15G1AC25N00000004_SOW_iManage Upgrade_Draft.pdf

PDF 88 KB Posted

Attached to
Upgrade to iManage Development and Production System Federal contract opportunity
Solicitation number
15G1AC25N00000004
Issued by
Department of Justice Office of the Inspector General

About this file

This Statement of Work (SOW) details an upgrade to the iManage Development & Production System for the Department of Justice Office of the Inspector General (DOJ OIG). The project requires addressing critical security vulnerabilities in the current system, including updating Apache HTTP Server from version 2.4.39 to 2.4.60, upgrading Apache Log4j from version 1.x to 2.x, and updating Python from version 1.2 to version 3.x. The upgrade is necessary to prevent potential unauthorized access and protect sensitive investigative documents stored across DOJ component agencies.

The project will be completed in three phases: Phase I involves reviewing the existing environment and documenting customizations, Phase II includes installing and configuring multiple software components on development and production servers, and Phase III focuses on user acceptance testing and technical support. The anticipated completion time is 3-6 months, with the contractor required to perform work remotely and subject to intermittent physical inspections. Strict personnel requirements include a favorably adjudicated Tier 4 High-risk Public Trust background investigation, U.S. citizenship, and adherence to specific security protocols for handling sensitive information.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work

Upgrade to iManage Development & Production System w/ Rollout Support

I. Background

a. The U.S. Department of Justice (DOJ), Office of the Inspector General

(OIG) is a statutorily created independent entity whose mission is to promote integrity, efficiency, and accountability within the Department of Justice. The Investigations Division’s (INV) mission is to detect and prevent fraud, waste, abuse, and misconduct; and to promote the rule of law through objective, independent oversight of the Department of

Justice. INV’s strategic objectives include maximizing the efficiency and economy of operations, promoting and maintaining data security, and ensuring the case management systems are updated, resilient, and secure.

II. Scope of Work

a. INV requires an upgrade to iManage (current version 10.2.5.37), the

Server (current version 10.3.0.287), and IDOL Indexer. iManage is a mission critical platform that serves as the official repository of case documents for all INV’s investigations. As such, iManage stores a large amount of sensitive information pertaining to criminal, civil, and administrative investigations affecting all of DOJ’s component agencies. iManage integrates with Law Manager, a database management system that supports INV’s case management system. A previous scan of iManage found a serious issue with the Apache HTTP

Server because it could be actively exploited by attackers. These security flaws allow attackers to find hidden or restricted web addresses (URLs) on servers using Apache. This could lead to them running harmful code or seeing the server's source code. The server is also running an outdated and unsupported version of Python, a general-purpose programming language for developers, which makes it even more vulnerable to unauthorized access. Hackers could use these flaws to access hidden URLs, run unauthorized code, or view sensitive files, which would undermine INV’s ability to fulfill its strategic objective of promoting data security.

III. Description of Requirement

a. Updates

i. The contractor shall upgrade the OIG’s current version of iManage to address the Apache vulnerability. The contractor shall also perform upgrades to the following web server daemons and applets. Once the iManage upgrade is complete, the contractor shall scan the iManage servers again to make sure all issues have been resolved.

1. Update Apache HTTP Server from version 2.4.39 to 2.4.60 or newer.

2. Update Apache Log4j from version 1.x to version 2.x.

3. Update Python from version 1.2 (unsupported) to version

3.x.

b. Project Workflow

Phase I

i. Review existing Environment including 3rd party one-directional integration with Law Manager.

ii. Review existing desktop customizations.

iii. Review existing Server customizations.

iv. Document Server and desktop customizations.

v. Provide Server Specs for Production and Development.

Phase II

The following items are needed on both the dev and production servers to upgrade iManage.

vi. Install and configure Work 10 DMS software on (1) server.

vii. Install and configure Work Web software on (1) DMS server.

viii. Install and configure RAVN Indexer software (1) set of servers.

ix. Install and configure Preview server software (1) Prod.

x. Install and configure Comm server (1) Dev.

xi. Upgrade databases (1) to the latest version.

xii. Configure for SSO.

xiii. The workspace Generation process is manual and will not be updated.

Phase III

xiv. Provide Test Scripts for User Acceptance Testing (UAT).

xv. Assisting with UAT activities.

xvi. Assisting the OIG with remediating technical issues.

The contractor shall complete the following activities:

xvii. Build servers for new development and install Windows Server and SQL Server software.

xviii. Schedule UAT training and testing resources.

xix. Conduct UAT activities.

xx. Remediate software and connectivity issues.

IV. Production cutovers require a weekend outage. If outages exceed Monday, 5:00am EST, the contractor shall notify the primary Point of Contact and remediate issues immediately. The OIG will monitor RAVN Indexer crawls and contractor will support as needed and open tickets with iManage technical support if necessary.

V. Deliverable and Deliverable Schedule

a. Database Updates

Contractor Deliverables

i. Assist with Database copy from current production to new production.

ii. Run the database upgrade process.

iii. Kickoff the indexer reconciliation process.

iv. Assist with their pre-release smoke testing.

v. Attend 30-minute weekly status meetings.

OIG Responsibilities

vi. Schedule the outage for the weekend cutover

vii. Communicate with end-users and stakeholders re: iManage outage details

viii. Copy current production database to new production

ix. Conduct smoke testing

x. Update Domain Name System (DNS) to point to new production

xi. Be the primary support provider for the iManage end-users

b. User Acceptance Testing (UAT) – Development and Production

Contractor Deliverables

i. Provide Test Scripts for UAT.

ii. Assist with UAT activities.

iii. Assist with remediating issues.

iv. Attending 30-minute weekly status meetings.

v. Remediate issues.

OIG Responsibilities

vi. Schedule UAT training and testing resources.

vii. Conduct UAT activities.

viii. Open tickets with iManage technical support.

Production Cutover Support

ix. Production cutover requires a weekend outage. The OIG will provide designated outage window to the contractor.

Post-Upgrade Technical Support

x. Contractor will provide up to 8 hours of post-upgrade technical support, as needed.

VI. Personnel Requirements

a. All contractors shall have a favorably adjudicated Tier 4 High-risk

Public Trust background investigation or have the ability to obtain a favorably adjudicated Tier 4 High-risk Public Trust background investigation.

b. Each employee of the Contractor working under this contract is subject to the security clearance requirements. Before assigning an employee to the contract, the Contracting Officer Representative (COR) will provide the necessary forms for completion.

c. The Contractor is responsible for screening all prospective employees for suitability for work on this contract. The OIG will provide national security adjudicative guidelines for determining eligibility for access to classified information or eligibility to hold a sensitive position upon contract award.

d. The Contractor shall maintain a database of all personnel that have been subject to the security clearance requirements of this contract. At a minimum, the database shall include the full name, position, location, date forms submitted to COR, date clearance granted/denied, and clearance type. All information in the database shall be made available to the COR or CO upon request.

e. The Contractor shall ensure that the following procedures are followed all materials are secured:

i. During working hours, the contractor must take care to prevent viewing of materials by other persons by covering or turning face down when necessary. The need-to-know principle shall be adhered to at all times.

ii. During non-working hours, DOJ materials shall be secured as soon as practicable after use. Government contract-related materials shall not be removed from the Contractor site without permission from the program office and DOJ OIG Office of

Security Programs (OSP).

iii. During non-working hours, entrances and exits to areas where

Government contract-related materials are kept shall be securely locked.

iv. Government materials must be transmitted by approved electronic means or contract personnel or approved electronic means or an authorized government agency courier service.

VII. Period of Performance

The anticipated time of completion is 3-6 months for the identified deliverables.

VIII. Place of Performance

a. The Contractor will perform the work remotely. The Contractor’s remote location will be subject to intermittent physical inspections

(also known as site visits) by designated OIG personnel. The OIG will not pay overtime for work performed on weekends, holidays, extended hours, or during the Government shutdown period.

IX. Government Furnished Property and Space

a. The Contractor shall perform all work on DOJ-issued laptops. Government issued

Personal Identity Verification (PIV) cards will be required to access the DOJ-issued laptops. Laptop users will be required to sign the OIG’s Hand receipt Personal property form and Rules of Behavior form at the time of laptop assignment.

b. The Contractor is responsible for proper care and safeguarding of all Government furnished property (GFP), including inventorying, tracking, etc. The Contractor shall reimburse the Government for any Government furnished property lost or stolen while in the Contractor's safekeeping. If any Government furnished property is lost or stolen, the Contractor shall notify the CO and COR as soon as possible. This notification shall be provided no later than one hour after such discovery was made by the Contractor. All

GFP shall be returned within 10 business days of contract expiration or upon request.

c. All work shall be saved to the OIG’s network drives. The OIG automatically backs up all saved files to the OIG network on a daily basis. Usage of external storage media is not permitted.

X. Days/Hours of Performance

a. The OIG business hours are Monday through Friday, 9:00am EST-

5:00pm. If any additional work outside of the business hours is needed, the contractor will coordinate with the POC. The OIG will not pay overtime for work performed on weekends, holidays, extended hours, or during the Government shutdown period.

b. The Contractor will not be required to work in the event of a government shutdown.

XI. SPECIAL CONTRACT REQUIREMENTS

Information Technology

a. Information Technology Equipment refers to computers, steno machines, transcription devices, printers, scanners, and all other technological devices used to electronically process information for the OIG.

b. Any Information Technology equipment used to process OIG information may be subject to certification/accreditation and/or disk-based sanitization to protect information.

c. Access to information technology equipment must be controlled and restricted to personnel authorized the equipment must be turned off, or otherwise disabled, when not in use.

XII. Notice to Proceed

Within ten (10) calendar days after the contract award, the Government will furnish the Contractor with personnel security application forms. The

Contractor shall complete and return to the COR all personnel security application forms within seven (7) calendar days after receipt. After a sufficient number of Contractor Personnel are cleared by the Government, a notice to proceed will be issued by the Contracting Officer specifying a performance start date.

XIII. Contractor Employee Residency Requirement

All contractor employees assigned to this contract and business within the

United States shall meet the DOJ Residency Requirement. The Residency

Requirement states that, for three of the five years immediately prior to applying for a position, the individual must have: 1) resided in the United

States; 2) worked for the United States overseas in a Federal or military capacity; or 3) be a dependent of a Federal or military employee serving overseas.

XIV. Prohibition on Use of Non-US Citizens

The Department of Justice does not permit the use of non-U.S. citizens in the performance of this contract or commitment for any position that involves access to or development of any DOJ IT system. By signing the contract or commitment document or commencing work there under, the contractor agrees to this restriction. In those instances where other non-IT requirements contained in the contract or commitment can be met by using non-U.S. citizens, those requirements shall be clearly described.

XV. Key Personnel

The personnel are considered to be essential to the work being performed hereunder. Prior to replacing any of the specified individuals, the Contractor shall immediately notify both the Contracting Officer and COR reasonably in advance and shall submit written justification (including proposed substitutions) in sufficient detail to permit evaluation of the impact on the program. No replacement of personnel shall be made by the Contractor without the written consent of the Contracting Officer.

XVI. Information Resellers or Data Brokers

Under this contract, the Department obtains personally identifiable information about individuals from the contractor. The contractor hereby certifies that it has a security policy in place which contains procedures to promptly notify any individual whose personally identifiable information (as defined by OMB) was, or is reasonably believed to have been, lost or acquired by an unauthorized person while the data is under the control of the contractor. In any case in which the data that was lost or improperly acquired reflects or consists of data that originated with the Department or reflects sensitive law enforcement or national security interest in the data, the contractor shall notify the Department contracting officer so that the

Department may determine whether notification would impede a law enforcement investigation or jeopardize national security. In such cases, the contractor shall not notify the individuals until it receives further instruction from the Department.

File details come from the government source that posted it. Updated .