Actuarial Consulting Services PWS - Jan 7 2020.docx
DOCX document 238 KB Posted
- Attached to
- FIMA Actuarial Consulting Services Federal contract opportunity
- Solicitation number
- FIMA01172020
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI - Actuarial Consulting Services.docx | DOCX document | |
| FIMA01172020 Amendment 0001.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Federal Emergency Management Agency National Flood Insurance Program
Performance Work Statement Actuarial Consulting Services January 2020
1. Background:
The Federal Insurance and Mitigation Administration (FIMA) is a component of the Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), which operates the Risk the National Flood Insurance Program (NFIP).
For over 50 years, FEMA’s National Flood Insurance Program (NFIP) has offered flood insurance coverage to homeowners, renters, and businesses as protection against flood losses. In return, local governments commit to sound floodplain management and related flood disaster mitigation efforts. In addition to offering flood insurance, the duties of the NFIP include identifying communities’ flood risks, mapping and publishing FIRMs (Flood Insurance Rate Maps) of those risks, helping communities meet floodplain management requirements, and encourage citizens to purchase flood insurance in order to equitably distribute burdens among the insured and the general public.
While the NFIP as currently organized satisfies these duties, FEMA identified two primary service gaps within the NFIP’s current risk rating approach: (1) policyholders don’t understand their flood risk and (2) the relationship between risk and rate is often inconsistent between structures with similar risk. Therefore, FIMA has redesigned its current risk rating approach to address these service gaps and improve overall customer experience through the Risk Rating 2.0 Initiative.
Risk Rating 2.0 The National Flood Insurance Program (NFIP) is redesigning its risk rating system by leveraging industry best practices and current technology to deliver rates that are fairer, easier to understand, and better reflect a property’s unique flood risk.
FEMA is focused on building a culture of preparedness by closing the insurance gap. Recognizing that purchasing flood insurance can be confusing and time-consuming, the National Flood Insurance Program (NFIP) is redesigning its risk rating system to improve the policyholder experience.
Through these efforts, FEMA’s goal is to make flood insurance significantly easier for agents to price and sell policies, and in turn, help customers better understand their flood risk and the importance of flood insurance.
Risk Rating 2.0 will fundamentally change the way FEMA rates a property’s flood risk and prices insurance. The current rating methodology has not changed since it was first developed in the 1970s. Since then, technology has evolved and so has FEMA’s understanding of flood risk.
Additionally, the current rating methodology is heavily dependent on the 1-percent-annual-chance-event, while Risk Rating 2.0 will incorporate a broader range of flood frequencies. FEMA will be pairing state-of-the-art industry technology with the NFIP’s mapping data to establish a new risk-informed rating plan. Catastrophe models, in combination with the ability to leverage the NFIP’s mapping data, will provide a better and more comprehensive understanding of risk at both the national and local level.
FEMA is building a new rating engine to help agents easily price and sell policies. It will also allow policyholders to better understand their property’s flood risk and how it is reflected in their cost of insurance. New rates for all NFIP-insured properties will go into effect nationwide on October 1, 2021.
Risk Rating 2.0 will comply with existing statutory caps on premium increases. This will help transition policyholders who may face otherwise substantial rate increases.
The new risk rating plan will use easier-to-understand rating characteristics for each property, such as:
· Distance to the coast or another flooding source;
· Different types of flood risk; and
· The cost to rebuild a home.
By reflecting the cost to rebuild, the new rating plan will also aim to deliver fairer rates for owners of lower-value homes.
The Government is procuring Actuarial Consulting Services to assist the NFIP Actuaries in maintaining and updating the rates developed under Risk Rating 2.0.
2. Contract Type:
The Government anticipates a firm fixed price, single award task order for this requirement.
3. Scope:
The Government seeks to procure actuarial consulting services to provide advice and guidance on actuarial activities for the NFIP, and to provide staff augmentation services to the NFIP actuaries as they grow their internal capabilities. The NFIP Actuaries have spent the past three years developing an industry-standard rating plan and desires a Contractor that can assist them in keeping their methodology current with advancements in data, tools, models (to include commercial catastrophe and FEMA developed models), and industry advancements. The Government desires the Contractor to work as “one team” with the NFIP Actuaries. This will require close collaboration on techniques and documents, with an iterative review process between the Government and the Contractor. The Contractor should not expect to use typical internal review processes for this Contract.
NFIP Actuarial Staffing Plan The Actuarial and Catastrophic Modeling Branch is currently developing their internal capabilities by hiring additional staff to complete the actuarial team. Below is a preliminary staffing plan for illustrative purposes:
The Contractor should expect the level of effort to decrease in option years, as the internal actuarial capabilities increase.
4. Description of Services This Performance Work Statement (PWS) includes services for the annual rate development, continuous improvement of actuarial techniques for the NFIP, assistance with FEMA model development, audit and litigation support, and other actuarial consulting activities.
Task 1: Learn NFIP Risk Rating 2.0 Rating Methodology Over the past three years, the NFIP Actuaries, with significant support from the NFIP Rating and Policy Forms contractor, have been developing a new methodology for rating flood risk for the NFIP through the Risk Rating 2.0 Initiative. The newly developed rating methodology is a complement of industry standard best practices and unique Government requirements. The NFIP Actuaries strongly desire to keep the newly developed rating methodology in place, and to make continual improvements based on changes in data, tools, models, and industry advancements. It is essential that the Contractor work with the NFIP Actuaries and the NFIP Rating and Policy Forms contractor to fully understand the Risk Rating 2.0 methodology. The Contractor should be confident in their ability to replicate the development of rates using this methodology prior to the expiration of the RR2.0 Rate Development Transition Services contract. For this reason, the Government is planning on up to six months of overlap between contracts to ensure a successful transition.
The Contractor will adopt the data and tools used to develop the Risk Rating 2.0 rating methodology. This includes learning the historical rationale for using the selected data sets, tools, and methodologies. Many decisions were driven based on programmatic policy and regulations, data availability and applicable methodologies. It will be important to understand that history, in order to make recommendations and develop courses of action to improve data and tools during future advancements of the rating methodology.
The Contractor will review the NFIP data augmentation process, to understand the NFIP raw data collected (pre-Risk Rating 2.0), the new data sets that will be collected (post-implementation of Risk Rating 2.0), the assumptions that are made to augment the NFIP data, and the data sets that have been procured to augment the NFIP data. The Contractor will learn how the non-NFIP data sets, market basket, uniform and orthogonal books, were built and used. The Contractor will review the FEMA developed and commercial catastrophe model runs and their output.
The Contractor will review the developed generalized linear models (GLMs) and other models and analyses, as well as selected rating factors. The Contractor should learn in-depth how the GLMs and other models were created and analyzed by the NFIP Rating and Policy Forms Contractor. The Contractor should strive to understand the history of rating factor selection and desired points of improvement from both the NFIP actuaries and the incumbent actuarial contractor.
Both the data augmentation and the GLM review processes will require the Contractor to use and apply Geographic Information System (GIS) data extensively.
Additionally, the NFIP has a set of regulations and programmatic rules that apply to how rates are developed and implemented. A few of these include, grandfathering, pre-firm subsidies, capped rate increases, transition rules, CRS program, etc. The Contractor should spend time during transition to understand these rules, their application to rate development, and their impact on the financial standing of the NFIP.
The Contractor will in the first six months of the period of performance complete a full review and training provided by the incumbent contractor and the NFIP actuaries of the current rating methodology. The Contractor will replicate how the rate development process, to demonstrate their capability to the Government, prior to taking-over rate development activities.
Task 2: Annual Rate Updates The Contractor will assist the NFIP Actuaries with the updating of flood insurance rates to be delivered on an annual basis. These updates can range from a simple update (without changing the underlying structure of the rates), to a more complex update (changes to the structure). The Government expects simple changes in most years, with more complex changes occurring approximately every three years. However, the extent of changes to the rates in both simple and complex years can vary and are dependent on factors such as: significant updates to commercial catastrophe models or newly available catastrophe models, improvements or additions to the underlying data sources, updates to FEMA-developed models, significant changes to the book of business, etc.
The Contractor will provide project management services for the technical rate development work. The Contractor will work closely with the Chief Actuary and government project managers, to ensure all work is coordinated closely across the Government and Contractor actuarial teams.
Simple Changes - For years with simple changes in rating, the Contractor will collaborate with the NFIP Actuaries to complete the following activities:
· Update factors: The factors need to be reviewed by the Contractor and NFIP Actuaries against performance metrics and loss experience and adjusted annually to adapt to changes in the book of business, and for NFIP policy and claims handling changes.
· Expenses: The Contractor will assist in reviewing and loading changes in loss adjustment expenses and other expenses into premiums.
· Deductibles and Policy Limits: The Contractor will assist in updating analyses of the deductibles and policy limits.
· Non-modeled loss: The commercial catastrophe models do not account for all losses due to flooding events. The NFIP view of risk changes with new data and analysis. The Contractor will assist in reviewing and refining non-modeled view of loss and update rates accordingly.
· Update target loss level: The Contractor will assist in evaluating changes in the catastrophe models, compare model results with historic losses using actuarially accepted techniques, and provide recommendations for changes to the target loss levels.
· Off-balancing: The Contractor will assist in off-balancing to target loss levels and how to allocate the target loss levels to the state level using the modeled losses.
· Underwriting Profit /Catastrophe Provision: The Contractor will assist in helping determine a catastrophe load based on the NFIP’s exposure. High variability of losses is a significant risk for the NFIP, and much of that variability is due to geographical concentrations of policyholders. Policyholders in highly concentrated areas expose the program to the additional risk while policyholders in less concentrated areas do not. Both the underwriting profit and the catastrophe provision should consider the additional risk posed by concentration. Some of the variability risk is ceded to reinsurers, and the cost of that reinsurance provides a starting point for reflecting concentration in underwriting profit and the catastrophe provision. The remaining variability in the risk retained should also be provided for.
· The Contractor will assist in determining which advancements from Task 4 can be incorporated without fully re-running GLMs.
More Complex Changes – In years where there have been significant changes to the commercial catastrophe models, significant progress has been made internally (see continuous improvement objective), or there has been a major shift in industry, then a complete re-running of the full rate development process will be required. More complex changes can include all changes described in the “simple changes” section, in addition to the below list of possible updates.
· Improve market baskets, uniform and orthogonal books, and in-force data: As new data is collected from policyholders (e.g. replacement cost values, first floor heights), the Contractor will assist in re-evaluating assumptions for the NFIP in-force data, as well as the market baskets and uniform and orthogonal books. The Contractor will assist in updating the market baskets, uniform and orthogonal books when required based on the changes and improvements in data. This might require help in identifying and procuring external sources of updated market basket locations.
· Coordinate Catastrophe Model runs: The Contractor will assist the NFIP Actuaries in running the catastrophe models and FEMA-developed models for the market basket, uniform and orthogonal books, and the NFIP in-force data. The Government is currently using three commercial storm surge and inland flood models, as well as a tsunami model. The Contractor will work with the NFIP Actuaries to review and compare models and provide insight on their results.
· Create GLMS: The Contractor will assist in creating GLMs and conducting other actuarial analyses for all catastrophe model for each peril - storm surge, inland flooding, and tsunami flooding. The Contractor will assist NFIP Actuaries in assessing the performance of the GLMs and other models. If modifications to the GLMs are required, the Contractor will assist in re-running the GLMs to improve their predictive capability. Additionally, the Contractor will advise the NFIP Actuaries on factor selections based on the GLMs and other models and determine how models should be weighted overall and on a factor basis. The Contractor will assist in blending model results based on these factor selections.
· Review Historical Loss: The Contractor will assist in comparing the expected loss ratios with historical losses in more depth than a typical year to determine if factors need to be adjusted to better account for experience.
These lists are not exhaustive. The Government will rely on the Contractor to provide insight and opinion on how the rating structure should change in any given year. Any updates made to the rating structure will be provided and explained to the NFIP programmatic, IT and insurance delivery teams to make sure changes are effectively implemented. The Contractor will assist the NFIP Actuaries in developing all required documentation for the activities described above, including a premium calculation worksheet (PCW).
The Contractor will develop materials equivalent to a state rate filing every year. In addition to the rate-filing, extensive documentation is required for Government record-keeping processes. The Contractor will maintain the databases created for rate development, including the geodatabase and the data dictionary. All decisions made on rate-making should be well-documented and provided to the Government on an ongoing basis. All intermediate work products should be provided to the Government on an ongoing basis.
Task 3: Continuous Improvement of Rating Methodology The NFIP Actuaries have spent considerable time updating their 50-year old rating methodology to better align with the insurance industry and ultimately to provide fairer premiums that better reflect flood risk to the policyholder. However, natural catastrophe insurance is still advancing and changing. The NFIP Actuaries strongly desire to stay current with industry and to not allow their rating techniques to diverge from industry standards again.
Industry Improvements The Contractor will assist the NFIP Actuaries in meeting their objective of staying current with industry best practices. The Contractor will review the natural catastrophe and home owner insurance industries rate filings, provide a summary of industry trends, and develop recommendations on how to apply any industry advancements to the NFIP rates. This includes reviews of data, tools, and actuarial techniques being applied in industry.
Internally Identified Improvements Throughout the rate development process under Risk Rating 2.0, the NFIP Actuaries identified additional improvements to the rating methodology that they would like to incorporate in the future. These include but are not limited to:
· Refining the underlying data sources (e.g. refined coastline, updating river networks, more complete data for Alaska, Hawaii, and the U.S. territories);
· Incorporating the concept of river class (based on difference between 10- or 100- year flood depths based on as many models as possible) into the coastline methodology;
· Increasing the ability to develop and customize depth-damage functions used in FEMA developed and commercial catastrophe models;
· Addressing certain sub-perils such as alluvial fans;
· Incorporating more models into state allocation view and territory factors;
· Exploring alternatives for pricing retained risk;
· Exploring ridge regression (and similar methodologies) as a possible improvement on minimizing excessive changes to rates; and
· Developing rating methodologies to incorporate additional mitigation credits that result in a reduction in risk that can be offered to policyholders.
The Contractor will work collaboratively with the NFIP Actuaries to incorporate these improvements and help define a more complete list throughout the course of the contract.
Model Development Additionally, the NFIP Actuaries have worked closely with the Engineering Divisions within FIMA to be able to utilize FEMA-develop flood models in their rating methodology. The current models used are the Mapping Data Integration (MDI) Approach and the Probabilistic Flood Risk Analysis (PFRA). The FIMA Engineers are in the early stages of developing their probabilistic flood modeling techniques. It is the desire of the Government to include these and any other FEMA-developed models in the insurance rates as the models mature. The Contractor will assist in model development by reviewing model runs, providing quality checks, asking questions about performance, and comparing the model results to industry catastrophe flood models. This process is iterative and ongoing.
In addition to helping the NFIP Actuaries identify and improve areas of the rating methodology, the Contractor will help incorporate these changes into the annual rating plan. It is important that advancements are weighed against policyholder experience to ensure there is no significant “whiplash” in premiums (e.g. premiums increasing one year and decreasing the next).
Task 4: Updating Rates with Policy Forms Implementation The National Flood Insurance Program is currently rewriting their flood insurance policy forms to align with industry standards and best practices. The policy forms are written in regulations, and therefore, rulemaking is required to change these forms. The rule-making process for the forms is currently underway and while it can take many years, it is expected to be completed prior to the expiration of the services described in this PWS. Prior to implementing the new policy forms, the Contractor will assist the NFIP Actuaries in evaluating and adjusting the rating methodology developed under Risk Rating 2.0 to account for the policy changes occurring with the implementation of new forms.
Examples of policy changes in the new forms that will also impact pricing are: tailored forms for commercial and non-residential exposures, the possible separation of tsunami as an optional coverage, changes in definitions, inclusion of endorsements, etc.
Task 5: Audit and Litigation Support Risk Rating 2.0 is a significant shift in how flood insurance rates are developed. Changes in policyholder premiums are expected. Therefore, the Government anticipates interest and scrutiny from governing bodies. The Contractor will support any audit or litigation activities as a result of rate changes under Risk Rating 2.0.
Task 6: Transition The Contractor will provide extensive transition to the Government and the follow-on contractor prior to completion of the contract period of performance.
5. Key Personnel Lead Actuary The Contractor shall provide a Senior Actuary that is responsible for all activity for the Actuarial Consulting Services Contract including but not limited to the production of the annual rate updates, recommendations for improvement, and providing support with audits and litigation.
The Lead Actuary must be an Associate or Fellow of an American or International actuarial society, with significant relevant work experience (over 10 years) in developing risk rating and classification plans for property and casualty insurance companies, with a significant portion of that experience being in natural catastrophe rating.
Geospatial Lead The Contractor shall provide a Geospatial Lead that is responsible for all geospatial activities for the Actuarial Consulting Services Contract including but not limited to the development and maintenance of geospatial layers, geodatabases, and data dictionaries.
The Geospatial Lead must have significant relevant experience (over 5 years) analyzing, selecting and tailoring Geospatial datasets for use in insurance rating plans. The Geospatial Lead must have experience using R, Python, Postgres SQL, and spatial statistics.
6. Deliverables
| DESCRIPTION |
| FREQUENCY |
| DUE DATES |
Monthly Technical Progress Narrative
| Monthly |
| Tenth (10th) of every month |
| Replication of Rating Methodology and Completed Transition Documentation (Objective 1) |
| Once |
| One Hundred and Eighty (180) calendar days from contract award |
| Annual Rate Filing Equivalent (Objective 2) |
| Annually |
| TBD |
| Review of Industry Advancements/Recommendations of Rate Improvements (Objective 3) |
| Annually |
| TBD |
| Updated Rates Based on Policy Forms (Objective 4) |
| Once |
| TBD |
| Audit and Litigation Documentation (Objective 5) |
| Periodically |
| As Required |
| Transition Documents (Objective 6) |
| Once |
| Upon Completion of the Contract |
Note: Deliverables will be delivered to the COR by the due date listed. The COR then has twenty (20) business days to review the deliverable and request corrections from the Contractor before the document is accepted by the Government. Some of these deliverables could be shared with other FEMA stakeholders. Deliverables may be delivered in electronic format using Microsoft products.
7. Government Furnished Equipment
· Portable laptops to conduct work behind the FEMA firewall
· All contractor personnel performing work using or reviewing FEMA data and non-public information will require a laptop
· Work space for the Contractor at FEMA facilities
· Access to appropriate personnel to complete all Objectives of the PWS.
8. Period of Performance The performance period of the contract will be up to five (5) years consisting of one twelve (12) month base and four (4) twelve (12) month options.
9. Place of Performance Due to the collaborative nature of the work, the Government anticipates frequent teleconferences and videoconferences and requires the Lead Actuary (or alternative, as approved by the Government) to be present at least once a month. As determined by the Government, the Contractor is allowed access to the FEMA Headquarters located in Washington, DC. The Government is allowed access to Contractor workspace for meetings and workshops related to this PWS.
10. Security Requirements All work performed under this PWS is unclassified. All personnel require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees’ receive a favorably adjudicated public trust suitability prior to entry on duty (EOD). All individuals will be U.S. citizens. The contractor shall follow the standards established within DHS and FEMA policy.
FOR OFFICIAL USE ONLY
In accordance with DHS Management Directive 11042.1 contractors, consultants and others to whom access is granted will abide by 11042.1; DHS policy regarding the identification and safeguarding of sensitive but unclassified information originated within DHS. It also applies to other sensitive but unclassified information received by DHS from other government and non-governmental activities. The contractor will:
1. Be aware of and comply with the safeguarding requirements for “For Official Use Only” (FOUO) information as outlined in this directive.
2. Participate in formal classroom or computer based training sessions presented to communicate the requirements for safeguarding FOUO and other sensitive but unclassified information.
3. Be aware that divulging information without proper authority could result in administrative or disciplinary action.
Contractors and Consultants shall:
Execute a DHS Form 11000-6, Sensitive but Unclassified Information Non Disclosure Agreement (NDA), as a condition of access to such information. Other individuals not assigned to or contractually obligated to DHS, but to whom access to information will be granted, may be requested to execute an N DA as determined by the applicable program manager. Execution of the N DA shall be effective upon publication of this directive and not applied retroactively.
BACKGROUND INVESTIGATIONS
All contractor personnel who require access to DHS or FEMA information systems, routine access to DHS or FEMA facilities, or access to sensitive information, including but not limited to Personally Identifiable Information (PII), shall be subject to a full background investigation commensurate with the level of the risk associated with the job function or work being performed. FEMA’s Personnel Security Division (PSD) will determine the risk designation for each contractor position by comparing the functions and duties of the position against those of a same or similar federal position, applying the same standard for evaluating the associated potential for impact on the integrity and efficiency of federal service.
Low Risk without Information System Access Contractor personnel occupying positions or performing functions with a Low Risk designation and who do not require access to DHS or FEMA information systems may undergo a Tier 1 investigation with a credit check and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract. (also reference Facility Access).
Low Risk with Information System Access Contractor personnel occupying positions or performing functions with a Low Risk designation and who require access to DHS or FEMA information systems shall undergo a Tier 2 Suitability Background Investigation (T2) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
Moderate Risk Contractor personnel occupying positions or performing functions with a Moderate Risk designation shall undergo a Tier 2 Suitability Background Investigation (T2) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
High Risk Contractor personnel occupying positions or performing functions with a High Risk designation shall undergo a Tier 4 Suitability Background Investigation (T4) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
Background Investigation Process To initiate the request to process contractor personnel, the Contractor shall provide the FEMA Contracting Officer’s Representative (COR) with all required information and comply with all necessary instructions to complete Section II of the FEMA Form 121-3-1-6, “Contract Fitness/Security Screening Request.” The FEMA COR shall ensure that all other applicable sections of the FEMA Form 121-3-1-6 are complete prior to submitting the form to FEMA PSD for processing. The Contractor shall also provide the FEMA COR with completed OF 306, “Declaration for Federal Employment,” forms for all contractor personnel.
Contractor personnel who already have a favorably adjudicated background investigation, may be eligible to perform work under this contract without further processing by FEMA PSD if:
· the investigation was completed within the last five years,
· it meets or exceeds the minimum requirement for the position they will occupy or functions they will perform on this contract,
· the contractor personnel have not had a break in employment since the prior favorable adjudication, and,
· FEMA PSD has verified the investigation and confirmed that no new derogatory information has been disclosed which may require a reinvestigation.
FEMA PSD will notify the COR of the names of the contractor personnel eligible to work based on prior, favorable adjudication. The COR will, in turn, notify the Contractor of the names of the favorably adjudicated contractor personnel, at which time the favorably adjudicated contractor personnel will be eligible to begin work under this contract.
For those contractor personnel who do not have an acceptable, prior, favorable adjudication or who otherwise require reinvestigation, FEMA PSD will issue an electronic notification via email directly to the contractor applicant/personnel that contains the following documents, which are incorporated into this contract by reference, along with a link to the Office of Personnel Management’s (OPM) Electronic Questionnaires for Investigation Processing (e-QIP) system and instructions for submitting the necessary information:
· Standard Form 85P, “Questionnaire for Public Trust Positions”
· Optional Form 306, “Declaration for Federal Employment”
· SF 87, “Fingerprint Card” (2 copies)
· DHS Form 11000-6, “Non-Disclosure Agreement”
· DHS Form 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act” FEMA PSD will only accept complete packages consisting of all of the above document and Standard Form 85P, which must be completed electronically through the Office of Personnel Management’s e-QIP system. The Contractor is responsible for ensuring that all contractor personnel timely and properly submit all required background information.
Once contractor personnel have properly submitted the complete package of all required background information, FEMA’s Personnel Security Division, at its sole discretion, may grant contractor personnel temporary eligibility to perform work under this contract prior to completion of the full background investigation if the Personnel Security Division’s initial review of the contractor personnel’s background information reveals no issues of concern. In such cases, FEMA’s Personnel Security Division will provide notice of such temporary eligibility to the COR who will then notify the Prime Contractor, at which time the identified contractor personnel will be temporarily eligible to begin work under this contract. Neither the Prime Contractor nor the contractor personnel has any right to such a grant of temporary eligibility. The grant of such temporary eligibility shall not be considered as assurance that the contactor personnel will remain eligible to perform work under this contract upon completion of and final adjudication of the full background investigation.
Upon favorable adjudication of the full background investigation, FEMA’s Personnel Security Division will update the contractor personnel’s security file and take no further action. In any instance where the final adjudication results in an unfavorable determination FEMA’s Personnel Security Division will notify the contractor personnel directly, in writing, of the decision and will provide the COR with the name(s) of the contractor personnel whose adjudication was unfavorable. The COR will then forward that information to the Contractor. Contractor personnel who receive an unfavorable adjudication shall be ineligible to perform work under this contract. Unfavorable adjudications are final and not subject to review or appeal.
Continued Eligibility and Reinvestigation Eligibility determinations based on a Low Risk T1, Moderate Risk T2S or High Risk T4 are valid for five years from the date that the investigation was completed and closed. Contractor personnel required to undergo a background investigation to perform work under this contract shall be ineligible to perform work under this contract upon the expiration the background investigation unless and until the contractor personnel have undergone a reinvestigation and FEMA’s Personnel Security Division has renewed their eligibility to perform work under this contract.
Exclusion by Contracting Officer The Contracting Officer (CO), independent of FEMA’s Personnel Security Division, may direct the Contractor be excluded from working on this contract. Any contractor found or deemed to be unfit or whose continued employment on the contract is deemed contrary to the public interest or inconsistent with the best interest of the agency may be removed.
FACILITY ACCESS
The Contractor shall comply with FEMA Directive 121-1 “FEMA Personal Identity Verification Guidance,” FEMA Directive 121-3 “Facility Access,” and FEMA Manual 121-3-1 “FEMA Credentialing Access Manual,” to arrange for contractor personnel’s access to FEMA facilities, which includes, but is not limited to, arrangements to obtain any necessary identity badges for contractor personnel.
Contractor personnel working within any FEMA facility who do not require access to DHS or FEMA IT systems and do not qualify for a PIV Card may be issued a Facility Access Card (FAC). FACs cannot exceed 180 days; all contractors requiring access greater than 180 days will need to qualify for and receive a PIV card before being allowed facility access beyond 180 days.
Contractor personnel shall not receive a FAC until they have submitted a SF 87, “Fingerprint Card,” and receive approval from FEMA PSD. Contractor personnel using a FAC for access to FEMA facilities must be escorted in Critical Infrastructure areas (i.e., server rooms, weapons rooms, mechanical rooms, etc.) at all times.
FEMA may deny facility access to any contractor personnel whom FEMA’s Office of the Chief Security Officer has determined to be a potential security threat.
The Contractor shall notify the FEMA COR of all terminations/resignations within five calendar days of occurrence. The Contractor must account for all forms of Government-provided identification issued to contractor employees under a contract (i.e., the PIV cards or other similar badges) must return such identification to FEMA as soon as any of the following occurs:
· When no longer needed for contract performance.
· Upon completion of a contractor employee’s employment.
· Upon contract completion or termination.
If an identification card or building pass is not available to be returned, the Contractor shall submit a report to the FEMA COR, referencing the pass or card number, name of the individual to whom it was issued, and the last known location and disposition of the pass or card.
The Contractor or contractor personnel’s failure to return all DHS- or FEMA-issued identification cards and building passes upon expiration, upon the contractor personnel’s removal from the contract, or upon demand by DHS or FEMA may subject the contractor personnel and the Contractor to civil and criminal liability.
UNAUTHORIZED DISCLOSURE OF CLASSIFIED OR UNCLASSIFIED INFORMATION
Contractors and Subcontractors who are working on this contract shall receive Unauthorized Disclosure of Classified or Unclassified Information training.
Access to the training can be obtained at:
https://securityawareness.usalearning.gov/unauthorizedrefresher/index.htm Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
OPSEC TRAINING
Contractors and Subcontractors who are working on this contract shall receive the OPSEC Awareness Brief.
Access to the briefing can be obtained at http://cdsetrain.dtic.mil/opsec Send the certificate of completion to the FEMA COR no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
INSIDER THREAT TRAINING
Insider Threat training for Contractors can be found at: http://cdsetrain.dtic.mil/itawareness/index.htm.
Certificate of training is required for all cleared contractor employees who are working with classified or unclassified information. All certificates must be sent to the assigned FEMA Contracting Officer Representative, before the Contractor or Subcontractor is granted access to classified or unclassified information but no later than 30 calendar days after awarded contract. All cleared contractor personnel are required to recertify Insider Threat training annually thereafter. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
DHS Enterprise Architecture Compliance All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the Contractor shall comply with the following Homeland Security Enterprise Architecture (HLS EA) requirements:
(a) All developed solutions and requirements shall be compliant with the HLS/FEMA EA.
(b) All IT hardware and/or software shall be compliant with the HLS/FEMA EA Technical Reference Model (TRM) Standards and Products Profile.
(c) Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.
(d) Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01[footnoteRef:1][1] and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines. [1: [1] Department of Homeland Security (DHS) Directives System, Enterprise Data Management Policy, 2008. https://www.dhs.gov/sites/default/files/publications/mgmt_directive_103_01_enterprise_data_management_policy.pdf]
(e) Applicability of IPv6 to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA related component acquisitions shall be IPv6 compliant as defined in the USGv6 Profile (NIST Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.
Accessibility Requirements (Section 508) Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology (EIT), they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.
All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable EIT accessibility standards have been identified:
Section 508 Applicable EIT Accessibility Standards 36 CFR 1194.21 Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.
36 CFR 1194.22 Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous Javascript and XML (AJAX) then 1194.21 Software standards also apply to fulfill functional performance criteria.
36 CFR 1194.31 Functional Performance Criteria, applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.
36 CFR 1194.41 Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required 1194.31 Functional Performance Criteria, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.
Section 508 Applicable Exceptions Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COTR and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply: 36 CFR 1194.3(b) Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.
Section 508 Compliance Requirements 36 CFR 1194.2(b) (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meet some but not all of the standards, the agency must procure the product that best meets the standards. When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.
Cyber Hygiene and Privacy Clauses
SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(2) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(3) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
| (1) | Truncated SSN (such as last 4 digits) |
| (2) | Date of birth (month, day, and year) |
| (3) | Citizenship or immigration status |
| (4) | Ethnic or religious affiliation |
| (5) | Sexual orientation |
| (6) | Criminal History |
| (7) | Medical Information |
| (8) | System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) |
Other PII may be “sensitive” depending on its context, such as a…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .