Draft SDAF SOW.pdf
PDF 390 KB Posted
- Attached to
- NCSES Secure Data Access Facility (SDAF) Federal contract opportunity
- Solicitation number
- 49100426Q0002
About this file
This Performance Work Statement (PWS) details a contract for the National Science Foundation's (NSF) National Center for Science and Engineering Statistics (NCSES) to maintain a Secure Data Access Facility (SDAF). The primary objective is to archive, maintain, disseminate, and provide secure remote access to restricted-use data from six scientific surveys, including the Early Career Doctorates Survey, Survey of Earned Doctorates, Survey of Doctorate Recipients, and others. The contractor will manage a secure digital environment where authorized researchers can access confidential microdata, using statistical software packages like SAS, Stata, SPSS, and R.
The contract is a Time & Materials agreement with a base period from 01/01/2026 to 12/31/2026, with a total budget of not-to-exceed $450,000 for researcher fees and $30,000 for the annual portal fee. Key contractor responsibilities include maintaining rigorous data confidentiality protocols, implementing robust cybersecurity measures, providing user support, managing an online licensing application, conducting disclosure reviews, and ensuring compliance with federal data protection regulations like the Privacy Act and CIPSEA. The contractor must have key personnel including a principal researcher with a doctorate and senior research scientists with master's degrees in statistics or social sciences, all with demonstrated experience in secure data management and statistical analysis.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SDAF - Sources Sought.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
2.0 Description of Services
2.1 Background
The National Center for Science and Engineering Statistics of the National Science Foundation (NSF, the Foundation), a Federal Statistical Agency, conducts surveys and other data collections and provides data and analyses about the nation’s activities and resources in science and engineering. It seeks to make these data available to a wide range of groups. Customers include government, education and industry officials and others engaged in funding, conducting, or managing R&D; science and engineering (S&E) education; the S&E workforce; or the reporting of issues related to science, engineering, and technology.
Data from the four abovementioned surveys contain individually identifiable information that are protected from disclosure by the Privacy Act of 1974, as amended; the Confidential Information Protection and Statistical Efficiency Act of 2002, Title V; and the National Science Foundation Act of 1950, as amended. Individually identifiable information includes any item, collection, or grouping of information pertaining to an individual including but not limited to, name, address, contact information, social security number, the individual’s education, financial transactions, or employment history. These statutes provide for the security and privacy of individually identifiable statistical data maintained by the NSF and the Federal Government. Sections of these laws make unlawful the disclosure or improper use of data containing individually identifiable information, and subject to a fine and/or imprisonment.
Other statutes may apply under certain circumstances, such as the Computer Fraud and Abuse Act of 1986, which makes it a felony to gain unauthorized access to a computer system containing Federal data, or to abuse the access one has, with the purpose of doing malicious destruction or damage.
Currently, NSF/NCSES provides access to data on scientists and engineers through publicly-available data tools, or as public-use microdata. Access to the restricted-use data is made available to authorized researchers through a data license. Licensees currently access this restricted-use data through the existing NCSES Secure Data Access Facility (SDAF).
The objective of this requirement is to:
To archive, maintain, disseminate and provide secure remote access to restricted-use data from the Early Career Doctorates Survey (ECDS), Survey of Earned Doctorates (SED), Survey of Doctorate Recipients (SDR), National Survey of College Graduates (NSCG), National Survey of Recent College Graduates (NSRCG) and Scientists and Engineers Statistical Data System (SESTAT) to authorized data users via remote access at a secure data access facility (SDAF) approved by the National Center for Science and Engineering Statistics. The SDAF will allow approved researchers to use standard statistical packages including but not limited to SAS, Stata, SPSS, R and Microsoft Office Suite, to analyze SED and SDR data via statistical methods including, but not limited to, hypothesis testing, regression, correlation analysis, and cross tabulations.
NSF is actively engaged in independent research projects pertaining to the provision of secure access to sensitive, confidential microdata. The NSF is committed to supporting research pertaining to the development and implementation of state-of-the-art processes by which approved researchers may access and manipulate sensitive data. The successful contractor must have staff available with expertise in building and supporting a secure environment for statistical agencies, foundations, and other organizations to deposit sensitive sets of microdata.
Furthermore, the contractor must have staff with expertise in confidentiality, disclosure review, researcher training, and outreach to the research and statistical communities. The SDAF will improve the capabilities of NSF to provide access to and increase the use of ECDS, SED, SDR, NSCG, NSRCG and potentially other NCSES survey data and expand the knowledge of and use of cutting edge tools and techniques that will be available. The SDAF contractor must have SAS, Stata, SPSS, R and Microsoft Office Suite at a minimum available for researchers.
Additional details on the surveys can be found here:
• Early Career Doctorates Survey: https://ncses.nsf.gov/surveys/early-career-doctorates/2017
• Survey of Earned Doctorates: https://ncses.nsf.gov/surveys/earned-doctorates/2024
• Doctorate Records File: Attachment F
• Survey of Doctorate Recipients: https://ncses.nsf.gov/surveys/doctorate-recipients/2023
• National Survey of College Graduates: https://ncses.nsf.gov/surveys/national-survey-college-graduates/2023
• National Survey of Recent College Graduates: https://ncsesdata.nsf.gov/recentgrads/2010/
• Scientists and Engineers Statistical Data System:
2.1.1 Purpose
The purpose of this requirement is to house and provide secure access to data and metadata from five NCSES surveys of individuals: 1) Early Career Doctorates Survey (ECDS), 2)Survey of Earned Doctorates (SED); 3) Survey of Doctorate Recipients (SDR); 4) National Survey of College Graduates (NSCG); and 5) National Survey of Recent College Graduates (NSRCG). Data from the SDR, NSCG and NSRCG are also available in the integrated Scientists and Engineers Statistical Data System (SESTAT) database. Additional surveys may be added to the contract as they are developed. The Contractor shall provide remote and secure access to these data via a Secure Data Access Facility (SDAF) as well as technical support to approved researchers [as defined by the National Science Foundation (NSF)] as well as National Center for Science and Engineering Statistics (NCSES) staff at NSF.
2.2 SCOPE
NCSES seeks contractor support for maintaining its remote secure data access facility (SDAF) for National Center for Science and Engineering Statistics (NCSES). NCSES uses the SDAF to allow approved researchers access to restricted use data in a secure virtual environment. The contractor shall be expected to maintain the infrastructure of the tool (e.g., keep hardware up to date, maintain annual software licenses), provide on-going technical support to researchers, and provide project management and reporting duties in support of the work, and expected to manage the online application system that researchers use to apply for the restricted-use data.
2.3 Statement of Work
2.3.1 Project Management
The contractor will provide project management to oversee the successful completion of all tasks in the statement of work.
https://ncsesdata.nsf.gov/recentgrads/2010/
2.3.1.1 Planning (roadmap)
Within 1 month after the contract has been awarded, the contractor must provide the Contracting Officer Representative (COR) a roadmap for this contract to include all of the tasks outlined below. The contractor will develop project-specific milestones and schedules. The contractor will provide written monthly progress reports to the COR on the status of NCSES’s desired milestones and goals. The contractor will provide quarterly and an annual virtual presentation to the COR and NCSES Leadership to outline past quarter/year outcomes and upcoming quarterly or yearly milestones and goals.
2.3.1.2 Risk management
The contractor will continue executing the existing risk management plan (provided by the COR), will maintain and review projects, schedules and resources, and will report risks to the COR on a monthly or time-sensitive basis that impact the overall project and how to avoid and/or correct it. The written monthly risk report must include identification of risks, an assessment of probability of occurrence and impact, risk management, and risk reporting and monitoring.
2.3.1.3 Documentation
The contractor will draft and maintain technical documentation for all products developed in this project. Documentation must be delivered with every major product release and approved by the NCSES
COR.
2.3.1.4 Communication management
NCSES will provide a communication plan that the contractor will implement. The communication plan outlines a communication protocol in at least the following areas: status meetings and reports, system documentation, system monitoring and reporting, and interacting and coordination with NCSES staff, contract-related personnel, and users of the SDAF environment, including those from additional agencies. As needed, the contractor will work with the COR and other key staff to suggest communication strategies to alert, inform, coordinate, update and brief NCSES staff, including Leadership, on any new or ongoing projects and initiatives.
2.3.1.5 Financial management, resources and procurement of hardware and software The contractor will manage the contract budget and maintain a detailed financial record of their costs.
The contractor will propose a financial management plan, including a proposal for a monthly financial report to the COR. The monthly financial report will include, at a minimum, the monthly break-down of the current and cumulative expenses and other direct costs for the entirety of the contract. The financial management reports will be incorporated in the monthly, quarterly, and year-end deliverables.
The contractor will work with the COR and NCSES staff to identify requirements and manage the procurement of software and services needed for this work. The contractor will also propose a resource plan, included in the proposal submission, that includes staffing and other resources needed to achieve milestones goals and known projects as of the contract start date.
2.3.1.6 Security Clearances
To ensure compliance with all data confidentiality requirements, including the Confidential Information Protection and Statistical Efficiency Act (CIPSEA) of 2018, all contractors with access to the SDAF and SCE will be required to become designated CIPSEA agents and take annual CIPSEA training. Additional security requirements for contractors may be necessary depending on the data used within the environment. The contractor will provide documentation of annual completion of security requirements to the COR.
2.3.1.7 Transition
The Contractor must coordinate an orderly transition of the Secure Data Access Facility project from the previous contractor during the time between award of this contract and expiration of the previous contract, for which the contract period is scheduled to end on December 31, 2025 .
The Contractor must:
(a) at the Contracting Officer’s Representative’s (COR’s) discretion, participate in five (5) or more meetings with the previous contractors to effect a smooth transition and to receive detailed information on the operation of SDAF and Secure Compute Environment;
(b) ensure receipt from the previous contractors or NCSES of complete documentation and all government furnished property, hardware, software, materials and data necessary to support continuation of full services, capabilities and outstanding technical and related work inherited from the previous contractors and promptly notify the COR of any omissions or deficiencies;
In addition, this task encompasses those planning and organizational efforts that lead to clear identification of the direction the project is heading and the activities encompassed by the project.
Project management includes internal Contractor management activities, as well as all forms of interaction and communication between the Contractor and NCSES.
2.3.2 Secure Data Access Facility
The Contractor will accomplish the following activities at a minimum to maintain the Secure Data Access Facility functions and capabilities.
2.3.2.1 Confidentiality Plan and Data Security Procedures (CPDSP) The data for inclusion in the SDAF includes but is not limited to surveys that collect and maintain personally identifiable information (name, address, date of birth) and confidential personal data (race, ethnicity, employment plans, salary, sources of educational support, etc.) that is collected under a pledge of confidentiality to respondents. In this statement of work, “individually identifiable information” refers to personally identifiable information and confidential personal data. Additional data may include linked datasets with survey, administrative, and third party or commercial data.
Therefore, handling of the NCSES data and other confidential data (“Data”) by the contractor will require special confidentiality protections be applied.
The Contractor must be responsible for protecting the confidentiality of Data about individuals, as required by the Privacy Act of 1974, the NSF Act of 1950 as amended, and the Confidential Information Protection and Statistical Efficiency Act (CIPSEA) of 2018. The Contractor must also be subject to all federal (e.g., Federal Information Security Management Act (FISMA), Federal Information Processing Standards (FIPS)), NSF, and NCSES policies on confidentiality protection, as specified by the NCSES Chief Statistician and the NCSES Confidentiality Officer, regarding Data storage and access, and Data dissemination and analysis in the SDAF12. These policies may change during the period of the contract.
1 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf 2 https://csrc.nist.gov/publications/detail/fips/200/final https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://csrc.nist.gov/publications/detail/fips/200/final
The Contractor must submit for review and approval by the COR, the NCSES Chief Statistician, and the NCSES Confidentiality Officer a detailed plan for protecting the security of Data in the SDAF (including all microdata and data files that are used as part of these Data), protecting the security of these Data when transferring/delivering confidential Data, protecting the confidentiality of the survey respondents, protecting the privacy of survey respondents among staff, protecting against disclosure of personally identifiable information (PII) for survey respondents, and documenting any other confidentiality and access issues for the Data.
This deliverable detailed plan will be called the Confidentiality Plan and Data Security Procedures (CPDSP) and must be submitted to the COR within one (1) month of contract award. The contractor must make responsive changes to the CPDSP and submit to the COR for approval within two weeks of receiving feedback on the CPDSP. The CPDSP should include :
• The security of the facility that will house the Data (including all microdata and data files that are used as part of these Data);
• The physical and environmental protections of the rooms in which the Data will be stored;
• Access control of the facility in which the Data are housed;
• Standards that address the physical and environmental protections for individuals who will access the Data remotely;
• Protections for the network on which the Data are housed;
• Authorization and access controls for the network on which the Data are housed;
• Network password requirements to access the network on which the Data are housed;
• Data use agreements;
• Data disclosure procedures and review;
The CPDSP must also include details on continuity plans, including a Contingency Plan (CP), a Disaster Recovery Plan (DRP), and a Continuity of Operations Plan (COOP) as described in Task 2.3.2.5. The contractor must update the CPDSP to reflect any changes in the NSF’s and OMB’s policies during the period of the contract. If necessary, the CPDSP can be modified at the discretion of and with approval from NCSES.
2.3.2.2 Physical Protection
Upon approval of the CPDSP by NCSES Chief Statistician, the contractor must implement procedures addressed in the CPDSP that protect the privacy of survey respondents for Data in the SDAF and protect against disclosure of individually identifiable information to unauthorized individuals. The contractor must strictly control access to individually identifiable information and ensure that only authorized personnel with a need to know will have access to such individually identifiable data.
The contractor must observe secure database maintenance practices and strict version control procedures and both these procedures should be documented in the CPDSP. The contractor must also document any new confidentiality and access issues that may arise that are not addressed in the CPDSP for the SDAF. The contractor must propose procedures for data protection and dissemination to address these issues and provide an updated CPDSP no later than one month after new issues are identified for approval by the NCSES Chief Statistician. NCSES has the right to conduct unannounced, unscheduled inspections of the Contractor’s site to assess compliance with the CPDSP.
2.3.2.3 Data Use Agreements
The Contractor must document and implement procedures to ensure that all Data under this contract will be protected from unlawful disclosure and that the Data will only be used for statistical purposes.
The contractor must make all staff working with individually identifiable data aware of the importance and requirements for maintaining confidentiality. A duly authorized representative of the Contractor’s organization with legal authority to bind the organization must sign the Organization Data Use Agreement (see Attachment C). ALL contractor staff (including any subcontractors) working on the Data must sign an NCSES Individual Data Use Agreement and Affidavit of Nondisclosure (see Attachments A and B) each year, acknowledging their responsibilities to protect the Data.
In addition, contractor staff using NCSES data will also be required annually to take NCSES-mandated training about data confidentiality. This training will be made available via the Internet or other media as approved by the NCSES Chief Statistician and the NCSES Confidentiality Officer.
The signed Data Use Agreement forms, certificates of completion for the confidentiality training, and the list of all signees must be delivered to NCSES within one month of award, and annually thereafter.
Before the Contractor receives any of the Data, these steps must be completed: 1) the CPDSP must be approved by NCSES, 2) the signed NCSES Data Use Agreements for Organizations and all individuals on the project must be received by the COR, and 3) staff must complete confidentiality training.
The Contractor must provide evidence that they have approval from their Institutional Review Board (IRB) or other legal authorities from their organization to conduct activities related to the use of these Data (i.e., they adhere to the requirements of their organization) before any actual Data can be provided to the Contractor. If the Contractor does not have an IRB, they must certify that they are following NSF’s Common Rule for the Protection of Human Subjects). 3
2.3.2.4 Data Disclosure Procedures and Review
The contractor must develop and submit an annual nondisclosure statement to the NCSES Chief Statistician for approval, documenting that all required staff have signed Data Use Agreements and attended confidentiality training and identifying all incidents of the disclosure of confidential Data. The COR will provide an example of a nondisclosure statement to the contractor for guidance. In addition, as part of its CPDSP, the Contractor must have an incident response plan (see OMB M-17-12, pp. 11-13) and further the contractor must notify the COR and the NCSES Chief Statistician in writing (electronic transmission is acceptable) within 1 hour of discovery of any unauthorized release of data with individually identifiable data to anyone other than persons who have signed NCSES Data Use Agreements. The contractor must submit a nondisclosure statement and statement of actual disclosures (should any occur) of Data to the Contracting Officer (CO), COR, and the NCSES Chief Statistician each December 30th during the contract period of performance and at the end of this contract.
2.3.2.5 Computer Processing and Security
All tasks requiring computer processing work must be conducted at the contractor's secure computer facility. The contractor must implement procedures to back up the Data on a regular basis and have a process for fast, secure recovery of archived Data to be approved by the COR. NCSES data cannot be
3 https://www.nsf.gov/bfa/dias/policy/docs/45cfr690.pdf https://www.nsf.gov/bfa/dias/policy/docs/45cfr690.pdf loaded onto a laptop computer or other removable device such as a thumb drive.
The contractor must maintain the SDAF data system servers in accordance with NSF's Implementation Policy for the Government Information Security Reform Act (Attachment D). This policy intends to ensure the integrity, confidentiality, authenticity, and non-repudiation of information and information systems supporting NCSES. The contractor must assist in the preparation of SDAF continuity plans as required by NSF and NCSES. These plans may include a Contingency Plan (CP), a Disaster Recovery Plan (DRP), and a Continuity of Operations Plan (COOP). The CP focuses on system or component disruptions, the DRP focuses on overall NSF disruptions, and the COOP focuses on maintaining business operations in the event of a catastrophic event. All of these plans must be documented as part of the CPDSP (see Task 2.3.2.1).
The contractor must follow the Federal Standards for Security (FIPS 140-2) (see Attachment E). Evidence of meeting this federal standard must also be documented in the CPDSP.
Because the SDAF will reside on the contractor’s servers, the contractor may have additional requirements of users, such as terms of use. The contractor must submit to the COR for approval within one month of contract award any additional terms of use. The contractor must not impose any additional terms of use on data users prior without obtaining approval of the CO and COR.
2.3.2.6 Survey Cycle Data Release
With approval from NCSES, the Contractor may receive access to Data for a new survey cycle that has not been publicly released. No release of any Data in any form for a new survey cycle is permitted until the COR issues an official release authorization to the Contractor. The Contractor must specify in the CPDSP and implement internal written procedures and policies to ensure that Data are not released before the official NCSES release date. Violation of this contract requirement is grounds for termination of the contract.
Even after Data for a survey cycle are approved for release by the COR, there are still limitations on the access to and use of the Data. The Contractor must follow the CPDSP as approved by NCSES. The Data are covered under a combination of the Privacy Act, NSF Act, and CIPSEA. As the manager for this system of records under the Privacy Act, the Director of NCSES is responsible for controlling access to the Data.
2.3.2.7 Maintain current versions of data for the SDAF
NCSES will provide current and complete versions of the SED, DRF, SDR, NSCG, NSRCG, EDCS, and SESTAT data files, documentation, and supplementary analysis files. The COR will provide additional files for these surveys when they are available. The DRF file is updated annually. The SDR and NSCG are updated biennially. The NSRCG, ECDS, and SESTAT have been discontinued, but should be stored and maintained within the SDAF. The COR may provide additional files for other surveys to be included in the SDAF during the period of performance. For proposal preparation purposes, the contractor may assume data from three additional surveys will be added.
2.3.2.8 Maintain the existing SDAF for housing and remote access for restricted-use NCSES data and additional Federal agency data The contractor will maintain the existing SDAF which will provide controlled access to confidential microdata to licensed users (“licensees”).
The contractor will provide access to NCSES data and other confidential data (including, but not limited to, data from other Federal agencies) within the SDAF as a service to licensees for a fixed period with the possibility of licensee renewal conditional on the data owner’s approval. The contractor support will include the following services:
• Account Administration
• System Usage
• Base Software Licensing and Licensing for Additional Software
• Use of Access Endpoint Hardware (if necessary)
• Technical Support and Disclosure Review
For budgeting purposes, NCSES expects the cost for each license to be approximately $3000 per year.
Access to the SDAF will be controlled by account IDs and passwords which meet NSF and NCSES standards.
The contractor must maintain existing training materials provided by NCSES for use of the SDAF. The contractor must make responsive changes to the training materials based on feedback from the COR and submit to the COR for approval within two weeks of receipt of feedback.
The contractor must maintain within the SDAF the existing, separate application for disclosure protection. This application allows researchers to deposit items for review and allow the COR and other authorized NCSES staff access to review. Upon COR approval of submitted materials, the contractor must release the materials to the researcher. The requirements for disclosure protection are provided in section 2.3.2.10.
2.3.2.9 SDAF Software
The facility will provide for each licensee: 2 gigabytes of storage space; 10 hours of technical support;
software, and any necessary hardware. The Contractor must make available to the licensees a complete suite of the most commonly used software (e.g., for word processing, spreadsheets, charting, presentations, statistical analysis (SPSS, SAS, R, SUDAAN)) for the analysis of the data and the writing up of results through the SDAF. In order to minimize the amount of raw output provided by the licensee to NCSES for review, and to maximize the presentation of final documents (in the form of presentations or journal articles), the SDAF must provide licensees with software that is reasonably needed to produce such final documents. Additional software (Tableau, Spark) may be needed as directed by the government.
Storage space provided for a specific license at the SDAF must be accessible to all users on the particular license even if the users are at different institutions. The SDAF will provide private work areas for each user under an individual license to share work and shared work areas for users and/or user groups across multiple licenses. The contractor must accommodate licensee requests for programs or documents from outside of the SDAF and place them within the individual’s workspace. The contractor must ensure the ability to securely partition project spaces to restrict access to groups of datasets by an approved set of users. The contractor must implement security controls to prevent insertion and removal of data and output from the environment by licensees without permission from designated individuals or data owners. Insertion of external data into project environments will be possible with the permission of government-designated individuals and update procedures for the requests for the future addition of non-NCSES data. The contractor must provide appropriate training for licensees on how to use the SDAF
2.3.2.10 SDAF User Capacity
The contractor must ensure the SDAF be initially designed to handle up to 150 users (not simultaneously). The COR may request the contractor to expand the SDAF to accommodate additional users.
2.3.2.11 Maintain on-line application for requesting, adding, and maintaining access to data in the
SDAF
Access to data in the SDAF requires a data license. The contractor must maintain the existing on-line application for researchers to submit license applications for access to and provisioning data in the SDAF. The COR may require the contractor to develop specifications for the application. At a minimum, NCSES expects it to include:
• Access to the requirements for obtaining a license (except for the security plan, requirements for which will depend on the technology used for access to the SDAF)
• Ability to submit a data requirements and a research plan for the researcher’s project
• Ability for licensees from different institutions to indicate that they would like a shared space for collaboration
• Ability for licensees to update their licenses (e.g. to request access to additional data, to add collaborating researchers, or to extend their license period)
• Ability to maintain a listing of all the proposed users on the license
• Access to the actual license document and forms for the licensee to download that the institution must send NSF after the analysis plan is approved and before researchers can access data in the SDAF.
• Ability for the COR and other authorized NCSES staff to access the submitted materials for review and approval.
• Upon approval by NCSES and the sponsoring agency, ability for the researcher to download the legal agreement for the appropriate signatures at the research institution and at NCSES.
The contractor must not give any user access to any data files until the license process is completed and the license is approved by the data owner.
In order to maintain the license, users must provide periodic feedback. The licensing application should allow for the following:
• An approval process to add new users to a license, or to remove existing users.
• Tracking of initial confidentiality training, updates, provisioned data sets and storage of documentation.
• The COR may require the contractor to update this licensing application if there are any changes to the licensing procedures required by the data owner.
2.3.2.12 Disclosure review of documents produced by licensees using data within the SDAF The contractor must conduct a review of all products and apply appropriate disclosure protection techniques. The COR will provide the appropriate technique(s) and parameters to protect the master data sets deposited in the SDAF under standard protocols and conditions. The contractor, in collaboration with the COR and working from current data owner guidance and in alignment with the CPDSP, will develop detailed disclosure avoidance specifications and submit them for approval to the COR within one month of receiving the techniques from the COR. The contractor must review tabulations that fall within standard protocols, the contractor must approve or reject the request and provide the reason for the actions within 1 business day or less of the submission. The contractor must maintain a record of all submissions and submit to the COR on a monthly basis.
The contractor must send any tabulations, analysis, or other research work that falls outside the standard protocols to the COR. The COR may request the contractor to provide recommendations for additional techniques for disclosure protection.
The contractor must maintain a running inventory of special situations and use it to suggest and develop improved disclosure specifications.
2.3.2.13 Documentation of the SDAF
The contractor must prepare and maintain separate technical documentation of the SDAF. This documentation must include technical specifications, information on the system architecture and any other information that will be required to facilitate the objectives of this project. Final documentation must be delivered to the COR for review one year prior to the end of the contract.
2.3.4 Secure Data Access Facility Support
In addition to creating the environment, we require the offeror to maintain the SDAF and provide customer support in establishing project spaces and supporting user access, user training, and “helpdesk” support.
2.3.5 System Support tasks
2.3.5.1 System Administration
The Contractor will, at a minimum, conduct the following activities to support the Secure Data Access Facility:
• Deploy system buildout/setup/updates, configuration changes, and patches.
• Maintain latest version/security patches on all software to be updated at least once a month.
• Support validation activities (testing/approving).
• Provide logging of user actions and production of audit logs to monitor suspicious behavior and security threats.
• Monitor system status and security scan results and respond as needed.
• Offerors should propose an approach that maximizes up time, including having a back-up system administrator.
2.3.6 Section 508 of Rehabilitation Act and general accessibility
Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-
220) requires that when federal agencies develop, procure, maintain, or use information and communication technology (ICT), it will be accessible to people with disabilities. Federal employees and members of the public who have disabilities must have access to, and use of, information and data that is comparable to people without disabilities.
Products, platforms and services delivered as part of this performance work statement that are ICT, or contain ICT, must conform to the Revised 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps.
A, C & D, and available at https://www.access- board.gov/guidelines-and-standards/communications-and-it/about-the-ict- refresh/final-rule/text-of-the-standards-and-guidelines.
2.4 Places of performance and work conditions/hours
The place of performance and work conditions and hours are to be determined by the Contractor. No work will be performed outside the United States, including accessing government data and email. Any government-provided equipment cannot be taken outside of the United States. The award will be for twelve (12) months. The period of performance is the time from award through 12/31/26. The base period will be from the time of award through the first 12 months.
2.5 Transition activities
To ensure the smooth transition-out of the project to a potential new contractor at the end of this contract, the contractor will develop and execute a COR approved transition-out plan for the project to a new contractor. This plan will be delivered 1 month before the expected end of the contract.
2.6 KEY PERSONNEL
The following labor categories are key personnel for this contract.
• Principal researcher - The minimum education requirement for the principal researcher is a doctorate degree in either information security statistics or a social science field (e.g., sociology, psychology). At the discretion of the contracting officer, specifically applicable years of experience, in the skills required, may be substituted for formal education. The principal researcher must have demonstrated experience in building and maintaining a confidential, secure data access environment. The principal researcher should possess demonstrated skills and/or knowledge in computer security, familiarity with federal regulations associated with data and computer security (e.g., Federal Information Processing Standards), database management, statistical confidentiality, and social science research principals.
• Senior research scientists - The minimum education requirement for the senior research scientists is a master’s level degree in either statistics or a social science field. These roles should have experience in conducting research, statistical confidentiality, statistical analysis, and data visualization. The skill sets related to these roles include conducting statistical analysis, expertise using statistical software and programming, reporting statistical results, and demonstrated skills using Microsoft Office.
• Senior statistical analyst - The minimum education requirement for the senior research scientists is a master’s level degree in either statistics or a social science field. These roles should have experience in conducting research, statistical confidentiality, statistical analysis, and data visualization. The skill sets related to these roles include conducting statistical analysis, expertise using statistical software and programming, reporting statistical results, and demonstrated skills using Microsoft Office.
Period Of Performance
Period of Performance Start End Base Period 01/01/2026 12/31/2026
Deliverable Schedule
Deliverable Reference Section Due Date Project Roadmap 2.3.1.1 Within 1 month after award Data Use Agreements 2.3.2.3 1 month after award Data Disclosure Procedures and Review
2.3.2.4 at the end of the contract
Any additional terms of use (if applicable)
2.3.2.5 within 1 month after award
Monthly Financial Reports 2.3.1.5 as agreed upon with COR Monthly Risk Reports 2.3.1.2 as agreed upon with COR Technical Documentation 2.3.1.3 as agreed upon with COR Maintain separate technical documentation of the SDAF
2.3.2.13 as agreed upon with COR
Transition-Out Plan 2.3.1.6 1 month prior to contract end
Contract Line Items and Contract Type
CLIN 001 (Time & Materials) Direct Labor Amount
CLIN 002 (Other Direct Costs) Not to exceed $450,000 for researcher fees and $30,000 for the annual portal fee
List of Attachments
• Attachment A: NCSES Individual Data Use Agreement
• Attachment B: NCSES Affidavit of Nondisclosure
• Attachment C: NCSES Organizational Data Use Agreement
• Attachment D: NSF Policy Regarding the Privacy of Sensitive Information
• Attachment E: FIPS Security Requirements (March 2006)
• Attachment F: Doctorate Record File Documentation
| 2.0 Description of Services |
| 2.1 Background |
| 2.3.1 Project Management |
| 2.3.1.1 Planning (roadmap) |
| 2.3.1.2 Risk management |
| 2.3.1.3 Documentation |
| 2.3.1.4 Communication management |
| 2.3.1.5 Financial management, resources and procurement of hardware and software |
| 2.3.1.6 Security Clearances |
| 2.3.1.7 Transition |
| 2.3.2.1 Confidentiality Plan and Data Security Procedures (CPDSP) |
| 2.3.2.2 Physical Protection |
| 2.3.2.3 Data Use Agreements |
| 2.3.2.4 Data Disclosure Procedures and Review |
| 2.3.2.5 Computer Processing and Security |
| 2.3.2.6 Survey Cycle Data Release |
| 2.3.2.7 Maintain current versions of data for the SDAF |
| 2.3.2.8 Maintain the existing SDAF for housing and remote access for restricted-use NCSES data and additional Federal agency data |
| 2.3.2.9 SDAF Software |
| 2.3.2.10 SDAF User Capacity |
| 2.3.2.11 Maintain on-line application for requesting, adding, and maintaining access to data in the SDAF |
| 2.3.2.12 Disclosure review of documents produced by licensees using data within the SDAF |
| 2.3.2.13 Documentation of the SDAF |
| 2.3.4 Secure Data Access Facility Support |
| 2.3.5.1 System Administration |
File details come from the government source that posted it. Updated .