Combined Synopsis.pdf

PDF 245 KB Posted

Attached to
Electronic Legal Research Federal contract opportunity
Solicitation number
15BNAS20Q00000019
Issued by
Department of Justice Bureau of Prisons Central Office

View the file

Other files for this federal contract opportunity

Other files attached to Electronic Legal Research, newest first.
File Type Posted
Combined Synopsis.pdf PDF
Statement of Work mod2.pdf PDF
Statement of Work Modification.pdf PDF
Statement of Work Final.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Combined Synopsis Electronic Law Library Enterprise License

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested and a written solicitation will not be issued.

The solicitation number is 15BNAS20Q00000019 and is issued as a request for quote. The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2020-04. The requirement is solicited unrestricted. The North American Industrial Classification (NAICS) code is 541512 and the applicable small business size standard is $30,000,000.

The Federal Bureau of Prisons, Central Office, Washington D.C., intends to award a firm-fixed price indefinite-delivery, requirements type contract to a responsible business entity for the supply of electronic law library enterprise license.

Introduction The Federal Bureau of Prisons, Central Office, Washington D.C., intends to award a firm-fixed price indefinite-delivery, requirements type contract to a responsible business entity for the supply of providing electronic legal research to all BOP correctional institutions for the use by the inmate population.

If an offeror takes exception to any solicitation terms and that exception does not meet the minimum requirements of the solicitation, the offer will be eliminated from award consideration. The Government intends to make a single award indefinite-delivery, requirements type contract with options based on a Technically Acceptable/Lowest price basis. This will be an “acceptable or unacceptable” evaluation. Quotes will have to meet all evaluation criteria identified to be considered for award, no partial awards will be made. Award shall be made on the basis of the lowest technical evaluated price of responses meeting or exceeding the acceptability standards for non-cost factors. Past performance will be evaluated by the Contracting Officer only as it relates to Responsibility.

The Bureau intends to make an award without discussions, however, reserves the right to open discussions if deemed necessary. The technical factors for this requirement are identified below.

CONTRACT PRICING

Contract pricing shall be based on a “per year” price. Contract pricing shall include all charges to the Government for provision of products required by this solicitation (e.g., overhead, profit, taxes, maintenance, transportation, etc.) The Government reserves the right to award without discussion;

therefore, the initial quote should contain the quoter’s best terms from a price standpoint. Pursuant to FAR 17.203(b), the Governments evaluation of quotes shall be inclusive of options.

SCHEDULE OF ITEMS:

CLIN 0001: Electronic Law Library Enterprise License (Base Period) Period of Performance (Date of Award through 12 months)

CLIN 0002: Electronic Law Library Enterprise License (Option Period One) Period of Performance (13 months through 24 months)

CLIN 0003: Electronic Law Library Enterprise License (Option Period Two) Period of Performance (25 months through 36 months)

CLIN 0004: Electronic Law Library Enterprise License (Option Period Three) Period of Performance (37 months through 48 months)

CLIN 0005: Electronic Law Library Enterprise License (Option Period Four) Period of Performance (49 months through 60 months)

CLIN0006: Electronic Law Library Enterprise License (Extension) Six Month Extension per FAR 52.217-8

Delivery of enterprise licenses must be delivered to the Bureau of Prisons by April 1, 2020.

Evaluation Process Description Each offer will be evaluated on all the evaluation criteria elements in this document, on an acceptable or unacceptable basis for all areas of need and shall be able to meet the entire need of the Statement of Work (SOW). Failure to meet a requirement will result in an offer being determined technically unacceptable.

Evaluation Panel Description The Evaluation Panel (EP) will be composed of Bureau of Prison employees with experience and knowledge of the solicitation requirements.

Evaluation Criteria Overview The Government will review the offeror’s written submission against three (3) factors. Those three factors include:

1. Technical

2. Past Performance

3. Price

Each EP member with technical knowledge will provide a narrative assessment of each offer based on the Technical. Past Performance criteria will be evaluated by the Contracting Officer. Each member will also make an acceptable/not acceptable determination for each offer. The results of this review will determine whether each offer is technically acceptable; will form the basis for the content of the Evaluation Report; and will assist in source selection.

Technical Evaluation The purpose of the technical evaluation is to allow the government to assess the offeror’s ability to meet the requirements per the Statement of Work based on the offeror’s technical offer. The following is a detailed description of the technical evaluation factors.

Technical Evaluation Criteria

1. Provide legal software updates on a portable hard drive.

• Updates are to be provided monthly.

• Updates are to be compliant with previously published (SOW) legal briefings and court updates.

2. Provide software capable of running on centralized servers. Installation must support MSI based setup.

3. Provide monthly software updates that do not allow the use of hot-key functions nor can it connect to the internet. Software must allow for generic login.

Past Performance Evaluation The purpose of the Past Performance evaluation is to allow the government to assess the offeror’s historic probability of meeting solicitation requirements. The offeror will provide three (3) of the contractor’s most recent contracts occurring during the past five years that are like or similar, relevant, in nature to the services required in the Statement of Work. Contracts listed may include those entered into with the Federal Government, agencies of state and local government, and commercial entities.

The Offeror shall address any instances of past performance problems in the referenced contracts and explain how these problems were resolved. Failure by the offeror to satisfactorily explain past performance will have an adverse effect on the past performance evaluation. The Government may consider efforts performed by the offeror for agencies of the federal, state, or local governments and commercial customers as potentially relevant to the Past Performance evaluation. Where relevant performance record indicates performance problems, the Government will consider the number and severity of the problems and the appropriateness and effectiveness of any corrective actions taken (not just planned or promised).

Offeror should not provide general information on their performance on the identified contracts.

General performance information MUST be obtained from the references on the Past Performance Questionnaire and submitted along with the contractor’s offer. Offerors without a record of relevant company past performance will be evaluated as neutral.

There are five sub-factors to be assessed:

1. Management Effectiveness

2. Quality and Workmanship

3. Timeliness/Adherence to Schedules

4. Training/Technical Support

5. Customer Satisfaction

All sub-factors are equally important.

Price Evaluation The Offeror’s pricing will be a factor in the award decision. The Contracting Officer will make an award based on the lowest price offer that is technically acceptable to the Government (considering both technical and past performance factors). The Contracting Officer will evaluate the offeror’s price quote and determine if it is fair and reasonable.

Solicitation Provisions:

The Provision at Federal Acquisitions Regulation (FAR) 52.212-1, Instructions to Offerors—Commercial Items (June 2008), applies to this acquisition. The terms and conditions for the following provisions are hereby incorporated into this solicitation as an addendum to FAR Provision 52.212-1: 52.252-1 Solicitation Provisions Incorporated by Reference (Feb 1998); 52.212-3 Offeror Representations and Certifications—Commercial Items (Mar 2011); 52.233-2 Services of Protest (Sept 2006).

52.252-1 Solicitation Provisions Incorporated by Reference (FEB 1998) This solicitation incorporates one or more solicitation provisions by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. The offeror is cautioned that the listed provisions may include blocks that must be completed by the offeror and submitted with its quotation or offer. In lieu of submitting the full text of those provisions, the offeror may identify the provision by paragraph identifier and provide the appropriate information with its quotation or offer. Also, the full text of a solicitation provision may be accessed electronically at this/these address(es): www.acquisition.gov.

52.204-7 System for Award Management 52.209-7 Information Regarding Responsibility Matters 52.212-1 Instructions to Offerors-Commercial Items 52.225-25 Prohibition on Contracting with Entities Engaging in Certain Activities or Transactions Relating to Iran-Representation and Certifications

The following provisions are incorporated into the solicitation in full text:

52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment The Offeror shall not complete the representation in this provision if the Offeror has represented that it “does not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in the performance of any contract, subcontract, or other contractual instrument” in the provision at 52.204-26, Covered Telecommunications Equipment or Services- Representation, or in paragraph (v) of the provision at 52.212-3, Offeror Representations and Certifications-Commercial Items.

(a) Definitions. As used in this provision— “Covered telecommunications equipment or services”, “critical technology”, and “substantial or essential component” have the meanings provided in clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(b) Prohibition. Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. Contractors are not prohibited from providing— http://www.acquisition.gov/

(1)A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(c) Procedures. The Offeror shall review the list of excluded parties in the System for Award Management (SAM) (https://www.sam.gov) for entities excluded from receiving federal awards for “covered telecommunications equipment or services”.

(d) Representation. The Offeror represents that it □ will, □ will not provide covered telecommunications equipment or services to the Government in the performance of any contract, subcontract or other contractual instrument resulting from this solicitation.

(e) Disclosures. If the Offeror has represented in paragraph (d) of this provision that it “will” provide covered telecommunications equipment or services”, the Offeror shall provide the following information as part of the offer—

(1) A description of all covered telecommunications equipment and services offered (include brand; model number, such as original equipment manufacturer (OEM) number, manufacturer part number, or wholesaler number; and item description, as applicable);

(2) Explanation of the proposed use of covered telecommunications equipment and services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph

(b) of this provision;

(3) For services, the entity providing the covered telecommunications services (include entity name, unique entity identifier, and Commercial and Government Entity (CAGE) code, if known); and

(4) For equipment, the entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the OEM or a distributor, if known).

52.233-2 Service of Protest (Sept 2006)

(a) Protests, as defined in section 33.101 of the Federal Acquisition Regulation, that are filed directly with an agency, and copies of any protests that are filed with the Government Accountability Office (GAO), shall be served on the Contracting Officer (addressed as follows) by obtaining written and dated acknowledgment of receipt from 320 1st Street NW, Room 901-5, Washington, DC 20534.

(b) The copy of any protest shall be received in the office designated above within one day of filing a protest with the GAO.

2852.233-70 Protests Filed Directly with the Department of Justice (Jan 1998)

(a) The following definitions apply in this provision:

(1) "Agency Protest Official" means the official, other than the contracting officer, designated to review and decide procurement protests filed with a contracting activity of the Department of Justice.

(2) "Deciding Official" means the person chosen by the protestor to decide the agency protest; it may be either the Contracting Officer or the Agency Protest Official.

(3) "Interested Party" means an actual or prospective offeror whose direct economic interest would be affected by the award of a contract or by the failure to award a contract.

(b) A protest filed directly with the Department of Justice must:

(1) Indicate that it is a protest to the agency.

(2) Be filed with the Contracting Officer.

(3) State whether the protestor chooses to have the Contracting Officer or the Agency Protest Official decide the protest. If the protestor is silent on this matter, the Contracting Officer will decide the protest.

(4) Indicate whether the protestor prefers to make an oral or written presentation of arguments in support of the protest to the deciding official.

(5) Include the information required by FAR 33.103(d)(2):

(i) Name, address, facsimile number and telephone number of the protestor.

(ii) Solicitation or contract number.

(iii) Detailed statement of the legal and factual grounds for the protest, to include a description of resulting prejudice to the protestor.

(iv) Copies of relevant documents.

(v) Request for a ruling by the agency.

(vi) Statement as to the form of relief requested.

(vii) All information establishing that the protestor is an interested party for the purpose of filing a protest.

(viii) All information establishing the timeliness of the protest.

(c) An interested party filing a protest with the Department of Justice has the choice of requesting either that the Contracting Officer or the Agency Protest Official decide the protest.

(d) The decision by the Agency Protest Official is an alternative to a decision by the Contracting Officer.

The Agency Protest Official will not consider appeals from the Contracting Officer's decision on an agency protest.

(e) The deciding official must conduct a scheduling conference with the protestor within five (5) days after the protest is filed. The scheduling conference will establish deadlines for oral or written arguments in support of the agency protest and for agency officials to present information in response to the protest issues. The deciding official may hear oral arguments in support of the agency protest at the same time as the scheduling conference, depending on availability of the necessary parties.

(f) Oral conferences may take place either by telephone or in person. Other parties may attend at the discretion of the deciding official.

(g) The protestor has only one opportunity to support or explain the substance of its protest.

Department of Justice procedures do not provide for any discovery. The deciding official may request additional information from either the agency or the protestor. The deciding official will resolve the protest through informal presentations or meetings to the maximum extent practicable.

(h) An interested party may represent itself or be represented by legal counsel. The Department of Justice will not reimburse the protester for any legal fees related to the agency protest.

(i) The Department of Justice will stay award or suspend contract performance in accordance with FAR 33.103(f). The stay or suspension, unless over-ridden, remains in effect until the protest is decided, dismissed, or withdrawn.

(j) The deciding official will make a best effort to issue a decision on the protest within twenty (20) days after the filing date. The decision may be oral or written.

(k) The Department of Justice may dismiss or stay proceeding on an agency protest if a protest on the same or similar basis is filed with a protest forum outside the Department of Justice.

52.27-103-71 FAITH-BASED AND COMMUNITY-BASED ORGANIZATIONS (AUD 2005)

Faith-based and Community-based organizations can submit offers/bids/quotations equally with other organizations for contracts for which they are eligible.

Contract Clauses:

ADDENDUM TO FAR 52.212-4, Contract Terms and Conditions-Commercial Items (FEB 2012) The terms and conditions for the following clauses are hereby incorporated into this solicitation and resulting contract as an addendum to FAR Clause 52.212-4 (FEB 2012).

52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders - Commercial Items (JAN 2014)

(1) 52.203-6; (2) 52.203-13; (4) 52.204-10; (6) 52.209-6; (7) 52.209-9; (8) 52.209-10; (14) 52.219-8; (23)

52.219-28 (26) 52.222-3; (28) 52.222-21; (29) 52.222-26; (30) 52.222-35; (31) 52.222-36; (32) 52.222-37; (33) 52.222-40; (38) 52.223-18; (42) 52.225-13; (48) 52.232-33; (51) 52.239-1

52.252-2, Clauses Incorporated by Reference (FEB 1998) This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov. Upon request the contracting officer shall provide the full text of any clause incorporated by reference.

52.202-1 Definitions 52.203-12, Limitation On Payments To Influence Certain Federal Transactions (Oct 2010) 52.204-19 Incorporation by Reference of Representations and Certifications.

52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment 52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment 52.212-4, Contract Terms and Conditions-Commercial Items (FEB 2012) 52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders - Commercial Items (AUG 2012)

52.218-000 CONTINUING CONTRACT PERFORMANCE DURING A PANDEMIC INFLUENZA OR OTHER

NATIONAL EMERGENCY (May 2008) 52.223-18 Encouraging Contractor Policies to Ban Text Messaging While Driving 52.225-13 Restrictions on Certain Foreign Purchases.

52.233-4 Applicable Law for Breach of Contract Claim

The following clauses are incorporated into the solicitation in full text:

52.21-603-70 Contracting Officer's Representative (COR) (June 2012) (a)Lindsey George ,CHIEF, INFORMATION MANAGEMENT SECTION , LELZA@BOP.GOV ,202-353-9381 , is hereby designated as the Contracting Officer's Representative (COR) under this contract.

(b) The COR is responsible, as applicable, for: receiving all deliverables, inspecting and accepting the supplies or services provide hereunder in accordance with the terms and conditions of this contract;

providing direction to the contractor which clarifies the contractor effort, fills in details or otherwise serves to accomplish the contractual Scope of Work; evaluating performance; and certifying all invoices/vouchers for acceptance of the supplies or services furnished for payment.

(c) The COR does not have the authority to alter the contractor's obligations under the contract, and/or modify any of the expressed terms, conditions, specifications, or cost of the agreement. If as a result of technical discussions it is desirable to alter/change contractual obligations or the Scope of Work, the Contracting Officer shall issue such changes.

52.24-403-70 Notice of Contractor Personnel Security Requirements (OCT 2005) Compliance with Homeland Security Presidential Directive-12 (HSPD-12) and Federal Information Processing Standard Publication 201 (FIPS 201) 1 entitled "Personal Identification Verification (PIV) for Federal Employees and Contractors," Phase I.

1. Long-Term Contractor Personnel:

In order to be compliant with HSPD-12/PIV I, the following investigative requirements must be met for each new long-term (2) contractor employee whose background investigation (BI) process begins on or after October 27, 2005:

a. Contractor Personnel must present two forms of identification in original form prior to badge issuance (acceptable documents are listed in Form I-9, OMB No. 1615-0047, "Employment Eligibility Verification," and at least one document must be a valid State or Federal government-issued picture ID);

b. Contractor Personnel must appear in person at least once before a DOJ official who is responsible for checking the identification documents. This identity proofing must be completed sometime during the clearance process but prior to badge issuance and must be documented by the DOJ official;

c. Contractor Personnel must undergo a BI commensurate with the designated risk level associated with the duties of each position. Outlined below are the minimum BI requirements for each risk level:

###High Risk - Background Investigation (5 year scope) ###Moderate Risk - Limited Background Investigation (LBI) or Minimum Background Investigation (MBI) ###Low Risk - National Agency Check with Inquiries (NACI) investigation

d. The pre-appointment BI waiver requirements for all position sensitivity levels are a:

1) Favorable review of the security questionnaire form;

2) Favorable fingerprint results;

3) Favorable credit report, if required;3

4) Waiver request memorandum, including both the Office of Personnel Management schedule date and position sensitivity/risk level; And

5) Favorable review of the National Agency Check (NAC) 4 portion of the applicable BI that is determined by position sensitivity/risk level. A badge may be issued following approval of the above waiver requirements.

If the NAC is not received within five days of OPM's scheduling date, the badge can be issued based on a favorable review of the Security Questionnaire and the Federal Bureau of Investigation Criminal History Check (i.e., fingerprint check results).

e. Badge re-validation will occur once the investigation is completed and favorably adjudicated. If the BI results so justify, badges issued under these procedures will be suspended or revoked.

2. Short-Term Contractor Personnel:

It is the policy of the DOJ that short-term contractors having access to DOJ information systems and/or DOJ facilities or space for six months or fewer are subject to the identity proofing requirements listed in items 1a. and 1b. above. The pre-appointment waiver requirements for short-term contractors are:

a. Favorable review of the security questionnaire form;

b. Favorable fingerprint results;

c. Favorable credit report, if required; (5) and

d. Waiver request memorandum indicating both the position sensitivity/risk level and the duration of the appointment. The commensurate BI does not need to be initiated. A badge may be issued following approval of the above waiver requirements and the badge will expire six months from the date of issuance. This process can only be used once for a short-term contractor in a twelve month period. This will ensure that any consecutive short-term appointments are subject to the full PIV-I identity proofing process. For example, if a contractor employee requires daily access for a three or four-week period, this contractor would be cleared according to the above short-term requirements. However, if a second request is submitted for the same contractor employee within a twelvemonth period for the purpose of extending the initial contract or for employment under a totally different contract for another three or four-week period, this contractor would now be considered "long-term" and must be cleared according to the long-term requirements as stated in this interim policy.

3. Intermittent Contractors:

An exception to the above-mentioned short-term requirements would be intermittent contractors.

a. For purposes of this policy, "intermittent" is defined as those contractor employees needing access to DOJ information systems and/or DOJ facilities or space for a maximum of one day per week, regardless of the duration of the required intermittent access. For example, the water delivery contractor that delivers water one time each week and is working on a one-year contract.

b. Contractors requiring intermittent access should follow the Department's escort policy. Please reference the August 11, 2004, and January 29, 2001, Department Security Officer policy memoranda that conveys the requirements for contractor facility escorted access.

c. Due to extenuating circumstances, if a component requests unescorted access or DOJ IT system access for an intermittent contractor, the same pre-employment background investigation waiver requirements that apply to short-term contractors are required.

d. If an intermittent contractor is approved for unescorted access, the contractor will only be issued a daily badge. The daily badge will be issued upon entrance into a DOJ facility or space and must be returned upon exiting the same facility or space.

e. If an intermittent contractor is approved for unescorted access, the approval will not exceed one year. If the intermittent contractor requires unescorted access beyond one year, the contractor will need to be re-approved each year.

4. An individual transferring from another department or agency shall not be re-adjudicated provided the individual has a current (within the last five years), favorably adjudicated BI meeting HSPD-12 and DOJ's BI requirements.

5. The DOJ's current escorted contractor policy remains unchanged by this acquisition notice.

Notes:

1. FIPS 201 is available at: www.csrc.nist.gov/publications/fips/fips201/FIPS-201-022505.pdf

2. Under HSPD-12, long-term contractors are contractors having access to DOJ information systems and/or DOJ facilities or space for six months or longer. The PIV-I identity proofing process, including initiation and adjudication of the required background investigation, is required for all new long-term contractors regardless of whether it is the current practice to issue a badge. The second phase of HSPD- 12 implementation (PIV-II) requires badge issuance to all affected long-term contractors.

3. For contractors in position sensitivity/risk levels above level 1, a favorable review of a credit check is required as part of the pre-appointment waiver package.

4. In order to avoid a delay in the hiring process, components should request an Advance NAC Report when initiating investigations to OPM. Per OPM ' s instructions, to obtain an Advance NAC Report, a Code " 3" must be placed in block " B " of the " Agency Use Only " section of the investigative form. This report is available for all case types.

5.For contractors in position sensitivity/risk levels above level 1, a favorable review of a credit check is required as part of the pre-appointment waiver package.

52.27-103-72 DOJ CONTRACTOR RESIDENCY REQUIREMENT BUREAU OF PRISONS (JUNE 2004)

For three of the five years immediately prior to submission of an offer/bid/quote, or prior to performance under a contract or commitment, individuals or contractor employees providing services must have:

1. Legally resided in the United States (U.S.);

2. worked for the U.S. overseas in a Federal or military capacity; or

3. been a dependent of a Federal or military employee serving overseas.

If the individual is not a U.S. citizen, they must be from a country allied with the U.S. The following website provides current information regarding allied countries:

http://www.opm.gov/employ/html/citizen.htm By signing this contract or commitment document, or by commencing performance, the contractor agrees to this restriction.

52.239-101 DOJ Residency Requirement - Information Technology (NOV 2008) Department of Justice (DOJ) Order 2640.2F prohibits the use of non-U.S. citizens in the performance of this contract or commitment for any position that involves access to or assisting in the development, operation, management, or maintenance of any DOJ Information Technology System. By signing this contract or by beginning performance, the contractor agrees to this restriction.

DJAR-PGD-15-03 Security of Department Information and Systems I. Applicability to Contractors and Subcontractors This clause applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of contractors, subcontractors, and CSPs (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information. It establishes and implements specific DOJ requirements applicable to this Contract. The requirements established herein are in addition to those required by the Federal Acquisition Regulation (“FAR”), including FAR 11.002(g) and 52.239-1, the Privacy Act of 1974, and any other applicable laws, mandates, Procurement Guidance Documents, and Executive Orders pertaining to the development and operation of Information Systems and the protection of Government Information. This clause does not alter or diminish any existing rights, obligation or liability under any other civil and/or criminal law, rule, regulation or mandate.

II. General Definitions The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.

A. Information means any communication or representation of knowledge such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. Information includes information in an electronic format that allows it be stored, retrieved or transmitted, also referred to as “data,” and “personally identifiable information” (“PII”), regardless of form.

B. Personally Identifiable Information (or PII) means any information about an individual maintained by an agency, including, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and information, which can be used to distinguish or trace an individual's identity, such as his or her name, social security number, date and place of birth, mother's maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual.

C. DOJ Information means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, Information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired in order to perform the contract.

D. Information System means any resources, or set of resources organized for accessing, collecting, storing, processing, maintaining, using, sharing, retrieving, disseminating, transmitting, or disposing of (hereinafter collectively, “processing, storing, or transmitting”) Information.

E. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information.

III. Confidentiality and Non-disclosure of DOJ Information A. Preliminary and final deliverables and all associated working papers and material generated by Contractor containing DOJ Information are the property of the U.S. Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Representative (“COR”) at the conclusion of the contract.

The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14.

B. All documents produced in the performance of this contract containing DOJ Information are the property of the U.S. Government and Contractor shall neither reproduce nor release to any third-party at any time, including during or at expiration or termination of the contract without the prior written permission of the CO.

C. Any DOJ information made available to Contractor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, Contractor assumes responsibility for the protection of the confidentiality of any and all DOJ Information processed, stored, or transmitted by the Contractor. When requested by the CO (typically no more than annually), Contractor shall provide a report to the CO identifying, to the best of Contractor’s knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed, stored, or transmitted under the Contract, including an estimate of the number of individuals for whom PII has been processed, stored or transmitted under the Contract and whether such information includes social security numbers (in whole or in part).

IV. Compliance with Information Technology Security Policies, Procedures and Requirements A. For all Covered Information Systems, Contractor shall comply with all security requirements, including but not limited to the regulations and guidance found in the Federal Information Security Management Act of 2014 (“FISMA”), Privacy Act of 1974, EGovernment Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, 199, and 200, OMB Memoranda, Federal Risk and Authorization Management Program (“FedRAMP”), DOJ IT Security Standards, including DOJ Order 2640.2, as amended. These requirements include but are not limited to:

1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise;

2. Providing security awareness training including, but not limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information Systems;

3. Creating, protecting, and retaining Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information;

4. Maintaining authorizations to operate any Covered Information System;

5. Performing continuous monitoring on all Covered Information Systems;

6. Establishing and maintaining baseline configurations and inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Information Systems;

7. Ensuring appropriate contingency planning has been performed, including DOJ Information and Covered Information System backups;

8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication methods where required;

9. Establishing an operational incident handling capability for Covered Information Systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and reporting incidents to appropriate officials and authorities within Contractor’s organization and the DOJ;

10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms, and personnel used to conduct such maintenance;

12. Protecting Covered Information System media containing DOJ Information, including paper, digital and electronic media; limiting access to DOJ Information to authorized users; and sanitizing or destroying Covered Information System media containing DOJ Information before disposal, release or reuse of such media;

13. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Information Systems to authorized U.S. citizens unless a waiver has been granted by the Contracting Officer (“CO”), and protecting the physical facilities and support infrastructure for such Information Systems;

14. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with DOJ Security standards;

15. Assessing the risk to DOJ Information in Covered Information Systems periodically, including scanning for vulnerabilities and remediating such vulnerabilities in accordance with DOJ policy and ensuring the timely removal of assets no longer supported by the Contractor;

16. Assessing the security controls of Covered Information Systems periodically to determine if the controls are effective in their application, developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in such Information Systems, and monitoring security controls on an ongoing basis to ensure the continued effectiveness of the controls;

17. Monitoring, controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Information Systems, and employing architectural designs, software development techniques, and systems engineering principles that promote effective security; and

18. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection from malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate action in response.

B. Contractor shall not process, store, or transmit DOJ Information using a Covered Information System without first obtaining an Authority to Operate (“ATO”) for each Covered Information System. The ATO shall be signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under this contract. The DOJ standards and requirements for obtaining an ATO may be found at DOJ Order 2640.2, as amended. (For Cloud Computing Systems, see Section V, below.)

C. Contractor shall ensure that no Non-U.S. citizen accesses or assists in the development, operation, management, or maintenance of any DOJ Information System, unless a waiver has been granted by the by the DOJ Component Head (or his or her designee) responsible for the DOJ Information System, the DOJ Chief Information Officer, and the DOJ Security Officer.

D. When requested by the DOJ CO or COR, or other DOJ official as described below, in connection with DOJ’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of DOJ Information, Contractor shall provide DOJ, including the Office of Inspector General (“OIG”) and Federal law enforcement components, (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Contractor’s facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by DOJ or agents acting on behalf of DOJ, and such access shall be provided within 72 hours of the request.

Additionally, Contractor shall cooperate with DOJ’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of DOJ Information.

E. The use of Contractor-owned laptops or other portable digital or electronic media to process or store DOJ Information covered by this clause is prohibited until Contractor provides a letter to the DOJ CO, and obtains the CO’s approval, certifying compliance with the following requirements:

1. Media must be encrypted using a NIST FIPS 140-2 approved product;

2. Contractor must develop and implement a process to ensure that security and other applications software is kept up-to-date;

3. Where applicable, media must utilize antivirus software and a host-based firewall mechanism;

4. Contractor must log all computer-readable data extracts from databases holding DOJ Information and verify that each extract including such data has been erased within 90 days of extraction or that its use is still required. All DOJ Information is sensitive information unless specifically designated as non-sensitive by the DOJ; and,

5. A Rules of Behavior (“ROB”) form must be signed by users. These rules must address, at a minimum, authorized and official use, prohibition against unauthorized users and use, and the protection of DOJ Information. The form also must notify the user that he or she has no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contractor-owned laptops or other portable digital or electronic media.

F. Contractor-owned removable media containing DOJ Information shall not be removed from DOJ facilities without prior approval of the DOJ CO or COR.

G. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with DOJ security requirements.

H. Contractor must keep an accurate inventory of digital or electronic media used in the performance of DOJ contracts.

I. Contractor must remove all DOJ Information from Contractor media and return all such information to the DOJ within 15 days of the expiration or termination of the contract, unless otherwise extended by the CO, or waived (in part or whole) by the CO, and all such information shall be returned to the DOJ in a format and form acceptable to the DOJ. The removal and return of all DOJ Information must be accomplished in accordance with DOJ IT Security Standard requirements, and an official of the Contractor shall provide a written certification certifying the removal and return of all such information to the CO within 15 days of the removal and return of all DOJ Information.

J. DOJ, at its discretion, may suspend Contractor’s access to any DOJ Information, or terminate the contract, when DOJ suspects that Contractor has failed to comply with any security requirement, or in the event of an Information System Security Incident (see Section V.E. below), where the Department determines that either event gives cause for such action. The suspension of access to DOJ Information may last until such time as DOJ, in its sole discretion, determines that the situation giving rise to such action has been corrected or no longer exists. Contractor understands that any suspension or termination in accordance with this provision shall be at no cost to the DOJ, and that upon request by the CO, Contractor must immediately return all DOJ Information to DOJ, as well as any media upon which DOJ Information resides, at Contractor’s expense.

V. Cloud Computing A. Cloud Computing means an Information System having the essential characteristics described in NIST SP 800-145, The NIST Definition of Cloud Computing. For the sake of this provision and clause, Cloud Computing includes Software as a Service, Platform as a Service, and Infrastructure as a Service, and deployment in a Private Cloud, Community Cloud, Public Cloud, or Hybrid Cloud.

B. Contractor may not utilize the Cloud system of any CSP unless:

1. The Cloud system and CSP have been evaluated and approved by a 3PAO certified under FedRAMP and Contractor has provided the most current Security Assessment Report (“SAR”) to the DOJ CO for consideration as part of Contractor’s overall System Security Plan, and any subsequent SARs within 30 days of issuance, and has received an ATO from the Authorizing Officialfor the DOJ component responsible for maintaining the security confidentiality, integrity, and availability of the DOJ Information under contract; or,

2. If not certified under FedRAMP, the Cloud System and CSP have received an ATO signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under the contract.

C. Contractor must ensure that the CSP allows DOJ to access and retrieve any DOJ Information processed, stored or transmitted in a Cloud system under this Contract within a reasonable time of any such request, but in no event less than 48 hours from the request. To ensure that the DOJ can fully and appropriately search and retrieve DOJ Information from the Cloud system, access shall include any schemas, meta-data, and other associated data artifacts. VI. Information System Security Breach or Incident A. Definitions

1. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any DOJ Information accessed by, retrievable from, processed by, stored on, or transmitted within, to or from any such system.

2. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed, Covered Information System Security Breach.

3. Security Incident means any Confirmed or Potential Covered Information System Security Breach.

B. Confirmed Breach. Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the DOJ CO and the CO's Representative (“COR”). If the Confirmed Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call DOJ-CERT at 1-866-US4-CERT

(1-866-874-2378) immediately (and in no event later than within 1 hour of discovery of the Confirmed Breach), and shall notify the CO and COR as soon as practicable.

C. Potential Breach.

1. Contractor shall report any Potential Breach within 72 hours of detection to the DOJ CO and the COR, unless Contractor has:

(a) completed its investigation of the Potential Breach in accordance with its own internal policies and procedures for identification, investigation and mitigation of Security Incidents and

(b) determined that there has been no Confirmed Breach.

2. If Contractor has not made a determination within 72 hours of detection of the Potential Breach whether an Confirmed Breach has occurred, Contractor shall report the Potential Breach to the DOJ CO and COR within one-hour (i.e., 73 hours from detection of the Potential Breach). If the time by which to report the Potential Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call the DOJ Computer Emergency Readiness Team (DOJ-CERT) at 1-866-US4-CERT (1-866-874-2378) within one-hour (i.e., 73 hours from detection of the Potential Breach) and contact the DOJ CO and COR as soon as practicable.

D. Any report submitted in accordance with paragraphs (B) and (C), above, shall identify (1) both the Information Systems and DOJ Information involved or at risk, including the type, amount, and level of sensitivity of the DOJ Information and, if the DOJ Information contains PII, the estimated number of unique instances of PII, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the USCERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by the DOJ. Contractor shall continue to provide written updates to the DOJ CO regarding the status of the Security Incident at least every three (3) calendar days until informed otherwise by the DOJ CO.

E. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident will be made by DOJ senior officials or the DOJ Core Management Team at DOJ’s discretion.

F. Upon notification of a Security Incident in accordance with this section, Contractor must provide to DOJ full access to any affected or potentially affected facility and/or Information System, including access by the DOJ OIG and Federal law enforcement organizations, and undertake any and all response actions DOJ determines are required to ensure the protection of DOJ Information, including providing all requested…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .