Attachment_A1_-_FBI_Security_Regulations.pdf

PDF 110 KB Posted

Attached to
FBI CJIS Mobile Biometric Application RFQ0023703 Federal contract opportunity
Solicitation number
RFQ0023703
Issued by
Department of Justice Federal Bureau of Investigation Headquarters Division

About this file

Attachment 1 - FBI Security Regulations

View the file

Other files for this federal contract opportunity

Other files attached to FBI CJIS Mobile Biometric Application RFQ0023703, newest first.
File Type Posted
Mobile_Biometric_Application_RFQ_Amednment_2.pdf PDF
Phase_2_Govt_Response.pdf PDF
ARQ_and_KMPL.docx DOCX document
Q A_MBA_RFQ0023703_PHASE_1.pdf PDF
Attachment_A2_MBA_Price_Template.xlsx XLSX spreadsheet
Mobile_Biometric_Application_RFQ_Amednment_1.pdf PDF
Mobile_Biometric_Application_RFQ_FINAL.pdf PDF
Attachment_A3_-_Validation_Checklist.pdf PDF
Attachment_A4_CLIENT_AUTHORIZATION_LETTER_EXAMPLE.pdf PDF
MASTER_QUESTION_TEMPLATE_FINAL.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFQ0023703 – Mobile Biometric App

Attachment A1 – FBI Security regulations

Department of Justice (DOJ) Procurement Guidance for Security of Systems and Data, Including Personally Identifiable Information

On 3/20/2008, the Senior Procurement Executive, DOJ, notified the FBI of requirements for addressing Department systems and data, including provisions governing the use of laptops by contractors which are to be included in all current and future contracts where a contractor handles data that originated within the Department, data that the contractor manages or acquires for the Department, and/or data that is acquired in order to perform on the contract and concerns Department programs or personnel. Effective immediately if a procurement is expected to result in the acquisition of services where the contractor handles data that originated within the Department, data that the contractor manages or acquires for the Department, and/or data that is acquired in order to perform the contract and concerns Department programs or personnel procurement officials are required to incorporate the appropriate special security requirements. It should be noted that within

Section A, paragraphs a, b, and d apply to all data, even data that may not be personally identifiable information (PII). Section B sets forth special security requirements that must be used in contracts involving PII obtained by the Department from a contractor, such as an information seller or data broker. A request for a wavier from the requirement to include these special security requirements, or deviations from the language (except those that are more stringent), must be made in writing to the Senior Procurement

Executive. Permission for a deviation or waiver will only be granted in unusual circumstances.

1.2 Special Security Requirements

A. Security of Systems and Data, Including Personally Identifiable Data

a. Systems Security

The work to be performed under this contract requires the handling of data that originated within the Department of Justice, data that the contractor manages or acquires for the

Department, and/or data that is acquired in order to perform the contract and concerns

Department programs or personnel.

For all systems handling such data, the contractor shall comply with all security requirements applicable to Department of Justice systems, including but not limited to all

Executive Branch system security requirements (e.g. requirements imposed by OMB and

NIST), DOJ IT Security Standards, and DOJ Order 2640.2E. The contractor shall provide DOJ access to and information regarding the contractor's systems when requested by the Department in connection with its efforts to ensure compliance with all such security requirements, and shall otherwise cooperate with the Department in such efforts.

DOJ access shall include independent validation testing of controls, system penetration testing by DOJ, FISMA data reviews and access by the DOJ Office of the Inspector

General for its reviews.

The use of contractor-owned laptops or other media storage devices to process or store data covered by this clause is prohibited until the contractor provides a letter to the

Contracting Officer (CO) certifying the following requirements:

1. Laptops must employ encryption using a NIST Federal Information Processing

Standard (FIPS) 140-2 approved product;

2. The contractor must develop and implement a process to ensure that security and other applications software is kept up-to-date;

3. Mobile computing devices will utilize anti-viral software and a host-based firewall mechanism;

4. The contractor shall log all computer-readable data extracts from databases holding sensitive information and verify each extract including sensitive data has been erased within 90 days or its use is still required. All DOJ information is sensitive information unless designated as non-sensitive by the Department;

5. Contractor-owned removable media, such as removable hard drives, flash drives, CDs, and floppy disks, containing DOJ data, shall not be removed from DOJ facilities unless encrypted using a NIST FIPS 140-2 approved product;

6. When no longer needed, all removable media and laptop hard drives shall be processed (sanitized, degaussed or destroyed) in accordance with security requirements applicable to DOJ;

7. Contracting firms shall keep an accurate inventory of devices used on DOJ contracts;

8. Rules of behavior must be signed by users. These rules shall address at a minimum:

authorized and official use; prohibition against unauthorized users; and protection of sensitive data and personally identifiable information;

9. All DOJ data will be removed from contractor-owned laptops upon termination of contractor work. This removal must be accomplished in accordance with DOJ IT

Security Standard requirements. Certification of data removal will be performed by the contractor's project management and a letter confirming certification will be delivered to the CO within 15 days of termination of contractor work;

b. Data Security

By acceptance of, or performance on, this contract, the contractor agrees that with respect to the data identified in paragraph a, in the event of an actual or suspected breach of such data (i.e., loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic), the contractor will immediately (and in no event later than within one hour or discovery) report the breach to the CO and the Contracting Officer's Technical Representative

(COTR).

If the data breach occurs outside of regular business hours and/or neither the CO nor the

COTR can be reached, the contractor shall call the DOJ Computer Emergency Readiness

Team (DOJCERT) at 1-866-US4-CERT (1-866-874-2378) within one hour of discovery of the breach. The contractor shall also notify the CO as soon as possible during regular business hours.

c. Personally Identifiable Information Notification Requirement

The contractor further certifies that it has a security policy in place that contains procedures to promptly notify any individual whose personally identification information

(as defined by OMB) was, or is reasonably believed to have been, breached. Any notification shall be coordinated with the Department, and shall not proceed until the

Department has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by the contract shall be coordinated with, and be subject to the approval of, the Department. The contractor assumes full responsibility for taking corrective action consistent with the Department's Data Breach Notification Procedures, which may include offering credit monitoring when appropriate.

d. Pass-through of Security Requirements to Subcontractors

The requirements set forth in Paragraphs a through c above, apply to all subcontractors who perform work in connection with this contract. For each subcontractor, the contractor must certify that it has required the subcontractor to adhere to all such requirements. Any breach by a subcontractor of any of the provisions set forth in this clause will be attributed to the contractor.

B. Information Resellers or Data Brokers

Under this contract, the Department obtains personally identifiable information about individuals from the contractor. The contractor hereby certified that it has a security policy in place which contains procedures to promptly notify any individual whose personally identifiable information (as defined by OMB) was, or is reasonably believed to have been, lost or acquired by an unauthorized person while the data is under the control of the contractor. In any case in which the data that was lost or improperly acquired reflects or consists of data that originated with the Department, or reflects sensitive law enforcement or national security interest in the data, the contractor shall notify the Department Contracting Officer so that the Department my determine whether notification would impede a law enforcement investigation or jeopardize national security. In such cases, the contractor shall notify the individuals until it receives further instruction from the Department.

PERSONNEL SECURITY REQUIREMENTS

The administrative control and maintenance of accurate records of contractors has been identified by both the Intelligence Community and FBI Executive Management as a matter of concern. With the continuous dependency on contractors to support the FBI, to include access to FBI facilities and information, if a procurement is expected to result in the acquisition of services involving the assignment of contractor personnel to FBI locations the Program Management Officer/Contracting Officer's Technical

Representative (COTR), in coordination with the assigned Chief Security Officer, are required to identify during procurement planning stages, whether an acquisition will require assignment of contractor personnel to FBI locations, and therefore require the anticipated contract to include the Special Security Clause identified below in 1.2.

1.2 Special Security Requirements

Security Requirements Applicable to Contractor Personnel Assigned to FBI Locations

Requirements are applicable to all individuals to be assigned to FBI locations, to include those identified as "Key Personnel", if specified in the contract. The contractor shall plan for expected attrition through advanced preparation and submission of required information.

Award of this contract is anticipated to result in assignment of contractor personnel to

FBI controlled or occupied space. Security and ethical conduct requirements, specific to the contract, to include a copy of the "Contractor & FBI Employees Ethics Standards

Factsheet" are provided. Any questions that the contractor or contractor personnel may have on the applicability of these requirements shall be addressed to the Contracting

Officer's Security Representative or (name of Chief Security Officer), Chief Security

Officer, at (telephone number). As such, all contractor personnel assigned to such space must be briefed, in advance of arrival, by the contractor on the provided FBI policies and procedures, as identified in the contract, regarding ethical conduct and security requirements. A list of assigned Contractor personnel and verification of their briefing, shall be provided to the cognizant contractor security officer for subsequent transmittal to the proper FBI Security Officer assigned oversight of this contract. This list must be provided no later than seven (7) days in advance of the individual's scheduled date of initial performance at an FBI location. Failure to provide the required verification of briefing will result in a delay of the individual's access to the facility.

Additionally, within 15 days from assignment to FBI space, the employee must attend an

FBI Security Awareness Briefing, which will further address FBI policies and procedures, as identified in FBI's Policy and Guidance Library. This training is currently satisfied through the contractor employee's attendance at the Security Division's Career

Services Management Unit's quarterly contractor's training offered at FBI, 935

Pennsylvania Avenue, NW, Washington, DC. The assigned FBI Chief Security Officer will contact the employee with the date and time of their scheduled briefing. Failure to attend this briefing or make arrangements to attend a subsequent briefing will result in immediate removal of the employee from FBI space. If contract performance is impacted as a result of removal of the employee, the contractor may be found in default of the contract. In the event that the development of information or material is not clearly covered by the contract or regulations, the contractor is required to seek FBI guidance regarding its handling of classified and/or unclassified information.

Only such persons who have been authorized by the Contracting Officer and/or the Chief

Security Officer/Contracting Officer's Security Representative, if the work is for other than specified personnel, shall be assigned to this work. In this connection, for identification purposes, the contractor will be required to submit the name, address, place and date of birth of all personnel who will be involved in the work hereunder. Said information will be required to be provided to the identified Chief Security Officer not later than seven (7) days in advance of the scheduled date of such work. Information relating to an individual(s) identified as "Key Personnel" should be reported to the Chief

Security Officer after the written consent of the Contracting Officer has been received.

All contractor personnel who receive a security clearance or access approval under the terms of this contract will be required to execute a FBI specified nondisclosure agreement.

The contractor agrees to abide by all applicable FBI security regulations governing personnel, facilities, technical, information systems, communications and protective programs.

The following reporting requirements are to be reported to the identified Chief Security

Officer as promptly as possible, but in no event later than two (2) business days after receipt of such knowledge.

a. Adverse Information. Contractors shall report any adverse information coming to their attention concerning any of their employees supporting this contract. Adverse information is defined as any information that adversely reflect on the integrity or character of an employee that suggests that his or her ability to safeguard FBI Sensitive

But Unclassified (SBU)/Law Enforcement Sensitive (LES) and/or classified information may be impaired, or that his or her access to the information clearly may not be in the interest of the FBI and/or National Security.

b. Suspicious Contacts. Contractors shall report efforts by any individual, regardless of nationality, to obtain illegal or unauthorized access to FBI SBU/LES or classified information or to compromise an employee.

c. Change in Employee Status. Contractors shall report (1) the death, (2) a name change,

(3) change in marital status, (4) change to performance which alters their originally assigned location and FBI Division to which they report, (5) termination of employment.

d. Employees Desiring Not to Perform on the Contract. Evidence that an employee no longer wishes to support the contract.

f. Official or Unofficial Foreign Travel.

CONTRACTOR SUITABILITY REQUIREMENT

Access to FBI facilities and information is subject to specific security and suitability requirements. The FBI reserves the right and prerogative to deny and/or restrict facility and information access of any contractor employee determined by the FBI, at any time prior to or during performance, to be unsuitable for access and/or present a risk of compromising sensitive government information to which he or she would have access to under this contract. Contractors will be allotted a reasonable amount of time, determined by the government, to replace the employee found not suitable for contract performance.

Failure to replace the employee may result in a no cost termination by the government

DOJ RESIDENCY REQUIREMENT

Background: (U//FOUO) On 12/10/2002, the Deputy Assistant Attorney General for

Policy, Management and Planning, amended the Department of Justice (DOJ) Residency

Requirement to apply to all DOJ contractor personnel employed within the United States, both United States citizens and non-United States citizens. This amendment was identified as a result of the events of September 11 and the enhanced security posture within the Department. This requirement can be waived by the Department for short-term contractor personnel (performing duties for a cumulative total of 14 days or less) if there is a critical need for their specialized and unique skills. These individuals must, however, be United States citizens or Permanent Resident Aliens. A waiver request from the Security Division’s Assistant Director outlining the extenuating circumstances along with the requisite contractor clearance security package should be submitted to the

Department Security Officer for approval. Each waiver request will be reviewed and a determination made on a case-by-case basis.

DOJ Residency Requirement

All contractor personnel employed within the United States, both United States citizens and non-United States citizens, are required to meet the following residency requirements:

a. For three of the five years immediately prior to applying for the specific contract position, the individual must have 1) resided in the United States; 2) worked for the

United States overseas in a Federal or military capability; or 3) be a dependent of a

Federal or military employee serving overseas.

The requirement may be waived for short term contractor personnel (performing duties for a cumulative total of 14 days or less) if there is a critical need for their specialized and unique skills. These individuals must, however, be United States citizens or Permanent

Resident Aliens.

CLASSIFIED CONTRACT SPECIAL SECURITY REQUIREMENT

The FBI has determined that performance of this effort requires that the Contractor have access to classified National Security Information (herein known as classified information). Classified information is Government information which requires protection in accordance with Executive Order 12356, Classified National Security

Information, and supplementing directives. Executive Order 13292, dated 28 March

2003, “Further Amendment to Executive Order 12356, as amended, “Classified National

Security Information” and implementation directives, provides principles and procedures for the proper classification and declassification of material. These principles and procedures are applicable to classified documents or materials generated by the contractor in performance of this contract.

The contractor shall comply with:

(1) The Security Agreement (DD Form 441), including the National Industrial

Security Program Operating Manual (DoD 5220.22-M)

(2) Any revisions to that manual, notice of which has been furnished to the contractor.

The Contractor shall abide by the requirements set forth in the DD Form 254 and the

National Industrial Security Program Operating Manual (NISPOM), DoD 5200.22-M) for the protection of classified information at its cleared facility, if applicable, as directed by the DSS. If the Contractor has access to classified information at a FBI or other

Government facility, it shall abide by the requirements set by the agency.

No classified document or material provided by the FBI, or generated by the contractor pursuant to the contract, may be downgraded or declassified unless authorized in writing by the CO.

The Contractor shall appoint a senior official to act as the Corporate Security Officer.

The individual shall interface with the FBI Security Office on all security matters, to include physical, personnel and protection of all Government information and data accessed by the Contractor.

Contractor personnel will require access to classified information and have access to classified areas. Contractor personnel shall possess at least an active and transferable

Government Secret clearance at the time of proposal submission. Contractors who will have access to FBI facilities, systems or data shall possess an active and transferable Top

Secret clearance at the time of proposal submission. The Government reserves the right to waive this requirement for any portion of the work that deals with technologies or data that is in the public domain. Contractor personnel assigned to this project shall be subject to routine criminal and credit checks by the FBI.

Contractor personnel shall be subject to counterintelligence focused polygraph examinations at the Government's discretion. The polygraph examinations may be required prior to acceptance or at any time during the task order, without notice.

The contractor shall maintain an overall security program in accordance with the requirements of the NISP. All automated information systems utilized to process FBI information will be operated in accordance with the requirements of the NISPOM, NISPOM Supplement, dated February 1995, DCID 6/3 and/or FBI certification and accreditation policies and procedures, as appropriate. Revisions to these documents, when published, will be provided to the contractor and will become a part hereof upon such issuance.

If subsequent to the date of this contract, the security classification or security requirements under this contract are caused to be changed by the Government and if the changes cause an increase or decrease in security costs or otherwise affect any other term or condition of this contract, the contract shall be subject to an equitable adjustment as if the changes were directed under the Changes clause of this contract.

The contractor agrees to insert terms that conform substantially to the language of this clause, including this paragraph, but excluding any reference to the Changes clause of this contract, in all subcontracts under this contract that involve access to classified

The contractor is obligated to comply with all relevant clauses and provisions incorporated into this contract and with the Contractor Non-Disclosure Agreement, and as referenced therein, the NISPOM, dated January 1995, and all applicable FBI security policies and procedures, including the DCIDs. As applicable, the contractor shall maintain a security program that meets the requirements of these documents.

Security requirements are a material conduction of this contract. This contract shall be subject to immediate termination for default, without the requirement for a 10-day cure notice, when it has been determined by the CO that a failure to fully comply with the security requirements of this contract resulted from the willful misconduct or lack of good faith on the part of any one of the Contractor’s directors or officers, or on the part of any of the managers, superintendents, or equivalents of the contractor who have supervision or direction of:

a. All or substantially all of the contractor’s business, or

b. All or substantially all of the contractor’s operations at any one plant or separate location in which this contract is being performed, or

c. A separate and complete major industrial operation in connection with the performance of this contract.

When deficiencies in the contractor’s security program are noted which do not warrant immediate default, the contractor shall be provided a written notice of the deficiencies and be given a period of 90 days in which to take corrective action. If the contractor fails to take the necessary corrective action, the CO may terminate the whole or any part of this contract, for default. The contractor shall maintain and administer, in accordance with all relevant clauses and provisions set forth or incorporated into this contract, a security program that meets the requirements of these documents.

CONSENT FOR WARRANTLESS SEARCHES OF DEPARTMENT OF JUSTICE

WORKPLACES

All cleared personnel accessing information within FBI controlled space are required to execute an FBI Form FD 1001 Consent for Warrantless Searches of Department of

Justice (DOJ) Workplaces as a condition of working at FBI facilities. The FBI's Director implemented the Attorney General's policy subjecting employees to warrantless physical searches of their offices or immediate workplaces within DOJ premises when authorized by the Attorney General (AG) or the Deputy Attorney General (DAG) based upon a determination that information the Department deems credible indicates that the employee:

1) is, or may be, disclosing classified information in an unauthorized manner;

2) has incurred excessive indebtedness or has acquired a level of affluence that can not be reasonably explained by other information;

3) had the capability and opportunity to disclose classified information that is believed to have been lost or compromised to a foreign power or an agent of a foreign power; or

4) has repeatedly or significantly mishandled or improperly stored classified

The search may extend to the entire office or workplace and anything within it that might hold classified information, including locked containers (such as briefcases) and electronic storage media (such as computer disk and handheld computers), whether owned by the government, by the employee, or by a third party. The search may be conducted by appropriate FBI personnel and/or law enforcement officers, on an announced or unannounced basis, during the workday or after hours. If discovered during a search, evidence of misconduct - whether related to storage or classified information, storage of sensitive but unclassified information, or a crime - will be collected and reported to appropriate authorities.

Contractor personnel who will meet the above criteria will be required to sign Form FD

1001 Consent for Warrantless Searches of Department of Justice (DOJ) Workplaces

(attached) upon award and forward the executed form(s) to the assigned Contracting

Officer's Representative. All forms will be retained by the FBI during the period the individual is providing services and two years after that individual's departure before final disposition is taken.

File details come from the government source that posted it. Updated .