TIB-2021-RFP-0003 CUI final.docx
DOCX document 189 KB Posted
- Attached to
- Legal Support Services M01 Federal contract opportunity
- Solicitation number
- TIB-2021-RFP-0003
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| TIB-2021-RFP-0003 M01 CUI final.docx | DOCX document | |
| Responses to_QA Legal Support CUI.xlsx | XLSX spreadsheet | |
| Attachment 001- NDA Contractor Employee CUI.docx | DOCX document | |
| Attachment 003 FRTIB RoB for Accessing IT Systems.pdf | ||
| Attachment 005 - QA Template CUI.xlsx | XLSX spreadsheet | |
| Attachment 002 - NDA Contractor Company.docx | DOCX document | |
| Attachment 004 Oracle Supplier Request Form.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
TIB-2021-RFP-0003 Section B
PAGE 1 OF
1. REQUISITION NO.
2. CONTRACT NO.
3. AWARD/EFFECTIVE DATE
4. ORDER NO.
5. SOLICITATION NUMBER
6. SOLICITATION ISSUE DATE
a. NAME
b. TELEPHONE NO. (No Collect Calls)
8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY
CODE
10. THIS ACQUISITION IS
UNRESTRICTED OR
SET ASIDE:
% FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ
IFB
RFP
15. DELIVER TO
CODE
16. ADMINISTERED BY
CODE
17a. CONTRACTOR/OFFEROR
CODE
FACILITY CODE
18a. PAYMENT WILL BE MADE BY
CODE
TELEPHONE NO.
DUNS:
DUNS+4:
PHONE:
FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19.
20.
21.
22.
23.
24.
ITEM NO.
SCHEDULE OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA
26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA
ARE
ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
ARE
ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________
29. AWARD OF CONTRACT: REF. ___________________________________ OFFER
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
DATED ________________________________. YOUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
(REV. 2/2012)
PREVIOUS EDITION IS NOT USABLE
Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
PR-2021-STD-0322
TIB-2021-RFP-0003
08-09-2021
FRTIB
77 K Street NE, Suite 1000 Washington DC 20002
X
922130
Net 30
N/A
77 K Street, NE Suite 1000
202-942-1600
See CONTINUATION Page This Request for Proposal (RFP) is to provide Legal Support Services to the Federal Retirement Thrift Investment Board
(FRTIB).
The Contractor shall furnish and make available all professional, technical, administrative, and management services, as well as supplies and materials needed to accomplish the tasks under the contract.
All questions regarding this RFP shall be submitted in writing only using Attachment 005- Q&A Template, to the Contracting Officer at Denise.Roberts-Maynard@FRTIB.Gov no later than 12:00pm EST on Wednesday, August 4, 2021
All quotes shall be submitted no later than 12:00pm EST on Wednesday, September 1, 2021
Contractor must certify FAR clauses 52.204-24 and 52.204-26 within this document prior to award of the contract.
See CONTINUATION Page
Denise Roberts-Maynard
Section A: Solicitation/Contract Form A.1 Background The Federal Retirement Investment Board (FRTIB) is an independent Federal government agency in the Executive Branch created by the Federal Employees’ Retirement System Act of 1986 (FERSA). The Thrift Savings Plan (TSP) is a retirement savings and investment plan for Federal civilian employees and members of the uniformed services that offers its participants the same type of savings and tax benefits that many private corporations offer their employees under I.R.C.§401(k) plans. The TSP is the largest participant-directed defined contribution plan in the world. The mission of the FRTIB is to administer the TSP solely in the interest of the participants and beneficiaries.
FRTIB is a self-funded agency with independent budgetary authority that receives no annual appropriations from Congress. FRTIB procurements adhere to the FAR, unless doing so would be inconsistent with the Agency’s fiduciary obligations under Federal Employees’ Retirement System Act (FERSA). FRTIB has adopted the FAR as its primary contracting policy and procedures for procuring its goods and services.
The Thrift Federal Acquisition Supplement (T-FAS) specifies when the Agency’s policies and practices deviate from the FAR. See link to T-FAS below.
https://www.frtib.gov/Procurement/DoingBusiness.html Summary of Need
The Office of General Counsel (OGC) has identified a need to procure temporary legal support services to increase its capacity to advise the Executive Director, FRTIB Board Members, members of the ELC and Agency staff on legal matters affecting the Agency as defined in the Statement of Work. The Contractor shall provide expertise and legal advice on issues relating to the Agency’s Privacy Program and in addition shall provide general legal support to OGC on an as-needed basis. The legal support will primarily be for the Agency’s Privacy Program (particularly in years 1 and 2) but may also involve general legal support to OGC’s other practice areas which include Employee Benefits, Employee Relations, Ethics, Compliance, Federal Procurement, and FOIA.
FRTIB intends to award a five (5) year, single award, Indefinite-Delivery, Indefinite-Quantity (IDIQ) contract that allows for Labor Hour (LH) and Firm-Fixed Price (FFP) Delivery Orders
The FRTIB Office of General Counsel (OGC) provides advice and counsel to the Executive Director, FRTIB Board Members, members of the Executive Leadership Council (ELC), and Agency staff on legal matters affecting the Agency:
Privacy Office The Privacy Office is housed within OGC and provides advice on a wide-range of privacy-related laws, regulations, and guidance, including, but not limited to the Privacy Act; the Federal Information Security Management Act, as amended (FISMA); Section 208 of the E-Government Act; OMB Circulars and Memoranda; and guidance from the National Institute of Standards and Technology (NIST). The Privacy Office drafts, and administers policies and procedures on privacy-related matters; reviews privacy impact assessments (PIAs) for FRTIB systems; reviews and revises Agency-wide system of records notices (SORN); and provides advice on other privacy-related matters as needed.
General Legal Advice The General Counsel has overall responsibility for all legal matters affecting the Agency and provides advice and opinions on issues including compliance with FERSA, administrative law, ethics, equal employment opportunity (EEO), personnel matters, procurement, the Freedom of Information Act (FOIA), the Privacy Act, and other laws that could affect the FRTIB.
Litigation Support OGC represents the Agency in a variety of litigation matters. These matters vary from employee relations, government contract, administrative law, to employee benefits litigation. These matters may be heard before the Equal Employment Opportunity Commission (EEOC), Merit Systems Protection Board (MSPB), the D.C. Office of Administrative Hearings, the Government Accountability Office (GAO), or other courts of competent jurisdiction.
Scope To accomplish the objectives of this IDIQ contract, the Contractor shall provide a wide range of legal support encompassing automated services, litigation support, legal products and services, along with a variety of current technologies that help attorneys or other professional staff members acquire, organize, analyze, and present evidence in conducting a lawsuit or investigation for OGC.
Section B. Supplies or Services B1. Contract Line Item Number (CLIN) Structure The proposed duration of contract is for five years, inclusive of one base year period and (4) 12-month option year ordering periods. This RFP will result in a single award IDIQ contract, with one (1) - 12 Month Base Year and four (4) Option Years. The contract period of performance is not to exceed 60 months. The Government is obligated only to the extent of authorized task orders actually made under the IDIQ contract. Specific tasks and/or work to be performed, will be detailed in, and solicited by, individual task orders issued under this IDIQ contract.
Base Year Contract Line Item Numbers (CLINs)
| CLIN |
| Labor Category |
| Estimated Hours |
| Labor Rate |
| Price |
| 0001 |
| Program Manager |
| 100 |
| $ |
| $ |
| 0002 |
| Staff Attorney (Privacy) |
| 1440 |
| $ |
| $ |
| 0003 |
| Staff Attorney (General) |
| 1000 |
| $ |
| $ |
| 0004 |
| ODC/Material |
| $ |
| $ |
| BASE YEAR TOTAL |
| $ |
Option Year One (1) Contract Line Item Numbers (CLINs)
| CLIN |
| Labor Category |
| Estimated Hours |
| Rate |
| NTE Price |
| 1001 |
| Program Manager |
| 100 |
| $ |
| $ |
| 1002 |
| Staff Attorney (Privacy) |
| 1920 |
| $ |
| $ |
| 1003 |
| Staff Attorney (General) |
| 960 |
| $ |
| $ |
| 1004 |
| ODC/Material |
| $ |
| $ |
| $ |
OPTION YEAR 1 TOTAL
Option Year Two (2) Contract Line Item Numbers (CLINs)
| CLIN |
| Labor Category |
| Estimated Hours |
| Rate |
| NTE Price |
| 2001 |
| Program Manager |
| 100 |
| $ |
| $ |
| 2001 |
| Staff Attorney (Privacy) |
| 1920 |
| $ |
| $ |
| 2003 |
| Staff Attorney (General) |
| 960 |
| $ |
| $ |
| 2004 |
| ODC/Material |
| $ |
| $ |
| $ |
OPTION YEAR 2 TOTAL
Option Year Three (3) Contract Line Item Numbers (CLINs)
| CLIN |
| Labor Category |
| Estimated Hours |
| Rate |
| NTE Price |
| 3001 |
| Program Manager |
| 100 |
| $ |
| $ |
| 3002 |
| Staff Attorney (Privacy) |
| 1920 |
| $ |
| $ |
| 3003 |
| Staff Attorney (General) |
| 960 |
| $ |
| $ |
| 3004 |
| ODC/Material |
| $ |
| $ |
| $ |
OPTION YEAR 3 TOTAL
Option Year Four (4) Contract Line Item Numbers (CLINs)
| CLIN |
| Labor Category |
| Estimated Hours |
| Rate |
| NTE Price |
| 4001 |
| Program Manager |
| 100 |
| $ |
| $ |
| 4002 |
| Staff Attorney (Privacy) |
| 1920 |
| $ |
| $ |
| 4003 |
| Staff Attorney (General) |
| 960 |
| $ |
| $ |
| 4004 |
| ODC/Material |
| $ |
| $ |
| $ |
| OPTION YEAR 4 TOTAL |
| $ |
GRAND TOTAL
B2. Ordering The Agency may order legal services that are related to legal matters, areas, or issues identified in this Statement of Work. Task order RFPs will include specific task order requirements as well as response instructions and evaluation criteria.
The Contractor shall have the opportunity to provide a technical proposal as well as pricing for required services on a labor hour or firm fixed price basis, as required by individual task order requests for proposal. The Contractor shall have up to 5 days to respond to task order request for proposals. The Contractor’s hourly rate shall be at or below negotiated IDIQ contract pricing for the relevant IDIQ contract year. The hourly rate shall include all costs necessary to complete the work for which the price is established including indirect costs, fees, taxes and profit. Travel shall be proposed separately on a not-to-exceed basis for each task order requirement and must be billed in accordance with the Federal Travel Regulation (FTR), including itemization and receipts as appropriate. Contractor personnel may not bill for time spent travelling.
B3. Minimum and Maximum Quantities The Agency estimates the figures in the table below as the volume of purchases. The Agency is obligated only to the minimum value of the IDIQ contract and to the extent of additional authorized purchases actually made via task orders under the IDIQ.
IDIQ Contract
| Minimum Hours |
| Maximum Hours |
| 0 |
| 20,000 |
Section C: Statement of Work Description and Specifications C1. Services The Contractor shall provide expert legal support services on an as needed basis including:
C.1.1 Task 1 - Privacy Office The Contractor shall provide qualified attorneys with expertise in the aforementioned privacy laws and guidance. The attorneys assigned to this contract shall have experience in advising agency personnel on privacy-related matters, and should have experience in reviewing PIAs, SORNs, and in drafting privacy-related policies and procedures.
The Contractor attorneys shall provide expert legal consulting services on an as-needed basis including but not limited to the following tasks:
(a) Providing general consulting services to the Privacy Office on all privacy-related laws. No later than two (2) weeks after task order award, the Contractor shall meet with the Privacy Office staff and the COR to become familiar with the parameters of FRTIB’s privacy program and about ongoing initiatives for which the Contractor shall work;
(b) Providing advice and expertise regarding the Privacy Act, including reviewing and revising Privacy Act statements as necessary;
(c) Assisting the Privacy Office to draft relevant privacy policies and procedures;
(d) Working with the Privacy office and the FRTIB’s Information Assurance Division (IAD) within the Office of Technology Services (OTS) to develop and apply privacy controls for FRTIB systems, pursuant to NIST SP 800-53, Appendix J;
(e) Working with the Privacy Office and IAD, where necessary, to review privacy threshold analyses (PTA) and PIAs for FRTIB systems and provide comments/edits regarding the legal sufficiency of those documents;
(f) Assisting the Privacy Office to review and revise Agency-wide system of records notices (SORNs), Privacy Act regulations, and other relevant regulatory materials, as necessary;
(g) Assisting the Privacy Office to develop training materials for Agency employees and contractor personnel on relevant privacy laws;
(h) Performing legal research and drafting legal opinions on privacy-related laws, regulations, and guidance, including various statutes, regulations, OMB Memoranda, and NIST guidance, as requested;
(i) Working with the Privacy Office to create a dedicated privacy resources page for FRTIB employees;
(j) Assisting the Privacy Office to revise web-based policies, and to review third-party websites and applications to ensure compliance with applicable privacy requirements;
(k) Attending in-person meetings with Agency personnel, and attend Privacy Council meetings (comprised of inter-governmental agency officials) and provide applicable notes and relevant materials to the Privacy Office when requested;
(l) Updating the Privacy Office about changes to relevant privacy laws and guidance, as well and relevant news articles; and
(m) Assisting with the tracking of remediation of audit findings, where applicable.
C.1.2 Task 2 - General Legal Advice The Contractor shall provide legal services that may include the following:
(a) Performing relevant legal research and preparing formal memoranda regarding said research, as requested;
(b) Developing options and written recommendations as to how the Agency or OGC should respond to legal issues; and
(c) Providing advice and expertise to OGC personnel regarding administrative, employment, privacy, intellectual property, employee benefits, and procurement law.
C.1.3 Task 3 - Litigation Support The Contractor shall provide legal services that may include the following:
(a) Performing relevant legal research as requested;
(b) Developing options and written recommendations as to how OGC should proceed with respect to complaints and claims raised in litigation;
(c) Preparing and reviewing relevant documents and pleadings;
(d) Assisting OGC with negotiations;
(e) Providing advice and expertise regarding local trial practice;
(f) Conducting or assisting OGC in conducting discovery, including assistance in deposing witnesses, defending depositions (including witnesses from the Agency, opposing parties, or other third parties), reviewing and analyzing document production and other written discovery, and responding to requests for written discovery;
(g) Preparing and filing or assisting OGC in preparing and filing court documents;
(h) Preparing and presenting or assisting OGC in preparing and presenting testimony at trial, including preparation, examination, and cross-examination of witnesses;
(i) Recommending and retaining outside expert witnesses as subcontractors;
(j) Attending, with or without FRTIB representatives, all court proceedings, conferences, pre-trial hearings, trial, and post-trial conferences and matters;
(k) Handling or assisting OGC with handling any subsequent appeals; and
(l) Providing related services as instructed by OGC personnel.
C2. Non-Disclosure and Conflicts of Interest The Agency will ensure that all individuals assigned to performance service on this contract sign Non-Disclosure Agreements, and applicable Ethic Agreements prior to beginning work on the contract. (see Attachments 001 and 002)
C3. Performance Standards The COR shall evaluate the Contractor’s performance under this IDIQ contract in accordance with the Performance Matrix Summary provided in the table below.
The Agency reserves the right to seek agreement to change the performance measures and/or performance targets throughout the IDIQ contract performance period. FRTIB will provide the Contractor with 30 days’ notice of any proposed changes to the stated performance measures or targets via an official modification to the IDIQ contract issued by the Contracting Officer. The same expectation and latitude is afforded the contractors, to propose revisions to the performance standards. Revisions must be agreed to bilaterally before they become effective.
The Contractor will be evaluated periodically on the following criteria:
1. Quality of Work Performed
2. Timeliness of Work
| Required Services |
| Performance Standard |
| Accepted Quality Level |
| Monitoring Method |
Provide advice and counsel and assist the Chief Privacy Officer in ensuring the FRTIB’s compliance with the Privacy Act and all related laws, regulations, and applicable guidance.
Contractor Performance demonstrates that Contractor’s advice is sound, well-reasoned, well-researched and anticipates obstacles that may arise in the future. Contractor written work product is well-written, thorough, exceptionally clear and effective and in accordance with all applicable laws, regulations, guidance, and internal Agency policies.
No deviation from the Performance Standard.
All work product is provided by the deadlines agreed to between the COR and Contractor.
Feedback from OGC staff and management, on an ongoing basis.
Provide advice and counsel and assist OGC in responding to requests for legal review in the areas of federal ethics, federal procurement, compliance, FOIA, or employee relations.
Contractor performance demonstrates that Contractor’s advice is sound, well-reasoned, well-researched, and anticipates obstacles that may arise in the future. Contractor written work product is well-written, thorough, exceptionally clear and effective and in accordance with all applicable laws, regulations, guidance, and internal Agency policies.
No deviation from the Performance Standard.
All work product is provided by the deadlines agreed to between the COR and Contractor.
Feedback from OGC staff and management, on an ongoing basis.
Provide advice and counsel and assist OGC attorneys in representing FRTIB’s interests in matters involving intellectual property and responses to internal and external audit requests.
Contractor performance demonstrates that Contractor’s advice is sound, well-reasoned, well-researched, and anticipates obstacles that may arise in the future. Contractor written work product is well-written, thorough, exceptionally clear and effective and in accordance with all applicable laws, regulations, guidance, and internal Agency policies.
No deviation from the Performance Standard.
All work product is provided by the deadlines agreed to between the COR and
Feedback from OGC staff and management, on an ongoing basis.
Provide advice and counsel and assist OGC in responding to requests for legal review in the area of employee benefits.
Contractor performance demonstrates that Contractor’s advice is sound, well-reasoned, well-researched, and anticipates obstacles that may arise in the future. Contractor written work product is well-written, thorough, exceptionally clear and effective and in accordance with all applicable laws, regulations, guidance, and internal Agency policies.
No deviation from the Performance Standard.
All work product is provided by the deadlines agreed to between the COR and
Feedback from OGC staff and management, on an ongoing basis.
C4. Key Personnel The offeror shall provide and supervise the skilled personnel required for the effective and efficient performance of this contract. The following descriptions represent the minimum requirements:
· Program Manager:
· Description: Primary interface with Agency in managing the project.
· The proposed staffer must have a minimum of five years of experience, in project management or providing project management legal support to federal agencies. Excellent oral and written communication skills are required.
· Staff Attorney (Privacy):
· Description: Provides advice and counsel on matters pertaining to the Privacy Act, E-Government Act of 2002, the Federal Information Security Management Act, and all related amendments, statutes and regulations. Provides advice and counsel on guidance issued by authorities in the field of federal privacy, such as OMB, NIST, and DHS.
· The Contractor must have graduated from an accredited U.S. law school and be barred in any state, or the District of Columbia. The Contractor must have a minimum of 1-year experience with the Privacy Act, the E-Government Act of 2002, the Federal Information Security Management Act, and all related amendments, statutes, and regulations. The Contractor must also demonstrate experience with guidance issued by authorities in the field of federal privacy, such as OMB, NIST, and DHS. General experience includes excellent interpersonal, communication and client counseling skills.
· Staff Attorney (General Law):
· Description: Provides advice and counsel in the areas of federal ethics, federal procurement, employee benefits, federal sector employee relations, and/or FOIA.
· The Contractor must have graduated from an accredited U.S. law school and be barred in any state, or the District of Columbia. The Contractor must have a minimum of 2 years’ experience in the practice areas identified in the SOW.
Section D: Packaging and Marketing Not Applicable Section E: Inspections and Acceptance The basis for acceptance shall be in compliance with the requirements set forth in the award resulting from this RFP.
The Contracting Officer Representative (COR) will have the right to reject or require correction of any deficiencies found in deliverables. In the event of rejection of any deliverable, the Contractor will be notified in writing by the COR of the specific reasons the deliverable was rejected. If no comments from the COR are provided within 10 business days of receipt, the deliverable will be deemed to have been accepted by the Agency. Documents rejected by the FRTIB must be resubmitted with changes within 10 business days and the FRTIB will have another 10 business-day review period. If after the third submission the deliverable is unacceptable to FRTIB, the Program Manager, COR, and Contracting Officer will meet to discuss corrective actions.
Section F: Performance / Deliverables F1. Period of Performance The period of performance on this contract consists of a 12-month base period and four (4) 12-month option periods. The total period of performance on this contract shall not exceed 60 months.
· Base Period – Twelve (12) months from contract award
· Option Period 1 – Twelve (12) months from the end of Base Period
· Option Period 2 – Twelve (12) months from the end of Option Period 1
· Option Period 3 – Twelve (12) months from the end of Option Period 2
· Option Period 4 – Twelve (12) months from the end of Option Period 3 F2. Contract Performance Location These services are to be performed at the Contractors facilities as well as at the offices of the FRTIB, located at 77 K Street, NE, Suite 1000, Washington, DC 20002. Telework must be approved by the COR.
F3. Deliverables
| Deliverable |
| Due Date/Occurrence |
| Format/Distribution |
| Kick-Off Meeting |
| Within 2 weeks of Contract Award |
| One-time occurrence in person or via teleconference |
| Agency meetings |
| As needed |
| In-person or via teleconference |
| Monthly Progress Report |
| On the 5th of each month |
F3.1 Deliverables for Task Order Deliverables will be defined for each Task Order. All deliverables must be submitted in a format approved by the Contracting Officer’s Representative (COR), to the COR and the CO.
F3.2 Monthly Progress Report Electronic copies of Monthly Progress Reports are due by the fifth of each month and shall outline the prior month’s activity for all months in which there was activity. The Contractor shall provide the COR and the CO with an itemized listing of overall contract and task status.
The progress report must cover all work performed and completed during the month for which the progress report is provided. Additionally, the report shall include:
(a) Status of the work in progress, noting all significant milestones with projected or actual completion dates, and a brief narrative regarding the status of each activity.
(b) Summary of the work to be performed during the subsequent month.
(c) Identification of any problems encountered or still outstanding, with an explanation of the cause and an overview of the planned resolution or a statement of how the problem will be resolved.
(d) Listing of funds expended (i.e., invoiced), and funds remaining and cost performance (actual versus planned) details, by month, and cumulatively on a per task basis.
(e) Staffing status updates, if changes occur or are anticipated.
F3.3 Government Furnished equipment (GFE)/ Government Furnished Information (GFI) FRTIB intends to provide GFE and GFI to the contractor awarded the IDIQ contract. The GFE provided includes: laptops, desk, phone, building badges, and Personal Identification Verification (PIV) cards. The GFI is accessible through Agency IT systems. Contractor employees to receive GFE and GFI must receive favorable adjudication of a background check, read and sign a FRTIB Rules of Behavior (RoB) (Attachment 003), and complete necessary cyber awareness training and if applicable records management training and privacy training.
Contractors upon receiving GFE must track all the equipment received by the Contractor’s employees to ensure all inventory is returned upon an employee’s departure or upon conclusion of the BPA. The GFE tracking requirement is applicable to any subcontractor or teaming partners of the Contractor.
Section G: Contract Administration Data G1. Contracting Officer (CO) Responsibility for contracting activities rests solely with the Agency’s CO. No conversation, recommendations, or direction, whether given directly by, or implied by Agency personnel, that will affect the scope, schedule, or price of the program, shall be acted upon by the Contractor unless specifically approved by the Agency CO. In the event that the Contractor implements changes to the contract at the direction of any person other than the CO, the Contractor will not receive reimbursement for the work performed pursuant to those unauthorized changes. Contractual interpretation and assistance may be obtained by contacting the CO.
G1.1 Contracting Officer Contact Information Name: Denise Roberts-Maynard Phone Number: 202.864.8771 or 202.841.7795 (cell) Email Address: Denise.Roberts-Maynard@FRTIB.gov G2. Contracting Officer Representative (COR) The CO shall designate a COR, who is responsible for administering the performance of work under this contract by:
(1) Monitoring the Offeror’s progress
(2) Assessing performance
(3) Recommending to the CO changes in requirements
(4) Interpreting the scope of work
(5) Performing inspections and acceptances of data items required by this order, and
(6) Assisting the Offeror in the resolution of technical problems encountered during the performance of the contract.
G2.1 Contracting Officer Representative Contact Information
| Name: TBD | ||
| Phone: TBD | ||
| Email: TBD | ||
| G3. | Electronic Invoicing and Payment Requirements – Invoice Processing Platform (IPP) |
Payment request must be submitted electronically through the U.S. Department of Treasury’s Invoice Processing Platform (IPP) system using the “Bill to Agency” of Interior Business Center – FMD. “Payment request” means any request for contract financing payment or invoice payment by the Contractor. Any changes to submitted invoice (short‐pay or withhold) will require resubmission of invoice with revised amount. To constitute a proper invoice, the payment request must comply with the requirements identified in the applicable Prompt Payment clause included in the contract, or the clause 52.212‐4 Contract Terms and Conditions – Commercial Items include in commercial item contracts. The IPP website address is: https://www.ipp.gov.
The Contractor must use the IPP website to register, access and use IPP for submitting requests for payment. The Contractor must attach invoices in IPP. The Contractor Government Business Point of Contact (as listed in SAM) will receive enrollment instructions via email from the Federal Reserve prior to the contract award date, but no more than 3 – 5 business days of the contract award date.
Contractor assistance with enrollment can be obtained by contacting the IPP Production Helpdesk via email IPPCustomerSupport@fiscal.treasury.gov or phone (866) 973-3131.
If the Contractor is unable to comply with the requirements to use IPP for submitting invoices for payment, the Contractor must submit a waiver request in writing to the Contracting Officer with its proposal or quotation.
G4. Oracle Supplier Request Form All contractors who have not previously provided the “Oracle Supplier Request Form” (Attachment 004) to the FRTIB must fill in the highlighted items on the form and submit it to the Contracting Officer within 3 business days after Contract Award.
G5. FRTIB Hours and Legal Holidays Normal business hours for FRTIB personnel are 8:00 AM to 5:00 PM Eastern Standard Time, Monday through Friday, excluding Federal holidays and official Federal Government closures in the Metropolitan DC area. The following Federal holidays are observed by the FRTIB:
| Holiday |
| Date |
| New Year’s Day |
| January 1 |
| Inauguration Day – National Capital Region only |
| January 20, as observed |
| Martin Luther King’s Birthday |
| Third Monday in January |
| President’s Day |
| Third Monday in February |
| Memorial Day |
| Last Monday in May |
| Juneteenth |
| June 19, as observed |
| Independence Day |
| July 4, as observed |
| Labor Day |
| First Monday in September |
| Columbus Day |
| Second Monday in October |
| Veteran’s Day |
| November 11, as observed |
| Thanksgiving Day |
| Fourth Thursday in November |
| Christmas Day |
| December 25 |
Section H: Special Contract Requirements
H.1 Safeguarding Controlled Unclassified Information (CUI)
(a) Definitions. As used in this clause— “Adequate security” means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
“Covered contractor information system” means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits Controlled Unclassified Information.
“Controlled Unclassified Information” means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is—
(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of FRTIB in support of the performance of the contract; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contract.
“Computer software” means computer programs, source code, source code listings, object code listings, design details, algorithms, processes, flow charts, formulae and related material that would enable the software to be reproduced, recreated, or recompiled. Computer software does not include computer data bases or computer software documentation.
“Information system” means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
“Technical information” means technical data or computer software, as those terms are defined in this clauses--Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
“Technical data” means recorded information, regardless of the form or method of the recording, of a scientific or technical nature (including computer software documentation). The term does not include computer software or data incidental to contract administration, such as financial and/or management information.
(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:
(1) For covered contractor information systems that are part of and Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:
(i) Cloud computing services shall be subject to the security requirements specified in the Cloud Computing Services clause of this contract.
(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.
(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:
(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final) in effect at the time the solicitation is issued or as authorized by the Contracting Officer.
(ii)
(A) The Contractor shall notify the FRTIB Chief Information Security Officer (CISO), via email, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.
(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the FRTIB Chief Technology Officer (CTO) or CISO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the FRTIB CTO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place. FRTIB acknowledges its understanding and acceptance of the variance that at the time of the execution of this contract the Contractor does not provide insider threat training but will use good faith efforts to put such training in place.
(C) If the FRTIB CTO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.
(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/resources/documents/) and that the cloud service provider complies with requirements in the clause for Cyber Incident Reporting, including malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures. These measures may be addressed in a system security plan.
(c) The contractor shall provide access to the Contractor’s facilities, personnel and information system documentation for the purposes of audit or inspection by an authorized regulator or designated security certification activity to ensure appropriate information security practices are in place.
(d) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(e) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor’s responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(f) Subcontracts. The Contractor shall—
(1) Include this clause, including this paragraph, in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve Controlled Unclassified Information, including subcontracts for commercial items, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as Controlled Unclassified Information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and
(2) Require subcontractors to notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause.
(End of Clause)
H.2 Compliance with Controls for Safeguarding Controlled Unclassified Information (CUI)
(a) Definitions. As used in this provision—
“Controlled Unclassified Information (CUI),” “covered contractor information system,” “cyber incident,” “information system,” and “technical information” are defined in clause H.1, Safeguarding Controlled Unclassified Information (CUI) and H.6, Cyber Incident Reporting.
(b) The security requirements required by contract clause H.2, Safeguarding Controlled Unclassified Information (CUI) and Cyber Incident Reporting, shall be implemented for all Controlled Unclassified Information (CUI) on all covered contractor information systems that support the performance of this contract.
(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see (b)(2) of clause H.1, Safeguarding Controlled Unclassified Information (CUI) and H.6 - Cyber Incident Reporting.
(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see http://dx.doi.org/10.6028/NIST.SP.800-171) that are in effect at the time the solicitation is issued or as authorized by the contracting officer.
(2) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the CISO, a written explanation of —
(i) Why a particular security requirement is not applicable; or
(ii) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.
(3) An authorized representative of the FRTIB CISO or Security Division will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.
(End of Clause)
H.3 RESERVED
H.4 RESERVED
H.5 RESERVED
H.6 Cyber Incident Reporting
(a) Definitions. As used in this clause—
“Breach” means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. A Breach is also considered an incident.
“Compromise” means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
“Computer software” means computer programs, source code, source code listings, object code listings, design details, algorithms, processes, flow charts, formulae and related material that would enable the software to be reproduced, recreated, or recompiled. Computer software does not include computer data bases or computer software documentation.
“Cyber incident” means an incident occurring through the use of computer networks that result in an actual or potentially adverse effect on an information system and/or the information residing therein.
“Forensic analysis” means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
“Incident” means an occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of FRTIB’s information or an FRTIB information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies with respect to FRTIB’s information or an FRTIB information system.
“Malicious software” means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
“Media” means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which controlled unclassified Information is recorded, stored, or printed within a covered contractor information system.
“Information system” means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
“Rapidly report” means within one (1) hour of first becoming aware of an incident or a Breach or within one (1) hour of determining with reasonable certainty that there has been an incident or a Breach involving FRTIB data."
(b) Cyber incident reporting requirement.
(1) When the Contractor discovers a cyber incident or breach that affects a covered contractor information system or the controlled unclassified information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall—
(i) Rapidly report cyber incidents to FRTIB at IncidentResponse@tsp.gov; and
(ii) Require training for contractors and subcontractors on how to identify and report an incident or breach;
(iii) Conduct a review for evidence of compromise of Controlled Unclassified Information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts, in identifying what information was or may have been accessed and by whom, creating timelines of user activity, determining methods and techniques used to access federal information, and identifying the attack vector. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident or breach, as well as other information systems on the Contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised Controlled Unclassified Information, or that affect the Contractor’s ability to provide operationally critical support.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for FRTIB and shall include, at a minimum, the required elements in accordance with FRTIB Cyber Incident Response Policy and Procedures.
(c) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to FRTIB CIO in accordance with instructions provided by the Contracting Officer. Do not send the malicious software to the Contracting Officer.
(d) Media preservation and protection. When a Contractor discovers a cyber incident or breach has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (b)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow FRTIB to request the media or decline interest.
(e) Cyber incident damage assessment activities. The Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.
(f) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(g) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor’s responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(h) Subcontracts. The Contractor shall—
(1) Include this clause, including this paragraph, in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve Controlled Unclassified Information, including subcontracts for commercial items, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as Controlled Unclassified Information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and
(2) Require subcontractors to provide the incident report number assigned by the Security Operations Center or Computer Security Incident Response Team (CSIRT), to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber-incident to FRTIB as required in paragraph (b) of this clause.
(End of Clause)
H.7 RESERVED
H.8 Recordkeeping & Proprietary Information
(a) Definitions. As used in this clause— “Contractor attributional/proprietary information” means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
(b) The Contractor agrees that the following conditions apply to any information it receives or creates in the performance of this contract:
(1) The Contractor shall protect the information against unauthorized access, modification, release, or disclosure.
(2) The Contractor shall ensure that its employees are subject to use and non-disclosure obligations consistent with this clause prior to the employees being provided access to or use of the information.
(3) All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take FRTIB provided Controlled Unclassified Information training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.
(c) If contractor’s performance of services results in a Breach of FRTIB data, as defined in Section H.1, the Contractor shall bear the losses and expenses (including attorneys’ fees) associated with the breach including costs associated with (1) providing notice of the breach to affected individuals and to applicable regulatory bodies; (2) establishing call centers for affected individuals; and (3) providing individuals with credit and identity monitoring and credit and identity restoration services on an opt-in basis. The necessary remediation measures will be determined by FRTIB in accordance with FRTIB’s Breach Response policy and procedures.
(d) FRTIB safeguarding and use of contractor attributional/proprietary information.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .