DJJP-17-RFP-1022_Attachment_9.pdf

PDF 90 KB Posted

Attached to
Information Technology Support Services 5 (ITSS-5) Federal contract opportunity
Solicitation number
DJJP-17-RFP-1022
Issued by
Department of Justice Offices Boards and Divisions Justice Management Division

About this file

ITSS-5 Security Of Department Information and Systems

View the file

Other files for this federal contract opportunity

Other files attached to Information Technology Support Services 5 (ITSS-5), newest first.
File Type Posted
RFP_Section_Revisions_and_Clarifications_Information_05.22.17.pdf PDF
DJJP-17-RFP-1022_Amendment_0004_05.23.17.pdf PDF
DJJP-17-RFP-1022_Attachment_1_Amendment_0003.xlsx XLSX spreadsheet
DJJP-17-RFP-1022_Attachment_5_Amendment_0003.pdf PDF
DJJP-17-RFP-1022_Attachment_8_Amendment_0003.xlsx XLSX spreadsheet
DJJP-17-RFP-1022_Amendment_0003_05.11.17.pdf PDF
DJJP-17-RFP-1022_Attachment_9_Amendment_0003.pdf PDF
DJJP-17-RFP-1022_Attachment_6_Amendment_0003.doc DOC document
DJJP-17-RFP-1022_A001_Attachment_1.xlsx XLSX spreadsheet
DJJP-17-RFP-1022.pdf PDF
DJJP-17-RFP-1022_Attachment_2.pdf PDF
DJJP-17-RFP-1022_Attachment_7.pdf PDF
DJJP-17-RFP-1022_Attachment_8.xls XLS spreadsheet
DJJP-17-RFP-1022_Attachment_6.pdf PDF
DJJP-17-RFP-1022_Attachment_5.pdf PDF
DJJP-17-RFP-1022_Attachment_1.xlsx XLSX spreadsheet
DJJP-17-RFP-1022_Attachment_3.pdf PDF
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Solicitation: DJJP-17-RFP-1022 Attachment 9

SECURITY OF DEPARTMENT INFORMATION AND SYSTEMS

Applicability of Contractor and Subcontractors This clause applies to Contractor, all subcontractors, including any cloud service provider (“CSP”), and personnel of Contractor, subcontractors, and CSPs (hereinafter collectively, “Contractor”) that may access, retrieve, process, store, transmit, or dispose of DOJ Information. It establishes and implements specific DOJ requirements applicable to this Contract. The requirements established herein are in addition to those included in the Federal Acquisition Regulation (“FAR”), including FAR 11.002(g) and 52.239-1, the Privacy Act of 1974, and any other applicable laws, mandates, or Executive Orders pertaining to the development and operation of Information Systems and the protection of Government Information. This clause does not alter or diminish any existing rights, obligation or liability under any other civil and/or criminal law, rule, regulation or mandate.

General Definitions The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.

A. Information means any communication or representation of knowledge such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. Information includes information in an electronic format that allows it be stored, retrieved or transmitted, also referred to as “data,” and “personally identifiable information,” (“PII”), regardless of form.

B. Personally Identifiable Information (or PII) means any information about an individual maintained by an agency, including, but not limited to, information related to education, financial transactions, medical history, and criminal or employment history and information, which can be used to distinguish or trace an individual's identity, such as his or her name, social security number, date and place of birth, mother's maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual.

C. DOJ Information means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, Information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired in order to perform the contract.

D. Information System means any resources, or set of resources organized for the accessing, collecting, storing, processing, maintaining, using, sharing, retrieving, disseminating, transmitting, or disposing of (hereinafter collectively, “processing, storing, or transmitting”) Information.

E. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information.

Confidentiality and Non-disclosure of DOJ Information

A. Preliminary and final deliverables and all associated working papers and material generated by Contractor containing DOJ information are the property of the U.S.

Government and must be submitted to the Contracting Officer (“CO”) or the CO’s Representative (“COR”) at the conclusion of the contract. The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52.227-14.

B. All documents produced in the performance of this contract containing DOJ Information are the property of the U.S. Government and Contractor shall neither reproduce nor release to any third-party at any time, including during or at expiration or termination of the contract without the prior written permission of the CO.

C. Any DOJ Information made available to Contractor under this contract shall be used only for the purpose of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, Contractor assumes responsibility for protection of the confidentiality of any and all DOJ Information processed, stored or transmitted by the Contractor. When requested by the CO (typically no more than annually), Contractor shall provide a report to the CO identifying, to the best of Contractor’s knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed, stored, or transmitted under the contract, including an estimate of the number of individuals for whom PII has been processed, stored or transmitted under the contract and whether such information includes social security numbers (in whole or in part).

Compliance with Information Technology Security Policies, Procedures, and Requirements

A. For all Covered Information Systems, Contractor shall comply with all security requirements, including but not limited to the regulations and guidance found in the Federal Information Security Management Act of 2014 (“FISMA”), Privacy Act of 1974, E-Government Act of 2002, National Institute of Standards and Technology (“NIST”) Special Publications (“SP”), including but not limited to NIST SP 800-37, 800-53, and 800-60 Volumes I and II, Federal Information Processing Standards (“FIPS”) Publications 140-2, 199, and 200, OMB Memoranda, Federal Risk and Authorization Management Program (“FedRAMP”), DOJ IT Security Standards, including DOJ Order 2640.2, as amended. These requirements include, but are not limited to:

1. Limiting access to DOJ Information and Covered Information Systems to authorized users and to transactions and functions that authorized users are permitted to exercise;

2. Providing security awareness training including, but not limited to, recognizing and reporting potential indicators of insider threats to users and managers of DOJ Information and Covered Information Systems;

3. Creating, protecting, and retaining Covered Information System audit records, reports, and supporting documentation to enable reviewing, monitoring, analysis, investigation, reconstruction, and reporting of unlawful, unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information;

4. Maintaining authorizations to operate any Covered Information System;

5. Performing continuous monitoring on all such Covered Information Systems;

6. Establishing and maintaining baseline configurations and inventories of Covered Information Systems, including hardware, software, firmware, and documentation, throughout the Information System Development Lifecycle, and establishing and enforcing security configuration settings for IT products employed in Information Systems;

7. Ensuring appropriate contingency planning has been performed, including DOJ Information and Covered Information System backups;

8. Identifying Covered Information System users, processes acting on behalf of users, or devices, and authenticating and verifying the identities of such users, processes, or devices, using multifactor authentication or HSPD-12 compliant authentication methods where required;

9. Establishing an operational incident handling capability for Covered Information Systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities, and tracking, documenting, and reporting incidents to appropriate officials and authorities within Contractor’s organization and the DOJ;

10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms, and personnel used to conduct such maintenance;

11. Reserved.

12. Protecting Covered Information System media containing DOJ Information, including paper, digital and electronic media; limiting access to DOJ Information to authorized users; and sanitizing or destroying Covered Information System media containing DOJ Information before disposal, release or reuse of such media;

13. Limiting physical access to Covered Information Systems, equipment, and physical facilities housing such Covered Information Systems to authorized U.S. citizens unless a waiver has been granted by the Contracting Officer (“CO”), and protecting the physical facilities and support infrastructure for such Information Systems;

14. Screening individuals prior to authorizing access to Covered Information Systems to ensure compliance with DOJ Security standards;

15. Assessing the risk to DOJ Information in Covered Information Systems periodically, including scanning for vulnerabilities and remediating such vulnerabilities in accordance with DOJ policy and ensuring the timely removal of assets no longer supported by the Contractor;

16. Assessing the security controls of Covered Information Systems periodically to determine if the controls are effective in their application, developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabilities in such Information Systems, and monitoring security controls on an ongoing basis to ensure the continued effectiveness of the controls;

17. Monitoring, controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Information Systems, and employing architectural designs, software development techniques, and systems engineering principles that promote effective security; and

18. Identifying, reporting, and correcting Covered Information System security flaws in a timely manner, providing protection from malicious code at appropriate locations, monitoring security alerts and advisories and taking appropriate action in response.

B. Contractor shall not process, store, or transmit DOJ Information using a Covered Information System without first obtaining an Authority to Operate (“ATO”) for each Covered Information System. The ATO shall be signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under this contract. The DOJ standards and requirements for obtaining an ATO may be found at DOJ Order 2640.2, as amended.

(For Cloud computing systems, see Section 5.5, below.)

C. Contractor shall ensure that no Non-U.S. citizen accesses or assists in the development, operation, management, or maintenance of any DOJ Information System, unless a waiver has been granted by the DOJ Component Head (or his or her designee) responsible for the DOJ Information System, the DOJ Chief Information Officer, and the DOJ Security Officer.

D. When requested by the DOH CO or COR, or other DOJ official as described below, in connection with DOJ’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of DOJ Information, Contractor shall provide DOJ including the Office of Inspector General (“OIG”) and Federal law enforcement Components, (1) access to any and all information and records, including electronic information, regarding a Covered Information Systems, and (2) physical access to Contractor’s facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by DOJ or agents acting on behalf of DOJ, and such access shall be provided within 72 hours of the request. Additionally, Contractor shall cooperate with DOJ’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of DOJ Information.

E. The use of Contractor-owned laptops or other portable digital or electronic media to process or store DOJ Information covered by this clause is prohibited until Contractor provides a letter to the DOJ CO, and obtains the CO’s approval, certifying compliance with the following requirements:

1. Media shall be encrypted using a NIST FIPS 140-2 approved product;

2. Contractor must develop and implement a process to ensure that security and other applications software is kept up-to-date;

3. Where applicable, media shall utilize antivirus software and a host-based firewall mechanism;

4. Contractor must log all computer-readable data extracts from databases holding DOJ information and verify each extract including such data has been erased within 90 calendar days of extraction or that its use is still required. All DOJ Information is sensitive information unless specifically designated as non-sensitive by the Department; and,

5. A Rules of Behavior (“ROB”) form must be signed by users. These rules must address at a minimum: authorized and official use; prohibition against unauthorized users and use, and the protection of DOJ Information. The form also must notify the user that he or she has no reasonable expectation of privacy regarding any communications transmitted through or data stored on Contractor-owned laptops or other portable digital or electronic media.

F. Contractor-owned removable media containing DOJ Information shall not be removed from DOJ facilities without prior approval from the DOJ CO or COR.

G. When no longer needed, all media must be processed (sanitized, degaussed, or destroyed) in accordance with DOJ security requirements.

H. Contractor must keep an accurate inventory of digital or electronic media used on DOJ contracts.

I. Contractor must remove all DOJ Information from Contractor media and return all such information to the DOJ within 15 calendar days of the expiration or termination of the contract, unless otherwise extended by the CO, or waived (in part or whole) by the CO, and all such information shall be returned to the DOH in a format and form acceptable to the DOJ. The removal and return of all DOJ Information must be accomplished in accordance with DOJ IT Security Standard requirements, and an official of the Contractor shall provide a written certification certifying the removal and return of all such information to the CO within 15 calendar days of removal and return of all DOJ Information.

J. DOJ, at its discretion, may suspend Contractor’s access to any DOJ Information or terminate the contract, when DOJ suspects that Contractor has failed to comply with any security requirement, or in the event of an Information System Security Incident (see Section 5.6 below) where the Department determines that either event gives cause for such action. The suspension of access to DOJ Information may last until such time as DOJ, in its sole discretion, determines that the situation giving rise to such action has been corrected or no longer exists. Contractor understands that any suspension or termination in accordance with this provision shall be at no cost to the DOJ, and that upon request by the CO, Contractor must immediately return all DOJ information to DOJ, as well as any media upon which DOJ Information resides, at Contractor’s expense.

Cloud Computing

A. Cloud Computing means an Information System having the essential characteristics described in NIST SP 800-145, The NIST Definition of Cloud Computing. For the sake of this provision and clause, Cloud Computing includes Software as a Service, Platform as a Service, and Infrastructure as a Service, and deployment in a Private Cloud, Community Cloud, Public Cloud, or Hybrid Cloud.

B. Contractor may not utilize the Cloud system of any CSP unless:

1. The Cloud system and CSP have been evaluated and approved by a Third Party Assessing Organization (3PAO) certified under FedRAMP and Contractor has provided the most current Security Assessment Report (“SAR”) to the DOJ CO for consideration as part of Contractor’s overall System Security Plan, and any subsequent SARs within 30 calendar days of issuance; and has received an ATO from the Authorizing Official for the DOJ component responsible for maintaining the security confidentiality, integrity, and availability of the DOJ Information under contract; or,

2. If not certified under FedRAMP, the Cloud System and CSP have received and ATO signed by the Authorizing Official for the DOJ component responsible for maintaining the security, confidentiality, integrity, and availability of the DOJ Information under the contract.

C. Contractor must ensure that the CSP allows DOJ to access and retrieve any DOJ Information processed, stored or transmitted in a Cloud system under this Contract within a reasonable time of any such request, but in no event less than 48 hours from the request.

To ensure that the DOJ can fully and appropriately search and retrieve DOJ Information from the Cloud system, access shall include any schemas, meta-data, and other associated data artifacts.

Information System Security Breach or Incident

A. Definitions

1. Confirmed Security Breach (hereinafter, “Confirmed Breach”) means any confirmed unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any retrievable from, processed by, stored on, or transmitted within, to or from any such system.

2. Potential Security Breach (hereinafter, “Potential Breach”) means any suspected, but unconfirmed, Covered Information System Security Breach.

3. Security Incident means any Confirmed or Potential Covered System Security Breach.

B. Confirmed Breach. Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the DOJ CO and the CO’s Representative (“COR”). If the Confirmed Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call DOJCERT at 1-866-US4-CERT (1-866-874-2378) immediately (and in no event later than within 1 hour of discovery of the Confirmed Breach), and shall notify the CO and COR as soon as practicable.

C. Potential Breach.

1. Contractor shall report any Potential Breach within 72 hours of detection to the DOJ CO and the COR, unless Contractor has (a) completed its investigation of the Potential Breach in accordance with its own internal policies and procedures for identification, investigation and mitigation of Security Incidents and (b) determined that there has been no Confirmed Breach.

2. If Contractor has not made a determination within 72 hours of detection of the Potential Breach whether a Confirmed Breach has occurred, Contractor shall report the Potential Breach to the DOJ CO and COR within one-hour (i.e., 73-hours from detection of the Potential Breach). If the time by which to report the Potential Breach occurs outside of regular business hours and/or neither the DOJ CO nor the COR can be reached, Contractor must call the DOJ Computer Emergency Readiness Team (DOJ-CERT) at 1-866-US4-CERT (1-866-874-2378) within one-hour (i.e., 73 hours from detection of the Potential Breach) and contact the DOJ CO and COR as soon as practicable.

D. Any report submitted in accordance with paragraphs (B) and (C), above, shall identify(1) both the Information Systems and DOJ Information involved or at risk, including the type, amount, and level of sensitivity of the DOJ Information and, if the DOJ Information contains PII, the estimated number of unique instances of PII, the estimated number of unique instances of PII, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the US-CERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector migration details, and all available incident details; and (4) any other information specifically requested by the DOJ. Contractor shall continue to provide a written updates to the DOJ CO regarding the status of the Security Incident at least every three (3) calendar days until informed otherwise by the DOJ CO.

E. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident will be made by DOJ senior officials or the DOJ Core Management Team at the DOJ’s discretion.

F. Upon notification of a Security Incident in accordance with this section, Contractor must provide to DOJ full access to any affected or potentially affected facility and/or Information System, including access by the DOJ OIG and Federal law enforcement organizations, and undertake any and all response actions DOJ determines is required to ensure the protection of DOJ Information, including providing all requested images, log files, and event information to facilitate rapid resolution of any Security Incident.

G. DOJ, at its sole discretion, may obtain, and Contractor shall permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any Security Incident. Additionally, DOJ, at its sole discretion, may require Contractor to retain, at Contractor’s expense, a Third Party Assessing Organization (3PAO), acceptable to DOJ, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.

H. Response activities related to any Security Incident undertaken by DOJ, including activities undertaken by Contractor, other federal agencies, and any third-party contractors or firms at the request or direction of DOJ, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Incident and/or liability for any additional response activities.

Contractor shall be responsible for all costs and related resource allocations required for all such response activities related to any Security Incident, including the cost of any penetration testing.

Personally Identifiable Information Notification Requirement

By signing this contract, the Contractor certifies that it has a security policy in place that contains procedures to promptly notify any individual whose Personally Identifiable Information (“PII”) was, or is reasonably determined by DOJ to have been, compromised. Any notification shall be coordinated with the DOJ CO and shall not proceed until the DOJ has made a determination that notification would not impede a law enforcement investigation or jeopardize national security.

The method and content of any notification by Contractor shall be coordinated with, and subject to the approval of DOJ. Contractor shall be responsible for taking corrective action consistent with the DOJ Data Breach Notification Procedures and as directed by the DOJ CO, including all costs and expenses associated with such corrective action, which may include providing credit monitoring to any individuals whose PII was actually or potentially compromised.

Pass-through of Security Requirements to Subcontractors and CSPs

The requirements set forth in the preceding paragraphs of this clause apply to all subcontractors and CSPs who perform work in connection with this Contract, including any CSP providing services for any other CSP under this Contract, and Contractor shall flow down this clause to all subcontractors and CSPs performing under this contract. Any breach by any subcontractor or CSP of any of the provisions set forth in this clause will be attributed to Contractor.

Common Security Configurations in Information Technology (IT) Products and Services

(a) The provider of information technology shall certify applications are fully functional and operate correctly as intended on systems using the United States Government Configuration Baseline (USGCB)) defined by National Institute of Standards and Technology (NIST) at http://usgcb.nist.gov/ .

(b) The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved FDCC configuration. The information technology should also use the Windows Installer Service for installation to the default “program files” directory and should be able to silently install and uninstall.

(c) Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.

PERSONNEL SECURITY REQUIREMENTS – CLASSIFIED

(a) The work to be performed under this contract will involve access to classified information [National Security Information (NSI)] as well as access to unclassified information.

All references to “contract(or) personnel” and “contract employee” in this clause include all individuals that will perform under this contract, including individuals employed by the Contractor, team member, subcontractor, consultant, and/or independent contractor.

(b) The Contractor shall comply with the National Industrial Security Program Operating Manual (NISPOM) for all work performed under this contract that involves access to classified information.

(c) Duplication or disclosure of the data and other information (classified and unclassified) to which the Contractor may have access as a result of this contract is prohibited by Public Law and is subject to criminal penalties.

Contractor Personnel

(a) The type of security investigation required will be governed by the type of information made available to Contractor personnel. Contractor personnel that require access to classified information will be processed through the National Industrial Security Program (NISP). Contractor personnel that require access to unclassified information will be subject to a Public Trust Investigation (PTI). Except where specifically noted otherwise (e.g., 1.1.2.4(a)), the Government will be responsible for conducting the investigation and the cost of the investigation. All investigations will be conducted in accordance with applicable Executive Orders, DOJ Orders, Office of Personnel Management (OPM) guidance, Homeland Security Presidential Directive 12 (HSPD-12), and Federal Information Processing Standard Publication

201 (FIPS 201).

(b) PTI certifications will be accepted from other Federal agencies provided the investigation performed by the other agency meets or exceeds DOJ requirements.

(c) The Contractor will not be permitted to commence performance under this contract until a sufficient number of its personnel, as determined by the COR and Security Programs Manager (SPM), have received the requisite NSI Clearance or PTI security approval.

(d) During the life of the contract, the Contractor shall ensure that no contract employee commences performance hereunder prior to receipt of a written authorization from the Contracting Officer, the COR, or the SPM.

Access to Classified Information

(a) The Contractor shall possess or be capable of obtaining a Defense Industrial Security Clearance Office (DISCO) Defense Industrial Security Clearance Facility Code and a Top Secret Facility Clearance to fully perform this contract. As directed by the COR and SPM, the Contractor shall submit the information necessary to allow the Government to prepare and obtain for the Contractor a "Department of Defense Contract Security Classification Specification" (DD Form 254) for this contract. Where such clearance is required, the Contractor agrees to provide information and access to Contractor facilities as may be required by Government investigators.

(b) Immediately after contract award (or receipt of the required Facility Clearance), the Contractor’s Facility Security Officer (FSO) shall furnish to the COR a list of all personnel proposed to work under this contract who have been processed through the NISP by the Defense Security Service (DSS). The Contractor shall update this information as individuals are added or deleted from the contract and the FSO shall provide the updated list to the COR.

(c) For each contract employee that requires access to classified information under this contract, the Contractor shall forward a Visit Authorization Request (VAR) or a copy of the Joint Personnel Adjudication System (JPAS) Personnel Summary printout indicating the current background investigation information and clearance level.

Access to Unclassified Information

Note: Contractor personnel that have a currently active, approved NSI clearance will not be processed for a Public Trust Investigation (PTI) if the current investigation meets the investigative requirements for the risk level of the position to be occupied under this DOJ contract.

(a) Contractor personnel only requiring access to unclassified information will fall under the following categories:

(1) High Risk. High risk positions are those positions that have the potential for exceptionally serious impact on the integrity and efficiency of the DOJ and involve duties especially critical to the DOJ or a program mission with broad scope of policy or program authority.

(2) Moderate Risk. Moderate risk positions are those positions that have the potential for moderate to serious impact on the integrity and efficiency of the DOJ. Duties involved are very important to the DOJ or program mission with significant program responsibility or delivery of services.

(3) Low Risk. Low Risk positions are those positions that have limited potential for adversely affecting the national security operations of the Department.

Pre-Appointment Background Investigations and Waivers

(a) Background investigations must be conducted and favorably adjudicated for each contract employee prior to commencing work on this contract. However, where programmatic needs do not permit the Government to wait for completion of the entire background investigation, a pre-appointment background investigation waiver can be granted by the SPM, in consultation with the cognizant COR. The extent of the background investigation will vary depending upon the Risk Category associated with each position and whether each position is long- or short-term. Short-term is defined as contract employees having access to Federally-controlled information systems and/or unescorted access to Federally-controlled facilities or space for six months or fewer. The requisite background investigation does not need to be initiated for short-term positions as part of the pre-employment waiver except in the case of non-U.S. citizen contract employees. However, long-term contract employees requiring unescorted access to Federally-controlled facilities and/or access to any Federally-controlled information system shall be subject to the requisite background investigations described below.

A waiver will be disapproved if it develops derogatory information that cannot be resolved in the contract employee’s favor. When a waiver has been disapproved, the COR, in consultation with the SPM, will determine (1) whether the contract employee will no longer be considered for work on a DOJ contract or (2) whether to wait for the completion and favorable adjudication of the background investigation before the contract employee commences work on a Department contract. The minimum pre-appointment investigative requirements are as follows:

(1) High Risk Positions. The minimum background investigation required is a five year scope Background Investigation (BI), and the five year reinvestigation required is an Access National Agency Check with Inquiries (ANACI). The Standard Form (SF) 85P, Questionnaire for Public Trust Positions, is required.

(2) Moderate Risk Positions. The minimum background investigation required is a Minimum Background Investigation (MBI) for “moderate” impact on the integrity and efficiency of the DOJ or a Limited Background Investigation (LBI) for “serious” impact potential on the DOJ’s integrity and efficiency. The five year reinvestigation required is a National Agency Check with Law and Credit (NACLC). The SF-85P is required.

(3) Low Risk/Non-Sensitive Positions. The minimum background investigation required for Low Risk/Non-Sensitive positions is a National Agency Check with Written Inquiries (NACI) and the required five year reinvestigation is also a NACI. The SF-85, Questionnaire for Non-Sensitive Positions, is required.

(b) The pre-appointment background investigation waiver requirements include:

(1) Favorable review of the security questionnaire form;

(2) Favorable FBI fingerprint results;

(3) Verification of citizenship (copy of a birth certificate, Naturalization

Certificate, or U.S. Passport);

(4) Verification of compliance with the DOJ residency requirement;

(5) Favorable credit report for contract personnel in High Risk and Moderate

Risk positions; and

(6) Verification of the initiation of the appropriate background investigation for long-term Contractor personnel.

Required Security Forms

(a) The following forms must be completed and submitted by the Contractor’s Corporate Security Officer for each contract employee PTI:

(1) FD-258 Applicant Fingerprint Card. Two sets are required per applicant.

The Contractor may schedule appointments with the SPM to be digitally fingerprinted; otherwise, fingerprinting by the FBI is required. All pertinent information must be completed by the individual taking the prints, or by the FBI if prints are taken there.

(2) SF-85 Questionnaire for Non-Sensitive Positions -or- SF-85P Questionnaire for Public Trust Positions. The contract employee shall complete the SF-85/SF-85P via the Electronic Security Questionnaires for Investigations Processing (e-QIP) System after first obtaining access to e-QIP from the SPM (see paragraph (c) below). The Contractor shall also submit a hard copy of the form (as completed and signed by the contract employee) with the remainder of the security package.

(3) DOJ-555 Fair Credit Reporting Act Disclosure. Authorizes DOJ to obtain one or more consumer/credit reports on the individual. This is required for Contractor personnel in High Risk and Moderate Risk positions.

(4) Foreign National Relatives and Associates Statement. This is only required if any relatives listed on the SF-85/SF-85P are foreign nationals.

(5) Confidentiality Agreement for Contractor and Subcontractor Employee.

See Separate Section H clause for confidentiality requirements.

(b) The Contractor shall also submit a credit report for each individual designated at the High Risk or Moderate Risk level, and have resolved satisfactorily any individual credit issues.

(c) Using e-QIP. Immediately after contract award, the Contractor shall designate an employee as its “e-QIP Initiator” and provide the name of this person to the COR. The e-QIP Initiator must have, at a minimum, a favorably adjudicated MBI and the appropriate DOJ security approval before being given access to e-QIP. After the e-QIP Initiator’s security approval is granted, the Contractor will be configured in e-QIP as a sub-agency to DOJ. The Contractor will then be responsible for initiating all contract personnel in e-QIP for completion of the security questionnaire form and forwarding the electronic form along with a hard copy of the form (as completed and signed by the contract employee) with the remainder of the security package to the designated DOJ representative. Subject to the prior approval of the SPM, the Contractor may designate an e-QIP Initiator for each subcontractor. Subcontractor e-QIP Initiators must have, at a minimum, a favorably adjudicated MBI and the appropriate DOJ security approval before being given access to e-QIP.

Citizenship and Residency Requirements

(a) Residency Requirement. Contract employees, both United States (U.S.) citizens and non-U.S. citizens, must meet the Department’s Residency Requirement, i.e., he/she must have lived in the U.S. three of the last five years immediately prior to employment under the Department contract; and/or worked for the U.S. overseas in a Federal or military capacity;

and/or be a dependent of a Federal or military employee serving overseas. At the Department’s sole discretion, the residency requirement may be waived by the Department Security Officer (DSO) on a case-by-case basis where justified by extenuating circumstances.

(b) Citizenship. The DOJ gives strong priority to contract employees that are U.S.

citizens and nationals. Any prospective contract employee that is a foreign national must be from a country allied with the U.S. (See http://www.opm.gov/employ/html/Citizen.htm). At the Department’s sole discretion, a waiver of the allied nations list requirement may be granted by the DSO on a case-by-case basis where justified by extenuating circumstances. The Contractor is responsible for verifying that all non-U.S. citizens working under this contract have been lawfully admitted to the U.S. Contract employees requiring access to DOJ Information Technology (IT) resources are subject to the following additional restriction:

Non-U.S. citizens are not authorized access to or permitted to assist in the development, operation, management or maintenance of DOJ IT systems unless a waiver has been granted by the Head of the DOJ component, with the concurrence of the DSO and the DOJ Chief Information Officer (CIO). Such a waiver will be granted only in exceptional and unique circumstances. It should be noted that the Justice Consolidated Office Network (JCON) is a sensitive “DOJ IT system” and any contract employee that will need access to JCON must be a U.S. citizen or have received a waiver.

(c) Dual Citizenship. U.S. citizens who hold dual citizenship with a foreign country may be considered for contract employment. However, how the contract employee obtained or exercises his or her dual citizenship status will be a consideration in the adjudication process.

Procedures for Pre-Screening Applicants and Investigation

(a) The Contractor shall perform the following pre-screening and investigation duties for all persons proposed for work under this contract:

(1) Furnish to each proposed contract employee the forms described in

Section 1.1.2.2 above and ensure that adequate instructions for completing the forms are provided to each applicant.

(2) Ensure that applicants obtain two (2) complete sets of their fingerprints on the prescribed Form FD-258 from an organization qualified to take fingerprints.

(3) Collect completed forms from each applicant and review all forms for completeness and correctness. This includes, for example, satisfactory resolution of address issues or discrepancies. Return any incomplete or incorrect form(s) to applicant(s) to be corrected and re-submitted.

(4) Submit completed forms to the COR by no later than (14) calendar days after receipt of the blank forms and access to e-QIP has been initiated.

(5) As directed by the COR, initiate pre-appointment waivers for certain positions. This may entail performing credit history checks and submission of these checks as part of the security package, including satisfactory resolution of any issues prior to submission to the Government.

(6) As directed by the COR, review all forms prior to their being submitted to DOJ to ensure that candidates meet DOJ requirements, including residency and citizenship requirements.

(b) The Department will be responsible for the following:

(1) Determine the appropriate risk level for each contract employee position.

(2) Provide the Contractor an adequate supply of forms and instructions for completing the forms within five business days after contract award. Ensure that the Contractor is provided access to the e-QIP system as described in 1.1.2.2(c).

(3) Ensure that completed security forms are forwarded to the appropriate investigating agency in accordance with appropriate internal procedures. The investigating agency will conduct the requisite investigations.

(4) Determine whether pre-appointment background investigation waivers will be needed, and if so, which positions will require such waivers. The COR will notify the Contractor which pre-appointment waivers to initiate.

(5) Notify the Contractor of the results of background investigations as they are completed and adjudicated. The COR will notify the Contractor of any applicants who are found ineligible for employment security approval so that the Contractor can immediately recruit and initiate paperwork to clear replacement applicants.

(6) Notify the Contracting Officer when a sufficient number of contract employees have received employment security approvals or pre-appointment waivers approvals. Upon receipt of this information and any other information which may be required elsewhere in the contract, the Contracting Officer will issue the Contractor a Notice to Proceed which permits the commencement of work under the contract.

(7) Maintain an up-to-date file of Certificates of Investigation (COI) and other background investigation-related documentation for all contract employees throughout the life of the contract.

(c) The investigating agency will furnish the relevant SPM the results of each proposed contract employee’s investigation through issuance of a Certificate of Investigation (COI). Upon receipt of the COI and any other pertinent documents from the investigating agency, the SPM will determine whether or not each proposed contract employee should be granted employment security approval. This decision process is called “adjudication.” The SPM will notify, if required, the investigating agency of the adjudicative determination of each investigation. If OPM is the investigating agency, this will be accomplished by the SPM completing and submitting to OPM an INV Form 79A, “Report of Agency Adjudicative Action.”

Identity Proofing and Badging

(a) During the life of this contract, the right to unescorted access to Federally-controlled facilities and/or access Federally-controlled information systems shall be made available after the contract employees have (1) met the identity proofing requirements outlined below, and (2) completed all other security requirements stated elsewhere in this contract. During all operations on Government premises, the contract employees shall comply with the rules and regulations governing the conduct of personnel and the operation of the facility. The Government reserves the right to require contract employees to "sign-in" upon entry and "sign-out" upon departure from the DOJ facility.

(b) All contract employees requiring unescorted access to Federally-controlled facilities and/or access to Federally-controlled information systems (regardless of whether they will be issued a DOJ badge), shall comply with the identity proofing and registration requirements outlined below:

(1) Contract employees must present two forms of identification in original form prior to commencement of work under this contract and badge issuance

(acceptable documents are listed in Form I-9, OMB No. 1615-0047, “Employment Eligibility Verification,” and at least one document must be a valid State or Federal government-issued picture ID);

(2) Contract employees must appear in person at least once before a DOJ official who is responsible for checking the identification documents. This identity proofing must be completed prior to commencement of work under this contract and badge issuance (as applicable), and must be documented by the DOJ official.

(c) All contract employees requiring unescorted access to a DOJ controlled facility shall comply with the badge requirements outlined below:

(1) When any Contractor employees enter a DOJ building for the first time, the contract employees shall allow one hour for security processing and the fabrication of buildings access badges.

(2) Building access badges shall be subject to periodic review by the Contractor's Supervisor and checked against the employee's personal identification. The contract employees shall present themselves for the issuance of renewed badges when required by the Government as scheduled by the COR or his designee. The Contractor shall notify the COR when employee badges are lost, and must immediately apply for reissuance of a replacement badge. The Contractor shall pay for reissued building access badges. It is the Contractor's responsibility to return badges to the COR or his designee when a contract employee is dismissed, terminated or assigned to duties not within the scope of this contract.

Replacement Personnel

(a) Security investigations are very costly to the Government. The Contractor shall make every effort to preclude incurrence of costs by the Government for security investigations for replacement of employees, and in so doing, shall assure that otherwise satisfactory and physically able employees assigned hereunder remain in contract performance for at least one (1) year. The Contractor shall take all necessary steps to assure that Contractor personnel who are selected for assignment to this contract are professionally qualified and personally reliable, of reputable background and sound character, and meet all other requirements stipulated herein.

(b) The fact that the Government performs security investigations shall not in any manner relieve the Contractor of its responsibility to assure that all personnel furnished are reliable and of reputable background and sound character. Should a security investigation conducted by the Government render ineligible a Contractor furnished employee, the Contracting Officer will investigate the cause and determine whether the Contractor has abdicated its responsibilities to make every effort to select reliable employees of reputable background and sound character. Should there be need to replace a contract employee due to nonperformance, the Contracting Officer will determine whether the Contractor has abdicated its responsibilities to make every effort to select trained and experienced employees.

(c) Should the Contracting Officer determine that the Contractor has failed to comply with the terms of Section 1.1.2.4(a), the Contractor may be held monetarily responsible, at a minimum, for all reasonable and necessary costs incurred by the Government to (a) provide coverage (performance) through assignment of individuals employed by the Government or third parties in those cases where absence of Contractor personnel would cause either a security threat or DOJ program disruption and (b) conduct security investigations in excess of those which would otherwise be required.

(d) Nothing in this Clause shall require the Contractor to bear costs involved in the conduct of security investigations for replacement of an employee who becomes deceased or severely ill for a long period of time.

(e) Acceptance by the Government of consideration to which the Government may be entitled pursuant to paragraph (c) above shall not be construed to establish a course of conduct which will serve to limit the rights and remedies otherwise available to the Government. Under no circumstances shall the Contractor fail to comply with the terms and conditions set forth herein without assuming liability for such failure as may be established pursuant to this Clause.

The rights and remedies conferred upon the Government by this Clause are in addition to all and other rights and remedies specified elsewhere in this contract or established by law.

Contractor Facility

(a) The Contractor shall implement physical controls as necessary to maintain the integrity and confidentiality of all data/information in its possession. At a minimum, the following requirements shall be in effect for Contractor controlled spaces where information is processed and/or stored:

(1) Access to the facility shall be limited to Contractor personnel or those escorted by Contractor personnel.

(2) Document/media storage areas shall be restricted to persons requiring access to them on a need-to-know basis and have a security access approval or clearance granted by the DOJ.

(3) All areas designated for the storage of Grand Jury information require locked entrances and exits during non-working hours or a steel file cabinet that can be secured with a steel lock-bar and a General Services Administration approved changeable combination padlock, or its equivalent. Grand Jury information containing other types of sensitive information such as Federal Tax Return information, witness security information, and other types of highly sensitive information that have more stringent security requirements shall be stored and protected pursuant to security regulations governing such information and special security instructions provided by the organization originating the information.

Grand Jury information containing classified NSI must be handled, processed, and stored in accordance with Executive Order 12958, as amended, or its successor.

(4) All designated storage areas/containers must be made available for inspection upon initial award of a contract and semiannually or as otherwise directed by the SPM, COR or COR designee.

(b) When Grand Jury information is in actual use by authorized personnel, it shall be protected as follows:

(1) Kept under constant review by an authorized person who is in a physical position to exercise direct security controls over the material;

(2) Covered, turned face down, placed in storage containers, or otherwise protected when unauthorized persons are present;

(3) The room containing the materials must be locked when vacated for short periods of time; and

(4) Returned to storage containers/areas as soon as practical after use.

Automation Equipment and Media Materials

(a) At the conclusion of the contract period, all media materials used in conjunction with this contract shall be turned in to the DOJ for destruction. This includes not only paper records, but also all removable, "consumable" media such as floppy disks, magnetic tapes, typewriter ribbons, CD-ROMs, DAT tapes, etc. Any of these media materials that become defective during contract performance shall be immediately turned in to the DOJ for destruction. The Government will not compensate the Contractor for the costs of these media materials.

(b) At the conclusion of the contract period, the Contractor shall…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .