A.10 SampleTask02 Geospatial-IT-Management Attachment F AMD01.pdf
PDF 259 KB Posted
- Attached to
- REMOTE SENSING & GEOSPATIAL SUPPORT Federal contract opportunity
- Solicitation number
- 12970224R0009
- Issued by
- Department of Agriculture Forest Service
About this file
This document is a Performance Work Statement (PWS) for a Sample Task related to a Remote Sensing & Geospatial Support Indefinite Delivery/Indefinite Quantity (IDIQ) contract with the United States Forest Service (USFS).
The PWS outlines the scope of work, required tasks, and quality assurance measures for providing Geospatial IT Management services to support the USFS Geospatial Technology and Applications Center (GTAC). Key tasks include system/application administration, desktop and notebook support, development and maintenance of geospatial applications and tools, and the development of an understory vegetation AI/deep learning model and web application. The contractor must adhere to IT security, accessibility, and coding requirements. The period of performance is April 2024 to April 2025, with the work primarily performed at GTAC facilities in Salt Lake City, Utah or virtually. This PWS is associated with Solicitation #12970224R0009 for Remote Sensing & Geospatial Support, which is a 100% small business set-aside contract.
View the file
Other files for this federal contract opportunity
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sample Task 02 Remote Sensing & Geospatial Support IDIQ Geospatial IT Management
Solicitation# 12970224R0009
Sample Task 02 GTAC Geospatial IT Management Task Order
Performance Work Statement (PWS) Amendment 001
11 April 2024
1. BACKGROUND
The USDA Forest Service Geospatial Technology and Applications Center (GTAC) is a detached unit of Washington Office Engineering, Technology and Geospatial Services staff, located in Salt Lake City, Utah. As a national technical center, GTAC provides remote sensing, Geospatial Information Systems (GIS), and other geospatial support, services and products to all levels of the Forest Service and its external agency partners. For approximately 20 years, GTAC’s ability to accomplish these objectives has been enabled by the availability of state-of-the-art Information Technology (IT) infrastructure and platforms maintained by highly skilled personnel with a geospatial focus.
2. SCOPE OF WORK/OBJECTIVE(S)
This task is designed to provide management and maintenance for GTAC IT infrastructure, systems and applications, onsite and at offsite federal partner locations. Offsite partner locations include, but are not limited to, Forest Service Virtual Data Center (VDC), Fire National Enterprise Support System (FireNESS), USGS EROS Data Center and NASA Goddard Space Flight Center (GSFC). The scope also includes related IT technical support services to GTAC and Forest Service staff and project cooperators to ensure uninterrupted operations and the delivery of support, services and products.
The Contractor shall provide operation, support, maintenance, troubleshooting and oversight for hardware and software comprising Forest Service GTAC IT systems/applications and associated infrastructure. This general GTAC IT support is applicable to the following areas:
• Obtain FS IT administrative accounts and permissions necessary to perform the following tasks in conjunction with GTAC and CIO staff.
• Maintain and provide technical support for desktop and notebook computers throughout the Center (in conjunction with FS Chief Information Office (CIO) counterparts).
• Maintain and administer processing servers, web servers and storage management devices located at GTAC and offsite locations.
• Maintain and administer GTAC network hardware, software and infrastructure (in conjunction with FS CIO counterparts and USDA Office of the Chief Information Officer (OCIO) counterparts)
• Maintain GTAC environmental/climate condition monitoring for IT rooms (in conjunction with GTAC facility management personnel).
• Maintain and provide technical support for GTAC on-network peripheral devices such as plotters, printers and scanners.
• Maintain and provide technical support for direct attached storage and other devices that connect directly to desktop or notebook computers.
• Maintain and provide technical support for local and enterprise storage solutions (network attached storage devices, cloud storage, etc.).
• Install and configure of approved software used on desktop or notebook computers and servers.
• Design, implement and maintain desktop, server and cloud-based geospatial applications for processing, analysis, modeling, visualization and mapping of remote sensing and other geospatial data.
• Design, implement and maintain websites and web-based geospatial applications for the analysis, visualization, access and delivery of remote sensing and other geospatial data products, map/data services, etc.
• Design, implement and maintain databases to support spatial and non-spatial applications.
• Design, implement and manage of IT solutions for the processing, storage and analysis of large geospatial datasets, particularly imagery and raster data, using physical and virtual infrastructure, cloud processing and analytics platforms, etc.
Due to uncertainties (i.e., frequency and duration of wildfire and hazard/disaster activity, system anomalies/failures, changes in requirements requested by cooperators and end users, etc.), specific technical requirements, types and quantities of deliverables and schedules, all activities over the period of performance shall be defined with joint concurrence by the Contracting Officer Representative (COR), GTAC business lead, the Contractor and relevant project cooperators. Planning and decision-making will be conducted in the context of available task order funding, current programmatic objectives/priorities, support requirements by project stakeholders/end users, and availability of contract support staff.
The number of hours requested by the Government, by labor category, for each task order activity are documented in Section 5.
The resulting task order will be Fixed Firm Price.
3. REQUIRED TASKS
3.1 SYSTEM/APPLICATIONS ADMINISTRATION.
The Contractor shall administer relevant IT devices and infrastructure (e.g., data processing servers, network and direct attached storage devices, production webservers, etc.) located at GTAC and at off-site IT environments. This infrastructure supports and sustains GTAC data storage, data processing, product generation, and delivery operations. System and applications administration activities will be conducted in IT environments provided by the Forest Service CIO, USDA OCIO, agency partners, commercial and government cloud platforms, etc. and include, but are not limited to:
• Maintain IT infrastructure and applications to support generation and storage of derivative remote sensing/geospatial data products, data processing/analysis and product generation, and distribution of data/products to end users.
• Coordinate with IT environment providers to perform automated monitoring and routine inspection of IT devices, infrastructure and applications to verify positive operational status.
• Coordinate with IT environment providers to conduct device and infrastructure administration, maintenance and repair activities.
• Coordinate with IT environment providers to respond to and address detected device and infrastructure failures and anomalies (i.e. hardware or network connectivity failures, etc.) and/or to address system administration needs.
• Coordinate with IT environment providers to plan and execute the installation, maintenance and configuration of approved commercial off-the-shelf (COTS), Government off-the-shelf (GOTS) and custom software/applications/tools to support systems and applications.
• Coordinate with IT environment providers to conduct routine system maintenance/management, including operating system updates/patches, security updates, virus signature updates and other system updates/patches.
• Apply and adhere to IT security protocols, checks and controls for provided IT environments.
• Comply with prescribed change management procedures for provided IT environments to initiate and execute requests/changes to IT infrastructure, environments and applications.
• Coordinate with the COR and GTAC business lead to document and maintain an inventory of all GTAC IT property to ensure its availability and security.
• Notify the COR and other key GTAC personnel if significant IT system failure or anomaly events occur.
3.1.1 QASP MEASURE. The Contractor effectively follows and adheres to change management procedures and IT best practices to support system administration activities in provided IT environments.
3.1.2 QASP MEASURE. The Contractor effectively leverages systems, tools and capabilities afforded by IT environment providers to ensure availability of GTAC IT infrastructure and applications and their access by end users.
3.1.3 QASP MEASURE. The Contractor coordinates with GTAC IT environment providers and delivers effective system administration and application management so that problems are detected and mitigations initiated within one (1) business day of detection.
3.2 DESKTOP AND NOTEBOOK SUPPORT.
The Contractor shall provide GTAC staff and on-site contract personnel with technical support for Forest Service desktop and notebook computers, associated applications, and related technologies. This support is supplemental to USDA Client Experience Center (CEC) support. Contractor support consists of troubleshooting and remediation of problems; and specification, configuration, and testing of computers, software and peripherals within established agency standards and guidelines. The Contractor will consult with the COR and GTAC business lead as necessary to prioritize support activities/tasks.
3.2.1 QASP Measure. Contractor provides initial response within one (1) business day to assistance requests received from GTAC staff or forwarded by the COR.
3.2.2 QASP Measure. Contractor provides accurate, reliable and complete technical support services and ensures proactive maintenance procedures are conducted.
3.3 APPLICATIONS, TOOLS AND UTILITIES DEVELOPMENT/MAINTENANCE.
The Contractor shall develop and maintain relevant IT applications, tools and utilities used by GTAC and its cooperators for processing, analysis, modeling, visualization and mapping of remote sensing and other geospatial data. These activities include implementation of new development efforts and/or technical updates and enhancements as necessary to existing capabilities to facilitate continuity in production workflows and delivery of accurate and consistent geospatial products. New development efforts or enhancements to existing capabilities shall be conducted in coordination with the COR and GTAC business lead and may include, but are not limited to:
• Development/maintenance of script-driven, graphic user interfaces for desktop geospatial software applications that support automated or semi-automated geospatial workflows and generation of accurate and standardized geospatial products (e.g. Event Mapping Tool, RSAC ERDAS tools, LPGS tools, etc.).
• Development/maintenance of workflow scripts and tools within geospatial processing, analysis, modeling, visualization and mapping frameworks of Forest Service enterprise commercial geospatial packages (ERDAS, ESRI, etc.), open-source geospatial packages (QGIS, GDAL, etc.) and cloud-computing platforms/technologies (Google Earth Engine, etc.) to support broader use by the Forest Service and external agency cooperators.
• Development/maintenance of customized tools to generate data visualization outputs (e.g. NIROPS KML generator, etc.).
• Development/maintenance of customized scripts/tools to support specific airborne imagery/data processing and analysis workflows and/or automation of repetitive tasks.
3.3.1 QASP MEASURE. The Contractor updates and maintains scripts/code as necessary and as directed by the COR and GTAC business lead to maintain operational continuity of the geospatial workflows and frameworks.
3.3.2 QASP MEASURE. The Contractor adheres to best coding practices/standards and scripts/code are appropriately documented and thoroughly tested prior to delivery to COR and GTAC business lead for review.
3.3.3 QASP MEASURE The Contractor shall conduct script/code integration with no or minimal interruption to operational continuity and/or functionality of the production/mapping framework (interruptions shall not exceed more than one (1) day).
3.4 UNDERSTORY VEGETATION AI/DEEP LEARNING MODEL AND WEB
APPLICATION.
The Contractor shall develop an understory vegetation AI/deep learning model to be utilized within ArcGIS Online (AGOL) using the AGOL Image Analyst extension capability. The output AI/deep learning model shall be posted to the USFS AGOL enterprise account/site using a GTAC AGOL Headless account. Data outputs from this model shall be shared and presented to the public via a custom developed web application (cannot use ESRI products).
• This AI/deep learning model shall be created to map understory vegetation for the Heen Latinee Experimental National Forest on the Tongass National Forest.
• Input vegetation data for the model shall be provided by the government and shall include TEUI data, Existing Vegetation Data, Tree Canopy Cover data, Photo-interpreted vegetation dominance type from aerial photos, and 2,000 ground collected understory vegetation plots.
o Model must use the 2,000 ground collected understory vegetation plots, all other datasets are optional o Model must produce a 5 class understory vegetation output dataset utilizing 1 to 25 acre polygon segments provide by the government.
• Remote sensing data for the model shall be gathered by the contractor and shall include: aerial imagery and satellite imagery (Worldview, LANDSAT, Sentinel) o 15cm UAS Imagery shall be provided by the government
• The web application must display the 5-class understory vegetation output polygon dataset, allow the user to zoom in/out between 1:500 and 1:250,000 scale, have a thematic map display, allow the user to query understory vegetation type by clicking on a polygon within the map interface, and pan/zoom & return query results within 2 seconds of user input.
o The web application shall be hosted at the USDA FS Virtual Data Center (VDC).
All FS Service Now hosting processes and administration requirements shall be utilized and followed Proper coordination with CIO shall be required o The web application shall not utilize ESRI tools or other commercial software.
o The web application shall make use of open source JavaScript web mapping options
• Activity 3.4 deliverables:
o AI/deep learning model
Database/Folder structure of imagery used in model o Web Application
3.4.1 QASP MEASURE. Understory vegetation products are developed using suitable imagery for the appropriate and/or requested assessment timing as assessed by the COR.
3.4.2 QASP MEASURE. The Contractor updates and maintains scripts/code as necessary and as directed by the COR and GTAC business lead to maintain operational continuity of the geospatial workflows and frameworks.
3.4.3 QASP MEASURE. The Contractor adheres to best coding practices/standards and scripts/code are appropriately documented and thoroughly tested prior to delivery to COR and GTAC business lead for review.
3.4.4 QASP MEASURE The Contractor shall conduct script/code integration with no or minimal interruption to operational continuity and/or functionality of the production/mapping framework (interruptions shall not exceed more than one (1) day).
4. OPTIONS
RESERVED
5. COMPLIANCE
Where applicable, the contractor shall provide deliverables in Plain Language (www.plainlanguage.gov) and in compliance with Section 508 of the Rehabilitation Act of 1973.
6. OTHER REPORTING REQUIREMENTS
The Contractor shall archive all relevant IT infrastructure management documentation, IT systems/applications documentation, meeting records/notes and other essential documentation in a storage location designated for the project. The Contractor shall keep the COR informed of activity conducted on this task order via labor reports for each billing period. Reports shall include daily hours worked by contract staff name, their associated labor category and description of accomplished activity(ies).
7. PLACE OF PERFORMANCE
The contractor must perform activities 3.1 and 3.2 at the Government-leased facilities at GTAC. Activity 3.3 and 3.4 shall performed virtually from a location approved by the COR.
8. PERIOD OF PERFORMANCE
The Contractor shall complete all work under the task order on or before 02 April 2025.
9. TRAVEL
Travel for this task order is unknown at this time, but may be necessary to address currently unanticipated meetings, coordination or support functions associated with GTAC IT infrastructure or IT system/application management activities. When travel is required, the contractor shall employ the most economical and efficient means of travel, including number of hours for travel. Prior to incurring any travel expense on a cost reimbursable basis, the contractor shall obtain written authorization to travel from the Contracting Officer or COR.
The Contractor shall provide justification for why travel is necessary and include travel dates, origin/destination, personnel traveling, and an estimate of total travel and labor cost, including supporting documentation. Travel shall be in accordance with FAR Part 31.205-46.
Reimbursement claims for expenses must be supported by valid receipts. The contractor shall provide a trip report to the COR within five (5) days of completion of travel.
10. GOVERNMENT FURNISHED PROPERTY (GFP)
GFP provided is in accordance with the basic contract.
11. MISSION ESSENTIAL SERVICES
Services under this task order are deemed as Mission Essential. Mission Essential services may require performance under all circumstances to ensure the protection of life, health, and safety of individuals. Notwithstanding any other clause of the contract, the contractor shall be responsible to perform those services identified as Mission Essential during crisis situations, as identified by the COR or Contracting Officer. In the event the contractor anticipates not being able to perform any of the Mission Essential services identified in the task order during a crisis situation, the contractor shall immediately notify the Contracting Officer, the COR, and any other designated representative and use its best efforts to cooperate with the Government in the Government’s efforts to maintain continuity of operations.
Unscheduled call-in support is not required; however, the Contractor shall coordinate with the COR to determine the appropriate contractor staff preparedness level to address emergency needs that may arise outside of normal business hours. This PWS shall not be interpreted as a service level agreement (SLA) that requires unplanned support outside of normal business hours.
The Government reserves the right in such crisis situations to use federal employees, or contract support from other contractors for Mission Essential services. The contractor shall segregate and separately identify all costs incurred in continuing performance of Mission Essential services in a crisis situation. The contractor shall notify the Contracting Officer of the costs within thirty days after continued performance has been directed by the Contracting Officer. The contractor shall include this paragraph as a clause in subcontracts.
12. SECURITY
Section 1
By accepting this contract/agreement, the Contractor/Cooperator and other external organizations (hereafter called Contractor) providing Information Technology (IT) resources or services to the US Forest Service (FS) agrees to comply with the applicable IT security policy as outlined in this document. The Contractor and other external organizations will be responsible for IT security for all systems connected to the FS network or operated by the Contractor and other external organizations for the FS, regardless of location. This clause is applicable to all or any part of the contract that includes IT resources or services in which the Contractor and other external organizations must have physical or electronic access to FS sensitive information that directly support the mission of the FS. The term “information technology,” as used in this clause, means any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information. This includes both major applications and general support systems as defined by OMB Circular A-130.
The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this task. The Contractor shall also protect all unclassified Government data, equipment, etc., by treating information as sensitive business, confidential information, controlling and limiting access to the information, and ensuring the data and equipment are secured within their facility.
The Contractor or other external organization will not publish or disclose in any manner, without the FS Contracting Officer’s written consent, the details of any programs, documentation, data, or safeguards either designed or developed by the Contractor or other external organization under this Contract or otherwise provided by the Government. The Contractor may be required to sign non-disclosure or other appropriate security agreements.
A written agreement between the FS and any contractors and other external organizations will be entered into before FS data and information otherwise exempt from public disclosure may be disclosed to the contractors and other external organizations. The Contractor and other external organizations will agree to establish and follow security precautions considered by the FS to be necessary to ensure proper handling of data and information. As may be identified elsewhere in this contract, the Contractor agrees that:
• The draft and final deliverables and all associated working papers and other materials deemed relevant by the COTR that have been generated by the Contractor in the performance of this contract are the property of the U.S. Government and must be submitted to the COTR at the conclusion of the tasks.
• All documents produced for this project are the property of the U.S. Government and cannot be reproduced or retained by the Contractor.
To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor will afford the Government access to the Contractor’s or other external organization’s facilities, installations, technical capabilities, operations, documentation, records, and databases. The Contractor will cooperate with Federal agencies and their officially credentialed representatives during official inspections or investigations concerning the protection of FS information. Cooperation may include providing relevant documentation showing proof of compliance with federal and agency requirements, and rendering other assistance as deemed necessary.
If new or unanticipated threats or hazards are discovered by either the Government or the Contractor or other external organization, or if existing safeguards have ceased to function, the discoverer will immediately bring the situation to the attention of the other party. The Contractor will report real or suspected incidents or violations immediately upon discovery to the USDA Computer Incident Response Team (CIRT), by e-mail, at cyber.incidents@usda.gov.
The Contractor shall insert these clauses in all subcontracts when the subcontractor is required to have routine physical access to a federally controlled facility and/or routine access to a federally controlled information system. Failure to comply with said requirements will constitute cause for termination.
The Contractor Agrees To –
(a) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies—
(i) The systems of records; and
(ii) The design, development, or operation work that the contractor is to perform;
(b) Include the Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and mailto:cyber.incidents@usda.gov
(c) Include this clause, including this paragraph (3), in all subcontracts awarded under this contract that requires the design, development, or operation of such a system of records.
In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency.
Definitions of the clause:
(a) “Operation of a system of records,” as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records.
(b) “Record,” as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person’s name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voiceprint or a photograph.
(c) “System of records on individuals,” as used in this clause, means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
The contractors and other external organizations will ensure that the following banner is displayed on all FS systems that contain Privacy Act information operated by the contractors and other external organizations prior to allowing anyone access to the system:
“This system contains information protected under the provisions of the Privacy Act of 1974 (Public Law 93-579). Any privacy information displayed on the screen or printed must be protected from unauthorized disclosure. Employees who violate privacy safeguards may be subject to disciplinary actions, a fine of up to $5,000, or both.”
Section 2
IT Security Training: The Contractor and other external organizations will ensure that its employees performing under this contract fulfill all Forest Service requirements for mandatory security awareness and role-based advanced security training in accordance with OMB Circular A-130, FISMA, and NIST requirements, and sign all applicable FS statements of responsibilities.
Background Investigations: All non-government employees with unescorted access to FS facilities, computer systems and/or FS information must have background investigations commensurate with the level of risk and magnitude of loss or harm. The FS will determine the level of background investigation and position classification needed.
Personal Identity Verification of Contractor Personnel: The Contractor shall be responsible for ensuring compliance by its employees with all applicable federal regulations, to include those of GSA, NIST, USDA, FS and HSPD-12. Contractors and their employees are subject to all Federal laws applicable to Government installations and are under the jurisdiction of the Federal Protective Service (FPS). The Contracting Officer Representatives (CORs; also known as Contracting Officer Technical Representatives), or other designated program/project officers, in conjunction with the FS HCM HSPD-12 staff, will assist the Contractor in processing the required Security Background Investigations/Clearances.
(1) The Contractor shall comply with the personal identity verification (PIV) policies and procedures established by U.S. Department of Agriculture (USDA) Directives 3800 series.
(2) Should the results of the PIV process require the exclusion of a Contractor’s employee, the Contracting Officer will notify the Contractor in writing.
(3) The Contractor must appoint a representative to manage this activity and to maintain a list of employees eligible for a USDA PIV ID Badge required for performance of the work.
(4) The responsibility of maintaining a sufficient workforce remains with the Contractor.
Employees may be barred by the Government from performance of the work should they be found ineligible or to have lost eligibility for a USDA PIV ID Badge. Failure to maintain a sufficient workforce of employees eligible for a USDA PIV ID Badge may be grounds for termination of the contract.
(5) The Contractor shall insert this clause in all subcontracts when the subcontractor is required to have access to a federally controlled facility or information system.
(6) The PIV Sponsor for this contract is the Contracting Officer Representative (COR), unless otherwise specified in this contract. The PIV Sponsor will be available to receive contractor identity information from * (hours and days) to * (hours and days) at * (office address for registration). The Government shall notify the Contractor if there is a change in the PIV Sponsor, the office address, or the office hours for registration.
(7) At this time, the Government will pay for and process all required security investigations/clearances, except as identified differently within this clause.
(8) The Contractor should be aware of any of its employees possibly having had a background investigation through another government agency. The investigation that was conducted, if verifiable by the FS HSPD-12 staff, and if it was completed within the last 5 years, can be accepted by the Government in lieu of a background check.
(9) The Contractor shall comply with any facility badging requirements for the issuance of building access, badges, etc.:
• Ensure that each of the Contractor’s employees has been issued either a temporary or permanent badge from the Government. A permanent badge will not be issued until the security questionnaire has been completed and favorably reviewed. Temporary or visitor badges will be provided for persons who are identified as having an infrequent or temporary legitimate business need for access to the site. As noted above, periods that exceed 180 days will require a permanent badge. The badge must be worn at all times while in the facility. It must be displayed above the waist. The individual will retain possession of the badge as long as continued admittance to the site is needed.
• Ensure the safekeeping, wearing, and visibility of Government-furnished badges.
• Immediately return all badges and permits to the Government when such need ceases to exist.
(10) The Contractor shall comply with any facility security requirements for access to the facility.
(11) The Contractor shall comply with all applicable rules governing parking at USDA locations.
Section 3
Secure Coding Skills: Contractor certifies that at least one member of each programming team working on any code (including C, Java, .Net, ASP.NET, Visual Basic) to be delivered to the Forest Service has earned the Global Information Assurance Certification for Secured Software Programming or equivalent.
Source code testing, binary code testing, application scanning, and penetration testing:
At least one week prior to delivery of any code due under this contract, Contractor will deliver to the COTR the following reports covering all code that will be delivered:
A. Source code testing results showing all potential security flaws identified by at least one of the commercial source code testing tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor will highlight all vulnerabilities rated “critical” and “high.” The Contractor must then correct the vulnerabilities, resend the code, and ensure the health of delivered source code.
B. For web applications, web application scanning test results showing all potential security flaws identified by at least one of the commercial web application scanning tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor will highlight all vulnerabilities rated “critical” and “high.”
C. For all applications: application penetration results.
Copyright Management and Responsibility: By delivering applications or programming code to the Federal Government, the vendor or Contractor certifies that they have the proper authority to transfer the property and will defend the Government against copyright or other lawsuit resulting from the application or programming delivered.
Section 4
The Contractor or other external organizations will develop, provide, implement, and maintain an IT System Security Plan for any system that includes acquisition, transmission or analysis of data owned by FS with significant replacement cost should the Contractor’s and other external organization’s copy be corrupted. This plan will describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. The plan will describe those parts of the contract to which this clause applies. The Contractor or other external organization’s IT System Security Plan will be compliant with applicable Federal laws that include, but are not limited to: (e.g., the Clinger-Cohen Act of 1996 and the Federal Information Security Management Act of 2002). The IT System Security Plan will meet IT security requirements in accordance with Federal and FS policies and procedures that include, but are not limited to: National Institute of Standards and Technology (NIST) SP 800-53 Guidelines.
The Contractor and other external organizations will ensure that the appropriate security banners are displayed on all FS systems (both public and private) operated by the contractors and other external organizations prior to allowing anyone access to the system.
13. SECTION 508/IT ACCESSIBILITY REQUIREMENTS
Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use information and communication technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public who have disabilities must have access to, and use of, information and data that is comparable to people without disabilities.
1. Products, platforms and services delivered as part of this work statement that are ICT, or contain ICT, must conform to the Revised 508 Standards, which are located at 36 C.F.R.
§ 1194.1 & Apps. A, C & D, and available at https://www.access-board.gov/guidelines-https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines
Item that contains ICT: FY22 GTAC IT Infrastructure Management and IT Systems- Applications Support
Applicable Functional Performance Criteria: All functional performance criteria apply when using an alternative design or technology that achieves substantially equivalent or greater accessibility and usability by individuals with disabilities, than would be provided by conformance to one or more of the requirements in Chapters 4-6 of the Revised 508 Standards, or when Chapters 4-6 do not address one or more functions of ICT.
Applicable requirements for software features and components: All WCAG Level AA Success Criteria, 502 Interoperability with Assistive Technology, 503 Application
Applicable requirements for hardware features and components: All requirements apply
Applicable support services and documentation: All requirements apply
Instructions to Offerors
1. Provide an Accessibility Conformance Report (ACR) for each commercially available Information and Communication Technology (ICT) item offered through this contract. Create the ACR using the Voluntary Product Accessibility Template Version
2.1 or later, located at https://www.itic.org/policy/accessibility/vpat. Complete each ACR in accordance with the instructions provided in the VPAT template. Each ACR must address the applicable Section 508 requirements referenced in the Work Statement. Each ACR shall state exactly how the ICT meets the applicable standards in the remarks/explanations column, or through additional narrative. All "Not Applicable" (N/A) responses must be explained in the remarks/explanations column or through additional narrative. Address each standard individually and with specificity, and clarify whether conformance is achieved throughout the entire ICT Item (for example - user functionality, administrator functionality, and reporting), or only in limited areas of the ICT Item. Provide a description of the evaluation methods used to support Section 508 conformance claims. The agency reserves the right, prior to making an award decision, to perform testing on some or all of the Offeror’s proposed ICT items to validate Section 508 conformance claims made in the ACR.
2. Describe your approach to incorporating universal design principles to ensure ICT products or services are designed to support disabled users.
3. Describe plans for features that do not fully conform to the Section 508 Standards.
4. Describe "typical" user scenarios and tasks, including individuals with disabilities, to ensure fair and accurate accessibility testing of the ICT product or service being offered.
https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.itic.org/policy/accessibility/vpat
Acceptance Criteria
1. Prior to acceptance, the government reserves the right to perform testing on required ICT items to validate the offeror’s Section 508 conformance claims. If the government determines that Section 508 conformance claims provided by the offeror represent a higher level of conformance than what is actually provided to the agency, the government shall, at its option, require the offeror to remediate the item to align with the offeror’s original Section 508 conformance claims prior to acceptance.
| 1. BACKGROUND |
| 2. SCOPE OF WORK/OBJECTIVE(S) |
| 3. REQUIRED TASKS |
| Notify the COR and other key GTAC personnel if significant IT system failure or anomaly events occur. |
| 3.1.1 QASP MEASURE. The Contractor effectively follows and adheres to change management procedures and IT best practices to support system administration activities in provided IT environments. |
| 3.1.2 QASP MEASURE. The Contractor effectively leverages systems, tools and capabilities afforded by IT environment providers to ensure availability of GTAC IT infrastructure and applications and their access by end users. |
| 3.1.3 QASP MEASURE. The Contractor coordinates with GTAC IT environment providers and delivers effective system administration and application management so that problems are detected and mitigations initiated within one (1) business day of detection. |
| Development/maintenance of script-driven, graphic user interfaces for desktop geospatial software applications that support automated or semi-automated geospatial workflows and generation of accurate and standardized geospatial products (e.g. Event ... |
| Development/maintenance of workflow scripts and tools within geospatial processing, analysis, modeling, visualization and mapping frameworks of Forest Service enterprise commercial geospatial packages (ERDAS, ESRI, etc.), open-source geospatial pack... |
| 3.3.1 QASP Measure. The Contractor updates and maintains scripts/code as necessary and as directed by the COR and GTAC business lead to maintain operational continuity of the geospatial workflows and frameworks. |
| 3.3.2 QASP Measure. The Contractor adheres to best coding practices/standards and scripts/code are appropriately documented and thoroughly tested prior to delivery to COR and GTAC business lead for review. |
| 3.3.3 QASP Measure The Contractor shall conduct script/code integration with no or minimal interruption to operational continuity and/or functionality of the production/mapping framework (interruptions shall not exceed more than one (1) day). |
| 3.4.1 QASP Measure. Understory vegetation products are developed using suitable imagery for the appropriate and/or requested assessment timing as assessed by the COR. |
| 3.4.2 QASP Measure. The Contractor updates and maintains scripts/code as necessary and as directed by the COR and GTAC business lead to maintain operational continuity of the geospatial workflows and frameworks. |
| 3.4.3 QASP Measure. The Contractor adheres to best coding practices/standards and scripts/code are appropriately documented and thoroughly tested prior to delivery to COR and GTAC business lead for review. |
| 3.4.4 QASP Measure The Contractor shall conduct script/code integration with no or minimal interruption to operational continuity and/or functionality of the production/mapping framework (interruptions shall not exceed more than one (1) day). |
File details come from the government source that posted it. Updated .