ASC RFP Amendment 2_26Jan23.docx

DOCX document 178 KB Posted

Attached to
Request For Proposal - Application Support Center (ASC) USCIS Federal contract opportunity
Solicitation number
Final_RFP_ASC_USCIS_28Dec2022
Issued by
Department of Homeland Security US Citizen and Immigration Services

About this file

This Request for Proposal (RFP) from the United States Citizenship and Immigration Services (USCIS) seeks Application Support Center (ASC) services. Offerors must provide staffing, management, facilities, and logistics to operate ASCs that collect biometrics and photos from immigration applicants. The incumbent contractor's performance period expires in 2023. Offerors must price services by facility and submit proposals by 10 January 2023, with award anticipated by summer 2023. The RFP requires staffing levels be maintained and outlines minimum standards for security, quality control, and continuity of operations. Pricing will be a key factor in the best value determination.

View the file

Other files for this federal contract opportunity

Other files attached to Request For Proposal - Application Support Center (ASC) USCIS, newest first.
File Type Posted
Attachment 9 Question Submission Form_CO Responses_9.xlsx XLSX spreadsheet
Attachment 6 - ASC Pricing Sheet_Amendment 9.xlsx XLSX spreadsheet
70SBUR23R00000004 Amendment 0009.pdf PDF
70SBUR23R00000004 Amendment 0008.pdf PDF
Attachment 6 - ASC Pricing Sheet_Amendment 8.xlsx XLSX spreadsheet
Attachment 9 Question Submission Form_CO Responses_7.xlsx XLSX spreadsheet
70SBUR23R00000004 Amendment 0007.pdf PDF
Attachment 12 SF1408.pdf PDF
Attachment 9 Question Submission Form_CO Responses_6.1.xlsx XLSX spreadsheet
Attachment 9 Question Submission Form_CO Responses_6.xlsx XLSX spreadsheet
70SBUR23R00000004 Amendment 0006.pdf PDF
Attachment 9 Question Submission Form_CO Responses_5.1.xlsx XLSX spreadsheet
Attachment 1_PWS_ASC_1Feb23_Amendment 5.docx DOCX document
Attachment 6 - ASC Pricing Sheet_Amendment 5.xlsx XLSX spreadsheet
ASC RFP Amendment 5_1Feb23.docx DOCX document
Attachment 6 - ASC Pricing Sheet_Amendment 4.xlsx XLSX spreadsheet
70SBUR23R00000004 Amendment 0003.pdf PDF
Attachment 9 Question Submission Form_CO Responses_3.xlsx XLSX spreadsheet
Attachment 11_ASC_Factor1_Subfactor2_Two Problem Statements.docx DOCX document
Attachment 6 - ASC Pricing Sheet_Amendment 3.xlsx XLSX spreadsheet
ASC RFP Amendment 3_30Jan23.docx DOCX document
Attachment 9 - Question Submission Form_CO responses_2.xlsx XLSX spreadsheet
Amendment 1 Continuation.pdf PDF
70SBUR23R00000004.pdf PDF
Attachment 5 - CHRI Statement of Understanding.pdf PDF
ASC RFP_70SBUR23R00000004.docx DOCX document
Attachment 2_Wage Determinations.docx DOCX document
Attachment 1_PWS_ASC_23Jan23_Amendment 2.docx DOCX document
Attachment 6 - ASC Pricing Sheet_Amendment 2.xlsx XLSX spreadsheet
70SBUR23R00000004 Amendment 2.pdf PDF
70SBUR23R00000004 Amendment 1 19Jan23.pdf PDF
Attachment 9 - Question Submission Form_CO responses.xlsx XLSX spreadsheet
Attachment 1_PWS_ASC_15Dec2022.docx DOCX document
Attachment 6 - ASC Pricing Sheet.xlsx XLSX spreadsheet
70SBUR23R00000004 Amendment 1 19Jan23.pdf PDF
ASC RFP Amendment 1.docx DOCX document
Attachment 9 - Question Submission Form_CO responses.xlsx XLSX spreadsheet
Attachment 1_PWS_ASC_10Jan23_Amendment 1.docx DOCX document
ASC RFP_70SBUR23R00000004.docx DOCX document
Attachment 6 - ASC Pricing Sheet.xlsx XLSX spreadsheet
70SBUR23R00000004.pdf PDF
Attachment 8 - Compliance Matrix.docx DOCX document
Attachment 5 - CHRI Statement of Understanding.pdf PDF
Attachment 3_CBA.pdf PDF
Attachment 9 - Question Submission Form.xlsx XLSX spreadsheet
Attachment 7_Past Performance Reference Form.docx DOCX document
Attachment 2_Wage Determinations.docx DOCX document
Attachment 1_PWS_ASC_15Dec2022.docx DOCX document
Attachment 4_CHRI security and management control outsourcing standard for non-channelers.pdf PDF
Attachment 10 - Security Requirement 5 (Aug 2020).pdf PDF
Show all 50

Request For Proposal - Application Support Center (ASC) USCIS has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Citizenship & Immigration Services (USCIS) Application Support Centers (ASC)

70SBUR23R00000004

Source Selection Sensitive – See FAR 2.101 and 3.104

Table of Contents

Part I - Schedule2
Part II - Contract Clauses and terms & conditions2
Part III - CONTRACT DOCUMENTS, EXHIBITS OR ATTACHMENTS27
Part IV Solicitation Provisions/INSTRUCTIONS/EVALUATION28
ADDENDUM TO FAR 52.212-1 INSTRUCTIONS TO OFFERORS – COMMERCIAL ITEMS54
3. Proposal Instructions:55
52.212-2 EVALUATION – COMMERCIAL Products and Commercial Services (Nov 2021) (Tailored)66
Factor 1 Staffing, Management, and Retention:68
Factor 2 Corporate Experience:70
Factor 3 Past Performance:71
Factor 4 Small Business Utilization:71
Factor 5 Price:72
Factor 6 DHS Mentor-Protégé Program Participation:73

Part I - Schedule

1. STANDARD FORM - 1449

2. CONTINUATION OF ANY BLOCKS FROM 1449

Not applicable Part II - Contract CLAUSES and terms & conditions

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at these addresses: http://www.acquisition.gov/far.

(End of clause)

FAR ClauseTitle and Date
52.203-3Gratuities (Apr 1984)
52.203-16Preventing Personal Conflicts of Interest (June 2020)
52.203-17Contractor Employee Whistleblower Rights and Requirement to Inform Employees of Whistleblower Rights (June 2020)
52.204-4Printed or Copied Double-Sided on Postconsumer Fiber Content Paper (May 2011)
52.204-9Personal Identity Verification of Contractor Personnel (Jan 2011)
52.212-4Contract Terms and Conditions – Commercial Products and Commercial Services (Nov 2021)
Alternate I (Nov 2021)
FILL-INS:
(a)(4) _To be filled in by offeror___
(e)(1)(iii)(D) _To be filled in by offeror__

(i)(1)(ii)(D)(1) Other Direct Costs: Facilities, Travel, and Equipment (i)(1)(ii)(D)(2) Indirect Costs: None

52.223-10Waste Reduction Program (May 2011)
52.223-19Compliance With Environmental Management Systems (May 2011)
52.224-1Privacy Act Notification (Apr 1984)
52.224-2Privacy Act (Apr 1984)
52.227-16Additional Data Requirements (Jun 1987)
52.227-17Rights in Data -- Special Works (Dec 2007)
52.228-5Insurance -- Work on a Government Installation (Jan 1997)
52.232-40Providing Accelerated Payments to Small Business Subcontractors (Dec 2013)
52.237-2Protection of Government Buildings, Equipment, and Vegetation (Apr 1984)
52.237-3Continuity of Services(Jan 1991)
52.242-13Bankruptcy (Jul 1995)
52.245-1Government Property (Sept 2021)
52.245-9Use and Charges (Apr 2012)
52.246-25Limitation of Liability – Services (Feb 1997)

52.212-5 Contract Terms and Conditions Required to Implement Statutes or Executive Orders -- Commercial Items (Oct 2022)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015).

(5) 52.233-3, Protest After Award (AUG 1996) ( 31 U.S.C. 3553).

(6) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and 108-78 ( 19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

|X| (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (JUN 2020), with Alternate I (NOV 2021) ( 41 U.S.C. 4704 and 10 U.S.C. 2402).

|_|(2) 52.203-13, Contractor Code of Business Ethics and Conduct (NOV 2021) ( 41 U.S.C. 3509)).

|_| (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (JUN 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)

|X| (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (JUN 2020) (Pub. L. 109-282) ( 31 U.S.C. 6101 note).

__ (5) [Reserved].

|X| (6) 52.204-14, Service Contract Reporting Requirements (OCT 2016) (Pub. L. 111-117, section 743 of Div. C).

|_| (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (OCT 2016) (Pub. L. 111-117, section 743 of Div. C).

|X| (8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (NOV 2021) ( 31 U.S.C. 6101 note).

|X| (9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (OCT 2018) ( 41 U.S.C. 2313).

__ (10) [Reserved].

|_| (11) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (OCT 2022) ( 15 U.S.C. 657a).

|X| (12) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (OCT 2022) (if the offeror elects to waive the preference, it shall so indicate in its offer) ( 15 U.S.C. 657a).

__ (13) [Reserved] |_| (14) (i) 52.219-6, Notice of Total Small Business Set-Aside (NOV 2020) ( 15 U.S.C. 644).

|_| (ii) Alternate I (MAR 2020) of 52.219-6.

|_| (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (NOV 2020) ( 15 U.S.C. 644).

|_| (ii) Alternate I (MAR 2020) of 52.219-7.

|X| (16) 52.219-8, Utilization of Small Business Concerns (OCT 2022) ( 15 U.S.C. 637(d)(2) and (3)).

|X| (17) (i) 52.219-9, Small Business Subcontracting Plan (OCT 2022) ( 15 U.S.C. 637(d)(4)).

|_| (ii) Alternate I (NOV 2016) of 52.219-9.

|X| (iii) Alternate II (NOV 2016) of 52.219-9.

|_| (iv) Alternate III (JUN 2020) of 52.219-9.

|_| (v) Alternate IV (SEP 2021) of 52.219-9.

|_| (18) (i) 52.219-13, Notice of Set-Aside of Orders (MAR 2020) ( 15 U.S.C. 644(r)).

|_| (ii) Alternate I (MAR 2020) of 52.219-13.

|_| (19) 52.219-14, Limitations on Subcontracting (OCT 2022) ( 15 U.S.C. 637s).

|X| (20) 52.219-16, Liquidated Damages—Subcontracting Plan (SEP 2021) ( 15 U.S.C. 637(d)(4)(F)(i)).

|_| (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (OCT 2022) ( 15 U.S.C. 657f).

|X| (22) (i) 52.219-28, Post Award Small Business Program Rerepresentation (OCT 2022) ( 15 U.S.C. 632(a)(2)).

|_| (ii) Alternate I (MAR 2020) of 52.219-28.

|_| (23) 52.219-29, Notice of Set-Aside for, or Sole-Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (OCT 2022) ( 15 U.S.C. 637(m)).

|_| (24) 52.219-30, Notice of Set-Aside for, or Sole-Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (OCT 2022) ( 15 U.S.C. 637(m)).

|_| (25) 52.219-32, Orders Issued Directly Under Small Business Reserves (MAR 2020) ( 15 U.S.C. 644(r)).

|_| (26) 52.219-33, Nonmanufacturer Rule (SEP 2021) ( 15U.S.C. 637(a)(17)).

|X| (27) 52.222-3, Convict Labor (JUN 2003) (E.O.11755).

|X| (28) 52.222-19, Child Labor-Cooperation with Authorities and Remedies (JAN 2022) (E.O.13126).

|X| (29) 52.222-21, Prohibition of Segregated Facilities (APR 2015).

|X| (30) (i) 52.222-26, Equal Opportunity (SEP 2016) (E.O.11246).

|_| (ii) Alternate I (FEB 1999) of 52.222-26.

|X| (31) (i) 52.222-35, Equal Opportunity for Veterans (JUN 2020) ( 38 U.S.C. 4212).

|_| (ii) Alternate I (JUL 2014) of 52.222-35.

|X| (32) (i) 52.222-36, Equal Opportunity for Workers with Disabilities (JUN 2020) ( 29 U.S.C. 793).

|_| (ii) Alternate I (JUL 2014) of 52.222-36.

|X| (33) 52.222-37, Employment Reports on Veterans (JUN 2020) ( 38 U.S.C. 4212).

|X| (34) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (DEC 2010) (E.O. 13496).

|X| (35) (i) 52.222-50, Combating Trafficking in Persons (NOV 2021) ( 22 U.S.C. chapter 78 and E.O. 13627).

|_| (ii) Alternate I (MAR 2015) of 52.222-50 ( 22 U.S.C. chapter 78 and E.O. 13627).

|X| (36) 52.222-54, Employment Eligibility Verification (MAY 2022) (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial products or commercial services as prescribed in FAR 22.1803.)

|_| (37) (i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA–Designated Items (May 2008) ( 42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

|_| (ii) Alternate I (MAY 2008) of 52.223-9 ( 42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)

|_| (38) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (Jun 2016) (E.O. 13693).

|_| (39) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (JUN 2016) (E.O. 13693).

|_| (40) (i) 52.223-13, Acquisition of EPEAT®-Registered Imaging Equipment (JUN 2014) (E.O.s 13423 and 13514).

|_| (ii) Alternate I (OCT 2015) of 52.223-13.

|_| (41) (i) 52.223-14, Acquisition of EPEAT®-Registered Televisions (JUN 2014) (E.O.s 13423 and 13514).

|_| (ii) Alternate I (Jun2014) of 52.223-14.

|_| (42) 52.223-15, Energy Efficiency in Energy-Consuming Products (MAY 2020) ( 42 U.S.C. 8259b).

|_| (43) (i) 52.223-16, Acquisition of EPEAT®-Registered Personal Computer Products (OCT 2015) (E.O.s 13423 and 13514).

|_| (ii) Alternate I (JUN 2014) of 52.223-16.

|X| (44) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving (JUN 2020) (E.O. 13513).

|_| (45) 52.223-20, Aerosols (JUN 2016) (E.O. 13693).

|_| (46) 52.223-21, Foams (Jun2016) (E.O. 13693).

|X| (47) (i) 52.224-3 Privacy Training (JAN 2017) (5 U.S.C. 552 a).

|_| (ii) Alternate I (JAN 2017) of 52.224-3.

|_| (48) 52.225-1, Buy American-Supplies (NOV 2021) ( 41 U.S.C. chapter 83).

|_| (49) (i) 52.225-3, Buy American-Free Trade Agreements-Israeli Trade Act (NOV 2021) ( 41 U.S.C.chapter83, 19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, Pub. L. 103-182, 108-77, 108-78, 108-286, 108-302, 109-53, 109-169, 109-283, 110-138, 112-41, 112-42, and 112-43.

|_| (ii) Alternate I (JAN 2021) of 52.225-3.

|_| (iii) Alternate II (JAN 2021) of 52.225-3.

|_| (iv) Alternate III (JAN 2021) of 52.225-3.

|_| (50) 52.225-5, Trade Agreements (OCT 2019) ( 19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note).

|X| (51) 52.225-13, Restrictions on Certain Foreign Purchases (FEB 2021) (E.O.’s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).

|_| (52) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302Note).

|_| (53) 52.226-4, Notice of Disaster or Emergency Area Set-Aside (Nov 2007) ( 42 U.S.C. 5150).

|_| (54) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (Nov2007) ( 42 U.S.C. 5150).

|_| (55) 52.229-12, Tax on Certain Foreign Procurements (FEB 2021).

|_| (56) 52.232-29, Terms for Financing of Purchases of Commercial Products and Commercial Services (NOV 2021) ( 41 U.S.C. 4505, 10 U.S.C. 2307(f)).

|_| (57) 52.232-30, Installment Payments for Commercial Products and Commercial Services (NOV 2021) ( 41 U.S.C. 4505, 10 U.S.C. 2307(f)).

|_| (58) 52.232-33, Payment by Electronic Funds Transfer-System for Award Management (OCT2018) ( 31 U.S.C. 3332).

|_| (59) 52.232-34, Payment by Electronic Funds Transfer-Other than System for Award Management (Jul 2013) ( 31 U.S.C. 3332).

|_| (60) 52.232-36, Payment by Third Party (MAY 2014) ( 31 U.S.C. 3332).

|X| (61) 52.239-1, Privacy or Security Safeguards (AUG 1996) ( 5 U.S.C. 552a).

|X| (62) 52.242-5, Payments to Small Business Subcontractors (JAN 2017) ( 15 U.S.C. 637(d)(13)).

|_| (63) (i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (NOV 2021) ( 46 U.S.C. 55305 and 10 U.S.C. 2631).

|_| (ii) Alternate I (APR 2003) of 52.247-64.

|_| (iii) Alternate II (NOV 2021) of 52.247-64.

(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

|_| (1) 52.222-41, Service Contract Labor Standards (AUG 2018) ( 41 U.S.C. chapter67).

|X| (2) 52.222-42, Statement of Equivalent Rates for Federal Hires (MAY 2014) ( 29 U.S.C. 206 and 41 U.S.C. chapter 67).

|X| (3) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (Multiple Year and Option Contracts) (AUG 2018) ( 29 U.S.C. 206 and 41 U.S.C. chapter 67).

|_| (4) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (May 2014) ( 29U.S.C.206 and 41 U.S.C. chapter 67).

|_| (5) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment-Requirements (May 2014) ( 41 U.S.C. chapter 67).

|_| (6) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements (MAY 2014) ( 41 U.S.C. chapter 67).

|_| (7) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026 (JAN 2022).

|_| (8) 52.222-62, Paid Sick Leave Under Executive Order 13706 (JAN 2022) (E.O. 13706).

|_| (9) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (Jun 2020) ( 42 U.S.C. 1792).

(d) Comptroller General Examination of Record. The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, as defined in FAR 2.101, on the date of award of this contract, and does not contain the clause at 52.215-2, Audit and Records-Negotiation.

(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor’s directly pertinent records involving transactions related to this contract.

(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.

(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.

(e) (1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c), and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial products or commercial services. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause-

(i) 52.203-13, Contractor Code of Business Ethics and Conduct (NOV 2021) ( 41 U.S.C. 3509).

(ii) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(iii) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).

(iv) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(v) 52.219-8, Utilization of Small Business Concerns (OCT 2022) ( 15 U.S.C. 637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds the applicable threshold specified in FAR 19.702(a) on the date of subcontract award, the subcontractor must include 52.219-8 in lower tier subcontracts that offer subcontracting opportunities.

(vi) 52.222-21, Prohibition of Segregated Facilities (APR 2015).

(vii) 52.222-26, Equal Opportunity (SEP 2015) (E.O.11246).

(viii) 52.222-35, Equal Opportunity for Veterans (JUN 2020) ( 38 U.S.C. 4212).

(ix) 52.222-36, Equal Opportunity for Workers with Disabilities (JUN 2020) ( 29 U.S.C. 793).

(x) 52.222-37, Employment Reports on Veterans (JUN 2020) ( 38 U.S.C. 4212).

(xi) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (DEC 2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.

(xii) 52.222-41, Service Contract Labor Standards (AUG 2018) ( 41 U.S.C. chapter 67).

(xiii) (A) 52.222-50, Combating Trafficking in Persons (NOV 2021) ( 22 U.S.C. chapter 78 and E.O 13627).

(B) Alternate I (MAR 2015) of 52.222-50 ( 22 U.S.C. chapter 78 and E.O. 13627).

(xiv) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment-Requirements (May2014) ( 41 U.S.C. chapter 67).

(xv) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements (MAY 2014) ( 41 U.S.C. chapter 67).

(xvi) 52.222-54, Employment Eligibility Verification (MAY 2022) (E.O. 12989).

(xvii) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026 (JAN 2022).

(xviii) 52.222-62, Paid Sick Leave Under Executive Order 13706 (JAN 2022) (E.O. 13706).

(xix) (A) 52.224-3, Privacy Training (Jan 2017) ( 5 U.S.C. 552a).

(B) Alternate I (JAN 2017) of 52.224-3.

(xx) 52.225-26, Contractors Performing Private Security Functions Outside the United States (OCT 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).

(xxi) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (JUN 2020) ( 42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.

(xxii) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (NOV 2021) ( 46 U.S.C. 55305 and 10 U.S.C. 2631). Flow down required in accordance with paragraph (d) of FAR clause 52.247-64.

(2) While not required, the Contractor may include in its subcontracts for commercial products and commercial services a minimal number of additional clauses necessary to satisfy its contractual obligations.

(End of Clause)

Addendum to FAR 52.212-5 (Oct 2022) Offerors shall validate their enrollment and use of the E-Verify System. This validation shall be provided with the Offeror’s representations and certifications

52.217-8 Option to Extend Services (Nov 1999) The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 30 days before the contract expires.

(End of clause)

52.217-9 Option to Extend the Term of the Contract (Mar 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 30 days before the contract expires; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 60 days before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 60 months.

(End of clause)

52.222-42 Statement of Equivalent Rates for Federal Hires (May 2014) In compliance with the Service Contract Labor Standards statute and the regulations of the Secretary of Labor (29 CFR part 4), this clause identifies the classes of service employees expected to be employed under the contract and states the wages and fringe benefits payable to each if they were employed by the contracting agency subject to the provisions of 5 U.S.C. 5341 or 5332.

This Statement is for Information Only:

It is not a Wage Determination

Position
Annual Rate
30% Benefits
Hourly Rate
Facility Observer GS – 0342-5 Step 1
$31,083
$40,408
$19.43
Biometric Technician – Immigration Services Clerk GS-0303-5 Step 1
$31,083
$40,408
$19.43
Supervisory Site Manager – GS-0301-11 Step 1
$56,983
$74,078
$35.62
Clerk/Receptionist GS-0304-5 Step 1
$31,083
$40,408
$19.43

(End of Clause) 52.232-18 Availability of Funds (Apr 1984) Funds are not presently available for this contract. The Government’s obligation under this contract is contingent upon the availability of appropriated funds from which payment for contract purposes can be made. No legal liability on the part of the Government for any payment may arise until funds are made available to the Contracting Officer for this contract and until the Contractor receives notice of such availability, to be confirmed in writing by the Contracting Officer.

(End of Clause)

52.253-1 Computer Generated Forms (Jan 1991)

(a) Any data required to be submitted on a Standard or Optional Form prescribed by the Federal Acquisition Regulation (FAR) may be submitted on a computer-generated version of the form, provided there is no change to the name, content, or sequence of the data elements on the form, and provided the form carries the Standard or Optional Form number and edition date.

(b) Unless prohibited by agency regulations, any data required to be submitted on an agency unique form prescribed by an agency supplement to the FAR may be submitted on a computer-generated version of the form provided there is no change to the name, content, or sequence of the data elements on the form and provided the form carries the agency form number and edition date.

(c) If the Contractor submits a computer-generated version of a form that is different than the required form, then the rights and obligations of the parties will be determined based on the content of the required form.

(End of Clause)

HOMELAND SECURITY ACQUISITION REGULATION (HSAR) CLAUSES INCORPORATED BY REFERENCE

The full text of HSAR clauses may be accessed electronically at the following address:

https://www.dhs.gov/sites/default/files/2022-05/HSAR%202006%20conformed%20-%20May%202021.pdf

HSAR ClauseTitle and Date
3052.222-70STRIKES OR PICKETING AFFECTING TIMELY COMPLETION OF THE CONTRACT WORK(DEC 2003)
3052.222-71STRIKES OR PICKETING AFFECTING ACCESS TO A DHS FACILITY

(DEC 2003)

3052.223-90 ACCIDENT AND FIRE REPORTING (DEC 2003)

HSAR CLAUSES - FULL TEXT

3052.209-72 ORGANIZATIONAL CONFLICT OF INTEREST (JUNE 2006)

(a) Determination. The Government has determined that this effort may result in an actual or potential conflict of interest, or may provide one or more offerors with the potential to attain an unfair competitive advantage. The nature of the conflict of interest and the limitation on future contracting No known potential or actual OCIs have been identified as of the date of the release of this solicitation. Offerors shall fill out disclosures in accordance with paragraph (c) of this clause.

(b) If any such conflict of interest is found to exist, the Contracting Officer may (1) disqualify the offeror, or (2) determine that it is otherwise in the best interest of the United States to contract with the offeror and include the appropriate provisions to avoid, neutralize, mitigate, or waive such conflict in the contract awarded. After discussion with the offeror, the Contracting Officer may determine that the actual conflict cannot be avoided, neutralized, mitigated or otherwise resolved to the satisfaction of the Government, and the offeror may be found ineligible for award.

(c) Disclosure: The offeror hereby represents, to the best of its knowledge that: ___ (1) It is not aware of any facts which create any actual or potential organizational conflicts of interest relating to the award of this contract, or ___ (2) It has included information in its proposal, providing all current information bearing on the existence of any actual or potential organizational conflicts of interest, and has included a mitigation plan in accordance with paragraph (d) of this clause.

(d) Mitigation. If an offeror with a potential or actual conflict of interest or unfair competitive advantage believes the conflict can be avoided, neutralized, or mitigated, the offeror shall submit a mitigation plan to the Government for review. Award of a contract where an actual or potential conflict of interest exists shall not occur before Government approval of the mitigation plan. If a mitigation plan is approved, the restrictions of this clause do not apply to the extent defined in the mitigation plan.

(e) Other Relevant Information: In addition to the mitigation plan, the Contracting Officer may require further relevant information from the offeror. The Contracting Officer will use all information submitted by the offeror, and any other relevant information known to DHS, to determine whether an award to the offeror may take place, and whether the mitigation plan adequately neutralizes or mitigates the conflict.

(f) Corporation Change. The successful offeror shall inform the Contracting Officer within thirty (30) calendar days of the effective date of any corporate mergers, acquisitions, and/or divestures that may affect this clause.

(g) Flow-down. The contractor shall insert the substance of this clause in each first tier subcontract that exceeds the simplified acquisition threshold.

(End of clause)

3052.212-70 CONTRACT TERMS AND CONDITIONS APPLICABLE TO DHS ACQUISITION OF COMMERCIAL ITEMS (SEP 2012) The Contractor agrees to comply with any provision or clause that is incorporated herein by reference to implement agency policy applicable to acquisition of commercial items or components. The provision or clause in effect based on the applicable regulation cited on the date the solicitation is issued applies unless otherwise stated herein. The following provisions and clauses are incorporated by reference:

(b) Clauses.

__X__3052.203-70 Instructions for Contractor Disclosure of Violations.

__X__3052.204-70 Security Requirements for Unclassified Information Technology Resources.

__X__3052.204-71 Contractor Employee Access.

____Alternate I __X__3052.205-70 Advertisement, Publicizing Awards, and Releases.

__X__3052.209-72 Organizational Conflict of Interest __X__3052.219-71 DHS Mentor Protégé Program.

__X__3052.242-72 Contracting Officer’s Technical Representative.

(End of clause)

3052.215-70 KEY PERSONNEL OR FACILITIES (DEC 2003)

(a) The personnel or facilities specified below are considered essential to the work being performed under this contract and may, with the consent of the contracting parties, be changed from time to time during the course of the contract by adding or deleting personnel or facilities, as appropriate.

(b) Before removing or replacing any of the specified individuals or facilities, the Contractor shall notify the Contracting Officer, in writing, before the change becomes effective. The Contractor shall submit sufficient information to support the proposed action and to enable the Contracting Officer to evaluate the potential impact of the change on this contract. The Contractor shall not remove or replace personnel or facilities until the Contracting Officer approves the change.

The Key Personnel under this Contract:

Corporate Program Manager, On-Site Project Manager, Assistant On-Site Project Manager, Facilities Manager, Financial Manager, Quality and Operations Manager, Logistics Manager, Procurement Specialist, Human Resources Manager and four (4) Regional Managers.

(End of clause)

3052.228-70 INSURANCE (DEC 2003)

In accordance with the clause entitled “Insurance - Work on a Government Installation" and “ Insurance - Liability to Third Persons” in Section I, insurance of the following kinds and minimum amounts shall be provided and maintained during the period of performance of this contract for work conducted on Government installations and on contractor leased space:

(a) Worker's compensation and employer's liability. The contractor shall, as a minimum, meet the requirements specified at (FAR) 48 CFR 28.307-2(a).

(b) General liability. The contractor shall, as a minimum, meet the requirements specified at (FAR) 48 CFR 28.307-2(b).

(c) Automobile liability. The contractor shall, as a minimum, meet the requirements specified at (FAR) 48 CFR 28.307-2(c).

(End of clause)

SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)

(HSAR Class Deviation 15-01)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause—

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods:

(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements.

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Unique Entity Identity Number (UEID);

(ii) Contract numbers affected unless all…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .