Laserfiche WebLink
Contract Clauses for Solicitation 47QSMD20R0001 Refresh Number 19 Contract Number: GS -07F -0031W <br />(G) Full cooperation with any Government agencies responsible for audits, <br />investigations, or corrective actions. <br />(d) Subcontracts. <br />(1) The Contractor shall include the substance of this clause, including this paragraph (d), in <br />subcontracts that exceed the threshold specified in FAR 3.1004(a) on the date of subcontract <br />award and have a performance period of more than 120 days. <br />(2) In altering this clause to identify the appropriate parties, all disclosures of violation of the civil <br />False Claims Act or of Federal criminal law shall be directed to the agency Office of the <br />Inspector General, with a copy to the Contracting Officer. <br />52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR <br />INFORMATION SYSTEMS (NOV 2021) <br />(a) Definitions. As used in this clause — <br />Covered contractor information system means an information system that is owned or operated by a contractor <br />that processes, stores, or transmits Federal contract information. <br />Federal contract information means information, not intended for public release, that is provided by or <br />generated for the Government under a contract to develop or deliver a product or service to the Government, but not <br />including information provided by the Government to the public (such as on public Web sites) or simple <br />transactional information, such as necessary to process payments. <br />Information means any communication or representation of knowledge such as facts, data, or opinions, in any <br />medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on <br />National Security Systems Instruction (CNSSI) 4009). <br />Information system means a discrete set of information resources organized for the collection, processing, <br />maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502). <br />Safeguarding means measures or controls that are prescribed to protect information systems. <br />(b) Safeguarding requirements and procedures. <br />(1) The Contractor shall apply the following basic safeguarding requirements and procedures to <br />protect covered contractor information systems. Requirements and procedures for basic <br />safeguarding of covered contractor information systems shall include, at a minimum, the <br />following security controls: <br />(i) Limit information system access to authorized users, processes acting on behalf of <br />authorized users, or devices (including other information systems). <br />(ii) Limit information system access to the types of transactions and functions that <br />authorized users are permitted to execute. <br />(iii) Verify and control/limit connections to and use of external information systems. <br />(iv) Control information posted or processed on publicly accessible information systems. <br />(v) Identify information system users, processes acting on behalf of users, or devices. <br />(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a <br />prerequisite to allowing access to organizational information systems. <br />Page: 112 of 216 <br />199 <br />