J_Attachment 1_PWS for O&M_Task Order 1_1.docx
DOCX document 134 KB Posted
- Attached to
- Minerals Revenue Management Support System Federal contract opportunity
- Solicitation number
- 140D0420R0005
About this file
This draft request for proposal outlines requirements for operations and maintenance support services for the Minerals Revenue Management Support System. Key details include providing help desk, system administration, software maintenance, disaster recovery, and security support for the financial, compliance, and business automation components of MRMSS. Additional requirements involve managing system change requests, conducting testing, ensuring regulatory compliance, and supporting internal and external audits. The support must be provided 24/7 and is estimated to last one base year with nine optional periods. The due date for questions on this draft RFP is February 23, with the formal RFP to follow thereafter. The Department of the Interior will evaluate responses for award.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section J, Attachment 1
U.S. Department of the Interior Office of Natural Resources Revenue (ONRR) Operations and Maintenance Services (O&M) Performance Work Statement (PWS)
Task Order: O&M Services for the Minerals Revenue Management Support System (MRMSS)
Title: MRMSS – O&M/Development and Enhancement for the ONRR/Program Application Operations, Support and Maintenance
1.
OBJECTIVE
The primary objective of this requirements document is to provision operations and maintenance (O&M) support of the Minerals Revenue Management Support System (MRMSS) components. The MRMSS is ONRR’s primary revenue management system to support the mission of ONRR. ONRR’s mission is “For the benefit of all Americans, ONRR collects, accounts for, and verifies natural resource and energy revenues due to States, American Indians, and the U.S. Treasury.”
This document delineates the primary objectives and requirements for O&M support of the MRMSS. The contractor shall submit, with its Task Order proposal, a comprehensive Performance Work Statement (PWS) to detail O&M tasks in support of the MRMSS.
2. MRMSS COMPONENTS – Refer to Attachment J_TE01
2.1. MRMSS Financial components (MRMSS-Financial)
· General Ledger
· Accounts Payable
· Accounts Receivable / Billing
· Debt Collection
· Royalty
· Reference
· Production
· Electronic reporting of production and royalty information (eCommerce)
· Electronic report of solid mineral production and royalty information (Solids P&R)
· Financial Reports
2.2. MRMSS Compliance Components (MRMSS-Compliance)
· Indian Pricing Tool (IPT)
· Supplemental Data Capture
· Compliance Program Tools (CPT)
· Office Workload Management System (OWMS)
· Operations Management Tool (OMT)
· Work Management
· Case Management
· Electronic Work Papers
· Document Repository
· Tracking Tools
· Compliance Information Management (CIM)
· Solids Compliance Program Tools (SCPT)
2.3. MRMSS Business Automation/Data Warehouse (MRMSS-BA/DW)
· Data Mining/Query Tools
· Business Intelligence reports and dashboards
· Industry Reports and Queries
· Internal and External portal – WebCenter Portal and Hyperion Portal
· Financial Reports
· eStatement of Accounts (eSOA)
· Lease Account Balance (eLab)
2.4. Underlying Infrastructure
· PeopleSoft & PeopleTools
· WebCenter Portal
· Hyperion Portal
· .NET Framework
· Oracle Business Intelligence (OBIEE)
· Oracle Business Intelligence Publisher (BIP)
· Data Anayltics
· Oracle Business Rules (OBR)
· Oracle Business Process Management SOA Suite
· Universal Content Manager (UCM) also, known as WebCenter Server (WCS)
· Identity and Access Management (I&AM) Suite
· Oracle Databases
3. SCOPE
The contractor shall provide comprehensive, information technology (IT) O&M support services and maintain those services over the life of this Task Order that meets or exceeds the Government objectives identified in this document.
This Task Order describes the technical needs, work outcomes and performance objectives essential to successful contract performance for providing O&M services for MRMSS. During the performance of this Task Order, the Contractor shall furnish creative, innovative and cost-effective approaches, and implement approved strategies based on best business practices and new technologies, reflecting how work objectives, technical needs and support levels will be met in support of the MRMSS.
The MRMSS has been classified as a MODERATE system based on FIPS199 and 800-60.
This Task Order will rely on measurable service levels (service level agreements (SLAs) refer to J_TE07) that define metric requirements to evaluate performance. The Contractor shall establish and maintain processes and systems for routinely measuring and reporting service levels and evaluating results. These processes should also include goal setting and process improvement to foster a continuous evaluation and improvement environment. The Government strongly encourages the Contractor to propose creative, innovative, and cost-effective contract approaches throughout the contract whereby active measurement, high goals and continuous improvement are beneficial not only to the government but also to the Contractor in a tangible way. Initial service levels described in this document are considered as a starting point and a basis for contract proposal. Actual SLAs (refer to attachment J_TE07) are expected to be dynamic, as both the Contractor and the government seek to establish baselines and continuously improve the quality of performance. The Quality Assurance Surveillance Plan (QASP) (J_TE11) provides how the performance of the task order will be monitored and the effectiveness of the quality of performance of this task order. The Contractor may propose additional or modified SLA’s which will be negotiated and agreed to prior to task order award.
4. OPERATIONS AND MAINTENANCE REQUIREMENTS
The MRMSS includes three (3) major components: Financial, Compliance, and Business Automation/Data Warehouse. The Contractor shall support operations by supporting the MRMSS environment as described in the Technical Exhibits. The Contractor shall provide services including full lifecycle software engineering support to a wide variety of systems that support day-to-day business functions of ONRR.
As an existing system, support of MRMSS includes the management and resolution of system change requests (SCRs). To facilitate the tracking of SCRs to the MRMSS, the Contractor shall utilize database tools to track SCR’s prioritized by ONRR. These tools should tie change requests approved by the Contracting Officer’s Representative (COR) to system modifications, design documents, and test plans. The Government will identify personnel that shall be granted access to these tools or be provided with reports clearly showing the requirements traceability information contained in the tools. The following sub-section provides additional O&M requirements for SCRs.
4.1. MRMSS Operations and Maintenance for System Change Requests
The Contractor shall provide Operations and Maintenance for system change request activities. MRMSS change request represents data request, system changes that generally require less than an estimated 120 hours to complete. These items include configuration changes, data extractions, small enhancements, data cleanup activity, modifications.
Separate task orders may be issued for enhancements, upgrades, and new development (reference SOO regarding more details regarding potential future enhancement task orders). Enhancement task orders require an estimated 120 hours or more.
As part of the operations and maintenance system change request activities, the Contractor shall:
· Provide resources for small enhancements as submitted by ONRR with an SCR
· Track all SCRs and provide ONRR access to the tracking system.
· Work with the COR to prioritize SCRs, confirm requirements, and schedule releases.
· Provide SCR specification documents for the COR’s review and approve prior to development.
· Support unplanned and emergency system change requests that may be generated by legislative mandate, in response to audit findings from various sources, or changes in hardware, software, telecommunications, or security requirements.
· Support information data request of information from the MRMSS by the COR in timeframes mutually agreed to between the Contractor and the COR. During the performance of this task order the Contractor may have to support rapid response data requests and the Contractor shall work with the Government to meet these critical requests. Past data requests have come from various entities such as; Congress, Department of Justice, GAO, IG, FOIA, other government agencies, and ONRR. Requests may consist of large volumes of data or at a level of detail which is beyond the capability of the Statistical Reporting tool. Information requests average four (4) requests per month, though the potential of significant increases may occur in response to a spike in media coverage.
· Support security assessments of the MRMSS environment (software, infrastructure, network, etc.). System remediation requiring code changes and/or over an estimated 120 hours or more will be tracked and prioritized through ONRR’s change management process.
4.2. Maintenance
Under this document, maintenance includes:
· Correcting software/programming defects, deficiencies, and errors
· Improving system performance in deployed software
· Adapting software to a new or changing environment
· Deploying software releases/upgrades
· Software and hardware vulnerability and patch management
· Software maintenance includes all required steps in the System Development Life Cycle such as source code, testing, and documentation.
The Contractor shall manage the introduction of vendor released software changes into the MRMSS in a manner consistent with ONRR change control requirements. The Contractor shall analyze the patches for applicability and communicate the results to ONRR. All patches shall be implemented through a controlled testing and evaluation process. Patches identified by the COR as emergency shall be implemented by the Contractor using an expedited patch management process. Once the COR has approved an emergency patch, the Contractor shall implement the patch within ten (10) working days. The Contractor shall communicate to ONRR any related risks, schedule and resource changes that may result from the expedited patch management process.
The Contractor and the Government shall review on a recurring basis, no less than annually:
· Lessons learned during the performance of this task order;
· New technologies and best business practices for creative, innovative, cost effective strategies and approaches to consider for implementation; and
· Costs of maintaining older equipment versus the benefits of new hardware or moving to cloud solutions.
4.3. Operations Support
The Contractor shall be responsible for support of the application components of the MRMSS including:
· IT hosting facilities management and physical security
· Upgrades and enhancements of hosted hardware and software
· MRMSS firewall management and maintenance
· Hardware and software maintenance for government owned equipment (GFE)
· Server administration, installation, maintenance, repair, security remediation and upgrades
· System back-ups and restores
· Applications system administration, installation, maintenance, repair and security remediation
· System disaster recovery
· Inventory control
· MRMSS software maintenance and software licenses renewal management
· Government MRMSS help desk generated issues
· User Acceptance Testing (UAT)
· Limited business recovery
· Configuration management
· Patch management of hardware and software per DOI guidelines. A patch management plan should be submitted within 30 days after award of this task order.
· Installing all software on the MRMSS and ensuring that any software introduced to the network meets all applicable guidelines and will work in the current MRMSS environment within agreed upon timeframes. Software introduced to the network must meet security requirements including original equipment manufacturer best practices.
4.4. DOI Network Trusted Internet Connection (TIC) Requirement
ONRR requires an updated network where DOI will be responsible for the network to the FedRAMP Data Center. The Data Center must allow Government managed network devices in the hosting facility. The Offeror’s proposal must satisfy DOI Trusted Internet Connection requirements.
4.5. IT Facilities Management and Physical Security
The IT facilities which host MRMSS shall have adequate facility services to provide the appropriate level of service and must be FedRAMP approved. The Contractor shall:
· Ensure that IT facilities in use continue to have the proper power, heating, cooling, ventilation, lighting, space management, construction, security, safe working environment, and maintenance as appropriate for the various sites.
· Provide upgrades and modernization to software and hardware provided through managed services.
· Ensure that a backup and recovery strategy is in place and properly tested. Quarterly testing of system backups shall be included in the plan.
· Provide a common repository of information regarding configuration management on all hardware and telecommunications equipment within the various IT hosting facilities.
· Plan and coordinate non-emergency outages affecting IT hosting facilities. This includes:
· Creating timely notification of outages;
· Maintaining physical security requirements and documents as deemed appropriate by the CO or COR; and
· Maintaining both physical and logical drawings of the processors, peripheral equipment, and their connectivity.
4.6. MRMSS Network Administration
The Contractor shall ensure system availability for MRMSS-related networking administration activities including:
· Government managed network devices
· Network problem identification
· Network capacity planning
· Network optimization and tuning
· Network configuration management
· Network certification and accreditation requirements
· Providing identity management of network access to authorized personnel
· Providing a secure environment for applications to reside
· Designing and implementing networks
· Establishing a testing environment
· Maintaining a testing environment
· Installation, maintenance, repair, and upgrades of all MRMSS hardware, firmware, software, and associated equipment.
· Performing frequent audits to assess security processes and controls ongoing basis.
· Consulting with customers and gathering requirements
4.7. Network Engineering, Installation, Maintenance, Repairs, and Upgrades
The Contractor shall ensure system availability for network engineering, installation, maintenance, repairs and upgrades including:
· MRMSS firewalls management and maintenance
· Server administration
· Server installation, repair, maintenance and upgrades
· MRMSS back-ups and restoration
· Applications system administration
· Disaster recovery planning and execution
· Alternate site fail over
· Cabling systems installation, maintenance and upgrades
4.8. MRMSS Firewall Management and Maintenance
The Contractor shall ensure that engineering, architecture, management, planning, implementing, maintaining, repairing, upgrading, configuring, and documenting MRMSS firewalls to ensure confidentiality, integrity, security, availability, and authenticity through the Internet/Intranet. To provide this support the Contractor shall:
· Respond to security needs and requirements, and directives/mandates.
· Maintain and manage MRMSS firewall components and configuration; and maintain the security posture of the MRMSS firewall components through the use of security tools.
· Continuously monitor the MRMSS firewall for adverse conditions and maintain incident reports to the COR.
· Notify the COR, System Owner, and/or the ONRR IT Security Officer of any security incidents that occur involving a specific site and/or IT asset.
· Coordinate with ONRR/DOI personnel and other contractors, as applicable, to discuss MRMSS firewall implementation and configuration issues. Alert the CO/COR of potential problems with an approved request prior to implementing.
· Implement approved MRMSS firewall exception requests.
· Maintain and update ONRR’s Continuous Diagnostics and Mitigation (CDM) Program for the MRMSS.
· Continuously monitor and audit system logs, and input and output control system.
4.9. Server Administration
The Contractor will be responsible in managing:
· Account management
· Monitoring and auditing system logs
· Backup and recovery
· Security
· Operating systems management
· Storage management
The Contractor shall perform all non-emergency disruptive work in the MRMSS environment during non-business or non-scheduled production hours, or at the direction of the CO/COR.
The Contractor shall provide access control in order to provide proper rights and privileges to approved users for specific applications. The Contractor shall maintain access logs and remove rights and privileges for terminated employees within timeframes specified in DOI directives.
4.10. MRMSS Server Installation, Maintenance, Repairs, and Upgrades
The Contractor shall ensure that the complete installation, testing, problem analysis, maintenance, repair, configuration, and documentation of all MRMSS hardware, firmware, software, and associated equipment that is installed as part of a server for system availability. The Contractor shall ensure no impacts to applications when the following activity occurs:
· Ensure that server operating systems are maintained at the level dictated by the DOI’s enterprise architecture.
· Monitor resource capacity and provide monthly capacity reports and notify the CO/COR when thresholds are exceeded.
· Meet system authorization requirements for current and anticipated server equipment.
· Identify server requirements and prepare a life cycle systems analysis.
· Create and maintain documentation to support the testing, installation, and operation of servers.
· Coordinate and validate changes with application owners.
· Coordinate all SCRs with the COR as it relates to IT services.
4.11. MRMSS System Back-Ups and Restorations
The Contractor shall support system back-ups and restore-functions to ensure availability and recovery per ONRR COOP. The Contractor shall also:
· Demonstrate and test back-up and restore reliability on an annual basis or as mutually agreed upon by the Government and the Contractor.
· Ensure the MRMSS restoration and/or reproduction of current and historical systems and applications.
· Ensure off-site storage and disaster recovery.
· Ensure backups are encrypted
4.12. MRMSS Application System Administration
The Contractor shall provide all support required to maintain and provide access to application systems according to system availability performance (SLA 13a and 13b). This support includes:
· Hosting the application and ancillary software on servers that provide adequate bandwidth and response time for number of average concurrent users
· Providing adequate network connections
· Web access interfaces where required
The Contractor shall provide a methodology for the capture and analysis of application and system resource utilization for the purpose of improving overall performance and availability. Annually, the Contractor shall collect and analyze relevant data to make innovative and cost-effective recommendations to result in improvements. At a minimum, data captured shall include transaction volumes by subsystem, database volumes, and network traffic volumes including bytes of data transacted, bandwidth utilization, CPU utilization, memory utilization, and number of concurrent users.
Any system changes to include application upgrades shall be conducted in a manner consistent with ONRR’s change management process. The Contractor shall work with ONRR to seek to optimize upgrades so as to limit the number of upgrades necessary and to minimize the disruption to operations and development caused by upgrades and related software freezes; unless optimization leads to extending vulnerability risks.
ONRR will prioritize systems change requests for small enhancements to existing MRMSS software. The Contractor shall be responsible for completing the request within agreed upon timeframes.
5. SYSTEM AND SUBSYSTEM TESTING FOR MRMSS
System and Acceptance testing for system changes for the MRMSS will be a joint effort between the Government and the Contractor. The testing will address both the functional and performance requirements as defined herein. All system and acceptance testing problems shall be documented and resolved prior to final government acceptance.
As part of system change releases, performance tests should be performed to assure the software and hardware system changes will provide the capacity and performance to meet and maintain the deadlines of all ONRR’s processes, that is, nightly batches and online availability.
To improve testing effectiveness and efficiency of the MRMSS, the Contractor shall use automated testing approaches when applicable and appropriate. As part of regression testing for system changes, upgrades, and software patches, automated testing will be the preferred method for the MRMSS, both by the Contractor and the Government. The automated testing approaches shall include the implementation of the PeopleSoft Test Framework.
The Contractor shall provide testing environment(s) that are approved by the Government, replicates the production environment, and allows system change testing from remote locations. The Contractor shall provide support during user acceptance testing (UAT). The Contractor shall thoroughly test software, including all change requirements and regression testing, before user acceptance testing. The Contractor shall develop test plans and scripts (including security) for system /change releases. The Contractor shall report all status and findings to the COR. The COR may delegate the verification of the test execution as well as the review of all associated documentation to a functional subject matter expert. The Contractor shall ensure that all test results are documented and provided to the COR as these documents may be required by external parties; that is, the Office of the Inspector General, General Accounting Office or other auditing entities.
As data elements and table changes are added, deleted, or modified to the MRMSS application, the Contractor shall follow the ONRR Data Administration Change Request process prior to implementation of system change requests.
Software will not be migrated to production until it is in accordance with defined Government requirements. If the software is migrated to production but software problems occur that indicate the software does not meet the defined Government requirements, the Contractor shall be responsible for fixing the problem and making the software compliant with defined Government requirements at no additional cost to the Government. The timeframe to implement the fix shall be mutually agreed to by the Government and the Contractor.
6. EMERGENCY PREPAREDNESS
6.1. Annual Business Recovery (Disaster) Activities
The Contractor shall support the Government’s emergency preparedness activities to include disaster recovery and continuity of operations planning. These activities are typically an annual event and planned by the Government. The Contractor will be provided guidance by the COR. The Contractor shall conduct and participate in test exercises as required by applicable Disaster Recovery Plans and Continuity of Operations Plans.
Should a Disaster or Business Recovery event occur and require the Government to move to an alternate recovery center from the Denver Federal Center, the Contractor shall work at the direction of the COR and any other government entity and/or vendor that supports connectivity to the MRMSS. It is understood that the Contractor will work with the Government as a priority to expedite the connectivity to critical core business operations (financial, compliance, and business automation).
Disaster recovery is defined as:
· Software failure
· Hardware failure
· Network failure
· Power outage
· Equipment damage
· Natural disaster
The government may request a failover activity after three (3) days of continued disaster recovery defined events.
6.2. Mission Critical Failover Activity
The Contractor shall furnish failover capability to an alternate site for application processing in compliance with OMB Circular A-130. The Government’s identified mission critical application is the financial component of the MRMSS. In the event of loss of the primary MRMSS hosting facility, the failover connectivity to the secondary site will be completed within four (4) hours.
The Contractor, on an annual basis, shall test the failover connectivity to ensure the four (4) hour minimum is satisfactorily met.
6.3. Mission Critical Recovery Activity
The Contractor shall provide recovery support to ensure mission critical application capability is retuned from the alternate site to the primary site for application processing in compliance with OMB Circular A-130. The Government’s identified mission critical application is the financial component of the MRMSS. Full restoration of MRMSS environment will be completed within two weeks of initial failover event.
7. INVENTORY CONTROL/GOVERNMENT FURNISHED PROPERTY AND EQUIPMENT
Hardware, software, and related material described in J_TE03. The Contractor shall work with the COR to maintain and update the GFP/GFE list. The Contractor shall identify and support the CO/COR in the disposal of excess GFP/GFE. Excess GFP/GFE disposal includes ensuring sanitation and transfer of sanitized equipment for disposal which include written certification provided to the CO/COR.
8. SOFTWARE LICENSE AND MAINTENANCE AGREEMENT SUPPORT
The Contractor shall support the management of maintenance and support agreements for the hardware and software outlined in J_TE03 and J_TE04. The Contractor shall ensure that all software license and maintenance agreements may be legally entered into by the Government. The Contractor shall register all such agreements in the name of the Government (ONRR) and that all allocations of software licenses at the user-level for licensed COTS applications are tracked and documented.
8.1. Support activities shall include:
· Ensuring continuity of coverage
· Ensuring adequacy of coverage
· Ensuring agreement information is available, complete, and accurate
· Analyzing cost effectiveness
9. USER SUPPORT FOR MRMSS
The Enterprise IT Service Desk for the Bureau of Safety and Environment Enforcement (BSEE) provides Tier 1 Customer Support.
9.1. Customer Support
The Contractor shall be responsible for Tier 2 and 3 Customer Support.
9.2. Customer Support shall include:
· Pre-service, during service, and post-service activities
· Resolving assigned ticketing from the Tier 1 provider
· Administer customer surveys and conduct follow-up discussions with CO/COR at a minimum quarterly
· Liaison with the other Government and non-Government customer support activities
9.3. MRMSS User Account Management
The Contractor shall be responsible for user access to the MRMSS. Account initiation/modification/termination administration includes the following:
· Process approved MRMSS Access Request Forms (MARF) and External MRMSS Access Request Form (EMARF)
· Maintain the MRMSS System Access Approval Guide
· Documenting permissions associated for each MRMSS user role
· Maintaining the MRMSS user account database(s). Currently there are multiple database, future state is to consolidate into one user account database.
· Maintain privileged user accounts (Reference Section 30).
· Provide user security account audit reports for all users within the MRMSS environment.
· Maintain and/or update systems that maintain access request information to allow for periodic IT security review done both internal and externally.
· The Contractor shall complete account initiation/modification/termination actions within one business day of an approved MARF or EMARF.
· The Contractor shall complete account termination actions for adverse terminations immediately (QUASA Report).
· The Contractor shall record, analyze, maintain, prepare, and submit quarterly reports regarding problem resolution occurrences and trends.
10. CLIENT APPLICATION SUPPORT ACTIVITIES
10.1. Batches
The Contractor shall perform MRMSS client application support activities to ensure day-to-day operation of MRMSS by proper planning, design, implementation, deployment, and administration and continuity. The majority of batch processing is run overnight. Nightly batch processing shall be completed prior to 5:00 AM MT for critical batches and 8:00 AM MT for non-critical batches. Refer to attachment J_TE05 for more information on critical versus non-critical batches and the number of batches. Some batch processes are run during normal business hours. The Contractor shall initiate and complete the daily batch processes in the defined scheduled J_TE05 or as mutually agreed to between the Contractor and the Government. If a critical batch cycle is not completed, the Contractor shall notify the COR by 5:00 AM MST the same business day. If a non-critical batch cycle is not completed, the Contractor shall notify the COR by 7:00 AM MST the same business day.
10.2. Production
The Contractor shall support day to day production activities. Upon request by the Government, updates and modifications to scheduled production activities will be mutually agreed to between the Government and the Contractor and performed by the Contractor.
· A monthly production activities calendar will be provided to the Contractor 2 weeks prior to the next month.
· Daily synopsis of production activities shall be provided to the Government.
10.3. Printing - Exception Processing (Billing) Invoice Generation
At the conclusion of the exception processing batch run, print runs are generated for invoices and other miscellaneous print products. Print runs are normally generated two (2) to three (3) times per week. The Contractor shall execute the print run and deliver the printed products to the COR within three (3) business hours of print completion. The average print job is approximately 20,000 pages per run.
11. SECURITY SUPPORT SERVICES
11.1. Definitions
· Security Services are the protection of information technology assets and the information within or passing through the assets.
· Protection is prevention of unauthorized access, use, disclosure, disruption, modification, or destruction in order to ensure the integrity, confidentiality, and availability of IT systems.
· Integrity guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.
· Confidentiality preserving authorized restrictions on access and disclosure, including protecting personal privacy and proprietary information.
· Availability ensures timely and reliable access to systems and use of the information and information systems.
11.2. Security Planning
The Contractor shall assist and support the Government in developing and maintaining an approved MRMSS System Security Plans (SSP) in accordance with the FISMA, OMB Circular A-130 and memoranda, DOI Information Security Policy Handbook, as well as identified laws, regulations, and directives in J_TE10. The Contractor shall annually update the Contractor System Security Plan when operational considerations (e.g., risks, threats, security assessment configurations, vulnerabilities, or security directives) change significantly, or as directed by the COR.
The Contractor shall support the annual review and updates to the MRMSS System Security Plan which includes annual updates to FISMA required documents maintained by the Contractor. The MRMSS documents to be maintained and updated are:
· Service Provider Security Controls
· Software Inventory
· Hardware Inventory
· Failover Architecture
· Technical Architecture Blueprint
· Configuration Management Plan (Hardware)
· Change Management Plan (Software)
· Contingency Plan
· System Inventory Description and Decomposition Diagram
· Service Provider System Security Plan
· Technical Description
· Functional Diagram
· ONRR to hosting environment diagram
· Engagement Hardware and Network Architecture
· Update the MRMSS SSP Supplemental Documents file
· Update MRMSS Security Technical Implementation Guides (STIGs) variance documentation for all MRMSS technical components.
· MRMSS Security Architecture Design (Security Detail Design)
11.3. System Security and Information Protection
The Contractor shall provide Security Services and support the MRMSS by complying with the laws, regulations, and guidelines identified in J_TE10 for the management of Information Systems and Financial Management Systems.
· The Contractor shall flow down all applicable security laws, regulations, and guidelines identified in J_TE10 to their subcontractors.
· The Contractor shall employ best business practices to ensure that Security Services are accomplished as prescribed in the Contractor System Security Plan and the MRMSS System Security Plan (SSP).
· The Contractor shall protect all MRMSS data at all times commensurate with the risk and magnitude that could result from a loss of confidentiality, availability, or integrity of the information within the MRMSS components.
· The Contractor shall serve as senior network security technical advisor and assist the Government in performing an annual detailed examination of the system security protection, procedures, and resource allocations necessary to maintain MRMSS’ compliance with Federal security directives and best business practices.
· The Contractor shall provide network vulnerability scanning services and analysis for the hosted MRMSS environment (hardware and software) and track configuration vulnerabilities. The Contractor shall report these results, corrective actions taken, and vulnerability mitigation to the CO/COR weekly. The Contractor shall, upon discovery of a potential vulnerability, provide options for remediation, justification for acceptance of risk, or an explanation of false positive. If the vulnerability remediation requires a code change and are more than 120 hours, then at the direction of the COR and prioritization, the Contractor shall remediate vulnerabilities through the change management process.
· The Contractor shall provide security and network support services for MRMSS 24 hours a day, seven (7) days a week that include:
· Responding to real or potential security events
· Responding to Federal data calls or other mandated reporting requirements
· Providing after-hours security support for the MRMSS networks.
· Notification of any and all adverse computer events with a negative consequence; potential data breaches; and the loss or theft of any government owned media and/or equipment as prescribed by the incident response procedures as identified in the DOI Security Handbook
· Coordinate response(s) to all incidents involving malicious or suspicious code as prescribed by the incident response procedures as identified in the DOI Security Handbook
· Maintain a database of all pertinent information relating to malicious code encounters and incidents including: the name of the malicious/suspicious code, affected user(s), organization, location, source, affected media, and whether the incident was internal or external to DOI.
· Coordinate with other Federal entities and contractors as needed.
· The Contractor shall implement and maintain security tools to protect the MRMSS to include configuration and dissemination mechanisms, filtering, blocking, auditing, monitoring, and alerting.
· The Contractor shall provide senior advisors, expertise, guidance, resources, and analysis for organizational and enterprise protection audits.
· The Contractor shall provide reports of incidents as they occur to the CO and COR and others as necessary.
· The Contractor shall ensure that all definition files for protective software (Intrusion Detection and Prevention Systems (IDPS), Anti-Malware/Virus) are kept current, within 24 hours of release of the new definitions either through manual or electronic means.
· The Contractor shall establish, implement, and maintain the following controls:
· Limit and control outside visibility to the MRMSS
· Limit and control network interfaces outside of the MRMSS security boundaries
· Monitor and report MRMSS anomalous, security related (network) activity
12. SECURITY RISK MANAGEMENT SUPPORT
The Contractor shall develop, facilitate, support, lead risk analysis, implement and maintain a Government approved risk management approach for protecting data, information and information systems for the MRMSS. The Contractor shall document and update annually the risk management process in the Contractor provided System Security Plan. This process must be used to support informed decisions related to the adequacy of protection, cost implications of further enhanced protection, and acceptance of residual risk.
The Contractor shall complete a self-assessment as described in the most current NIST 800-53 to ensure the MRMSS meets minimum standards for a moderate system.
13. QUALITY ASSURANCE
13.1. Quality Assurance Plan (QAP) and Quality Assurance Surveillance Plan (QASP)
The Contractor shall establish and maintain a complete Quality Assurance Plan (QAP) to ensure the requirements of this task order are provided as specified. This QAP should align with the Quality Management sections of the Contractor’s Project Management Plan (PMP) and shall describe the Contractor’s approach to ensure the effectiveness of O&M support services delivery. The Draft QAP shall be submitted with the Contractor’s Task Order proposal. After Task Order award, the Government will provide comments to the Contractor for resolution and upon such resolution, the Contractor shall provide a Final QAP to the Government for approval.
The QAP shall include the following:
· A description of the inspection system covering all services listed.
· Specifics as to the frequency of the inspections.
· The title of the individual(s) who shall perform each inspection and their organizational placement.
· A description of the methods for identifying, correcting and preventing defects in the quality of service performed before the level becomes unacceptable.
· On-site records of all inspections conducted by the Contractor. The inspection record’s format shall include:
· Date, time and location of the inspection.
· A signature block for the person who performed the inspection.
· Rating of acceptable or unacceptable.
· Area designated for deficiencies noted and corrective action taken.
· Total number of inspections.
As a complement to the QAP, the Government shall utilize a Quality Assurance Surveillance Plan (QASP) to monitor the effective and quality of O&M work performed by the Contractor. A Draft QASP is attached hereto as J_TE11. The Contractor shall adhere QASP and, with its proposal to this Task Order, provide updates to the QASP that describe how the Contractor proposes that quality surveillance be accomplished. The CO will notify the Contractor of acceptance or required modifications to the QASP before the task order start date. The Contractor shall make appropriate modifications (at no additional cost to the Government) and obtain acceptance of the QASP by the CO before the start of the first operational performance period. The Government has the right to require revisions of the QASP (at no cost to the Government) should the incorporated QASP fail to control the quality of the services provided at any time during the task order performance.
13.2. Quality Assurance for Software Development
The Contractor shall provide a methodology for testing and validating secure software development, installations, and modifications. This methodology shall thoroughly prove to ONRR that the software will work in the production environment prior to initial use by the end user.
The plan shall address issues including but not limited to:
· Does the product description meet ONRR’s requirements?
· Is the software product functionality clearly described?
· Does the product run on ONRR equipment and can it be integrated with other ONRR systems?
· Does the product interface with other commercially available software products available in the market place?
· Can the user product testing be accomplished from remote locations?
· Has the software been developed in a secure manner?
The Contractor shall create and maintain a Customer Satisfaction Measurement (CSM) Plan, which shall be submitted to the COR for review and approval within 60 days of task order award. The CSM Plan shall demonstrate the Contractor’s ability to measure customer satisfaction with software development, installations and modifications. The results of the measurement plan execution will be included in the Contractor’s performance evaluation.
All testing shall include volume testing, stress testing, secure application development testing, vulnerability testing, code flaw testing, consistency testing, and robustness testing, that is, run scenarios with wrong inputs or with failing connected equipment and evaluate the robustness of the software. The CSM Plan shall also include the ability for simultaneous testing of multiple application environments. The CSM Plan shall also include monitoring of the non-production environment to ensure availability during designated user acceptance testing.
14. CONTINUITY OF OPERATIONS (COO) PLAN
The Contractor shall provide a Continuity of Operations (COO) Plan to describe how continuity of operations will be assured in support of the MRMSS. The COO Plan shall include methods for meeting performance standards when the workload fluctuates due to planned and unplanned events. The Contractor shall maintain the COO Plan and submit a revised written COO Plan no later than August 1st of each year, updating the previous year’s plan to take into account all lessons learned. The Contractor’s COO Plan shall address the following events and situations:
· Recruitment methodology, hiring difficulties, and risks and seasonal hiring.
· Identification of risk areas.
· Sudden short-term and long-term workload increases and decreases.
· Strikes by employees, subcontractors, and major vendors used in support of this task order.
· Disasters.
· Catastrophic events.
· Adverse weather conditions.
· Loss of essential operational functions.
The Contractor shall address the following aspects for the events and situations above:
· Describe the response (both initial and subsequent) to the situation to assure continued operations.
· Identify the potential resource requirements and how additional resources will be obtained.
· Describe the processes or approaches of communications and coordination needed with the Government, that is, the need for a control center, meetings, and reports.
15. MRMSS NETWORK CONNECTIVITY
The Contractor shall support VPN capability for the MRMSS applications for remote access, business, and disaster recovery.
Access to the Government Citrix portal is granted to the State and Tribal Royalty Audit Committee (STRAC) community in various locations in the United States, to telecommuters, and to other government agencies. Government external customers, including the energy industry, are provided access to an Internet-facing portal currently located in the MRMSS hosted environment. Access by other Department of the Interior federal employees will be supported with the use of the individual’s credentials and personal identification verification identification cards.
The MRMSS network will be configured to sit behind the DOI Trusted Internet Connection (TIC). This will require Government managed devices in the hosting facility.
16. INTERNAL AND EXTERNAL AUDIT SUPPORT
Throughout each year, internal and external auditors will be allowed to review and test a variety of controls within the MMRSS. These audits will include financial and security reviews. The Contractor shall assist and participate in these audits as requested by the COR. The COR will provide the Contractor information as to the activities and updates to deliverables required for any audit review. ONRR will provide the Contractor 30 days’ notice of review and Contractor-required activities. In the event that ONRR is not provided with 30 days’ notice of the audit, then ONRR will notify the Contractor as soon as ONRR receives notification of the audit. On average, there are three (3) to four (4) audits per year.
17. GENERAL ADMINISTRATIVE REQUIREMENTS
17.1. Documents
All reports, work plans, agendas, presentations, process flows, and other documents developed or generated by the Contractor under this task order shall be viewable and editable in MS Office Suite products (compatible with ONRR’s current version).
17.2. Software Related Documentation
The Contractor shall provide independent access to system development life cycle (SDLC) documentation as directed by the COR, including:
· Design documentation; that is, conceptual design, general design, and detailed design
· Business/Functional Requirements Documentation
· Test Plans, Results and Documentation
· Source Code Documentation (The COR shall limit access to source code documentation and determine on a need to know basis the individual(s) that will be provided access to the code documentation.)
18. PERIOD OF PERFORMANCE
The period of performance for this task order is date of award for a period of one (1) year thereafter, hereto referred to as the Base Period, followed by nine option periods which will be unilaterally exercised by the Government. All terms and conditions applicable to the Base Period shall extend to all subsequent Option Period. The Government is under no obligation to exercise the Option Periods and reserves the right to partially exercise any Option Period dependent on requirements or budget changes. The Base Year beginning performance will be adjusted based on the transition plan.
| Base / Option Periods |
| Begin Period of Performance |
| End Period of Performance |
| Base Period |
| TBD |
| TBD |
| Option Period 1 |
| TBD |
| TBD |
| Option Period 2 |
| TBD |
| TBD |
| Option Period 3 |
| TBD |
| TBD |
| Option Period 4 |
| TBD |
| TBD |
| Option Period 5 |
| TBD |
| TBD |
| Option Period 6 |
| TBD |
| TBD |
| Option Period 7 |
| TBD |
| TBD |
| Option Period 8 |
| TBD |
| TBD |
| Option Period 9 |
| TBD |
| TBD |
Note: The start of the O&M task order start is dependent on the transition period.
19. TYPE OF CONTRACT
Firm Fixed Price.
20. OTHER DIRECT COSTS, AND MATERIALS
Other Direct Costs (ODCs) and Materials may be required in performance of this Task Order as agreed upon by the Government and Contractor at Task Order award. All ODCs and Materials will Included in the final price.
21. TRAVEL
Travel may be required in the performance of this Task Order as agreed upon by the Government and Contractor at Task Order award. All travel will be issued as reimbursable IAW the Federal Travel Regulations. The Government will require appropriate invoicing to support travel.
22. HOURS OF OPERATION
The Contractor shall provide 24x7 operations of the MRMSS environment.
General MRMSS support is required from 5:00 am to 7:00 pm Mountain Time, Monday through Friday, excluding Federal Holidays.
23. PROJECT MANAGEMENT PLAN
The Contractor shall prepare an annual MRMSS O&M Project Management Plan describing O&M activities, organizational resources, and management controls to be employed to meet the cost, performance and schedule requirements for this task order. The Project Management Plan shall detail the products, methods for developing the products, and the allocation of staff and other resources necessary to support the MRMSS O&M. The Project Management Plan may be requested to be updated at the direction of the COR as MRMSS O&M priorities may change throughout the year and the schedule shall capture these changes. The Project Management Plan will include a planned Project Schedule for the annual MRMSS O&M activities.
24. RELEASE OF DATA
The contractor and/or contractor personnel shall not divulge or release any data or information developed or obtained in performance of this effort written approval of the Contracting Officer (CO). The contractor shall not use, disclose, or reproduce proprietary data that may or may not carry a restrictive legend, other than as required in the performance of this effort.
25. SOFTWARE QUALITY CONTROL & ASSURANCE
Any software developed for the government under this contract must be verified and validated by the contractor to be free of malicious code. The contractor will assure that secure code practices and reviews are integrated into the development process of all software. The contractor will be held liable for any damage or loss of business as a direct result of developed software containing malicious code.
26. LOCATION OF SOFTWARE DEVELOPMENT
Custom software development and outsource operations must be located in the United States to the maximum extent practical. If such services are proposed to be performed abroad, the contractor must provide an acceptable security plan specifically to address mitigation of the resulting problems of communication, control, and data protection.
27. CONTINGENCY PLAN
The Contractor shall submit a contingency plan in accordance with NIST SP 800-34 and DOI Contingency Plan Guide. The Contractor shall submit contingency plans to the COR for review and approval. NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor shall request copies of the DOI Contingency Plan Guide by contacting the CO or COR. [Reference Technical Exhibit 9 (TE-09) Section 2.6.1.3, Contingency Plan]
28. LOGON BANNER
All Government and Contractor employees and external websites who will access Department of Interior data must acknowledge a Government-approved logon warning prior to each logon to the system.
29. INTERCONNECTION SECURITY AGREEMENT (ISA)
Federal policy requires federal agencies and/or corporation supporting information technology connections for federal agencies establish interconnection agreements. Specifically, Office of Management and Budget (OMB) Circular A-130, Appendix III, requires agencies and/or services on behalf of federal agencies obtain written management authorization before connecting their IT systems to other systems, based on an acceptable level of risk.
Current State: To comply with these requirements, the contractor shall collaborate with the Government (ONRR) to maintain an Interconnection Security Agreement (ISA) that defines and documents the rules of behavior and controls that must be maintained for the system interconnections between two Government offices - Bureau of Safety and Environmental Enforcement (BSEE) and ONRR - that are necessary to provide the MRMSS services described in this Statement of Work.
Future: Any changes to the environment when there is a change in connectivity to a government system, the contractor shall work with the government to develop a current ISA. This ISA shall be mutually agreed to by both the contractor and Government.
The ISA will be consistent with the requirements specified in the Office of Management and Budget (OMB) Circular A-130, Appendix III, for…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .