1. Statement of Work.pdf

PDF 374 KB Posted

Attached to
Software for Bridge Management Federal contract opportunity
Solicitation number
12760424Q0065
Issued by
Department of Agriculture Forest Service

About this file

This document is a Statement of Work for a Bridge Management System (BMS) with an integrated mobile application and a tool to transition existing bridge data to the new Specification for the National Bridge Inventory (SNBI) format. The Forest Service is seeking a cloud-based BMS that can store comprehensive bridge inspection data, integrate with a mobile app for field data collection, and include a tool to transition existing bridge data to the SNBI format. The BMS must be FedRAMP certified or in the certification process, support 660 users across 500 sites, and manage up to 8,000 structures. Key technical requirements include security, accessibility, and data rights provisions. The period of performance is one year with four one-year option periods. Deliverables include the BMS tool, a data transition tool, mobile app, and related software licenses. Vendors must provide line item pricing for software licenses and comply with IT security, Section 508, and IPv6 requirements.

View the file

Other files for this federal contract opportunity

Other files attached to Software for Bridge Management, newest first.
File Type Posted
Q and A for 12760424Q0065.xlsx XLSX spreadsheet
3. USDA Security Contract Language.pdf PDF
4. Revised Section 508 Contract Language.pdf PDF
2. Accessibility Requirements Language.pdf PDF
Combined Synopsis_Solicitation.pdf PDF
RFQ 12760424Q0065.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1 | P a g e

U.S. Department of Agriculture Natural Resources and Environment, Forest Service FY2024 Chief Information Office Bridge Management System (BMS) with Integrated Mobile Application & Specifications for the National Bridge Inventory (SNBI) transition tool

Statement of Work March 05, 2024

2 | P a g e

Contents

1. Introduction

2. Business Requirements

3. Technical Requirements

4. Period of Performance

5. Deliverables

Software License Line Item Data

a. Deliverable Schedule:

b. Applicable Documents:

6. Equipment

7. Standard IT Security Language

SECURITY LANGUAGE FOR ALL CONTRACTS

ACQUIRING AND/OR IMPLEMENTING SOFTWARE APPLICATIONS

ACQUIRING EXTERNAL IT SERVICES (PROCESSING, STORING, OR

TRANSMITTING FS DATA ON A NON-FS SYSTEM)

ASSESSMENT, AUTHORIZATION, AND CONTINUOUS MONITORING OF

EXTERNAL INFORMATION SYSTEMS

8. Section 508 – Accessibility of Information and Communications Technology

Section 508 Compliance

9. IPv6 Requirements

10. Contract Officer Representative

3 | P a g e

1. Introduction Established in 1905, the Forest Service (FS) is a federal agency that manages public lands in national forests and grasslands under a founding principle, "To provide the greatest amount of good for the greatest amount of people in the long run". The agency’s mission is to “sustain the health, diversity, and productivity of the Nation’s forests and grasslands to meet the needs of present and future generations”. The FS has the responsibility for stewardship of more than 193 million acres of the nation’s forests and grasslands; for developing and communicating scientific knowledge through research and development that leads to informed natural resource decision-making; for delivering technical assistance through state and private forestry programs; and for sharing knowledge and experience with others in the global community through international forestry. Performing this mission requires a strong and effective network of operational and administrative support.

The United States Department of Agriculture (USDA), Natural Resources and Environment (NRE), Forest Service (FS) is seeking a contract vehicle for a Bridge Management System (BMS) with an integrated mobile application and tool for transitioning data from the Coding Guide to Specifications for the National Bridge Inventory (SNBI) format.

All data created, produced, and stored on this software will be the property of the USDA, NRE, and FS.

2. Business Requirements The Forest Service is required to track data describing the condition of road bridges open to public travel. The Road Bridge and Culverts applications under Natural Resource Manager (NRM) currently serve as the National Forest System (NFS) road bridge inventory database of record and is and describes attributes for each road bridge, including its structural characteristics, dimensions, inspection information, and needed maintenance work items. New inspection regulations were mandated in a 2022 rule and changes to bridge data management are currently being phased in through 2024. A modern Bridge Management System (BMS) that accommodates new data formatting required by the 2022 rule and has other required capabilities is needed.

The United States Forest Service (USFS) must acquire a BMS configured for the Specifications for National Bridge Inventory (SNBI) in FY24 to meet implementation deadlines set by the Federal Highway Administration. A rule issued in 2022 and detailed in the Code of Federal Regulations (23 CFR 650.315) compels the USFS to transition from using the existing bridge coding guide to using the SNBI for collection and management of bridge safety inspection data.

The USFS seeks a BMS that is fully configured for SNBI data collection and other requirements of the recently updated laws codified in the National Bridge Inspection Standards (NBIS).

The vendor must be in active pursuit of FedRAMP certification.

3. Technical Requirements

Bridge Management System (BMS) overall characteristics:

• A cloud based BMS capable of storing comprehensive bridge inspection data in Coding

Guide and SNBI formats, and storing official bridge record documents such as drawings, load ratings, investigative reports, and past inspection reports.

4 | P a g e

• The BMS must be integrated with a tool for comprehensive transitioning of data from Coding Guide to SNBI formatting; and a mobile application for field data collection for routine, nonredundant steel tension member (NSTM), underwater, and special inspections.

• BMS must already be fully developed and configured to meet the 2022 NBIS updates and collection of data per the SNBI.

• The bridge management system must be certified in the Federal Risk and Authorization Management Program (FedRAMP) or currently in the certification process with expected attainment in calendar year 2024.

• Dynamic customizable dashboards, filters, and alerts

• 660 Forest Service users will need access to the BMS from 500 agency administrative sites and while teleworking.

• The BMS must include access by consultants hired by the Forest Service.

• A BMS for up to 8,000 structures

• Vendor 24/7 support of FedRAMP cloud and end users

• Vendor-provided user training live (MS Teams) & online (recorded webinars)

• Export capabilities of bridge data into UDSA Forest Service system of record databases

• Agency managers must be able to define and limit which bridge files Forest Service and consultant users may access and edit.

• The BMS, transition tool, and mobile applications must have integrated references including the Coding Guide, SNBI, Bridge Inspectors Reference Manual, Manual for Bridge Evaluation, and the FHWA Coding Guide / SNBI Data Crosswalk.

• BMS must have Single Sign On capabilities

• The BMS and mobile application must have maintenance activity management capabilities including inspector identification of needed work, deferred maintenance tracking, and capture of work completion. Maintenance work items must be customizable by the agency.

• Must have features allowing agency bridge program managers to review draft inspections in the BMS and approve or reject.

• BMS must allow users and reviewers to easily identify all inspection fields that have been changed or updated.

• Integrated management of Critical Findings including initial identification, management of active findings, and resolution

• QC and QA features to prevent, identify and correct fatal errors in the annual NBI tape conveyed to FHWA and to promote compliance with NBIS Metrics

• Interactive mapping interface with individual and batch structure inspection scheduling and file selection capabilities.

• Inspection schedule management capabilities including monitoring of upcoming and overdue inspections and tools to assign and schedule inspections in a timely manner in accordance with NBIS requirements.

5 | P a g e

• Capability to create and customize agency-defined add-on data fields

• Customizable final inspection report PDF formatting

• Customizable automated email alerts to program managers including but not limited to critical findings, scour reviews required, load ratings required per NBIS due to drop in condition rating, load postings called for, and closed bridges

• Capability to automatically store reports and inspection files & photos on agency drives with the ability to configure the folder structure, folder name, and file names based on agency needs.

• BMS must identify bridges that should be put on a reduced inspection interval per NBIS Method 1 and identify bridges that are eligible for extended intervals per Method 1.

• BMS must be able to identify when initial, NSTM, and underwater inspections are required for new and rehabilitated bridges.

• backup and restoration of database that is kept for a minimum of 30 days with data preservation even if data center is temporarily unavailable; backups provided upon request

• The bridge management database must have an uptime or Service Level Agreement of at least 99% per month

• BMS database must be able to create the JSON file for the annual NBI submittal to

FHWA

• Option for vendor IT development support for customization

Mobile application characteristics:

• Customizable data collection format

• Device application must allow inspectors to easily identify all inspection fields that have been changed or updated.

• Voice dictation by inspector

• Sketch functionality on the field device including marking up images or plan sheets

• Photos can be taken using tablet camera and integrated into working inspection file on the device without mandatory manual photo upload in an office setting. Capability to associate photos to an inspection item or defect. Photo captioning capabilities.

• Mobile device data collection with GPS location that integrates with the BMS and has offline data collection capability. Automated uploading of all tablet-collected data into the BMS cloud over cell or Wi-Fi network with no manual inspection data entry.

Coding Guide to SNBI format data transition tool characteristics:

• Automated tool for batch transitioning existing Coding Guide data to the new SNBI format.

• Ability to load inspection data for the entire bridge inventory into the transition tool in

MS Excel format

• Automated population of appropriate temporary codes for bridges still pending SNBI inspection

6 | P a g e

• Identification of fields requiring user selection with attributes configured to prevent and minimize coding errors

• Ability to transition data without the known errors in the transition tool found at National Bridge Inventory (NBI) – Based on the SNBI or Transition Tool - web-based application for transitioning data from Coding Guide to SNBI for SNBI attributes B.LR.05, B.LR.06, B.AP.01, B.AP.04, B.F.01, B.H.01, B.H.02, B.H.07, B.H.12, B.H.13, B.H.14, B.H.15, B.H.16, B.H.17, B.SP.01, & B.SP.05

• Ability to batch update an SNBI attribute for multiple bridges

• Export capabilities for incorporation into the BMS, MS Excel, or as a JSON file for NBI tape submittal.

• Ability to store some SNBI attribute data while the agency is still using our existing bridge database that is not configured for SNBI data.

• Consultant access to the Coding Guide / SNBI transition tool with ability to limit what structures can be accessed.

• Ability to review all transitioned data before integrating into the official BMS database

Details of Technical Requirements (See Bill of Materials (BOM) for more details).

4. Period of Performance The Base Period of Performance is for one year from:

May 1, 2024 – April 30, 2025 If needed, at the option of the Government, the contract may be renewed for 4 Option Periods.

The contract shall not exceed a total of 60 months if all options are exercised.

Option Schedules:

Option Year 1: May 1, 2025 – April 30, 2026 Option Year 2: May 1, 2026 – April 30, 2027 Option Year 3: May 1, 2027 – April 30, 2028 Option Year 4: May 1, 2028 – April 30, 2029

5. Deliverables 1 BMS Tool Must provide USFS and end users access to a commercial Bridge Management System that meets the 2022 NBIS and use of the SNBI and has an integrated mobile application.

Upon contract award

2 Availability Requirement

USFS and end users must be able to access the BMS Tool and Add-ons 100% of the time outside of maintenance windows.

Upon contract award

3 Alerts add-on Provide Add-ons for creating customized alerts for bridge program end users

Upon contract award https://www.fhwa.dot.gov/bridge/snbi.cfm https://fhwaapps.fhwa.dot.gov/snbip?_gl=1*mxeexv*_ga*MTAwODE2NjIzNy4xNzA5OTE4ODI4*_ga_VW1SFWJKBB*MTcwOTkxODgyOC4xLjEuMTcwOTkxODg5OC4wLjAuMA..

https://fhwaapps.fhwa.dot.gov/snbip?_gl=1*mxeexv*_ga*MTAwODE2NjIzNy4xNzA5OTE4ODI4*_ga_VW1SFWJKBB*MTcwOTkxODgyOC4xLjEuMTcwOTkxODg5OC4wLjAuMA..

7 | P a g e

4 PDF Inspection Report/Photo Storage add-on

Provide Add-ons for automated systematic storage of bridge safety inspection reports and bridge inspection photos

Upon contract award

5 Coding Guide to SNBI data transition tool

Provide the companion product to transition existing 1995 Recording and Coding Guide bridge data to the required new Specifications for the National Bridge Inventory (SNBI) format

Upon contract award

6 USDA Forest Service Support

Provide vendor product support including initial configuration, customization, customer support, & training including formal kickoff meeting between USDA Forest Service bridge engineers and vendor.

Upon contract award

Software License Line Item Data In accordance with Office of Management and Budget Memorandum M-16-12, Category Management Policy 16-1: Improving the Acquisition and Management of Information Technology: Software Licensing, USDA must maintain an inventory of its software licenses, including pricing data. The contractor shall provide line item pricing data on all software licenses provided to USDA at award and/or during performance of the contract/order. The attachment entitled “Software Template Line Item Pricing” must be completed and provided with bid package prior to award date.

a. Deliverable Schedule:

Deliverables:

- All licenses will be functional upon the date of delivery

- All software maintenance will be operational upon the date of award

Deliverable Submitted to: Due Date:

Software Line Item Pricing Spreadsheet

(SWLIPS).

Contracting Officer’s Representative

(COR).

Provided with bid package for providing of upcoming Software Activation for Licenses Provided After Award Date.

b. Applicable Documents:

The attached spreadsheet template with line item pricing of software will be delivered electronically to the CO listed below.

6. Equipment There is no government equipment furnished for this effort.

8 | P a g e

1. Standard IT Security Language

SECURITY LANGUAGE FOR ALL CONTRACTS

1.1 By accepting this contract/agreement, the Contractor and other external organizations (hereafter called Contractor) providing Information Technology (IT) resources or services to the United States Forest Service (FS) agrees to comply with the applicable IT security policy as outlined in this document. The Contractor and other external organizations will be responsible for IT security for all systems connected to the FS network or operated by the Contractor and other external organizations for the FS, regardless of location. This clause is applicable to all or any part of the contract that includes IT resources or services in which the Contractor and other external organizations must have physical or logical access to FS information that directly support the mission of the FS. The term “information technology,” as used in this clause, means any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information. This includes both major applications and general support systems as defined by Office of Management and Budget (OMB) Circular A-130.

1.2 The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this task. The Contractor shall also protect all unclassified Government data, equipment, etc., by treating information as sensitive business, confidential information, controlling and limiting access to the information, and ensuring the data and equipment are secured within their facility.

1.3 The Contractor or other external organization will not publish or disclose in any manner, without the FS Contracting Officer’s written consent, the details of any programs, documentation, data, or safeguards either designed or developed by the Contractor or other external organization under this Contract or otherwise provided by the Government. The Contractor may be required to sign non-disclosure or other appropriate security agreements. A written agreement between the FS and any contractors and other external organizations will be entered into before FS data and information otherwise exempt from public disclosure may be disclosed to the contractors and other external organizations. The Contractor and other external organizations will agree to establish and follow security precautions considered by the FS to be necessary to ensure proper handling of data and information.

1.3.1 Data Rights. As may be identified elsewhere in this contract, the Contractor agrees that:

1.3.1.1 The draft and final deliverables and all associated working papers and other materials deemed relevant by the Contracting Officer’s Representative (COR) that have been generated by the Contractor in the performance of this contract are the property of the United States Government and must be submitted to the COR at the conclusion of the tasks.

1.3.1.2 All documents produced for this project are the property of the United States Government and cannot be reproduced or retained by the Contractor.

9 | P a g e

1.3.1.3 FS will retain unrestricted rights to all federally owned and/or federally managed data and/or metadata that FS either owns or manages that is handled under this contract. Specifically, FS retains ownership of any user created/loaded data and applications collected, maintained, used, or operated on behalf of FS and hosted on contractor’s infrastructure, as well as maintains the right to request full copies of these at any time. If requested, data shall be available to FS within one

(1) business day from request date or within the timeframe specified and provided using an encryption standard that meets FS requirements. In addition, the data shall be provided at no additional cost to FS. The contractor shall maintain all information in accordance with Executive Order 13556 – Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and FS policies and shall not dispose of any records unless authorized by FS. All contractors shall complete the applicable USDA/FS records management training at least annually during the life of this contract.

1.3.1.4 The contractor shall be accountable and document all activities associated with the transport of government information, devices, and media transported outside controlled areas and/or facilities. These include information stored on digital media (e.g., CD- ROM, tapes, etc.), non-digital media (e.g., paper), and mobile/portable devices (e.g., USB flash drives, external hard drives, and SD cards).

1.3.1.5 All information, devices and media shall be encrypted with FS-approved encryption mechanisms to protect the confidentiality, integrity, and availability of all government information transported outside of controlled facilities.

1.3.1.6 The contractor shall ensure all electronic and paper records are appropriately disposed of, and all devices and media are sanitized, in accordance with NIST SP 800-88 Rev 1, Guidelines for Media Sanitization.

1.4 To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor will afford the Government access to the Contractor’s or other external organization’s facilities, installations, technical capabilities, operations, documentation, records, and databases. The Contractor will cooperate with Federal agencies and their officially credentialed representatives during official inspections or investigations concerning the protection of FS information.

Cooperation may include providing relevant documentation showing proof of compliance with federal and agency requirements and rendering other assistance as deemed necessary.

1.5 If new or unanticipated threats or hazards are discovered by either the Government or the Contractor or other external organization, or if existing safeguards have ceased to function, the discoverer will immediately bring the situation to the attention of the other party. The Contractor will report real or suspected incidents or violations immediately upon discovery to the USDA Computer Incident Response and Recovery Branch (CIRRB), by e-mail, at cyber.incidents@usda.gov.

mailto:cyber.incidents@usda.gov

10 | P a g e

1.6 When the design, development, or operation of a system of records on individuals is required to accomplish an agency function, the Contractor will be required to design, develop, or operate a system of records on individuals subject to the Privacy Act of 1974, Public Law 93- 579, December 31,1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Act may involve the imposition of criminal penalties.

1.6.1 The Contractor agrees to –

1.6.1.1 Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies—

1.6.1.1.1 The systems of records; and

1.6.1.1.2 The design, development, or operation work that the contractor is to perform.

1.6.1.2 Include the Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and

1.6.1.3 Include this clause, including this paragraph (3), in all subcontracts awarded under this contract that requires the design, development, or operation of such a system of records.

1.6.2 In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency.

1.6.3 Definitions include:

1.6.3.1 “Operation of a system of records,” as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records.

1.6.3.2 “Record,” as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person’s name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voiceprint or a photograph.

https://gcc02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fuscode.house.gov%2Fbrowse.xhtml%3Bjsessionid%3D114A3287C7B3359E597506A31FC855B3&data=04%7C01%7C%7C7244ba25b77f4be12aa408d93bfaf14a%7Ced5b36e701ee4ebc867ee03cfa0d4697%7C0%7C0%7C637606771256949694%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=VbE6huKqM1L2ncIqqFcseWt5L6qsT1rL%2B1LJ50F%2B5mw%3D&reserved=0

11 | P a g e

1.6.3.3 “System of records on individuals,” as used in this clause, means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.

1.6.3.4 “Personally Identifiable Information", as used in this clause, means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. (See Office of Management and Budget (OMB) Circular A- 130, Managing Federal Information as a Strategic Resource).

1.6.4 The FS will provide initial privacy training, and annual privacy training thereafter, to Contractor employees for the duration of this contract.

1.6.5 Completion of a FS-developed or FS-conducted training course shall be deemed to satisfy these elements.

1.6.6 The Contractor shall maintain and, upon request, provide documentation of completion of privacy training to the Contracting Officer.

1.6.7 The Contractor shall not allow any employee access to a system of records, or permit any employee to create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information, or to design, develop, maintain, or operate a system of records unless the employee has completed privacy training, as required by this clause.

1.6.8 The substance of this clause, including this paragraph, shall be included in all subcontracts under this contract, when subcontractor employees will:

1.6.8.1 Have access to a system of records;

1.6.8.2 Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information; or

1.6.8.3 Design, develop, maintain, or operate a system of records.

1.6.9 The contractors and other external organizations will ensure that the following banner is displayed on all FS systems that contain Privacy Act information operated by the contractors and other external organizations prior to allowing anyone access to the system:

“This system contains information protected under the provisions of the Privacy Act of 1974 (Public Law 93-579). Any privacy information displayed on the screen or printed must be protected from unauthorized disclosure. Employees who violate privacy safeguards may be subject to disciplinary actions, a fine of up to $5,000, or both.”

12 | P a g e

ACQUIRING AND/OR IMPLEMENTING SOFTWARE APPLICATIONS

3.1 Best Practices: The contractor shall follow secure coding best practice requirements, as directed by the United States Computer Emergency Readiness Team (US- CERT) specified standards and the Open Web Application Security Project (OWASP) that will limit system software vulnerability exploits.

3.2 Secure Coding Skills: Contractor certifies that at least one member of each programming team working on any code (including C, Java, .Net, ASP.NET, Visual Basic) to be delivered to the Forest Service has earned the Global Information Assurance Certification for Secured Software Programming or equivalent.

3.3 Source code testing, binary code testing, application scanning, and penetration testing: At least one week prior to delivery of any code due under this contract, Contractor will deliver to the FS Program Manager, or delegated sponsor, the following reports covering all code that will be delivered:

3.3.1 Source code testing results showing all potential security flaws identified by at least one of the commercial source code testing tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor will highlight all vulnerabilities rated “critical” and “high.” The Contractor must then correct the vulnerabilities, resend the code, and ensure the health of delivered source code.

3.3.2 For web applications, web application scanning test results showing all potential security flaws identified by at least one of the commercial web application scanning tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor will highlight all vulnerabilities rated “critical” and “high.”

3.3.3 For all applications: application penetration results.

ACQUIRING EXTERNAL IT SERVICES (PROCESSING, STORING, OR TRANSMITTING FS DATA

ON A NON-FS SYSTEM)

4.1 The Contractor or other external organizations will develop, provide, implement, and maintain an IT System Security Plan for any system that includes acquisition, transmission or analysis of data owned by FS with significant replacement cost should the Contractor’s and other external organization’s copy be corrupted. This plan will describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. The plan will describe those parts of the contract to which this clause applies. The Contractor or other external organization’s IT System Security Plan will be compliant with applicable Federal laws that include, but are not limited to: (e.g., the Clinger- Cohen Act of 1996 and the Federal Information Security Management Act of 2002). The IT System Security Plan will meet IT security and privacy requirements in accordance with Federal and FS policies and procedures that include but are not limited to: National Institute of Standards and Technology (NIST) SP 800-53 Guidelines.

13 | P a g e

4.2 The Contractor and other external organizations will ensure that the appropriate security banners are displayed on all FS systems (both public and private) operated by the contractors and other external organizations prior to allowing anyone access to the system.

ASSESSMENT, AUTHORIZATION, AND CONTINUOUS MONITORING OF EXTERNAL

INFORMATION SYSTEMS

5.1 The Contractor shall comply with all applicable directives to protect the confidentiality, integrity and availability of information systems owned or operated by a contractor that processes, stores, or transmits Forest Service (FS) information, including: the Federal Information Security Modernization Act of 2014 (FISMA); Executive Orders (EO); Office of Management and Budget (OMB); Cybersecurity and Infrastructure Security Agency (CISA);

National Institute of Science and Technology (NIST); General Services Administration (GSA);

United States Department of Agriculture (USDA); FS; and other applicable laws, regulations, guidance and policies.

5.2 The Contractor shall apply the basic safeguarding requirements and procedures to protect covered contractor information systems defined in FAR 52.204-21, as well as those described in the rest of this section (subparagraphs 5.2 through 5.15).

5.3 The Contractor shall support the Assessment & Authorization (A&A) for the Authority to Operate (ATO) of the system, based on its NIST categorization, in accordance with NIST Special Publication (SP) 800-53 and the current USDA Risk Management Framework (RMF) process.

5.3.1 The Contractor must work with the FS and supply deliverables and support activities to support the A&A for the system, including the System Security and Privacy Plan (SSP);

Contingency Plan (CP); Configuration Management Plan (CMP); Incident Response Plan (IRP);

Disaster Recovery Plan (DRP); E-Authentication Threshold / Risk Assessment(s); Privacy Threshold / Impact Assessment(s); CP and DRP Tests; and any other required documents to ensure the system shall receive an ATO.

5.3.2 Contractor must work with the FS to complete a security assessment / risk assessment of the system by the Forest Service’s independent assessor, which is documented in a Security Assessment Report (SAR).

5.3.3 Gaps between required controls and Contractor’s implementation identified in the SAR shall be documented, approved, and tracked for mitigation in a Plan of Action and Milestones (POA&M) document completed in accordance with USDA Plan of Action and Milestones (POA&M) Standard Operating Procedures (SOP). The Contractor shall provide initial and periodic technical input to FS in responding to POA&M items by identifying the intended mitigations, estimated costs, and expected timelines that may be required to address security weaknesses.

5.4 The Contractor must work with the FS and provide appropriate controls to implement federal standards for: audit logging; encryption of data in transit and at rest; phishing-resistant multifactor authentication (MFA); and zero trust architecture (ZTA). This includes compliance https://www.acquisition.gov/far/part-52#FAR_52_204_21

14 | P a g e with the relevant provisions of Executive Order (EO) 14028, Improving the Nation’s Cybersecurity (May 12, 2021); OMB M-21-31, Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents; OMB M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles (January 2022); OMB M-19-17, Enabling Mission Delivery through Improved Identity, Credential, and Access Management (May 2019); and other related directives and guidance from OMB, the Cybersecurity and Infrastructure Security Agency (CISA), USDA, FS, and the information system owner.

5.5 The Contractor shall conduct and document ongoing Asset Management and Configuration Management for all hardware and software components.

5.6 The Contractor shall conduct and document an ongoing Vulnerability Management, including vulnerability scans, installation of vendor-released security patches, or other vulnerability remediations for the information system and its components. The Contractor shall report vulnerabilities identified in any component through scans or other methods. The FS shall determine the risk rating of these vulnerabilities. All critical vulnerabilities must be mitigated within 14 days and all High, Medium, and Low vulnerabilities must be mitigated within 30 days from the date vulnerabilities are identified. A shorter timeframe may be required by CISA in a Binding Operational Directive or Emergency Directive. Variance from approved mitigation must be approved in accordance with USDA POA&M SOP.

5.7 The Contractor shall ensure that government information, other than unrestricted information, being transmitted from federal government entities to external entities is routed through a Trusted Internet Connection (TIC) as defined in TIC 3.0 guidance documentation established by CISA.

5.8 Continuous Monitoring / Ongoing Security Assessment & Authorization (SA&A).

Following the issuance of an ATO, contractors shall support continuous monitoring activities to identify and remediate risks while monitoring changing conditions which could potentially affect the ability to conduct core missions and business functions. The Contractor must work with the FS and supply deliverables and implement activities to support Continuous Monitoring of the system, including annual reviews and updates of ATO documentation such as an SSP, CP, CMP, IRP, DRP and SAR; required testing of CP, DRP and IRP; and POA&M updates.

5.9 As part of Continuous Monitoring, the Contractor must provide requested artifacts, and response to queries, regarding contractor’s security control implementation and practices needed to support the Forest Service demonstrating on-going compliance with Federal security requirements.

5.10 The Contractor shall ensure that information systems or services provided to the FS adhere to all applicable Department of Homeland Security cybersecurity Binding Operational Directives (BODs) and Emergency Directives requirements (https://cyber.dhs.gov/directives/).

5.11 The Contractor shall monitor for, report, and respond to mitigate as required, any security incidents.

https://cyber.dhs.gov/directives/

15 | P a g e

5.12 To comply with the FedRAMP Authorization Act (part of the FY23 National Defense Authorization Act (NDAA), Sec. 5921, page 1055), Executive Order (EO) 14028, as well as guidance from OMB and CISA, the use of any cloud products or services in this acquisition requires authorization in accordance with Federal Risk and Authorization Management Program (FedRAMP) procedures published by GSA, and USDA departmental policies.

5.13 If a cloud solution will be used, then a USDA-issued, FedRAMP- Compliant ATO is a Federal and a Departmental requirement. Although a cloud service provider may have been granted an ATO by the FedRAMP Project Management Office (PMO) or another Federal agency, the Department must also grant an ATO for any cloud services used by the Department, which documents an explicit authorization decision by an Authorization Official within the Department. In addition to the FedRAMP-compliant ATO, the contractor shall complete and maintain an agency SA&A package to obtain agency ATO prior to system deployment/service implementation. More details on FedRAMP requirements can be found at https://www.fedramp.gov/.

5.14 Data Jurisdiction. The Contractor shall store all information within the security authorization boundary, data at rest or data backup, within the Continental United States

(CONUS).

5.15 The Contractor shall understand the terms of the service agreements that define the legal relationships between cloud customers and cloud providers and work with Program Office to develop and maintain a Service Level Agreement (SLA). The SLA will define: (1) Performance metrics, how they will be monitored, and penalties for failure to meet them; (2) Data lifecycle management and data element identification and disposition; (3) Roles, responsibilities, and reporting requirements; and (4) Both parties will be responsible for possessing the SLA.

8. Section 508 – Accessibility of Information and Communications Technology

This contract vehicle is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C.

749d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220). The Revised Section 508 Standards, which consist of 508 Chapters 1 and 2 (Appendix A), along with Chapters 3 through 7 (Appendix C), contain scoping and technical requirements for information and communication technology (ICT) to ensure accessibility and usability by individuals with disabilities. Compliance with these standards is mandatory for Federal agencies subject to Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d).

Each ICT product or service furnished under this contract shall comply with the Revised Section 508 ICT Accessibility Standards at a minimum, as specified in the contract. If any furnished product or service is determined to be noncompliant, the Contracting Officer will notify the Contractor in writing. The Contractor shall, without charge to the Government, remediate or replace the noncompliant products or services within a specified timeframe as determined by the Government in writing. If such remediation or replacement is not completed within the time specified, the Government shall have the following recourses:

https://www.fedramp.gov/

16 | P a g e

1) Cancellation of the contract, delivery, task order, purchase, or line item without termination liabilities; or

2) In the case of custom ICT being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the noncompliant ICT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.

The contractor must ensure all noncompliant ICT products and services are provided pursuant to extensive market research and exhibit the highest level of compliance while satisfying the contract requirements.

For every ICT product or service accepted under this contract by the Government that does not comply with the Revised Section 508 Accessibility Standards, the contractor shall, at the discretion of the Government, remediate or upgrade the item with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date, whichever shall occur first.

Section 508 Compliance Vendors, contractors, and their respective ICT products and services shall comply with the following standards, policies, and procedures. In the event of conflicts between the referenced documents and this contract vehicle, the contract vehicle shall take precedence.

1) Revised Section 508 ICT Accessibility Standards

2) Section 508 of the Rehabilitation Act as amended (29 U.S.C. 794d)

3) Federal Acquisition Regulation (FAR) Subpart 39.2

4) USDA Section 508 Departmental Regulation

Additionally, all contract deliverables are subject to these standards.

All ICT products and services, regardless of format, must conform to the applicable Section 508 standards to allow Federal employees and members of the public with disabilities equivalent access to and use of information and data provided to those without disabilities.

All contractors, sub-contractors, and consultants are responsible for preparing or posting content must comply with the applicable Section 508 accessibility standards and, where applicable, those set forth in the referenced policy or standards document. Remediation of any noncompliant ICT or materials as set forth in this contract vehicle shall be the responsibility of the contractor, sub-contractor, or consultant.

According to the Access Board’s Section 508 Scoping Requirements The following Section 508 provisions apply to the products and/or services identified in this contract vehicle:

• C202 Functional Performance Criteria: Where the requirements in Chapters 4 and 5 do not address one or more functions of telecommunications or customer premises equipment, the functions not addressed shall conform to the Functional Performance Criteria specified in Chapter 3.

• C203 Electronic Content: Electronic content that is integral to the use of telecommunications or customer premises equipment shall conform to the most current WCAG Level A and Level AA Success Criteria and Conformance Requirements.

https://www.access-board.gov/ict/#about-the-ict-accessibility-standards https://www.access-board.gov/law/ra.html#text-of-section-508-of-the-rehabilitation-act-of-1973-as-amended-29-usc-794d https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2039_2.html http://www.ocio.usda.gov/document/departmental-regulation-4030-001 https://www.access-board.gov/ict/#508-chapter-2-scoping-requirements https://www.access-board.gov/ict/#C202-functional-performance-criteria https://www.access-board.gov/ict/#C203-electronic-content

17 | P a g e

• C204 Hardware: Where components of telecommunications equipment and customer premises equipment are hardware, and transmit information or have a user interface, those components shall conform to applicable requirements in Chapter 4.

• C205 Software: Where software is integral to the use of telecommunications functions of telecommunications equipment or customer premises equipment and has a user interface, such software shall conform to C205 and the applicable requirements in Chapter 5.

WCAG Conformance: User interface components, as well as the content of platforms and applications shall conform to the most current WCAG Level A and Level AA Success Criteria and Conformance Requirements.

• C206 Support Documentation and Services: Where support documentation and services and provided for telecommunications equipment and customer premises equipment, manufacturers shall ensure that such documentation and services conform to Chapter 6 and are made available upon request at no additional charge.

In addition, vendors and contractors shall comply with the standards, policies, and procedures below for all ICT pursuant to this contract:

• For Custom ICT Development Services, the vendor or contractor shall ensure the ICT fully conforms to the applicable Revised Section 508 standards prior to delivery and before final acceptance.

• For Installation, Configuration, and Integration Services, the vendor or contractor shall not install, configure, or integrate the equipment and software in a way that reduces the level of conformance with the applicable Revised Section 508 standards.

• For Maintenance, Upgrades, and Replacements, the vendor or contractor shall ensure maintenance upgrades, substitutions, and replacements do not reduce the original level of conformance with the applicable Revised Section 508 standards at the time of the contract award.

• Service Personnel are ensured by the vendor or contractor to possess the knowledge, skills, and ability necessary to address the applicable Revised Section 508 standards and shall provide supporting documentation upon request.

• When providing Hosting Services, the vendor or contractor shall not reduce the existing level of conformance of the electronic content with the applicable Revised Section 508 standards.

• When purchasing ICT where 1) Section 508 validation is not possible prior to award, 2) the ICT will be changed after the award, or 3) ICT will be hosted in a third-party environment, the vendor or contractor shall test and validate the ICT solution for conformance to the Revised Section 508 standards, in accordance with the required testing methods as defined by the agency.

• The vendor or contractor shall document and maintain information regarding the measures taken to ensure compliance with the applicable requirements. This documentation includes but is not limited to testing records, product demonstrations, and reported defects by end users and testers.

• Prior to acceptance, the vendor or contractor shall provide an Accessibility Conformance Report (ACR) for each ICT item that is developed, updated, and/or https://www.access-board.gov/ict/#C204-hardware https://www.access-board.gov/ict/#C205-software https://www.access-board.gov/ict/#C206-documentation-services

18 | P a g e configured for the agency, and when product substitutions are offered. The ACR should be based on the latest version of the Voluntary Product Accessibility Template (VPAT) provided by the Information Technology Industry Council (ITI). To be considered for award, an ACR must be submitted for each ICT item, and must be completed according to the instructions provided by the ITI.

Note: A supplemental ACR may be required if the agency has additional or stricter accessibility requirements than what is outlined in the VPAT.

• Prior to acceptance, the agency reserves the right to require a full working demonstration of the completed ICT item to demonstrate conformance to the agency’s accessibility requirements in addition to independent testing to validate.

• In the case of non-compliance where the vendor or contractor claims its products and/or services satisfy the applicable Revised Section 508 standards specified in the contract vehicle, the contracting officer will promptly inform the vendor or contractor in writing of the non-compliance. The vendor or contractor shall, at no cost to the agency, repair or replace the non-compliant products or services within the period specified by the contracting officer.

All Information and Communications Technology (ICT) subject to the Revised Section 508 standards will be evaluated for Section 508 conformance and usability. The test must be administered by a Federal Section 508 Testing Center. All maintenance for ICT that requires upgrades, modifications, installations, repairs, and purchases shall adhere to the Revised Section 508 standards.

9. IPv6 Requirements Vendor shall provide Supplier Declaration of Conformity SDOC(s) documenting:

(a) Any system, hardware, software, firmware or networked component (voice, video or data) developed, procured or acquired in support or performance of this contract shall be capable of transmitting, receiving, processing, forwarding and storing digital information across system boundaries utilizing system packets that are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 500-267) and corresponding declarations of conformance defined in the USGv6 Test Program. In addition, this system shall maintain interoperability with IPv4 systems and provide at least the same level of performance and reliability capabilities of IPv4 products:

(b) Specifically, any new IP product or system developed, acquired, or produced must:

1) Interoperate with both IPv6 and IPv4 systems and products, and

2) Have available contractor/vendor IPv6 technical support for development and implementation and fielded product management.

(c) As IPv6 evolves, the Contractor commits to upgrading or providing an appropriate migration path for each item developed, delivered, or utilized at no additional cost to the Government.

https://www.section508.gov/sell/vpat http://www.itic.org/policy/accessibility

19 | P a g e

(d) The Contractor shall provide technical support for both IPv4 and IPv6.

(e) Any system or software must be able to operate on networks supporting IPv4, IPv6 or one that supports both.

(f) Any product whose non-compliance is discovered and made known to the Contractor within one year after acceptance shall be upgraded, modified, or replaced to bring it into compliance at no additional cost to the Government.

10. Contract Specialist

Troy Boudro USDA – Forest Service – IT Contracting Branch troy.boudro@usda.gov

11. Contract Officer Representative Roger Garza USDA – Forest Service – CIO

The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements to the Contracting Officer, including Government drawings, designs, specifications: monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies; coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract or order.

mailto:troy.boudro@usda.gov

1. Introduction
2. Business Requirements
3. Technical Requirements
4. Period of Performance
5. Deliverables
Software License Line Item Data
a. Deliverable Schedule:
b. Applicable Documents:
6. Equipment
1. Standard IT Security Language
SECURITY LANGUAGE FOR ALL CONTRACTS
ACQUIRING AND/OR IMPLEMENTING SOFTWARE APPLICATIONS

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .