SOW Janitorial Services Complete_PRIV reviewed_5.18.21.pdf

PDF 209 KB Posted

Attached to
Janitorial Services in Saipan Federal contract opportunity
Solicitation number
70FBR921Q00000029
Issued by
Federal Emergency Management Agency Region 9

View the file

Other files for this federal contract opportunity

Other files attached to Janitorial Services in Saipan, newest first.
File Type Posted
70FBR921Q00000029 Janitorial Services-Solicitation.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work (SOW) Janitorial Services

FEMA JRO & FSA Fire Station No. 4

The purpose of this procurement action is to obtain cleaning services for two FEMA facilities: Joint Recovery Office and FSA Fire Station #4. The contractor shall perform cleaning services in all designated spaces including interior and exterior spaces, including, but not limited to entrances, lobbies, corridors, bathrooms, office areas, kitchens, breakrooms, conference rooms, entrance ways, lobbies, storage areas, and walkways.

1. GENERAL REQUIREMENTS

The Contractor shall include all planning, administration, and management necessary to ensure that all services comply with the contract, schedules, instructions from the COR and all applicable laws and regulations. The Contractor shall comply with all specifications and requirements in the contract. The Contractor shall perform all related support functions such as supply, quality control, financial oversight, and maintenance of complete records and files.

2. Mission:

FEMA is authorized to provide disaster assistance to the Commonwealth of the Northern Marina Islands, Saipan, for emergencies, major disasters, and Incidents of National Significance under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (Public Law 93-288), as amended.

Per that authorization, this Statement of Work applies to the villages in the federal emergency disaster declaration DR-4404-MP.

Janitorial services are required within the Joint Recovery Office and the Fire Station No. 4 facility to provide a clean and healthy work environment for the FEMA employees stationed at each facility. Maintaining sanitary conditions within the facilities helps prevent the spread of germs and illness.

3. SCOPE:

The Contractor shall perform cleaning work, including furnishing all labor, material, tools/equipment, and services, for the Joint Recovery Office and the FSA Fire Station #4. Offices cleaning services includes but are not limited to cleaning of office space including office furniture (table/desktops), windows, and bathrooms. While maintaining their working area and rest/lunch area clean.

The required cleaning services shall include:

Sweep all floor areas. Floors shall be free of dust, mud, sand, liquid spills, and other debris.

Furniture, appliances, trash receptacles, and other moveable items shall be tilted or moved to clean underneath and behind. Mopping of all office floors (including lobby entrance and egress therein) of the Joint Recovery Office will be performed at the close of business (16:00) every Friday. Mopping of all office floors for the FSA Fire Station #4 will be performed one hour prior to close of business (1500) every Friday. When completed, the floors shall have a uniform appearance with no streaks, smears, swirl marks, detergent residue, or any evidence of remaining dirt or standing water.

Disinfecting of all surface areas of including, but not limited to, desks, chairs, kitchen areas, telephone tables, corridor shelves, bathroom areas, and other common surface areas. All furniture shall be free of dust, dirt, and sticky surfaces or areas. Disinfecting will be performed on Mondays/Wednesdays/Fridays. After cleaning is completed, the furniture needs to be replaced to the original position.

Thorough cleaning and sanitation of toilets, bathroom mirrors, and any other bathroom fixtures using suitable non-abrasive cleaners and disinfectants. All surfaces shall be free of grime, soap scum, mold, and smudges. Restocking of supplies (toilet paper, paper towels, hand soap). Damp mopping of restrooms to be performed daily.

Thorough cleaning of kitchen facilities, to include sweeping, wiping down and sanitizing the sinks, counters, and other surfaces, cleaning the inside, outside and on top of cabinets and pantry, microwaves, stove/oven, refrigerator, and freezer. Restocking of supplies (hand soap and paper towels).

Dust remove grease marks and wipe down windows or fix glass panels on the inside to include windows, windowsills, and tracks. For high windows, the contractor shall provide any ladders and safety equipment or appropriate means to reach them.

Spot cleaning walls. As appropriate, sweep debris from walkways and corridors.

Working Hours Per Facility:

Joint Recovery Office:

• Weekdays between 0730 and 1630, Monday through Fridays, except for holidays.

FSA Fire Station #4:

• Weekdays between 1200 and 1600, Tuesdays and Fridays ONLY, except for holidays.

If a Contractor employee is absent, the Contractor is responsible to provide replacement staff.

4. CONTRACTOR ROLES AND RESPONSIBILITIES:

Contractor roles and responsibilities are contingent on the services required specific to the disaster event. The Contractor shall:

4.1 GENERAL. The Contractor shall maintain discipline at the site and shall take all reasonable precautions to prevent any unlawful, riotous, or disorderly conduct by Contractor employees at the site. The Contractor shall preserve peace and protect persons and property on site. The Government reserves the right to direct the Contractor to remove an employee from the worksite for failure to comply with the standards of conduct. The Contractor shall immediately replace such an employee to maintain continuity of services at no additional costs to the Government.

4.2 PERSONAL EQUIPMENT. The Contractor shall provide, to each employee personal equipment.

The Contractor shall also provide personal protective equipment to all its employees, including but not limited to boots and gloves.

4.3 PERSONNEL SECURITY. After contract award, the Contractor shall provide the following list of data on each employee who will be working under the contract. The Contractor shall include a list of workers and supervisors assigned to this project, including planned back-up personnel. The Government will run background checks on these individuals. For everyone the list shall include:

• Full Name

• Place and Date of Birth

• Current Address

• Other information required by Security to provide recurring access to the facility.

4.4 MATERIALS AND EQUIPMENT. The Contractor shall provide all necessary cleaning supplies and equipment to perform the work identified in this contract. Please see below a list of the minimum materials, equipment, supplies and personal protective equipment to be supplied.

Materials/Expendables to be used and provided by the Contractor:

• Latex gloves or similar, brushes, buckets, “wet floor “ Signs, ladders, brooms, sweepers, dustpans, mop with mop heads, squeezer, alcohol, chlorine, disinfectant spray and wipes, glass cleaner, detergent, sponges, cloths , paper towels, garbage bags, staff personal protective equipment.

4.5 PERSONAL INJURIES OR DAMAGES. The Contractor agrees that the Government shall not be responsible for personal injuries or for damages to:

• any property of the Contractor,

• employees, or

• any other person

The Contractor shall hold harmless and indemnify the Government from any claims arising, except in the instance of gross negligence on the part of the Government.

4.6 ENVIRONMENTAL PROTECTION. The Contractor shall protect oceans and drainage ditches from chemical contamination, sediment run-off, construction debris, and other damage. Soil erosion and sediment control provisions and maintenance in accordance with local requirements are required. In the case of a spill or release of any sort, the Contractor shall immediately notify the COR.

Dispose of all materials and supplies in compliance with all Federal, State, and Local laws, regulations, and rules. The Contractor shall pay any fees associated with the removal and disposal of hazardous waste.

4.7 CONTRACTOR SAFETY. The Contractor shall protect the property from all potential hazards.

The Contractor will adhere to and enforce all applicable local safety regulations. The Contractor shall report any accidents, injuries, fires or other incidents of a serious nature or incidents requiring emergency response to the COR and offsite office coordinator, immediately. Contractor personnel shall wear appropriate personal protective equipment for the task being performed.

The Contractor shall furnish all required safety equipment and/or clothing, which may be required for personnel as mandated by Federal, State, and Local code. This will include maintaining a safe working environment for the Contractor’s employees, FEMA staff, other Contractors, and the public. At no time shall the Contractor leave unattended or otherwise unprotected, any safety hazard that might cause injury to persons.

The Contractor shall comply with the Federal and CNMI Department of Labor and the Occupational Safety and Health Administration (OSHA) safety regulations, rules, and requirements, as well as any Federal, State, County and Local laws, codes, and ordinances.

The Contractor shall supply all Material Safety Data Sheets (MSDS) for products proposed to be used to the COR.

4.6 COMMUNICATIONS. The Contractor will identify and notify COR of potential project constraints. Actively coordinate with the FEMA CO or COR. Provide reports, as defined by the COR. Ensure that all reports meet the information needs specified, and any additional information requested by the COR. Maintain accurate records and provide all documents as required in the contract.

4.7 Obtain a DUNS number and follow federal guidelines for invoicing and payments as required by the contract.

5.0 FEMA ROLES AND RESPONSIBLITIES:

To support Contractor activities related to the service responsibilities, FEMA shall perform the tasks detailed below. The scope of services provided by FEMA may vary based on the need of the event, and scope of services provided by the Contractor or other Federal agencies.

• Meet its financial obligation

• Monitor the spending of Taxpayer funds.

• Hold contractor accountable for all terms and conditions.

6.0 DELIVERABLES AND DELIVERY SCHEDULE:

The purpose of the Reports and Deliverables Section is to provide the COR with information that will be used to assess and track how the mission is being carried out. The COR will determine if any of the reports that are generally required by the Government are deemed unnecessary for this contract. The COR will notify the Contractor in writing to inform the Contractor of what reports will be required as part of this contract.

7.0 FIXED RATE AGREEMENT:

This is a fixed rate agreement inclusive of all cost of labor, equipment and supplies necessary for cleaning and disinfecting (gloves, mop bucket, mop handle and mop head, brooms, dust pans, soaps, sprays, wipes, trash bags, etc.). No Government Furnished Equipment or materials/supplies will be supplied.

8.0 PLACE OF PERFORMANCE:

FEMA Federal Staging Area Fire Station No. 4 Koblerville, Saipan, MP 96950 Operational Hours: 0730 to 1600

FEMA Joint Recovery Office TSL Plaza Suite 2A Beach Road, Garapan, Saipan, MP 96950 Operational Hours: 0730 to 1600

9.0 PERIOD OF PERFORMANCE:

The Contractor shall provide services for a base period of ninety (90) days from the time of award. Three (3) additional ninety (90) day options will be included in the contract for extension.

10.0 RESPONSIBILTIES.

10.1 Need to Know

The contractor will limit access to the PII provided by FEMA under this contract only to the contractor’s authorized personnel who need to know the information to accomplish the tasks outlined in this contract.

10.2 Prohibition on Computer Matching

The contractor shall ensure no computer matching, as that term is defined in 5 U.S.C. § 552a(a)(8), will occur for the purpose of establishing in or verifying eligibility or compliance as it relates to cash or in-kind assistance or payments under federal benefit programs.

10.3 Recipient Requirement

If at any time during the term of this contract any part of FEMA PII, in any form, that the contractor obtains from FEMA ceases to be required by the contractor for the performance of the contract, or upon the termination of the contract, whichever occurs first, the contractor shall, within fourteen (14) days thereafter, promptly notify FEMA and securely return PII to FEMA, or, at FEMA’s written request destroy, un-install and/or remove all copies of such PII in the contractor’s possession or control, and certify in writing to FEMA that such tasks have been completed.

10.4 Safeguarding of Sensitive Information (Mar 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause—

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107- 296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee); Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(2) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(3) Any information that is designated “sensitive” or subject to other controls, safeguards, or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000- 6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three

(3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed

SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The Contractor shall update its SA package by one of the following methods:

(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls.

The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced.

The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract.

Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements.

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for

Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Data Universal Numbering System (DUNS).

(ii) Contract numbers affected unless all contracts by the company are affected.

(iii) Facility CAGE code if the location of the event is different than the prime contractor location.

(iv) Point of contact (POC) if different than the POC recorded in the System for Award Management (address, position, telephone, email).

(v) Contracting Officer POC (address, telephone, email).

(vi) Contract clearance level.

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network.

(viii) Government programs, platforms or systems involved.

(ix) Location(s) of incident.

(x) Date and time the incident was discovered.

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level.

(xii) Description of the Government PII and/or SPII contained within the system.

(xiii) Number of people potentially affected, and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

(g) Sensitive Information Incident Response Requirements.

(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or Component CIO and Headquarters or Component Privacy Officer.

(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:

(i) Inspections,

(ii) Investigations,

(iii) Forensic reviews, and

(iv) Data analyses and processing.

(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

(h) Additional PII and/or SPII Notification Requirements.

(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the Contractor shall be coordinated with, and subject to prior written approval by the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, utilizing the DHS Privacy Incident Handling Guidance. The Contractor shall not proceed with notification unless the Contracting Officer, in consultation with the Headquarters or Component Privacy Officer, has determined in writing that notification is appropriate.

(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:

(i) A brief description of the incident.

(ii) A description of the types of PII and SPII involved.

(iii) A statement as to whether the PII or SPII was encrypted or protected by other means.

(iv) Steps individuals may take to protect themselves.

(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and

(vi) Information identifying who individuals may contact for additional information.

(i) Credit Monitoring Requirements. In the event that a sensitive information incident involves PII or SPII, the Contractor may be required to, as directed by the Contracting Officer:

(1) Provide notification to affected individuals as described above; and/or

(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified. Credit monitoring services shall be provided from a company with which the Contractor has no affiliation. At a minimum, credit monitoring services shall include:

(i) Triple credit bureau monitoring.

(ii) Daily customer service.

(iii) Alerts provided to the individual for changes and fraud; and

(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or

(3) Establish a dedicated call center. Call center services shall include:

(i) A dedicated telephone number to contact customer service within a fixed period.

(ii) Information necessary for registrants/enrollees to access credit reports and credit scores.

(iii) Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics.

(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate.

(v) Customized FAQs, approved in writing by the Contracting Officer in coordination with the Headquarters or Component Chief Privacy Officer; and

(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.

(j) Certification of Sanitization of Government and Government-Activity-Related Files and Information. As part of contract closeout, the Contractor shall submit the certification to the COR and the Contracting Officer following the template provided in NIST Special

Publication 800-88 Guidelines for Media Sanitization.

11.0 SECURITY

All personnel require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees receive a favorably adjudicated public trust suitability prior to entry on duty (EOD). All individuals will be U.S.

citizens. The contractor shall follow the standards established within DHS and FEMA policy.

Certificate of training is required for all cleared contractor employees who are working with classified or unclassified information. All certificates must be sent to the assigned FEMA Contracting Officer Representative (COR), before the contractor or subcontractor is granted access to classified or unclassified information but no later than 30 calendar days after awarded contract. Send certificates of completion for Unauthorized Disclosure, OPSEC, and Insider Threat to the FEMA COR no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.

Unauthorized Disclosure of Classified or Unclassified Information Contractors and subcontractors who are working on this contract shall receive Unauthorized Disclosure of Classified or Unclassified Information training.

Access to the training can be obtained at:

https://securityawareness.usalearning.gov/disclosure/index.html

OPSEC Training Contractors and subcontractors who are working on this contract shall receive the OPSEC Awareness Brief.

Access to the briefing can be obtained at https://securityawareness.usalearning.gov/opsec/index.htm

Insider Threat Training https://securityawareness.usalearning.gov/disclosure/index.html https://securityawareness.usalearning.gov/opsec/index.htm

Insider Threat training for contractors can be found at:

https://securityawareness.usalearning.gov/itawareness/index.htm#

For Official Use Only (FOUO) Information In accordance with DHS Management Directive 11042.1 contractors, consultants, and others to whom access is granted will abide by 11042.1; DHS policy regarding the identification and safeguarding of sensitive but unclassified information originated within DHS. It also applies to other sensitive but unclassified information received by DHS from other government and non-governmental activities.

The contractor shall:

1. Be aware of and comply with the safeguarding requirements for “For Official Use Only” (FOUO) information as outlined in this directive.

2. Participate in formal classroom or computer-based training sessions presented to communicate the requirements for safeguarding FOUO and other sensitive but unclassified information.

3. Be aware that divulging information without proper authority could result in administrative or disciplinary action.

Contractors and consultants shall execute a DHS Form 11000-6, Sensitive but Unclassified Information Non Disclosure Agreement (NDA), as a condition of access to such information. Other individuals not assigned to or contractually obligated to DHS, but to whom access to information will be granted, may be requested to execute an NDA as determined by the applicable program manager. Execution of the NDA shall be effective upon date of the DHS Policy and not applied retroactively.

FEMA does not intend to share PII with this contractor, however it is possible during their duties that they may encounter documents containing PII. Privacy and cyber security clauses are in place to ensure contractor compliance with proper PII handling procedures.

12.0 APPLICABLE DOCUMENTS:

Employee Identification - Contractor personnel working on this requirement shall wear an identification badge that, at minimum, displays the contractor’s name, the employee’s photo, and the employee’s name. Contractor employees shall comply with all Government escort rules and requirements. Provide manufacturer documentation for maintenance performance schedule.

https://securityawareness.usalearning.gov/itawareness/index.htm

File details come from the government source that posted it. Updated .