Attachment_C_-_REVISED_SOW_Amendment__000004.pdf

PDF 247 KB Posted

Attached to
Trustee/401a/Record Keeping Federal contract opportunity
Solicitation number
SECHQ115R0003
Issued by
Securities and Exchange Commission

View the file

Other files for this federal contract opportunity

Other files attached to Trustee/401a/Record Keeping, newest first.
File Type Posted
SF_30.pdf PDF
Attachment_H-_Mandatory_Training_for_Contactor_Personnel.pdf PDF
Attachment_C_-_SOW.pdf PDF
Attachment_F_-_NDA.pdf PDF
Attachment_E_-_SEC's_Clauses.pdf PDF
Attachment_B-_Amended_Combined_Synopsis_Solicitation.pdf PDF
Attachment_D_-_REVISED_Pricing_Schedule_Final.pdf PDF
Attachment_G_-_Past_Performance.pdf PDF
Amendment_00007.pdf PDF
Attachment_C_-_SOW_Amendment__000006.pdf PDF
Amendment_00006.pdf PDF
Attachment_B-_Combined_Synopsis_Solicitation.pdf PDF
Amendment_00005.pdf PDF
Amendment_00004.pdf PDF
Amendment_00003.pdf PDF
Amendment_0002.pdf PDF
Amendment_000001.pdf PDF
Attachment_F_-_NDA.pdf PDF
Attachment_A_-_SF1449.pdf PDF
Attachment_C_-_SOW.pdf PDF
Attachment_D_-Pricing_Schedule_401a.docx DOCX document
Attachment_B-_Combined_Synopsis_Solicitation.pdf PDF
Attachment_E_-_SEC's_Clauses.pdf PDF
Show all 23

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Supplemental Retirement Program (SRP) Attachment C

U.S. Securities and Exchange Commission

OHR – Office of Human Resources Supplemental Retirement Program (SRP) – Trustee and Custodian

REVISED

Statement of Work

Formatted: Font: 28 pt

Formatted: Centered

Table of Contents

C.1 SCOPE…………………………………….……………………………………………………………………………………………………………………3

C.2 BACKGROUND…………………………………………………………………………………………………………………………………………… 3

C.3 BUSINESS REQUIREMENTS………………………………………………………………………………………………………………………… 3

C.4 FEDERAL REQUIREMENTS & SEC REGULATIONS………….………………………………………………………………………………7

C.5 DOCUMENTATION UPDATES……………………………………………………………………………………………………………………. 10

C.6 RISK MANAGEMENT…………..……………………………………………………………………………………………………………………..10

SECTION D – PACKAGING AND MARKING…..…….…………………………………………………………………………………………….10

SECTION E – INSPECTION AND ACCEPTANCE…..…….………………………………………………………………………………………..10

SECTION F – DELIVERIES OR PERFORMANCE……………………………………………………………………………………………………10

SECTION G – SPECIAL CONTRACT REQUIREMENTS ….……..…….………………………………………………………………………..11

C.1 Scope

The U.S. Securities and Exchange Commission ("SEC") is searching for a vendor that will hold the assets for eligible SEC employees who are enrolled in a new defined contribution retirement plan under Section 401(a) of the Internal Revenue Code (referred to herein as the “Plan” or as the “Supplemental Retirement Plan”). The vendor will act as the Trustee and Custodian for the Plan. The Plan will hold only employer contributions. If the vendor has prototype 401(a) Plan documents, it should provide a copy in its response to this solicitation.

The Plan’s main objective will be to safeguard the principal and any increases thereto due to interest accumulation. The Plan’s objective will not include maximizing return on the principal. The SEC anticipates that the Plan will direct that all assets be invested in a business savings-type account initially, in a manner that will qualify for “pass-through” FDIC insurance as a retirement plan. The SEC may consider moving some of the assets into CDs or Treasury securities or some other secure vehicle at a later date.

The SEC estimates that there will be approximately 3100 participants initially, with an annual estimated net increase of 200 participants per year. The SEC estimates that the Plan assets will be approximately $14 million by early 2015, with an annual estimated net increase in holdings of approximately $7 million. The participants will not be allowed to direct investments. The SEC anticipates that participants will have limited rights to make withdrawals beyond the rights afforded by law, and accordingly estimates that the number of withdrawals will be fewer than 300 per year during the contract period. The initial plan assets will be 100% vested, but new investments may be subject to a vesting period.

Examples of required Trustee services include:

• serving as the Plan Trustee in accordance with the requirements of Section 401(a) of the Internal Revenue Code;

• keeping the Plan assets in trust; and

• maintaining auditable records of all Plan assets and submitting to periodic audits as required by law, including as required to enable the SEC to respond to inquiries by, e.g., Congress, the General Accountability Office, the Internal Revenue Service, etc.

Examples of required Custodian services include:

• receiving plan assets bi-weekly via electronic wire transfers from the SEC’s payroll provider (currently the Department of the Interior);

• following instructions from the Recordkeeper and the Trustee regarding withdrawals and distributions, including the ability to make wire transfers to the Recordkeeper; and1

• providing trust reconciliation reports on a monthly basis• separately accounting for any amounts forfeited by nonvested participants, and notifying the SEC any time that balance approaches $250,000 (or the then-applicable FDIC insurance limit).

*Note: A separate RFP will be issued for a Recordkeeper that will closely coordinate with this RFP.

Formatted: Centered

In response to this solicitation, the vendor must stipulate any associated fees for acceptance of the bi-weekly wire transfers. In addition, the vendor must have the ability to accept any additional discretionary payments the agency may choose to make, whether through the SEC’s payroll provider or directly from the SEC, and in its response to this solicitation must state the amount of any associated fees (under current rate schedules).

The vendor will not make any decisions as to employee eligibility, contribution amounts, distributions or disputes. Authorized Federal employees from the SEC retain all responsibility for making determinations as to eligibility, contribution amounts, distributions and resolution of disputes. The vendor will not be responsible for directly interacting with Plan participants. Contributions will be subject to the Internal Revenue Service (IRS) maximum elective deferral limits, annual additions limits, and any other applicable laws and regulations governing retirement plans, but the vendor will not be responsible for ensuring compliance with those limits.

The vendor must be an institution that does not fall under the purview of the SEC’s regulatory authority. The vendor must be fully insured by the appropriate regulator (e.g., FDIC, NCUA).

C.2 Background

The mission of the SEC is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation. The SEC oversees the key participants in the securities industry, including securities exchanges, securities brokers and dealers, investment advisors, and mutual funds.

As part of Securities and Exchange Commission’s (SEC’s) compensation model and pursuant to the negotiated agreement with the National Treasury Employees Union (NTEU), the SEC is establishing a supplemental retirement program in addition to standard federal retirement programs such as Federal Employees Retirement System (FERS), the Civil Service Retirement System (CSRS), and the Thrift Savings Plan (TSP) for eligible employees. This supplemental retirement plan will cover nearly all of the SEC’s 4600 employees, who are located in the Washington, DC headquarters office as well as 11 regional offices throughout the US.

C.3 Business Requirements

C.3.1 - The SEC will develop the Supplemental Retirement Plan Rules and related requirements. Such rules and requirements will, among other things, provide for strict controls to prevent vendor’s discretion to make entitlement determinations calculate distribution amounts or resolve disputes. An audit of vendor actions will be within the scope of responsibilities of the SEC. The rules and requirements will be provided to the contractor before work begins. The contractor must develop and understand the SEC Supplemental Retirement Plan design and rules, data elements, accounting, financial, and auditing requirements.

C.3.2 - The contractor shall provide a financial vehicle to meet the Plan’s accounting, financial reporting and internal control requirements. Travel to the SEC’s headquarters in Washington, DC may be required, for familiarization and design of financial reports to support the Agency’s reporting for the supplemental retirement program.

C.3.3 – The contractor shall deliver financial disclosures governing defined contribution plans subject to ERISA as required by the Department of Labor, IRS or other regulatory concerns. These deliverables should be provided at the intervals prescribed by applicable law.

C.3.4 - The contractor shall ensure privacy and security of all data, maintaining the Commission’s standards for the handling of sensitive data.

Note the following: Safeguarding of Information/Maintain Privacy and Security

a) DELETE

a) Security Requirement for Contract Staff: All individuals working on the effort must have a Moderate Risk Public Trust (MRPT) determination from the Agency to facilitate the protection of sensitive account data.

b) Incident Reporting: Notify the COR of any breach of security. Security incidents must be reported and addressed immediately, so as to contain the incident, establish countermeasures to mitigate the impact of the incident, and recover from it. The party discovering the incident in accordance with its procedures will report security incidents.

c) Security Parameters: Specify security parameters used to exchange information with the Agency, including, but not limited to, encryption being used during transport; whether the data (including passwords) is encrypted in storage; type of connection; etc.

C.3.5 – The contractor shall respond to telephone and e-mail inquiries by the SEC representatives and return calls/messages within 24 hours or 1 business day.

C.4 Federal Requirements & SEC Regulations

C.4.1 Federal Requirements. The following is a sample list of federal requirements consisting of laws, policies, standards and guidance required for information protection. The contractor will be subject to the same information protection requirements as the SEC under the E-Government Act of 2002. The list that follows is not all-inclusive and the contractor shall follow the same requirements as the Commission.

DELETE

• Office of Management and Budget (OMB) Circular A-11, Revised, “Preparation, Submission and

Execution of the Budget” (July 2003)

• OMB Circular A-130, Revised, “Management of Federal Information Resources” (November 2000)

• OMB Federal Enterprise Architecture Program Management Office (FEAPMO) Reference Models and

Circular A-11 Guidance. www.feapmo.gov.

• Privacy Act of 1974, Public Law 93-579 (5 U.S.C. 552a)

• The E-Government Act of 2002, Public Law 107-347

• Office of Management and Budget (OMB) Memorandum M-12-20, FY 2012 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management

• OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions 1 of the E-

Government Act of 2002, September 30,2003

• Federal Information Processing Standard (FIPS) Publication (PUB) 201, Personal Identity Verification

(PIV) of Federal Employees and Contractors, March 2006

• FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006

• FIPS PUB 197, Advanced Encryption Standard, November 2001

Formatted: Font: Bold

Formatted: Strikethrough

Formatted: Indent: Left: 0.5", No bullets or numbering

Formatted: Font: Bold

Formatted: Strikethrough

Formatted: Strikethrough

Formatted: Strikethrough

Formatted: Strikethrough

• National Institute for Standards and Technology (NIST), Special Publication (SP) 800-122, Guide for Protecting the Confidentiality of Personally Identifiable Information (PII), April 2010

• NIST SP 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010

• NIST SP 800-115, Technical Guide to Information Security Testing and Assessment Sept 2008

• NIST SP 800-100, Information Security Handbook: A Guide for Managers, Oct 2006

• NIST SP 800-95, Guide to Secure Web Services, Aug 2007

• NIST SP 800-92, Guide to Computer Security Log Management, Sep 2006

• NIST SP 800-88, Guidelines for Media Sanitization, Sep 2006

• NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide, August 2012

• NIST SP 800-53 Rev. 3, Recommended Security Controls for Federal Information Systems and

Organizations, Aug 2009

• NIST SP 800-53A, Revision 1, Guide for Assessing the Security Controls in Federal Information

Systems, June 2010

• NIST SP 800-44 Version 2, Guidelines on Securing Public Web Servers, Sep 2007

• NIST SP 800-30, Revision 1, Guide for Conducting Risk Assessments, September 2012

• NIST SP 800-70, Revision 2, National Checklist Program for IT Products: Guidelines for Checklist Users and Developers, February 2011

C.4.2 SEC Regulations DELETE

• Information Technology Security Program, SECR 24-2, approved December 8, 1998

• IT Security Program Technical Bulletin: Identification, Authentication and Passwords, SECR 24-2.1, April 4,

• Safeguarding Non-Public Information, SECR 23-2A, approved January 21, 2000

• Use of SEC Office Equipment SECR 24-4.3, approved 03/08/2002

• Use of Personal Digital Assistant (PDA) Devices SECR 24-5.2, approved 11/02/2002

• Enterprise Architecture SECR 24-1.6, approved 11/02/2002

• Certification and Accreditation SECR 24-2.4, approved 07/18/2002

• Network Security SECR 24-2-7, approved 09/11/2002

• Electronic Mail SECR 5-10, approved 05/20/1996

• Enterprise Backup of Electronic Data SECR 24-2.6

• Virus and Malicious Software Detection and Prevention SECR 24-2.2

• Use of Internet Browsers and Access to the World Wide Web SECR24-3, approved 12/30/1998

• Information Technology Security Program, SECR 24-04, approved 10/4/2005

• Information Collection Program, SECR 24-09, approved 07/29/2009

C.4.3 Security Requirements. The contractor shall meet all the requirements listed below. DELETE

C.4.3.1 Requirements Management. DELETE The Contractor shall provide all necessary personnel, administrative, financial, and managerial resources necessary to perform all tasks described in this Statement of Work (SOW).

C.4.3.2 Security Issue Review. DELETEThe Contractor shall remediate problems identified during security testing. All significant issues (typically those rated as HIGH and often those rated as MEDIUM) should be resolved before the system/interface or connectivity is allowed to go into production. The Contractor shall resolve as many security audit-related Plan of Action and Milestones (POA&M) items as possible and within a reasonable timeframe. The Contractor shall document the resolution and provide supporting evidence of changes. The Contractor shall schedule a conference meeting with the COR, OIT Security Group staff, and relevant SEC staff to review the state of the POA&M resolutions. The Contractor shall provide the SEC with the number and description of resolved POA&M items identified in the security review.

Formatted: Strikethrough

Formatted: Strikethrough

Formatted: Strikethrough

Formatted: Strikethrough

Formatted: Font: Bold

C.4.3.3 Security Assessment. DELETE OIT Security Team performs Security Assessment and Authorization (SA&A) for a product to be deployed. This process is designed to allow the SEC to identify any risks associated with the system and either mitigate them or formally accept any residual risk. This requirement is based on the NIST 800 family of documents and includes:

• Enumeration - activity aimed at identifying devices and components and cross-referencing with provided inventory lists

• Vulnerability Scanning - performs network-based vulnerability assessment of customer’s servers, workstations, and any other network device or appliance in scope. The assessment will identify vulnerabilities associated with network services, operating systems, and devices that are un-patched or have out-of-date software security patches;

• Penetration Testing - attempts to exploit weaknesses identified from vulnerability scanning to verify legitimate findings, eliminate false-positives, and determine the extent of the vulnerability and potential remediation steps that may be taken; and

• Functional Testing - Perform specific tests, examinations, and inspections against NIST 800-53 controls not tested by the other activities.

The Contractor shall provide the Security Team with: (1) a system demonstration; (2) test user IDs; (3) Access to the system; (4) System Security Plan (SSP); and (5) additional documents as required under the NIST 800 series for Security Assessment & Authorization; 508 compliance information. The Contractor shall provide ongoing support to update the required SA&A documentation. The OIT Security Team provides the test reports.

C.4.4 Project Management

C.4.4.1 Project Coordination. The Contractor shall coordinate with the COR and SEC Program/Project Managers to provide regular project plan and schedule updates.

C.4.4.2 Project Status Reports. The Contractor shall prepare and deliver to the COR periodic formal Project Status Reports and more frequent informal written status updates.

C.4.5 Project Meetings

C.4.5.1 Kick-Off Meeting. Within one (1) week after the award, the Contractor shall participate in a kick-off meeting attended by Key Contractor personnel, the SEC Contracting Officer (CO), the Contracting Officers Representative (COR), and other key SEC personnel to introduce project members and their roles and responsibilities, introduce the SEC “Rules of the Road”, and discuss the requirements of the systems, the project schedule, security requirements, connections and restrictions, at a minimum.

C.4.5.2 Status Meetings. The Contractor shall participate in periodic project status meetings attended by key Contractor personnel, the COR and other key SEC personnel.

C.4.5.3 Meeting Minutes. The Contractor shall provide kick-off and status meeting minutes to the COR for review. The Contractor shall work with the COR to resolve any disagreements that may arise and provide the COR with final meeting minutes for review and approval.

C.4.5.4 Briefings. The Contractor shall prepare and deliver quarterly briefings that cover key project accomplishments including milestones met and deliverables. The briefing shall address matters that are essential to ensure overall success of the task including funding status, project schedule, and an analysis of

Formatted: No bullets or numbering, Widow/Orphan control, Adjust space between Latin and Asian text

Formatted: No bullets or numbering, Widow/Orphan control, Adjust space between Latin and Asian text the risks that may affect successful task completion. The Contractor shall provide the COR with briefing materials for review prior to the presentation. The Contractor shall incorporate feedback from COR and shall provide the COR with final briefing materials for review and approval.

C.4.6 Project Plans. The Contractor shall develop and document a plan for implementing the project that addresses considerations including, but not limited to:

• Possible business process and associated standards/procedures redesign and definition;

• Business process/system integration;

• Coding, configuration, and customization;

• Coordinated documentation, testing, and schedule;

• Production deployment which includes a back-out plan;

• Training;

• Communications/change management; and

• Transition from manual and paper-based system of records.

The Contractor shall review the implementation plan with the COR and relevant stakeholders. The Contractor shall deliver the document to the COR for review; the Contractor shall incorporate feedback from the COR and shall provide the COR with a final document for review and approval. The approved Project Schedule shall become the baseline for the contract. The Contractor shall notify the COR of any deviations or changes to the plan, the reasons for changes, and shall provide the COR with written draft of updates to the plan for review and approval.

C.5 Risk Management. The Contractor shall coordinate and assist the COR to develop and maintain a Risk Registry throughout the lifecycle of the project. The Contractor shall immediately notify the COR of any major risk to the project and provide recommendation on the mitigation of the risk.

SECTION D - PACKAGING AND MARKING

D.1 Marking. All information submitted to the Contracting Officer or the COR, or their designated point of contact, shall clearly indicate the number of the contract for which the information is being submitted.

SECTION E - INSPECTION AND ACCEPTANCE

E.1 Inspection and Acceptance. Inspection and acceptance of the supplies and/or services to be furnished under this contract will be performed by the COR. The COR will assess performance of Contractor personnel on an ongoing basis, and communicate the results to the Contractor. The COR will not discuss performance concerns with Contractor personnel. Should a problem arise regarding performance or the overall level of service, the contactor shall have no more than three (3) business days in which to correct the problem. This may result in the removal of Contractor personnel from the award.

SECTION F - DELIVERIES OR PERFORMANCE

F.1 Period of Performance. The period of performance is for the Base of two (2) years and three (3) one

(1) year options periods to follow the base year.

F.1.1 Option Periods. This contract has three (3) one-year option periods. If all options are exercised, the period of performance will not exceed a total of five (5) years six (6) months (the contract may be extended up to six months – see Section I – 52.217-8). If exercised, the period of performance for each successive option will begin the day after the expiration of the previous year and continue for one year. Exercise of any option requires a modification signed by an SEC Contracting Officer.

F.1.2 Award of an initial contract will not obligate the Government to exercise any contractual option. Prior to exercising any option, the Government will make a determination that (1) funds are available, (2) the requirement covered by the option fulfills an existing need of the Government, and (3) the exercise of the option is the most advantageous method of fulfilling the Government’s need, price and other factors considered.

F.1.3 Failure to exercise an option shall not obligate the Government to pay any charges other than the contract price including exercised options.

F.2 Place of Performance. The Contractor shall perform development work at the Contractor’s work site location (off-site).

F.3 Schedule of Deliverables. The Contractor shall prepare and provide deliverables in electronic format to the COR. The COR will review all deliverables and provide comments and/or approvals/disapprovals in a timely manner so as not to adversely impact the project schedule. Deliverable schedules may include, but will not be limited to, the following:

Section Deliverable Schedule C.3 Business Requirements Per approved project schedule C.4 Section 508 Per approved project schedule C.4.3.2 Security Issue Review Per approved project schedule C.4.3.3 Security Penetration Per approved project schedule C.4.4 Project Management Per approved project schedule C.5? Documentation Updates Per approved project schedule C.5 Risk Management Per approved project schedule G.9.(c), (d), (f) Personally Identifiable

Information Per approved project schedule

G.10 Disaster Recovery Per approved project plan

F.3.1 Documenting, Inspecting, and Accepting Contract Deliverables. The Contractor shall submit all deliverables requiring a transmittal sheet with either the attached Deliverable Transmittal sheet or an alternative transmittal sheet that contains substantially the same information.

F.4 Place of Delivery. The deliverables to be furnished under this contract shall be delivered to the following addresses:

U.S. Securities and Exchange Commission Station Place 100 F Street NE Washington, D.C. 20549 Attn:Deidre Robinson

Formatted: Widow/Orphan control, Adjust space between Latin and Asian text, Adjust space between Asian text and numbers

F.5 Hours of Performance. The Contractor shall be available during normal business hours on all Federal Government business days during the term of the contract. This support shall occur during normal business hours between 7:00 AM to 7:00 PM. EST, Monday through Friday, excluding Federal holidays and official Federal Government closures in the Metropolitan DC area. However, the SEC may require services outside of regular business hours. Exceptions may be made on a case-by-case basis and must be pre-approved by the Government COR.

SECTION G - SPECIAL CONTRACT REQUIREMENTS

G.1 Type of Contract. It is anticipated that this contract will be awarded on a Firm Fixed Price (FFP) basis.

G.2 Security and Privacy Act Matters. The security classification for work performed under this contract is Public Trust. The documents that shall be reviewed and produced are non-public and sensitive in nature and shall be protected from unauthorized disclosure. Work on this project request that personnel have access to Privacy Act Information. Personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations.

G.2.1 Compliance with Security Regulations, Policies and Procedures. The Contractor shall be responsible for compliance by its employees with SEC security regulations, policies, and procedures. This includes safekeeping, wearing, and visibility of identification badges. The SEC will issue Contractor identification badges to on-site Contractor personnel, and the badges shall be visible at all times while employees are on SEC premises. The Contractor shall provide all requested information (the SEC will provide forms to the Contractor at time of award) required to facilitate issuance of identification badges and shall conform to applicable regulations concerning the use and possession of the badges. The Contractor shall be responsible for ensuring that all identification badges issued to the Contractor employees are returned within forty-eight (48) hours following the completion of the contract, relocation, or termination of an employee and/or request of the Contracting Officer or the COR.

G.3 Conflicts of Interest.

(a) General. Subpart 9.5 of the Federal Acquisition Regulation 48 C.F.R. 9.5, prescribes responsibilities, general rules, and procedures for identifying, evaluating, and resolving organization conflicts of interest.

(b) Purpose. The purpose of this clause is to avoid, neutralize, or otherwise mitigate organizational conflicts of interest which might exist related to a Contractor’s performance of work required by this contract. Such conflicts may arise in situations including, but not limited to: a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement in which it has provided assistance in the preparation of the Government’s requirements and specifications; a Contractor’s providing advisory assistance to the Government in a procurement in which the Contractor’s firm or one which the Contractor represents is an actual or potential Offeror; and a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement where the Contractor has obtained confidential or proprietary information relating to competing Offerors as a result of the Contractor’s work on prior task orders.

(c) Definition. For purposes of this clause, the term “Contractor” means: The Contractor; any of the Contractor’s parents, affiliates or other entities in which the Contractor or such parents or affiliates have a financial interest; successors in interest to the Contractor or any of its parents or affiliates; proposed consultants or subcontractors at any tier; and employees thereof.

(d) Restrictions. The Contractor agrees:

1. To remain ineligible to participate in any capacity (including participating as a prime Contractor, subcontractor, or as the representative of another party) in contracts, subcontracts, or Proposal (whether solicited or unsolicited) that directly relate to the Contractor’s performance of work under this

Contract.

2. Prior to beginning work on a task order, to execute such Confidentiality Agreements, Statements of

Non-Disclosure or other documents which the Contracting Officer may, in his/her sole discretion, require in order to protect the proprietary nature or confidentiality of information provided by the Government or otherwise received by the Contractor in connection with its work under this Contract.

3. As otherwise provided in this Contract, not to accept any compensation or any other form of payment from a broker, potential lessor, or any source other than the Government for services rendered under this Contract, and to employ aggressive strategies to minimize the Government’s lease costs where the Contractor would entitled by common business practice to receive a real estate commission or any form of payment from a broker, potential lessor, or other party, for work performed under this Contract.

4. To immediately notify the Contracting Officer of any offer of compensation, other form of payment, or thing of value, made by a broker, potential lessor, or any source other than the Government to the Contractor related to services rendered under this Contract, regardless of whether such offer was made during Contractor’s performance of work under a given task order or subsequent to Contractor’s completion of work under such task order.

5. Prior to the acceptance of a task order request, to immediately notify the Contracting Officer of any potential conflict of interest which would prevent or limit the Contractor’s ability to perform the work requested.

6. To immediately notify the Contracting Officer of any conflict of interest discovered during Contractor’s performance of work pursuant to a Government issued task order; provided that the Contracting Officer shall have the right to impose such restrictions as he/she deems appropriate on Contractor’s performance based on the existence of such a conflict or, if the Contracting Officer determines that such restrictions would not adequately address the conflict of interest at issue, to terminate the Contractor’s performance of work under the task order at no cost to the Government.

7. As otherwise provided in this Contract, that if the Contractor declines to accept a task order request and subsequently participates (either directly or as a representative of another party) in a Government contracting action that was the subject of the task order request, then the fee which the Contractor would have been entitled to receive for such task order work or the fee actually paid by the Government for the task order’s performance by another Contractor, whichever is greater, shall be applied toward the Contractor’s minimum ordering guarantee.

8. That in the event that Contractor knowingly withholds the existence of a conflict of interest from the Government, that the Contracting Officer may terminate this Contract at no cost to the Government and any minimum guarantee(s) otherwise applicable to the Contractor will be forfeited; provided, that the foregoing shall be in addition to all other remedies and causes of action which the Government may have against the Contractor, including the suspension and/or debarment of the Contractor.

9. To include this Conflict of Interest clause, including this subparagraph, in all of the Contractor’s subcontracts at all tiers (appropriately modified to preserve the Government’s rights hereunder) which involve the performance of work by subcontractors in support of this Contract.

10. That, in addition to the remedies enumerated above, the Government may terminate this Contract for cause in the event of the Contractor’s breach of any of the above restrictions.

G.4 Compliance with Regulations. The Contractor shall comply with all statutes, regulations, directives, instructions, and references applicable to the conduct of this acquisition as imposed by the Federal Government and the SEC, including, without limitation, those specified or referred to in this contract.

The Contractor and its employees shall become acquainted with and shall comply with the rules and regulations of the SEC’s facilities, including, but not limited to security, controlled access, personnel clearances, and conduct with respect to health and safety at the site, regardless of whether or not title to the facility is vested in the SEC.

G.5 Non-Disclosure Requirements. Required non-disclosure forms are attached and must be completed and returned to the Contracting Officer before starting work under this contract.

G.5.1 Restrictions on Use, Disclosure, and Duplication of Confidential and Non-Public Information.

Confidential and non-public information, for purposes of this clause but is not limited to, all financial, statistical, personnel and/or technical data which is furnished, produced, generated, or otherwise available to the Contractor, during the performance of this contract. Unless otherwise specified, confidential and non-public information shall not be used for purposes other than performance of work under this contract without the prior written consent of the Contracting Officer. The Contractor, and its employees, agents, subcontractors, and subcontractor personnel are restricted from duplicating or disclosing confidential or non-public information, in whole or in part, outside the SEC for purposes other than fulfillment of the requirements set forth in this contract. Any presentation of any confidential or non-public information, or any reports or material derived from confidential or non-public information shall be subject to review of the Contracting Officer prior to publication or dissemination. Any questions about whether information is confidential or non-public shall be referred to the Contracting Officer prior to use disclosure or duplication.

G.6 Background Investigations. DELETE

G.6.1 Pre-Employment Check. The Contractor shall be subject to a complete pre-employment check, which will be completed by the SEC. The pre-employment check shall include a background investigation of each proposed employee under this contract to determine suitability for employment on the basis of qualifications for the job. The Contractor shall submit U.S. Office of Personnel Management (OPM) Standard Form 85P for each prospective employee. OPM Standard Form 85P is available at http://www.opm.gov/forms. The Government reserves the right of final approval for prospective employees. The pre-employment check shall include, but not be limited to the checks identified below. The Contractor shall make its best efforts to provide employees that pass the SEC’s security screening. Failure of employee(s) to pass the security screening is not a justifiable cause for schedule slippages. The SEC is currently revising its security processes and there may be a change to this process by time of award.

G.6.2 Criminal History Check. The SEC may contact local law enforcement authorities and the Federal Bureau of Investigation (FBI) to determine the criminal history of each prospective contract employee.

G.6.3 Credit History Check. Credit history shall evidence the Contract employee to be responsible with credit obligations. A Contract employee receiving an unfavorable credit rating must be approved by the COR prior to acceptance to this Contract. In the event of an unsatisfactory credit rating, the Contractor shall submit an explanation of the circumstances and the employee shall not be assigned to the contract prior to Contracting Officer approval.

G.6.4 Background Checks. Due to the sensitive nature of the information contained in SEC filings and concerns regarding the security and integrity of this information, the SEC may conduct background checks of proposed key personnel in addition to reference checks. It shall be the responsibility of the Contractor throughout the life of this contract to inform the SEC of any changes in its key personnel so that the appropriate background and reference checks may be conducted. The Contractor also agrees to include the substance of this clause in any of its subcontracts.

The Contractor shall conduct a background investigation regarding the criminal record and credit history of all employees who will be assigned to work on the contract. The Contractor shall not assign to work on the contract and shall immediately remove from work on the contract any employee who has been convicted within the past ten years of fraud or any other felony.

Formatted: Strikethrough

The Contractor shall certify to the SEC that a background investigation has been conducted on each employee who is assigned to work on the contract. The Contractor shall conduct follow-up background investigations every twelve months on each employee assigned to the contract, unless the SEC directs otherwise.

G.7 Personnel. The Contractor shall provide skilled personnel required for the effective and efficient performance of this contract. The SEC reserves the right to review all resumes of all personnel assigned to this contract and the results of the background investigations conducted by the Contractor. The SEC has the right to require the removal of any Contractor personnel assigned to this contract, at any time, for any reason.

G.7.1 Key Personnel. The Contractor shall designate specific key personnel who are essential to the successful performance of this contract.

G.7.1.1 Contractor Substitution of Key Personnel. Following award, and throughout the life of this contract, the Contractor shall permit no substitution of key personnel without the written consent of the Contracting Officer, unless such substitutions are necessitated by an individual’s sudden illness, death or termination of employment. In the event that substitution of personnel is desired, the Contractor shall notify the Contracting Officer in writing at least thirty (30) calendar days before any key personnel substitution is made, if possible.

The Contractor shall submit a justification in sufficient detail to permit evaluation of the impact on the contract or its performance, with the resume of the proposed replacement personnel. The Contractor shall obtain the Contracting Officer’s written approval prior to any changes in the contract participation of the personnel named as key personnel. Proposed substitute personnel shall have experience and education at least substantially equal to those of the personnel being replaced. Requests for substitutions shall provide a detailed explanation of the circumstances necessitating such changes, a resume for each proposed substitute, and any other information as requested by the Contracting Officer. The Contracting Officer will evaluate such requests and promptly notify the Contractor of approval or disapproval thereof.

G.7.2 Contractor Responsibilities/Standards of Conduct (Nov 2012). The Contractor shall furnish all managerial, supervisory, and personnel to successfully, effectively, and efficiently accomplish all work required by this contract. Contractor personnel are employees of the Contractor and under its administrative control and supervision. Contractor personnel are not employees of the Government.

The Contractor shall select, supervise and exercise control and direction over its employees under this contract. The SEC will not exercise any supervision over the Contractor’s employees, but may, in coordination with Contractor management, provide sufficient direction to contractor personnel to ensure that the purposes of the contract are met and the government’s interests are protected.

Contractor shall be responsible for:

• Approving time cards of its employees;

• Approving leave requests of its employees;

• Performing performance evaluations of its employees;

• Making hiring and firing decisions for its employees;

• Informing its employees that they are not employees of the SEC and have not received an appointment in the federal service;

• Informing its employees that they are not to accept direction from employees of the SEC beyond that required to accomplish the purposes of the Contract;

• Informing its employees that the Contractor is responsible for approval of their time cards, leave requests, performance evaluations, and for hiring and firing decisions;

• Directing their employees to identify themselves in their communications (and in their work product as appropriate) as contractors rather than SEC or Federal employees, and ensuring that they in fact do so;

• Directing their employees to display their distinguishing badges or other visible identification of their status as contractors at meetings with government or outside personnel; and

• Considering during their performance of the contract whether any actions they are taking would limit the ability of an SEC employee to exercise discretion on an inherently governmental function and bring such actions to the attention of the COR.

The Contractor is accountable to the SEC for the actions of its personnel. The Contractor’s employees, when on-site at SEC facilities under this contract, shall only engage in duties specified in the statement of work, task order, or other work statement, and not in other business, or political, charitable, or other duties. The Contractor shall not recruit on SEC premises or otherwise act to disrupt official SEC business. The Contractor shall be responsible when its employees are on-site at the SEC for maintaining satisfactory standards of employee competency, conduct, appearance, and integrity, and shall be responsible for taking such disciplinary action with respect to its employees as may be necessary. Contractor employees are expected to adhere to standards of conduct that reflect credit on themselves, their employer, the SEC, and the Federal Government.

G.8 Section 508 Requirements. Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C.

794d), as amended by the Workforce Investment Act of 1998, all electronic and information technology (EIT) products and services developed, acquired, maintained, and/or used under this contract/order must comply with the Electronic and Information Technology Accessibility Provisions set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in FAR 39.2.The complete text of Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/provisions.htm.

DELETE

All EIT products must comply with the following standards. Descriptions of the standards are viewable at the link Section 508 Standards.

• 36 CFR 1194 Section 21-Software applications and operating systems

• 36 CFR 1194 Section 22-Web-based Intranet and Internet Information and Applications

• 36 CFR 1194 Section 23-Telecommunication Products

• 36 CFR 1194 Section 24-Video and Multimedia Products

• 36 CFR 1194 Section 25-Self-contained, closed products

• 36 CFR 1194 Section 26-Desktop and Portable Computers

• 36 CFR 1194 Section 31-Functional Performance Criteria

• 36 CFR 1194 Section 41-Information, documentation, and support

• Offerors that fail to demonstrate compliance with the above standards, or provide equivalent salient characteristics, may be eliminated from further consideration for award.

• The Contractor shall indicate for each line item in the schedule whether each product or service is compliant or non-compliant with the accessibility standards at 36 CFR 1194 using a Voluntary Product Accessibility Template (VPAT). Further, the quote must indicate where full details of compliance can be found (e.g., vendor’s website or other exact location). The offeror further represents that all EIT products and services that are less than fully compliant have been reviewed and plans to correct are in place.

• Respondents to this solicitation must provide any additional detailed information necessary for determining applicable Section 508 standards conformance, as well as for documenting EIT products and/or services that are incidental to the project, which would constitute an exception to Section 508 requirements. If a vendor claims its products and/or services, including EIT deliverables such as electronic documents and reports, meet applicable Section 508 standards, and it is later determined by the Government – i.e., after award of a contract/order, that products and/or services delivered do not conform to the described accessibility, remediation of the products and/or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.

G.8.1 Electronic and Information Technology (EIT). In accordance with Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), all EIT supplies or services provided under this contract must comply with the applicable accessibility standards issued by the Architectural and Transportation Barriers Compliance Board at 36 CFR Part 1194 (see FAR Subpart 39.2). Electronic and information technology (EIT) is defined at FAR 2.101.

G.8.2 Electronic and Information Technology Accessibility. Each Electronic and Information Technology (EIT) product or service furnished under this contract shall comply with the Electronic and Information Technology Accessibility Standards (36 CFR 1194 Subpart B-D). If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-

Formatted: Font: Not Bold

Formatted: Not Strikethrough

Formatted: Font: Bold, Strikethrough

Formatted: Strikethrough compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:

Cancellation of the contract, delivery or task order, purchase or line item without termination liabilities; or, In the case of custom Electronic and Information Technology (EIT) being developed for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm and the contractor shall reimburse the Government for any expenses incurred thereby.

For every EIT product or service accepted under this contract by the Government that does not comply with 36 CFR 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either the planned refresh cycle of the product or service, or on the contract renewal date, whichever shall occur first.

In the event of a modification(s) to this contract/order, which adds new EIT products and services or revises the type of, or specifications for, products and services the Contractor is to provide, including EIT deliverables such as electronic documents and reports, the Contracting Officer may require that the Contractor provide an update of information provided in the solicitation to identify EIT compliance. Under any maintenance agreement, Contractor agrees to maintain compliance with Section 508 of the Rehabilitation Act of 1973 for all hardware/software.

G.9 Personally Identifiable Information (PII). A Contractor that designs, develops, or operates a system of records on individuals, or otherwise collects or has access to personally identifiable information (PII) in the performance of this contract shall, prior to taking such action, comply with the following requirements:

(a) The Contractor shall have established policies and procedures in place to safeguard SEC PII. The policies and procedures shall provide the Contractor’s processes for identifying, assessing and mitigating privacy risks associated with PII. The policies and procedures shall also cover training of employees on their roles and responsibilities for safeguarding SEC PII and incident management of suspected or confirmed loss of SEC PII in accordance with OMB’s Recommendations for Identity Theft Related Data Breach Notification, September 20, 2006, and OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007.

(b) The Contractor shall also ensure that all processes, procedures and equipment associated with PII comply with all laws, regulations, and security mandates as defined by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-61 Revision 1 and are aligned with the incident categories and timelines referenced in Table J-1 of NIST SP 800-61, as well as U.S. government and SEC policies developed to safeguard the confidentially, integrity and availability of SEC data that may contain PII. In support of these requirements, the Contractor shall have:

• policies, procedures, and mechanisms designed to restrict access to SEC data on Contractor, subcontractor, or SEC inter/intra agency partner systems exclusively to authorized personnel;

• policies, procedures, and mechanisms that prevent transmission or disclosure of SEC data to an unauthorized party;

• policies, procedures, and mechanisms that ensure SEC data on portable devices are encrypted using methods compliant with Information Processing Standard 140-2; and

• policies, procedures, and mechanisms that ensure SEC data transmitted across public networks (i.e., the Internet) by the Contractor, or its employees, agents or subcontractors, are protected using encryption compliant with Federal Information Processing Standard 140-2.

(c) The Contractor shall provide quarterly assessments to the SEC demonstrating that the policies, procedures, and mechanisms required by (b) continue to be functional, that the Contractor is compliant with these requirements, and that these requirements are effective.

(d) The Contractor shall provide a copy of its privacy policies to the Contracting Officer. The Contractor shall also provide a copy of the policies and procedures (or otherwise make such policies and procedures available) to all of its employees, agents, and subcontractors assigned to perform the requirements set forth in this contract.

(e) The Contractor shall ensure that those individuals adhere to the Contractor’s policies and procedures relating to PII and to SEC-prescribed policies and procedures for the safe handling of SEC PII, including privacy and security training requirements and privacy incident management.

(f) The Contractor’s employees, agents, and subcontractors shall immediately alert the SEC of any event, including the suspected or confirmed loss of SEC PII, that could potentially affect the privacy rights of individuals or which violates any federal law, regulation, mandate or requirement as defined in NIST 800-122 by contacting the SEC Information Systems Security point of contact and the SEC Incident Response Team at cops@sec.gov.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .