Attachment_2_-_SOW_NCCIC_Alternate_Communications_final.docx
DOCX document 213 KB Posted
- Attached to
- Technical and administrative support for the Shared Resources (SHARES) High Frequency (HF) Radio Program Federal contract opportunity
- Solicitation number
- HSHQDC-16-Q-00483
About this file
Attachment 2 - SOW
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachement_3_-_Pricing_Template_HSHQDC-16-Q-00483.xlsx | XLSX spreadsheet | |
| Attachment_4_PPQ.docx | DOCX document | |
| Attachment_5_-_SF_-18_HSHQDC-16-Q-00483.pdf | ||
| Attachment_1_-_Instructions_to_Offerors.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 2
U.S. Department of Homeland Security National Protection and Programs Directorate Office of Cybersecurity and Communications National Cybersecurity & Communications Integration Center
Mission Statement “Support and promote communications capabilities used by emergency responders and Government officials to keep America safe, secure, and resilient”
Vision Statement “Unify and lead the nationwide effort to improve emergency communications capabilities across all levels of Government
STATEMENT of WORK
FOR
NCCIC ALTERNATE EMERGENCY COMMUNICATIONS PROGRAM
1.0 GENERAL
Background The Federal Government must have the ability to communicate at all times and under all circumstances in order to carry out critical and time sensitive missions as set forth by Executive Order (EO) 13618, Assignment of National Security and Emergency Preparedness (NS/EP) Communications Functions, and Title 18 of the Homeland Security Act of 2002, as amended, 6 U.S.C. § 571. Survivable, resilient, enduring, and effective communications, both domestic and international, are essential to enable the executive branch to communicate within itself and with: the legislative and judicial branches; State, local, territorial, and tribal governments; private sector entities; and the public, allies, and other nations. Such communications must be possible under all circumstances to ensure national security, effectively manage emergencies, and improve national resilience. The work performed under this contract is designated to provide the Government administrative and technical support of the National Coordinating Center (NCC) for alternate emergency communications to include satellite and high frequency (HF) radio. Specifically, this SOW identifies the work products required to support the technical, administrative, operational, and readiness activities for the four primary radio operations: SHARES HF Radio, National Coordinating Center for Communications HF Radio (NCC-HF), NCC Auxiliary HF Radio (NCC-AUX), and the SHARES Information Network (SINET), to include the Department and Agency Continuity Network (DACN) and the Resilient All-Media (RAM) Network. The term “SHARES” or “SHARES programs” as used in this document refers to all of these radio and continuity communications programs and other activities of the NCC and the volunteer SHARES network members collectively. The “High Frequency” spectrum is used significantly, though not exclusively, by this program. Use of that term herein does not imply any limitation on the radio frequency expertise that the contractor will be required to provide, as it is expected that the minimum qualifications of the contractor team will include VHF and UHF land mobile radio expertise, as well as Ka, Ku, and L band satellite.
Executive Order (EO) 13618 is the major source of legal and authoritative guidance for developing, implementing, and operating National Security and Emergency Preparedness (NS/EP) communications programs such as the NCCIC Alternate Emergency Communications Program. Specifically, the SHARES HF Radio capability and program was developed by the NCS[footnoteRef:1] and approved by the Executive Office of the President in NCS Directive 3-3, "Shared Resources (SHARES) High Frequency (HF) Radio Program," in January 1989. SHARES makes use of the combined resources and capabilities of existing Federal and federally affiliated HF radio stations on a shared, interoperable basis to provide critical backup communications during emergencies to support national security and emergency preparedness (NS/EP) requirements. Accordingly, NCS Directive 3-3 charged the Manager, NCS, with development and administration of the SHARES program. Two NCS issuances are maintained for SHARES[footnoteRef:2]: NCS Manual (NCSM) 3-3-1, "SHARES User Manual", and NCS Handbook (NCSH) 3-3-1, "SHARES Directory". Over 1,700 federal and federally affiliated HF radio stations currently participate in SHARES. [1: NCS – National Communications System predecessor to the NCC] [2: Appendix to 47 CFR 216, National Communications System Issuance; NCS Directive 3-3, Telecommunications Operations]
The NCC is responsible for, and through this contract also provides, technical and administrative support to the SHARES HF Interoperability Working Group (SHARES IWG). The SHARES Program Manager serves as SHARES IWG Chairman, and is responsible for publishing and distributing meeting announcements and minutes, maintaining the SHARES workbook and other documents, addressing federal HF interoperability issues, providing support to SHARES during emergency situations, monitoring and coordinating SHARES Coordination Network activities, and planning, conducting and evaluating nationwide SHARES exercises.
SHARES incorporates the resources of more than 1,700 HF radio stations contributed by over 100 industry, Federal, and state organizations to form a nationwide emergency message-handling network All major telecommunications and internet/cable service providers are eligible to be members of SHARES and NCC-HF, and their membership allows for emergency communications to coordinate the repair or restoration of the Public Switched Telephone Network (PSTN) and other telecommunications infrastructure. Additionally, the SHARES network covers the 10 GSA regional offices along with Washington, DC headquarters, state and county emergency management agencies to support the NCCIC mission of coordinating the restoration of communications services (Emergency Support Function 2, Communications) under the National Response Framework (NRF). In support of NS/EP telecommunications requirements that include the NRF and continuity of operations (COOP), the NCC manages these networks to coordinate the restoration of critical communications services and to enhance the decision-making ability of Federal and state leaders by providing the capability to convey information in an all-hazards environment.
The services provided under the contract shall be used to support the following organizational goals of the National Cybersecurity & Communications Integration Center (NCCIC):
· Overseeing the development, testing, implementation, and sustainment of NS/EP communications, including communications that support Continuity of Operations and Continuity of Government; Federal, State, local, territorial, and tribal emergency preparedness and response communications; non-military executive branch communications systems; critical infrastructure and key resources (CI/KR) providers, and private voluntary organizations / non-governmental organizations (PVO/NGO), particularly with respect to resilient continuity communications. .
· Incorporating, integrating, and ensuring the necessary combination of hardness, redundancy, mobility, connectivity, interoperability, restorability, and security to obtain, to the maximum extent practicable, the survivability of NS/EP communications under all circumstances, including conditions of crisis or emergency. Hardness includes protecting information systems and support equipment/facilities from the effects of electromagnetic pulse (EMP) and cyber-based attacks.
· Creating and maintaining shared situational awareness among its partners and constituents with resilient communications, databases, and information systems; and
· Assisting in the initiation, coordination, restoration, and reconstitution of National Security or Emergency Preparedness (NS/EP) communications services and facilities under all conditions, crises, or emergencies, including executing Emergency Support Function 2- Communications (ESF-2) responsibilities under the National Response Framework (NRF).
Scope The scope of the contract is to provide technical and administrative support to the NCCIC and SHARES members with alternate emergency communications to include the emergency radio program activities and related initiatives, as directed by the SHARES Program Manager. Specifically, the contractor shall provide staffing and support services under “TASK AREA 1: PROJECT AND CONTRACT MANAGEMENT”, “TASK AREA 2: OPERATIONS SUPPORT”, and “SURGE SUPPORT”. Support shall be provided for the functioning of the SHARES program office, SHARES programs and associated radio and information system networks, and the SHARES Interoperability Working Group (IWG) activities. This support shall include technical assistance in the disciplines of HF and other radio and network operations, operational training, installation, maintenance, enhancement, and configuration management. In addition, support shall include planning and administration of SHARES outreach activities, coordination of SHARES emergency activations and SHARES exercise activities. Historically, the HF Radio Program has experienced approximately 3%-5% growth annually in member stations and associated support activities; that growth is anticipated to continue for the duration of this contract with accelerated growth likely for at least the first two (2) years.
Objective In accordance with EO 13618, the Federal Government must have the ability to communicate at all times and under all circumstances to carry out its most critical and time sensitive missions. Survivable, resilient, enduring, and effective communications, both domestic and international, are essential to enable the executive branch to communicate within itself and with the legislative and judicial branches; State, local, territorial, and tribal governments; private sector entities; key resources (PVO/NGO and CI/KR), and the public, allies, and other nations. Such communications must be possible under all circumstances to ensure national security, effectively manage emergencies, and improve national resilience. The views of all levels of government, the private and nonprofit sectors, and the public must be considered in the development of national security and emergency preparedness (NS/EP) communications policies, programs, and capabilities.
Applicable Documents
1.1.1 COMPLIANCE DOCUMENTS
The following documents provide specifications, standards, or guidelines that must be complied with in order to meet the requirements of this contract:
· Executive Order (EO) 13618, Assignment of National Security and Emergency Preparedness (NS/EP) Communications Functions
· Title 18 of the Homeland Security Act of 2002, as amended, 6 U.S.C. § 571
· OMB Memo M-05-16
· National Security Presidential Directive (NSPD)-51
· Homeland Security Presidential Directive (HSPD)-8
· Homeland Security Presidential Directive (HSPD)-20
· Section 706 of the Communications Act of 1934
· Presidential Decision Directive 63 (PDD-63)
· Homeland Security Presidential Directive-7 (HSPD-7)
· National Response Framework (NRF) with focus on ESF-2 Annex
· DHS 4300A Sensitive System Handbook
· DHS 4300B National Security Systems Handbook
· SHARES Radio Program Documentation (Manuals/Handbooks/SOPs/etc.)
· MIL-STD-188-141 Department of Defense Interface Standard: Interoperability and Performance Standards for Medium and High Frequency Radio Systems
· MIL-STD-188-110 Serial - US Department of Defense standard for HF Communications, Serial PSK mode
· STANAG 5066 "Profile for High Frequency (HF) Radio Data Communication"
· All applicable DHS Management Directives:
https://www.dhs.gov/department-homeland-security-management-directives
2.0 SPECIFIC REQUIREMENTS AND TASKS
Task Area 1: Project and CONTRACT Management The contractor shall provide the necessary project management to include the planning, direction, coordination, and control necessary to accomplish all work requirements stated in this SOW. The SHARES Program Manager (SPM) may establish policies, procedures, templates, guidelines etc. for information management, to include desired style, formatting, grammar, correspondence, filing, storage, organization, labelling etc. of products produced for the government.
2.1.1 SHARES PROGRAM SUPPORT
Under this task, the contractor shall provide technical and administrative support to the SHARES program office. Specifically, the contractor shall assist the SHARES Program Manager (SPM) in planning meetings, and providing technical support to the SPM and working groups. The contractor shall assist the government in incorporating SHARES capabilities in emergency response planning and report preparation. The contractor shall also update and maintain the SHARES Operations Manuals to include the NCS SHARES Manual/NCSM 3-3-1 and NCS SHARES Handbook/NCSH 3-3-1 (and similar documents), support the SHARES data bases (i.e. utilize data bases to maintain SHARES membership, operations, inventory, asset management, configuration management, and other data; and data base programming to correct software errors and to enhance functionality and reliability), prepare for publication and distribute updates to NCSM 3-3-1 and NCSH 3-3-1 and other program related documents. The contractor shall prepare and distribute (after approval by the SPM) the SHARES Newsletter, and manage and maintain the Federal Registry of ALE Address Code database - NCSM 3-3-2 (or follow-on databases). The contractor, with SPM, and/or COR guidance and approval, shall also administer the SHARES Outreach Program, maintain the SHARES Auxiliary Equipment Program, purchase radio and system capabilities and services to support continuity and disaster operations and training, and publish SHARES Program brochures, fact sheets, advertising etc., to include the SHARES program briefing power point. These outreach documents will be updated on a monthly basis or as directed by the SPM. The contractor shall print and distribute SHARES Certificates of Appreciation and Certificates of Participation after select SHARES operational activities as directed by the SPM.
2.1.1.1 Database Administration
Maintain availability and integrity of the databases controlled by the SPO [SHARES Program Office], including: creating and managing backup copies; update access permissions; normalize database relationships and minimize or eliminate data redundancy; review and update data validation; design new tables, reports, queries etc.; create and update documentation; and other services customarily done by a database administrator; establishment of a trouble-ticket tracking system for internal issues and for customer service
2.1.1.2 Database Programing
Create, modify, and document computer code for all SPO databases; create and maintain queries and reports etc. as required; execute queries and reports etc. as required, post-process and distribute results as required; develop and maintain data collection tools such as PDF and HTML forms and applications developed in the Microsoft Office Suite etc.; maintenance of trouble-ticket tracking system
2.1.1.3 IT Support
For systems not managed by DHS, the contractor shall update anti-virus software, apply operating software and application software updates, manage disk space, maintain access rights and user accounts, replace consumable supplies (ink, toner, paper etc.), troubleshoot and repair hardware and software, provide technical support to SPO personnel (operating system, applications, peripheral devices etc.)
2.1.1.4 Radio Operations
Operate telecommunications equipment, including but not limited to LF, MF, HF, LMR, Satellite, Wi-Fi, microwave, telephone (PBX etc.); IP switches, routers etc.; conducting communications using a variety of modes (voice, video, and data), including maintaining the station log and recording and delivering message traffic; configuring operating parameters, adjusting, troubleshooting, and repairing telecommunications equipment including transceivers, antenna tuners, preamplifiers, amplifiers, power supplies, interfaces, antenna rotators and their controllers, ancillary equipment; antennas and feedlines, switches and routers etc.
2.1.1.5 Radio Engineering and Maintenance
Design, installation, and implementation of radio systems and protective measures (Electromagnetic Pulse (EMP), lightning, power surges/sags, electrical noise etc.); troubleshooting and repairing operational and technical problems with communications systems; develop and supervise or execute preventative maintenance program
2.1.1.6 Administrative Support
Data entry, customer service, research and preparation of reports, record-keeping, correspondence management, filing, maintaining stock of office supplies etc.; purchasing (may be supported by off-site personnel)
2.1.2 SHARES INTEROPERABILITY WORKING GROUP ( SHARES IWG)
Under this task, the contractor shall provide technical and administrative support to the SHARES Interoperability Working Group (“SHARES IWG” or “IWG”). Specifically, the contractor shall assist the SHARES Program Manager (SPM) in planning SHARES IWG meetings, including sending meeting invitations and reminder notices, scheduling, agenda development, and preparing and distributing IWG minutes, and providing technical support to the SPM and subgroup (working group, committee, etc.) coordinators in the preparation and coordination of HF interoperability issue papers, and administration (information gathering, evaluation, and information sharing) of designated “items of interest” and “action items”. The contractor shall also support the SHARES IWG meetings by finding speakers for presentations on technical topics of interest to SHARES members. Selection of speakers and topics is subject to approval by the SPM. The contractor shall also record, transcribe, and distribute minutes and presentation materials of IWG meetings, and maintain attendance records, email addresses, and email distribution groups of IWG participants. Contractor shall prepare presentation materials (such as PowerPoint slide decks, PDF documents, hand-outs, etc.), meeting administration materials (sign-in sheets, printed copies of the agenda, etc.), and shall operate such devices as are necessary to conduct the meeting such as a telephone conference bridge, speakerphone, projector, computers for webinar participation, sound systems, lighting etc. The contractor shall develop and maintain a resilient conference bridge with web presentation capabilities for use during the SHARES IWG meetings and during contingency operations that allows for PIN-based participant access and real-time audio monitoring (per user) with an ability to mute any individual offending party. The contractor will also maintain an FOUO-level secure website to upload IWG presentations and post IWG minutes and agendas. When the contractor provides radio training the PM will ensure that all material developed and taught is approved by the Government task lead or COR and the PM will ensure the contractor is properly identified as a contractor at any training or community outreach event. Any time the contractor attends a conference as part of the SHAREs program, the contractor will ensure they are properly identified and will not speak for the government concerning the SHAREs program.
2.1.3 TASK MANAGEMENT:
2.1.3.1 Determine project organization and overall management, technical, personnel, and physical resources management, and cost and schedule control mechanisms. Designate and identify a task manager who will be responsible for task cost, schedule, technical performance, and functional activities, and who will provide all planning, direction, and coordination necessary to accomplish work requirements.
2.1.3.2 Prepare an event-driven Integrated Master Plan (IMP) in Microsoft Word that will document the program accomplishments. The IMP, subject to COR approval, shall describe the technical approach, organizational resources, and management controls the contractor will employ to meet the cost, performance, and schedule requirements. The IMP will also provide the outline for Monthly Status Reports (MSRs) and quarterly Program Management Reviews (PMRs).
2.1.3.3 Prepare a time-phased Integrated Master Schedule (IMS) in Microsoft Project that contains the networked, detailed tasks necessary to ensure successful contract performance. The IMS shall be traceable to the IMP, the contract work breakdown structure, and the SOW. The IMS will be used to verify attainability of contract objectives, evaluate progress toward meeting program objectives, and integrate the program schedule activities with all related components.
2.1.3.4 Schedule and participate in an initial kickoff meeting within fifteen (15) calendar days after contract award to review requirements and establish firm dates for the contract deliverable requirements list (CDRL), which shall be reflected in the written MSRs. Schedule and participate in quarterly PMRs within 10 calendar days of the end of the pertinent quarter.
2.1.3.5 Prepare and deliver the monthly spend plan to address planned and expended funds for each month. The spend plan should include fund/ceiling amounts, percentage spent amount, and totals.
2.1.3.6 Prepare and present MSRs to address changes made in the PMR and serve as the vehicle that establishes firm dates for incremental deliverables. The MSRs are due within 5 business days of the end of the pertinent month.
2.1.3.7 Prepare and present a SHARES EMP Protection Guidelines Manual documenting equipment and best practices for EMP protecting SHARES equipment and sites; Due four (4) months after contract award.
Task Area 2: Operations Support The contractor shall perform the following operational tasks in support of this contract.
2.1.4 OPERATIONAL, EXERCISE, AND TRAINING FOR THE SHARES PROGRAM
Under this task, and at the direction of and approval by the SPM, and/or COR, the contractor shall provide operational support to SHARES during routine operations (including tests and exercises) and emergencies, maintain and enhance SHARES readiness, and provide operational SHARES training. Specifically, the contractor shall provide operational and administrative support to the SHARES emergency communications effort when activated[footnoteRef:3]. Emergency radio network operations support shall include managing radio traffic during NS/EP incidents and other times requiring coordination among SHARES participants. This support shall include but not be limited to maintaining the status of the SHARES operational networks and preparing and distributing SHARES Operational Status Reports. The contractor shall provide operational and administrative support to SHARES Coordination Network (SCN) channels and nets (i.e. interaction between radio stations on a designated radio channel or channels during a specified time period) during routine operations and emergencies, prepare and distribute SCN Operational Level Change Notices, and provide manning for the SHARES Headquarters, COOP and alternate sites, SHARES exercises, SCN on-the-air check-ins, and during training sessions. Following each operational event, as directed by the SPM, the contractor shall prepare and distribute a SHARES Confirmation Card. As directed by the SPM, the contractor shall plan and conduct four (4) nationwide SHARES exercises per calendar year, nominally one per quarter. The contractor shall also coordinate the weekly SHARES National Nets scheduled for 1500Z to 1700Z each Wednesday and other dates and times as specified by the SPM. SHARES Confirmation Cards shall be prepared and distributed to participating radio members supporting the operational response upon SPM approval. As directed by the SPM, the contractor shall provide on-the-air operational training to SHARES station personnel and SHARES HQ personnel. Additionally, the contractor shall develop and provide training (training materials covering operational procedures, HF and other radio fundamentals, and equipment operation) suitable for use by all SHARES members; document procedures and prepare training materials specific to the NCC radio facilities, update hardware and software, and perform configuration management of the facility (including hardware, software, equipment, furniture etc.). SHARES exercises shall be conducted approximately once per quarter. The SPM may adjust exercise dates as necessary. [3: “Activated” – Enhanced operations beyond the normal day-to-day requirements with or without any advance notice or specific declaration.]
2.1.5 NETWORK MANAGEMENT SUPPORT FOR THE NCC SHARES MISSIONS
Under this task the contractor shall provide administrative, exercise, maintenance, training, and network support to NCC SHARES operations. Specifically, the contractor shall maintain an NCC equipment inventory, categorized by facility site, using the appropriate DHS forms for inclusion into the DHS inventory system as required based on DHS thresholds. The contractor shall also establish and maintain a site point of contact and equipment database. On a monthly basis, the contractor shall review and update as necessary the status of each site to include equipment, facility, and operator capability to perform the NCC mission Results of the review are to be included in the MSRs. The contractor shall also conduct periodic on-air activities to assess the operational capability of the NCC and SHARES member sites. The contractor shall coordinate the integration of NCC stations into all appropriate SHARES exercises, and monitor and evaluate the level of participation by site. The contractor shall assist the government as a main point of contact for maintenance related problems reported by site personnel, by receiving and tracking inoperable equipment, and conducting depot level and on-site maintenance on NCC-HF equipment. The contractor shall assist the government by coordinating any required vendor-level maintenance. The contractor shall facilitate or perform any required packing and shipping of equipment transferred between locations or being sent for repair. Upon approval by the government, the contractor shall purchase, check-out, and install new equipment. Finally, the contractor shall maintain the NCC Operations Manuals, brochures, and other documentation. The contractor will be required to maintain all SHARES radio facilities under the control of the SPM in neat, orderly, and professional appearing condition.
2.1.6 MANAGEMENT SUPPORT FOR NCC-AUX MISSIONS
Under this task, the contractor shall provide administrative and management support to the NCC AUX Mission program. Specifically, the contractor shall maintain a site point of contact and equipment database and coordinate the integration of NCC-AUX stations and other non-HF AUX stations into SHARES exercises and operations, and monitor level of participation by site. The contractor shall maintain records for and issue NCC AUX call signs in accordance with guidelines established by the SPM. The contractor shall create and issue Certificates of Participation to participating members, and maintain the NCC AUX Program brochure and other documentation.
2.1.7 PROVIDE RADIO ENGINEERING AND OPERATIONAL SUPPORT FOR NCC SHARES FACILITIES AND MOBILE CAPABILITIES The contractor shall operate and maintain the radio and antenna systems (not limited to HF) and associated ancillary equipment at the NCC headquarters facility and other stations and mobile/transportable capabilities including remote and alternate sites to support NCC mission requirements. All contractor personnel must regularly operate all NCC radio equipment at their duty station(s) as well a periodic operation of all radio equipment at other facilities or nodes under the control of the SPM. .
2.1.8 SPECIALIZED OPERATIONS/MAINTENANCE: CURRENTLY AT CULPEPER, VIRGINIA
The Culpeper radio site is one of the operational control nodes for SHARES programs. Unless emergency conditions require full-time activation this backup site is anticipated to require two (2) site visits (regular duty hours) per visit per month or as directed by the SPM. Other sites in addition to, or instead of, Culpeper may require contractor maintenance and support within 50 miles of the National Capitol Region.
2.1.9 SPECIALIZED OPERATIONS/MAINTENANCE: MT. WEATHER EMERGENCY OPERATIONS CENTER (MWEOC), VIRGINIA FACILITY The MWEOC radio site is one of the operational control nodes for the SHARES Programs. Unless emergency conditions require full-time activation, this backup site is anticipated to require two (2) site visits (regular duty hours) per visit per month or as directed by the SPM.
2.1.10 ALTERNATE OPERATING LOCATION: CORRY STATION, PENSACOLA FLORIDA
Corry Station is the primary alternate operating location for the NCCIC. At the direction of the SPM and with the approval of the COR, contractor personnel may be required to travel to and support this location on an as-needed basis.
2.1.11 ALTERNATE OPERATING LOCATION: IDAHO FALLS, IDAHO
Idaho Falls Idaho is the secondary alternate operating location for the NCCIC. At the direction of the SPM and with the approval of the COR, contractor personnel may be required to travel to and/or support this location on an as-needed basis.
2.1.12 SHARES ALERTING NETWORK (SAN)
The contractor shall provide support to the development, testing, implementation, and operation of a SHARES Alerting Network. Conceptually this network may incorporate Low Frequency (LF) and Medium Frequency (MF) radio spectrum in addition to the more commonly used parts of the radio spectrum.
2.1.13 SHARES INFORMATION NETWORK (SINET)
The contractor shall continue planning, systems integration, testing, fielding, and operations and maintenance for the SHARES Information Network (SINET) which will link SHARES users by means of HF radio, mobile phones, Voice over IP (VoIP) networks, satellite links, Land Mobile Radio, and other technologies. Specifically, the contractor shall maintain and administer the operational government-provided PBX, mobility, and conferencing servers and associated software and configurations that have been customized to meet the requirements of the SHARES program. The contractor shall also assist the SHARES program office staff with IT Security Certification and Accreditation artifacts and conduct tests to assess the application of VoIP and encryption in support of the SHARES program. In addition, the SINET will incorporate cyber and EMP resilient capabilities to support the NCCIC missions and to serve as a model for the rest of the NS/EP community. It is required that the contractor have specific, in-depth expertise in EMP and cyber resilient system engineering and maintenance for communications/information systems. Shoretel PBX equipment installation and operations experience is mandatory to be considered minimally qualified. The planning, systems engineering, site/equipment layouts, and cost/schedules will be provided in the SINET Program Plan report that will updated on a monthly basis. Part of the systems engineering section will be a detailed explanation of the EMP and cyber protection provided for the SHARES Information Network.
3.0 SURGE SUPPORT (OPTIONAL)
If in the judgment of the government and at the direction of the SPM, additional support is required to effectively manage and execute the routine and emergency response mission of SHARES, additional program support may be required dependent on the operational requirement as defined by the government. The type of support may include specialized radio subject matter experts, installation, logistics, administrative support (including database entry, programming, and administration) and communications security specialists.
4.0 PRIVACY PROVISIONS
NPPD must ensure that acquired services comply with federal privacy requirements by including the following privacy provisions in relevant solicitations, Statements of Work (SOWs) or other contractual deliverables.
Safeguarding of Sensitive Information (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause – “Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual’s identity, such as name, Social Security Number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security Number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security Numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal history
(7) Medical information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information
(2) DHS Sensitive Systems Policy Directive 4300A
(3) DHS 4300A Sensitive Systems Handbook and Attachments
(4) DHS Security Authorization Process Guide
(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information
(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program
(7) DHS Information Security Performance Plan (current fiscal year)
(8) DHS Privacy Incident Handling Guidance
(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by stature or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 12.01, February 12, 2016), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlines in NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete the PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.
(f) Sensitive Information Incident Reporting Requirements
(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .