Appendix_4_-_NPSAS-16_Contractor_Employee_Security_Screening_Policy.docx

DOCX document 25 KB Posted

Attached to
National Postsecondary Student Aid Study (NPSAS 2016) & Postsecondary Longitudinal Studies Federal contract opportunity
Solicitation number
ED-IES-13-R-0011
Issued by
Department of Education Contracts and Acquisition Management

About this file

APPENDIX 4 - CONTRACTOR EMPLOYEE SECURITY SCREENING POLICY - NPSAS 2016

View the file

Other files for this federal contract opportunity

Other files attached to National Postsecondary Student Aid Study (NPSAS 2016) & Postsecondary Longitudinal Studies, newest first.
File Type Posted
Attachment_A_-_NPSAS-16_Performance_Work_Statement_(SAS).pdf PDF
Amendment_3_-_NPSAS_2016.pdf PDF
Appendix_3_-NPSAS-16_IT_Program_Assessment_Guide_copy.pdf PDF
Attachment_D_-_NPSAS-16_Billing_Instructions.docx DOCX document
Attachment_B_-_NPSAS-16_Quality_Assurance_Surveillance_Plan_(2).docx DOCX document
Attachment_F_-_NPSAS-16_Contractor_Employee_Security_Screening.docx DOCX document
Attachment_A_-_NPSAS-16_Performance_Work_Statement_040113.docx DOCX document
Attachment_H_-_NPSAS-16_Evaluation_Criteria.doc DOC document
Attachment_I_-_NPSAS-16_Subcontracting_Plan_Review_Forms.docx DOCX document
Attachment_J_-_NPSAS-16_Contract_Tasks.doc DOC document
Attachment_C_-_NPSAS-16_Pricing_Schedules_for_Fixed_Price_Deliverables_rev0419.docx DOCX document
FormSF33_NPSAS-16.pdf PDF
Appendix_2-_NPSAS-16_WebVTS_Data_Upload_Specifications.docx DOCX document
Appendix_1_-_NPSAS-16_Data_Elements_.xlsx XLSX spreadsheet
Attachment_G_-_NPSAS-16_Conflict_of_Interest_Certification.docx DOCX document
Attachment_E_-_NPSAS-16_Past_Performance.docx DOCX document
Attachment_A_-_DRAFT_PWS_NPSAS_04_01_13.docx DOCX document
Presolicitation_12-14.pdf PDF
presolicitation_conf.mp3 MP3 file
Draft_Performance_Work_Statement_NPSAS_2016.docx DOCX document
Draft_Performance_Work_Statement_NPSAS_2016.docx DOCX document
Draft_PWS_NPSAS_2016_-_RFI —
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

APPENDIX 4

CONTRACTOR EMPLOYEE SECURITY SCREENING POLICY

2015-16 National Postsecondary Student Aid Study (NPSAS 2016) & Postsecondary Longitudinal Studies

(ED-IES-13-R-0011)

The Department has established policy on personnel security screening for all contractor and subcontractor employees and their field staff. The relevant Departmental Directive is OM:5-101. It was last updated in July 2010 and can be found at: http://www2.ed.gov/policy/gen/leg/foia/acsom5101.pdf.

The contractor must comply with the personnel security-screening requirements in OM:5-101 throughout the life of the contract.

The type of screening and the timing of the screening will depend upon the nature of the contractor position, the type of data the contractor employee will have access to, or the type of Departmental information technology (IT) system they will access. Personnel security screenings will be commensurate with the risk and magnitude of harm the individual could cause to the Department or the public. A position risk level will be assigned to each contractor employee position, before a solicitation is released, consistent with the descriptions in Appendix I of OM:5-101. Hence, each contractor employee working on this contract must be assigned a position risk level. Depending on the risk level assigned to each person's position, a follow-up background investigation by the Office of Personnel Management (OPM) may occur.

The contractor must identify one of their employees as a security liaison for this process. This Contractor Security Liaison coordinates the distribution, collection, and dissemination of various forms required in this process. They answer general questions from their employees on completing the security screening process. And, they are the first point of contact for contractor employees in using the OPM‟s Internet based security screening portal called e-QIP (http://www.opm.gov/e-qip/). The contractor is also responsible for ensuring that all subcontractors follow these personnel security screening procedures.

NCES requires each contractor employee to have or apply for a clearance for the security level designated for the position held on a contract.

Contractor employees who have undergone appropriate personnel security screening for another Federal agency will be required to submit proof of that personnel security screening for validation. For these employees, the contractor or subcontractor must follow these required steps:

1. The contractor must send the COR a letter on Company letterhead that lists the full name of each employee with a pre-existing clearance, the agency that cleared the employee, the level of the clearance, and the date of the clearance. This letter must be transmitted to the COR within two (2) business days of starting work on an NCES contract.

2. In those cases where any of the required information on level of clearance, agency that cleared the employee and date of clearance is not available, the contractor must send the COR a letter on Company letterhead that lists the full name and Social Security Number for each employee with a pre-existing clearance. This letter must be transmitted to the COR within two (2) business days of starting work on an NCES contract.

3. The COR will transmit the letter to the NCES Security Representative for processing.

4. The NCES Security Representative reviews the letter to ensure that the required information is provided and either returns it to the contractor for completion or releases it to the Department of Education Chief of Personnel Security. The contractor must resubmit the letter to the COR within 7 business days or the contractor employee must be removed from the contract.

5. The NCES Security Representative will notify the contractor or subcontractor if the pre-existing clearance was identified and ruled to be acceptable by the Department of Education Chief of Personnel Security.

6. Those employees whose pre-existing clearances are not verified and approved must follow the process outlined next to apply for a security clearance.

For contractor employees who have not undergone appropriate personnel security screening for another Federal agency, all contractors must comply with the Principal Office (PO) Executive Office or Computer Security Officer‟s pre-processing requirements for personnel security screening and granting access privileges. No contractor employees are permitted unsupervised access to unclassified sensitive information (i.e., personally identifiable information), direct access to respondents who are minors, or Department of Education IT systems until they have submitted applicable security screening documents.

For each contractor employee in a moderate risk level position the completed security screening documents must be accepted by the COR and the NCES Security Representative and submitted to the Department of Education Chief of Personnel Security within 14 days of the date the contractor employee starts working on the contract. In order to meet this Departmental requirement, steps 1 through 7 must be completed within 14 days of the date the contractor employee starts working on the contract. To meet this 14 day deadline and the interim deadlines specified below, it is strongly recommended that the contractor request the account initiation three (3) weeks before the contractor employee starts contract work and encourage each contractor employee to complete all required security screening forms before starting contract work.

Contractor employees in High Risk IT (6C) Level positions require preliminary personnel security screenings before they are given access to unclassified sensitive information or Department of Education IT systems (see page 7 of OM:5-101 for more details).

The security screening of contractor and subcontractor employees not holding ED recognized security screening credentials must follow these required steps:

1. The contractor must provide the COR with an electronic listing of all employees on a specific contract, with the risk level associated with the position held by each employee as specified in the contract solicitation. The COR will review the electronic listing for completeness and approve. The listing will not be approved if it is found to be incomplete.

2. The Department of Education participates in the OPM e-QIP system to facilitate the security screening process for contractor employees. NCES will initiate an e-QIP account for each contractor employee. It is advisable to request the account initiation three (3) weeks before the contractor employee starts contract work. For the initiation of these accounts, the Contractor Security Liaison must use the COR-approved list of employees and the risk levels assigned to the employees‟ positions to produce and submit the following list using the attached template:

a. For each contractor employee provide: Social Security Number, Full Name, Date of Birth, Place of Birth, risk level, e-Mail Address, and phone number. The Contractor Security Liaison must place the spreadsheet in a password protected file, then upload the list to the NCES secure server, and send an e-mail notification of the transmission to the NCES Security Representative. The NCES security staff will use this list to establish the contactor employee e-QIP accounts. The COR will work with the contractor to establish access to the NCES secure server at the outset of the contract.

b. Once NCES sets up the e-QIP accounts for contract employees, the NCES Security Representative will send an email to the Contractor Security Liaison stating that the employee has an active account on the e-QIP system. The COR is copied on this email notification.

c. The Contractor Security Liaison must notify their employees of this active account. A computer with Internet access and web browsing software is required for the contractor employee to access their E-QIP account. Each employee must log into their personal account in e-QIP, enter the requested information, finish the application process and print, sign, and date the e-QIP signature pages.

3. Each contractor employee must submit a completed set of security screening forms to their Contractor Security Liaison as provided by the NCES Security Representative, including for example:

a. The signed and dated e-QIP signature pages,

b. The Declaration of Federal Employment (OPM form OF-306),

c. The Fair Credit Release Form,

d. The Request for Security Officer Action (RSA) Form,

1) The contractor employee shall complete only those items in section 1 of the form (name, date of birth, place of birth, organization, position title, duty station, social security number, and work phone number).

2) The contractor shall complete section 5 (Project Requiring Highest ADP Level) using the assigned security clearance for each employee’s position.

e. Two sets of fingerprints on separate copies of form FD-258,

1) The Contractor Security Liaison shall help arrange fingerprinting for each contractor and subcontractor employee. Fingerprinting can usually be done at a local police station. (Electronic fingerprints are not accepted at this time.)

4. Each contractor must ensure that the forms are complete and that all contractor employee required security screening forms are transmitted to the COR within two (2) business days of an employee starting work on an NCES contract.

a. The Contractor Security Liaison must collate the forms in each security screening package by employee and transmit a complete set of security screening documents for each employee to the COR via courier (e.g., Federal Express) using a tracking number with signature required,

b. The COR will not accept security screening packages that are not collated by employee (i.e., all forms noted in point 3 above will be bundled by employee). The COR will review all security screening documents for each contractor employee for completeness, returning any incomplete security screening documents to the Contractor Security Liaison for completion. The contractor must resubmit the completed security screening documents to the COR within 7 business days or the contractor employee must be removed from the contract. No contractor employees are permitted unsupervised access to unclassified sensitive information (personally identifiable information), direct access to respondents who are minors, or Department of Education IT systems until they have resubmitted applicable screening documents.

5. The COR will submit the completed packages of security screening documents to the NCES Security Representative for processing.

6. The NCES Security Representative reviews each package of security screening documents and electronic information submission to ensure everything required has been provided and either rejects the package, sending it back to the submitter for completion/correction or releases it to the Department of Education Chief of Personnel Security. In the event that an application is rejected at this stage, the contractor must resubmit the corrected forms to the COR, or have the contractor employee correct the e-QIP submission, within two business days. The NCES Security Representative must be notified as soon as the updated e-QIP submission is completed.

7. The contractor employee application for each individual in a moderate risk level position must be submitted to the Department of Education Chief of Personnel Security within 14 days of the date the contractor employee starts working on the contract. Contractor employees in High Risk IT (6C) Level positions require preliminary personnel security screenings before they are given access to unclassified sensitive information or Department of Education IT systems.

8. After a package of security screening documents is transmitted to the Department of Education Chief of Personnel Security, the Office of Management security staff conducts a further review and either rejects the package of security screening documents, sending it back to the submitter for completion/correction or releases it to OPM.

9. OPM then assigns an investigator to conduct the type of investigation indicated by the department (this is tied to the level of access to PII that the applicant will have).

10. The Chief of Personnel Security will request the expansion of background investigations to obtain additional information to the extent necessary to make personnel acceptability or suitability determinations. These determinations will be made using criteria established by the OPM for the purpose of determining suitability for employment in the Federal competitive service, as described in 5 CFR 731.202, and other OPM guidance as applicable. The Chief of Personnel Security determines whether a contractor employee is acceptable for the position from a personnel security standpoint.

11. When the OPM investigation is complete, the RSA form with the clearance indicated is sent to the Department of Education’s Office of Management for processing.

12. The Office of Management returns the RSA form to the NCES Security Representative for recordation and distribution to the COR.

13. The COR transmits the RSA form with clearance indicated to the Contractor Security Liaison for their records and for distribution to the Contract Project Leader.

14. The Contract Project Leader then distributes copies of the clearance to the employee.

15. The Chief of Personnel Security will inform the NCES COR when he or she determines that a contractor employee is not acceptable to render service(s) or, if appropriate, to otherwise perform under a contract.

16. Each contractor will officially notify its contractor employee if he or she will no longer work on an ED contract.

17. In the event a contractor employee is deemed unacceptable for the position from a personnel security standpoint, the Chief of Personnel Security will usually provide the contractor employee with an opportunity to refute, explain, clarify, or mitigate information in question.

18. If, after final determination by the Chief of Personnel Security, a decision is made that the contractor employee is not acceptable to render services on a contract and access is denied, the COR will inform the Contracting Officer. The Contracting Officer must inform the contractor (i.e. employing firm) that the contractor employee is not acceptable to render services in this particular position, or, if appropriate, to otherwise perform under the contract. The contractor will notify the contractor employee. A final determination cannot be appealed.

19. At any time during the life of the contract a contractor or subcontractor employee (including any field staff) discontinues work on the contract or leaves the employment of the contractor, the contractor shall notify the COR within two days of the date that the employee is no longer working on the contract or within one business day if removed for cause. The contractor shall provide the reason why the employee is no longer working on the contract. The COR will provide this information to the NCES Security Representative.

20. Each contractor is responsible for the protection of sensitive or Privacy Act-protected information from unauthorized use or misuse by its employees, subcontractors, or temporary workers, and for preventing access to others, who are not authorized and have no need to know such information.

21. The contractor shall submit monthly information to the COR indicating which employees were billed to the contract that include the e-QIP number of the person being billed. The COR will reject payments to employees without an e-QIP number. For employees with pre-existing clearances from other contracts, this shall be noted on the monthly payment form.

The contractor shall verify with the COR that the security screening processes have not changed by the time the contract is active.

File details come from the government source that posted it. Updated .