RFQ_88310323Q00076_Combined syn sol_Archive Social.pdf
PDF 400 KB Posted
- Attached to
- NARA Archive Social Federal contract opportunity
- Solicitation number
- 88310323Q00076
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NARA – 88310323Q00076
(i)This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in FAR Subpart 12.6, Streamlined Procedures for Evaluation and Solicitation for Commercial Items as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotations are being requested and a written solicitation will not be issued.
(ii) The solicitation number is 88310323Q00076 and is issued as a Request for Quotation (RFQ).
All responsible sources may submit a quotation which shall be considered by the agency.
(iii) The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2023-02 effective March 16, 2023.
(iv) NARA intends to make an award to Archive Social IAW FAR 13.106-1(b)(1)(i) under NAICS Code 513210
(v) CONTRACT LINE ITEM NUMBER(S): See Enclosure 1, Schedule of Prices.
(vi) REQUIREMENT: This is a purchase for monthly social media archive hosting, support and associated data services, with an additional optional 2 sprints of professional services, both described on the attached schedule.
(vii) PERIOD OF PERFORMANCE: The period of performance will be 6 months from date of award.
(viii) FAR provision 52.212-1, Instructions to Offerors - Commercial Items (Mar 2023) applies to this acquisition.
(ix) 52.212-2 is not applicable- Soliciting from a Single Source IAW FAR 13.106-1(b)(1)(i)
(x) FAR provision 52.212-3, Offeror Representations and Certifications - Commercial Items (Dec 2022) - The Offeror shall complete only paragraph (b) of this provision if the Offeror has completed the annual representations and certification electronically in the System for Award Management (SAM) accessed through https://www.sam.gov. If the Offeror has not completed the annual representations and certifications electronically, the Offeror shall complete only paragraphs (c) through (v) of this provision.
(xi) FAR clause 52.212-4, Contract Terms and Conditions - Commercial Items (DEC 2022) – see Enclosure 4 (Addenda to FAR clause 52.212-4).
(xii) FAR clause 52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders - Commercial Items (MAR 2023) - see Enclosure 4, FAR Clauses for the full text of this clause and for additional applicable FAR clauses.
(xiii) See Enclosure 3 for additional terms and conditions
(xiv) DPAS Not Applicable
(xv) QUOTATION DUE DATE: May 12, 2023, 5:00PM ET
(xvi) QUOTATION SUBMISSION INSTRUCTIONS:
Submit to Ty Senour at tyler.senour@nara.gov
Enclosure 1
SCHEDULE OF PRICES
CLIN DESCRIPTION QTY Unit Unit Price Extended Price
0001 Monthly EOP-45 social media archive hosting, support, and associated data services.
The discovery sprint scope shall be investigation of capture issues with social media records from the previously provided SIPs including Instagram, Youtube and Flickr and delivery of SOW(s) for recovery and data delivery of updated SIPS. The SOW(s) created may be executed via optional sprints under CLIN 0002.
Subscription term: 6 months from date of award
6 Mo $
0002 Optional CLIN IAW FAR 52.217-7, Option for Increased Quantity-Separately Priced Line Item
Fixed Price per sprint - one agile software engineering team sprint - cross-functional agile team of 2 weeks duration for execution of CLIN 001 SOW(s) for social media record recovery and data delivery of updated SIPs including Instagram, Youtube and Flickr where capture issues of records were discovered Max # of sprints: 2
As part of the Agile process, at the beginning of each sprint, NARA will approve the specific plans for each iteration and acceptance criteria; establish the priorities; approve plan revisions reflecting the experience from completed iterations, and approve final deliverables to determine whether it meets the stated requirements.
Prior to each sprint, the Contractor and NARA shall agree upon a sprint cadence and a Definition of Done for the upcoming sprint, including any required deliverables.
2 EA
The Government reserves the right to reject any invoice for which an iteration failed to meet pre-established, agreed-to objectives
Enclosure 2
CONTRACT ADMINISTRATION
I. GOVERNMENT CONTRACT ADMINISTRATION
a. This Contract will be administered by:
National Archives and Records Administration Office of the Chief Acquisition Officer (Z) 8601 Adelphi Road, Room 3340 College Park, MD 20740-6001
b. Contract Specialist (CS):
See award document.
c. Contracting Officer (CO):
Any warranted Z CO.
The CO has the overall responsibility for the administration of this Contract. Written communication to the Contract Specialist must reference the contract number and must either be emailed or mailed, postage prepaid, to the above address.
The CO alone, without delegation, is authorized to take actions on behalf of the Government to amend, modify, or deviate from the contract terms, conditions, requirements, specifications, details and/or delivery schedules; make final decisions on disputed deductions from contract payments for non-performance or unsatisfactory performance; terminate the contract for convenience or default; and issue final decision contract questions or matters under dispute. However, the CO may delegate certain other responsibilities to authorized representatives.
II. CONTRACTING OFFICER’S REPRESENTATIVE (COR) LEVEL 1:
a. COR: See award document
b. The individual named above is designated as the Contracting Officer’s Representative (COR) to assist the CO in the discharge of the CO’s responsibilities. The COR serves as the point of contact through which the Contractor can relay questions or problems of a technical nature to the CS and the CO. The COR is responsible for the inspection and acceptance of the contract requirements and for the review and certification of invoices for the contract requirements.
c. In no event will any understanding or agreement, modification, change order, or other matter deviating from the terms of the contract between the Contractor and any person other than the CO be effective or binding upon the Government.
d. When, in the opinion of the Contractor, the COR requests effort outside the existing scope of the contract, the Contractor must promptly notify the CO in writing.
e. No action will be taken by the Contractor under such technical instruction unless the CO has issued a contractual change.
III. ELECTRONIC INVOICING AND PAYMENT REQUIREMENTS – INVOICE PROCESSING
PLATFORM (IPP) (JANUARY 2020)
Payment requests must be submitted electronically through the U. S. Department of the Treasury's Invoice Processing Platform System (IPP).
"Payment request" means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in the applicable Prompt Payment clause included in the contract, or the clause 52.212-4 Contract Terms and Conditions – Commercial Items included in commercial item contracts. The IPP website address is: https://www.ipp.gov.
Under this contract, the following documents are required to be submitted as an attachment to the IPP invoice: Invoices shall be submitted after Government’s acceptance of all deliverables. The invoice shall contain information required by FAR 52.212-4(g).
Contractor Invoice to include:
1. Award number
2. CLIN/Item number of deliverable
3. Description of deliverable
4. Price of deliverable
5. Quantity of deliverable
6. Date deliverable was provided to the Government for inspection if applicable
7. Serial number/part number if applicable
The Contractor must use the IPP website to register, access and use IPP for submitting requests for payment. Assistance with enrollment can be obtained by contacting the IPP Customer Support Helpdesk by sending an email to IPPCustomerSupport@fiscal.treasury.gov or phone (866) 973-3131.
If the Contractor is unable to comply with the requirement to use IPP for submitting invoices for payment, the Contractor must submit a waiver request in writing to the Contracting Officer with its proposal or quotation.
IV. FINAL PAYMENT
Before final NARA payment is made, the Contractor must furnish to the CO a written release of all claims against the Government arising by virtue of the contract, other than claims in stated amounts as may be specifically excluded by the Contractor from the operation of the release. If the Contractor’s claim to amounts payable under the contract has been assigned under the Assignment of Claims Act of 1940, as amended (31 U.S.C. § 203, 41 U.S.C. § 15), a release may also be requested of the assignee. To ensure that all necessary adjustments for non-performance or unsatisfactory performance have been made and a release of claims has been submitted before the contract is closed out, the final NARA payment will be made in thirty (30) calendar days after receipt of a proper invoice, date of completion of performance, or receipt of release of claims by the CO, whichever is later.
Enclosure 3
ADDITIONAL NARA TERMS AND CONDITIONS
I. LOW IMPACT SOFTWARE AS A SERVICE MINIMUM SECURITY REQUIREMENTS
(a) NARA's Chief Privacy Officer, and Cybersecurity and Information Assurance Division (IS) performed a thorough review of the risk these services pose to NARA and the current FedRAMP guidance on LI-SaaS. Consistent with OMB A-130 and in accordance with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, Guide for Applying theRisk Management Framework to Federal Information Systems, NARA has developed the following terms and conditions applicable to LI-SaaS based on the FedRAMP tailored guidance for LI-SaaS. All the tailored FedRAMP requirements not included in NARA's baseline are documented as accepted risks from the Designated Accrediting Authority
(DAA).
(b) These terms and conditions are applicable to the Cloud Service Provider (CSP) or reseller of the software-as-a-service, and must flow down to any subcontractor providing the government with a software-as-a-service. These requirements ensure the minimum requirements are in place to be alerted to a network intrusion and determine the source of that intrusion, as well as what information may have been compromised.
(c) Minimum Security Requirements for LI-SaaS Acquisition:
Control ID Control Name Requirement
AU-2 Audit Events The information system shall be capable of auditing the following events:
1. Successful and unsuccessful attempts to access, modify, or delete security objects
2. Successful and unsuccessful logon attempts
3. Privileged activities or other system level access,
4. Starting and ending time for user access to the system,
5. Concurrent logons from different machines
6. Successful and unsuccessful accesses to objects
7. All program initiations
8. All direct access to the information system.
AU-3 Content of Audit Records
The information system shall generate audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event. In order to achieve this, audit records must include the following:
1. Date and time of the event
2. The component of the information system (e.g., software component, hardware component) where the event occurred
3. Type of event
4. Subject identity
5. The outcome (success or failure) of the event
AU-6 Audit Review, Analysis, and Reporting
For the system, administrators must:
1. Review and analyze information system audit records at least on a weekly basis for indications of inappropriate or unusual activity
2. Report findings to designated officials AU-8 Time Stamps The information system shall:
1. Use internal system clocks to generate time stamps for audit records;
2. Record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT)
AU-9 Protection of Audit Information
The information system shall protect audit information and audit tools from unauthorized access, modification, and deletion.
AU-12 Audit Generation The information system shall:
1. Provide audit record generation capability for the list of auditable events defined above in AU-2
2. Allow administrators to select which auditable events are to be audited by specific components of the information system
3. Generate audit records for the list of audited events defined in AU-2 with the content as defined in AU-3
IA-2 Identification and Authentication
The information system shall:
1. Uniquely identify and authenticate users (or processes acting on behalf of users)
2. Implement multifactor authentication for network access to privileged accounts.
IR-1 Ensures a capability exists for reporting security incidents.
Ensures a capability exists for responding to security incidents.
The SaaS provider shall develop, document, and disseminate to SaaS personnel:
• An incident response policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among entities, and compliance
• Procedures to facilitate the implementation of the incident response policy and associated incident response controls
• Review and update the current incident response policy and incident response procedures at least annually
SI-2 Flaw Remediation The SaaS provider shall:
• Identify, report, and correct information system
Flaws
• Test software updates related to flaw remediation for effectiveness and potential side effects on information systems before installation
• Incorporate flaw remediation into the SaaS provider's configuration management process.
• Installs security-relevant software and firmware updates within the following defined timeframes related to vulnerability severity:
30 days for critical and high vulnerabilities 60 days for medium vulnerabilities 90 days for low vulnerabilities
SI-3 Malicious Code
Protection The information system shall:
1. Employ malicious code protection mechanisms at information system entry and exit points to detect and eradicate malicious code:
• Transported by electronic mail, electronic mail attachments, web accesses, removable media, or other common means; or
• Inserted through the exploitation of information system vulnerabilities
2. Update malicious code protection mechanisms (including signature definitions) whenever new releases are available
3. Configure malicious code protection mechanisms to:
a. Perform periodic scans of the information system and real-time scans of files from external sources at as the files are downloaded, opened, or executed
b. block malicious code; quarantine malicious code; and send an alert to administrators in response to malicious code detection
II. INTERNET PROTOCOL (MAY 2021)
The Vendor shall ensure that all systems, including hardware, software, firmware, and/or network components developed, procured, or acquired in support and/or performance of this delivery order using the Internet Protocol (IP) are developed and used, in accordance with, commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile. All products or systems using the Internet Protocol may maintain provisions for IPv4 backward compatibility for non-governmental use.
III. SECURITY OF INFORMATION AND PROTECTION OF CONTROLLED
UNCLASSIFIED INFORMATION, INCLUDING PERSONALLY IDENTIFIABLE
INFORMATION (APRIL 2017)
(a) Applicability
This clause applies to all controlled unclassified information, which may include personally identifiable information, as defined in Section B, regardless of the medium in which it is found and includes paper records.
(b) Definitions. As used in this clause:
“Breach” means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to personally identifiable information, in usable form whether physical or electronic.
“Controlled Unclassified Information” means information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or Government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic;
requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.
“Personally identifiable information (PII)” means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States. Examples of PII include the following:
(1) Name.
(2) Date of birth.
(3) Mailing address.
(4) Telephone number.
(5) Social Security Number.
(6) Email address.
(7) Zip code.
(8) Account numbers.
(9) Certificate/license numbers.
(10) Vehicle identifiers including license plates.
(11) Uniform resource locators (URLs).
(12) Internet protocol addresses.
(13) Biometric identifiers (e.g., fingerprints).
(14) Photographic facial images.
(15) Any other unique identifying number or characteristic.
(16) Any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive personally identifiable information (sensitive PII)” means a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
(1) Complete social security numbers, alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered sensitive PII even if they are not coupled with additional PII.
(2) Additional examples include any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
(i) Driver’s license number, passport number, or truncated social security number (such as last 4 digits);
(ii) Date of birth (month, day, and year);
(iii) Citizenship or immigration status;
(iv) Financial information such as account numbers or electronic funds transfer information;
(v) Medical information; and/or
(vi) System authentication information such as mother’s maiden name, account passwords or personal identification numbers.
(3) Other PII may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but it is not sensitive.
(c) Data Security.
(1) The Contractor shall limit access to the data covered by this clause to those employees and subcontractor who require the information in order to perform their official duties under this contract.
(2) The Contractor employees, and subcontractors must physically or electronically secure CUI, which may include sensitive PII, when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss.
(3) When CUI is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed in accordance with NIST 800-88 standards.
(4) The Contractor shall only use CUI obtained under this contract for purposes of the Contractor; it shall not be disclosed, released, disseminated, or published without the prior written consent of the Contracting Officer.
(5) If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, The Contractor shall follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.
(6) At expiration or termination of this contract, the Contractor shall turn over all CUI obtained under the Contractor that is in its possession.
(d) Systems Access. Work to be performed under this contract may require the handling of CUI, including PII. The Contractor shall provide the Government access to, and information regarding those systems handling CUI, including sensitive PII for the Government under the Contractor, when requested by the Government, as part of the Contractor’s responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the Government in assuring compliance with such requirements. Government access shall include independent testing of controls, system penetration testing by the Government, Federal Information Security Management Act data reviews, and access by agency Inspectors General (IG) for IG reviews.
When requested by the NARA CO or COR or other NARA official as described herein, in connection with NARA’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of NARA Information, Contractor shall provide NARA, including the NARA OIG,
(1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Contractor's facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation of testing controls, system penetration testing, and FISMA data reviews by NARA or agents acting on behalf of NARA, and such access shall be provided within 72 hours of the request. Additionally, the Contractor shall cooperate with NARA’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of NARA information.
(e) Systems Security.
(1) In performing its duties related to management, operation, and/or access of systems containing PII under this contract, the Contractor, its employees and subcontractors shall comply with all applicable security requirements and rules of conduct applicable to the agency’s systems as described in:
a) NARA Directive 1608 http://www.archives.gov/foia/directives/nara1608.pdf
b) NARA Notice 2010-045;
c) NARA Penalty Guide (Personnel 300, Appendix 752A - Penalty Guide); and
d) NARA’s Media Protection Methodology.
(2) In addition, the use of Contractor-Owned laptops or other portable storage devices to process or store sensitive PII is prohibited under this contract until the Contractor provides, and the Contracting Officer, in coordination with the Senior Agency Official for Privacy (SAOP) or the SAOP’s designee, approves the Contractor’s written acknowledgment that the following requirements are met:
(i) Laptops and other portable storage devices must employ encryption that is NIST Federal Information Processing Standard (FIPS) 140-2 validated (or its successor) http://csrc.nist.gov/publications/PubsFIPS.html, and approved.
(ii) The Contractor has developed and implemented a process to ensure that security and other applications software are kept current.
(iii) Mobile computing devices utilize anti-virus software and a host-based firewall mechanism.
(iv) Removable media, such as hard drives, flash drives, devices with flash memory, CDs and floppy disks containing CUI, which may include sensitive PII shall not be removed from a Government facility unless they are encrypted using a NIST FIPS 140-2 or successor approved product.
(v) When no longer needed, all removable media, hard drives, and flash memory shall be destroyed in accordance with Government security requirements identified in NARA’s Media Protection Methodology.
(vi) The Contractor shall maintain an accurate inventory of devices used in the performance of this contract.
(3) All NARA information obtained under this contract shall be removed from Contractor- Owned information technology assets at the direction of the Contracting Officer or Contracting Officer’s Representative. Removal must be accomplished in accordance with standard FedRAMP controls for media protection in moderate IT systems and NIST 800-88 standards.
Certification of data removal will be performed by the Contractor’s Project Manager and written notification confirming acknowledgment will be delivered to the Contracting Officer within 30 days of the direction to remove the information.
http://www.archives.gov/foia/directives/nara1608.pdf http://csrc.nist.gov/publications/PubsFIPS.html http://csrc.nist.gov/publications/PubsFIPS.html
(4) Back up or mirrors of any systems or files containing CUI shall be treated in the same manner as the original data containing CUI, with the same protections and obligations.
(5) The Contractor shall require FIPS 140-2 (or successor) encryption of any sensitive PII when transmitted electronically across the Internet or other public works.
(f) Breach Notification to Government.
(1) The Contractor has been provided with: NARA Directive 1608, and is aware of its roles, responsibilities, and relationship with the Government in case of data breach.
(2) In the event of any actual or suspected breach of sensitive PII, the Contractor shall immediately, and in no event later than one hour of discovery, report the breach to the Contracting Officer, the COR, the Senior Agency Official for Privacy (currently NARA’s General Counsel garymstern@nara.gov) and the Chief Information Officer (only for IT requirements) in accordance with NARA Directive 1608.
(3) The Contractor is responsible for positively verifying that notification is received and acknowledged by appropriate Government parties identified in subparagraph (2) above.
(4) In the event of a confirmed, potential or suspected Security Breach, involving unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any NARA Information accessed by, retrievable from, processed by stored on, or transmitted within, to or from any such system, Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the NARA CO and the CO's Representative (''COR").
(5) NARA, at its sole discretion, may obtain, and Contractor will permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any security incident, PII or Security Breach. Additionally. NARA, at its sole discretion, may require Contractor to retain, at Contractor's expense, a Third Party Assessing Organization (3PAO) acceptable to NARA, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.
(6) Any report submitted in accordance with paragraphs (1), (2) and (3) above, shall identify (I) both the Information Systems and NARA Information involved or at risk, including the type, amount, and level of sensitivity of the NARA Information and, if the NARA Information contains PII, the estimated number of unique instances of Pll, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the USCERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by the NARA. Contractor shall continue to provide written updates to the NARA CO regarding the status of the Security incident at least every three (3) calendar days until informed otherwise by the NARA CO.
(7) Response activities related to any security incident or PII or Security Breach undertaken by NARA, including activities undertaken by Contractor, other federal agencies, and any third-party contractors or firms at the request or direction of NARA, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Security Incident and/or liability for any additional response activities. Contractor shall be responsible for all costs and related resource a locations required for all such response activities related to any Security Incident or Breach, including the cost of any penetration testing.
(g) Personally Identifiable Information Notification Requirement
Contractor certifies that it has a security policy in place that contains procedures to promptly notify any individual whose Personally Identifiable Information ("Pll") was, or is reasonably determined by NARA to have been, compromised. Any notification shall be coordinated with the NARA CO and shall not proceed until NARA has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by Contractor shall be coordinated with, and subject to the approval of, NARA. Contractor shall be responsible for taking corrective action consistent with NARA Data Breach Notification Procedures and as directed by the NARA CO, including all costs and expenses associated already covered by above clauses added in PII clause with such corrective action, which may include providing credit monitoring to any individuals whose Pll was actually or potentially compromised. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident, Breach, or PII Breach will be made by NARA senior officials at NARA’s discretion.
(h) Flowdown of security requirements to subcontractors.
(1) The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph (g), in all subcontracts under this contract, and require written subcontractor acknowledgement of same.
(2) Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.
IV. CONFIDENTIALITY OF INFORMATION
(a) Confidential information is any information that, if subject to unauthorized access, modification, loss, or misuse could adversely affect the national interest, the conduct of Federal programs, or the privacy of individuals, but has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy. Confidential information also includes proprietary data and information for which other restrictions on access apply.
(b) The Contracting Officer and the Contractor may, by mutual consent, identify elsewhere in this contract specific information and/or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential.
Similarly, the Contracting Officer and the Contractor may, by mutual consent, identify such confidential information from time to time during the performance of the contract. Failure to agree will be settled pursuant to the “Disputes” clause.
(c) While in the course of performance of this contract, the Contractor may have access to confidential information and communications, including but not limited to Personally Identifiable Information (PII). Confidential information may be contained in printed material or on electronic media. The Contractor will preserve the confidentiality of all such information and communications and agrees not to disclose, release, disseminate, or publish any such information or communications for any purposes whatsoever without the prior approval of the Contracting Officer. Failure to comply with the provisions of this paragraph will be grounds for Termination for Cause and the Contractor may be liable for damages. This provision shall survive the expiration or termination of the period of performance of this contract.
(d) If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, the Contractor will follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.
(e) During the course of the performance of this contract, the Contractor may have access to and use of data and information which may be considered proprietary by other contractors, or which may otherwise be of such a nature that its dissemination or use, other than in performance of this contract, would be adverse to the interest of NARA and these other contractors.
(f) Except as may be otherwise agreed to with these other contractors, the Contractor agrees that it will not use, disclose or reproduce proprietary data and information belonging to these other contractors other than as required in the performance of this contract; provided, however, that nothing herein shall be construed as: (1) precluding the use of any such data or information independently acquired by the Contractor without such limitation; or (2) prohibiting an agreement at no cost to NARA between the Contractor and these contractors which provides for greater rights to the Contractor.
(g) When considering a request to disclose, release, disseminate, or publish confidential information, the Contracting Officer will consult with appropriate program and legal officials.
(h) At the discretion of the Contracting Officer, the Contractor’s employees may be required to sign a non-disclosure agreement prior to performing any work under this contract.
(i) The terms of this paragraph apply to all Contractor employees, subcontractors and consultants and must be incorporated into any subcontract.
V. Governing Law
Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this
Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order;
this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.
VI: SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:
1. Definitions.
(a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”
(b) Licensor. The term “licensor” shall mean the contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “contractor” is the party identified in Block 17a on the SF1449. If the contractor is a reseller and not the Licensor, the contractor remains responsible for performance under this order.
(c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.
(d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.
(e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.
(f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.
(g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).
0. Software License
(a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.
(b) The Government may use the software in a networked environment.
(c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).
(d) All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.
3. Software Maintenance and Technical Support
(a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this contract or order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received the contractor is neither authorized nor permitted to renew any of the previously furnished services.
(b) The contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.
(c) Any telephone support provided by contractor shall be at no additional cost.
(d) The contractor shall provide all maintenance services in a timely manner in accordance with the contractor’s customary practice or as defined in the Performance Work Statement/Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the contractor (e.g., www.ppirs.gov).
(e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.
0. Disabling Software Code. The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, http://www.ppirs.gov/ node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.
Manuals and Publications. Upon Government request, the contractor shall furnish the most current version of the user manual and publications for all products/services provided under this contract or order at no cost.
Enclosure 4
FAR CLAUSES
I. FAR 52.212-4 – Contract Terms and Conditions – Commercial Items (Dec 2022)
II. FAR 52.212-5 – Contract Terms and Conditions Required to Implement Statues or Executive Orders – Commercial Items (Jan 2021)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (Jul 2018) (Section 1634 of Pub. L. 115- 91).
(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (Aug 2019) (Section 889(a)(1)(A) of Pub. L. 115-232).
(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015).
(5) 52.233-3, Protest After Award (Aug 1996) (31 U.S.C. 3553).
(6) 52.233-4, Applicable Law for Breach of Contract Claim (Oct 2004) (Public Laws 108-77 and 108-78 (19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
_X_ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Sept 2006), with Alternate I (Oct 1995) (41 U.S.C. 4704 and 10 U.S.C. 2402).
__ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (Oct 2015) (41 U.S.C.
3509)).
__ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (June 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)
__ (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (Oct 2018) (Pub. L. 109-282) (31 U.S.C. 6101 note).
__ (5)[Reserved].
__ (6) 52.204-14, Service Contract Reporting Requirements (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
__ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
_X_ (8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (Oct 2015) (31 U.S.C. 6101 note).
_X_ (9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Oct 2018) (41 U.S.C. 2313).
__ (10)[Reserved].
__ (11) (i) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Nov 2011) (15 U.S.C.657a).
__ (ii) Alternate I (Nov 2011) of 52.219-3.
__ (12) (i) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Oct 2014) (if the offeror elects to waive the preference, it shall so indicate in its offer) (15 U.S.C. 657a).
__ (ii) Alternate I (Jan 2011) of 52.219-4.
__ (13)[Reserved] __ (14) (i) 52.219-6, Notice of Total Small Business Set-Aside (Nov 2011) (15 U.S.C.644).
__ (ii) Alternate I (Mar 2020) of 52.219-6 __ (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (June 2003) (15 U.S.C. 644).
__ (ii) Alternate I (Oct 1995) of 52.219-7.
__ (iii) Alternate II (Mar 2004) of 52.219-7.
__ (16) 52.219-8, Utilization of Small Business Concerns (Oct 2018) (15 U.S.C. 637(d)(2) and (3)).
__ (17) (i) 52.219-9, Small Business Subcontracting Plan (Aug 2018) (15 U.S.C. 637(d)(4)) __ (ii) Alternate I (Nov 2016) of 52.219-9.
__ (iii) Alternate II (Nov 2016) of 52.219-9.
__ (iv) Alternate III (Nov 2016) of 52.219-9.
__ (v) Alternate IV (Aug 2018) of 52.219-9 __ (18) (i) 52.219-13, Notice of Set-Aside of Orders (Mar 2020) (15 U.S.C. 644(r)).
__ (ii) Alternate I (Mar 2020) of 52.219-13 __ (19) 52.219-14, Limitations on Subcontracting (Mar 2020) (15 U.S.C.637(a)(14)).
__ (20) 52.219-16, Liquidated Damages-Subcontracting Plan (Jan 1999) (15 U.S.C.
637(d)(4)(F)(i)).
__ (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (Oct 2019) (15 U.S.C. 657f).
__ (22) (i) 52.219-28, Post Award Small Business Program Rerepresentation (Jul 2013) (15 U.S.C. 632(a)(2)).
__ (ii) Alternate I (MAR 2020) of 52.219-28.
__ (23) 52.219-29, Notice of Set-Aside for, or Sole Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (Dec 2015) (15 U.S.C. 637(m)).
__ (24) 52.219-30, Notice of Set-Aside for, or Sole Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (Dec 2015) (15 U.S.C. 637(m)).
(25) 52.219-32, Orders Issued Directly Under Small Business Reserves (Mar 2020) (15 U.S.C.
644(r)).
(26) 52.219-33, Nonmanufacturer Rule (Mar 2020) (15 U.S.C. 637(a)(17)).
_X_ (27) 52.222-3, Convict Labor (June 2003) (E.O.11755).
_X_ (28) 52.222-19, Child Labor-Cooperation with Authorities and Remedies (Jan 2020) (E.O.13126).
_X_ (29) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).
_X_ (30) (i) 52.222-26, Equal Opportunity (Sept 2016) (E.O.11246).
__ (ii) Alternate I (Feb 1999) of 52.222-26.
_X_ (31) (i) 52.222-35, Equal Opportunity for Veterans (Oct 2015) (38 U.S.C. 4212).
__ (ii) Alternate I (July 2014) of 52.222-35.
_X_ (32) (i) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) (29 U.S.C.793).
__ (ii) Alternate I (July 2014) of 52.222-36.
_X_ (33) 52.222-37, Employment Reports on Veterans (Feb 2016) (38 U.S.C. 4212).
_X_ (34) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496).
_X_ (35) (i) 52.222-50, Combating Trafficking in Persons (Jan 2019) (22 U.S.C. chapter 78 and E.O. 13627).
__ (ii) Alternate I (Mar 2015) of 52.222-50 (22 U.S.C. chapter78 and E.O. 13627).
__ (36) 52.222-54, Employment Eligibility Verification (Oct 2015). (Executive Order 12989).
(Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial items as prescribed in 22.1803.)
__ (37) (i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA–Designated Items (May 2008) (42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
__ (ii) Alternate I (May 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
__ (38) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (Jun 2016) (E.O. 13693).
__ (39) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (Jun 2016) (E.O. 13693).
__ (40) (i) 52.223-13,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .