HC1028-16-T-0162.docx
DOCX document 94 KB Posted
- Attached to
- Uptrends Software Maintenance for DNS Federal contract opportunity
- Solicitation number
- HC1028-16-T-0162
- Issued by
- Defense Information Systems Agency
About this file
RFQ
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CMTMA2162331_JA_MFR_2_Redacted.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
HC1028-16-T-0162
Section SF 1449 - CONTINUATION SHEET
| ITEM NO |
| SUPPLIES/SERVICES |
| QUANTITY |
| UNIT |
| UNIT PRICE |
| AMOUNT |
| 48 |
| Each |
Uptrends Monitoring
FFP
Enterprise Account Probes for DNS monitoring - 1 minute intervals (12 months) FOB: Destination
PURCHASE REQUEST NUMBER: CMTMA2162331
NET AMT
| ITEM NO |
| SUPPLIES/SERVICES |
| QUANTITY |
| UNIT |
| UNIT PRICE |
| AMOUNT |
| 2,400 |
| Each |
Uptrends SMS/text messages
FFP
Allowance for SMS/Text messages per month
NET AMT
| ITEM NO |
| SUPPLIES/SERVICES |
| QUANTITY |
| UNIT |
| UNIT PRICE |
| AMOUNT |
| 48 |
| Each |
| OPTION |
| Uptrends Monitoring |
FFP
Enterprise Account Probes for DNS monitoring - 1 minute intervals (12 months)
NET AMT
| ITEM NO |
| SUPPLIES/SERVICES |
| QUANTITY |
| UNIT |
| UNIT PRICE |
| AMOUNT |
| 3,000 |
| Each |
| OPTION |
| Uptrends SMS/text messages |
FFP
NET AMT
| ITEM NO |
| SUPPLIES/SERVICES |
| QUANTITY |
| UNIT |
| UNIT PRICE |
| AMOUNT |
| 48 |
| Each |
| OPTION |
| Uptrends Monitoring |
FFP
Enterprise Account Probes for DNS monitoring - 1 minute intervals (12 months)
NET AMT
| ITEM NO |
| SUPPLIES/SERVICES |
| QUANTITY |
| UNIT |
| UNIT PRICE |
| AMOUNT |
| 3,000 |
| Each |
| OPTION |
| Uptrends SMS/text messages |
FFP
NET AMT
SECTION 508
The following Section 508 Accessibility Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) to this acquisition:
Technical Standards
|X| 1194.21 - Software Applications and Operating Systems |_| 1194.22 - Web Based Intranet and Internet Information and Applications |_| 1194.23 - Telecommunications Products |_| 1194.24 - Video and Multimedia Products |_| 1194.25 - Self-Contained, Closed Products |_| 1194.26 - Desktop and Portable Computers |X| 1194.41 - Information, Documentation and Support
The Technical Standards above facilitate the assurance that the maximum technical standards are provided to the Offerors. Functional Performance Criteria is the minimally acceptable standards to ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic and information technology (E&IT) products are proposed.
Functional Performance Criteria
|X| 1194.31 - Functional Performance Criteria
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
| CLIN |
| INSPECT AT |
| INSPECT BY |
| ACCEPT AT |
| ACCEPT BY |
| 0001 |
| N/A |
| N/A |
| N/A |
| Government |
| 0002 |
| N/A |
| N/A |
| N/A |
| Government |
| 1001 |
| N/A |
| N/A |
| N/A |
| Government |
| 1002 |
| N/A |
| N/A |
| N/A |
| Government |
| 2001 |
| N/A |
| N/A |
| N/A |
| Government |
| 2002 |
| N/A |
| N/A |
| N/A |
| Government |
DELIVERY INFORMATION
| CLIN |
| DELIVERY DATE |
| QUANTITY |
| SHIP TO ADDRESS |
| DODAAC |
| 0001 |
| POP 30-SEP-2016 TO |
29-SEP-2017
| N/A |
| DISA |
BLDG 6906, 6910 COOPER AVENUE
FORT MEADE MD 20755
SHERRY GREEN
301-225-8692
HC1047
| 0002 |
| POP 30-SEP-2016 TO |
29-SEP-2017
| N/A |
| (SAME AS PREVIOUS LOCATION) |
HC1047
| 1001 |
| POP 30-SEP-2017 TO |
29-SEP-2018
| N/A |
| (SAME AS PREVIOUS LOCATION) |
HC1047
| 1002 |
| POP 30-SEP-2017 TO |
29-SEP-2018
| N/A |
| (SAME AS PREVIOUS LOCATION) |
HC1047
| 2001 |
| POP 30-SEP-2018 TO |
29-SEP-2019
| N/A |
| (SAME AS PREVIOUS LOCATION) |
HC1047
| 2002 |
| POP 30-SEP-2018 TO |
29-SEP-2019
| N/A |
| (SAME AS PREVIOUS LOCATION) |
HC1047
CLAUSES INCORPORATED BY REFERENCE
| 52.203-3 |
| Gratuities |
| APR 1984 |
| 52.203-6 |
| Restrictions On Subcontractor Sales To The Government |
| SEP 2006 |
| 52.204-4 |
| Printed or Copied Double-Sided on Postconsumer Fiber Content Paper |
| MAY 2011 |
| 52.204-10 |
| Reporting Executive Compensation and First-Tier Subcontract Awards |
| OCT 2015 |
| 52.209-2 |
| Prohibition on Contracting with Inverted Domestic Corporations--Representation |
| NOV 2015 |
| 52.209-6 |
| Protecting the Government's Interest When Subcontracting With Contractors Debarred, Suspended, or Proposed for Debarment |
| OCT 2015 |
| 52.212-1 |
| Instructions to Offerors--Commercial Items |
| OCT 2015 |
| 52.212-2 |
| Evaluation - Commercial Items |
| OCT 2014 |
| 52.212-3 |
| Offeror Representations and Certification--Commercial Items |
| APR 2016 |
| 52.212-4 |
| Contract Terms and Conditions--Commercial Items |
| MAY 2015 |
| 52.212-5 |
| Contract Terms and Conditions Required to Implement Statutes or Executive Orders--Commercial Items |
| JUN 2016 |
| 52.215-9000 |
| Cross Reference Matrix |
| JUL 2014 |
| 52.216-9000 |
| Ordering Procedures for External Agencies |
| JAN 2016 |
| 52.217-8 |
| Option To Extend Services |
| NOV 1999 |
| 52.217-9 |
| Option To Extend The Term Of The Contract |
| MAR 2000 |
| 52.219-8 |
| Utilization of Small Business Concerns |
| OCT 2014 |
| 52.222-3 |
| Convict Labor |
| JUN 2003 |
| 52.222-17 |
| Nondisplacement of Qualified Workers |
| MAY 2014 |
| 52.222-26 |
| Equal Opportunity |
| APR 2015 |
| 52.222-35 |
| Equal Opportunity for Veterans |
| OCT 2015 |
| 52.222-36 |
| Equal Opportunity for Workers with Disabilities |
| JUL 2014 |
| 52.222-37 |
| Employment Reports on Veterans |
| FEB 2016 |
| 52.222-40 |
| Notification of Employee Rights Under the National Labor Relations Act |
| DEC 2010 |
| 52.222-41 |
| Service Contract Labor Standards |
| MAY 2014 |
| 52.222-50 |
| Combating Trafficking in Persons |
| MAR 2015 |
| 52.222-51 |
| Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment--Requirements |
| MAY 2014 |
| 52.222-53 |
| Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services--Requirements |
| MAY 2014 |
| 52.222-54 |
| Employment Eligibility Verification |
| OCT 2015 |
| 52.223-18 |
| Encouraging Contractor Policies To Ban Text Messaging While Driving |
| AUG 2011 |
| 52.225-13 |
| Restrictions on Certain Foreign Purchases |
| JUN 2008 |
| 52.230-3 |
| Disclosure And Consistency Of Cost Accounting Practices |
| OCT 2015 |
| 52.232-33 |
| Payment by Electronic Funds Transfer--System for Award Management |
| JUL 2013 |
| 52.233-2 |
| Service Of Protest |
| SEP 2006 |
| 52.233-3 |
| Protest After Award |
| AUG 1996 |
| 52.233-4 |
| Applicable Law for Breach of Contract Claim |
| OCT 2004 |
| 52.242-13 |
| Bankruptcy |
| JUL 1995 |
| 52.247-34 |
| F.O.B. Destination |
| NOV 1991 |
| 52.252-1 |
| Solicitation Provisions Incorporated By Reference |
| FEB 1998 |
| 52.252-5 |
| Authorized Deviations In Provisions |
| APR 1984 |
| 52.253-1 |
| Computer Generated Forms |
| JAN 1991 |
| 252.203-7000 |
| Requirements Relating to Compensation of Former DoD Officials |
| SEP 2011 |
| 252.203-7002 |
| Requirement to Inform Employees of Whistleblower Rights |
| SEP 2013 |
| 252.203-7003 |
| Agency Office of the Inspector General |
| DEC 2012 |
| 252.203-7005 |
| Representation Relating to Compensation of Former DoD Officials |
| NOV 2011 |
| 252.204-7003 |
| Control Of Government Personnel Work Product |
| APR 1992 |
| 252.204-7006 |
| Billing Instructions |
| OCT 2005 |
| 252.204-7012 |
| Safeguarding Covered Defense Information and Cyber Incident Reporting. |
| DEC 2015 |
| 252.204-7015 |
| Notice of Authorized Disclosure of Information for Litigation Support |
| MAY 2016 |
| 252.205-7000 |
| Provision Of Information To Cooperative Agreement Holders |
| DEC 1991 |
| 252.209-7004 |
| Subcontracting With Firms That Are Owned or Controlled By The Government of a Country that is a State Sponsor of Terrorism |
| OCT 2015 |
| 252.211-7003 |
| Item Unique Identification and Valuation |
| MAR 2016 |
| 252.211-7008 |
| Use of Government-Assigned Serial Numbers |
| SEP 2010 |
| 252.222-7007 |
| Representation Regarding Combating Trafficking in Persons |
| JAN 2015 |
| 252.223-7008 |
| Prohibition of Hexavalent Chromium |
| JUN 2013 |
| 252.225-7012 |
| Preference For Certain Domestic Commodities |
| FEB 2013 |
| 252.225-7048 |
| Export-Controlled Items |
| JUN 2013 |
| 252.225-7050 |
| Disclosure of Ownership or Control by the Government of a Country that is a State Sponsor of Terrorism |
| OCT 2015 |
| 252.227-7014 |
| Rights in Noncommercial Computer Software and Noncommercial Computer Software Documentation |
| FEB 2014 |
| 252.227-7015 |
| Technical Data--Commercial Items |
| FEB 2014 |
| 252.227-7016 |
| Rights in Bid or Proposal Information |
| JAN 2011 |
| 252.227-7017 |
| Identification and Assertion of Use, Release, or Disclosure Restrictions |
| JAN 2011 |
| 252.227-7030 |
| Technical Data--Withholding Of Payment |
| MAR 2000 |
| 252.227-7037 |
| Validation of Restrictive Markings on Technical Data |
| JUN 2013 |
| 252.232-7003 |
| Electronic Submission of Payment Requests and Receiving Reports |
| JUN 2012 |
| 252.232-7010 |
| Levies on Contract Payments |
| DEC 2006 |
| 252.237-7010 |
| Prohibition on Interrogation of Detainees by Contractor Personnel |
| JUN 2013 |
| 252.239-7000 |
| Protection Against Compromising Emanations |
| JUN 2004 |
| 252.239-7001 |
| Information Assurance Contractor Training and Certification |
| JAN 2008 |
| 252.239-7017 |
| Notice of Supply Chain Risk |
| NOV 2013 |
| 252.239-7018 |
| Supply Chain Risk |
| OCT 2015 |
| 252.243-7001 |
| Pricing Of Contract Modifications |
| DEC 1991 |
| 252.243-7002 |
| Requests for Equitable Adjustment |
| DEC 2012 |
| 252.244-7000 |
| Subcontracts for Commercial Items |
| JUN 2013 |
| 252.244-7001 |
| Contractor Purchasing System Administration |
| MAY 2014 |
| 252.246-7000 |
| Material Inspection And Receiving Report |
| MAR 2008 |
| 252.247-7023 |
| Transportation of Supplies by Sea |
| APR 2014 |
CLAUSES INCORPORATED BY FULL TEXT
52.204-9000 POINTS OF CONTACT (AUG 2005)
Contracting Officer Name: Tricia L. Singler Organization/Office Symbol: DITCO/PL8321 Phone No.: 618-229-9378 E-Mail Address: tricia.l.singler.civ@mail.mil
Contract Specialist Name: Tricia L. Singler Organization/Office Symbol: DITCO/PL8321 Phone No.: 618-229-9378 E-Mail Address: tricia.l.singler.civ@mail.mil
COR/Mission Partner Point of Contact (Note: To be filled in upon contract award) Name:
Organization/Office Symbol:
Phone No.:
E-Mail Address:
Contractor Point of Contact Contractor Legal Business Name:
DUNS:
CAGE CODE:
Contractor POC:
E-Mail Address:
Phone Number:
Fax Number:
(End of clause)
52.204-9001 CONTRACT/ORDER CLOSEOUT—FIXED-PRICE, TIME-AND-MATERIALS, OR LABOR-HOURS (JAN 2007)
Timely contract closeout is a priority under this contract/order. The Contractor shall submit a final invoice within ninety (90) calendar days after the expiration of this contract/order, unless the Contractor requests and is granted an extension by the Contracting Officer, in writing. In addition, and concurrent with the submission of the final invoice, the Contractor shall notify the Contracting Officer of the amount of excess funds that can be deobligated from this contract/order so the closeout process can begin as soon as possible upon expiration of this contract/order. A bilateral contract/order closeout modification will be forwarded to the Contractor by the Contracting Officer and must be signed by the Contractor and returned to the Contracting Officer within thirty (30) calendar days of issuance of the modification. A Contractor’s failure to respond and/or sign the bilateral closeout modification within thirty (30) calendar days of receipt will constitute approval of the terms of the modification and the modification will subsequently be processed unilaterally by the Contracting Officer to deobligate excess funds and close this contract/order.
If this contract/order contains option periods, the Contractor is required to submit an invoice within ninety (90) calendar days after expiration of the base period of performance and the expiration of each exercised option period of performance to allow for deobligation of excess funds that were obligated in those respective periods of performance.
52.209-9000 ORGANIZATIONAL AND CONSULTANT CONFLICTS OF INTEREST (OCCI) (DEC 2005)
(a) An offeror shall identify in its proposal, quote, bid or any resulting contract, any potential or actual Organizational and Consultant Conflicts of Interest (OCCI) as described in FAR Subpart 9.5. This includes actual or potential conflicts of interests of proposed subcontractors. If an offeror identifies in its proposal, quote, bid or any resulting contract, a potential or actual conflict of interests the offeror shall submit an Organizational and Consultant Conflicts of Interest Mitigation Plan to the contracting officer. The Organizational and Consultant Conflicts of Interest Mitigation Plan shall describe how the offeror addresses potential or actual conflicts of interest and identify how they will avoid, neutralize, or mitigate present or future conflicts of interest.
(b) Offerors must consider whether their involvement and participation raises any OCCI issues, especially in the following areas when:
(1) Providing systems engineering and technical direction.
(2) Preparing specifications or work statements and/or objectives.
(3) Providing evaluation services.
(4) Obtaining access to proprietary information.
(c) If a prime contractor or subcontractor breaches any of the OCCI restrictions, or does not disclose or misrepresents any relevant facts concerning its conflict of interest, the government may take appropriate action, including terminating the contract, in additional to any remedies that may be otherwise permitted by the contract or operation of law.
52.211-9000 REQUIREMENT TO SUBMIT AN ELECTRONIC PRODUCT LIST (OCT 2015)
The contractor shall submit the following in addition to complying with all requirements of DFARS 252.211-7003, Item Identification and Valuation:
(a) Complete the Electronic Product List (EPL) attached to this contract for all products delivered under this contract. If a copy of the EPL has not been provide with the contract document, the EPL should be obtained from the Contracting Officer. A separate EPL shall be submitted each time products are delivered under this contract, including when products are replaced through a warranty or service support agreement.
(b) The EPL shall be delivered electronically for review and approval to the Acceptor identified as the Customer/COR/TM Point of Contact in the clause at 52.204-9000, Points of Contact if method of payment is via the government purchase card, or the WAWF point of contact identified in the clause at DFARS 252.232-7006, Wide Area WorkFlow Payment Instructions for contracts process through WAWF. A copy of the EPL shall also be submitted to the Manpower, Personnel and Security (MPS) Directorate at the following email address: disa.meade.mps.list.mps31-warehouse-branch-cam-l@mail.mil.
(c) The contractor shall submit the EPL to the Acceptor and MPS in advance of or concurrently with delivery of products. The Acceptor will not accept products delivered under this contract until the EPL is approved.
(d) If the EPL is delivered in advance of the products, the Acceptor will notify the contractor via email if the list is approved or disapproved. If the EPL is delivered concurrently with the products, acceptance of the products delivered via WAWF will also serve as approval of the EPL.
52.225-25 PROHIBITION ON CONTRACTING WITH ENTITIES ENGAGING IN CERTAIN ACTIVITIES OR TRANSACTIONS RELATING TO IRAN--REPRESENTATION AND CERTIFICATIONS. (OCT 2015)
(a) Definitions. As used in this provision--
Person--
(1) Means--
(i) A natural person;
(ii) A corporation, business association, partnership, society, trust, financial institution, insurer, underwriter, guarantor, and any other business organization, any other nongovernmental entity, organization, or group, and any governmental entity operating as a business enterprise; and
(iii) Any successor to any entity described in paragraph (1)(ii) of this definition; and
(2) Does not include a government or governmental entity that is not operating as a business enterprise.
Sensitive technology--
(1) Means hardware, software, telecommunications equipment, or any other technology that is to be used specifically--
(i) To restrict the free flow of unbiased information in Iran; or
(ii) To disrupt, monitor, or otherwise restrict speech of the people of Iran; and
(2) Does not include information or informational materials the export of which the President does not have the authority to regulate or prohibit pursuant to section 203(b)(3) of the International Emergency Economic Powers Act (50 U.S.C. 1702(b)(3)).
(b) The offeror shall email questions concerning sensitive technology to the Department of State at CISADA106@state.gov.
(c) Except as provided in paragraph (d) of this provision or if a waiver has been granted in accordance with 25.703-4, by submission of its offer, the offeror—
(1) Represents, to the best of its knowledge and belief, that the offeror does not export any sensitive technology to the government of Iran or any entities or individuals owned or controlled by, or acting on behalf or at the direction of, the government of Iran;
(2) Certifies that the offeror, or any person owned or controlled by the offeror, does not engage in any activities for which sanctions may be imposed under section 5 of the Iran Sanctions Act. These sanctioned activities are in the areas of development of the petroleum resources of Iran, production of refined petroleum products in Iran, sale and provision of refined petroleum products to Iran, and contributing to Iran's ability to acquire or develop certain weapons or technologies; and
(3) Certifies that the offeror, and any person owned or controlled by the offeror, does not knowingly engage in any transaction that exceeds $3,500 with Iran's Revolutionary Guard Corps or any of its officials, agents, or affiliates, the property and interests in property of which are blocked pursuant to the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.) (see OFAC's Specially Designated Nationals and Blocked Persons List at http://www.treasury.gov/ofac/downloads/t11sdn.pdf).
(d) Exception for trade agreements. The representation requirement of paragraph (c)(1) and the certification requirements of paragraphs (c)(2) and (c)(3) of this provision do not apply if—
(1) This solicitation includes a trade agreements notice or certification (e.g., 52.225-4, 52.225-6, 52.225-12, 52.225-24, or comparable agency provision); and
(2) The offeror has certified that all the offered products to be supplied are designated country end products or designated country construction material.
(End of provision)
52.237-9001 ENTERPRISE-WIDE CONTRACTOR MANPOWER REPORTING APPLICATION (eCMRA) REPORTING (JAN 2015)
The contractor shall ensure ALL contractor labor hours including subcontractor, at all levels/tiers, labor hours required for the performance of services provided under this contract are reported via a secure data collection site.
The contractor and all subcontractors, at all levels/tiers, providing direct labor under this contract shall report complete and accurate data for the labor executed during the period of performance during each Government fiscal year (FY), which runs from October 1 to September 30. The Contractor shall input the data into the appropriate eCMRA reporting tool, which can be accessed via a secure web site at http://www.ecmra.mil/. There are four separate eCMRA tools: Army, Air Force, Navy and All Other Defense Components. The appropriate eCMRA reporting tool to use is determined by the requiring activity being supported (e.g., if DISA awards a contract for an Air Force requiring activity, the contractor shall load the required reporting data in the “Department of Air Force CMRA” tool). While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. The contractor shall completely fill in all required data fields. The contractor shall enter initial data into the appropriate eCMRA tool to establish the basic contract record no later than 15 working days after receipt of contract award or contract modification incorporating this clause. The contractor shall notify the COR when the basic contract record has been established in the appropriate eCMRA tool.
eCMRA User Manuals and Frequently Asked Questions (FAQs) are available at http://www.ecmra.mil/
Contractors may direct technical questions to the eCMRA help desk at usaf.pentagon.saf-aq.mbx.cmra-help-desk-dod@mail.mil
52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):
http://farsite.hill.af.mil
52.252-6 AUTHORIZED DEVIATIONS IN CLAUSES (APR 1984)
(a) The use in this solicitation or contract of any Federal Acquisition Regulation (48 CFR Chapter 1) clause with an authorized deviation is indicated by the addition of "(DEVIATION)" after the date of the clause.
(b) The use in this solicitation or contract of any DFARS (48 CFR Chapter 2) clause with an authorized deviation is indicated by the addition of "(DEVIATION)" after the name of the regulation.
252.204-7008 COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS (DEVIATION 2016-O0001)(DEC 2015)
(a) Definitions. As used in this provision— “Controlled technical information,” “covered contractor information system,” and “covered defense information” are defined in clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DEVIATION 2016-O0001)(OCT 2015).
(b) The security requirements required by contract clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DEVIATION 2016-O0001)(OCT 2015) shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.
(c) If the Offeror anticipates that additional time will be necessary to implement derived security requirement 3.5.3 “Use of multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts” within National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations (see http://dx.doi.org/10.6028/NIST.SP.800-171), the Offeror shall notify the Contracting Officer that they will implement the requirement within 9 months of contract award.
(d) If the Offeror proposes to deviate from any of the security requirements in NIST SP 800-171that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—
(1) Why a particular security requirement is not applicable; or
(2) How an alternative, but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.
(e) An authorized representative of the DoD CIO will approve or disapprove offeror requests to deviate from NIST SP 800-171 requirements in writing prior to contract award. Any approved deviation from NIST SP 800-171 shall be incorporated into the resulting contract.
(End of provision)
252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING (DEC 2015)
(a) Definitions. As used in this clause--
Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
Contractor attributional/proprietary information means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
Contractor information system means an information system belonging to, or operated by or for, the Contractor.
Controlled technical information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
Covered contractor information system means an information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
Covered defense information means unclassified information that--
(i) Is--
(A) Provided to the contractor by or on behalf of DoD in connection with the performance of the contract; or
(B) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract; and
(ii) Falls in any of the following categories:
(A) Controlled technical information.
(B) Critical information (operations security). Specific facts identified through the Operations Security process about friendly intentions, capabilities, and activities vitally needed by adversaries for them to plan and act effectively so as to guarantee failure or unacceptable consequences for friendly mission accomplishment (part of Operations Security process).
(C) Export control. Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. To include dual use items; items identified in export administration regulations, international traffic in arms regulations and munitions list; license applications; and sensitive nuclear technology information.
(D) Any other information, marked or otherwise identified in the contract, that requires safeguarding or disseminationcontrols pursuant to and consistent with law, regulations, and Governmentwide policies (e.g., privacy, proprietary business information).
Cyber incident means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
Forensic analysis means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
Malicious software means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
Media means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which information is recorded, stored, or printed within an information system.
Operationally critical support means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
Rapid(ly) report(ing) means within 72 hours of discovery of any cyber incident.
Technical information means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Non Commercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The Contractor shall provide adequate security for all covered defense information on all covered contractor information systems that support the performance of work under this contract. To provide adequate security, the Contractor shall--
(1) Implement information systems security protections on all covered contractor information systems including, at a minimum--
(i) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government--
(A) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract; and
(B) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract; or
(ii) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1)(i) of this clause--
(A) The security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, ``Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,'' http://dx.doi.org/10.6028/NIST.SP.800-171 that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, as soon as practical, but not later than December 31, 2017. The Contractor shall notify the DoD CIO, via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award; or
(B) Alternative but equally effective security measures used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection accepted in writing by an authorized representative of the DoD CIO; and
(2) Apply other security measures when the Contractor reasonably determines that such measures, in addition to those identified in paragraph (b)(1) of this clause, may be required to provide adequate security in a dynamic environment based on an assessed risk or vulnerability.
(c) Cyber incident reporting requirement.
(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support, the Contractor shall--
(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor's network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor's ability to provide operationally critical support; and
(ii) Rapidly report cyber incidents to DoD at http://dibnet.dod.mil.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at http://dibnet.dod.mil.
(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see http://iase.disa.mil/pki/eca/Pages/index.aspx.
(d) Malicious software. The Contractor or subcontractors that discover and isolate malicious software in connection with a reported cyber incident shall submit the malicious software in accordance with instructions provided by the Contracting Officer.
(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.
(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.
(i) Use and release of contractor attributional/proprietary information not created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD--
(1) To entities with missions that may be affected by such information;
(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
(3) To Government entities that conduct counterintelligence or law enforcement investigations;
(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or
(5) To a support services contractor (``recipient'') that is directly supporting Government activities under a contract that includes the clause at 252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government's use and release of such information.
(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor's responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(m) Subcontracts. The Contractor shall--
(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve a covered contractor information system, including subcontracts for commercial items, without alteration, except to identify the parties;
and
(2) When this clause is included in a subcontract, require subcontractors to rapidly report cyber incidents directly to DoD at http://dibnet.dod.mil and the prime Contractor. This includes providing the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable.
252.225-7048 EXPORT-CONTROLLED ITEMS (JUNE 2013)
(a) Definition. ``Export-controlled items,'' as used in this clause, means items subject to the Export Administration Regulations (EAR) (15 CFR Parts 730-774) or the International Traffic in Arms Regulations (ITAR) (22 CFR Parts 120-130). The term includes--
(1) ``Defense items,'' defined in the Arms Export Control Act, 22 U.S.C. 2778(j)(4)(A), as defense articles, defense services, and related technical data, and further defined in the ITAR, 22 CFR Part 120; and
(2) ``Items,'' defined in the EAR as ``commodities'', ``software'', and ``technology,'' terms that are also defined in the
EAR, 15 CFR 772.1.
(b) The Contractor shall comply with all applicable laws and regulations regarding export-controlled items, including, but not limited to, the requirement for contractors to register with the Department of State in accordance with the ITAR. The Contractor shall consult with the Department of State regarding any questions relating to compliance with the ITAR and shall consult with the Department of Commerce regarding any questions relating to compliance with the EAR.
(c) The Contractor's responsibility to comply with all applicable laws and regulations regarding export-controlled items exists independent of, and is not established or limited by, the information provided by this clause.
(d) Nothing in the terms of this contract adds, changes, supersedes, or waives any of the requirements of applicable Federal laws, Executive orders, and regulations, including but not limited to—
(1) The Export Administration Act of 1979, as amended (50 U.S.C. App. 2401, et seq.);
(2) The Arms Export Control Act (22 U.S.C. 2751, et seq.);
(3) The International Emergency Economic Powers Act (50 U.S.C. 1701, et seq.);
(4) The Export Administration Regulations (15 CFR Parts 730-774);
(5) The International Traffic in Arms Regulations (22 CFR Parts 120-130); and
(6) Executive Order 13222, as extended.
(e) The Contractor shall include the substance of this clause, including this paragraph (e), in all subcontracts.
252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (MAY 2013)
Department of Defense Activity Address Code (DoDAAC) is a six position code that uniquely identifies a unit, activity, or organization.
Document type means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).
Local processing office (LPO) is the office responsible for payment certification when payment certification is done external to the entitlement system.
(b) Electronic invoicing. The WAWF system is the method to electronically process vendor payment requests and receiving reports, as authorized by DFARS 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall--
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.acquisition.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this Web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.
(e) WAWF methods of document submission. Document submissions may be via Web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor must use the following information when submitting payment requests and receiving reports in WAWF for this contract/order:
(1) Document type. The Contractor shall use the following document type(s).
FOB Destination
(2) Inspection/acceptance location. The Contractor shall select the following inspection/acceptance location(s) in WAWF, as specified by the contracting officer.
Not applicable
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table* Field Name in WAWF Data to be entered in WAWF
| Pay Official DoDAAC | HQ0131 | ||
| Issue By DoDAAC | HC1028 | ||
| Admin DoDAAC | HC1028 | ||
| Inspect By DoDAAC | HC1047 | ||
| Ship To Code | NA | ||
| Ship From Code | NA | ||
| Mark For Code | NA | ||
| Service Approver (DoDAAC) | HC1047 | ||
| Service Acceptor (DoDAAC) | HC1047 | ||
| Accept at Other DoDAAC | NA | ||
| LPO DoDAAC | NA | ||
| DCAA Auditor DoDAAC | NA | ||
| Other DoDAAC(s) | NA |
(4) Payment request and supporting documentation. The Contractor shall ensure a payment request includes appropriate contract line item and subline item descriptions of the work performed or supplies delivered, unit price/cost per unit, fee (if applicable), and all relevant back-up documentation, as defined in DFARS Appendix F, (e.g. timesheets) in support of each payment request.
(5) WAWF email notifications. The Contractor shall enter the email address identified below in the “Send Additional Email Notifications” field of WAWF once a document is submitted in the system.
Acceptor: Ship To/Service Acceptor DoDAAC: HC1047 Name: Sherry Green Phone Number: 301-225-8692 E-Mail: sherry.m.green.civ@mail.mil Pay official: Pay DoDAAC: HQ0131
(g) WAWF point of contact. (1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity's WAWF point of contact.
Payment Processing Questions: Contact the following DFAS office as specified in the contract/order:
Columbus Center -- 1-800-756-4571 HQ0131 – Option 2, then Option 2
(2) For technical WAWF help, contact the WAWF helpdesk at 866-618-5988.
252.239-7010 CLOUD COMPUTING SERVICES (AUG 2015)
Authorizing official, as described in DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), means the senior Federal official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.
Cloud computing means a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This includes other commercial terms, such as on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. It also includes commercial offerings for software-as-a-service, infrastructure-as-a-service, and platform-as-a-service.
Cyber incident means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
Government data means any information, document, media, or machine readable material regardless of physical form or characteristics, that is created or obtained by the Government in the course of official Government business.
Government-related data means any information, document, media, or machine readable material regardless of physical form or characteristics that is created or obtained by a contractor through the storage, processing, or communication of Government data. This does not include contractor's business records e.g. financial records, legal records etc. or data such as operating procedures, software coding or algorithms that are not uniquely applied to the Government data.
Media means physical devices or writing surfaces including, but not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
Spillage security incident that results in the transfer of classified or controlled unclassified information onto an information system not accredited (i.e., authorized) for the appropriate security level.
(b) Cloud computing security requirements. The requirements of this clause are applicable when using cloud computing to provide information technology services in the performance of the contract.
(1) If the Contractor indicated in its offer that it ``does not anticipate the use of cloud computing services in the performance of a resultant contract,'' in response to provision 252.239-7009, Representation of Use of Cloud Computing, and after the award of this contract, the Contractor proposes to use cloud computing services in the performance of the contract, the Contractor shall obtain approval from the Contracting Officer prior to utilizing cloud computing services in performance of the contract.
(2) The Contractor shall implement and maintain administrative, technical, and physical safeguards and controls with the security level and services required in accordance with the Cloud Computing Security Requirements Guide (SRG) (version in effect at the time the solicitation is issued or as authorized by the Contracting Officer) found at http://iase.disa.mil/cloud_security/Pages/index.aspx;
(3) The Contractor shall maintain within the United States or outlying areas all Government data that is not physically located on DoD premises, unless the Contractor receives written notification from the Contracting Officer to use another location, in accordance with DFARS 239.7602-2(a).
(c) Limitations on access to, and use and disclosure of Government data and Government-related data.
(1) The Contractor shall not access, use, or disclose Government data unless specifically authorized by the terms of this contract or a task order or delivery order issued hereunder.
(i) If authorized by the terms of this contract or a task order or delivery order issued hereunder, any access to, or use or disclosure of, Government data shall only be for purposes specified in this contract or task order or delivery order.
(ii) The Contractor shall ensure that its employees are subject to all such access, use, and disclosure prohibitions and obligations.
(iii) These access, use, and disclosure prohibitions and obligations shall survive the expiration or termination of this contract.
(2) The Contractor shall use Government-related data only to manage the operational environment that supports the Government data and for no other purpose unless otherwise permitted with the prior written approval of the Contracting Officer.
(d) Cloud computing services cyber incident reporting. The Contractor shall report all cyber incidents that are related to the cloud computing service provided under this contract. Reports shall be submitted to the Department of Defense via http://dibnet.dod.mil/.
(e) Malicious software. The Contractor or subcontractors that discover and isolate malicious software in connection with a reported cyber incident shall submit the malicious software in accordance with instructions provided by the Contracting Officer.
(f) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (d) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
(g) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
(h) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (f) of this clause.
(i) Records management and facility access.
(1) The Contractor shall provide the Contracting Officer all Government data and Government-related data in the format specified in the contract.
(2) The Contractor shall dispose of Government data and Government-related data in accordance with the terms of the contract and provide the confirmation of disposition to the Contracting Officer in accordance with contract closeout procedures.
(3) The Contractor shall provide the Government, or its authorized representatives, access to all Government data and Government-related data, access to contractor personnel involved in performance of the contract, and physical access to any Contractor facility with Government data, for the purpose of audits, investigations, inspections, or other similar activities, as authorized by law or regulation.
(j) Notification of third party access requests. The Contractor shall notify the Contracting Officer promptly of any requests from a third party for access to Government data or Government-related data, including any warrants, seizures, or subpoenas it receives, including those from another Federal, State, or Local agency. The Contractor shall cooperate with the Contracting Officer to take all measures to protect Government data and Government-related data from any unauthorized disclosure.
(k) Spillage. Upon notification by the Government of a spillage, or upon the Contractor's discovery of a spillage, the Contractor shall cooperate with the Contracting Officer to address the spillage in compliance with agency procedures.
(l) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (l), in all subcontracts that involve or may involve cloud services, including subcontracts for commercial items.
Additional Accounting and Appropriation Data
97X4930.5F20 000 C1013 0 068142 2F
CLIN/SubCLIN Purchase Request Number Obligated Amount image1.wmf image2.wmf
File details come from the government source that posted it. Updated .