Draft SOW - NCSES License Data Security Inspections and ISSO Services.pdf

PDF 263 KB Posted

Attached to
NATIONAL CENTER FOR SCIENCE AND ENGINEERING STATISTICS DATA SECURITY INSPECTIONS AND ISSO SERVICES Federal contract opportunity
Solicitation number
49100424K0013
Issued by
National Science Foundation Division of Acquisition and Cooperative Support

About this file

This statement of work outlines requirements for data security inspection and information system security officer services. The National Center for Science and Engineering Statistics seeks a contractor to perform periodic on-site inspections of licensee sites handling restricted-use data and review data security plans. The contractor must also maintain a license documentation system and provide information system security officer support. Key requirements include conducting 75-75-75 inspections annually over three years, reviewing 50 security plans annually, scanning license documents and storing them securely, identifying data classification levels, and ensuring systems compliance. The period of performance is one base year with two optional years. The primary place of performance is the contractor's facilities. Monthly progress reports and meetings are required.

View the file

Other files for this federal contract opportunity

Other files attached to NATIONAL CENTER FOR SCIENCE AND ENGINEERING STATISTICS DATA SECURITY INSPECTIONS AND ISSO SERVICES, newest first.
File Type Posted
Sources Sought - NCSES License Data Security Inspection and ISSO Services.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work NCSES License Data Security Inspections and ISSO Services

Contract Type: Firm-Fixed Price

1.0 PURPOSE

The National Center for Education Statistics (NCES), through its contractors, shall provide data security support services to the National Center for Science and Engineering Statistics (NCSES) of the National Science Foundation (NSF) by performing periodic, on-site inspections of selected NSF/NCSES licensee sites where researchers have licensing agreements for NSF/NCSES restricted-use data files and reviews of data security plans submitted by the licensure applicants. Federal Agencies use the term “restricted-use data” when data contain individually identifiable information or data are collected under a pledge of confidentiality. Strict security procedures are required to protect restricted-use data. Data security support services ensure that adequate safeguards are in place by licensees to prevent misuse or release of such information.

2.0 BACKGROUND

The security procedures used to protect restricted use data are based on the Privacy Act of 1974, as amended; the Foundations for Evidence-Based Policymaking Act of 2018; and the National Science Foundation Act of 1950, as amended. These statutes provide for the security and privacy of restricted use data collected by the NSF and other Federal Agencies. Sections of these laws make unlawful the disclosure or improper use of restricted-use data, and subject to a fine and/or imprisonment. Other statutes may apply under certain circumstances, such as the Computer Fraud and Abuse Act of 1986, which makes it a felony to gain unauthorized access to a computer system containing Federal data, or to abuse the access one has with the purpose of doing malicious destruction or damage.

3.0 AUTHORITY

The authority to issue data licenses and to conduct inspections is provided by the National Science Foundation Act of 1950, as amended, 42 U, S. C. Sections 1862, 1864, and 1870 and CIPSEA.

3.1 RESPONSIBILITIES

1. NCSES is responsible for providing a complete list of licensees and their sites that will need to be inspected. NCSES will update the list as licensees are added or deleted. NCSES will specify any license that it views as problematic and a high priority for inspection.

2. NCSES will provide data security plans needing review on a flow basis.

3. NCSES is responsible for providing all licensing materials (i.e. applications, amendments) directly to the data security contractor for storage and conversion to a digital medium.

4. NCES will ensure the number of inspections and data security plan reviews are completed based on the specifications under Section 4.0 Scope of Work are completed.

4.0 SCOPE OF WORK

Task 1: Data Security Inspections

The contractor shall:

a. Perform data security and compliance inspections on NCSES licensees from 3/1/2024 through 8/31/2027 The contractor will notify the NCSES Data Licensing Coordinator of the geographical location of each inspection and:

1.1.1 Review and determine whether all security procedures as prescribed in the NSF/NCSES

“Restricted-Use Data Procedures Guide” have been implemented or honored by the licensee.

1.1.2 Review and verify data handling procedures, verify that all persons having access to restricted-use data have executed affidavits (oaths of non-disclosure), and note any exceptions. Evidence of compliance or violation of the terms of the agreement and security procedures shall be forwarded to the NCSES Chief Statistician for review and appropriate action.

b. Perform data security and compliance inspections during each contract year as follows:

1.2.1. 75 data security and compliance inspections during base year: 3/1/2024-2/28/2025

1.2.2. 75 data security and compliance inspections during optional year 1: 3/1/2025-

2/28/2026

1.2.3 75 data security and compliance inspections during optional year 2: 3/1/2026-

2/28/2027

Task 2: Deliverable for Data Security Inspections

Provide in electronic format, within two weeks of an inspection, a site inspection report.

Task 3: Data Security Plan Reviews

The contractor shall:

3.1 Review and determine whether the licensee’s security plan includes the appropriate steps/procedures as prescribed in the NSF/NCSES “Restricted-Use Data Procedures Guide.”

3.2 Review and approve security plan documentation submitted by potential licensees prior to the formulation and submission of all required license documents to the NCSES Data Licensing Coordinator.

3.3 Perform up to 50 data security plan reviews in the base year and each subsequent optional year.

Task 4: Deliverable for Data Security Plan Review

Provide in electronic format, within 14 calendar days of receiving security plan procedures, a report documenting the findings to the NCSES data coordinator.

Task 5: License Documentation System (LDS) Support Services

5.1 The contractor shall maintain and continue to update the License Documentation System (LDS) that converts paper license documents using high resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text, in the form of electronic Acrobat PDF files that simulate the original license document forms. These PDF files will have the advantage of being keyword-searchable and fully secure. The system will allow for easy exportability and will allow for data conversion to alternative file systems according to NCSES needs (see further details below).

The Government owns the LDS software and contents. The contractor shall convert paper license documents using high-resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text files that are accessible across standard software platforms. The contractor must maintain a system that produces a customized electronic archiving solution by using data imaging to scan the paper files and by converting them into electronic PDF files. The resulting PDF files simulate the original document format, but the contractor shall ensure that they are keyword-searchable, fully secure, and have backwards compatibility with legacy systems while maintaining simple upgradability.

Every month, an authorized contractor employee shall pick up paper license documents in person, convert them into PDF files, and deliver the .pdfs of the licenses on a CD to NCSES.

5.2 The contractor shall provide secure off-site office space for systematic storage of license documents after they have been scanned into the LDS. The office space shall: a) be an office room approximately 20 feet by 20 feet in width and depth; b) have least seven (7) four (4) drawer fire proof cabinets; c) have 24-hour CCTV monitoring (Non-IP access) seven (7) days per week; d) in house DVR recording and monitored by contract cleared personnel only; e) first floor office must be windowless and second and above must have at a minimum 8mm blast proof glass film on all windows; f) steel interior office entrance door; g) interior walls run to ceiling above and do not stop at ceiling tile height; and h) the room and office should have an alarm system installed (including window sensors and motion detectors). The government needs to have easy accessibility to the physical data storage for monitoring purpose. The secure off-site office shall be located within 50 miles from the NCSES office. The site should be ready at the time of the award and the COR reserves the right to inspect the facility and room.

Task 6: Continued ISSO Services

The contractor will provide both project management and technical support for reviewing, assessing, and documenting the security of NCSES’s IT systems. Using their expertise in these domains and working with internal and external stakeholders, the contractor shall:

1. Identify which NCSES data sets fall under what level of sensitivity from a security standpoint. Please note that the ISSO must be familiar with the federal standards associated with these various classifications.

2. Identify what kinds of protections are necessary for NCSES to put into place based on the aforementioned classification.

3. Be able to audit NCSES IT systems and interfaces that have access to the data to ensure compliance with federal regulations based on #2.

4. Ability to coordinate multiple stakeholder interests in this type of work. For example, in addition to working within NCSES, the ISSO would need to work with NSF IT organizations.

5. Be capable of collaborating (e.g., some writing, reviewing or work) with contractors and staff towards the development of a data system security plan.

Task 7 (Optional): Conduct inspections of NCSES’s Contractor’s Sites

The contractor shall:

Perform data security and compliance inspections on NCSES’s data collection contractor’s sites from 3/1/2024 through 2/28/2027. The contractor will notify the NCSES Data Licensing Coordinator of the geographical location of each inspection and:

1.1.3 Review and determine whether all security procedures as prescribed in the contractor’s data security plan have been implemented or honored by the licensee.

1.1.4 Review and verify data handling procedures, verify that all persons having access to restricted-use data have signed data-use agreements, and note any exceptions. Evidence of compliance or violation of the terms of the agreement and security procedures shall be forwarded to the NCSES Chief Statistician for review and appropriate action.

c. Perform data security and compliance inspections during each contract year as follows:

1.2.1. 37 data security and compliance inspections during base year: 3/1/2024-2/28/2025

1.2.2. 37 data security and compliance inspections during optional year 1: 3/1/2025-

2/28/2026

1.2.3 37 data security and compliance inspections during optional year 2: 3/1/2026-

2/28/2027

5.0 REPORTING OF DATA SECURITY BREACHES

If there is a suspected or known breach/disclosure of PII due to lost, theft, intercepted transfer, or other, the contractor must ensure that this breach is reported to the agency as soon as the contractor has knowledge of it rather than waiting to submit an electronic report.

6.0 CONTRACTOR PERSONNEL

The Contractor shall provide sufficient management to ensure that these tasks are performed efficiently, accurately, on time, and in compliance with the requirements of this document.

Specifically, the Contractor shall designate a single manager to oversee these tasks and supervise staff assigned. The Contractor shall ensure that a monthly performance and progress report is submitted outlining the expenditures, billings, progress, status, and any problems/issues encountered in the performance of these tasks.

6.1 QUALIFIED PERSONNEL

The Contractor must provide qualified personnel to perform all requirements specified in this SOW.

6.2 CONTINUITY OF SUPPORT

The Contractor must ensure that the contractually required level of support for this requirement is maintained at all times. The Contractor must ensure that all contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor must provide e-mail notification to the Contracting Officer’s Representative (COR) prior to employee absence. Otherwise, the Contractor must provide a fully qualified replacement.

7.0 SECURITY

Contractor access to controlled unclassified information may be required under this SOW.

Contractor employees must safeguard this information against unauthorized disclosure or dissemination.

8.0 PERIOD OF PERFORMANCE

The period of performance for this contract is a one-year base period with two one-year option periods as follows:

Base Period One Year Option Period One One Year Option Period Two One Year

9.0 PLACE OF PERFORMANCE

The primary place of performance will be the Contractor’s facilities.

10.0 HOURS OF OPERATION

Contractor employees should be available for periodic meetings between the hours of 10:00AM and 3:00PM EST, Monday through Friday (except Federal holidays). However, there may be occasions when Contractor employees must be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this SOW.

11.0 TRAVEL

Contractor travel may be required to support this requirement. All travel required by the Government outside the local commuting area(s) will be reimbursed to the Contractor in accordance with the Federal Travel Regulations. The Contractor must be responsible for obtaining COR approval (electronic mail is acceptable) for all reimbursable travel in advance of each travel event.

12.0 POST AWARD CONFERENCE

The Contractor must attend a Post Award Conference with the Contracting Officer and the COR no later than 10 business days after the date of award. The purpose of the Post Award Conference, which will be chaired by the Contracting Officer, is to discuss technical and contracting objectives of this contract and review the Contractor's draft project plan. The Post Award Conference will be held via teleconference.

13.0 PROGRESS REPORTS

The contractor must provide a monthly progress report to the Contracting Officer and COR via electronic mail. This report must include a summary of all Contractor work performed, including a breakdown of labor hours by labor category, all direct costs by line item, an assessment of technical progress, schedule status, any travel conducted and any Contractor concerns or recommendations for the previous reporting period.

14.0 PROGRESS MEETINGS

The contractor must be responsible for keeping the COR informed regarding Contractor progress throughout the performance period of this contract and ensure Contractor activities are aligned with NCSES objectives. At a minimum, the Contractor must review the status and results of Contractor performance with the COR on a monthly basis via telephone or Zoom.

15.0 PROTECTION OF INFORMATION

Contractor access to controlled unclassified information protected under the Privacy Act is required under this SOW. Contractor employees must safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation.

16.0 GOVERNMENT FURNISHED RESOURCES

The Government will not furnish any resources to the Contractor in support of this contract.

17.0 GOVERNMENT ACCEPTANCE PERIOD

The COR will review deliverables prior to acceptance and provide the contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.

17.1 The COR will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted proposal.

In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions.

17.2 The COR will have 10 business days to review deliverables and make comments. The Contractor must have 7 business days to make corrections and redeliver.

17.3 All other review times and schedules for deliverables must be agreed upon by the parties based on the final approved Project Plan. The Contractor must be responsible for timely delivery to Government personnel in the agreed upon review chain, at each stage of the review. The Contractor must work with personnel reviewing the deliverables to assure that the established schedule is maintained.

18.0 DELIVERABLES

The Contractor must consider items in BOLD as having mandatory due dates. The Contractor may propose amendments to this schedule in writing to the Government in advance of existing deadlines. The contractor shall deliver the following items listed in the Delivery Schedule Table list.

18.1 METHOD OF DELIVERY

Electronic copies shall be delivered using Microsoft Office suite of tools (for example, MS WORD, MS EXCEL, MS POWERPOINT, MS PROJECT, or MS ACCESS format), unless otherwise specified by the COR. Electronic submission shall be made via email, unless otherwise agreed to by the COR.

ITEM SOW

REFERENCE DELIVERABLE / EVENT DUE BY

DISTRIBUTION

1 12.0 Post Award Conference 10 Business Days After Award

TBD

2 10.0 Progress Reports Monthly

COR

3 2.1 Summary reports for each inspection TBD

COR

Statement of Work

File details come from the government source that posted it. Updated .