HIS PWS_Draft.docx
DOCX document 121 KB Posted
- Attached to
- FEMA Housing Inspection Services Programs Federal contract opportunity
- Solicitation number
- 70FB8022I0FEMAHIS
View the file
Other files for this federal contract opportunity
Show all 41
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT A
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF HOMELAND SECURITY (DHS)
FEDERAL EMERGENCY MANAGEMENT AGENCY (FEMA)
OFFICE OF RESPONSE AND RECOVERY (ORR)
INDIVIDUAL ASSISTANCE (IA)
HOUSING INSPECTION SERVICES (HIS)
March 2022 Part 1 General Information
| 1.1 | The purpose of this contract is to obtain residential damage assessments for survivors affected by presidentially declared disasters within the United States, Native American Reservations and its Territories. The Federal Emergency Management Agency (FEMA) is authorized pursuant to the Disaster Relief and Emergency Assistance Act (PL-93-288) (herein referred to as the “Act) as amended by the Robert T. Stafford Act (P.L. 100-707), to provide assistance to survivors of presidentially declared disasters and emergencies. The residential damage assessments provided under this contract are used in determining survivor eligibility for FEMA programs. Urgency is paramount, as these services have a direct impact on the recovery efforts of disaster survivors. Performance parameters set forth within this IDIQ Performance Work Statement (PWS) may be refined at the task order level. |
| 1.2 | Background: FEMA’s mission is to support our citizen’s and first responders, to ensure that as a nation, we work together to build, sustain, and improve our capability to prepare for, protect against, respond to, recover from, and mitigate all hazards. The Office of Response and Recovery mission is to provide guidance, leadership and oversight to build, sustain and improve the coordination and delivery of support to citizens and State, local, tribal and territorial governments to save lives, reduce suffering, protect property and recover from all hazards. Individual Assistance’s mission is to ensure disaster survivors. FEMA is charged with ensuring that all individuals and families adversely affected by a presidentially declared disaster or emergency have timely access to the full range of FEMA programs. The residential damage assessments provided under this contract are used in determining survivor eligibility for FEMA programs. Urgency is paramount, as these services have a direct impact on the recovery efforts of disaster survivors. |
FEMA currently employs a government workforce of roughly 100 inspectors who conduct inspections immediately after declaration and at the closure of each event. Statistically, this staff has satisfied the assessment of nearly eighty percent (80%) of declared events when representing twenty percent (20%) of returned inspections. Conversely, 20% of declared events represents 80% of all inspections conducted, typically those that occur during the fall hurricane season or no-notice events such as large scale earthquakes.
The requirement to staff a large number of inspectors immediately following a Presidential Declaration has historically been a daunting task. While FEMA understands this challenge, the timely assessment of residential damages remains paramount to the Individual Assistance program to avoid prolonged survivor displacement and the utilization of emergency resources.
1.3 Description of Services/Introduction: The contractor shall provide all personnel, equipment, tools, materials, supervision, and other items and services necessary to perform housing inspections as defined in this Performance Work Statement (PWS), except as specified in Section 3 as government-furnished property and services.
Using special purpose software, the contractor shall collect and report disaster-caused residential and personal property losses verifying ownership, occupancy and survivor needs by means approved by FEMA. Contractors should expect to collect data related to the extent of damage to real property; private multi-family properties, road and bridge repairs needed, the habitability of the home; ownership, occupancy and insurance verification information; the extent of damage to personal property and vehicles; information regarding other disaster expenses and needs; and area access issues. The contractor must perform to the standards in the Performance Requirements Summary (PRS) and in accordance with the terms and conditions of the contract. The historical work issued is listed in Table A, for illustration purposes. Work under the contract is global and may occur in the Continental United States or and Outside Continental United States simultaneously. The work may include one or multiple County(s) within State(s), United States Territory(s), or Native American Reservation(s). The conditions and parameters of schedule and performance are located within the Performance Requirements Summary (PRS) (Attachment 2).
1.4 Performance Objectives: The contractor shall, at a minimum, perform the following:
· Return inspections in a timely manner to prevent survivor displacement and to avoid undue burden on emergency resources with emphasis placed on the initial days following task order award.
· Using special purpose software provided by FEMA, accomplish the collection and reporting of inspection data to include survivor residence verification.
· Perform to the standards established in the Performance Requirements Summary (PRS) and in accordance with the terms and conditions of this contract.
· Ensure all required level of support for this contract is maintained at all times. If for any reason the Contractor staffing levels are not maintained and essential personnel will not be immediately replaced, the Contractor shall provide e-mail notification to the Contracting Officer’s Representative (COR), explaining the discrepancy and the planned corrective action.
· Develop a Quality Management System capable of the following key activities:
· Monitor, measure, analyze, control, and improve processes;
· Reduce product variation;
· Measure/verify product conformity;
· Establish mechanisms for field product performance feedback;
· and implement an effective root-cause analysis and corrective and preventative action system.
· Maintain and adhere to an approved quality management system. The QMS shall adhere to the requirements of FAR 46.202-4 -- Higher-Level Contract Quality Requirements 46.203 - Criteria for Use of Contract Quality Requirements. Any updated copy of the QCP shall be provided to the Contracting Officer for review and approval as changes occur.
· Be responsible for the training of all contractor employees required to meet the terms of this contract and must occur prior to performing work under this contract. The contractor is expected to develop and maintain a training program for its employees and sub-contracted employees. Training curricula and content for inspectors shall be approved by FEMA prior to use, which includes any modifications to training. Training must be comprehensive in nature addressing damage caused by natural and manmade perils as covered by the Stafford Act. Acceptable records of staff training shall include training course title, employee name or inspector ID number and dates of completion.
| 1.5 | Scope of Work: The Contractor shall provide all personnel, equipment, tools, materials, supervision, and other items and services necessary to perform housing inspections in support of FEMA’s requirement to facilitate assistance to survivors of Presidentially Declared disasters and emergencies as authorized pursuant to the Disaster Relief and Emergency Assistance Act (PL-93-288) (herein referred to as the “Act) as amended by the Robert T. Stafford Act (P.L. 100-707). |
| 1.6 | Inspection Types: |
The types of initial inspections to be conducted under this contract are onsite traditional line item, onsite damage level, remote damage level and geospatial inspections as describe within Section 5 Specific Tasks.
1.7 Technical Assistance Task Orders
Unique disaster related tasks arise during disaster declarations requiring technical assistance to be implemented. Examples of technical assistance are:
a.) Disaster Inspector Shelter coordinators that will provide a link between the survivor and the inspector when telecommunication is a challenge b.) Deliver FEMA Info flyers to addresses in disaster stricken areas.
c) Provide ad-hoc instructional services for IA Recovery disaster damage and collection of data processes for inter-Governmental agencies supporting the IA programs such as IA Recovery Residential Damage Inspections Training.
d.) Mobile home site inspections for the IA housing program.
e.) Asset delivery services. I.e. delivery of IA Recovery supplies and materials.
Execution of technical assistance will be via the Task Order Proposal Request (TOPR) process used under this contract.
When services are needed, the Government will forward to the Contractor the Performance Work Statement (PWS) or Statement of Objectives and a Request for Proposal (RFP). Work shall not commence until a task order is in place, unless a written notice is issued by the Contracting Officer allowing work to begin immediately due to urgency. The Contractor staff shall be in place within 48 hours of Task Order notification.
The Contractor’s proposal shall include itemized costs and a technical proposal. Proposed costs shall be negotiable and the technical proposal shall be subject to Government approval. The technical proposal shall describe in detail the proposed process for implementing and fulfilling the Government's requirement, including detailed staffing plans and performance dates, and specify deliverables, including reports and proposed methods for delivering materials, delivery dates, locations and the proposed labor category to perform the task. Refer to Attachment #(TBD), Department of Labor Wage Determinations distributed with each technical assistance request for labor rate tasking categories applicable to the technical assistance task cost line items. In addition, the technical proposal shall specify cost estimates for the entire period of performance to include the Generalist Labor category used for this effort. The Government shall provide the Contractor 48 hour notification of the end of the technical assistance need and shall not incur cost beyond the end date regardless of the estimated performance period.
1.8 Period of Performance: The period of performance consists of one (1) 12-month base period and four (4) 12-month option periods.
· Base Period
· Ordering Period I
· Ordering Period II
· Ordering Period III
· Ordering Period IV
1.9 Quality Control: In compliance with the inspection/acceptance requirements of FAR Clause 52.212-4, the contractor must provide a quality control plan (QCP) to ensure services are performed in accordance with this PWS to the Contracting Officer for acceptance within 30 days after contract award in electronic format. The Contracting Officer will notify the contractor of acceptance or required modifications to the QCP within seven (7) business days of receipt. The contractor must make appropriate modifications and obtain acceptance of the QCP by the Contracting Officer before contract performance can begin.
The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with Performance Requirements Summary (PRS). The description must include specifics as the areas to be inspected on both a scheduled and unscheduled basis, frequency of inspections, and the title and organizational placement of the quality control inspections. At a minimum, the QCP must provide:
· A description of the records to be kept to document quality control inspections and corrective or preventive actions taken.
· A description of the methods to be used for identifying and preventing defects in the quality of service performed.
· When changes are made to the QCP, a complete QCP must be submitted to the CO and COR within 5 working days.
1.10 Quality Assurance: The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
Performance under this contract will be subject to the requirements of FAR 42.15 (Contractor Performance Information) and registration in the Contractor Performance Assessment Reporting System (CPARS) and Past Performance Information Retrieval System (PPIRS) metric tools.
1.11 Type of Contract: The government will award a hybrid – Firm Fixed Price and Cost Reimbursable (FFP/CR)
1.12 Phase In: The contractor shall be fully capable of fulfilling all the contract’s terms and conditions not later than 90 days following contract award. The Contractor shall be responsible for maintaining continuity of operations that will meet all FEMA’s requirements during normal operations and disaster events. Contractor shall provide landlines, cell phones, smart phones, external data connections, T-1 lines, licensing costs, servers, routers, firewalls, data storage, maintenance, (etc. as approved by FEMA). The Contractor shall have contingencies in place to be able to perform inspections of residences via electronic means at the damaged residence. The Contractor shall use Government Furnished Equipment and/or Contractor Acquired Property (includes CAP software) in addition to Government Furnished data plans and software. The Contractor shall provide mobile communication systems such as Broadband Access Cards or other mobile communication devices to include optional methods of communicating data from the field to FEMA if broadband systems are not available. The Contractor shall execute all phase-in activities in accordance with its proposed technical approach.
1.13 Phase Out Period: Continuity of the services required under this contract are vital to the Government. In accordance with FAR Clause 52.237-3 (Continuity of Services), upon notification from the Contracting Officer, the Contractor shall furnish phase-in, phase-out services for up to 90 days with a successor firm. The Contractor shall provide FEMA their approaches to transition workloads and transfer equipment from the incumbent Contractors. The Contracting Officer shall issue a written notice to the contractor to submit a plan six (6) months prior to the contract expiring. The required transition services will commence the day after the contract expires and last for 90 days. All Phase out activities shall be in accordance with the Contractors negotiated plan and training program’s technical approach.
1.14 Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend a post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5, no later than five (5) business days after the date of award. The purpose of the pre-performance conference, which will be chaired by the Program Manager, is to discuss technical and contracting objectives of this contract and review the Contractor's Quality Management System. Any required corrective actions will be due not later than ten (10) days following the pre- performance conference. The post award/pre-performance conference will be held at the Government’s facility or via teleconference.
The contracting officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the contracting officer will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues.
1.15 Contracting Officer Representative (COR) and Task Monitor (TM): The COR and Task Monitors will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration The COR is authorized to perform the following functions: performing surveillance/inspection and acceptance; monitor activities, cost, providing input to contractor performance evaluations, and notifications to the Contracting Officer; making recommendations for invoices and payments; managing Government Furnished Assets (when required); managing Contractor Employee Access (when required); and perform oversight of inherently Governmental and critical functions.
A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.
1.16 Key Contractor Personnel: The follow personnel are considered key personnel by the government: Contract Program Manager for this contract.
The Contractor shall provide a Program Manager who shall be responsible for all work performed under this contract. The Program Manager is further designated as Key by the Government. The Program Manager shall ensure all aspects of the contract and associated task orders are being adhered to and serve as the single point of contact for the CO and COR for all issues, including supervisory/management of contractor personnel, human resource management, performance management, and quality assurance/quality improvement management.
The name of this person and an alternate(s) who shall act for the contractor when the manager is absent shall be designated in writing to the contracting officer. Additionally, the Contractor shall not replace the Program Manager without prior approval from the CO. Any replacements to Key Personnel must be approved by the CO in writing 30 days in advance of any replacement. Any replacement must have equivalent or superior qualifications.
The project manager or alternate(s) must have full authority to act for the contractor on all contract matters relating to daily operation of this contract. During business hours of Monday through Friday 7 AM to 5 PM, the project manager or alternate(s) must be available to discuss problem areas within 30 minutes of FEMA’s request to meet and/or teleconference with Government personnel designated by the Contracting Officer. After business hours, weekends, and holidays; the manager or alternate(s) must be available within 60 minutes of FEMA’s request.
The project manager and alternate(s) must be able to read, write, speak, and understand English. The project manager and alternate(s) shall be designated as key personnel.
The Offeror shall provide Key Personnel resumes as part of the proposal.
1.17 Identification of Contractor Employees: The contractor shall provide qualified personnel to perform all requirements specified in this PWS. An employee background pre-check shall be conducted. Qualified personnel must have acceptable technical experience and education for their designated position. The contractor must not employ persons for work on this contract if considered by the Contracting Officer to be a potential threat to the health, safety, security, general well-being, or operational mission of FEMA or the population it serves.
Contractor employees visiting Government facilities shall wear a FEMA issued identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.
Contractor employees working on-site at Government facilities or at a disaster site shall wear a FEMA issued identification badge. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent (in meetings, when answering Government telephones, in e-mail messages, etc.) and display the Government issued badge in plain view above the waist at all times.
Contractor’s employees shall comply with Government and DHS policies when visiting or working at Government facilities. The contractor appointed Project Manager shall ensure contractor employees understand and abide by the aforementioned Government and DHS policies.
Contractor’s employees shall comply with all Center for Disease Control (CDC) guidelines and all active Executive Orders regarding the wearing of masks, maintaining physical distance, and other public health measures in place where they are on-duty. Refer to Technical Exhibit 24 Inspections during pandemic type events.
The Government may, at its sole discretion, via the Contracting Officer, direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons. Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.
1.18 Physical Security: The contractor must be responsible for safeguarding all Government property provided for contractor use. (Refer to Attachment 3.1 - Personal Property Manual) The contractor shall disclose the responsible party for physical security. At the end of each work period, all Government property, equipment and materials must be secured. (A site visit will be performed by FEMA post award before the end of the transition period. Any non-conformities found shall be remedied within 5 working days).
1.19 Place of Performance: The work to be performed under this contract may occur in the Continental United States and Outside Continental United States simultaneously. The work may include one or multiple County(s) within State(s), United States Territory(s), or Native American Reservation(s).
Alternate places of performance shall be coordinated with the Contracting Officer’s Representative (COR) and approved by the Contracting Officer (CO).
1.20 Personnel Security Requirements: All work performed under this PWS is unclassified. All personnel require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees receive a favorably adjudicated public trust suitability prior to entry on duty (EOD) and must maintain the level of security required for the life of the contract.
1.21 Background Investigations:
All Housing Inspection Services contractor staff will be issued a DHS HSPD12 PIV card with an expiration date no greater than two (2) years from date of issuance. The determination of the length of the PIV issuance is done through their ISMS account with their position and contract type. Every PIV has an expiration date printed on the upper right-hand corner for holders to confirm activation, and when close to expiring will need to contact their sponsor and if they are still eligible under an active position, they will go to a PCIF issuance station and get a replacement PIV. PIV badges shall be retrieved from the contract inspectors or any support personnel if no longer associated under or working under this contract. The badges shall be returned to FEMA.
All contractor personnel who require access to DHS or FEMA information systems, routine access to DHS or FEMA facilities, or access to sensitive information, including but not limited to Personally Identifiable Information (PII), shall be subject to a full background investigation commensurate with the level of the risk associated with the job function or work being performed. FEMA’s Personnel Security Division (PSD) will determine the risk designation for each contractor position by comparing the functions and duties of the position against those of a same or similar federal position, applying the same standard for evaluating the associated potential for impact on the integrity and efficiency of federal service. Contractor personnel shall meet the investigation level security requirements and be U.S. citizens.
Moderate Risk (minimum background for inspectors) Contractor personnel occupying positions or performing functions with a Moderate Risk designation shall undergo a Tier 2 Suitability Background Investigation (T2) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract High Risk Contractor personnel occupying positions or performing functions with a High Risk designation shall undergo a Tier 4 Background Investigation (T4) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
A favorably adjudicated BI will remain acceptable for the purpose of reciprocity where a T4 investigation is required for a period of 5 years from the date of completion and favorable adjudication provided that all other requirements for the application of reciprocity are met.
1.22 Contractor Background / Prescreening of potential Employees:
Government will provide security adjudication of all staff working on this contract. See Technical Exhibit TBD, Security Requirements and Procedures for specific details.
Contractors performing on this contract must be United States Citizens. Contractor applicants must also be 18 years of age or older to allow for the conduct of certain security related queries.
To initiate the request to process Contractor personnel, the Contractor shall provide the FEMA Contracting Officer’s Representative (COR) with all required information and comply with all necessary instructions to complete Section II of the DHS Form 11000-25, “Contract Fitness/Security Screening Request.” The FEMA COR shall ensure that all other applicable sections of the DHS Form 11000-25 are complete prior to submitting the form to FEMA PSD for processing. The Contractor shall also provide the FEMA COR with completed OF 306, “Declaration for Federal Employment,” forms for all Contractor personnel.
Prescreening:
FEMA will determine contractor personnel’s eligibility to perform work under this contract. The Contractor shall ensure that contractor personnel the Contractor proposes to perform work under this contract are United States citizens and have a personal background free from issues that may render them ineligible to perform work under this contract. The Contractor shall coordinate all required security documents and ensure they are complete and accurate before submitting to the FEMA COR or Field Security Division personnel. The following list identifies some common issues that can potentially render an individual ineligible to perform work under this contract. This list is not intended to be all-inclusive and does not represent the full scope of personal conduct and character evaluated in the personnel screening process. To improve the likelihood that FEMA will determine contractor personnel are eligible to perform work under this contract, the Contractor should screen out candidates whose background contains any of the following issues:
• Lack of U.S. Citizenship (lawful permanent residents are not U.S. citizens),
• Recent or multiple charges for driving under the influence (DUI) or similar charges,
• Conduct issues involving alcohol use,
• Involvement with illegal drugs,
• Pending criminal charge/open dispositions,
• Prior arrests,
• Currently on probation or parole,
• Currently subject to a domestic-violence or other court-ordered protection order,
• Registered sex offender or narcotic offender,
• Any delinquent Federal loans,
• Delinquent Federal or State taxes, including failure to file,
• Delinquent child support payments,
• Excessive or past due/delinquent personal debt,
• History of traffic violations.
A background, free of the listed issues, does not guarantee FEMA will find the contractor personnel eligible to perform work under this contract.
***NOTE: Those who do not pass DHS/FEMA’s adjudication process cannot serve as contractor’s supporting FEMA contracts. Contractor personnel are not paid to complete fingerprinting, background screening documents, e-QIP or any other requirements related to background investigations.*** Prior to submitting sponsorship forms to FEMA for candidates that do not have a FEMA approved background check, the offeror shall conduct a pre-screening of potential employees and other sub-contractor personnel that will work under this contract. As a result of this pre- check, any candidate for work under this contract shall be disqualified from submission to personnel security that reveals one or more of the disqualification criteria outlined on Technical Exhibit TBD – Security Requirements and Procedures. All sponsorship forms submitted to the FEMA COR shall include pre-screening certification of the sponsored candidate at the time of submission. A record of pre-screenings completed using the methods bulleted in Technical Exhibit #18A shall be retained by the contractor throughout the life of the contract and available at any time for review and audit by the FEMA COR. The contractor is not required to submit to FEMA the actual results of the pre-screening. Report of Pre-screening shall be included in the Inspector Availability Report as described in Section 4.6.9 titled Inspector Baseline Inspector Staffing Report.
Contractor personnel who already have a favorably adjudicated background investigation, may be eligible to perform work under this contract without further processing by FEMA PSD if:
· the investigation was completed within the last five years,
· it meets or exceeds the minimum requirement for the position they will occupy or functions they will perform on this contract,
· the Contractor personnel have not had a 2 year break in employment since the prior favorable adjudication, and
· FEMA PSD has verified the investigation and confirmed that no new derogatory information has been disclosed which may require a reinvestigation.
FEMA PSD will notify the COR of the names of the Contractor personnel eligible to work based on prior, favorable adjudication. The COR will, in turn, notify the Contractor of the names of the favorably adjudicated Contractor personnel, at which time the favorably adjudicated Contractor personnel will be eligible to begin work under this contract.
For those Contractor personnel who do not have an acceptable, prior, favorable adjudication or who otherwise require reinvestigation, FEMA PSD will issue an electronic notification via email to the Contractor personnel that contains the following documents, along with a link to the Office of Personnel Management’s Electronic Questionnaires for Investigation Processing (e-QIP) system and instructions for submitting the necessary information:
| • | Standard Form 85P, “Questionnaire for Public Trust Positions |
| • | Listing of FEMA Fingerprint Locations and/or SF 87, “Fingerprint Card” (2 copies) |
| • | DHS Form 11000-6, “Non-Disclosure Agreement” |
| • | DHS Form 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act” |
| • | OPM Optional Form 306 “Declaration for Federal Employment” |
FEMA PSD will only accept complete packages consisting of all of the above document and Standard Form 85P, which must be completed electronically through the Office of Personnel Management’s e-QIP system. The Contractor is responsible for ensuring that all Contractor personnel timely and properly submit all required background information. The Contractor is responsible for ensuring that all Contractor personnel complete the e-QIP process within 5 days.
Once Contractor personnel have properly submitted the complete package of all required background information, FEMA’s Personnel Security Division, at its sole discretion, may grant Contractor personnel temporary eligibility to perform work under this contract prior to completion of the full background investigation if the Personnel Security Division’s initial review of the Contractor personnel’s background information reveals no issues of concern. In such cases, FEMA’s Personnel Security Division will provide notice of such temporary eligibility to the COR who will then notify the Prime Contractor, at which time the identified Contractor personnel will be temporarily eligible to begin work under this contract. Neither the Prime Contractor nor the Contractor personnel has any right to such a grant of temporary eligibility. The grant of such temporary eligibility shall not be considered as assurance that the contactor personnel will remain eligible to perform work under this contract upon completion of and final adjudication of the full background investigation.
Upon favorable adjudication of the full background investigation, FEMA’s Personnel Security Division will update the Contractor personnel’s security file and notify the contractor of the final determination. In any instance where the final adjudication results in an unfavorable determination FEMA’s Personnel Security Division will notify the Contractor personnel directly, in writing, of the decision and will provide the COR with the name(s) of the Contractor personnel whose adjudication was unfavorable. The COR will then forward that information to the Contractor. Contractor personnel who receive an unfavorable adjudication shall be ineligible to perform work under this contract. Unfavorable adjudications are final and not subject to review or appeal.
1.23 Continued Eligibility and Reinvestigation
Eligibility determinations based on a NACI=T1, MBI=T2 and BI=T4 are valid for five years from the date that the investigation was completed and closed. Contractor personnel required to undergo a background investigation to perform work under this contract shall be ineligible to perform work under this contract upon the expiration the background investigation unless and until the Contractor personnel have undergone a reinvestigation and FEMA’s Personnel Security Division has renewed their eligibility to perform work under this contract.
Exclusion by Contracting Officer The Contracting Officer, independent of FEMA’s Personnel Security Division, may direct the Contractor to exclude from working on this contract any Contractor found or deemed to be unfit or whose continued employment on the contract is deemed contrary to the public interest or inconsistent with the best interest of the agency.
The Contractor is responsible for ensuring that each Contractor personnel is scheduled to be fingerprinted at one of the FEMA Fingerprint locations or by visiting a local law enforcement organization
1.24 Separation from Contract
The Contractor shall notify the FEMA COR of all terminations/resignations within five calendar days of occurrence. The Contractor must account for all forms of Government-provided identification issued to contractor employees under a contract (i.e., the PIV cards or other similar badges) must return such identification to FEMA as soon as any of the following occurs:
· When no longer needed for contract performance.
· Upon completion of a contractor employee’s employment.
· Upon contract completion or termination.
1.25 Information Sharing:
1.25.1 Access to Information: FEMA will provide the contractor access to portions of NEMIS and ACE systems for this contract. FEMA will share with the contractor limited PII applicant information and inspection status conditions outlined in Technical Exhibit TBD Data Elements. FEMA will not permit any PII data elements to be placed or stored on any contractor systems.
The information sharing outlined in this contract is covered in the following Privacy Impact Assessment(s): DHS/FEMA/PIA-049 Individual Assistance (IA) Program and DHS/ALL/PIA-059 DHS Employee Collaboration Tools.
1.25.2 Legal Authority & System of Record Notice
The information sharing outlined in this contract is authorized by the following System of Records Notice(s) (SORN) and Routine Use(s): DHS/FEMA-008 Disaster Recovery Assistance Files SORN 78 FR 25282 (April 30, 2013), Routine Use F. FEMA collects, maintains, uses, and disseminates personally identifiable information (PII) from its survivors/registrants in order to determine eligibility for IHP, as well as to direct and refer survivor/registrants to all possible sources of disaster assistance. Survivor/registrant PII is protected by the Privacy Act and Disaster Recovery Assistance Files SORN.
As authorized by the routine provision of the Privacy Act, 5 U.S.C. § 552a(b)(3), FEMA may disclose survivor/registrant PII to other federal agencies, and agencies of states, tribal, and local governments who have programs that make available any disaster assistance to individuals and households and/or give preference of priority to disaster applicants, pursuant to Routine Use F of the Disaster Recovery Assistance Files SORN.
1.25.3 Need to Know
The contractor will limit access to the PII provided by FEMA under this contract only to the contractor’s authorized personnel who need to know the information to accomplish the tasks outlined in this contract.
1.25.4 Prohibition on Computer Matching
The contractor shall ensure no computer matching, as that term is defined in 5 U.S.C. § 552a(a)(8), will occur for the purpose of establishing in or verifying eligibility or compliance as it relates to cash or in-kind assistance or payments under federal benefit programs.
1.25.5 Recipient Requirement
If at any time during the term of this contract any part of FEMA PII, in any form, that the contractor obtains from FEMA ceases to be required by the contractor for the performance of the contract, or upon the termination of the contract, whichever occurs first, the contractor shall, within fourteen (14) days thereafter, promptly notify FEMA and securely return PII to FEMA, or, at FEMA’s written request destroy, un-install and/or remove all copies of such PII in the contractor’s possession or control, and certify in writing to FEMA that such tasks have been completed.
1.25.6 Safeguarding of Sensitive Information
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause— “Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
| (1) | Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee); |
| (2) | Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee); |
| (3) | Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and |
| (4) | Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures. |
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
| (1) | Truncated SSN (such as last 4 digits) |
| (2) | Date of birth (month, day, and year) |
| (3) | Citizenship or immigration status |
| (4) | Ethnic or religious affiliation |
| (5) | Sexual orientation |
| (6) | Criminal History |
| (7) | Medical Information |
| (8) | System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) |
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
| (c) | Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to: |
| (1) | DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information |
| (2) | DHS Sensitive Systems Policy Directive 4300A |
| (3) | DHS 4300A Sensitive Systems Handbook and Attachments |
| (4) | DHS Security Authorization Process Guide |
| (5) | DHS Handbook for Safeguarding Sensitive Personally Identifiable Information |
| (6) | DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program |
| (7) | DHS Information Security Performance Plan (current fiscal year) |
| (8) | DHS Privacy Incident Handling Guidance |
| (9) | Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html |
| (10) | National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html |
| (11) | NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html |
| (d) | Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required. |
| (1) | Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program. |
| (2) | The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract. |
| (3) | All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form. |
| (4) | The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in |
these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
a. Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
i. Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
ii. Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .