15-223-SOL-00185_Atch_1_IDIQ_SOW.pdf

PDF 204 KB Posted

Attached to
Electronic Laboratory Notebook Federal contract opportunity
Solicitation number
15-223-SOL-00185
Issued by
Department of Health and Human Services Food and Drug Administration

About this file

IDIQ Statement of Work

View the file

Other files for this federal contract opportunity

Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

15-223-SOL-00185 Atch1 IDIQ SOW

Attachment 1 – Electronic Laboratory Notebook (ELN) Indefinite Delivery Indefinite Quantity (IDIQ) Statement of Work (SOW)

Amendment 1 Note: Changes are highlighted in yellow.

Contents

1. BACKGROUND

2. OBJECTIVE

3. TECHNICAL STANDARDS AND GUIDELINES

3.1. FDA Tailored Enterprise Performance Life Cycle (EPLC)

3.2. FDA Master Approved Technologies List (MAT)

3.3. Authorization to Operate (ATO)

3.4. Contractor Compliance

3.5. Compatibility with FDA’s Environment

3.6 IT Security

3.7 Technical Environment

4. SCOPE

5. REQUIREMENTS

5.1. Project Management

5.1.1. Meetings

5.1.2. Documentation

5.2. Technical Functionality and Features

5.3. Software Licenses

5.4. Technical Support/Software Maintenace

5.5. Operations and Maintenance (Labor Category-based Pricing)

5.6. Training Support (Labor Category-based Pricing)

5.7. Development Modernization and Enhancement (Labor Category-based Pricing)

6. DELIVERABLES

7. SECTION 508 COMPLIANCE

1. BACKGROUND

The Electronic Laboratory Notebook (ELN) is an initiative to provide scientists the ability to replace their hand-written official laboratory paper notebooks with intuitive software. An ELN is a computer program which can be used to document research, experiments, and procedures performed in a laboratory. ELN’s also allow for the direct incorporation of data from laboratory instruments to streamline the process of recording statistics, instrumentation test results, graphs, and charts. With the use of this technology, scientists will be given the ability to save, organize, compile, share, and protect intellectual property.

Scientists across the US Food and Drug Administration (FDA) having varying requirements for ELN’s. For example, the Center for Food Safety and Nutrition’s (CFSAN) Office of the Center Director (OCD) needs to ensure scientists have the tools necessary to execute the Center’s mission to protect public health.

Currently, there is no Laboratory Information Management System (LIMS) deployed and several CFSAN scientists use hand-written official Laboratory paper notebooks for documenting research. OCD in collaboration with other CFSAN offices is exploring Electronic Laboratory Notebook (ELN) sol utions to document and enhance the work of researchers. Other FDA centers and offices have similar needs.

2. OBJECTIVE

The objective of this Indefinite Delivery Indefinite Quantity (IDIQ) contract is for the FDA to procure ELN Software solution(s) and associated services that meet the documentation and archiving needs of the FDA’s teaching, research, and outreach missions while protecting the legal, privacy, and policy interests of the FDA.

3. TECHNICAL STANDARDS AND GUIDELINES

Any software required on FDA client computers, or in FDA data centers, as part of the overall solution design must not conflict with FDA technical standards. Software that is required as part of the solution design that is not already approved for use within FDA must be evaluated by the FDA IT Investment Management (ITIM) governance process and receive approval prior to award.

3.1. FDA Tailored Enterprise Performance Life Cycle (EPLC)

Refer to Attachment 6 for more information. All activities/tasks performed under this contract shall be monitored and managed in accordance with IT best practices defined in the Health and Human Service Enterprise Performance Life Cycle (EPLC) guidance document. Applicable artifacts that may be required will be specified, as necessary, in each individual task order.

3.2. FDA Master Approved Technologies List (MAT)

The FDA Master Approved Technology (MAT) List contains a list of approved and not approved technologies that include applications (software), infrastructure and peripherals (hardware), and scientific software and devices. The FDA is responsible for initiating the ITIM process and ensuring the proposed ELN software solution is on the MAT list prior to issuing an award.

3.3. Authorization to Operate (ATO)

The Contractor shall support FDA stakeholders to identify and document security requirements associated with obtaining the Authorization to Operate (ATO) including NIST SP 800-53 Rev. 3. As tasked, the Contractor shall document updated control descriptions for any NIST SP 800-53 Rev. 3 controls that will be impacted due to the work performed.

3.4. Contractor Compliance

The Contractor shall be responsible for knowledge of and compliance with all applicable federal information technology and information management laws, regulations, policies, and standards at the government-wide, HHS, and FDA levels. At the government-wide level, these include Office of Management and Budget (OMB), National Institute of Standards and Technology (NIST), and General Accounting Office (GAO). These can be primarily found at or through the Federal CIO Council website at: http://www.cio.gov/. HHS documents are found at: http://www.hhs.gov/oirm/

3.5. Compatibility with FDA’s Environment

The suggested software must be compatible with FDA’s technical environment, upgrades to technical environment, security requirements, and/or be capable of being minimally configured to be compatible. Please see GFI Appendix B for current technical reference architecture standards. These standards may change over time and vendors are expected to maintain a software refresh schedule that is in compliance with these standards. Contractors will be notified if the technical architecture is at risk of falling out of compliance. The proposed ELN Software solutions must be compatible any PC, Laptop, Scientific computing station, or Tablet running any of Windows 7, Windows 8.1, Windows 10, Unix, and Linux operating systems (minimum) and Oracle 11g / 12g databases.

3.6 IT Security

The Contractor shall ensure the system is compliant with Federal and agency security requirements. The Contractor shall support all security related activities including the certification and accreditation process.

http://www.cio.gov/ http://www.hhs.gov/oirm/

The Contractor shall comply with the following:

• FDA Security Authorization Process: Security Authorization is the approach FDA follows to fulfill Federal Information Security Management Act (FISMA), Office of Management and Budget (OMB) and Department of Health and Human Services (HHS) requirements to ensure that information resources have adequate security to protect the Confidentiality, Integrity and Availability of information collected, processed, transmitted, stored, or disseminated by the agency. For further information see: FDA Security Authorization Toolkit (SP 800-37 Rev. 1: Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach.

http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf)

• NIST & OMB Requirements:

o NIST SP800-53 - This publication was developed by the Joint Task Force

Transformation Initiative Interagency Working Group with representatives from the Civil, Defense, and Intelligence Communities in an ongoing effort to produce a unified information security framework for the federal government— including a consistent process for selecting and specifying safeguards and countermeasures (i.e., security controls) for federal information systems. SP 800-53 Rev. 3: Recommended Security Controls for Federal Information Systems and Organizations.

http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800 53-rev3-final_updated-errata_05-01-2010.pdf o FISMA The E-Government Act (Public Law 107-347) passed by the 107th Congress and signed into law by the President in December 2002 recognized the importance of information security to the economic and national security interests of the United States. Title III of the E- Government Act, entitled the Federal Information Security Management Act (FISMA) requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. For further information see: Federal Information Security Management Act (FISMA) o NIST - The E-Government Act [Public Law 107-347] passed by the 107th Congress and signed into law by the President in December 2002 recognized http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf) http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800 http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800 http://csrc.nist.gov/drivers/documents/HR2458-final.pdf http://csrc.nist.gov/drivers/documents/FISMA-final.pdf http://csrc.nist.gov/drivers/documents/FISMA-final.pdf http://csrc.nist.gov/drivers/documents/FISMA-final.pdf http://csrc.nist.gov/groups/SMA/fisma/index.html the importance of information security to the economic and national security interests of the United States. Title III of the E- Government Act, entitled the Federal Information Security Management Act of 2002 (FISMA), included duties and responsibilities for theComputer Security Division in Section 303 “National Institute ofStandards and Technology.” For further information see: NIST: ComputerSecurity Division - Computer Security Resource Center o OMB - The core mission of OMB is to serve the President of the United

States in implementing his vision across the Executive Branch. OMB is the largest component of the Executive Office of the President. It reports directly to the President and helps a wide range of executive departments and agencies across the Federal Government to implement the commitments and priorities of the President. As the implementation and enforcement arm of Presidential policy government-wide, OMB carries out its mission through five critical processes that are essential to the President’s ability to plan and implement his priorities across the Executive Branch. For further information see: White House: Office of Management and Budget

• Client Software Security - Any client software installed on FDA desktop, laptop with docking station, and scientific workstation computers for the purposes of accessing the data shall not use key-logging and/or network capturing functionality to transmit any data from the FDA system except for login information specific to the data and data (e.g. SQL queries or similar methods) accessing the Contractor’s application data sets.

• Information Security System Configuration Standards - The Federal Information Security Management Act (FISMA) ( section 3544(b)(2)(D)(iii) ) requires each Federal Government agency to develop minimally acceptable system configuration requirements and ensure compliance with the configuration requirements. Systems with non-default configurations have fewer vulnerabilities and are better able to thwart network attacks. The Office of Management and Budget (OMB) requires agencies to cite the percentage of systems that have been implemented using a standard system configuration policy in their annual FISMA report. To comply with OMB requirements, the FDA has created a standard set of system configuration guides for the core software utilized at the FDA. The standards must be applied to all systems, to include contractor hosted systems, that process, store or transmit FDA information.

http://csrc.nist.gov/index.html http://csrc.nist.gov/index.html http://www.whitehouse.gov/omb/ http://www.whitehouse.gov/omb/ http://csrc.nist.gov/groups/SMA/fisma/index.html http://csrc.nist.gov/groups/SMA/fisma/index.html http://csrc.nist.gov/drivers/documents/FISMA-final.pdf

3.7 Technical Environment

The proposed ELN solution shall be hosted at the FDA Scientific Data Center (SDC) and virtually available to scientists in remote locations. The FDA SDC is housed in College Park, in the Wiley building, at 5100 Paint Branch Parkway. It houses CFSAN’s central scientific computing systems and storage. Analysis is performed on a variety of HPC platforms, from stand-alone multiple processors workstations, Virtual Machine platforms and multiple node HPC platforms. As the business need grows the FDA may determine to migrate the ELN solution from the FDA SDC to the Ashburn Data Center (ADC).

The FDA will host the solution within its own environment. A web based solution will be deployed and accessed completely internal to the FDA. The FDA does not have a private cloud.

4. SCOPE

The scope of this contract encompasses all of the software and related services necessary to configure, integrate, implement, deploy and maintain ELN software that meets the FDA’s requirements.

5. REQUIREMENTS

5.1. Project Management

For the task orders released under this contract, the Contractor shall provide task order level project management to establish control, management, monitoring and notification mechanisms, ensuring that contracted tasks stay on track and important milestones and performance measures are met.

Representative Project Management activies include:

• Enterprise Performance Lifecycle (EPLC) management

• The overall progress of the project;

• Progress on planned deliverables;

• Accounting for deliverables;

• Action items for the following month;

• Manage Change Control Requests

• Configuration or customization issues

• Any current or anticipated problems with scheduled activities

• Identified risks

• Invoice issues or concerns

• Accomplishments

• Task Order Management Plan describing the technical approach, organizational resources, risk management, quality assurance and other management controls to be employed to meet the cost, performance and schedule requirements throughout task order execution.

5.1.1. Meetings

As tasked, the Contractor shall support regularly scheduled and impromptu formal and informal meetings such as weekly meetings, monthly meeting, informal review meetings, and formal presentations.

Depending on the type of meeting, the Contractor may be tasked with preparing materials for and participating in all required meetings to ensure that adequate information is disseminated relative to the project status, governance council, and project team reviews. The Contractor may also be tasked with a variety of activities for meeting planning including, but not limited to:

• Schedule meeting place and time

• Provide supporting information that may be required to include agendas

• Ensure all necessary materials are distributed far enough in advance to allow for review

• Prepare meeting room

• Give presentations

• Facilitate discussions

• Summarize discussions

• Draft notes and/or minutes of the preceding

• Facilitate kickoff meeting

5.1.2. Documentation

The Contractor shall provide documentation specific to the technical solution applied. Documentation may include software technical specifications, test scripts, configuration and installation guides to support a secure and authorized solution.

The Contractor shall work with the COR and IT PM to determine the appropriate EPLC documentation required for use of the COTs product on FDA’s network. The Contractor shall create agreed upon documentation and submit to the COR and IT PM. Typical documents include:

• Project Charter

• Business Requirements Document

• Systems Requirement Specification (SRS)

• Requirements Traceability Matrix

• Test Plan

• Training Plan

• User Manual

5.2. Technical Functionality and Features

The proposed ELN solution shall contain features to support scientific activities related to the experimental process; specimen collection, sample identification, protocol documentation, instrument data reports, molecular formulations, milestones, project updates, scientist collaborations, linking documents, upload images and files, Principal Investigator review and signature, audit trail documentation, test kit usage, bar code printing and scanning, and inventory control (ordering, location assignment, expiration flagging, decrementing reagent quantities).

The proposed ELN Software solution shall have the following functionality requirements:

ELN Mandatory Requirements – Out of the Box

Design Experiments and customize reports

Support for templates and forms

Define and route test requests Evaluate Results

Allow priority status to be assigned

Dashboards

Ability to collect/export data, charts, pictures from instruments and other sources

Small instrument connectivity (pH Meters, balances…etc)

Capability to add scanned images

Capability to add files and attachments

Ability to annotate comments Inventory Control: location and determination of reagent levels, expiration dates, & instruments

Supports unique sample IDs to be generated for samples and receive specimens

Ability to correct errors and document for quality control

Find functions; key word search for related experiments and documents

Supports PIV & digital signatures

Track progress

Ability to view all experiments under their PI

Allow full auditing of all activities

Record creation to comply with 21 CFR Part 11 Track Chain of Custody

Identify individual who entered or corrected data

Supports formulations/stoichiometry

Support for barcode; printing labels and scanning

Ability to bookmark experiments

Support for special characters

Track instrument; calibration history, maintenance schedules/events

Web Based- Capable of using IE and/or Firefox

Databasecompatible with technical environment

Meets Federal Information Security Management Act (FISMA) Requirements

Capability to create and print PDF records

Support query engines (searches)

Meets Federal Information Processing Standard (FIPS) 140-2 encryption protocol as needed

Device/Platform diagnostic Agnostic

ELN Non-Mandatory Requirements

Hand/stylus writing capability

Collaborate and securely share research information

Original source data availability for further modifications/update notebook

Drawing tools

Use on mobile devices

Staff communication using messages and links

Telework compatibility; work from home or travel in a secure environment

Meets future lab quality standards (ISO, cGLP) Access

Access to ELN controlled by Principal Investigator Single

Single Sign-On/Active Directory Integration Developer

Developer Application Program Interface provided

“Offline” Mode

Auto save feature

5.3. Software Licenses

The Contractor shall provide network ELN software licenses for FDA users. The FDA expects between 16 and 1,270 users of the ELN licenses.

5.4. Technical Support/Software Maintenace

As tasked, the Contractor shall provide technical support by phone, email, and online. Representative activities include:

• Provide expert advice and best practice recommendations on how to use the software

• Participate in Root cause identification

• Provide 1:1 support on specific problems

• Resolve user access problems: login issues and password resets

• Maintain a list of users

• Assign permission rights

• Troubleshoot issues

• Track volume of calls

• Maintain an issue log

• Track the time it takes to resolve issues

• Issue customer satisfaction surveys

5.5. Operations and Maintenance (Labor Category-based Pricing)

The contractor shall maintain the functionality, reliability, availability, performance, stability, sustainability, and security of the ELN and associated software. The contractor shall identify, track and analyze enhancement requests, bugs, and other issues as the Change Control Requests (CCRs). The contractor shall perform minor development activities to implement enhancement requests approved by the appropriate Change Control Board (CCB). The contractor shall maintain, support, and evolve code, scripts, designs, documentation, reports, and templates. The contractor shall analyze the impact of infrastructure, software upgrades, capacity, and other changes to the FDA IT environments. Deliverable products shall be validated and tested to ensure that they meet applicable / specified standards, policy, business requirements, and quality measures. O&M includes day-to-day operations, maintenance, and help desk support to ensure that the system performs its intended functions. Representative activities include:

• System Administration

• Maintenance of EPLC artifacts and other system documents;

• Performance monitoring and tuning;

• Release management;

• Implementation of CCRs approved by the CCB;

• Risk assessment and management;

• Maintenance of security accreditation;

• Data Quality assurance;

• Support of system hardware and infrastructure upgrades;

• Configuration Management;

• Help Desk Support and Issue Tracking;

• User Training

• Releases, patches and upgrades

• Testing

5.6. Training Support (Labor Category-based Pricing)

The Contractor shall plan, develop and deliver specific training services. Training programs (courses, material, etc.) will be evaluated, tracked, and measured for effectiveness in meeting business goals and objectives. Training documentation shall be delivered in accordance with the software maintenance specifications and not at additional cost. Training may be conducted remotely or on-site at FDA facilities. Representative activities under this task area may include:

• Performance of training assessments, evaluations and analyses;

• Developing a training plan;

• Developing training material;

• Providing on-demand training;

• Updating training material to stay in line with updates made to the data standardization efforts and tool/analytics; and,

• Developing and implementing web-based training

5.7. Development Modernization and Enhancement (Labor Category-based Pricing)

The contractor shall perform DME activities in support of the ELN software. DME activities are related to development of new systems or modernization and enhancements of existing components of the ELN software. DME includes but is not limited to development of additional features and functionality, improving performance, integration with other FDA systems, increasing storage capacity, and scalability initiatives. As DME modules are deployed into the production environment, they will “roll into” the O&M task order in effect at the time of production

Additional representative activities under this task area may include:

• Configure, customize and test plan ELN COTS product

• Prepare test plans to ensure proper testing of all modules of the ELN COTS product is performed in all non-production environments before the go-live date

• Conduct user acceptance testing (UAT) and training for the initial deployment to the FDA user community that will use the selected ELN COTS product

• Release management

6. DELIVERABLES

Deliverables shall be specified in the task orders released under this contract. Deliverable products shall be reviewed, validated and tested as appropriate to ensure that they meet applicable/specified standards, policy, business requirements and quality measures.

7. SECTION 508 COMPLIANCE

The Contractor shall support the Government in its compliance with Section 508 throughout the development and implementation of the work to be performed. Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d) requires that when Federal agencies develop, procure, maintain, or use electronic information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who do not have disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.

Applicable standards are:

SECTION SUBSECTION STANDARD

DESCRIPTION

1194.21 a, b, c, d, e, f, g, h, i, j, k ,l

Software applications and operating systems

1194.41 a, b, c Information, documentation, and support.

Additional Section 508 information can be found at the following websites:

http://www.section508.gov/index.cfm?FuseAction=Content&ID=12 http://www.access-board.gov/508.htm http://www.w3.org/WAI/Resources http://www.section508.gov/index.cfm?FuseAction=Content&ID=12 http://www.section508.gov/index.cfm?FuseAction=Content&ID=12 http://www.access-board.gov/508.htm http://www.access-board.gov/508.htm http://www.w3.org/WAI/Resources http://www.w3.org/WAI/Resources

1. BACKGROUND
2. OBJECTIVE
3. TECHNICAL STANDARDS AND GUIDELINES
3.1. FDA Tailored Enterprise Performance Life Cycle (EPLC)
3.2. FDA Master Approved Technologies List (MAT)
3.3. Authorization to Operate (ATO)
3.4. Contractor Compliance
3.5. Compatibility with FDA’s Environment
3.6 IT Security
3.7 Technical Environment
4. SCOPE
5. REQUIREMENTS
5.1. Project Management
5.1.1. Meetings
5.1.2. Documentation
5.2. Technical Functionality and Features
5.3. Software Licenses
5.4. Technical Support/Software Maintenace
5.5. Operations and Maintenance (Labor Category-based Pricing)
5.6. Training Support (Labor Category-based Pricing)
5.7. Development Modernization and Enhancement (Labor Category-based Pricing)
6. DELIVERABLES
7. SECTION 508 COMPLIANCE

File details come from the government source that posted it. Updated .