Supporting Statement
Paperwork Reduction Act Submission
Department of Veterans Affairs Acquisition Regulation (VAAR)
804.1970 and Clause 852.204-71
2900-xxxx
Explain the circumstances that make the collection of information necessary. Identify legal or administrative requirements that necessitate the collection of information.
As a result of proposed rule, RIN 2900-AQ41 posted to the Federal Register 86FR64132 on November 17, 2021, VAAR case 2015-V016, this is a request from the Department of Veterans Affairs (VA) for OMB approval of a new Information Collection (IC). Under Public Law 113-283, Federal Information Security Modernization Act of 2014, each agency of the Federal Government must provide security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.
In order for VA to comply with Public Law 113-283, Federal Information Security Modernization Act of 2014, VA developed VAAR clause, 852.204-71, Information and Information System Security, and a new section 804.1970, Information security policy—contractor general responsibilities. The clause and the section contain the following information collection requirements from the public.
Information Collection Requirement |
Clause/Section |
Contractor/subcontractor employee reassignment and termination notification |
852.204-71 |
Report of known or suspected security/privacy incident and data breach |
852.204-71, 804.1970 |
Provide an annual training certificate |
852.204-71 |
Submission of data retention, destruction plan and contractor self-certification |
852.204-71 |
Maintain records and compliance reports regarding HIPAA security and privacy rule compliance |
804.1970 |
Submission of a detailed security plan |
852.204-71 |
Report of all requests for, demands for production of, or inquiries, including court orders, about VA information and information systems |
Clause 852.204-71, Information and Information System Security, is required to be inserted by the contracting officer when the clause at FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems is required to be included in accordance with FAR 4.1903. This includes when the contractor or a subcontractor at any tier may have Federal contract information residing in or transiting through its information system.
This clause is intended to protect VA information, VA sensitive information and information systems by requiring contractor and subcontractor personnel to be subject to the same Federal laws, regulations, standards, and VA directives and Handbooks as VA and VA personnel regarding information and information system security.
The information collections do not involve the use of automation.
The information collections required by the clause are based on events happening during the contract period and on specific contracts. There are no other means to collect this data nor similar information already available as it does not exist in reportable form from other sources and is specific to actual performance under the contract. Therefore, there will be no duplication.
If the collection of information impacts small businesses or other small entities, describe any methods used to minimize burden.
Small businesses will be affected in the same way as large businesses in order to comply with the statute and safeguard VA sensitive information, information systems, and information technology.
Failure to collect the information could expose vulnerabilities in VA sensitive information, information systems, and information technology.
VA does not expect that any contractor/subcontractor would submit a response more often than quarterly, unless an employee working on a VA system or with access to VA information is reassigned or leaves the Contractor or subcontractor’s employ during that quarter. All the reporting requirements are included in the solicitation and/or contract. Therefore, respondents have more than 30 days to prepare written responses.
Note: this section will be updated when the proposed rule 839 is published in the Federal Register and at the end of public comment period. Address comment received related to this IC, if any.
There were no efforts to consult with persons outside the agency beyond the publication of this proposed rule in the Federal Register.
No payments or gifts have been provided.
This information is disclosed only to the extent consistent with prudent business practices and current regulations.
The request for information does not include any questions of a sensitive nature.
The number of respondents, frequency of responses, annual hour burden, and explanation for each form is reported as follows:
852.204-71, Information and Information System Security and section 804.1970, Information security policy—contractor general responsibilities.
Total Burden Hours: 4,069
Total Number of Respondents: 8,223
Average Number of Respondents: 1,175
Total Annual Responses: 8,223
Average Annual Responses: 1,175
Contractor/subcontractor employee reassignment and termination notification.
No. of respondents |
x No. of responses per respondent |
x No. of minutes |
÷ by 60
|
Number of Burden Hours |
1,357 |
1 |
5 |
113 |
Report of known or suspected security/privacy incident and data breach.
No. of respondents |
x No. of responses per respondent |
x No. of minutes |
÷ by 60
|
Number of Burden Hours |
807 |
1 |
180 |
2,421 |
Submission of contractor/subcontractor employee annual training certificate.
No. of respondents |
x No. of responses per respondent |
x No. of minutes |
÷ by 60
|
Number of Burden Hours |
3,016 |
1 |
2 |
101 |
Submission of data retention, destruction plan and contractor self-certification.
No. of respondents |
x No. of responses per respondent |
x No. of minutes |
÷ by 60
|
Number of Burden Hours |
452 |
1 |
5 |
38 |
Maintain records and compliance reports regarding HIPAA security and privacy rule compliance.
No. of respondents |
x No. of responses per respondent |
x No. of minutes |
÷ by 60
|
Number of Burden Hours |
2,138 |
1 |
30 |
1,069 |
Detailed security plan submission.
No. of respondents |
x No. of responses per respondent |
x No. of minutes |
÷ by 60
|
Number of Burden Hours |
302 |
1 |
60 |
Report of all requests for, demands for, production of, or inquiries, including court orders, about VA information and information systems.
No. of respondents |
x No. of responses per respondent |
x No. of minutes |
÷ by 60
|
Number of Burden Hours |
151 |
1 |
10 |
If this request for approval covers more than one form, provide separate hour burden estimates for each form and aggregate the hour burdens in Item 13 of OMB 83-1.
No other form is required by VAAR for use in this collection.
Provide estimates of annual cost to respondents for the hour burdens for collections of information. The cost of contracting out or paying outside parties for information collection activities should not be included here. Instead, this cost should be included in Item 14.
Total estimated annual cost to all respondents: $189,371 (4,069 hours at $46.54 per hour). This is based on the Bureau of Labor Statistics May 2020 Occupational Employment and Wages code “15-1231 Computer Network Support Specialists” mean hourly wage is $34.16 plus 36.25% fringe benefits per OMB Memo M-08-13 dated March 11, 2008.
There are no capital or start-up costs associated with the information collection.
Total Estimated Burden Hours to the Government: 4,069
Total Estimated Cost to the Government: $167,846
$167,887 (4,069 hours at $41.26, based on 2021 OPM Salary Table, including benefits of 36.25% per OMB Memo M-08-13 dated March 11, 2008, of the average GS 11, Step 5, VA contracting officer).
OPM 2021 Salary Table can be located at Pay & Leave : Salaries & Wages - OPM.gov
This is a new information collection.
There are no plans to publish any data received from this information collection.
VA will display the expiration date for OMB approval of the information collection.
There are no exceptions.
Statistical methods will not be employed.
File Type | application/vnd.openxmlformats-officedocument.wordprocessingml.document |
Author | Rennie, Crystal |
File Modified | 0000-00-00 |
File Created | 2021-11-24 |