Amendment 006 RFP.pdf
PDF 426 KB Posted
- Attached to
- Assessment & Authorization (A&A) Services IDIQ Contract Federal contract opportunity
- Solicitation number
- SB1341-12-RP-0005
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 009 Questions and Responses.pdf | ||
| Amendment 007 RFP.pdf | ||
| Amendment 006 Details.pdf | ||
| Amendment 005 Questions and Responses.pdf | ||
| Amendment 004 Questions and Responses.pdf | ||
| Amendment 003.pdf | ||
| RFP SB1341-12-RP-0005.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION, OFFER AND AWARD 1. THIS CONTRACT IS A RATED
ORDER UNDER DPAS (15 CFR 700)
RATING
PAGE OF
PAGES
2. CONTRACT NUMBER 3. SOLICITATION NUMBER 4. TYPE OF SOLICITATION 5. DATE ISSUED 6. REQUISITION/PURCHASE NUMBER
SB1341-12-RP-0005 SEALED BID (IFB)
NEGOTIATED (RFP)
NB181000-12-00495
NB181000-12-00495
7. ISSUED BY CODE 000SB 8. ADDRESS OFFER TO (If other than Item 7)
NATIONAL INST OF STDS AND TECHNOLOGY
100 BUREAU DRIVE STOP 1640
BUILDING 301 ROOM B129
GAITHERSBURG MD 20899-1640
NATIONAL INST OF STDS AND TECHNOLOGY
100 BUREAU DRIVE STOP 1640
BUILDING 301 ROOM B129
GAITHERSBURG MD 20899-1640
NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".
SOLICITATION
9. Sealed offers in original and 4 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in Keith Bubar NIST Building 301, Room B152 100 Bureau Drive Stop 1640 Gaithersburg, MD 20899-1640 until 12:00
PM ET
local time FEB 02, (Hour) (Date)
CAUTION - LATE Submissions, Modifications, and Withdrawls: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
10. FOR
INFORMATION CALL
A. NAME
KEITH BUBAR
B. TELEPHONE (NO COLLECT CALLS)
301-975-8329
C. E-MAIL ADDRESS
KBUBAR@MAIL.NIST.GOV
11. TABLE OF CONTENTS
(X) SEC. DESCRIPTION PAGES(S) (X) SEC. DESCRIPTION PAGE(S)
PART 1 - THE SCHEDULE PART II - CONTRACT CLAUSES
X A SOLICITATION/CONTRACT FORM 1 - 1 X I CONTRACT CLAUSES 31 - 44
X B SUPPLIES OR SERVICES AND PRICES/COSTS 2 - 7 PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X C DESCRIPTION/SPECS./WORK STATEMENT 8 - 16 X J LIST OF ATTACHMENTS 45 - 62
D PACKAGING AND MARKING - PART IV - PRESENTATIONS AND INSTRUCTIONS
X E INSPECTION AND ACCEPTANCE 17 - 17 X K REPRESENTATIONS, CERTIFICATIONS AND OTHER 63 - 72
X F DELIVERIES OR PERFORMANCE 18 - 18 STATEMENTS OF OFFERORS
X G CONTRACT ADMINISTRATION DATA 19 - 20 X L INSTRS., CONDS., AND NOTICES TO OFFERORS 73 - 78
X H SPECIAL CONTRACT REQUIREMENTS 21 - 30 X M EVALUATION FACTORS FOR AWARD 79 - 82
OFFER
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all itmes upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52.232-8)
10 CALENDAR DAYS (%) 20 CALENDAR DAYS (%) 30 CALENDAR DAYS (%) CALENDAR DAYS (%)
14. ACKNOWLEDGMENT OF AMENDMENTS AMENDMENT NO. DATE AMENDMENT NO. DATE
(The offeror acknowledges receipt of amendments to the SOLICITATION for offerors and related documents numbered and dated):
CODE FACILITY 16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN OFFER
15A. NAME AND
ADDRESS OF
OFFEROR
DUNS: (Type or print)
15B. TELEPHONE NUMBER
15C. CHECK IF REMITTANCE ADDRESS IS DIFFERENT FROM
ABOVE - ENTER SUCH ADDRESS IN SCHEDULE.
17. SIGNATURE 18. OFFER DATE
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION
See Schedule
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
10 U.S.C 23004(c) ( ) 41 U.S.C 253(c) ( )
23. SUBMIT INVOICES TO ADDRESS SHOWN IN
(4 copies unless otherwise specified)
ITEM
24. ADMINISTERED BY CODE 25. PAYMENT WILL BE MADE BY CODE
26. NAME OF CONTRACTING OFFICER(Type or print) 27. UNITED STATES OF AMERICA 28. AWARD DATE
(Signature of Contracting Officer)
IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official writen notice. (Must be fully completed by offeror)
AUTHORIZED FOR LOCAL REPRODUCTION
Previous edition is unusable
STANDARD FORM 33 (REV. 9-97)
Prescribed by GSA - FAR (48 CFR) 53.214(c)
SCHEDULE Continued
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
NTE NTE
0001 Base Period
Contractor performance of the requirements set forth in Section C Performance Work Statement.
PR NUMBER: NB181000-12-00495
1.00 LO
NTE NTE
0002 Option Period 1
Contractor performance of the requirements set forth in Section C Performance Work Statement.
1.00 LO
0003 Option Period 2
0004 Option Period 3
0005 Option Period 4
Table of Contents
SECTION B SUPPLIES OR SERVICES AND PRICES/COSTS
B. 1 1352.216-75 MINIMUM AND MAXIMUM CONTRACT AMOUNTS (APR 2010)
B. 2 1352.216-77 CEILING PRICE (APR 2010)
B. 3 LABOR CATEGORIES AND RATES
SECTION C DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
C. 1 IDIQ PERFORMANCE WORK STATEMENT
SECTION E INSPECTION AND ACCEPTANCE
E. 1 52.246-4 INSPECTION OF SERVICES--FIXED-PRICE (AUG 1996)
E. 2 52.246-6 INSPECTION--TIME-AND-MATERIAL AND LABOR-HOUR (MAR 2001)
SECTION F DELIVERIES OR PERFORMANCE
F. 1 52.242-15 STOP-WORK ORDER (AUG 1989)
F. 2 52.242-17 GOVERNMENT DELAY OF WORK (APR 1984)
F. 3 1352.270-70 PERIOD OF PERFORMANCE (APR 2010)
SECTION G CONTRACT ADMINISTRATION DATA
G. 1 1352.201-70 CONTRACTING OFFICER?s AUTHORITY (APR 2010)
G. 2 1352.201-72 CONTRACTING OFFICER?s REPRESENTATIVE (C0R) (APR 2010)
G. 3 1352.216-76 PLACEMENT OF ORDERS (APR 2010)
G. 4 1352.245-70 GOVERNMENT FURNISHED PROPERTY (APR 2010)
SECTION H SPECIAL CONTRACT REQUIREMENTS
H. 1 1352.208-70 RESTRICTIONS ON PRINTING AND DUPLICATING (APR 2010)
H. 2 1352.209-73 COMPLIANCE WITH THE LAWS (APR 2010)
H. 3 1352.209-74 ORGANIZATIONAL CONFLICT OF INTEREST (APR 2010)
H. 4 1352.228-72 DEDUCTIBLES UNDER REQUIRED INSURANCE COVERAGE- FIXED PRICE (APR 2010)
H. 5 1352.231-71 DUPLICATION OF EFFORT (APR 2010)
H. 6 1352.209-72 RESTRICTIONS AGAINST DISCLOSURE (APR 2010)
H. 7 1352.216-74 TASK ORDERS (APR 2010)
H. 8 1352.228-70 INSURANCE COVERAGE (APR 2010)
H. 9 1352.233-70 AGENCY PROTESTS (APR 2010)
H. 10 1352.237-70 SECURITY PROCESSING REQUIREMENTS - HIGH OR MODERATE RISK CONTRACTS (APR
2010)
H. 11 1352.239-71 ELECTRONIC AND INFORMATION TECHNOLOGY (APR 2010)
H. 12 1352.239-72 SECURITY REQUIREMENTS FOR INFORMATION TECHNOLOGY RESOURCES (APR 2010)
H. 13 NIST LOCAL-07 COMPUTER SECURITY POLICY
H. 14 NIST LOCAL-40 BILLING INSTRUCTIONS FOR DELIVERY/TASK ORDERS
H. 15 SECURITY REQUIREMENTS - LOW RISK CONTRACTS
H. 16 KEY PERSONNEL
SECTION I CONTRACT CLAUSES
I. 1 52.202-1 DEFINITIONS (JUL 2004)
I. 2 52.203-3 GRATUITIES (APR 1984)
I. 3 52.203-5 COVENANT AGAINST CONTINGENT FEES (APR 1984)
I. 4 52.203-6 I RESTRICTIONS ON SUBCONTRACTOR SALES TO THE GOVERNMENT (SEP 2006)-- ALTERNATE I
(OCT 1995)
I. 5 52.203-7 ANTI-KICKBACK PROCEDURES (OCT 2010)
I. 6 52.203-8 CANCELLATION, RESCISSION, AND RECOVERY OF FUNDS FOR ILLEGAL OR IMPROPER ACTIVITY
(JAN 1997)
I. 7 52.203-10 PRICE OR FEE ADJUSTMENT FOR ILLEGAL OR IMPROPER ACTIVITY (JAN 1997)
I. 8 52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN FEDERAL TRANSACTIONS (OCT 2010)
I. 9 52.204-4 PRINTED OR COPIED DOUBLE-SIDED ON POSTCONSUMER FIBER CONTENT PAPER (MAY 2011)
I. 10 52.204-7 CENTRAL CONTRACTOR REGISTRATION (APR 2008)
I. 11 52.204-9 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR PERSONNEL (JAN 2011)
I. 12 52.204-10 REPORTING EXECUTIVE COMPENSATION AND FIRST-TIER SUBCONTRACT AWARDS (JUL 2010).. 31
I. 13 52.209-6 PROTECTING THE GOVERNMENT`s INTEREST WHEN SUBCONTRACTING WITH CONTRACTORS
DEBARRED, SUSPENDED, OR PROPOSED FOR DEBARMENT (DEC 2010)
I. 14 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (JAN 2011)
I. 15 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (JUN 2010)
I. 16 52.215-2 AUDIT AND RECORDS--NEGOTIATION (OCT 2010)
I. 17 52.215-8 ORDER OF PRECEDENCE--UNIFORM CONTRACT FORMAT (OCT 1997)
I. 18 52.223-5 POLLUTION PREVENTION AND RIGHT-TO-KNOW INFORMATION (MAY 2011)
I. 19 52.223-6 DRUG-FREE WORKPLACE (MAY 2001)
I. 20 52.224-1 PRIVACY ACT NOTIFICATION (APR 1984)
I. 21 52.224-2 PRIVACY ACT (APR 1984)
I. 22 52.227-1 AUTHORIZATION AND CONSENT (DEC 2007)
I. 23 52.228-5 INSURANCE--WORK ON A GOVERNMENT INSTALLATION (JAN 1997)
I. 24 52.229-3 FEDERAL, STATE, AND LOCAL TAXES (APR 2003)
I. 25 52.232-1 PAYMENTS (APR 1984)
I. 26 52.232-8 DISCOUNTS FOR PROMPT PAYMENT (FEB 2002)
I. 27 52.232-11 EXTRAS (APR 1984)
I. 28 52.232-17 INTEREST (OCT 2010)
I. 29 52.233-1 DISPUTES (JUL 2002)
I. 30 52.233-3 PROTEST AFTER AWARD (AUG 1996)
I. 31 52.233-4 APPLICABLE LAW FOR BREACH OF CONTRACT CLAIM (OCT 2004)
I. 32 52.237-2 PROTECTION OF GOVERNMENT BUILDINGS, EQUIPMENT, AND VEGETATION (APR 1984)
I. 33 52.242-13 BANKRUPTCY (JUL 1995)
I. 34 52.243-1 I CHANGES--FIXED-PRICE (AUG 1987)--ALTERNATE I (APR 1984)
I. 35 52.243-3 CHANGES--TIME-AND-MATERIALS OR LABOR-HOURS (SEP 2000)
I. 36 52.244-2 SUBCONTRACTS (OCT 2010)
I. 37 52.244-5 COMPETITION IN SUBCONTRACTING (DEC 1996)
I. 38 52.246-23 LIMITATION OF LIABILITY (FEB 1997)
I. 39 52.246-25 LIMITATION OF LIABILITY--SERVICES (FEB 1997)
I. 40 52.249-1 TERMINATION FOR CONVENIENCE OF THE GOVERNMENT (FIXED-PRICE) (SHORT FORM) (APR
1984)
I. 41 52.249-6 IV TERMINATION (COST-REIMBURSEMENT) (MAY 2004)--ALTERNATE IV (SEP 1996)
I. 42 52.253-1 COMPUTER GENERATED FORMS (JAN 1991)
I. 43 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS--
COMMERCIAL ITEMS (NOV 2011)
I. 44 52.216-18 ORDERING (OCT 1995)
I. 45 52.216-19 ORDER LIMITATIONS (OCT 1995)
I. 46 52.216-22 INDEFINITE QUANTITY (OCT 1995)
I. 47 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)
I. 48 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)
I. 49 52.227-14 RIGHTS IN DATA--GENERAL (DEC 2007)
I. 50 52.232-7 PAYMENTS UNDER TIME-AND-MATERIALS AND LABOR-HOUR CONTRACTS (FEB 2007)
I. 51 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
SECTION J LIST OF ATTACHMENTS
J. 1 TASK ORDER 1 PWS
J. 2 PAST PERFORMANCE QUESTIONNAIRE TEMPLATE
SECTION K REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF OFFERORS
K. 1 52.204-8 ANNUAL REPRESENTATIONS AND CERTIFICATIONS (NOV 2011)
K. 2 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS--COMMERCIAL ITEMS (NOV 2011)
SECTION L INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS
L. 1 52.216-1 TYPE OF CONTRACT (APR 1984)
L. 2 52.233-2 SERVICE OF PROTEST (SEP 2006)
L. 3 1352.215-72 INQUIRIES (APR 2010)
L. 4 1352.233-70 AGENCY PROTESTS (APR 2010)
L. 5 PROPOSAL PREPARATION/SUBMISSION INSTRUCTIONS
SECTION M EVALUATION FACTORS FOR AWARD
M. 1 52.217-5 EVALUATION OF OPTIONS (JUL 1990)
M. 2 EVALUATION FACTORS FOR AWARD
SECTION B
SUPPLIES OR SERVICES AND PRICES/COSTS
B. 1 1352.216-75 MINIMUM AND MAXIMUM CONTRACT AMOUNTS (APR 2010)
During the term of the contract, the Government shall place orders totaling a minimum of $20,000.00 . The amount of all orders shall not exceed $9,000,000.00 .
(End of clause)
B. 2 1352.216-77 CEILING PRICE (APR 2010)
The ceiling price of this contract is $9,000,000.00 . The contractor shall not make expenditures nor incur obligations in the performance of this contract which exceed the ceiling price specified herein, except at the contractor?s own risk.
B. 3 LABOR CATEGORIES AND RATES
Labor Category Labor Category Description
Base Period Hourly Labor Rate
Option Period 1 Hourly Labor Rate
Option Period 2 Hourly Labor Rate
Option Period 3 Hourly Labor Rate
Option Period 4 Hourly Labor Rate
Supervisor/ Project Manager
$XX.XX $XX.XX $XX.XX $XX.XX $XX.XX
Labor Category X
$XX.XX $XX.XX $XX.XX $XX.XX $XX.XX
Labor Category Y
$XX.XX $XX.XX $XX.XX $XX.XX $XX.XX
Labor Category Z
$XX.XX $XX.XX $XX.XX $XX.XX $XX.XX
SECTION C
DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
C. 1 IDIQ PERFORMANCE WORK STATEMENT
PERFORMANCE WORK STATEMENT (PWS)
PERFORMANCE WORK STATEMENT
BASE IDIQ CONTRACT FOR A&A SERVICES
I. BACKGROUND
The U. S. Department of Commerce (DOC), National Institute of Standards and Technology (NIST) located in Gaithersburg, Maryland and in Boulder, Colorado is a research organization with a very diverse information technology environment and security needs. NIST requires a Contractor to assist in the security authorization activities of NIST’s computer systems as required by NIST’s Assessment & Authorization (A&A) program based on the Risk Management Framework within DOC’s IT Security Program Policy, Federal Information Security Management Act (FISMA), and NIST guidance. These requirements include system security officer and security assessment support that involves reviewing and/or maintaining NIST system security posture.
II. SCOPE
The scope of this Indefinite-Delivery, Indefinite-Quantity (IDIQ) contract is for contractor provision of all labor, project oversight, administration and technical expertise required to perform security assessment tasks as defined in individual task orders.
NIST operational systems (refer to Attachment A for list of NIST systems) are scheduled for A&A activities each fiscal year. This contract does not require the Contractor to assess all NIST systems, but each task order will require the contractor to provide assistance to the Government in support of these activities, with the list of systems to be assessed provided by the COR.
For the purposes of this PWS, a system is a universal term to describe a group of information technology components (including but not limited to computers, applications, and networks) that have similar security requirements, a common function, and/or operate under the same management in the same general environment. Most systems are comprised of between twenty
(20) and four thousand (4000) assets, but some systems consist of only a few system components or even a single or several specialized applications. The system components vary widely and can include, but are not limited to the following: desktops, workstations, servers, portables, networked printers, applications, and network devices. Operating systems vary widely and include, but are not limited to Microsoft, Linux, UNIX, Cisco, Macintosh, and recently mobile platform OSs such as Apple IOS, Android, and Windows Mobile. NIST system security categorizations are a mix of Low and Moderate-impact, but there is always a possibility of a new system being rated as High-impact.
The contractor may be required to perform A&A services at both the NIST Gaithersburg, MD and Boulder, CO campuses, as well as other federal and commercial sites. The contractor shall be able to provide at least four Key Personnel contract employees for each individual task order.
However, the level of effort required for individual task orders may reach up to ten Key Personnel contract employees.
III. CONTRACT TYPE
This is an IDIQ type contract. Both firm fixed price and labor hour type task orders may be issued under this contract.
IV. CONTRACTOR PERFORMANCE REQUIREMENTS
The Contractor shall be responsible for maintaining accurate records of project activities under each individual task order. The contractor shall be responsible for any or all of the following specific tasks under a given task order. Each task order will specify which of the following tasks the contractor shall be responsible for, and will provide further details on the requirements. The following descriptions are summaries of the tasks, and the further detailed descriptions of the specific tasks to be performed by the contractor will be detailed in each task order. These summaries provide a baseline for the work that will be performed in each task order.
A. Task A – Security Officer and Assessment Services
The Contractor shall assist the Government in providing system security officer support and providing security assessment activities as required by FISMA and Special Publication (SP) 800- 37 Revision 1 for systems, such as those noted in Attachment A to this PWS. System security officer and A&A activities shall include reviewing system boundaries, completing and/or updating system security plans, network diagrams, hardware asset and software inventories, and contingency plans, performing security assessments to include vulnerability scanning and secure configuration testing using Tenable Security Center and HP WebInspect, performing onsite evaluations of IT configurations, and documenting assessment steps, results, and risks. The contractor may be required to work with other federal employees throughout performance of this task.
A&A support emphasis is on accurate identification, documentation, and testing of security controls for system assessments scheduled during the period of performance. The Contractor shall perform security control assessments based on SP800-53Rev3 and SP800-53A, including technical vulnerability scanning and secure configuration assessments, web vulnerability scanning, and analysis of results. Security assessment results shall be documented within Security Assessment Plans, vulnerability scan analyses, Security Assessment Reports, and Plans of Actions & Milestones (POA&Ms). The culmination of each assessment shall be documented for NIST Authorizing Officials within the Security Assessment Report, which shall include summary of system assessment activities, and a Risk Assessment table documenting risks to the system and detailing risks to be accepted as well as those requiring POA&Ms.
System security officer support emphasis is on accurately identifying assets and risks (threat/likelihood/impact) to the system, working closely with developers and system administrators to provide guidance on secure IT implementation, performing maintenance and ensuring consistency across security documents, providing assurance that the level of risk and risk acceptance are commensurate with the controls that are implemented or should be implemented on the system, conducting security impact reviews of information technology acquisitions, and ensuring security control descriptions and stated residual risks are comprehensive and understood by the system owner.
All activities shall be based on criteria outlined in the latest versions of NIST Special Publications (SP) 800-18, 800-37, 800-53, 800-53A, 800-60 (all found at http://csrc.nist.gov/publications/nistpubs/index.html).
Task A Deliverables
The contractor may be responsible for part of or all of the security documentation, in accordance with NIST A&A templates, developed in accordance with the NIST Special Publications, that will be provided by NIST, for each task order during the performance of this contract. This required security documentation shall include all or a portion of the following:
• Security Assessment Report – Executive summary of security testing activities, description of identified risks, and plans of actions and milestones.
• System Security Plan – Description of system and applicable security controls.
• System Diagram – Network diagram depicting physical architecture of the system.
• Software Inventory – List of major software included within the system.
• Asset Inventory – List of hardware and operating systems included within the system.
• Contingency Plan – List of components of the system that are backed up for recovery purposes, description of how they are backed up, and tested.
• Privacy Threshold Analysis – Determines if Personally Identifiable Information (PII) or
Business Identifiable Information (BII) is processed or stored within the system.
• Privacy Impact Analysis – Questionnaire concerning the nature and protection of PII/BII if it is processed or stored within the system.
• Security Assessment Plan – Test plan and results for applicable security controls.
• Vulnerability Scan Analysis – Description and risk levels of identified vulnerabilities
# Contractor Deliverable Required Delivery Date
a. Security Authorization Package for NIST IT systems. Format: Completed NIST-provided templates stored on secure share drive.
Due dates will be provided in each individual task order.
B. Task B - Status Reporting
Specific reporting requirements will be detailed in each individual task order. At a minimum, the Contractor shall be required to provide the COR with a written bi-weekly status report throughout the performance of a given task order, in Microsoft Word format, to identify progress, action items resolved, outstanding action items, and possible problems that could impact the quality or timeliness of deliverables.
At a minimum, the Contractor shall also be required to provide the COR with a written monthly breakdown of hours billed to the Government by email, in Microsoft Excel format throughout performance of individual task orders. A spreadsheet template shall be provided by the Government.
V. CONTRACTOR PERSONNEL REQUIREMENTS:
Contractor personnel that work directly on any task order under this contract or have direct oversight responsibility for those persons must be US Citizens and have passed equivalent to a Moderate-level Risk background investigation or higher prior to commencing work under this task order. The COR may accept similar current clearances issued by other agencies.
Additionally, due to the increase in classified information needing to be assessed, Contractor personnel must also have the ability to obtain and maintain a US Secret level clearance.
Contractor personnel that work directly on task orders under this contract must obtain and maintain a professional security certification (e.g. CISSP, GIAC, CAP). If the Contractor personnel proposed for a given task order do not have an active certification, the required certification must be obtained in accordance with an Individual Development Plan (IDP) that has been accepted by the COR.
Contractor personnel that work directly on task orders under this contract must attend the NIST new staff orientation within two weeks after task order award and complete the annual security awareness briefing within one month after task award order. The NIST IT Access and Use (Rules of Behavior) must also be read and signed prior to being granted access to any NIST IT accounts.
VI. GOVERNMENT FURNISHED PROPERTY/INFORMATION:
For each task order, NIST will:
NIST will provide all required data and onsite workspace and other facilities to the Contractor as may be required to fulfill tasks. NIST will provide space and building services at the Gaithersburg and Boulder sites for the duration of the task order.
NIST will provide onsite Contractor personnel with appropriate hardware, software, and equipment required to perform the requirements of this PWS and maintain security of NIST data.
The contractor is prohibited from performing work related to this contract on any hardware not provided by NIST.
NIST will provide telephones to the Contractor for business use only.
VII. PERIOD OF PERFORMANCE
The period of performance of this IDIQ contract is for one (1) base period of one year, and four
(4) option periods of one year each. Below is a table depicting the period of performance of the base contract.
PERIOD START DATE END DATE
Base Period Date of Award One Year from Date of award
Option Period 1 1st Day After Expiration of Base Period
One Year from start of Option Period I
Option Period 2 1st Day After Expiration of Option Period 1
One Year from start of Option Period 2
Option Period 3 1st Day After Expiration of Option Period 2
One Year from start of Option Period 3
Option Period 4 1st Day After Expiration of Option Period 3
One Year from start of Option Period 4
VIII. PLACE OF PERFORMANCE:
The place of performance for the work will be specified in individual task orders. However, the work shall be performed at both the NIST Gaithersburg, MD and Boulder, CO campuses.
However, if during the performance of a given task order, Contractor non-local travel may become necessary, then the Contractor shall submit a proposal to the Contracting Officer detailing all of the anticipated travel costs, including names of Contractor personnel, intended travel dates, breakdown of airfare costs, rental car costs, and any other direct costs, as well as purpose of the travel. Then, if NIST elects to authorize the Contractor to incur such travel costs, the Government would modify the task order to authorize such travel and to obligate funds to pay for such travel. The Contractor incurs travel costs at its own risk before the Contracting Officer provides written authorization for the Contractor to be reimbursed for such travel costs.
All travel costs will be paid in accordance with Federal Travel Regulation (http://www.gsa.gov/portal/content/104790)
IX. HOLIDAYS
In performing under a given task order, the Contractor shall note that NIST observes the following Federal Holidays:
• New Years Day
• Martin Luther King’s Birthday
• Inauguration Day
• Presidents Day
• Memorial Day
• Independence Day
• Labor Day
• Columbus Day
• Veterans Day
• Thanksgiving Day
• Christmas Day
The Contractor will not have access to NIST employees or to the NIST facilities during the observed Federal Holidays or when Federal facilities are closed due to emergencies or Executive Orders. The Contractor’s personnel must call the NIST status line at (301) 975-8000 to determine whether NIST is open before its personnel report to work during national emergencies or during inclement weather.
IV. PERFORMANCE REQUIREMENTS SUMMARY
Desired Outcomes Required Service Performance Standard Monitoring Method
1) NIST IT System security testing and documentation are completed as required by NIST and DOC Policy and federal law.
Existing documentation and procedures shall be reviewed; System Owners, System Security Officers, and System Administrators shall be interviewed; applicable 800-53 (latest revision) controls shall be documented and tested;
consistency among the documents shall be analyzed and corrected;
and documentation is created or updated as necessary.
All IT System security documentation shall be submitted in compliance with FIPS 199, and latest versions of NIST Special Publications 800-18, 800- 26, 800-30, 800-34, 800- 37, 800-53, 800-53A, and 800-60; 100% timeliness is required based on NIST assessment milestone schedules. 100% accuracy and completeness are required on all final documentation.
100% COR Inspection
ATTACHMENT A
SYSTEMS FOR SUBTASK A
ID System Name Type
NIST 100 01 Director's Office System Mixed LAN NIST 100 02 AD Staff Offices System Mixed LAN NIST 100 03 NAIS Application NIST 107 02 Public and Business Affairs System Mixed LAN NIST 107 03 Conference Registration System Application NIST 150 01 Safety Office System Mixed LAN NIST 150 02 Safety Applications Application NIST 160 01 CFO/CHCO/CFMO Office System Mixed LAN NIST 162 01 Commerce Business Systems (CBS) Application NIST 162 03 Travel Manager Application NIST 162 05 Corporate Information System Application NIST 164 01 Commerce Standard Acquisition Reporting System (CSTARS) Application
NIST 165 01 Grants Management Information System (GMIS) Application
NIST 172 01 Human Resources System Application NIST 180 01 OCIO Support System Mixed LAN NIST 181 01 NIST Network Security Mixed LAN NIST 181 02 Public Server System Mixed LAN NIST 181 04 NIST Network Infrastructure Mixed LAN NIST 182 01 NIST Managed Desktops Mixed LAN NIST 182 02 IT Services Management System Mixed LAN NIST 183 01 Applications Systems Division (ASD) Moderate Applications Application
NIST 183 06 Application Servers and Databases Mixed LAN NIST 183 07 Applications Systems Division (ASD) Low Applications Application
NIST 183 08 ISG System Mixed LAN NIST 184 04 Central Web Server System Mixed LAN NIST 184 10 Enterprise Server System Mixed LAN NIST 184 12 NIST Central Computing Facility System Mixed LAN
NIST 185 01 Telephone Switch Gaithersburg Mixed LAN NIST 185 02 Telephone Switch Boulder Mixed LAN NIST 190 01 OFPM Office System Mixed LAN NIST 191 01 Physical Security Gaithersburg System Mixed LAN
NIST 191 02 Emergency Service System Mixed LAN NIST 192 01 Property Management System Mixed LAN NIST 193 05 Facilities Management System Mixed LAN NIST 194 02 Physical Security Boulder System Mixed LAN NIST 194 03 Engineering, Maintenance, Safety & Support (EMSS) Building Management System Mixed LAN
NIST 450 01 National Quality Program System Mixed LAN
NIST 470 01 Advanced Technology General Support System Mixed LAN
NIST 480 01 Center Information Management System (CIMS)/ MEP Enterprise Information System (MEIS)
Mixed LAN
NIST 602 01 Special Programs Office Mixed LAN
NIST 610 02 NIST Center for Neutron Research- Lab and Admin Systems (formerly numbered 856 03)
Mixed LAN
NIST 620 01 Center for Nanoscale Science and Technology System Mixed LAN
NIST 630 01 Locally Managed Assets Mixed LAN
NIST 637 01 Surface and Microanalysis Science Division Mixed LAN
NIST 640 01 Measurement Services Division - Standard Reference Materials Mixed LAN
NIST 640 02 Measurement Services Division - Calibration Services Mixed LAN
NIST 653 01 High Pressure Hydrogen System Mixed LAN NIST 654 01 American Dental Association Mixed LAN NIST 680 01 Physical Measurement Laboratory Support System Mixed LAN
NIST 680 02 Physical Measurement Laboratory Administrative Support System Mixed LAN
NIST 680 03 Physical Measurement Laboratory Application Support System Mixed LAN
NIST 688 01 Time Scale and Network Time Service Mixed LAN NIST 730 01 EL Managed Infrastructure Mixed LAN NIST 730 02 Experimental and Independent Resources Mixed LAN
NIST 770 01 ITL Research System Mixed LAN NIST 773 01 ITL Computer Security Division Mixed LAN
SECTION E
INSPECTION AND ACCEPTANCE
E. 1 52.246-4 INSPECTION OF SERVICES--FIXED-PRICE (AUG 1996)
(Reference 52.246-4)
E. 2 52.246-6 INSPECTION--TIME-AND-MATERIAL AND LABOR-HOUR (MAR 2001)
(Reference 52.246-6)
SECTION F
DELIVERIES OR PERFORMANCE
F. 1 52.242-15 STOP-WORK ORDER (AUG 1989)
(Reference 52.242-15)
F. 2 52.242-17 GOVERNMENT DELAY OF WORK (APR 1984)
(Reference 52.242-17)
F. 3 1352.270-70 PERIOD OF PERFORMANCE (APR 2010)
(a) The base period of performance of this contract is from TBD through TBD . If an option is exercised, the period of performance shall be extended through the end of that option period.
(b) The option periods that may be exercised are as follows:
Period Start Date End Date Option I TBD TBD Option II TBD TBD Option III TBD TBD Option IV TBD TBD
(c)The notice requirements for unilateral exercise of option periods are set out in FAR 52.217-9.
SECTION G
CONTRACT ADMINISTRATION DATA
G. 1 1352.201-70 CONTRACTING OFFICER?s AUTHORITY (APR 2010)
(Reference 1352.201-70)
G. 2 1352.201-72 CONTRACTING OFFICER?s REPRESENTATIVE (C0R) (APR 2010)
(a) TBD is hereby designated as the Contracting Officer?s Representative (COR). The COR may be changed at any time by the Government without prior notice to the contractor by a unilateral modification to the contract. The COR is located at:
TBD
TBD
TBD
Phone Number: TBD Email: TBD
(b) The responsibilities and limitations of the COR are as follows:
(1) The COR is responsible for the technical aspects of the contract and serves as technical liaison with the contractor. The COR is also responsible for the final inspection and acceptance of all deliverables and such other responsibilities as may be specified in the contract.
(2) The COR is not authorized to make any commitments or otherwise obligate the Government or authorize any changes which affect the contract price, terms or conditions. Any contractor request for changes shall be referred to the Contracting Officer directly or through the COR. No such changes shall be made without the express written prior authorization of the Contracting Officer.
The Contracting Officer may designate assistant or alternate COR(s) to act for the COR by naming such assistant/alternate(s) in writing and transmitting a copy of such designation to the contractor.
G. 3 1352.216-76 PLACEMENT OF ORDERS (APR 2010)
(a) The contractor shall provide goods and/or services under this contract only as directed in orders issued by authorized individuals. In accordance with FAR 16.505, each order will include:
(1) Date of order;
(2) Contract number and order number;
(3) Item number and description, quantity, and unit price or estimated cost or fee;
(4) Delivery or performance date;
(5) Place of delivery or performance (including consignee);
(6) Packaging, packing, and shipping instructions, if any;
(7) Accounting and appropriation data;
(8) Method of payment and payment office, if not specified in the contract;
(9) Any other pertinent information.
(b) In accordance with FAR 52.216-18, Ordering, the following individuals (or activities) are authorized to place orders against this contract:
NIST Contracting Officer N/A
(c) If multiple awards have been made, the contact information for the DOC task and delivery order ombudsman is N/A
G. 4 1352.245-70 GOVERNMENT FURNISHED PROPERTY (APR 2010)
The Government will provide the following item(s) of Government property to the contractor . The contractor shall be accountable for, and have stewardship of, the property in the performance of this contract. This property shall be used and maintained by the contractor in accordance with provisions of the "Government Property" clause included in this contract.
Item No. TBD Description TBD Quantity TBD Delivery Date TBD Property/Tag Number (if applicable) TBD
SECTION H
SPECIAL CONTRACT REQUIREMENTS
H. 1 1352.208-70 RESTRICTIONS ON PRINTING AND DUPLICATING (APR 2010)
(Reference 1352.208-70)
H. 2 1352.209-73 COMPLIANCE WITH THE LAWS (APR 2010)
(Reference 1352.209-73)
H. 3 1352.209-74 ORGANIZATIONAL CONFLICT OF INTEREST (APR 2010)
(Reference 1352.209-74)
H. 4 1352.228-72 DEDUCTIBLES UNDER REQUIRED INSURANCE COVERAGE- FIXED PRICE (APR 2010)
(Reference 1352.228-72)
H. 5 1352.231-71 DUPLICATION OF EFFORT (APR 2010)
(Reference 1352.231-71)
H. 6 1352.209-72 RESTRICTIONS AGAINST DISCLOSURE (APR 2010)
(a) The contractor agrees, in the performance of this contract, to keep the information furnished by the Government or acquired/developed by the contractor in performance of the contract and designated by the Contracting Officer or Contracting Officer?s Representative, in the strictest confidence. The contractor also agrees not to publish or otherwise divulge such information, in whole or in part, in any manner or form, nor to authorize or permit others to do so, taking such reasonable measures as are necessary to restrict access to such information while in the contractor?s possession, to those employees needing such information to perform the work described herein, i.e., on a "need to know" basis. The contractor agrees to immediately notify the Contracting Officer in writing in the event that the contractor determines or has reason to suspect a breach of this requirement has occurred.
(b) The contractor agrees that it will not disclose any information described in subsection (a) to any person unless prior written approval is obtained from the Contracting Officer. The contractor agrees to insert the substance of this clause in any consultant agreement or subcontract hereunder.
H. 7 1352.216-74 TASK ORDERS (APR 2010)
(a) In task order contracts, all work shall be initiated only by issuance of fully executed task orders issued by the Contracting Officer. The work to be performed under these orders must be within the scope of the contract. The Government is only liable for labor hours and costs expended under the terms and conditions of this contract to the extent that a fully executed task order has been issued and covers the required work and costs. Charges for any work not authorized shall be disallowed.
(b) For each task order under the contract, the Contracting Office shall send a request for proposal to the contractor(s). The request will contain a detailed description of the tasks to be achieved, a schedule for completion of the task order, and deliverables to be provided by the contractor.
(c) The contractor shall submit a proposal defining the technical approach to be taken to complete the task order, work schedule and proposed cost/price.
(d) After any necessary negotiations, the contractor shall submit a final proposal.
(e) Task orders will be considered fully executed upon signature of the Contracting Officer. The contractor shall begin work on the task order in accordance with the effective date of the order.
(f) The contractor shall notify the Contracting Officer of any instructions or guidance given that may impact the cost, schedule or deliverables of the task order. A formal modification to the task order must be issued by the Contracting Officer before any changes can be made.
(g) Task orders may be placed during the period of performance of the contract. Labor rates applicable to hours expended in performance of an order will be the contract rates that are in effect at the time the task order is issued.
(h) If multiple awards are made by the Government, the CO shall provide each awardee a fair opportunity to be considered for each task order over the micro-purchase threshold unless one of the exceptions at FAR 16.505(b) applies.
H. 8 1352.228-70 INSURANCE COVERAGE (APR 2010)
(a) Workers Compensation and Employer?s Liability. The contractor is required to comply with applicable federal and state workers'' compensation and occupational disease statutes. If occupational diseases are not compensable under those statutes, they shall be covered under the employer?s liability section of the insurance policy, except when contract operations are so commingled with a contractor?s commercial operations that it would not be practical to require this coverage. Employer?s liability coverage of at least $100,000 shall be required, except in states with exclusive or monopolistic funds that do not permit workers'' compensation to be written by private carriers.
(b) General liability.
(1) The contractor shall have bodily injury liability insurance coverage written on the comprehensive form of policy of at least $500,000 per occurrence.
(2) When special circumstances apply in accordance with FAR 28.307-2(b), Property Damage Liability Insurance shall be required in the amount of $0.00 .
(c) Automobile liability. The contractor shall have automobile liability insurance written on the comprehensive form of policy. The policy shall provide for bodily injury and property damage liability covering the operation of all automobiles used in connection with performing the contract.
Policies covering automobiles operated in the United States shall provide coverage of at least $200,000 per person and $500,000 per occurrence for bodily injury and $20,000 per occurrence for property damage.
(d) Aircraft public and passenger liability. When aircraft are used in connection with performing the contract, the contractor shall have aircraft public and passenger liability insurance. Coverage shall be at least $200,000 per person and $500,000 per occurrence for bodily injury, other than passenger liability, and $200,000 per occurrence for property damage. Coverage for passenger liability bodily injury shall be at least $200,000 multiplied by the number of seats or passengers, whichever is greater.
(e) Vessel liability. When contract performance involves use of vessels, the Contractor shall provide, vessel collision liability and protection and indemnity liability insurance as determined by the Government.
H. 9 1352.233-70 AGENCY PROTESTS (APR 2010)
(a) An agency protest may be filed with either: (1) the contracting officer, or (2) at a level above the contracting officer, with the appropriate agency Protest Decision Authority. See 64 Fed. Reg.
16,651 (April 6, 1999)
(b) Agency protests filed with the Contracting Officer shall be sent to the following address: NIST 100 Bureau Drive Bldg 301 Room B164 Gaithersburg, MD 20899-1640
(c) Agency protests filed with the agency Protest Decision Authority shall be sent to the following address: NIST 100 Bureau Drive Bldg 301 Room B164 Gaithersburg, MD 20899-1640
(d) A complete copy of all agency protests, including all attachments, shall be served upon the Contract Law Division of the Office of the General Counsel within one day of filing a protest with either the Contracting Officer or the Protest Decision Authority.
(e) Service upon the Contract Law Division shall be made as follows:
U.S. Department of Commerce Office of the General Counsel Chief, Contract Law Division Room 5893 Herbert C. Hoover Building
14th Street and Constitution Avenue, N.W.
Washington, D.C. 20230.
FAX: (202) 482-5858
H. 10 1352.237-70 SECURITY PROCESSING REQUIREMENTS - HIGH OR MODERATE RISK CONTRACTS (APR 2010)
(a) Investigative Requirements for High and Moderate Risk Contracts. All contractor (and subcontractor) personnel proposed to be employed under a High or Moderate Risk contract shall undergo security processing by the Department?s Office of Security before being eligible to work on the premises of any Department of Commerce facility, or through a Department of Commerce IT system. All Department of Commerce security processing pertinent to this contract will be conducted at no cost to the contractor. The level of contract risk will determine the type and scope of such processing as noted below.
(1) Non-IT Service Contracts
(i) High Risk - Background Investigation (BI)
(ii) Moderate Risk - Moderate Background Investigation (MBI)
(2) IT Service Contracts
(i) High Risk IT - Background Investigation (BI)
(ii) Moderate Risk IT - Background Investigation (BI)
(b) In addition to the investigations noted above, non-U.S. citizens must have a pre-appointment check that includes an Immigration and Customs Enforcement agency check.
(c) Additional Requirements for Foreign Nationals (Non-U.S. Citizens) To be employed under this contract within the United States, non-U.S. citizens must have:
(1) Official legal status in the United States
(2) Continuously resided in the United States for the last two years; and
(3) Advance approval from the servicing Security Officer of the contracting operating unit in consultation with the Office of Security (OSY) headquarters. (OSY routinely consults with appropriate agencies regarding the use of non-U.S. citizens on contracts and can provide up-to-date information concerning this matter.)
(d) Security Processing Requirement. Processing requirements for High and Moderate Risk Contracts are as follows:
(1) The contractor must complete and submit the following forms to the Contracting Officer Representative (COR):
(i) Standard Form 85P (SF 85P), Questionnaire for Public Trust Positions;
(ii) FD 258, Fingerprint Chart with OPM?s designation in the ORI Block; and (iii Credit Release Authorization.
(2) The Sponsor will ensure that these forms have been properly completed, initiate the CD-254, Contract Security Classification Specification, and forward the documents to the cognizant Security Officer.
(3) Upon completion of the security processing, the Office of Security, through the servicing Security Officer and the COR, will notify the contractor in writing of the individual?s eligibility to be given access to a Department of Commerce facility or Department of Commerce IT system.
(4) Security processing shall consist of limited personal background inquiries pertaining to verification of name, physical description, marital status, present and former residences, education, employment history, criminal record, personal references, medical fitness, fingerprint classification, and other pertinent information. For non-U.S. citizens, the COR must request an Immigration and Customs Enforcement (formerly INS) agency check. It is the option of the Office of Security to repeat the security processing on any contract employee at its discretion.
(e) Notification of Disqualifying Information. If the Office of Security receives disqualifying information on a contract employee, the COR will be notified. The COR, in coordination with the contracting officer, will immediately remove the contract employee from duty requiring access to Departmental facilities or IT systems. Contract employees may be barred from working on the premises of a facility for any of the following:
(1) Conviction of a felony of a crime of violence or of a misdemeanor involving moral turpitude.
(2) Falsification of information entered on security screening forms or of other documents submitted to the Department.
(3) Improper conduct once performing on the contract, including criminal, infamous, dishonest, immoral, or notoriously disgraceful conduct or other conduct prejudicial to the Government regardless of whether the conduct directly related to the contract.
(4) Any behavior judged to pose a potential threat to Departmental information systems, personnel, property, or other assets.
(f) Failure to comply with the requirements may result in termination of the contract or removal of some contract employees from Department of Commerce facilities or access to IT systems.
(g) Access to National security Information. Compliance with these requirements shall not be construed as providing a contract employee clearance to have access to national security information.
(h) The Contractor shall include the substance of this clause, including this paragraph, in all subcontracts.
(End of Clause)
H. 11 1352.239-71 ELECTRONIC AND INFORMATION TECHNOLOGY (APR 2010)
(a) To be considered eligible for award, offerors must propose electronic and information technology (EIT) that meet the applicable Access Board accessibility standards at 36 CFR 1194 designated below:
XX 1194.21 Software applications and operating systems XX 1194.22 Web-based intranet and internet information and applications XX 1194.23 Telecommunications products
1194.24 Video and multimedia products
1194.25 Self-contained, closed products
XX 1194.26 Desktop and portable computers XX 1194.31 Functional performance criteria XX 1194.41 Information, documentation and support
(b) The standards do not require the installation of specific accessibility-related software or the attachment of an assistive technology device, but merely require that the EIT be compatible with such software and devices so that it can be made accessible if so required by the agency in the future.
(c) Alternatively, offerors may propose products and services that provide equivalent facilitation.
Such offers will be considered to have met the provisions of the Access Board standards for the feature or components providing equivalent facilitation. If none of the offers that meet all applicable provisions of the standards could be accepted without imposing an undue burden on the agency or component, or if none of the offerors propose products or services that fully meet all of the applicable Access Board?s provisions, those offerors whose products or services meet some of the applicable provisions will be considered eligible for award. Awards will not be made to an offeror meeting all or some of the applicable Access Board provisions if award would impose an undue burden upon the agency.
(d) Offerors must submit representation information concerning their products by completing the VPAT template at www.Section508.gov.
H. 12 1352.239-72 SECURITY REQUIREMENTS FOR INFORMATION TECHNOLOGY RESOURCES (APR 2010)
(a) Applicability. This clause is applicable to all contracts that require contractor electronic access to Department of Commerce sensitive non-national security or national security information contained in systems, or administrative control of systems by a contractor that process or store information that directly supports the mission of the Agency.
(b) Definitions. For purposes of this clause, the term "Sensitive" is defined by the guidance set forth in the Computer Security Act of 1987 (P.L. 100-235), including the following definition of the term:
(1) Sensitive information is "? any information, the loss, misuse, or unauthorized access to, or modification of which could adversely affect the national interest or the, conduct of federal programs, or the privacy to which individuals are entitled under section 552a of title 5, United States Code (The Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy."
(2) For purposes of this clause, the term "National Security" is defined by the guidance set forth in:
(i) The DOC IT Security Program Policy and Minimum Implementation Standards, Section 4.3.
(ii) The DOC Security Manual, Chapter 18.
(iii) Executive Order 12958, as amended, Classified National Security Information. Classified or national security information is information that has been specifically authorized to be protected from unauthorized disclosure in the interest of national defense or foreign policy under an Executive Order or Act of Congress.
(3) Information technology resources include, but are not limited to, hardware, application software, system software, and information (data). Information technology services include, but are not limited to, the management, operation (including input, processing, transmission, and output), maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.
(c) The contractor shall be responsible for implementing sufficient Information Technology security, to reasonably prevent the compromise of DOC IT resources for all of the contractor?
s systems that are interconnected with a DOC network or DOC systems that are operated by the contractor.
(d) All contractor personnel performing under this contract and contractor equipment used to process or store DOC data, or to connect to DOC networks, must comply with the requirements contained in the DOC Information Technology Management Handbook (see DOC, Office of the Chief Information Officer website), or equivalent/more specific agency or operating unit counsel guidance as specified immediately hereafter .
(e) Contractor personnel requiring a user account for access to systems operated by the contractor for DOC or interconnected to a DOC network to perform contract services shall be screened at an appropriate level in accordance with Commerce Acquisition Manual 1337.70, Security Processing Requirements for Service Contracts.
(f) Within 5 days after contract award, the contractor shall certify in writing to the COR that its employees, in performance of the contract, have completed initial IT security orientation training in DOC IT Security policies, procedures, computer ethics, and best practices, in accordance with DOC IT Security Program Policy, chapter 15, section 15.3. The COR will inform the contractor of any other available DOC training resources.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .