2.1.1 70B06C24R00000002 Attachment 2- Statement of Work.pdf

PDF 432 KB Posted

Attached to
U. S. Customs and Border Protection Office of Training & Development Enterprise Training & Resource Management System & Support Services Federal contract opportunity
Solicitation number
70B06C24R00000002
Issued by
Department of Homeland Security Customs and Border Protection

About this file

This statement of work outlines requirements for an enterprise training and resource management system and support services. U.S. Customs and Border Protection seeks a cloud-based, commercial off-the-shelf software-as-a-service solution to manage all aspects of training for over 74,000 government and contractor personnel. Required capabilities include personnel management, training administration, registration, testing, resource scheduling, housing management, reporting, and compliance tracking. The contractor must provide implementation, customizations, maintenance, help desk support, project management, data migration, and a transition plan. Key deliverables include security documentation, training materials, status reports, and a transition out plan. The place of performance is the contractor's location, with no anticipated travel. The period of performance is five years from award.

View the file

Other files for this federal contract opportunity

Other files attached to U. S. Customs and Border Protection Office of Training & Development Enterprise Training & Resource Management System & Support Services, newest first.
File Type Posted
2.5.1 70B06C24R00000002 A00001 SF30.pdf PDF
2.5.1 70B06C24R00000002 A00001 Question & Answer.xlsx XLSX spreadsheet
2.1.1 70B06C24R00000002.pdf PDF
2.1.1 70B06C24R00000002 Attachment 1- ETMS Pricing Worksheet.xlsx XLSX spreadsheet
2.1.1 70B06C24R00000002 Attachment 3- Initial Capabilities.xlsx XLSX spreadsheet
2.1.1 70B06C24R00000002 Attachment 4- Role Based Narratives.pdf PDF
2.1.1 70B06C24R00000002 Attachment 2- Statement of Work- Appendix A- Functional Requirements.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Request for Proposals (RFP) 70B06C24R00000002

U.S. Customs and Border Protection

Office of Training Development

Statement of Work for

ENTERPRISE TRAINING AND RESOURCE MANAGEMENT SYSTEM

August 08, 2023

Table of Contents

1. Background

2. Scope

3. Reference Documents and Authorities

4. Solution Configuration

4.1. Authentication, Authorization, and Security

4.2. Enterprise Architecture Compliance

5. Interchanges

5.1. Interchange for all Training Data

5.2. Interchange for the Creation and Maintenance of User Accounts

6. Transition

6.1. Transition-In Period

6.2. Transition-Out Period

6.3. Data Migration

7. Training

8. Subscription Services

8.1. Maintenance

8.1.1. Service-Level Objectives

8.1.2. System Availability

8.1.3. Scheduled Maintenance

8.1.4. New Releases / Updates

8.1.4.1. Delivery Instructions

8.1.4.2. Inspection and Acceptance

8.1.4.3. Custom Features

8.1.5. Data Retention Requirements

8.1.6. Points of Contact

8.2. Help Desk

8.2.1. Priority 1

8.2.2. Priority 2

8.3. Project Management

8.3.1. Meeting and Reporting Requirements

8.3.2. Monthly Status Report

9. Deliverables

9.1. General Deliverables

10. Government-Furnished Equipment and Information

11. Data Rights

12. Primary Point of Contact

13. Travel

14. Other Direct Costs (ODC)

15. Place of Performance

16. Contracting Officer Representative

1. Background

The mission of the U.S. Customs and Border Protection (CBP) is to protect the Nation’s borders while facilitating legitimate trade and travel. CBP’s Office of Training and Development (OTD) supports that mission by coordinating and providing training to CBP’s 74,000+ Government and

Contractor personnel who are located throughout the United States (U.S.), its territories, preclearance ports of entry, and international offices. CBP requires an enterprise, academy, and resource management system to record and track course completions; register students; generate transcripts; schedule instructors and resources; facilitate overall class management; support various assessment types and grading scales; and create, store, manage, and deliver online and blended content.

2. Scope

CBP is seeking one comprehensive system to deliver a proven, modular, interconnected software that supports training for CBP’s enterprise which includes law enforcement supporting academies, advanced training, and synchronous and asynchronous training. The cloud-based software solution shall be a Federal Risk and Authorization Management Program (FedRAMP) moderate authorized and 508 compliant, commercial off-the-shelf (COTS), software-as-a-service

(SaaS) system for the management of all aspects of learning, including instructor-led, online, and blended training. The system shall include compliance processes that span all aspects of law enforcement training (basic through advanced, field, and in-service) and facilitate and support professional development of the CBP workforce and support CBP’s mission readiness. The software solution shall consist of a single unified architecture that is developed, provided, and maintained by a sole Contractor and designed specifically for supporting law enforcement.

Records shall have audit tracing and shall be tracked in a legally defensible manner.

The management and accurate record keeping of training is crucial to CBP as a law enforcement agency for tracking qualifications and certifications to ensure officers, agents, specialists, and other professional personnel are in compliance and qualified to perform their duties. Law enforcement training includes numerous complex assessment types with varying custom grading scales including unique attributes for physical fitness, firearms, defensive tactics, and other complex skills-based assessments. The successful completion of courses, exams, and assessments are major components that are evaluated for CBP employees to graduate from the academies and have complex weighting factors that must be calculated in the system and automatically rolled into graduation scores across the entire curriculum model. It is critical to support the various assessment types and grading scales as well as maintain complete detailed hire-to-retire training records.

The software system shall support and automate critical training operations across the following key areas expanded on in Appendix A – System Functionality Deliverables:

• System administration and integration

• Personnel management

• Training

• Registration

• Testing

• Surveys

• Resource management and scheduling

• Housing management

• Reporting

• Compliance

The software system shall meet the following security requirements:

• FedRAMP authorized at a Moderate Impact level [as defined in Federal Information

Processing Standards (FIPS) 199];

• Criminal Justice Information Services (CJIS) compliant via an independent third-party review;

• National Institute of Standards and Technology (NIST) 800 53.v4 conformant;

• implemented and conformant with the best-practices security required by the Federal

Information Security Management Act (FISMA) legislation;

• all data stored in the continental United States; and

• client data hosted within a secure Government cloud environment.

3. Reference Documents and Authorities

Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security

Act, Public Law 107-296, 196 Stat.2135), Title 49, Code of Federal Regulations, Part 1520

Records on Individuals within the Content Management System (CMS) are subject to the

Privacy Act of 1974 (See FAR 52.224- 2). The most up-to-date version will apply.

Handbook Safeguarding Sensitive Personally Identifiable Information

DHS 4300a Sensitive Systems Handbook

Security Authorization Process Guide.pdf

CISA Cloud Security Technical Reference Architecture Version1.pdf

Mgmt Dir 140-01 Info Tech Security Program Revision 02.pdf

Federal Cloud Computing Strategy 02142011.pdf

Security Authorization of Information Systems in Cloud Computing Environments, December

NIST FIPS 200, Minimum Security Requirements for Federal Information and Information

Systems

NIST FIPS 201 ―Personal Identity Verification (PIV) of Federal Employees and Contractors

NIST SP 500-292, NIST Cloud Computing Reference Architecture

NIST SP 800-30, Risk Management Guide for Information Technology Systems rev-1 Final, dated Sept 2012

NIST SP 800-34 R1, Contingency Planning Guide for Federal Information Systems Final, dated

May 2010 https://www.dhs.gov/publication/handbook-safeguarding-sensitive-personally-identifiable-information https://www.dhs.gov/publication/dhs-4300a-sensitive-systems-handbook https://www.dhs.gov/sites/default/files/publications/Security%20Authorization%20Process%20Guide_1.pdf https://www.cisa.gov/sites/default/files/publications/CISA%20Cloud%20Security%20Technical%20Reference%20Architecture_Version%201.pdf https://www.dhs.gov/sites/default/files/publications/mgmt/information-and-technology-management/mgmt-dir_140-01-info-tech-security-program_revision-02.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/assets/egov_docs/vivek-kundra-federal-cloud-computing-strategy-02142011.pdf https://www.gao.gov/assets/gao-20-126.pdf https://www.gao.gov/assets/gao-20-126.pdf https://csrc.nist.gov/publications/detail/fips/200/final https://csrc.nist.gov/publications/detail/fips/200/final https://www.nist.gov/programs-projects/personal-identity-verification-piv-federal-employees-and-contractors https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-292.pdf https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

NIST SP800-37 R1, Guide for Applying the Risk Management Framework to Federal

Information Systems: A Security Life Cycle Approach, dated February 2010

NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems, dated

August 2002

NIST SP 800-53 R3, Recommended Security Controls for Federal Information Systems and

Organizations, dated August 2009

NIST SP 800-60 R1 Vol1 , Guide for Mapping Types of Information and Information Systems to

Security Categories Final, dated August 2008

NIST SP 800-63 R1, Electronic Authentication Guideline, dated December 2011

NIST SP 800-88, Guidelines for Media Sanitization Rev1 Final, dated September 2006

NIST SP 800-116, A Recommendation for the Use of PIV Credentials in Physical Access

Control Systems (PACS), dated November 2008

NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information

(PII) Final, dated April 2010

NIST SP 800-125, Guide to Security for Full Virtualization Technologies Final, dated January

NIST SP 800-137, Information Continuous Monitoring for Federal Information Systems and

Organizations, dated September 2011

NIST SP 800-144, Guidelines on Security and Privacy in Public Cloud Computing Final, dated

December 2011

NIST SP 800-145. A NIST Definition of Cloud Computing Final, dated September 2011

NIST SP 800-146, DRAFT Cloud Computing Synopsis and Recommendations, dated May 12, Office of Management and Budget (OMB) Circular A-130, Management of Federal Information

Resources

Public Law 107-347, E-Government Act of 2002, including Title III, Federal Information

Security Management Act (FISMA)

DHS Acquisition Instruction/Guidebook 102-01-001 Appendix B SELC Guide version 2.0

Homeland Security Presidential Directive 12

OMB M-06-16-Implementation of the Federal Civil Penalties Inflation Adjustment Act

OMB M-11-11 "Continued Implementation of Homeland Security Presidential Directive (HSPD)

12– Policy for a Common Identification Standard for Federal Employees and Contractors"

OMB M-10-15 ―FY 2010 Reporting Instructions for the Federal Information Security

Management Act and Agency Privacy Management

Handbook (HB) 1400-05D CBP Information Systems Security Policies and Procedures

Handbook Version 3.0, February 8, 2012

National Information Exchange Model (NIEM) Section 508 of the Rehabilitation Act

DHS Standard Operating Architecture (SOA)

36 CFR 1194.2 - Guidelines for Section 255 of the Communications Act.

36 CFR 1194.3 - General exceptions https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/archive/2014-06-05 https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/archive/2014-06-05 https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-47.pdf https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-47.pdf https://csrc.nist.gov/publications/detail/sp/800-53/rev-3/archive/2010-05-01 https://csrc.nist.gov/publications/detail/sp/800-53/rev-3/archive/2010-05-01 https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-63/1/archive/2011-12-12 https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-116/archive/2008-11-20 https://csrc.nist.gov/publications/detail/sp/800-116/archive/2008-11-20 https://csrc.nist.gov/publications/detail/sp/800-122/final https://csrc.nist.gov/publications/detail/sp/800-122/final https://csrc.nist.gov/publications/detail/sp/800-125/final https://csrc.nist.gov/publications/detail/sp/800-125/final https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-137.pdf https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-137.pdf https://csrc.nist.gov/publications/detail/sp/800-144/final https://csrc.nist.gov/publications/detail/sp/800-144/final https://csrc.nist.gov/publications/detail/sp/800-145/final https://csrc.nist.gov/csrc/media/publications/sp/800-146/final/documents/draft-nist-sp800-146.pdf https://csrc.nist.gov/csrc/media/publications/sp/800-146/final/documents/draft-nist-sp800-146.pdf https://www.cio.gov/policies-and-priorities/circular-a-130/ https://www.cio.gov/policies-and-priorities/circular-a-130/ https://www.congress.gov/107/plaws/publ347/PLAW-107publ347.pdf https://www.congress.gov/107/plaws/publ347/PLAW-107publ347.pdf https://www.dhs.gov/sites/default/files/publications/Systems%20Engineering%20Life%20Cycle.pdf https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2016/m-16-06.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2011/m11-10.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2011/m11-10.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2010/m10-15.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2010/m10-15.pdf https://www.cbp.gov/trade/rulings/directives-handbooks https://www.cbp.gov/trade/rulings/directives-handbooks https://www.niem.gov/disclaimer#:~:text=Section%20508%20requires%20that%20individuals,undue%20burden%20would%20be%20imposed https://www.dhs.gov/xlibrary/assets/itpa-dndo-jaccis.pdf https://www.ecfr.gov/current/title-36/section-1194.2 https://www.govinfo.gov/app/details/CFR-2011-title36-vol3/CFR-2011-title36-vol3-sec1194-3

36 CFR 1194.22 - Web-based Intranet and Internet Information and Applications

36 CFR 1194.31 - Functional Performance Criteria

36 CFR 1194.41 - Information, Documentation, and Support

Management Directive 4010.2: Section 508 Program Management Office & Electronic and

Information Technology Accessibility

Computer Security Act of 1987 (40 U.S.C. 1441 et seq.)

Government Information Security Reform Act of 2000

NIST Special Publication 800-207

4. Solution Configuration

The Contractor shall work with CBP OTD System Administrators and/or COR and provide all requested information to facilitate receiving the necessary security authorizations required by the

Department of Homeland Security (DHS) and CBP. The Contractor shall ensure the solution is ready to achieve a CBP-issued Authority to Operate (ATO). The solution shall support all CBP employees and Contractor personnel nationwide and in various international locations. All solution(s) shall meet Section 508 compliance requirements.

The software shall support the following key areas expanded on in Appendix A – System

Functionality Deliverables:

• System administration and integration

• Personnel management

• Training

• Registration

• Testing

• Surveys

• Resource management and scheduling

• Housing management

• Reporting

• Compliance

The Contractor shall provide the following services for the life of the contract:

• Software procurement, implementation, data migration, establishing data interchanges, and licensing;

• Modifications/customizations as ordered through Custom Development contract line-item (CLINs);

• Consulting support, including training and documentation required to support implementation and management of the system;

https://www.govinfo.gov/app/details/CFR-2013-title36-vol3/CFR-2013-title36-vol3-sec1194-22 https://www.govinfo.gov/app/details/CFR-2011-title36-vol3/CFR-2011-title36-vol3-sec1194-31 https://www.govinfo.gov/app/details/CFR-2012-title36-vol3/CFR-2012-title36-vol3-sec1194-41 https://www.dhs.gov/publication/management-directive-40102-section-508-program-management-office-electronic-and https://www.dhs.gov/publication/management-directive-40102-section-508-program-management-office-electronic-and https://uscode.house.gov/view.xhtml?req=granuleid:USC-2000-title40-section1441&num=0&edition=2000 https://www.epa.gov/sites/default/files/2015-12/documents/gisra.pdf https://csrc.nist.gov/pubs/sp/800/207/final

• Maintenance of user data and ability to import external files of various file formats within security controls such comma-separated values (.csv), Excel (.xls), portable document format (.pdf), etc.;

• Cloud hosting in a FedRamp High authorized environment;

• Software must be FedRamp authorized at a moderate level;

• Software must follow the full stack engineering, which is FedRamp authorized and listed on FedRamp.gov marketplace;

• Support 24/7/365 access to the system for CBP personnel, outside periods of scheduled maintenance;

• Help desk support for tiers 2 and 3 (in-depth and expert technical support);

• Systems analysis, programming, quality assurance testing, and training to implement enhancements to support evolving and emerging training requirements;

• Systems analysis, programming, quality assurance testing, and training to onboard additional academies, training facilities;

• Modifications/customizations of business-specific reports to support enhancements made for evolving and emerging training requirements;

• Assistance in completing privacy compliance documentation required by the

Government as necessary. Required Contractor support completing the requisite documents shall be limited to system-specific information and the handling of information within the system; and

• Single sign-on (SSO) access to all system components.

The Contractor Information System Security Officer (ISSO) shall coordinate all security activities with the Federal ISSO and/or System Owner. The Risk Management Division

Information System Security Manager (ISSM) will provide guidance to the Federal ISSO for management with the Contractor ISSO where needed.

All security compliance documents will be reviewed and approved by the CBP Chief

Information Security Officer (CISO) and accepted by the CBP Contracting Officer (CO), or CO designee, upon creation and after any subsequent changes, before they go into effect.

4.1. Authentication, Authorization, and Security

The software system shall meet the following security requirements:

• Fully FedRAMP authorized at a Moderate Impact level (as defined in FIPS 199).

• Software must follow the full stack engineering, which is FedRamp authorized and listed on FedRamp.gov.

• Criminal Justice Information Services (CJIS) compliant via an independent third-party review.

• NIST 800 53.v4 conformant.

• Implemented and conformant with the best-practices security required by the

FISMA legislation.

• All data shall be stored in the continental United States.

• Client data hosted within a secure Government Cloud environment.

• Use Active Directory (AD) based Single Sign On (SSO) services for authentication.

• Allow authorized persons to create usernames and passwords for users who do not have the ability to use SSO.

• Provide multiple permission levels for the different roles identified by CBP.

• Have internal capability to control access to content based on attributes provided by CBP.

• Be fully Public Key Infrastructure (PKI) enabled and transmit all data over Secure

Sockets Layer (SSL) encrypted channels.

• Incorporate e-signatures.

• Have the capability to restrict access to content based on the center or unit that is delivering the content, i.e., data partitioning.

• Afford a high level of password security features, for instance:

o Allows the administrator to require users to use strong passwords o Limits the use of old passwords o Defines parameters for strong passwords for users o Requires users to change the password on first login o Locks users out after a certain number of failed login attempts o Requires users to change passwords regularly (using notifications) o Sets limits on periods of inactivity o Only users can change their password o Encrypts stored passwords

• Allow Personal Identity Verification (PIV) Card access.

• Allow the creation of customized administrator roles (to be managed by CBP staff).

4.2. Enterprise Architecture Compliance

All solutions and services shall meet CBP Enterprise Architecture policies, standards, and procedures. Specifically, the Contractor shall comply with the following Homeland Security

Enterprise Architecture (HLS EA) requirements:

• All developed solutions and requirements shall be compliant with the HLS EA.

• All IT hardware or software shall be compliant with the HLS EA Technical

Reference Model (TRM) Standards and Products Profile.

• Description information for all data assets, information exchanges and data standards whether adopted or developed shall be submitted to the government for review and insertion into the DHS Data Reference Model and Enterprise

Architecture Information Repository.

• In compliance with Office of Management and Budget (OMB) mandates, all network hardware shall be IPv6 compatible without modification, upgrade, or replacement.

• All Information Technology assets being developed, procured, or acquired shall be IPv6 capable.

• Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

• Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components

(networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB

Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6)

Profile National Institute of Standards and Technology (NIST).

5. Interchanges

The Contractor shall create interchanges between the software system and the DHS Human

Capital (HC) Enterprise Information Environment (EIE) to transmit and retrieve training and user data to and from the software solution.

5.1. Interchange for all Training Data

The Contractor shall create an interchange to transmit training data from the software solution to the DHS HC EIE. CBP estimates 25- 30 data elements will need to be transmitted, specific elements to be provided upon award, or as identified during contract performance.

5.2. Interchange for the Creation and Maintenance of User Accounts

The Contractor shall create an interchange to create and maintain users, user accounts, and user attributes such as, but not limited to, user organization, job titles, and supervisors. The

Contractor shall not store or require Social Security Numbers (SSN) in their solution. The

Contractor shall receive a unique identifier for each user from DHS/CBP during the creation process.

Upon award, the Contractor shall provide CBP with the Application Programming Interface

(API) documentation for their solutions.

6. Transition

The Contractor shall develop transition plans that encompass both phasing in (start-up) and transitioning out at the time of contract completion.

6.1. Transition-In Period

The transition-in plan, not to exceed one (1) year, shall be based on the completed version of the one submitted with the Contractor’s successful proposal, as negotiated, and approved after delivery per the Deliverable Schedule, and shall provide the following:

• Plans and activities for training and orienting personnel who serve in key iterations or who shall perform tasks of a technical nature;

• The schedule and process for accounting for transferring custody of expendable supplies and parts that were acquired under the terms and conditions of the contract; and

• The schedule, formal inventory, and accounting records for transferring custody of Government-furnished capitalized and non-capitalized equipment.

6.2. Transition-Out Period

The Contractor shall develop and submit a comprehensive transition-out plan 60 days prior to completion of this contract. The Contractor’s transition-out plan shall not disrupt or adversely impact the day-to-day conduct of Government business and shall achieve a smooth and orderly transfer of responsibility to a successor. The transition-out plan shall fully describe how the Contractor shall approach the following issues:

• Employee notification

• Retention of personnel

• Turnover of work in progress, inventories, and Government property

• Removal of Contractor-owned property

• Data and information transfer

• Other actions required ensuring continuity of operations

• Security debriefings for incumbent personnel holding security clearances

The transition-out plan shall require an inventory by the outgoing Contractor and the

Government before a joint inventory can be conducted between the outgoing Contractor and the successor. The inventory shall include, if applicable:

• Reconciliation of all property accounts, requisitions, and work in progress

• Turn in of excess property

• Cleanup of the Contractor’s work areas

• Provision for training of the successor’s personnel on web-based tracking systems used in performance of this SOW, specialized equipment, utilities systems, and ongoing work that the successor would be required to complete.

The Government may create a punch list of deficiencies or unmet contractual requirements at or near the time of completion of the contract. The Government may employ the services of another Contractor or third party in the development of such punch list and upon completion provide the Contractor with a copy of work not completed, to include the monetary value the

Government has assigned for each item.

At any time up to 60 calendar days prior to the completion of this contract, a successor

Contractor or Government observation period may occur, at which time, personnel of the incoming workforce may observe operations and performance methods of the outgoing

Contractor. This shall allow for orderly turnover of facilities, equipment, and records and shall help to ensure continuity of service. The outgoing Contractor shall not defer any requirements for the purpose of avoiding responsibility or of transferring such responsibility to the succeeding Contractor. The outgoing Contractor shall fully cooperate with the successor Contractor and the Government so as to not interfere with their work or duties.

6.3. Data Migration

The Contractor shall migrate data from the existing training and resource management system to the solution. This data may include, but is not limited to employee/user data, training data, course content data, tests, surveys, content metadata, external training request, workflows, training activity, progress data, and instructional content and eLearning. Data migration include activities such as:

• Identifying and mapping data

• Identifying any necessary data conversions

• Validating the data mapping

• Validating data conversions

• Executing the migration and conversions

• Testing the migration and conversions

• Correcting data migration and conversion issues

• Validating the migrated and/or converted data

7. Training

The Contractor shall provide detailed instruction on how to configure and set up the solution prior to the official launch. The Contractor shall provide a proposed training schedule including the duration and number of sessions required to cover all training topics. Training should include the following areas:

• Creating user accounts

• Managing user roles and permissions

• Defining organizational hierarchies within the system

• Partitioning data

• Uploading and organizing different types of content

• Using system modules/functionalities

• Troubleshooting common issues

• Ensuring overall stability and performance of the system

The training should be delivered by experienced trainers who are knowledgeable about the solution. The training can be conducted through a combination of on-site sessions, virtual instructor-led training, or self-paced online modules. The training should include hands-on experience and opportunities for participants to ask questions and seek clarification.

The Contractor shall provide comprehensive training materials, including user manuals, reference guides, and any necessary documentation to supplement the training sessions in an editable format. These training materials should be made available to the system administrators both during and after the training for future reference.

Updated training materials/release notes shall be provided with each software release.

Contractor supplied training shall include present and upcoming new functionality release tutorials during regular scheduled meetings as needed.

8. Subscription Services

The Contractor shall provide the following subscription services for the solution:

8.1. Maintenance

The Contractor shall provide cloud maintenance services (if applicable), to include technical services to ensure that the system remains fully operational as outlined in the below service-level objectives. The Contractor shall interface with CBP’s Office of Information and

Technology (OIT) to support access to the system as necessary. Support services shall include system upgrades and reprogramming to address upgrades/refreshment.

8.1.1. Service-Level Objectives

The Contractor shall provide system support services meeting the service-level objectives. The resulting service-level agreements (SLA) at a minimum shall address and meet the Government’s service-level objectives requirements. SLAs include procurement, installation, initial training, system upgrades, site maintenance, software support, routine scheduling, monitoring system applications for abnormal operation, and help desk to support problem resolution.

8.1.2. System Availability

The service availability requirement shall have the system available 99.9% of the time, excluding scheduled maintenance.

8.1.3. Scheduled Maintenance

Scheduled maintenance includes any maintenance of the system and network elements to which CBP wide area network (WAN) is connected (a) of which the Government is notified 48 hours in advance, and (b) that is performed during the agreed upon maintenance schedule determined by CBP. Notice of scheduled maintenance shall be provided to the CBP System Administrators by the Contractor via email.

8.1.4. New Releases / Updates

The Contractor shall notify CBP of upcoming changes that may impact how users interact with the solution and provide a schedule of upcoming releases and updates. The system shall be updated to the new releases offered to industry on a periodic basis (minimum 4 times a year) with the ability for the Government to determine what and when updates will be released. The Contractor shall provide CBP with time to test and validate the release/update.

The Contractor shall provide updated training materials and documentation in editable formats for any new releases and updates within ten (10) business days of deployment.

8.1.4.1. Delivery Instructions

The Contractor shall maintain an environment that mirrors CBP’s production environment for the purpose of user acceptance testing (UAT) and training. The

Contractor shall emulate the configurations that exist in the CBP production environment to include the current customizations. When code is ready to be submitted to CBP, CBP shall access this environment and conduct acceptance testing to validate the defined requirements and system design have been met before the code can be implemented at CBP.

All requirements and design documentation shall have a status of final before coding begins. Screen mockups are required when requested for functions. Operation manuals/release notes shall be provided in Word or PDF documents that can include images of screen shots or architectural models as needed. Project schedules shall be maintained in Microsoft Excel or Microsoft Word and submitted to the COR within five (5) business days of an update or modification.

8.1.4.2. Inspection and Acceptance

CBP staff will conduct an acceptance test on the Contractor’s site acceptance testing

(SAT) environment before enhancements/modifications are implemented and accepted by CBP.

Acceptance Criteria: The general quality measures, as set forth below, shall be applied to each deliverable received from the Contractor under this contract.

Accuracy: The work performed shall meet CBP requirements and the COR’s prior written approval for providing software support.

Documentation of work shall be accurate in presentation, technical content, and adherence to accepted elements of style.

Clarity: Work products shall be clear and concise; engineering terms shall be used, as appropriate. All diagrams shall be easy to understand and relevant to the supporting narrative.

File Editing: All text and diagrammatic files shall be editable by the Government.

Timeliness: Work products shall be submitted on or before due dates specified in project schedules.

UAT: The Contractor shall perform the system programming and development testing on their premises. The Contractor shall support UAT conducted by CBP personnel but shall not be required to be at a CBP location. UAT shall be conducted by OTD personnel and shall be performed in the SAT environment.

The COR will notify the Contractor of acceptance or rejection of the deliverable within ten (10) business days of the Government’s receipt of the deliverable. If rejected, the Contractor shall have to put forth a plan to mediate within ten (10) business days.

8.1.4.3. Custom Features

The Contractor shall, if upon government’s request, perform and document system design for submission to CBP System Administrators for approval, programming, testing, and implementation. Requested Design documentation may include screen mockups for screen changes or implementation of new screens and report mockups for new or enhanced reports. Design documentation shall also include the system path to access new or changed functions.

The Contractor is responsible for code development and quality assurance testing of the software before being delivered and implemented on the system. The Contractor shall maintain regular communications with the CBP System Administrators to ensure that all requirements are understood, documented, and delivered as documented.

System design and development (or CBP customizations) shall be implemented in small iterative deliverables to ensure the system grows and evolves with future trends and technologies. All custom development shall be submitted to the CBP System

Administrators with screen mockups and cost estimates for review and approval prior to beginning development. All proposals and invoices for custom development shall define how the price was derived in order to be accepted.

8.1.5. Data Retention Requirements

Student information shall be retained on the Contractor’s cloud for the term of the contract, as to remain retrievable throughout the active career of CBP personnel. Student records and training schedules shall be retained to validate the type, duration, and extent of training provided. This information provides a mechanism to validate training and experience for purposes of qualifying for jobs, obtaining training credit with colleges and universities, and establishing a student’s knowledge base for a given situation in the work environment. At the time of decommission of the Contractor’s system, the records shall be transferred to the replacement system or back to CBP, as directed by the Government at the time of decommissioning.

8.1.6. Points of Contact

The Contractor shall provide, as part of the SLA, points of contact (POCs) to include primary and alternate support. POC information shall include name, phone number, and email address.

8.2. Help Desk

The Contractor shall provide U.S. based help desk (telephonic) and on-call maintenance support. The Contractor’s help desk support shall coordinate with the CBP help desk. The

Contractor shall provide the CBP help desk with a phone number of the Contractor help desk support. The Contractor’s help desk support shall support tiers 2 and 3 for all issues that are not inherently Governmental: 8 a.m. to 6 p.m. Monday to Friday Eastern Time (ET) for noncritical incidents (priority 2). In the event of a system failure or critical incident, the

Contractor shall notify the CBP System Administrators within 15 minutes of acknowledgement and begin work to resolve the failure or incident. Critical incidents are categorized as follows: (1) entire site is down, (2) users cannot login, or (3) system data is not accessible.

The Contractor shall provide tiers 2 and 3 support, to include resolving functional, technical, and policy-related issues that CBP’s tier 1 help desk cannot support. In addition, tiers 2 and 3 shall utilize an issue-tracking portal to manage and distribute help ticket requests. The portal shall provide an immediate response to the users, and all email thread and actions shall be tracked in a reportable manner. Based on ticket volume, resources allocated to the tier 2 help desk may also be positioned to support other functional areas of the project.

Helpdesk deliverables:

• Maintain a tiers 2 and 3 ticketing system and record all issues in the ticketing system.

• Meet the Government’s expectations for acceptable SLA for working and closing tiers 2 and 3 issued tickets.

• Provide monthly reporting metrics on tiers 2 and 3 tickets.

8.2.1. Priority 1

Operational System Down: Priority 1 occurs when the system is failing in an operational environment resulting in a complete loss of capability. This type of problem severely impacts CBP objectives and requires timely response and corrective action.

Acknowledgement is required 15 minutes after notification. Initial response is required

30 minutes following notification. Corrective action is required to begin on the same day or no later than one (1) day after issued diagnosis is complete.

8.2.2. Priority 2

System is Not Functioning as Specified: Priority 2 occurs when a function of the system is not behaving as specified. Operational work can continue but the system is not performing to specification (degraded) and corrective action is required. Examples are data latency or intermittent operation. Acknowledgement is required one (1) hour after notification. Initial response is required three (3) hours following notification. Corrective action is required to begin on the same day or no later than one (1) day after issued diagnosis is complete.

8.3. Project Management

Provide project management support required to carry out the tasks and comply with this

Statement of Work (SOW). Contractor progress against tasks shall be assessed in informal status daily discussions (where discussions could include phone conversations and/or email exchange) between the Contractor and the Contracting Officer’s Representative (COR). The

Contractor shall support the weekly status meetings to be chaired by the project manager.

Additionally, the Contractor shall prepare and submit monthly status reports to the COR. As a minimum, the report shall contain the following:

• activity summary;

• major milestones;

• open action items;

• project risks and responses;

• modification progress to schedule performance;

• major activities planned for the succeeding month; and

• status of configuration changes including due dates for mockups and implementation, as well as an updated accounting record of configuration changes.

Tasks that are late shall be listed on monthly status reports with an explanation of why they are late, and a discussion of remediation actions planned to alleviate the schedule delay. This report shall be prepared in a narrative format suitable for reproduction. Electronic submittal may be made via email to the COR and the Contracting Officer. The monthly status reports shall be reviewed during the monthly meeting with the Contractor. These status reports shall include unforeseen issues that impact the:

• critical path;

• risks;

• known issues; and/or

• the completion date of the project, which shall also be reported to the COR via email within four (4) business hours of their discovery.

8.3.1. Meeting and Reporting Requirements

Weekly status meetings shall be conducted via teleconference to discuss the following topics:

• Issues

• Anomalies

• Upgrades, enhancements, and modifications

• Projects (provide status, updates to schedules, milestones)

The Contractor shall submit meeting minutes and all action items to the COR within five

(5) business days of the end of the meeting via email.

At a minimum, the Contractor shall provide at least one (1) project manager and one (1) systems engineer to provide administrative and system updates for all weekly meetings.

The Government will provide at least one (1) systems administrator and the COR.

Additional personnel may be provided on either side based on need.

8.3.2. Monthly Status Report

The Contractor shall submit a monthly status report to the COR by the tenth (10) business day of each month via email. The monthly status report shall address functional accomplishments, issues, unresolved problems, and a plan of action for resolving any problems identified by the Government.

This report shall contain the following information:

• cover letter with the Contractor’s name and address, the contract number, the date of the report, and the period covered by the report;

• significant changes to the Contractor’s organization or method of operation;

• description of significant events occurring during the reporting period;

• status of pending deliverables with expected delivery dates;

• problem areas affecting technical, schedule, or cost elements of the contract, including background, impact, and recommendations· for resolution;

• results related to previously identified problem areas with conclusions and recommendations;

• trip reports and significant results;

• Name and telephone number of the preparer of the report;

• Planned accomplishments for the next reporting period; and

• For each task area, the Contractor shall provide the status and expected timeframe for completing the associated tasks.

9. Deliverables

All written contract deliverables require COR approval and formal acceptance by the COR. The

Government will have up to ten (10) business days after receipt of a deliverable to accept or reject any product. If the COR rejects a deliverable, the Contractor will be provided specific written comments detailing the basis for the rejection and recommended corrective action. The

Contractor shall have up to ten (10) calendar days to address each specific written comment by either incorporating the requested Government change or providing an explanation of why the

Government change is not being incorporated. The Government will have an additional five (5) calendar days to review and provide a final decision regarding acceptance or rejection of the deliverable.

9.1. General Deliverables

Deliverables Deadline

Kick-Off Meeting Day of award

Data retention plan 10 Days after award

IT security plan 10 Days after award

Project management plan 14 Days after award

Project schedule - In the ITAR Clauses Appendix 10 Days after award

Any issues identified by the Contractor that affect the critical path shall be communicated to the COR in writing.

Within 4 hours of discovery

Proof IT security accreditation to include:

• Final IT security plan

• Risk assessment

• Security test and evaluation

• Disaster recovery plan

• Continuity of operations (COOP) plan

20 Days after award

Continuous monitoring data report (Security Authorization

Process Guide.pdf)

Monthly by the 10th

Monthly status reports Monthly by the 10th

Program status meetings Weekly

Updated project schedule Weekly

Single sign-on 30 days after award

Financial reports (invoices, incurred costs and funds status)

Monthly by the 10th

Presentations, demonstrations, mockups, project support materials

As required

Release notes With each software release

Training materials Within 20 days of award, and as required

Perform tasks and provide documentation to support the

Security Authorization process

3 months after award and as required

Complete any customizations requested by CBP Within agreed upon timeframe as established in the task order

Help desk Implementation 14 days prior to the https://www.dhs.gov/sites/default/files/publications/Security%20Authorization%20Process%20Guide_1.pdf https://www.dhs.gov/sites/default/files/publications/Security%20Authorization%20Process%20Guide_1.pdf enterprise rollout

Transition-in plan 14 days after ward

Transition-out plan 60 days prior to the end of the contract

Extract Data 90 days before shutdown

Sanitize equipment and media 60 days before shutdown

Attest and evidence of sanitization 30 days before shutdown

10. Government-Furnished Equipment and Information

The Government anticipates a limited need for CBP-issued laptops in order to assist with integration efforts. The Government will provide information for SSO, Integration with CBP systems, and data migration as required.

Contractor must take all reasonable efforts to safely, securely, and properly handle and maintain all Government-furnished property provided to the Contractor for use under this contract.

Contractor must track and maintain all Government furnished property and only use

Government-furnished property for use in the performance of this contract. Contractor is responsible for any loss or damage to Government-furnished property.

11. Data Rights

Notwithstanding any other clause concerning data, all data produced, recorded, transferred, or manipulated under this contract, including all source codes and all trainings, shall remain the exclusive property of the Government. The Government shall retain exclusive right and domain over any by-product, document, or data produced under this contract, or any other use of the data produced under this contract. These documents and data shall be confidential and shall not be disclosed to any third party without prior written permission of CBP.

12. Primary Point of Contact

The Contractor shall designate a Primary Point of Contact (POC) for the duration of this contract. The Primary POC shall serve as the main liaison between the Contractor and the

Government and shall be responsible for coordinating all communication and interactions related to the implementation and maintenance of the solution.

The Primary POC is required to possess a comprehensive understanding of the solution and its functionalities, as well as the technical and operational aspects of the system. This knowledge is crucial to ensure effective communication, troubleshooting, and timely resolution of any issues that may arise during the course of the contract.

The Contractor shall provide the Government with the contact information of the designated

Primary POC, including name, title, email address, and direct phone number. The Primary POC shall be readily accessible and responsive during regular business hours.

13. Travel

No contractor travel outside of the local commuting area is expected for the resulting contract. If the Contractor is required to travel outside 50 miles from its location, then the contractor shall invoice against a Not to Exceed (NTE) travel budget contract line item (CLIN) included in the award.

The Contractor will be reimbursed for Government pre-approved travel at the rates provided in the Federal Travel Regulations (FTR- www.gsa.gov/ftr ) for long distance travel only. Travel will only be reimbursable to the extent authorized in writing (email) in advance by the COR. The

COR shall receive travel requests at least 3 business days in advance of the travel start date

14. Other Direct Costs (ODC)

No ODCs are anticipated under this contract.

15. Place of Performance

The work for this contract will be performed at the Contractor’s location.

16. Contracting Officer Representative

The COR for this effort is:

Ms. Jennifer Poole

(P): 304.535.5119

(E): Jennifer.A.Poole@cbp.dhs.gov.

mailto:%20Jennifer.A.Poole@cbp.dhs.gov

File details come from the government source that posted it. Updated .