ICE SOW.pdf
PDF 330 KB Posted
- Attached to
- National Health Interview Survey Federal contract opportunity
- Solicitation number
- 75D301-23-R-72749
About this file
This statement of work describes requirements for a National Health Interview Survey data support contract opportunity with the Department of Health and Human Services Centers for Disease Control and Prevention. The contract would provide labor support including two intermediate statisticians to perform descriptive data analysis, quality assurance work, and data requests. It would also provide two software developers, one focused on web and database development and the other on SAS programming, to assist with data processing, quality checks, and documentation generation. The base period of performance is from September 4, 2023 to September 3, 2024 with an option period from September 4, 2024 to September 3, 2025. The statement of work outlines required tasks, deliverables, and performance standards for effective contract management and achievement of objectives.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions SAM.GOV.docx | DOCX document | |
| Solicitation 75D301-23-R-72749.doc | DOC document | |
| Solicitation No. 75D301-23-R-72749 .doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work / Performance Work Statement
Title: National Health Interview Survey Data Support
Period of performance of this contract is: 09/04/2023 to 09/03/2025 Base Period: 09/04/2023 to 09/03/2024 Option Period One: 09/04/2024 to 09/03/2025
SECTION 1 – BACKGROUND
The National Health Interview Survey (NHIS) is the nation’s primary source of general health information for the resident civilian noninstitutionalized population and has continuously collected data annually since 1957. Each year, NHIS interviews around 30,000 households, randomly selects one adult and one child (if any) per household and collects health information for around 27,000 sample adults and 9,000 sample children. The Data Analysis and Quality Assurance Branch (DAQAB) of Division of the Health Interview Statistics (DHIS) is responsible for checking the quality of survey data collected by Census interviewers, preparing survey file documentation, analysis of survey data and subsequent dissemination of analytic products, providing technical consultation to NHIS data users. The Data Production and Systems Branch (DPSB) of Division of the Health Interview Statistics (DHIS) is responsible for data receive control and preliminary data quality checks of the survey responses, editing, recoding, processing and transformation of the data, and the generation of public use and restricted use data files and documentation files. Branch staff work closely and collaboratively with other staff in the Division to develop the content, ensure the quality of the data and metadata and produce release artifacts for public dissemination on the NCHS website.
SECTION 2 – PURPOSE/OBJECTIVE
The purpose of this requisition is to acquire the services of two software developers and two intermediate statisticians.
The two intermediate statisticians will assume responsibility for the following tasks: NHIS descriptive data analysis, review and verification of estimates and text, and assistance with quality assurance work.
The intermediate statisticians should have the following skills to be able to successfully evaluate NHIS microdata and accompanying documentation, perform analytic activities, and provide technical consultation to data users:
Advanced logic skills Intermediate experience with descriptive procedures and data management and manipulation in the SAS statistical programming environment; beginner experience or some familiarity with similar processes in R may also be useful, but is not required
Intermediate experience using Microsoft Word and Excel Intermediate knowledge of statistical methods and techniques, and their application to data analysis and evaluation Advanced writing skills for reporting results of statistical analyses and for conveying technical information Good interpersonal and communication skills to work collaboratively in a multi-disciplinary team environment Ability to plan, organize, and carry out tasks independently and with a good track record of responding to requests quickly, and meeting production deadlines.
The two software developers will have different responsibilities.
Software developer I (Web and database development) must be familiar with web and database technology and interfacing with statistical programming environments like SAS using Extract, Transform and Load (ETL) processes. Experience working with the Microsoft SQL Server relational database and associated Business Intelligence (BI) tools such as SQL Server Integration Services (SSIS), SQL Server Analysis Services (SSAS), SQL Server Reporting Services (SSRS), and application development using Visual Studio, ASP.net and C# are highly desirable. These tools will be used to load metadata from external systems, edit and modify the metadata in the database, generate a variety of reports from the metadata using a dashboard of applications and extract the metadata for external applications such as data visualizations, etc. Interfacing these applications with a SAS environment that is used for all data processing will also be useful.
Software developer II (SAS programming) must have experience in the SAS programming language with knowledge of programming using the data step, SAS macro, and/or SAS component objects. Experience with the Microsoft SQL server database and tools like SSIS and SSRS, Python programming, or machine learning is preferred but not required. The SAS programmer will assist staff in developing applications to clean and quality assure the raw data and develop programs to create new variables according to specifications. The SAS programmer will also work with the metadata to generate documentation and other auxiliary files.
SECTION 3 – SCOPE OF WORK
The Contractor will provide labor to support production activities, quality assurance, analytic, technical consultation activities and production activities on-site.
SECTION 4 – TASKS TO BE PERFORMED
Task 1: Project and Account Management
1. Kick-off meeting: A kickoff meeting shall be held no later than 15 business days after the initial award is made to discuss plans and timelines as well as clarify roles and responsibilities.
2. Weekly Conference Call: A weekly conference call with CDC COR, must be held, initiated, and led by the contractor. The purpose of this call is ongoing review of task performance.
3. Quality Control Plan: Following the kick off meeting, the contractor shall develop a written work plan, minimally including all essential interim and final deliverables, key staff responsible for tasks (including contractor, CDC or other partners) and clarifications or updates specific to each task in greater detail than may have been included in the original proposal (for COR review and correction before acceptance). The Quality Control Plan is due no later than 15 business days after the kickoff meeting. The Quality Control must contain:
a. a series of specific reports and activities proposed by the contractor following the kick- off meeting, to be developed by the contractor during the course of the project, inclusive of the contractor’s plan for ongoing monitoring and evaluation of services to assure high quality performance and customer satisfaction.
b. hours of operation,
c. contractor plan for employee management including how the contractor will avoid any appearances of personal services by the CDC, and
d. the contractor’s plan to maintain services during emergencies, such as building closure, inclement weather, etc.
The Quality Control plan must be a distributable document for sharing with key CDC management/staff impacted by this project, as needed. The Quality Control plan is due no later than 10 business days following the kickoff meeting. The Quality Control (and any schedule of interim deliverables) may be revised according to CDC acceptance of the updated Quality Control by the COR during the project with the restriction that these changes must not impact the overall period of performance, scope, or specifications of the award, or otherwise impinge on the authority of the contracting officer. It is the responsibility of the contractor to fully understand what changes require contracting officer approval.
4. Monthly Reporting: The contractor must provide a monthly report including updates on the specific tasks and deliverables expressly broken out, as described in the work plan.
The monthly report shall be used as 1) a tracking tool for success of this project, 2) documentation of effort/services as invoiced in the matching monthly invoice, and 3) support for project improvements. The contractor shall develop the monthly report format for review and approval by the COR. The monthly report is due NLT than the 5th calendar day of each month.
5. Written reports: As specified by the contract, the contractor must be able to prepare written reports and other materials documenting various aspects of the projects. All reports and materials must follow CDC’s editorial and authorship guidelines and must be reviewed/cleared according to CDC procedures. Copies of the reports must be submitted in electronic formats and media appropriate for CDC’s use, as specified by the contract.
Reports and materials must be written in plain language, logically organized and conducted using technology appropriate for the communication objectives.
6. Contractor shall have a Transition Plan in place at start of contract and shall include in discussions during the Kick-off Meeting. Transition Plan shall detail the planned transition methodology in logical sequence to ensure a smooth transition of all tasks/subtasks without interruption or degradation of service levels. The contractor shall include an approach that ensures the successful achievement while limiting impact to existing programs/projects.
7. Contractor shall monitor and manage the quality and timeliness of work and deliverables.
Advises COR on significant issues and problems related to work accomplishment and ensure that actions are timely and reviewed at critical points.
Task 2: Two Statisticians The statisticians will perform the following:
1. Respond to data requests – Using SAS, perform analysis of NHIS data and generate basic descriptive statistics and prevalence estimates.
2. Provide independent verification – Using SAS, perform analysis of NHIS data in order to validate estimates for various products prior to release.
3. Prepare data for updates to data query products – Using SAS, perform analysis of NHIS data and exports estimates into the appropriate format for input into data query tools.
4. Review data query products – Ensure changes, updates, and minor modifications have been implemented in data query tools.
5. Review other print and electronic data products – check text for typos, consistency of estimates in text vs. tables, figures, and statistical programming output, and footnotes and notes for accurate reporting of appropriate methodologies.
6. Review microdata – Check frequencies and skip patterns, as well as accompanying microdata documentation for NHIS data prior to release. Perform other quality assurance activities as needed.
7. Provide assistance with automating quality assurance activities – Use SAS and Excel to assemble large volumes of output used to facilitate the NHIS quality assurance program.
8. Submit a monthly activity report.
Task 3: Software Developer I & II Software developer I (Web and database development) will perform the following:
1. Database support: Studies, loads, modifies, and enhances the MID database schema using SQL DDL statements; develops SQL queries (CRUD operations) to extract data, SQL stored procedures, functions, views to implement business logic, ensures that database integrity is preserved; ensures that the database is optimized for retrieval performance.
2. Programming support: Develops interactive applications using the MVC design pattern that belong in a suite of dashboard applications that generate reports, update individual database records, flexibly search, retrieve, and display matching variable metadata using an intuitive user interface, extract metadata for downstream applications, perform data quality checks, generate final user documentation, etc. using software development best practices. Edits, tests and debugs programs in an agile environment to deliver applications that are robust and reliable.
3. Statistical programming: Writes SAS programs to quality check NHIS metadata and data at various stages of production. Programs the interface between SAS and the database environment. Ensures that programs that manipulate survey data are metadata-driven.
4. Documentation – Follows best practices to document all program with meaningful comments. All other documents should be section 508 compliant for accessibility.
5. Quality assurance – Provides quality assurance testing for all system modifications to ensure the development and distribution of quality products. Develops formal application test plans and test requirements documents as required.
6. Submit a monthly activity report.
The software developer II (SAS programming) will perform the following:
7. Programming support – Studies system requirements and data flow schema, translates edit specifications into SAS programs. Tests, edits, debugs, revises, and refines the program as needed to produce the required deliverables. Familiarity with MS Office applications (e.g., MS Excel, Word) is required, as is the ability to incorporate these applications into SAS programming.
8. Documentation – Documents all procedures used throughout the program and prepares run documentation that explains the purpose and sequence of the data processing steps clearly.
Creates section 508 compliant documents for accessibility.
9. Works with the SQL server database team to develop applications to access the metadata database to generate reports and other auxiliary data files and uses this information to implement data-driven approaches.
10. Quality assurance – Provides quality assurance testing for all system modifications to ensure the development and distribution of quality products. Assists with roll out of systems and documentation. Develops formal application test plans and test requirements documents as required. Runs SAS programs to generate data quality reports for variable universes and frequencies. Alerts analysts when anomalies are identified.
11. Data Analysis – Creates ad hoc tabulations as requested by analysts or other programmers.
Is able to investigate and resolve data problems and anomalies independently by generating cross tabulations. Familiar with basic statistical analysis methodology and can use it to elucidate data issues.
12. Submit a monthly activity report.
SECTION 6 – DELIVERABLES/REPORTING SCHEDULE
Task Deliverable Quantity/Format Due Date Deliver To 1 Quality
Control Plan 1 No later than
10 business days after the kickoff meeting.
Technical Monitor/COR/CO
2 and 3 Monthly Activity Report
12 (per year) 3rd business day of the following month.
Technical Monitor/COR
SUBSECTION A – PERFORMANCE MATRIX
PERFORMANCE
OBJECTIVE
STANDARD PERFORMANCE
THRESHOLD
ACCEPTABLE
QUALITY LEVELS
(AQLs)
METHOD OF
SURVEILLANCE
Task 1 Quality Control Plan
The Contractor shall submit the Quality Control plan is due no later than 10 business days following the kickoff meeting.
Zero Deviation from Standard
100% Inspection
Task 2 2 Statisticians
The Contractor shall submit a monthly activity report detailing all tasks completed and status of tasks in progress.
Zero Deviation from Standard
100% Inspection
Task 3 Software Developer I & II
The Contractor shall submit a monthly activity report detailing all tasks completed and status of tasks in progress.
Zero Deviation from Standard
100% Inspection
SECTION 7 – MINIMUM VENDOR QUALIFICATIONS
The Contractor must have a minimum of four (4) years of college level education and 3-5 years of relevant experience.
SECTION 8 – ADDITIONAL REQUIREMENTS
DATA USAGE:
All data, software and supporting materials acquired under this contract become the property of the U.S. Government. Under no circumstances shall an offeror place a copyright that will in any way limit the government’s use of any of the materials for which the vendor develops, provides and/or receives payment under this contract.
All data collected under the contract shall not be tabulated, analyzed, or summarized for oral/poster presentation, reports, or publications without expressed prior permission of NCHS staff. No oral/poster presentations, reports, or publications on data collected under the contract may be co-authored by the contractor without prior approval of the NCHS Task Order COR or proper clearance by NCHS staff.
508 COMPLIANCE:
HHSAR Provision, 352.239-73: Electronic and Information Technology Accessibility Notice
(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998 and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Standards (36 CFR part 1194), require that when Federal agencies develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.
(b) Accordingly, any offeror responding to this solicitation must comply with established HHS EIT accessibility standards. Information about Section 508 is available at http://www.hhs.gov/web/508.
The complete text of the Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/standards.htm.
(c) The Section 508 accessibility standards applicable to this contract are: 1194.
205 WCAG 2.0 Level A & AA Success Criteria 302 Functional Performance Criteria 502 Inoperability with Assistive Technology 504 Authoring Tools 602 Support Documentation 603 Support Services In order to facilitate the Government's determination whether proposed EIT supplies meet applicable Section 508 accessibility standards, offerors must submit an HHS Section 508 Product Assessment Template, in accordance with its completion instructions. The purpose of the template is to assist HHS acquisition and program officials in determining whether proposed EIT supplies conform to applicable Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and documentation detail - whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the HHS Section 508 Evaluation Template are available under Section 508 policy on the HHS Web site http://hhs.gov/web/508.
In order to facilitate the Government's determination whether proposed EIT services meet applicable Section 508 accessibility standards, offerors must provide enough information to assist the Government in determining that the EIT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.
(d) Respondents to this solicitation must identify any exception to Section 508 requirements. If a offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.
(e) Electronic content must be accessible to HHS acceptance criteria. Checklist for various formats are available at http://508.hhs.gov/, or from the Section 508 Coordinator listed at https://www.hhs.gov/web/section-508/additional-resources/section-508-contacts/index.html.
Materials that are final items for delivery should be accompanied by the appropriate checklist, except upon approval of the Contracting Officer or Representative.
SECURITY
1. Security and Privacy Requirements
1.1 Applicability
The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and/or information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2. Safeguarding Information and Information Systems In accordance with the Federal Information Processing Standards Publication (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
3. Information Security Categorization The Contractor and any sub-Contractors shall handle/protect all information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800- 60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality: [ ] Low [ X ] Moderate [ ] High Integrity: [ ] Low [ X ] Moderate [ ] High Availability: [ X ] Low [ ] Moderate [ ] High Overall Risk Level: [ ] Low [ X ] Moderate [ ] High
Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:
[ ] No PII [ X ] Yes PII
PII Confidentiality Impact Level has been determined to be: [ ] Low [ X ] Moderate [ ] High
4. Personally Identifiable Information (PII) Per the Office of Management and Budget (OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.
5. Controlled Unclassified Information (CUI) CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
b. disclosed to authorized personnel on a Need-To-Know basis;
c. as determined by CDC, protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
6. Protection of Sensitive Information For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M- 06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
7. Confidentiality and Nondisclosure of Information Any information provided to the Contractor (and/or any subcontractor) by HHS or collected by the Contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS, CDC, and NCHS policies. Unauthorized disclosure of information will be subject to the applicable HHS, CDC, and NCHS sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
8. Internet Protocol Version 6 (IPv6)
All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
9. Government Websites All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended. As per CDC Policy, CDC-IR- 2008-01, the use of non-CDC.GOV domain names is prohibited.
10. Software Assurance The Contractor (and/or any subcontractor) shall ensure IT applications designed and developed for end users (including mobile applications and software licenses) run in the standard user context without requiring elevated administrative privileges.
a. The Contractor (and/or any subcontractor) shall follow secure coding best practice requirements, as directed by the United States Computer Emergency Readiness Team (US-CERT) specified standards and the Open Web Application Security Project (OWASP) that will limit system software vulnerability exploits.
b. The Contractor (and/or any subcontractor) shall ensure IT applications designed and developed for end users (including mobile applications and software licenses) run in the standard user context without requiring elevated administrative privileges.
c. The Contractor (and/or any subcontractor) shall follow secure coding best practice requirements, as directed by United States Computer Emergency Readiness Team (US- CERT) specified standards and the Open Web Application Security Project (OWASP), that will limit system software vulnerability exploits.
d. The Contractor (and/or any subcontractor) shall ensure that computer software developed on behalf of HHS or tailored from an open-source product, is fully functional and operates correctly on systems configured in accordance with government policy and federal configuration standards. The Contractor shall test applicable products and versions with all relevant and current updates and patches updated prior to installing in the HHS environment. No sensitive data shall be used during software testing.
e. The Contractor (and/or any subcontractor) shall protect information that is deemed sensitive from unauthorized disclosure to persons, organizations or subcontractors who do not have a need to know the information. Information which, either alone or when compared with other reasonably-available information, is deemed sensitive or proprietary by HHS shall be protected as instructed in accordance with the magnitude of the loss or harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the data. This language also applies to all subcontractors that are performing under this contract.
f. The Contractor (and/or any subcontractor) shall remediate all risks or vulnerabilities immediately after the risks or vulnerabilities have been identified in the software.
11. Contract Documentation The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
12. Standard for Encryption
The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI],
c. proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
d. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
e. Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2.
The Contractor shall provide a written copy of the validation documentation to the
COR.
f. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys.
Encryption keys shall be provided to CDC Office of Chief Information Officer
(OCIO).
13. Contractor Non-Disclosure Agreement (NDA) Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
Centers for Disease Control and Prevention (CDC) Contractor Non-Disclosure Agreement
I. Non-public Information [Name of contractor] understands that in order to fulfill the responsibilities pursuant to [Contract name and number] between the Centers for Disease Control and Prevention and [Name of CDC contractor] dated [date], employees of [contractor] will have access to non-public information, including confidential and privileged information contained in government-owned information technology systems. For purposes of this agreement, confidential information means government information that is not or will not be generally available to the public. Privileged information means information which cannot be disclosed without the prior written consent of the CDC.
In order to properly safeguard non-public information, [contractor] agrees to ensure that prior to being granted access to government information or the commencement of work for the CDC, whichever is applicable, all employees will sign a Non-Disclosure Agreement (NDA) provided by the CDC prior to beginning work for the CDC. Contractor agrees to submit to the contracting official the original signed copies of NDAs signed by the contractor’s employees in accordance with the instructions provided by the contracting official. Failure to provide signed NDAs in accordance with this agreement and instructions provided by the contracting official could delay or prevent the employee from commencing or continuing work at the CDC until such agreement is signed and returned to the contracting official.
Contractor further agrees that it will not cause or encourage any employee to disclose, publish, divulge, release, or make known in any manner or to any extent, to any individual other than an authorized Government employee any non-public information that the employee may obtain in connection with the performance of the employee’s responsibilities to the CDC.
II. Procurement-Sensitive Information Contractor further agrees that it will not cause or encourage any employee to disclose, publish, divulge, release, or make known in any manner or to any extent, to any individual, other than an authorized Government employee, any procurement-sensitive information gained while in connection with fulfilling the employee’s responsibilities at the CDC. For purposes of this agreement, procurement-sensitive information includes, but is not limited to, all information in Statements of Work (SOW), Requests for Contract (RFC), and Requests for Proposal (RFP);
Responses to RFPs, including questions from potential offerors; non-public information regarding procurements; all documents, conversations, discussions, data, correspondence, electronic mail (e-mail), presentations, or any other written or verbal communications relating to, concerning, or affecting proposed or pending solicitations or awards; procurement data; contract information plans;
strategies; source selection information and documentation; offerors’ identities; technical and cost data; the identity of government personal involved in the solicitation; the schedule of key technical and procurement events in the award determination process; and any other information that may provide an unfair competitive advantage to a contractor or potential contractor if improperly disclosed to them, or any of their employees.
Contractor understands and agrees that employee access to any procurement-sensitive information may create a conflict of interest which will preclude contractor from becoming a competitor for any acquisition(s) resulting from this information. Therefore, if an employee participates in any discussions relating to procurement-sensitive information, assists in developing any procurement-sensitive information, or otherwise obtains any procurement-sensitive information during the course of performing duties at the CDC, contractor understands and agrees that contractor may be excluded from competing for any acquisition(s) resulting from this information.
III. Identification of Non-Government Employees Contractor understands that its employees are not agents of the Government. Therefore, unless otherwise directed in writing by the CDC, contractor agrees to assist and monitor employee compliance with the following identification procedures:
A. At the beginning of interactions with CDC employees, employees of other governmental entities, members of the public, or the media (when such communication or interaction relates to the contractor’s work with the CDC), contractors’ employees will identify themselves as an employee of a contractor.
B. Contractors’ employees will include the following disclosures in all written communications, including outgoing electronic mail (e-mail) messages, in connection with contractual duties to the
CDC:
Employee’s name Name of contractor Center or office affiliation Centers for Disease Control and Prevention C. At the beginning of telephone conversations or conference calls, contractors’ employees will identify themselves as an employee of a contractor.
D. Contractors should not wear any CDC logo on clothing, except for a CDC issued security badge while carrying out work for CDC or on CDC premises. The only other exception is when a CDC management official has granted permission to use the CDC logo.
E. Contractors’ employees will program CDC voice mail message to identify themselves as an employee of a contractor.
I understand that federal laws including, 18 U.S.C. 641 and 18 U.S.C. 2071, provide criminal penalties for, among other things, unlawfully removing, destroying or converting to personal use, or use of another, any public records. Contractor acknowledges that contractor has read and fully understands this agreement.
Name of contractor: ___________________________________ Signature of Authorized Representative of Contractor:_________________________________ Date:________________
Copies retained by: contracting official and contractor
14. Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002.
The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.
15. Training
1. Mandatory Training for All Contractor Staff
All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
2. Role-based Training All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum. All HHS employees and Contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.
have met their RBT requirement.
3. Training Record The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
16. Rules of Behavior
a. The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
b. All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the Contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
17. Incident Response FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for another than authorized purpose.
OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information” (03 January 2017) states:
Definition of an Incident: An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Definition of a Breach: The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for another than authorized purpose.
It further adds:
A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for another use rather than the authorized purpose.
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.
Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:
a. The Contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.
b. All Contractors and subcontractors shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all Contractors and subcontractors shall protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
c. All Contractors and subcontractors shall participate in regular training on how to identify and report a breach.
d. All Contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US-CERT) notification guidelines.
To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC) or CDC Computer Incident Response Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655-2245, whether the response is positive or negative.
e. All Contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.
f. All Contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with HHS/CDC Policy and the HHS/CDC Breach Response Plan and to assist with responding to a breach.
g. Cloud service providers shall use guidance provided in the FedRAMP Incident Communications Procedures when deciding when to report directly to US-CERT first or notify CDC first.
h. Identify roles and responsibilities, in accordance with HHS/CDC Breach Response Policy and the HHS/CDC Breach Response Plan. To this end, the Contractor shall NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, all notifications must be pre-approved by the appropriate CDC officials, consistent with HHS/CDC Breach Response Plan, and the Contractor shall then send CDC- approved notifications to affected individuals; and,
i. Acknowledge that CDC will not interpret report of a breach, by itself, as conclusive evidence that the Contractor or its subcontractor failed to provide adequate safeguards for
PII.
18. Position Sensitivity Designations All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). As such, the following position sensitivity designations apply unless otherwise adjusted by the COR with a risk-based decision accepted by the NCHS Information Systems Security Officer and the Contract Officer.
Sensitive / High Risk Positions – Public Trust Level 6 or Higher is required for all Contractor (and/or any subcontractor) employees with elevated privileges (e.g. logical/physical systems access privileges that exceed ordinary/routine access or use), such as:
system administrators;
database administrators;
system developers;
staff with duties that involve physical/logical control and/or protection of information technology systems that process high, moderate, or low US Government information; and or similar as determined by the COR, ISSO, and CO.
Sensitive / Moderate Risk Positions – Public Trust Level 5 or Higher is required for all Contractor (and/or any subcontractor) employees who, as part of their duties, are exposed to or handle sensitive US Government information (e.g. PII, Procurement Information, information subject to NDA, Controlled Unclassified Information (CUI)…) in any format (e.g. Audio, Electronic, Printed…) An HSPD-12/PIV card is required for all Contractor (and/or any subcontractor) employees who require unescorted, regular physical access to CDC facilities, and/or require access to the CDC enterprise network / PIV-enabled IT systems to carry out their job duties.
A favorable National Agency Check is the minimum investigation required for this contract for all Contractor (and/or any subcontractor) employees whose positions are not considered Sensitive / High Risk, Sensitive / Moderate Risk or require HSPD-12/PIV cards.
19. Homeland Security Presidential Directive (HSPD)-12 The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .