RFI-1145PCFYS0003.pdf
PDF 1 MB Posted
- Attached to
- RFI-1145PCFYS0003 - TeleSANE Services - Request for Information Federal contract opportunity
- Solicitation number
- 1145PCFYS0003
- Issued by
- Peace Corps
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Office of the Chief Financial Officer Acquisition and Contract Management
1275 First St NE Washington DC 20526
REQUEST FOR INFORMATION (RFI):
TeleSANE Service
RFI-1145PCFYS0003
THIS IS NOT A SOLICITATION. The Peace Corps Office of the Chief Financial Officer, Acquisition and Contract Management (OCFO/ACM), on behalf of the Office of the Director, is issuing this Request for Information (RFI) seeking information and capability statement for the information provided in the section, Request for Information (RFI), below. THIS IS A RFI BEING RELEASED
PURSUANT TO FEDERAL ACQUISITION REGULATION (FAR) PART 10: MARKET
RESEARCH.
1. Background
2. Requirement
The Peace Corps is seeking information from qualified sources in industry in order to provide 24/7 coverage for TeleSANE services.
3. RFI Questions
Interested vendors are requested to include, at a minimum, the following information:
a) Organization Name
b) Address
c) Website
d) Point of Contact name
e) Title
f) Telephone number
g) Email
h) Cage Code
i) NAICs Code
j) System of Award Management (SAM) Unique Entity Identifier (UEI) number
k) GSA schedule and categories, if applicable
l) Small Business status, if applicable
In addition, vendors are requested to provide brief, succinct responses to the following questions:
(Please note: should the Agency move forward with a request for quote, there will be an opportunity to provide in-depth responses at a later date) https://www.peacecorps.gov/
Peace Corps – RFI-1145PCFYS0003 Page 2 of 3
a) How many years of experience do you have in delivering and/or supporting TeleSANE services?
b) Is your company capable of providing the above listed service? If so, please provide a capability statement. Please be specific.
c) What unique capabilities do you have when offering TeleSANE and continuing educational offerings for the Peace Corps?
d) What type of technology/equipment have you used in the past to deliver TeleSANE services?
Please name the brand and model #.
e) Would you propose using the same type of technology/equipment for the Peace Corps
TeleSANE service?
f) Is your proposed technology/equipment compatible with the HIPAA compliant Zoom product?
g) When could Peace Corps realistically expect to have the TeleSANE services up and running?
h) If it is necessary for you to maintain your own medical records, how would store these records?
i) What is your capacity to recruit and sustain a workforce of trained and certified SANE nurses?
j) What is your strategy to retain TeleSANE nurses?
k) Peace Corps has a major international presence. Do you have experience providing TeleSANE services internationally, or do you have cultural competencies you can share as part of your capabilities?
PWS Section 3.0 Deliverables Questions:
l) What would your approach be to address the deliverable #8 (Testimony for cases adjudicated in the United States upon subpoena)?
m) PCMEDICS is Peace Corps' electronic medical record (EMR). It stands for Peace Corps Medical Electronic Documentation and Inventory Control System. Unlike other EMRs, PCMEDICS is an internal, organically developed medical records system. How would you provide medical documentation which can be readily input to such a system? What would your approach be to address the deliverable #6 (Template for Medical Record)?
Market Research:
Open Market:
The Peace Corps has tentatively identified North American Industry Classification System Codes (NAICS) 621999 for this requirement with a U.S. Small Business Administration (SBA) size standard of $18,000,000.00.
4. Instructions for RFI Responses and Deadline
Respondents must submit their responses in writing no later than 12:00 p.m. Eastern Standard Time, Washington, DC Local Time on December 21st, 2022, to the following POCs via email:
http://redirect.state.sbu/?url=https://www.peacecorps.gov/
Peace Corps – RFI-1145PCFYS0003 Page 3 of 3
Christina Ostronic, Contract Specialist (Costronic@peacecorps.gov) and Maria Anguiano, Contracting Officer (Manguiano@peacecorps.gov).
This is a RFI and should not be construed as a solicitation announcement. This RFI does not constitute a request for quote nor does it restrict the Government as to the ultimate acquisition approach. The submission of this information is for market research and planning purposes only. It is not to be construed as a commitment by the government to procure any services, nor is it the intent of the Peace Corps to award a contract on the basis of this RFI or otherwise pay for the information sought. Any information provided to the Government is strictly voluntary and given with no expectation of compensation and shall be provided at no cost to the Government.
Propriety information submitted in response to this RFI will be protected from unauthorized disclosure as required by the Federal Acquisition Regulation (FAR). All propriety markings should be clearly delineated. The respondent shall identify where data is restricted by propriety or other rights and mark accordingly.
*Please note Attachment 1: Performance Work Statement (PWS) (Draft) which directly follows* http://redirect.state.sbu/?url=https://www.peacecorps.gov/ mailto:Costronic@peacecorps.gov mailto:Manguiano@peacecorps.gov
PERFORMANCE WORK STATEMENT (PWS)
FOR
TeleSANE Services
FOR
Office of Health Services
1.0 GENERAL
1.1 BACKGROUND:
The Peace Corps is an independent executive agency of the federal government established in 1961 by President John F. Kennedy to promote world peace and friendship through the service of American volunteers abroad. The volunteers’ service fulfills the three primary goals established in the founding legislation:
• To help the people of interested countries in meeting their need for trained men and women
• To help promote a better understanding of Americans on the part of the peoples served;
and
• To help promote a better understanding of other peoples on the part of Americans.
For information about where Peace Corps serves, please visit the Countries page on our website:
https://www.peacecorps.gov/countries/. For more information on the Peace Corps mandate and mission, see the Peace Corps website: https://www.peacecorps.gov/about/history/. The mission of Peace Corps’ Office of Health Services (OHS) is to provide quality medical and mental health services and support to Peace Corps Invitees, Peace Corps Trainees/Volunteers (PCT/PCVs), and Returned Peace Corps Volunteers (RPCVs). Peace Corps has an internal team of on-site doctors and other medical professionals at approximately 58 Peace Corps posts located worldwide.
Medical Officers located at overseas Posts (PCMOs) provide and coordinate needed health care services for PCVs. Volunteers are typically placed in rural environments, often at a considerable distance from the Peace Corps main office and medical unit in-country. In both the major cities and in rural areas, Volunteers often face varying and limiting bandwidths, connectivity, and electricity. The Agency does not issue a mobile phone, laptop, or tablet to Volunteers. Typically, Volunteers bring a device (i.e. mobile phone, laptop, tablet, etc.) from the U.S. or purchase a device in-country. Technological limitations occur variably for each Volunteer at any given time.
For example, each region, country, and PCV site may experience intermittent electricity, limited or nonexistent internet access, and/or lack of standardized mobile devices (or no device at all)
The Kate Puzey Peace Corps Volunteer Protection Act of 2011 (Kate Puzey Act, or KPA) was passed into law on November 21, 2011. This Act mandated that “at a volunteer’s discretion, provision of a sexual assault forensic exam in accordance with applicable host country law”
RF - 1145PCFYS0003 Attachment 1 - PWS
The Office of Health Services wants to ensure that PCMOs provide a competent, trauma informed forensic-medical history and forensic exam by supplementing their training with TeleSANE services.
TeleSANE services -sometimes referred to as TeleSAFE- are an emerging branch of telemedicine that utilizes remote forensic nurse experts to communicate and collaborate with point of care clinicians to provide expert live guidance in evidence collection, intervention and quality control; using digital and telecommunication technology.
The 2011 Sexual Assault Advisory Committee also recommended that the Peace Corps work with an organization to provide TeleSANE services. They noted that “PCMOs do not provide medical forensic services on a daily basis so it is not expected for all of that knowledge to be at the forefront of their mind”.
Given the historically low numbers of SAFE exams conducted by the PCMOs, TeleSANE services will be used to build on the PCMOs skills by providing real-time technical assistance and guidance for the underutilized yet critical evidence collection skill set needed to support Peace Corps Volunteers/Trainees who request a sexual assault forensic examination- in accordance with applicable host country law.
1.2 SCOPE:
The Peace Corps seeks a contractor to provide Tele-SANE services to support PCMOs in conducting Sexual Assault Forensic Exam (SAFE) for PCV/Ts. TeleSANE services include live assistance and consultation with the SAFE exam and other related services. Tele-SANE services shall be available and adequately staffed 24 hours a day on a year-round basis (24/7/365).
1.3 OBJECTIVE:
The objective of this contract is to improve the experience of PCVs who need a SAFE exam and to promote integrity and accuracy of the evidentiary forensic collection for cases that PCMOs can legally conduct or consult on. This objective includes providing a 24-hour Tele-SANE service to assist Peace Corp Medical Officers (PCMOs) during a Sexual Assault Forensic Exam (SAFE), answer consult questions, assist and review forensic documentation, assist with evidence packaging and to provide fact and/or expert testimony.
2.0 PERFORMANCE REQUIREMENTS:
2.1 General Requirements
The Contractor shall provide trained sexual assault nurse examiners available 24/7/365 to provide live assistance with a SAFE exam. See Section X for minimum qualifications for sexual assault nurse examiners.
The Contractor shall be available to provide live services within 59 minutes of notification.
The Contractor shall provide all live services via two way visual HIPAA compliant Zoom platform. In the event there are technology/connectivity challenges with the Zoom platform, the Contractor shall provide services via telephone.
The Contractor shall discuss the case with the PCMO before engaging with the
PCV/T.
2.1.1 Engagement with PCV/T
The Contractor shall confirm there is a written consent from the PCV/T to be present during the exam.
The Contractor shall obtain an additional verbal consent directly from the
PCV/T.
The Contractor shall obtain an additional verbal consent to be present virtually during the ano-genital exam.
The Contractor shall explain to PCV/T the reason that they are there.
The Contractor shall answer any questions the PCV/T has during the exam and in the presence of the PCMO or support person.
2.2 Live Services Outlined
The Contractor shall provide live assistance to the PCMO with a sexual assault forensic exam including but not limited to:
• history taking,
• swabbing,
• collection of trace evidence,
• photography of injuries and non-injuries,
• alternate light source and
• genito-anal exam
• The Contractor shall provide live assistance with documenting the forensic examination paperwork
The Contractor shall provide live assistance with packaging forensic specimens and clothing as instructed in Technical Guideline 542 and Manual Section 243
2.3 Other Services
2.3.1 The Contractor shall create a medical record (Deliverable # 6) and send it securely to the PCMO within 12 hours of each exam.
2.3.2 The Contractor shall be available to provide fact and/or expert testimony for cases adjudicated in the United States upon subpoena.
2.3.3 The Contractor shall provide a debrief session upon conclusion of a mock or real exam within three (3) business days using a competency/QA tool and general feedback.
2.4 Training
2.4.1 The Contractor shall participate in an unannounced quarterly simulation to assess response time, technology and proficiency of procedures.
2.4.2 The Contractor shall provide scheduled mock exam trainings of the TeleSANE services to assess the equipment/supplies, technology and competencies of the health unit and PCMO(s) to 30 of the Peace Corps posts; with an estimated increase of five (5) exams per year.
2.4.3 The Contractor shall provide a minimum of three continuing education credit hours of content, supplies and presenters-related to sexual assault and/or intimate partner violence- to the annual continuing medical education conference. This will be in person or virtual dependent upon the format of the conference (estimated two CME sessions per year).
2.4.4 The Contractor shall provide one 60 to 90 minute webinar per year-on sexual assault and/or intimate partner violence- to the Peace Corps Medical Officers.
3.0 DELIVERABLES:
Item No.
Deliverable Description Frequenc y
PWS
Reference
Deliver to Format Due
1 QCP The Contractor shall submit a quality control plan (QCP) covering all task areas and deliverables in accordance with this PWS. The plan shall demonstrate how the Contractor will ensure quality performance and satisfy the requirements of the PWS
Once Section 6.1 COR Word documen t
Within 15 days of award
3 Monthly Meeting
Monthly Section 5.3.2
COR Word documen t
24 hours before monthly meeting
4 FedRAMP Authorization Plan
Documentation to validate the timeline for acquiring FedRAMP Authorized designation (not required for systems designated as FedRAMP Authorized)
Once Section 9.1.2.2
COR Documen ts
Within 90 days of award
5 Continuous Monitoring Documentation
Confirmation of maintenance of system security in accordance with FedRAMP
Monthly Section 9.1.3
FedRAMP repository
Documen ts
Monthly guidance for the system’s current designation
6 Template for Medical Record
Peace Corps and Vendor will collaborate to create the template for the Medical Record Document
Once 2.3 COR/SA Nurse
Documen t
Within 60 days of award
7 Kick-Off Meeting
Once 5.3.1 COR/Peace Corps Team
Meeting Within 10 days of award
8 Testimony for cases adjudicated in the United States upon subpoena.
As Needed 2.3.2 COR Testimon y
By provided due date
9 Unannounced quarterly simulation to assess response time, technology and proficiency of procedures.
Quarterly 2.4.1 COR/PCMOs /MOs
Virtual Meeting
By provided Due Date
10 Mock exam trainings of the TeleSANE services to assess the equipment/supplies, technology and competencies of the health unit and PCMO(s) to 30 of the Peace Corps posts; with an estimated increase in five (5) exams per year.
Annually 2.4.2 COR/PCMOs /MOs
Virtual training
TBD
11 Continuing education credit hours to the annual continuing medical education conference
Minimum of three continuing education credit hours of content per session, supplies and presenters-related to sexual assault and/or intimate partner violence- to the annual continuing medical education conference (estimated two CME sessions per year)
Annually 2.4.3 COR/PCMOs /MOs
In Person or Virtual presenta tion
TBD
12 Webinar The Contractor shall provide one 60 to 90 minute webinar per year-on sexual assault and/or intimate partner violence- to the Peace Corps Medical Officers.
Annually 2.4.4 COR/PCMOs /MOs
Webinar TBD
13 Live assistance with a SAFE exams
24/7/365 2.2 Peace Corps Clinicians
14 Conduct a debrief session for every mock
A 30 to 60 minute debrief session with Peace Corps competency/QA tool to discuss achievements and any opportunities for improvement.
As needed 2.3.3 Peace Corps Clinicians, Forensic Nurse Specialist
Virtual Meeting
Within three business days of exam.
and/or real exam.
4.0 PERFORMACNE REQUIREMENTS SUMMARY (PRS)
The contractor service requirements are summarized into performance objectives that relate directly to mission essential items. The performance threshold briefly describes the minimum acceptable levels of service required for each requirement. These thresholds are critical to mission success.
Service Output Performance Objective
Acceptable Quality Level
(AQL)
Method of Surveillance
TeleSANE Service
All required service performed within the specified time requirements.
Contractor meets the specified time requirement 95% of the time
Periodic surveillance by the COR or government designee
Training All required service performed within the specified time requirements.
Contractor meets the specified time requirement 95% of the time
Periodic surveillance by the COR or government designee
5.0 ADDITIONAL CONTRACTOR REQUIREMENTS:
5.1 Key Personnel
The Contractor shall identify Key Personnel labor categories and tasks to be completed by the designated Key Personnel. The proposed Key Personnel shall have a minimum of 5 years’ experience in the field they are being proposed.
Program Manager: The program manager must be a registered nurse with nursing management experience. Must have reporting experience. Experience with managing telehealth or TeleSANE services. Experience with budgeting and resource allocation. Cultural sensitivity is a must.
Sexual assault nurse examiners. The sexual assault nurse examiners must have a minimum of two years’ experience, certified as a SANE-A, have cultural sensitivity.
IT Support: The IT Support Personnel shall be available to provide Tier 3 Support including, but not limited to: directing remote support to users for network problems, systems integration, diagnosing problems, recommending and implementing solutions, troubleshooting data sharing infrastructure issues, solving complex system issues, and providing follow-up.
The Contractor shall identify staff for positions designated as “Key Personnel.” The Government deems these positions as critical to the performance of work under this contract. Any proposed substitutes for individuals occupying these positions shall possess qualifications equal to or superior to those of the key personnel being replaced. The inability of the Contractor to provide personnel with equal to or superior qualifications of the key personnel may result in termination of the contract. The CO may at his/her discretion add to or subtract from this list.
All key personnel are subject to the following requirements:
Replacement is subject to the prior written approval of the COR.
Requests for replacement shall include a detailed resume containing a description of position duties and qualifications, as well as information about the qualifications of the individual(s) proposed and any security clearance(s) held.
Contractor proposals to move any key personnel off the contract shall be submitted in writing at least thirty (30) days in advance of proposed move, and are subject to the approval of the COR, including approval of proposed replacement.
5.2 : The Contractor shall have the following:
• 24/7 TeleSANE support line dedicated to the Peace Corps
• HIPAA compliant portal to exchange photos and documents
• Equipment to magnify the appearance of micro-injuries
5.3 Meetings
5.3.1 Post-Award and “Kickoff” meeting:
Unless otherwise determined by the Contracting Officer, a post-award orientation and technical kickoff meeting will be scheduled within ten (10) business days following the contract award and will be coordinated by the Contracting Officer. The purpose of the conference will be to familiarize the Contractor with the contract’s administration procedures, clarifications, requirements and expectations. The meeting will be structured to achieve a clear and mutual understanding of all contractual administrative requirements and to identify any potential problems. Technical discussions will focus on the requirements of the PWS, deliverables and Contractor’s project plan. The meeting will be held at PC Headquarters, by virtual conference or via teleconference.
5.3.2 Monthly Reviews
The Contractor shall be available for monthly meetings with the COR to review reports, discuss general program operation and address any issues or concerns. Meetings may be held via teleconference or video conference. The Contractor is responsible for the meeting agenda. The date and time and method of meetings will be mutually agreed between the Contractor and Government. The Contractor shall be available to communicate on a regular basis via telephone or email, to address any problems that arise in the administration of this contract. The Contractor shall participate in a post-award (contract kick-off) meeting within 10 days after contract award. The post-award meeting will be held at the Contractor’s facility or via teleconference or video conference.
6.0 QUALITY CONTROL
6.1 Quality Control Plan
The Contractor shall submit a quality control plan (QCP) covering all task areas and deliverables in accordance with this PWS. The Contractor shall develop, implement and maintain an effective QCP to ensure that services are performed in accordance with the PWS and its established standards. The Contractor shall develop and implement procedures to identify, prevent and ensure non-recurrence of defective services. The Contractor’s quality control program is a means to assure that the work complies with the requirements of the contract award. Upon review by the PC primary COR and acceptance by the CO, the Contractor shall operate under the QCP. The QCP shall promote excellence in all functional areas of the contract, and the specifics of the QCP may be changed periodically to ensure successful performance of this contract. Upon any proposed changes, the Contractor shall submit a revised QCP to the CO/COR/ for review and acceptance.
6.2 Quality Assurance Surveillance Plan
The Government will evaluate the Contractor’s performance in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a means for evaluating whether the Contractor is meeting the performance standards/quality levels identified in the PWS and the Contractor’s quality control plan (QCP), and to ensure that the government pays only for the level of services received.
The Government intends to utilize the QASP to monitor the quality of the Contractor’s performance. The oversight provided for in the QASP will help to ensure that service levels reach and maintain the required levels throughout the contract term. Further, the QASP provides the COR with a proactive way to avoid unacceptable or deficient performance. The QASP will be finalized after acceptance of the Contractor’s QCP by the CO. The QASP is a living document; it will not be incorporated into the contract award and may be updated by the Government as necessary. The Government will use the QASP as internal guidance for determining how to monitor compliance with the contract’s terms and conditions, and for identifying non-conforming services to determine appropriate action. This plan sets forth the method and manner by which the Government intends to conduct surveillance of work under this requirement and is subject to unilateral change by the Government without modification of the contract. All work required by the PWS is subject to surveillance whether specifically included in the plan.
6.3 IT Security and Privacy Requirements
The Contractor shall implement the controls contained within the FedRAMP Cloud Computing Security Requirements Baseline and FedRAMP Continuous Monitoring Requirements for Moderate impact systems (as defined in FIPS PUB 199). These documents define requirements for compliance to meet minimum Federal information security and privacy requirements for Moderate impact systems. The FedRAMP baseline controls are based on NIST Special Publication 800-53, Revision 4, “Security and Privacy Controls for Federal Information Systems and Organizations” (as amended), and also includes a set of additional controls for use within systems providing cloud services to the federal government.
The Contractor’s solution must be identified on the FedRAMP website and designated as Ready, In Process or Authorized.
The Contractor shall follow FedRAMP guidelines and security guidance. If the system’s FedRAMP Authorized designation is revoked and the deficiencies are greater than agency risk tolerance thresholds, the solution will be determined as having become unacceptable.
6.3.1 Assessment of the System
The Contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement. The Level of Effort for the Assessment and Authorization (A&A) is based on the System’s FIPS PUB 199 categorization. The Contractor shall create, maintain and update the following documentation using FedRAMP requirements and templates, which are available at FedRAMP.gov.
• Privacy Impact Assessment (PIA)
• FedRAMP Test Procedures and Results
• Security Assessment Report (SAR)
• System Security Plan (SSP)
• Contingency Plan (CP)
• Business Impact Analysis
• Contingency Plan (CP) Test Results
• Plan of Action and Milestones (POA&M)
• Continuous Monitoring Plan (CMP)
• FedRAMP Control Tailoring Workbook
• Control Implementation Summary Table
• Results of Penetration Testing
• Software Code Review
• Interconnection Security Agreements/Service Level Agreements/Memorandum of
Agreements
The Contractor’s information systems shall be assessed by an accredited FedRAMP Third Party Assessment Organization (3PAO) initially and whenever there is a significant change to the system’s security posture in accordance with the FedRAMP Continuous Monitoring Plan.
The Government reserves the right to perform Security Assessment and Penetration Testing (of its instance). If the Government exercises this right, the Contractor shall allow Government employees (or designated third parties) to conduct Security Assessment and Penetration Testing activities to include control reviews in accordance with FedRAMP requirements. Penetration shall be supported by mutually agreed upon Rules of Engagement (RoE). Review activities include but are not limited to manual penetration testing; automated scanning of operating systems, web applications; wireless scanning;
network device scanning to include routers, switches, and firewall, and IDS/IPS; databases and other applicable systems, including general support structure, that support the processing, transportation, storage, or security of Government information for vulnerabilities.
The Contractor shall provide access to the Federal Government, or their designee acting as their agent, when requested, in order to verify compliance with the requirements for an information technology security program. The Government reserves the right to conduct on-site inspections. The Contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review.
Physical Access Considerations – If the Contractor’s solution operates within an Infrastructure as a Service (IaaS) that is FedRAMP authorized (e.g., AWS); physical access to the physical datacenter environment will be governed by the terms of access allowed by the underlying infrastructure provider as defined in the FedRAMP A&A authorization package.
RF - 1145PCFYS0003 Attachment 1 - PWS https://www.fedramp.gov/ https://www.fedramp.gov/
Identified gaps between required FedRAMP Security Control Baselines and Continuous Monitoring controls and the Contractor's implementation as documented in the Security Assessment Report shall be tracked by the Contractor for mitigation in a Plan of Action and Milestones (POA&M) document.
Depending on the severity of the gaps, the Government may require them to be remediated before a Peace Corps authorization is issued.
The Contractor is responsible for mitigating all security risks found during A&A and continuous monitoring activities. All high-risk vulnerabilities must be mitigated within 30 days and all moderate risk vulnerabilities must be mitigated within 90 days from the date vulnerabilities are formally identified. The Government will determine the risk rating of vulnerabilities.
6.3.2 Authorization of the System
The Contractor shall make available any existing assessment and authorization package for Peace Corps’ review and provide necessary documentation and access to facilitate the Peace Corps Moderate Impact SaaS A&A process.
6.3.2.1 FedRAMP Authorized Designated Systems
If the Contractor’s solution is designated as FedRAMP Authorized on the FedRAMP website (https://marketplace.fedramp.gov), Peace Corps will leverage the FedRAMP Assessment and Authorization package for the Contractor’s solution to document and assess the customer controls for which Peace Corps has responsibility and issue a Peace Corps ATO for the agency’s instance of the Contractor’s solution. The Contractor shall work with the Peace Corps to facilitate documentation and assessment of required customer controls, as necessary.
6.3.2.2 FedRAMP Ready or In Process Designated Systems
If the Contractor’s solution is NOT already designated as FedRAMP Authorized, it shall:
a. Be designated as FedRAMP Ready or FedRAMP In Process on the FedRAMP Website;
AND
b. Operate on an IaaS environment that is designated as FedRAMP Authorized; AND
c. Deliver within 90 days of contract award a completed FedRAMP Authorization Plan including compliance gaps, remediation plan, work breakdown structure and milestones that align with the timeline to achieve a FedRAMP Authorized designation within one year of contract award. This may be presented during a pre-authorization kickoff meeting. If the Contractor does not provide an acceptable FedRAMP Authorization Plan or Peace Corps’ assessment demonstrates a significant gap in capabilities that will preclude achievement of a FedRAMP authorization within one year of the contract award, Peace Corps will terminate the contract.
If all requirements defined above are met the Contractor will have one year from the date of contract award to achieve FedRAMP Authorized designation for the solution. During this transitional period, Peace Corps may issue an agency specific authorization (i.e., not FedRAMP) not to exceed one year (to allow the Contractor to achieve FedRAMP compliance) leveraging an existing ATO with another Federal Department/Agency (D/A) (with supporting A&A Package).
Without a FedRAMP Authorized designation within one year of contract award, Peace Corps will not continue to use the product and will not exercise any available option periods.
https://marketplace.fedramp.gov/
6.3.2.3 Essential Security Controls
The Contractor shall ensure these essential security controls are implemented. The Contractor shall implement FedRAMP control parameters and implementation guidance, as applicable. Further, the Contractor shall make the proposed system and security architecture of the information system available to the OCIO Security, Policy & Governance team for review and approval before commencement of system build (architecture, infrastructure, and code (as applicable)) and/or the start of A&A activities.
Table 1- Essential Security Controls
Control ID Control Title
AC-2 Account Management
AU-2 Audit Events
CM-6 Configuration Settings
CP-7 Alternative Processing Site
CP-8 Telecom Services
IA-2 (1) Identification and Authentication (Organizational Users) | Network Access to Privileged Accounts
IA-2 (2) Identification and Authentication (Organizational Users) | Network Access to Non-Privileged Accounts
IA-2 (12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials
IA-7 Cryptographic Module Authentication
MP-4 Media Storage
MP-5 Media Transport
PL-8 Information Security Architecture
RA-5 Vulnerability Scanning
SC-8 / SC-
8(1)
Transmission Confidentiality and Integrity / Transmission Confidentiality and Integrity | Cryptographic or Alternate Physical Protection
Control ID Control Title
SC-13 Cryptographic Protection
SC-17 PKI Certificates
SC-18 Mobile Code
SC-22 Architecture and Provisioning for Name / Address Resolution Service
SC-28 (1) Protection of Information at Rest | Cryptographic Protection
SI-2 Flaw Remediation
SI-3 Malicious Code Protection
SI-4 Information System Monitoring
SI-10 Information Input Validation
6.3.3 Reporting and Continuous Monitoring
Maintenance of the FedRAMP designation will be through continuous monitoring and periodic audit of the operational controls within a Contractor’s system, environment, and processes to confirm the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Continuous monitoring, security controls and supporting deliverables are updated in accordance with FedRAMP guidelines and submitted to the MAX.Gov Portal or repository designated by the FedRAMP program.
The documentation (or lack thereof) submitted to the FedRAMP-designated repository provide a current understanding of the security state and risk posture of the information systems. The documentation will allow the Federal Departments/Agencies leveraging the service providers’ cloud offering to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur. Contractors will be required to provide updated documentation and automated data feeds as defined in the FedRAMP Continuous Monitoring Plan.
6.3.3.1 FedRAMP Ready or In Process Systems
The Contractor shall provide the Peace Corps continuous monitoring deliverables in support of a one (1) year conditional authorization (if necessary) to achieve FedRAMP authorization. These deliverables confirm the maintenance of the system security and ensure progress to full FedRAMP Authorized designation. Deliverables shall include:
• Quarterly OS-including database, and web application, vulnerability scans as specified in the NIST SP 800-53 Control RA-5 parameter in Peace Corps’s Control
Tailoring Workbook (deliverable shall include raw results and findings shall be included in the POA&M document);
• Quarterly Plan of Action and Milestones (POA&M);
• Annual A&A Package updates including the System Security Plan, Contingency Plan, Business Impact Analysis, Configuration Management Plan, Contingency Plan Test Report, and Annual FISMA Assessment.
Upon achievement of FedRAMP Authorized designation, Peace Corps will accept the FedRAMP A&A and continuous monitoring documentation made available on the MAX.Gov Portal or a repository designated by the FedRAMP program in agreement with FedRAMP guidelines to satisfy the continuous monitoring requirement.
6.3.4 Personnel Security Requirements
All contractor and subcontractor personnel performing work under this contract shall satisfy all requirements for appropriate security eligibility in dealing with access to facilities, information and information systems belonging to or being used on behalf of the Peace Corps. This includes providing all requested information and completion of necessary forms for the purpose of processing Contractor personnel for a background investigation deemed sufficient for access to the Peace Corps’ facilities and logical access to the Peace Corps information systems. The Contractor shall be responsible for ensuring compliance with the below requirements by all of the Contractor’s and subcontractor’s staff. It is the responsibility of the Contractor to provide technically qualified and cleared/security eligible personnel to satisfy this requirement.
In compliance with Homeland Security Presidential Directive 12 (HSPD-12), the Peace Corps will conduct background checks of all new Contractor employees to verify their suitability for access to federal space. If a proposed Contractor employee has an active security clearance granted by another Federal agency, which can be verified through Office of Personnel Management’s Clearance Verification System, and the contractor employee was processed via HSPD-12 Personal Identity Verification procedures, the proposed contractor employee will normally not have to be re-investigated.
Contractor employees will be required to submit the following documents at least 14 days prior to the date that they expect to begin work: an OF-306, Fair Credit Release, Tax Check Waiver, two fingerprint cards and photocopies of two IDs (e.g., passport, driver’s license, voter registration card, etc.) taken by the fingerprinting official, and PC-1336 or narrative signed statement indicating whether the individual Contractor or any of the Contractor’s employees who have unescorted access to Peace Corps premises or access to Peace Corps IT networks in performing work for the Peace Corps have been involved in or have had any connection with intelligence activities or related work, and if so, the nature and dates of this involvement. In addition, the COR will submit a Work Access Authorization Form (WAAF) on behalf of each Contractor employee. Upon submission of these documents, the Peace Corps’ Office of Safety and Security (S&S) will usually require the Contractor to complete E-QIP, the online security questionnaire.
Failure to meet the requirement of the PC-1336 will result in the individual contractor being rated ineligible for consideration. Individuals who have been engaged in certain intelligence activity or related work or who have been employed by or connected with an intelligence agency are ineligible to serve as Contractors who have unescorted access to Peace Corps premises or access to Peace Corps IT networks.
Acceptance to serve as Contractors who have unescorted access or access to Peace Corps IT networks may preclude employment by certain intelligence organizations for a specific period of time, determined by the employing agency, after the subject Peace Corps work ceases.
Contractors who have unescorted access to Peace Corps premises or access to Peace Corps IT networks, cannot within the last 10 years (a) have been employed by an Intelligence Agency; (b) have engaged in intelligence activity; or (c) have a relationship with an Intelligence Agency or intelligence activity. The Peace Corps permanently bars from Contractor work which requires unescorted access to Peace Corps premises or access to Peace Corps IT networks any person who has been employed by the Central Intelligence Agency (CIA).
Intelligence Agency is defined as (a) any agency, division of an agency, or instrumentality of the United States Government that is a member of the United States Intelligence Community and (b) any other agency, division of an agency, or instrumentality of the United States Government or any foreign government, a substantial part of whose mission has been determined by the General Counsel to include intelligence activity or related work. This bar on an applicant who is or was employed by an Intelligence Agency applies whether or not the applicant was engaged in intelligence activity for the Intelligence Agency.
Intelligence activity is defined as any activities or specialized training involved or related to the clandestine collection of information, or the analysis or dissemination of such information, intended for use by the US Government or any foreign government in formulating or implementing political or military policy in regards to other countries and/or the involvement in covert actions designed to influence events in foreign countries. The fact that the name of an employer or the description of a person’s work uses or does not use the term “intelligence” does not, in and of itself, mean that the person has or has not engaged in intelligence activity or related work.
Additionally, employment is defined as the existence of a relationship of employer and employee, whether full-time or part-time, permanent or temporary, whether or not the individual is engaged in intelligence activity for an employer, without regard to the length of time the relationship existed or is proposed to exist, and includes for purposes of this restriction individuals performing duties as volunteers, fellows, interns, consultants, personal services contractors, contractors, and employees of contractors who were assigned to work for an Intelligence Agency or to engage in intelligence activities. Employees of contractors who were or are not themselves assigned to work for an Intelligence Agency or to engage in intelligence activities are not considered to have been or to be employed by an Intelligence Agency.
Additionally, applicants whose background discloses a relationship to an Intelligence Agency or intelligence activity may be ineligible to serve as Contractors who have unescorted access to Peace Corps premises or access to Peace Corps IT networks. The term relationship means any association with an Intelligence Agency or with an intelligence activity, if such association could be the basis for an inference or the appearance that an applicant was engaged in an intelligence activity. The association could include, but not be limited to, one based upon familial, personal, or financial connection to an Intelligence Agency or with an intelligence activity. Determinations of the eligibility or periods of ineligibility of such applicants will be made by the General Counsel on a case by case basis. Except when the CIA or the National Security Agency (NSA) is involved, if a connection with an Intelligence Agency involves an immediate family member who works or has worked in intelligence, the immediate family member should complete the form, not the contractor. If an individual Contractor has an immediate family member who works for or has worked for the CIA, s/he should not give them this PC-1336 form to complete. Rather, she/he must contact the relative in person – not by phone, email, social networking, or any other means that is not in person – and ask him or her to contact the General Counsel at the CIA. If the intelligence connection involves the NSA, the contractor (or, if the connection is with a family member, that person) must contact NSA’s Pre-Pub Office at 443-634-4095 before submitting this PC- 1336 form to Peace Corps.
Upon submission of all required documents, the Peace Corps’ Office of Safety and Security (S&S) will conduct required records checks. Following the receipt of the results of those inquiries, a determination will be made as to whether or not the Contractor employee should be given interim access while the remainder of the investigation is completed. If a favorable determination is made, S&S will grant interim access and issue an identification badge that will be used by the Contractor employee to gain access to the Peace Corps facilities. Additionally, the Contractor employee shall abide by all physical requirements of the Agency, e.g. wearing of ID cards, evacuation plans, etc.
Upon the favorable adjudication of the completed investigation, the Contractor employee’s status will be changed from interim to final. If however, during the course of the investigation, an issue is discovered that could impact on granting final unescorted access status or access to Peace Corps information systems, the Contractor employee will be barred from unescorted access to the Peace Corps facilities or IT systems until the precipitating issue can be resolved.
If for any reason, at the sole discretion of the Peace Corps, the Office of Safety and Security denies a Contractor employee final unescorted access, the Contractor shall immediately assign a replacement resource with similar qualifications to provide the required services. The replacement employee will be subject to the requirements of this section.
At the end of the Contractor employee’s performance at the Peace Corps facility, whether at the end of the contract or during the period of performance, the Contractor employee shall turn in his/her Peace Corps issued identification badge to the COR and all individually issued Peace Corps furnished equipment prior to departure. The applicable Peace Corps Staffing Analyst for the COR will promptly remove the Contractor employee from the Peace Corps software tracking systems such as e-mail, Personnel Tracking System (PTS), etc.
Contractors are notified that, should the personnel they provide as part of their quotes not be available for immediate commencement of this requirement in accordance with the Key Personnel Clause and replacement candidates are not provided within 10 calendar days, the Peace Corps reserves the right to unilaterally de-obligate the funds under the contract and solicit a new contractor.
The Contractor shall provide a report of separated staff on a monthly basis, beginning 60 days after execution of the contract.
6.3.5 Sensitive Information Storage
Sensitive But Unclassified (SBU) information, data, and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The Contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to Government control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following NIST Special Publication 800-88, “Guidelines for Media Sanitization.” The destruction, purging or clearing of media specific to the CSP will be recorded and supplied upon request of the Government.
6.3.6 Protection of Information
The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The Contractor shall also protect all Government data, equipment, etc. by treating the information in accordance with its FISMA system categorization.
All information about the systems gathered or created under this contract should be considered as SBU information. If Contractor personnel must remove any information from the primary work area that is included in the ATO boundary, they should protect it to the same FedRAMP requirements. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.
6.3.6.1 Unrestricted Rights to Data
The government will retain unrestricted rights to government data. The ordering activity retains ownership of any user created/loaded data and applications hosted on vendor’s infrastructure, as well as maintains the right to request full copies of these at any time.
6.3.6.2 Personally Identifiable Information
Personally Identifiable Information (PII) is in the scope of acquisition and PII is expected to be stored in the vendor's cloud solution. The vendor shall prepare a Privacy Threshold Assessment (PTA) to either document PII is not in scope, or determine which categories of information will be stored, processed, or transmitted by the system. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.
PII (should it come into scope) will require the following guidelines be adhered to.
• The vendor’s information system must be authorized at least at the FIPS PUB 199 Moderate level.
• For any system that collects, maintains or disseminates PII, a PIA must be completed by the Contractor and provided to the Peace Corps Privacy Office for review along with the other authorization to operate (ATO) documents.
• If the system retrieves information using PII, the Privacy Act applies and it must have a system of records notice (SORN) published in the Federal Register.
• If PII is collected from individuals by the system, a Privacy Act Statement (i.e., Privacy Notice) must be provided to users prior to their use of the application on what data is being collected and why, as well as the authority for the collection and the impact of not providing some or all of it. The Privacy Act Statement must be available to the individual directly on the form used to collect the information. Providing a link back to the Statement from the form is acceptable.
6.3.6.3 Protected Health Information
The Contractor meets the definition of business associate, “Business associate” shall generally have the same meaning as the term “business associate” at 45 CFR 160.103 of the Health Insurance Portability and Accountability Act (HIPAA) and the Peace Corps meets the definition of a covered entity. “Covered entity” shall generally have the same meaning as the term “covered entity” at 45 CFR 160.103 of the HIPAA. Therefore, a Business Associate Agreement (BAA) between the Contractor and the Peace Corps is required to comply with HIPAA Rules, “HIPAA Rules” shall mean the Privacy, Security, Breach
Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164. Section H.3 serves as the required BAA. As a Business Associate, the Contractor shall comply with the HIPAA applicable to a business associate performing under this Contract. The following terms used in this contract shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
• The Contractor shall not use or disclose protected health information and use appropriate safeguards to prevent use or disclosure of Protected Health Information (PHI) or Personally Identifiable Information (PII) except as permitted or required by this contract or as required by law.
• The Contractor shall use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits in the execution of this contract.
• The Contractor shall mitigate, to the extent practicable, any harmful effect that is known to the Contractor of a use or disclosure of PHI/PII in violation of the requirements of this contract.
• The…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .