SOW.docx

DOCX document 17 KB Posted

Attached to
Certified Hard Drive Shredding Services Federal contract opportunity
Solicitation number
WF133F17RQ0325
Issued by
Department of Commerce National Oceanic and Atmospheric Administration

About this file

Statement of Work

View the file

Other files for this federal contract opportunity

Other files attached to Certified Hard Drive Shredding Services, newest first.
File Type Posted
Wage_Determination.docx DOCX document
Combined_Synopsis_Sol;.docx DOCX document
FormSF18_final.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Certified Hard Drive Shredding Services Information Technology Services (ITS) Division Background:

The Pacific Islands Fisheries Science Center (PIFSC) of the National Marine Fisheries Service (NMFS) is part of the National Oceanic and Atmospheric Administration (NOAA). The Center administers scientific research and monitoring programs that support the domestic and international conservation and management of living marine resources.

PIFSC is headquartered in Honolulu, Hawaii. The Center has taken a leading role in marine research on ecosystems, both in the insular and pelagic environments. It is implementing a multidisciplinary research strategy including an ecosystem observation system and scientific analysis to support ecosystem approaches to management and restoration of living marine resources. It conducts a wide range of activities including resource surveys and stock assessments, fishery monitoring, economic and sociological studies, oceanographic research and monitoring, critical habitat evaluation, life history and ecology studies, and advanced oceanographic and ecosystem modeling and simulations. The Information Technology Services (ITS) section provides the infrastructure and IT tools needed by all PIFSC employees to complete their jobs while enforcing the mandated security requirements.

Statement of Work:

ITS requires a vendor to provide certified sanitization services for media destruction in accordance with NIST Special Publication 800-88 Revision 1: Guidelines for Media Sanitization, dated December 2014, which can be found at http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf. The sanitization process removes information from the media such that the information cannot be retrieved or reconstructed. Sanitization techniques, including clearing, purging, cryptographic erase, and destruction, prevent the disclosure of information to unauthorized individuals when such media is reused or released for disposal. While some techniques may render the Target Data infeasible to retrieve through the device interface and unable to be used for subsequent storage of data, the device is not considered destroyed unless Target Data retrieval is infeasible using state of the art laboratory techniques. disintegrate, pulverize, melt and incinerate. Vendors will be asked to shred a maximum of 250 hard drives with a certificate of data destruction provided for each hard drive at the completion of the destruction process.

Because the hard drives contain personally identifiable information and business identifiable information, the hard drives cannot be shipped to vendors offering these services outside the state of Hawaii. The successful vendor must be located in the local Honolulu area within a 20 minute driving radius of NOAA’s Ford Island facility, 1845 Wasp Boulevard, Honolulu, HI 96818.

Deliverables:

· Certificate of data destruction provided for each hard drive at the completion of the destruction process.

IT-Security:

Contractors will have access to staff contact and personal information, some of which is considered sensitive or personally identifiable information (PII). Contractors will safeguard and hold confidential all PII/sensitive information and shall seek instruction from the federal sponsor on required protocols as needed.

The contractor agrees, in the performance of this contract, to keep the information furnished by the Government and designated by the contracting officer or Contracting Officer’s Representative (COR) in the strictest confidence. The contractor also agree not to publish or otherwise divulge such information in whole or part, in any manner or form, nor to authorize or permit others to do so, taking such reasonable measures as are necessary to restrict access to such information while in the contractor’s possession, to those employees needing such information to perform the work provided herein, i.e., on a “need to know” basis. The contractor agrees to immediately notify the contracting officer in writing in the event that the contractor determines or has reason to suspect a breach of this requirement.

Secure Communications: The contractor must verify with the government prior to transmission of information that all information designated as sensitive will meet National Institute of Standards and Technology (NIST) Federal Information Processing FIPS 140-2 validated cryptographic module(s).

The contractor agrees that it will not disclose any information described in performance of this activity to any persons or individual unless prior written approval is obtained from the contracting officer. Whenever the contractor is uncertain with regard to the proper handling of information/data under the contract, the contractor shall obtain a written determination from the contracting officer. The contractor agrees to insert the substance of this clause in any consultant agreement or subcontract hereunder.

Upon completion of this requirement, the contractor will certify in writing to the contracting officer that:

Except as approved in writing by the contracting officer, they have not disclosed and any data or media collected, developed, and/or correlated in the performance of this acquisition, and have not retained any data or media collected, developed, and/or correlated in the performance of this acquisition.

All instances of data or media in the possession or under the control of the contractor has been destroyed using one of the methods for secure destruction of unclassified but sensitive information recommended by the National Security Agency in the Media Destruction Guidance available online at http://www.nsa.gov/ia/guidance/media_destruction_guidance/index.shtml.

File details come from the government source that posted it. Updated .