SOW_Handheld Training.pdf

PDF 461 KB Posted

Attached to
Small-Scale, Handheld, and Chemical Identification Equipment Training Federal contract opportunity
Solicitation number
232025(2)
Issued by
Department of Homeland Security Customs and Border Protection

About this file

This is a Statement of Work (SOW) from U.S. Customs and Border Protection (CBP) for Small-Scale, Handheld, and Chemical Identification Equipment Training to support CBP's Non-Intrusive Inspection (NII) Program. The SOW outlines requirements for vendor-led training across multiple handheld devices including Gemini, MX908, TruNarc, Smart Ray Vision, ITVS Videoscopes, Viken HBI, ThruVision TAC16, and Density Meter systems.

The contract will be awarded as a Blanket Purchase Agreement with a base period from 04/30/2025 through 04/29/2026 and four one-year ordering periods through 04/29/2030. Training will be delivered as credits, with each credit covering 16 hours of instruction for varying class sizes (12-40 students depending on course type) at CBP ports of entry and border crossings both CONUS and OCONUS. Key requirements include providing all course materials, training aids, consumables, electronic record keeping of rosters and evaluations, and biweekly dashboard updates. The contractor must maintain vendor-provided email addresses for trainers, who must be vetted bi-annually by CBP. Monthly reports showing training credits used/remaining and scheduled courses are required. All training products and materials become U.S. Government property upon delivery and acceptance.

View the file

Other files for this federal contract opportunity

Other files attached to Small-Scale, Handheld, and Chemical Identification Equipment Training, newest first.
File Type Posted
RFI_Handheld Training.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Department of Homeland Security

U.S. Customs and Border Protection

Statement of Work

For:

U.S. CUSTOMS AND BORDER PROTECTION

NON-INTRUSIVE INSPECTION SYSTEMS

Small-Scale, Handheld, and Chemical Identification Equipment Training

PREPARED BY:

NII PROGRAM MANAGEMENT OFFICE (PMO)

Contents

1 PURPOSE

1.1 Background and Scope

1.2 Objective

1.3 Period of Performance:

1.4 Place of Performance:

1.5 Delivery

1.6 Invoicing

2 Requirements

2.1 Operator Training

2.2 Ownership

2.3 Training Material/Course Development

2.4 Training Execution

2.5 Training Deliverables

3 INFORMATION TECHNOLOGY SECURITY

3.1 Basic Requirements

3.2 Security Authorization

3.3 Encryption Compliance Requirement

3.4 Security Review

3.5 DHS Security Policy Requirement

3.6 Enterprise Security Architecture

3.7 Information Assurance

3.8 Continuous Monitoring

3.9 Access to Unclassified Facilities, Information Technology (IT) Resources, and Sensitive Information

3.10 Personal Identity Verification (PIV) of Contractor Personnel

3.11 PIV Credential Compliance

3.12 CBP Contractor Handling PII Level

3.13 Security Requirements for Unclassified Information Technology Resources

3.14 3052.204-71 CONTRACTOR EMPLOYEE ACCESS (JULY 2023)

3.15 3052.204-72 - SAFEGUARDING OF CONTROLLED UNCLASSIFIED

INFORMATION (JULY 2023)

3.16 INFORMATION TECHNOLOGY SECURITY AWARENESS TRAINING

(JULY 2023)

3.17 3052.204-72 - SAFEGUARDING OF CONTROLLED UNCLASSIFIED

INFORMATION (JULY 2023)

3.18 DHS-CBP Enterprise Architecture Compliance

3.19 Supply Chain Risk Management Terms and Conditions:

3.20 DHS Information Technology Portfolio Alignment

3.21 Accessibility Requirements (Section 508 Compliance)

3.22 Section 508 applicability to Information and Communications Technology (ICT): Passive Body Scanner

3.23 ISO Terms and Conditions for Sensitive but Unclassified Requests

3.24 Security Review Requirement

3.25 Enterprise Security Architecture

3.26 Supply Chain Risk Management

3.27 Personal Identification Verification (PIV) Credential Compliance

3.28 Security Requirements for Unclassified Information Technology Resources Requirement

3.29 3052.204-70 Security requirements for unclassified information technology resources

3.30 3052.204-71 Contractor employee access

3.31 3052.204-73 NOTIFICATION AND CREDIT MONITORING

REQUIREMENTS FOR PERSONALLY IDENTIFIABLE INFORMATION

INCIDENTS (JULY 2023)

3.32 OCIO CISO CYBER-SUPPLY CHAIN RISK MANAGEMENT (C-SCRM)

4 SPECIAL CONSIDERATIONS

4.1 Changes to the SOW

4.2 Travel

4.3 Points of Contact

Statement of Work

1 PURPOSE

The U.S. Customs and Border Protection (CBP), Non-Intrusive Inspection (NII PMO) Program intends to award a Blanket Purchase Agreement for to support Small-Scale, Handheld, and Chemical Identification equipment training. The purpose of this procurement is to provide CBP ports of entry (POE’s) and land border crossings with well-trained officers familiar with various devices in service and the ability to operate them at moment’s notice.

1.1 Background and Scope

Part of the mission of U.S. Customs and Border Protection (CBP) Office of Field Operations (OFO), U.S. Border Patrol (USBP), and Office of Air and Marine (OAM), is ensuring the continuous training development for the various handheld devices within the Non-Intrusive Inspection’s (NII) inventory as identified in this

SOW.

Handheld devices are portable NII System designed to examine specific areas of Conveyances or Travelers in order to locate anomalies. The vendor-led training will cover the following: Gemini Operator, Gemini Low Dose Differences, Gemini Refresher, MX908 Operator, MX908 Refresher, TruNarc Operator, USCBP DrugIQ, Smart Ray Vision Operator, ITVS Videoscopes Operator, Viken HBI Operator, ThruVision TAC16 Operator, ThruVision TAC16 Passive Body Scanner Refresher and Administrator, and Density Meter Operator courses.

1.2 Objective

CBP requires training across a multitude of handheld or small-scale NII systems, since a well-trained employee usually shows greater productivity and higher quality of work-output than an untrained employee in the same working hours.

Training improves the skills of employees in the performance of a particular job.

An increase in the skills usually helps to increase both quantity and quality of output.

As directed by NIID, the training materials shall be updated by the contractor to reflect evolving CBP standard operating procedures, changing operational priorities, and in accordance with CBP Office of Training and Development (OTD) criteria.

Video production and image collection shall be done in coordination with NIID and the operational components in CBP and shall remain the property of the Government.

The Contractor shall provide on-site instruction including set-up, course material (paper or electronic), training aids, including devices needed beyond CBP and/or Government Furnished equipment, at training location, any required consumables, and clean-up of the facility. The vendor shall also include an electronic method of record keeping for class rosters, all training dates (past, present, and future) and course evaluations. This electronic dashboard will be updated biweekly, at a minimum. The contractor shall provide a roster to local training coordinators, the Office of Training and Development (OTD) and the Training and Cargo Academy (TCA) at the conclusion of training. The vendor shall also provide an electronic means of course scheduling with the points of contact while including NIID in all communications.

1.3 Period of Performance:

This is a single award Blanket Purchase Agreement (BPA) to satisfy the urgent requirement for training. The period of performance for this single award Blanket Purchase Agreement (BPA) is as follows:

Base Ordering Period: 04/30/2025 through 04/29/2026 BPA Ordering Period 1: 04/30/2026 through 04/29/2027 BPA Ordering Period 2: 04/30/2027 through 04/29/2028 BPA Ordering Period 3: 04/30/2028 through 04/29/2029 BPA Ordering Period 4: 04/30/2029 through 04/29/2030

1.4 Place of Performance:

The place of performance will various CBP POEs and Border Crossings both CONUS and OCONUS.

1.5 Delivery

The training will be delivered as credits, which includes 16 hours of instruction per training credit at a designated field location with associated logistics and supplies (see section for further requirements). As directed by NIID, this training can be CONUS or OCONUS. Additionally, the vendor shall provide support in the development and/or periodic revision of training materials.

Training credits will have no expiration date, once purchased from CBP.

1.6 Invoicing

The Contractor shall submit one (1) FFP invoice for the Base Period thirty days

(30) after the contract award for the full amount of the POP outlined in this SOW.

Option(s) shall be invoiced thirty days (30) after a fully ratified modification to exercise the option for the full amount of the POP outlined in this SOW. The invoice shall be simultaneously transmitted electronically to the COR at the e-mail address provided in the section below, and the Contractor shall invoice CBP per CBP invoicing clause, “Electronic Invoicing and Payment Requirements – Invoice Processing Platform (IPP) (JAN 2016).”

Please ensure the following are included in all invoices:

• Contract number.

• Order Number (e.g., Task Order, Delivery Order, Purchase Order, etc.).

• Description of supplies or services provided for a specified time period.

• CLIN the supplies or services are charged under.

• Unit price and total amount of each item; and discount terms (if applicable).

• Company name, telephone number, taxpayer’s identification number, and complete mailing address to which payment will be mailed.

• Backup documentation showing the government has received the goods and/or services.

Payment requests shall be submitted electronically through the U. S. Department of the Treasury's Invoice Processing Platform System (IPP).

"Payment request" means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in FAR 32.905(b), "Payment documentation and process." The IPP website address is: https://www.ipp.gov.

A courtesy e-mail notification upon invoice submission in IPP shall be sent by the Contractor to the COR. Only the CO has the authority to represent the Government in cases where the delivery order requires a change in the terms and conditions, delivery schedule, scope of work and/or price of the products and/or services under this task order.

2 REQUIREMENTS

2.1 Operator Training

The Contractor shall provide on-site training and all training materials for CBP operator personnel at each site, using materials including classroom instruction, user/instructor guides/manuals, video, computers and on-the-job training aids (this is for the classroom training portion). Each class shall consist of the number of students listed in 2.4. to the corresponding course.

2.2 Ownership

All training products (including developmental documents, notes, storyboards, etc.) shall become the property of the United States Government upon delivery and acceptance by the government. All rights for use, modification, and repurposing of the training, in whole or in part, shall belong to the Government.

2.3 Training Material/Course Development

Each training credit shall cover 16 hours of training and will include all course materials needed. This shall also include the vendor lead trainers’ travel, printing, consumables and test material as needed, and logistics (shipping) associated with the course. This includes CONUS and OCONUS training sites and conform to the schedule as requested by the local CBP POC.

All trainers will be vetted by CBP bi-annually to access CBP facilities. All trainers will use vendor-provided email addresses for coordination and contact.

All training PowerPoints, Quick Reference Guides (QRGs) and hands-on skills practices/exercises shall be created in accordance with the CBP mission and given to the students for future reference.

The Vendor Training Program Manager (TPM) will work with CBP NII to create CBP-compliant training materials approved by OTD. The Program Manager will assist with any SOP development, upcoming updates to any of the equipment, changes to the training and will provide SMEs as needed for future development or guidelines.

2.4 Training Execution

This section covers the courses the vendor shall provide to CBP along with the number of students the courses shall serve and what the courses shall cover.

For the following courses, the Trainer should verify that the CBP provided devices are using the most current CBP LSS approved vendor- and user libraries (i.e. Gemini, MX908, and TruNarc).

Course Credit(s) Student Count

CBP ACADIS Description

Gemini Operator

1 24 GEMINI-

(G0723026- 35)

BTNX

Fentanyl Strips (G0620001- 03)

16-hour, OEM certified, CBP custom course, that includes basic training of the Gemini instrument, safe sampling techniques of chemicals, including narcotics, explosives, and other chemicals of concern. The course also provides customized hands-on exercises. Instruction will cover all classes of drugs, including, club drugs, depressants, inhalants, hallucinogenics, stimulants, dissociatives, as well as other new trends. This course also certifies the users in Rapid Response Fentanyl Strips (BTNX).

For those POEs that have Gemini Low Doses, this course will also include OEM certification on Gemini LD. Includes QRG’s, PPE, consumables and BTNX strips and other test kits to conduct the course.

Gemini Low Dose Differences

¼ Credit 12 4-hour OEM certified CBP custom course for those officers who already have taken the OEM certified Gemini course. This course is interactive lecture, supported by hands-on training on identifying low dose/low concentration narcotics.

Gemini Refresher

¼ Credit 24-In Person or unlimited Webinar

4-hour, CBP custom OEM course.

This CBP custom course can be either in person or instructor lead on-line webinar. The course is a Gemini refresher and covers some of the basic Gemini training along with updated information on safe sampling and interactive instruction.

MX908

Operator

½ Credit 12 G1429001-13 8-hour course, OEM certified, CBP custom designed course, that includes basic training on the MX908, and custom hands-on exercises designed for CBP.

CBP ACADIS Description

MX908

Refresher

¼ Credit 12 4-hour course, OEM certified, CBP custom designed course. The course is a MX908 refresher is for students who have had the basic MX908 training. This training covers some of the basic MX908 training along with updated information on safe sampling.

TruNarc Operator

¼ Credit, 2 classes per day, 4 classes per credit

20 G0727032-13 4-hour, OEM certified, CBP custom course will cover the use of the TruNarc and sampling techniques.

Course also includes proper techniques for using the H kit to detect low concentration, low dose amounts of drugs, including Fentanyl.

This course is 50% hands on, with students gaining first-hand experience operating several skill stations, using many different types of sampling techniques and testing real world chemicals

USCBP

DrugIQ

1 Credit 40 8-hour, CBP DrugIQ prepares responders and investigators to implement risk-based response tactics to safely respond to incidents involving synthetic opioids, counterfeit pills, and clandestine labs.

This course shall cover all classes of drugs to include, Club drugs, 2CB, Ketamine, NNDMT, THC extraction, edibles, and ice methamphetamine, as well as other new trends.

Smart Ray Vision Operator

¼ Credit, 2 classes per day

12 G0727040-13 4-hour, CBP customized OEM certified course with interactive lecture, supported by hands-on training. This course covers use of the SRV in the many CBP environments. Each course is mission specific to the POE, checkpoint, or station.

CBP ACADIS Description

ITVS Video Scope Kits Operator

¼ Credit 15 G0727045-42 4-hour, CBP customized OEM certified course with interactive lecture, supported by hands-on training. This course covers the basic training of the ITVS videoscope kits along with hands-on field applications.

Viken Handheld HBI Operator

¼ Credit 15 G0197001-43 4-hour, CBP customized OEM certified course with interactive lecture, supported by hands-on training. This course covers the basic training of the HBI family of devices along with hands-on field applications.

For any students with admin privileges, include any additional instruction for user management and admin functions.

ThruVision

TAC16

Operator Course

½ Credit 12-20 G0727039-

4-hour, CBP customized OEM certified course with interactive lecture, supported by hands-on training. This course covers the basic training of the ThruVision system, along with hands-on field applications. A CBP customized training kit is left behind for each location for future trainings.

ThruVision

TAC16

Passive Body Scanner Refresher

1/8 Credit 12-20 or unlimited webinar

2-hour, CBP custom OEM course.

This CBP custom course can be either in person or instructor lead on-line webinar. The course is a ThruVision TAC Personal Body Scanner (PBS) Operator refresher and covers some of the basic training along with best practices and interactive instruction.

ThruVision

TAC16

Passive Body Scanner Administrator Course

1/8 Credit 4-8 or unlimited webinar

G0727038-13 2-hour course, supplemental training for Operator Course that provides additional instruction for user access management, data management and system set-up/configuration settings.

CBP ACADIS Description

Density Meter Operator

½ Credit 12 8-hour course, OEM certified, CBP custom designed course, that includes basic training on the Density Meter, and custom hands-on exercises designed for CBP.

Training credits can also be used by CBP NII for any other training needs on equipment for which the vendor is OEM certified. They may also be applied to training for a CBP custom built course on new emerging threats, training needs or other equipment that is purchased.

Field users shall be able to request training by either reaching out to NIID or reaching out to the training vendor directly. The training vendor shall include NIID on communication with the field user(s). All training requests shall be approved by NIID before the training vendor schedules the training.

2.5 Training Deliverables

No later than the 10th of each calendar month a report shall be provided to NIID showing:

• how many and, if applicable, what type of training credits were completed/used to date for the current period of performance,

• how many training credits remain, and, if applicable, what types of training credits remain,

• any courses and credits are scheduled,

• and any courses and credits that are pending approvals.

3 INFORMATION TECHNOLOGY SECURITY

The Contractor shall adhere to all DHS and CBP IT security policies and the basic requirements, security authorization, encryption compliance, and pass security review.

3.1 Basic Requirements

The Contractor shall adhere to all DHS and CBP IT security policies listed in the applicable documents section, including the guidelines and policies stated in the DHS Sensitive Systems Policy Directive 4300A, chapters 4 and 5, or any subsequent, replacement or revised publication. This policy mandates DHS organizational elements, including Contractors, follow guidelines outlined in the DHS 4300A Policy Directive (Version 13.3, February 13, 2023), Information Technology Security Program, Version 13, with attachments or any subsequent, replacement or revised publication.

DHS Directive 4300A, Section 3.2., Basic Requirements outlines the management, operational and technical baseline security requirements (BLSR) for DHS Components to ensure confidentiality, integrity, availability, authenticity and non-repudiation of sensitive information systems. The DHS 4300A Policy Directive (Version 13.3, February 13, 2023) provides greater detail of the BLSRs, including the roles and responsibilities associated with each.

CBP will provide personnel with the appropriate background investigation, clearance levels to support the security certification/accreditation processes under this Agreement in accordance with DHS 4300A Policy Directive (Version 13.3, February 13, 2023), paragraph 4.1.1.d. During all systems development life cycle (SDLC) phases of CBP systems, CBP personnel will develop documentation and provide any required information for all levels of classification in support of the certification/accreditation process. In addition, all security certification/accreditation will be performed using the DHS certification/accreditation process, methodology and tools.

The contractor shall provide systems that conform to the following requirements:

Legacy air gapped non-integrated systems shall:

Wi-Fi shall not be used and be disabled but have the ability to be enabled if CBP/OIT approves of its use.

All operating systems must use the requisite DHS Security Technical Implementation Guides (STIGs) for hardening configurations All vendor contractors shall not remove image data from systems nor store said data on contractor networks Ground-truthing or tuning of systems will be performed only on CBP systems and not on contractor networks unless specifically authorized.

Integrated networked systems shall follow the above requirements and additionally:

If systems are using WIFI the design must be explicitly reviewed and approved by the CBP ENTSD organization and Security and Technology Policy (STP).

Other, wireless connectivity may be approved by ENTSD Systems must be patched and security updates maintained according to DHS patching standards (within 30 days usually) CBP Information Systems Security Policies and Procedures, Information Security Continuous Monitoring guidelines.

Username/Password authentication is not allowed

3.2 Security Authorization

A Security Authorization of any infrastructure directly in support of the DHS information system shall be performed by the Contractor as a general support system (GSS) prior to DHS occupancy to characterize the network, identify threats, identify vulnerabilities, analyze existing and planned security controls, determine likelihood of threat, analyze impact, determine risk, recommend controls, perform remediation on identified deficiencies, and document the results. The Security Authorization shall be performed in accordance with the DHS Security Policy and the controls provided by the hosting provider shall be equal to or stronger than the Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, Section 3, security categorization of the DHS information system.

At the beginning of the contract, and annually thereafter, the Contractor shall provide the results of an independent assessment and verification of security controls in the Contractor’s format. The independent assessment and verification shall apply the same standards that DHS applies in the Security Authorization Process of its information systems. Any deficiencies noted during this assessment shall be provided to the Contracting Officer Representative (COR) for entry into the DHS Plan of Action and Milestone (POA&M) Management Process. The Contractor shall use the DHS POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies shall be corrected within the timeframes dictated by the DHS POA&M Management Process. Contractor procedures shall be subject to periodic, unannounced assessments by DHS officials. The physical aspects associated with Contractor activities shall also be subject to such assessments.

On a periodic basis, the DHS and its Components, including the DHS Office of Inspector General, may choose to evaluate any or all of the security controls implemented by the Contractor under these clauses. Evaluation could include, but is not limited to vulnerability scanning. The DHS and its Components reserve the right to conduct audits at their discretion. With ten working days notice, at the request of the Government, the Contractor shall fully cooperate and facilitate in a Government-sponsored security control assessment at each location wherein DHS information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of DHS, including those initiated by the Office of the Inspector General.

The government may conduct a security control assessment on shorter notice (to include unannounced assessments) determined by DHS in the event of a security incident.

3.3 Encryption Compliance Requirement

1. Systems requiring encryption shall comply with FIPS 197 Advanced Encryption Standard (AES) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2.

2. Systems requiring encryption shall comply with National Security

Agency (NSA) Type 2 or Type 1 encryption.

3. Only cryptographic modules that are FIPS 197 (AES 256) compliant and have received FIPS 140-2 validation at the level appropriate to their intended use may be used in systems requiring encryption.

Public Key Infrastructure (PKI) (see paragraph 5.5.2.l of the Department of Homeland Security (DHS) Sensitive Systems Policy Directive 4300A).

3.4 Security Review

The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS including the organization of the DHS Office of the Chief Information Officer, Office of Inspector General, the CBP Chief Information Security Officer, authorized COR, and other Government oversight organizations, access to the Contractor’s and subcontractor’s facilities, installations, operations, documentation, databases, and personnel used in the performance of this contract. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of Government oversight organizations external to the DHS.

The Contractor shall provide access to the extent necessary for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of DHS/CBP data or the function of computer systems operated on behalf of DHS/CBP, and to preserve evidence of computer crime.

3.5 DHS Security Policy Requirement

All hardware, software, and services provided under this must be compliant with DHS 4300A DHS Sensitive System Policy, Section 4.8, and the DHS 4300A Policy Directive (Version 13.3, February 13, 2023), Section 4.8.

3.6 Enterprise Security Architecture

The contractor shall utilize and adhere to the DHS Enterprise Security Architecture in accordance with applicable laws and DHS policies to the satisfaction of the DHS COR. Areas of consideration could include:

1. Use of multi-tier design (separating web, application, and data base) with policy enforcement between tiers

2. Compliance to DHS Identity Credential and Access Management

(ICAM)

3. Security reporting to DHS central control points (i.e., the DHS Enterprise Security Operations Center (ESOC) and integration into DHS Security Incident Response

4. Integration into DHS Change Management (for example, the Infrastructure Change Control Board (ICCB) process)

5. Performance of security maintenance activities per continuous monitoring requirements

3.7 Information Assurance

Information Assurance (IA) is considered a requirement for all systems used to input, process, store, display, or transmit sensitive or national security information. IA is achieved through the acquisition and appropriate implementation of evaluated or validated commercial-off-the-shelf (COTS) IA and IA-enabled Information Technology (IT) products. These products provide for the availability of systems. The products also ensure the integrity and confidentiality of information and the authentication and nonrepudiation of parties in electronic transactions.

Strong preference is given to the acquisition of COTS IA and IA-enabled IT products (to be used on systems entering, processing, storing, displaying, or transmitting sensitive information) that have been evaluated and validated by authorized commercial laboratories or by National Institute of Standards and Technology (NIST), as appropriate, in accordance with the following:

- The NIST Federal Information Processing Standards (FIPS) validation program

- The National Security Area (NSA) /NIST National Information Assurance Partnership (NIAP) Evaluation and Validation Program

- The International Common Criteria for Information Security Technology Evaluation Mutual Recognition Agreement

3.8 Continuous Monitoring

The contractor shall participate in DHS Continuous Monitoring Strategy and methods or shall provide a Continuous Monitoring capability that the DHS determines acceptable. The DHS Chief Information Security Officer (CISO) issues annual updates to its Continuous Monitoring requirements via the Annual Information Security Performance Plan. At a minimum, the contractor shall implement the following processes:

Asset Management Vulnerability Management Configuration Management Malware Management Log Integration

Security Information Event Management (SIEM) Integration Patch Management

The Contractor shall provide near-real-time security status information to the DHS ESOC. The Contractor shall establish a monitoring scope at least as comprehensive and stringent as described in DHS 4300A Policy Directive (Version 13.3, February 13, 2023), Attachment F, “Incident Response.”

Specific Protections

Specific protections that shall be provided by the contractor include, but are not limited to the following:

Intrusion Detection Systems and Monitoring

The Contractor shall provide the design, configuration, implementation, and maintenance of the sensors and hardware that are required to support the Network Intrusion Detection System (NIDS) solution. The contractor is responsible for creating and maintaining the NIDS rule sets. The NIDS solution should provide real-time alerts. These alerts and other relevant information shall be located in a central repository. The NIDS shall operate 24x7x365. A summary of alerts shall be reported to the DHS COR in weekly status reports. If an abnormality or anomaly is identified, the contractor shall notify the appropriate DHS point of contact in accordance with the incident response plan.

Physical and Information Security and Monitoring The Contractor shall provide a facility using appropriate protective measures to provide for physical security. The facility will be located within the United States and its territories. The contractor shall maintain a process to control physical access to DHS IT assets. DHS IT Assets shall be monitored 24x7x365. A summary of unauthorized access attempts shall be reported to the appropriate DHS security office.

Vulnerability Assessments The Contractor shall provide all information from any managed device to DHS, as requested, and shall assist, as needed, to perform periodic vulnerability assessments of the network, operating systems, and applications to identify vulnerabilities and propose mitigations.

Vulnerability assessments shall be included as part of compliance with the continuous monitoring of the system.

Anti-malware (e.g., virus, spam) The Contractor shall design, implement, monitor and manage a comprehensive anti-malware service. The contractor shall provide all maintenance for the system providing the anti-malware capabilities to include configuration, definition updates, and comply with DHS’ configuration management / release management requirements when changes are required. A summary of alerts shall be reported to DHS COR in weekly status reports. If an abnormality or anomaly is identified, the contractor shall notify the appropriate DHS point of contact in accordance with the incident response plan.

Patch Management

The Contractor shall perform patch management services. The contractor shall push apply patches that are required by vendors and the DHS system owner. This is to ensure that the infrastructure and applications that directly support the DHS information system are current in their release and that all security patches are applied. The contractor shall be informed by DHS which patches are required by DHS through the Information Security Vulnerability Management bulletins and advisories.

Core applications, the ones DHS utilizes to fulfill their mission, shall be tested by DHS. However, the contractor shall be responsible for deploying patches as directed by DHS. It is recommended that all other applications (host-based intrusion detection system (HIDS), network intrusion detection system (NIDS), Anti-malware, and Firewall shall be tested by the contractor prior to deployment in a test environment.

Log Retention Log files for all infrastructure devices, physical access, and anti-malware should be retained online for 180 days and offline for three years.

3.9 Access to Unclassified Facilities, Information Technology (IT)

Resources, and Sensitive Information

IT resources and sensitive information during the acquisition process and contract performance are essential to the DHS mission. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive But Unclassified (For Official Use Only) Information paragraph 6, describes how Contractors must handle sensitive but unclassified information. DHS Sensitive Systems Policy Directive 4300A, paragraph 3.4, and DHS 4300A Policy Directive (Version 13.3, February 13, 2023), MD 4300A Information Technology Security Program, Chapter 4, prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering Contractors specifically for all Task Orders that require access to DHS facilities, IT resources or sensitive information. Contractors shall not use or redistribute any DHS information processed, stored, or transmitted by the Contractor except as specified in the task order.

Contractors who require access to the DHS network, such as when conducting remote maintenance, require a background investigation in accordance with DHS 4300A Policy Directive (Version 13.3, February 13, 2023), MD 4300.A, paragraph 4.1.1.d.

3.10 Personal Identity Verification (PIV) of Contractor Personnel

a. The Contractor shall comply with agency personal identity verification procedures identified in the contract that implement Homeland Security Presidential Directive-12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors, paragraph 3, Office of Management and Budget (OMB) guidance M-05-24, Appendix A, chapters 3 and 4, and Federal Information Processing Standards Publication (FIPS PUB) Number 201-2, Personnel Identity Verification of Federal Employees and Contractors, Section 2.

b. The Contractor shall insert this clause in all subcontracts when the subcontractor is required to have routine physical access to a Federally controlled facility or routine access to a Federally -controlled information system.

3.11 PIV Credential Compliance

Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting Homeland Security Presidential Directorate HSPD-12 PIV credentials as a method of identity verification and authentication.

Procurements for software products or software developments shall be compliant by PIV by accepting PIV credentials as the common means of authentication for access for federal employees and Contractors.

PIV-enabled information systems must demonstrate that they can correctly work with PIV credentials by responding to the cryptographic challenge in the authentication protocol before granting access.

If a system is identified to be non-compliant with HSPD-12 for PIV credential enablement, a remediation plan/or achieving HSPD-12 compliance shall be required/or review, evaluation, and approval by the

CISO.

3.12 CBP Contractor Handling PII Level

When a contractor, on the behalf of CBP, handles Sensitive PII data, stores and transmits, the contractor will Accredit (ATO) this information system to the (HHM) FIPS level”

3.13 Security Requirements for Unclassified Information Technology Resources

a. The Contractor shall be responsible for Information Technology

(IT) security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency’s mission.

b. The Contractor shall provide, implement, and maintain an IT Security Plan. This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.

(b.1) Within 30 days after contract award, the Contractor shall submit for approval its IT Security Plan in the Contractor’s format, which shall be consistent with and further detail the approach contained in the officer’s Quote.

The plan, as approved by the Contracting Officer, shall be incorporated into the contract as a compliance document.

(b.2) The Contractor’s IT Security Plan shall comply with Federal laws that include, but are not limited to, the Computer Security Act of 1987 (40 USC 1441 et seq.),sections 5 and 6; the Federal Information Security Management Act (44 USC 3554 (b)) of 2014; and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130, Appendix III, A.3.b (2).

(b.3) The security plan shall specifically include instructions regarding handling and protecting sensitive information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.

c. Examples of tasks that require security provisions include— (c.1) Acquisition, transmission or analysis of data owned by DHS with significant replacement cost should the Contractor’s copy be corrupted; and

(c.2) Access to DHS networks or computers at a level beyond that granted the general public (e.g., such as bypassing a firewall).

d. At the expiration of the contract, the Contractor shall return all sensitive DHS information and IT resources provided to the Contractor during the contract, and certify that all non-public DHS information has been purged from any Contractor- owned system.

Components shall conduct reviews to ensure that the security requirements in the contract are implemented and enforced.

e. Within 6 months after contract award, the Contractor shall submit written proof, in the Contractor’s format, of IT Security accreditation to DHS for approval by the DHS Contracting Officer.

Accreditation will proceed according to the criteria of the DHS Sensitive System Policy Publication, 4300A, Section 3.9, or any replacement publication, which the Contracting Officer will provide upon request. This accreditation will include a final security plan, risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan. This accreditation, when accepted by the Contracting Officer, shall be incorporated into the contract as a compliance document. The Contractor shall comply with the approved accreditation documentation.

3.14 3052.204-71 CONTRACTOR EMPLOYEE ACCESS (JULY 2023)

(a) Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:

(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical Facility Anti-Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual “Safeguarding Information Designated as Chemical-Terrorism Vulnerability Information” dated September 2008);

(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (title XXII, subtitle B of the Homeland Security Act of 2002 as amended through Pub. L. 116–283), PCII’s implementing regulations (6 CFR part 29), the PCII Program Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security, the PCII Program Manager, or a PCII Program Manager Designee;

(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive Security Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or designee), including Department of Homeland Security MD 11056.1, “Sensitive Security Information (SSI)” and, within the Transportation Security Administration, TSA MD 2810.1, “SSI Program”;

(4) Homeland Security Agreement Information means information the Department of Homeland Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement. The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion Center Initiative and activities for cyber information sharing consistent with the Cybersecurity Information Sharing Act of 2015;

(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;

(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;

(7) Information Systems Vulnerability Information (ISVI) means:

(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release; switching, router, and gateway information;

interconnections and access methods; and mission or business use/need.

Examples of ISVI are systems inventories and enterprise architecture models.

Information pertaining to national security systems and eligible for classification under Executive Order 13526 will be classified as appropriate; and/or

(ii) Information regarding developing or current technology, the release of which could hinder the objectives of the Department, compromise a technological advantage or countermeasure, cause a denial of service, or provide an adversary with sufficient information to clone, counterfeit, or circumvent a process or system;

(8) Operations Security Information means Department of Homeland Security information that could be collected, analyzed, and exploited by a foreign adversary to identify intentions, capabilities, operations, and vulnerabilities that threaten operational security for the missions of the Department;

(9) Personnel Security Information means information that could result in physical risk to Department of Homeland Security personnel or other individuals whom the Department is responsible for protecting;

(10) Physical Security Information means reviews or reports illustrating or disclosing facility infrastructure or security vulnerabilities related to the protection of Federal buildings, grounds, or property. For example, threat assessments, system security plans, contingency plans, risk management plans, business impact analysis studies, and certification and accreditation documentation;

(11) Privacy Information includes both Personally Identifiable Information (PII) and Sensitive Personally Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual’s identity, either alone, or when combined with other information that is linked or linkable to a specific individual; and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. To determine whether information is PII, DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual. Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.

(i) Examples of stand-alone PII that are particularly sensitive include: Social Security numbers (SSNs), driver’s license or State identification numbers, Alien Registration Numbers (A-numbers), financial account numbers, and biometric identifiers.

(ii) Multiple pieces of information may present an increased risk of harm to the individual when combined, posing an increased risk of harm to the individual.

SPII may also consist of any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:

(A) Truncated SSN (such as last 4 digits);

(B) Date of birth (month, day, and year);

(C) Citizenship or immigration status;

(D) Ethnic or religious affiliation;

(E) Sexual orientation;

(F) Criminal history;

(G) Medical information; and

(H) System authentication information, such as mother’s birth name, account passwords, or personal identification numbers (PINs).

(iii) Other PII that may present an increased risk of harm to the individual depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. The context includes the purpose for which the PII was collected, maintained, and used. This assessment is critical because the same information in different contexts can reveal additional information about the impacted individual.

(b) Information Resources means information and related resources, such as personnel, equipment, funds, and information technology.

(c) Contractor employees working on this contract must complete such forms as may be necessary for security or other reasons, including the conduct of background investigations to determine suitability. Completed forms shall be submitted as directed by the Contracting Officer. Upon the Contracting Officer’s request, the Contractor’s employees shall be fingerprinted or subject to other investigations as required. All Contractor employees requiring recurring access to government facilities or access to CUI or information resources are required to have a favorably adjudicated background investigation prior to commencing work on this contract unless this requirement is waived under Departmental procedures.

(d) The Contracting Officer may require the Contractor to prohibit individuals from working on the contract if the Government deems their initial or continued employment contrary to the public interest for any reason, including, but not limited to, carelessness, insubordination, incompetence, or security concerns.

(e) Work under this contract may involve access to CUI. The Contractor shall access and use CUI only for the purpose of furnishing advice or assistance directly to the Government in support of the Government’s activities, and shall not disclose, orally or in writing, CUI for any other purpose to any person unless authorized in writing by the Contracting Officer. For those Contractor employees authorized to access CUI, the Contractor shall ensure that these persons receive initial and refresher training concerning the protection and disclosure of CUI.

Initial training shall be completed within 60 days of contract award and refresher training shall be completed every 2 years thereafter.

(f) The Contractor shall include this clause in all subcontracts at any tier where the subcontractor may have access to government facilities, CUI, or information resources.

(End of Basic clause)

ALTERNATE I (JULY 2023)

(g) Before receiving access to information resources under this contract, the individual must complete a security briefing; additional training for specific categories of CUI, if identified in the contract; and any nondisclosure agreement furnished by DHS. The Contracting Officer’s Representative (COR) will arrange the security briefing and any additional training required for specific categories of

CUI.

(h) The Contractor shall have access only to those areas of DHS information resources explicitly stated in this contract or approved by the COR in writing as necessary for performance of the work under this contract. Any attempts by Contractor personnel to gain access to any information resources not expressly authorized by the terms and conditions in this contract, or as approved in writing by the COR, are strictly prohibited. In the event of violation of this provision, DHS will take appropriate actions with regard to the contract and the individual(s) involved.

(i) Contractor access to DHS networks from a remote location is a temporary privilege for mutual convenience while the Contractor performs business for DHS. It is not a right, a guarantee of access, a condition of the contract, or government-furnished equipment (GFE).

(j) Contractor access will be terminated for unauthorized use. The Contractor agrees to hold and save DHS harmless from any unauthorized use and agrees not to request additional time or money under the contract for any delays resulting from unauthorized use or access.

(k) Non-U.S. citizens shall not be authorized to access or assist in the development, operation, management, or maintenance of Department IT systems under the contract, unless a waiver has been granted by the Head of the Component or designee, with the concurrence of both the Department’s Chief Security Officer (CSO) and the Chief Information Officer (CIO) or their designees.

Within DHS Headquarters, the waiver may be granted only with the approval of both the CSO and the CIO or their designees. In order for a waiver to be granted:

(1) There must be a compelling reason for using this individual as opposed to a U.S. citizen; and

(2) The waiver must be in the best interest of the Government.

(l) Contractors shall identify in their proposals the names and citizenship of all non-U.S. citizens proposed to work under the contract. Any additions or deletions of non-U.S. citizens after contract award shall also be reported to the Contracting Officer.

(End of Alternate I (July 2023) clause)

ALTERNATE II (JULY 2023)

(g) Each individual employed under the contract shall be a citizen of the United States of America, or an alien who has been lawfully admitted for permanent residence as evidenced by a Permanent Resident Card (USCIS I-551).

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .