SharePoint - SOW.doc
DOC document 251 KB Posted
- Attached to
- SharePoint Integration and Support Services Federal contract opportunity
- Solicitation number
- HSCETC-10-R-00015
- Issued by
- Immigration and Customs Enforcement
About this file
Draft SOW for the IDIQ contract.
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. Department of Homeland Security
Immigration and Customs Enforcement (ICE)
SharePoint Integration & Support
Statement of Work - IDIQ Office of the Chief Information Officer (OCIO)
801 I Street, NW
Washington, D.C. 20536
1.0
PROJECT TITLE
ICE SharePoint Integration and Support Services 2.0
BACKGROUND
ICE’s mission is to protect national security by enforcing our nation's customs and immigration laws. This responsibility includes such tasks as border security, targeting international street gangs, cyber crimes, intellectual property rights, and secure communities. In addition to the Chief Information Office and headquarters complement, ICE includes five operating divisions: Federal Protective Service, Intelligence, Investigations, International Affairs, and Detention and Removal Operations. To promote information sharing and business process automation throughout the agency, the ICE Collaboration Tool (ICECT) is under development for distribution to interested offices throughout ICE.
The Office of the Chief Information Officer (OCIO) is the organization responsible for information technology in ICE. OCIO is responsible for supporting business processes with the design, development, programming, testing, implementation, technical support and maintenance of ICE automated systems to include but not limited to the management of all ICE computer facilities and systems which also includes hardware, software, data, video, wireless and voice telecommunications and their related financial resources and applications. OCIO is responsible for identifying and evaluating new technologies for insertion into the current technical architecture in support of ICE business processes.
The Immigration and Customs Enforcement (ICE) is dependent upon information technology to fulfil its mission. The dynamic growth in workload and staffing has resulted in the expanded use of information technology by ICE users. As enhanced performance requirements are identified by the agency to address business process automation within the various programs the need to provide specific, improved, faster and more robust functionality, responsiveness and availability for ICE production applications.
An essential and fundamental tool in addressing many of the above requirements is the enhancement of the ICE Collaboration Tool (ICECT). This state of the art application environment provides a highly integrated set of enterprise class tools capable of providing business automation, custom workflow, document and information sharing and powerful customization capabilities. Without this modern capability, ICE cannot efficiently fulfil its mission. Consequently, ICE seeks to continue to enhance, expand, and upgrade the ICECT in order to ensure this environment continues to address the agency’s needs now and in the future.
3.0 SCOPE
The scope of this contract is to provide the Government all necessary management, supervision, materials, services, support, maintenance, identification, and performance resources for the ICECT environment operational and maintenance activities. The Contractor shall support existing and prospective ICECT sites as the agency expands the ICECT operational model to include additional ICE programs as required. The tasks under this contract include supporting validation and measurement of system integration in the areas of collaboration, security, connected systems, operational efficiency and deployments, installation, testing, documentation, problem resolution and maintenance of the ICECT production and other related environments.
The Contractor shall be able to perform and support all aspects associated with Microsoft Office SharePoint Server 2007 including administration, operations, development, troubleshooting, design and implementation of these environmental solutions. This work shall be performed in accordance and consistent with the objectives of this contract and SOW. The contractor shall be knowledgeable of records management 5015.2 Specification, historic preservation regulations, and the ICE System Lifecycle Methodology. The Contractor shall provide developer and support expertise to develop, implement and maintain solutions and transfer knowledge to the Government; Support validation and measurement of system integration in the areas of collaboration, security, connected systems, operational efficiency and deployments. The Contractor shall provide technical and programmatic support on major task area projects, including planning and budgeting; defining the technology architecture; establish project requirements, priorities and deadlines; coordinate resources across projects; analyze, cost, schedule and technical performance; and develop integrated project schedules across multiple teams working on development activities. The Contractor shall stay abreast of emerging technologies and shall provide the technical expertise and support identifying, coordinating and implementing new technologies into the ICE environment.
The Contractor shall work around the government’s schedule to minimize disruptions. The Contractor shall handle all aspects of system design and development, installation and conduct performance testing to assure that connections meet specifications. This is a centralized approach for addressing the ICECT environment operational needs for the ICECT environment at a reasonable cost.
ICE requires an Indefinite Delivery – Indefinite Quantity (IDIQ) contract that will allow the Systems Development Division flexibility to accomplish its mission in a constantly moving environment. This contract is a hybrid comprised of Firm Fixed Price, Cost Reimbursement, and Cost-Plus Fixed Fee CLINs.
4.0 APPLICABLE DOCUMENTS
The Contractor shall comply with all technology standards and architecture policies, processes, and procedures defined in ICE OCIO Architecture Division publications. These publications include, but are not limited to, the following:
· ICE System Lifecycle Management (SLM) Handbook
· ICE Enterprise Systems Assurance Plan
· ICE Architecture Test and Evaluation Plan
· ICE Web Standards and Guidelines
· ICE Technical Reference Model and Standards Profile
The Contractor shall not deviate from the SLM Process (including any tailored SLM work pattern) without express approval granted by the Government via the formal Request for Deviation (RFD) Process. If a deviation from the SLM Process is desired, the Program Manager must submit a formal RFD to the Architecture Division for adjudication. The Contractor shall not proceed with the deviation unless the Architecture Division approves the formal request and grants a waiver to deviate from the SLM Process. If the Architecture Division approves the RFD, the Contractor shall comply with all stipulations specified within the approval notification.
DHS HLS EA Compliance
All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures as it relates to this Statement of Work and associated Task Order. Specifically, the contractor shall comply with the following Homeland Security Enterprise Architecture (HLS EA) requirements:
· All developed solutions and requirements shall be compliant with the HLS EA.
· All IT hardware or software shall be compliant with the HLS EA Technology Reference Model (TRM) Standards and Products Profile.
· All data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the DHS Enterprise Data Management Office (EDMO) for review and insertion into the DHS Data Reference Model.
· The Contractor shall utilize a SharePoint (SP) development environment consisting of hardware and software products compliant with HLS EA standards. If the Contractor SP development environment will not consist of hardware and software products found in the DHS Technology Reference Model (TRM), a TIP must be compiled and submitted for EA approval to the DHS EACOE (Enterprise Architecture Center of Excellence). The TIP consists of a number of technical documents necessary to obtain EA approval for the software and/or hardware that is not currently listed on the DHS TRM. The TIP must be submitted and approved PRIOR to purchase of the Contractor SP development environment’s hardware and software products.
5.0 SPECIFIC TASKS
The anticipated Contract Line Item Numbering (CLIN) structure is:
| Tasks |
| Task Type |
| Program Management |
| Firm Fixed Price |
| Program Consulting Support |
| Cost Plus Fixed Fee |
| Special Projects (Optional) |
| Firm Fixed Price |
| Other Direct Costs (i.e. travel, equipment/software, misc.) |
| Cost Reimbursable |
The Contractor shall provide the required expertise to implement solutions and transfer knowledge to the Government and support validation and measurement of system integration in the areas of collaboration, security, connected systems, operational efficiency and deployments.
The Contractor shall define the technology architecture and ensure that the following processes are integrated: ICE Systems Lifecycle Management (SLM), Information Systems Security, Certification and Accreditation (C&A), and Capital Planning and Investment Control (CPIC). The Contractor shall collaborate with DHS efforts as directed to represent the ICE Program Office.
The Contractor shall provide site administration and site configuration support for agency program collaboration sites and sub-sites as necessary.
The Contractor shall provide technical and programmatic support on major task area projects from initiation through implementation, including planning, budgeting, development, implementation, and operations and maintenance. Under the direction of the ICE Task Manager and other Government Subject Matter Experts (SMEs), the Contractor shall establish project requirements; priorities and deadlines; and coordinate resources across projects.
The Contractor shall prepare and present white papers and progress reports for management using project management applications to analyze costs, schedules, and technical performance of the work.
The Contractor shall coordinate among the task leaders, project managers, and Government organizations to develop integrated project schedules across multiple teams working on engineering activities.
The Contractor shall stay abreast of emerging technologies and shall provide the technical expertise and support identifying, coordinating and implementing new technologies into the ICECT environment.
The ICECT Contingency Plan will be reviewed and tested on an annual basis, as required by DHS of all IT systems. Testing is done through coordination with the appropriate contractor security testing personnel. Once fully deployed, the ICECT Contingency Plan will be tested and validated, and results will be uploaded into Trusted Agent FISMA (TAF).
DHS/ICE requires that all IT Contingency Plans be exercised annually. Backup and restoration procedures, as well as other routine contingency-related matters, are part of the annual test exercise.
Contract performance shall be coordinated by ICE’s Office of the Chief Information Officer (OCIO), Systems Development Division, Administrative Systems Branch.
6.0 DELIVERABLES AND DELIVERY SCHEDULE
Deliverables and Delivery Schedule
The deliverables identified below are the minimum required deliverables, and additional deliverables may be required by individual task order. The Contractor shall provide deliverables associated with the work project, assignments, and activities by electronic delivery to the COTR’s e-mail address using Microsoft Office file formats.
Deliverable Number 1: Task Area Weekly/Monthly Report
The Contractor shall provide separate weekly and cumulative monthly status reports for each Subtask listed in the Statement of Work. The status report shall include accomplishments, status of ongoing activities, management issues, recommendations for problem resolution, and upcoming activities. The status report shall identify any completed travel and projects and provide planned travel and resources required for the next 30 days (see Deliverable Matrix).
The Contractor shall provide the Progress Reports to the ICE Task Manager and COTR and the reports shall include but is not limited to significant accomplishments and/or issues. Progress Reports shall include, at a minimum, the following topics in the order indicated, with a detailed explanation of issues:
· Title of project
· Associated CLINs
· Date Assigned
· Projected Completion Date
· Assigned by
· Reporting period
· Progress of project during the reporting period
· Identification of significant accomplishments or issues noted
· Planned solutions of issues, including risks to cost, schedule or performance elements of the task order
· Schedule - percent or degree completed by task to date, critical path analysis, ability to meet contract schedule, reasons for slippage, and path to recovery
· Cost - analysis of actual costs incurred in relation to budget and progress to date, burn rates, and cost estimate to complete project within budget.
· Other items as required (e.g., trip reports, meeting minutes, etc.).
Deliverable Number 2: Quarterly GFP Inventory Reports The Contractor shall provide the inventory listing to the COTR in electronic format. This listing shall also include all ODC pending and/or committed. The format shall be Microsoft Excel compatible (see deliverable matrix).
The Contractor shall maintain the asset management systems by the ICE Task Manager in compliance with the 98% accuracy rate set forth by ICE. The Contractor shall provide weekly inventory reports to the ICE Task Manager. The Contractor shall provide written notification within 24 hours to the ICE Task Manager and COTR on any and all issues/concerns regarding inventory control.
Deliverable Number 3: Monthly ODC Listing
The Contactor shall provide the COTR a monthly ODC listing of all the ODCs for the month. This shall included but is not limited to the task area, work number, cost and work status. The listing shall be provided to the COTR in electronic format on the close of business (COB) of the second Monday of each Month. The format must be Microsoft Excel compatible (see deliverable matrix).
Deliverable Number 4: Quality Control Plan (QCP)
The Contractor shall provide a QCP for this Task Area. The QCP shall provide details of how the contractor intends to perform quality control checks, the process for tracking issues, communication strategy, and the quality control measures for all areas and responsibilities of this Task Area to include but not limited to all deliverables, all CLINs and work activities, assignments, and projects. The Contractor shall be prepared to address COTR concerns and requirements as well to include the QCP Report schedule and due date.
The Contractor shall provide the draft QCP to the COTR within 15 working days of award for the Government to review. When the COTR provides the comments back to the Contractor the Contractor shall incorporate the comments and provide the final QCP to the COTR and CO within 10 working days.
Deliverable Number 5: Monthly QCP Report
The Contractor shall provide the COTR a copy of the monthly QCP in electronic format. The format shall be Microsoft Excel compatible.
Deliverable Number 6: Security Report
The Contractor shall provide the COTR the security report as required by the COTR.
Deliverable Number 7: Employee Listing
The Contractor shall provide a monthly listing of all contractor staff to include Subcontractors. This report shall also include the hours used versus hours projected by CLIN, position, and employee, or as required by the COTR. The listing is due to the COTR by the seventh working day of the month. The schedule shall be included in the QCP. This listing shall include but not limited to the following fields:
Last Name
First Name and Middle Initial
Position
Position ID number Task Area
Employment Status (Active, Terminated, Pending EOD, Released)
Status Date
Risk Level
Security Status (EOD, Terminated, Pending EOD, Released)
Work Location
Deliverable Number 8: Ad Hoc Reports
The Contractor shall provide, develop, maintain, update, store, and distribute ad-hoc reports as requested by the ICE Task Manager. Examples include: Design Reviews; User Acceptance Testing (UAT) Analysis Summary Reports; Technical Reference Model (TRM); SLM Technical Review Summaries; SLM Letters to the File; Document Assessment reports; Standards Profile; Standards Documentation; simulation and modelling analyses; technology patterns; configuration management operating procedures; and any deliverables associated with requirements management or domain planning. (See deliverable matrix)
Deliverable Number 9: Transition Plan
The Contractor shall be responsible for the transition of all technical activities by CLINs. The Contractor shall complete the technical transition within 60 days of being formally notified or effective date. The technical activities, which shall be included as part of the technical transition, consist of but are not limited to the transition plans for:
· Inventory and orderly transfer of all Government Furnished Equipment/Property (GFE/GFP), software and licenses.
· Transfer of documentation currently in process with Task Order award.
· Transfer of all Software coding in process with the Task Order award.
· Establishment of a facility for housing hardware, if any.
· Coordinating the body of work with the current Contractor and turnover of tasking, staffing, etc.
The Contractor’s transition plan shall be approved by the Government Task Manager and shall contain a milestone schedule of events and system turnovers. The plan shall address transitioning systems with no disruption in operational services. The Contractor shall provide the transition plan within 7 working days of being formally notified or effective date of the Task Order. To ensure the necessary continuity of services and to maintain the current level of support, the OCIO ICE will retain services of the incumbent Contractor for the transition period, if required, to fully support the transition of CLIN requirements to the successor vendor by providing personnel and documentation required to facilitate a successful transition.
Deliverable Number 10: Technology Insertion Package (TIP) The Contractor shall utilize a Microsoft Office SharePoint Server (SP) development environment consisting of hardware and software products compliant with HLS EA standards. If the Contractor SP development environment will not consist of hardware and software products found in the DHS Technology Reference Model (TRM), a TIP must be compiled and submitted for EA approval to the DHS EACOE (Enterprise Architecture Center of Excellence). The TIP consists of a number of technical documents necessary to obtain EA approval for the software and/or hardware that is not currently listed on the DHS TRM. The TIP must be submitted and approved PRIOR to purchase of the Contractor SP development environment’s hardware and software products.
Deliverable Number 11: Information Technology Security Plan A Draft IT Security Plan is due with the Contractor’s proposal. The final IT Security Plan shall be submitted 30 days after contract award.
DELIVERABLE MATRIX
| DEL. # |
| FREQ |
| DATE OF SUBMISSION |
| COPIES |
| ICE DISTRIBUTION |
| Task Area Weekly/Monthly Report |
| 1 |
| Monthly |
| 15th of the following month |
| 3 (electronic) |
| COTR |
Task Manager
CO
| Quarterly GFP Inventory Reports |
| 2 |
| Quarterly |
| 15th working day of the quarter (i.e., January, April, July, and October) |
| 2 (electronic) |
| COTR |
Task Manager
| Monthly ODC Listing |
| 3 |
| Monthly |
| COB of the second Monday of each Month |
| 1 (electronic) |
| COTR |
| Quality Control Plan |
| 4 |
| With Proposal |
| With each Task Order Proposal |
| 1 |
| CO |
| Monthly QCP Report |
| 5 |
| As needed |
| Monthly |
| 2 |
(electronic)
TM
COTR
Security
Report
| 6 |
| weekly |
| COB every 3rd Wednesday |
| 2 |
| TM |
COTR
| Employee Listing |
| 7 |
| Monthly |
| Monthly |
| 2 |
| CO |
COTR
| Ad Hoc Reports |
| 8 |
| As Requested |
| When Requested |
| 1(electronic) |
| COTR |
| Transition Plan |
| 9 |
| With proposal |
| With Proposal |
| 1(electronic) |
| CO |
| Technology Insertion Package |
| 10 |
| As needed |
| When requested |
| 3(electronic) |
| Task Manager |
COTR
DHS EACOE
| IT Security Plan |
| 11 |
| With Proposal |
| A Draft IT Security Plan is due with the Contractor’s proposal. The final IT Security Plan shall be submitted 30 days after contract award. |
| 3(electronic) |
| Task Manager |
COTR
ICE Information Assurance Division
Additional deliverables may be established for specific task orders based on specific requirements.
Acceptance Criteria
ICE will accept or reject deliverables. If rejected, the Contractor shall make corrections as specified and resubmit the deliverable for review and approval. All deliverables are subject to the ICE Government Task Manager’s review and approval. The Contractor must obtain the Government’s Task Manager sign-off approval accepting the work. If a deliverable is rejected, the Contractor will have to make corrections as specified by the Government Task Manager and resubmit the deliverable for review and approval to the COTR and Government Task Manager. The Contractor shall also inform the COTR in writing within five (5) days of the rejection and shall identify what measures that have been put into place to reduce future rejection of deliverables.
Invoicing The Contractor shall submit an invoice for each Subtask separately billed, 10 working days after the close of the previous month to include: Contractor name, labor categories, labor costs, completed travel, overtime, and any Other Direct Costs (ODCs) for the invoice period.
The invoice shall list the total number of hours worked by each Contractor employee by CLIN/SLIN. Any extended work hours must be listed separately for each Contractor employee with the dates and specific hours worked. Signed authorization by the Government Task Manager and the COTR must be attached to the invoice. The invoice shall include all costs incurred by the contractor on behalf of the Government, regardless of whether or not those costs have been invoiced by the contractor, any subcontractor, or vendor. Incurred cost reporting shall be estimated for the current month, and the current month’s incurred cost shall be accumulated for the contract year period. The contractor shall also provide projected total incurred costs for the remainder of the contract period of performance based on historical burn rate.
Subcontractor costs shall separately identified, specifying actual dates and hours worked, along with actual costs incurred.
All travel must be approved in advance and the Contractor employees shall include reference to the approved travel authorization form (Attachment 1), and all travel related receipts (such as transportation, hotel, rental car, and other incidentals for each trip) with the invoicing spreadsheet.
The Other Direct Costs (ODCs) must be approved in advance by the Task Manager for each period of performance; the Contractor shall reference the ODC (Attachment 1) tracking number on the invoicing spreadsheet. Should the Contractor employee perform activities for another DHS entity, the Contractor employee must note the number of hours, the date worked, and the name of the DHS entity. Signed ODC authorization by the Government Task Manager and the COTR must be attached to the invoice.
An authorized Contractor official shall certify that the invoice is current, accurate and complete to the best of the official’s knowledge.
7.0 GOVERNMENT-FURNISHED EQUIPMENT
No Government Furnished Equipment or Information is anticipated with the initial award. Individual task orders shall specify any equipment of information to be furnished by the Government. The Contractor shall keep an accurate inventory of Government-furnished equipment. All information developed by the Contractor under this Task shall be the property of the Federal Government and provided to ICE upon request and at the end of the period of performance.
8.0 PLACE OF PERFORMANCE
Work for each task order under this contract will be performed primarily at Contractor’s facilities. Frequent travel to DHS offices in the Washington, DC metropolitan area for meetings and briefings will be required. It is preferred that the Contractor’s operating facility should be within the Washington, DC metropolitan area for travel time to the DHS, ICE OCIO Office located at 801 I Street NW, Washington DC. Occasional travel to sites outside of the Washington, DC area is required in conjunction with the performance of contract project requirements.
9.0 PERIOD OF PERFORMANCE
The period of performance shall be a One-Year Base Period with (4) one-year options.
| Year |
| Period of Performance |
| Base Year |
| April 15 2010 – March 14 2011 |
| Option Year 1 |
| April 15 2011 – March 14 2012 |
| Option Year 2 |
| April 15 2012 – March 14 2013 |
| Option Year 3 |
| April 15 2013 – March 14 2014 |
| Option Year 4 |
| April 15 2014 – March 14 2015 |
10.0 ACCESSIBILITY REQUIREMENTS
Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology, they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.
All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable standards have been identified:
36 CFR 1194.21 – Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.
36 CFR 1194.22 – Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous JavaScript and XML (AJAX) then “1194.21 Software” standards also apply to fulfill functional performance criteria.
36 CFR 1194.24 – Video and Multimedia Products, applies to all video and multimedia products that are procured or developed under this work statement. Any video or multimedia presentation shall also comply with the software standards (1194.21) when the presentation is through the use of a Web or Software application interface having user controls available. This standard applies to any training videos provided under this work statement.
36 CFR 1194.31 – Functional Performance Criteria applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.
36 CFR 1194.41 – Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required “1194.31 Functional Performance Criteria”, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.
Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COTR and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply:
36 CFR 1194.2(b) – (COTS/GOTS products). When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meets some but not all of the standards, the agency must procure the product that best meets the standards.
When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires approval from the DHS Office on Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.
The Contractor shall perform and complete miscellaneous tasks, projects, or activities identified and assigned by the COTR or designee that are not specifically addressed by the above descriptions and line items but are associated with the Task Area functions duties and responsibilities.
36 CFR 1194.3(b) – Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.
10.1 IT SECURITY REQUIREMENTS
General Clause
To ensure the security of the DHS/ICE information in their charge, ICE contractors and sub-contractors must adhere to the same computer security rules and regulations as government employees unless an exception to policy is agreed to by the prime contractors, ICE ISSM and Contracting Officer and detailed in the contract. Non-DHS Federal employees or contractors who fail to comply with DHS/ICE security policies are subject to having their access to DHS/ICE IT systems and facilities terminated, whether or not the failure results in criminal prosecution. The DHS Rules of Behavior document applies to DHS/ICE support contractors and Sub-contractors.
Federal Desktop Core Configuration (FDCC)
The Contractor shall certify that applications are fully functional and operate correctly as intended on systems using the FDCC. This includes Internet Explorer 7 configured to operate on Windows XP, Vista, and Windows 7. The standard installations, operation, maintenance, update, and/or patching of software shall not alter the configuration settings from the approved FDCC. The information technology should also use the Windows Installer Service for installation to the default “program files” directory and should be able to silently install and uninstall.
Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
Access to Unclassified Facilities, Information Technology Resources, and Sensitive Information
The assurance of the security of unclassified facilities, Information Technology (IT) resources, and sensitive information during the acquisition process and contract performance are essential to the DHS mission. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive But Unclassified (For Official Use Only) Information, describes how contractors must handle sensitive but unclassified information. DHS MD 4300.1 Information Technology Systems Security and the DHS Sensitive Systems Handbook prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering contractors specifically for all Task Orders that require access to DHS facilities, IT resources or sensitive information. Contractors shall not use or redistribute any DHS information processed, stored, or transmitted by the contractor except as specified in the task order.
Interconnection Security Agreements
Interconnections between DHS and non-DHS IT systems shall be established only through controlled interfaces and via approved service providers. The controlled interfaces shall be accredited at the highest security level of information on the network. Connections with other Federal agencies shall be documented based on interagency agreements; memoranda of understanding, service level agreements or interconnect service agreements.
Security Policy References Clause
The following primary DHS/ICE IT Security documents are applicable to contractor/subcontractor operations supporting Sensitive But Unclassified (SBU) based contracts. Additionally, ICE and its contractors must conform to other DHS Management Directives (MD) (Note: these additional MD documents appear on DHS-Online in the Management Directives Section. Volume 11000 “Security and Volume 4000 “IT Systems” are of particular importance in the support of computer security practices). All services, hardware, and software provided under this task order must be compliant with DHS Information Security Policy, identified in MD4300.1, Information Technology Systems Security Program and 4300A Sensitive Systems Handbook.
· DHS 4300A, Sensitive Systems Policy Directive
· DHS 4300A, IT Security Sensitive Systems Handbook
· ICE Directive, IT Security Policy for SBU Systems
· DHS Information Technology Systems Security Policy, MD4300.1 SECURITY REQUIREMENTS FOR UNCLASSIFIED INFORMATION TECHNOLOGY RESOURCES (JUN 2006)
(a) The Contractor shall be responsible for Information Technology (IT) security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency's mission.
(b) The Contractor shall provide, implement, and maintain an IT Security Plan. This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.
(1) Within 30 days after contract award, the contractor shall submit for approval its final IT Security Plan, which shall be consistent with and further detail the approach contained in the offeror's proposal. The plan, as approved by the Contracting Officer, shall be incorporated into the contract as a compliance document.
(2) The Contractor's IT Security Plan shall comply with Federal laws that include, but are not limited to, the Computer Security Act of 1987 (40 U.S.C. 1441 et seq.); the Government Information Security Reform Act of 2000; and the Federal Information Security Management Act of 2002; and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130.
(3) The security plan shall specifically include instructions regarding handling and protecting sensitive information at the Contractor's site (including any information stored, processed, or transmitted using the Contractor's computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.
(c) Examples of tasks that require security provisions include--
(1) Acquisition, transmission or analysis of data owned by DHS with significant replacement cost should the contractor's copy be corrupted; and
(2) Access to DHS networks or computers at a level beyond that granted the general public (e.g., such as bypassing a firewall).
(d) At the expiration of the contract, the contractor shall return all sensitive DHS information and IT resources provided to the contractor during the contract, and certify that all non-public DHS information has been purged from any contractor-owned system. Components shall conduct reviews to ensure that the security requirements in the contract are implemented and enforced.
(e) Within 6 months after contract award, the contractor shall submit written proof of IT Security accreditation to DHS for approval by the DHS Contracting Officer. Accreditation will proceed according to the criteria of the DHS Sensitive System Policy Publication, 4300A (Version 5.5, September 30, 2007) or any replacement publication, which the Contracting Officer will provide upon request. This accreditation will include a final security plan, risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan. This accreditation, when accepted by the Contracting Officer, shall be incorporated into the contract as a compliance document. The contractor shall comply with the approved accreditation documentation.
In addition to documentation required for certification and accreditation, the Contractor shall ensure that all items outlined in Sections 5.1-5.3 are developed and implemented in accordance to the requirements and guidance documents stated in Section 4.2, as applicable.
(f) Encryption. The Contractor shall ensure that all encryption is FIPS 140-2 and FIPS 197 Advanced Encryption Standard (AES) 256 compliant
10.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
ICE has determined that performance of this Task Order requires that the Contractor, subcontractor(s), vendors(s), etc. have access to sensitive ICE information, Polygraph Top Secret or Sensitive Secret Clearance TS SCI information and that the Contractor shall adhere to the following requirements.
a. Suitability Determination
ICE shall have and exercise full control over granting, denying, withholding or terminating unescorted government facility and/or sensitive Government information access for Contractor employees, based upon the results of a background investigation. ICE may, as it deems appropriate, authorize and make a favourable entry on duty (EOD) decision based on preliminary security checks. The favourable EOD decision would allow the employees to commence work temporarily prior to the completion of the full investigation. The granting of a favourable EOD decision shall not be considered as assurance that a full employment suitability authorization will follow as a result thereof. The granting of a favourable EOD decision or a full employment suitability determination shall in no way prevent, preclude, or bar the withdrawal or termination of any such access by ICE, at any time during the term of the purchase order. No employee of the Contractor shall be allowed unescorted access to a Government facility without a favourable EOD decision or suitability determination by the Security Office. Contract employees assigned to the contract not needing access to sensitive ICE information or recurring access to ICE facilities will not be subject to security suitability screening.
b. Background Investigations
Contract employees (to include applicants, temporaries, part-time and replacement employees) under this contract, needing access to sensitive information, shall undergo a position sensitivity analysis based on the duties each individual will perform on the purchase order. The results of the position sensitivity analysis shall identify the appropriate results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. All background investigations will be processed through the Security Office. Prospective Contractor employees shall submit the following completed forms to the Security Office through the COTR no less than thirty (30) days before the starting date of the contract or thirty (30) days prior to entry on duty of any employees, whether a replacement, addition, subcontractor employee, or vendor:
(i) Standard Form 85P, “Questionnaire for Public Trust Positions”
(ii) FD Form 258, “Fingerprint Card” (2 copies)
(iii) Foreign National Relatives or Associates Statement
(iv) Form DOJ-555, “Disclosure and Authorization Pertaining to Consumer Reports pursuant to the Fair Credit Reporting Act.
ICE will provide required forms, at the time of award of the contract. The Security Office will accept only completed packages. Specific instructions on submission of packages will be provided upon award of the contract.
Be advised that unless an applicant requiring access to sensitive information has resided in the US for three of the past five years, the Government may not be able to complete a satisfactory background investigation. In such cases, ICE retains the right to deem an applicant as ineligible due to insufficient background information.
In the interest of limiting access to potentially sensitive information and systems, ICE will consider only US Citizens and Legal Permanent Residents for employment on this contract.
c. Continued Eligibility
If a prospective employee is found to be ineligible for access to Government facilities or information, the COTR will advise the Contractor that the employee shall not continue to work or to be assigned to work under this contract.
The Security Office may require drug screening for probable cause at any time and/or when the Contractor independently identifies circumstances where probable cause exists.
ICE reserves the right and prerogative to deny and/or restrict the facility and information access of any Contractor employee whose actions are in conflict with the Department of Justice (DOJ) standards of conduct, 5 CFR 2635 and 5 CFR 3801, or whom ICE determines to present a risk of compromising sensitive Government information to which he or she would have access under this purchase order.
The Contractor shall report any adverse information coming to their attention concerning contract employees under this purchase order to the ICE Security Office. Reports based on rumor or innuendo should not be made. The subsequent termination of employment of an employee does not obviate the requirement to submit this report. The report shall include the employees’ name and social security number, along with the adverse information being reported.
The Security Office must be notified of all terminations/resignations within five (5) days of occurrence. The Contractor shall return any expired ICE issued identification cards and building passes, or those of terminated employees to the COTR. If an identification card or building pass is not available to be returned, a report must be submitted to the COTR, referencing the pass or card number, name of individuals to whom issued, the last known location and disposition of the pass or card.
d. Employment Eligibility
The Contractor must agree that each employee working on this purchase order will have a Social Security Card issued and approved by the Social Security Administration. The Contractor shall be responsible to the Government for acts and omissions of his own employees and for any Subcontractor(s) and their employees. Subject to existing law, regulations and/or other provisions of this purchase order, illegal or undocumented aliens will not be employed by the Contractor, or with this purchase order. The Contractor shall ensure that this provision is expressly incorporated into any and all Subcontracts or subordinate agreements issued in support of this purchase order.
e. Security Management
The Contractor shall appoint a senior official to act as the Corporate Security Officer. The individual shall interface with the Security Office through the COTR on all security matters, to include physical, personnel, and protection of all Government information and data accessed by the Contractor.
The COTR and the Security Office shall have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements of this purchase order. Should the COTR determine that the Contractor is not complying with the security requirements of this contract; the Contractor shall be informed in writing by the Contracting Officer (CO) of the proper action to be taken in order to effect compliance with such requirements.
f. TAIS Clearance
When sensitive Government information is processed on Telecommunications and Automated Information Systems (TAIS), the Contractor agrees to provide for the administrative control of sensitive data being processed and to adhere to the procedures governing such data as outlined in DOJ Order 2640.2C, TAIS Security.
g. Personal Service
ICE has determined the requirements as outlined in this SOW are in the best interest of the Government, economic and other factors considered, and is not being used to procure personal services prohibited by the Federal Acquisition Regulation (FAR) Part 37.104 entitled “Personal Services Contract.”
10.3 USE OF GOVERNMENT EQUIPMENT
Contractors are not authorized to use government office equipment of IT systems/computers for personal use under any circumstances, unless limited personal use is specifically permitted by the contract. When so authorized, contractors shall be governed by the limited personal use policies in the referenced documents.
(a) Sensitive Information, as used in this Chapter, means any information, the loss, misuse, disclosure, or unauthorized access to or modification of which could adversely affect the national or homeland security interest, or the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal
Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
(b) “Information Technology Resources” include, but are not limited to, computer equipment, networking equipment, telecommunications equipment, cabling, network drives, computer drives, network software, computer software, software programs, intranet sites, and internet sites.
(c) Contractor employees working on this contract must complete such forms as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability. Completed forms shall be submitted as directed by the Contracting Officer. Upon the Contracting Officer's request, the Contractor's employees shall be fingerprinted, or subject to other investigations as required. All contractor employees requiring recurring access to Government facilities or access to sensitive information or IT resources are required to have a favourably adjudicated background investigation prior to commencing work on this contract unless this requirement is waived under Departmental procedures.
(d) The Contracting Officer may require the contractor to prohibit individuals from working on the contract if the government deems their initial or continued employment contrary to the public interest for any reason, including, but not limited to, carelessness, insubordination, incompetence, or security concerns.
(e) Work under this contract may involve access to sensitive information. Therefore, the Contractor shall not disclose, orally or in writing, any sensitive information to any person unless authorized in writing by the Contracting Officer. For those contractor employees authorized access to sensitive information, the contractor shall ensure that these persons receive training concerning the protection and disclosure of sensitive information both during and after contract performance.
(f) The Contractor shall include the substance of this clause in all subcontracts at any tier where the subcontractor may have access to Government facilities, sensitive information, or resources.
When the contract will require contractor employees to have access to Information Technology (IT) resources, add the following paragraphs:
(g) Before receiving access to IT resources under this contract the individual must receive a security briefing, which the Contracting Officer’s Technical Representative (COTR) will arrange, and complete any nondisclosure agreement furnished by DHS.
(h) The…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .