BPA PWS Winter Loader Rentals_final.pdf
PDF 228 KB Posted
- Attached to
- Winter Loader Rental Blanket Purchase Agreement Federal contract opportunity
- Solicitation number
- W51AA1BPA
- Issued by
- Department of the Army
About this file
This document is a Performance Work Statement (PWS) for a Blanket Purchase Agreement (BPA) to provide rental of one Case 921 Wheeled Front Enter Loader and three Case 821 Wheeled Front Enter Loaders with 5-yard buckets to support operations at Tobyhanna Army Depot. The rental period is for up to 5 years, with one 6-month requirement anticipated per year. The loaders must be no more than 3 years old and include quick detach buckets, ride control, and backup cameras. The contractor must provide all necessary personnel, equipment, transportation, and supervision to deliver and pick up the loaders at the specified location. Key requirements include contractor employee training, security procedures, and OPSEC countermeasures. The related federal contract opportunity is a solicitation for this BPA, with responses due by August 23, 2024.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Request for Information BPA_Winter loader rental.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Winter Loader Rental Blanket Purchase Agreement (BPA)
Performance Work Statement (PWS)
1. General: This Winter Loader BPA Master Agreement is to provide one (1) Case 921 Wheeled Front Enter Loader and three (3) Case 821 Wheeled Front Enter Loaders with a 5-yard bucket capacity or equivalent to be rented by
Tobyhanna Army Depot. All loaders should not be more than 3 years old, have quick detach buckets, ride control and back up cameras. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the
Contractor who, in turn is responsible to the Government.
1.1 Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation. tools, materials, supervision and other items and non-personal services necessary to perform the delivery of one Case 921 Wheeled Front Enter Loader and 3 Case 821 Wheeled Front Enter Loaders with a 5-yard bucket capacity or equivalent as defined in the PWS except for those items specified as government furnished property and services. The contractor shall perform to the standards in this BPA Master Agreement.
1.2 Objectives: The rental services described in this PWS will keep the depot running to its optimal level so that all workload requirements can be met by the Government.
1.3 Scope: Rental of one Case 921 Wheeled Front Enter Loader and 3 Case 821 Wheeled Front Enter Loaders with a 5-yard bucket capacity or equivalent.
1.3.1 Rental of the one Case 921 Wheeled Front Enter Loader and 3 Case 821 Wheeled Front Enter Loaders with a
5-yard bucket capacity or equivalent will include the delivery and pick up of the loaders to Bldg. 15, Motor Pool at
Tobyhanna Army Depot.
1.4 Period of Performance: The period of performance for this BPA will not exceed 5 years after date of BPA
Master Agreement. It is anticipated that there will be 1 requirement per year with a period of performance of six months (i.e. October 15- April 15).
1.5 Other General Information
1.5.1 The contractor will not be required to perform services on the following holidays: New Year's Day Labor Day
Martin Luther King Jr.'s Birthday Columbus Day
President's Day Veteran's Day
Memorial Day Thanksgiving Day
Independence Day Christmas Day
1.5.2 Hours of Operation: The contractor is responsible for conducting business between the hours of 0700 and
1530 Monday thru Friday except for Federal holidays or when the government facility is closed due to local or national emergencies, administrative closings or similar government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within the PWS when the government facility is not closed for the above reasons.
1.5.3 Place of Performance: The rentals to be delivered under this contract will be delivered to Tobyhanna Anny
Depot, Building 15.
POC is Bernadette Girgenti (570)615-9413.
SEC OPS
All TYAD contracts and other acquisition-related documents must ensure privacy and security controls follow the information, and that contractors and service providers protect Privacy Act information in the same way the organization adhering to the Federal Acquisition Regulations (FAR) Privacy Act provisions (Subparts 24.1 and
24.2) and include the specified contract clauses (Parts 52.224-1 and 52.224-2), as appropriate, to ensure that personal information is protected as mandated.
In addition to the changes authorized by the clause of this contract; should Force Protection Condition (FPCON) at the installation change, the Government may require changes in contractor security matters and/or processes.
FPCON impact on work levels.
Current FPCON: Bravo
FPCON Charlie: Applies when a hostile incident occurs within the CDR’s area of interest (AOI), or intel is received indicating a hostile act or targeting against DoD elements, PAX, or facilities is likely.
FPCON Delta: Applies when a terrorist attack or hostile act has occurred or is anticipated against specific installations or operating areas.
1. __X___ During FPCONs Charlie and Delta, All services are discontinued. All services will resume when the FPCON level is reduced to level Bravo or lower.
2. _____This contract and its employees are considered mission essential. Therefore, all contractor employees are required to report for duty and remain on duty during declared emergencies and/or elevated FPCON levels unless otherwise directed by the contacting officer via the appropriate COR.
Unscheduled gate closures by the Security Police may occur at any time causing all personnel entering or exiting a closed installation to experience a delay. This cannot be predicted or prevented. Contractors are not compensated for unexpected closures or delays.
Vehicles operated by contractor personnel are subject to search pursuant to applicable regulations. Any moving violation of any applicable motor vehicle regulation may result in the termination of the contractor employee’s installation driving privileges.
The contractor’s employees shall become familiar with and obey the regulations of the installation; including fire, traffic, safety and security regulations while on the installation. Contractor employees should only enter restricted areas when required to do so and only upon prior approval. All contractor employees shall carry proper identification with them at all times. The contractor shall ensure compliance with all regulations and orders of the installation which may affect performance.
(If Required) The contractor shall provide support during contingencies, exercises, heightened operations, and adverse weather or security closures in the accomplishment of performance requirements. From time to time, the
Base Commander may decide to close all or part of a base in response to an unforeseen emergency or similar occurrence. Such emergencies include adverse weather such as snow, or ice, "an act of God,” such as tornado or earthquake, or a base disaster such as a gas leak or fire.
Emergency Communications and Services.
If assigned to TYAD for seven-days or longer, contractors will enroll in the ALERT! Mass Warning Notification
System (MWNS) at https://alertservices.csd.disa.mil/.
Alert! MWNS is NOT optional - it is a Headquarters Department of the Army (HQDA) requirement to be a registered user.
Due to the life-safety implications of the information being relayed and the requirement to provide immediate alerts and warnings, personnel assigned to TYAD must ensure that their personal contact information, including after-duty hours contact information, as appropriate (e.g., personal cellular phone numbers or landline phone numbers), e-mail addresses, home address, etc., are entered into the system and regularly updated or verified every 90 days to remain current and accurate.
• A Common Access Card (CAC) is required to register for ALERT!
• If a CAC has not been deemed necessary for the contractor (see below paragraph: Common Access Card
(CAC), COR will send the following information to usarmy.tyad.tyad.mbx.secops-at@army.mil to manually input personnel data into ALERT!
https://usg01.safelinks.protection.office365.us/?url=https%3A%2F%2Falertservices.csd.disa.mil%2F&data=05%7C02%7Claura.l.mulrooney.civ%40army.mil%7C73b946e509c9422bb19c08dc2d608869%7Cfae6d70f954b481192b60530d6f84c43%7C0%7C0%7C638435139818984692%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=PJ4RKmcoiR9WhaAPRYf0PSx61qOIYMxQF2NUrxa53dM%3D&reserved=0 mailto:usarmy.tyad.tyad.mbx.secops-at@army.mil
• Full Name
• Cell Phone
• Is SMS ok for alerts? Yes or No
• Contractor: For what Cost Center
• Name of COR
• Expected length of contract
In the event of a life-threatening emergency or natural disaster, COR will account for assigned contractors. COR will send personnel accountability report to Emergency Operations Center (EOC).
Base closure announcements will be disseminated via ALERT! MWNS.
Antiterrorism (AT) Level I Training. All contractor employees, to include subcontractor employees, requiring access to Army installations, facilities, and controlled access areas shall complete AT Level I awareness training prior to contract report date. This training is required for any additional or new contractor employees, who start after that period. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/POC within 10 calendar days after completion of training by all employees and subcontractor personnel. AT level I awareness training is available at the following website: https://jko.jten.mil course# JS-US007 for their training. Completion of contractor employee training will be documented on ELTY form
583, TYAD On-Post Training Record, or contractor equivalent. As applicable, contractor employees must complete annual AT awareness training as it pertains the length of the contract.
iWATCH Army Training. This locally developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 calendar days of contract award and within 30 calendar days of new employees commencing performance with the results reported to the COR NLT 60 calendar days after contract award. Contractors and all associated sub-contractors will be briefed by the TYAD Antiterrorism/Force Protection officer. It is recommended this training be conducted as part of an initial entry briefing or unit/organization newcomer’s briefings. Send training requests to usarmy.tyad.tyad.mbx.secops-at@army.mil, completion of contractor employee training will be documented on ELTY form 583, TYAD On-Post Training Record or contractor equivalent.
Access and General Protection/Security Policy and Procedures. Contractor and all associated sub-contractor employees shall comply with applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative). The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by TYAD
Law Enforcement. Contractor workforce must comply with all personal identity verification requirements as directed by DoD, HQDA, and/or local policy.
Contractor and all associated sub-contractor employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening
Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by the government representative), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.
A background check and approval from Tobyhanna Army Depot (TYAD) Law Enforcement is required for all contractor and subcontractor personnel prior to on-site access at TYAD. All persons seeking entrance to TYAD shall submit to and comply with all security standards and requirements in force at the time such persons are seeking entry. All contractors, regardless of resident status or citizenship, will be subject to vehicle search and intense in-processing by TYAD security personnel prior to being granted access to TYAD. This security screening process may be time consuming, and access may be delayed or denied. The contractor shall ensure ELTY Form 648-C is completed for all contractor and subcontractor personnel requiring depot access to include warranty services. The
TYAD point of contact (POC) will provide ELTY Form 648-C, “Request Access to Tobyhanna Army Depot” to the contractor/vendor at least ten days prior to the expected visit date for completion. The contractor/vendor shall return the completed ELTY Form 648-C to the TYAD POC in a timely manner so the same may be submitted to Security for processing no later than seven days prior to the visit. All the required fields on the form shall be complete and accurate by the contractor/vendor for timely processing. This requirement is inclusive of on-site supervisory or managerial personnel and sub-contractor personnel that the contractor anticipates will be performing work or visiting on-site. This security screening does not relieve the contractor of any responsibilities to conduct thorough pre-employment background checks and drug screening. Contractor workers will not be granted access to the work site until security screening is completed and access is approved. Any contractor personnel on-site who fail screening will not be permitted further access to TYAD.
https://jko.jten.mil/ mailto:usarmy.tyad.tyad.mbx.secops-at@army.mil
Submit the completed ELTY Forms 648-C form(s) to the COR or POC. Ensure contracts include the provisions that check for the possibility of and prevent undocumented workers for inclusion in contracted work related to Army missions.
The company will ensure that its employees entering Army-controlled installations or facilities have obtained access badges and passes in accordance with facility regulations and that these badges and passes are obtained in advance so as not to delay the accomplishment of contracted services.
Common Access Card (CAC): [If applicable.] Before CAC issuance, the contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation in accordance with Army Directive 2014-05. The contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled
NACI at the Office of Personnel Management.
Contractors shall be identified with Government issued identification card (e.g., Common Access Card (CAC) or unit specified identification card). When required, contractor personnel shall comply with local security policies to wear their identification card in a standardized manner, clearly visible attached to the torso of the exterior garment above the belt and below the shoulders except when in use (i.e., inserted in a computer CAC reader) or when in controlled areas requiring other credentials as the primary method of identification. To access any Government base and certain facilities, the contractor shall present required identification card upon demand. Upon exit from
Government facilities, the contractor shall conceal their credentials (CAC or other credentials) from plain view. The contractor and Contractor Security Manager/Officer shall coordinate with the COR for Government credential issues.
For contractors that do not require CAC, but require access to a DoD facility or installation: Contractor and all associated subcontractor employees shall comply with adjudication standards and procedures using the National
Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (Army
Directive 2014-05/AR 190-13); applicable installation, facility and area commander installation and facility access and local security policies and procedures (provided by Government representative); or, at OCONUS locations, in accordance with status-of-forces agreements and other theater regulations.
Collection of Badges: The Contractor shall account for all forms of Government-provided identification issued to the Contractor employees in connection with performance under this contract. The Contractor shall return such identification to the issuing agency at the earliest of any of the following, unless otherwise determined by the
Government:
(1) When no longer needed for contract performance.
(2) Upon completion of the Contractor employee’s employment.
(3) Upon contract completion or termination.
The Contracting Officer may delay final payment under a contract if the Contractor fails to comply with these requirements. The Contractor shall insert the substance of this clause, including this paragraph, in all subcontracts when the subcontractor’s employees are required to have routine physical access to a federally controlled facility and/or routine access to a federally controlled information system. It shall be the responsibility of the prime
Contractor to return such identification to the issuing agency in accordance with the terms set forth in of this section, unless otherwise approved in writing by the Contracting Officer. The company will return all issued U.S.
Government Common Access Cards, installation badges, and/or access passes to the COR when the contract is completed or when a contractor employee no longer requires access to the installation or facility. Contractor personnel will obtain a vehicle pass for access to the military installation and Common Access Cards (CAC) for computer access, if applicable.
Security Clearances. [If applicable.] Performance of work will require access to classified information or equipment IAW the DD Form 254, Contract Security Classification Specification, provided as an attachment.
Contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires contractors to comply with— (1) The Security
Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-
M); (2) any revisions to DOD 5220.22-M, notice of which has been furnished to the contractor. If subsequent to the date of this contract, the security classification or security requirements under this contract are changed by the
Government and if the changes cause an increase or decrease in security costs or otherwise affect any other term or condition of this contract, the contract shall be subject to an equitable adjustment as if the changes were directed under the Changes clause of this contract.
The Contractor agrees to insert terms that conform substantially to the language of this clause but excluding any reference to the Changes clause of this contract, in all subcontracts under this contract that involve access to classified information. Contractor personnel performing IT sensitive duties are subject to investigative and assignment requirements IAW AR 25-2, AR 380-67, DoD 8570.0 and affiliated regulations. Army regulation available at www.apd.army.mil.
Threat Awareness and Reporting Program (TARP). [If applicable.] For all contractors with security clearances, per AR 381-12, TARP contractor employees must receive initial and annual TARP training by a CI Agent or other trainer as specified.
Insider Threat Program. The contractor will establish and maintain an insider threat program to gather, integrate, and report relevant and available information indicative of a potential or actual insider threat, consistent with E.O.
13587 and Presidential Memorandum “National Insider Threat Policy and Minimum Standards for Executive
Branch Insider Threat Programs.”
Operations Security (OPSEC). OPSEC shall be considered across the entire spectrum of DoD missions, functions, programs, and activities. OPSEC is applicable to all personnel, missions, and supporting activities on a daily basis.
For OPSEC to be effective, all Army personnel (Soldiers, Family members, DA civilians, and contractors) must be aware of OPSEC and understand how it compliments traditional security programs. OPSEC principles and tactics protect not just organizations, but also individuals, their families, and other loved ones.
Personnel who knowingly, willfully, or negligently fail to protect critical information from unauthorized disclosure may be subject to administrative, disciplinary, contractual, or criminal action.
OPSEC awareness and execution is crucial to Army Success. The risk of exposure to critical or classified information is mitigated by providing OPSEC training.
Contracts that Require an OPSEC Standing Operating Procedure/Plan. [If applicable.] The contractor shall develop an OPSEC Standing Operating Procedure (SOP) or OPSEC Plan within 90 calendar days of contract award, to be reviewed and approved by the responsible Government OPSEC officer, per AR 530-1, Operations Security. This SOP/Plan will include the organization’s critical information, why it needs to be protected, where it is located, who is responsible for it, and how to protect it. In addition, the contractor shall identify an individual who will be an OPSEC Coordinator. The contractor will ensure this individual becomes
OPSEC Level II certified as per AR 530-1.
Operations Security Training. In accordance with AR 530-1, Operations Security, (4-2-a) OPSEC Level I certification training. The target audience for Level I is all personnel (which includes Soldiers, civilians, and contractors). Level I training is composed of both initial and continual (annual) awareness training.
(1) Initial OPSEC awareness training. All newly assigned personnel within the first 30 days of arrival in the organization (this includes accessions and initial entry programs) must receive initial training. It is recommended this training be conducted as part of an initial entry briefing or unit/organization newcomer’s briefings. This training is provided by TYADs OPSEC officer and can be conducted via distance learning, providing all necessary objectives are met.
Initial training focuses on TYAD-specific critical information and countermeasures. Contractors must contact
TYADs OPSEC Officer to schedule OPSEC Level I Initial training. Initial training may not be “read and initial”.
(2) Continuous (annual) OPSEC awareness training. OPSEC awareness training must be continually provided to the workforce, reemphasizing the importance of sound OPSEC practices.
OPSEC Level I Continuous (annual) training is available at the following website:
https://securityawareness.usalearning.gov/opsec/index.htm
The contractor shall submit OPSEC Level I Continual (annual) certificates of completion for each affected contractor employee and subcontractor employee, to the COR within 10 calendar days after completion of training. Completion of training will be documented on ELTY 583, TYAD On-Post Training Record or contractor equivalent.
OPSEC Countermeasures. The specific OPSEC countermeasures that follow are intended to eliminate or mitigate vulnerabilities. Complying with established security policies and procedures also supports the overall OPSEC https://securityawareness.usalearning.gov/opsec/index.htm objective. All personnel (Soldiers, civilians, and contractors) at every level are required to protected critical information that could potentially be exploited by adversaries. The following OPSEC countermeasures support the protection of critical information identified in TYADs OPSEC Level I training, TYADs Critical Information List, and they are required to be implemented by everyone in all day-to-day activities.
1. Complete mandatory training, practice OPSEC, and implement TYAD OPSEC countermeasures to protect critical information (CI) and other sensitive unclassified information in the execution of military operations performed or supported by the contractor in support of the mission. Protection of CI will include the adherence to and execution of countermeasures which the contractor initiates or as provided by TYAD, for CI on or related to the
SOW/PWS.
2. Contractor personnel shall not discuss government operations in public or over unprotected or unencrypted communications. Official business and controlled unclassified information (CUI) may only be transmitted as directed in the SOW/PWS. CUI must be marked and protected according to DoD and TYAD regulations. Do not take CUI off the installation.
3. Because observation of events, operations, physical changes, etc. may reveal National Security information, specific restrictions are needed to preclude unintentional release of this information to unauthorized parties.
(Unauthorized disclosure and transfer of National Security Information is punishable under 18 USC § 793.)
Therefore, contractor personnel shall not disclose to unauthorized third parties, post to company websites, unofficial sites, publications, newsletters, or other media (including Social Networking sites) any images, data or information, or observed events that reveal critical/sensitive government information about operations, personnel, equipment, including, but not limited to: tactics, techniques and procedures, production or work schedules, any visible or concealed modifications, upgrades, additions to vessels, aircraft, or weapons or equipment; increases, change, or decreases in work/deployment frequency or government personnel, vehicle, vessel or aircraft movements;
specialized equipment orders, deliveries, shipments, etc.,
a. A documented OPSEC reviews will be conducted of all information prior to being released to the public regardless of format. OPSEC Reviews must be completed and documented by an OPSEC Level II certified individual.
b. When in doubt, company press releases related to this contract should be coordinated through the
Contracting Officer Representative (COR) or Technical Point of Contact, as applicable.
4. Unauthorized disclosures and attempts to solicit classified or critical information by unauthorized third parties or others not affiliated with this contract shall be reported to the TYADs Security Operations Branch, TYADs Law
Enforcement Branch, contract point of contact, and your company Facility Security Officer and/or the Defense
Security Service. Non-Disclosure requirements remain in effect during the duration of this contract and indefinitely thereafter.
5. Government issued badges, identification shall be removed and/or concealed from plain sight when off station and shall not be left in vehicles or unprotected. Badges and passes may not be duplicated or copied or loaned to others. Lost or stolen identification badges, vehicle passes etc. will be immediately reported to the installation
Security Office.
6. It is strongly recommended the contractor mark and protect related internal production schedules, deliverables, inventories, shortages, and identified vulnerabilities related to production of government material.
Internal company markings e.g., Business Sensitive, etc., are appropriate for identifying the aforementioned as sensitive information. Specific Government-provided information, drawings etc., will be protected in accordance with guidance in applicable paragraphs of the SOW.
7. All government information must be properly destroyed at contract termination or returned to the government at the government’s discretion.
Information Security (INFOSEC)
Contractor personnel must comply with local security requirements for entry and exit control for personnel and property at the Government leased facility or any Government facility where work is being performed.
Contractor employees will be required to comply with all Government security regulations and requirements. Initial and periodic security training and briefings will be required. Failure to comply with security requirements can cause for removal and the Contractor will not be permitted to provide service on this contract.
The Contractor shall not divulge any information about DoD files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the
Government leased facility or any other Government facilities were work is being performed. Identification shall be worn and displayed as required.
COMSEC/IT Security. All communications with DOD organizations are subject to communications security
(COMSEC) review. All telephone communications networks are continually subject to intercept by unfriendly intelligence organizations. DOD has authorized the military departments to conduct COMSEC monitoring and recording of telephone calls originating from, or terminating at, DOD organizations. Therefore, the contractor is advised that any time contractor place or receive a call they are subject to COMSEC procedures. The contractor shall ensure wide and frequent dissemination of the above information to all employees dealing with DOD information. The contractor shall abide by all Government regulations concerning the authorized use of the
Government's computer network, including the restriction against using the network to recruit Government personnel or advertise job openings.
Safeguarding Controlled Unclassified Information (CUI)
CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI. 32 CFR 2002.4(aa) as implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re- using, and disposing of the information.” 81
Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. Marked appropriately;
b. Disclosed to authorized personnel on a “Need-To-Know” basis;
c. Protected in accordance with NIST SP 800-53, Rev. 4 Security and Privacy controls for Federal
Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information
Systems and Organizations if handled by internal Contractor system; and
d. Returned to TYAD control, destroyed when no longer needed, or held until otherwise directed. Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media
Sanitization.
Safeguarding Sensitive Information: For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with FISMA by securing it with a FIPS
140-2 validated solution.
Confidentiality, Integrity, Availability, and Nondisclosure of Information: Any information provided to the contractor (and/or any subcontractor) by TYAD or collected by the contractor on behalf of TYAD shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The contractor assumes responsibility for protection of the confidentiality, integrity, and availability of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the contractor. Each contractor employee or any of its subcontractors at any level to whom any TYAD records may be made available or disclosed shall be notified in writing by the contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein. The confidentiality, integrity, and availability of such information shall be protected in accordance with TYAD policies and instructions. Unauthorized disclosure of information will be subject to the TYAD sanction policies and/or governed by the following laws and regulations:
• 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
• 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
• 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
• 18 U.S.C. 1030 The Computer Fraud and Abuse Act (CFAA)
• 44 U.S.C. 3301 Definition of Records
Government Access for Security Assessment: In addition to the Inspection Clause in the contract, the contractor
(and/or any subcontractor) shall afford the Government access to the contractor’s facilities, installations, operations, documentation, information systems, and personnel used in performance of this contract to the extent required to carry out a program of security assessment (to include vulnerability testing), investigation, and audit to safeguard
Security and Privacy Requirements for Information Technology Procurements against threats and hazards to the confidentiality, integrity, and availability of federal data or to the protection of information systems operated on behalf of TYAD, including but are not limited to:
a. At any tier handling or accessing information, consent to and allow the Government, or an independent third party working at the Government’s direction, without notice at any time during a weekday during regular business hours contractor local time, to access contractor and subcontractor installations, facilities, infrastructure, data centers, equipment (including but not limited to all servers, computing devices, and portable media), operations, documentation (whether in electronic, paper, or other forms), databases, and personnel which are used in performance of the contract. The purpose of the access is to facilitate performance inspections and reviews, security and compliance audits, and law enforcement investigations. For security audits, the audit may include but not be limited to such items as buffer overflows, open ports, unnecessary services, lack of user input filtering, cross site scripting vulnerabilities, Structured Query Language (SQL) injection vulnerabilities, and any other known vulnerabilities.
b. At any tier handling or accessing protected information, fully cooperate with all audits, inspections, investigations, forensic analysis, or other reviews or requirements needed to carry out requirements presented in applicable law or policy. Beyond providing access, full cooperation also includes, but is not limited to, disclosure to investigators of information sufficient to identify the nature and extent of any criminal or fraudulent activity and the individuals responsible for that activity. It includes timely and complete production of requested data, metadata, information, and records relevant to any inspection, audit, investigation, or review, and making employees of the contractor available for interview by inspectors, auditors, and investigators upon request. Full cooperation also includes allowing the Government to make reproductions or copies of information and equipment, including, if necessary, collecting a machine or system image capture.
c. Cooperate with inspections, audits, investigations, and reviews.
National Defense Authorization Act Section 889 Compliance: DoD, GSA, and NASA have issued an interim rule amending the Federal Acquisition Regulation (FAR) to implement section 889(a)(1)(B) of the John S. McCain
National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2019 (Pub. L. 115-232). Section 889(a)(1)(B) prohibits executive agencies from entering into, extending, or renewing a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, on or after August 13, 2020, unless an exception applies, or a waiver is granted. See solicitation provision 52.204-24 and clause 52.204-25.
Physical Security: The Contractor shall be responsible for safeguarding all government equipment, information and property provided for Contractor use. At the close of each work period, government facilities, equipment and materials shall be secured.
Key Control. [If applicable.] The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality
Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the KO.
In the event keys, other than master keys, are lost and/or duplicated, the Contractor shall, upon direction of the KO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the locks or locks shall be deducted from the monthly payment due to the
Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaces by the
Government and the total cost deducted from the monthly payment due to the Contractor.
The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the
Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas or personnel authorized entrance by the KO.
Lock Combination. [If applicable.] The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations.
These procedures shall be included in the Contractor’s Quality Control Plan.
File details come from the government source that posted it. Updated .