SPRDL115R0383-0003.pdf

PDF 30 KB Posted

Attached to
SPECIALIZED SHIPPING AND STORAGE CONTAINERS Federal contract opportunity
Solicitation number
SPRDL115R0383
Issued by
Department of the Army Materiel Command TACOM Life Cycle Management Command

About this file

Amendment 0003

View the file

Other files for this federal contract opportunity

Other files attached to SPECIALIZED SHIPPING AND STORAGE CONTAINERS, newest first.
File Type Posted
SPRDL115R0383-0005.pdf PDF
SPRDL115R0383-0004.pdf PDF
SPRDL115R0383-0002.pdf PDF
SPRDL115R0383-0001.pdf PDF
SPRDL115R0383.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT 1. Contract ID Code Page Of

2. Amendment/Modification No.

3. Effective Date

4. Requisition/Purchase Req No.

5. Project No. (If applicable)

6. Issued By Code 7. Administered By (If other than Item 6) Code

8. Name And Address Of Contractor (No., Street, City, County, State and Zip Code)

9A. Amendment Of Solicitation No.

9B. Dated (See Item 11)

10A. Modification Of Contract/Order No.

10B. Dated (See Item 13) Code Facility Code

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

The above numbered solicitation is amended as set forth in item 14. The hour and date specified for receipt of Offers is extended, is not extended.

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended by one of the following methods:

(a) By completing items 8 and 15, and returning ____________ copies of the amendments: (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

12. Accounting And Appropriation Data (If required)

13. THIS ITEM ONLY APPLIES TO MODIFICATIONS OF CONTRACTS/ORDERS

It Modifies The Contract/Order No. As Described In Item 14.

A. This Change Order is Issued Pursuant To: The Changes Set Forth In Item 14 Are Made In

The Contract/Order No. In Item 10A.

B. The Above Numbered Contract/Order Is Modified To Reflect The Administrative Changes (such as changes in paying office, appropriation data, etc.) Set

Forth In Item 14, Pursuant To The Authority of FAR 43.103(b).

C. This Supplemental Agreement Is Entered Into Pursuant To Authority Of:

D. Other (Specify type of modification and authority)

E. IMPORTANT: Contractor is not, is required to sign this document and return _______________ copies to the Issuing Office.

14. Description Of Amendment/Modification (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

Except as provided herein, all terms and conditions of the document referenced in item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. Name And Title Of Signer (Type or print)

16A. Name And Title Of Contracting Officer (Type or print)

15B. Contractor/Offeror 15C. Date Signed 16B. United States Of America 16C. Date Signed

By (Signature of person authorized to sign) (Signature of Contracting Officer)

NSN 7540-01-152-8070

PREVIOUS EDITIONS UNUSABLE

30-105-02 STANDARD FORM 30 (REV. 10-83)

Prescribed by GSA FAR (48 CFR) 53.243

SEE SCHEDULE

X

Firm Fixed Price

0003 2015OCT13

SPRDL1

DLA LAND WARREN

WARREN, MI 48397-5000

HTTP://CONTRACTING.TACOM.ARMY.MIL

SHIRLEY GHARAGOZLOO

EMAIL: SHIRLEY.R.GHARAGOZLOO.CIV@MAIL.MIL

SPRDL1-15-R-0383

2015SEP03

X

X 2015NOV03 03:00pm

/SIGNED/

2 signed

SEE SECOND PAGE FOR DESCRIPTION

1 11

CONTINUATION SHEET

Reference No. of Document Being Continued Page of

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

SECTION A - SUPPLEMENTAL INFORMATION

Buyer Name: SHIRLEY GHARAGOZLOO

Buyer Office Symbol/Telephone Number: DSCC-ZG/(586)282-3169

Type of Contract 1: Firm Fixed Price

Kind of Contract: Supply Contracts and Priced Orders

*** End of Narrative A0000 ***

SPRDL1-15-R-0383, Amendment 0003

1. The purpose of Amendment 0003 is to extend the hour and date set for receipt of proposals while the Government reviews engineering questions related to TDP 12344459.

2. The closing date is extended from October 13, 2015 to November 3, 2015 (3:00 PM local time).

3. Changes to solicitation terms and conditions are shown on the following pages. DUE TO PROBLEMS WITH THE FBO BID SUBMISSION MODULE, VENDORS ARE NOW AUTHORIZED TO SUBMIT OFFERS BY EMAIL DIRECTLY TO THE BUYER SHOWN IN BLOCK 6 ON PAGE 1.

*** END OF NARRATIVE A0003 ***

Status Regulatory Cite Title Date Status Regulatory Cite Title Date _______ _______________ ______________________________________________________________________ ____________ _______ _______________ ______________________________________________________________________ ____________

A-1 CHANGED 52.204-4016 WARREN ELECTRONIC CONTRACTING OCT/2015

(TACOM)

IMPORTANT NOTICE:

TEMPORARY CHANGE TO SOLICITATION TECH DATA AND QUOTE/PROPOSAL SUBMISSION PROCESS

Posting of solicitation Technical Data to FBO and the FBO Vendor Proposal Submission function have been temporarily disabled on the FBO website. Until further notice, interested vendors should submit quotes/proposals to the Contract Specialist listed on the first page of the solicitation. Instructions for obtaining Technical Data (if applicable) can be found in Section C clause 52.211-4072 Technical Data

Information. The solicitation will be amended to notify vendors when the FBO website is fully functioning for quote/proposal submissions and Technical Data access.

(a) Note to offerors:

Please pay close attention to the solicitation closing date and time as stated on the cover page of this solicitation, local time (EST), for DLA Land Warren. In accordance with FAR 15.208(a), offerors are responsible for submitting proposals, and any revisions and modifications, so as to be received by the Government office designated in the solicitation by the time specified.

It is the Offeror's responsibility to ensure the proposal is received by the date and time specified on the cover page of this solicitation. In accordance with FAR 15.208, if the proposal was not received at the initial point of entry to the Government infrastructure (in this case, received through FBO) by the exact date and time specified on the cover page of this solicitation, it will be determined late. Proposal is defined to mean that ALL volumes or parts required in the solicitation are included in the electronic submission.

Note: There is no "expected" or "target" length of time for proposal submission; size and content may be factors, therefore offerors are strongly cautioned when submitting proposals to allow adequate time for submission.

(b) Any award issued as a result of this solicitation will be distributed electronically. In the event of a FOIA request for a copy of any award issued as a result of this solicitation, or any subsequent modifications to the contract, the contract and modifications will be released, including the awarded unit price. This is the notice required by Executive Order 12600 (June 23, 1987) of our intention to release unit prices in response to any request under the Freedom of Information Act (FOIA), 5 USC 552. Unit price is defined as the contract price per unit or item purchased as it appears in Section B of the contract and is NOT referring to nor does it include Cost or

Pricing data/information. If you object to such release in the base contract or contract modifications, and you intend to submit an offer, notify the contracting officer in writing prior to the closing date identified in this solicitation and include the rationale for your objection consistent with the provisions of FOIA. A release determination will be made based on rationale given.

(c) Questions pertaining to this solicitation should be directed to the Contract Specialist identified on the cover page of this solicitation. For technical assistance in doing business with the Government, and doing business electronically, please visit the

Procurement Technical Assistance Center (PTAC) website at http://www.aptac-us.org/ to locate a regional center.

[End of Provision]

2 11

SPRDL1-15-R-0383 0003

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

3 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

SECTION C - DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

Status Regulatory Cite Title Date Status Regulatory Cite Title Date _______ _______________ ______________________________________________________________________ ____________ _______ _______________ ______________________________________________________________________ ____________

C-1 CHANGED 52.211-4072 TECHNICAL DATA PACKAGE INFORMATION OCT/2015

(TACOM)

The following Xd item applies to this solicitation:

[ ] 1. There is no Technical Data Package (TDP) included with this solicitation.

[X] 2. The TDP for this solicitation resides within AMRDEC SAFE (https://safe.amrdec.army.mil/safe/), associated with this solicitation number.

To access the data through AMRDEC:

a. [ ] This item requires a Use and Non-Disclosure Agreement - You must submit an email to the Contract

Specialist to request access to the technical data associated with this solicitation. The email to the Contract Specialist should include the completed Use and Non-Disclosure Agreement and the following information:

Subject Line: Explicit Access Request

- Solicitation #

- Vendor Name

- Contractor Name

- DUNS

- Cage #

[X] This item does not require a Use and Non-Disclosure Agreement In order to receive access to the technical data associated with this solicitation, submit an email request to the following mailbox: mailto:usarmy.detroit.acc.mbx.wrn-idq@mail.mil.

The email request should include the following information:

Subject Line: Explicit Access Request

- Solicitation #

- Vendor Name

- Contractor Name

- DUNS

- Cage #

b. If multiple individuals in your company need access to the Technical Data Package (TDP) for a solicitation and an explicit access request is required, each individual MUST follow the instructions in either 2(a) or 2(b) above.

c. Upon completion of the explicit access request, vendors will receive an email from the AMRDEC SAFE site containing all the information needed to access the technical data.

- Vendors will have 14 (fourteen) days to access the technical data. The TDP will become unavailable on day 14 (fourteen).

- If the vendor does not download the technical data during that time they must resubmit a request to access the technical and provide the information listed in section 2(b).

d. [X] Export Control Warning Notice - The technical data associated with this solicitation contains Export

Controlled material.

(1) TDPs that have an Export Control Warning Notice are subject to the Arms Export Control Act (Title 22, U.S.C., Sec

2751, et.seq.) or the Export Administration Act of 1979, as amended, Title 50, U.S.C, App. 2401 et. seq.

(2) Further dissemination must be in accordance with provisions of DoD Directive 5230.25. This also applies to distribution of the TDP to all SUBCONTRACTORS at every level.

4 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

(3) To obtain these TDPs, vendors and contractors must have a current DD 2345, Militarily Critical Technical Data

Agreement on file with Defense Logistics Information Service (DLIS).\~ If you are currently certified, you may proceed to the applicable next step in section 2(a) above and your MPIN will be verified.\~ To obtain certification, go to http://www.dlis.dla.mil/jcp/

Click on documents and follow instructions provided. Processing time is estimated at six (6) to ten (10) weeks after receipt. The Contract Process Management will allow you to access export controlled TDPs once certification is confirmed.

(4) Upon completion of the purposes for which Government Technical Data has been provided, the Contractor is required to destroy all documents, including all reproductions, duplications, or copies thereof as may have been further distributed by the Contractor. Destruction of this technical data shall be accomplished by: shredding, pulping, burning, or melting any physical copies of the TDP and/or deletion or removal of downloaded TDP files from computer drives and electronic devices, and any copies of those files.

e. User information for AMRDEC SAFE is located at https://safe.amrdec.army.mil/safe/ under the Quick Links section at the

Getting Started Guide.

[End of clause]

5 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

6 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

SECTION I - CONTRACT CLAUSES

Status Regulatory Cite Title Date Status Regulatory Cite Title Date _______ _______________ ______________________________________________________________________ ____________ _______ _______________ ______________________________________________________________________ ____________

I-1 DELETED 252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING SEP/2015

I-2 ADDED 252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING OCT/2015

(DEV 2016- (DEVIATION 2016-O0001)

O0001)

(a) Definitions. As used in this clause--

"Adequate security" means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.

"Compromise" means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.

"Contractor attributional/proprietary information" means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.

"Contractor information system" means an information system belonging to, or operated by or for, the Contractor.

"Controlled technical information" means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction

5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.

"Covered contractor information system" means an information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.

Covered defense information means unclassified information that--

(i) Is--

(A) Provided to the contractor by or on behalf of DoD in connection with the performance of the contract; or

(B) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract; and

(ii) Falls in any of the following categories:

(A) Controlled technical information.

(B) Critical information (operations security). Specific facts identified through the Operations Security process about friendly intentions, capabilities, and activities vitally needed by adversaries for them to plan and act effectively so as to guarantee failure or unacceptable consequences for friendly mission accomplishment (part of Operations Security process).

(C) Export control. Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. To include dual use items; items identified in export administration regulations, international traffic in arms regulations and munitions list; license applications; and sensitive nuclear technology information.

(D) Any other information, marked or otherwise identified in the contract, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies (e.g., privacy, proprietary business information).

"Cyber incident" means actions taken through the use of computer networks that result in an actual or potentially adverse effect on an information system and/or the information residing therein.

"Forensic analysis" means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.

"Malicious software" means computer software or firmware intended to perform an unauthorized process that will have adverse impact on

7 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.

"Media" means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which information is recorded, stored, or printed within an information system.

"Operationally critical support" means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.

"Rapid(ly) report(ing)" means within 72 hours of discovery of any cyber incident.

"Technical information" means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Non Commercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract.

Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.

(b) Adequate security. The Contractor shall provide adequate security for all covered defense information on all covered contractor information systems that support the performance of work under this contract. To provide adequate security, the Contractor shall

(1) Implement information systems security protections on all covered contractor information systems including, at a minimum--

(i) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government--

(A) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing

Services, of this contract; and

(B) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract; or

(ii) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1)(i) of this clause--

(A) The security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, "Protecting Controlled

Unclassified Information in Nonfederal Information Systems and Organizations," (see http://dx.doi.org/10.6028/NIST.SP.800-171) that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer with the exception of the derived security requirement 3.5.3 Use of multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts, which will be required not later than 9 months after award of the contract, if the Contractor notified the contracting officer in accordance with paragraph (c) of the provision 252.204-7008, Compliance with Safeguarding Covered Defense

Information Controls (DEVIATION 2016-O0001)(OCT 2015); or

(B) Alternative but equally effective security measures used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection approved in writing by an authorized representative of the DoD Chief Information Officer (CIO) prior to contract award; and

(2) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraph (b)(1) of this clause, may be required to provide adequate security in a dynamic environment based on an assessed risk or vulnerability.

(c) Cyber incident reporting requirement.

(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractors ability to perform the requirements of the contract that are designated as operationally critical support, the Contractor shall--

(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractors network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the

Contractors ability to provide operationally critical support; and

(ii) Rapidly report cyber incidents to DoD at http://dibnet.dod.mil.

8 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at http://dibnet.dod.mil.

(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see http://iase.disa.mil/pki/eca/Pages/index.aspx.

(d) Malicious software. The Contractor or subcontractors that discover and isolate malicious software in connection with a reported cyber incident shall submit the malicious software in accordance with instructions provided by the Contracting Officer.

(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide

DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.

(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.

(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.

(i) Use and release of contractor attributional/proprietary information not created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD

(1) To entities with missions that may be affected by such information;

(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;

(3) To Government entities that conduct counterintelligence or law enforcement investigations;

(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial

Base (DIB) participants in the program at 32 CFR part 236); or

(5) To a support services contractor (recipient) that is directly supporting Government activities under a contract that includes the clause at 252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.

(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Governments use and release of such information.

(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.

(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractors responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.

(m) Subcontracts. The Contractor shall--

(1) Include the substance of this clause, including this paragraph (m), in all subcontracts, including subcontracts for commercial items; and

9 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

(2) Require subcontractors to rapidly report cyber incidents directly to DoD at http://dibnet.dod.mil and the prime Contractor. This includes providing the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable.

(End of clause)

10 11

Name of Offeror or Contractor:

PIIN/SIIN MOD/AMD

SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS

Status Regulatory Cite Title Date Status Regulatory Cite Title Date _______ _______________ ______________________________________________________________________ ____________ _______ _______________ ______________________________________________________________________ ____________

L-1 DELETED 252.204-7008 COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS AUG/2015

L-2 ADDED 252.204-7008 COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS OCT/2015

(DEV 2016- (DEVIATION 2016-O0001)

O0001)

(a) Definitions. As used in this provision--

"Controlled technical information," "covered contractor information system," and "covered defense information" are defined in clause

252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DEVIATION 2016-O0001)(OCT 2015).

(b) The security requirements required by contract clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident

Reporting (DEVIATION 2016-O0001)(OCT 2015) shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.

(c) If the Offeror anticipates that additional time will be necessary to implement derived security requirement 3.5.3 "Use of multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts" within

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations (see http://dx.doi.org/10.6028/NIST.SP.800-171), the Offeror shall notify the

Contracting Officer that they will implement the requirement within 9 months of contract award.

(d) If the Offeror proposes to deviate from any of the security requirements in NIST SP 800-171that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of--

(1) Why a particular security requirement is not applicable; or

(2) How an alternative, but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.

(e) An authorized representative of the DoD CIO will approve or disapprove offeror requests to deviate from NIST SP 800-171 requirements in writing prior to contract award. Any approved deviation from NIST SP 800-171 shall be incorporated into the resulting contract.

(End of provision)

11 11

SECTION A
SECTION C
SECTION I
SECTION L

File details come from the government source that posted it. Updated .