Attachment_C_-_SOW.pdf

PDF 349 KB Posted

Attached to
Trustee/401a/Record Keeping Federal contract opportunity
Solicitation number
SECHQ115R0003
Issued by
Securities and Exchange Commission

About this file

SOW

View the file

Other files for this federal contract opportunity

Other files attached to Trustee/401a/Record Keeping, newest first.
File Type Posted
SF_30.pdf PDF
Attachment_H-_Mandatory_Training_for_Contactor_Personnel.pdf PDF
Attachment_F_-_NDA.pdf PDF
Attachment_D_-_REVISED_Pricing_Schedule_Final.pdf PDF
Attachment_G_-_Past_Performance.pdf PDF
Attachment_E_-_SEC's_Clauses.pdf PDF
Attachment_B-_Amended_Combined_Synopsis_Solicitation.pdf PDF
Amendment_00007.pdf PDF
Attachment_C_-_SOW_Amendment__000006.pdf PDF
Amendment_00006.pdf PDF
Attachment_B-_Combined_Synopsis_Solicitation.pdf PDF
Amendment_00005.pdf PDF
Attachment_C_-_REVISED_SOW_Amendment__000004.pdf PDF
Amendment_00004.pdf PDF
Amendment_00003.pdf PDF
Amendment_0002.pdf PDF
Amendment_000001.pdf PDF
Attachment_F_-_NDA.pdf PDF
Attachment_B-_Combined_Synopsis_Solicitation.pdf PDF
Attachment_E_-_SEC's_Clauses.pdf PDF
Attachment_A_-_SF1449.pdf PDF
Attachment_C_-_SOW.pdf PDF
Attachment_D_-Pricing_Schedule_401a.docx DOCX document
Show all 23

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Supplemental Retirement Program (SRP) Attachment C

U.S. Securities and Exchange Commission

OHR – Office of Human Resources Supplemental Retirement Program (SRP) Trustee, Custodian, and Recordkeeper Services

Statement of Work

Table of Contents

1.0 SCOPE……………………………………………………………..………………………………………………….…………………3

2.0 BACKGROUND…………………………………………………………….………………………………………………………..…56

3.0 BUSINESS REQUIREMENTS…………………………………………….……………………………………………………..…65

4.0 FEDERAL REQUIREMENTS & SEC REGULATIONS………..………………………………………….………………108

5.0 RISK MANAGEMENT………………………………….…………………..……………………………………..……………..…113

6.0 PACKAGING AND MARKING………………………….………………………………………………….….……………….113

7.0 INSPECTION AND ACCEPTANCE…..………………..……………………………………………………………………..…124

8.0 DELIVERIES OR PERFORMANCE…………………………..……….……………………………………………………….142

9.0 SPECIAL CONTRACT REQUIREMENTS….……………..……..………………..………………………………………..1315

10.0 TYPE OF CONTRACTRECOGNIZED

HOLIDAYS………..………………………………………………………………………..…………………………..2630

11.0 RECOGNIZED

HOLIDAYSACRONYMS………………….………………………………………………………………………..……………………………30.2

12.0 PLACE OF PERFORMANCEGENERAL

INFORMATION..………….……………………………………………………….………………………………2630

13.0 GENERAL INFORMATION……………………………………………..…………………………………………………….26

134.0 LANGUAGE REQUIREMENT & DRESS CODE…………………………………………….……………….………….2831

15.0 ACRONYMS……………………………………………………………………………….……….……………………….………28

1.0 Scope

The U.S. Securities and Exchange Commission ("SEC") is searching for a contractor that will provide Trustee, Custodian, and Recordkeeping services for eligible SEC employees in a new defined contribution program that will comply with Section 401(a) of the Internal Revenue Code (referred to herein as the “Plan” or as the “Supplemental Retirement Plan”). Ideally, one contractor will provide a single solution that encompasses all three aspects of administering the Plan; however, to the extent administratively feasible (as determined by the SEC), contractors may partner to provide the requested services. Both teaming and subcontracting are permissible under this RFP. Contractors who choose to subcontract or team must have those arrangements in place prior to responding to this solicitation. If subcontracting is proposed, all labor and materials proposed must be contained within the prime contractor’s contract. Furthermore, the prime contractor must disclose to the Government’s Contracting Officer (CO) a copy of the subcontract pricing, terms and conditions, or subcontracting agreement. The Government will evaluate the acceptability of any teaming or subcontracting arrangement as part of its evaluation of price. Failure to provide complete supporting documentation may result in no further consideration of the Offeror’s offer. In this solicitation, the term “contractor” refers to each separate entity that proposes to partner together to fulfill the SEC’s requirements.

The contractor must not be directly regulated by the SEC, but a contractor will not be disqualified solely because it (or one or more partners) is part of a corporate structure that includes one or more entities that are directly regulated by the SEC. The contractor selected to serve as Custodian must be an entity that is directly regulated by the Office of the Comptroller of the Currency or the National Credit Union Administration. The contractor must be fully insured against any liability it may incur as a result of administering the Plan.

The Plan will hold only employer contributions. Plan participants will not be allowed to direct investments; all investment decisions will be made by the SEC. The Plan’s objective will be to safeguard the principal and any increases due to interest accumulation. The Plan’s objective will not include maximizing return on the principal. The SEC anticipates that the Plan will direct that all assets be invested in a business savings-type account initially, in a manner that will qualify for “pass-through” FDIC insurance as a retirement plan. The SEC may consider moving some of the assets into CDs or Treasury securities or some other secure vehicle at a later date. If the contractor also offers a managed mutual fund solution comprised solely of broad fund classes (not, for example, sector or other limited funds), and employs advisers that are not directly regulated by the SEC who could advise the SEC with regard to its investment options in that product, it should include detailed information of those services (including how and by whom the advisers are regulated) in its response.

If the contractor has prototype 401(a) Plan documents, it should provide a copy in its response to this solicitation.

The contractor will be responsible for:

As Trustee:

• Serve as the Plan Trustee in accordance with the requirements of Section 401(a) of the

Internal Revenue Code.

• Keep the Plan assets in trust (fiduciary responsibility).

• Provide advisory services to the extent necessary for the SEC to appropriately direct the

Trustee to manage the Plan’s assets.

• Maintain auditable records of all Plan assets and submit to periodic audits as required by law, including as required to enable the SEC to respond to inquiries by, e.g., Congress, the General Accountability Office, the Internal Revenue Service, etc.

As Custodian:

• Receive plan assets bi-weekly via electronic wire transfers from the SEC’s payroll provider (currently the Department of the Interior/National Business Center

(DOI/NBC)).

• Accept discretionary payments the SEC may choose to make, whether through the SEC’s payroll provider or directly from the SEC.

• Follow instructions from the Recordkeeper and the Trustee regarding withdrawals and distributions, and satisfy those instructions in the form of a check, wire transfer, direct rollover, or as otherwise requested.

• Provide reconciliation reports on a monthly basis.

• Separately account for any amounts forfeited by nonvested participants; and

• Notify the SEC any time that balance approaches $250,000 (or the then-applicable

FDIC insurance limit).

As Recordkeeper:

• Receive bi-weekly census data from the SEC’s payroll provider, currently DOI/NBC.

• Process all relevant paperwork (including associated tax forms) for new and departing participants and (if permitted by the Plan) in-service withdrawals.

• Create and maintain individual participant records containing all pertinent financial data (e.g., account balance, bi-weekly deposits, withdrawals, allocations of interest or other earnings on the omnibus trust account, vested amounts, non-vested amounts). This information must be sufficient to meet the FDIC’s “pass-through” insurance rules for retirement plans.

• Provide a secure web-based platform for participants to manage and verify all aspects of their individual account, including the ability to enroll, make withdrawal requests (as permitted by law or by the Plan), view bi-weekly deposits, view amounts credited to their account as share of interest or other earnings on the omnibus trust account, view amounts deducted from their account as share of costs, view amounts vested and amounts not vested, view total individual participant balance, view statements, and submit account inquiries.

• Provide call center services with hours that allow participants in any continental U.S.

time zone reasonable access to those services, including enrollment support, employee support for inquiries, dispute management, and escalation to SEC-OHR.

• Provide participants with an account statement at least annually, and provide participants the option to receive any such statement(s) electronically or in hard copy.

• Direct the Custodian to make required or permitted withdrawals, distributions, or rollovers;

• Submit to periodic audits of all Plan records and documentation as required by law or upon request by the Trustee or the SEC;

• The contractor must provide all services in a secure web-based environment that is Section 508 Compliant.

• Ensure compliance with applicable IRS benefit limitations and (as needed) correct plan errors, and ensure corrections are properly recorded with the IRS and other appropriate governing entities.

The contractor will not make any decisions as to employee eligibility, contribution amounts, distributions, or disputes. Authorized Federal employees from the SEC retain all responsibility for making determinations as to eligibility, contribution amounts, distributions, and resolution of disputes.

The SEC estimates that there will be approximately 3300 participants initially, with an annual estimated net increase of 400 participants per year. The SEC estimates that the Plan assets will be approximately $14 million in 2015, with an estimated annual net increase in holdings of approximately $7 million during the first two years of the Plan. The net increase in holdings after the first two years will depend on whether the Plan allows participants to make in-service withdrawals. The initial plan assets will be 100% vested, but new investments may be subject to a vesting period. The SEC estimates that the number of withdrawals during the first two years of the Plan will be fewer than 400 per year. The number of withdrawals after the first two years will depend on whether the Plan allows participants to make in-service withdrawals. The contractor should identify any limitations on the number of transactions it is able to process per year.

The Plan will be drafted by the SEC’s outside counsel. A Summary Plan Description (SPD) will be made available, at least electronically, to SEC employees. The contractor will work with SEC-OHR to develop informational materials for electronic and hardcopy distribution to SEC employees, and may use the SPD in that process. The contractor may be required to provide annual updates to informational materials.

The contractor will be responsible for ensuring that all such materials are Section 508-compliant and transmitted to the SEC electronically in a format that is 508-compliant and easily transferrable to the SEC’s web environment.

The contractor’s recordkeeping solution will go through the SEC information technology security assessment process. A detailed description of the process is in section 4.3.3 Security Assessment.

The contractor’s expertise must include:

• Understanding contribution and matching principles of the federal government’s Thrift Savings Plan program;

• Understanding governmental or large company payroll operations and transmittal of file data

• Service model that provides a high quality and transparent participant experience; efficient and high-quality plan sponsor experience and consistent plan sponsor reporting mechanisms;

• Reliability and an ongoing commitment to quality and technology;

• High level of data integrity to ensure maximum security of Personally Identifiable Information;

• and

• Significant understanding of qualified defined contribution plans, plan features, and provisions of law.

2. Background

The mission of the SEC is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation. The SEC oversees the key participants in the securities industry, including securities exchanges, securities brokers and dealers, and investment advisors.

As part of the SEC’s compensation model, it is establishing a supplemental retirement program in addition to standard federal retirement programs such as Federal Employees Retirement System (FERS), the Civil Service Retirement System (CSRS), and the Thrift Savings Plan (TSP) for eligible employees. This supplemental retirement plan will have the potential to include all of the SEC’s 4000+ employees, who are located in the Washington, DC headquarters office as well as all regional offices throughout the US.

Travel to the SEC’s headquarters in Washington, DC may be required, for familiarization and design of financial reports to support the Agency’s reporting for the supplemental retirement program.

3. Business Requirements

3.1 - The contractor will provide trustee, custodian and recordkeeping services for SEC’s supplemental retirement program. Trust and custodial services should safeguard assets and meet the Plan’s accounting, financial reporting, and internal control requirements. The contractor will also provide recordkeeping services, through a system that is configurable and scalable.

The SEC will develop the Supplemental Retirement Plan rules and related requirements. Such rules and requirements will, among other things, provide for strict controls to prevent contractor’s discretion to make entitlement determinations, calculate distribution amounts, or resolve disputes. An audit of contractor actions will be within the scope of responsibilities of the SEC. The rules and requirements will be provided to the contractor before work begins. The contractor must understand the SEC

Supplemental Retirement Plan design and rules, data elements, accounting, financial, and auditing requirements. Tasks identified under each area of responsibility (e.g., Trustee, Custodian, Recordkeeper) below will be performed by the contractor.

As Trustee:

a. Serve as the Plan Trustee in accordance with the requirements of Section 401(a) of the

Internal Revenue Code.

b. Keep the Plan assets in trust (fiduciary responsibility).

c. Provide advisory services to the extent necessary for the SEC to appropriately direct the

Trustee to manage the Plan’s assets.

d. Maintain auditable records of all Plan assets and submit to periodic audits as required by law, including as required to enable the SEC to respond to inquiries by, e.g., Congress, the General Accountability Office, the Internal Revenue Service, etc.

As Custodian:

a. Receive plan assets bi-weekly via electronic wire transfers from the SEC’s payroll provider

(currently the Department of the Interior/National Business Center (DOI/NBC)).Accept discretionary payments the SEC may choose to make, whether through the SEC’s payroll provider or directly from the SEC.

b. Follow instructions from the Recordkeeper and the Trustee regarding withdrawals and distributions, and satisfy those instructions in the form of a check, wire transfer, direct rollover, or as otherwise requested.

c. Provide reconciliation reports on a monthly basis.

d. Separately account for any amounts forfeited by nonvested participants.

e. Notify the SEC any time that balance approaches $250,000 (or the then-applicable FDIC insurance limit).

3.2 -The contractor will provide a non-developmental recordkeeping system that is configurable and scalable to meet the needs of the SEC’s Supplemental Retirement Plan. Electronic platforms (front end and back end) similar to those used by financial institutions, the Federal Thrift Savings Plan (www.tsp.gov), and 401(k) providers is an acceptable solution. The platform will be hosted by the contractor, not the SEC. The deployment date for the system is scheduled for August 2015. The SEC will request a presentation of the solution as part of the evaluation process. Tasks identified below will be performed by the contractor. Deliverables associated with these tasks are identified in the Schedule of Deliverables, paragraph 8.3.

a. Accept bi-weekly census data from SEC’s payroll provider, currently the Department of Interior/National Business Center (DOI/NBC);

b. Create and maintain individual participant records containing all pertinent financial data (e.g., account balance, bi-weekly deposits, withdrawals, allocations of interest or other earnings on the omnibus trust account, vested amounts, non-vested amounts);

c. Provide a secure web-based platform for participants to manage and verify all aspects of their individual account, including the ability to enroll, make withdrawal requests, view bi-weekly deposits, view amounts credited to their account as share of interest or other earnings on the omnibus trust account, view amounts deducted from their account as share of costs, view amounts vested and amounts not vested, view total individual participant balance, view statements, and submit account inquiries. This information must be sufficient to meet the FDIC’s “pass-through” insurance rules for retirement plans;

d. Create an account for each newly eligible for participate; maintain all pertinent financial data for that account, obtain enrollment and beneficiary information insofar as possible;

e. In conjunction with SEC-OHR, create informational materials describing the Plan in easy-to-understand terms, including any options for withdrawals, limitations on participation, vesting requirements, FAQs, etc. for distribution and use by SEC employees;

f. Create standard forms for use by SEC employees (e.g., beneficiary identification or change, requests for withdrawal or rollover, declarations, etc.);

g. Receive and maintain beneficiary forms and other declarations/directives for each participant;

h. Provide management reports, including bi-weekly reconciliations of account balances;

i. Reconcile account activities with the Trustee and, if different, the Custodian;

j. Process requests for withdrawals (i.e., confirm withdrawal is allowable under the Plan, send instructions to Trustee and Custodian for delivery of payment to the withdrawing participant, timely prepare and submit any tax forms necessary to report withdrawal, and any other required recordkeeping or paperwork);

k. Provide the SEC any documentation necessary or helpful to support DOL and IRS filings and compliance requirements;

l. Monitor combined employer and employee deferral limits and develop safeguards to ensure no participant exceeds applicable tax deferral limits, and develop a written plan for resolving any unintentional noncompliance with tax laws, rules, or regulations;

m. Provide termination notices to former employees or those who are no longer eligible to receive agency contributions;

n. Provide call center services with hours that allow participants in any continental U.S. time zone reasonable access to those services, including enrollment support, employee support for inquiries, case management and escalation; (Reference 8.5 of the SOW)

o. Provide participants with an account statement at least annually, and provide participants the option to receive any such statement(s) electronically or in hard copy;

p. Provide the SEC with a data file, on an annual basis, of all participant records by each individual, reflecting bi-weekly contributions; all disbursements, interest applied, fees assessed and year end account status for the plan year. This file must be provided electronically within 30 days of the end of each plan year; and

q. Provide all services in a secure web-based environment.

3.2.1 – Informational Materials –

• Create informational materials describing the Plan in easy-to-understand terms, including any options for withdrawals, limitations on participation, vesting requirements, FAQs, etc. for distribution and use by SEC employees. These materials will be narrative and include graphics necessary to convey highlights and other pertinent facts and instructions of the Plan. The document length could be up to six double sided 8 1/2 by 11 pages;

• Create standard forms for use by SEC employees (e.g., beneficiary identification or change, requests for withdrawal or rollover, declarations, etc.). Forms should be fillable, replicable from screen to print and to the greatest extent allowable accept electronic signatures; and

• At least annually or more frequently, all forms and informational materials will be reviewed and an assessment as to revisions will be made. All documents should be 508 compliant and be made available electronically.

3.3 - The contractor will not make any decisions as to employee eligibility, contribution amounts, distributions, or disputes. Authorized Federal employees from the SEC retain all responsibility for making determinations as to eligibility, contribution amounts, distributions, and resolution of disputes.

3.4 - The contractor will be responsible for ensuring compliance with applicable IRS maximum elective deferral limits, annual addition limits, and any other applicable laws and regulations governing retirement plans. The contractor will be responsible for correcting plan errors and ensure corrections are properly recorded with the IRS and other appropriate governing entities.

3.5 – The Plan will cover only Federal government employees and as such the Plan is not subject to ERISA. However, the contractor shall be capable of delivering financial disclosures similar to those required when a plan is subject to ERISA as required by the Department of Labor, IRS or other regulatory concerns. These deliverables should be provided at the intervals prescribed by applicable law.

3.6 – The contractor must respond to telephone and e-mail inquiries by SEC employees (participants) and representatives (SEC plan administrators)and return calls/messages within one (1) business day.

3.7 - Travel to the SEC’s headquarters in Washington, DC may be required, for familiarization and design of financial reports to support the Agency’s reporting for the supplemental retirement program. Once the Plan is operational, periodic travel may be required to SEC’s headquarters to confer on matters pertaining to governance.

3.8- The contractor must ensure privacy and security of all data, maintaining the Commission’s standards for the handling of sensitive data.

Safeguarding of Information/Maintain Privacy and Security Note the following:

a) Security Requirement for Contract Staff: All individuals working on the effort must have a Moderate Risk Public Trust (MRPT) determination from the Agency to facilitate the protection of sensitive account data.

b) Incident Reporting: Notify the COR of any breach of security. Security incidents must be reported and addressed immediately, so as to contain the incident, establish countermeasures to mitigate the impact of the incident, and recover from it. The party discovering the incident in accordance with its procedures will report security incidents.

c) Security Parameters: Specify security parameters used to exchange information with the Agency, including, but not limited to, encryption being used during transport; whether the data (including passwords) is encrypted in storage; type of connection; etc.

4.0 Federal Requirements & SEC Regulations

4.1 Federal Requirements. The following is a sample list of federal requirements consisting of laws, policies, standards and guidance required for information protection. The contractor will be subject to the same information protection requirements as the SEC under the E-Government Act of 2002. The list that follows is not all-inclusive and the contractor must follow the same requirements as the Commission.

• Office of Management and Budget (OMB) Circular A-11, Revised, “Preparation, Submission and Execution of the Budget” (July 2003)

• OMB Circular A-130, Revised, “Management of Federal Information Resources” (November 2000)

• OMB Federal Enterprise Architecture Program Management Office (FEAPMO) Reference Models and Circular A-11 Guidance. www.feapmo.gov.

• Privacy Act of 1974, Public Law 93-579 (5 U.S.C. 552a)

• The E-Government Act of 2002, Public Law 107-347

• Office of Management and Budget (OMB) Memorandum M-12-20, FY 2012 Reporting

Instructions for the Federal Information Security Management Act and Agency Privacy Management

• OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions 1 of the E- Government Act of 2002, September 30,2003

• Federal Information Processing Standard (FIPS) Publication (PUB) 201, Personal Identity Verification (PIV) of Federal Employees and Contractors, March 2006

• FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006

• FIPS PUB 197, Advanced Encryption Standard, November 2001

Formatted: Left http://www.usdoj.gov/opcl/privstat.htm http://www.whitehouse.gov/omb/memoranda/m03-22.html

• National Institute for Standards and Technology (NIST), Special Publication (SP) 800-122, Guide for Protecting the Confidentiality of Personally Identifiable Information (PII), April 2010

• NIST SP 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010

• NIST SP 800-115, Technical Guide to Information Security Testing and Assessment Sept 2008

• NIST SP 800-100, Information Security Handbook: A Guide for Managers, Oct 2006

• NIST SP 800-95, Guide to Secure Web Services, Aug 2007

• NIST SP 800-92, Guide to Computer Security Log Management, Sep 2006

• NIST SP 800-88, Guidelines for Media Sanitization, Sep 2006

• NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide, August 2012

• NIST SP 800-53 Rev. 3, Recommended Security Controls for Federal Information Systems and

Organizations, Aug 2009

• NIST SP 800-53A, Revision 1, Guide for Assessing the Security Controls in Federal Information

Systems, June 2010

• NIST SP 800-44 Version 2, Guidelines on Securing Public Web Servers, Sep 2007

• NIST SP 800-30, Revision 1, Guide for Conducting Risk Assessments, September 2012

• NIST SP 800-70, Revision 2, National Checklist Program for IT Products: Guidelines for Checklist

Users and Developers, February 2011

4.2 SEC Regulations

• Information Technology Security Program, SECR 24-2, approved December 8, 1998

• IT Security Program Technical Bulletin: Identification, Authentication and Passwords, SECR 24-

2.1, April 4, 2001

• Safeguarding Non-Public Information, SECR 23-2A, approved January 21, 2000

• Use of SEC Office Equipment SECR 24-4.3, approved 03/08/2002

• Use of Personal Digital Assistant (PDA) Devices SECR 24-5.2, approved 11/02/2002

• Enterprise Architecture SECR 24-1.6, approved 11/02/2002

• Certification and Accreditation SECR 24-2.4, approved 07/18/2002

• Network Security SECR 24-2-7, approved 09/11/2002

• Electronic Mail SECR 5-10, approved 05/20/1996

• Enterprise Backup of Electronic Data SECR 24-2.6

• Virus and Malicious Software Detection and Prevention SECR 24-2.2

• Use of Internet Browsers and Access to the World Wide Web SECR24-3, approved 12/30/1998

• Information Technology Security Program, SECR 24-04, approved 10/4/2005

• Information Collection Program, SECR 24-09, approved 07/29/2009

4.3 Security Requirements. The contractor must meet all the requirements listed below.

4.3.1 Requirements Management. The Contractor will provide all necessary personnel, administrative, financial, and managerial resources necessary to perform all tasks described in this Statement of Work (SOW).

4.3.2 Security Issue Review. The Contractor must remediate problems identified during security testing. All significant issues (typically those rated as HIGH and often those rated as MEDIUM) should be resolved before the system/interface or connectivity is allowed to go into production. The Contractor must resolve as many security audit-related Plan of Action and Milestones (POA&M) items as possible and within a reasonable timeframe. The Contractor shall document the resolution and provide http://opc-ad-mossfe1/sites/ofa/irm/policy/SECR/SECR24-09_Information_Collection_Program.doc supporting evidence of changes. The Contractor shall schedule a conference meeting with the COR, OIT Security Group staff, and relevant SEC staff to review the state of the POA&M resolutions. The Contractor shall provide the SEC with the number and description of resolved POA&M items identified in the security review.

4.3.3 Security Assessment. OIT Security Team performs Security Assessment and Authorization (SA&A) for a product to be deployed. This process is designed to allow the SEC to identify any risks associated with the system and either mitigate them or formally accept any residual risk. This requirement is based on the NIST 800 family of documents and includes:

• Enumeration - activity aimed at identifying devices and components and cross-referencing with provided inventory lists;

• Vulnerability Scanning - performs network-based vulnerability assessment of customer’s servers, workstations, and any other network device or appliance in scope. The assessment will identify vulnerabilities associated with network services, operating systems, and devices that are un-patched or have out-of-date software security patches;

• Penetration Testing - attempts to exploit weaknesses identified from vulnerability scanning to verify legitimate findings, eliminate false-positives, and determine the extent of the vulnerability and potential remediation steps that may be taken; and

• Functional Testing - Perform specific tests, examinations, and inspections against NIST 800-53 controls not tested by the other activities.

The Contractor shall provide the Security Team with: (1) a system demonstration; (2) test user IDs; (3) Access to the system; (4) System Security Plan (SSP); and (5) additional documents as required under the NIST 800 series for Security Assessment & Authorization; 508 compliance information. The Contractor must provide ongoing support to update the required SA&A documentation. The OIT Security Team provides the test reports.

4.4 Project Management

4.4.1 Project Coordination. The Contractor shall coordinate with the COR and/or existing SEC Program/Project Managers shall provide regular project plan and schedule updates. It is expected that the Contractor Senior/ Technical Lead will drive the day-to-day aspects of the project for the Contractor and provide regular and appropriate updates to the COR and/or existing Program/Project Managers.

4.4.2 Project Status Reports. The Contractor must prepare and deliver to the COR periodic formal Project Status Reports and more frequent informal written status updates.

4.5 Project Meetings

4.5.1 Kick-Off Meeting. Within one (1) week after the award, the Contractor will participate in a kick-off meeting attended by Key Contractor personnel, the SEC Contracting Officer (CO), the Contracting Officers Representative (COR), and other key SEC personnel to introduce project members and their roles and responsibilities, introduce the SEC “Rules of the Road”, and discuss the requirements of the systems, the project schedule, security requirements, connections and restrictions, at a minimum.

4.5.2 Status Meetings. The Contractor must participate in periodic project status meetings attended by key Contractor personnel, the COR and other key SEC personnel.

4.5.3 Meeting Minutes. The Contractor must provide kick-off and status meeting minutes to the COR for review. The Contractor must work with the COR to resolve any disagreements that may arise and provide the COR with final meeting minutes for review and approval.

4.5.4 Briefings. The Contractor must prepare and deliver quarterly briefings that cover key project accomplishments including milestones met and deliverables. The briefing must address matters that are essential to ensure overall success of the task including funding status, project schedule, and an analysis of the risks that may affect successful task completion. The Contractor must provide the COR with briefing materials for review prior to the presentation. The Contractor must incorporate feedback from COR and must provide the COR with final briefing materials for review and approval.

4.6 Project Plans. The Contractor must develop and document a plan for implementing the project that addresses considerations including, but not limited to:

• Possible business process and associated standards/procedures redesign and definition;

• Business process/system integration;

• Coding, configuration, and customization;

• Coordinated documentation, testing, and schedule;

• Production deployment which includes a back-out plan;

• Training;

• Communications/change management; Transition from manual and paper-based system of records; and

• Methodology for transitioning participant’s records and data (electronic and paper) to SEC at prescribed intervals and upon conclusion of the contract. To include a description of processes used to transition services to a successor provider; and procedures for data disposal and certification of data disposal.

The Contractor must review the implementation plan with the COR and relevant stakeholders. The Contractor must deliver the document to the COR for review; the Contractor must incorporate feedback from the COR and must provide the COR with a final document for review and approval. The approved Project Schedule will become the baseline for the contract. The Contractor shall notify the COR of any deviations or changes to the plan, the reasons for changes, and shall provide the COR with written draft of updates to the plan for review and approval.

5.0 Risk Management The Contractor shall coordinate and assist the COR to develop and maintain a

Risk Registry throughout the lifecycle of the project. The Contractor shall immediately notify the COR of any major risk to the project and provide recommendation on the mitigation of the risk.

6.0 PACKAGING AND MARKING

6.1 Packaging and Marking. Preservation, packaging, packing and marking of all deliverable contract line items must conform to normal commercial packing standards to assure safe delivery at destination.

6.2 Marking. All information submitted to the Contracting Officer or the COR, or their designated point of contact, must clearly indicate the number of the contract for which the information is being submitted.

7.0 INSPECTION AND ACCEPTANCE

7.1 Inspection and Acceptance. Inspection and acceptance of the supplies and/or services to be furnished under this contract will be performed by the COR. The COR will assess performance of Contractor personnel on an ongoing basis, and communicate the results to the Contractor. The COR will not discuss performance concerns with Contractor personnel. Should a problem arise regarding performance or the overall level of service, the contactor shall have no more than three (3) business days in which to correct the problem. This may result in the removal of Contractor personnel from the award.

8.0 DELIVERIES OF PERFORMANCE

8.1 Period of Performance. The period of performance is two (2) years from date of award, with three (3) one-year option periods to follow the base year.

8.1.1 Option Periods. This contract has three (3) one-year option periods. If all options are exercised, the period of performance will not exceed a total of five (5) years six (6) months (the contract may be extended up to six months). If exercised, the period of performance for each successive option will begin the day after the expiration of the previous year and continue for one year.

Exercise of any option requires a modification signed by an SEC Contracting Officer.

8.1.2 Award of an initial contract will not obligate the Government to exercise any contractual option.

Prior to exercising any option, the Government will make a determination that (1) funds are available, (2) the requirement covered by the option fulfills an existing need of the Government, and (3) the exercise of the option is the most advantageous method of fulfilling the Government’s need, price and other factors considered.

8.1.3 Failure to exercise an option will not obligate the Government to pay any charges other than the contract price including exercised options.

8.2 Place of Performance. Services will be performed electronically in a virtual environment, therefore, the contractor must be able to perform services to all SEC employees, who are located throughout the continental US.

8.3 Schedule of Deliverables. The Contractor must prepare and provide deliverables in electronic format to the COR. The COR will review all deliverables and provide comments and/or approvals/disapprovals in a timely manner so as not to adversely impact the project schedule.

Deliverable schedules may include, but will not be limited to, the following:

Section Deliverable Schedule

3. Business Requirements Per approved project schedule

3.2.1 Informational Materials Per approved project schedule

4.3.2 Security Issue Review Per approved project schedule

4.3.3 Security Assessment Per approved project schedule

4.5 Project Meetings Per approved project schedule

4.6 Project Plans Per approved project schedule

5.0 Risk Management Per approved project schedule

9.7 Section 508 Per approved project schedule

8.3.1 Documenting, Inspecting, and Accepting Contract Deliverables. The Contractor must submit all deliverables requiring a transmittal sheet with either the attached Deliverable Transmittal sheet or an alternative transmittal sheet that contains substantially the same information.

8.4 Place of Delivery. The deliverables to be furnished under this contract must be delivered to the following addresses:

U.S. Securities and Exchange Commission Station Place 100 F Street NE Washington, D.C. 20549 Attn: Deidre Robinson

8.5 Hours of Performance. The Contractor must be available during normal business hours on all

Federal Government business days during the term of the contract. This support must occur during normal business hours between 7:00 AM to 7:00 PM. EST, Monday through Friday, excluding Federal holidays and official Federal Government closures in the Metropolitan DC area. However, the SEC may require services outside of regular business hours. Exceptions may be made on a case-by-case basis and must be pre-approved by the Government COR.

9. SPECIAL CONTRACT REQUIREMENTS

9.1 Type of Contract. It is anticipated that this agreement will be a hybrid contract awarded in part on a Firm Fixed Price (FFP) basis and in part on a Time & Materials (TM) basis.

9.2 Security and Privacy Act Matters. The security classification for work performed under this contract is Public Trust. The documents that must be reviewed and produced are non-public and sensitive in nature and must be protected from unauthorized disclosure. Work on this project requires that personnel have access to Privacy Act Information. Personnel must adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations.

9.2.1 Compliance with Security Regulations, Policies and Procedures. The Contractor must be responsible for compliance by its employees with SEC security regulations, policies, and procedures. This includes safekeeping, wearing, and visibility of identification badges. The SEC will issue Contractor identification badges to on-site Contractor personnel, and the badges must be visible at all times while employees are on SEC premises. The Contractor must provide all requested information (the SEC will provide forms to the Contractor at time of award) required to facilitate issuance of identification badges and must conform to applicable regulations concerning the use and possession of the badges. The Contractor will be responsible for ensuring that all identification badges issued to the Contractor employees are returned within forty-eight (48) hours following the completion of the contract, relocation, or termination of an employee and/or request of the Contracting Officer or the COR.

9.2.2 Conflicts of Interest.

(a) General. Subpart 9.5 of the Federal Acquisition Regulation 48 C.F.R. 9.5, prescribes responsibilities, general rules, and procedures for identifying, evaluating, and resolving organization conflicts of interest.

(b) Purpose. The purpose of this clause is to avoid, neutralize, or otherwise mitigate organizational conflicts of interest which might exist related to a Contractor’s performance of work required by this contract. Such conflicts may arise in situations including, but not limited to: a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement in which it has provided assistance in the preparation of the Government’s requirements and specifications; a Contractor’s providing advisory assistance to the Government in a procurement in which the Contractor’s firm or one which the Contractor represents is an actual or potential Offeror; and a Contractor’s participation, as an Offeror or representative of an Offeror, in a procurement where the Contractor has obtained confidential or proprietary information relating to competing Offerors as a result of the Contractor’s work on prior task orders.

(c) Definition. For purposes of this clause, the term “Contractor” means: The Contractor; any of the Contractor’s parents, affiliates or other entities in which the Contractor or such parents or affiliates have a financial interest; successors in interest to the Contractor or any of its parents or affiliates; proposed consultants or subcontractors at any tier; and employees thereof.

(d) Restrictions. The Contractor agrees:

1. To remain ineligible to participate in any capacity (including participating as a prime Contractor, subcontractor, or as the representative of another party) in contracts, subcontracts, or Proposal (whether solicited or unsolicited) that directly relate to the Contractor’s performance of work under this Contract.

2. Prior to beginning work on a task order, to execute such Confidentiality Agreements, Statements of Non-Disclosure or other documents which the Contracting Officer may, in his/her sole discretion, require in order to protect the proprietary nature or confidentiality of information provided by the Government or otherwise received by the Contractor in connection with its work under this Contract.

3. As otherwise provided in this Contract, not to accept any compensation or any other form of payment from a broker, potential lessor, or any source other than the Government for services rendered under this Contract, and to employ aggressive strategies to minimize the Government’s lease costs where the Contractor would entitled by common business practice to receive a real estate commission or any form of payment from a broker, potential lessor, or other party, for work performed under this Contract.

4. To immediately notify the Contracting Officer of any offer of compensation, other form of payment, or thing of value, made by a broker, potential lessor, or any source other than the Government to the Contractor related to services rendered under this Contract, regardless of whether such offer was made during Contractor’s performance of work under a given task order or subsequent to Contractor’s completion of work under such task order.

5. Prior to the acceptance of a task order request, to immediately notify the Contracting Officer of any potential conflict of interest which would prevent or limit the Contractor’s ability to perform the work requested.

6. To immediately notify the Contracting Officer of any conflict of interest discovered during Contractor’s performance of work pursuant to a Government issued task order;

provided that the Contracting Officer shall have the right to impose such restrictions as he/she deems appropriate on Contractor’s performance based on the existence of such a conflict or, if the Contracting Officer determines that such restrictions would not adequately address the conflict of interest at issue, to terminate the Contractor’s performance of work under the task order at no cost to the Government.

7. As otherwise provided in this Contract, that if the Contractor declines to accept a task order request and subsequently participates (either directly or as a representative of another party) in a Government contracting action that was the subject of the task order request, then the fee which the Contractor would have been entitled to receive for such task order work or the fee actually paid by the Government for the task order’s performance by another Contractor, whichever is greater, shall be applied toward the Contractor’s minimum ordering guarantee.

8. That in the event that Contractor knowingly withholds the existence of a conflict of interest from the Government, that the Contracting Officer may terminate this Contract at no cost to the Government and any minimum guarantee(s) otherwise applicable to the Contractor will be forfeited; provided, that the foregoing shall be in addition to all other remedies and causes of action which the Government may have against the Contractor, including the suspension and/or debarment of the Contractor.

9. To include this Conflict of Interest clause, including this subparagraph, in all of the Contractor’s subcontracts at all tiers (appropriately modified to preserve the Government’s rights hereunder) which involve the performance of work by subcontractors in support of this Contract.

10. That, in addition to the remedies enumerated above, the Government may terminate this Contract for cause in the event of the Contractor’s breach of any of the above restrictions.

9.3 Compliance with Regulations. The Contractor must comply with all statutes, regulations, directives, instructions, and references applicable to the conduct of this acquisition as imposed by the Federal Government and the SEC, including, without limitation, those specified or referred to in this contract.

The Contractor and its employees must become acquainted with and comply with the rules and regulations of the SEC’s facilities, including, but not limited to security, controlled access, personnel clearances, and conduct with respect to health and safety at the site, regardless of whether or not title to the facility is vested in the SEC.

9.4 Non-Disclosure Requirements. Required non-disclosure forms are attached and must be completed and returned to the Contracting Officer before starting work under this contract.

9.4.1 Restrictions on Use, Disclosure, and Duplication of Confidential and Non-Public Information.

Confidential and non-public information, for purposes of this clause includes but is not limited to, all financial, statistical, personnel and/or technical data which is furnished, produced, generated, or otherwise available to the Contractor, during the performance of this contract.

Unless otherwise specified, confidential and non-public information must not be used for purposes other than performance of work under this contract without the prior written consent of the Contracting Officer. The Contractor, and its employees, agents, subcontractors, and subcontractor personnel are restricted from duplicating or disclosing confidential or non-public information, in whole or in part, outside the SEC for purposes other than fulfillment of the requirements set forth in this contract. Any presentation of any confidential or non-public information, or any reports or material derived from confidential or non-public information will be subject to review of the Contracting Officer prior to publication or dissemination. Any questions about whether information is confidential or non-public shall be referred to the Contracting Officer prior to use disclosure or duplication.

9.5 Non-Disclosure Agreement for Confidential and Non-Public Information. Rules 3(b)(1) and

3(b)(7) of the SEC's conduct regulation (17 C.F.R. 200.735-3(b)(1) and (7)) expressly prohibit unauthorized disclosure and improper use of confidential or non-public information or documents. The Contractor, and its employees, agents, subcontractors, and subcontractor personnel who will have access to confidential or non-public information or documents in the performance of the contract, agree to be bound by the provisions of rules 3(b)(1) and 3(b)(7) of the SEC's conduct regulation and the terms set forth in the attached non-disclosure agreements (Attachments 1 & 2). The Contractor and all personnel assigned to the contract agree not to divulge to any unauthorized person non-public or confidential information obtained from the SEC in performance of their duties under the contract.

The Contractor and all employees, agents, subcontractors and subcontractor personnel who will have access to confidential or non-public information or documents during the performance of their duties under the contract must execute the attached Non-Disclosure Agreements (Attachments 1 & 2) as applicable and return it to the Contracting Officer before being given access to such information or documents.

Violation of this clause by the Contractor, its employees, agents, subcontractors, or subcontractor personnel may result in default of the contract and/or civil suits and/or criminal prosecution.

9.5.1 SEC Non-Disclosure Agreement. The Contractor must submit to the Contracting Officer a list of its employees, agents, and subcontractors that will be authorized access to SEC information by virtue of performing the requirements set forth in this contract. Each person identified on the list must then sign a non-disclosure agreement (Attachment 1) and submit it to the Contracting Officer before starting work at the SEC. The Contractor will also ensure that all of its employees, agents, and subcontractors assigned to perform the requirements set forth in this contract adhere to the terms of the non-disclosure agreement, protecting all confidential or non-public information. Assignment of staff who has not executed the non-disclosure agreement or failure to adhere to this statement will result in action by the Contracting Officer, as deemed appropriate.

9.6 Background Investigations.

9.6.1 Pre-Employment Check. The Contractor will be subject to a complete pre-employment check, which will be completed by the SEC. The pre-employment check will include a background investigation of each proposed employee under this contract to determine suitability for employment on the basis of qualifications for the job. The Contractor must submit U.S. Office of Personnel Management (OPM) Standard Form 85P for each prospective employee. OPM Standard Form 85P is available at http://www.opm.gov/forms. The Government reserves the right of final approval for prospective employees. The pre-employment check will include, but not be limited to the checks identified below. The Contractor will make its best efforts to provide employees that pass the SEC’s security screening. Failure of employee(s) to pass the security screening is not a justifiable cause for schedule slippages. The SEC is currently revising its security processes and there may be a change to this process by time of award.

9.6.2 Criminal History Check. The SEC may contact local law enforcement authorities and the Federal

Bureau of Investigation (FBI) to determine the criminal history of each…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .