REPUBLIC 2.pdf

PDF 664 KB Posted

Attached to
Solid Waste Removal- FCI Elkton Federal contract opportunity
Solicitation number
15B21625P00000026
Issued by
Department of Justice Bureau of Prisons Federal Correctional Institution Elkton

About this file

This is a Standard Form 1449 Solicitation/Contract/Order for Commercial Products and Commercial Services for solid waste disposal services at FCI Elkton, issued by the Federal Bureau of Prisons. The solicitation number is RFQP02162500002, with responses due by November 12, 2024 at 10:00 ET, and the contract includes both firm-fixed price terms and net 30 payment terms.

The scope includes rental of four 32-cubic yard trash compactors per month, pull charges and disposal fees for FCI (three times per week for 10 months), FSL (bi-weekly), and outside areas (once monthly), along with additional pull charges on will-call basis. The contractor Republic Services will provide these services at specified unit prices, including $1,058.92 per month for compactor rental and $626.01 per haul for various pull charges. The contract contains extensive security and privacy requirements for contractor personnel and systems, including mandatory security training, incident reporting procedures, and specific protocols for handling DOJ information.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

u n I q UC, en n iy ID~ j 2-~ 'IM QM ~c ;> i:23 RFQP02162500002 Page 1 of 20

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 AND 30.

1 REQUISIT ION NU!✓ BER PAGE 1 OF

:rn 2 COl'lTRACT NUMBER J AYI\.\ROf::FFECTIVE , • ORDER NUl,IEER 5 SOLICITATION NUM3ER 6 SOLICITATION ISSUE

OATE DATE

R FQP02 I 6250000_ I II0X/202.J

7. FOR SOLICITATION a NAME b TELEPHONE NUMEER (No cote<:: caMs) 8 OFFER DUE DATE / LOCAL

!HAE

INFORMATION CALL: HEIDI BOURNE I IBOURNE0;BOl'.GOV 11 /12/202.J 10:00 ET 9 ISSUED BY CODE I 1582 16 10 THE' ACQUISITION IS 0 UNRESTRICTED OR □ SET ASIDE % FOR

Fcdcr11I Burl·au of l'rirnns

□ NORTH AMERICAN SMAU.. BUSJNESS □ \.'VOMEt,.-C>.\t,;£.0 SMAU FC'I Ellton BUSINESS {WJS6) INDUSTRY CLASSIFICATION

8730 Scr<>i;HS Road □ ttUBZONE 5!.W..l. STANDARD (NACS).

BUSl '-E:$:j □ ECONOMJCJ..U. Y OlSADVAtlT AGED 562J I_! Lisbon, OJI 4-1 43!

□ SERVICE-OISAB.EO

WCUEJ -Or.\N!:0 $.MAU BUSINESS

VE TERAN O'l.t.E 0 (EOl'.058) SIZE STANDARD

Sl.tAU. BUSINESS □ t(A)

(SOVOSBI

11 DELIVERY FOR FREE ON BOARD 12 DISCOUNT TERMS 13~ RATING

(FOB) DESTINATION UNLESS 13a THIS CONTRACT IS A

BLOCK IS MARKED □ RA TEO ORDER UNDER THE 14 METHOD OFSO!.ICITATION REQUEST

NET 30 DEF~NSE PRIORITIES AND

0 REQUEST □ INVITATION

□ SEE SCHEDULE

□ FOR ALLOCATIONS SYSTEM - FOR QUOTE FOR 810 PROPOSAL DPAS (ISCFR 700) (RFO) (IFB) (RFP)

15. DELIVER TO CODE I 151121 6 16 AD!~ INISTERED BY CODE 1513216

fc<lcr:il U111c..·au of Prisons f-"cd1..·ul Bureau of Prison s F("I El l.1011 FC'I Ell. Ion 8730 Scro~gs Road K730 Ser~ , Koad l.ishon. 0 11 44432 Lisbon. 011 444J2

I 7a CONffiACTOR/ CODE! I F,\CILITY I 18a PAYMENT 'hill BE MADE BY CODE I BEi K

OFF EROR CODE

~LJ..blA,C 1'1..•Jrr3il Bureau o f Prison;

FCI Ell.ion

1'0 IIOX 1~9

L is lain. 01 I 444.>!

TELEPHONE NUMBER

□ 17b. CHECK IF REMITTANCE DIFFERENT A ID PUT SUCH ADDRESS IN 18b SUBMIT INVOICES TO ADDRESS SHOhN IN EJLOCK 18a UNLESS BLOCK

OFFER BELOWIS CHECKED □ SEE ADDENDUM

19. 20. 21 . 22. 23 . 24.

ITEM NUMBER SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

The provision of Solid \Va:tc l)isposal Ser ices fo r FCI ELKTO N. Sec allachcd Sta1c.:111c.:11t of Work .

UEI:

Finn Fi.\c.:d Price.:

Se.: Continuation Shc,:1{ ) ( uso Reverse an&or A~acn Add:,ona! Sneots as Neressar1)

25 ACCOUNTING AND APPROPRIATION DATA 26 TOTAL AWARD AMOUNT (For Govemmen: Use Onj,)

27a SOLICITATION INCOR?ORATI:S BY REFERENCE (FEDERAL ACOU!SITION REGULA TIO I ) FAR 52 212-1. 52 212-4. FAR 52 212.J H ARE ~ ARE tJOT ATTACHED

AN052212-5AREATTACHEO ADDENDA

27b CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52 212-4 FAR 52 212-5 IS A TT ACHED ADDENDA ARE □ ARE NOT ATTACHED

~ 28. CONTRACTOR IS REOU1RED TO SIGN THIS DOCUMENT A D RETURN CO?ES TO

ISSUING OFFICE. CONTR,-.CTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH

□ Z9 AWARD OFCONTR;;CT REFERENCE

OFFER DATED YOUR OFFER ON SOLICITATION (ElLOC,<

OR OTHER'AiSE IDENTIFIED ABOVE AND CN ANY ADD1TIONAL SHEETS SUBJECT TO THE 5) INCLUOrJG ANY ADDITIONS OR CHANGESI\HICH ARE SET FORTH

TERMS AND CONDITIONS SPECIFIED

I

30a SIGj~~\~l :R~ONTRACTOR

30b NAME W!\1 ITLE < F SIGNER t Type or pm() f{)¾JL r lobc I C,-/1-11

AUTHORIZED FOR LOCAL REPROD UCTION

PREVIOUS EDITION IS NOT USABLE

30c DA TE SIGNED

11/11/1-<-/

HEREIN IS ACCEPTED AS TO ITEMS

31a UNITED ST,>.TES OF AMERICA (SIGNMURE OFCONTRACTJNG CFFiCERJ

310 r-.A\IE OF THE CONTR/CTINGOFFICER (Type o, prnl) 31c DATE SIGNED

1-!cidi Bourne

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA· FAR (48 CFR) 53 21 2

RFQP02162500002 Page 2 of 20

19. 20. 21. 22. 23. 24 .

ITEM NUMBER SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEE N

□ RECEIVED □ INSPECTED □ ACCEPTED. AND CONFORMS TO THE CONTRACT. EXCEPT AS NOTED: ____ ________ _

32b. SIGNATURE OF AUTHORIZED GOVERNMENT 32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVE RNMENT REPRESENTATIVE 321. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32g. E•MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

33. SHIP NUMBER 34. VOUCH ER NUMBER 35. AMOUNT VERIFIED 36. PAYMENT 37. CHECK NUMBER

CORRECT FOR

O coMPLETE □PARTIAL □ FINAL

I PARTIAL I I FINAL

38. SIR ACCOUNT NUMBER 39. SIR VOUCHER NUMBER 40 PAID BY

41~. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Prine)

41b. SIGNATURE AND TITLE OF CERTIFYING OFF ICER 4 1c. DATE

42b. RECEIVED AT (Location)

42c. DATE REC"D (YYIM/1.IDD) 142d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 11/2021) BACK

Section

RFQP02162500002 Page 3 of 20

Table of Contents

Descri lion Pa e Number

Solicitation/Contract Form Commodity or Services Schedule Contract Clauses

DOJ-02 Contractor Privacy Requirements (JAN 2022) DOJ-05 Security of Department Information and Systems DOJ-05 (OCT 2023)

List of Attachments Solicitation Provisions

RFQP02162500002 Page 4 of 20

Section 1 - Commodity or Services Schedule

SCHEDULE OF SUPPLIES/SERVICES

CONTINUATION SHEET

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE

0001 Rental of (4) 32 cubic yard trash compactors (per month) 0 s ,ose. oi2.

PSC: S222 21.,t-f . 13 vtl Per mcnn"

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE

0002 Pull charges and disposal fee (FCl)3 TIMES A WEEK for 10 0 s (l2t.,- cJ I months

PSC: S222 oerh~ I

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE

0003 Additional pu ll charges & disposal fees (FCI) (Will Call) 0 s (..,U.,,-01

PSC: S222 {)f:..Yh@I I

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE

0004 Pull charges and disposal fee (FSL) (Bi weekly) 0 5 021.,.01

PSC: S222 Per h/lJJ/

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE

0005 Additional pull charges & disposal fees (FSL) (Will Call) 0 s (.,Lv-0 j

PSC: S222

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE

0006 Pull charges & disposal fees (Outside- once a month) Will Call 0 s_(pU,.01

PSC: S222

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE

0007 Trip charges fee if pull cannot be complete due to BOP 0 s 250.<.0

PSC: S222

Aggregate Total: $ ___________ (Base + All Options)

AMOUNT

s

AMOUNT

s

AMOUNT

s

AMOUNT

s

AMOUNT

s

AMOUNT

s

AMOUNT

s

RFQP02162500002 Page 5 of 20

Section 2 • Contract Clauses

Clauses By Full Text

DOJ-02 Contractor Privacy Requirements (JAN 2022)

A. Limitin Access to Privac Act and Other Sensitive Information

(1) Privacy Act Information

In accordance with FAR 52 .224-1 Privacy Act Notification (APR 1984) and FAR 52 .224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 19 7 4, the contractor is advised that the re levant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at !l.!.ms ://www.justice .gov/oocl/doj-s stems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies' websites or by searching the Federal Digital System (FDsys) available at htto://www.9QQ,.g.9v/fdsys/. SORNs may be updated at any time .

(2) Prohibition on Performing Work Outside a Government Facility/Netvvork/Equipment

Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or Waas and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in th is document at authorized Government facili ties; the Contractor is prohibited from performing these tasks at or removing Government-furn ished information to any other facility ; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furn ished equipment in authorized government owned facilities regardless of remote work authorizations .

(3) Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationsh ip (Subcontractor) in support of this contract requiring the disclosure of information , documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

(4) Separation Checklist for Contractor Employees

The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify : (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (Pll)[2) , in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate: and (3) term ination of any technological access to the Contractor's facilities or systems that would permit the terminated employee's access to PII or other sensitive information.

In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed , the Prime Contractor must notify the Contracting Officer with in 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer. then the Contractor should notify the Contract Officer's Representative (COR).

B.

RFQP02162500002 Page 6 of 20

Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise , the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facil itate the return of equipment.

and Remediation

(1) Required Security and Privacy Training for Contractors

The Contractor must ensure that all employees take appropriate privacy training , including Subcontractors who have access to P II as well as the creation , use, dissemination and/or destruction of PII at the outset of the employee's work on the contract and every year thereafter. Training must include procedures on how to properly handle Pll , including heightened security requirements for the transporting or transmission of sensitive PII , and reporting requ irements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at htlQs://www.'ustice.gQ'djmd/learndo· The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness . Contractor employees are required to sign the "Privacy Rules of Behavior," acknowledging and agreeing to abide by privacy law, policy, and certa in privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ 's computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.

The Contractor should maintain copies of certi fi cates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the requ ired privacy and cybersecurity training .

(2) Safeguarding Pl/ Requirements

Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII. including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII} . Th is requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.

(3) Non-Disclosure Agreement Requirement

Prior to commencing work. all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the OOJ IT Rules of Behavior. The Non-Disclosure Agreement:

(a) prohibits the Contractor from reta ining or divulging any PII or other sensitive information , or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and

(b) requires the Contractor to report any loss of control , compromise , unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.

The Contractor should mainta in signed copies of the NOA for all employees as a record of compliance. The Contractor should also provide copies of each employee's signed NOA to the Contracting Officer before the employee may commence work under the contract/task order.

(4) Prohibition on Use of Pl/ in Vendor Billing and Administrative Records

The Contractor's invoicing, billing , and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created , obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for

RFQP02162500002 Page 7 of 20

Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.

(5) Reporting Actual or Suspected Data Breach

Contractors must report any actual or suspected breach of PII with in one hour of discovery.(4) A "breach" Is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure , unauthorized acquisition, or any simi lar occurrence where : (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose.

The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ's inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remed iating any harm to potential victims .

(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01 (5) , Reporting and Response Procedures for a Breach of Pe rsonally Identifiable Information.

(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR ; and the Contracting Officer within one (1) hour of the initial discovery .

(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj .gov.

202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the fo llowing information:

(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6) Date, time , and location of the incident.

(ii) Amount, type, and sensitivity of information that may have been lost or compromised , accessed without authorization , etc.

(iii) Contractor's assessment of the like lihood that the information was compromised or lost and the reasons behind the assessment.[7)

(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.

(v) Cause of the incident and whether the company's security plan was followed and, if not. which specific provisions were not followed.(8]

(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise .

(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required .

(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files , and event information to facilitate rapid resolution of sensitive information incidents.

(e) At the Government's discretion , Contractor employees or Subcontractor employees may be identified as no longer eligible to access PI I or to work on that contract based on their actions related to the loss or compromise of Pit.

(6) Victim Remediation

At DOJ's request, the Contractor is responsible for notify ing victims and providing victim remediation services in the event of a breach of PII held by the Contractor. its agents. or its Subcontractors, under this contract. Victim remediation services shal l include at least 18 months of cred it monitoring and. for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work , the Contractor ag rees to full cooperation in the event of a breach.

The Contractor should be self- insured to the extent necessary to handle any reasonably fo reseeable breach , with another source of income, to fully cover the costs of breach response , including but not limited to victim remediation .

RFQP02162500002 Page 8 of 20

C. Government Records Trainin OwnershiR,,.j!_nd Mana ement

(1) Records Management Training and Compliance

(a) The Contractor must ensure that all employees and Subcontractors that have access to Pl! as well as to those involved in the creation. use. dissemination and/or destruction of Pl! take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR.

This training will be provided at the outset of the Subcontractor's/employee's work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management tra ining.

(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records conta ining Pl! and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission. or state of completion .

(2) Records Creation, Ownership, and Disposition

(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information.

The Contractor shall certify , in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.

(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor's Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data del iverables to permit the agency to use the data.

(c) The Contractor shall not reta in. use, sell , disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer's Representative . The Agency and its contractors are responsib le for preventing the alienation or unauthorized destruction of records , including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.

D. Data Privacy and Oversigh

(1) Restrictions on Testing or Training Using Real Data Containing Pl/

The use of rea l data containing PII from any source for testing or training purposes is generally prohibited . The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.

(2) Requirements for Contractor IT Systems Hosting Government Data

The Contracto r is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration , testing, training, maintenance, use, or disposal.

(3) Requirement to Support Privacy Compliance

(a) If this contract requires the development, maintenance or administration of information technology[9] , the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document. if requested by

RFQP02162500002 Page 9 of 20

Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required . The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj .gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.

(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation , the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO}, and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion .

The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53 , Rev. S; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key 0MB guidelines, e.g., 0MB Circular A-130.

[1] "[T)he term ·record ' means any item, collection, or grouping of information about an individual that is maintained by an agency, including , but not limited to, his education, financial transactions, medical history , and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or vo ice print or a photograph ." 5 U.S.C . § 552a(a)(4) . "[T)he term 'system of records' means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol. or other identifying particular assigned to the individual." 5 U.S.C. § 552a(a)(5).

(21 As stated in FAR 52.224-3 and Office of Management and Budget (0MB) Circular A-130. Managing Federal Information as a Strategic Resource (2016), "'personally identifiable information' means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual." Regarding "sensitive PII,'' ' [t]he sensitivi ty level of the PII will depend on the context, including the purpose for which the PII is created , collected , used, processed , stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals' names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared , and the abi lity to access the information ." OMS Circular A-130, at App. 11 -2.

[3) The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.

[4) As stated in DOJ Instruction 0900, "Contractors must notify the Contracting Officer, the Contracting Officer's Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents , including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines. and the US-CERT notification guidelines."

[5] https://www.justice .gov/fi le/4336/download [6) As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII ; purpose for which PII is collected , mainta ined, and used; extent to which PII identifies a peculiarly vulnerable population ; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e .g., whether PI I was structured or unstructured) ; leng th of time PII was exposed; any evidence confirming that PII is being misused or that ii was never accessed .

[7] As stated in DOJ Instruction 0900 , the report should include the nature of the cyber threat (e .g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.

[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible. usable , and intentionally targeted .

(9) As defined in 40 U.S.C. § 11 101 , the term "information technology· means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition , storage, analysis, evaluation, manipulation. management, movement, control , display , switch ing , interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and simi lar procedures, services (including

RFQP02162500002 Page 10 of 20 support services) , and related resources; but does not include any equipment acquired by a federal contractor incidenta l to a federal contract.

(1 OJ In this instance, the term ·project" is used to scope the activities (e.g., creating , collecting , using , processing, storing , maintaining, disseminating , disclosing , or disposing of in formation) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.

(End of Clause)

DOJ-05 Security of Department Information and Systems DOJ-05 (OCT 2023)

I. Applicability to Contractors and Subcontractors Section 2839.102 of the Justice Acquisition Regulation (JAR), (48 C.F.R. § 2839.102), applies to this contract. Accordingly.

all contractors are obligated to comply with all applicable DOJ security policies. directives. or guidance documents , including the security requiremen ts in the provisions in this contract clause. This contract clause applies to all contractors and subcontractors, including cloud service providers ("CSPs"), and personnel of the contractors and subcontractors (hereinafter collectively, "Contractor") that may access, collect, store, process, ma intain . use, share, retrieve, disseminate. transmit. or dispose of DOJ Information. The security requirements set forth herein are in addition to those required by the Federal Acquisition Regulation ("FAR"), and any other applicable laws, mandates. contract clauses. DOJ policies, directives or guidance documents and Executive Orders pertaining to the development and operation of Information Systems and/or the protection of Government Information. This clause does not alter or diminish any existing rights. obl igations, or liability under any other civil and/or criminal law, rule , regulat ion, or mandate.

II. General Definitions The following general definitions apply to this clause . Specific definitions also apply as set forth in other paragraphs.

A. Authorization to Ope rate (" ATO"), as defined in National Institute of Standards and Technology ("NIST") Special Publication ("SP") 800-37 Revision 2, is the official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission , functions, image, or reputation) , agency assets , individuals. other organizations.

and the Nation based on the implementation of an agreed-upon set of security and privacy controls.

B. Cloud Computing . as defined in DOJ Order 0904 Cybersecurity Program, is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e .g., networks, servers, storage , applications. and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics.

three service models. and four deployment models in accordance wi th NIST SP 800- 145 .

C. Covered Contract is any contract , order or other agreement under which the contractor, or a subcontractor at any tier, including a cloud service provider, may access, collect, store , process. maintain, use. share. retrieve.

disseminate , transmit, or dispose of DOJ Information (a s defined below) in the course of providing a product or service to the Department, with the exception of acquisitions under the micro-purchase threshold.

D. Covered Information System means any information system used for. involved with, or allowing , the processing, storing , or transmitting of OOJ In formation under a Covered Contract.

E. Data means recorded information , regard less of form or the media on which it may be recorded . The term includes technical data, computer software, and personally identifiable information (PII) (defined below) . The term does not include information incidental lo contract administration. such as financial , administrative, cost or pricing , or management information.

F. DOJ Information . as defined in DOJ Order 0904 , means any Information that is owned , produced . controlled .

protected by, or otherwise within the custody or responsibi lity of the DOJ. including . without limitation , information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ. (2) managed or acquired by the Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired to perform the contract.

RFQP02162500002 Page 11 of 20

G. Information, as defined in DOJ Order 0904, is any communication or representation of knowledge such as facts , data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. This includes any communication or representation of knowledge in an electronic format tha t allows it to be stored, retrieved , or transmitted .

H. Information System, means a discrete set of information resources organized for the collection , processing, maintenance, use, sharing , dissemination, or disposition of information (44 U.S.C. 3502(8)) .

I. Personally ldentifia ble Information ("PII") . as defined in the FAR 24.101, means information that can be used to distinguish or trace an individua l's identity , either alone or when combined with other information that is linked or linkable to a specific individual. It includes but is not limited to common data elements such as names, addresses, dates of birth, and places of employment, to identity documents , Social Security numbers or other government-issued identifiers, precise location information, medical history, and biometric records.

This definition covers all PII that is created by or becomes available to the contractor, including its employees, subcontractors, or affiliates, as a result of performing under this contract. PII , as supplementally defined in DOJ Order 0904 , also includes information about an individual maintained by an agency, including , but not limited to.

information re lated to education , financial transactions, medical history, and criminal or employment history and informa tion , which can be used to distinguish or trace an individual's identity .

J. Private Cloud , as defined in NIST SP 800-145, is the deployment model for cloud infrastructure provisioned for exclusive use by a single organization compri sing multiple consumers (e.g., business units) . It may be owned, managed, and operated by the organization, a third party, or some combination of them. and it may exist on or off premises .

K. Security Breach means any security incident (as defined below) that directly relates to the loss of contro l, compromise. exfiltration , manipulation, unauthorized disclosure, unauthorized acquisition, unauthorized exposure or unauthorized access or any similar occurrence of any Covered Information System or any DOJ Information or any Pll accessed by , retrievable from, processed by, stored on , or transmitted within , to or from any such system. This includes incidents where (1) a person other than an authorized user accesses or potentially accesses PII or DOJ Information or (2) an authorized user accesses or potentially accesses Pll or DOJ Information for an unauthorized purpose.

a. Potential Security Breach (hereinafter, "Potentia l Breach") means any suspected, but unconfirmed security breach (as defined above).

b. Confirmed Security Breach (hereinafter, "Confirmed Breach") means any confirmed security breach (as defined above).

L. Security Incident means any occurrence that (1) may actually or imminently jeopardize , without lawful authority , the availability, integrity, authentication, confidentiality , or nonrepudiation of DOJ Information or a Covered Information System; or (2) may constitute a violation or imminent threat of violation of law. security pol icies, security procedures. or acceptable use policies.

a. Potential Security Incident means any suspected, but unconfirmed security incident (as defined above).

b. Confirmed Security Incident means any confirmed security incident (as defined above).

M. Vulnerability , as defined in DOJ Vulnerabil ity Management Plan. and the OCIO Information Security Management Procedure, means a weakness or flaw discovered in the design of a system that, when exploited, may result in a loss of confidentially , integrity, or availability of DOJ Information or an Information System.

Ill. Confidentiality and Non-Disclosure of DOJ Information A. Preliminary and final contract deliverables and all associated working papers and material generated by the Contractor developed using DOJ Information, product, source code, and/or methods of operations, are the property of the U.S. Government and must be submitted to the Contracting Officer ("CO") or the CO's Representative ("COR") at the conclusion of the contract. The U.S. Government has unlimited data rights to all such deliverables and associated working papers and materials in accordance with FAR 52 .227-14 (Rights in Data-General) . The Contractor will define a method of monitoring the development activity to include any activity associated with DOJ Information, product, source code, and methods of operations. The data rights and development details shall be defined within the Contract.

RFQP02162500002 Page 12 of20

If the Contractor intends to utilize its existing data, for which it has a patent or copyright, to develop a contract del iverable, it is incumbent upon the Contractor to negotiate with the CO the proper FAR Part 27 clauses in the contract to protect its existing data.

B. Pursuant to FAR 52 .227-1 4(d){2), all documents and data produced in the performance of this contract conta ining DOJ Information, product code, source code, and/or methods of operations are the property of the U.S. Government and, without the prior written permission of the CO, the Contractor shal l neither reproduce nor release such information to any third-party at any time , including during performance or following expiration and/ or termination of the contract.

C. Any DOJ Information made available to the Contractor under this contract shall be used only for the purpose of performance of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of this contract. In performance of this contract, the Contractor assumes responsibil ity for the protection of the confidentia li ty of all DOJ Information processed, stored, or transmitted by the Contractor. The Contractor shall comply with information security respons ibilities and duties throughout the contract and after expiration/termination as appropriate per contract close-out activities. When requested by the CO (typically no more than annually) , the Contractor shall provide a report to the CO identify ing , to the best of the Contractor's knowledge and belief, the type, amount, and level of sensitivity of the DOJ Information processed , stored, or transmitted under the Contract, including an estimate of the number of individuals for whom PII has been processed, stored or transm itted under the Contract and whether such information includes social security numbers (in whole or in part).

IV. Compliance with Information Technology Security Policies , Procedures and Requirements A. For all Covered Information Systems, in addition to any other applicable requirements , as set forth in Part I, the Contractor shall comply with the security requirements of the Federal Information Security Modernization Act of 2014 ("FISMA "), Privacy Act of 1974, E-Government Act of 2002, National Institute of Standards and Technology C- NIST") Special Publ ications ("SP"), including NIST SP 800-37, 800-53, and 800-60 Volumes I and II , Federal Information Processing Standards ("FIPS") Publications 140-2, 199, and 200, Federal Risk and Authorization Management Program (" FedRAMP"), DOJ IT Security Standards as amended, and 0MB Memoranda relating to the security of information and/or Federal Information Systems.

B. In addition, for all Covered Information Systems, the Contractor shall comply with the following requirements , which are listed here only to highlight certa in specific applicable requirements from one of the sources identified in the first paragraph of th is Section. This is not an exhaustive list of all such requirements with which the Contractor is obligated to comply, and the omission of a requirement from this list should not be construed as negating the materia li ty of that requirement. These requ irements and those in the authorities in the prior paragraph should be read together.

1. Limiting access to DOJ Information and Covered Information Systems to au thorized users and to tra nsactions and functions that authorized users are permitted to exercise.

2. Providing security awareness train ing at least annually to all Contractor employees and contractors involved with the Covered Contract. Such training shall include, but not be limited to , recognizing and reporting potentia l indicators of insider threats to users and managers of DOJ Information and Covered Information Systems.

3. Creating , protecting, and reta ining , in accordance with applicable requi rements but in any event at least until the expiration of the contract , Covered Information System audit records , reports , and supporting documentation to enable reviewing , monitoring, analysis. investigation , reconstruction, and reporting of unlawful , unauthorized, or inappropriate activity related to such Covered Information Systems and/or DOJ Information.

4. Ma intaining authorizations to operate any Covered Information System.

5. Performing continuous monitoring on all Covered Information Systems, to include but not be limited to , collecting , reviewing , and analyzing appropriate logs and timely investigating security alerts and potential security incidents.

RFQP02162500002 Page 13 of 20

6. Establishing and maintaining baseline configurations and current inventories of Covered Information Systems, including hardware, software, firmware , and documentation. throughout the In formation System Development Lifecycle , and establishing and enforcing security configuration settings for IT products employed in Covered Information Systems.

7. Ensuring appropriate contingency planning has been performed. including OOJ Information and Covered Information System backups.

8. Identifying Covered Information System users. processes acting on behalf of users, or devices.

and authenticating and verifying the identities of such users, processes. or devices, using multifactor authentication or HSPD-12 compliant authentication methods as defined by NIST 800-63-3, Digital Identity Guidelines or current revision.

9. Establishing and maintaining an operational incident handling capabil ity for Covered Information Systems that includes adequate and timely development, logging. detection , analysis, containment.

recovery , and user response activities, and tracking, documenting , and timely reporting incidents to appropriate officials and authorities within the Contractor's organization and the DOJ.

10. Performing periodic and timely maintenance on Covered Information Systems, and providing effective controls on tools, techniques, mechanisms , and personnel used to conduct such maintenance.

11. Protecting Covered Information System media containing OOJ Information, including paper. digital and electronic media , and DOJ assets under Contractor control : protecting them from environmental impacts. access. and equipment positioning requirements defined: limiting access to DOJ Information to authorized users: and sanitizing or destroying Covered Information System media containing DOJ Information before disposal , release or reuse of such med ia.

12. Limiting physical access to Covered Information Systems. equipment. and physical facilities housing such Covered Information Systems to authorized personnel according to DOJ 03.

13. Screening individuals prior to authorizing access to Covered Information Systems to ensure comp liance with DOJ Security standards including personnel background checks.

14. Continuously assessing the risk to DOJ Information in Covered Information Systems . including scanning and remediating vulnerabil ities. or implementing appropriate mitigation in accordance with DOJ policy , and ensuring the timely removal of assets no longer supported by the Contractor.

15. Continuously monitoring the application of security controls of Covered Information Systems, assessing the efficacy of such controls , and developing and implementing plans of action designed to correct deficiencies and eliminate or reduce vulnerabil ities in such Covered Information Systems.

16. Monitoring , controlling, and protecting information transmitted or received by Covered Information Systems at the external boundaries and key internal boundaries of such Covered Information Systems.

and employing architectural designs. software development techniques, and systems engineering principles that promote effective security .

17. Identifying, reporting , and correcting Covered Information System security flaws in a timely manner, providing protection from mal icious code at appropriate locations. monitoring security alerts and advisories and taking appropriate and timely action in response .

18. Ensuring return of Government Furnished Equipment ("GFE") and/or PIV card assets within 10 business days of notification for end of use (contract end. staff change, etc.).

19. Complying with rights in data (FAR 52 .227-14 ) as to the development. management, and protection of DOJ Information.

20 . Reporting on risks or known issues impacting DOJ Services (staffing . hardware. process , changes, etc.) through the Contractor's CO or COR , DOJ Service Owner CSO"), and Government Technical Manager ("GTM ") including risk mitigation activities.

RFQP02162500002 Page 14 of 20

21 . Reporting through the Contractor's CO or COR on any projected or planned changes in corporate ownership, covered information system design, and/or any technica l changes that could impact the confidentiality, integrity or availabil ity of OOJ Information, data, or systems. Changes to system design must be updated through the authorization process per NIST SP 800-37 Revision 2, Step 6 ('Continuous Monitoring") or current NIST revision.

22 . When, as part of operating within the DOJ environment, the Contractor's covered information system is subject to review, audit, or assessment by th ird parties, facilitating OOJ access to information system resources, faci li ties, personnel , and documentation in a timely manner as required by the auditors. Should a third-party organization conduct a review of any Covered Information System, the Contractor must provide a copy of the report to DOJ, through the CO and COR .

23. Completing an attestation that meets 0MB Memorandum M-22-18 for software procurements followi ng the template attestation form developed by NIST. The attestation form must be returned to the CO and COR for sharing with the component Chief Information Officer (CIO) .

24 . Reporting on outages impacting OOJ Services through the Contractor's CO, COR , and DOJ Service Owner (SO) to include event and mitigation details .

C. The Contractor shall not process, store, or transmit OOJ Information using a Covered Information System without first ob taining an ATO for each Covered Information System . The ATO shall be signed by the Authorizing Official for the DOJ component responsible for maintaining the security , confidentiality, integrity , and availability of the DOJ Information under th is contract. (For Cloud Computing Systems, see Section V, below.)

D. The Contractor shall ensure compliance with DOJ-03 (Personnel Security Requirements for Contractor Employees) as to all Covered Information Systems.

E. When requested by the DOJ CO or COR as described below, the Contractor shall provide DOJ, including the Office of Inspector General (' OIG") and Federal law enforcement components, (1) access to any and all information and records, including electronic information, regard ing a Covered Information System, and

(2) physical access to the Contractor's facilities, installations, systems, operations, documents, records, and databases. Such access may include independent val idation testing of controls, system penetration testing , and FISMA data reviews by DOJ or agents acting on behalf of DOJ, and such access shall be provided within 72 hours of the request.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .