Attachment_4_PWS_Security_Attachment.pdf

PDF 35 KB Posted

Attached to
Trainer Developer II Federal contract opportunity
Solicitation number
ID07180011
Issued by
GSA Federal Acquisition Service

About this file

This document outlines security requirements for a multiple award IDIQ contract to provide information technology and engineering services to the 502nd Trainer Development Squadron. Services include researching, designing, developing, fabricating, and maintaining simulation and training systems. Contractors must comply with DoD, Air Force, and other government security regulations regarding classified and unclassified information. Requirements include obtaining security clearances, implementing visitor security procedures, controlling access to installations and restricted areas, reporting security incidents, and conducting training. The pre-solicitation notice seeks proposals due around September 21, 2018 for a five-year IDIQ contract period beginning March 12, 2019 to provide these services to the 502nd Trainer Development Squadron located at Joint Base San Antonio-Fort Sam Houston, Texas.

Attachment 4 - PWS Security Attachment

View the file

Other files for this federal contract opportunity

Other files attached to Trainer Developer II, newest first.
File Type Posted
Revised_Attachment_6_GSA_Form_527.pdf PDF
ID07180011_PWS_FINAL_4Oct2018.pdf PDF
ID07180011_Questions_and_Answers_Final.pdf PDF
ID07180011_QASP_FINAL_4Oct2018.pdf PDF
Attachment_7_Past_Performance_Questionnaire_Form.docx DOCX document
ID07180011_Solicitation_7.9.2018.pdf PDF
Attachment_8_Tax_Liability_Letter.docx DOCX document
Attachment_6_GSA_Form_527.pdf PDF
ID07180011_RFP_First_Step_READ_ME_FIRST.pdf PDF
Attachment_5_Consent_To__Purchase_Form.xlsx XLSX spreadsheet
Attachment_1_Pricing_Spreadsheet.xlsx XLSX spreadsheet
Attachment_2_Historical_Information.docx DOCX document
Attachment_10_Past_Performance_Reference_Information_Sheet.docx DOCX document
Attachment_9_Subcontracting_Plan_Template.doc DOC document
Attachment_3_Labor_Category_Descriptions.doc DOC document
Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT 4

ID07180011

Performance Work Statement Security Attachment

1. Visitor Group Security Agreement (VGSA). The contractor shall enter into a long-term visitor group security agreement if service performance is on base. This agreement shall outline how the contractor integrates security requirements for service operations with the Air Force to ensure effective and economical operation on the installation. The agreement shall include:

a. Security support provided by the Air Force to the contractor shall include storage containers for classified information/material, use of base destruction facilities, classified reproduction facilities, use of base classified mail services, security badging, base visitor control, investigation of security incidents, base traffic regulations and the use of security forms and conducting inspections required by DoD 5220.22-R, Industrial Security Regulation, Air Force Policy Directive 16-14, Security Enterprise Governance, and Air Force Instruction 16-1406, Air Force Industrial Security Program.

b. Security support requiring joint Air Force and contractor coordination includes packaging classified information, mailing and receiving classified materials, implementing emergency procedures for protection of classified information, security checks and internal security controls for protection of classified material and high-value pilferable property.

c. On base, the long-term visitor group security agreement may take the place of a Standard Practice Procedure (SPP).

2. Obtaining and Retrieving Identification Media. As prescribed by the AFFAR 5352.242- 9000, Contractor access to Air Force installations, the contractor shall comply with the following requirements:

a. The contractor shall obtain installation access passes for all contractor personnel who make frequent visits to or perform work on the Air Force installation(s) cited in the contract.

Contractor personnel are required to present the installation access pass while visiting or performing work on the installation.

b. No later than ten working days prior to contract commencement, the contractor shall submit a written request on company letterhead to the program manager listing the following:

contract number, location of work site, start and stop dates, and names, dates of birth, driver’s license number and state of issue for the contractor employees needing access to the base. The authorized program manager will endorse the request and forward it to the issuing installation pass and registration office or security forces for processing. Contractors will present government (state or federal) issued ID, before being issued a pass to enter the installation.

Before being issued a pass to enter the installation, a criminal history check will be conducted for every individual requesting a pass. Personnel employed by the contractor and operating a motor vehicle on the installation must possess proof of the following:

(1) Liability Insurance

(2) Current License Plates

(3) Current State Inspection Sticker (If Required)

(4) Valid State Driver License

(5) A phone number for sponsor on base

c. Vehicles owned by the contractor with the company name permanently printed on them are not required to obtain a pass as long as a current work order is presented at the time of entry. However, current liability insurance, state inspection sticker, and registration is required.

The person driving the vehicle must have a valid operator license for the type of vehicle.

d. Upon completion or termination of the contract or expiration of the identification passes, the contractor shall ensure that all base identification credentials issued to contractor employees are returned to the issuing office. If a contractor employee has been terminated, the credentials will need to be retrieved and returned to issuing activity so that employee does not have base access. If the credential is not retrieved then SF will need to be notified so base access is not allowed.

e. Failure to comply with these requirements may result in withholding of final payment.

3. Pass and Identification Items. The contractor shall ensure the following pass and identification items required for service performance are obtained for employees and non-government owned vehicles:

a. Installation Access Pass (IAP) (DBIDS), Visitor/Vehicle Pass (AFMAN 31-116), used for contracts for less than six months to include one-day visits (i.e. warranty work)..

b. Installation Access Card (IAC) (DBIDS), (AFMAN 31-113), used for contracts for more than six months or more.

c. DoD Common Access Card (CAC), (AFI 36-3026), used for contracts for more than six months and requirement exists for access to the government computer systems and software.

CAC applications are accomplished by Trusted Agents via the Trusted Agent Sponsorship System (TASS).

4. Security Clearance Requirements. The contractor must possess or obtain an appropriate facility security clearance, (Top Secret, Secret, Confidential-select one) prior to performing work on a classified government contract. If the contractor does not possess a facility clearance the government will request one. The government assumes costs and conducts investigations for Top Secret, Secret, and Confidential facility security clearances. The contractor shall request personnel security clearances, at the company’s expense, for employees requiring access to classified information within 15 days after receiving a facility clearance or, if the contractor is already cleared, within 15 days after service award. Due to costs involved with security investigations, requests for personnel security clearances shall be kept to the minimum amount employees required to perform contract requirements.

5. List of Employees. The contractor shall maintain a current list of employees. The list shall include employee's name, social security number, and level of security clearance. The list shall be validated and signed by the company Facility Security Officer (FSO) and provided to the contracting officer and Information Protection Office (IP Office) at each performance site 30 days prior to the service start date. Updated listings shall be provided when an employee's status or information changes. A Visit Request for all employees with a security clearance is required to be sent through the Joint Personnel Adjudication System (JPAS), and must be updated at least annually. The contractor shall notify the Information Protection Office at each operating location 30 days before on-base performance of the service. The notification shall include:

a. Name, address, and telephone number of company key management representatives.

b. The contract number and contracting agency.

c. The highest level of classified information to which employees require access.

d. The location(s) of service performance and future performance, if known.

e. The date service performance begins.

f. Any change to information previously provided under this paragraph.

6. Suitability Investigations. Contractor personnel not requiring access to classified shall successfully complete, as a minimum, a Tier 1 (T1) investigation, before operating government furnished workstations. The contractor shall comply with the DoD 5200.2-R, Personnel Security Program, AFMAN 33-152, User Responsibilities and Guidance for Information Systems, and AFI 17-130, Air Force Cybersecurity Program Management, requirements. T1 investigation requests are initiated using the Standard Form (SF) 85 and are submitted to the installation Information Protection Office through the using agency’s Unit Security Manager. T1 investigations are different from the Wants and Warrants checks, and are provided by the government at no additional cost to the contractor.

7. Security Monitor Appointment. The contractor shall appoint a security representative for the on base long term visitor group. The security representative may be a full-time position or an additional duty position. The security representative shall work with the host organization to provide employees with training required by DoDM 5200.01, Information Security Program, AFPD 16-14, Security Enterprise Governance, and AFI 16-1404, Air Force Information Security Program. The contractor shall provide initial and follow-on training to contractor personnel who work in Air Force controlled/restricted areas. Air Force restricted and controlled areas are explained in AFI 31-101, Integrated Defense.

8. Additional Security Requirements. In accordance with DoDM 5200.01, Information Security Program and AFI 16-1404, the contractor shall comply with AFSSI 7700, Emission Security (EMSEC) Program; applicable AFKAGs, AFIs, and AFSSIs for Communication Security (COMSEC); and AFI 10-701, Operations Security (OPSEC) Instructions. The contractor will comply with DoD Standard 22/Force Protection Condition Measures, DoD Standard 25/Level I- AT Awareness Training, and associated tasking contained in AFI 10-245, Antiterrorism (AT) standards. Level I AT Awareness training is available for contractor personnel and can be requested by calling the local installation AT Office.

9. Freedom Of Information Act Program (FOIA). The contractor shall comply with DoD Regulation 5400.7-R/Air Force Supplement, DoD Freedom Of Information Act Program, requirements. The regulation sets policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding For Official Use Only (FOUO) material. The contractor shall comply with AFI 33-332, Privacy Act Program, when collecting and maintaining information protected by the Privacy Act of 1974 authorized by Title 10, United States Code, Section 8013. The contractor shall remove or destroy official records only in accordance with AFI 33-322 Records Management, or other directives authorized in AFI 33-364, Records Disposition—Procedures and Responsibilities.

10. Reporting Requirements. The contractor shall comply with AFI 71-101, Volume- 1, Criminal Investigations, and Volume-2, Protective Service Matters, requirements. Contractor personnel shall report to an appropriate authority, any information or circumstances of which they are aware may pose a threat to the security of DoD personnel, contractor personnel, resources, and classified or unclassified defense information. Contractor employees shall be briefed by their immediate supervisor upon initial on-base assignment and as required thereafter.

1. Physical Security. Areas controlled by contractor employees shall comply with base Operations Plans/instructions for FPCON procedures, Random Antiterrorism Measures (RAMS) and local search/identification requirements. The contractor shall safeguard all government property, including controlled forms, provided for contractor use. At the close of each work period, government training equipment, ground aerospace vehicles, facilities, support equipment, and other valuable materials shall be secured. During increased FPCONs, contractors may have limited access to the installation and should expect entrance delays.

12. Operating Instructions. For controlled areas used exclusively by the contractor, the contractor shall develop an Operating Instruction (OI) for internal circulation control, protection of resources and to regulate entry into Air Force controlled areas during normal, simulated and actual emergency operations. The OI shall be written in accordance with AFI 31-101, the local base Operations Plan usually referred to as an OPLAN and AFI 10-245, Air Force Antiterrorism (AT) Standards, and coordinated through the Information Protection (IP) office.

13. Key Control. The contractor shall establish and implement key control procedures in the Quality Control Plan to ensure keys issued to the contractor by the government are properly safeguarded and not used by unauthorized personnel. The contractor shall not duplicate keys issued by the government. Lost keys shall be reported immediately to the contracting officer.

The government replaces lost keys or performs re-keying. The total cost of lost keys, re-keying or lock replacement shall be deducted from the monthly payment due to the contractor. The contractor shall ensure its employees do not allow government issued keys to be used by personnel other than current authorized contractor employees. Contractor employees shall not use keys to open work areas for personnel other than contractor employees engaged in performance of duties, unless authorized by the government functional area chief.

14. Lock Combinations. The contractor shall establish procedures in local OIs ensuring lock combinations are not revealed to unauthorized persons and ensure the procedures are implemented. The contractor is not authorized to record lock combinations without written approval by the government functional area chief. Records with written combinations to authorized secure storage containers or Secure Storage Rooms (SSR), shall be marked and safeguarded at the highest classification level as the classified material maintained inside the approved containers. The contractor shall comply with DoDM 5200.01, Vol 3 security requirements for changing combinations to storage containers used to maintain classified materials.

15. Traffic Laws. The contractor and their employees shall comply with base traffic regulations.

16. Healthcare. Healthcare provided at the local military treatment facility on an emergency reimbursable basis only.

File details come from the government source that posted it. Updated .