Attachment_1_SOW_Individual_ID_Verification-Authentication_Support_Svc_ALL_EDITS.pdf

PDF 199 KB Posted

Attached to
Identity Verification and Authentication Federal contract opportunity
Solicitation number
HSFE80-13-R-0005
Issued by
Federal Emergency Management Agency Recovery Section

About this file

Attachment 1 SOW Individual ID Verification-Authentication Support Svc

View the file

Other files for this federal contract opportunity

Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK (SOW)

Individual Identity Verification and Authentication Support Services

HSFE80-13-R-0005

4/29/2013

FEMA

Procurement Sensitive

Table of Contents

1.0 INTRODUCTION/AUTHORITIES

2.0 MISSION

3.0 BACKGROUND

4.0 PURPOSE

5.0 PROGRAM REQUIREMENTS

5.1 IDENTITY VERIFICATION AND AUTHENTICATION SERVICES

5.2 VEHICLE SEARCH

5.3 AGGREGATE INSURANCE DATA

5.4 HOMEOWNER’S INSURANCE INFORMATION

5.5 INVESTIGATION TOOL

5.6 TECHNICAL ASSISTANCE

6.0 PERIOD AND PLACE OF PERFORMANCE

7.0 DELIVERABLES AND DELIVERY SCHEDULE

8.0 GOVERNMENT FURNISHED EQUIPMENT (GFE):

9.0 TRANSITION, CONTRACTOR STAFFING AND KEY PERSONNEL PLANS:

10.0 SECURITY

11.0 TRANSACTIONAL VOLUME

12.0 APPLICABLE DOCUMENTS

13.0 REPORTING

13.1 24 HOUR DISASTER DATA ASSESSMENT REPORT

13.2 OWNER/OCCUPANT REPORT:

13.3 MULTIPLE APPLICATION REPORT:

13.4 INVOICE SUMMARY REPORT:

14.0 TECHNICAL ENVIRONMENT

15.0 CONSTRAINTS

CURRENT "AS IS" DESCRIPTION

1.0 INTRODUCTION/AUTHORITIES

Under the authority of the Robert T. Stafford Disaster Relief and Emergency Assistance Act, Public Law 93-288, as amended, 42 U.S.C. 5121-5207, and Related Authorities, Federal Emergency Management Agency (FEMA) assists state and local governments, as well as individuals and households, during natural and man-made disasters. One of the many services that FEMA offers is the ability for disaster survivors to find and apply for disaster assistance via the Internet and Call Centers.

Executive Order 13411: Improving Assistance for Disaster Victims was enacted to take actions for improving the delivery of Federal disaster assistance. As a result, the Disaster Assistance Improvement Program (DAIP) related to centralize the application process and information including application status updates for 17 Federal agencies and 60 assistance programs on DisasterAssistance.gov. FEMA is the DAIP managing partner agency.

As part of the DAIP mission (and FEMA Strategic Plan Objective), the program takes action to prevent fraud, waste, and abuse with regard to Federal assistance programs.

Executive Order 13520: Reducing Improper Payments was signed on November 20, 2009; promotes greater transparency, Government and contractor accountability, data sharing and collaboration among stakeholders toward the mission of reducing improper payments and other forms of fraud, waste, and abuse.

2.0 MISSION

The Federal Emergency Management Agency (FEMA) leads and supports the nation in a risk-based, comprehensive emergency management system on behalf of the Federal Government. FEMA provides preparedness, protection, response, recovery, and mitigation support to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other man-made disasters in the United States CONUS and OCONUS. A critical component to supporting FEMA's mission is ensuring that only bona-fide and eligible individuals are provided Government assistance. This is achieved through verifying the identity and authenticating individuals registering for disaster assistance.

3.0 BACKGROUND

A presidential disaster declaration occurs after a sequence of events, beginning with the disaster incident.

Following the incident, the state’s governor may request a Preliminary Damage Assessment (PDA), which will be forwarded to FEMA headquarters. PDAs may be requested by the state to determine the impact and magnitude of damage and the resulting unmet needs of individuals, public sector, and the community as a whole prior to a request for a Federal declaration. The assessment includes the number of houses damaged, the number of people displaced, etc. At the conclusion of the PDA, a recommendation report is compiled and submitted. If the PDA determined the recovery requirement exceeds local and state or U.S. Territory resources, FEMA will submit a formal request for a presidential disaster declaration.

Disaster survivors request recovery services based on an existing identity and/or property in the region where a disaster occurred. Disaster survivors are encouraged to request FEMA assistance by dialing a toll-free number to access one of FEMA’s permanent or disaster specific call centers or by applying on-line at DisasterAssistance.gov where the applications (registrations) are entered into the National Emergency Management Information System (NEMIS)/Integrated Security and Access Control (ISAAC)

(NEMIS/ISAAC).

http://disasterassistance.gov/ http://disasterassistance.gov/

The current environment uses an identity outcome of "pass/fail" with reason codes provided by the incumbent contractor based on the profile information FEMA gathers from the applicant during registration intake. The point of entry exists when a disaster survivor provides information during registration and FEMA's Human Services Specialists enter the data or the disaster survivor enters the data directly into DisasterAssistance.gov to send a digital record to the contractor for verification. Both property and identity validation is obtained from this set of data. Services provided will determine if the property at the address specified is owned or occupied by the applicant.

Occupancy and ownership are key eligibility factors for most FEMA programs. As a result, FEMA is interested in obtaining additional information such as property ownership and occupancy records associated with the name and Social Security Number (SSN). In order to streamline our registration process, FEMA also requests additional information such as: address, phone, vehicle and other data to ‘pre-populate’ our registration form.

4.0 PURPOSE

FEMA requires support services which includes but is not limited to, data, verification and authentication of identity, occupancy, ownership, insurance, vehicle and demographic information for individuals registering for FEMA disaster assistance where a disaster has occurred or been declared. Furthermore, FEMA seeks products and services in the prevention of fraud, waste, and abuse within the domain of Government financial assistance programs.

5.0 PROGRAM REQUIREMENTS

5.1 IDENTITY VERIFICATION AND AUTHENTICATION SERVICES

FEMA uses Identity Verification and Authentication (IV&A) services as a part of the registration process for disaster survivors to apply online for disaster assistance.

Identity Verification shall verify that an applicant's name, address, SSN and Date of Birth (DOB) exists and is related to the person applying. An example of a strong identity verification service would include validation of a person based on the full name, SSN, date of birth, and address across an array of public, private, and proprietary databases. Identity verification should check (among other validations of the person’s data) that:

a) SSN is valid;

b) SSN is not associated with a deceased person;

c) SSN is related to the named person;

d) SSN is not associated with more than one person.

The Contractor will define the level of assurance they intend for identity verification within the fastest obtainable timeframe providing scores of probability of success that an identity is reliable. Outcome results, either pass/fail with reason codes, or equivalent system, must be the highest possible for a victim to be granted service, but the fastest obtainable for FEMA to make a decision to grant services. Name matches should take into consideration common use of nicknames, e.g., Jonathan could match to Jon, Jonny, etc. The contractor provides an ID verification of the applicant associated with the profile.

FEMA has a requirement to authenticate applicants who establish on-line (web-based) profiles and ensure that the applicant is who s/he says s/he is and has not stolen wallet information. This is currently done by having the applicant take a four question quiz (see 'as is' process picture), which the Contractor shall generate from information in its search results to a database(s) (e.g., a quiz question might be, "which of the following five addresses have you lived at in the last ten years?")

In terms of strong Identity Authentication, FEMA requires level two authentication service. (See Attachment 5 NIST Special Publication 800-63 for more information). For example, FEMA authentication service uses a Personal Identification Number (PIN) and an authentication “quiz” that ask questions based on Personal Identifying Information (PII). Quiz questions may be determined after the award and may be changed by FEMA at any time upon discussion with the contractor. A list of recommended quiz questions shall be provided to FEMA at time of proposal.

IV&A services for the proposed solution are expected to provide near-perfect performance in terms of identity verification and allowing users to authenticate. The solution should verify the identity of a person successfully at a rate of 99% or better after six months of general availability and authenticate users successfully 95% or better after six months of general availability. Furthermore:

• FEMA uses the NEMIS/ISAAC system for determining eligibility and tracking disaster grants and other assistance as well as for support to disaster operations. A contractor establishes a query based on applicant information provided by FEMA via NEMIS/ISAAC and begins the process of validating and authenticating the disaster applicant as a "true identity." Many times, valid applicants do not have the necessary documents needed as a basis for identification. A process and protocol must exist to repetitively and consistently authenticate and verify applicant identities during a disaster and filter out fraudulent claimants.

• If the solution includes new technology, then commercial-off-the-shelf (COTS) products are preferred over custom development of software. Solution must comply with DHS/FEMA IT infrastructure. More information regarding existing systems, technology, and data sources that exist within FEMA are included in the Technical Environment section below.

• Scale to support transactions from a maximum of 750,000 concurrent users in a disaster scenario with extreme demand for disaster assistance registrations with the ability to surge to support load capacity of 25,000 transactions per hour. The threshold for detecting fraud, waste, and abuse and for calculating risk scores shall be real-time or near real-time with 24x7availability and 99.9% uptime.

Response time per transaction shall be six (6) seconds or less.

• Comply with the rules and regulations for Government security and privacy of information such as the Privacy Act, Privacy Impact Assessment (PIA) and Federal Information System Management Act (FISMA). Overall, the solution must show credible safeguarding of Personally Identifiable Information (PII) including sensitive information such as Social Security Number (SSN).

Safeguarding PII data is paramount. The government will monitor the contractor for satisfactory work practices, processes and systems. The Contractor will be responsible for reporting all breach/losses to the COR, or designate, within one (1) hour of the loss. The Contractor is responsible for all PII protection and monitoring cost associated to a breach. The contractor shall supply a plan to offer the identity theft protection or credit monitoring services at no cost to the government for the affected individuals. Plan(s) may require approval by the FEMA Privacy Office prior to execution.

Receive, in addition to identity verification and authentication services, other important information and services alleviating fraudulent requests for assistance:

The Contractor shall provide a risk rating for the temporary address in cases where an assistance check is being requested. Vacant lots, cemeteries, government buildings, commercial buildings, massage parlors, etc. would receive a high-risk rating using a classification system such as Standard Industrial Classification (SIC) codes to identify high risk properties.

The Contractor shall not be contractually bound to save FEMA-provided information in their database but may store the transactions in their accounting system for the duration of the contract.

FEMA’s copy of the information is stored in the NEMIS system and transmitted via the FEMA Switched Network – both NEMIS and the FEMA Switched Network are fully certified and accredited by DHS.

FEMA will collect a small volume of applicant-specific information via an Interactive Voice Response (IVR). The contractor is not required to maintain or operate the IVR. FEMA will collect the information and provide the data to the contractor. The contractor will use the IVR data provided by FEMA to provide additional information for pre-populating call center screens. This capability speeds up the registration process, increases accuracy, and helps deter fraudulent claims.

This capability is currently under development with FEMA.

Obtain Contractor recommendations of the best query data tied to emergency victims in the disaster region. In the event that the Contractor verifies identity, occupancy or ownership for an applicant that FEMA later has reason to question, the contractor needs to provide specific information regarding why the applicant was verified. This research is estimated to occur for no more than one percent (1%) of applicants sent for verification.

5.2 VEHICLE SEARCH

Utilize DMV records containing driver’s license registration information and vehicle information, sourced directly from states DMVs, where commercially available by law, and are supplemented with additional data from national aggregators to support data pre-population. This data pre-population shall assist in expediting the completion of applications by pre-populating driver and vehicle information, where available.

This capability is currently under development with FEMA.

5.3 AGGREGATE INSURANCE DATA

Utilize the homeowner’s insurance information to determine if a residence surveyed during a Preliminary Damage Assessment (PDA) currently carries homeowners insurance. With this information, FEMA can more accurately calculate the amount of probable assistance required as of a result of a disaster. Data at the property level is preferable; however, data at the lowest geographically area available would be acceptable (census block, United States National Grid (USNG), street, block or zip code).

This data would be utilized by the Reports and Analysis team. The insurance data would be stored and accessed within the FEMA Operational Data Store (ODS) where the Reports and Analysis team would utilize the data for reporting and analysis. The data would be linked to data stored in the FEMA Mobile Enterprise Damage Assessment System (MEDAS) through street address and/or GPS coordinates in combination with current FEMA data.

Quarterly data updates shall be provided to ensure the data utilized in reports and analysis recommendations is the most current data available. Each data set shall be versioned to differentiate each set. Non-FCRA or FCRA use would be agreed upon at time of award. If applicable, FEMA shall be notified how the proposed functionality would enable data to be provided by contributing carrier’s consent. Contractor shall identify the percent of carriers ready to participate and what percent of the CONUS or OCONUS data is available to

FEMA.

At the time of the proposal, an implementation plan shall be provided to FEMA to identify timelines, necessary agreements and outline how the contractor will secure various percentages of CONUS or OCONUS insurance data into their database

5.4 HOMEOWNER’S INSURANCE INFORMATION

Utilize the homeowner insurance data received to pre-populate the Intranet Registration Intake application during the Registration Intake process. This information will enable the Human Services Specialist (HSS) to save time by verifying the applicant’s information. This will also eliminate the chances of misspellings and other errors that may occur during the RI process.

All information that will be obtained by FEMA will be saved in order to help make a determination on the applicants request for assistance. Overall this information will be useful throughout the entire FEMA process from the beginning of the registration to the end during the final decision that is being made on the case. All information is subject to the Privacy Act, System of Records Notice (SORN) and relevant Freedom of Information Act (FOIA) portion (5 U.S.C. §552(b) (6) protecting identity of policy holders from being disclosed in response to a request.

FEMA is seeking to secure the fields identified below:

• Name of Carrier

• Policy Status (expired, in-effect, cancelled, disputed)

• Policy Period TO/FROM

• Type of Policy (flood, homeowners etc.)

• Type of Coverage insured for the property listed

• Policyholder

• Policy Number

The four minimum fields:

• Name of Carrier

• Policy Period TO/FROM

• Type of Policy (flood, homeowners etc.)

• Policyholder

Non-FCRA or FCRA permissible purposes would be agreed upon at time of award. If applicable, FEMA shall be notified how the proposed functionality would enable data to be provided by contributing carrier’s consent. Contractor shall identify the percent of carriers ready to participate and what percent of the CONUS or OCONUS data is available to FEMA.

At the time of the proposal, an implementation plan shall be provided to FEMA to identify timelines, necessary agreements and outline how the contractor will secure various percentages of CONUS or OCONUS homeowner policies is available to FEMA.

5.5 INVESTIGATION TOOL

Obtain up to fifty (50) licenses/seats with the ability to add additional if the need arises to utilize an investigative tool to assist with enforcing laws and regulations, prevent fraud, waste, and abuse of FEMA individual assistance programs using advanced data linking technology. Shall enable users to instantly gather and analyze current, comprehensive and authoritative public records information, allowing them to perform their jobs more efficiently and effectively. The investigative tool will assist in identification and verification of applicants damaged dwellings, current address, telephone numbers, and household members and their associated relationships. Products shall be compatible to FEMA Security and IT systems.

The investigative tool will provide quality data, including credit bureaus and non-credit bureau sources, such as Department of Motor Vehicles’ data (to include driver’s license and motor vehicle registration data), property tax roll and deed transfers, utility records, Social Security Administration, etc.

Shall enable FEMA approved users to submit electronic batch search requests to verify sensitive personal identifiable information such as names, social security numbers, date of birth, current or previous physical and mailing address, phone numbers, deceased person(s) etc.

Enable FEMA appointed individual(s) to serve as the site/software administrator to establish, maintain, monitor and terminate user rights to the system.

The vendor shall provide training and guides at no additional cost to the government educating systems users. If the solution is not a web based tool, then software must be approved by the DHS/FEMA Enterprise Architecture Board to be listed on the Technical Reference Model (TRM). Monthly invoices shall be supported by access to reports to verify users’ activity and charges billed.

5.6 TECHNICAL ASSISTANCE

When services are needed, the Government will forward to the Contractor the Statement of Work (SOW) and a Request for Proposal (RFP). Work shall not commence until a task order or modification is in place, unless a written Pre-Authorization Notice is issued by the Contracting Officer allowing work to begin immediately due to urgency.

The Work Proposal shall describe in detail the proposed process for implementing and fulfilling the Government's requirement, including detailed staffing plans and performances dates, and specify deliverables, including reports and methods for delivering materials, delivery dates, locations and the propose labor to perform the task. The Government will provide the Contractor 72 hour notification of the end of the technical assistance need and shall not incur cost beyond the end date regardless of the estimated performance period.

FEMA is seeking an integrated, scalable, near or real time, cost-efficient solution that provides an adaptive risk assessment and risk mitigation strategy to identify, design, and implement necessary controls for preventing improper payments as a result of fraud, waste, and abuse within Government disaster assistance programs.

An innovative solution would not only deliver the desired features but would provide near-perfect performance in detection of fraud and work seamlessly in an integrated technical environment with a comprehensive, end-to-end workflow that includes manual processes as well as automated processes.

The solutions shall:

• Outline a process for analyzing the level of fraud, waste, and abuse (in the forms of improper payments and/or errors), setting up a baseline of measurements, monitoring the measures, and reporting the results with recommendations for improvement on the performance metrics. This requirement has several performance-related targets including: a) hit rate of 99% or better for being able to identify the applicant, b) pass rate 95% or better for allowing applicants to proceed with assistance, and c) error rate such as false negative and false positives are 2% or less. The performance measures (and other metrics) should be base-lined, monitored, reported, and improved within six (6) months period after general availability.

For example, the DHS E-Verify system for verifying employment authorization reduced Final Non- Confirmations (or system mismatches) to less than 4% and system errors (i.e., initial mismatches that were later confirmed for work authorization) to less than 1%. FEMA aims to achieve similar or better results for any potential solution for fraud, waste, and abuse detection and mitigation.

• Integrate with a generic rules engine that supports sophisticated management of a configurable set of rules for risk assessment (i.e., fraud indicators) and automated, systematic processing of rules.

For example, flexible rules definition and rules grouping are two desirable features for a rules engine.

• Provide out-of-the-box, industry proven rules for risk assessment (i.e., fraud indicators) of possible fraud, waste, and abuse within the domain of Government financial and other forms of assistance.

The following rules or fraud indicators shall be included:

• Social Security Number (SSN) is Valid. The SSN specified in the application for disaster assistance is validated against data from the Social Security Administration using the applicant’s first name, last name, damaged dwelling address, damaged dwelling phone number, and date of birth.

• Social Security Number is a Multi-instance Number. Check database(s) for multiple instances of the SSN with variations such as variations of the name. For example, one vendor has a SSN-multi check that includes a parameter for the number of multiple instances to manage the level of sensitivity to the data.

• Social Security Number Belongs to a Minor. The validated person associated to the SSN is less than 18 years old at the date of the inquiry. If the SSN holder is a minor/dependent, information such as name, SSN, relationship, and legal status for the parent(s) or legal guardian(s) will be desired.

• Non-verifiable Damaged Dwelling Address. Check the damaged dwelling address that is street, city, state, and zip code specified in the application for disaster assistance to determine if it can be verified consistently across industry database(s) including the United States Postal Service (USPS) database for mailing address.

• Verified Address Does Not Match. Check in industry database(s) that the verified address returned for the applicant matches the damaged dwelling address that is street, city, state, and zip code provided in the application for disaster assistance. Check that the verified current mailing address in the industry database(s) matches the current mailing address provided in the application for disaster assistance.

• Current Address Belongs to an Institution. Check that the current address specified in the application for disaster assistance belongs to an institution such as a prison, hospital, hotel, camp ground, etc. rather than a residential address.

• Valid Dependent(s) in Household. Check dependent(s) with first name, last name, and SSN specified in the application for disaster assistance to determine if dependent is actually a non-dependent

• Applicant has Previously Submitted a Fraudulent Application. Check Government database(s) and possible industry fraud database(s) for any fraud investigation whether fraud is pending investigation or confirmed cases for the SSN of the applicant.

• SSN of Deceased Person. Check the SSN of the applicant to determine if the Social Security Administration has reported the owner of the SSN to be deceased. In some cases, disaster assistance may be given to the beneficiary of the deceased person, but there is likely to be other requirements such as providing a death certificate.

• Income Verification. Check the reported household total income to determine if the actual household total income matches recently verified income sources including but not limited to federal tax returns, credit applications, etc.

• Primary Residence. Check the damaged dwelling address that is street, city, state, and zip code specified in the application for disaster assistance to determine if the dwelling was the primary residence of the applicant.

• Owner Occupied Residence. Check to determine that the applicant owns (e.g., check with title companies) rather than rents or just occupies the residence.

• Payment Address and EFT Verification. Verify that the payment address and/or EFT account information match the specified recipient (e.g., full name, SSN, and date of birth).

Verify that the payment address is deliverable and not a forwarded mailing address.

• Provide a flexible, configurable risk scoring functionality using the out-of-the-box and/or additionally configured risk rules (i.e., fraud indicators) to assign a risk score for a particular disaster assistance application. The risk score shall be flexible to allow different risk categories (e.g., high risk, medium risk, low risk, and little/no risk), different weights for fraud indicators, and other changes to the risk score formulation.

• Risk analytics in terms of showing a pattern or statistical data for different fraud indicators would be desirable for finding potential areas of fraud, waste, and abuse. For example, discuss tools and processes for data mining and matching algorithms to determine patterns of improper payments from fraud, waste, and abuse. Information can feed fraud auditing and investigation as well as improve the fraud screening process.

• Provide FEMA with the ability to produce case reports for fraud investigation, ad-hoc reporting, and case management functionality as part of an overall approach for risk mitigation of improper payments and other forms of fraud, waste, and abuse.

• Leverage legacy IT systems, technology, and data sources for cost and design efficiency in a Service-Oriented Architecture (SOA) environment. For example, generic rules engines may already exist within the agency and may be used by existing FEMA systems. FEMA is looking for the best, cost efficient solutions and data sources from the private sector (and/or public sector), and therefore, it may involve leveraging existing systems, services, and data sources.

6.0 PERIOD AND PLACE OF PERFORMANCE

The term of the anticipated period of performance is a total of 60 months that includes a 12-month base period and four 12 month option periods. Inclusion of the option periods does not obligate the Government to exercise the options. The place of performance is not known and will be determined at time of award. Firm fixed price task orders will be issued to provide services and performance will be provided as a service by the contractor at their own facility.

7.0 DELIVERABLES AND DELIVERY SCHEDULE

Task Deliverables to or by Expected Completion Timeframe

Insurance Implementation Plans COR, CS and CO At Proposal

Transition Plan COR, CS and CO At Proposal IV&A Services Transaction Volume 365/24/7 six seconds or less Vehicle Search Transaction Volume 365/24/7 six seconds or less

Aggregate Insurance Data Versioned Insurance Data Quarterly

Homeowner’s Insurance Information Transaction Volume 365/24/7 six seconds or less

Investigation Tool 50 licenses to Admin/COR Monthly

PII Breach Notification & Plan COR Within one (1) hour of incident, per PII incident/breach

Technical Assistance Solution Fraud, Waste & Abuse As needed

Reports Distributed Accordingly 24 Hours, Monthly, Quarterly, Year End, AD-HOC as needed

8.0 GOVERNMENT FURNISHED EQUIPMENT (GFE):

N/A

9.0 TRANSITION, CONTRACTOR STAFFING AND KEY PERSONNEL PLANS:

A transition from the current service provider within ninety (90) days from award of contract is required.

Transition is defined as a seamless operation on a non-interference and non-interruption-in-services basis. The Contractor shall finalize a Transition Plan five (5) days after award. The Plan will address all facets of the transition that the Offeror deems important but, at a minimum, should address the timeline, actions, responsibilities and the processes for transition, including adjusting to surge requirements on a 24/7 basis, should a disaster strike at the same time the transition takes place.

Offeror(s) should submit a plan for achieving the SOW.

Offeror(s) should submit a Communications Plan which would outline personnel involved in the project and their respective responsibilities.

Offeror(s) should submit a Project Plan which outlines the goals, objectives, deliverables and milestones associated with this project.

10.0 SECURITY

Unclassified

Offeror(s) should submit a Security Plan which outlines the security policies, protocols, and controls related to the project.

11.0 TRANSACTIONAL VOLUME

The average number of applicants applying for assistance between 2005 and 2011 was 883,000. Experience has indicated a historical range of annual applicants from 150,000 to 2.7 Million.

Budgeting and Funding Costs for this type of service have historically been charged directly to the disasters generating the traffic flow. The previous contract identified a weakness in the theory. Charges are incurred in states that may not receive a disaster declaration for Individual Assistance. It is suggested that FEMA enable a CLIN for non-disaster specific funds to pay for transactions occurring outside of declared areas/states. During an eighteen month study, approximately four percent (4%) of transactions were non disaster related. This sampling is inclusive of low and high disaster activity.

12.0 APPLICABLE DOCUMENTS

Documents applicable to this program are listed below:

• Solicitation HSFE80-13-R-0005 Individual Identity Verification and Authentication Support

Services

• DHS 4300A Sensitive System Handbook 4300A Version 6.1 or later (Attachment 2) in regards to security policies and accreditation

• Critical Infrastructure Information Act of 2002; Title II Subtitle B, of the Homeland Security Act

(Attachment 3) describing PCII procedures

• INTERIM SENSITIVE SECURITY INFORMATION (SSI) (Attachment 4) Policies and

Procedures for Safeguarding and Control of SSI, as defined in Title 49, CFR part 1520

• National Institute of Standards and Technology (NIST)-NIST Special Publication 800-63

Electronic Authentication Guideline (Attachment 5)

13.0 REPORTING

At the time of a disaster declaration or amendment, FEMA will provide the contractor with a list of counties that are included in the disaster declaration or amendment. The contractor will be required to digitally provide to the COR, the following reports regarding the declared counties/regions. FEMA shall also obtain information from the contractor regarding any demographic information available delivered in an agreed upon method after award or on an ad-hoc basis

13.1 24 HOUR DISASTER DATA ASSESSMENT REPORT

FEMA is seeking to obtain information from the contractor regarding any demographic information available; specifically relating to the number of households, median income and various insurance coverage and/or types, in areas where disasters have been declared. At the time of a disaster declaration, FEMA will provide to the contractor a list of counties where individual assistance has been authorized.

The report shall contain the quantity of demographic information available at the time to include a percentage of households in the area for which identity, ownership and occupancy data are available.

Obtain from the Contractor a Disaster Data Assessment Report for the county or counties that are included in each Disaster Declaration. Disaster Declarations are sometimes amended or expanded to include additional counties. The report must be available no later than 24 hours after each Disaster Declaration or amendment. The report will contain information relating to the total number of households, median income, and number of households with homeowners insurance, number of households with flood insurance and an estimate of the percentage of households in the area for which this data is available. The report will provide this information for each county within the disaster area as well as combined information for all counties included in the Disaster Declaration. Report shall include the following:

• Number of households in each county and the combined number of households for all counties in the disaster area.

• Median income in each county and combined median income for all counties in the disaster area.

• Number of households with homeowners insurance in each county and the combined number of households with homeowners insurance for all counties in the disaster area.

• Number of households with flood insurance in each county and the combined number of households with flood insurance for all counties in the disaster area.

• Percentage of total number of households in the area for which this data is available.

• One Disaster Data Assessment report will be required within 24 hours after each disaster declaration or amendment.

Additionally, FEMA is seeking the information as described immediately above on an ad-hoc/as needed pre-declaration basis within 24 hours of the request.

13.2 OWNER/OCCUPANT REPORT:

Obtain from the Contractor an Owner/Occupant Report for the county or counties that are included in each Disaster Declaration. Disaster Declarations are sometimes amended or expanded to include additional counties. The report must be available no later than 24 hours after each Disaster Declaration or amendment. The report will identify the number of owner/occupant households as well as an estimate of the number of households in the disaster area for which ownership and occupancy can be determined. The report will provide owner occupancy data for each county within the disaster area and combined information for all counties included in the disaster declaration. Report shall include the following:

• Number of households in each county and the combined number of households for all counties in the disaster area.

• Number of owner/occupant households in each county and the combined number of owner/occupant households for all counties in the disaster area.

• Percentage of total numbers of households in the area for which this data is available.

• One Owner/Occupant report will be required within 24 hours after each disaster declaration or amendment.

13.3 MULTIPLE APPLICATION REPORT:

Obtain from the Contractor a Multiple Application Report. The weekly reports will identify all individuals or households repeatedly sent for Identity Verification. The report will identify individuals who may have intentionally varied data (i.e. name, SSN, or street address) to defraud the Federal Government. Further it should identify problems that individuals are having with the registration process that cause them to intentionally register more than one time per declaration.

13.4 INVOICE SUMMARY REPORT:

At the time of the billing, a transaction summary and running accumulation report shall be submitted to support the monthly billed activity. File content, format and delivery method will be determined at the time of the award.

14.0 TECHNICAL ENVIRONMENT

DHS/FEMA follows an Enterprise Architecture (EA) framework that guides the development and integration of agency systems including the DAIP systems. The FEMA systems have been developed for an Oracle 10/11G Real Applications Cluster (RAC) database and an Oracle 10/11G Application ServerAS) high availability, three-tiered environment. The Contractor shall progress with technology as FEMA’s needs progress. The applications are used by the FEMA Call Center and direct public (i.e., Internet) to assist individuals affected by disasters or catastrophic events. The FEMA production environment supports 15,000 concurrent users. Additionally, FEMA uses commercially managed services that provide support for another 15,000 concurrent users for a total native capacity to handle up to 30,000 concurrent users. FEMA is moving to a DHS Data Center which will handle up to an additional 15,000 users. A commercial edge-caching, load balancing solution is used to manage the load among the production and managed services.

Sensitive information will be protected using encryption. Any Personally Identifiable Information (PII) shall be stored or transported in an AES 256 bit encrypted format for billing and contractual accountability purposes. NEMIS sends the name, address, SSN and DOB of applicants to the Contractor.

15.0 CONSTRAINTS

The Contractor shall adhere to the following constraints

• Transaction response speed shall be not more than six (6) seconds.

• The process will deliver identity verification data accessible to FEMA in near or real time across the

NEMIS/ISAAC interface. The contractor will be responsible for delivering the transactional service via the Internet to a government provided interface housed at Mount Weather Emergency Operating Center in Bluemount, VA, and/or other DHS consolidated data center(s).

• The FEMA goal is 100% "True Identity" verification and authentication.

• The Contractor shall report and measure validated identities by volume processed and scores provided as 'pass/fail' or other system.

• Identification verification and authentication services are required for people residing anywhere in the disaster region.

• The Contractor shall conform to the NEMIS/ISAAC interface via its corporate Virtual Private Network.

• Authentication services involve information subject to the provisions of the Privacy Act, the Federal

Information Security Management Act, and similar laws and regulations. A protected information process for guarding applicant data is required. Any personal or private data exchanged is protected pursuant to all Federal data statutes and guidelines issued at any time for data derived from the databases accessible by the service provider for the outcomes stated. Personally Identifiable Information transaction data provided by FEMA shall not be added to the successful contractor's database, but rather shall be stored or transported in an AES 256-bit encrypted format for billing, transactional, and contractual accountability purposes for the length of the contract. Personal Information or Privacy Act Data obtained or provided through this contract may not be used for any other purposes. The Contractor will be required to comply with the security requirements of HSAR 3052.204-70 and HSAR 3052.204-71. These requirements are both included in Section C of this document.

• Contractor shall use a system that shows valid or invalid (pass/fail is used currently) in designating the identity of the applicant for monitoring and surveillance of outcomes. FEMA requires access to the rationale for both designations on each transaction.

• At time of award and thereafter, the testing of the process and protocols will be made available to predict the accuracy rates and compliance with industry best practice to meet or exceed the performance standard for achieving the highest accuracy within the commercial best practices approach. The Contractor shall have a test interface and a set of test transactional data that will enable FEMA to validate that its requirements are met, and to aid in regression testing application changes that may not involve changes to the Contractor's interface.

• The Contractor shall have a high availability architecture and hot standby capability.

• FEMA will provide NEMIS/ISAAC interface assistance to send transactions on a near real-time basis to the contractor and to receive (in less than six seconds) an automated contractor response. This response may be a "PASS/FAIL" with reasons for a "FAIL" response to an identity verification request, a four-question quiz with the correct answer to each question noted for authentication purposes, or an "OWNER/OCCUPANT" response to that transaction. The interface is an extensible Markup Language (XML) exchange via the contractor's Secure Socket Layer (SSL) tunnel through the Internet. FEMA will reconfigure this interface to support the Contractor's Internet Protocol addresses, make minor changes to the XML transaction and response formatting, and work with the Contractor's technical staff to establish an operational link.

16.0 CURRENT "AS IS" DESCRIPTION

The following is a description of how FEMA is performing this function at present to detail all the required steps in the process. The Contractor may recommend alternative ways to do this and meet the overall objective of verification and authentication. The FEMA/NEMIS system, as part of its enterprise-wide disaster response function, incorporates as one of its functional modules a standard universal access management system termed the Integrated Security and Access Control (ISAAC) authentication system which resides on a dedicated authentication server. FEMA ISAAC provides internal and external user account access request, review, and approval for all FEMA disaster response systems, with the goal of meeting FEMA's immediate and continuing need to provide adequate access control and identity management process. As an enterprise service, this module will accept transaction data in XML or equivalent format. FEMA expects that any of the systems available in the commercial marketplace can interface with this FEMA system with minimal modification to the module by FEMA.

The following is a description of the required bi-directional transaction data items that must be exchanged between the Government and the contractor.

• Applicants can initiate transactions in two different ways, either directly by using the Internet, or by telephone with a FEMA intake registration processor entering the transactional data based upon the information provided by the applicant.

• The first step under either alternative results in the following information being presented to the third-party contractor for anyone or combination of the menu of transactions which currently are:

o Identity verification o Identity authentication o Ownership/occupancy verification o Renter occupancy verification o Residency status (local region, state, nation of origin and status of citizenship)

Currently, separate transactions employing all the steps below are performed for each of these required parameters.

• Initial data presented to the Contractor from the Government:

o First name o Last name o SSN o Date of Birth o Address-street o Address-city o Address-state o Address-zip o Transaction ID generated by the Government o Client ID (e.g. FEMA) o Action (request) ID (such as ID verification, ID Authentication, Ownership and/or Occupancy) generated by the Government

• Associated data created by the contractor and included as a permanent record for all transactions:

o Transaction ID generated by the Government and provided as inputs o Action (request) ID generated by the Government and provided as inputs o Transaction ID generated by the contractor o Possible Exception message o Exception ID (predefined) o Exception message

The registration process halts while the contractor is processing this transaction. The Government, therefore, expects that the reply is prompt. Expectations are that average response time is six (6) seconds or less per transaction with no transaction taking longer than ten (10) seconds.

• Processing results created by the Contractor are sent to the Government:

• ID verification

• Pass/fail value

• SSN-Iast name match

• Address-last name match

• SSN not issued to a deceased person

• SSN not issued before date of birth

• SSN is unique

• Quiz

• 4 multiple-choice questions quiz 10 question 1 question 2 question 3 question 4

• Submit Quiz (with quiz 10 as inputs)

• Pass/fail based on predefined pass rate (such as 3 out of 4 as pass)

• Ownership and Occupancy

• True/false value for Ownership and Occupancy

• Occupancy

• True/false value for Occupancy

• Based upon the results of the query, the application process either continues or is terminated pending further action by the applicant to resolve any discrepancy. The Government expects the Contractor to, on a continuing basis; indicate to the Government a probability score, either in terms of a missed question on a quiz, or an overall scoring number that the applicant associated with each transaction is authentic. For high risk and postal service flags returned for addresses, the data currently returned from 'data' end to authentication end and ultimately to FEMA varies slightly. The data portion returns a Y or N flag via XML to the authentication service, which uses the terms PASS or FAIL based on the data. To determine how to interpret the Y or N translations, the following is planned for use:

• If <addr_deliverable> is Y then Pass. If N or U is returned then Fail

• If <addr_business> is Y then Fail. If N or U is returned then Pass

• If <addr_maildrop> is Y then Fail. If N or U is returned then Pass

• If <addr_highrisk> is Y then Fail. If N or U is returned then Pass

Current system graphic:

Identity Verification-Step 1

1. Data Registration provided by FEMA to VENDOR (App. Services Rep.)

Name

Social Security #

Address

Phone #

Name Social Security #

3. Notification (App.

Services Rep.)

Pass Fail Will receive notification within 6 seconds for both (both must be verified to pass)

6 seconds or less

Provided across NEMIS

INTERFACE

2. Verification (Service Provider)

-Vendor provides ID justification for Failure

Identity Authentication

1. Must have already registered for FEMA disaster assistance

5. Password and PIN # issued to gain access

3. Answer questions to authenticate

Question

4. Authentication Must answer 3 out of 4 questions correctly

Only way to create an account is through DisasterAssistance.gov.

2. Create an account online by visiting webpage

Question 1

Question 2

Question 3

Question 4

Provided across

NEMIS

INTERFACE

Owner/Occupancy Verification

1. Data Registration (App. Services Rep.)

Name

Social Security #

Address

Phone #

2. Verification (Service Provider)

Name Social Security #

Ownership Occupancy

3. Notification (App.

Services Rep.)

Pass Fail

Will receive notification within 6 seconds for both (both must be verified to pass)

6 seconds or less

6 seconds or less

6 seconds – 3 + minutes

Will receive notification within 6 seconds up to 3 minutes or more (both must be verified to pass)

Provided across NEMIS

INTERFACE

http://disasterassistance.gov/

1.0 INTRODUCTION/AUTHORITIES
2.0 MISSION
3.0 BACKGROUND
4.0 PURPOSE
5.0 PROGRAM REQUIREMENTS
5.1 IDENTITY VERIFICATION AND AUTHENTICATION SERVICES
5.2 VEHICLE SEARCH
5.3 AGGREGATE INSURANCE DATA
5.4 HOMEOWNER’S INSURANCE INFORMATION
5.5 INVESTIGATION TOOL
5.6 TECHNICAL ASSISTANCE
6.0 PERIOD AND PLACE OF PERFORMANCE
7.0 DELIVERABLES AND DELIVERY SCHEDULE
8.0 GOVERNMENT FURNISHED EQUIPMENT (GFE):
9.0 TRANSITION, CONTRACTOR STAFFING AND KEY PERSONNEL PLANS:
10.0 SECURITY
12.0 APPLICABLE DOCUMENTS
13.0 REPORTING
13.1 24 HOUR DISASTER DATA ASSESSMENT REPORT
13.2 OWNER/OCCUPANT REPORT:
13.3 MULTIPLE APPLICATION REPORT:
13.4 INVOICE SUMMARY REPORT:
14.0 TECHNICAL ENVIRONMENT
15.0 CONSTRAINTS
16.0 CURRENT "AS IS" DESCRIPTION

File details come from the government source that posted it. Updated .