Attachment_A_-_PWS.doc

DOC document 266 KB Posted

Attached to
NCES DATA LICENSING AND INSPECTION SUPPORT Federal contract opportunity
Solicitation number
ED-IES-13-R-0004
Issued by
Department of Education Contracts and Acquisition Management

About this file

ATTACHMENT A - PERFORMANCE WORK STATEMENT (PWS) NCES DATA LICENSING AND INSPECTION SUPPORT

View the file

Other files for this federal contract opportunity

Other files attached to NCES DATA LICENSING AND INSPECTION SUPPORT, newest first.
File Type Posted
AMENDMENT_001_signed.pdf PDF
SF1449_-_Solicitation_NCES_DATA_LICENSING_AND_INSPECTION_SUPPORT.pdf PDF
Attachment_B_QASP.docx DOCX document
Attachment_C_Past_Performance_Form.doc DOC document
Draft_PWS_-NCES_Data_Licensing_Inspection_Support_12-10-2012.doc DOC document
RFI_Capability_Satement_Instructions-_NCES_DATA_LICENSING_and_INSPECTION_SUPPORT.docx DOCX document
Draft_PWS_-_NCES_Data_Licensing__Inspection_Support_11-13-2012.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

NCES Data Licensing and Inspection Support

ED-IES-13-R-0004

I. Background The National Center for Education Statistics (NCES) of the Institute of Education Science (IES) is the primary federal entity for collecting, analyzing, and reporting data related to education in the United States and other nations. It fulfills a congressional mandate to collect, collate, analyze, and report full and complete statistics on the condition of education in the United States; conduct and publish reports and specialized analyses of the meaning and significance of such statistics; assist state and local education agencies in improving their statistical systems; and review and report on education activities in foreign countries.

II. Purpose

The Statistical Standard Programs (SSP) within the Office of Deputy Commissioner (ODC) of NCES provides state-of-the-art technical and statistical support to the Center and to federal and non-federal organizations and entities that engage in statistical work in support of the mission of IES/NCES. One of SSP’s responsibilities is to devise, administer, and monitor all facets of the preservation of the confidentiality of individually identifiable information in data held and disseminated by IES/NCES as required by law and regulation.

SSP has a need for a contractor to perform periodic, on-site inspections of selected IES/NCES licensee sites where researchers have licensing agreements with IES/NCES to access IES/NCES restricted-use data files, to maintain and update the License Documentation System, to review data security plans submitted by the licensure applicants, and to perform data inspection technical assistance.

The Government anticipates awarding an Indefinite Delivery, Indefinite Quantity (IDIQ) contract with Firm-Fixed Price Task Orders.

III. Enabling Legislation The authority for this project resides in law H.R.3801, an Act to “provide for improvement of Federal education research, statistics, evaluation, information, and dissemination, and for other purposes.” Under Title I, Part C, Sec. 151 of the Act, it states:

(a) ESTABLISHMENT.—There is established in the Institute a National Center for Education Statistics (in this part referred to as the ‘‘Statistics Center’’). (b) MISSION.—The mission of the Statistics Center shall be — (1) to collect and analyze education information and statistics in a manner that meets the highest methodological standards; (2) to report education information and statistics in a timely manner; and (3) to collect, analyze, and report education information and statistics in a manner that — (A) is objective, secular, neutral, and nonideological and is free of partisan political influence and racial, cultural, gender, or regional bias; and (B) is relevant and useful to practitioners, researchers, policymakers, and the public.

Further, the Sec.154 of the Act states NCES’ performance of duties as follows:

(a) GRANTS, CONTRACTS, AND COOPERATIVE AGREEMENTS. — In carrying out the duties under this part, the Statistics Commissioner, may award grants, enter into contracts and cooperative agreements, and provide technical assistance.

(c) DURATION. — Notwithstanding any other provision of law, the grants, contracts, and cooperative agreements under this section may be awarded, on a competitive basis, for a period of not more than 5 years, and may be renewed at the discretion of the Statistics Commissioner for an additional period of not more than 5 years.

IV. Restricted-use Data Licensing System Restricted-use Data Licensing Procedure

Many individuals, such as staff of IES/NCES, employees of contractors, staff of State and local education agencies, and research staff in other units of the Department of Education, may require the use of complete data sets that contain individual records and information that make the identification and disclosure of data for specific individuals possible. Access to these data may be necessary either for the purpose of data collection and verification or for analysis that is consistent with the purpose for which the data were collected. Others, such as scholars, researchers, and policy makers, may also need access to this kind of data.

All external users of IES/NCES individually identifiable data must enter into a legal agreement to protect the shared data consistent with the IES/NCES provisions of law. As part of this legal agreement, they must take an oath of non-disclosure, and undertake commitments with respect to security of the data. Files and records of the legal agreements and the oaths of non-disclosure are maintained by the IES/NCES as a system of records as defined by the Privacy Act of 1974.

IES/NCES has made a significant effort to make its data more useful to the education community. This has involved a greater linkage of surveys, more geographic detail, and the expansion of data-items. There is often a significant amount of information available to the public about the units or individuals surveyed through external universe files or through other external sources. In most surveys, the inclusion of all of the survey information collected on a “public” release data file (or CD-ROM) makes it easy to disclose individual identities. For this reason, IES/NCES conducts disclosure risk analyses and modifies or suppresses data in order to release a “public use” file that meets the confidentiality requirements.

While public use data files meet the needs of a large number of data users, other users require more detail. By law, the Director of IES can authorize outside use of potentially identifiable information for statistical purposes. However, the Director must be able to protect the identity of individuals in data held and distributed by IES/NCES.

IES/NCES provides sworn individuals access to data in a monitored environment at IES/NCES or through licensing agreements that permit a sworn user to have access at his/her own facility. All persons with access to identifiable information must enter into a legal agreement to protect the shared data consistent with the IES/NCES provisions of law. As part of this legal agreement, they must sign and notarize an affidavit of non-disclosure, be able to justify their planned use of the data, and give reasons why the public-use file is not sufficient for research needs.

Those who desire access to individually identifiable information at their own facility through a licensing agreement must provide security for the data files. The licensing agreement includes a Security Plan that contains detailed requirements for those security procedures. IES/NCES has licensed a number of Federal agencies, State agencies, various research organizations, and research universities. The period of time for the license usually depends upon the length of the research project, with renewable licenses available for periods of 1 to 5 years.

Before IES/NCES grants a license, the potential licensees must agree to the terms of the license that address the protection of the identity of individual records. IES/NCES, as required by the Education Sciences Reform Act of 2002, is responsible for the physical security of confidential information and computer security both in-house, for contractor licensees, and any others who have direct access to IES/NCES confidential data. IES/NCES also has a mandate to share information with the education research community in order to maximize the data utility.

A Restricted-Use Data Procedures Manual that addresses all aspects of the IES/NCES licensing program and the procedures for inspection can be found at: http://nces.ed.gov/pubs96/96860rev.pdf. All persons having access to IES/NCES restricted data must follow the requirements and restrictions in the method of maintenance and handling of individually identifiable information, as specified in this manual.

The Procedures Manual describes how institutions and individual researchers may apply for access to potentially individually identifiable information, and how organizations enter into licensing agreements for receipt, retention, protection, and utilization of databases containing restricted data. Each license only grants access for up to seven (7) users of the approved dataset. If a Principal Project Officer (PPO) wants to add users to an existing license that already contains seven (7) users, he/she needs to apply for another license. In recent years, NCES granted approximately 200 original, first time licenses each year.

License Documentation System (LDS)

According to the licensing process described in the Chapter 2 of the Restricted-Use Data Procedures Manual, institutions and individuals must submit an online formal request through the NCES Electronic Application System to initiate the application process. Once the request is accepted, the applicant must submit the following paper documents to the IES Data Security Office for approval: a signed License Agreement, executed Affidavits of Nondisclosure, and a signed Security Plan.

The LDS is a mechanism that converts the paper license documents using high resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text, in the form of electronic Acrobat PDF files that simulate the original license document forms. The PDF files have the advantage of being keyword-searchable and fully secure. The system allows for easy exportability and allows for data conversion to alternative file systems according to IES/NCES needs.

Confidentiality Laws

Among the data that IES/NCES collects, many contain individually identifiable information, which is confidential and protected by federal law. The relevant laws about survey data that contain individual identifiable information are found in the following:

Privacy Act of 1974, as amended – “The purpose of this Act is to provide certain safeguards for an individual against invasion of personal privacy by requiring Federal agencies … to collect, maintain, use or disseminate any record of identifiable personal information in a manner that assures that such action is for necessary and lawful purposes, that the information is current and accurate for its intended use, and that adequate safeguards are provided to prevent misuse of such information.”

Family Educational Rights and Privacy Act of 1974 – The use of data is vital to ensuring the best education for our children. The benefits of using student data must always be balanced with the need to protect students’ privacy rights. It is essential that everyone who has access to personally identifiable student data understands their roles and responsibilities to protect that information and uphold the student’s privacy and confidentiality. These regulations are designed to both protect privacy and to help us ensure that all State or federally funded education programs are adequately preparing children for success in the next stage of life, whether that is in kindergarten or the workforce. These regulations strengthen enforcement, ensure the safety of students, and ensure our taxpayer funds are invested in effective programs.

USA Patriot Act of 2001 – This law permits the Attorney General to petition a court of competent jurisdiction for an ex parte order requiring the Secretary of the Department of Education to provide data relevant to an authorized investigation or prosecution of an offense concerning national or international terrorism. Any data obtained by the Attorney General for these purposes must be subject to a confidentiality agreement negotiated between the Secretary and the Attorney General. This law was incorporated into the Education Sciences Reform Act of 2002.

Education Sciences Reform Act of 2002 – Under this law all individually identifiable information about students, their families, and their schools shall remain confidential. To this end, this law requires that no person may:

a.

Use any individually identifiable information furnished under the provisions of this section for any purpose other than statistical purposes for which it is supplied, except in the case of terrorism (see discussion of the Patriot Act);

b.

Make any publication whereby the data furnished by any particular person under this section can be identified; or c.

Permit anyone other than the individuals authorized by the Commissioner to examine the individual reports.

E-Government Act of 2002, Title III, Federal Information Security Management Act (FISMA): The law is enacted to “provide a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets." FISMA requires each agency to develop, document, and implement an agency wide information security program “providing information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of (i) information collected or maintained by or on behalf of the agency; and (ii) information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.”

E-Government Act of 2002, Title V, Subtitle A, Confidential Information Protection and Statistical Efficiency Act (CIPSEA) – Under this law all data or information acquired from individuals or organizations by any federal agency under a pledge of confidentiality for exclusively statistical purposes shall not be disclosed by the agency in identifiable form, for any use other than an exclusively statistical purpose.

It has been determined that any person, whether Federal employee, employee of a contractor, employee of a State or local education agency, or any other person who has access to individually identifiable information or the possibility of access to such data, must take an oath not to disclosure individually identifiable data. Any data release from IES/NCES or from its contractors that will go to parties not sworn to confidentiality (i.e., the general public) must be structured so that the identities of individuals cannot easily be derived from review or analysis of the data.

Thus, IES/NCES must ensure that sufficient precautions are taken when it authorizes outside use of data with individual identifiers to protect such information from disclosure. At the same time, IES/NCES must continue to maximize the utility of its statistical data both within and outside IES/NCES subject to confidentiality constraints.

V. Scope of Work

This section provides a general overview of the requirements to be performed over the life of the contract. The specific information regarding Task Orders is available in Section VI. The contractor shall work with the Government to develop and implement procedures for all tasks in this PWS, including the performance of licensee inspections at sites located throughout the U.S.

Requirement A: IES/NCES Data Security Site Inspection Support Services

The contractor shall perform its services at the contractor’s site, NCES, or by traveling to licensees sites located throughout the U.S. The contractor shall plan for an average site visit of four hours. To preserve the element of surprise in the inspection, while at the same time minimizing the cost of unnecessary travel, the contractor shall call in advance, ideally one day ahead, to the Principal Project Officer (PPO) on the license to be inspected, identifying him or herself as a representative of the federal government who needs to schedule an appointment with the individual.

A-1. Select Inspection Sites Within two weeks after the contract is awarded, the contractor shall work with the Task Leader and Contracting Officer’s Representative (COR) to select licenses for data security and compliance inspection. Seventy percent (70%) of the selected licenses for inspection should be located at different sites/organizations as some sites/organizations may obtain more than one license. The criteria for selecting the site inspection include, but are not limited to, 1) the licensees who have not been previously inspected, 2) new licensees, and 3) the licensees with reported difficulties with security requirements. The selected licenses for inspection shall distribute evenly in each of the Census Bureau’s Regions (i.e., Northeast, Midwest, South, and West). Often, but not always, these sites are visited in clusters of up to 3 sites. Appendix A lists some possible inspection locations by region.

A-2. Complete a Site Inspection Plan The contractor shall submit the proposed plan for inspecting these selected licenses and obtain the approval from the Task Leader and COR within two (2) weeks after the selection of is approved by the Task Leader and COR. The plan shall contain information including, but is not limited to: 1) the list of the selected licenses for inspection including license number, name of the PPO, location of the organization, etc., and 2) the tentative month for each inspection. The contractor shall plan approximately one fourth (1/4) of the inspections per 3month. Additionally, among the identified licenses, up to one fourth (1/4) of them are subject to change based on programmatic needs or knowledge of recent or suspected security violations.

A-3. Update the Site Inspection Form Within one month after the contract is awarded, the contractor shall work with the Task Leader and COR to modify and finalize a computer assisted site inspection form that is currently used for conducting the inspections. The current inspection form is shown in Appendix B.

The final site inspection form should, at minimum, collect information on areas generally to be checked during the inspection. These areas can be found in the Restricted-Use Data Procedures Manual (http://nces.ed.gov/statprog/rudman). These site inspection forms shall be marked as “For Office Use Only” to ensure confidentiality within the Department.

A-4. Conduct Site Inspections

The content of a site inspection includes, but is not limited to:

i. reviewing and determining whether all security procedures, as prescribed in the IES Restricted-Use Data Procedures Manual, the licensee’s approved Security Plan, and License Agreement, have been implemented or honored by the licensee;

ii. working with licensees to correct any minor infractions to facilitate compliance;

iii. reviewing and verifying authorized users, by confirming that all persons having access to restricted-use data have executed and notarized affidavits of non-disclosure, and that any exceptions are noted in the inspection report;

iv. assisting in the retrieval of restricted-use data from licensees and/or from the location originally issued the restricted-use data when poor protection of data warrants the retrieval. Prior to retrieval of the data, the contractor shall get permission from the IES Data Security Officer and COR.

v. bearing responsibility for the security of the licensee’s License information and all relevant NCES data to and from the sites.

The contractor shall complete an inspection form and electronically transmit the form to the Task Leader and Data Security Officer for review and appropriate action within two (2) weeks after the inspection is conducted. The individual inspection report should include evidence of compliance with or violation of the terms of the licensing and security procedures. In addition to the individual inspection reports, the contractor shall also submit a bi-weekly “Action Required” spreadsheet indicating any concerns identified during the site inspections and providing suggestions for potential actions. The currently used Action Required spreadsheet includes the following columns: date, license number, organization name, PPO name, notes from the site inspector, comments from NCES, and completion indicator. Minor infractions corrected in1d. ii should be included in the Inspection Report.

Requirement B: License Documentation System (LDS) Support Services

B-1. Maintain and Update LDS

The contractor shall maintain and continue to update the License Documentation System (LDS) that converts paper license documents using high resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text, in the form of electronic Acrobat PDF files that simulate the original license document forms. These PDF files will have the advantage of being keyword-searchable and fully secure. The system will allow for easy exportability and will allow for data conversion to alternative file systems according to IES/NCES needs (see further details below).

The Government owns the LDS software and contents. The contractor shall convert paper license documents using high-resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text files that are accessible across standard software platforms. The contractor must maintain a system that produces a customized electronic archiving solution by using data imaging to scan the paper files and by converting them into electronic PDF files. The resulting PDF files simulate the original document format, but the contractor shall ensure that they are keyword-searchable, fully secure, and have backwards compatibility with legacy systems while maintaining simple upgradability.

Every two (2) weeks, the an authorized contractor employee shall pick up paper license documents in person, convert them into PDF files, and upload the updated LDS information to the IES/NCES secure server.

B-2. Provide Physical Storage for License Documents

The contractor shall provide secure off-site office space for systematic storage of license documents after they have been scanned into the LDS. The office space shall: a) be an office room approximately 20 feet by 20 feet in width and depth; b) have least seven (7) four (4) drawer fire proof cabinets; c) have 24-hour CCTV monitoring (Non-IP access) seven (7) days per week; d) in house DVR recording and monitored by contract cleared personnel only; e) first floor office must be windowless and second and above must have at a minimum 8mm blast proof glass film on all windows; f) steel interior office entrance door; g) interior walls run to ceiling above and do not stop at ceiling tile height; and h) the room and office should have an alarm system installed (including window sensors and motion detectors).

The contractor shall include in their technical proposal a drawing that depicts the floor plan of the storage office space. Ideally, the drawing should include a layout of items and where they are placed in the office (i.e. fire proof file cabinets, work station, placement of monitoring devices, windows, doors, etc.).

Requirement C: Data Inspection Technical Support Services

The contractor shall provide inspection technical support services to the IES/NCES Data Security Program Office. At the request of IES/NCES, the contractor shall answer security questions from IES/NCES about the security of licensees’ facilities and other questions about the physical and electronic safeguarding IES/NCES confidential data.

Requirement D: Data Security Plan Document Review Services The contractor shall review and approve Security Plan proposals submitted by prospective licensees. The Security Plan form can be found at http://nces.ed.gov/statprog/rudman/pdf/j.pdf. The contractor’s review is to ensure that the licensee’s Security Plan meets all security requirements specified in the Restricted-Use Data Procedures Manual. For the Security Plan proposals that do not meet all security requirements (i.e., contains insufficient or unclear information about the security requirements), the contractor shall provide the applicants with clear review result delineating the specific requirements that need to added or clarified.

VI. Task Orders and WORK ORDER REQUESTS Task order 1: Data Security Site Inspection Support Services for 170 licenses This task order includes the work delineated in Requirements A-1, A-2, A-3 and A-4 under Section V. A total of 170 licenses shall be inspected under this task order for the base year (year 1). For years 2-10 (Option Year 1, Option Year 2, Option Year 3, Option Year 4 and the Renewal Period which may be up to 5 years), a total of 200 licenses for each year shall be inspected under this task order. (See Section VII, Period of Performance, for more information regarding the life of the contract.) The Government expects to award Task Order 1 upon award of the contract.

Task order 2: License Documentation System (LDS) Support Services

This task order includes the work delineated in Requirements B-1 and B-2 under Section V. The Government expects to award Task Order 2 upon award of the contract.

Task order 3: Data Inspection Technical Support Services

This task order includes the work delineated in the Requirements C under Section V. The Government expects to award Task Order 3 upon award of the contract.

WORK ORDER REQUESTS:

Data Security Site Inspection Support Services for 25 licenses

These work order requests include the work delineated in Requirements A-1, A-2, and A-4 under Section V. A total of 25 licenses shall be inspected under this task order. The Data Security Site Inspection Support Services for 25 licenses will be issued on an as needed basis.

Security Plan Document Review Services for 50 Security Plan proposals

These work order requests include the work delineated in the Requirements D under Section V. The Security Plan Document Review Services for 50 Security Plan proposals will be issued on an as needed basis.

VII. Period of Performance

The period of performance for the base year of this contract is nine and one-half months starting July 1, 2013 to continue through April 16, 2014. After the base year, the contract will be awarded for a 12 month period with annual one-year options (Option Year 1, Option Year 2, Option Year 3, Option Year 4) for years two through five (2-5) of the contract, if exercised. For example, the second year of the contract will start April 17, 2014 to continue through April 16, 2015, if the annual option is exercise. Further, in accordance with PL 107.279, Section 154, the NCES Commissioner has the discretion to renew the contract for an additional period of not more than five years. Therefore, the total period of performance is 10 years.

VIII. Transition

Over the first week of the contract, if necessary, the Government may request transition meetings with the current contractor, the new contractor Project Director and Data Security Investigator, the Task Leader, and the COR, aimed at orienting the new contractors to the work to be done. In the transition meetings, the new contractor will have opportunities to review examples of acceptable deliverables, and ask any clarification questions. The number of hours for the transition is a total of 20 hours.

IX. Assumptions

The contractor shall pay for all the travel, per diem, and any other costs associated with site visits. This includes travel to and from the licensee sites. No government reimbursements for these costs will be made as a result of work conducted under this contract. In order to minimize its own travel cost, the contractor is encouraged to conduct inspections in clusters of multiple sites when in certain regions of the country.

All data, either in paper or electronic form, related to the work of this task are confidential. The paper documents that need to be converted into PDF files and stored in the License Documentation System shall be picked up in person by an authorized contractor employee on a biweekly schedule. The government also needs to have easy accessibility to the physical data storage for monitoring purpose. For these reasons, the contractor selected to conduct the work described in the PWS must be located within 50 miles from the NCES office.

The Contract shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4. Specific criteria to be deemed IPv6 capable are:

· An IPv6 Capable system must meet the IPv6 base requirements defined by the USGv6 Profile and Testing program as found here “http://w3.antd.nist.gov/usgv6/testing.html”.

· Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities.

· Systems shall implement IPv4/IPv6dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with.

· If either protocol is possible, systems shall employ IPv6.

· The contractor shall provide IPv6 technical support for system development, implementation and management

· System Development Standards:

Information systems shall be developed in accordance with the ED Lifecycle Management Framework (LCM), ACS-OCIO 1-106.

X. Estimated Level of Effort For the base year of work (7/1/2013 – 4/16/2014), the Government estimates the following hours for the Task Orders:

Task Orders 1, 2, and 3 combined: Approximately a total of 396 hours of a Project Director/Senior Data Security Investigator, 982 hours of a Data Security Investigator, and 190 hours of Research Assistant.

WORK ORDER REQUEST:

Data Security Site Inspection Support Services for 25 licenses

Approximately a total of 60 hours of a Project Director/Senior Data Security Investigator and 125 hours of a Data Security Investigator for every 25 license inspections.

Security Plan Document Review Services for 50 Security Plan proposals Approximately a total of 100 hours of a Data Security Investigator for every 50 security plan proposal reviews.

For the Option years 1 through 9, the Government estimates the following hours for the Task Orders:

Task Orders 1, 2, and 3 combined: Approximately a total of 500 hours of a Project Director/Senior Data Security Investigator, 1240 hours of a Data Security Investigator, and 240 hours of Research Assistant.

Data Security Site Inspection Support Services for 25 licenses

Approximately a total of 60 hours of a Project Director/Senior Data Security Investigator and 125 hours of a Data Security Investigator for every 25 license inspections.

Security Plan Document Review Services for 50 Security Plan proposals Approximately a total of 100 hours of a Data Security Investigator for every 50 security plan proposal reviews.

The personnel performing the license inspections shall be experienced working with institutions of higher education, research organizations, state governments, and other categories of users of restricted IES/NCES data and shall have a minimum of six (6) years of law enforcement investigative experience, including four (4) of those years specifically in the area of security plan formulation and sensitive inspections. The personnel shall be acquainted with the NCES “Restricted-Use Procedures Manual” and the provisions of the Privacy Act of 1974, as amended, Family Educational Rights and Privacy Act of 1974the U.S, Patriot Act of 2001, Education Sciences Reform Act of 2002, , and Federal and Confidential Information Protection and Statistical Efficiency Act of 2002.

The personnel performing the licensing inspection shall also pass the required IES/NCES security clearance procedure and the IES/NCES annual security training required of all contractors before conducting any site inspections.

XI. Deliverables

Requirements
Deliverable
Estimated Due Date
Requirement A-1: Select Inspection Sites
A List of licenses for inspection
Within two weeks of Task Order initiation
Requirement A-2 : Complete a Site Inspection Plan
An inspection plan containing: 1) the list of licenses to be inspected including license number, name of the PPO, location of the organization, etc., and 2) the tentative month for each inspection.
Within two weeks after the list of licenses is approved
Requirement A-3: Update the Site Inspection Form
Computer assisted interview tool and inspection form

Within one month of contract initiation

Requirement A-4: Conduct Site Inspections
Individual inspection report for each inspection
Within two weeks after each site visit; ongoing
An “Action Required” spreadsheet listing the concerns identified during the site inspections and providing suggestions for potential actions.
Biweekly

A monthly report that includes:

1) a cumulative report that includes the list of license inspections in each of the previous months in the contract year by each license number, PPO name, city, state, and organization’s name;

2) the list of licenses to be inspected in the current month by each license number, PPO name, city, state, and organization’s name; and

3) the list of licenses to be inspected in the remainder of the year, by month;

The 5th of each month.

Requirement B-1: Maintain and Update LDS
A monthly report that includes:

1) a cumulative report that includes the list of paper license documents scanned into the License Documentation System (LDS) in each of the previous months in the contract year by each license number, PPO name, city, state, and organization’s name; and;

The 5th of each month.

Requirement C: Data Inspection Technical Support Services
A monthly report includes the number of hours contractor provided technical support to IES/NCES about licensees by each license number, PPO name, city, state, and organization’s name.
The 5th of each month.
Requirement D: Data Security Plan Document Review Services
A monthly report includes a cumulative report that includes the list of security plans reviewed in each of the previous months in the contract year by each license number, PPO name, city, state, and organization’s name.
The 5th of each month when the services are needed.

XII. Pricing Schedule

By the 16th of the month, the contractor shall submit to the Government an invoice of the deliverables that were submitted to and accepted by the Government during the previous calendar month.

XIII. Invoicing and Monthly Reports

Invoicing

The invoice for the prior month’s work much be received by 16th of each month. The invoice shall be submitted to OCFOCAMInvoicing@ed.gov with a carbon copy to the Contract Specialist, COR, and appointed Task Leader.

Monthly Report

The contractor shall submit monthly reports on or before the 5th of each month. The monthly reports are to be submitted via paper and electronic transmission. The monthly report shall be submitted to the COR, appointed Task Leader, and Contract Specialist.

XIV. Place of Performance

The contractor shall perform its services either at the contractor’s site, or at the office of IES/NCES, or by traveling to other licensee sites located throughout the United States and performing its services, as requested by the Government.

XV. Other Requirements

Confidentiality Requirements

The contractor shall implement such confidentiality and security provisions as NCES may require.

Deliverables

The contractor shall provide all deliverables in electronic formats.

XVI. Government Furnished-Information The Government owns the LDS software and existing database.

Appendix A

Potential Locations of License Inspection

The possible locations of license inspection may include, but is not limited to, the cities in the table below. The locations are subject to change due to constant addition and deletion of the licenses.

Region 1: Northeast

New England
Middle Atlantic

CT: New Haven, Storrs

MA: Amherst, Boston, Cambridge, Chestnut Hill, Medford, Northampton, Roxbury, Shrewsbury, Somerville, Waltham, Wellesley, Woburn

ME: Lewiston

NH: Durham

RI: Kingston, Providence

VT: Burlington NJ: Glassboro, Joint Base McGuire Dix Lakehurst, Mahwah, Montclair, New Brunswick, Piscataway, Princeton, Teaneck, Wayne

NY: Albany, Alfred, Binghamton, Bronx, Buffalo, Canton, Cortland, Flushing, Hamilton, New York, Queens, Rochester, Saratoga Springs, Stony Brook, Syracuse

PA: Bethlehem, Haverford, Middletown, Newtown, Philadelphia, Pittsburgh, University Park, Villanova

Region 2: Midwest

East North Central
West North Central

IL: Champaign, Chicago, DeKalb, Normal, Springfield

IN: Bloomington, Notre Dame, West Lafayette

MI: Ann Arbor, Detroit, East Lansing, Kalamazoo, Mt. Pleasant, University Center

OH: Cincinnati, Cleveland, Columbus, Dayton, Kent, University Heights

WI: La Crosse, Madison, River Falls IA: Iowa City

KS: Lawrence, Manhattan, Topeka

MN: Minneapolis, St. Cloud, St. Paul

MO: Springfield, St. Louis

ND: Fargo

NE: Lincoln, Omaha

Appendix A

Region 3: South

South Atlantic
East South Central
West South Central

DC: Washington

FL: Boca Raton, Coral Gables, Ft. Myers, Gainesville, Orlando, Tallahassee

GA: Athens, Atlanta, Kennesaw

MD: Baltimore, Bethesda, Bowie, College Park, Rockville

NC: Chapel Hill, Charlotte, Davidson, Durham, Elon, Raleigh, Winston-Salem

SC: Columbia, Rock Hill

VA: Alexandria, Arlington, Blacksburg, Charlottesville, Fairfax, Lexington, Norfolk, Richmond, Williamsburg AL: Auburn, Tuscaloosa

KY: Lexington, Louisville

MS: Mississippi State University

TN: Knoxville, Nashville AR: Fayetteville, Little Rock

LA: Lafayette

OK: Norman, Stillwater, Tulsa

TX: Austin, Denton, Houston, Huntsville, Odessa, Richardson

Region 4: West

Mountain
Pacific

CO: Boulder, Colorado Springs, Denver, Fort Collins, Greeley

MT: Bozeman, Missoula

NV: Las Vegas

UT: Provo, Salt Lake City CA: Aliso Viejo, Bakersfield, Berkeley, Chico, Davis, Fullerton, Long Beach, Los Angeles, Menlo Park, Merced, Northridge, Oakland, Orange, Palo Alto, Riverside, Sacramento, San Diego, San Francisco, San Luis Obispo, Santa Barbara, Santa Monica, Stanford

HI: Honolulu

OR: Eugene

WA: Seattle

Appendix B

Site Inspection Form

Restricted-Use Data Security Assessment

□ COMPLIANT □ NONCOMPLIANT

Inspection Date:
_______________________________
Data Holder:
_______________________________________
License Number:
_______________________________
Organization:
_______________________________________
Person Interviewed:
_______________________________
City & state:
_________________
Phone: _____________

THIS AREA TO BE COMPLETED BY NCES REPRESENTATIVE DOING ONSITE INSPECTION:

Is the location consistent with the License Agreement Security Plan? _____________________________________ □ YES □ NO

Is the Data Holder currently using the restricted-use data? (IF NO, advise Data Holder to contact Client Program office to close license) _______________________________________________________________________________________ □ YES □ NO

Minor Infractions

□
Data Holder not available at the time of the inspection
□
No computer warning signs
□
Office door unlocked
□
License files not located with data
□
Window(s) open
□
Unauthorized users have access to the project office
□
Computer viewable by non-employees
□
Use of weak passwords
□
Unlocked data storage cabinet
□
Other:
□
Data Holder lost key to data storage cabinet

Major Infractions

□
Data Holder lost data
□
Computer connected to internet
□
Data Holder relocated
□
Data Holder not in control of data
□
Use of laptop computer
□
Unauthorized users have access to data
□
Data use at home residence
□
Computer is not password protected
□
NCES representative denied access to data
□
Lack of adequate firewall protection
□
Data loaded on server or network
□
Lack of antivirus software
□
Use of external hard drive/USB flash drive
□
Other:

Facility Security

□
Open access building
□
Swipe card access required for office suites
□
Building doors locked after normal business hours
□
Receptionist present at main entrance
□
External door is accessible after business hours only with a swipe card
□
There is evidence of suspicious activity (see comments sheet)
□
No security guard/police force in place
□
Other:

NCES Representative Action Taken

□
Follow up with Data Holder
□
Forwarded to Data Security Officer
□
Data Holder does not respond to NCES representative’s attempts to contact
□
Other:

Photos

Photo 1 Description: _________________________________ Photo 2 Description: _________________________________

Photo 3 Description: _________________________________ Photo 4 Description: _________________________________

NCES Representative: _______________________ Signature: ________________ Date: __________

Photos

Photo 5 Description: _________________________________ Photo 6 Description: _________________________________

Comments

Inspection Interview Notes

Inspection Date:
_______________________________
Data Holder:
_______________________________________
License Number:
_______________________________
Organization:
_______________________________________
Person Interviewed:
_______________________________
City & state:
_________________
Phone: _____________

THIS AREA TO BE COMPLETED BY NCES REPRESENTATIVE DOING ONSITE INSPECTION:

� As amended by Federal Register, 62:35044-35050.

- 1 -

File details come from the government source that posted it. Updated .