B.IV.1 - Solicitation 15A00021R00000103 -v20210922.pdf
PDF 120 KB Posted
- Attached to
- National Vehicle Maintenance Services/Program Federal contract opportunity
- Solicitation number
- 15A00021R00000103
About this file
This is a solicitation for national vehicle maintenance services. The Bureau of Alcohol, Tobacco, Firearms and Explosives is seeking proposals for a bureau-wide vehicle management solution, including maintenance and repair services for its fleet. Interested vendors must submit proposals by September 27, 2021. Award will be made to the responsive offeror providing the lowest price that is technically acceptable based on the statement of work. The selected contractor must be able to deliver services nationwide within required timeframes. The period of performance is one base year with four optional one-year extensions.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| B.IV.1 - Appendix A - ATF List of Offices.pdf | ||
| B.IV.1 - Attachment B Subcontracting Goals.docx | DOCX document | |
| B.III.1 - National Vehicle Maintenance SOW & QASP - v20210909.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
15A00021R00000103 Page 1 of 40
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 & 30
1. REQUISITION NUMBER
DJA-21-ALAD-PR-0784
PAGE 1 OF
5. SOLICITATION NUMBER
15A00021R00000103
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 6. SOLICITATION ISSUE
DATE
09/22/2021
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
Brandon.Hodnett@ATF.gov
b. TELEPHONE NUMBER (No collect calls)
(O) 2026487612 (F) 2026489654
8. OFFER DUE DATE / LOCAL
TIME
09/27/2021 12:00 ET
CODE 15A000
ATF - ACQUSITIONS BRANCH
Brandon Hodnett 99 New York Ave, NE Washington, DC 20226
9. ISSUED BY X UNRESTRICTED OR SET ASIDE: % FOR
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
10. THE ACQUISITION IS
SEE
SCHEDULE
11. DELIVERY FOR FOB DESTINATION
UNLESS BLOCK IS MARKED
NET 30
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER DPAS
(15 CFR 700)
13b. RATING
RFQ IFB X RFP
14. METHOD OF SOLICITATION
15A000CODE15. DELIVER TO
ATF - Property, Acquisitions and Safety Division (PASD) 99 New York Ave NE
WASHINGTON, DC 20226
DIVISION CHIEF
CODE 15A00016. ADMINISTERED BY
ATF - ACQUSITIONS BRANCH
Brandon Hodnett 99 New York Ave, NE Washington, DC 20226
(O) 2026487612
(F) 2026489654 Brandon.Hodnett@ATF.gov
FACILITY
CODE
CODE
TELEPHONE NO.
17a. CONTRACTOR/
OFFEROR
A404040CODE18a. PAYMENT WILL BE MADE BY
ATF - Finance Branch 99 New York Avenue NE, #4.S-288 Washington, DC 20226
(O) (202) 648-7860 Finance.Branch@ATF.gov
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER SEE ADDENDUM
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS
CHECKED
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
National Vehicle Management Services Firm Fixed Price
See Continuation Sheet(s) (Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
X 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA X ARE ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
X 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN ____ COPIES TO
ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH
OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE
TERMS AND CONDITIONS SPECIFIED.
29. AWARD OF CONTRACT: REF. _____________________________ OFFER
DATED _________________ . YOUR OFFER ON SOLICITATION (BLOCK 5)
INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH HEREIN,
IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF THE CONTRACTING OFFICER (TYPE OR PRINT)
Jeannine H Beavers
31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
15A00021R00000103 Page 2 of 40
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: _________________________________
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
PARTIAL FINAL
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
COMPLETE PARTIAL FINAL
36. PAYMENT 37. CHECK NUMBER
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
15A00021R00000103 Page 3 of 40
Table of Contents
Section Description Page Number
1 Solicitation/Contract Form 2 Commodity or Services Schedule 3 Contract Clauses
ATF-10 CONTRACTOR-ACQUIRED INSURANCE REQUIREMENTS (July 19, 2007) ATF-11 ATF IDENTIFICATION (ID) MEDIA (Revised April 3, 2008)
ATF-12 NON-US CITIZENS PROHIBITED FROM ACCESS TO DOJ INFORMATION
TECHNOLOGY (IT) SYSTEMS (Revised May 31,2007) ATF-14 ELECTRONIC INVOICING (Revised October 27, 2008) ATF-17 NOTICE TO THE GOVERNMENT OF DELAYS (Revised July 19, 2007) ATF-19 AUTHORITY TO OBLIGATE THE GOVERNMENT (Revised July 19, 2007) ATF-22 CONFIDENTIALITY OF INFORMATION AND DISCLOSURE (Revised April 3, 2008)
ATF-26 SECURITY OF SYSTEMS AND DATA, INCLUDING PERSONALLY-IDENTIFIABLE
INFORMATION (PII) (Revised May 22, 2008) ATF-29 STATEMENT OF WORK / SPECIFICATIONS (Continued) (March 23, 2009)
ATF-46 CORPORATE REPRESENTATION REGARDING FELONY CONVICTION UNDER ANY
FEDERAL LAW OR UNPAID DELINQUENT TAX LIABILITY - Award (Deviation 2015-02) (March 2015)
ATF-47 CONTRACTOR INTERNAL CONFIDENTIALITY AGREEMENTS OR STATEMENTS
PROHIBITING OR RESTRICTING REPORTING OF WASTE, FRAUD, AND ABUSE (Deviation 2015-02) (March 2015)
ATF-49 ATF-49 SECURITY OF INFORMATION AND INFORMATION SYSTEMS, INCLUDING
PERSONALLY-IDENTIFIABLE DATA (PII) (Revised April 8, 2016) ATF-50 LIMITATIONS ON SUBCONTRACTING UNDER SMALL BUSINESS SET-ASIDES (May 24, 2019) ATF-51 INDEPENDENT CONTRACTOR (March 9, 2021) ATF-52 INDEMNIFICATION CLAUSE (May 2021)
ATF-53 WHISTLEBLOWER INFORMATION FOR EMPLOYEES OF DOJ CONTRACTORS,
SUBCONTRACTORS, GRANTEES, SUBGRANTEES OR PERSONAL-SERVICES
CONTRACTORS (March 2021) 52.202-1 Definitions (Jun 2020) 52.203-6 Restrictions on Subcontractor Sales to the Government (Jun 2020) 52.203-17 Contractor Employee Whistleblower Rights and Requirement To Inform Employees of Whistleblower Rights (Jun 2020) 52.204-7 System for Award Management (Oct 2018) 52.204-19 Incorporation by Reference of Representations and Certifications (Dec 2014) 52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment (Aug 2020) 52.212-4 Contract Terms and Conditions-Commercial Items (Oct 2018) 52.217-8 Option to Extend Services (Nov 1999) 52.232-1 Payments (Apr 1984) 52.232-39 Unenforceability of Unauthorized Obligations (Jun 2013) 52.233-4 Applicable Law for Breach of Contract Claim (Oct 2004) 52.212-5 Contract Terms and Conditions Required to Implement Statutes or Executive Orders- Commercial Items (Jul 2021) 52.219-9 Small Business Subcontracting Plan (Jun 2020) 52.232-40 Providing Accelerated Payments to Small Business Subcontractors (Dec 2013) 52.244-6 Subcontracts for Commercial Items (Jul 2021) ATF-39 National Security Risk Assessment (November 2013)
4 List of Attachments Section J List of Documents, Exhibits and Other Attachments
5 Solicitation Provisions 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment (Oct 2020) Section L INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS Section M Evaluation Factors
15A00021R00000103 Page 4 of 40
Section 2 - Commodity or Services Schedule
SCHEDULE OF SUPPLIES/SERVICES
CONTINUATION SHEET
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 Bureau Wide National Vehicle Management Services (NVM) solution.
Please see Attachment A: STATEMENT OF WORK (SOW) AND
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
PSC: R499
Line Period of Performance: 09/30/2021 - 09/29/2022
Base Period
12 MO $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
1001 Option Year 1:
Bureau Wide National Vehicle Management Services (NVM) solution.
Please see Attachment A: STATEMENT OF WORK (SOW) AND
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
PSC: R499
Line Period of Performance: 09/30/2022 - 09/29/2023
Option Period
12 MO $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
2001 Option Year 2:
Bureau Wide National Vehicle Management Services (NVM) solution.
Please see Attachment A: STATEMENT OF WORK (SOW) AND
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
PSC: R499
Line Period of Performance: 09/30/2023 - 09/29/2024
Option Period
12 MO $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
3001 Option Year 3:
Bureau Wide National Vehicle Management Services (NVM) solution.
Please see Attachment A: STATEMENT OF WORK (SOW) AND
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
PSC: R499
Line Period of Performance: 09/30/2024 - 09/29/2025
Option Period
12 MO $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
4001 Option Year 4:
Bureau Wide National Vehicle Management Services (NVM) solution.
Please see Attachment A: STATEMENT OF WORK (SOW) AND
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
PSC: R499
Line Period of Performance: 09/30/2025 - 09/29/2026
Option Period
12 MO $________ $_________________
15A00021R00000103 Page 5 of 40
Section 3 - Contract Clauses
A.1 ADDENDUM TO FAR 52.212-4, Contract Terms and Conditions-Commercial Items (Oct 2018)
The terms and conditions for the following clauses are hereby incorporated into this solicitation and resulting contract as an addendum to FAR clause 52.212-4.
Clauses By Reference
52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov
Clause Title Fill-ins (if applicable)
52.202-1 Definitions (Jun 2020)
52.203-6 Restrictions on Subcontractor Sales to the Government (Jun 2020)
52.203-17 Contractor Employee Whistleblower Rights and Requirement To
Inform Employees of Whistleblower Rights (Jun 2020)
52.204-7 System for Award Management (Oct 2018)
52.204-19 Incorporation by Reference of Representations and Certifications (Dec
2014)
52.204-25 Prohibition on Contracting for Certain Telecommunications and Video
Surveillance Services or Equipment (Aug 2020)
52.212-4 Contract Terms and Conditions-Commercial Items (Oct 2018)
52.217-8 Option to Extend Services (Nov 1999) Period of Time: "60 days"
52.232-1 Payments (Apr 1984)
52.232-39 Unenforceability of Unauthorized Obligations (Jun 2013)
52.233-4 Applicable Law for Breach of Contract Claim (Oct 2004)
Clauses By Full Text
ATF-10 CONTRACTOR-ACQUIRED INSURANCE REQUIREMENTS (July 19, 2007)
In accordance with the clause entitled "Insurance - Work on a Government Installation" in Section I, insurance of the following kinds and minimum amounts shall be provided and maintained during the period of performance of this contract:
15A00021R00000103 Page 6 of 40
(a) Worker's compensation and employer's liability. The contractor shall, as a minimum, meet the requirements specified at FAR 28.307-2(a).
(b) General liability. The contractor shall, as a minimum, meet the requirements specified at FAR 28.307-2(b).
(c) Automobile liability. The contractor shall as a minimum, meet the requirements specified at FAR 28.307-2(c).
(End of Clause)
ATF-11 ATF IDENTIFICATION (ID) MEDIA (Revised April 3, 2008)
Contractor personnel who successfully complete the background investigation will be issued ATF Identification (ID) MEDIA and those assigned to provide services in the ATF Headquarters building or other ATF facilities will be issued an electronic access card.
ID Media and Access Control Cards are the property of the United States Government (ATF) and must be accounted for at all times.
It is the responsibility of the contract manager and the Contracting Officer's Representative (COR) to ensure that the ID Media and access card of any employee who leaves the contract is recovered and immediately returned and forwarded or delivered to the ATF Physical Security Programs Branch.
If ID MEDIA or access cards are lost, stolen, or not recovered, the contractor is liable for replacement costs.In addition, payroll, or other monies due individuals may be held until ID media is returned or otherwise accounted for by separating individuals, or the result of an appropriate investigation. The COR shall initiate appropriate loss/theft reports to document the event. Copies of the required reports shall be provided to the Physical Security Programs Branch and the Office of Inspection.
(End of Clause)
ATF-12 NON-US CITIZENS PROHIBITED FROM ACCESS TO DOJ INFORMATION TECHNOLOGY (IT) SYSTEMS (Revised May 31,2007)
The Department of Justice does not permit the use of Non-U.S. citizens in the performance of this contract or commitment for any position that involves access to or development of any DOJ Information Technology (IT) system. By signing the contract or commitment document, the contractor agrees to this restriction.
In those instances where other non-IT requirements contained in the contract or commitment can be met by using Non-U.S. citizens, those requirements shall be clearly described.
Financial Responsibility: Contractor employees who have delinquent unpaid debt may be required to provide proof of payment and/or proof of participation in a payment plan. If this documentation cannot be provided, the Contractor employee's background investigation may be terminated and/or access to ATF facilities, proprietary information and data, including automated information systems may be terminated, without the Contractor being offered an opportunity to mitigate the information.
A contractor employee who is in direct violation of a policy established, by DOJ or ATF may be denied access to ATF facilities, proprietary information and data, including automated information systems, without being offered an opportunity to mitigate the information.
ATF-14 ELECTRONIC INVOICING (Revised October 27, 2008)
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) encourages contractors to invoice electronically.
Invoicing electronically saves time, money, and physical storage space for both the Government and the contractor.
Each invoice must be a proper invoice in accordance with Federal Acquisition Regulations (FAR) 32.905(b). The contractor may submit a combined invoice with each ATF contract/order number. The invoice must clearly identify the specific Contract Line Item (CLIN) or item number for which the contractor is seeking payment under the contract/order. If the invoice covers multiple CLINs or item numbers, the invoice must clearly identify specific amounts and activity applicable to each.
Electronic invoices must be submitted to the ATF Contracting Officer's Representative (COR)/POC named in Section G/Section
3.3 of this contract and Financial Management Division (FMD), Finance.Branch@ATF.gov. Electronic invoices will serve as the official, original copy. The e-mail subject line must contain the name of the ATF COR/POC named in Section G/Section 3.3 of the
15A00021R00000103 Page 7 of 40 obligation document, the Order/Award number, the Invoice number and Vendor name (i.e.: John Doe_DJAxxxxxxxxx_Invoice #xxx_ABC, Inc.). ATF will return to the vendor any invoices that do not contain the correct subject line information.
Contractors who are unable to submit electronic invoices may mail their invoices to the COR/POC named in Section G/Section 3.3 of this contract and FMD address provided below:
Bureau of Alcohol, Tobacco, Firearms & Explosives Attn: Finance Branch EXPEDITE CONTRACT INVOICE 99 New York Avenue, NE Mail Drop 4S-288 Washington, DC 20226
ATF-17 NOTICE TO THE GOVERNMENT OF DELAYS (Revised July 19, 2007)
In the event the Contractor encounters difficulty in meeting performance requirements, or when he anticipates difficulty in complying with the contract delivery schedule or completion date, or whenever the Contractor has knowledge that any actual or potential situation is delaying or threatens to delay the timely performance of the contract, the Contractor shall immediately notify the Contracting Officer and the Contracting Officer's Representative COR(s), in writing, giving pertinent details; provided, however, that this date shall be information only in character and that this provision shall not be construed as a waiver by the Government of any delivery schedule or date, or any rights or remedies provided by law or under this contract.
ATF-19 AUTHORITY TO OBLIGATE THE GOVERNMENT (Revised July 19, 2007)
The Contracting Officer is the only individual who can legally commit or obligate the Government to the expenditure of public funds.
No cost chargeable to the proposed contract can be incurred before receipt of a fully executed contract or specific authorization from the Contracting Officer.
ATF-22 CONFIDENTIALITY OF INFORMATION AND DISCLOSURE (Revised April 3, 2008)
The Contractor agrees, in the performance of this contract, to keep all information contained in source documents or other media furnished by the Government in the strictest confidence. The Contractor also agrees not to publish or otherwise divulge such information in whole or in part, in any manner or form, nor to authorize or permit others to do so, taking such reasonable measures as are necessary to restrict access to such information while in the Contractor s possession, to those employees needing such information to perform the work provided herein, e.g., on a need to know basis. There shall be no dissemination or publication, except within and between the Contractor and any subcontractors, of information developed under this contract or contained in the reports to be furnished pursuant to this contract without prior written approval from the Contracting Officer. No news release (including photographs and films, public announcements, denial or confirmation of same) on any part of the subject matter of this contract or any phase of any program hereunder shall be made without the prior written approval of the Contracting Officer. The Contractor is prohibited from releasing to any source, other than the sponsoring activity, any interim, draft and final reports or information pertaining to services performed under this contract until report approval or official review has been obtained. Furthermore, the contractor shall insure that the cover of all interim, draft and final reports contain the following statement: "The view, opinions, and/ or findings contained in this report are those of the author(s) and should not be construed as an official Government position, policy or decision, unless so designated by other documentation."
The Contractor agrees to immediately notify in writing the Contracting Officer named herein, in the event that the Contractor determines or has reason to suspect a breach of this requirement. The Contractor agrees to insert the substance of this clause in any consultant agreement or subcontract hereunder.
15A00021R00000103 Page 8 of 40
(a) Confidential information, as used in this clause, means (1) information or data of a personal nature proprietary about an individual, or (2) information or data submitted by or pertaining CONFIDENTIALITY to an institution or organization, or (3) information or data pertaining to a law enforcement investigation or operation.
(b) In addition to the types of confidential information described in (a) (1), (2) and (3) above, information which might require special consideration with regard to the timing of its disclosure such as draft budget and strategic plans, studies or research, audits, etc.
(c) The Contracting Officer and the Contractor may, by mutual consent, identify elsewhere in this contract specific information and/ or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential. Similarly, the Contracting Officer and the Contractor may, by mutual consent, identify such confidential information from time to time during the performance of the contract. Failure to agree will be settled pursuant to the Disputes clause.
(d) If it is established that information to be utilized under this contract is subject to the Privacy Act, the Contractor will follow the rules and procedures of the disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.
(e) Confidential information, as defined in (a)(1) and (2) above, shall not be disclosed without the prior written consent of the individual, institution, or organization. Confidential information, as defined in (a)(3) shall not be disclosed without the prior written consent of the Bureau of Alcohol, Tobacco, Firearms & Explosives (ATF).
(f) Whenever the Contractor is uncertain with regard to the proper handling of material under the contract, or if the material in question is subject to the Privacy Act or is confidential information subject to the provisions of this clause, the Contractor shall obtain a written determination from the Contracting Officer prior to any release, disclosure, dissemination, or publication.
(g) The provisions of paragraph (e) of this clause shall not apply when the information is subject to conflicting or overlapping provisions in other Federal, State, or local laws.
ATF-26 SECURITY OF SYSTEMS AND DATA, INCLUDING PERSONALLY-IDENTIFIABLE INFORMATION (PII) (Revised May 22, 2008)
a. Systems Security
The work to be performed under this contract requires the handling of data that originated within the Department, data that the contractor manages or acquires for the Department, and/or data that is acquired in order to perform the contract and concerns Department programs or personnel.
For all systems handling such data, the contractor shall comply with all security requirements applicable to Department of Justice (DOJ) systems, including but not limited to all Executive Branch system security requirements (e.g., requirements imposed by the Office of Management and Budget [OMB] and the National Institute of Standards and Technology [NIST]), DOJ IT Security Standards, DOJ Order 2640.2E, and the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Order 7250.1.The contractor shall provide DOJ access to and information regarding the contractor's systems when requested by the Department in connection with its efforts to ensure compliance with all such security requirements, and shall otherwise cooperate with the Department in such efforts.DOJ access shall include independent validation testing of controls, system penetration testing by DOJ/ATF, Federal Information Security Management Act (FISMA) data reviews, and access by the Department s Office of the Inspector General for its reviews.
The use of contractor-owned laptops or other media storage devices to process or store data covered by this clause is prohibited until the contractor provides a letter to the contracting officer (CO) certifying the following requirements:
1. Laptops must employ encryption using a NIST Federal Information Processing Standard (FIPS) 140-2 approved product;
2. The contractor must develop and implement a process to ensure that security and other applications software is kept up-to-date;
3. Mobile computing devices will utilize anti-viral software and a host-based firewall mechanism;
15A00021R00000103 Page 9 of 40
4. The contractor shall log all computer-readable data extracts from databases holding sensitive information and verify each extract including sensitive data has been erased within 90 days or its use is still required. All DOJ information is sensitive information unless designated as non-sensitive by the Department;
5. Contractor-owned removable media, such as removable hard drives, flash drives, CDs, and floppy disks, containing DOJ data, shall not be removed from DOJ facilities unless encrypted using a NIST FIPS 140-2 approved product;
6. When no longer needed, all removable media and laptop hard drives shall be processed (sanitized, degaussed, or destroyed) in accordance with security requirements applicable to DOJ;
7. Contracting firms shall keep an accurate inventory of devices used on DOJ contracts;
8. Rules of behavior must be signed by users. These rules shall address at a minimum: authorized and official use; prohibition against unauthorized users; and protection of sensitive data and personally identifiable information;
9. All DOJ data will be removed from contractor-owned laptops upon termination of contractor work. This removal must be accomplished in accordance with DOJ/ATF Information Technology (IT) Security policy requirements. Certification of data removal will be performed by the contractor's project manager and a letter confirming certification will be delivered to the CO within 15 days of termination of contractor work;
b. Data Security
By acceptance of, or performance on, this contract, the contractor agrees that with respect to the data identified in paragraph a, in the event of any actual or suspected breach of such data (i.e., loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic), the contractor will immediately (and in no event later than within one (1) hour of discovery) report the breach to the DOJ CO and the contracting officer's representative (COR).
If the data breach occurs outside of regular business hours and/or neither the CO nor the COR can be reached, the contractor shall contact the Bureau of ATF s, Office of Science and Technology (OST) Help Desk at 1-877-875-3723 within one (1) hour of discovery of the breach. The contractor shall also notify the CO as soon as possible during regular business hours.
c. Personally Identifiable Information Notification Requirement
The contractor further certifies that it has a security policy in place that contains procedures to promptly notify any individual whose personally identifiable information (as defined OMB) was, or is reasonably believed to have been, breached. Any notification shall be coordinated with ATF s OST Information Systems Security Office, and shall not proceed until ATF has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by the contractor shall be coordinated with, and be subject to the approval of ATF.The contractor assumes full responsibility for taking corrective action consistent with the Department's Data Breach Notification Procedures, which may include offering credit monitoring when appropriate.
d. Pass-through of Security Requirements to Subcontractors
The requirements set forth in Paragraphs a through c above apply to all subcontractors who perform work in connection with this contract. For each subcontractor, the contractor must certify that it has required the subcontractor to adhere to all such requirements.
Any breach by a subcontractor of any of the provisions set forth in this clause will be attributed to the contractor.
ATF-29 STATEMENT OF WORK / SPECIFICATIONS (Continued) (March 23, 2009)
The Contractor shall furnish the necessary personnel, material, equipment, services and facilities (except as otherwise specified), to perform the Statement of Work (SOW) / Specifications and all Section J attachments (as applicable).
(End of Clause)
ATF-46 CORPORATE REPRESENTATION REGARDING FELONY CONVICTION UNDER ANY FEDERAL LAW OR UNPAID DELINQUENT TAX LIABILITY - Award (Deviation 2015-02) (March 2015)
15A00021R00000103 Page 10 of 40
(a) None of the funds made available by the Department’s current Appropriations Act may be used to enter into a contract, memorandum of understanding, or cooperative agreement with a corporation –
(1) convicted of a felony criminal violation under any Federal law within the preceding 24 months, where the awarding agency is aware of the conviction, unless an agency has considered suspension or debarment of the corporation and made a determination that this further action is not necessary to protect the interests of the Government, or
(2) that has any unpaid Federal tax liability that has been assessed, for which all judicial and administrative remedies have been exhausted or have lapsed, and that is not being paid in a timely manner pursuant to an agreement with the authority responsible for collecting the tax liability, where the awarding agency is aware of the unpaid tax liability, unless an agency has considered suspension or debarment of the corporation and made a determination that this further action is not necessary to protect the interests of the Government.
(b) By accepting this award or order, in writing or by performance, the offeror/contractor represents that –
(1) the offeror is not a corporation convicted of a felony criminal violation under any Federal or State law within the preceding 24 months; and,
(2) the offeror is not a corporation that has any unpaid Federal or State tax liability that has been assessed, for which all judicial and administrative remedies have been exhausted or have lapsed, and that is not being paid in a timely manner pursuant to an agreement with the authority responsible for collecting the tax liability.
ATF-47 CONTRACTOR INTERNAL CONFIDENTIALITY AGREEMENTS OR STATEMENTS PROHIBITING OR RESTRICTING REPORTING OF WASTE, FRAUD, AND ABUSE (Deviation 2015-02) (March 2015)
By accepting this award or order, the contractor certifies that it does not require employees or contractors of the contractor seeking to report fraud, waste, and abuse to sign internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or contractors from lawfully reporting waste, fraud, and abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.
ATF-49 ATF-49 SECURITY OF INFORMATION AND INFORMATION SYSTEMS, INCLUDING PERSONALLY- IDENTIFIABLE DATA (PII) (Revised April 8, 2016)
I. Applicability to Contractors and Subcontractors This clause applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of contractors, subcontractors, and CSPs (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information. It establishes and implements specific DOJ requirements applicable to this Contract. The requirements established herein are in addition to those required by the Federal Acquisition Regulation (“FAR”), in-cluding FAR 11.002(g) and 52.239-1, the Privacy Act of 1974, and any other applicable laws, mandates, Procurement Guidance Doc-uments, and Executive Orders pertaining to the development and operation of Information Systems and the protection of Government Information. This clause does not alter or diminish any existing rights, obligation or liability under any other civil and/or criminal law, rule, regulation or mandate.
II. General Definitions The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.
A. Information means any communication or representation of knowledge such as facts, data, or opinions, in any form or medi-um, including textual, numerical, graphic, cartographic, narrative, or audiovisual. Information includes information in an electronic format that allows it be stored, retrieved or transmitted, also referred to as “data,” and “personally identifiable information” (“PII”), re-gardless of form.
B. Personally Identifiable Information (or PII) means any information about an individual maintained by an agency, including, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and in-formation, which can be used to distinguish or trace an individual's identity, such as his or her name, social security number, date and place of birth, mother's maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual.
C. DOJ Information means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, Information related to DOJ programs or personnel. It includes, without limit-
15A00021R00000103 Page 11 of 40 ation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired in order to perform the contract.
D. Information System means any resources, or set of resources organized for accessing, collecting, storing, processing, main-taining, using, sharing, retrieving, disseminating, transmitting, or disposing of (hereinafter collectively, “processing, storing, or trans-mitting”) Information.
E. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information.
III. Confidentiality and Non-disclosure of DOJ Information A. Preliminary and final deliverables and all associated working papers and material generated by Contractor containing DOJ In-formation are the property of the U.S. Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Representat-ive (“COR”) at the conclusion of the contract. The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14.
B. All documents produced in the performance of this contract containing DOJ Information are the property of the U.S. Govern-ment and Contractor shall neither reproduce nor release to any third-party at any time, including during or at expiration or termination of the contract without the prior written permission of the CO.
C. Any DOJ information made available to Contractor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, Contractor assumes responsibility for the protection of the confidentiality of any and all DOJ Information processed, stored, or transmitted by the Contractor. When requested by the CO (typically no more than annually), Contractor shall provide a report to the CO identifying, to the best of Contractor’s knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed, stored, or transmitted under the Contract, including an estimate of the number of indi- viduals for whom PII has been processed, stored or transmitted under the Contract and whether such information includes social secur- ity numbers (in whole or in part).
IV. Compliance with Information Technology Security Policies, Procedures and Requirements A. For all Covered Information Systems, Contractor shall comply with all security requirements, including but not limited to the regulations and guidance found in the Federal Information Security Management Act of 2014 (“FISMA”), Privacy Act of 1974, E- Government Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Pro- cessing Standards (“FIPS”) Publications 140-2, 199, and 200, OMB Memoranda, Federal Risk and Authorization Management Pro- gram (“FedRAMP”), DOJ IT Security Standards, including DOJ Order 2640.2, as amended. These requirements include but are not limited to:
1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise;
2. Providing security awareness training including, but not limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information Systems;
3. Creating, protecting, and retaining Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information;
4. Maintaining authorizations to operate any Covered Information System;
5. Performing continuous monitoring on all Covered Information Systems;
6. Establishing and maintaining baseline configurations and inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Information Systems;
7. Ensuring appropriate contingency planning has been performed, including DOJ Information and Covered Information System backups;
8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verify-ing the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication methods where required;
9. Establishing an operational incident handling capability for Covered Information Systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and reporting incidents to appro-priate officials and authorities within Contractor’s organization and the DOJ;
10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms, and personnel used to conduct such maintenance;
11. Protecting Covered Information System media containing DOJ Information, including paper, digital and electronic media; lim-iting access to DOJ Information to authorized users; and sanitizing or destroying Covered Information System media containing DOJ Information before disposal, release or reuse of such media;
15A00021R00000103 Page 12 of 40
12. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Informa-tion Systems to authorized U.S. citizens unless a waiver has been granted by the Contracting Officer (“CO”), and protecting the phys-ical facilities and support infrastructure for such Information Systems;
13. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with DOJ Security standards;
14. Assessing the risk to DOJ Information in Covered Information Systems periodically, including scanning for vulnerabilities and remediating such vulnerabilities in accordance with DOJ policy and ensuring the timely removal of assets no longer supported by the Contractor;
15. Assessing the security controls of Covered Information Systems periodically to determine if the controls are effective in their application, developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in such Information Systems, and monitoring security controls on an ongoing basis to ensure the continued effectiveness of the controls;
16. Monitoring, controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Information Systems, and employing architectural designs, software development techniques, and systems engineering principles that promote effective security; and
17. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection from malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate action in response.
B. Contractor shall not process, store, or transmit DOJ Information using a Covered Information System without first obtaining an Authority to Operate (“ATO”) for each Covered Information System. The ATO shall be signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under this contract. The DOJ standards and requirements for obtaining an ATO may be found at DOJ Order 2640.2, as amended. (For Cloud Computing Systems, see Section V, below.)
C. Contractor shall ensure that no Non-U.S. citizen accesses or assists in the development, operation, management, or mainten-ance of any DOJ Information System, unless a waiver has been granted by the by the DOJ Component Head (or his or her designee) responsible for the DOJ Information System, the DOJ Chief Information Officer, and the DOJ Security Officer.
D. When requested by the DOJ CO or COR, or other DOJ official as described below, in connection with DOJ’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integ-rity, and availability of DOJ Information, Contractor shall provide DOJ, including the Office of Inspector General (“OIG”) and Feder-al law enforcement components, (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Contractor’s facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data re-views by DOJ or agents acting on behalf of DOJ, and such access shall be provided within 72 hours of the request. Additionally, Con-tractor shall cooperate with DOJ’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of DOJ Information.
E. The use of Contractor-owned laptops or other portable digital or electronic media to process or store DOJ Information covered by this clause is prohibited until Contractor provides a letter to the DOJ CO, and obtains the CO’s approval, certifying compliance with the following requirements:
1. Media must be encrypted using a NIST FIPS 140-2 approved product;
2. Contractor must develop and implement a process to ensure that security and other applications software is kept up-to-date;
3. Where applicable, media must utilize antivirus software and a host- based firewall mechanism;
4. Contractor must log all computer-readable data extracts from databases holding DOJ Information and verify that each extract including such data has been erased within 90 days of extraction or that its use is still required. All DOJ Information is sensitive in-formation unless specifically designated as non-sensitive by the DOJ; and,
5. A Rules of Behavior (“ROB”) form must be signed by users. These rules must address, at a minimum, authorized and official use, prohibition against unauthorized users and use, and the protection of DOJ Information. The form also must notify the user that he or she has no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contractor- owned laptops or other portable digital or electronic media.
F. Contractor-owned removable media containing DOJ Information shall not be removed from DOJ facilities without prior ap-proval of the DOJ CO or COR.
G. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with DOJ security re-quirements.
H. Contractor must keep an accurate inventory of digital or electronic media used in the performance of DOJ contracts.
I. Contractor must remove all DOJ Information from Contractor media and return all such information to the DOJ within 15 days of the expiration or termination of the contract, unless otherwise extended by the CO, or waived (in part or whole) by the CO, and all such information shall be returned to the DOJ in a format and form acceptable to the DOJ. The removal and return of all DOJ Information must be accomplished in accordance with DOJ IT Security Standard requirements, and an official of the Contractor shall provide a written certification certifying the removal and return of all such information to the CO within 15 days of the removal and return of all DOJ Information.
15A00021R00000103 Page 13 of 40
J. DOJ, at its discretion, may suspend Contractor’s access to any DOJ Information, or terminate the contract, when DOJ suspects that Contractor has failed to comply with any security requirement, or in the event of an Information System Security Incident (see Section V.E. below), where the Department determines that either event gives cause for such action. The suspension of access to DOJ Information may last until such time as DOJ, in its sole discretion, determines that the situation giving rise to such action has been cor-rected or no longer exists. Contractor understands that any suspension or termination in accordance with this provision shall be at no cost to the DOJ, and that upon request by the CO, Contractor must immediately return all DOJ Information to DOJ, as well as any media upon which DOJ Information resides, at Contractor’s expense.
V. Cloud Computing A. Cloud Computing means an Information System having the essential characteristics described in NIST SP 800-145, The NIST Definition of Cloud Computing. For the sake of this provision and clause, Cloud Computing includes Software as a Service, Platform as a Service, and Infrastructure as a Service, and deployment in a Private Cloud, Community Cloud, Public Cloud, or Hybrid Cloud.
B. Contractor may not utilize the Cloud system of any CSP unless:
1. The Cloud system and CSP have been evaluated and approved by a 3PAO certified under FedRAMP and Contractor has provided the most current Security Assessment Report (“SAR”) to the DOJ CO for consideration as part of Contractor’s overall Sys-tem Security Plan, and any subsequent SARs within 30 days of issuance, and has received an ATO from the Authorizing Official for the DOJ component responsible for maintaining the security confidentiality, integrity, and availability of the DOJ Information under contract; or,
2. If not certified under FedRAMP, the Cloud System and CSP have received an ATO signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under the contract.
C. Contractor must ensure that the CSP allows DOJ to access and retrieve any DOJ Information processed, stored or transmitted in a Cloud system under this Contract within a reasonable time of any such request, but in no event less than 48 hours from the re- quest.
To ensure that the DOJ can fully and appropriately search and retrieve DOJ Information from the Cloud system, access shall include any schemas, meta-data, and other associated data artifacts.
VI. Information System Security Breach or Incident A. Definitions
1. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any DOJ Informa-tion accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system.
2. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed, Covered Information Sys-tem Security Breach.
3. Security Incident means any Confirmed or Potential Covered Information System Security Breach.
B. Confirmed Breach. Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the DOJ CO and the CO's Representative (“COR”). If the Confirmed Breach occurs outside of regular business hours and/ or neither the DOJ CO nor the COR can be reached, Contractor must call DOJ-CERT at 1-866-US4-CERT (1-866-874-2378) immediately (and in no event later than within 1 hour of discovery of the Confirmed Breach), and shall notify the CO and COR as soon as practicable.
C. Potential Breach.
1. Contractor shall report any Potential Breach within 72 hours of detection to the DOJ CO and the COR, unless Contractor has
(a) completed its investigation of the Potential Breach in accordance with its own internal policies and procedures for identification, investigation and mitigation of Security Incidents and (b) determined that there has been no Confirmed Breach.
2. If Contractor has not made a determination within 72 hours of detection of the Potential Breach whether an Confirmed Breach has occurred, Contractor shall report the Potential Breach to the DOJ CO and COR within one-hour (i.e., 73 hours from detection of the Potential Breach). If the time by which to report the Potential Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call the DOJ Computer Emergency Readiness Team (DOJ-CERT) at 1-866-US4-CERT (1-866-874-2378) within one-hour (i.e., 73 hours from detection of the Potential Breach) and contact the DOJ CO and COR as soon as practicable.
D. Any report submitted in accordance with paragraphs (B) and (C), above, shall identify (1) both the Information Systems and DOJ Information involved or at risk, including the type, amount, and level of sensitivity of the DOJ Information and, if the DOJ In-formation contains PII, the estimated number of unique instances of PII, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the US- CERT Federal In-cident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by the DOJ.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .