Parking Services Solicitation 70B01C20R00000038.docx
DOCX document 210 KB Posted
- Attached to
- New Orleans Parking Services Federal contract opportunity
- Solicitation number
- 70B01C20R00000038
About this file
This solicitation requests proposals for parking services in New Orleans, Louisiana. The contractor shall provide both garage parking and open-air parking on a 24/7 basis for Customs and Border Protection employees working at 423 Canal Street. Parking must be convenient and safe for employees and able to accommodate vehicles near the work location. Proposals are due by March 12, 2020. The potential contract period is one base year with two one-year options, running from April 2020 through March 2023. Pricing details and vehicle quantities are included. The soliciting agency is the Department of Homeland Security Customs and Border Protection.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 70B01C20R00000038 Attachment 1-New Orleans Parking Services Statement of Work.docx | DOCX document | |
| 70B01C20R00000038 Attachment 3- New Orleans Parking Services Past Experience Questionnaire .docx | DOCX document | |
| 70B01C20R00000038 Attachment 2-New Orleans Parking Services Price Sheet..xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Solicitation 70B01C20R00000038
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
1. REQUISITION NUMBER
2. CONTRACT NO.
3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER
5. SOLICITATION NUMBER
70B01C20R00000038
6. SOLICITATION ISSUE DATE
02/28/2020
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
Joseph Ohene
b. TELEPHONE NUMBER(No collect calls) Email Joseph.Ohene@cbp.dhs.gov
8.OFFER DUE DATE/ 03/12/2020 LOCAL TIME 1 PM EST
July 19, 2013 at 1 P.M. (local time)
| 9. ISSUED BY CODE |
| 7014 |
| 10. THIS ACQUISITION IS |
| |X| UNRESTRICTED OR |
| |_| SET ASIDE100:____ % FOR: |
Tržiště 15
118 01 Praha 1 - Malá Strana
| |_| SMALL BUSINESS |
| |_| WOMEN-OWNED SMALL BUSINESS |
DHS - Customs & Border Protection Customs and Border Protection 1300 Pennsylvania Ave, NW Procurement Directorate NP 1310
|_| HUBZONE SMALL
BUSINESS
|_| (WOSB) ELLIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM NAICS: 812930
Washington DC 20229
|_| SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
|_| EDWOSB
| |_| 8 (A) |
| SIZE STANDARD: |
11. DELIVERY FOR FOB DESTINAT-
TION UNLESS BLOCK IS
MARKED
|X| SEE SCHEDULE
| 12. DISCOUNT TERMS |
| |_| 13a. THIS CONTRACT IS A |
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
|_| RFQ |_| IFB |X| RFP
| 15. DELIVER TO |
| CODE |
| 16. ADMINISTERED BY |
| CODE |
DHS - Customs & Border Protection Customs and Border Protection 1300 Pennsylvania Ave, NW Procurement Directorate NP 1310
Washington DC 20229
17a. CONTRACTOR/
OFFERER
TELEPHONE NO.
CODE
FACILITY CODE
| 18a. PAYMENT WILL BE MADE BY |
| CODE |
|_|17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER
| 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK | |
| BELOW IS CHECKED | |_| SEE ADDENDUM |
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
New Orleans Parking Services (Reserved)
New Orleans Parking Services (Unreserved)
EA
EA
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA
26. TOTAL AWARD AMOUNT (For Govt. Use Only)
| |X| 27a.SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA |
| |X| ARE |_| ARE NOT ATTACHED |
| |_| 27b.CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA |
| |_| ARE |_| ARE NOT ATTACHED |
| |_| 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN ____ COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED HEREIN. |
| |_| 29. AWARD OF CONTRACT: REF. _________________ OFFER DATED ____________. YOUR OFFER ON SOLICITATION (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS: |
| 30a. SIGNATURE OF OFFEROR/CONTRACTOR |
| 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) |
30b. NAME AND TITLE OF SIGNER (Type or print)
30c. DATE SIGNED
31b. NAME OF CONTRACTING OFFICER (Type or print)
31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 1449 (REV. 2/2012)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
TABLE OF CONTENTS
| SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS | 1 | |
| SECTION 1 SCHEDULES | 3 | |
| I.1 | SCHEDULE OF SUPPLIES/SERVICES | 3 |
| I.2 | DELIVERY SCHEDULE | 3 |
| SECTION II | CONTRACT CLAUSES | 4 |
| II.1 | 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998) | 4 |
| II.2 | 52.204-18 COMMERCIAL AND GOVERNMENT ENTITY CODE MAINTENANCE (JUL 2016) | 4 |
| II.3 | 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (OCT 2018) | 4 |
| II.4 | 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS - COMMERCIAL ITEMS (JAN 2020) | 4 |
| II.5 | 52.203-19 PROHIBITION ON CONTRACTING WITH ENTITIES THAT REQUIRE CERTAIN INTERNAL CONFIDENTIALITY AGREEMENTS (JAN 2017) | 9 |
| II.6 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000) | 10 | |
| II.7 CONTRACTING OFFICER’S AUTHORITY (MAR 2003) | 10 | |
| II.8 ELECTRONIC INVOICING AND PAYMENT REQUIREMENTS- INVOICE PROCESSING PLATFORM (IPP) | 10 | |
| (JAN 2016) | 10 | |
| II.9 SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015) | 11 | |
| II.10 3052.204-71, CONTRACTOR EMPLOYEE ACCESS (SEP 2012) | 17 | |
| II.11 GOVERNMENT CONSENT OF PUBLICATION/ENDORSEMENT (MAR 2003) | 18 | |
| II.12 SECURITY PROCEDURES (APR 2019) | 18 | |
| II.13 DISCLOSURE OF INFORMATION (MAR 2003) | 20 | |
| II.14 NON-PERSONAL SERVICE (MAR 2003) | 20 | |
| II.15 | ADDITIONAL CONTRACTOR PERSONNEL REQUIREMENTS (OCT 2007) | 21 |
| II.16 | POST AWARD EVALUATION OF CONTRACTOR PERFORMANCE (JUL 2014) | 21 |
| II.17 | HOLIDAYS AND ADMINISTRATIVE LEAVE (MAR 2003) | 22 |
| SECTION III | SOLICITATION PROVISIONS | 23 |
| III.1 | 52.203-18 PROHIBITION ON CONTRACTING WITH ENTITIES THAT REQUIRE CERTAIN INTERNAL CONFIDENTIALITY AGREEMENTS OR STATEMENTS – REPRESENTATION (JAN 2017) | 23 |
| III.2 | 52.204-7 SYSTEM FOR AWARD MANAGEMENT (OCT 2018) | 23 |
| III.3 | 52.204-16 COMMERCIAL AND GOVERNMENT ENTITY CODE REPORTING (JUL 2016) | 23 |
| III.4 | 52.204-17 OWNERSHIP OR CONTROL OF OFFEROR (JUL 2016) | 23 |
| III.5 | 52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION SYSTEMS (JUN 2016) | 23 |
| III.6 | 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018) | 23 |
| III.7 | 52.209-12 - CERTIFICATION REGARDING TAX MATTERS (FEB 2016) | 23 |
| III.8 | 52.204-13 - SYSTEM FOR AWARD MANAGEMENT MAINTENANCE (OCT 2018) | 23 |
| III.9 | 52.232-40 - PROVIDING ACCELERATED PAYMENTS TO SMALL BUSINESS SUBCONTRACTORS (DEC 2013) | 23 |
| III.10 | 52.250-2 SAFETY ACT COVERAGE NOT APPLICABLE (FEB 2009) | 23 |
| III.11 | 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS--COMMERCIAL ITEMS (OCT 2018) | 23 |
| III.12 | TYPE OF CONTRACT (APR 1984) | 35 |
| III.13 | ADDENDUM TO FAR 52.212-1 INSTRUCTIONS TO OFFERORS--COMMERCIAL ITEMS (OCT 2018) | 35 |
| III.14 | FAR 52.212-2, EVALUATION – COMMERCIAL ITEMS (OCT 2014) | 38 |
| III.15 ADDENDUM TO FAR 52.212-2, EVALUATION – COMMERCIAL ITEMS (OCT 2014) | 38 |
SECTION 1 SCHEDULES
I.1 SCHEDULE OF SUPPLIES/SERVICES
10 New Orleans Parking Services 36 EA
20 New Orleans Parking Services 47 EA
SEE PRICE SHEET FOR DETAILED SCHEDULE
I.2 DELIVERY SCHEDULE
| Customs and Border Protection 1300 Pennsylvania Av, NW Washington, DC 20229 | 10 | 36 | TBD |
| 20 | 47 | TBD |
I.3 PERIOD OF PERFORMANCE (Based on Projected Award Date) (MAR 2003)
The period of performance of the anticipated contract is date of award through 1 year from date award, with two (2), one year option periods, resulting in a contract of up to three (3) years total, if all option periods are exercised in accordance with FAR 52.217-9 Option to Extend the Term of the Contract.
Base - April 1, 2020 to March 31, 2021
Option 1 - April 1, 2021 to March 31, 2022
Option 2 - April 1, 2022 to March 31, 2023
I.4 DESCRIPTION:
U.S. Customs and Border Protection (CBP) has identified the need for parking services in New Orleans. The contractor shall provide garage parking and open air (outdoor) parking on a 24/7 basis to Customs and Border Protection employees who work at 423 Canal St., New Orleans, LA 70130 building location.
Solicitation 70B01C20R00000038
SECTION II CONTRACT CLAUSES
II.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):
www.acquisition.gov
I. FEDERAL ACQUISITION REGULATION (48 CHAPTER 1) CLAUSES
NUMBER TITLE
II.2 52.204-18 COMMERCIAL AND GOVERNMENT ENTITY CODE MAINTENANCE (JUL 2016)
II.3 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (OCT 2018)
II.4 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS - COMMERCIAL ITEMS (JAN 2020)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
(1) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (Jul 2018) (Section 1634 of Pub. L. 115-91).
(2) 52.203–19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113–235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions))
(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (AUG 2019) (Section 889(a)(1)(A) of Pub. L. 115-232)
(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015)
(5) 52.233-3, Protest After Award (AUG 1996) (31 U.S.C. 3553).
(6) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108–77 and 108–78 (19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
[Contracting Officer check as appropriate]
[X] (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (SEP 2006), with Alternate I (OCT 1995) (41 U.S.C. 4704 and 10 U.S.C. 2402).
(2) 52.203-13, Contractor Code of Business Ethics and Conduct (OCT 2015) (41 U.S.C. 3509).
(3) 52.203-15, Whistleblower Protections Under the American Recovery and Reinvestment Act of 2009 (JUN 2010) (Section 1553 of Pub. L. 111-5). Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)
[X] (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (OCT 2018) (Pub. L. 109-282) (31 U.S.C. 6101 note).
[] (5) [Reserved].
[x] (6) 52.204-14, Service Contract Reporting Requirements (OCT 2016) (Pub. L. 111-117, section 743 of Div. C).
[X] (7) 52.209-6, Protecting the Government's Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment (OCT 2015) (31 U.S.C. 6101 note).
[X] (9) 52.209-9 Updates of Publicly Available Information Regarding Responsibility Matters (Oct 2018) (41 U.S.C. 2313 http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title41-section2313&num=0&edition=prelim).
[] (10) [Reserved].
[] (11) (i) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (NOV 2011) (15 U.S.C. 657a).
[] (ii) Alternate I (Nov 2011) of 52.219-3.
[] (12) (i) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (OCT 2014) (if the offeror elects to waive the preference, it shall so indicate in its offer) (15 U.S.C. 657a).
[] (ii) Alternate I (JAN 2011) of 52.219-4.
[] (13) [Reserved]
(14) (i) 52.219-6, Notice of Total Small Business Set-Aside (NOV 2011) (15 U.S.C. 644).
[] (ii) Alternate I (NOV 2011).
[] (iii) Alternate II (NOV 2011).
[] (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (JUN 2003) (15 U.S.C. 644).
[] (ii) Alternate I (OCT 1995) of 52.219-7.
[] (iii) Alternate II (MAR 2004) of 52.219-7.
[x] (16) 52.219-8, Utilization of Small Business Concerns (OCT 2018 (15 U.S.C. 637(d)(2) and (3)).
[] (17) (i) 52.219-9, Small Business Subcontracting Plan (AUG 2018) (15 U.S.C. 637(d)(4).
[] (ii) Alternate I (NOV 2016) of 52.219-9.
[x] (iii) Alternate II (NOV 2016) of 52.219-9.
[] (iv) Alternate III (JAN 2017) of 52.219-9.
[] (v) Alternate IV (JAN 2017) of 52.219-9.
[] (18) 52.219-13, Notice of Set-Aside of Orders (NOV 2011) (15 U.S.C. 644(r)).
[] (19) 52.219-14, Limitations on Subcontracting (JAN 2017) (15 U.S.C. 637(a)(14)).
[] (20) 52.219-16, Liquidated Damages--Subcontracting Plan (JAN 1999) (15 U.S.C. 637(d)(4)(F)(i)).
[] (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (NOV 2011) (15 U.S.C. 657f).
[] (22) 52.219-28, Post Award Small Business Program Rerepresentation (JUL 2013) (15 U.S.C. 632(a)(2)).
[] (23) 52.219-29, Notice of Set-Aside for, or Sole Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (DEC 2015) (15 U.S.C. 637(m)).
[] (24) 52.219-30, Notice of Set-Aside for, or Sole Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (DEC 2015) (15 U.S.C. 637(m)).
[X] (25) 52.222-3, Convict Labor (JUN 2003) (E.O. 11755).
[X] (26) 52.222-19, Child Labor--Cooperation with Authorities and Remedies (Jan 2020) (E.O. 13126).
[X] (27) 52.222-21, Prohibition of Segregated Facilities (APR 2015).
[X] (28) 52.222-26, Equal Opportunity (AUG 2018) (E.O. 11246)
[] (ii) Alternate I (FEB 1999) of 52.222-26.
[X] (29) 52.222-35, Equal Opportunity for Veterans (OCT 2015) (38 U.S.C. 4212)
[] (ii) Alternate I (JUL 2014) of 52.222-35.
[X] (30) 52.222-36, Affirmative Action for Workers with Disabilities (JUL 2014) (29 U.S.C. 793).
[X] (31) 52.222-37, Employment Reports on Veterans (FEB 2016) (38 U.S.C. 4212).
[X] (32) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (DEC 2010) (E.O. 13496).
[X] (33)(i) 52.222-50, Combating Trafficking in Persons (JAN 2019) (22 U.S.C. chapter 78 and E.O. 13627).
[] (ii) Alternate I (MAR 2015) of 52.222-50 (22 U.S.C. chapter 78 and E.O. 13627).
[] (34) 52.222-54, Employment Eligibility Verification (OCT 2015). (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial items as prescribed in 22.1803.)
[] (35)(i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA-Designated Products Items (MAY 2008) (42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
[] (ii) Alternate I (MAY 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
[] (36) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (JUN 2016) (E.O. 13693).
[] (37) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (JUN 2016) (E.O. 13693)
[] (38) (i) 52.223-13, Acquisition of EPEAT®-Registered Imaging Equipment (JUN 2014) (E.O.s 13423 and 13514).
[] (ii) Alternate I (OCT 2015) of 52.223-13.
[] (39) (i) 52.223-14, Acquisition of EPEAT®-Registered Televisions (JUN 2014) (E.O.s 13423 and 13514).
[] (ii) Alternate I (JUN 2014) of 52.223-14.
[] (40) 52.223-15, Energy Efficiency in Energy--Consuming Products (DEC 2007) (42 U.S.C. 8259b).
[] (41)(i) 52.223-16, Acquisition of EPEAT®-Registered Personal Computer Products (OCT 2015) (E.O.s 13423 and 13514).
[] (ii) Alternate I (JUN 2014) of 52.223-16.
[X] (42) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving (AUG 2011).
[] (43) 52.223-20, Aerosols (JUN 2016) (E.O. 13693).
[] (44) 52.223-21, Foams (JUN 2016) (E.O. 13693).
[] (45) (i) 52.224-3, Privacy Training (JAN 2017) (5 U.S.C. 552a).
[] (ii) Alternate I (JAN 2017) of 52.224-3.
[] (46) 52.225-1, Buy American—Supplies (MAY 2014) (41 U.S.C. chapter 83).
[] (47)(i) 52.225-3, Buy American—Free Trade Agreements—Israeli Trade Act (MAY 2014) (41 U.S.C. chapter 83, 19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, Pub. L. 103–182, 108–77, 108–78, 108–286, 108–302, 109–53, 109–169, 109–283, 110–138, 112–41, 112–42, and 112–43.
[] (ii) Alternate I (MAY 2014) of 52.225-3.
[] (iii) Alternate II (MAY 2014) of 52.225-3.
[] (iv) Alternate III (MAY 2014) of 52.225-3.
[x] (48) 52.225-5, Trade Agreements (OCT 2019) (19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note).
[x] (49) 52.225-13, Restrictions on Certain Foreign Purchases (JUN 2008) (E.o.s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).
[] (50) 52.225-26, Contractors Performing Private Security Functions Outside the United States (OCT 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).
[] (51) 52.226-4, Notice of Disaster or Emergency Area set-Aside (NOV 2007)
[] (52) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (NOV 2007)
[] (53) 52.232-29, Terms for Financing of Purchases of Commercial Items (FEB 2002) (41 U.S.C. 4505, 10 U.S.C. 2307(f)).
[] (54) 52.232-30, Installment Payments for Commercial Items (JAN 2017) (41 U.S.C. 4505, 10 U.S.C. 2307(f)).
[X] (55) 52.232-33, Payment by Electronic Funds Transfer--System for Award Management (OCT 2018) (31 U.S.C. 3332).
[] (56) 52.232-34, Payment by Electronic Funds Transfer--Other than System for Award Management (JUL 2013) (31 U.S.C. 3332).
[] (57) 52.232-36, Payment by Third Party (MAY 2014) (31 U.S.C. 3332).
[X] (58) 52.239-1, Privacy or Security Safeguards (AUG 1996) (5 U.S.C. 552a).
[ ] (59) 52.242-5, Payments to Small Business Subcontractors (JAN 2017)(15 U.S.C. 637(d)(12)
[] (60)(i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (FEB 2006) (46 U.S.C. Appx. 1241(b) and 10 U.S.C. 2631).
[] (ii) Alternate I (APR 2003) of 52.247-64.
(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
[Contracting Officer check as appropriate.]
[] (1) 52.222-17, Nondisplacement of Qualified Workers (MAY 2014) (E.O. 13495).
[ ](2) 52.222-41, Service Contract Labor Standards (AUG 2018) (41 U.S.C. chapter 67).
[] (3) 52.222-42, Statement of Equivalent Rates for Federal Hires (AUG 2018) (29 U.S.C. 206 and 41 U.S.C. chapter 67).
In compliance with the Service Contract Act of 1965, as amended, and the regulations of the Secretary of Labor (29 CFR part 4), this clause identifies the classes of service employees expected to be employed under the contract and states the wages and fringe benefits payable to each if they were employed by the contracting agency subject to the provisions of 5 U.S.C. 5341 or 5332.
[] (4) 52.222–43, Fair Labor Standards Act and Service Contract Labor Standards—Price Adjustment (Multiple Year and Option Contracts) (MAY 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).
[] (5) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards—Price Adjustment (MAY 2014) (29 U.S.C 206 and 41 U.S.C. chapter 67).
[] (6) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment—Requirements (MAY 2014) (41 U.S.C. Chapter 67).
[] (7) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services—Requirements (MAY 2014) (41 U.S.C. chapter 67).
[ ] (8) 52.222-55, Minimum Wages Under Executive Order 13658 (DEC 2015) (Executive Order 13658)
[] (9) 52.222-62, Paid Sick Leave Under Executive Order 13706 (JAN 2017) (E.O. 13706)
[] (10) 52.226–6, Promoting Excess Food Donation to Nonprofit Organizations (MAY 2014) (42 U.S.C. 1792).
[] (11) 52.237-11, Accepting and Dispensing of $1 Coin (SEP 2008) (31 U.S.C. 5112(p)(1)).
(d) Comptroller General Examination of Record The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, and does not contain the clause at 52.215-2, Audit and Records--Negotiation.
(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor's directly pertinent records involving transactions related to this contract.
(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR Subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.
(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.
(e) (1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c), and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in paragraphs (e)(1) in a subcontract for commercial items. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause--
(i) 52.203-13, Contractor Code of Business Ethics and Conduct (OCT 2015) (41 U.S.C. 3509).
(ii) 52.203–19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113–235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(iii) 52.219-8, Utilization of Small Business Concerns (NOV 2016) (15 U.S.C. 637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds $700,000 ($1.5 million for construction of any public facility), the subcontractor must include 52.219–8 in lower tier subcontracts that offer subcontracting opportunities.
(iv) 52.222-17, Nondisplacement of Qualified Workers (MAY 2014) (E.O. 13495). Flow down required in accordance with paragraph (l) of FAR clause 52.222–17.
(v) 52.222-21, Prohibition of Segregated Facilities (APR 2015)
(vi) Equal Opportunity (SEP 2016) (E.O. 11246).
(vii) 52.222-35, Equal Opportunity for Veterans (OCT 2015) (38 U.S.C. 4212).
(viii) 52.222-36, Affirmative Action for Workers with Disabilities (JUL 2014) (29 U.S.C. 793).
(ix) 52.222-37, Employment Reports on Veterans (FEB 2016) (38 U.S.C. 4212)
(x) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (DEC 2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.
(xi) 52.222-41, Service Contract Labor Standards (MAY 2014) (41 U.S.C. chapter 67).
(xii) [x] (A) 52.222-50, Combating Trafficking in Persons (MAR 2015) (22 U.S.C. chapter 78 and E.O. 13627).
[] (B) Alternate I (MAR 2015) of 52.222-50 (22 U.S.C. chapter 78 and E.O. 13627).
(xiii) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment—Requirements (MAY 2014) (41 U.S.C. chapter 67).
(xiv) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services—Requirements (MAY 2014) (41 U.S.C. chapter 67).
(xv) 52.222-54, Employment Eligibility Verification (OCT 2015).
(xvi) 52.222-55, Minimum Wages Under Executive Order 13658 (DEC 2015) (Executive Order 13658).
(xvii) 52.222-62 Paid Sick Leave Under Executive Order 13706 (JAN 2017) (E.O. 13706).
(xvii) (A) 52.224-3, Privacy Training (JAN 2017) (5 U.S.C. 552a).
(B) Alternate I (JAN 2017) of 52.224-3.
(xix) 52.225-26, Contractors Performing Private Security Functions Outside the United States (OCT 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).
(xx) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (MAY 2014) (42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.
(xxi) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (FEB 2006) (46 U.S.C. Appx 1241(b) and 10 U.S.C. 2631). Flow down required in accordance with paragraph (d) of FAR clause 52.247-64.
(2) While not required, the Contractor may include in its subcontracts for commercial items a minimal number of additional clauses necessary to satisfy its contractual obligations.
(End of Clause)
II.5 52.203-19 PROHIBITION ON CONTRACTING WITH ENTITIES THAT REQUIRE CERTAIN INTERNAL CONFIDENTIALITY AGREEMENTS (JAN 2017)
(a) The Contractor shall not require its employees or subcontractors seeking to report fraud, waste, or abuse to sign or comply with internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting waste, fraud, or abuse related to the execution of a Government contract to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information (e.g., agency Office of the Inspector General).
(b) The Contractor shall notify current employees and subcontractors that prohibitions and restrictions of any internal confidentiality agreements covered by this clause, to the extent that such prohibitions and restrictions are inconsistent with the prohibitions of this clause, are no longer in effect.
(c) The prohibition in paragraph (a) of this clause does not contravene requirements applicable to Standard Form 312 (Classified Information Nondisclosure Agreement), Form 4414 (Sensitive Compartmented Information Nondisclosure Agreement), or any other form issued by a Federal department or agency governing the nondisclosure of classified information.
(d) In accordance with Section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015, (Pub. L. 113-235) use of funds appropriated (or otherwise made available) under that or any other Act may be prohibited, if the Government determines that the Contractor is not in compliance with the provisions of this clause.
(e) The Contractor shall include the substance of this clause, including this paragraph (f), in subcontracts under such contracts.
(f) The Government may seek any available remedies in the event the contractor fails to comply with the provisions of this clause.
II.6 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)
The Government may extend the term of this contract by written notice to the Contractor within thirty (30) days of contract expiration; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least sixty (60) days before the contract expires. The preliminary notice does not commit the Government to an extension.
If the Government exercises this option, the extended contract shall be considered to include this option clause.
The total duration of this contract, including the exercise of any options under this clause, shall not exceed sixty (60) months.
(End of Clause)
II.7 CONTRACTING OFFICER’S AUTHORITY (MAR 2003)
The Contracting Officer is the only person authorized to approve changes in any of the requirements of this contract. In the event the Contractor effects any changes at the direction of any person other than the Contracting Officer, the changes will be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in costs incurred as a result thereof. The Contracting Officer shall be the only individual authorized to accept nonconforming work, waive any requirement of the contract, or to modify any term or condition of the contract. The Contracting Officer is the only individual who can legally obligate Government funds. No cost chargeable to the proposed contract can be incurred before receipt of a fully executed contract or specific authorization from the Contracting Officer.
[End of Clause]
II.8 ELECTRONIC INVOICING AND PAYMENT REQUIREMENTS- INVOICE PROCESSING PLATFORM (IPP)
(JAN 2016)
Beginning April 11, 2016, payment requests for all new awards must be submitted electronically through the U. S. Department of the Treasury's Invoice Processing Platform System (IPP). Payment terms for existing contracts and orders awarded prior to April 11, 2016 remain the same. The Contractor must use IPP for contracts and orders awarded April 11, 2016 or later, and must use the non-IPP invoicing process for those contracts and orders awarded prior to April 11, 2016.
"Payment request" means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in FAR 32.905(b), "Payment documentation and process" and the applicable Prompt Payment clause included in this contract. The IPP website address is: https://www.ipp.gov.
Under this contract, the following documents are required to be submitted as an attachment to the IPP:
-_____ Page 1 of Awarded Contract __________________ The IPP was designed and developed for Contractors to enroll, access and use IPP for submitting requests for payment. Contractor assistance with enrollment can be obtained by contacting IPPCustomerSupport@fms.treas.gov or phone (866) 973-3131.
If the Contractor is unable to comply with the requirement to use IPP for submitting invoices for payment, the Contractor must submit a waiver request in writing to the contracting officer.
II.9 SAFEGUARDING OF SENSITIVE INFORMATION (MAR 2015)
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
| (1) | Truncated SSN (such as last 4 digits) |
| (2) | Date of birth (month, day, and year) |
| (3) | Citizenship or immigration status |
| (4) | Ethnic or religious affiliation |
| (5) | Sexual orientation |
| (6) | Criminal History |
| (7) | Medical Information |
| (8) | System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) |
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:
| (1) | DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information |
| (2) | DHS Sensitive Systems Policy Directive 4300A |
| (3) | DHS 4300A Sensitive Systems Handbook and Attachments |
| (4) | DHS Security Authorization Process Guide |
| (5) | DHS Handbook for Safeguarding Sensitive Personally Identifiable Information |
| (6) | DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program |
| (7) | DHS Information Security Performance Plan (current fiscal year) |
| (8) | DHS Privacy Incident Handling Guidance |
| (9) | Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html |
(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html
(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html
(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.
(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.
(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.
(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.
(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.
(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.
(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.
(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.
(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.
(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.
(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.
(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.
(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.
(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.
(f) Sensitive Information Incident Reporting Requirements.
(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.
(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:
| (i) | Data Universal Numbering System (DUNS); |
| (ii) | Contract numbers affected unless all contracts by the company are affected; |
| (iii) | Facility CAGE code if the location of the event is different than the prime contractor location; |
| (iv) | Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email); |
| (v) | Contracting Officer POC (address, telephone, email); |
| (vi) | Contract clearance level; |
| (vii) | Name of subcontractor and CAGE code if this was an incident on a subcontractor network; |
| (viii) | Government programs, platforms or systems involved; |
| (ix) | Location(s) of incident; |
| (x) | Date and time the incident was discovered; |
| (xi) | Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level; |
| (xii) | Description of the Government PII and/or SPII contained within the system; |
| (xiii) | Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and |
| (xiv) | Any additional information relevant to the incident. |
(g) Sensitive…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .