KeyTrak SOW-2022 (Final).doc
DOC document 402 KB Posted
- Attached to
- KeyTrak Maintenance Federal contract opportunity
- Solicitation number
- OSFLO-393-2022-0015-RAW
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
KeyTrak Maintenance Statement of Work March 18, 2022
Introduction/Background
The Centers for Medicare & Medicaid Services currently has an eight (8) drawer KeyTrak key control security system used to control and account for all CMS related hard keys. CMS has a need to keep this key control security system functional at all times to ensure that all agency keys are properly protected and controlled.
Objective The objective of this project is to procure a contract that will provide maintenance support services for this eight (8) drawer key control security system located the CMS-Baltimore facility located at 7500 Security Blvd in Baltimore, Maryland 21244. This contract will be for a base-year with four option year periods, which can be exercised at the discretion of the agency.
Scope of Work
Provide one year of telephonic 24/7 software service support and repairs (as necessary) through the replacement of hardware for existing eight drawer KeyTrak Key Control Security System. The following hardware and software components are to be included in this maintenance agreement:
Automated Report
Generator Drawers KeyTrak Server System with EXP Software Laser Printer Reservation Plus Security Camera Web Plus
Section 508 Language for Supporting Documents in CAMS
SECTION 508 - ACCESSIBILITY OF ELECTRONIC AND INFORMATION TECHNOLOGY
This task order is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the workforce Investment Act of 1998 (P.L. 105- 220). Specifically, subsection 508(a)(1) requires that when the Federal Government procures Electronic and Information Technology (EIT), the EIT must allow Federal employees and individuals of the public with disabilities comparable access to and use of information and data that is provided to Federal employees and individuals of the public without disabilities.
| The EIT accessibility standards at 36 CFR Part 1194 were developed by the Architectural and Transportation Barriers Compliance Board ("Access Board") and apply to contracts and task/delivery orders, awarded under indefinite quantity contracts on or after June 25, 2001. |
| Each Electronic and Information Technology (EIT) product or service furnished under this contract shall comply with the Electronic and Information Technology Accessibility Standards (36 CFR 1194), as specified in the contract, as a minimum. If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses: |
| Cancellation of the contract, delivery or task order, purchase or line item without termination liabilities; or |
| In the case of custom Electronic and Information Technology (EIT) being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the noncompliant EIT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby. |
| The contractor must ensure that all EIT products that are less than fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy the contract requirements. |
| For every EIT product or service accepted under this contract by the Government that does not comply with 36 CFR 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date; whichever shall occur first. |
Section 508 Compliance for Communications
The (Contractor name goes here) shall comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this SOW, PWS, or TO, the SOW, PWS, or TO shall take precedence.
Rehabilitation Act, Section 508 Accessibility Standards
29 U.S.C. 794d (Rehabilitation Act as amended)
36 CFR 1194 (508 Standards) https://www.access-board.gov/guidelines-and-standards/communications-and- it/about-the-section-508-standards/section-508-standards
FAR 39.2 (Section 508)
CMS/HHS Standards, policies and procedures (Section 508)
In addition, all contract deliverables are subject to these 508 standards as applicable.
Regardless of format, all Web content or communications materials produced, including text, audio or video - must conform to applicable Section 508 standards to allow federal employees and members of the public with disabilities to access information that is comparable to information provided to persons without disabilities. All contractors (including subcontractors) or consultants responsible for preparing or posting content must comply with applicable Section 508 accessibility standards, and where applicable, those set forth in the referenced policy or standards documents above. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the SOW, PWS, or TO, shall be the responsibility of the contractor or consultant.
The following Section 508 provisions apply to the content or communications material identified in this SOW, PWS, or TO:
36 CFR Part 1194.21 a - l
36 CFR Part 1194.22 a - p
36 CFR Part 1194.31 a - f
36 CFR Part 1194.41 a – c
The contractor shall provide a completed Section 508 Product Assessment Template and the contractor shall state exactly how proposed EIT deliverable(s) meet or does not meet the applicable standards.
The following Section 508 provisions apply for software development material identified in this SOW, PWS, or TO:
For software development, the Contractor/Developer/Vendor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards 29 U.S.C. 794d (Rehabilitation Act as amended)
36 CFR 1194 (508 Standards) 36 CFR Part 1194.21 (a – l) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c) https://www.access-board.gov/guidelines-and-standards/communications-and- it/about-the-section-508-standards/section-508-standards (508 Standards)
FAR 39.2 (Section 508)
| CMS/HHS Standards, policies and procedures (Section 508) |
| Information Technology – General Information (http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS- Information-Technology/Section508/index.html) |
For web-based applications, the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
29 U.S.C. 794d (Rehabilitation Act as amended)
36 CFR 1194 (508 Standards) 36 CFR Part 1194.22 (a – p) 36 CFR Part 1194.41 (a – c) https://www.access-board.gov/guidelines-and-standards/communications-and- it/about-the-section-508-standards/section-508-standards (508 Standards)
FAR 39.2 (Section 508)
| CMS/HHS Standards, policies and procedures (Section 508) |
| Information Technology – General Information (http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS- Information-Technology/Section508/index.html) |
CMS SECURITY CLAUSE
CMS SECURITY CLAUSE
Applicability In accordance with OMB Memorandum M-05-24, Implementation of Homeland Security Presidential Directive 12 (HSPD-12): Policy for a Common Identification Standard for Federal Employees and Contractors, dated August 27, 2004, and Federal Information Processing Standard (FIPS) PUB Number 201-2, Personal Identity Verification (PIV) of Federal Employees and Contractors, CMS must achieve appropriate security assurance for multiple applications by efficiently verifying the claimed identity of individuals seeking physical access to Federally controlled government facilities and/or logical access to federally controlled information systems. Contractors that require routine physical access to a CMS facility and/or routine access to a CMS federally controlled information system will be required to obtain a CMS issued PIV, PIV-I or Locally Based Physical Access card. FIPS PUB 201-2 specifies the architecture and technical requirements for a common identification standard for Federal employees and Contractors.
When a PIV or PIV-I card is provided, it shall be used in conjunction with a compliant card reader and middleware for logical system access. The Contractor shall (1) Include FIPS 201- 2 compliant, HSPD-12 card readers with the purchase of servers, desktops, and laptops; and
(2) comply with FAR 52.204-9, Personal Identity Verification of Contractor Personnel.
Definitions
“Agency Access” means access to CMS facilities, sensitive information, information systems or other CMS resources.
“Applicant” is a Contractor employee for whom the Contractor submits an application for a CMS identification card.
“Contractor Employee” means prime Contractor and subcontractor employees who require agency access to perform work under a CMS contract.
“Official station”— As defined by Federal Travel Regulations, An area defined by the agency that includes the location where the employee regularly performs his or her duties or an invitational traveler’s home or regular place of business. The area may be a mileage radius around a particular point, a geographic boundary, or any other definite domain, provided no part of the area is more than 50 miles from where the employee regularly performs his or her duties or from an invitational traveler’s home or regular place of business. If the employee’s work involves recurring travel or varies on a recurring basis, the location where the work activities of the employee’s position of record are based is considered the regular place of work.
“Federal Identification Card” (or “ID card”) means a federal government issued or accepted identification card such as a Personal Identity Verification (PIV) card, Personal Identity Verification-Interoperable (PIV-I) card, or a Local-Based Physical Access Card issued by CMS, or a Local-Based Physical Access Card issued by another Federal agency and approved by CMS. “Issuing Office” means the CMS entity that issues identification cards to Contractor employees.
“Locally Based Physical Access Card” means an access Card that is graphically personalized for visual identification, that does not contain an embedded computer chip, and is only used for physical access.
“Local Security Servicing Organization” means the CMS entity that provides security services to the CMS organization sponsoring the contract, Division of Physical Security and Strategic Information (DPSSI).
“Logical Access” means the ability for the Contractor to interact with CMS information systems, databases, digital infrastructure, or data via access control procedures such as identification, authentication, and authorization.
“Personal Identity Verification (PIV) card,” as defined in FIPS PUB 201-2, is a physical artifact (e.g., identity card, “smart” card) issued to an individual that contains a PIV Card Application which stores identity credentials (e.g., photograph, cryptographic keys, digitized fingerprint representation) so that the claimed identity of the cardholder can be verified against the stored credentials by another person (human readable and verifiable) or an automated process (computer readable and verifiable).
“Personal Identity Verification-Interoperable (PIV-I) card” similar to a PIV card, is a physical artifact (e.g., identity card, “smart” card) issued to an individual that contains a PIV Card Application which stores identity credentials (e.g., photograph, cryptographic keys, digitized fingerprint representation) so that the claimed identity of the cardholder can be verified against the stored credentials by another person (human readable and verifiable) or an automated process (computer readable and verifiable). PIV-I cards are issued by a non- federal government entity to non-federal government staff. PIV-I cards are issued in a manner that allows federal relying parties to trust the cards. The PIV-I cards uses the same standards of vetting and issuance developed by the U.S. government for its employees
Screening of Contractor Employees
Contractor Screening of Applicants
Contractor Responsibility: The Contractor shall pre-screen individuals designated for employment under any CMS contract by verifying minimum suitability requirements to ensure that only qualified candidates are considered for contract employment. At the discretion of the government, the government reserves the right to request and/or review Contractor employee vetting processes. The federal minimum suitability requirements can be found below in section (c)(2)—Suitability Requirements, and are also contained in 5 CFR 731.202. The Contractor shall exercise due diligence in pre-screening all employees prior to submission to CMS for agency access.
Alien Status: The Contractor shall monitor an alien’s (foreign nationals) continued authorization for employment in the United States. If requested by the Agency, the Contractor shall provide documentation to the Contracting Officer (CO) or the Contracting Officer’s Representative (COR) that validates that the Employment Eligibility Verification (e-Verify) requirement has been met for each Contractor or sub-Contractor employee working on the contract in accordance with Federal Acquisition Regulation (FAR) 52.222-54 - Employment Eligibility Verification.
Residency Requirement: All CMS Contractor applicants shall have lived in the United States at least three (3) out of the last five (5) years prior to submitting an application for a Federal ID Card. CMS will process background investigations for foreign nationals in accordance with Office of Personnel Management (OPM) guidance. Contractor employees who worked for the U. S. Government as an employee overseas in a Federal or military capacity; and/or been a dependent of a U.S. Federal or military employee serving overseas, must be able to provide state-side reference coverage. State- side coverage information is required to make a suitability or security determination. Examples of state-side coverage information include: the state-side address of the company headquarters where the applicant’s personnel file is located, the state-side address of the Professor in charge of the applicant’s “Study Abroad” program, the religious organization, charity, educational, or other non-profit organization records for the applicant’s overseas missions, and/or the state-side addresses of anyone who worked or studied with the applicant while overseas.
Selective Service Registration: All males born after December 31, 1959, must meet the Federal Selective Service System requirements as established on www.sss.gov.
Identification Card Application Process
ID Card Sponsor: The CMS Contracting Officer’s Representative (COR) will be the CMS ID card Sponsor and point of contact for the Contractor’s application for a CMS ID card. The COR will review and approve/deny the HHS ID Badge Request before the form is submitted to the CMS, Office of Support Services and Operations, (OSSO), Division of Personnel Security Services (DPS), for processing. If approved, an applicant may be issued either a Personal Identity Verification (PIV) or PIV- I card that meets the standards of HSPD-12 or a Local-Based Physical Access Card.
Contractor Application Required Submissions: All applicants shall submit an HHS ID Badge Request form for issuance of a Federal ID Card. Unless otherwise directed by the ID Card Sponsor or DPS, applicants are required to electronically submit the request form via CMS’ Enterprise User Administration (EUA) Electronic Front-end Interface (EFI) system, which is located at https://eua.cms.gov/efi. To assist users with the application process, a user’s guide is located at:https://www.cms.gov/About- CMS/Contracting-With-CMS/ContractingGeneralInformation/Contracting-Policy-and- Resources.html.
The EUA users guide link should be used to obtain the most current instructional guidance.
PIV Training: Contractors who need PIV or PIV-I card shall complete HHS PIV Applicant Training, which is found at https://www.cms.gov/About-CMS/Contracting- With-CMS/ContractingGeneralInformation/Contracting-Policy-and-Resources.html. A copy of the completion certificate shall be included with the EFI application.
CMS Applicant Evaluations: CMS will evaluate an applicant’s required access level. Once the review is complete and accepted for further processing, the applicant will be contacted by DPS to submit the below information, as applicable.
| e-QIP: Contractor employees will be required to submit information into e-QIP, a web-based automated system that is designed to facilitate the processing of standard investigative forms used when conducting background investigations for Federal security, suitability, fitness and credentialing purposes. |
| Fingerprints: Instructions for obtaining fingerprints will be provided by CMS, OSSO, DPS. |
| OF 306: Contractor employees may be required to complete the Optional Form (OF) 306, Declaration for Federal Employment which can be found at https://www.opm.gov/forms/pdf_fill/of0306.PDF. |
| Access to Restricted Area(s): The CMS COR will initiate all Federal ID card holders’ physical access requests via Physical Access Control System (PACS) Central at https://pam.cms.local. |
Suitability Requirements: CMS may decline to grant agency access to a Contractor employee including, but not limited to, any of the criteria cited below:
| Misconduct or negligence in employment; |
| Criminal or dishonest conduct; |
| Material, intentional false statement, or deception or fraud in examination or appointment; |
| Refusal to furnish testimony as required by § 5.4 of 5 CFR 731.202; |
| Alcohol abuse, without evidence of substantial rehabilitation, of a nature and duration that suggests that the applicant or appointee would be prevented from performing the duties of the position in question, or would constitute a direct threat to the property or safety of the applicant or appointee or others; |
| Illegal use of narcotics, drugs, or other controlled substances without evidence of substantial rehabilitation; |
| Knowing and willful engagement in acts or activities designed to overthrow the |
U.S. Government by force; and Any statutory or regulatory bar which prevents the lawful employment of the person involved in the position in question.
Badge Issuance: Upon approval of the badging application process and prior to starting work on the contract, applicants whose official station is located within 50 miles from CMS’ central office or one of its regional offices will be contacted to appear in person, at least two times (estimated at one hour for each visit), and shall provide two (2) original forms of identity source documents in order to generate the badge/ID. The identity source documents shall come from the list of acceptable documents included in FIPS 201-2, located at http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.201-2.pdf. At least one (1) document shall be a valid State or Federal government-issued picture ID. PIV-I mobile enrollment stations will be made available for applicants that have an official station more than 50 miles from CMS or any of its regional offices, and the employee will not need to travel to a CMS Office. The Contractor will be contacted by CMS for further instructions on the badging process in this scenario.
CMS Position Designation Assessment CMS will assign a risk and sensitivity level designation analysis to the overall contract and/or to Contractor employee positions by category, group or individual. The risk and sensitivity level designations will be the basis for determining the level and type of personnel security investigations required for Contractor employees. At a minimum, the FBI National Criminal History Check (fingerprint check) must be favorably adjudicated. Additionally, the OPM e-QIP and other required forms must be accepted by DPS before a CMS identification card will be issued.
Post Badging Training Requirements:
Contractor employees that receive an HHS ID Badge are expected to complete the following online trainings each year, according to the timeframes indicated below, and annually thereafter. The below list is not all inclusive and the COR may indicate training that must be taken in addition to the below:
| Security and Insider Threat Awareness and Training (30 days after receiving badge): This course outlines the role of Contractors with regard to protecting information and ensuring the secure operation of CMS federally controlled information systems. Estimated time to complete is one hour. |
| Computer Based Training (CBT) (within 3 days of approved EUA account): This training offers several modules to familiarize contractor employees with features of CMS’ webinar service. Estimated time to complete is one hour. |
Background Investigation and Adjudication
Upon contract award and receipt of an HHS ID Badge Request, CMS will initiate the Agency Access procedures, to include a background investigation.
CMS may accept favorable background investigation adjudications from other Federal agencies when there has been no break in service. A favorable adjudication does not preclude CMS from initiating a new investigation when deemed necessary. Each CMS sponsored Contractor shall use the OPM e-QIP system to complete any required investigative forms.
The Contractor remains fully responsible for ensuring contract performance pending completion of background investigations of Contractor personnel. Employees that do not require access to CMS federally controlled information systems, facilities, or sensitive information in order to perform their duties may begin work on a contract immediately and need not submit an HHS ID Badge Request.
| Failure to cooperate with OPM or Agency representatives during the background investigation process is considered grounds for removal from the contract. |
| DPS may provide written notification to the Contractor employee, with a copy to the COR, of all suitability/non-suitability decisions. A CMS adjudicative decision (based on criminal history results or completed investigation results) is final, and is not subject to appeal. |
| Contractor personnel for whom DPS determines to be ineligible for ID issuance will be required to cease working on the contract immediately. |
| The Contractor shall immediately submit an adverse information report, in writing to the CO with a copy to the COR, of any adverse information regarding any of its employees that may impact their ability to perform under this contract. Reports should be based on reliable and substantiated information, not on rumor or innuendo. The report shall include, at a minimum, the Contractor employee's name and associated contract number along with the adverse information. The COR will forward the adverse information report to the DPS for review and/or action. |
| At the Agency’s discretion, Contractor personnel may be provided an opportunity to explain or refute unfavorable information before an adjudicative decision is rendered on whether or not to withdraw the Federal ID from the individual in question. Under the provision of the Privacy Act of 1974, Contractor personnel may request a copy of their own investigation by submitting a written request to the OPM Federal Investigative Services (FIS) Freedom of Information (FOI) office. The following OPM-FOI link is being provided to afford one the instructions for obtaining a copy of one’s file: https://www.opm.gov/investigations/freedom-of-information-and-privacy-act- requests/. |
Background Investigation Cost
The government will bear the cost of background investigations that are performed at the direction of CMS’ personnel security representatives by the Federal government’s approved and designated background investigation service provider, the OPM.
At the Agency's discretion, if an investigated Contractor employee leaves the employment of the Contractor, or otherwise is no longer associated with the contract within one (1) year from the date the background investigation was completed, the Contractor may be required to reimburse CMS for the full cost of the investigation. Depending upon the type of background investigation conducted and the cost incurred by CMS, the Contractor cost will be determined based upon the current OPM fiscal year billing rates, which can be found at http://www.opm.gov/investigations/background-investigations/federal-investigations- notices. The amount to be paid by the Contractor shall be due and payable when the CO submits a written letter notifying the Contractor as to the cost of the investigation. The Contractor shall pay the amount due within thirty (30) days of the date of the CO's letter by check, made payable to the "United States Treasury." The Contractor shall provide a copy of the CO's letter as an attachment to the check and submit both to the Office of Financial Management at the following address:
Centers for Medicare & Medicaid Services PO Box 7520 Baltimore, Maryland 21207
Identification Card Custody and Control
The Contractor is responsible for the custody and control of all forms of Federal identification issued by CMS to Contractor employees. The Contractor shall immediately notify the COR when a Contractor employee no longer requires agency access due to transfer, completion of a project, retirement, removal from work on the contract, or termination of employment. Return all CMS Federal ID cards to:
The Centers for Medicare and Medicaid Services Attn: DPS, Mailstop: SL-17-06 7500 Security Boulevard Baltimore, Maryland 21244
The Contractor shall also ensure that Contractor employees comply with CMS requirements concerning the renewal, loss, theft, or damage of an ID card.
Failure to comply with the requirements for custody and control of CMS issued ID cards may result in a delay in withholding final payment or contract termination, based on the potential for serious harm caused by inappropriate access to CMS facilities, sensitive information, information systems or other CMS resources.
Renewal: A Contractor employee’s CMS issued ID card is valid for a maximum of five (5) years and 9 months or until the contract expiration date (including option periods), whichever occurs first. The renewal process should begin six weeks before the ID card expiration date by contacting the COR. If an ID card is not renewed before it expires, the Contractor employee will be required to sign-in daily for facility access and may have limited access to information systems and other resources. Contractor ID card certificate(s) require yearly updates from the issuance date. The yearly updates should be coordinated between the contractor and the COR.
Lost/Stolen: Immediately upon detection that an ID card is lost or stolen, the Contractor or Contractor employee shall report a lost or stolen ID card to the COR and the local security servicing organization at SECURITY@cms.hhs.gov. The Contractor shall also submit an Incident Report within 48 hours, to the COR, DPS at Badging@cms.hhs.gov, and the local security servicing organization. The Incident Report shall describe the circumstances of the loss or theft. If the loss or theft is reported by the Contractor to the local police, a copy of the police report shall be provided to the COR. The Contractor employee shall sign in daily for facility access and may have limited access to information systems and other resources until the replacement card is issued.
Replacement: An ID card will be replaced if it is damaged, contains incorrect data, or is lost or stolen for more than three (3) days, provided there is a continuing need for agency access to perform work under the contract.
In the event that the PIV card or certificate(s) are not renewed in a timely fashion, or the ID card requires replacement due to being lost, stolen, or damaged, the contractor employee will go through the “Badge Issuance” process again as described in above in section (c)(2). In any of these events, contact your COR to coordinate the appropriate next steps.
i. Surrender ID Cards/Access Cards, Government Equipment
CMS reserves the right to suspend or withdraw ID card access at any time for any reason. Access will be restored upon the resolution of the issue(s).
Upon notification that routine access to CMS facilities, sensitive information, federally controlled information systems or other CMS resources is no longer required, the Contractor shall surrender the CMS issued ID card, access card, keys, computer equipment, and other government property to the CMS COR or directly to CMS at the address referenced above in section (f). DPS Contractor personnel who do not return their government issued property within 48 hours of the last day of authorized access to CMS, may be permanently barred from CMS systems and facilities and may be subject to fines and penalties, as authorized by applicable Federal or State laws.
File details come from the government source that posted it. Updated .