MS submission and tracking SOW Attachment I.pdf

PDF 340 KB Posted

Attached to
Manuscript Submission and Tracking System - Sources Sought Federal contract opportunity
Solicitation number
75N96021Q00004
Issued by
Department of Health and Human Services National Institutes of Health National Institute of Environmental Health Sciences

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

////////////yATTACHMENT I – STATEMENT OF WORK (SOW)

ENVIRONMENTAL HEALTH PERSPECTIVES

MANUSCRIPT SUBMISSION AND TRACKING SYSTEM

NATIONAL INSTITUTE OF ENVIRONMENTAL HEALTH SCIENCES

RESEARCH TRIANGLE PARK, NORTH CAROLINA

1. BACKGROUND: The National Institute of Environmental Health Sciences (NIEHS) publishes the monthly scientific journal Environmental Health Perspectives (EHP). EHP is a world-renowned journal that helps the National Institute of Environmental Health Sciences (NIEHS) to implement its strategic plan of advancing science and improving health. EHP disseminates cutting-edge research throughout the scientific community. The name EHP is synonymous with quality due to years of hard work from its dedicated team.

EHP is a fully open-access (OA) journal that charges no author fees or page charges, and yet still produces and distributes high quality, composed, peer reviewed, and edited content. EHP is also an online-only journal; this distribution model keeps EHP content accessible to all authors and readers, and keeps the journal at the forefront of the publishing landscape. The journal is made available for free (Open Access, http://www.plos.org/about/open-access) online at https://www.EHPonline.org. EHP provides Advance Publication versions of papers upon acceptance and deposits their content into PubMed Central. EHP publishes 12 issues per year, in a monthly format. Each issue consists of both Research and original News content. This diversity of content helps EHP to reach a broad audience, from researchers and clinicians to policymakers and citizen scientists.

2. OBJECTIVES: The flow of new manuscripts is vital to the life of a journal. Without content, a publication cannot succeed. The manuscript submission and tracking system is the first interface that an author is presented with once they have decided to submit to the journal, so it is critical that they have a positive user experience.

Likewise, the journal staff and its contractors must interface with this system on a daily basis to keep work moving between the editorial office, the Associate Editors, Reviewers, and the authors themselves. Any breakdowns or inefficiencies will be felt by a vast number of parties and could delay the sensitive metric of time to publication.

This document outlines the requirements of a manuscript submission and tracking system for EHP, and the company that will support it.

3. TASKS: The Government will not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the contractor who, in turn is responsible to the Government. The contractor, in turn, shall be accountable to the Government for contractor personnel, subcontractors, or contract service providers. The contractor shall provide the following services:

3.1 Technical Requirements

The following technical requirements must be met in order for the system to be considered for use by EHP. Any systems that do not substantively meet these requirements will not be considered for use.

1. The system shall accept manuscripts in both Microsoft Word and TeX (LaTeX and RevTeX, for example, and their associated BibTex and style files) formats and successfully build them into a preview PDF with other file formats automatically.

2. The system shall accept a wide variety of figure file formats, including PDF, TIFF, EPS, BMP, and JPG, and shall successfully build them into a preview PDF with the manuscript and other file formats automatically.

3. The system shall accept supplemental material uploads from authors: these will include text documents, figures, tables, video, audio, and data sets, among others. There shall be no restrictions on the file types that authors can provide, but EHP shall be able to restrict file types as it chooses for certain types of uploads. These materials shall also be accessible to all Editors and Reviewers during the peer review process.

http://www.plos.org/about/open-access) http://www.plos.org/about/open-access) https://www.ehponline.org/

4. The system shall have the ability for EHP to build custom submission questions and fields for authors, and to make changes to these questions directly without intervention from the provider’s technical support staff.

5. The system shall allow EHP to define required metadata fields, both during initial setup of the product and during the normal use of the product, without intervention from the provider’s technical support staff.

6. The system shall offer a role-based permissions system for users, so new users can be assigned permissions to perform their job function quickly and easily.

7. The system shall log email correspondence sent to the editors, reviewers, and authors, including attachments (of any file type).

8. The system shall track all dates associated with the submission, peer review, and acceptance of the paper.

9. The system shall provide a mechanism for creating and using email templates for each peer review and production task. These emails shall allow for the use of hyperlinks and merge data to automatically pull relevant manuscript metadata (titles, authors, manuscript number, digital object identifier (DOI)) into the email templates.

10. The system shall allow user self-service options for updating contact information and resetting passwords.

11. The system shall be capable of sending automated reminder messages to authors, editors, associate/deputy editors, and reviewers on a schedule that is defined by EHP. Configuration options must allow these reminders to be sent both before and after the assignment is due.

12. The system shall have a robust administration portal to ensure that EHP can directly modify the workflow, author upload requirements, article types, and various staff interfaces.

13. The system shall allow easy assignment of peer review tasks to reviewers and Associate/Deputy Editors.

14. The system shall contain an integrated Production module to track and administer production tasks after manuscript acceptance.

15. The system shall allow reviewers and Editors to be able to insert dates when they will be unavailable to participate in reviews, and shall restrict the flow of new assignments to them during these times.

16. The system shall be capable of exporting manuscript files (Word or TeX documents, figures, supplemental materials, and all associated files) in a Zip bundle, along with XML metadata (JATS XML shall be supported) and transmitting it as a bundle via ftp/sftp to an external server.

17. The system shall allow EHP to define the production workflow steps and allow EHP to directly modify those steps as needed. The system shall also provide an overview of all manuscripts in production, with relevant dates of completion for each step.

18. The system shall provide the ability to directly upload manuscripts to the iThenticate/CrossCheck system. There shall be options for both automatic upload of all content, and manual upload of selected manuscripts only. The resulting “similarity score” shall be displayed within the user interface of the system.

19. A system for compiling articles into an issue shall be included in the production module.

20. The system shall include a People database for allowing users to register and keep basic contact and login information on file. It shall also allow for a data transfer from the People database of our current system (Editorial Manager), ensuring that accounts and roles for current users are transferred to the new system.

21. The system shall have custom flags for both manuscripts and people.

22. The system shall be capable of assigning DOIs to all articles, using the preferred format of the publisher.

23. Open Researcher and Contributor ID (ORCiD) integration is required. Authors shall be able to key-in and lookup their ORCiD IDs (and the IDs of their co-authors) from within the submission interface, and users shall also be allowed to log into the system using their ORCiD IDs.

24. The system shall provide Ringgold integration. Authors shall be able to select their institution from the Ringgold database during submission of their paper.

25. The system shall support Co-author verification, whereby co-authors will be prompted by the system via email to confirm that they have acted as an author on the uploaded manuscript.

26. The system shall be web-based and hosted by the provider (either directly or via a hosting agreement)

– NIEHS will not host this system on our servers. As a web-based system, uptime is critical, so scheduled maintenance periods shall be communicated to the government well in advance, and unscheduled maintenance periods shall be kept to a minimum.

27. The system shall provide a robust reporting system. The reporting system shall offer both pre-configured reports and the ability to create ad-hoc reports. Such reports shall be run and delivered to users on a schedule.

28. The provider shall include an online Help system for users, with documentation on all major features.

Help videos shall also be provided for major features and shall also be accessible online.

29. All historic manuscript data and metadata from the current system (Editorial Manager) shall be preserved in any new system, and shall be accessible and reportable as “live” data in the new system via the normal workflow and reporting interfaces.

30. The system shall have the ability to reverse feed data from outside providers (composition systems, web hosts, data aggregators). This shall be a fully electronic mechanism whereby data/metadata files and packages can be delivered to the platform via automated means and ingested without follow-up action by the outside provider.

31. The system shall not impose hard file-size limits on the upload of any materials, including but not limited to manuscripts, figures, and supplemental materials. Publisher controls that allow EHP to set such limits for itself are encouraged, but the platform nor provider shall impose restrictions of the size of the files that can be attached to a manuscript record. Any system that imposes such restrictions on the publisher will not be considered.

32. The platform provider is free to implement an archive policy for manuscript files, but files shall not be archived prior to one (1) year from the paper’s acceptance date. The provider shall provide file restoration services upon request from EHP, and there shall be no charge to EHP for up to ten (10) restoration requests per contract year; additional requests beyond this may be billed at the provider’s nominal rate. Restored files shall remain on the platform for a minimum of thirty (30) days before they can be re-archived. Manuscript metadata shall not be subject to the archive policy and shall remain live on the platform at all times.

33. The system shall support invited/proposed manuscripts initiated by EHP and provide EHP the ability to define specific metadata and requirements for these manuscripts. These invited manuscripts shall follow the same review and production steps in the submission system as submitted manuscripts.

34. The platform shall support integration with preprint servers bioRxiv and medRxiv (at a minimum), allowing authors to submit papers to EHP directly from those systems into the platform.

35. The system shall support the ability to rate both papers and those involved in the review process for quality. The ability for the journal to customize and define when and how papers, editors, and reviewers are rated would be preferred. Alternatively, the system can support the following areas without customization:

a. Rating the quality of the original manuscript, and the ability to provide a separate rating for revisions.

b. Rating the performance of the Associate Editor on their handling of the manuscript.

c. Allowing subordinate editors (such as Associate Editors) to rate both the quality of the manuscript and the quality of the reviews.

36. The system shall also be Section 508 compliant. See Section XYZ below for additional information and the applicable 508 standards.

3.1 Customer Service

Robust and responsive customer service is essential to the success of any product. Questions and problems always occur, and timely, accurate responses shall be provided in those scenarios. A Project Manager/Customer Support contact shall be assigned to the EHP account at all times, and direct phone and email contact information for this individual (and for a backup) shall be provided to the government.

The Project Manager shall be available for routine status calls with EHP staff, no more than once per month for up to one (1) hour, to discuss performance issues with the system and/or customer service representatives.

In the event that the NIEHS EHP support contact will change, at least two (2) weeks’ notice shall be provided to the government. In addition, the government reserves the right to request that a new customer service representative be assigned to EHP’s account if EHP finds performance of the assigned representative to be in question.

In order to make the best use of the system, EHP staff will require ongoing training. The vendor shall supply up to eight (8) hours of remote (WebEx, Zoom, or equivalent) general training per contract year, and additionally up to eight (8) hours of remote (WebEx, Zoom, or equivalent) training per contract year focused on utilizing the reporting functionality (both basic and advanced) of the system. The training schedule and material to be covered shall be worked out between the Project Manager and EHP staff, but training does not need to be conducted by the Project Manager; the vendor is free to identify the individual most qualified to conduct the training. The vendor may expect each training session to be attended by multiple EHP staff members (no more than 6 participants per session).

The Project Manager/Customer Support rep shall also be available to design up to six (6) custom reports for EHP per year, based on requirements provided by EHP staff. These reports shall be continuously available in the system, and editable by EHP.

There shall be no per-incident charges to EHP for contacting the provider’s Customer Support, or for any training or support functions described in this section.

3.3 Experience with Scholarly/Scientific Publishers

The scholarly and scientific publishing landscape is far different from the commercial publishing landscape and contains significantly different requirements. EHP seeks to partner with a company that has significant experience catering directly to the needs of scholarly and scientific journal publishers.

Companies offering systems that have been inadequately repurposed from commercial needs will not be considered (“inadequate” being defined as not meeting the technical needs required in this statement of work).

4. QUALITY CONTROL: The Government is committed to a highly interactive relationship between quality control by the contractor and quality assurance by the government recipient of services. This relationship shall be achieved through an effective prevention based quality control program dedicated to ensuring the best possible products and services to end users. The Quality Control Plan (QCP) shall be updated five (5) days after contract award. The QCP shall document how the contractor intends on meeting and complying with the quality standards established in this PWS. At a minimum, the QCP shall include a self-inspection plan, an internal staffing plan, and an outline of the procedures that the contractor will use to maintain quality, timeliness, responsiveness, customer satisfaction, and any other requirements set forth in this PWS.

The contractor’s QCP shall be maintained throughout the life of the contract and shall include the contractor’s procedures to routinely evaluate the effectiveness of the plan to ensure the contractor is meeting the performance standards and requirements of the contract.

5. SECTION 508 COMPLIANCE: All content published in EHP must be Section 508 accessibility guidelines as defined by the federal government. Please see the following URLs for details:

• Section 508 Information: http://www.section508.gov/

• Guide to the Section 508 Standards: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards

• Making Files Accessible: http://www.hhs.gov/web/section-508/making-files-accessible/index.html

NOTE: If the deliverable includes features and functions in addition to those identified as requirements, these features and functions also need to conform to relevant Section 508 technical provisions, functional performance criteria, and information, documentation and support.

6. PHASE-IN/PHASE-OUT PERIOD: EHP seeks to have this system in place no later than January 1, 2021, or earlier if transitioning to a new system (as an appropriate overlap period will be required). The system will be administered by EHP staff and contractors, and initial training will need to be provided to http://www.section508.gov/ https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards http://www.hhs.gov/web/section-508/making-files-accessible/index.html this group prior to EHP going live with it. Training materials shall include documentation, web-based information, and remote-learning instructional classes.

7. OTHER CONSIDERATIONS

• Restriction on contractor’s use of or dissemination of databases: Mailing lists either furnished to the contractor by the COR or prepared by the contractor as part of its continuing efforts to support the journal are protected by the Privacy Act, and shall not be used by the contractor or any other third party for any purposes other than for the expressed purpose of this contract. Mailing lists provided as part of this contract shall not be disseminated to other persons or entities, except the COR and EIC, and shall not be used by the contractor, its subcontractors, or any other organization of persons for any purpose other than the services specifically described by the SOW and contract document. The contractor shall ensure that all subcontracts and consultant agreements in support of this contract include this restriction.

• Privacy Act Notice: This PWS requires the Parties to do one or more of the following: design, develop, or operate a system of records on individuals to accomplish an agency function in accordance with the Privacy Act of 1974, Public Law 93-579, December 31, 1974 (5 USC 552a) and applicable agency regulations. Violation of the Act may involve the imposition of criminal penalties. The Privacy Act System of Records applicable to this project is Number 09-90-0024.

8. DATA RIGHTS: The Government has unlimited rights to all documents/material produced under this contract to the extent permitted by the data rights clauses. The parties mutually acknowledge their understanding that this is the government’s intent. All documents and materials, to include the source codes of any software, if applicable, produced under this contract shall be government owned and are the property of the government with all rights and privileges of ownership/copyright belonging exclusively to the government. These documents and materials may not be used or sold by the contractor without written permission from the contracting officer. All materials supplied to the Government will be the sole property of the government and may not be used for any other purpose. This right does not abrogate any other government rights.

9. PERIOD OF PERFORMANCE: The requirement has a five (5) year ordering period. The ordering period includes a one (1) month phase-in period. Individual task orders issued cannot exceed a 12 month period.

9.1 Phase-In/Phase-Out Period: To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the contractor shall have personnel on board during the 30 day Phase-In, and for up to 6 months during Phase-Out. During the phase in period, the contractor shall become familiar with performance requirements in order to commence full performance of services on the contract start date. The contractor shall prepare to assume full responsibility for all areas of operation in accordance with the terms and conditions of this contract. The contractor shall take all actions necessary for a smooth transition of the contracted support operations. Transition requirements are as follows:

• Publication of EHP online shall proceed on schedule and without interruption.

• Live work will be assigned to the contractor during the phase-in period, but the deadlines specified in Sec.

4.3 will not be enforced during phase-in.

• In order to minimize the disruption of service for any follow-on contract, the incumbent shall participate with the successor contractor and the contract officer representative (COR) in an orderly transfer of services for any follow-on contract. It is anticipated that a 30 day transition period is set aside at the end of the routine performance period for the phase-out of the contractor’s performance. Any resulting contract from this SOW shall include the phase-out transition period in the established completion date. During the transition period, the incumbent shall prepare transition reports and documents which shall describe the status of translation efforts, as well as any outstanding issues that a new contractor shall need to know in order to continue service of the publication with minimal disruption.

• All electronic and print documentation and materials developed under the contract (including applications, databases, and intellectual property) shall be transferred, as directed by the COR, to the successor or the NIEHS.

10. HOURS OF OPERATION: The contractor shall be responsible for providing routine services between the core hours of 8:00 AM – 5:00 PM Eastern time Monday through Friday, except federal holidays or when the government facility is closed due to local or national emergencies, administrative closings or similar government directed facility closings. All responses to queries from EHP staff and authors, reviewers, and associate editors must be issued in a timely manner, usually the same business day. The contractor shall at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this SOW when the government facility is not closed for the above reasons. When hiring personnel, the contractor shall keep in mind that the stability and continuity of the workforce are essential. No overtime (OT) or compensatory time (CT) is authorized under this contract.

10.1. Federal Holidays: The National Institutes of Environmental Health Sciences observes the following holidays:

• New Year’s Day Labor Day

• Martin Luther King’s Birthday Columbus Day

• Presidents Day Veteran’s Day

• Memorial Day Thanksgiving Day

• Independence Day Christmas Day

11. PLACE OF PERFORMANCE: The management office place of performance, and the place of performance for EHP’s customer support representative, shall be anywhere in the United States.

Additionally, writers and podcast hosts can be anywhere in the United States, as these positions require high-level language skills due to the customer support requirement. Any other personnel involved in the contract outside of these particular positions, can be anywhere in the world as long as they are available in the required times of operations so as not to delay any contract requirement to the Government.

12. CONTRACTOR PERSONNEL: The contractor shall provide personnel who are qualified to provide all services and work in a professional and courteous manner. Contractor personnel shall abide by applicable regulations, NIEHS rules and procedures, and present a neat appearance if working at NIEHS locations. Contract staff shall demonstrate the following proficiencies:

• Curating original scientific content for publication in a scholarly journal.

• Establishing and maintaining a network of professional writers qualified to author content that deals with complicated scientific and policy matters.

• Experience seeking appropriate graphical and image content for use with scientific materials.

• Demonstrated experience working with items under copyright, reading and interpreting contracts and licenses, and discussing contracts and licensing terms with customers who are not contracts and copyright experts.

• Demonstrated pre-existing network of original artists and photographers capable of providing professional, original content suitable for publication in a scholarly journal.

• Demonstrated experience managing the generation of original audio content for publication on the web.

12.1 KEY PERSONNEL: Qualified personnel shall be provided by the Contractor for performance of work listed herein to assure that requests for services are responded to in a prompt and safe manner. The following will be considered key personnel by the Government:

12.1.1 Central Customer Support Representative: The representative shall act as a single point of contact for all inquiries from the journal.

- Qualifications: A minimum of a High school diploma and a minimum of 2 years of customer service experience. Shall demonstrate strong customer service abilities and experience working with scholarly authors, researchers, translators, and reviewers.

13. GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES: This section identifies those items such as property, information and/or services that will be provided for the contractor’s use (without cost to the contractor) to allow the contractor to provide the required services, such as materials, facilities, training, etc. as follows:

• Facilities: The Government shall not furnish workspace, workstations, computers.

• Materials: The Government will not provide Standard Operational Procedures (SOPs), applicable regulations, manuals, texts, briefs or any other materials associated with these projects.

• Training: The Government will not provide any training, management, or accountability for contractor’s staff beyond the initial guidance given during initial setup, and the ongoing feedback that is provided throughout the course of the contract.

14. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES: The contractor shall furnish all supplies, equipment, and services required to perform work under this contract that are not listed under section 13 of this PWS.

• Items: The contractor shall provide all required hardware, software, licenses, internet access, etc., along with all necessary support, to perform this work. The Government shall not provide any equipment, materials, or technical support. The contractor will not have access to the NIEHS network or email accounts.

• Security/Security Log: The contractor shall maintain the security and integrity of their systems at all times. This includes promptly installing updates to mitigate security threats, actively testing all software releases for potential security holes, and promptly informing customers of known or suspected data breaches.

15. SECURITY

15.1 Baseline Security Requirements

1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

2) Safeguarding Information and Information Systems. In accordance with the Federal

Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity;

and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the

HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed..

3) Information Security Categorization. In accordance with FIPS 199 and National Institute of

Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [ X ] Low [ ] Moderate [ ] High Integrity: [ X ] Low [ ] Moderate [ ] High Availability: [ X ] Low [ ] Moderate [ ] High Overall Risk Level: [ X ] Low [ ] Moderate [ ] High

Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[ X ] No PII [ ] Yes PII

4) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.

5) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its mailto:fisma@hhs.gov http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and NIH policies. Unauthorized disclosure of information will be subject to the HHS/NIH sanction policies and/or governed by the following laws and regulations:

a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

6) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).

7) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.

8) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents provided by NIH or NIEHS to comply with contract deliverables as appropriate.

9) Standard for Encryption. The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information

[PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140- 2 validated encryption solution.

c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and NIH-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use have been validated under the Cryptographic

Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR within 15 days of implementation.

e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to the COR upon request and at the conclusion of the contract.

http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf

10) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the NIH non-disclosure agreement. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.

11) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the NIEHS Privacy Coordinator or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a full PIA needs to be completed.

a. If the results of the PTA show that a full PIA is needed, the Contractor shall assist the

NIEHS Privacy Coordinator or designee with completing a PIA for the system or information within 30 days after completion of the PTA and in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002.

b. The Contractor shall assist the NIEHS Privacy Coordinator or designee in reviewing the

PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.

15.2 Incident Response

The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/NIEHS ISSO teams within 24 hours, whether the response is positive or negative.

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for any other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.

In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:

1) Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.

2) NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send notifications approved by the NIEHS ISSO and NIEHS Privacy Coordinator to affected individuals within 1 business day of communication approval.

3) Report all suspected and confirmed information security and privacy incidents and breaches to the NIEHS ISSO Team isso@niehs.nih.gov, COR, CO, NIH SOP (or his or her designee), and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour, and consistent with the applicable NIH and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:

c. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;

d. not include any sensitive information in the subject or body of any reporting e-mail; and

e. encrypt sensitive information in attachments to email, media, etc.

4) Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally

Identifiable Information HHS/NIH and NIEHS incident response policies when handling PII breaches.

5) Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation.

15.3 Contract Initiation and Expiration

1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology or related NIH guidance and in accordance with the HHS Contract Closeout Guide (2012).

2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.

3) Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

4) Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO within 3 business days before an employee stops working under this contract.

mailto:isso@niehs.nih.gov

5) Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR.

Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or NIH policies.

6) The Contractor (and/or any subcontractor) shall perform and document the actions identified in the NIH Contractor Employee Separation Checklist when an employee terminates work under this contract within 3 business days of the employee’s exit from the contract. All documentation shall be made available to the CO and/or COR upon request.

15.4 Records Management and Retention

The Contractor (and/or any subcontractor) shall maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS/NIH/NIEHS policies and shall not dispose of any records unless authorized by HHS/NIH/NIEHS.

In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS/NIH/NIEHS policies

15.5 Security Requirements for GOCO and COCO Resources

1) Federal Policies. The Contractor (and/or any subcontractor) shall comply with applicable federal laws that include, but are not limited to, the HHS Information Security and Privacy Policy (IS2P), NIH and NIEHS policies; Federal Information Security Modernization Act (FISMA) of 2014, (44 U.S.C. 101); National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations; Office of Management and Budget (OMB) Circular A-130, Managing Information as a Strategic Resource; and other applicable federal laws, regulations, NIST guidance, and Departmental policies.

2) Security Assessment and Authorization (SA&A). A valid authority to operate (ATO) certifies that the Contractor’s information system meets the contract’s requirements to protect the agency data. If the system under this contract does not have a valid ATO, the Contractor (and/or any subcontractor) shall work with the agency and supply the deliverables required to complete the ATO within 15 days following the beginning of work on the contract. The Contractor shall conduct the SA&A requirements in accordance with HHS IS2P/NIH requirements, NIST SP 800- 37, Guide for Applying the Risk Management Framework to Federal Information Systems:

A Security Life Cycle Approach (latest revision).

NIH/NIEHS acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the system security and privacy controls are implemented and operating effectively.

a. SA&A Package Deliverables - The Contractor (and/or any subcontractor) shall provide an

SA&A package within 15 days following the beginning of work on the contract to the CO and/or COR. The following SA&A deliverables are required to complete the SA&A package:

• System Security Plan (SSP) – due to the NIEHS ISSO isso@niehs.nih.gov within 15 days following the beginning of work on the contract. The SSP shall comply with the NIST SP 800- 18, Guide for Developing Security Plans for Federal Information Systems, the Federal mailto:isso@niehs.nih.gov

Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline requirements, and other applicable NIST guidance as well as HHS and NIH policies and other guidance. The SSP shall be consistent with and detail the approach to IT security contained in the Contractor’s bid or proposal that resulted in the award of this contract. The SSP shall provide an overview of the system environment and security requirements to protect the information system as well as describe all applicable security controls in place or planned for meeting those requirements. It should provide a structured process for planning adequate, cost-effective security protection for a system. The Contractor shall update the SSP at least annually thereafter.

• Security Assessment Plan/Report (SAP/SAR) – due 15 days following the beginning of work on the contract. The security assessment shall be conducted by an assessor appropriate with the scale of the contract and be consistent with NIST SP 800-53A, NIST SP 800-30, and HHS and NIH policies. The assessor will document the assessment results in the SAR.

Thereafter, the Contractor, in coordination with NIH shall conduct the assessment of the security controls and update the SAR at least annually.

• POA&M – due 30 days following the beginning of work on the contract. The POA&M shall be documented consistent with the HHS Standard for Plan of Action and Milestones and NIH policies. All high-risk weaknesses must be mitigated within 30 days and all medium weaknesses must be mitigated within 75 days. from the date the weaknesses are formally identified and documented. NIH will determine the risk rating of vulnerabilities.

Identified risks stemming from deficiencies related to the security control baseline implementation, assessment, continuous monitoring, vulnerability scanning, and other security reviews and sources, as documented in the SAR, shall be documented and tracked by the Contractor for mitigation in the POA&M document. Depending on the severity of the risks, NIH or NIEHS may require designated POAM weaknesses to be remediated before an ATO is issued. Thereafter, the POA&M shall be updated at least quarterly.

• Contingency Plan and Contingency Plan Test – due 30 days following the beginning of work on the contract. The Contingency Plan must be developed in accordance with NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, and be consistent with HHS and NIH policies. Upon acceptance by the System Owner, the Contractor, in coordination with the System Owner, shall test the Contingency Plan and prepare a Contingency Plan Test Report that includes the test results, lessons learned and any action items that need to be addressed.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .