DRAFT_Operations_ _Maintenance_RFP_4-2016.pdf
PDF 562 KB Posted
- Attached to
- FEMA OCIO Operations and Maintenance (O&M) Federal contract opportunity
- Solicitation number
- HSFE30-16-R-0009
About this file
This draft request for proposal from the Federal Emergency Management Agency solicits offers for information technology operations and maintenance services. The indefinite delivery/indefinite quantity contract would have a one-year base period and four one-year option periods, with a total potential value of $300 million. Services sought include IT infrastructure support, service desk functions, asset management, and cybersecurity monitoring. The solicitation targets small businesses, with NAICS codes and size standards listed. The final RFP is expected in summer 2016.
View the file
Other files for this federal contract opportunity
Show all 46
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DRAFT Operations and Maintenance (O&M) Request for Proposal (RFP) HSFE30-16-R-0009
U.S. Department of Homeland Security
Operations & Mantenance DRAFT Request for Proposal (RFP)
HSFE30-16-R-0009
April 8, 2016 Department of Homeland Security (DHS)
Federal Emergency Management Agency (FEMA) Office of Chief Procurement Officer (OCPO)
SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS
B.1 General Description The Contractor shall supply the technical and management solutions as described in Section C, Performance Work Statement (PWS).
B.2 Type of Contract The Federal Emergency Management Agency (FEMA) intends to award a single Indefinite Delivery/Indefinite Quantity (IDIQ) contract resulting from this solicitation under Federal Acquisition Regulation (FAR) Part 15, Contracting by Negotiation. The contract resulting from this solicitation will be available for use by all FEMA components and are mandatory-for-consideration. Firm-Fixed Price (FFP), FFP, Time and Materials (T&M), Level-of-Effort (LOE), and Cost Reimbursement, Task Orders may be issued under this contract.
Applicable North American Industry Classification Code System (NAICS) are as follows:
541519; the small business size standard is $27.5 million 541511; the small business size standard is $27.5 million 541512; the small business size standard is $27.5 million 541618; the small business size standard is $15.0 million
B.3 Contract Term This contract will have a one (1) year base ordering period, with four (4) one-year option ordering periods for a total term, if all options are exercised, of five (5) years. For the option periods, the contract shall be renewable as provided in FAR Clause 52.217-9, Option to Extend the Term of the Contract (March 2000), incorporated by reference. The period of performance of any task order issued under the contract shall not exceed twelve (12) months after the expiration of the last option period of the IDIQ contract in accordance with FAR Clause 52.216-22 (OCT 1995), Indefinite Quantity, incorporated by reference in Section I.
B.4 Contract Minimums and Ceiling (not to exceed)
(a) The minimum guaranteed amount for this IDIQ contract is $50.00. The exercise of an option does not re-establish the contract minimum for the IDIQ contract.
(b) The specific quantities will be identified on each task order issued under the base contract. The Government has no obligation to issue Task Orders (TOs) to the Contractor(s) beyond the amount specified in paragraph (a) above. The Contractor will only be paid for effort that has been authorized by the Government and performed in accordance with the contract/task order specifications, except for the minimum amount guaranteed.
(c) The total value of all TOs awarded under this contract must not exceed the ceiling value of $300,000,000.00.
B.5 Attachment J.1 – Price/Cost Tables
SECTION C – PERFORMANCE WORK STATEMENT (PWS)
SEE ATTACHMENT J-2 – Performance Work Statement (PWS)
SECTION D – PACKING, PACKAGING, AND MARKING
D.1 Environmental Considerations When applicable, the Contractor shall use materials which have the least hazardous impact on the environment.
D.2 Branding The contractor shall comply with the requirements of any DHS/FEMA Branding and Marking policies. As a matter of law, Federal criminal statutes prohibit unauthorized uses of the DHS/FEMA Seal. In addition, DHS/FEMA policy prohibits granting authorization for certain commercial uses of the Seal. It is permissible to reference DHS/FEMA in materials if the reference is limited to true, factual statements. The words DHS/FEMA and/or Homeland Security/Federal Emergency Management Agency should appear in the same color, font, and size as the rest of the text in the document. Moreover, such references shall not imply in any way an endorsement of a product, company, or technology.
SECTION E - INSPECTION AND ACCEPTANCE
E.1 CLAUSES INCORPORATED BY REFERENCE (FAR 52.252-2) (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at www.acquisition.gov/far.
FAR Clause No. Title and Date 52.246-4 Inspection of Services – Fixed Price (AUG 1996) 52.246-5 Inspection of Services – Cost Reimbursement (APR 1984) 52.246-6 Inspection – Time and Material and Labor-Hour (MAY 2001)
Inspection and acceptance of all services performed under each task order will comply with applicable FAR clauses, depending upon the contract type of the order.
E.2 Partial Acceptance Partial acceptance will be allowed solely at the discretion of the Government. In the event the Government determines that partial acceptance is allowable, the Task Order must specifically state that they are allowable. The COR identified in Section G of this contract will inspect and accept all work and deliverables required under the contract.
SECTION F – DELIVERY OR PERFORMANCE
F.1 Clauses Incorporated by Reference (FAR 52.252-2) (FEB 1998) This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at www.acquisition.gov/far.
FAR Clause No. Title and Date 52.242-15 ALT I Stop-Work Order (AUG 1989)
52.242-17 Government Delay of Work (APR 1984)
F.2 Performance Schedules The Contractor shall provide all personnel within the specified time stated in the respective task order or within a lesser amount of time, if proposed by the Contractor. The Contractor may request that it be permitted to provide services within a longer period of time for extremely large or complex task order requests requiring Subject Matter Experts or task orders with diverse delivery locations. The decision to permit or negotiate a longer period of time for performance rests exclusively with the Contracting Officer.
F.3 Place of Performance A significant portion of the IT services required under this contract will be provided and performed at the FEMA Headquarters in Washington, D.C., Mount Weather, VA., Winchester, VA., Texas, and or other FEMA locations to be specified via task order. Travel to other FEMA facilities may be required. This includes travel to FEMA fixed facilities or Contractor-managed facilities within the Continental United States locations. The government may require all work to be conducted from the Contractor’s facilities at any time. Notwithstanding, performance may be required anywhere that FEMA has a presence. The specific place of performance will be stated in the individual Task Orders.
Contractor travel may be required to support TOs under this contract. If travel is required and authorized to be billed under a TO, all travel will be reimbursed to the Contractor in accordance with the Federal Travel Regulations. The Contractor shall be responsible for obtaining COR approval (e-mail is acceptable) for all reimbursable travel in advance of each travel event. Travel expenses within 50 miles of the place of performance will not be reimbursed.
SECTION G – CONTRACT ADMINISTRATION DATA
G.1 Contracting and Administration Authority The following sections describe the roles and responsibility of individuals who will be the primary points of contact for the Government on matters regarding contract administration as well as other administrative information. The Government reserves the right to unilaterally change any of these individual assignments at any time. Contract-level inquiries should be made to Nicole.Smith@fema.dhs.gov and Edna.McKellery@fema.dhs.gov.
G.1.1 FEMA Contracting Officer (IDIQ-level)
(a) The FEMA Contracting Officer is the only person authorized to approve changes to or modify any of the requirements under the IDIQ contract. In the event the Contractor effects any such change at the direction of any person other than the CO, the change will be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in costs incurred as a result thereof. The FEMA CO is:
Name: Contracting Officer, Nicole Smith Address: Federal Emergency Management Agency 500 C. Street, SW, 3rd Floor
Washington, DC 20472-3205 Email: Nicole.Smith@fema.dhs.gov
Tel No: (202) 212-4109
Name: Contracting Officer, Edna.McKellery Address: Federal Emergency Management Agency 500 C. Street, SW, 3rd Floor
Washington, DC 20472-3205 Email: Edna.McKellery@fema.dhs.gov
Tel No: (202) 212-3497
(b) The Contractor shall submit requests for modification of this contract and other administrative requests to Nicole.Smith@fema.dhs.gov and Edna.McKellery@fema.dhs.gov and copy the Contracting Officer Technical Representative (COR).
(c) Contractual problems of any nature should be handled as soon as possible, and according to applicable public laws and regulations (e.g., Federal Acquisition Regulation). The problem resolution escalation sequence in FEMA is as follows: 1) the initial point of contact for problem resolution is the Contracting Officer’s Representative (COR) authorized to oversee services, 2) then the Contracting Officer that awarded the Task Order.
(d) Requests for information on matters related to this contract, such as explanation of terms and contract interpretation, shall be submitted to the FEMA CO. The CO is the only official authorized to terminate for cause, to issue notices of termination for cause, and to issue cure notices and show cause notices for the IDIQ contract.
G.1.2 FEMA Federal Program Manager The FEMA Program Manager (PM) within has the overall responsibility for the technical program. The PM, with support of the COR, is responsible for the program related activities, including reporting, communications, marketing, outreach and training. The FEMA PM is:
Name: (To be completed at award) Address: ATTN: Joe Smith/Office Symbol Federal Emergency Management Agency 500 C. Street, SW, Washington, DC 20472-3205 Email:
Tel No:
G.1.3 FEMA Contracting Officer’s Representative The FEMA CORs have responsibility for receipt and acceptance of the contract-level deliverables and reports and past performance reporting for the IDIQ contract. The IDIQ CORs support the CO and PM in the general management of the program. Each functional area has a
COR.
IDIQ Level COR Name: Jody Mathias Address: Joe Smith/Office Symbol 19844 Blue Ridge Mountain Rd.
Mount Weather Email: Jody.Mathias@fema.dhs.gov Tel No 540-542-5331
Functional Area #1 COR:
Name:
Address: Joe Smith/Office Symbol Federal Emergency Management Agency 500 C. Street, SW
Washington, DC 20472-3205
Functional Area #2 COR:
Name:
Address: Joe Smith/Office Symbol Federal Emergency Management Agency 500 C. Street, SW
Washington, DC 20472-3205
Functional Area #3 COR:
Address: Joe Smith/Office Symbol Federal Emergency Management Agency 500 C. Street, SW
Washington, DC 20472-3205
Functional Area #4 COR:
Address: Joe Smith/Office Symbol Federal Emergency Management Agency 500 C. Street, SW
Washington, DC 20472-3205
Functional Area #5 COR:
Address: Joe Smith/Office Symbol Federal Emergency Management Agency 500 C. Street, SW
Washington, DC 20472-3205
G.1.4 Contracting Officer’s Representative (COR) The COs may designate CORs for individual task orders that will be responsible for the day-to-day oversight of the Task Order.
The COR will represent the CO in the administration of technical details within the scope of the task order. The COR is also responsible for the final inspection and acceptance of all task order deliverables and reports, and such other responsibilities as may be specified in the order. The COR is not otherwise authorized to make any representations or commitments of any kind on behalf of the CO or the Government. The COR does not have authority to alter the Contractor’s obligations or to change the order specifications, price, terms or conditions. If, as a result of technical discussions, it is desirable to modify order obligations or the specification, changes will be issued in writing and signed by the CO.
(A) The designated COR may provide written technical direction to the Contractor concerning the work performed under the contract. Technical direction is limited to direction that fills in details or otherwise completes the general description of the work set forth in the contract.
Technical direction includes:
1) Directions to the Contractor that suggest pursuit of certain lines of inquiry, shift work emphasis, fill in details or otherwise serve to accomplish the contractual statement of work.
2) Guidelines to the Contractor, that help interpret technical portions of work descriptions.
(B) Technical direction must be within the general scope of work stated in the contract.
Technical direction may not be used to:
1) Assign additional work under the contract.
2) Direct a change as defined in the “CHANGES” clause of the contract.
3) Increase or decrease the contract price or estimated contract amount (including fee), as applicable, the direct labor hours, or time required for contract performance.
4) Change any of the terms, conditions or specifications of the contract.
5) Interfere with the Contractor’s rights to perform the terms and conditions of the contract.
(C) All technical direction has to be in writing (or via e-mail) by the applicable COR.
(D) If the Contractor believes any technical direction calls for effort outside the scope of the contract or is inconsistent with this requirement, the Contractor must notify the Contracting Officer in writing within five (5) working days after receipt of any such instruction. The Contractor must not proceed with the work affected by the technical direction unless and until the Contractor is notified by the Contracting Officer that the technical direction is within the scope of this contract. To notify the Contractor, the Contracting Officer will either issue an appropriate contract modification within a reasonable time or advise the Contractor in writing within 30 days that the instruction or direction is-
1) Rescinded in its entirety; or
2) Within the scope of the contract and does not constitute a change under the changes clause of the contract, and that the Contractor should proceed promptly with its performance.
(E) Failure of the Contractor and Contracting Officer to agree that the instruction or direction is both within the scope of the contract and does not constitute a change under the changes clause, or a failure to agree upon the contract action to be taken with respect to the instruction or direction, is subject to the Disputes clause of this contract.
(F) Any action(s) taken by the Contractor in response to any direction given by any person other than the Contracting Officer or the applicable COR is at the Contractor’s risk.
(G) Nothing in the foregoing paragraph will excuse the Contractor from performing that portion of the contractual work statement which is not affected by the disputed technical direction.
G.2 Contractor Representatives The Contractor shall identify a Contract Administrator and Contractor Program Manager who shall have the authority to make contract and technical decisions respectively regarding this contract. The Contract Administrator will act for the Contractor for the duration of this contract or until the Contracting Officer has been notified by the Contractor in writing of his/her replacement. The Contractor Program Manager is designated as key personnel, and any proposed substitutions shall be made in accordance with H. The Contractor shall not direct bill for either the Contract Administrator or the Contractor Program Manager on the base IDIQ contract or any individual Task Order(s).
G.2.3 Contract Administrator The Contract Administrator shall be responsible for all contract administration issues and shall act as the central point of contact with the Government for all such issues. The Contract Administrator shall have full authority to act for the Contractor in all contractual matters.
G.2.6.2 Contractor Program Manager The Contractor shall appoint a Program Manager who will be the Contractor’s authorized representative for technical and administrative performance of all services required hereunder.
The Program Manager shall provide the single point of contact through which all Contractor/Government communications, work, and technical direction shall flow. The Program Manager shall receive and execute, on behalf of the Contractor, such technical direction as the Contracting Officer and his/her designated representative may issue within the terms and conditions of the contract. All administrative support of the Contractor’s technical personnel, and all interface and interaction with subcontractors used by the Contractor in performance of this contract, shall be the responsibility of the Contractor.
G.3 Ordering Procedures
(a) The CO will provide a request to the contractor, within the scope of the IDIQ Performance Work Statement (PWS).
(b) The CO will use a manual solicitation approach. The contractor shall evaluate the scope of the request and provide a proposal/ quote.
(c) The proposal shall indicate either compliance with or exception to the requirements, risks, assumptions and any conflict of interest issues. Written technical proposals shall address as appropriate: (other items may be requested at CO discretion)
• Proposed personnel;
• Technical Approach;
• Proposed rates;
• Other proposal elements (materials, travel and training, etc.);
• Task Order terms;
• Other pertinent data, (e.g., potential conflict of interest issues)
(d) The proposal shall include detailed pricing for all services requested at rates equal to or lower than those established in the IDIQ contract. The Government is permitted to negotiate pricing other than originally proposed and established in the contract.
(e) Other related information shall always in be in writing and shall address relevant information as required by the contract or requested by the CO. The contractor shall assume all costs associated with proposal preparation for task orders. Contractors will not be reimbursed for proposal preparation.
G.4 Task Orders Task Orders issued under this contract may contain the following information:
(a) Date of order;
(b) Contract number and Task Order number;
(c) Description, quantity ordered and contract price;
(d) Period of Performance;
(e) Place of Performance;
(f) Accounting and appropriation data;
(g) Any other pertinent information such as name and address of Contractor;
G.5 Invoicing and Payment (Task-Order Level) Unless otherwise stated in the TO, the Contractor shall submit an original invoice containing the following information:
(a) Name and address of the Contractor;
(b) Invoice date and number;
(c) Contract number, contract line item number (CLIN) and task order number;
(d) Description, quantity, unit of measure, unit price and extended price of the items delivered;
(e) Terms of any discount for prompt payment offered;
(f) Name and address of official to whom payment is to be sent;
(g) Name, title, and phone number of person to notify in event of defective invoice; and
(h) Electronic funds transfer (EFT) banking information.
All invoices shall be submitted to the “Designated Billing Office” and/or “Designated Payment Office” address specified in each task order. Invoices will be handled in accordance with the Prompt Payment Act and a payment will be made for items accepted by the Government that have been provided as set forth in each task order. Invoices may be submitted via e-mail to Fema-finance-vendor-payment@fema.dhs.gov. The telephone number is 540-504-1900.
G.6 Unauthorized Work The Contractor is not authorized at any time to commence TO performance prior to the issuance of a signed TO or other written approval provided by the CO to begin work.
G.7 Federal Holidays The Government observes the following federal holidays. When any such day falls on a Saturday, the preceding Friday is observed. When any such day falls on a Sunday, the following Monday is observed.
New Year’s Day Labor Day Martin Luther King, Jr.’s Birthday
Columbus Day
Presidents’ Day Veterans’ Day Memorial Day Thanksgiving Day Independence Day Christmas Day Inauguration Day
SECTION H – SPECIAL CONTRACT REQUIREMENTS
H.1 Advertisements, Publicizing Awards and News Releases Under no circumstances shall the Contractor, or anyone acting on behalf of the Contractor, refer to the supplies, services, or equipment furnished pursuant to the provisions of this contract in any publicity/ news release or commercial advertising without first obtaining explicit written consent to do so from the FEMA Contracting Officer. This restriction does not apply to marketing materials developed for presentation to potential government customers of this contract vehicle.
The Contractor agrees not to refer to awards in commercial advertising in such a manner as to state or imply that the product or service provided is endorsed or preferred by the Federal Government or is considered by the Government to be superior to other products or services.
H.2 Key Personnel – Contractor Program Manager The Contractor’s Program Manager is designated as Key Personnel. The Program Manager will be the Contractor’s authorized representative for technical and administrative performance of all services required under this contract. Responsibilities for the Program Manager are described in Chapter B, Section G.2.6.2.
The person occupying the Program Manager position may, with the consent of the FEMA Contracting Officer, be substituted or otherwise replaced, during the term of the contract. Prior to removing or replacing the Program Manager, the Contractor shall request, in writing, approval for such action from the FEMA Contracting Officer at least thirty (30) calendar days in advance of the proposed effective date.
H.2.1 Resumes Attachment J.3 Labor Category Descriptions includes descriptions of applicable labor categories and corresponding education and experience requirements. Resumes will not be evaluated. Resumes will be reviewed to ensure labor category descriptions and education and experience requirements are satisfied. Contractor personnel security requirements will be listed in each task order. Top Secret security status is favorable.
H.3 Identification of Contractor Personnel The Contractor shall ensure that its employees and subcontractors will identify themselves as employees of their company while working on FEMA contracts. For example, Contractor personnel shall introduce themselves in person and in voice-mail, as employees of their respective companies, and not as FEMA employees. Under no circumstances and at no time shall subcontractors of the prime identify themselves as employees of the prime or in any other way suggest, by action or inaction, that they are employees of the prime. Failure to adhere to this requirement may constitute grounds for termination for cause of the base FEMA IDIQ contract. Contractor shall ensure that their personnel use the following format signature on all official e-mails generated by DHS computers:
Name Position or Professional Title
Prime FEMA Contractor Name OR Subcontractor Company Name in support of Prime FEMA Contractor Name Supporting the __________Division/Office of FEMA Phone Fax
H.4 Post-Award Evaluation of Contractor Performance Contractor Performance Evaluations: Annual and final evaluations of Contractor performance, at both the IDIQ and individual TO levels, will be prepared on this contract in accordance with FAR 42.1500. The final performance evaluations will be prepared following the end of the period of performance. Annual and final evaluations will be provided to the Contractor as soon as practicable after completion of the evaluation. The Contractor can elect to review the evaluation and submit additional information or a rebuttal statement. The Contractor shall be permitted thirty (30) days to respond. Contractor response is voluntary. Any disagreement between the parties regarding an evaluation will be referred to the cognizant Division Director (or his/her equivalent), whose decision is final. Copies of the evaluations, Contractor responses, and review comments, if any, will be retained as part of the contract file, and may be used to support future award decisions.
Electronic Access to Contractor Performance Evaluations: FAR 42.15 requires agencies to prepare annual and final evaluations of Contractor performance. The Past Performance Information Retrieval System (PPIRS) is used to record and maintain past performance information. The FEMA utilizes the Contractor Performance Assessment Reporting System (CPARS), which feeds its information into the PPIRS system in order to share information with other federal agencies. The process for submitting such reports shall be in accordance with agency procedures (see below). Contractors may view evaluations, once completed via CPARS, through a secure Web site that can be obtained at the following URL - www.ppirs.gov.
The registration process requires the Contractor to identify an individual that will serve as a primary contact and who will be authorized access to the evaluation for review and comment. In addition, the Contractor shall be required to identify a secondary contact who will be responsible for notifying the cognizant contracting official in the event the primary contact is unavailable to process the evaluation within a thirty (30) day time period. Once a performance evaluation has been prepared and is ready for comment, the CPARS will send an email to the Contractor representative notifying that individual that a performance evaluation is electronically available for review and comment.
H.5 Post-Award Conference The Contractor shall participate in a post-award conference that will be held approximately (10) business days after contract award. The purpose of the post-award conference is to aid both the Contractor and the Government in achieving a clear and mutual understanding of all contract requirements and identify and resolve potential problems (See FAR Subpart 42.5).
The FEMA COR is responsible for establishing the time and place of the conference and will notify the appropriate Government representatives and the Contractor. The FEMA CO will designate or act as the chairperson at the conference. The chairperson of the conference shall conduct the meeting.
The post-award conferences will establish work level points of contact, determine the administration strategy, roles and responsibilities, and other information pertinent to the successful administration of and participation in the FEMA Support Services IDIQ.
H.6 Access to Unclassified Facilities, Information Technology Resources, and Sensitive Information The assurance of the security of unclassified facilities, Information Technology (IT) resources, and sensitive information during the acquisition process and contract performance are essential to the DHS/FEMA mission. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive But Unclassified (For Official Use Only) Information, describes how Contractors must handle sensitive but unclassified information. DHS MD 4300.1 Information Technology Systems Security and the DHS Sensitive Systems Handbook prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering Contractors specifically for all orders that require access to facilities, IT resources or sensitive information.
Contractors shall not use or redistribute any DHS information processed, stored, or transmitted by the Contractor except as specified in the task order.
H.7 FEMA Contract-Level Reporting – Small Business Socio-Economic Category
(a) Definitions:
“Cost of contract performance incurred by personnel” as used in this clause means:
(1) For Time & Material and Labor-Hour Contract Line Item Numbers, total personnel cost is the total cost excluding materials.
(2) For fixed price Contract Line Item Numbers, total personnel costs equals the total costs incurred less materials and subcontract costs.
(b) By submission of an offer and execution of a contract, the Offeror/Contractor agrees that in performance of the contract in the case of a contract for—
(1) Services (except construction). At least 50 percent of the cost of contract performance incurred for personnel shall be expended for employees of the concern.
(2) Supplies (other than procurement from a non- manufacturer of such supplies). The concern shall perform work for at least 50 percent of the cost of manufacturing the supplies, not including the cost of materials.
(c) For orders under the FEMA contract, the provisions in paragraph (b) shall be applied separately to each individual Task Order level rather than to the contract as a whole. The Contractor shall, on a semi-annual basis, provide a report to the FEMA COR which outlines the percentage of work performed on each completed Task Order. For Task Orders with multiple periods, the Contractor shall include any completed base or option period(s) on the semi-annual report.
(d) Remedies
(1) If the contractor fails to comply with the requirements in paragraph (b) above, the contractor shall repay the Government the following amount:
(i) Fixed Price Contracts / Contract Line Item Numbers: (50 percent less actual percentage of work performed by the concern) x Total Contract Price
(ii) T&M Contracts / Contract Line Item Numbers: (50 percent less actual percentage of work performed by the concern) x Total Costs Billed Under the Contract
H.8 Government Records
(a) Government's Records: Except as is provided in paragraph (b) may be otherwise agreed upon by the Government and the Contractor, all records acquired or generated by the Contractor, in its performance of this contract shall be the property of the Government; and shall be delivered to the Government or otherwise disposed of by the Contractor, either as the FEMA Contracting Officer may from time to time direct during the progress of the work or, in any event, as the FEMA Contracting Officer directs upon settlement of this contract. The Contractor shall, subject to security regulations, requirements, and other provisions of the contract, have the right to inspect; and at its own expense, duplicate only those processes, procedures, or records delivered, or to be delivered, to the Government by the Contractor under this contract, or retain duplicates which are in excess of the Government's requirements. However, nothing in this paragraph shall: (1) permit the Contractor to duplicate or retain for its own purposes any official Government documents or proprietary information relating to the Government or to other Contractors; (2) constitute any commitment on the part of the Government to retain such records for any period beyond customary retention periods for the various types of records; and (3) have any effect on the provisions of FAR Clause 52.227-14 (DEC 2007), entitled "Rights in Data - General."
(b) Contractor's Own Records: The following records are considered the property of the Contractor and not within the scope of paragraph (a) above:
(1) Personnel records and files maintained on individual employees, applicants and former employees;
(2) Privileged or confidential Contractor financial information and correspondence between segments of the Contractor's organization; and
(3) Internal legal files.
(c) Inspection and Audit of Records: All records acquired, or generated by the Contractor under this contract, and in the possession of the Contractor, including those described in paragraph (b) above (exclusive of subparagraph (b)(2) and (b)(3)), shall be subject to inspection and audit any reasonable times. The Contractor shall afford the proper facilities for such inspection and audit.
H.9 Disclosure of Information – Official Use Only Each officer or employee of the Contractor or Subcontractor at any tier to whom “Official Use Only” information may be made available or disclosed shall be notified in writing by the Contractor that “Official Use Only” information disclosed to such officer or employee can be used only for a purpose and to the extent authorized herein, and that further disclosure of any such “Official Use Only” information, by any means, for a purpose or to an extent unauthorized herein, may subject the offender to criminal sanctions imposed by 18 U.S.C. Sections 641 and 3571. Section 641 of 18 U.S.C. provides, in pertinent part, that whoever knowingly converts to his use or the use of another, or without authority sells, conveys, or disposes of any record of the United States or whoever receives the same with the intent to convert it to his use or gain, knowing it to have been converted, shall be guilty of a crime punishable by a fine or imprisoned up to ten years or both.
H.10 Confidentiality of Information
(a) To the extent that the work under this contract requires that the Contractor be given access to confidential or proprietary business, technical, or financial information belonging to other private parties or the Government, the Contractor shall after receipt thereof, treat such information as confidential and agrees not to appropriate such information for its own use or to disclose such information to third parties unless specifically authorized by the Contracting Officer in writing.
The foregoing obligations, however, shall not apply to:
(1) Information which, at the time of receipt by the Contractor, is in the public domain;
(2) Information which is published after receipt thereof by the Contractor or otherwise becomes part of the public domain through no fault of the Contractor;
(3) Information which the Contractor can demonstrate was in its possession at the time of receipt thereof and was not acquired directly or indirectly from the Government or other companies; or,
(4) Information which the Contractor can demonstrate was received by them from a third party who did not require the Contractor to hold it in their confidence.
(b) The Contractor shall obtain the written agreement, in a form satisfactory to the FEMA Contracting Officer, of each employee permitted access, whereby the employee agrees that he/she will not discuss, divulge, or disclose any such information or data to any person or entity except those persons within the Contractor's organization directly concerned with the performance of the contract.
(c) The Contractor agrees that upon request by the Contracting Officer, it will execute an approved agreement with any party whose facilities or proprietary data they are given access to in regards to the restrictive use and disclosure of the data and the information obtained from such facilities. Upon request by Contracting Officer, such an agreement shall also be signed by Contractor personnel.
(d) This language shall flow down to all subcontracts.
H.11 Government-Furnished Property and Government-Furnished Information Specific requirements for Government-furnished property and/or Government-furnished information will be addressed at the TO level.
H.12 Safeguarding of Sensitive Information (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive a s stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan.
Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information
HSAR Class Deviation 15-01 Attachment 1: Safeguarding of Sensitive Information (MAR 2015)
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information.
DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources.
The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones.
Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods:
(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced.
The Contractor shall afford DHS, the Office of the Inspector General, and other Government…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .