UPDATED_Attachment_A_Performance_Work_Statement_11.27.17.pdf

PDF 102 KB Posted

Attached to
Risk Management Services- IDIQ Federal contract opportunity
Solicitation number
R17PS00246
Issued by
Department of the Interior Bureau of Reclamation

About this file

UPDATED Attachment A Performance Work Statement 11.27.2017

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

IT Risk Management Services IDIQ R17PS00246 Page 1 of 10

ATTACHMENT A

PERFORMANCE WORK STATEMENT (PWS)

08/24/2017

1.0 INTRODUCTION:

1.1 Bureau of Reclamation (Reclamation): Reclamation is a water management agency with 600 dams in the 17 western states. We are known best for construction of dams, power plants, and canals, including Hoover Dam on the Colorado River, Grand Coulee Dam on the Columbia River, and Folsom Dam on the American River. Reclamation is the largest wholesaler of water in the country and second largest producer of hydroelectric power in the western US. Reclamation is organized into five regions (Great Plains [GP], Lower Colorado [LC], Mid-Pacific [MP], Pacific Northwest [PN], and Upper Colorado [UC])

1.2 The United States Bureau of Reclamation (USBR) Risk Management Services Group is responsible for implementing and maintaining compliance with Federal cybersecurity, and related privacy, requirements.

The purpose of the professional services IDIQ is to perform required work in support of risk management activities through a task order when workload either exceeds the capacity of the assigned federal staff or requires specialty knowledge and experienced federal staff does not possess.

2.0 SCOPE:

2.1 Risk Management support services performed under this professional services IDIQ contract includes technical and professional services to support execution of Reclamation's mission. Services will support the following functional areas: Continuous Diagnostics & Mitigation (CDM); Federal Information Security Management Act (FISMA) Compliance; Industrial Control System (ICS) Security; Information System Security Officer (ISSO) Services; and Privacy Act Compliance.

2.2 The types of services performed under this professional services IDIQ may include: business analyst, communications specialist, cybersecurity engineer, cybersecurity specialist, cybersecurity architect, data analyst, document specialist, editor, forensics analyst, functional subject matter expert, information assurance engineer, information system consultant, network security engineer, privacy specialist, program analyst, project manager, radio frequency engineer, spectrum engineer, system administrator, systems engineer, technical writer and training specialist.

2.3 Contract employees may be required to travel either occasionally or continuously in the performance of a task order. The predominant service area includes the seventeen western United States, but may include other locations as required for client needs.

2.4 The position titles which are being sought for inclusion in the IDIQ described in this PWS are set forth in Attachment F: IDIQ Pricing: Provided in Excel Format. Offerors must submit labor category descriptions for each level of each labor category title as part of their technical proposal in accordance with FAR 52.212-1(b)(4)).

3.0 CONTRACTORS IN THE FEDERAL WORKPLACE- NONPERSONAL SERVICES:

3.1 OVERVIEW: Federal government agencies shall not award personal services contracts unless specifically authorized by statute. No such authority exists for this contract, and the services acquired hereunder are not personal in nature.

3.2 A personal services contract is characterized by the employer-employee relationship it creates between the

IT Risk Management Services IDIQ R17PS00246 Page 2 of 10

Government and the contractor's personnel. An employer-employee relationship under a service contract occurs when, as a result of the contract's terms or the manner of its administration during performance, contractor personnel are subject to the relatively continuous supervision and control of a Government officer or employee. Therefore, Government employees do not supervise contractors or perform supervisory type functions such as approving leave, providing performance evaluations, approving awards, etc.

Contractor employees are not Government personnel and are subject to different laws, rules and regulations than Government personnel. Contractor employees are subject to the work rules of their particular employer, and any restrictions imposed by the contract or detailed PWS. The contract/detailed PWS defines the scope of the contractor employee responsibilities as well as the relationship between the contractor and the government.

3.3 ADMINISTRATIVE FUNCTIONS: Contract employees are not allowed administrative leave for such functions as picnics and other office social events, blood drives, luncheons, retirement ceremonies, dedications, town hall meetings, special emphasis programs, etc. They are contracted to perform a function.

If they are not performing that function, they are not entitled to pay and the Government is not billed. Staff meetings are an exception if discussion is pertinent to the job the contractor is currently working.

Supervisors may not request contractors to help set up office events or volunteer time for office events unless the event is directly related to the task(s) cited in the contract/detailed PWS.

3.4 AWARDS: Contract employees are not eligible to receive monetary awards, such as On-The-Spot Awards, performance awards, etc, from the Government.

3.5 CHARITABLE CONTRIBUTIONS: Government personnel may not officially or unofficially solicit contractor employees for charitable contributions either on or off duty. Contractors are not prohibited from voluntarily contributing or purchasing fund-raiser items.

3.6 COMPENSATORY TIME: Government personnel may not authorize compensatory time for contractors.

3.7 CONTRACTOR EMPLOYER RESPONSIBILITIES: Included, but not limited to, are payment of wages;

benefits (insurance, vacation); training (unless task related specialized training is not available from contractor's sources); EEO guidance; counseling, behavior/performance problems; other training/guidance/assistance required by their employee.

3.8 GOVERNMENT REPRESENTATION: Contract employees cannot perform tasks that require them to represent the Government in policy or decision making or in government functions such as EEO Committees, Savings Bonds or CFC Campaigns, Boards, etc.

3.9 HOLIDAYS: Do not include holidays in the total verified on the contractor employer timesheet unless the employee worked that day. If so, annotate "Actually worked holiday" on the timesheet.

3.10 INTERVIEWS: Hiring is the sole responsibility of the contractor. The Government may review resumes for technical and professional categories where specific expertise is required. A Government representative may observe during an interview conducted by the contractor to answer questions concerning the task order requirements.

3.11 OVERTIME: Contract employees may work overtime, but the requirement must be stated in or added to the task order so that the customer can verify the overtime is authorized. When authorized, contractors will be paid time and a half when working overtime.

IT Risk Management Services IDIQ R17PS00246 Page 3 of 10

3.12 RAISES: The Government may not initiate cost of living raises for contractors. However, certain criteria do provide for cost of living type increases from the contractor employer. Otherwise, the Government may initiate rate changes only when the contractor-employee's responsibilities have changed. In these instances, the Government will suggest a new rate of pay and support the request with a revised PWS.

3.13 PRIVATELY OWNED VEHICLES (POV): If the task order requires a contract employee to use their own vehicle for travel, then the contract employee will be reimbursed in accordance with the detailed PWS limited by the Federal Travel Regulations.

3.14 SUPERVISION: To be provided by the contractor/employer. This includes monitoring employee performance, affecting necessary employee disciplinary actions, dealing with conduct issues, and awards.

Any problems with performance, attendance, personal problems, etc. should be referred to the contractor through the Contracting Officer.

3.15 TASK ORDER: If the scope of a task(s) is altered, then a task order modification must be executed by the Contracting Officer before any changed work is assigned.

3.16 UNFORESEEN FACILITY CLOSURE: Contract employees are not entitled to administrative leave. If a Government decision to close is made before working hours, the contractor will be notified using normal notification procedures. Contractor employees are not required to perform any services on day(s) of the closure and shall receive no payment for such periods. In the event of a partial day, unforeseen facility closure, the Contractor shall notify contractor-employees within one hour of receiving notice of facility closure. Payment of a partial day closure will be made only for the actual time worked. Contractors are authorized pay for time spent on fire/emergency drills as long as it is recorded.

4.0 PERSONNEL QUALIFICATIONS:

4.1 The detailed PWS for each Task Order will include minimum qualifications for individuals to perform the tasks. Provide personnel with the minimum qualifications for each detailed PWS. Minimum qualifications may include, but not necessarily limited to with:

4.1.1 National Institutes of Standards and Technology (NIST): Knowledge of and experience with relevant NIST guidance. Task orders may require expert level knowledge and experience with one or more of the following NIST publications:

• NIST SP 800- 18, Guide for Developing Security Plans for Federal Information Systems http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf

• NIST SP 800-30, Guide for Conducting Risk Assessments http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

• NIST SP 800-34, Contingency Planning Guide for Federal Information Systems http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf

• NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems:

A Security Life Cycle Approach http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800- 37r1.pdf

• NIST SP 800-39,Managing Information Security Risk: Organization, Mission, and Information System View http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf

• NIST SP 800-40, Guide to Enterprise Patch Management Technologies http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r3.pdf http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r3.pdf

IT Risk Management Services IDIQ R17PS00246 Page 4 of 10

• NIST SP 800-41, Guidelines on Firewalls and Firewall Policy http://csrc.nist.gov/publications/nistpubs/800-41-Rev1/sp800-41-rev1.pdf

• NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf

• NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf

• NIST SP 800-61, Computer Security Incident Handling Guide http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

• NIST SP 800-82, Guide to Industrial Control Systems (ICS) Security http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf

• NIST SP 800-83, Guide to Malware Incident Prevention and Handling for Desktops and Laptops http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-83r1.pdf

• NIST SP 800-153, Guidelines for Securing Wireless Local Area Networks (WLANs) http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-153.pdf

• NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf

4.1.2 Specialized Subject Matter Expert (SME): Subject matter expertise and experience for specialized tasks may include the following.

4.1.2.1 CDM: Expert level knowledge of and experience with CDM activities related to Hardware Asset Management, Software Asset Management, Configuration Setting Management, Vulnerability Management and Operational Security Management. Mastery of and skill in applying the configuration, implementation, managing and monitoring of security event correlation tools (e.g., IEM, SIEM, Splunk etc.), performing data reduction and assessing the robustness of security systems and designs. Expert knowledge interpreting and incorporating data from multiple tool sources and identifying systemic security issues based on the analysis of vulnerability and configuration data.

Expert knowledge of intrusion detection tools, applications and techniques for detecting host and network-based intrusions

4.1.2.2 FISMA: Expert level knowledge of and experience with FISMA-related activities to include system security plans, contingency plans, incident response plans, configuration management plans, security control requirements and assessments, Plan of Action and Milestones (POA&M), and training requirements.

4.1.2.3 ICS: Expert knowledge and experience with configuring and operating ICS technology components (Remote Terminal Units (RTU), Programmable Logic Controllers (PLCs), relays, sensors, switches etc.), ICS protocols (Modbus, Profibus, Common Industrial Protocol etc.) and ICS systems (Supervisory Control and Data Acquisition (SCADA), Physical Access Control Systems (PACS), Building Automation Systems (BAS) etc.) components.

4.1.2.4 ISSO: Expert knowledge and experience with performing all ISSO-related tasks to include the following for all assigned systems; ensuring that the appropriate operational security posture is maintained; serving as a principal security advisor on all matters, technical and otherwise; developing http://csrc.nist.gov/publications/nistpubs/800-41-Rev1/sp800-41-rev1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-83r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-153.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf

IT Risk Management Services IDIQ R17PS00246 Page 5 of 10 security procedures; continuous monitoring of security controls to ensure that they continue to be implemented correctly, operating as intended and producing the desired outcome with respect for meeting the security requirements; developing and updating the system security plan and all relevant components; assessing the security impact of changes; conducting annual assessment activities in accordance with Mid-Year and Annual Assurance Statement requirements; managing the POA&M process; providing the required system access, information and documentation to security control assessors; and leading required A&A activities.

4.1.2.5 Privacy: Expert knowledge and experience with Privacy Act-related activities to include Privacy Impact Assessments (PIA), personally identifiable information (PII), PII breach procedures and recovery methods, privacy control requirements and assessments and training requirements.

4.1.2.6 Network security: Expert knowledge of network security architecture concepts to include topology, protocols, components, and principles (e.g., application of Defense-in-Depth) and the common attack vectors on the network layer. Skill in network mapping and recreating network topologies, protecting a network against malware, detecting host and network-based intrusions, reading and interpreting signatures, performing packet-level analysis and network traffic analysis. Knowledge and skills to configure, use and monitor network protection components (e.g., Firewalls, VPNs, network intrusion detection systems).

4.1.2.7 Vulnerability management: Expert knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return-oriented attacks, and malicious code) and malware analysis concepts and methodology. Skill in conducting vulnerability/penetration scans, recognizing vulnerabilities and preparing technical vulnerability, risk and security impact analyses. Expert knowledge of new and emerging technologies, programming language structures and logic, Unix/Windows command line, ports and services and penetration testing principles, tools, and techniques (e.g., metasploit, neosploit, etc.). Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution, etc.) and different operational threat environments (e.g., first generation [script kiddies], second generation [non-nation state sponsored], and third generation [nation state sponsored]). Knowledge of different types of network and general attack stages (e.g., footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.).

4.1.2.8 System Administration: Expert knowledge of Windows, Linux and Unix system configuration and administration, anti-virus software, patch management, optimization techniques, common protocols (SNMP, HTTP, HTTPS, SMTP, NTP, LDAP, KERBEROS, RADIUS, SFTP etc.), and scripting techniques.

4.2 The detailed PWS for each Task Order may include certification requirements for individuals to perform the tasks. Provide personnel with the required education or certifications for each detailed PWS.

4.3 Proposals for the contractor selection (base agreement) must include how the contractor will acquire personnel with the required qualifications for each task order when the contractor does not already employ personnel that would qualify.

5.0 TASK ORDER PROCEDURES

5.1 A detailed PWS will be issued by the government for each Task Order to be placed against IDIQ contract(s) awarded from this PWS. The detailed PWS will include the period of performance; place of performance;

travel requirements (if necessary); description of the task or tasks to be performed; deliverables; minimum

IT Risk Management Services IDIQ R17PS00246 Page 6 of 10 qualifications for individuals to perform the task, work schedule (if necessary), and other information pertinent to the task.

5.2 The detailed PWS may require individual(s) providing the services to be physically located at the offices/sites requiring the services or at their home office.

5.3 Unless the detailed PWS allows additional days, the contractor will be allowed up to 10 business days to respond. The response will include the contractor’s approach for performing the tasks, qualifications for employee(s) who will perform the tasks, price for performing the tasks, and assumptions used in preparing the response to meet all the requirements of the detailed PWS. Reclamation will evaluate responses on technical merit and consideration of price. Reclamation may accept or reject the response or request further clarification and/or revisions to the response. The contractor shall respond to requests for clarifications or revisions by the close of the next business day.

5.4 After a task order is issued, the contractor may need to make a substitution. In these instances, the contractor will provide employee qualifications for substitutes or replacements of employees accepted in the proposal. Substitute and replacement employee qualifications will be at least equal to or exceed the qualifications of the employee they are substituting for or replacing or provide consideration. Reclamation will evaluate the qualifications of the substitutes or replacements. Reclamation must accept the substitute or replacement employee prior to the employee mobilizing and performing the detailed PWS. All costs incurred as a result of the substitution (i.e. travel, labor for transferring task order knowledge, overlapping time on site, recruitment, differential pay, etc.) will not be an expense to the government.

5.5 Issuing task orders. Task orders may only be issued by the Bureau of Reclamation Denver Contracting Office. No other offices have authority to issue a task order.

5.6 In accordance with FAR 16.505(b), all IDIQ contract holders, regardless of socio-economic classification (unless the Contracting Officer determines a set-aside to be appropriate), will be provided a fair opportunity to be awarded task orders. Fair opportunity will not apply when an exception applies in accordance with FAR 16.505(b)(2).

5.7 Task order Ombudsman:

Waleska Pierantoni

1849 C ST NW RM 4249 WASHINGTON DC

Phone: (202)513-0719 Fax: (202)513-7645 Email: waleska_pierantoni@ios.doi.gov

6.0 PERIOD OF PERFORMANCE:

6.1 This IDIQ will have a five (5) year ordering period from the date of award.

6.2 Work Schedule: A work schedule may be defined in the detailed PWS for each Task Order. The contractor shall use the work schedule issued for preparing proposals to a detailed PWS. The detailed PWS may have tasks whose durations are dependent on activities by others (i.e. inspection of construction activities by a construction contractor). Actual work schedules may vary from the work schedules identified in the detailed PWS. For these instances, Task Orders will be issued on a labor-hour basis.

IT Risk Management Services IDIQ R17PS00246 Page 7 of 10

6.3 Overtime: Overtime is defined as hours in excess of forty (40) hours per work week. If overtime is required for a Task Order it will be included in the detailed PWS. Overtime will be reflected as a separate line item for pricing. The Government is not liable for any overtime effort performed by the contractor without prior approval from the Contracting Officer.

6.4 Office Closure: In the event of an unexpected office closure such as for severe weather conditions, contractor personnel shall be directed by the Contracting Officer regarding reporting requirements and procedures. The contractor is responsible for all notification and costs associated with office closure. All non-work due to unexpected office closure will be at no cost to the Government unless expressly authorized by the Contracting Officer.

6.5 Holidays: The Federal Government will observe and normal work functions are closed for the holidays listed below. Task Order work schedules may or may not observe these holidays.

New Years Day Martin Luther King Jr. Birthday President's Day Memorial Day Independence Day Labor Day Columbus Day Veterans Day Thanksgiving Christmas

6.5.1 Holidays also include any other holiday designated by Federal law, Executive Order or Presidential Proclamation.

6.5.2 When holidays fall on a Saturday, the preceding Friday is observed; when any such day falls on a Sunday, the following Monday is observed. Observance of such days by Government personnel shall not be cause for additional period of performance or entitlement to compensation except as set forth in the contract.

7.0 Price:

7.1 The prices in Volume VIII Attachment F– IDIQ Pricing: Provided in Excel Format, will be the maximum hourly rates for each professional service and level of service. Price proposals for task orders may discount hourly rates to less than maximum prices in the Schedule. Task order proposals may not have a higher rate than the maximum price in the Schedule.

8.0 GOVERNMENT-FURNISHED EQUIPMENT (GFE) AND MATERIALS:

8.1 GFE: None, unless listed in the detailed PWS for an order.

8.2 Government Furnished Materials: None, unless listed in the detailed PWS for an order.

8.3 The Contactor could be responsible for providing all required equipment, material and supplies necessary.

The government anticipates the following equipment will be required: Notebook computer and computer software with the capability to transmit electronic reports in the required formats, internet access, cell phone, digital camera, SD cards for photos, and personal protective gear including safety glasses, hearing

IT Risk Management Services IDIQ R17PS00246 Page 8 of 10 protection, safety boots, hard hat, harness, and safety vest to accomplish the required tasks. To insure compatibility with Reclamation’s programs, computer generated deliverables be provided in the following formats: Microsoft Word 2010 or newer, Microsoft Excel 2010 or newer, most up to date Adobe Professional (reader and writer).

8.4 Government Furnished Resources: If any Government furnished resources are provided, they will be provided in accordance with applicable standards, regulations and guidance and are limited to those identified in the detailed PWS for the individual Task Orders. Government facilitates and services that may be made available under this contract include but are not limited to office space, general office equipment, specialized equipment, communications services and devices, and reproduction services. For purposes of this contract and the Task Orders issued hereunder, Government furnished resources shall not include Government Vehicles, nor shall contractor personnel be allowed to ride in Government vehicles without prior authorization.

9.0 REGULATIONS/POLICIES: Fully comply with Reclamation and DOI security standards.

10.0 TRAVEL: Required travel using a privately-owned vehicle will be reimbursed for mileage as authorized at standard GSA rates or cost of rental car. Per Diem will be allowed as provided for by GSA Federal Travel Regulations as posted on www.gsa.gov. Airline travel will be reimbursed at cost for lowest reasonably accommodating travel. Travel expenses will not be reimbursed for incidental travel to an office within fifty miles of an individual's home residence or office unless specifically authorized in an individual task order.

10.1 Reclamation may require a contractor to travel, but the authorization must be contained in the original task order or added by modification. Reclamation through the detailed PWS may be specific as to mode of transportation, reporting and completion dates and times of travel, rental car or POV. Limitations on food and lodging and POV will be determined in accordance with the Federal Travel Regulations.

11.0 GOVERNMENT VEHICLES: Contract employees required to utilize any Government vehicle (cars, trucks, heavy equipment, etc.) either as a driver or passenger shall be required to sign a “Hold Harmless” release. This includes Government-procured rental vehicles. The Contractor shall use or rent their own vehicles whenever possible and practical. Signed releases are due to the CO 1 day before use of a Government vehicle.

Government vehicles are for official use only.

12.0 SECURITY:

12.1 Key Personnel - The contractor shall provide key personnel with appropriate security clearances at the time of award of the PWS. At a minimum, these checks shall be consistent with the requirements of Homeland Security Presidential Directive 12 and Reclamation policy or memoranda. The results of these clearances shall be provided to the Federal Government COR, COTR, and other designated Federal staff upon request, but consistent with maintaining privacy of the individuals.

12.2 Background Investigations - Contract employees must have, at a minimum, a National Agency Check with written Inquiries (NACI); National Agency Check with written Inquiries and Credit (NACIC); or equivalent investigation completed to continue work under this PWS. A higher-level background investigation, up to and including a National Security Clearance, may be required for some positions. Successful results from the Federal Bureau of Investigation National Criminal History Check (i.e., fingerprint check) must be received for issuance of a federal identity credential supporting access to Reclamation facilities and IT systems and for issuance of the required identity credential.

12.3 Background Investigation Requirements - Subject to the requirements of each task, all contractors must have, at a minimum, a completed and had successfully adjudicated a NACI or NACIC, to include a http://www.gsa.gov/

IT Risk Management Services IDIQ R17PS00246 Page 9 of 10 fingerprint check prior to their start date. To support timely access to Reclamation’s work environment, all access and background forms must be completed no less than two weeks prior to the anticipated start date to allow the Government adequate time to complete the fingerprint check. Those receiving favorable results from the fingerprint check will be granted only limited access until the full background check is complete.

At the discretion of the Government, more extensive background checks or a National Security Clearance may be required for certain positions. Failure to complete required background check forms in a timely manner will delay or prevent the contractor’s staff from accessing Reclamation facilities or IT systems.

12.4 Background Investigation Costs - The costs associated with the submission of pertinent documentation, such as fingerprints, or other related forms, that are required by the Government to process Public Trust Investigations, including the NACI or NACIC, will be the responsibility of the Contractor. The Government is responsible for costs related with the processing, adjudicating and granting of Public Trust investigations and determinations, and with processing, adjudicating and issuance of HSPD-12 compliant identity access cards. Where a National Security Clearance is required, any related costs associated with the investigation, processing, adjudication, or granting of a National Security Clearance will be borne by the Contractor.

12.5 Badges - Employees working at a Government facility shall be required to display, on their person, a Government-provided Personal Identification Verification (PIV) Card, that will include the full name of the employee and the legal name under which the contractor is operating. Policies, procedures, and detailed instructions for obtaining PIV Cards are available at the Department of Interior’s DOI ACCESS Home page at https://portal.doi.net/DOIAccess/Pages/default.aspx. The identification badge numbers and data will be kept in a Government-maintained computer database for security purposes. The contractor shall return all badges to the Government program manager, or designee, on the same day an individual's employment is terminated and/or upon termination of the Task Order. The contractor shall notify the Government program manager, or designee, immediately of any lost badges or within 24 hours. Contract personnel are not allowed to share badges or access cards and shall not display badges outside of Government facilities or sites. The Contractor may be required to turn in access control cards or identification cards on a daily basis

– based the site or facility where work is supported or completed.

12.6 Data Security - Contractor staff may have access to privileged and confidential (For Official Use Only) materials of the United States Government. These printed and electronic documents are for internal use only and remain the sole property of the United States Government. Some of these materials are protected by the Privacy Act of 1974 (AMENDED) and Title 38. Unauthorized disclosure of Privacy Act or Title 38 covered materials is a criminal offense. Each contractor employee will be given access to only the information and facilities needed to perform the work associated with the task order.

12.7 System Security - The contractor(s) shall comply with all the physical and data security policies in effect at Reclamation. The contractor shall participate in security functions relevant to the tasks being performed that may include Security Safeguard Reviews, audits, reporting suspected security violations, acting to secure system environments, responding to computer security alerts and any other review or actions required to ensure computer systems are not violated or vulnerable. This may also include physical security as authentication devices are deployed for access control to Government-controlled space occupied by Reclamation employees and employees of tenant agencies.

12.8 Security Training - All Contractor employees will be subject to Reclamation’s requirements for Federal Information Systems Security Awareness (FISSA) and Role-Based Security Training (RBST). Although all Contractor staff will be required to complete FISSA, RBST will be provided to the Contractor’s staff on the basis of work responsibilities. Reclamation will bear the costs of FISSA training. The costs of RBST will https://portal.doi.net/DOIAccess/Pages/default.aspx

IT Risk Management Services IDIQ R17PS00246 Page 10 of 10 be the responsibility of the Contractor. Failure of the Contractor’s staff to complete required FISSA or RBST will be cause for removal of that individual from work activities covered under this PWS. In addition and at the discretion of the Government, other training may be required. Costs for additional training sessions will be the responsibility of the Government.

13.0 TRAINING: The Contractor is responsible for all training for its employees except when training can only be provided by Reclamation.

13.1 The Government does not pay for contractor-employee training unless the training is unique to the job and is needed to perform the work identified in the task order/detailed PWS. Otherwise, the contractor shall provide its employees with information on such matters as EEO, sexual harassment, safety, and drugs/violence in the workplace, as these are personnel issues. Specialized skill requirements such as proficiency with Excel, PowerPoint, etc., should be identified in the detailed PWS and this training is the responsibility of the contractor. Mandatory training for employees may also be required for contractors as determined by Reclamation management.

14.0 DELIVERABLES: Deliverables for each task order will be included in the detailed PWS for each task order. .

These deliverables may include but are not limited to: weekly or monthly timesheets, reports, findings, summaries, etc. All costs associated with the preparation, reproduction, coordination, submissions for review, rewrites, final reports, copies, postage, etc., shall be included in the price.

15.0 QUALITY:

15.1 Contractor’s Performance Assessment Report System (CPARS): For requirements over the threshold ($100,000 for services) a CPARS report will be created. This report will be completed by the COR at the end of the performance period. For more information, go to www.cpars.csd.disa.mil/cparsmain.htm .

15.2 Measuring Quality: Quality measurements will be listed in the detailed PWS for each order and may include, and is not limited to, one or more of the following:

15.2.1 Deliver written reports and/or required documentation by due date 95 percent of the time, and no later than one week after due date 100 percent of the time.

15.2.2 Attend and participate in required meetings with no more than one absence or incident of unavailability.

16.0 IDENTIFICATION OF CONTRACTOR EMPLOYEES: All contract personnel are required to identify themselves as contractors. Whether attending meetings, answering Government telephones, or working in other situations where their contractor status is not obvious to third parties, they must make their status known to avoid creating an impression that they are Government employees.

http://www.cpars.csd.disa.mil/cparsmain.htm

1.0 INTRODUCTION:
1.1 Bureau of Reclamation (Reclamation): Reclamation is a water management agency with 600 dams in the 17 western states. We are known best for construction of dams, power plants, and canals, including Hoover Dam on the Colorado River, Grand Coulee D...
1.2 The United States Bureau of Reclamation (USBR) Risk Management Services Group is responsible for implementing and maintaining compliance with Federal cybersecurity, and related privacy, requirements. The purpose of the professional services IDIQ ...
2.0 SCOPE:
2.1 Risk Management support services performed under this professional services IDIQ contract includes technical and professional services to support execution of Reclamation's mission. Services will support the following functional areas: Continuous ...
2.2 The types of services performed under this professional services IDIQ may include: business analyst, communications specialist, cybersecurity engineer, cybersecurity specialist, cybersecurity architect, data analyst, document specialist, editor, f...
2.3 Contract employees may be required to travel either occasionally or continuously in the performance of a task order. The predominant service area includes the seventeen western United States, but may include other locations as required for client ...
2.4 The position titles which are being sought for inclusion in the IDIQ described in this PWS are set forth in Attachment F: IDIQ Pricing: Provided in Excel Format. Offerors must submit labor category descriptions for each level of each labor catego...
3.0 CONTRACTORS IN THE FEDERAL WORKPLACE- NONPERSONAL SERVICES:
3.1 OVERVIEW: Federal government agencies shall not award personal services contracts unless specifically authorized by statute. No such authority exists for this contract, and the services acquired hereunder are not personal in nature.
3.2 A personal services contract is characterized by the employer-employee relationship it creates between the Government and the contractor's personnel. An employer-employee relationship under a service contract occurs when, as a result of the contra...
3.3 ADMINISTRATIVE FUNCTIONS: Contract employees are not allowed administrative leave for such functions as picnics and other office social events, blood drives, luncheons, retirement ceremonies, dedications, town hall meetings, special emphasis progr...
3.4 AWARDS: Contract employees are not eligible to receive monetary awards, such as On-The-Spot Awards, performance awards, etc, from the Government.
3.5 CHARITABLE CONTRIBUTIONS: Government personnel may not officially or unofficially solicit contractor employees for charitable contributions either on or off duty. Contractors are not prohibited from voluntarily contributing or purchasing fund-rais...
3.6 COMPENSATORY TIME: Government personnel may not authorize compensatory time for contractors.
3.7 CONTRACTOR EMPLOYER RESPONSIBILITIES: Included, but not limited to, are payment of wages; benefits (insurance, vacation); training (unless task related specialized training is not available from contractor's sources); EEO guidance; counseling, beh...
3.8 GOVERNMENT REPRESENTATION: Contract employees cannot perform tasks that require them to represent the Government in policy or decision making or in government functions such as EEO Committees, Savings Bonds or CFC Campaigns, Boards, etc.
3.9 HOLIDAYS: Do not include holidays in the total verified on the contractor employer timesheet unless the employee worked that day. If so, annotate "Actually worked holiday" on the timesheet.
3.10 INTERVIEWS: Hiring is the sole responsibility of the contractor. The Government may review resumes for technical and professional categories where specific expertise is required. A Government representative may observe during an interview conduct...
3.11 OVERTIME: Contract employees may work overtime, but the requirement must be stated in or added to the task order so that the customer can verify the overtime is authorized. When authorized, contractors will be paid time and a half when working ov...
3.12 RAISES: The Government may not initiate cost of living raises for contractors. However, certain criteria do provide for cost of living type increases from the contractor employer. Otherwise, the Government may initiate rate changes only when the ...
3.13 PRIVATELY OWNED VEHICLES (POV): If the task order requires a contract employee to use their own vehicle for travel, then the contract employee will be reimbursed in accordance with the detailed PWS limited by the Federal Travel Regulations.
3.14 SUPERVISION: To be provided by the contractor/employer. This includes monitoring employee performance, affecting necessary employee disciplinary actions, dealing with conduct issues, and awards. Any problems with performance, attendance, personal...
3.15 TASK ORDER: If the scope of a task(s) is altered, then a task order modification must be executed by the Contracting Officer before any changed work is assigned.
3.16 UNFORESEEN FACILITY CLOSURE: Contract employees are not entitled to administrative leave. If a Government decision to close is made before working hours, the contractor will be notified using normal notification procedures. Contractor employees a...
4.0 PERSONNEL QUALIFICATIONS:
4.1 The detailed PWS for each Task Order will include minimum qualifications for individuals to perform the tasks. Provide personnel with the minimum qualifications for each detailed PWS. Minimum qualifications may include, but not necessarily limit...
4.1.1 National Institutes of Standards and Technology (NIST): Knowledge of and experience with relevant NIST guidance. Task orders may require expert level knowledge and experience with one or more of the following NIST publications:
4.1.2 Specialized Subject Matter Expert (SME): Subject matter expertise and experience for specialized tasks may include the following.
4.1.2.1 CDM: Expert level knowledge of and experience with CDM activities related to Hardware Asset Management, Software Asset Management, Configuration Setting Management, Vulnerability Management and Operational Security Management. Mastery of and ...
4.1.2.2 FISMA: Expert level knowledge of and experience with FISMA-related activities to include system security plans, contingency plans, incident response plans, configuration management plans, security control requirements and assessments, Plan of ...
4.1.2.3 ICS: Expert knowledge and experience with configuring and operating ICS technology components (Remote Terminal Units (RTU), Programmable Logic Controllers (PLCs), relays, sensors, switches etc.), ICS protocols (Modbus, Profibus, Common Industr...
4.1.2.4 ISSO: Expert knowledge and experience with performing all ISSO-related tasks to include the following for all assigned systems; ensuring that the appropriate operational security posture is maintained; serving as a principal security advisor o...
4.1.2.5 Privacy: Expert knowledge and experience with Privacy Act-related activities to include Privacy Impact Assessments (PIA), personally identifiable information (PII), PII breach procedures and recovery methods, privacy control requirements and a...
4.1.2.6 Network security: Expert knowledge of network security architecture concepts to include topology, protocols, components, and principles (e.g., application of Defense-in-Depth) and the common attack vectors on the network layer. Skill in netwo...
4.1.2.7 Vulnerability management: Expert knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return-oriente...
4.1.2.8 System Administration: Expert knowledge of Windows, Linux and Unix system configuration and administration, anti-virus software, patch management, optimization techniques, common protocols (SNMP, HTTP, HTTPS, SMTP, NTP, LDAP, KERBEROS, RADIUS,...
4.2 The detailed PWS for each Task Order may include certification requirements for individuals to perform the tasks. Provide personnel with the required education or certifications for each detailed PWS.
4.3 Proposals for the contractor selection (base agreement) must include how the contractor will acquire personnel with the required qualifications for each task order when the contractor does not already employ personnel that would qualify.
5.0 TASK ORDER PROCEDURES
5.1 A detailed PWS will be issued by the government for each Task Order to be placed against IDIQ contract(s) awarded from this PWS. The detailed PWS will include the period of performance; place of performance; travel requirements (if necessary); des...
5.2 The detailed PWS may require individual(s) providing the services to be physically located at the offices/sites requiring the services or at their home office.
5.3 Unless the detailed PWS allows additional days, the contractor will be allowed up to 10 business days to respond. The response will include the contractor’s approach for performing the tasks, qualifications for employee(s) who will perform the ta...
5.4 After a task order is issued, the contractor may need to make a substitution. In these instances, the contractor will provide employee qualifications for substitutes or replacements of employees accepted in the proposal. Substitute and replaceme...
5.5 Issuing task orders. Task orders may only be issued by the Bureau of Reclamation Denver Contracting Office. No other offices have authority to issue a task order.
5.6 In accordance with FAR 16.505(b), all IDIQ contract holders, regardless of socio-economic classification (unless the Contracting Officer determines a set-aside to be appropriate), will be provided a fair opportunity to be awarded task orders. Fa...
5.7 Task order Ombudsman:
Waleska Pierantoni
1849 C ST NW RM 4249 WASHINGTON DC
Phone: (202)513-0719
Fax: (202)513-7645
Email: waleska_pierantoni@ios.doi.gov
6.0 PERIOD OF PERFORMANCE:
6.1 This IDIQ will have a five (5) year ordering period from the date of award.
6.2 Work Schedule: A work schedule may be defined in the detailed PWS for each Task Order. The contractor shall use the work schedule issued for preparing proposals to a detailed PWS. The detailed PWS may have tasks whose durations are dependent on ...
6.3 Overtime: Overtime is defined as hours in excess of forty (40) hours per work week. If overtime is required for a Task Order it will be included in the detailed PWS. Overtime will be reflected as a separate line item for pricing. The Government is...
6.4 Office Closure: In the event of an unexpected office closure such as for severe weather conditions, contractor personnel shall be directed by the Contracting Officer regarding reporting requirements and procedures. The contractor is responsible fo...
6.5 Holidays: The Federal Government will observe and normal work functions are closed for the holidays listed below. Task Order work schedules may or may not observe these holidays.
New Years Day
Martin Luther King Jr. Birthday
President's Day
Memorial Day
Independence Day
Labor Day
Columbus Day
Veterans Day
Thanksgiving
Christmas
6.5.1 Holidays also include any other holiday designated by Federal law, Executive Order or Presidential Proclamation.
6.5.2 When holidays fall on a Saturday, the preceding Friday is observed; when any such day falls on a Sunday, the following Monday is observed. Observance of such days by Government personnel shall not be cause for additional period of performance or...
7.0 Price:
7.1 The prices in Volume VIII Attachment F– IDIQ Pricing: Provided in Excel Format, will be the maximum hourly rates for each professional service and level of service. Price proposals for task orders may discount hourly rates to less than maximum pr...
8.0 GOVERNMENT-FURNISHED EQUIPMENT (GFE) AND MATERIALS:
8.1 GFE: None, unless listed in the detailed PWS for an order.
8.2 Government Furnished Materials: None, unless listed in the detailed PWS for an order.
8.3 The Contactor could be responsible for providing all required equipment, material and supplies necessary. The government anticipates the following equipment will be required: Notebook computer and computer software with the capability to transmit ...
8.4 Government Furnished Resources: If any Government furnished resources are provided, they will be provided in accordance with applicable standards, regulations and guidance and are limited to those identified in the detailed PWS for the individual...
9.0 REGULATIONS/POLICIES: Fully comply with Reclamation and DOI security standards.
10.0 TRAVEL: Required travel using a privately-owned vehicle will be reimbursed for mileage as authorized at standard GSA rates or cost of rental car. Per Diem will be allowed as provided for by GSA Federal Travel Regulations as posted on www.gsa.gov...
10.1 Reclamation may require a contractor to travel, but the authorization must be contained in the original task order or added by modification. Reclamation through the detailed PWS may be specific as to mode of transportation, reporting and completi...
11.0 GOVERNMENT VEHICLES: Contract employees required to utilize any Government vehicle (cars, trucks, heavy equipment, etc.) either as a driver or passenger shall be required to sign a “Hold Harmless” release. This includes Government-procured renta...
12.0 SECURITY:
12.1 Key Personnel - The contractor shall provide key personnel with appropriate security clearances at the time of award of the PWS. At a minimum, these checks shall be consistent with the requirements of Homeland Security Presidential Directive 12 ...
12.2 Background Investigations - Contract employees must have, at a minimum, a National Agency Check with written Inquiries (NACI); National Agency Check with written Inquiries and Credit (NACIC); or equivalent investigation completed to continue work...
12.3 Background Investigation Requirements - Subject to the requirements of each task, all contractors must have, at a minimum, a completed and had successfully adjudicated a NACI or NACIC, to include a fingerprint check prior to their start date. To...

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.