ATTACHMENT A SOW.pdf
PDF 267 KB Posted
- Attached to
- Cloud Hosting and Support Services Federal contract opportunity
- Solicitation number
- ED-IES-12-R-0100
About this file
Attachment A - SOW
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 03 signed.pdf | ||
| Amendment 02.pdf | ||
| Amendment 01 - ED-IES-12-R-0100.pdf | ||
| ATTACHMENT C CONTRACTOR PERFORMANCE INFORMATION.pdf | ||
| ED-IES-12-R-0100 Solicitation.pdf | ||
| ATTACHMENT E-- BILLING INSTRUCTIONS.pdf | ||
| ATTACHMENT B QASP.pdf | ||
| ATTACHMENT D SECURITY RISK LEVELS.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment A
STATEMENT OF WORK
CLOUD HOSTING SUPPORT AND SERVICES
FOR THE INSTITUTE OF EDUCATION SCIENCES
I. BACKGROUND
The Institute of Education Sciences (IES) of the U.S. Department of Education (ED) currently hosts an array of websites that support its data collection and dissemination activities in its own dedicated server facility. To reduce costs, improve efficiency, and allow for growth and innovation, IES has identified
Infrastructure-as-a-Service (IaaS) or cloud hosting as the best option to replace its physical datacenter.
IaaS hosting model enables convenient, on-demand network access to a shared pool of configurable and reliable computing resources that can be rapidly provisioned and released with minimal user effort or service provider interaction. Additional server, storage, and bandwidth resources can be added almost immediately as demand increases and as applications grow in complexity and size. Managing IaaS can be done by IES staff using a web interface or programmatically using an application programming interface
(API), allowing us to scale up or down resources as necessary. Instead of paying for individual servers on a purchase or lease basis, IES will pay for abstract metered computer resources such as central processing using (CPU) cycles, memory, storage, with an ability to increase or decrease our usage as needed with the associated fees adjusting accordingly.
The IaaS service sought by IES would host and serve most or all of the public-facing websites and systems currently housed in IES’ physical data center. The proposed IaaS service should be able to be certified and accredited to Federal Information Security Management Act (FISMA) requirements with a
Federal Information Processing Standard (FIPS) 199 categorization of Moderate and comply with the security standards detailed in the FIPS 140-2.
II. SCOPE OF WORK
The scope of the contract includes all work associated with the IaaS Cloud service.
The base Period of Performance will be one 12 month base period from date of award with four one-year option periods.
The objective of this Statement of Work is to acquire the services of a Contractor to provide server operations support and access to a virtualized hosting environment that is capable of being certified and accredited at the FISMA-Moderate level to support IES in its dissemination and survey collection systems.
III. REQUIREMENTS
The Contractor shall provide system operations support staff with experience supporting federal data centers with both physical and virtualized environments.
The Contractor shall provide access to a cost effective virtualized hosting solution based on industry standards and best practices. The virtualized hosting solution shall provide the best value to Government while at the same time allowing IES the flexibility to meet future requirements. The virtualized hosting solution shall meet all requirements set forth in this section. The Contractor’s proposal shall describe their methods of compliance with these requirements and will be incorporated into the proposed service level agreement (SLA).
Task 1. System Operations Support Requirements
The Contractor shall provide system operations support staff equivalent to three (3) full-time FTEs, able to perform their work on-site at the government’s facility. Support staff shall have experience working with systems in a federal owned data center and demonstrate an understanding through past performance of government IT mandates, regulations and best practices. Support staff shall have demonstrated experience with and have strong understanding of privacy and data integrity concerns of federal statistical agencies.
The contractor shall:
a. Support IES' website operations by providing technical expertise in Microsoft Windows Server, Microsoft SQL Server, and Microsoft Internet Information Services (IIS).
b. Support IES' server operations by maintaining the physical server environment that currently hosts IES’s systems. These server support efforts will gradually shift to the IaaS hosting solution as services are transitioned from physical to virtual hosting.
c. Plan and support the migration of IES’ systems from the current physical hosting environment to the IaaS virtual hosting solution.
d. Provide management of the virtual network and virtual servers, Microsoft server and IIS support, SQL database maintenance, and ad hoc custom application support. The contractor staff shall act as technical point of contact on system related issues for other contractor staff working with IES.
Task 2. IaaS Solution
General Requirements for IaaS Solution
The Contractor shall provide a cost effective cloud-based infrastructure as a service that utilizes industry standards and best practices that meet or exceed the following criteria.
The Contractor shall:
a. Provide access to an IaaS hosted by an established cloud services provider that can demonstrate past performance with federal government clients that meets or exceeds FISMA requirements for information systems categorized as FIPS-199 defined Moderate and complies with the Federal
Risk and Authorization Management Process (FedRAMP) requirements.
b. Provide a solution that shall be physically located in the continental United States, and be in a facility capable of being certified and accredited to host U.S. Government systems.
c. Provide a solution that has a flexible, scalable, and reconfigurable technical foundation to respond to increasing usage demands and government needs.
d. Provide a technical foundation which allows IES to deploy its web hosting architecture.
e. Provide a robust, fault tolerant infrastructure that allows for high availability of 99.9%, and a one
(1) hour recovery time after failure.
f. Provide multiple physical hosting facilities in different geographic locations to allow for hardware fault tolerance, disaster recovery, and reduced network latency.
g. Provide an IaaS solution provider that has zero-exit costs (e.g., no lock in) to migrate to other providers if necessary.
h. Provide documentation of their compliance with appropriate industry standards as applied to the proposed hosted solution.
i. Have demonstrated experience with and have strong understanding of privacy concerns of federal statistical agencies in respect to sensitive data.
j. Provide technical documentation required for certification and accreditation.
Technical Requirements for IaaS Solution
The Contractor shall provide a cost effective solution that utilizes proven and stable virtualization technologies, which encompass the following criteria:
Virtual Infrastructure:
a. Provides centralized, web-based management of virtual resources.
b. Provides machine-to-machine interfaces (e.g., application programming interface (API) or command line) to manage virtual resources.
c. Provides the capability to report real-time usage metrics to include CPU, memory, disk, and network.
d. Provides support for virtual machines running Microsoft Windows and Linux with full root access.
e. Provides the capability to dynamically reallocate virtual machines based on load, with minimal service interruption.
f. Provides the capability to create virtual machine templates, allowing IES to define its own virtual machine images and upload them to be used.
g. Provides the capability to copy or clone virtual machines for archiving, troubleshooting, and testing.
h. Provides multiple network interfaces per virtual server to allow for network fault tolerance.
i. Provides multiple IP addresses per network interface.
j. Provides the option to load-balance internet traffic to multiple servers and nodes.
k. Provides the option to create an isolated virtual private network, allowing for IES to assign its own IP address ranges, create subnets and routing tables that can limit network connectivity, isolate servers by role, and provide better security.
l. Provides support for Internet Protocol version 6 (IPv6).
Virtualization Hypervisor:
a. Provides virtualization capabilities that support 32 bit and 64 bit operations
b. Provides support for multiple processor virtual machines up to 8 cores.
c. Provides support for virtual machines with virtual processors that are equivalent to 3 GHz per virtual processor core.
d. Provides support for virtual machines with memory requirements up to 68 GB.
Virtualization Storage:
a. Provides high availability centralized network accessible storage.
b. Provides the ability to attach multiple drives per virtual server instance.
c. Provides the ability to snapshot storage volumes for backup and replication purposes.
d. Provides adequate flexibility for increasing storage capacity up to 1 TB per drive.
e. Provides the ability to scale across multiple physical sites.
IV. TASK ORDER REQUIREMENTS
ED contemplates awarding a firm-fixed-price Indefinite Delivery Indefinite Quantity (IDIQ) contract to a single, successful offeror. Work under Task 3 and Task 4 will be issued as task orders, as the need arises. The contractor shall not perform the following tasks unless ED issues a task order.
Task 3. System Licenses
The Contractor shall provide system and software licenses allowing for additional functionality in support of IES’ cloud hosted systems. Examples of additional licenses and services include, but are not limited to, Sourcefire Snort IDS, Riverbed Stingray Traffic Manager and Application Firewall, and Google
Enterprise Search Services – Google Site Search.
Task 4. Technical Writing
The Contractor shall provide technical writing services for preparation of documentation in support of
Security Certification & Accreditation.
This documentation shall include, but is not limited to:
a. Annual Self-Assessment
b. Configuration Management Plan
c. Contingency Plan/Disaster Recovery Plan
d. Contingency Plan Test
e. Data Sensitivity Worksheet
f. System Security Plan
g. Business Impact Analysis
h. Privacy Impact Assessments
V. DELIVERABLES
Schedule of Deliverables
Activity Deliverable Estimated Due Date
Task 1. System Operations
Support
Support personnel assigned to support IaaS systems
Within three weeks from award date
Task 2. IaaS Hosting Service Availability of Base Virtualized
Hosting Environment
Within two weeks from award date
Task 3. System Licenses System license or software Within two weeks of request for license
Task 4. Technical Writing Preparation of documentation in support of Security Certification and Accreditation (C&A)
Initial draft due 2 weeks after assignment; revised versions due
1 week after comments received
VI. INVOICING
Invoicing
The contractor shall submit to the Government an invoice for the deliverables that were submitted to and accepted by the Government during that month. The invoice for the prior month’s work must be received by 21st of each month. The invoice shall be submitted to OCFOCAMINVOICNG@ED.GOV with a carbon copy to the Contracting Officer (CO), Contract Specialist (CS), Contracting Officer
Representative (COR) , and Task Leader.
Monthly Report
Along with the invoice, the contractor shall submit monthly reports on or before the 10th of each month.
The monthly reports are to be submitted electronic transmission. The monthly report shall be submitted to the CO, CS, COR, and Task Leader.
The report shall include the following:
a) The progress on each task and activity relative to the schedule and a discussion of discrepancies;
b) Accomplishments associated with each task and activity for the month;
c) Problems that have been resolved or are in need of resolution;
mailto:OCFOCAMINVOICNG@ED.GOV
d) A discussion of the work to be performed during the next monthly reporting period;
e) The number of hours expended by all contractor staff by staff person;
f) The number of hours expended by all subcontractor staff by person;
g) Brief description of the work performed by each subcontractor during the month;
h) Funding expended by major category, including staff, travel, consultant, subcontractors, and other costs, including obligated costs of subcontractors; and
i) Expected future technical and budgetary problems and proposed solutions to these.
VII. PLACE OF PERFORMANCE
The contractor shall perform the majority of the work identified on-site at the government location. This will be considered the primary duty station. ED will provide adequate workspace for contractor staff located on-site. ED will provide access badges, email accounts, desks, copy and fax services, and supplies necessary to complete the requirements of the assigned work.
VIII. OTHER REQUIREMENTS
Confidentiality Requirements
The Contractor shall implement such confidentiality and security provisions as IES may require (see
Section IX).
Staffing
The contractor shall provide in writing at least two (2) weeks advanced notice for replacement of staff proposed. This notice shall be provided to the CO, CS, COR, and Task Leader and shall include justification (including proposed substitutions) in sufficient detail to permit evaluation of the impact on the program. All resumes of proposed replacement staff must be provided and approved by the COR and
Task Leader before replacing any individual on this project.
Deliverables
The contractor shall provide all deliverables in electronic formats. The contractor shall provide all computer programming source file and code used in the creation of deliverables.
IX. DATA CONFIDENTIALITY, DATA SECURITY PLAN, AFFIDAVIT OF
NONDISCLOSURE, AND QUALITY CONTROL
Confidentiality of Individuals and Institutions
IES assures participating individuals and institutions that any data collected conforms to the IES standards for protecting the privacy of individuals as required by Section 183 of the Education Sciences
Reform Act of 2002 (P.L. 107-279):
“. . . all collection, maintenance, use, and wide dissemination of data by the Institute, including each office, board, committee, and Center of the Institute, shall conform with the requirements of section 552A of Title 5, United States Code [which protects the confidentiality rights of individual respondents with regard to the data collected, reported, and published under this title].” (Section 183)
Under the ESRAof 2002 (ESRA 2002), all individually identifiable information about students, their families, and their schools shall remain confidential. To this end, this law requires that no person may:
Use any individually identifiable information furnished under the provisions of this section for any purpose other than statistical purposes for which it is supplied, except in the case of terrorism;
Make any publication whereby the data furnished by any particular person under this section can be identified; or
Permit anyone other than the individuals authorized by the Commissioner to examine individual reports.
Further, individually identifiable information is immune from legal process, and shall not, without the consent of the individual concerned, be admitted as evidence or used for any purpose in any action, suit, or other judicial or administrative proceeding, except in the case of terrorism. Employees, including temporary employees, or other persons who have sworn to observe the limitations imposed by this law, who knowingly publish or communicate any individually identifiable information will be subject to fines of up to $250,000 or up to 5 years in prison, or both (Class E felony).
Protection and Security of Data
The confidentiality of individually identifiable information contained in project documents, data, and other information supplied by the IES/ED or information acquired in the course of performance under this contract where the information was furnished under the provisions of Section 183 of the Education
Sciences Reform Act (ESRA) of 2002 is a material aspect of the contract and must be maintained, secured, and protected from disclosure as provided in Section 183. The Privacy Act of 1974 (5 U.S.C.
552a) also applies.
The contractor shall be familiar with and comply with:
1) The Privacy Act of 1974 (5 U.S.C. 552a),
2) Confidentiality Information Protection and Statistical Efficiency Act (CIPSEA) of 2002 (P.L.
107-347, Title V, Subtitle A, “Confidential Information Protection”),
3) Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. 1232g; 34 CFR Part 99),
4) The Freedom of Information Act (5 U.S.C. 552),
5) The Education Sciences Reform Act of 2002 (P.L. 107-279),
6) No Child Left Behind Act (20 U.S.C. 70),
7) USA Patriot Act of 2001 (P.L. 107-56),
8) Office of Management and Budget (OMB) Federal Statistical Confidentiality Order of 1997,
9) OMB Guidance of 7/12/2006 on the Reporting of Incidents Involving Personally Identifiable
Information (M-06-19), http://www.whitehouse.gov/OMB/memoranda/fy2006/mo6-19.pdf ,
10) OMB Guidance of 5/22/2006 on Safeguarding Personally Identifiable Information (M- 06-15) http://www/whitehouse.gov/omb/memoranda/fy2006/m-06-15.pdf,
11) Federal Information Security Management Act (FISMA) of 2002 (P.L. 107-347, Title III),
12) Federal Risk and Authorization Management Process (FedRAMP)
13) Section 508 of the Rehabilitation Act (29 U.S.C. '794 d)
14) Any new legislation that impacts the data collection through this contract.
The contractor shall maintain the confidentiality of all documents, data, and other information supplied by
IES/ED or acquired in the course of performance of this contract, except for any documents or other information specifically designated as non-confidential by IES/ED. The contractor shall take such measures as are necessary to maintain the required security and protection of confidential information
(see section Data Security Plan).
Compliance with ED IT Security Policy
The contractor, and all sub-contractors, shall comply with ED’s IT security policy requirements, specifically those set forth in the ‘Handbook for Information Assurance Security Policy (OCIO-01)’, and other applicable procedures and guidance. The contractor, and all sub-contractors, shall develop and implement management, operational and technical security controls to assure required levels of protection for information systems. The contractor, and all sub-contractors, shall further comply with all applicable
Federal IT security requirements including, but not limited to, the Federal Information Security
Management Act (FISMA) of 2002 and the Federal Risk and Authorization Management Process
(FedRAMP).
These security requirements include, but are not limited to, the successful Certification and Accreditation
(C&A) or Security Authorization (SA) of the system (includes commercially owned and operated systems managed by the commercial vendor and its sub-contractors, supporting Department programs, contracts, and projects); obtaining a full Authority to Operate (ATO) before being granted operational status;
performance of annual self-assessments of security controls; annual Contingency Plan testing;
performance of periodic vulnerability scans; updating all information system security documentation as changes occur; and other continuous monitoring activities, which may include, mapping, penetration and other intrusive scanning. Full and unfettered access for ED’s third party Managed Security Services
Provider (MSSP) must be granted to access all computers and networks used for this system.
Additionally, when there is a significant change to the system’s security posture, the system (Federal and commercial prime- and sub- contractors included) must have a new C&A or SA, with all required activities to obtain a new ATO, signed by the Authorizing Official (AO).
System security controls shall be designed and implemented consistent with National Institute of
Standards and Technology (NIST) SP 800-53 Rev 3, ‘Recommended Security Controls for Federal
Information Systems and Organizations.’ All NIST SP 800-53 controls must be tested / assessed no less than every 3 years, according to federal and Department policy. The risk impact level of the system will be determined via the completion of ED's inventory form and shall meet the accurate depiction of security categorization as outlined in Federal Information Publishing Standards (FIPS) 199, ‘Standards for
Security Categorization of Federal Information and Information Systems.’
System security documentation shall be developed to record and support the implementation of the security controls for the system. This documentation shall be maintained for the life of the system. The contractor, and all sub-contractors, shall review and update the system security documentation at least annually and after significant changes to the system, to ensure the relevance and accurate depiction of the implemented system controls and to reflect changes to the system and its environment of operation.
Security documentation must be developed in accordance with the NIST 800 series and Department of
Education policy and guidance.
The contractor, and all sub-contractors, shall allow ED employees (or Department designated third party contractors) access to the hosting facility to conduct C&A/SA activities to include control reviews in accordance with NIST SP 800-53, Rev. 3 and NIST SP 800-53A. The contractor, and all sub-contractors, shall be available for interviews and demonstrations of security control compliance to support the
C&A/SA process and continuous monitoring of system security. In addition, if the system is rated as
‘Moderate’ or ‘High’ for FIPS 199 risk impact, vulnerability scanning and penetration testing shall be performed on the hosting facility and application as part of the C&A/SA process. Appropriate access agreements will be reviewed and signed before any scanning or testing occurs.
Identified deficiencies between required NIST SP 800-53 Rev. 3 controls and the contractor’s, and all sub-contractor’s implementation, as documented in the Risk Assessment Report, System Security Plan
(SSP) and Security Assessment Report (SAR), shall be tracked for mitigation through the development of a Plan of Action and Milestones (POA&M) in accordance with the ‘Handbook for Information Assurance
Security Policy (OCIO-01).’ Depending on the severity of the deficiencies, ED may require remediation before an ATO is issued.
All awarded contracts shall ensure that:
1. Their IT product/system is monitored during all hours of operations using entrusted detective/preventive systems;
2. Their IT product/system has current antiviral products installed and operational;
3. Their IT product/system is scanned on a reoccurring basis;
4. Vulnerabilities are remediated in a timely manner on their IT product/system; and
5. Access/view for cyber security situational awareness on their IT product/system is made available to ED CIRC (cyber incident response capability).
Internet Protocol version 6 (IPv6)
For IPv6, the contractor shall provide commercially available, off-the-shelf solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of
IPv4. Specific criteria to be deemed IPv6 capable are:
An IPv6 capable system that meets the IPv6 base requirements defined by the USGv6 Profile and
Testing program as found here (http://www.antd.nist.gov/usgv6/profile.html).
Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities.
Systems shall implement IPv4/IPv6 dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems shall employ IPv6.
The contractor shall provide IPv6 technical support for system development, implementation and management.
System Development Standards
Information systems shall be developed in accordance with the ED Lifecycle Management Framework
(LCM), ACS-OCIO 1-106.
Reporting of Data Security Breaches
If there is a suspected or known breach/disclosure of Personally Identifiable Information (PII) due to lost, theft, intercepted transfer, or other, the contractor must ensure that this breach is reported to the agency as soon as the contractor has knowledge of it. Per Office of Management and Budget Memorandum M-06-
19, Federal agencies have a requirement to report breaches of PII security to a Federal incident response center. IES must notify ED within 30 minutes of discovering the incident (and the agency should not distinguish between suspected or confirmed breaches). The data security plan must be written to reflect this requirement, and the contractor must provide sufficient notification and documentation of the suspected loss, as it is understood at the time of notification to the agency for this requirement to be met.
Follow-up reports of the final status of loss events will also be prepared by the contractor within a reasonable period of time as advised by the IES COR.
Freedom of Information Act (FOIA) Requests
If the contractor receives a FOIA request for any data under this contract, then the contractor will immediately refer this request to the COR. IES will process all FOIA requests related to this contract.
Implementation of Data Security Plan
The contractor shall conform to the agreed-upon approved data security plan, in all activities, and shall http://www.antd.nist.gov/usgv6/profile.html strictly enforce all procedures for ensuring confidentiality. These procedures will apply to all phases of the project, including (but not limited to):
1) Data collection in the field;
2) The transfer or transport of PII in any format, including paper records and electronic data files;
3) Safeguarding and storage of master data files and response/collection documents and electronic files.
Affidavit of Nondisclosure
Any contractor employee with access to confidential information including IT systems used for receiving, storing, transmitting, and accessing confidential information (i.e., personally identifiable information) under this contract shall first sign an Affidavit of Nondisclosure. Before any contractor employee starts work on the contract and has access to confidential information, a signed Affidavit of Nondisclosure must be completed. As new staff start and require access to confidential information or as staff who originally did not require such access subsequently need it, an Affidavit of Nondisclosure shall be executed by them on the first working day of the assignment. The contractor shall indicate the position in the organization of the person signing the Affidavit of Nondisclosure, and the person’s functional relationship to this project in a memorandum provided to the COR.
The contractor shall execute these Affidavits of Nondisclosure, submit the signed Affidavits to the COR, and the contractor shall maintain the copies at its office. The contractor shall make Acrobat pdf copies of new Affidavits as they are completed. Throughout the life of the contract Affidavits of Nondisclosure for new project staff, including any short-term personnel, will be submitted to the COR on a flow basis. The contractor shall be able to produce the original hard copies of the Affidavits within a few hours notice from the COR.
Security and Confidentiality Training
During the course of work on the tasks in this contract, contractor employees will be supporting IaaS used for receiving, storing, transmitting, and accessing data that are confidential. Given the restrictions on the use and handling of confidential information, all contractor employees with access to confidential information related to this contract shall be required to participate in IES approved security and confidentiality training.
Contractor Employee Security Screening Requirements
ED has established policy on personnel security screening for all contractor and subcontractor employees and their field staff. The relevant Departmental Directive is OM:5-101. It was last updated in July 2010 and can be found at: http://www2.ed.gov/policy/gen/leg/foia/acsom5101.pdf . The contractor must comply with the personnel security-screening requirements in OM:5-101 throughout the life of the contract.
All contractor and subcontractor employees must undergo personnel security screening if they will be employed for thirty (30) days or more.
http://www2.ed.gov/policy/gen/leg/foia/acsom5101.pdf
The type of screening and the timing of the screening will depend upon the nature of the contractor position, the type of data the contractor employee will have access to, or the type of ED IT system they will access. Personnel security screenings will be commensurate with the risk and magnitude of harm the individual could cause to ED or the public. A position risk level will be assigned to each contractor employee position, before a solicitation is released, consistent with the descriptions in Appendix I of
OM:5-101. Hence, each contractor employee working on this contract must be assigned a position risk level. Depending on the risk level assigned to each person's position, a follow-up background investigation by the Office of Personnel Management (OPM) may occur.
The contractor must identify one of their employees as a security liaison for this process. This
Contractor Security Liaison coordinates the distribution, collection, and dissemination of various forms required in this process. They answer general questions from their employees on completing the security screening process. And, they are the first point of contact for contractor employees in using the OPM’s internet based security screening portal called the Electronic
Questionnaires for Investigations Processing (e-QIP) ( http://www.opm.gov/e-qip/ ). The contractor is also responsible for ensuring that all subcontractors follow these personnel security screening procedures.
IES requires each contractor employee to have or apply for a clearance for the security level designated for the position held on a contract.
Contractor employees who have undergone appropriate personnel security screening for another Federal agency will be required to submit proof of that personnel security screening for validation. For these employees, the contractor or subcontractor must follow these required steps:
1. The contractor must send the COR a letter on Company letterhead that lists the full name of each employee with a pre-existing clearance, the agency that cleared the employee, the level of the clearance, and the date of the clearance. This letter must be transmitted to the COR within two (2) business days of starting work on an IES contract.
2. In those cases where any of the required information on level of clearance, agency that cleared the employee and date of clearance is not available, the contractor must send the COR a letter on
Company letterhead that lists the full name and Social Security Number for each employee with a pre-existing clearance. This letter must be transmitted to the COR within two (2) business days of starting work on an IES contract.
3. The COR will transmit the letter to the IES Security Representative for processing.
4. The IES Security Representative reviews the letter to ensure that the required information is provided and either returns it to the contractor for completion or releases it to ED’s Chief of Personnel Security. The contractor must resubmit the letter to the COR within 7 business days or the contractor employee must be removed from the contract.
5. The IES Security Representative will notify the contractor or subcontractor if the pre-existing clearance was identified and ruled to be acceptable by ED’s Chief of Personnel Security.
http://www.opm.gov/e-qip/
6. Those employees whose pre-existing clearances are not verified and approved must follow the process outlined next to apply for a security clearance.
For contractor employees who have not undergone appropriate personnel security screening for another
Federal agency, all contractors must comply with the Principal Office (PO) Executive Office or Computer
Security Officer’s pre-processing requirements for personnel security screening and granting access privileges. No contractor employees are permitted unsupervised access to unclassified sensitive information (i.e., personally identifiable information), direct access to respondents who are minors, or Department of Education IT systems until they have submitted applicable security screening documents.
For each contractor employee in a high risk level position the completed security screening documents must be accepted by the COR and the IES Security Representative and submitted to ED’s Chief of
Personnel Security within 14 days of the date the contractor employee starts working on the contract. In order to meet this Departmental requirement, steps 1 through 7 must be completed within 14 days of the date the contractor employee starts working on the contract. To meet this 14 day deadline and the interim deadlines specified below, it is strongly recommended that the contractor request the account initiation three (3) weeks before the contractor employee starts contract work and encourage each contractor employee to complete all required security screening forms before starting contract work.
Contractor employees in High Risk IT (6C) Level positions require preliminary personnel security screenings before they are given access to unclassified sensitive information or Department of Education
IT systems.
The security screening of contractor and subcontractor employees not holding ED recognized security screening credentials must follow these required steps:
1. The contractor must provide the COR with an electronic listing of all employees on a specific contract, with the risk level associated with the position held by each employee as specified in the contract solicitation. The COR will review the electronic listing for completeness and approve. The listing will not be approved if it is found to be incomplete.
2. ED’s participates in the OPM e-QIP system to facilitate the security screening process for contractor employees. IES will initiate an e-QIP account for each contractor employee. It is advisable to request the account initiation three (3) weeks before the contractor employee starts contract work. For the initiation of these accounts, the Contractor Security Liaison must use the COR-approved list of employees and the risk levels assigned to the employees’ positions to produce and submit the following list using the attached template:
a. For each contractor employee provide: Social Security Number, Full Name, Date of Birth, Place of Birth, risk level, e-Mail Address, and phone number. The Contractor Security Liaison must place the spreadsheet in a password protected file, then upload the list to the IES secure server, and send an e-mail notification of the transmission to the IES Security Representative. The IES security staff will use this list to establish the contactor employee e-QIP accounts. The COR will work with the contractor to establish access to the IES secure server at the outset of the contract.
b. Once IES sets up the e-QIP accounts for contract employees, the IES Security Representative will send an email to the Contractor Security Liaison stating that the employee has an active account on the e-QIP system. The COR is copied on this email notification.
c. The Contractor Security Liaison must notify their employees of this active account. A computer with Internet access and web browsing software is required for the contractor employee to access their E-QIP account. Each employee must log into their personal account in e-QIP, enter the requested information, finish the application process and print, sign, and date the e-QIP signature pages.
3. Each contractor employee must submit a completed set of security screening forms to their Contractor
Security Liaison as provided by the IES Security Representative, including for example:
a. The signed and dated e-QIP signature pages,
b. The Declaration of Federal Employment (OPM form OF-306),
c. The Fair Credit Release Form,
d. The Request for Security Officer Action (RSA) Form,
1) The contractor employee shall complete only those items in section 1 of the form (name, date of birth, place of birth, organization, position title, duty station, social security number, and work phone number).
2) The contractor shall complete section 5 (Project Requiring Highest ADP Level) using the assigned security clearance for each employee’s position.
e. Two sets of fingerprints on separate copies of form FD-258,
1) The Contractor Security Liaison shall help arrange fingerprinting for each contractor and subcontractor employee. Fingerprinting can usually be done at a local police station.
(Electronic fingerprints are not accepted at this time.)
4. Each contractor must ensure that the forms are complete and that all contractor employee required security screening forms are transmitted to the COR within two (2) business days of an employee starting work on an IES contract.
a. The Contractor Security Liaison must collate the forms in each security screening package by employee and transmit a complete set of security screening documents for each employee to the
COR via courier (e.g., Federal Express) using a tracking number with signature required,
b. The COR will not accept security screening packages that are not collated by employee (i.e., all forms noted in point 3 above will be bundled by employee). The COR will review all security screening documents for each contractor employee for completeness, returning any incomplete security screening documents to the Contractor Security Liaison for completion. The contractor must resubmit the completed security screening documents to the COR within 7 business days or the contractor employee must be removed from the contract. No contractor employees are permitted unsupervised access to unclassified sensitive information (personally identifiable information), direct access to respondents who are minors, or Department of Education IT systems until they have resubmitted applicable screening documents.
5. The COR will submit the completed packages of security screening documents to the IES Security
Representative for processing.
6. The IES Security Representative reviews each package of security screening documents and electronic information submission to ensure everything required has been provided and either rejects the package, sending it back to the submitter for completion/correction or releases it to ED’s Chief of
Personnel Security. In the event that an application is rejected at this stage, the contractor must resubmit the corrected forms to the COR, or have the contractor employee correct the e-QIP submission, within two business days. The IES Security Representative must be notified as soon as the updated e-QIP submission is completed.
7. The contractor employee application for each individual in a moderate risk level position must be submitted to ED’s Chief of Personnel Security within 14 days of the date the contractor employee starts working on the contract. Contractor employees in High Risk IT (6C) Level positions require preliminary personnel security screenings before they are given access to unclassified sensitive information or Department of Education IT systems.
8. After a package of security screening documents is transmitted to ED Chief of Personnel Security, the
Office of Management security staff conducts a further review and either rejects the package of security screening documents, sending it back to the submitter for completion/correction or releases it to OPM.
9. OPM then assigns an investigator to conduct the type of investigation indicated by the department
(this is tied to the level of access to PII that the applicant will have).
10. The Chief of Personnel Security will request the expansion of background investigations to obtain additional information to the extent necessary to make personnel acceptability or suitability determinations. These determinations will be made using criteria established by the OPM for the purpose of determining suitability for employment in the Federal competitive service, as described in
5 Code of Federal Regulations (CFR) 731.202, and other OPM guidance as applicable. The Chief of
Personnel Security determines whether a contractor employee is acceptable for the position from a personnel security standpoint.
11. When the OPM investigation is complete, the RSA form with the clearance indicated is sent to ED’s
Office of Management for processing.
12. The Office of Management returns the RSA form to the IES Security Representative for recordation and distribution to the COR.
13. The COR transmits the RSA form with clearance indicated to the Contractor Security Liaison for their records and for distribution to the Contract Project Leader.
14. The Contract Project Leader then distributes copies of the clearance to the employee.
15. The Chief of Personnel Security will inform the IES COR when he or she determines that a contractor employee is not acceptable to render service(s) or, if appropriate, to otherwise perform under a contract.
16. Each contractor will officially notify its contractor employee if he or she will no longer work on an
ED contract.
17. In the event a contractor employee is deemed unacceptable for the position from a personnel security standpoint, the Chief of Personnel Security will usually provide the contractor employee with an opportunity to refute, explain, clarify, or mitigate information in question.
18. If, after final determination by the Chief of Personnel Security, a decision is made that the contractor employee is not acceptable to render services on a contract and access is denied, the COR will inform the Contracting Officer. The Contracting Officer must inform the contractor (i.e. employing firm) that the contractor employee is not acceptable to render services in this particular position, or, if appropriate, to otherwise perform under the contract. The contractor will notify the contractor employee. A final determination cannot be appealed.
19. At any time during the life of the contract a contractor or subcontractor employee (including any field staff) discontinues work on the contract or leaves the employment of the contractor, the contractor shall notify the COR within two days of the date that the employee is no longer working on the contract or within one business day if removed for cause. The contractor shall provide the reason why the employee is no longer working on the contract. The COR will provide this information to the IES
Security Representative.
20. Each contractor is responsible for the protection of sensitive or Privacy Act-protected information from unauthorized use or misuse by its employees, subcontractors, or temporary workers, and for preventing access to others, who are not authorized and have no need to know such information.
21. The contractor shall submit monthly information to the COR indicating which employees were billed to the contract that include the e-QIP number of the person being billed. The COR will reject payments to employees without an e-QIP number. For employees with pre-existing clearances from other contracts, this shall be noted on the monthly payment form.
The contractor shall verify with the COR that the security screening processes have not changed by the time the contract is active.
File details come from the government source that posted it. Updated .