C-P-Addenda - 70FA2021Q00000015.pdf
PDF 861 KB Posted
- Attached to
- NFA Program Support Services Federal contract opportunity
- Solicitation number
- 70FA2021Q00000015
About this file
This is a combined synopsis/solicitation for commercial items issued by the Federal Emergency Management Agency (FEMA) Preparedness Section. The solicitation seeks proposals for contractor support services to support the United States Fire Administration (USFA) / National Fire Academy (NFA) in areas of logistical, word processing, editorial, and conferences/meetings support. The period of performance is one base year plus four option years, from October 1, 2021 to September 30, 2026. The place of performance is the National Emergency Training Center in Emmitsburg, Maryland. This is a total Woman-Owned Small Business set-aside under NAICS code 561990 with a size standard of no more than $12 million in average annual receipts. Proposals are due by 2:00PM on June 3, 2021. The solicitation incorporates FAR clauses by reference and includes additional terms within attachments. Any questions must be submitted by May 27, 2021 to the point of contact listed.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 3 - Eval Factors Response Instruct and Eval Procedures Amend A00001.pdf | ||
| C-P-Addenda - 70FA2021Q00000015 Amend A00001.pdf | ||
| Attachment 5 - QandA - Amend A00001.pdf | ||
| Attachment 4 - RFQ Response Pricing Templates.xlsx | XLSX spreadsheet | |
| Attachment 1 - PWS - USFA-NFA Program Support Services.pdf | ||
| Attachment 5 - QandA.docx | DOCX document | |
| Attachment 3 - Eval Factors Response Instruct and Eval Procedures.pdf | ||
| Attachment 2 - WD No. 2015-4270 Rev. No. 15 last revised 2021.04.07.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFQ# 70FA2021Q00000015
THIS PAGE / SPACE INTENTIONALLY LEFT BLANK FOR COMBINED SYNOPSIS /
SOLICITATION…THE SF 1449 WILL BE INSERTED HERE UPON AWARD
TABLE OF CONENTS
Table of Contents
TABLE OF CONENTS
SECTION A – SF 1449
SECTION B – CONTINUATION BLOCKS from SF 1449
B.1 Billing & Invoice Instructions
SECTION C – CONTRACT CLAUSES
C.1 52.212-4 Contract Terms and Conditions–Commercial Items (Oct. 2018)
C.2 Addenda to 52.212-4
C.2.1 Other Applicable FAR Clauses Incorporated by Reference
C.2.2 Other Applicable FAR Clauses Incorporated in Full Text
C.2.3 DHS & HSAR Clauses Incorporated by Reference
C.2.4 DHS & HSAR Clauses Incorporated in Full Text
C.2.5 FEMA Clauses
C.2.6 Other Terms and Conditions
C.2.7 Security Considerations
C.3 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive
Orders—Commercial Items (Jan 2021)
SECTION D – CONTRACT DOCUMENTS, EXHIBITS, or ATTACHMENTS
SECTION E – SOLICITATION PROVISIONS
E.1 52.212-1 Instructions to Offerors–Commercial Items (Jun 2020)
E.2 Addenda to 52.212-1
E.2.1 Addendum to FAR 52.212-1
E.2.2 Other Applicable FAR Provisions Incorporated by Reference
E.2.3 Other Applicable FAR Provisions Incorporated in Full Text
E.2.4 FEMA Provisions
E.2.5 Offer Preparation and Submission Instructions
E.3 Addendum for Description of Evaluation Factors and Procedures pursuant to FAR 13.106 as permitted by FAR 12.602 [and in lieu of 52.212-2 Evaluation–Commercial Items (Oct 2014)]
Overview & Evaluation Factors
Evaluation Procedures
Evaluation of Options
Award Notice or Offer Acceptance
E.4 52.212-3 Offerors Representations and Certifications–Commercial Items (Feb 2021)
SECTION A – SF 1449
To be inserted at award.
SECTION B – CONTINUATION BLOCKS from SF 1449
B.1 Billing & Invoice Instructions The Contractor shall submit monthly invoices electronically (preferably) in pdf format
(preferably) to the FEMA Finance Center at FEMA-FINANCE-VENDOR-
Payments@fema.dhs.gov and copy the CO, COR, Alternate COR, and Contract Specialist.
To be considered proper and in addition to the requirements of the clause at FAR 52.212-4(g), invoices shall contain at a minimum the following:
(1) Names and address of the servicing finance office (as follows)
FEMA Finance Center
P.O. Box 9001
Winchester VA 22604
(2) Name and address of Contractor.
(3) Invoice (submission) date and number. If submitted invoice(s) requires revision(s), an
“R” and corresponding number shall be added to the end of the Invoice #. Ex. Revision
1 e.g. “######R1” or Revision 2 e.g. “#####R2” and so on. Final invoices shall be represented as “######-FINAL.”
(4) Contract, Overarching Contract and Task or Delivery Order, OR Purchase Order
Number.
(5) Name of CO and COR or Authorized Invoice Approver.
(6) Date of Delivery or Service → show the month, day and year, beginning and ending dates of supplies or services delivered including any shipping number and date of shipment, including bill of lading number and weight of shipment if shipped on
Government bill of lading.
(7) A summary of claimed current and cumulative goods and services delivered and accepted to date by item and by CLIN, which must include description of each CLIN.
(8) Discount terms if applicable.
(9) Name and address of official to whom payment is to be sent.
(10) Name, title, and phone number of person to notify in event of defective invoice.
(11) Taxpayer Identification Number (TIN) and electronic funds transfer (EFT) information or directions e.g. pay via SAM.gov ACH.
SECTION C – CONTRACT CLAUSES
C.1 52.212-4 Contract Terms and Conditions–Commercial Items (Oct. 2018)
Incorporated by reference in combined synopsis and solicitation and in Purchase Order via SF
1449 Block 27b.
mailto:FEMA-FINANCE-VENDOR-Payments@fema.dhs.gov mailto:FEMA-FINANCE-VENDOR-Payments@fema.dhs.gov
C.2 Addenda to 52.212-4
C.2.1 Other Applicable FAR Clauses Incorporated by Reference
Clause Description Date
52.204-4 Printed or Copied Double-Sided on Postconsumer Fiber Content Paper May 2011
52.204-9 Personal Identity Verification of Contractor Personnel Jan 2011
52.204-13 System for Award Management Maintenance Oct 2018
52.204-18 Commercial and Government Entity Code Maintenance Aug 2020
52.204-19 Incorporation by Reference of Representations and Certifications Dec 2014
52.223-10 Waste Reduction Program May 2011
52.224-1 Privacy Act Notification Apr 1984
52.224-2 Privacy Act Apr 1984
52.224-3 Privacy Training Alternate I Jan 2017
52.227-14 Rights in Data–General May 2014
52.228-5 Insurance–Work on a Government Installation Jan 1997
52.232-18 Availability of Funds Apr 1984
52.232-40 Providing Accelerated Payments to Small Business Subcontractors Dec 2013
52.237-2 Protection of Government Buildings, Equipment, and Vegetation Apr1984
52.245-1 Government Property Alternate I Jan 2017
52.245-9 Use and Charges Apr 2012
C.2.2 Other Applicable FAR Clauses Incorporated in Full Text
52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance
Services or Equipment (DEVIATION 20-05) (Aug 2020)
(a) Definitions. As used in this clause—
Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet).
Covered foreign country means The People’s Republic of China.
Covered telecommunications equipment or services means–
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE
Corporation (or any subsidiary or affiliate of such entities);
(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);
(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National
Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.
Critical technology means–
(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part
774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled-
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology;
or
(ii) For reasons relating to regional stability or surreptitious listening;
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of
Federal Regulations (relating to export and import of nuclear equipment and material);
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the
Export Control Reform Act of 2018 (50 U.S.C. 4817).
Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow the use of another's network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone provider A to a customer of telephone company B) or sharing data and other information resources.
Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include an internal or third-party audit.
Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high.
Substantial or essential component means any component necessary for the proper function or performance of a piece of equipment, system, or service.
(b) Prohibition.
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal
Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system.
The Contractor is prohibited from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104.
(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for
Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August
13, 2020, from entering into a contract, or extending or renewing a contract, with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104.
This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract.
(c) Exceptions. This clause does not prohibit contractors from providing—
(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(d) Reporting requirement.
(1) In the event the Contractor identifies covered telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during contract performance, or the Contractor is notified of such by a subcontractor at any tier or by any other source, the Contractor shall report the information in paragraph (d)(2) of this clause in writing via email to the Contracting Officer, Contracting
Officer’s Representative, and the Enterprise Security Operations Center (SOC) at
NDAA_Incidents@hq.dhs.gov, with required information in the body of the email. In the case of the Department of Defense, the Contractor shall report to the website at https://dibnet.dod.mil.
For indefinite delivery contracts, the Contractor shall report to the Enterprise SOC, Contracting
Officer for the indefinite delivery contract and the Contracting Officer(s) and Contracting
Officer’s Representative(s) for any affected order, or in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.
(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause
(i) Within one business day from the date of such identification or notification: the contract number; the order number(s), if applicable; supplier name; supplier unique entity identifier (if known); supplier Commercial and Government Entity (CAGE) code (if known);
brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available information about mitigation actions undertaken or recommended.
In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of https://www.acquisition.gov/content/part-4-administrative-and-information-matters#id1989GI040ZO mailto:NDAA_Incidents@hq.dhs.gov https://dibnet.dod.mil/ https://dibnet.dod.mil/ covered telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.
(e) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (e) and excluding paragraph (b)(2), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial items.
(End of clause)
52.217-8 Option to Extend Services (Nov 1999)
The Government may require continued performance of any services within the limits and at the rates specified in the contract from the/those CLIN(s) in the PoP active or applicable directly prior to the time period covered by the exercise of the option under this clause. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of
Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 15 days prior to the current expiration of the contract.
(End of clause)
52.217-9 Option to Extend the Term of the Contract (Mar 2000)
(a) The Government may extend the term of this contract by written notice to the Contractor within 30 days [insert the period of time within which the Contracting Officer may exercise the option]; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 30 days before the contract expires. The preliminary notice does not commit the Government to an extension.
(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.
(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 5 years.
(End of clause)
52.252-2 Clauses Incorporated by Reference (Feb 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):
www.acquisition.gov
(End of clause)
C.2.3 DHS & HSAR Clauses Incorporated by Reference
Clause Description Date
3052.211-70 Index for Specifications Dec 2003 http://www.acquisition.gov/
Clause Description Date
3052.222-70 Strikes or Picketing Affecting Timely Completion of the Contract Work Dec 2003
3052.222-71 Strikes or Picketing Affecting Access to a DHS Facility Dec 2003
C.2.4 DHS & HSAR Clauses Incorporated in Full Text
3052.204-71 Contractor Employee Access (Sep 2012) Alternate I (Sep 2012)
(a) Sensitive Information, as used in this clause, means any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an
Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure
Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-
296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal
Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of
Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation
Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
(b) “Information Technology Resources” include, but are not limited to, computer equipment, networking equipment, telecommunications equipment, cabling, network drives, computer drives, network software, computer software, software programs, intranet sites, and internet sites.
(c) Contractor employees working on this contract must complete such forms as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability. Completed forms shall be submitted as directed by the Contracting Officer.
Upon the Contracting Officer's request, the Contractor's employees shall be fingerprinted, or subject to other investigations as required. All Contractor employees requiring recurring access to Government facilities or access to sensitive information or IT resources are required to have a favorably adjudicated background investigation prior to commencing work on this contract unless this requirement is waived under Departmental procedures.
(d) The Contracting Officer may require the Contractor to prohibit individuals from working on the contract if the Government deems their initial or continued employment contrary to the public interest for any reason, including, but not limited to, carelessness, insubordination, incompetence, or security concerns.
(e) Work under this contract may involve access to sensitive information. Therefore, the
Contractor shall not disclose, orally or in writing, any sensitive information to any person unless authorized in writing by the Contracting Officer. For those Contractor employees authorized access to sensitive information, the Contractor shall ensure that these persons receive training concerning the protection and disclosure of sensitive information both during and after contract performance.
(f) The Contractor shall include the substance of this clause in all subcontracts at any tier where the subcontractor may have access to Government facilities, sensitive information, or resources.
(g) Before receiving access to IT resources under this contract the individual must receive a security briefing, which the Contracting Officer’s Representative (COR) will arrange, and complete any nondisclosure agreement furnished by DHS.
(h) The Contractor shall have access only to those areas of DHS information technology resources explicitly stated in this contract or approved by the COR in writing as necessary for performance of the work under this contract. Any attempts by Contractor personnel to gain access to any information technology resources not expressly authorized by the statement of work, other terms and conditions in this contract, or as approved in writing by the COR, is strictly prohibited. In the event of violation of this provision, DHS will take appropriate actions with regard to the contract and the individual(s) involved.
(i) Contractor access to DHS networks from a remote location is a temporary privilege for mutual convenience while the Contractor performs business for the DHS Component. It is not a right, a guarantee of access, a condition of the contract, or Government Furnished Equipment
(GFE).
(j) Contractor access will be terminated for unauthorized use. The Contractor agrees to hold and save DHS harmless from any unauthorized use and agrees not to request additional time or money under the contract for any delays resulting from unauthorized use or access.
(k) Non-U.S. citizens shall not be authorized to access or assist in the development, operation, management or maintenance of Department IT systems under the contract, unless a waiver has been granted by the Head of the Component or designee, with the concurrence of both the
Department’s Chief Security Officer (CSO) and the Chief Information Officer (CIO) or their designees. Within DHS Headquarters, the waiver may be granted only with the approval of both the CSO and the CIO or their designees. In order for a waiver to be granted:
(1) There must be a compelling reason for using this individual as opposed to a U. S. citizen; and
(2) The waiver must be in the best interest of the Government.
(l) Contractors shall identify in their proposals the names and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the contracting officer.
(End of clause)
3052.212-70 Contract Terms and Conditions Applicable to DHS Acquisition of Commercial Items
(Sep 2012)
The Contractor agrees to comply with any provision or clause that is incorporated herein by reference to implement agency policy applicable to acquisition of commercial items or components. The provision or clause in effect based on the applicable regulation cited on the date the solicitation is issued applies unless otherwise stated herein. The following provisions and clauses are incorporated by reference:
(a) Provisions.
3052.209-72 Organizational Conflicts of Interest.
3052.216-70 Evaluation of Offers Subject to An Economic Price Adjustment Clause.
3052.219-72 Evaluation of Prime Contractor Participation in the DHS Mentor Protégé
Program.
(b) Clauses.
3052.203-70 Instructions for Contractor Disclosure of Violations.
3052.204-70 Security Requirements for Unclassified Information Technology Resources.
X 3052.204-71 Contractor Employee Access. → Reference Full Text Version of Clause
X Alternate I → Reference Full Text Version of Clause
X 3052.205-70 Advertisement, Publicizing Awards, and Releases Alternate I.
3052.209-73 Limitation on Future Contracting.
X 3052.215-70 Key Personnel or Facilities → Reference Full Text Version of Clause
3052.216-71 Determination of Award Fee.
3052.216-72 Performance Evaluation Plan.
3052.216-73 Distribution of Award Fee.
3052.217-91 Performance. (USCG)
3052.217-92 Inspection and Manner of Doing Work. (USCG)
3052.217-93 Subcontracts. (USCG)
3052.217-94 Lay Days. (USCG)
3052.217-95 Liability and Insurance. (USCG)
3052.217-96 Title. (USCG)
3052.217-97 Discharge of Liens. (USCG)
3052.217-98 Delays. (USCG)
3052.217-99 Department of Labor Safety and Health Regulations for Ship Repair. (USCG)
3052.217-100 Guarantee. (USCG)
3052.219-70 Small Business Subcontracting Plan Reporting.
3052.219-71 DHS Mentor Protégé Program.
X 3052.228-70 Insurance.
3052.228-90 Notification of Miller Act Payment Bond Protection. (USCG)
3052.228-91 Loss of or Damage to Leased Aircraft. (USCG)
3052.228-92 Fair Market Value of Aircraft. (USCG)
3052.228-93 Risk and Indemnities. (USCG)
3052.236-70 Special Provisions for Work at Operating Airports.
X 3052.242-72 Contracting Officer’s Representative.
3052.247-70 F.o.B. Origin Information.
Alternate I
Alternate II
3052.247-71 F.o.B. Origin Only.
3052.247-72 F.o.B. Destination Only.
(End of clause)
3052.215-70 Key Personnel or Facilities (Dec 2003)
(a) The personnel or facilities specified below are considered essential to the work being performed under this contract and may, with the consent of the contracting parties, be changed from time to time during the course of the contract by adding or deleting personnel or facilities, as appropriate.
(b) Before removing or replacing any of the specified individuals or facilities, the Contractor shall notify the Contracting Officer, in writing, before the change becomes effective. The
Contractor shall submit sufficient information to support the proposed action and to enable the
Contracting Officer to evaluate the potential impact of the change on this contract. The
Contractor shall not remove or replace personnel or facilities until the Contracting Officer approves the change.
Key Personnel under this Contract:
Position / Title Individual
Project Manager To be completed by Gov. at award
Key Facilities under this Contract:
NONE
Minimum Qualifications for Key Personnel
Project Manager – The Contractor shall provide a full-time, on-site Project Manager to be responsible for overall project coordination, contract personnel, and to act as the central point of contact with the Government. The Project Manager shall be authorized to act for the Contractor in all matters pertaining to this contract. The Project Manager shall be available on-site Monday through Friday. Work hours may be flexible between 7:30 a.m. through 5:30 p.m. During other than normal business hours, the Project Manager shall respond to on-site requests as necessary. The Project Manager shall have as a minimum the following qualifications / functional capabilities:
(1) A minimum of five (5) years proven project management experience.
(2) The ability to schedule and track work, write reports and communicate effectively with other persons.
(3) The ability to supervise employees working under this contract.
(4) Previous experience in multi-service contracts of similar size and scope.
(End of clause)
Safeguarding of Sensitive Information (2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of
Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure
Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-
296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal
Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of
Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation
Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official
Use Only) Information
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel
Suitability and Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for
Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and
Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only)
Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy
Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for
Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard
SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of
Homeland Security Personnel Suitability and Security Program establishes procedures, program http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://csrc.nist.gov/publications/PubsSPs.html responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form
11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the
Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the
ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the
DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security
Assessment Plan, Security Assessment Report, and Authorization to Operate Letter.
Additional documents that may be required include a Plan(s) of Action and Milestones and
Interconnection Security Agreement(s). During the development of SA documentation, the
Contractor shall submit a signed SA package, validated by an independent third party, to the
COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified
SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy
Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the
DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy
Act System of Records Notice (SORN), or modifications thereto, are required. The
Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones.
Support in this context includes responding timely to requests for information from the
Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy.
Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods:
(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls.
The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced.
The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the
Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of
Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security
Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the
Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the
Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the
Government and are defined in the Fiscal Year 2014 DHS Information Security Performance
Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.
(f) Sensitive Information Incident Reporting Requirements.
(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting
Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting
Officer’s email address is not immediately available, the Contractor shall contact the Contracting
Officer immediately after reporting the incident to the Headquarters or Component SOC. The
Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for
Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment.
A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.
(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
(i) Data Universal Numbering System (DUNS);
(ii) Contract numbers affected unless all contracts by the company are affected;
(iii) Facility CAGE code if the location of the event is different than the prime contractor location;
(iv) Point of contact (POC) if different than the POC recorded in the System for Award
Management (address, position, telephone, email);
(v) Contracting Officer POC (address, telephone, email);
(vi) Contract clearance level;
(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;
(viii) Government programs, platforms or systems involved;
(ix) Location(s) of incident;
(x) Date and time the incident was discovered;
(xi) Server names where sensitive information resided at the time of the incident, both at the
Contractor and subcontractor level;
(xii) Description of the Government PII and/or SPII contained within the system;
(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and
(xiv) Any additional information relevant to the incident.
(g) Sensitive Information Incident Response Requirements.
(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the
Headquarters or Component CIO and Headquarters or Component Privacy Officer.
(2) The Contractor shall provide full access and cooperation for all activities determined by the
Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:
(i) Inspections,
(ii) Investigations,
(iii) Forensic reviews, and
(iv) Data analyses and processing.
(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.
(h) Additional PII and/or SPII Notification Requirements.
(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the
Contractor shall be coordinated with, and subject to prior written approval by the Contracting
Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS
Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.
(2) Subject to Government analysis of the incident and the terms of its instructions to the
Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .