FEMA MSAT G2 Program SOW.pdf
PDF 387 KB Posted
- Attached to
- MSAT G2 hardware and services Federal contract opportunity
- Solicitation number
- 70FA3022R00000006
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Demonstrated Prior Experience Questionnaire_MSAT G2.docx | DOCX document | |
| 70FA3022R00000006 - MSAT.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEPARTMENT OF HOMELAND SECURITY (DHS)
FEDERAL EMERGENCY MANAGEMENT AGENCY
(FEMA)
STATEMENT OF WORK
FEMA MSAT G2 Program
Source-Selection Sensitive, FOUO Page 2 of 24
Table of Contents
1 Project Description
1.1 Project Background
1.2 Scope
2 Statement of Work
2.1 Task 1: Mobile Satellite Radio and Voice Services
2.2 Task 2: Management Services
2.2.1 Fault Management
2.2.2 Account Management
2.2.2.1 Account Manager
2.2.2.2 Account Billing
2.2.3 Completion of Order
2.2.4 Reports
2.2.5 Technical Assistance
2.2.6 Security Management
2.3 Task 3: Transition and Implementation
2.3.1 Transition-In and Implementation
2.3.2 Transition-Out
2.4 Deliverables and Delivery Schedule
2.5 Period of Performance
2.6 Place of Performance
3 Section 508 Requirements
4 Security Training
5 Privacy
INFORMATION SHARING
Source-Selection Sensitive, FOUO Page 3 of 24
1 Project Description
The Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA) MSAT G2
Program, hereinafter referred to as MSAT or MSAT Program, provides a commercial satellite-based subscription services for two-way, push-to-talk (PTT) dispatch radio and voice telephone service for use by
FEMA emergency responders. These telecommunication services support FEMA’s disaster response and recovery efforts and the continuity of operations (COOP) program nationwide.
1.1 Project Background
The Department of Homeland Security (DHS), Federal Emergency Management Agency’s (FEMA) primary mission is to reduce the loss of life and property and protect the Nation from all hazards, including natural disasters, acts of terrorism, and other manmade disasters, by leading and supporting, the Nation in a risk-based, comprehensive emergency management Under the authority of the Robert T. Stafford Disaster Relief and
Emergency Assistance Act, as amended, Public Law (P.L.) 93-288, FEMA assists State and local governments across the Nation to respond to and recover from natural and man-made disasters. FEMA’s mission is to support our citizens and first responders to ensure that as a nation we work together to build, sustain, and improve our capability to prepare for, protect against, respond to, recover from, and mitigate all hazards.
FEMA full-time employees work at headquarters located in Washington D.C. There are regional and area offices across the country, Mount Weather Emergency Operations Center, and the National Emergency Training Center in Emmitsburg, Maryland, respectively. FEMA also has standby disaster assistance employees who are available for deployment after disasters. FEMA requires satellite-based subscription services for push to talk
(PTT) dispatch radio and voice telephony service to meet its responsibility to provide seamless communication between its supporting personnel in the event of a disaster.
The purpose of this SOW is to describe the satellite services and support required by FEMA for national disaster operations. The Contractor shall be responsible for providing satellite airtime services to support FEMA’s existing equipment assets and any new devices acquired during the period of performance of this contract.
Currently, the MSAT mission is being supported through a satellite subscription service contract. This contract provides a two-way, PTT dispatch radio service and voice service for FEMA’s current estimated device count of
350 satellite radio devices. The devices operate on the Ligado Networks satellite network. The Ligado network is often recognized by the names of the satellites in operation: MSAT 1 & 2 and SkyTerra 1. Services provided on the Ligado Networks satellite network include:
▪ PTT satellite radio service for dispatch operations via talk groups
▪ Telephone Public Switched Telephone Network (PSTN) services
▪ Satellite Mutual Aid Radio Talk (SMART) talk groups for interoperable communications amongst public safety agencies
FEMA has a continued need for the MSAT G2 requirements in order to maintain service for FEMA’s current devices and any future devices that are purchased as the older devices are phased out.
1.2 Scope
The Contractor shall provide pre-existing, pre-engineered mobile satellite airtime services on the Ligado
Networks satellite network to FEMA anywhere within the established Ligado Networks Satellite Network
Coverage Area under all FEMA mission conditions. The Contractor shall transition FEMA current inventory of devices, activate new devices, de-activate old devices, and modify Talk Group configurations as required.
FEMA’s device count and associated service plan requirement are depicted in Attachment 1, FEMA MSAT
Service Requirements.
http://satellite-communications-products/satrad/ http://satellite-communications-products/satrad/ http://satellite-communications-products/satrad/ http://satellite-communications-products/satrad/smart-talk-groups/
Source-Selection Sensitive, FOUO Page 4 of 24
The Contractor shall:
1. Provide rapidly deployable mobile satellite communications to support disaster emergency response communications, and to support continuity of operations through service diversity (supplementing terrestrial networks).
2. Provide technologically advanced, effective, and cost efficient commercial satellite-based subscription services for two-way, PTT dispatch radio and voice telephony service within the Ligado Networks
Satellite Network Coverage Area for use by FEMA emergency responders.
3. Satisfy requirements for additional services (i.e. activation of new devices and Talk Group configuration) during emergency, surge and non-emergency situations.
4. Provide pricing for MSAT G2 terminal and hardware purchase.
5. Provide pricing plan for tech refresh / bulk terminal purchase and possible maintenance plans.
6. Provide effective and efficient work flow processes that capture FEMA programmatic approvals, use electronic ordering, and capture order accuracy detail (e.g., what was ordered, by whom, fiscal and cost data, and status information).
7. Promptly resolve trouble reports and manage troubleshooting issues with minimal impact on customers.
8. Transition-in existing services as appropriate within seven (7) calendar days of contract award.
9. Ensure accurate, timely invoicing and reporting.
The contractor shall provide services within the Ligado Networks satellite network subscription services to support FEMA’s MSAT Program devices.
2 Statement of Work
The SOW describes the services the Contractor shall be capable of providing to meet FEMA’s MSAT Program requirements.
2.1 Task 1: Mobile Satellite Radio and Voice Services
The Contractor shall provide the Government with satellite communication subscription services anywhere within the established Ligado Networks Satellite Network Coverage Area, illustrated in Figure 1 below:
Figure 1: Ligado Networks Satellite Network Coverage Map
Source-Selection Sensitive, FOUO Page 5 of 24
The Contractor shall provide FEMA with Ligado Networks satellite network subscription services for FEMA’s current inventory of devices and any future devices procured that require service during this period of performance. The services shall include the following:
1. Satellite airtime services
2. Telephone/PSTN services
3. E-911 Service
4. PTT satellite radio service for dispatch via talk groups
5. SMART talk groups for interoperable communications amongst public safety agencies
6. Activation of devices
7. De-activation of devices
8. Addition of talk groups to devices
9. Deletion of talk groups from devices
Within seven (7) calendar days of the Contract award, the Contractor shall provide voice telephony services, E-
911 service, and the specific two-way, PTT dispatch radio service for our “always on” activated 273 devices described in Attachment 1: FEMA MSAT Service Requirements.
In addition to this, the contractor shall provide services for surge capacity before, during and after disaster response.
Figure 2 provides a summary of the requirements contained in Attachment 1.
Service Device Count
Current active devices with no changes required 273
Current active devices that require talk group additions and/or updates 0
Surge Capacity 77
Total 350
Figure 2: FEMA Service Plan Requirement Summary
1*: At the present time there are no devices that require talk group or service activations. Surge capability needs to be addressed for future disaster responses.
2.2 Task 2: Management Services
The Contractor shall provide management services for all mobile satellite services provided. Management and
Operations Services encompass the essential activities and requirements necessary to provide quality services to
FEMA throughout the life-cycle of the Contract. Management and Operations Services begins with the overarching program management that sets the appropriate resources, systems, and processes in place with leadership to balance contract compliance, to meet the needs of FEMA and to manage the day-to-day operations and activities as required under this SOW.
The Contractor’s solution shall address managing, maintaining, and reporting on services provided to FEMA.
Service Management encompasses the processes, systems, and data required for the Contractor to ensure the quality of services delivered to the Government. The solution shall be capable of collecting and delivering the near real-time monitoring, fault/incident/outage reporting, and information access required to ensure effective and efficient operations, performance, and availability consistent with commercial best practices.
The contractor shall provide support of all services for Surge and Disaster response within 12 hours of notification. Contractor shall respond to service activation orders to support a disaster within two (2) hours after
Source-Selection Sensitive, FOUO Page 6 of 24 receiving written notification from FEMA to the Contractor’s customer service office. The contractor shall provide 24x7 United States based Network Operations Center support to assist with these services.
2.2.1 Fault Management
The Contractor’s solution shall provide the ability to recognize, isolate, correct and log faults that occur in the
Ligado Networks satellite network and use trend analysis to predict errors so that the network is always available. The contractor shall provide 24x7 United States based Network Operations Center support to ensure that timely fault resolution can be completed with a call to one location. The contractor shall provide both a local and 800 number that can be dialed by emergency responders.
2.2.2 Account Management
The Contractor’s solution shall include Account Management to gather usage statistics, track network utilization information, such that FEMA can be appropriately billed or charged for accounting purposes.
2.2.2.1 Account Manager
The Contractor shall provide a dedicated Account Manager responsible for managing FEMA’s service requirements.
2.2.2.2 Account Billing
The Contractor shall submit electronic data (Excel, CSV, or TXT files) of device, usage, service plan, and billing information to the appropriate COR and FEMA Vendor Finance on a monthly basis to ensure accountability and proper inventory management. Billing invoice format must be consistent with FEMA’s
Network Inventory and Optimization Solution (NiOS). Figure 3 below is an example of the billing format columns:
NiOS Invoice Columns
Foundation Account (If Applicable)
Invoice Number
Invoice Date
Cycle Begin Date
Cycle Close Date
Account Number
Unique Billing Identifier (Primary ID)
Secondary ID
FEMA Order Number
Rate Plan (Primary)
Rate Plan (Secondary [Feature])
Total Charge
Rate Plan (Primary) Charge
Rate Plan (Secondary [Feature]) Charge
Usage Category (Charged, pooled, free) Minutes Charge
Usage Category (Charged, pooled, free) Minutes Used
Usage Category (Charged, pooled, free) KB Charge
Usage Category (Charged, pooled, free) KB Used
Usage Category (Charged, pooled, free) Messaging Charge
Source-Selection Sensitive, FOUO Page 7 of 24
Usage Category (Charged, pooled, free) Messaging Used
Figure 3: NiOS Billing Format Example
The contractor shall ensure that all contract modifications that begin out of normal billing cycle with new activations will only be billed accordingly for the contracted period of performance (POP).
2.2.3 Completion of Order
The Contractor shall submit “Notice of Completion of Order” to the FEMA Enterprise Circuit Provisioning
Team / Primary COR (ECP) that provides detailed notification of completion for each order and service via
FEMA centralized ordering system or email.
2.2.4 Reports
FEMA has the need for reporting to complement its satellite communications services. Upon FEMA request, custom reports on orders, voice service plan usage, device Talk Group plans, billing, costs, savings, and trouble reports shall be provided and included in the Contractor’s solution. Typically, these reports refer to Call Data
Records (CDR) and/or other information pertaining to usage.
The reporting capability shall allow the ability to export all fields into Excel for data manipulation purposes.
Historical reporting shall be available for a minimum of 12 months.
The reporting capability shall include a customized Electronic Serial Number (ESN) Inventory List reporting capability that includes the Data Fields described in Figure 4:
ESN Inventory Data Fields Description
Device Sat ESN Device Satellite Electronic Service Number
MT ID Mobile Terminal Number ID Number
Call Type Voice or Data
MSAT # Mobile Satellite Number
Toll Free # Toll-free Number
NR MT ID Network Radio Mobile Terminal ID Number
NR Net ID Tag Network Radio Network ID Tag Number for the Talk Group
NR Description Network Radio Description
NR Monitor Code Network Radio Level of Monitoring Code
* FEMA Specific SIM Owner Name FEMA Specific Subscriber Identity Module
Owner Name (FEMA Region, Mobile
Emergency Response Support (MERS)
Team, etc.)
* FEMA Specific SIM Location FEMA Specific Subscriber Identity Module
Location (FEMA Region, Mobile Emergency
Response Support (MERS) Location, Joint
Field Office (JFO), etc.)
* FEMA Specific SIM Barcode Information FEMA Specific Subscriber Identity Module
Barcode Information
* These Data Fields shall be accessible by authorized FEMA users to populate the reporting data fields
Source-Selection Sensitive, FOUO Page 8 of 24
Figure 4: ESN Inventory Data Fields
2.2.5 Technical Assistance
The Contractor shall provide 24 hours a day, 7 days a week, 365 days a year US based technical assistance to all designated persons within FEMA. The contractor shall provide both a toll free and local number for all technical assistance calls.
The Contractor shall provide FEMA with escalation policies and procedures, with timeframes for expected levels of service to demonstrate prompt resolution of trouble reports and issues of all services, while ensuring minimal impact on customers.
2.2.6 Security Management
The Contractor’s solution shall include security management to control access to assets in its network to ensure that the network environment is secure and that the gathered security-related information is analyzed regularly.
Security management functions include managing network authentication, authorization, and auditing, such that both internal and external users only have access to appropriate network resources.
The solution shall restrict access to FEMA accounts to pre-authorized FEMA employees, representatives, and
FEMA contracted account management team members. No one, except the pre-authorized FEMA employees, representatives, and FEMA contracted account management team members, shall be authorized to make changes to FEMA accounts.
2.3 Task 3: Transition and Implementation
The Contractor shall execute a transition-in and implementation strategy that will effectively facilitate the seamless transition of FEMA’s current mobile satellite services from the existing service to the services awarded under this Contract within seven (7) calendar days of award.
2.3.1 Transition-In and Implementation
Contractor shall provide a Transition-In and Implementation Plan describing its transition approach and its action plan including technical and service management procedures to provide satellite communications subscriptions services throughout the life of the Contract. The Transition-In and Implementation Plan shall, at a minimum, address the following:
• Transition-In o The Contractor shall collaborate with the government and existing contractors to identify and transition-in the required services and solutions.
o The Transition-In and Implementation Plan shall include coordination with the Government, identification of key transition events, a transition schedule, identification of risks and mitigation strategies, key persons participating, and specific action that will be taken to alleviate risks that become issues.
o The Contractor shall be responsible for delivering a transition-in project plan with a comprehensive timeline for transition with their proposal submission.
o The Contractor shall be responsible for delivering a comprehensive risk and mitigation plan for transition-in efforts with their proposal submission.
o Contractor shall execute Implementation Plan and effectively transition services with seven (7) calendar days of Contract award.
• The contractor shall provide support of all services for surge and disaster response within 12 hours of notification.
• No cost or additional fees policy for:
Source-Selection Sensitive, FOUO Page 9 of 24 o Device Activation and Deactivation o Talk Group Addition and Deletion o Reports
• Termination of service and billing for lost or stolen equipment within 24 hours of notification
• Ability for current active devices to retain their current Toll-Free and MSAT phone numbers
2.3.2 Transition-Out
The Contractor shall provide Transition-Out services and a Transition-Out Plan describing its transition approach to another vendor as directed by the government in the Contract.
• The Contractor shall deliver a Transition-Out Plan for transferring MSAT G2 services to a successor vendor.
• The Contractor shall deliver transition-out plans that mirror the new Contractor’s transition-in plans and project schedules at the request of the government.
• During the transition-out period, there may be adjustments to the transition-in and transition-out plan and the Contractor shall review and revise their plan(s) accordingly.
• The Contractor shall facilitate, support and conduct transition-out activities in collaboration with the government and existing contractor in order to transition out the MSAT services and environment inclusive of functionalities, data and capabilities.
• The Contractor shall perform current contract requirements during the transition-out process.
• The Contractor shall conduct detailed overview sessions with the new contractor as directed by the government in order to provide visibility and insight into the existing solution and business processes.
• The Contractor shall deliver a final report outlining all work accomplished under the Contract and any issues/problems encountered. The report shall also make recommendations to enhance future performance of MSAT services.
• The contractor shall support transition-out activities by participating in Integrated Project Teams, providing timely responses to requests for information from FEMA or requests made on FEMA’s behalf and raising risks and issues for discussions.
2.4 Deliverables and Delivery Schedule
CONTRACT DELIVERABLES: The following deliverables are required for this award are as follows:
Deliverable Due Date
Kickoff meeting Within three (3) business days from
Contract award date
Transition-In and Implementation Plan Submitted with the Contractor's proposal
Conference Calls Periodic
Draft Project Plan Draft due at the Kick-Off Meeting for
Government review and comment
Final Project Plan Within ten (10) business days of the
Kick-Off Meeting. The Contractor shall continue to update and revise the plan as needed throughout the life of the Contract.
Source-Selection Sensitive, FOUO Page 10 of 24
Reports Report requirements may be specified to the Contract
Completion of Order Notices Upon completion of Contract requirements.
Account Billing Monthly
Conference Calls Periodic
2.5 Period of Performance
The period of performance shall be for one (1) 12-month Base Period plus four (4) 12-month Option Periods.
2.6 Place of Performance
The Contractor shall provide the required service(s) anywhere in the Ligado Networks Satellite Network
Coverage Area under all FEMA mission conditions.
Network and operational support services shall be performed at the Contractor’s facilities.
3 Section 508 Requirements
N/A
4 Security Training
SECURITY: All personnel require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees receive a favorably adjudicated public trust suitability prior to entry on duty (EOD). All individuals will be U.S. citizens. The contractor shall follow the standards established within DHS and FEMA policy.
Certificate of training is required for all cleared contractor employees who are working with classified or unclassified information. All certificates must be sent to the assigned FEMA Contracting Officer
Representative (COR), before the contractor or subcontractor is granted access to classified or unclassified information but no later than 30 calendar days after awarded contract. Send certificates of completion for
Unauthorized Disclosure, OPSEC, and Insider Threat to the FEMA COR no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
Unauthorized Disclosure of Classified or Unclassified Information
Contractors and subcontractors who are working on this contract shall receive Unauthorized Disclosure of
Classified or Unclassified Information training.
Access to the training can be obtained at:
https://securityawareness.usalearning.gov/disclosure/index.html
OPSEC Training
Contractors and subcontractors who are working on this contract shall receive the OPSEC Awareness Brief.
Access to the briefing can be obtained at https://securityawareness.usalearning.gov/opsec/
Insider Threat Training
Insider Threat training for contractors can be found at:
https://securityawareness.usalearning.gov/disclosure/index.html https://securityawareness.usalearning.gov/opsec/
Source-Selection Sensitive, FOUO Page 11 of 24 https://securityawareness.usalearning.gov/itawareness/index.htm#
For Official Use Only (FOUO) Information
In accordance with DHS Management Directive 11042.1 contractors, consultants and others to whom access is granted will abide by 11042.1; DHS policy regarding the identification and safeguarding of sensitive but unclassified information originated within DHS. It also applies to other sensitive but unclassified information received by DHS from other government and non-governmental activities.
The contractor shall:
1. Be aware of and comply with the safeguarding requirements for “For Official Use Only” (FOUO) information as outlined in this directive.
2. Participate in formal classroom or computer-based training sessions presented to communicate the requirements for safeguarding FOUO and other sensitive but unclassified information.
3. Be aware that divulging information without proper authority could result in administrative or disciplinary action.
Contractors and consultants shall execute a DHS Form 11000-6, Sensitive but Unclassified Information Non
Disclosure Agreement (NDA), as a condition of access to such information. Other individuals not assigned to or contractually obligated to DHS, but to whom access to information will be granted, may be requested to execute an NDA as determined by the applicable program manager. Execution of the NDA shall be effective upon date of the DHS Policy and not applied retroactively.
5 Privacy
SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
https://securityawareness.usalearning.gov/itawareness/index.htm
Source-Selection Sensitive, FOUO Page 12 of 24
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy
Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information
Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII
Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the
Department of Homeland Security (including the Assistant Secretary for the Transportation Security
Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements.
Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
Source-Selection Sensitive, FOUO Page 13 of 24
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only)
Information
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and
Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic
Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and
Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD
11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how
Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE
ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS
Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of
Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and
Security Program.
Source-Selection Sensitive, FOUO Page 14 of 24
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s
Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the
Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy
Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS
Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the
Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan
Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and
Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the
Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the
Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST
Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and
Organizations. The Contractor shall address all deficiencies before submitting the SA package to the
Government for acceptance.
Source-Selection Sensitive, FOUO Page 15 of 24
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or
Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and
SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the
Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy.
Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three
(3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The
Contractor shall update its SA package by one of the following methods:
(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the
Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the
Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the
Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the
Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the
Contractor IT system under this contract. Restricting access may include disconnecting the system
Source-Selection Sensitive, FOUO Page 16 of 24 processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the
Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request.
Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS
Information Security Performance Plan, or successor publication. The Contractor shall provide the
Government with all information to fully satisfy Federal reporting requirements for Contractor systems.
(f) Sensitive Information Incident Reporting Requirements.
(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or
Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A
Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the
Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2
Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the
Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.
(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in
4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
(i) Data Universal Numbering System (DUNS);
(ii) Contract numbers affected unless all contracts by the company are affected;
(iii) Facility CAGE code if the location of the event is different than the prime contractor location;
(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management
(address, position, telephone, email);
(v) Contracting Officer POC (address, telephone, email);
(vi) Contract clearance level;
(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;
(viii) Government programs, platforms or systems involved;
(ix) Location(s) of incident;
(x) Date and time the incident was discovered;
(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;
(xii) Description of the Government PII and/or SPII contained within the system;
(xiii) Number of people potentially affected, and the estimate or actual number of records exposed and/or contained within the system; and
(xiv) Any additional information relevant to the incident.
Source-Selection Sensitive, FOUO Page 17 of 24
(g) Sensitive Information Incident Response Requirements.
(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and
Headquarters or Component Privacy Officer.
(2) The Contractor shall provide full access and cooperation for all activities determined by the
Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:
(i) Inspections,
(ii) Investigations,
(iii) Forensic reviews, and
(iv) Data analyses and processing.
(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.
(h) Additional PII and/or SPII Notification Requirements.
(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting
Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or
Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or
Component Privacy Officer, has determined in writing that notification is appropriate.
(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:
(i) A brief description of the incident;
(ii) A description of the types of PII and SPII involved;
(iii) A statement as to whether the PII or SPII was encrypted or protected by other means;
(iv) Steps individuals may take to protect themselves;
(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and
(vi) Information identifying who individuals may contact for additional information.
(i) Credit Monitoring Requirements. In the event that a sensitive information incident involves PII or SPII, the Contractor may be required to, as directed by the Contracting Officer:
(1) Provide notification to affected individuals as described above; and/or
Source-Selection Sensitive, FOUO Page 18 of 24
(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified.
Credit monitoring services shall be provided from a company with which the Contractor has no affiliation.
At a minimum, credit monitoring services shall include:
(i) Triple credit bureau monitoring;
(ii) Daily customer service;
(iii) Alerts provided to the individual for changes and fraud; and
(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or
(3) Establish a dedicated call center. Call center services shall include:
(i) A dedicated telephone number to contact customer service within a fixed period;
(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;
(iii) Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics;
(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate;
(v) Customized FAQs, approved in writing by the Contracting Officer in coordination with the
Headquarters or Component Chief Privacy Officer; and
(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.
(j) Certification of Sanitization of Government and Government-Activity-Related Files and Information.
As part of contract closeout, the Contractor shall submit the certification to the COR and the Contracting
Officer following the template provided in NIST Special Publication 800-88 Guidelines for Media
Sanitization.
INFORMATION SHARING
A. INFORMATION SHARING RESPONSIBILITIES. The Contractor will use the information only for the purpose of this Agreement.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .