SOW_-_FINAL_PRESOLICITATION.docx

DOCX document 277 KB Posted

Attached to
NASIS for BIE Federal contract opportunity
Solicitation number
140A1619Q0071
Issued by
Department of the Interior Bureau of Indian Affairs Central Office

About this file

Statement of Work

View the file

Other files for this federal contract opportunity

Other files attached to NASIS for BIE, newest first.
File Type Posted
Q&A_FINAL.pdf PDF
Sol_140A1619Q0071_Amd_0001.pdf PDF
RDD_-_FINAL_1.4.pdf PDF
B08_Solicitation_140A1619Q0071.pdf PDF
DOI_Cloud_Policy_-_FINAL.pdf PDF
Sol_140A1619Q0071.pdf PDF
RDD_Crosswalk.xlsx XLSX spreadsheet
Federal_Cloud_Policy_-_FINAL.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Bureau of Indian Education Programs

Native American Student Information System (NASIS) Statement of Work (SOW) Bureau of Indian Affairs

Document Created: 12 February 2018

Last Updated: 19 March 2019

Version 3.0

Table of Contents

C. STATEMENT OF WORK6
C.1 Introduction6
C.1.1 Project Description6
C.1.2 Background6
C.1.3 Concept of Operations7
C.2 GENERAL REQUIREMENTS8
C.2.1 SYSTEM REQUIREMENTS8
C.2.2 DEPARTMENT OF THE INTERIOR REQUIREMENTS8
C.2.2.1 Services Delivery Method9
C.2.2.2 Contingency Planning and Disaster Recovery9
C.2.2.3 System Security Plan9
C.2.2.4 Annual System Security Review9
C.2.2.5 Assessment and Authorization9
C.2.2.6 Infrastructure10
C.2.2.7 Section 508 Compliance10
C.2.2.8 Background Investigations11
C.2.2.9 Non-disclosure Agreement11
C.2.2.10 Security Awareness Training (SAT)11
C.2.2.11 Personnel Changes11
C.2.2.12 Contractor Location11
C.2.2.14 Intellectual Property Rights11
C.2.2.15 Independent Validation and Verification (IV&V)11
C.2.2.17 System Logon Banner12
C.2.2.18 Incident Reporting12
C.2.2.19 Quality Control (Malware Code)12
C.2.2.20 Annual Self-Assessment13
C.2.2.21 System Logon Banner Acknowledgement13
C.2.2.22 Security Controls13
C.2.2.23 Contingency Plan14
C.2.2.24 Vulnerability Analysis14
C.2.2.25 Privacy Impact Assessment (PIA)14
C.2.2.26 System Of Record Notice (SORN)14
C.2.2.27 List of IT Security Related Deliverables:15
C.2.3 CSAS-ASP SERVICES16
C.2.4 PROGRAM TECHNICAL SUPPORT16
C.2.5 BIE ASP OPERATIONAL CONTROL16
C.3 SPECIFIC TASKS16
C.3.1 PROJECT MANAGEMENT AND PLANNING (Task 1)16
C.3.1.1 Project Implementation Plan (PIP)17
C.3.1.2 Monthly Status Reports17
C.3.1.3 Weekly Status Report17
C.3.1.4 Weekly Progress Meetings17
C.3.1.5 Action Item Tracking18
C.3.1.6 Quarterly Progress Review18
C.3.1.7 Web-based Project Information Exchange18
C.3.1.8 Project Kick-off Meeting18
C.3.2 REPORTING AND ANALYSIS SERVICES (Task 2)18
C.3.2.1 ESSA Reporting18
C.3.2.1.1 Consolidated State Performance Report (CSPR)18
C.3.2.1.2 Annual Measurement of Achievement (AMA)19
C.3.2.1.3 Consolidated BIE State Report Card19
C.3.2.1.4 Individual School Report Cards20
C.3.2.1.5 Teacher Qualifications Report20
C.3.2.2 ISEP Reporting21
C.3.2.2.1 Instructional Average Daily Membership (ADM)21
C.3.2.2.2 Residential Attendance21
C.3.2.2.3 Calculation Report22
C.3.2.2.4 Instructional Certification Report22
C.3.2.2.5 Residential Certification Report22
C.3.2.2.6 Student Count Waiver Request Form22
C.3.2.2.7 30 Day Residential Report22
C.3.2.2.8 Instructional First 10 Day of school year23
C.3.2.2.9 Absence 10 Consecutive Days23
C.3.2.3 SPED/OSEP Reporting (U.S. Department of Education EDEN Submission)24
C.3.2.3.1 Students with Disability Count24
C.3.2.3.2 Personnel24
C.3.2.3.3 Environments24
C.3.2.3.4 Exits25
C.3.2.3.5 Discipline25
C.3.2.3.6 Achievement26
C.3.2.3.7 Coordinated Early Intervening Service26
C.3.2.3.8 State Performance Plan Indicators26
C.3.2.4 GPRA Report27
C.3.2.5 Common Core Data27
C.3.2.6 Management Reporting27
C.3.2.6.1 Revised Utilization Report27
C.3.2.6.2 Data Integrity Report27
C.3.2.7 EDFACTS Reporting28
C.3.2.8 AMA Data Elements28
C.3.2.8.1 Assessment Set-up/Load28
C.3.2.8.2 Full Academic Year (FAY) Set-up28
C.3.2.8.3 Participation Rate Set-up for 23 States29
C.3.2.8.4 Attendance Rate Set-up29
C.3.2.8.5 Graduation Rate Set-up29
C.3.2.8.6 Data Validation29
C.3.2.8.7 Military Student Data Identifier31
C.3.2.8.8 Foster Care Student Data Identifier31
C.3.2.8.9 Homeless Student Data Identifier31
C.3.3 FEDERAL GOVERNMENT REPORTING REQUIREMENTS – Configuration (Task 3)31
C.3.3.1 Special Education IEP Forms31
C.3.3.2 Special Education Process Forms31
C.3.3.3 FACE Program31
C.3.3.4 Gifted and Talented32
C.3.3.5 English Learners32
C.3.4 TRAINING (Task 4)32
C.3.4.1 Interchange Training32
C.3.4.2 WebEx Training32
C.3.4.3 NASIS User Training32
C.3.4.3.1 System Administrator Training32
C.3.4.3.2 Registrar/Census Training32
C.3.4.3.3 Teacher Grade Book Training32
C.3.4.3.4 Residential Training32
C.3.4.4 Special Education Forms/Process Training and Other Supplemental Programs33
C.3.4.5 Class Scheduling Training33
C.3.4.6 BIE NASIS Program Certification Training33
C.3.4.6.1 BIE Specific Topic33
C.3.4.6.2 BIE Specific Training Materials33
C.3.5 DATA CLEAN-UP (Task 5)33
C.3.5.1 Data Synchronization33
C.3.5.2 Data Standardization33
C.3.6 NASIS SYSTEM OPERATION AND MAINTENANCE (O&M) (Task 6a, 6b & 6c)34
C.3.6.1 License (Task 6a)35
C.3.6.2 Application Hosting (Task 6b)35
C.3.6.2.1 Managed Hosting36
C.3.6.2.2 Cloud Hosting36
C.3.6.3 Help Desk Support (Task 6c)36
C.3.6.3.1 Support Summary Reports36
C.3.6.3.2 Data Integrity Assistance/ISEP36
C.3.6.3.3 Data Integrity Assistance/Other36
C.3.6.3.4 Ongoing Technical Support36
C.3.7 DELIVERABLES37

C. STATEMENT OF WORK

C.1 Introduction The Statement of Work (SOW) has been prepared in conjunction with the Requirements Definition Document (RDD), and the RDD should be considered as part of the SOW in its entirety.

This Requirements Definition Document (RDD) describes the Native American Student Information System (NASIS) business and functionality requirements.

This RDD was prepared by the Bureau of Indian Education (BIE) Chief Academic Office, Division of School Operations and the Indian Affairs, Office of Information Management Technology (IA-OIMT). The RDD supports the following activities:

· Procurement of the system

· Design and development of the system

· Evaluation of the product in all subsequent phases of the life cycle

· Enhancement of the product in all subsequent phases of the life cycle

· Monitor and determine the success criteria of the project C.1.1 Project Description The purpose of the Native American Student Information System (NASIS) investment is to improve student achievement through a student information data management system for the Bureau of Indian Education. NASIS will deliver services to the BIE Central Office as well as related services to the schools.

C.1.2 Background School Year 2018-2019 will be the 13th year of the Bureau of Indian Education’s (BIE) Native American Student Information System (NASIS). The current NASIS system is implemented and utilized by 186 bureau-funded schools and peripheral dormitories, Albuquerque Service Center (ASC), Education Resource Centers (ERC) and Central BIE offices. NASIS is a web-based centralized Application Service Provider (ASP) provided student information system meeting the unique geographical, environmental, and technological requirements and constraints of the BIE’s national school system located in 23 states, with approximately 46,000 students in grades kindergarten to twelve as well as Family and Child Education (FACE). The Indian School Equalization Program (ISEP) is the base school program funding source for all bureau-funded schools. The BIE is comprised of a Central office located in Washington, DC, that includes the Office of the Director and the Associate Deputy Director, Division of Performance and Accountability (DPA) located in Albuquerque, NM, three Associate Deputy Director Offices, Education Resource Centers nationwide, and 186 schools and dormitories in the continental United States. Relative to Federal reporting requirements, the BIE is considered a State entity. Thus, NASIS is set up as a bureau-wide system supporting both state and school level functionality.

The reporting and analysis includes the requirements of the Indian School Equalization Program, the Educational Amendments of 1978 P.L. 95-561, Elementary and Secondary Education Act of 1965, reauthorized as the “Every Student Succeeds Act (ESSA)”, P.L. 114-95, and the Individuals with Disability Education Act (IDEA). ESSA mandates BIE to collect and report on Title I, II, IV, VI, and X requirements. Reporting and analysis includes the Department of the Interior, Indian School Equalization Program including the 15% set-aside for Special Education (SPED), ISEP supplemental programs (Gifted and Talented and Language Development, Enhancement Program, and Family and Child Education Program (FACE).

Hyperlinks:

· NIST SP 800-53 Rev. 4 https://csrc.nist.gov/csrc/media/publications/sp/800-53/Rev. 4/archive/2013-04-30/documents/sp800-53-rev4-ipd.pdf

· NIST SP 800-64 Rev. 2 https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final

C.1.3 Concept of Operations BIE successfully implemented NASIS with required reporting and analysis identified in the Requirements Definition Document (RDD). This SOW addresses the need for on-going operations and maintenance, continued and new training, and updates to meet the BIE’s federal reporting and analysis requirements meeting mandated Public Laws 114-95 Every Student Succeeds Act (ESSA), and Individuals with Disabilities Act (IDEA). The contractor will provide BIE a web-based, centralized student information system as an ASP on per student basis at all bureau-wide sites. NASIS is a centralized system for supporting teachers, other school staff, students, parents and Central Office staff. The BIE will provide reports required by Federal and State education agencies, and provide the data to analyze student performance and to use in school improvement planning.

C.2 GENERAL REQUIREMENTS

C.2.1 SYSTEM REQUIREMENTS

The Contractor shall provide Centralized, School Administration Services as an ASP (CSAS-ASP) for three organizational levels within the bureau-wide BIE school system. These levels are:

Central Office (including Central Office staff located in sites other than the DC Office): Offices reviewing or collecting data from all BIE schools for appropriate purposes as required by law on an annual and as needed basis. Data access shall be limited to read only and to specific types or categories of school data as determined by BIE. The system shall provide an ad-hoc reporting capability and the capability to download and/or export data in a variety of formats for appropriate compilation and submission of reports to U.S. Congress, U.S. Department of Education, 23 states, and all federal reporting entities. BIE may require changes made to the system when new data requirements are identified.

Education Resource Center (ERC): An ERC is a regional office/sub-district that provides oversight to an assigned number of schools. Data access for system users in this category shall be limited to read only and to specific types or categories of school data as determined by BIE. The system shall have the ability to restrict data access for each ERC to those schools under its purview. Currently, there are 15 regional ERCs; however, this number may change. The system shall accommodate organizational changes that include realignment of the specific schools under each ERC. School Site: A BIE-funded school or residential dormitories in the continental United States is a School Site. Data access for system users in this category shall be restricted to only that data pertinent to each specific school. Within each BIE school, data access shall be limited by definitive school positions and follow the read/write, read only, or no access provisions of the vendor's application and database management software as reviewed and accepted by BIE. The system shall accommodate additions, restructuring, and elimination of school sites.

C.2.2 DEPARTMENT OF THE INTERIOR REQUIREMENTS

The technology used by the system shall continue to comply with the technology standards approved by the Chief Information Officer (CIO) and the system architecture shall follow the guideline specified in the N-Tier Architecture. The Contractor shall operate and maintain the CSAS-ASP to include providing application software system support, updates, and new version releases, help desk support and user training.

The contractor is providing program Information Technology services and will perform these services in a Department of the Interior (DOI) or Indian Affairs (IA) Office of Information Management Technology (OIMT) approved development and/or test environments only. The DOI, IA-OIMT or one of their approved hosting entities are the only entities allowed to procure, operate, secure and maintain infrastructure and operational environments. The contractor through the guidance of CO and/or COR will adhere to all DOI and IA-OIMT established Information Technology regulations, policies and directives to include but not limited to capital planning, investment review, lifecycle management, change management, security and authority to operate. All production environments regardless of the hosting entity will be operated by IA-OIMT to include any system environment provided by any approved external hosting provider. Any new IT systems or services must be approved by the IA-OIMT executive currently known as the Associate Chief Information Officer (ACIO). All new IT systems or services that may be developed or supported by this contract will be approved by the ACIO prior to them being released. The contractor through the COR will follow change management and related processes to deploy any new IT service or system.

C.2.2.1 Services Delivery Method

The NASIS Operation and maintenance of the student information system will be delivered either as a cloud-based COTS solution, or managed hosting by the vendor or Indian Affairs in Albuquerque, NM at the Bureau of Indian Affairs (BIA) Data Center (ADC) as well as help desk and support.

Both the production and back-up sites must meet current federal information technology requirements including but not limited to current version NIST SP 800-53 Rev. 4, and NIST SP 800-64 Rev. 2 system life cycle. Cloud-based COTS solutions shall also be implemented in accordance with the “Federal Cloud Computing Strategy,” dated February 8, 2011, released by The White House (Appendix A), and DOI’s “Acquisition of Information Technology Cloud Services/Mandatory Use of Pre-Approved Cloud Hosting Services and Contracts” Memorandum, dated August 7, 2018 (Appendix B). There is potential for future policy, “2018 Federal Cloud Computing Strategy – Cloud Smart”, that shall require adherence once the draft policy is realized and implemented within DOI-IA. The draft policy was published September 25, 2018, in the Federal Register, 83 FR 48457, in a Notice of public comment period.

C.2.2.2 Contingency Planning and Disaster Recovery

Office of Management and Budget (OMB) Circular A-130 Revised, and DOI policies require that information systems have a contingency plan (described by National Institute of Standards and Technology Special Publication NIST SP 800-34 Rev. 1, Contingency Planning Guide for Information Technology Systems) that is updated on an annual basis and that the plan be tested and documented on an annual basis. For delivery of services by an ASP, the requirement for the plans and testing must be fulfilled by contractor.

Hyperlinks:

· NIST SP 800-34 Rev. 1 https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final C.2.2.3 System Security Plan

OMB Circular A-130 and DOI policies require that information systems have a System Security Plan (SSP) as described by NIST SP800-18, Guide for Developing Security Plans for Federal Information Systems. For delivery of services by an ASP, the requirement must be fulfilled by contractor.

C.2.2.4 Annual System Security Review

The Federal Information Security Modernization Act (FISMA) requires that information systems undergo annual security review. For delivery of services by an ASP, the government will require administrative rights access to the system and any contractor operated data center and development facility to perform the annual review.

https://www.nist.gov/programs-projects/federal-information-security-management-act-fisma-implementation-project C.2.2.5 Assessment and Authorization

OMB Circular A-130 and DOI policies require information systems to be assessed and authorized prior to going into production. For delivery of services by an ASP, the government will require timely access to the NASIS system and any NASIS contractor operated hosting facility to perform the Assessment and Authorization (A&A). Contractor will provide information as required. The NASIS system will be subjected to network-based vulnerability scans. Reassessments shall occur whenever there is a major change that affects security. The contractor must follow current NIST Special Publications (as amended) 800-18 Rev. 1, 800-30 Rev. 1, NIST SP 800-37 Rev. 1, 800-60 Vol. 1 Rev. 1 and 800-60 Vol. 2 Rev. 1, 800-53 Rev. 4, Federal Information Processing Standard (FIPS) 199 and FIPS 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment. The Government will reserve the right to conduct the ST&E using either Government personnel or an independent contractor.

The contractor will take appropriate and timely action (this will be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.

The Designated Approving Authority (DAA) for the system will be the official identified in DOI Secretarial Order No. 3255.

Hyperlinks:

· OMB Circular A-130 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/OMB/circulars/a130/a130revised.pdf

· 800-18 Rev. 1 https://csrc.nist.gov/publications/detail/sp/800-18/rev-1/final

· 800-30 Rev. 1 https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

· NIST SP 800-37 Rev. 1 https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final

· 800-60 Vol. 1 Rev. 1 https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final

· 800-60 Vol. 2 Rev. 1 https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final

· 800-53 Rev. 4 https://csrc.nist.gov/publications/detail/white-paper/2014/02/19/summary-of-nist-sp-800-53-Rev. 4-security--privacy-controls/final

· Federal Information Processing Standard (FIPS) 199 https://csrc.nist.gov/publications/detail/fips/199/final

· FIPS 200

https://csrc.nist.gov/publications/detail/fips/200/final

· DOI Security Test & Evaluation (ST&E) Guide https://www.doi.gov/ocio/customers/assessment

· DOI Privacy Impact Assessment https://www.doi.gov/privacy/pia C.2.2.6 Infrastructure

For ASP delivery of services and for contractor operation of a BIE-owned system, the contractor shall provide the infrastructure necessary to operate and maintain NASIS. NASIS is required to be available on a 24x7 basis with 99.97% uptime. (Reference C.3.6.2 for the host site locations.)

C.2.2.7 Section 508 Compliance

The contractor shall ensure that all electronic and information technology delivered in compliance with this SOW meets the accessibility standards of 365 Code of Federal Regulations (CFR) 1194.36. CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended March 23, 2018. This standard is viewable at http://www.section508.gov. In June 2001, the Federal Acquisition Regulations (FAR) was modified to comply with CFR 1194 via the addition of a new Subpart 39.2. The FAR is viewable at https://www.acquisition.gov/browsefar C.2.2.8 Background Investigations Contractor employees who will have access to DOI information or will develop custom applications are subject to background investigations. The level/complexity of background investigations must be the same as for a Federal employee holding a similar position; DM441, Chapter 3 (https://elips.doi.gov/ELIPS/0/doc/2827/Page1.aspx) (https://www.doi.gov/sites/doi.gov/files/elips/documents/chapter_3_position_risk_and_sensitivity_level_designation.doc) provides guidance for the appropriate background investigations based on types of access with elevated rights. The solicitation and contract should state the levels required for applicable labor categories or positions with the appropriate back ground investigation.

C.2.2.9 Non-disclosure Agreement Contractor employees who will have access to DOI or Service information or will develop custom applications must sign a non-disclosure agreement prior to gaining access. Each agreement must be tailored to the contract. A draft or sample agreement may be included in solicitations. After award, the COR and IA Contracting will develop the final Non-Disclosure Agreement (NDA) agreements, with the review and approval of the DOI Solicitor Office.

C.2.2.10 Security Awareness Training (SAT) Contractor employees must take DOI’s end-user computer security awareness training prior to being granted access to DOI data or being issued a user account. Security Awareness Training must be renewed annually. The contractor must complete yearly the DOI FISSA mandated security awareness training and the completed certificates must be submitted to the COR/ACOR on a yearly basis.

C.2.2.11 Personnel Changes The contractor must notify the COR immediately when an employee working on the NASIS system is reassigned or leaves the contractor’s employ, and prior to an unfriendly termination.

C.2.2.12 Contractor Location Outsourced operations must be located in the United States.

C.2.2.14 Intellectual Property Rights DOI will own the intellectual property rights to any software developed on its behalf to the maximum extent practical. Generally, FAR 52.227-14, Rights in Data-General (https://www.acquisition.gov/browsefar), and its alternates will be used in the contract. However, deviation from this policy may be necessary as circumstances warrant.

C.2.2.15 Independent Validation and Verification (IV&V) An IV&V process is performed to ensure the system meets the stated requirements of the BIE. The BIE will perform the initial validation and verification during acceptance testing and reserves the right to bring in an independent group to perform an IV&V in future years of the contract. The BIE will fund this IV&V. Vendor testing must be performed on the development and pre-deployment environments before production is upgraded or patched.

C.2.2.17 System Logon Banner A DOI-approved logon banner must be displayed on the first page of any accessible web pages owned by DOI/BIE. Applications developed or maintained under this contract must contain a BIE approved logon warning advising users of rules, restrictions, and privacy expectations for that application. The text of such warning will be provided by the Government system owner.

The DOI-approved internet logon banner as of July 2018:

“THIS IS A NOTICE OF MONITORING OF THE DEPARTMENT OF THE INTERIOR (DOI) INFORMATION SYSTEMS.

This computer system, including all related equipment, networks, and network devices (including Internet access), is provided by the Department of the Interior (DOI) in accordance with the agency policy for official use and limited personal use.

All agency computer systems may be monitored for all lawful purposes, including but not limited to, ensuring that use is authorized, for management of the system, to facilitate protection against unauthorized access, and to verify security procedures, survivability and operational security. Any information on this computer system may be examined, recorded, copied and used for authorized purposes at any time.

All information, including personal information, placed or sent over this system may be monitored, and users of this system are reminded that such monitoring does occur. Therefore, there should be no expectation of privacy with respect to use of this system.

By logging into this agency computer system, you acknowledge and consent to the monitoring of this system. Evidence of your use, authorized or unauthorized, collected during monitoring may be used for civil, criminal, administrative, or other adverse action. Unauthorized or illegal use may subject you to prosecution.”

C.2.2.18 Incident Reporting The contractor must report computer security incidents affecting DOI/BIE data or systems in accordance with the DOI Computer Incident Response Guide. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed. The DOI of CIRC requires all incidents to be report within one hour of the occurrence of the suspected incident.

C.2.2.19 Quality Control (Malware Code) All software and hardware must be free of malicious code.

C.2.2.20 Annual Self-Assessment The contractor must conduct an annual self-assessment in accordance with NIST SP 800-53 Rev. 4 and NIST SP 800-53A Rev. 4 on all MAs, GSSs, and outsourced applications in production or a reference to public facilities, such as a website or office, where it may be accessed. Both hard copy and electronic copies of the assessment will be provided to the COR. The Government will reserve the right to conduct such an assessment using Government personnel or another contractor. The contractor will take appropriate and timely action to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.

Hyperlinks:

· NIST SP 800-53 Rev. 4 https://csrc.nist.gov/publications/detail/white-paper/2014/02/19/summary-of-nist-sp-800-53-Rev. 4-security--privacy-controls/final

· NIST SP 800-53A Rev. 4 https://csrc.nist.gov/publications/detail/sp/800-53a/Rev. 4/final C.2.2.21 System Logon Banner Acknowledgement Anyone who will access DOI data must acknowledge a Government-approved logon warning prior to each logon to the system.

C.2.2.22 Security Controls Contractors will be required to ensure compliance with the security control requirements of NIST SP 800-53 Rev. 4, or current version, and Federal Information Processing Standard (FIPS) 200, which are appropriate to the sensitivity and criticality of the data or system. NIST FIPS 199 will be used to determine sensitivity and criticality. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where they will be accessed in the development or maintenance of custom applications. The contractor shall, with the knowledge and concurrence of the Government system owner, be responsible for Information Technology (IT) security for all non-government-owned systems used in the development of and systems intended for eventual delivery to the DOI/BIE in fulfillment of contract requirements. This includes IT, hardware, software, databases, networks, and telecommunications systems.

Security functionality in applications or integrated systems delivered hereunder must operate with the Government systems on which or with which it will eventually be deployed. Products delivered hereunder must not cause the incorrect operation of government resources or loss of integrity, confidentiality, or availability of electronic information or data.

The Contractor shall ensure compliance with the security control requirements of the current version of NIST SP 800-53 (as amended) and FIPS 200 (as amended) appropriate to the sensitivity and criticality of the application/system assigned by the Government based on FIPS 199 (as amended). NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. FIPS documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. DOI documents will be provided by the Contracting Officer upon request. Please see Appendix A, page 61, section 2.6.1 for DOI guidance.

The Department of Homeland Security (DHS) Continuous Diagnostic and Mitigation (CDM) Phase 1 project requires the Operating Systems hosting the NASIS application have installed the CDM required current version of the IBM Bigfix/IEM hardware/software inventory scanning tool. The IBM BigFix/IEM tool must be installed with administrative rights.

C.2.2.23 Contingency Plan The contractor will submit a contingency plan in accordance with NIST SP 800-34 Rev. 1 (as amended) or current version and the DOI Contingency Plan Guide. The plan must be approved by the COR and the BIE ISSO. A copy of the annual test results will be provided to the COR and the BIE ISSO. This requirement concerns BIE systems residing at contractor controlled sites or on contractor-owned systems that host DOI/BIE data. Please see Appendix A, page 72, section 2.6.1.3 for DOI guidance.

C.2.2.24 Vulnerability Analysis All systems operated and managed by the contractor shall be scanned monthly with a vulnerability analysis tool provided by the Government. All “safe” or “non-destructive” checks must be turned on. All digital copies of each monthly vulnerability report and session data shall be provided to the COR and BIE ISSO.

The Government may conduct additional independent vulnerability scans, prearranged or unannounced. All high value systems and systems accessible from the Internet will be tested monthly for remote vulnerabilities. Independent penetration testing may be performed by the Government or by another contractor.

With the knowledge and concurrence of the Government system owner; the contractor shall take immediate action to correct or mitigate any IT security vulnerability discovered during any vulnerability testing, as needed, to bring the system into compliance with security standards invoked elsewhere in this work statement.

The contractor will perform security testing on designated BIE/DOI systems using testing techniques described in NIST SP 800-115, or current revision, Technical Guide to Information Security Testing and Assessment, including vulnerability analysis and penetration testing. When DOI provides the testing tool, all “safe” and “non-destructive” checks must be turned on. All electronic copies of each report and session data shall be provided to the applicable Government system owner, COR, and BIE ISSO. Please see Appendix A, Page 94, section 2.1.3 for DOI guidance.

C.2.2.25 Privacy Impact Assessment (PIA) The DOI has published Privacy Impact Assessment guidance for assistance with creating PIA documentation and for the annual review. The DOI guide will be provided by the Contracting Officer.

C.2.2.26 System Of Record Notice (SORN) The NASIS system must have a SORN created and updated when there is any significant change made to the NASIS system. The Privacy Act of 1974, as amended, requires the creation of a SORN. be completed and reviewed annually. OMB has published Circular A-108 (https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/circulars/A108/omb_circular_a-108.pdf) guidance on the creation and annual review of SORN’s.

C.2.2.27 List of IT Security Related Deliverables:

Title
Description
Due Date/Frequency
Government Approval and Surveillance
Plan of Action and Milestones (POA&M)
As described in, and in accordance with, the IT Security and Privacy Requirements document.
Upon Completion prior to authorization to move to Service Ready status and Quarterly thereafter
Contracting Officer’s Representative (COR), Government system owner, Government Technical Lead
Vulnerability and Security Configuration Scan Report
As described in, and in accordance with, the IT Security and Privacy Requirements document.
Monthly
Contracting Officer’s Representative (COR), Government system owner, Government Technical Lead
Continuous Monitoring Report
As described in, and in accordance with, the IT Security and Privacy Requirements document.
Monthly
Contracting Officer’s Representative (COR), Government system owner, Government Technical Lead
Documentation for Audit Requirements
As described in, and in accordance with, the IT Security and Privacy Requirements document.
30 calendar days after written request
Contracting Officer’s Representative (COR), Government system owner, Government Technical Lead
Training Compliance Report
As described in, and in accordance with, the IT Security and Privacy Requirements document.
Annually
Contracting Officer’s Representative (COR), Government system owner, Government Technical Lead
Security Incidents
As described in, and in accordance with, the IT Security and Privacy Requirements document.
Per Incident (immediately but not more than 1 hour)
Contracting Officer (CO), Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO), DOI-CIRC
Contractor Employee Report
Report of all contractor employees that have access to Government Data with status of required background checks as specified.
Annually on contract award anniversary date and within 3 business days upon written request
Contracting Officer’s Representative (COR)

C.2.3 CSAS-ASP SERVICES

The objective of this task is to provide day-to-day functionality to the BIE Office, the ASC, all ERCs, and BIE school sites. The Contractor shall:

· Deliver CSAS-ASP services over the common Internet that use a standard browser interface.

· Satisfy the functional requirements for a school administration systems listed in the RDD.

· Provide each school site with a unique calendar for the entire year and be able to account, at a minimum, for holidays, snow days, in-service days, and staff Development days.

· Provide hosting equipment at BIE facilities.

· Allow accessibility via the Internet.

· Provide services availability of 24 hours a day, 7days a week, 365 days a year.

· Maintain an Operational Ready Rate (ORR) of at least 99.97% validated by metrics submitted each month.

· Provide appropriate system application documentation. This documentation shall include interactive help from within application modules and on-line access to current reference documentation. (The Government may consider alternate documentation methods if equally effective.)

· Ensure data protection via continuous back-up with separate off-site storage that meets best commercial practice and standard legal chain of custody requirements.

· Ensures data recovery in accordance with the approved DOI IAIT Disaster Recovery Plan.

· Ensure system security in accordance with the approved DOI IAIT System Security Plan.

C.2.4 PROGRAM TECHNICAL SUPPORT

The Contractor shall provide technical and program support, as directed by BIE, to assist with:

•Program Reviews,
•Product Briefings and Demonstrations
•System Management
•Future Planning
•Other support as may be required by BIE

C.2.5 BIE ASP OPERATIONAL CONTROL

The Contractor shall support the BIE transition to the ASP Operational Control if required.

C.3 SPECIFIC TASKS

The SOW encompasses the tasks as delineated below.

C.3.1 PROJECT MANAGEMENT AND PLANNING (Task 1) (Task 1) Contractor shall manage and lead execution of the contract effort, including the efforts of subcontractors. Contractor will work with the BIE to plan and execute the project.

C.3.1.1 Project Implementation Plan (PIP) Contractor will Develop and maintain a Project Implementation Plan (PIP) and track progress against the plan. A draft PIP will be provided to the BIE not later than 15 calendar days following the execution of a contract. An updated plan shall be provided with the Monthly Status Report. The PIP activities will include:

· Data center Development and implementation

· Data conversion that includes all existing and historical data through date of conversion for both state and district editions.

· All existing state and district edition reports and data fields shall be converted and functional to the new system.

· A role based training plan will be created for all BIE and NASIS users from BIE funded schools.

· The Disaster Recovery Plan shall outline and describe the disaster recovery measures that will be employed at the central facility. The plan shall incorporate best commercial practices, describes the utilities and detailed procedures for data back-up and recovery, and include, at a minimum, initial testing and thereafter, annual testing.

· The System Security Plan shall outline and describe the security measures that will be employed to protect BIE school data at the central facility. The plan shall incorporate best commercial practices for United States educational environments and adherence to Federal, DOI, BIA, and BIE security policies. The plan shall also specifically address the use of virtual private network (VPN) technology. The PIP shall include a section that specifically addresses those security measures that BIE must have in place at each BIE site and when.

· The Risk Mitigation Plan shall address identified risks and describe the actions necessary to mitigate those risks.

· The PIP shall include, in addition to appropriate narrative descriptions, a project schedule showing a detailed work breakdown structure with task dependencies. These schedules shall be submitted monthly in both printed and electronic format.

C.3.1.2 Monthly Status Reports Contractor shall provide Monthly Status Reports. The monthly report, due by the 10th of each month for the preceding month, shall describe accomplishments for the reporting period, issues, current and cumulative financial status, and projected activities for the next reporting period. An updated PIP and Action Items List will be provided with the report.

C.3.1.3 Weekly Status Report Contractor shall provide a Status Report weekly to the Contracting Officer’s Representative and the Supervisor Education Program Specialist by the close of business on the last working day of each week. Each report, shall describe accomplishments for the reporting period, issues, current and cumulative financial status, and projected activities for the next reporting period. An updated PIP and Action Items List will be provided with the report. With each Weekly Status Report the Contractor shall provide metrics and lists that clearly show by school, NASIS usage by type (production, test, etc.), user support provided by category, data migration status, and training status. Contractor shall require such reports from its sub-contractors.

C.3.1.4 Weekly Progress Meetings Contractor shall conduct Weekly Progress Meetings with all of the Contractors sub-contractors. The Contractor shall also attend Weekly Joint Progress Meetings as scheduled and facilitated by the Supervisor Education Program Specialist, who shall also prepare the agenda. Such meetings shall be used to raise issues, present status and progress, and make decisions. However, discussions of any significant length shall be taken off-line to other meetings as directed by the facilitator.

C.3.1.5 Action Item Tracking Contractor shall maintain and manage an Action Items List at the Contractor level and review the status of the items at the Weekly Progress Meetings. Contractor shall also maintain and execute a list of action items assigned to the Contractor by the Supervisor Education Program Specialist.

C.3.1.6 Quarterly Progress Review Contractor shall host a Quarterly Progress Review (QPR), the purpose of which is for the contractor to provide a comprehensive review of the status of the contract to include execution against the schedule and expenditures plan, progress toward addressing action Items, potential issues, recommendations for project enhancements, and plans for the next quarter. The first QPR will be held on a date as mutually agreed by the government and the contractor.

C.3.1.7 Web-based Project Information Exchange The contractor shall investigate the need to implement a Web-based information exchange capability to facilitate the sharing of documents, schedules, and other information required by the project team and will recommend a course of action to the government. The contractor will implement a capability as approved by the government. As many individuals will be involved in the project, a convenient way of exchanging information will be needed. The website would be deactivated when its continued use is not necessary. Selected individuals will have the ability to post information to the website. Access to the website shall be controlled through the use of passwords or similarly effective technology. Contractor recommendation shall be delivered to the Government 3 weeks after execution of this contract and have an operational website not later than 3 weeks from the Governments approval to proceed.

C.3.1.8 Project Kick-off Meeting An integrated team project kick-off meeting to be held not later than 5 business days following execution of the contract. The date and location of the meeting shall be as mutually agreed by the government and the contractor.

C.3.2 REPORTING AND ANALYSIS SERVICES (Task 2) C.3.2.1 ESSA Reporting The Bureau of Indian Education receives funds from the U.S. Department of Education to carry out programs authorized under the Every Student Succeeds Act (ESSA). NASIS will produce the reports required by ESSA. Required reports are:

C.3.2.1.1 Consolidated State Performance Report (CSPR) http://www.bie.edu/cs/groups/xbie/documents/text/idc-037394.pdf

The Contractor will produce, maintain and update the summative data that will facilitate inputting data by the BIE into the CSPR portion of the Education Data Exchange Network (EDEN). In general, data included can be found within the NASIS system and includes summative data and disaggregated data. Examples of data include:

Students by grades served under Title I, II, IV, VI, IX

· Males and females

· Students with disabilities

· Students with status of active duty military parent(s)

· Students with status of living in a homeless condition

· Students with status of foster care placement

· English Learners (EL)

· Progress of English Learners

· Students by race and ethnicity

· Student proficiencies on state assessments in reading, language arts, mathematics, and science

· Schools progressing or not progressing in meeting Measures of Accountability

· Suspensions, expulsions, violence incidents

· Graduation by 4-year cohort and option for 5-year cohort C.3.2.1.2 Annual Measurement of Achievement (AMA) Annual measures of accountability by State

BIE ESSA State Plan is at https://www.bie.edu/ESSA/index.htm

ESSA State Plan Submission is at https://www2.ed.gov/admins/lead/account/stateplan17/statesubmission.html The Contractor will produce, maintain and update reports from information within NASIS that makes an AMA determination for each school using the criteria for AMA determination as described in the Approved Accountability Workbook for the state where the school is located. BIE’s State Plan will be contingent upon the outcome of negotiated rulemaking.

C.3.2.1.3 Consolidated BIE State Report Card Consolidated and Individual State Report Cards may be altered by the results of the negotiated rulemaking to allow flexibility as future decisions are made. Example, additional indicators may be added that are not addressed in this document such as chronic absenteeism, school climate, parent engagement, etc.

https://www.bie.edu/HowAreWeDoing/Scorecards/index.htm

State report cards must include information related to BIE’s system of accountability that uses indicators of school success, possibly including: (1) academic achievement as measured by proficiency on the annual assessments in mathematics, reading/language arts, and science for K-12 students; (2) an indicator of student growth for K-8 students; (3) high school graduation rates for high schools; (4) progress in achieving English Proficiency for K-12 students; and at least one indicators of school success or school support for elementary and middle schools as well as for high school, (i.e., student engagement, educator engagement, postsecondary readiness, school climate and safety, student access to and completion of advanced coursework. The data must include all schools in the BIE system.

The following three components of assessment data must include all students in the grades tested in the State, not just those students enrolled for a full academic year, as defined by the State. At a minimum, States must provide assessment data from their reading/language arts, mathematics and science assessments. Beginning with assessment data from the 2017-2018 school year, for each grade and subject tested, the State report card must include:

•Information on the percentage of students tested. States must report the percentage of students not tested or the inverse, the percentage of students tested. Either approach is acceptable. This information must be disaggregated by the following subgroups: All Students, Major Racial & Ethnic groups, Students with Disabilities, English Learner, Homeless, Military, Foster Care and Gender.
•Information on student achievement proficiency level disaggregated by the following subgroups: All Students, Major Racial & Ethnic groups, Students with Disabilities, English Learner, Homeless, Military, Foster Care and Gender.
•The most recent 2-year trend data in student achievement for each subject and for each grade.
•An annual State Report Card is to be generated by the student information system at the end of each school year.

C.3.2.1.4 Individual School Report Cards https://www2.ed.gov/admins/lead/account/stateplan17/statesubmission.html Similar to State report cards, BIE school report cards must include information related to BIE’s accountability system, including student proficiency on academic assessments, and other accountability indicators, teacher qualifications as that information applies to the school.

The following components of assessment data must include all students in the grades tested in the school as a whole and all students in the grades tested in each school, not just those students enrolled for a full academic year, as defined by the State. At a minimum, a school must provide assessment data from its states reading/language arts, science and mathematics assessments. For each grade and subject tested, the school report card must include the following:

•Information on the percentage of students tested. Schools must report the percentage of students not tested or the inverse, the percentage of students tested. Either approach is acceptable. This information must be disaggregated by the following subgroups: All Students, Major Racial & Ethnic groups, Students with Disabilities, English Learner, Homeless and Gender.
•Information on student achievement at each proficiency level (e.g., advanced, proficient, basic, below basic), disaggregated by the following subgroups: All Students, Major Racial & Ethnic groups, Students with Disabilities, English Learner, Homeless and Gender.
•Annual Individual School Report Cards are to be generated by the student information system at the end of each school year.

C.3.2.1.5 Teacher Qualifications Report The state report card must describe the professional qualifications of teachers in the state, including information on the number and percentage of inexperienced teachers, principals, and other school leaders; teacher teaching with emergency or provisional credentials; and teachers who are not teaching in the subject or field for which the teacher is certified or licensed. The information must be presented in the aggregate and disaggregated by high-poverty compared to low-poverty schools. Teacher Qualification data is to be included in the State and School report cards.

C.3.2.2 ISEP Reporting The Indian School Equalization Program (ISEP) is governed by the Federal Regulation 25 CFR Part 39 and is the primary funding source for all BIE schools. The Federal Regulations are located at http://www.ecfr.gov/cgi-bin/text-idx?c=ecfr&tpl=/ecfrbrowse/Title25/25cfr39_main_02.tpl.

ISEP is a set of four instructional, three residential, and two transportation programs. It is also a formula to equitably distribute Congressional appropriated funds based upon a three-year average of weighted student unit for each instructional and residential program. Transportation is a program based on miles driven to transport students from home to school and return and the type of road traveled on. The transportation program includes day and boarding miles. For specific boarding schools, transportation includes reimbursable expenses for air, commercial bus or train, and charters to transport students from home to school and return. The instructional and residential programs identify, for funding purpose, each students instructional, residential, and supplemental needs. The instructional program includes three supplemental programs: Special Education, Gifted and Talented, and Language Development. The residential program includes one supplemental program: Exceptional Child Residential (Special Education). The ISEP process involves the direct participation of schools, Education Resource Centers (ERC), and BIE Offices. Schools must encode the required student data and ensure the appropriate documentation is on file to justify funding. The contractor will develop a secure file storage in the system for all Personal Identifiable Information (PII) and documentation. The ERCs must verify and certify the required student data for their respective schools. Once data is certified, data must be locked to prevent modification and access is limited to authorized personnel for modification. The BIE Offices must collect and process the system wide student data for the annual 80% distribution of ISEP funds by July 1 and remaining 20% by December 1. The NASIS system must produce the following reports and forms (C.3.2.2.1 – C.3.2.2.9):

C.3.2.2.1 Instructional Average Daily Membership (ADM) The Contractor shall provide by school, student membership report of all instructional students meeting the requirements for instructional funding. The report is for all schools having an instructional program. The report must be by name, birth date, gender, grade level, enrollment dates, membership day count, tribal code, and supplemental instructional need (gift and talented, language Development and special education needs), for all instructional students.

C.3.2.2.2 Residential Attendance The Contractor shall provide by school, student membership report of all residential students meeting the requirements for residential funding. The report is for all boarding schools and peripheral dormitories. The report must be by name, birth date, gender, grade level, enrollment dates, membership day count, tribal code, and supplemental residential need, for all residential students.

C.3.2.2.3 Calculation Report (Combining instructional/residential) The Contractor shall provide by school, a weighted student unit funding report that aggregates each schools total certified student count by instructional and/or residential programs and by grade levels.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.