06_Attachment 1 - Requirements Traceability Matrix.xlsx

XLSX spreadsheet 27 KB Posted

Attached to
FOIA/Privacy Act System & Services Federal contract opportunity
Solicitation number
16PBGC23Q0004
Issued by
Pension Benefit Guaranty Corporation

About this file

This document contains a requirements traceability matrix and statement of objectives for a federal solicitation seeking a Freedom of Information Act online system replacement solution. Key requirements for the cloud-hosted software-as-a-service solution include mandatory compliance with FedRAMP authorization, integration with Login.gov for user authentication, and operational security at NIST SP 800-53 Revision 4 impact level of moderate. The solution must provide functionality for electronic FOIA and Privacy Act request intake and processing, redaction and records management tools, public-facing reading room capabilities, and integration with other federal systems. The procuring agency is the Pension Benefit Guaranty Corporation.

View the file

Other files for this federal contract opportunity

Other files attached to FOIA/Privacy Act System & Services, newest first.
File Type Posted
06_16PBGC23Q0004_FOIA.pdf PDF
06_Attachment 4 - Pricing Breakout.24 Oct 2022.docx DOCX document
06_Attachment 3 - IT Solutions Life Cycle Management Handbook.pdf PDF
06_Attachment 2 - IT Solutions Life Cycle Management Framework.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Requirements

No.Sub-CategoryMandatory/Regulatory RequirementVendor ResponseComments or Notes from Vendor (Optional)
1Min ReqSoftware-as-a-Service Cloud Hosted
2Min ReqGSA FedRamp Authorized
3Min ReqIntegrated with Login.Gov
No.Sub-CategoryFunctional RequirementVendor ResponseComments or Notes from Vendor (Optional)
1BaseWeb-based processing interface
2BaseWorkflow for FOIA/PA requests
3BaseImage-enabled Redaction tool
4BaseRepository/storage
5BaseInterfaces with email (incoming/outgoing)
6BaseStorage Capacity Flexibility /Cloud Security
7BaseProduct Training Plan- Electronic Training and User Manuals, Ease and Length of Onboarding, Implementation Plan, which allows users to understand, use, administer, and support the FOIA solution
8BaseHelp Desk support that will assist with functional and technical difficulties
9BaseCustomization of Workflow-Ability to change workflow without the developer
10BaseRequests-multi track capability
11BaseLicensing model-flexibility with the quantity of licenses (not required to purchase a license for each user)
12BaseReporting functionality/Auto-generate a FOIA log
13BaseAbility to create user roles and permissions
14BaseUser friendly capability
15BaseUpload templates to the system
16BaseWorkflow Automation-assign tasks
17BaseGenerate emails to requester...with a .gov suffix
18BaseDelinquent payment requester tracking
19BaseAll upgrades and required training included in the initial licensing
20BaseCustomization of workflows-audit trails, ability to change configurations without the developer
21BaseAbility to customize metrics reports
22BaseSupport for manual intake of requests
23BaseAdministrative Appeal Process- tracks and relates appeals to the original request
24BaseExpedited Processing/Fee waiver Processing Capability
25BaseRecords migration--allow for the integration of documents with a hash value created by FOIAonline
26BaseSearch requests by subject matter
27BaseFlexibility/costs for configurations or modifications after initial development
28BaseSearch requests by keyword, disposition, exemptions, requester name, requester organization
29IntegrationMigration of all data from FOIAonline
30IntegrationGenerates Annual FOIA DOJ reports
31IntegrationIntegate with SharePoint
32IntegrationAccept Electronic Payments and integrates with Pay.gov
33IntegrationDashboard reporting
34IntegrationE-discovery capabilities- search record custodians records; search record custodians SharePoint
35IntegrationIntegrate with Agency's Power BI
36IntegrationCross integration with relativity
37ProcessingFOIA/PA processing features
38ProcessingAssigns response deadlines by request and task type
39ProcessingAllows for request tolling (pausing the clock)
40ProcessingTracks deadlines w/reminders
41ProcessingAutomatic Notification of Duplicate Incoming Requests
42ProcessingArtificial Intelligence redaction tool
43ProcessingDe-duplication-removes duplicate records (perhaps integrated within Redaction Tool)
44ProcessingData and records image enabled for redaction
45ProcessingSend final Disclosure Determination and responsive records to requester from the processing platform
46ProcessingIngest various file types: audio, video, non-text files, TIF, pdf, csv, OCR, pst, docx, jpg
47ProcessingAuto-calculate fees and generate invoices
48ProcessingRedaction tool produces records that are 508 compliant
49ProcessingRetention schedules-configurable retention schedule, is it an auto-delete
50ProcessingData limits, cloud storage, file size maximum volume
51ProcessingRedaction tool produce an excel spreadsheet output
52ProcessingIntegrated Redaction Tool-Edit redactions within the same document
53ProcessingRedaction tool-ability to redact multimedia files, i.e. sound, video
54ProcessingRedact content across a document set--allow changes of case file during the reviewing stage
55ProcessingAbility to upload records for processing
56ProcessingEnd to end request processing capability
57ProcessingIdentification of duplicate records
58ProcessingBates numbering with redaction tool
59ProcessingGenerate Vaughn Index
60ProcessingProgram offices/recordholders ability to upload responsive records to system
61ProcessingExtend the workflow to end-users, ability to interact with recordholders from the system, search request emails, reminder emails
62ProcessingFile size reduction capability, automatically compress file size for delivery to the requester for voluminous requests
63ProcessingSearch by metadata for redactions
64ProcessingAbility to sort responsive records, records management, smart records capability
65ProcessingArtificial Intelligence/Predictive tool- Ability to program and/or control
66ProcessingRedaction tool--can perform a side-by-side comparison (of past disclosure determination)
67ProcessingControl of Artificial Intelligence functions (ability to configure without developer)
68ProcessingQuality Assurance Artificial Intelligence--Audit
69ProcessingRecord encryption
70ProcessingA document should be hosted by each file, even if it is a duplicate record
71ProcessingAccepts/Tracks/Reports metadata
72Public PortalPublic-facing portal for request initiation…
73Public PortalAPI capability to FOIA.gov
74Public PortalAllows public to track status
75Public PortalAllows for publication of final disclosure determinations and responsive documents via platform
76Public PortalRequester Digital Certification of Identity capability from public portal
77Public PortalRequesters ability to keyword search across all FOIA requests
78Public PortalSelf-contained public reading room
79Public PortalAutomatic uploads to the reading room
No.Sub-CategorySecurity/IT RequirementVendor ResponseComments or Notes from Vendor (Optional)
1SecuritySystem must be a cloud system (meeting all five cloud characteristics as defined in NIST SP 800-145) offering cloud services on the FedRAMP site with a status of "Ready" (with no agency sponsorship by PBGC required). (see Min Req 3 above)
2SecurityMaterials should be available on the FedRAMP repository on OMB MAX for the ISSPO team to add the new system to the relevant PBGC system boundary and achieve Authorization to Operate (ATO).
3SecurityAs a FedRAMP system, vendor should provide at least a monthly ConMon meeting (continuous monitoring control implementation and PO&AM status review), either for PBGC or for all of its agency users.
4SecurityProcured system must be able to attain an ATO within a PBGC system boundary (projected to be OGCFedRAMP) before data migration activities can begin, as per the FISMA (Federal Information Security Modernization Act of 2014). (The ATO required for migration may be limited/specific to migration activities if the ECD so recommends and approves.)
5SecurityProcured system Should Have a full and unqualified ATO within a PBGC system boundary before user account provisioning and production usage begins, as per FISMA 2014.
6SecurityThe system should be operating and evaluated at NIST SP 800-53 Rev. 4 at a minimum with a clear plan to Rev. 5 when it has been released.
7SecurityThe system must be FedRAMP authorized at the Moderate impact security level baseline.
8SecurityThe system must support iCAM processes by providing active user/role lists as emailed electronic files at least weekly.
9SecurityThe system must support iCAM processes by providing automated active user/role lists as emailed electronic files at least weekly.

10 Security The system Integrates with Federated Services that use SAML (such as ADFS) for Authentication for PBGC internal users.

11 Security The system must support ingestion of audit logs into PBGC's Splunk system.

12PrivacyIdentity proofing and authentication of all FOIA/PA requesters which meets the requirements of OMB memo M-21-04 (with a service such as, for example, Login.gov)
13Privacy/
SecuritySystem must support an Identity Assurance Level (IAL) of IAL2 (per NIST SP 800-63a) for requestors using the citizen-facing portal to submit PA requests. (Other non-portal methods can also be used for request submission and for requestor identity validation by PBGC.)
14Privacy/
SecuritySystem must support an Authenticator Assurance Level (AAL) of AAL2 (multi-factor authentication).
15Privacy/
SecuritySystem must support a Federation Assurance Level (FAL) of FAL2 (encryption using approved cryptography) for all communcations to and within the solution.
16PrivacyLanguage on the citizen-facing web page(s) of the solution which meets the labeling requirements of OMB memo M-21-04 Appendix I, including proper Privacy Act notice(s) and consent forms when relevant.
17PrivacyMaterials provided by the vendor as needed to help update and publish relevant SORNs (System of Record Notice(s)) for the system.
18508508 compliant
19ITSolution is used by 5 Federal Agencies

File details come from the government source that posted it. Updated .