Attachment 2 - Task Order 2 - CTRP-SD - Amendment 1_0001.pdf

PDF 478 KB Posted

Attached to
NCI BITSDIS IDIQ Federal contract opportunity
Solicitation number
140D0421R0007
Issued by
Department of the Interior Departmental Offices Interior Business Center

About this file

This task order statement of work outlines software development and support services required by the National Cancer Institute's Clinical Trials Reporting Program. The contractor shall provide project management, software development, testing, systems engineering, and security management services. Key deliverables include a task order management plan, monthly status reports, technical documentation, and developed software meeting requirements. The contractor must utilize agile methodologies and maintain the CTRP software in a cloud-based environment. Response times and due dates for deliverables are defined. The National Institutes of Health is the contracting agency.

View the file

Other files for this federal contract opportunity

Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 2: Task Order 2 – CTRP-SD Solicitation 140D0421R0007

Clinical Trials Reporting Program – Software Development (CTRP-SD) Support Services

SECTION 1 – TASK ORDER INTRODUCTION

1.1 GENERAL

This task order requirement is for Clinical Trials Reporting Program – Software Development (CTRP-SD) Support Services.

1.2 SUBMISSION OF QUESTIONS

Contractors shall submit questions in accordance with the instructions provided in the IDIQ Solicitation.

1.3 ANTICIPATED AWARD TYPE

The Government anticipates awarding a Time-and-Materials (T&M) task order. Travel and Other Direct Costs (ODCs) are anticipated in performance of this task order.

SECTION 2 – TASK ORDER STATEMENT OF WORK

2.1 PURPOSE

The purpose of this requirement is to acquire several classes of professional project management, analysis methodologies, software development, testing and quality assurance, systems engineering, and security management services in support of NCI’s Clinical Trials Reporting Program (CTRP.)

2.2 BACKGROUND

The CTRP fulfills a recommendation made by the NCI Clinical Trials Working Group (CTWG) to the National Cancer Advisory Board. This comprehensive database of the entire NCI portfolio will help identify gaps in clinical research and duplicative studies, as well as facilitate effective clinical trial prioritization, trial search and trial matching.

CTRP is a web-based program that is designed to serve as a single, definitive source of information on all NCI-supported cancer-related clinical trials. The CTRP system receives submissions and updates from lead organizations, such as the NCI-Designated cancer centers and from systems within NCI, including those maintained within the Cancer Therapy Evaluation Program (CTEP) and the Division of Cancer Prevention (DCP). CTRP captures information covering all key aspects of a clinical trial — including study design, sponsors, investigators, participating sites, eligibility criteria, trial status, and accrual. The data collected in CTRP is used by NCI to coordinate research efforts and facilitate effective clinical trial prioritization.

Planning for CTRP began in 2008, and development began in 2009, continuing to the present. In 2016 CTRP development and operations were migrated to a FISMA Moderate Amazon Web Services (AWS) cloud environment. This transition was accompanied by significant changes in team composition and project management style that are characterized by agile principles and advanced cloud-based DevOps enabling continuous delivery. Since that time, CTRP has achieved key milestones such as self-service business intelligence analytics and reporting via the newly developed Scientific Trials Analytics Platform (STRAP). The reliable generation of CTRP-generated Data Table 4 reports for interventional cancer clinical trials are essential for P30 Cancer Center Support Grants management.

The work to be performed under this task order continues the development and maintenance of CTRP software systems.

NCI Clinical Trials Reporting Program Software Development and Maintenance (NCI-

CTRP-SD)

The CTRP system is composed of several components that require ongoing development and maintenance. CTRP 5.x+ gathers information about trials funded by NCI and taking place in NCI Designated Cancer Centers. The Scientific Trials Analytics Platform (STRAP) is the reporting component that provides information about trials registered in CTRP to internal and external users. STRAP is the source of CTRP-generated Data Table 4, a report of interventional clinical research studies open at a Cancer Center during a center-defined 12-month reporting period, is used for competing and non-competing grant applications. The Data Warehouse is a set of databases that support the distribution of data to critical partners including NCI’s cancer clinical trial search function on cancer.gov and for use by trial sponsors, including NCI, for Clinicaltrials.gov registration. Additionally, the CTRP software system includes integrations with other NCI supported systems including, Enterprise Vocabulary Services, cancer Data Services Repository (caDSR), Cancer Trials Evaluation Program (CTEP) systems and other Government systems, such as ClinicalTrials.gov. as well as other appropriate third-party systems.

Of significant importance is the identification of the CTRP platform for use in collecting, analyzing, tracking, and reporting serology test results in support the National Covid-19 initiative. The CTRP software and database analysis and reporting capabilities will be used in direct support of research and testing necessary to rapidly develop and deploy safe and effective Covid-19 vaccines.

2.3 OBJECTIVE

The Contractor shall provide a variety of technical support to both new and ongoing application development, documentation, and maintenance efforts and deliver software and documentation products that effectively meet approved NCI requirements and established architectures in support of the National Cancer Institute’s (NCI) Clinical Trials Reporting Program (CTRP).

These services include, but are not limited to the following:

• Maintain, enhance, refactor CTRP, as appropriate;

• Design, develop, document, test, operate and publish CTRP;

• Deploy, test, provide hosting, and maintain a cloud based CTRP system;

• Assist NCI in completing analysis of alternatives for ongoing development and hosting approaches;

• Support analysis, planning, and migration of CTRP to new cloud-based environments as directed by the NCI;

• Provide operational support for bioinformatics pipelines;

• Provide operational support for cloud infrastructure;

• Support data sharing;

• Support the analysis and data loading of data associated with interventional trials and non-interventional studies into CTRP software systems;

• Provide and/or facilitate high-level project plans for all efforts;

• Provide program planning and support for automated CTRP reporting;

• Develop and deploy solutions to improve cancer clinical trial search and retrieval, including, but not limited to, activities of the Finding Cancer Trials Collaborative;

• Provide systems analysis to enhance data submission and curation;

• Facilitate strategic alignment, shared standards, improved interoperability through collaboration with related projects such as Enterprise Vocabulary Services;

• Development of methods that utilize Natural Language Processing (NLP) and

Machine Learning technology to support and automate clinical trial protocol evaluation, classification and annotation;

• Develop structured and computable representation of clinical trial protocols in general, specifically the eligibility criteria for improved clinical trial search and patient/trial matching;

• Provide analysis for integrated NCI systems and services (e.g. CTRP integrations);

and

• Provide Help Desk and technical support.

2.4 SCOPE

The Scope of this Task Order covers a variety of work activities required to meet the stated objectives. Activities performed will include but are limited to; providing subject matter expertise, consulting, and technical services supporting program and project management of the planning, acquisition, definition, design, development, implementation, operation, and maintenance of services, applications, and software, hardware, and communications infrastructures to support NCI’s Clinical Trials Reporting Program. The Contractor shall provide several general classes of professional project management, software development, testing and quality assurance, systems engineering, and security management services in support of NCI’s Clinical Trials Reporting Program. These services require interaction with senior NCI scientific, business and IT managers, program stakeholders, and other contractors. The NCI Center for Biomedical Informatics and IT (CBIIT) will provide guidance for software development, testing, deployment, and hosting. The government’s Contracting Officer’s Representative will provide tasking and Task Order direction.

The scope of services to be provided includes, but is not limited to, the following:

• Project Management;

• Complete project documentation;

• Business application analysis;

• Application requirements definition;

• Application design;

• Analysis method development;

• Application development;

• Application integration;

• Application documentation;

• Application user support;

• Application maintenance;

• Application testing;

• Quality control and assurance;

• Compliance management of sensitive information;

• Cloud Systems Engineering; and

• Information security.

Importantly, this effort includes the support, not only of existing activities, but also of new and emerging initiatives to support the acquisition, abstraction, safe storage, maintenance and distribution of cancer clinical trial data, including accrual, and its associated metadata. All aspects of these related projects shall follow modern best practices in a manner consistent with the objectives of system reliability, speed, interoperability, high data quality, scalability, elasticity, and security appropriate for adhering to federal standards for PHI, PII, and emerging GDPR requirements.

Further, the Contractor shall consider costs and seek ways to optimize the dollars associated with all efforts and consider ways to continually lower the costs for all projects, including the creation of reusable modules. Work includes but is not limited to analysis, planning, cost estimation, monitoring, tracking, reporting; system and database requirements definition, design, development, documentation, implementation, update, bioinformatics support, and operations and maintenance. The expertise and support provided will assist Federal staff to plan, implement, control, and manage on-going and new work to achieve approved NCI and CBIIT plans, goals, and objectives.

The Contractor shall report directly to the government’s Contracting Officer’s Representative (COR) and shall not play any role in directing or managing work of any other project or support contractor staff. Work products shall include program and data files, recommendations, analyses, functional requirements documentation, technical documentation, management reports, briefings, and fully tested and functional software.

2.5 TASK AREAS

Independently and not as an agent of the Government, the Contractor shall furnish all the necessary services, qualified personnel, material, equipment, hosting environments, and facilities, not otherwise provided by the Government, as needed to perform this SOW at the direction of the COR in the Task Areas specified below.

2.5.1 Task Area 1 – Task Order Management

The Contractor shall provide the technical and functional activities necessary for the management of this Task Order and all activities described in it.

The Contractor shall institute and maintain an effective, efficient, and responsive management organization that shall be responsible for the management and oversight of all personnel and financial resources utilized in the performance of this contract. The Contractor’s management organization shall be responsible for ensuring that all work activities are performed in a timely and cost-effective manner while maintaining the highest quality of performance.

2.5.1.1 Task Order Management Plan

The Contractor shall provide a Task Order Management Plan outlining the Tasks, Subtasks, schedules, and approaches to be used to provide the required services including the specific tools to be used, deliverable documents, analyses, and reports to be developed. The plan will describe the resources and the company's policies and procedures for the effective management of this Task Order and all work performed.

The plan shall address the task areas described in the following Statement of Work (SOW) subsections and shall be consistent with the methodologies and approaches proposed for overall program/project management contained in the Contractor's proposal. When approved by the COR, this plan shall be implemented and used to monitor, control, and report progress, issues, and resource expenditure.

An initial draft Task Order Management Plan including Continuous Performance Improvement and Quality Assurance sections shall be provided as an attachment to the Contractor’s proposal.

This initial draft plan shall be updated or modified as required after discussion in the Task Order kickoff meeting and submitted as a draft deliverable product as specified in Section 6 below.

In addition to technical sections outlining key tasks, schedules and milestones, the Task Order Management Plan shall contain resource management sections containing projected burn rates, staffing labor categories and rates, and projected hours by month. The plan shall be updated monthly, and updates shall be provided as part of the monthly status reporting.

The Contractor shall participate in Task management meetings and provide bi-weekly status updates and monthly written status reports, monitoring the performance and progress toward successful completion of this SOW.

2.5.1.2 Contract Start-Up Meeting

Within ten business days of award, the Contractor shall participate in a Contract Start-Up Meeting and present an orientation briefing for the Government. The intent of the briefing is to initiate the communication process between the Government and Contractor by introducing key Task participants and explaining their roles, reviewing communication ground rules, and assuring a common understanding of the work to be accomplished under this SOW.

2.5.1.3 Status Meetings and Reports

The Contractor shall participate in recurring management meetings to provide progress and status updates. Additional recurring meetings may be requested and scheduled as needed to meet project requirements.

Currently scheduled meetings include:

• Weekly Issues and Risks Meeting;

• Weekly Project Status Meeting; and

• Monthly Leadership Status Meeting.

2.5.1.4 Contractor Interfaces

The Contractor and/or its subcontractors may be required, as part of the performance of this effort, to interact with other contractors working for the government in collaborative tasks and activities. Such other contractors shall not direct this Contractor and/or its subcontractors in any manner. Also, this Contractor and/or its subcontractors shall not direct the work of other contractors in any manner.

When appropriate, the Government shall establish an initial introduction and contact between the Contractor and other contractors and participate in an initial meeting at which the conventions for the scheduling and conduct of future meetings/contacts shall be established. Any CORs of other contracts efforts shall be included in any establishment of conventions.

The Contractor shall work closely with other contractors to document and implement the procedures to be used to ensure open, timely, and effective communication, information exchange, and reporting among the contractors and the government.

2.5.1.5 Contractor/Subcontractor Personnel

The Contractor shall be responsible for managing and overseeing the activities of all Contractor personnel, as well as subcontractor efforts used in performance of this effort. The Contractor's management responsibilities shall include all activities necessary to ensure the accomplishment of timely and effective support, performed in accordance with the requirements contained in the

SOW.

Resumes submitted for employees assigned to perform under this SOW shall document experience directly applicable to the functions to be performed. Further, these prior work experiences shall be specific and of sufficient variety and duration that demonstrate the employee is able to perform the functions effectively and efficiently assigned.

The contractor shall provide dedicated engineering support capacity to ensure CTRP operations in the specified scope and at the specified service level including but not limited to user account and type of data access, user materials management, bug fixing, outage mitigation and functionality restoration throughout the entire duration of the contract. The team size and composition must reflect a reasonable reserve capacity that can accommodate vacation time and sick leave in all critical project support roles. Responsibilities towards other projects must not jeopardize the Contractor’s ability to fulfil any necessary CTRP support functions or meet agreed up delivery deadlines unless explicitly approved by the COR.

2.5.1.6 Technical Organization and Management

The Contractor shall identify and maintain a management structure and organization with overall project control and authority for the performance of work under the task order. The Contractor's management structure and organization shall ensure that the following requirements are met throughout the life of the task order:

• A technically proficient and professionally capable integrated project team (IPT) including, as a minimum, representatives from the following groups shall be established, used, and maintained throughout the life of the task order to inform and guide project management and work efforts:

o Business owners and/or functional users;

o Business analysis;

o Technical analysis and design;

o Technical architecture;

o Polyglot software development;

o Data science, information analysis and visualization;

o Testing and quality assurance;

o Information security;

o Systems and cloud engineering; and o Application support.

• A well-functioning, useable and available communication process and tool(s) to ensure all IPT members and stakeholders are involved in project related discussions and decisions, and those decision are recorded and adequately published;

• A technical project manager with knowledge, skills, and experience in successfully managing an agile development project similar in size, scope, and complexity;

• A technical lead with knowledge, skills, and experience in successful agile development of software of similar size, scope, and complexity including the advanced use of cloud platforms and technology. The technical lead shall have a fully defined role and the authority and responsibility to provide technical leadership and guidance in the development process;

• System architecture knowledge, skills, and experience in successful agile development of software of similar size, scope, and complexity in a cloud-based environment.

Substantial demonstrated experience in modern state-of-the-art tech stacks, microservice based architecture, and DevOps;

• Senior cloud operations expertise with a strong background in Amazon Web Services (AWS) or a similar cloud platform with demonstrated expertise in PaaS and SaaS;

programming languages like Python; shell scripting, orchestration systems, container based deployment technologies like Docker, and experience in setting up and maintaining a cloud based continuous integration and deployment pipeline;

• Data science and/or machine learning expertise with strong skills to implement data analysis methods leveraging artificial intelligence, machine learning and natural language technologies, preferably with experience in processing clinical research data;

• Senior frontend engineering expertise with extensive knowledge of JavaScript, HTML, CSS, and modern dynamic web technology frameworks, cross browser performance optimization, real-time data streams, and 508 compliance. The contractor shall provide excellent client interaction and communications skills and fundamental understanding of clinical trials, portfolio management and clinical research data;

• Senior data warehouse engineering expertise with demonstrated expertise in data integration and normalization, master- and metadata management and experience in creating a multitier data warehousing architecture that includes and integrates operational data stores, normalized relational databases and no-SQL datastores, document stores into a comprehensive information management solutions that supports accurate, complex and high-performance business intelligence, analysis and reporting needs for both public and private data. Understanding of clinical research data is a preferred skill;

• The contractor shall establish a small team of IPT members (Honest Brokers) that have been specifically trained to access, evaluate and analyze managed sensitive data (such as accrual information and personal identifiable information). Access to sensitive data shall be audited and restricted to the members of this Honest Brokers group;

• Where knowledge, skills, experience, and abilities are appropriate for specific activity requirements, assigned staff shall be cross trained and able to back up or fill multiple roles such that no single task is dependent upon a single individual;

• Continuous coverage shall be provided to ensure tasks are not negatively impacted by individual staff schedules, availability, or absence;

• Management and reporting methodologies shall be implemented in alignment with CIO and CBIIT policies and standards to ensure responsive and effective performance of all subcontractor staff;

• Risk and issue management processes shall be defined and implemented to ensure that problems are avoided and/or resolved with minimal impact on performance, schedule, and cost;

• Methodologies and approaches shall be defined in conjunction with government managers and implemented and revised as necessary to ensure collegial and professional working relationships with NCI staff and other contractors;

• Continuous feedback on technical performance shall be requested and obtained from NCI and external stakeholders monthly and provided to Contractor and NCI management on all areas of Task Order performance;

• The quality and timeliness of the deliverable products and services provided under this Task Order shall be continually monitored to ensure performance improvement throughout the life of the task order; and

• All staff resources used for the performance of work under the Task Order shall be identified, their roles clearly defined, and their relationship to the organization and project established and identified for approval by the government’s Contracting Officer’s Representative (COR.) Any changes to this approved staffing model and assigned staff must receive prior approval from the COR.

2.5.1.7 Continuous Performance Improvement and Management

The Contractor shall manage this Task Order using a Continuous Performance Improvement monitoring and reporting approach. Areas in which the government is interested in monitoring performance relate to:

• Technical effectiveness and quality;

• Timeliness and schedule;

• Working relationships with government and other contractor staff;

• Risk and issue management; and

• Resource management and cost control.

The Contractor shall develop, implement, and maintain a continuous improvement program that focuses on continual productivity improvement, quality enhancement, and resource savings, and is designed to promote excellence, innovation, and efficiencies, both in Contractor performance and in the performance of the CTRP mission. The Contractor shall report in the Monthly Project Status Report on quantitative and qualitative improvements resulting from the continuous improvement program and include outstanding issues that need improvement with an anticipated completion date.

The Contractor shall implement a metrics and reporting process to evaluate organizational performance, progress, and efficiency in performing the activities of this task order.

Additionally, the Contractor shall coordinate with NCI managers to ensure that the metrics developed and implemented allow effective and efficient monitoring and evaluation of task and organizational progress.

The Contractor shall submit a draft Continuous Performance Improvement section outlining proposed performance measures; review schedules; renegotiation or measurement change methods; and proposed incentive award performance levels. Final contents of this draft plan including metrics, performance measures, and incentive award levels will be negotiated with the awarded Contractor and form the basis for the award of incentives.

The Contractor’s continuous performance improvement process shall focus on measuring the performance against the performance measures established by the Contractor and accepted by the government in the Task Order Management Plan. The program shall include measurements of productivity and quality, as well as task management measurements. These metrics shall be incorporated in the periodic progress, financial, and Task Order management reports submitted under this Task Order.

2.5.1.8 Continuous Quality Assurance, Quality Control, and Improvement Program The Contractor shall establish, implement, and maintain an effective continuous quality assurance/control program to ensure consistent technical quality for all deliverables, work products, and services performed under this task order. The quality assurance/control program shall include management and technical reviews and audits to validate the quality of the work performed by the Contractor's personnel and of the work performed by its subcontractors.

The contractor shall include a Quality Control section in the Task Order Management Plan specifying the tasks, sub tasks, and approaches to be used to ensure adequate accuracy and quality of products delivered and services provided. The Contractor shall ensure that all employees, at any level, can elevate quality concerns to Contractor task and senior management.

The Contractor shall ensure that all assigned personnel are sufficiently qualified to execute the tasks listed in this SOW. The Contractor shall bear responsibility to meet the cost, performance, and schedule requirements in this Task Order throughout its execution. The Contractor will ensure that all personnel are adequately trained sufficiently qualified to execute the tasks listed in this SOW. This includes, but is not limited, to the use of the agile methodology, software necessary for this project, as well as all applicable confidentiality, privacy, information security, and conflict of interest regulations and corresponding NIH and HHS policies.

Contractor/subcontractor staff shall sign Non-Disclosure Agreements as they may have access to data that may contain personally identifiable and/or business sensitive information.

Additionally, the Contractor shall furnish insights into the success of processes and provide suggestions for changes to improve work efficiency and end-user satisfaction.

2.5.1.9 Documentation, Documentation Delivery, Storage, and Internal Coordination and

Communication Well written, complete, up to date, and accurate documentation is important to all project stakeholders and managers. It is essential for all stakeholders and participants to be able to fulfill their roles and provides an up to date view of ongoing tasks and activities, and future plans as well as technical details required to ensure performance, progress, and future tasks and maintenance activities.

The Contractor shall be responsible for the standards, content, detail, maintenance, storage, and control of all project documentation. This may entail working closely with other Contractors in a collaborative and congenial relationship to ensure that project and business owner needs are met.

The Contractor shall use NIH email for all communication associated with this contract. The Contractor shall use secure NCI storage space (as identified by the COR) for delivery and storage of CTRP documentation in addition to required hard copy management deliverables specified below. This, or other specified, Government furnished storage space shall also be used by the project to communicate details about the project to the internal stakeholder community.

Documentation intended for the public will be made available on a suitable publicly accessible government space identified by the COR.

The Contractor shall ensure that documentation delivered is traceable through complete life cycle documentation. Technical deliverables and system functionality shall be based upon requirements traceable back to business needs and objectives. Technical specifications and system functions shall be based upon approved specifications. Test results shall trace back to specifications and requirements.

2.5.2 Task Area 2 – Software Development

The contractor shall develop and enhance the software that support the current CTRP system and continue to meet the business requirements.

The contractor shall ensure that the writing of new CTRP software uses a simplified code base, supports enhanced reusability of the code, and utilizes improved technology while eliminating any remaining irrelevant legacy application requirements and outdated technologies. This includes maintaining the current architecture of the application into several interconnected but still separate modules, which simplifies ongoing development and maintenance.

Whenever appropriate, changes shall be identified and, when approved, made to ensure reducing future operations and maintenance costs, increase the ability to react to new feature requests and optimize functionality, and create a more secure application.

2.5.2.1 Development Methodology

The contractor will continue the development and maintenance of the CTRP-SW platform following a DevOps methodology. Deployable units will be prioritized, defined, and delivered as they are completed.

The contractor will also facilitate meetings in which stakeholders and participants attempt to form a common understanding of pre-planned features. These meetings may lead to significant changes in the requirements for the deliverables in progress at that time. While small adjustments of requirements or their interpretations are to be expected during implementation, fundamental changes during real-time development slows progress, increases cost, and lessens business owner confidence of success.

To avoid these issues, the Contractor shall implement and follow a true DevOps development, incremental delivery, and continuous process improvement approach. An integrated project team shall be formed and used to provide input and ensure understanding, acceptance, and approval of decisions made. The Contractor shall ensure that best-practice code development and documentation standards are followed.

It is essential that the IPT has sufficient protected reserve capacity and ability to address high priority bugfixes, mitigate outages and restore functionality quickly at all times during business hours.

2.5.2.2 CTRP Requirements Review and Validation

The Contractor shall review currently documented requirements and planned development priorities and validate these with the business owner. Additionally, the contractor shall work with the business owner, stakeholders, and participants to ensure all known and anticipated requirements are well documented and prioritized for submission into the change management process and inclusion in future development.

The Contractor shall analyze the requirements and in a timely fashion communicate the implementation consequences if requirements modifications have the potential to significantly lower system complexity and/or cost, improve reliability, security, performance or maintainability of CTRP. In that case the Contractor shall outline alternatives in a manner that allows the COR and the Government client to fully understand consequences, risks and benefits, and subsequently make a decision on whether to approve (one of) the proposed requirements modification(s).

2.5.2.3 Validation and Optimization of the Technology Stack

The Contractor shall continue to evaluate the existing technology stack for appropriateness, effectiveness, cost benefit, technical capability and performance and, if available, propose more modern technologies and cost-effective products for improvement.

The Contractor shall optimize alignment and harmonization of technology platform, framework and application choices with NCI CBIIT’s increasing adoption of cloud services in general and AWS in particular without jeopardizing individual project requirements. This is of particular significance when it comes to the adoption of non-Fed Ramped solutions which shall require prior approval by the COR in coordination with the office of NCI of CIO. The Contractor shall first consider options that are already licensed or approved by the NCI.

The Contractor shall provide support from a system architect with knowledge and expertise in these technologies and the skills and abilities to provide technical architecture input and guidance to the IPT. A system architect will assist the IPT to ensure that the tech stack is fully optimized and setup to provide maximum benefit to the project and application.

In addition, the system architect shall review the current tech stack to confirm its applicability and/or make and justify recommendations for change and improvement. In this context the Contractor shall maintain a high-level of communication and coordination with the NCI office of CIO to facilitate a common technology adoption strategy, common NCI-wide management of cloud infrastructure, maximize any economies of scale, support project portability between different NCI managed cloud instances and resource pooling, and implement tech stacks that simplify the certification process for the Authorization to Operate (ATO).

2.5.2.4 CTRP Refactoring and Development

Using the methodology outlined in Section 5.2.1 Development Methodology above and updated requirements resulting from the CTRP Requirements Review and Validation described in Section 5.2.2 above, the Contractor shall refactor, modernize, and update CTRP software based upon business owner approved requirements and plans. Software developed will be implemented, tested, and installed on an incremental basis in releases and on schedules approved by the business owner.

At a minimum, all software shall be tested using a three-part process including development testing, integration testing, and user acceptance testing before deployment into an operational environment and use. Test plans, test scenarios, expected results, and actual results shall be provided for all integration and user acceptance testing. If necessary, errors found during testing shall be repaired and retested. Software shall not be deployed without having passed testing and acceptance by the government.

Upon completion of the development and deployment process, the government shall have received fully functional software meeting approved requirements and all technical and user documentation necessary to train, operate, and maintain the software. At a minimum, this shall include updated requirements, instructor and training materials, software design documentation, software/system maintenance manual and other required and industry standard technical documentation such as a data dictionary, flow charts, etc.

CTRP’s primary purpose is to provide the NCI the ability to objectively evaluate its return on investment of the NCI supported Clinical Trial Enterprise. The high-level requirements of the CTRP application can be summarized as follows.

The system shall:

• Serve as a comprehensive database containing information on all NCI-funded clinical trials to facilitate better planning and management across clinical trial venues;

• Provide capabilities for viewing, analyzing, comparing, and mining data across trials;

• Support Legal Compliance with the Food and Drug Administration (FDA)

Amendments Act of 2007 (FDAAA), which requires registration and updating of clinical trial data in ClinicalTrials.gov; as well as support compliance with NIH grant reporting requirements: https://grants.nih.gov/policy/clinical-trials.htm;

• Support clinical trial registration, curation and quality control of the submitted clinical trial information, and annotation with scientific terminologies such as the NCI Thesaurus;

• Support Cancer Center Clinical Trials Portfolio Analysis and Performance Monitoring, along with Policy Compliance for Cancer Center grantees, which requires submission of the Cancer Center Support Grant (CCSG) Summary Data Table 4 to the Office of Cancer Centers (OCC);

• Enable Clinical Trials Search of NCI-supported clinical trials by making data publicly available for Third Party Consumption including NCI’s Cancer.gov Clinical Trials Search website;

• Ensure a clear separation of data made available for public consumption from sensitive, or otherwise access restricted data reserved for NCI internal use;

• Securely and compliantly store and manage personally identifiable information (PII), including but not limited to participant accrual data, as protected non-public information;

• Facilitate automated trial matching based on genetic analysis reports and/or data from electronic medical records by supporting development and management of portable structured clinical trial eligibility criteria and patient matching algorithms.

https://grants.nih.gov/policy/clinical-trials.htm

• Facilitate the collection, analysis, tracking, and reporting of serology test results in support the National Covid-19 initiative.

Furthermore, the following service level shall be guaranteed for the CTRP system:

• Uninterrupted uptime for clinical trial registration from 8 AM to 8 PM Eastern Time on all business days (or as defined by the US federal government);

• Continuous 24/7 operation of all APIs with reasonable service windows for scheduled maintenance coordinated with the government’s Contracting Officer’s Representative.

2.5.3 Task Area 3 – Transition Planning and Support

In the final year of the Task Order, or in the event the Government requirements necessitate a re-compete of the requirements of this SOW, and prior to completion of this Task Order’s period of performance, the Contractor shall develop and deliver a Transition Plan. The purpose of the Transition Plan is to ensure an orderly and successful transition of the CTRP effort should the incumbent Contractor not be selected during the re-competition of the Task Order. This Transition Plan shall include processes, procedures, and activities the Contractor shall use, if not selected for a follow-on contract, to adequately educate and train the successful contractor’s employees and smoothly and effectively transition work activities to the new Contractor. When tasked, the Contractor shall implement the Transition Plan and assist the business owner to transition knowledge, processes, tasks, activities, etc. to the follow-on contractor.

The Contractor shall maintain and transition administrative management for the CTRP Task Order and provide senior project and communication management oversight during the transition. Overall maintenance and transition of administrative support may include such functions as maintaining adequate staffing; work scheduling, attending meetings with the NCI COR and CTRP leadership, and preparing status reports as required by the NCI COR.

2.5.4 Task Area 4 – Helpdesk and Application Support

The Contractor shall staff a helpdesk during regular business hours from 8 AM ET to 6 PM ET that provides technical and applications support for the CTRP application. The helpdesk will serve intra- and extramural CTRP users and CCCT business owners.

The Contractor shall track all helpdesk requests from initial contact to resolution utilizing the NCI/COR prescribed IT Service Management tool (currently Service Now). If the resolution involves project activities tracked in a different system, then bidirectional pointers are to be added to ensure traceability.

The Contractor shall establish and adhere to reasonable Service Level Agreement policies in line with the project requirements and priorities and shall ensure exposure of sensitive information is limited to desired and pre-defined audiences.

Specifically, the contractor shall ensure that all helpdesk requests are answered within the same business day. The response should provide either a solution, the requested information, or in case this is not possible, planned next steps and an estimate for a resolving response. Automated responses are encouraged when acknowledging the receipt of the helpdesk requests but should be followed up with a targeted communication and request-specific information.

The contractor shall develop and refine training material such as user manuals, How-to and Frequently Asked Questions (FAQ) documents that can be used to improve help-desk efficiency and support quality.

The contractor shall be able to provide detailed reports and statistics on the helpdesk support activity upon request by the business owner.

2.5.5 Task Area 5 - Other Services Required to Support SOW Requirements The Contractor shall provide other related support of tasks and projects within the scope of this SOW as required for successful completion and as directed by the Government’s assigned COR.

2.6 NIH FISMA and FEDRAMP INFORMATION SECURITY and/or PHYSICAL

ACCESS SECURITY Compliance Requirements

Prohibition on Contractor Involvement with Terrorist Activities The Contractor acknowledges that U.S. Executive Orders and Laws, including but not limited to E.O. 13224 and P.L. 107-56, prohibit transactions with, and the provision of resources and support to, individuals and organizations associated with terrorism. It is the legal responsibility of the Contractor to ensure compliance with these Executive Orders and Laws. This clause must be included in all subcontracts issued under this contract.

NIH FISMA and FEDRAMP Information Security and/or Physical Access Security guidance

INFORMATION SECURITY AND/OR PHYSICAL ACCESS SECURITY

A. Position Sensitivity Designations- All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract:

[ ] Level 6: Public Trust - High Risk. Contractor/subcontractor employees assigned to Level 6 positions shall undergo a Suitability Determination and Background Investigation (MBI).

[ ] Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

[X] Level 1: Non-Sensitive. Contractor/subcontractor employees assigned to Level 1 positions shall undergo a Suitability Determination and National Check and Inquiry Investigation (NACI).

1. HOMELAND SECURITY PRESIDENTIAL DIRECTIVE (HSPD)-12

The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order

13467, Part 1 §1.2. For additional information, see HSPD-12 policy at:

https://www.dhs.gov/homeland-security-presidential-directive-12)

Roster-

a. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO within fourteen (14) calendar days after the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within seven (7) calendar days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at:

https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_ 10-15-12.xlsx

b. If the Contractor is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

c. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

d. The Contractor shall notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the contract and if they have previously been the subject of national agency checks or background investigations.

e. All contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract. Contractors may begin work after the fingerprint check has been completed.

f. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-14. Accordingly, the Contractor shall ensure that any additional employees whose names it submits for work under this contract have a reasonable chance for approval.

g. Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the contract price of no more that the cost of the additional investigation(s).

h. The Contractor shall include language similar to this "HHS Controlled Facilities and Information Systems Security" language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

https://www.dhs.gov/homeland-security-presidential-directive-12 https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx

i. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.

j. Within 7 calendar days after the Government's final acceptance of the work under this contract, or upon termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.

B. Security Assessment and Authorization (SA&A)- A valid authority to operate (ATO) certifies that the Contractor's information system meets the contract's requirements to protect the agency data. If the system under this contract does not have a valid ATO, the Contractor (and/or any subcontractor) shall work with the agency and supply the deliverables required to complete the ATO within the specified timeline(s) within three (3) months after contract award. The Contractor shall conduct the SA&A requirements in accordance with HHS IS2P, NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach (latest revision).

For an existing ATO, Contracting Officer Representative must make a determination if the existing ATO provides appropriate safeguards or if an additional ATO is required for the performance of the contract and state as such.

NIH acceptance of the ATO does not alleviate the Contractor's responsibility to ensure the system security and privacy controls are implemented and operating effectively.

C. A Package Deliverables - The Contractor (and/or any subcontractor) shall provide a SA&A package within 30 days of contract award to the CO and/or COR. The following SA&A deliverables are required to complete the SA&A package.

• System Security Plan (SSP) - due within 30 days after contract award. The SSP shall comply with the NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, the Federal Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline requirements, and other applicable NIST guidance as well as HHS and NIH policies and other guidance. The SSP shall be consistent with and detail the approach to IT security contained in the Contractor's bid or proposal that resulted in the award of this contract. The SSP shall provide an overview of the system environment and security requirements to protect the information system as well as describe all applicable security controls in place or planned for meeting those requirements. It should provide a structured process for planning adequate, cost-effective security protection for a system.

The Contractor shall update the SSP at least annually thereafter.

• Security Assessment Plan/Report (SAP/SAR) - due 30 days after the contract award.

The security assessment shall be conducted by the assessor and be consistent with NIST SP 800-53A, NIST SP 800-30, and HHS and NIH policies. The assessor will document the assessment results in the SAR. The NIH should determine which security control baseline applies and then make a determination on the appropriateness/necessity of obtaining an independent assessment. Assessments of controls can be performed by contractor, government, or third parties, with third party verification considered the strongest. If independent assessment is required, include statement below. Thereafter, the

Contractor, in coordination with the NIH…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .