastructure. CSD actively engages the public and private sectors as well as international partners to prepare for, prevent, and respond to catastrophic incidents that could degrade or overwhelm strategic assets.

CSD works to prevent or minimize disruptions to our critical information infrastructure in order to protect the public, the economy, government services, and the overall security of the United States. It does this by supporting a series of continuous efforts designed to further safeguard federal government systems by reducing potential vulnerabilities, protecting against cyber intrusions, anticipating future threats, enhancing the security and reliability of the cyber ecosystem, and ensuring the interoperability and continuity of national security and emergency preparedness communications.

CSD has a requirement to replace and upgrade an existing closed circuit television (CCTV) system to improve security for leased space currently occupied by CSD at 4601 N Fairfax Drive Arlington, VA 22203.

This upgrade is an integral part in the overall mission to improve the cyber posture and resiliency of the Nation’s critical infrastructure. Therefore, CSD has a need to maintain compliance and standardization in workspace access, employee safety, and facility security.

1.1 Scope

The contractor shall furnish and install new and replacement turnkey AXIS brand (or equivalent) equipment for a closed circuit television system that is compatible with the VideoNEXT system for use in leased office space occupied by CSD at 4601 N. Fairfax Dr. in Arlington, Virginia.

1.2 OBJECTIVE

The objective of this procurement is to upgrade and replace the existing AXIS brand CCTV equipment with the same brand name (or equal) equipment that is compatible with the VideoNEXT system, which is the system currently in use across DHS that consolidates and streams the CCTV video feed.

1.3 APPLICABLE DOCUMENTS

There are no compliance or reference documents for this requirement.

The government will provide drawings of the existing site.

2.0 SPECIFIC REQUIREMENTS/TASKS

2.0 Remove and Replace Existing Closed Circuit Television (CCTV) System. The contractor shall remove and/or replace existing CCTV cameras and install a turnkey AXIS brand (or an equivalent brand) of CCTV equipment that is compatible with the current VideoNEXT CCTV operating system at 4601 N. Fairfax Dr., Arlington VA. For CCTV equipment to be compatible with VideoNEXT out of the box, cameras are required to be network-based and support Open Network Video Interface Forum (ONVIF) profiles Profile S and G.

All Cameras are required to capture 1080p resolution or greater. All cameras are required to be day and night functional. All cameras are required to be vandal resistant to IK08 or greater rating.

Cameras installed in interior building spaces shall be fixed dome type cameras.

Cameras that are installed in the exterior of the building, the loading dock, and the parking garage must be designed for outdoor use, must be auto focus, include the point, tilt, zoom (PTZ) capability, and must zoom to 18x or greater.

The contractor shall furnish all labor and materials necessary to complete the installation of the system. All equipment shall be installed to meet the Americans with Disabilities Act. All necessary power for the system will be identified by CISA’s building management, and will be connected to emergency power, if possible. Old wire will be replaced where necessary and all wire, except runs above false ceiling, shall be run in approved raceway to protect the wire from damage and tampering. All wire run above false ceiling shall be secured up and off of the suspended ceiling. If the ceiling is plenum, high temperature Teflon wire shall be used for runs in the plenum. The contractor shall install all system components in accordance with the manufacturer’s instructions and ANSI C2 requirements. The contractor shall perform all the work, provide products, system integration, engineering and design work required for the project in order to ensure fully operative systems and proper installation of all equipment.

The building areas that require coverage and the quantities/locations are as follows:

• Contractor shall install two (2) CCTV cameras on B1 elevator lobby.

• Contractor shall install two (2) CCTV cameras on B2 elevator lobby.

• Contractor shall replace one (1) existing elevator lobby CCTV camera.

• Contractor shall install one (1) CCTV camera in lobby area looking at main entry doors.

• Contractor shall install two (2) CCTV cameras to each 2nd floor stairwell.

• Contractor shall install two (2) CCTV cameras to each 3rd floor stairwell.

• Contractor shall replace six (6) existing 4th floor CCTV cameras.

• Contractor shall install two (2) CCTV cameras to each 4th floor stairwell.

• Contractor shall install two (2) CCTV cameras to each 5th floor stairwell.

• Contractor shall replace one (1) existing CCTV camera on parking garage ramp, side entry to lobby.

• Contractor shall install one (1) CCTV camera on building to watch front main entrance.

• Contractor shall replace one (1) existing CCTV camera just outside loading dock.

• Contractor shall install one (1) CCTV camera inside loading dock.

• Contractor shall install one (1) VideoNext-compatible 2U rack server configured as a Network Video Recorder for installation into the 4th floor LAN room

• Contractor shall provide a rack-mounted Uninterruptible Power Source (UPS) to serve the Network Video Recorder

• Contractor shall install two (2) viewing stations 32” ultrawide CCTV monitors at the 2nd floor Guard Desk.

• Contractor shall install a VideoNext compatible video workstation (PTZ controller) to allow viewers to control exterior PTZ functions

• Contractor shall install a VideoNext compatible streaming device, brand name or equivalent to the AOPEN Digital Engine.

• Contractor shall connect new CCTV system to the master VideoNEXT system at the DHS NAC for those cameras covering secure areas.

• Contractor shall ensure the replacement or upgraded equipment fits in the existing spaces.

The contractor shall:

• Provide all calculations and analysis to support design, materials and equipment

• Provide and pay for all labor, materials, and equipment

• Pay required sales, gross receipts, and other taxes

• Secure and pay for plan check fees, permits, and licenses necessary for execution of work as applicable for the project

• Give required notices

• Comply with codes, ordinances, regulations, and other legal requirements of public authorities, which bear on performance of work.

• Ensure CCTV equipment, that is under consideration for procurement, meets US

Government supply chain security requirements.

The contractor shall provide written proof (such as manufacture statement) of product compliance with (FAR Case 2018–017): Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment; and section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2019 (Pub. L. 115–232).

“White Label” equipment (equipment that has been sold with no markings to another company for branding and resale) is prohibited.

ISC Standards apply– i.e. capable of 30 days recording, 30 frames per second, 4 Common Interface Format (4 CIF)

Work that is scheduled should be done with skilled labor and shall not be attempted with common labor. At all times, the contractor shall have on the job ample equipment and personnel to carry on the work properly, including such tools as may be necessary to meet emergency requirements. Contractor shall remove and dispose of old wires not utilized. Contractor shall be responsible for the removal of trash and debris created by the installation.

Coordination: The contractor is responsible for all parts of work under this contract, including all work, which he may subcontract. If the various items of work are grouped under separate Divisions in the Specifications for convenience of reference only and the contractor may allocate this work to Subcontractors and suppliers at his discretion. It shall be his responsibility, however, to settle definitely that portion of the work which each shall do. The owner and FPS assume no responsibility whatsoever for any jurisdictional claim by any trade involved. The contractor shall insure complete cooperation by all parties, which he may bring together to accomplish the work described.

Submittals: The contractor shall identify any deviation from requirements of the contract documents and state all product and system limitations, which may be detrimental to successful performance of the completed work. The contractor shall coordinate submission of any supporting materials including shop drawings and product data of affected systems, components, products and accessories to form a single submittal. CISA shall have prior approval any contract deviation and/or product and system limitation impacting system performance.

Operation and Maintenance Manuals, As-Built Drawings: A copy of the operation and maintenance manuals shall be delivered to the CISA Security Management Representative prior to the beginning of the performance verification testing. Shop drawings shall be provided but not limited to the following: warranties, equipment location, and wire drawing, and cut sheets on all the equipment installed at the completion of the job.

Guarantee: The contractor and any subcontractor shall guarantee all work executed under this contract, both as to material and workmanship, for a period of twelve (12) months after the date of the certificate of substantial completion, unless otherwise specifically provided for in the contract and provide a quote for an optional 2nd year warranty. Contractor shall replace any material found defective at the time of installation (including faulty workmanship) with new material. Any replacement shall be done promptly and at no additional cost to CISA or tenant agency and at the least inconvenience to the agency.

Performance Verification Test: After all work has been completed the contractor shall personally inspect the work and prepare a punch list. When this punch list is completed, he will advise the Contracting Officer’s Representative (COR) that he is ready for the final inspection. The contractor shall conduct a performance verification test at the end of the installation prior to the system being turned over to the government. The testing shall be scheduled with the project manager no less than 48 hours before testing.

3.0 CONTRACTOR PERSONNEL

The Contracting personnel:

• Shall be licensed and certified to service, install and maintain all the CCTV camera security equipment associated with the requirement.

• Shall be vetted and on the DHS access approval list.

• Shall have prior knowledge of DHS access systems.

4.0 OTHER APPLICABLE CONDITIONS

4.1 SECURITY

No additional Security Guidelines for this requirement.

4.2 PERIOD OF PERFORMANCE

The period of performance for this contract is one (1) year after Date of Award.

4.3 PLACE OF PERFORMANCE

The primary place of performance will be at the CSD facilities at 4601 N. Fairfax Dr., Arlington, VA 22203.

4.4 HOURS OF PERFORMANCE

Normal business operating hours 8:00 am-5:00 pm Monday -Friday.

4.5 TRAVEL

Travel is not authorized for contractor personnel.

4.6 PROJECT PLAN

The Contractor shall provide a draft Project Plan within ten days after contract award for Government review and comment. The Contractor shall provide a final Project Plan to the COR not later than five business days after receiving Government comments on the draft plan.

4.7 PROGRESS REPORTS

The Project Manager shall provide a monthly progress report to the Contracting Officer and COR via electronic mail. This report shall include a summary of all Contractor work performed, all direct costs by line item, an assessment of technical progress, schedule status, and any Contractor concerns or recommendations for the previous reporting period.

4.8 PROGRESS MEETINGS

The Project Manager shall be available to meet with the COR and/or Government Project Manager upon request to present deliverables, discuss progress, exchange information and resolve emergent technical problems and issues. These meetings shall take place at Government Facilities at the work site.

4.9 GENERAL REPORT REQUIREMENTS

The Contractor shall provide all written reports and deliverables in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows 10 and Microsoft Office Applications).

4.10 SECTION 508 COMPLIANCE

Section 508 Requirements

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) (codified at 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.

1. All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT or that contain ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps. A, C & D, and available at https://www.gpo.gov/fdsys/pkg/CFR-2017-title36-vol3/pdf/CFR-2017-title36-vol3-part1194.pdf. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards.

Item that contains Information and Communications Technology (ICT): Video monitor Applicable Exception: N/A Authorization #: N/A Applicable Functional Performance Criteria: Does not apply Applicable 508 requirements for electronic content features and components (including Multi-media (video/audio)): Does not apply Applicable 508 requirements for software features and components: Does not apply Applicable 508 requirements for hardware features and components (including Video Displays and Monitors): All requirements in Chapter 4 apply Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply

2. Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018.

Instructions to Offerors

1. For each commercially available Information and Communications Technology (ICT) item offered through this contract, the Offeror shall provide an Accessibility Conformance Report (ACR). The ACR shall be created using the Voluntary Product Accessibility Template Version

2.0 508 (or later). The template can be found at https://www.itic.org/policy/accessibility/vpat.

Each ACR shall be completed in accordance with all the instructions provided in the VPAT template. Each ACR must address the applicable Section 508 requirements referenced in the Work Statement. Each ACR shall state exactly how the ICT meets the applicable standards in the remarks/explanations column, or through additional narrative. All “Supports”, “Supports with Exceptions”, “Does Not Support”, and “Not Applicable” (N/A) responses must be explained in the remarks/explanations column or through additional narrative. The offeror is cautioned to address each standard individually and with specificity, and to be clear whether conformance is achieved throughout the entire ICT Item (for example - user functionality, administrator functionality, and reporting), or only in limited areas of the ICT Item. The ACR shall provide a description of the evaluation methods used to support Section 508 conformance claims. The agency reserves the right, prior to making an award decision, to perform testing on some or all of the Offeror’s proposed ICT items to validate Section 508 conformance claims made in the ACR.

Acceptance Criteria 1 .Before accepting ICT required under the contract, the government reserves the right to perform testing on required ICT items to validate the offeror’s Section 508 conformance claims.

If the government determines that Section 508 conformance claims provided by the offeror represent a higher level of conformance than what is actually provided to the agency, the government shall, at its option, require the offeror to remediate the item to align with the offeror’s original Section 508 conformance claims prior to acceptance.

5.0 GOVERNMENT FURNISHED RESOURCES

There are no Government furnished resources in this requirement.

6.0 CONTRACTOR FURNISHED PROPERTY

The Contractor shall provide their own tools to accomplish the task.

7.0 GOVERNMENT ACCEPTANCE PERIOD

The COR will review deliverables prior to acceptance and provide the contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.

7.1 The COR will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted proposal.

In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions.

7.2 The COR will have ten (10) business days to review deliverables and make comments. The Contractor shall have five (5) business days to make corrections and redeliver.

8.3 All other review times and schedules for deliverables shall be agreed upon by the parties based on the final approved Project Plan. The Contractor shall be responsible for timely delivery to Government personnel in the agreed upon review chain, at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to assure that the established schedule is maintained.

8.0 DHS ENTERPRISE ARCHITECTURE COMPLIANCE TERMS AND

CONDITIONS

All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures.

Specifically, the contractor shall comply with the following HLS EA requirements:

- All developed solutions and requirements shall be compliant with the HLS EA.

- All IT hardware and software shall be compliant with the HLS EA Technical Reference Model

(TRM) Standards and Products Profile.

- Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.

- Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

- Applicability of Internet Protocol Version 6 (IPv6) to DRS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the US. Government Version 6 (USGv6) Profile National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

9.0 DHS GEOSPATIAL INFORMATION SYSTEM TERMS AND CONDITIONS

All implementations including geospatial data, information, and services shall comply with the policies and requirements set forth in the DHS Geospatial Information Infrastructure (GII), including (but not limited to) the following:

- All data built to the GII, whether adopted or developed, shall be submitted to the government for review and insertion into the DHS Data Reference Model.

- All software built to the GII, whether adopted or developed, shall be submitted to the government for review and insertion into the DHS Technical Reference Model.

10.0 DELIVERABLES

The Contractor shall consider items in BOLD as having mandatory due dates. Items in italics are deliverables or events that must be reviewed and/or approved by the COR prior to proceeding to next deliverable or event in this SOW.

ITEM SOW

REFERENCE

DELIVERABLE/

EVENT DUE BY DISTRIBUTION

1 2.1 CCTV

Equipment

In accordance with Project Plan

N/A

2 4.6 Draft Project Plan 10 days after contract award

COR, CO

3 4.6 Final Project Plan 5 days after receipt of comments

COR, CO

4 4.7 Progress Reports 10th day following end of month

COR, CO, PM

The COR will review deliverables prior to acceptance and provide the contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.

10.1 The COR will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted proposal.

In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions.

10.2 The COR will have ten (10) business days to review deliverables and make comments.

The Contractor shall have five (5) business days to make corrections and redeliver.

10.3 All other review times and schedules for deliverables shall be agreed upon by the parties based on the final approved Project Plan. The Contractor shall be responsible for timely delivery to Government personnel in the agreed upon review chain, at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to assure that the established schedule is maintained.

11.0ACCOUNTABLE PROPERTY

This requirement does not include accountable property.

12.0 SECURITY

SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause—

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to:

name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security

Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive but Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. DHS Sensitive Systems Policy Direction 4300A Version 13.1, July 27, 2017 provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 13.1, July 27, 2017), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 12.0, November 15, 2015), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter.

Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document.

The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii)Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the

Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities.

The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements.

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract.

If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Data Universal Numbering System (DUNS);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email);

(v) Contracting Officer POC (address, telephone, email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the Government PII and/or SPII contained within the system;

(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

(g) Sensitive Information Incident Response Requirements.

(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.

(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:

(i) Inspections,

(ii) Investigations,

(iii) Forensic reviews, and

(iv) Data analyses and processing.

(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

(h) Additional PII and/or SPII Notification Requirements.

(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance.

The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.

(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:

(i) A brief description of the incident;

(ii) A description of the types of PII and SPII involved;

(iii) A statement as to whether the PII or SPII was encrypted or protected by other means;

(iv) Steps individuals may take to protect themselves;

(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and

(vi) Information identifying who individuals may contact for additional information.

(i) Credit Monitoring Requirements. In the event that a sensitive information incident involves PII or SPII, the Contractor may be required to, as directed by the Contracting Officer:

(1) Provide notification to affected individuals as described above; and/or

(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified. Credit monitoring services shall be provided from a company with which the Contractor has no affiliation. At a minimum, credit monitoring services shall include:

(i) Triple credit bureau monitoring;

(ii) Daily customer service;

(iii)Alerts provided to the individual for changes and fraud; and

(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or

(3) Establish a dedicated call center. Call center services shall include:

(i) A dedicated telephone number to contact customer service within a fixed period;

(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;

(iii)Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics;

(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate;

(v) Customized FAQs, approved in writing by the Contracting Officer in coordination with the Headquarters or Component Chief Privacy Officer; and

(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.

(j) Certification of Sanitization of Government and Government-Activity-Related Files and Information. As part of contract closeout, the Contractor shall submit the certification to the COR and the Contracting Officer following the template provided in NIST Special Publication 800-88 Guidelines for Media Sanitization.

INFORMATION SECURITY AND PRIVACY TRAINING (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Security Training Requirements.

(1) All users of Federal information systems are required by Title 5, Code of Federal Regulations, Part 930.301, Subpart C, as amended, to be exposed to security awareness materials annually or whenever system security changes occur, or when the user’s responsibilities change. The Department of Homeland Security (DHS) requires that Contractor employees take an annual Information Technology Security Awareness Training course before accessing sensitive information under the contract. Unless otherwise specified, the training shall be completed within thirty (30) days of contract award and be completed on an annual basis thereafter not later than October 31st of each year.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .