Attachment_C_-_SOW_Amendment__000006.pdf
PDF 206 KB Posted
- Attached to
- Trustee/401a/Record Keeping Federal contract opportunity
- Solicitation number
- SECHQ115R0003
- Issued by
- Securities and Exchange Commission
About this file
Revised Attachment C
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SF_30.pdf | ||
| Attachment_D_-_REVISED_Pricing_Schedule_Final.pdf | ||
| Attachment_G_-_Past_Performance.pdf | ||
| Attachment_F_-_NDA.pdf | ||
| Attachment_E_-_SEC's_Clauses.pdf | ||
| Attachment_B-_Amended_Combined_Synopsis_Solicitation.pdf | ||
| Attachment_H-_Mandatory_Training_for_Contactor_Personnel.pdf | ||
| Attachment_C_-_SOW.pdf | ||
| Amendment_00007.pdf | ||
| Attachment_B-_Combined_Synopsis_Solicitation.pdf | ||
| Amendment_00006.pdf | ||
| Amendment_00005.pdf | ||
| Attachment_C_-_REVISED_SOW_Amendment__000004.pdf | ||
| Amendment_00004.pdf | ||
| Amendment_00003.pdf | ||
| Amendment_0002.pdf | ||
| Amendment_000001.pdf | ||
| Attachment_B-_Combined_Synopsis_Solicitation.pdf | ||
| Attachment_E_-_SEC's_Clauses.pdf | ||
| Attachment_A_-_SF1449.pdf | ||
| Attachment_C_-_SOW.pdf | ||
| Attachment_D_-Pricing_Schedule_401a.docx | DOCX document | |
| Attachment_F_-_NDA.pdf |
Show all 23
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Supplemental Retirement Program (SRP) Attachment C
U.S. Securities and Exchange Commission
OHR – Office of Human Resources Supplemental Retirement Program (SRP) – Trustee and Custodian
REVISED
Statement of Work
Table of Contents
C.1 SCOPE…………………………………….……………………………………………………………………………………………………………………3
C.2 BACKGROUND…………………………………………………………………………………………………………………………………………… 3
C.3 BUSINESS REQUIREMENTS………………………………………………………………………………………………………………………… 3
C.4 FEDERAL REQUIREMENTS & SEC REGULATIONS………….………………………………………………………………………………7
C.5 DOCUMENTATION UPDATES……………………………………………………………………………………………………………………. 10
C.6 RISK MANAGEMENT…………..……………………………………………………………………………………………………………………..10
SECTION D – PACKAGING AND MARKING…..…….…………………………………………………………………………………………….10
SECTION E – INSPECTION AND ACCEPTANCE…..…….………………………………………………………………………………………..10
SECTION F – DELIVERIES OR PERFORMANCE……………………………………………………………………………………………………10
SECTION G – SPECIAL CONTRACT REQUIREMENTS ….……..…….………………………………………………………………………..11
C.1 Scope
The U.S. Securities and Exchange Commission ("SEC") is searching for a vendor that will hold the assets for eligible SEC employees who are enrolled in a new defined contribution retirement plan under Section 401(a) of the Internal Revenue Code (referred to herein as the “Plan” or as the “Supplemental Retirement Plan”). The vendor will act as the Trustee and Custodian for the Plan. The Plan will hold only employer contributions. If the vendor has prototype 401(a) Plan documents, it should provide a copy in its response to this solicitation.
The Plan’s main objective will be to safeguard the principal and any increases thereto due to interest accumulation. The Plan’s objective will not include maximizing return on the principal. The SEC anticipates that the Plan will direct that all assets be invested in a business savings-type account initially, in a manner that will qualify for “pass-through” FDIC insurance as a retirement plan. The SEC may consider moving some of the assets into CDs or Treasury securities or some other secure vehicle at a later date.
The SEC estimates that there will be approximately 3100 participants initially, with an annual estimated net increase of 200 participants per year. The SEC estimates that the Plan assets will be approximately $14 million by early 2015, with an annual estimated net increase in holdings of approximately $7 million. The participants will not be allowed to direct investments. The SEC anticipates that participants will have limited rights to make withdrawals beyond the rights afforded by law, and accordingly estimates that the number of withdrawals will be fewer than 300 per year during the contract period. The initial plan assets will be 100% vested, but new investments may be subject to a vesting period.
Examples of required Trustee services include:
• serving as the Plan Trustee in accordance with the requirements of Section 401(a) of the Internal Revenue Code;
• keeping the Plan assets in trust; and
• maintaining auditable records of all Plan assets and submitting to periodic audits as required by law, including as required to enable the SEC to respond to inquiries by, e.g., Congress, the General Accountability Office, the Internal Revenue Service, etc.
Examples of required Custodian services include:
• receiving plan assets bi-weekly via electronic wire transfers from the SEC’s payroll provider (currently the Department of the Interior);
• following instructions from the Recordkeeper and the Trustee regarding withdrawals and distributions, including the ability to make wire transfers to the Recordkeeper; and1
• providing trust reconciliation reports on a monthly basis• separately accounting for any amounts forfeited by nonvested participants, and notifying the SEC any time that balance approaches $250,000 (or the then-applicable FDIC insurance limit).
In response to this solicitation, the vendor must stipulate any associated fees for acceptance of the bi-weekly wire transfers. In addition, the vendor must have the ability to accept any additional discretionary payments
*Note: A separate RFP will be issued for a Recordkeeper that will closely coordinate with this RFP.
the agency may choose to make, whether through the SEC’s payroll provider or directly from the SEC, and in its response to this solicitation must state the amount of any associated fees (under current rate schedules).
The vendor will not make any decisions as to employee eligibility, contribution amounts, distributions or disputes. Authorized Federal employees from the SEC retain all responsibility for making determinations as to eligibility, contribution amounts, distributions and resolution of disputes. The vendor will not be responsible for directly interacting with Plan participants. Contributions will be subject to the Internal Revenue Service (IRS) maximum elective deferral limits, annual additions limits, and any other applicable laws and regulations governing retirement plans, but the vendor will not be responsible for ensuring compliance with those limits.
The vendor must be an institution that does not fall under the purview of the SEC’s regulatory authority. The vendor must be fully insured by the appropriate regulator (e.g., FDIC, NCUA).
C.2 Background
The mission of the SEC is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation. The SEC oversees the key participants in the securities industry, including securities exchanges, securities brokers and dealers, investment advisors, and mutual funds.
As part of Securities and Exchange Commission’s (SEC’s) compensation model and pursuant to the negotiated agreement with the National Treasury Employees Union (NTEU), the SEC is establishing a supplemental retirement program in addition to standard federal retirement programs such as Federal Employees Retirement System (FERS), the Civil Service Retirement System (CSRS), and the Thrift Savings Plan (TSP) for eligible employees. This supplemental retirement plan will cover nearly all of the SEC’s 4600 employees, who are located in the Washington, DC headquarters office as well as 11 regional offices throughout the US.
C.3 Business Requirements
C.3.1 - The SEC will develop the Supplemental Retirement Plan Rules and related requirements. Such rules and requirements will, among other things, provide for strict controls to prevent vendor’s discretion to make entitlement determinations calculate distribution amounts or resolve disputes. An audit of vendor actions will be within the scope of responsibilities of the SEC. The rules and requirements will be provided to the contractor before work begins. The contractor must develop and understand the SEC Supplemental Retirement Plan design and rules, data elements, accounting, financial, and auditing requirements.
C.3.2 - The contractor shall provide a financial vehicle to meet the Plan’s accounting, financial reporting and internal control requirements. Travel to the SEC’s headquarters in Washington, DC may be required, for familiarization and design of financial reports to support the Agency’s reporting for the supplemental retirement program.
C.3.3 – The contractor shall deliver financial disclosures governing defined contribution plans subject to ERISA as required by the Department of Labor, IRS or other regulatory concerns. These deliverables should be provided at the intervals prescribed by applicable law.
C.3.4 - The contractor shall ensure privacy and security of all data, maintaining the Commission’s standards for the handling of sensitive data.
Note the following: Safeguarding of Information/Maintain Privacy and Security
a) Security Requirements: The Contractor shall have in place adequate safeguards and measures to maintain the privacy and security of SEC customer accounts.
b) Incident Reporting: Notify the COR of any breach of security. Security incidents must be reported and addressed immediately, so as to contain the incident, establish countermeasures to mitigate the impact of the incident, and recover from it. The party discovering the incident in accordance with its procedures will report security incidents.
c) Security Parameters: Specify security parameters used to exchange information with the Agency, including, but not limited to, encryption being used during transport; whether the data (including passwords) is encrypted in storage; type of connection; etc.
C.3.5 – The contractor shall respond to telephone and e-mail inquiries by the SEC representatives and return calls/messages within 24 hours or 1 business day.
C.4 Federal Requirements & SEC Regulations
C.4.1 Federal Requirements. DELETE
C.4.2 SEC Regulations DELETE
C.4.3 Security Requirements DELETE
C.4.3.1 Requirements Management. DELETE
C.4.3.2 Security Issue Review. DELETE
C.4.3.3 Security Assessment. DELETE
C.4.4 Project Management
C.4.4.1 Project Coordination. The Contractor shall coordinate with the COR and SEC Program/Project Managers to provide regular project plan and schedule updates.
C.4.4.2 Project Status Reports. The Contractor shall prepare and deliver to the COR periodic formal Project Status Reports and more frequent informal written status updates.
C.4.5 Project Meetings
C.4.5.1 Kick-Off Meeting. Within one (1) week after the award, the Contractor shall participate in a kick-off meeting attended by Key Contractor personnel, the SEC Contracting Officer (CO), the Contracting Officers Representative (COR), and other key SEC personnel to introduce project members and their roles and responsibilities, introduce the SEC “Rules of the Road”, and discuss the requirements of the systems, the project schedule, security requirements, connections and restrictions, at a minimum.
C.4.5.2 Status Meetings. The Contractor shall participate in periodic project status meetings attended by key Contractor personnel, the COR and other key SEC personnel.
C.4.5.3 Meeting Minutes. The Contractor shall provide kick-off and status meeting minutes to the COR for review. The Contractor shall work with the COR to resolve any disagreements that may arise and provide the COR with final meeting minutes for review and approval.
C.4.5.4 Briefings. The Contractor shall prepare and deliver quarterly briefings that cover key project accomplishments including milestones met and deliverables. The briefing shall address matters that are essential to ensure overall success of the task including funding status, project schedule, and an analysis of the risks that may affect successful task completion. The Contractor shall provide the COR with briefing materials for review prior to the presentation. The Contractor shall incorporate feedback from COR and shall provide the COR with final briefing materials for review and approval.
C.4.6 Project Plans. The Contractor shall develop and document a plan for implementing the project that addresses considerations including, but not limited to:
• Possible business process and associated standards/procedures redesign and definition;
• Business process/system integration;
• Coding, configuration, and customization;
• Coordinated documentation, testing, and schedule;
• Production deployment which includes a back-out plan;
• Training;
• Communications/change management; and
• Transition from manual and paper-based system of records.
The Contractor shall review the implementation plan with the COR and relevant stakeholders. The Contractor shall deliver the document to the COR for review; the Contractor shall incorporate feedback from the COR and shall provide the COR with a final document for review and approval. The approved Project Schedule shall become the baseline for the contract. The Contractor shall notify the COR of any deviations or changes to the plan, the reasons for changes, and shall provide the COR with written draft of updates to the plan for review and approval.
C.5 Risk Management. The Contractor shall coordinate and assist the COR to develop and maintain a Risk Registry throughout the lifecycle of the project. The Contractor shall immediately notify the COR of any major risk to the project and provide recommendation on the mitigation of the risk.
SECTION D - PACKAGING AND MARKING
D.1 Marking. All information submitted to the Contracting Officer or the COR, or their designated point of contact, shall clearly indicate the number of the contract for which the information is being submitted.
SECTION E - INSPECTION AND ACCEPTANCE
E.1 Inspection and Acceptance. Inspection and acceptance of the supplies and/or services to be furnished under this contract will be performed by the COR. The COR will assess performance of Contractor personnel on an ongoing basis, and communicate the results to the Contractor. The COR will not discuss performance concerns with Contractor personnel. Should a problem arise regarding performance or the overall level of service, the contactor shall have no more than three (3) business days in which to correct the problem. This may result in the removal of Contractor personnel from the award.
SECTION F - DELIVERIES OR PERFORMANCE
F.1 Period of Performance. The period of performance is for the Base of two (2) years and three (3) one
(1) year options periods to follow the base year.
F.1.1 Option Periods. This contract has three (3) one-year option periods. If all options are exercised, the period of performance will not exceed a total of five (5) years six (6) months (the contract may be extended up to six months – see Section I – 52.217-8). If exercised, the period of performance for each successive option will begin the day after the expiration of the previous year and continue for one year. Exercise of any option requires a modification signed by an SEC Contracting Officer.
F.1.2 Award of an initial contract will not obligate the Government to exercise any contractual option. Prior to exercising any option, the Government will make a determination that (1) funds are available, (2) the requirement covered by the option fulfills an existing need of the Government, and (3) the exercise of the option is the most advantageous method of fulfilling the Government’s need, price and other factors considered.
F.1.3 Failure to exercise an option shall not obligate the Government to pay any charges other than the contract price including exercised options.
F.2 Place of Performance. The Contractor shall perform development work at the Contractor’s work site location (off-site).
F.3 Schedule of Deliverables. The Contractor shall prepare and provide deliverables in electronic format to the COR. The COR will review all deliverables and provide comments and/or approvals/disapprovals in a timely manner so as not to adversely impact the project schedule. Deliverable schedules may include, but will not be limited to, the following:
Section Deliverable Schedule C.3 Business Requirements Per approved project schedule C.4.4 Project Management Per approved project schedule C.5 Risk Management Per approved project schedule G.9.(c), (d), (f) Personally Identifiable
Information Per approved project schedule
G.10 Disaster Recovery Per approved project plan
F.3.1 Documenting, Inspecting, and Accepting Contract Deliverables. The Contractor shall submit all deliverables requiring a transmittal sheet with either the attached Deliverable Transmittal sheet or an alternative transmittal sheet that contains substantially the same information.
F.4 Place of Delivery. The deliverables to be furnished under this contract shall be delivered to the following addresses:
U.S. Securities and Exchange Commission Station Place 100 F Street NE Washington, D.C. 20549 Attn:Deidre Robinson
F.5 Hours of Performance. The Contractor shall be available during normal business hours on all Federal Government business days during the term of the contract. This support shall occur during normal business hours between 7:00 AM to 7:00 PM. EST, Monday through Friday, excluding Federal holidays and official Federal Government closures in the Metropolitan DC area. However, the SEC may require services outside of regular business hours. Exceptions may be made on a case-by-case basis and must be pre-approved by the Government COR.
SECTION G - SPECIAL CONTRACT REQUIREMENTS
G.1 Type of Contract. It is anticipated that this contract will be awarded on a Firm Fixed Price (FFP) basis.
G.2 Security and Privacy Act Matters. The security classification for work performed under this contract is Public Trust. The documents that shall be reviewed and produced are non-public and sensitive in nature and shall be protected from unauthorized disclosure. Work on this project request that personnel have access to Privacy Act Information. Personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations.
G.2.1 Compliance with Security Regulations, Policies and Procedures. The Contractor shall be responsible for compliance by its employees with SEC security regulations, policies, and procedures. This includes safekeeping, wearing, and visibility of identification badges. The SEC will issue Contractor identification badges to on-site Contractor personnel, and the badges shall be visible at all times while employees are on SEC premises. The Contractor shall provide all requested information (the SEC will provide forms to the Contractor at time of award) required to facilitate issuance of identification badges and shall conform to applicable regulations concerning the use and possession of the badges. The Contractor shall be responsible for ensuring that all identification badges issued to the Contractor employees are returned within forty-eight (48) hours following the completion of the contract, relocation, or termination of an employee and/or request of the Contracting Officer or the COR.
G.3 Conflicts of Interest.
(a) General. Subpart 9.5 of the Federal Acquisition Regulation 48 C.F.R. 9.5, prescribes responsibilities, general rules, and procedures for identifying, evaluating, and resolving organization conflicts of interest.
(b) Purpose. The purpose of this clause is to avoid, neutralize, or otherwise mitigate organizational conflicts of interest which might exist related to a Contractor’s performance of work required by this contract. Such conflicts may arise in situations including, but not limited to: a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement in which it has provided assistance in the preparation of the Government’s requirements and specifications; a Contractor’s providing advisory assistance to the Government in a procurement in which the Contractor’s firm or one which the Contractor represents is an actual or potential Offeror; and a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement where the Contractor has obtained confidential or proprietary information relating to competing Offerors as a result of the Contractor’s work on prior task orders.
(c) Definition. For purposes of this clause, the term “Contractor” means: The Contractor; any of the Contractor’s parents, affiliates or other entities in which the Contractor or such parents or affiliates have a financial interest; successors in interest to the Contractor or any of its parents or affiliates; proposed consultants or subcontractors at any tier; and employees thereof.
(d) Restrictions. The Contractor agrees:
1. To remain ineligible to participate in any capacity (including participating as a prime Contractor, subcontractor, or as the representative of another party) in contracts, subcontracts, or Proposal (whether solicited or unsolicited) that directly relate to the Contractor’s performance of work under this Contract.
2. Prior to beginning work on a task order, to execute such Confidentiality Agreements, Statements of Non-Disclosure or other documents which the Contracting Officer may, in his/her sole discretion, require in order to protect the proprietary nature or confidentiality of information provided by the Government or otherwise received by the Contractor in connection with its work under this Contract.
3. As otherwise provided in this Contract, not to accept any compensation or any other form of payment from a broker, potential lessor, or any source other than the Government for services rendered under this Contract, and to employ aggressive strategies to minimize the Government’s lease costs where the Contractor would entitled by common business practice to receive a real estate commission or any form of payment from a broker, potential lessor, or other party, for work performed under this Contract.
4. To immediately notify the Contracting Officer of any offer of compensation, other form of payment, or thing of value, made by a broker, potential lessor, or any source other than the Government to the Contractor related to services rendered under this Contract, regardless of whether such offer was made during Contractor’s performance of work under a given task order or subsequent to Contractor’s completion of work under such task order.
5. Prior to the acceptance of a task order request, to immediately notify the Contracting Officer of any potential conflict of interest which would prevent or limit the Contractor’s ability to perform the work requested.
6. To immediately notify the Contracting Officer of any conflict of interest discovered during Contractor’s performance of work pursuant to a Government issued task order; provided that the Contracting Officer shall have the right to impose such restrictions as he/she deems appropriate on Contractor’s performance based on the existence of such a conflict or, if the Contracting Officer determines that such restrictions would not adequately address the conflict of interest at issue, to terminate the Contractor’s performance of work under the task order at no cost to the Government.
7. As otherwise provided in this Contract, that if the Contractor declines to accept a task order request and subsequently participates (either directly or as a representative of another party) in a Government contracting action that was the subject of the task order request, then the fee which the Contractor would have been entitled to receive for such task order work or the fee actually paid by the Government for the task order’s performance by another Contractor, whichever is greater, shall be applied toward the Contractor’s minimum ordering guarantee.
8. That in the event that Contractor knowingly withholds the existence of a conflict of interest from the Government, that the Contracting Officer may terminate this Contract at no cost to the Government and any minimum guarantee(s) otherwise applicable to the Contractor will be forfeited; provided, that the foregoing shall be in addition to all other remedies and causes of action which the Government may have against the Contractor, including the suspension and/or debarment of the Contractor.
9. To include this Conflict of Interest clause, including this subparagraph, in all of the Contractor’s subcontracts at all tiers (appropriately modified to preserve the Government’s rights hereunder) which involve the performance of work by subcontractors in support of this Contract.
10. That, in addition to the remedies enumerated above, the Government may terminate this Contract for cause in the event of the Contractor’s breach of any of the above restrictions.
G.4 Compliance with Regulations. The Contractor shall comply with all statutes, regulations, directives, instructions, and references applicable to the conduct of this acquisition as imposed by the Federal Government and the SEC, including, without limitation, those specified or referred to in this contract.
The Contractor and its employees shall become acquainted with and shall comply with the rules and regulations of the SEC’s facilities, including, but not limited to security, controlled access, personnel clearances, and conduct with respect to health and safety at the site, regardless of whether or not title to the facility is vested in the SEC.
G.5 Non-Disclosure Requirements. Required non-disclosure forms are attached and must be completed and returned to the Contracting Officer before starting work under this contract.
G.5.1 Restrictions on Use, Disclosure, and Duplication of Confidential and Non-Public Information.
Confidential and non-public information, for purposes of this clause but is not limited to, all financial, statistical, personnel and/or technical data which is furnished, produced, generated, or otherwise available to the Contractor, during the performance of this contract. Unless otherwise specified, confidential and non-public information shall not be used for purposes other than performance of work under this contract without the prior written consent of the Contracting Officer. The Contractor, and its employees, agents, subcontractors, and subcontractor personnel are restricted from duplicating or disclosing confidential or non-public information, in whole or in part, outside the SEC for purposes other than fulfillment of the requirements set forth in this contract. Any presentation of any confidential or non-public information, or any reports or material derived from confidential or non-public information shall be subject to review of the Contracting Officer prior to publication or dissemination. Any questions about whether information is confidential or non-public shall be referred to the Contracting Officer prior to use disclosure or duplication.
G.6 Background Investigations. DELETE
G.7 Personnel. The Contractor shall provide skilled personnel required for the effective and efficient performance of this contract. The SEC reserves the right to review all resumes of all personnel assigned to this contract and the results of the background investigations conducted by the Contractor. The SEC has the right to require the removal of any Contractor personnel assigned to this contract, at any time, for any reason.
G.7.1 Key Personnel. The Contractor shall designate specific key personnel who are essential to the successful performance of this contract.
G.7.1.1 Contractor Substitution of Key Personnel. Following award, and throughout the life of this contract, the Contractor shall permit no substitution of key personnel without the written consent of the Contracting Officer, unless such substitutions are necessitated by an individual’s sudden illness, death or termination of employment. In the event that substitution of personnel is desired, the Contractor shall notify the Contracting Officer in writing at least thirty (30) calendar days before any key personnel substitution is made, if possible.
The Contractor shall submit a justification in sufficient detail to permit evaluation of the impact on the contract or its performance, with the resume of the proposed replacement personnel. The Contractor shall obtain the Contracting Officer’s written approval prior to any changes in the contract participation of the personnel named as key personnel. Proposed substitute personnel shall have experience and education at least substantially equal to those of the personnel being replaced. Requests for substitutions shall provide a detailed explanation of the circumstances necessitating such changes, a resume for each proposed substitute, and any other information as requested by the Contracting Officer. The Contracting Officer will evaluate such requests and promptly notify the Contractor of approval or disapproval thereof.
G.7.2 Contractor Responsibilities/Standards of Conduct (Nov 2012). The Contractor shall furnish all managerial, supervisory, and personnel to successfully, effectively, and efficiently accomplish all work required by this contract. Contractor personnel are employees of the Contractor and under its administrative control and supervision. Contractor personnel are not employees of the Government.
The Contractor shall select, supervise and exercise control and direction over its employees under this contract. The SEC will not exercise any supervision over the Contractor’s employees, but may, in coordination with Contractor management, provide sufficient direction to contractor personnel to ensure that the purposes of the contract are met and the government’s interests are protected.
The Contractor is accountable to the SEC for the actions of its personnel. The Contractor’s employees, when on-site at SEC facilities under this contract, shall only engage in duties specified in the statement of work, task order, or other work statement, and not in other business, or political, charitable, or other duties. The Contractor shall not recruit on SEC premises or otherwise act to disrupt official SEC business. The Contractor shall be responsible when its employees are on-site at the SEC for maintaining satisfactory standards of employee competency, conduct, appearance, and integrity, and shall be responsible for taking such disciplinary action with respect to its employees as may be necessary. Contractor employees are expected to adhere to standards of conduct that reflect credit on themselves, their employer, the SEC, and the Federal Government.
G.8 Section 508 Requirements. DELETE
G.9 Personally Identifiable Information (PII). A Contractor that designs, develops, or operates a system of records on individuals, or otherwise collects or has access to personally identifiable information (PII) in the performance of this contract shall, prior to taking such action, comply with the following requirements:
(a) The Contractor shall have established policies and procedures in place to safeguard SEC PII. The policies and procedures shall provide the Contractor’s processes for identifying, assessing and mitigating privacy risks associated with PII. The policies and procedures shall also cover training of employees on their roles and responsibilities for safeguarding SEC PII and incident management of suspected or confirmed loss of SEC PII in accordance with OMB’s Recommendations for Identity Theft Related Data Breach Notification, September 20, 2006, and OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007.
(b) The Contractor shall also ensure that all processes, procedures and equipment associated with PII comply with all laws, regulations, and security mandates as defined by National Institute of Standards and Technology
(NIST) Special Publication (SP) 800-61 Revision 1 and are aligned with the incident categories and timelines referenced in Table J-1 of NIST SP 800-61, as well as U.S. government and SEC policies developed to safeguard the confidentially, integrity and availability of SEC data that may contain PII. In support of these requirements, the Contractor shall have:
• policies, procedures, and mechanisms designed to restrict access to SEC data on Contractor, subcontractor, or SEC inter/intra agency partner systems exclusively to authorized personnel;
• policies, procedures, and mechanisms that prevent transmission or disclosure of SEC data to an unauthorized party;
• policies, procedures, and mechanisms that ensure SEC data on portable devices are encrypted using methods compliant with Information Processing Standard 140-2; and
• policies, procedures, and mechanisms that ensure SEC data transmitted across public networks (i.e., the Internet) by the Contractor, or its employees, agents or subcontractors, are protected using encryption compliant with Federal Information Processing Standard 140-2.
(c) The Contractor shall provide quarterly assessments to the SEC demonstrating that the policies, procedures, and mechanisms required by (b) continue to be functional, that the Contractor is compliant with these requirements, and that these requirements are effective.
(d) The Contractor shall provide a copy of its privacy policies to the Contracting Officer. The Contractor shall also provide a copy of the policies and procedures (or otherwise make such policies and procedures available) to all of its employees, agents, and subcontractors assigned to perform the requirements set forth in this contract.
(e) The Contractor shall ensure that those individuals adhere to the Contractor’s policies and procedures relating to PII and to SEC-prescribed policies and procedures for the safe handling of SEC PII, including privacy and security training requirements and privacy incident management.
(f) The Contractor’s employees, agents, and subcontractors shall immediately alert the SEC of any event, including the suspected or confirmed loss of SEC PII, that could potentially affect the privacy rights of individuals or which violates any federal law, regulation, mandate or requirement as defined in NIST 800-122 by contacting the SEC Information Systems Security point of contact and the SEC Incident Response Team at cops@sec.gov. The Contractor shall act in accordance with its policies and procedures in the event of any suspected loss of SEC PII and shall support the SEC’s investigation and resolution of reported incidents as requested by the SEC. For purposes of this Clause, a “suspected loss of PII” shall be interpreted liberally to mean any situation in which the loss of PII or unapproved access to PII is deemed a reasonable possibility.
G.10 Disaster Recovery. Contractor shall create and implement policies, processes and procedures to address the information system security requirements needed for disaster recovery in the event of a disruption of the information service(s) provided. This includes regular review and test of a disaster recovery plan(s) related to recovering the information service(s) provided. Results of all disaster recovery plan tests, exercises or actual events, including but not limited to after-action reports, lessons learned and plan updates will be made available to SEC for review within ten (10) working days of a request by SEC. Furthermore, SEC will be provided a point of contact for disaster recovery planning and exercise for the information service(s) provided.
G.11 Approval of Subcontracts. The Government reserves the right to approve or disapprove any subcontract and any subcontractor selected. Therefore, the Contractor shall obtain the Contracting Officer’s approval of all subcontractors and provide copies of subcontracts for any work required by this contract.
G.12 Travel. There will be no reimbursement for travel expenses incurred within the Washington, DC metropolitan area. In the event that a requirement for travel outside of the Washington DC metropolitan area arises, travel shall be pre-approved by the COR by submitting travel plans with names, dates, locations and estimated expenses at least two weeks in advance of the planned travel. If the place of performance is other than the SEC Headquarters, travel may be allowable and reimbursable subject to the following limitations:
1. Any subsistence allowance (i.e., meals and lodging) is limited by a per diem allowance prescribed by the
Federal per diem schedule -http://www.gsa.gov/Portal/gsa/ep/contentView.do?contentId=17943&contentType=GSA_BASIC;
2. Expenses incurred as a result of travel using a personal automobile are reimbursed as prescribed on the link above;
3. Reimbursement of air and train travel is limited to the most economical rate and reasonably traveled route;
and
4. Each out-of-pocket travel and allowable miscellaneous administrative expense exceeding $75 requires a receipt that is to be attached to the invoice. The Contractor shall submit the required documentation to the COR no later than five (5) business days after completion of each trip. In most cases travel may be one trip per month for 1-2 days; in some circumstances it may be two day trips. If travel is allowable the SEC follows the Federal Travel Regulation regarding use of government rates for travel.
G.13 Government-Furnished Equipment - DELETE
G.14 Common Security Configurations. Common security configurations are published on NIST’s web site http://checklists.nist.gov. NIST’s Computer Security Division website is located at http://csrc.nist.gov. For more information about the security content automation program, see http://nvd.nist.gov/scap.cfm. NIST Special Publication 800-70, ‘Security Configuration Checklist Program for IT Products,’ is located at http://csrc.nist.gov/checklists/SP800-70-DRAFT.pdf.
G.15 Intellectual Property. DELETE
G.16 Contractor Performance Evaluation. Prior to the exercise of an option under the contract/order or at the end of the conclusion of work under the contract/order, the SEC will submit an electronic record of the Contractor’s performance to the Contractors Performance Assessment Retrieval System (CPARS) for processing. Once the evaluation is processed in CPARS, it will be made available in the Past Performance Information Retrieval System (PPIRS) for Government use in evaluating the Contractor’s past performance as part of a source selection action.
No later than 30 days after award, the Contractor shall furnish the Contracting Officer with:
• the name,
• position title,
• phone number, and
• email address of the Contractor’s representative designated to have access to the evaluation for this contract.
The Contracting Officer will ensure that the information regarding the Contractor’s designated representative is provided to the SEC Contractor Performance Assessment Reporting System Focal Point.
The Contractor’s designated representative will have the ability to review, comment, and state whether or not the Contractor agrees with the evaluation and return the evaluation to the Contracting Officer Representative (COR) within 30 calendar days after its receipt.
If the Contractor desires a meeting to discuss the evaluation, it must be requested, in writing, no later than seven calendar days from the receipt of the evaluation. This meeting will be held during the Contractor’s 30-http://www.gsa.gov/Portal/gsa/ep/contentView.do?contentId=17943&contentType=GSA_BASIC http://csrc.nist.gov/checklists/SP800-70-DRAFT.pdf calendar day review period. If after the meeting, the Contractor disagrees with assessment, the Contractor may request that the Office of Acquisition Operations Branch Chief resolve the matter.
It shall be the sole responsibility of the Contractor to inform the Contracting Officer or COR of any changes to the Contractor’s designated representative. Any such changes do not require a modification to the terms and conditions of the contract/order.
G.17 Communicating Non-public or Sensitive Information. When communicating “Non-public or Sensitive information” via email, during the period of this contract, the Contractor shall submit all such communications using Zixmail. ZixMail encrypts outgoing messages, decrypts and validates incoming messages, and authenticates both the sender's and recipient's e-mail identities. The Contractor shall use the following instructions for using Zixmail:*
Login at U.S. Securities and Exchange Commission Secure Email Password Authorization. View message under the “Inbox” tab or create and send new messages from the “Compose” tab. Messages are created and sent similar to a typical e-mail messaging system and include: recipients, CC, subject line, body and attachments.
*Notes: The Contractor must register a new account first at U.S. Securities and Exchange Commission Secure Email Password Authorization prior to reading or sending encrypted messages. The Contractor will be provided with a link to create an account the first time you send them an encrypted message. This link will also be used by the Contractor subsequently to read and compose messages. The Contractor can only send encrypted e-mail messages from the ZixMail portal to SEC employees. All e-mail contents, including attachments, are encrypted when sent using this method.”
G.18 Contractor Time Keeping. DELETE
G.19 Supplies. DELETE
G.20 Intellectual Property Rights. DELETE
G.21 Software Warranty. DELETE
| OHR – Office of Human Resources |
| C.4.3 Security Requirements DELETE |
| C.4.4 Project Management |
| C.4.4.1 Project Coordination. The Contractor shall coordinate with the COR and SEC Program/Project Managers to provide regular project plan and schedule updates. |
| C.4.4.2 Project Status Reports. The Contractor shall prepare and deliver to the COR periodic formal Project Status Reports and more frequent informal written status updates. |
| C.4.5 Project Meetings |
| C.4.5.1 Kick-Off Meeting. Within one (1) week after the award, the Contractor shall participate in a kick-off meeting attended by Key Contractor personnel, the SEC Contracting Officer (CO), the Contracting Officers Representative (COR), and other key... |
| C.4.5.2 Status Meetings. The Contractor shall participate in periodic project status meetings attended by key Contractor personnel, the COR and other key SEC personnel. |
| C.4.5.3 Meeting Minutes. The Contractor shall provide kick-off and status meeting minutes to the COR for review. The Contractor shall work with the COR to resolve any disagreements that may arise and provide the COR with final meeting minutes for rev... |
| C.4.5.4 Briefings. The Contractor shall prepare and deliver quarterly briefings that cover key project accomplishments including milestones met and deliverables. The briefing shall address matters that are essential to ensure overall success of the t... |
| C.4.6 Project Plans. The Contractor shall develop and document a plan for implementing the project that addresses considerations including, but not limited to: |
| F.1 Period of Performance. The period of performance is for the Base of two (2) years and three (3) one (1) year options periods to follow the base year. |
| F.3.1 Documenting, Inspecting, and Accepting Contract Deliverables. The Contractor shall submit all deliverables requiring a transmittal sheet with either the attached Deliverable Transmittal sheet or an alternative transmittal sheet that contains ... |
| G.11 Approval of Subcontracts. The Government reserves the right to approve or disapprove any subcontract and any subcontractor selected. Therefore, the Contractor shall obtain the Contracting Officer’s approval of all subcontractors and provide c... |
| G.14 Common Security Configurations. Common security configurations are published on NIST’s web site http://checklists.nist.gov. NIST’s Computer Security Division website is located at http://csrc.nist.gov. For more information about the security c... |
File details come from the government source that posted it. Updated .