2.1.1 70B06C24R00000002 Attachment 2- Statement of Work DRAFT.pdf

PDF 1 MB Posted

Attached to
U. S. Customs and Border Protection Office of Training & Development Enterprise Training & Resource Management System & Support Services Federal contract opportunity
Solicitation number
201339916
Issued by
Department of Homeland Security Customs and Border Protection

About this file

This statement of work outlines requirements for an enterprise training and resource management system and support services for the U.S. Customs and Border Protection Office of Training and Development. The cloud-based software as a service solution must support all aspects of training management including personnel, courses, registration, testing, surveys, resource scheduling, housing, reporting, and compliance. Key requirements include full FedRAMP Moderate authorization, NIST 800-53 compliance, data hosting within the U.S., single sign-on access, and customizations. The contractor must provide data migration, maintenance and support services, help desk support, project management, training, and security documentation. Deliverables include implementation plans, security documentation, customizations, status reports, release notes and training materials. The place of performance is the contractor's location. The period of performance is one base year with four option years and the contract type is firm-fixed price.

View the file

Other files for this federal contract opportunity

Other files attached to U. S. Customs and Border Protection Office of Training & Development Enterprise Training & Resource Management System & Support Services, newest first.
File Type Posted
2.1.1 70B06C24R00000002 DRAFT.pdf PDF
2.1.1 70B06C24R00000002 Attachment 1- ETMS Pricing Worksheet DRAFT.xlsx XLSX spreadsheet
2.1.1 70B06C24R00000002 Attachment 5- Role Based Narratives DRAFT.pdf PDF
2.1.1 70B06C24R00000002 Attachment 4- Interview Questions DRAFT.pdf PDF
2.1.1 70B06C24R00000002 Attachment 2- Statement of Work- Appendix A- Functional Requirements DRAFT.pdf PDF
2.1.1 70B06C24R00000002 Attachment 3- Solution Capability Survey DRAFT.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Customs and Border Protection

Office of Training Development

Statement of Work for

ENTERPRISE TRAINING AND RESOURCE MANAGEMENT SYSTEM

June 26, 2023 DRAFT

Table of Contents

1. Background

2. Scope

3. Reference Documents and Authorities

4. Solution Configuration

4.1. Authentication, Authorization, and Security

4.2. Enterprise Architecture Compliance

5. Interchanges

5.1. Interchange for all Training Data

5.2. Interchange for the Creation and Maintenance of User Accounts

6. Transition/Go-Live

6.1. Transition-In Period

6.2. Data Migration

6.3. Transition-Out Period

7. Training

8. Subscription Services

8.1. Maintenance

8.1.1. Service-Level Objectives

8.1.2. System Availability

8.1.3. Scheduled Maintenance

8.1.4. New Releases / Updates

8.1.4.1. Delivery Instructions

8.1.4.2. Inspection and Acceptance

8.1.4.3. Custom Features

8.1.5. Data Retention Requirements

8.1.6. Points of Contact

8.2. Help Desk

8.2.1. Priority 1

8.2.2. Priority 2

8.2.3. Mean Time to Respond

8.2.4. Mean Time to Repair

8.3. Project Management .......................................................................................................... 18 DRAFT

8.3.1. Meeting and Reporting Requirements

8.3.2. Monthly Status Report

8.4. Key Personnel

9. Deliverables

9.1. General Deliverables

10. Government-Furnished Equipment and Information

11. Travel

12. Other Direct Costs (ODC)

13. Place of Performance

14. Contracting Officer Representative

DRAFT

1. Background

The mission of the U.S. Customs and Border Protection (CBP) is to protect the Nation’s borders while facilitating legitimate trade and travel. CBP’s Office of Training and Development (OTD) supports that mission by coordinating and providing training to CBP’s 74,000+ Government and

Contractor personnel who are located throughout the United States (U.S.), it’s territories, preclearance ports of entry, and international offices. CBP requires an enterprise, academy, and resource management system to record and track course completions; register students; generate transcripts; schedule instructors and resources; facilitate overall class management; support various assessment types and grading scales; and create, store, manage, and deliver online and blended content.

2. Scope

CBP is seeking one comprehensive system to deliver a proven, modular, interconnected software that supports training for CBP’s enterprise which includes law enforcement supporting academies, advanced training, and synchronous and asynchronous training. The cloud-based software solution shall be a Federal Risk and Authorization Management Program (FedRAMP) moderate authorized and 508 compliant, commercial off-the-shelf (COTS), software-as-a-service

(SaaS) system for the management of all aspects of learning, including instructor-led, online, and blended training. The system shall include compliance processes that span all aspects of law enforcement training (basic through advanced, field, and in-service) and facilitate and support professional development of the CBP workforce and support CBP’s mission readiness. The software solution shall consist of a single unified architecture that is developed, provided, and maintained by a sole Contractor and designed specifically for supporting law enforcement.

Records shall have audit tracing and shall be tracked in a legally defensible manner.

The management and accurate record keeping of training is crucial to CBP as a law enforcement agency for tracking qualifications and certifications to ensure officers, agents, specialists, and other professional personnel are in compliance and qualified to perform their duties. Law enforcement training includes numerous complex assessment types with varying custom grading scales including unique attributes for physical fitness, firearms, defensive tactics, and other complex skills-based assessments. The successful completion of courses, exams, and assessments are major components that are evaluated for CBP employees to graduate from the academies and have complex weighting factors that must be calculated in the system and automatically rolled into graduation scores across the entire curriculum model. It is critical to support the various assessment types and grading scales as well as maintain complete detailed hire-to-retire training records.

The software system shall support and automate critical training operations across the following key areas expanded on in Appendix A – System Functionality Deliverables:

• System administration and integration

• Personnel management

• Training DRAFT

• Registration

• Testing

• Surveys

• Resource management and scheduling

• Housing management

• Reporting

• Compliance

The software system shall meet the following security requirements:

• FedRAMP authorized at a Moderate Impact level [as defined in Federal Information

Processing Standards (FIPS) 199];

• Criminal Justice Information Services (CJIS) compliant via an independent third-party review;

• National Institute of Standards and Technology (NIST) 800 53.v4 conformant;

• implemented and conformant with the best-practices security required by the Federal

Information Security Management Act (FISMA) legislation;

• all data stored in the continental United States; and

• client data hosted within a secure Government cloud environment.

3. Reference Documents and Authorities

Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security

Act, Public Law 107-296, 196 Stat.2135), Title 49, Code of Federal Regulations, Part 1520

Records on Individuals within the Content Management System (CMS) are subject to the

Privacy Act of 1974 (See FAR 52.224- 2).

Handbook Safeguarding Sensitive Personally Identifiable Information

DHS 4300a Sensitive Systems Handbook

Security Authorization Process Guide.pdf

CISA Cloud Security Technical Reference Architecture Version1.pdf

Mgmt Dir 140-01 Info Tech Security Program Revision 02.pdf

Federal Cloud Computing Strategy 02142011.pdf

Security Authorization of Information Systems in Cloud Computing Environments, December

NIST FIPS 200, Minimum Security Requirements for Federal Information and Information

Systems

NIST FIPS 201 ―Personal Identity Verification (PIV) of Federal Employees and Contractors

NIST SP 500-292, NIST Cloud Computing Reference Architecture

NIST SP 800-30, Risk Management Guide for Information Technology Systems rev-1 Final, dated Sept 2012

NIST SP 800-34 R1, Contingency Planning Guide for Federal Information Systems Final, dated

May 2010 DRAFT https://www.dhs.gov/publication/handbook-safeguarding-sensitive-personally-identifiable-information https://www.dhs.gov/publication/dhs-4300a-sensitive-systems-handbook https://www.dhs.gov/sites/default/files/publications/Security%20Authorization%20Process%20Guide_1.pdf https://www.cisa.gov/sites/default/files/publications/CISA%20Cloud%20Security%20Technical%20Reference%20Architecture_Version%201.pdf https://www.dhs.gov/sites/default/files/publications/mgmt/information-and-technology-management/mgmt-dir_140-01-info-tech-security-program_revision-02.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/assets/egov_docs/vivek-kundra-federal-cloud-computing-strategy-02142011.pdf https://www.gao.gov/assets/gao-20-126.pdf https://www.gao.gov/assets/gao-20-126.pdf https://csrc.nist.gov/publications/detail/fips/200/final https://csrc.nist.gov/publications/detail/fips/200/final https://www.nist.gov/programs-projects/personal-identity-verification-piv-federal-employees-and-contractors https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-292.pdf https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

NIST SP800-37 R1, Guide for Applying the Risk Management Framework to Federal

Information Systems: A Security Life Cycle Approach, dated February 2010

NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems, dated

August 2002

NIST SP 800-53 R3, Recommended Security Controls for Federal Information Systems and

Organizations, dated August 2009

NIST SP 800-60 R1 Vol1 , Guide for Mapping Types of Information and Information Systems to

Security Categories Final, dated August 2008

NIST SP 800-63 R1, Electronic Authentication Guideline, dated December 2011

NIST SP 800-88, Guidelines for Media Sanitization Rev1 Final, dated September 2006

NIST SP 800-116, A Recommendation for the Use of PIV Credentials in Physical Access

Control Systems (PACS), dated November 2008

NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information

(PII) Final, dated April 2010

NIST SP 800-125, Guide to Security for Full Virtualization Technologies Final, dated January

NIST SP 800-137, Information Continuous Monitoring for Federal Information Systems and

Organizations, dated September 2011

NIST SP 800-144, Guidelines on Security and Privacy in Public Cloud Computing Final, dated

December 2011

NIST SP 800-145. A NIST Definition of Cloud Computing Final, dated September 2011

NIST SP 800-146, DRAFT Cloud Computing Synopsis and Recommendations, dated May 12, Office of Management and Budget (OMB) Circular A-130, Management of Federal Information

Resources

Public Law 107-347, E-Government Act of 2002, including Title III, Federal Information

Security Management Act (FISMA)

DHS Acquisition Instruction/Guidebook 102-01-001 Appendix B SELC Guide version 2.0

Homeland Security Presidential Directive 12

OMB M-06-16-Implementation of the Federal Civil Penalties Inflation Adjustment Act

OMB M-11-11 "Continued Implementation of Homeland Security Presidential Directive (HSPD)

12– Policy for a Common Identification Standard for Federal Employees and Contractors"

OMB M-10-15 ―FY 2010 Reporting Instructions for the Federal Information Security

Management Act and Agency Privacy Management

Handbook (HB) 1400-05D CBP Information Systems Security Policies and Procedures

Handbook Version 3.0, February 8, 2012

National Information Exchange Model (NIEM) Section 508 of the Rehabilitation Act

DHS Standard Operating Architecture (SOA)

36 CFR 1194.2 - Guidelines for Section 255 of the Communications Act.

36 CFR 1194.3 - General exceptions DRAFT https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/archive/2014-06-05 https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/archive/2014-06-05 https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-47.pdf https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-47.pdf https://csrc.nist.gov/publications/detail/sp/800-53/rev-3/archive/2010-05-01 https://csrc.nist.gov/publications/detail/sp/800-53/rev-3/archive/2010-05-01 https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-63/1/archive/2011-12-12 https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-116/archive/2008-11-20 https://csrc.nist.gov/publications/detail/sp/800-116/archive/2008-11-20 https://csrc.nist.gov/publications/detail/sp/800-122/final https://csrc.nist.gov/publications/detail/sp/800-122/final https://csrc.nist.gov/publications/detail/sp/800-125/final https://csrc.nist.gov/publications/detail/sp/800-125/final https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-137.pdf https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-137.pdf https://csrc.nist.gov/publications/detail/sp/800-144/final https://csrc.nist.gov/publications/detail/sp/800-144/final https://csrc.nist.gov/publications/detail/sp/800-145/final https://csrc.nist.gov/csrc/media/publications/sp/800-146/final/documents/draft-nist-sp800-146.pdf https://csrc.nist.gov/csrc/media/publications/sp/800-146/final/documents/draft-nist-sp800-146.pdf https://www.cio.gov/policies-and-priorities/circular-a-130/ https://www.cio.gov/policies-and-priorities/circular-a-130/ https://www.congress.gov/107/plaws/publ347/PLAW-107publ347.pdf https://www.congress.gov/107/plaws/publ347/PLAW-107publ347.pdf https://www.dhs.gov/sites/default/files/publications/Systems%20Engineering%20Life%20Cycle.pdf https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2016/m-16-06.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2011/m11-10.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2011/m11-10.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2010/m10-15.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2010/m10-15.pdf https://www.cbp.gov/trade/rulings/directives-handbooks https://www.cbp.gov/trade/rulings/directives-handbooks https://www.niem.gov/disclaimer#:~:text=Section%20508%20requires%20that%20individuals,undue%20burden%20would%20be%20imposed https://www.dhs.gov/xlibrary/assets/itpa-dndo-jaccis.pdf https://www.ecfr.gov/current/title-36/section-1194.2 https://www.govinfo.gov/app/details/CFR-2011-title36-vol3/CFR-2011-title36-vol3-sec1194-3

36 CFR 1194.22 - Web-based Intranet and Internet Information and Applications

36 CFR 1194.31 - Functional Performance Criteria

36 CFR 1194.41 - Information, Documentation, and Support

Management Directive 4010.2: Section 508 Program Management Office & Electronic and

Information Technology Accessibility

Computer Security Act of 1987 (40 U.S.C. 1441 et seq.)

Government Information Security Reform Act of 2000

4. Solution Configuration

The Contractor shall work with CBP OTD System Administrators and/or COR and provide all requested information to facilitate receiving the necessary security authorizations required by the

Department of Homeland Security (DHS) and CBP. The Contractor shall ensure the solution is ready to achieve a CBP-issued Authority to Operate (ATO). The solution shall support all CBP employees and Contractor personnel nationwide and in various international locations. All solution(s) shall meet Section 508 compliance requirements.

The software shall support the following key areas expanded on in Appendix A – System

Functionality Deliverables:

• System administration and integration

• Personnel management

• Training

• Registration

• Testing

• Surveys

• Resource management and scheduling

• Housing management

• Reporting

• Compliance

The Contractor shall provide the following services for the life of the contract:

• Software procurement, implementation, data migration, establishing data interchanges, and licensing;

• Modifications/customizations optional contract line-item number (CLIN);

• Consulting support, including training and documentation required to support implementation and management of the system;

• Maintenance of user data and ability to import external files of various file formats within security controls such as Chiasmus Key File (.xis), Multimedia Builder (.mdb), comma-separated values (.csv), text document file (.txt), etc.;

• Cloud hosting in a FedRamp Moderate authorized environment; DRAFT https://www.govinfo.gov/app/details/CFR-2013-title36-vol3/CFR-2013-title36-vol3-sec1194-22 https://www.govinfo.gov/app/details/CFR-2011-title36-vol3/CFR-2011-title36-vol3-sec1194-31 https://www.govinfo.gov/app/details/CFR-2012-title36-vol3/CFR-2012-title36-vol3-sec1194-41 https://www.dhs.gov/publication/management-directive-40102-section-508-program-management-office-electronic-and https://www.dhs.gov/publication/management-directive-40102-section-508-program-management-office-electronic-and https://uscode.house.gov/view.xhtml?req=granuleid:USC-2000-title40-section1441&num=0&edition=2000 https://www.epa.gov/sites/default/files/2015-12/documents/gisra.pdf

• Software must follow the full stack engineering, which is FedRamp authorized and listed on FedRamp.gov;

• Support 24/7/365 access to the system for CBP personnel;

• Help desk support for tiers 2 and 3 (in-depth and expert technical support);

• Systems analysis, programming, quality assurance testing, and training to implement enhancements to support evolving and emerging training requirements;

• Systems analysis, programming, quality assurance testing, and training to onboard additional academies, training facilities;

• Modifications/customizations of business-specific reports to support enhancements made for evolving and emerging training requirements;

• Assistance in completing privacy compliance documentation required by the

Government as necessary. Required Contractor support completing the requisite documents shall be limited to system-specific information and the handling of information within the system; and

• Single sign-on (SSO) access to all system components.

The Contractor Information System Security Officer (ISSO) shall coordinate all security activities with the Federal ISSO and/or System Owner. The Risk Management Division

Information System Security Manager (ISSM) will provide guidance to the Federal ISSO for management with the Contractor ISSO where needed.

All security compliance documents will be reviewed and approved by the CBP Chief

Information Security Officer (CISO) and accepted by the CBP Contracting Officer (CO), or CO designee, upon creation and after any subsequent changes, before they go into effect.

4.1. Authentication, Authorization, and Security

The software system shall meet the following security requirements:

• Fully FedRAMP authorized at a Moderate Impact level (as defined in FIPS 199).

• Software must follow the full stack engineering, which is FedRamp authorized and listed on FedRamp.gov.

• Criminal Justice Information Services (CJIS) compliant via an independent third-party review.

• NIST 800 53.v4 conformant.

• Implemented and conformant with the best-practices security required by the

FISMA legislation.

• All data shall be stored in the continental United States.

• Client data hosted within a secure Government Cloud environment.

• Use Active Directory (AD) based Single Sign On (SSO) services for authentication.

• Allow authorized persons to create usernames and passwords for users who do not have the ability to use SSO.

• Provide multiple permission levels for the different roles identified by CBP. DRAFT

• Have internal capability to control access to content based on attributes provided by CBP.

• Be fully Public Key Infrastructure (PKI) enabled and transmit all data over Secure

Sockets Layer (SSL) encrypted channels.

• Incorporate e-signatures.

• Have the capability to restrict access to content based on the center or unit that is delivering the content, i.e., data partitioning.

• Afford a high level of password security features, for instance:

o Allows the administrator to require users to use strong passwords o Limits the use of old passwords o Defines parameters for strong passwords for users o Requires users to change the password on first login o Locks users out after a certain number of failed login attempts o Requires users to change passwords regularly (using notifications) o Sets limits on periods of inactivity o Only users can change their password o Encrypts stored passwords

• Allow Personal Identity Verification (PIV) Card access.

• Allow the creation of customized administrator roles (to be managed by CBP staff).

4.2. Enterprise Architecture Compliance

All solutions and services shall meet CBP Enterprise Architecture policies, standards, and procedures. Specifically, the Contractor shall comply with the following Homeland Security

Enterprise Architecture (HLS EA) requirements:

• All developed solutions and requirements shall be compliant with the HLS EA.

• All IT hardware or software shall be compliant with the HLS EA Technical

Reference Model (TRM) Standards and Products Profile.

• Description information for all data assets, information exchanges and data standards whether adopted or developed shall be submitted to the government for review and insertion into the DHS Data Reference Model and Enterprise

Architecture Information Repository.

• In compliance with Office of Management and Budget (OMB) mandates, all network hardware shall be IPv6 compatible without modification, upgrade, or replacement.

• All Information Technology assets being developed, procured, or acquired shall be IPv6 capable.

• Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines. DRAFT

• Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components

(networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB

Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6)

Profile National Institute of Standards and Technology (NIST).

5. Interchanges

The Contractor shall create interchanges between the software system and the DHS Human

Capital (HC) Enterprise Information Environment (EIE) to transmit and retrieve all training and user data to and from the software solution.

5.1. Interchange for all Training Data

The Contractor shall create an interchange to transmit all training data from the software solution to the DHS HC EIE.

5.2. Interchange for the Creation and Maintenance of User Accounts

The Contractor shall create an interchange to create and maintain users, user accounts, and user attributes such as, but not limited to, user organization, job titles, and supervisors. The

Contractor shall not store or require Social Security Numbers (SSN) in their solution. The

Contractor shall receive a unique identifier for each user from DHS/CBP during the creation process.

Upon award, the Contractor shall provide CBP with the Application Programming Interface

(API) documentation for their solutions.

6. Transition/Go-Live

The Contractor shall develop transition plans that encompass both phasing in (start-up) and transitioning out at the time of contract completion.

6.1. Transition-In Period

The Contractors shall create a detailed project plan that outlines the tasks, timelines, and milestones associated with the transition and go-live process. The transition-in plan shall be based on the completed version of the one submitted with the Contractor’s successful proposal, as negotiated, and approved at the time of contract award, and shall cover activities such as:

• Data Migration

• System Configuration DRAFT

• Inspection and Acceptance

• Training

• Deployment

The transition plan should include details regarding system deployment, user communication, user access provisioning, and any required downtime or system migration. It should specify specific go-live dates or blackout periods to be considered.

The plan shall also include activities for training and orienting personnel who serve in key iterations or who shall perform tasks of a technical nature, the schedule and process for accounting for transferring custody of expendable supplies and parts that were acquired under the terms and conditions of the contract, and the schedule, formal inventory, and accounting records for transferring custody of Government-furnished capitalized and non-capitalized equipment.

6.2. Data Migration

The Contractor shall migrate data from the existing training and resource management system to the solution. This data may include, but is not limited to employee/user data, training data, course content data, tests, surveys, content metadata, external training request, workflows, training activity, progress data, and instructional content and eLearning. Data migration include activities such as:

• Identifying and mapping data

• Identifying any necessary data conversions

• Validating the data mapping

• Validating data conversions

• Executing the migration and conversions

• Testing the migration and conversions

• Correcting data migration and conversion issues

• Validating the migrated and/or converted data

6.3. Transition-Out Period

The Contractor shall develop and submit a comprehensive transition-out plan 60 days prior to completion of this contract. The Contractor’s transition-out plan shall not disrupt or adversely impact the day-to-day conduct of Government business and shall achieve a smooth and orderly transfer of responsibility to a successor. The transition-out plan shall fully describe how the Contractor shall approach the following issues:

• Employee notification

• Retention of personnel

• Turnover of work in progress, inventories, and Government property

• Removal of Contractor-owned property DRAFT

• Data and information transfer

• Other actions required ensuring continuity of operations

• Security debriefings for incumbent personnel holding security clearances

The transition-out plan shall require an inventory by the outgoing Contractor and the

Government before a joint inventory can be conducted between the outgoing Contractor and the successor. The inventory shall include, if applicable:

• Reconciliation of all property accounts, requisitions, and work in progress

• Turn in of excess property

• Cleanup of the Contractor’s work areas

• Provision for training of the successor’s personnel on web-based tracking systems used in performance of this SOW, specialized equipment, utilities systems, and ongoing work that the successor would be required to complete.

The Government may create a punch list of deficiencies or unmet contractual requirements at or near the time of completion of the contract. The Government may employ the services of another Contractor or third party in the development of such punch list and upon completion provide the Contractor with a copy of work not completed, to include the monetary value the

Government has assigned for each item.

At any time up to 60 calendar days prior to the completion of this contract, a successor

Contractor or Government observation period may occur, at which time, personnel of the incoming workforce may observe operations and performance methods of the outgoing

Contractor. This shall allow for orderly turnover of facilities, equipment, and records and shall help to ensure continuity of service. The outgoing Contractor shall not defer any requirements for the purpose of avoiding responsibility or of transferring such responsibility to the succeeding Contractor. The outgoing Contractor shall fully cooperate with the successor Contractor and the Government so as to not interfere with their work or duties.

7. Training

The Contractor shall provide detailed instruction on how to configure and set up the solution prior to the official launch. The Contractor shall provide a proposed training schedule including the duration and number of sessions required to cover all training topics. Training should include the following areas:

• Creating user accounts

• Managing user roles and permissions

• Defining organizational hierarchies within the system

• Partitioning data

• Uploading and organizing different types of content

• Using system modules/functionalities

• Troubleshooting common issues

• Ensuring overall stability and performance of the system DRAFT

The training should be delivered by experienced trainers who are knowledgeable about the solution. The training can be conducted through a combination of on-site sessions, virtual instructor-led training, or self-paced online modules. The training should include hands-on experience and opportunities for participants to as questions and seek clarification.

The Contractor shall provide comprehensive training materials, including user manuals, reference guides, and any necessary documentation to supplement the training sessions in an editable format. These training materials should be made available to the system administrators both during and after the training for future reference.

Updated training materials/release notes shall be provided with each software release.

Contractor supplied training shall include present and upcoming new functionality release tutorials during regular scheduled meetings as needed.

8. Subscription Services

The Contractor shall provide the following subscription services for the solution:

8.1. Maintenance

The Contractor shall provide cloud maintenance services (if applicable), to include technical services to ensure that the system remains fully operational as outlined in the below service-level objectives. The Contractor shall interface with CBP’s Office of Information and

Technology (OIT) to support access to the system as necessary. Support services shall include system upgrades and reprogramming to address upgrades/refreshment.

8.1.1. Service-Level Objectives

The Contractor shall provide system support services meeting the service-level objectives. The resulting service-level agreements (SLA) at a minimum shall address and meet the Government’s service-level objectives requirements. SLAs include procurement, installation, initial training, system upgrades, site maintenance, software support, routine scheduling, monitoring system applications for abnormal operation, and help desk to support problem resolution.

8.1.2. System Availability

The service availability requirement shall have the system available 99.9% of the time, excluding scheduled maintenance.

8.1.3. Scheduled Maintenance

Scheduled maintenance includes any maintenance of the system and network elements to which CBP wide area network (WAN) is connected (a) of which the Government is notified 48 hours in advance, and (b) that is performed during the agreed upon DRAFT maintenance schedule determined by CBP. Notice of scheduled maintenance shall be provided to the CBP System Administrators by the Contractor via email.

8.1.4. New Releases / Updates

The Contractor shall notify CBP of upcoming changes that may impact how users interact with the solution and provide a schedule of upcoming releases and updates. The system shall be updated to the new releases offered to industry on a periodic basis (minimum 4 times a year) with the ability for the Government to determine what and when updates will be released. The Contractor shall provide CBP with time to test and validate the release/update.

The Contractor shall provide updated training materials and documentation in editable formats for any new releases and updates within five (5) business days of deployment.

8.1.4.1. Delivery Instructions

The Contractor shall maintain an environment that mirrors CBP’s production environment for the purpose of user acceptance testing (UAT) and training. The

Contractor shall emulate the configurations that exist in the CBP production environment to include the current customizations. When code is ready to be submitted to CBP, CBP shall access this environment and conduct acceptance testing to validate the defined requirements and system design have been met before the code can be implemented at CBP.

All requirements and design documentation shall have a status of final before coding begins. Screen mockups are required when requested for functions. Operation manuals/release notes shall be provided in Word or PDF documents that can include images of screen shots or architectural models as needed. Project schedules shall be maintained in Microsoft Excel or Microsoft Word and submitted to the COR within five (5) business days of an update or modification.

8.1.4.2. Inspection and Acceptance

CBP staff will conduct an acceptance test on the Contractor’s site acceptance testing

(SAT) environment before enhancements/modifications are implemented and accepted by CBP.

Acceptance Criteria: The general quality measures, as set forth below, shall be applied to each deliverable received from the Contractor under this contract.

Accuracy: The work performed shall meet CBP requirements and the COR’s prior written approval for providing software support. DRAFT

Documentation of work shall be accurate in presentation, technical content, and adherence to accepted elements of style.

Clarity: Work products shall be clear and concise; engineering terms shall be used, as appropriate. All diagrams shall be easy to understand and relevant to the supporting narrative.

File Editing: All text and diagrammatic files shall be editable by the Government.

Timeliness: Work products shall be submitted on or before due dates specified in project schedules.

UAT: The Contractor shall perform the system programming and development testing on their premises. The Contractor shall support UAT conducted by CBP personnel but shall not be required to be at a CBP location. UAT shall be conducted by OTD personnel and shall be performed in the SAT environment.

The COR will notify the Contractor of acceptance or rejection of the deliverable within ten (10) business days of the Government’s receipt of the deliverable. If rejected, the Contractor shall have to put forth a plan to mediate within ten (10) business days.

8.1.4.3. Custom Features

The Contractor shall, if upon government’s request, perform and document system design for submission to CBP System Administrators for approval, programming, testing, and implementation. Requested Design documentation may include screen mockups for screen changes or implementation of new screens and report mockups for new or enhanced reports. Design documentation shall also include the system path to access new or changed functions.

The Contractor is responsible for code development and quality assurance testing of the software before being delivered and implemented on the system. The Contractor shall maintain regular communications with the CBP System Administrators to ensure that all requirements are understood, documented, and delivered as documented.

System design and development (or CBP customizations) shall be implemented in small iterative deliverables to ensure the system grows and evolves with future trends and technologies. All custom development shall be submitted to the CBP System

Administrators with screen mockups and cost estimates for review and approval prior to beginning development. All proposals and invoices for custom development shall define how the price was derived in order to be accepted.

8.1.5. Data Retention Requirements

Student information shall be retained for 40 years, or to the Government’s requirements, as to remain retrievable throughout the active career of CBP personnel. Student records DRAFT and training schedules shall be retained to validate the type, duration, and extent of training provided. This information provides a mechanism to validate training and experience for purposes of qualifying for jobs, obtaining training credit with colleges and universities, and establishing a student’s knowledge base for a given situation in the work environment.

8.1.6. Points of Contact

The Contractor shall provide, as part of the SLA, points of contact (POCs) to include primary and alternate support. POC information shall include name, phone number, and email address.

8.2. Help Desk

The Contractor shall provide U.S. based help desk (telephonic) and on-call maintenance support. The Contractor’s help desk support shall coordinate with the CBP help desk. The

Contractor shall provide the CBP help desk with a phone number of the Contractor help desk support. The Contractor’s help desk support shall support tiers 2 and 3 for all issues that are not inherently Governmental: 8 a.m. to 6 p.m. Monday to Friday Eastern Time (ET) for noncritical incidents (priority 2). In the event of a system failure or critical incident, the

Contractor shall notify the CBP System Administrators within 15 minutes of acknowledgement and begin work to resolve the failure or incident. Critical incidents are categorized as follows: (1) entire site is down, (2) users cannot login, or (3) system data is not accessible.

The Contractor shall provide tiers 2 and 3 support, to include resolving functional, technical, and policy-related issues that CBP’s tier 1 help desk cannot support. In addition, tiers 2 and 3 shall utilize an issue-tracking portal to manage and distribute help ticket requests. The portal shall provide an immediate response to the users, and all email thread and actions shall be tracked in a reportable manner. Based on ticket volume, resources allocated to the tier 2 help desk may also be positioned to support other functional areas of the project.

Helpdesk deliverables:

• Maintain a tiers 2 and 3 ticketing system and record all issues in the ticketing system.

• Meet the Government’s expectations for acceptable SLA for working and closing tiers 2 and 3 issued tickets.

• Provide monthly reporting metrics on tiers 2 and 3 tickets.

8.2.1. Priority 1

Operational System Down: Priority 1 occurs when the system is failing in an operational environment resulting in a complete loss of capability. This type of problem severely impacts CBP objectives and requires timely response and corrective action.

Acknowledgement is required 15 minutes after notification. Initial response is required

30 minutes following notification. Corrective action is required to begin on the same day or no later than one (1) day after issued diagnosis is complete. DRAFT

8.2.2. Priority 2

System is Not Functioning as Specified: Priority 2 occurs when a function of the system is not behaving as specified. Operational work can continue but the system is not performing to specification (degraded) and corrective action is required. Examples are data latency or intermittent operation. Acknowledgement is required one (1) hour after notification. Initial response is required three (3) hours following notification. Corrective action is required to begin on the same day or no later than one (1) day after issued diagnosis is complete.

8.2.3. Mean Time to Respond

The mean time to respond objective is 30 minutes. This objective is defined as the response time to the Government’s requests for repair and other technical problems

(averaged per month on all response times for all submitted trouble calls).

8.2.4. Mean Time to Repair

The mean time to repair objective is 24 hours. This objective is defined as repairs made resulting from trouble calls made by the Government. The time starts after the problem is analyzed, and the Government is directly notified that a repair action is required.

8.3. Project Management

Provide project management support required to carry out the tasks and comply with this

Statement of Work (SOW). Contractor progress against tasks shall be assessed in informal status daily discussions (where discussions could include phone conversations and/or email exchange) between the Contractor and the Contracting Officer’s Representative (COR). The

Contractor shall support the weekly status meetings to be chaired by the project manager.

Additionally, the Contractor shall prepare and submit monthly status reports to the COR. As a minimum, the report shall contain the following:

• activity summary;

• major milestones;

• open action items;

• project risks and responses;

• modification progress to schedule performance;

• major activities planned for the succeeding month; and

• status of configuration changes including due dates for mockups and implementation, as well as an updated accounting record of configuration changes.

Tasks that are late shall be listed on monthly status reports with an explanation of why they are late, and a discussion of remediation actions planned to alleviate the schedule delay. This report shall be prepared in a narrative format suitable for reproduction. Electronic submittal DRAFT may be made via email to the COR and the Contracting Officer. The monthly status reports shall be reviewed during the monthly meeting with the Contractor. These status reports shall include unforeseen issues that impact the:

• critical path;

• risks;

• known issues; and/or

• the completion date of the project, which shall also be reported to the COR via email within four (4) business hours of their discovery.

8.3.1. Meeting and Reporting Requirements

Weekly status meetings shall be conducted via teleconference to discuss the following topics:

• Issues

• Anomalies

• Upgrades, enhancements, and modifications

• Projects (provide status, updates to schedules, milestones)

The Contractor shall submit meeting minutes and all action items to the COR within five

(5) business days of the end of the meeting via email.

At a minimum, the Contractor shall provide at least one (1) project manager and one (1) systems engineer to provide administrative and system updates for all weekly meetings.

The Government will provide at least one (1) systems administrator and the COR.

Additional personnel may be provided on either side based on need.

8.3.2. Monthly Status Report

The Contractor shall submit a monthly status report to the COR by the tenth (10) business day of each month via email. The monthly status report shall address functional accomplishments, issues, unresolved problems, and a plan of action for resolving any problems identified by the Government.

This report shall contain the following information:

• cover letter with the Contractor’s name and address, the contract number, the date of the report, and the period covered by the report;

• significant changes to the Contractor’s organization or method of operation;

• description of significant events occurring during the reporting period;

• status of pending deliverables with expected delivery dates;

• problem areas affecting technical, schedule, or cost elements of the contract, including background, impact, and recommendations· for resolution;

• results related to previously identified problem areas with conclusions and recommendations; DRAFT

• trip reports and significant results;

• Name and telephone number of the preparer of the report;

• Planned accomplishments for the next reporting period; and

• For each task area, the Contractor shall provide the status and expected timeframe for completing the associated tasks.

8.4. Key Personnel

The Contractor agrees to assign tasks to those persons who are necessary to fill the requirements of the Contract, whose resumes are submitted with its proposal, and who have been specifically defined as key personnel. The Contractor shall propose key personnel responsible for CBP evaluation that include subject matter experts on federal law enforcement training, Section 508, and the COTS solution. CBP requires the following qualified key personnel/position:

• Project Manager - extensive experience in managing projects and personnel who shall be responsible for the planning, execution, and implementation of projects.

Education/Experience/Qualifications: Bachelor of Arts (B.A.) or Bachelor of

Science (B.S.) degree and 10 years of information technology (IT) or telecommunications experience, including at least five (5) years of IT software management experience.

CBP reserves the right to request the following personnel/positions with Government right to waive qualifications in lieu of experience:

• Senior Application Developer - extensive software development experience with web-based technologies. Education/Experience/Qualifications: B.A. or B.S.

degree or five (5) years of equivalent experience in a related field. Basic experience: Shall have five (5) years of computer experience in at least two (2) of the following disciplines: system analysis, system programming, application programming, and equipment analysis. Specialized Experience: at least three (3) years of experience developing applications using advanced technologies, including internet protocols, web-based, and .NET technology. Technologies include Hypertext Markup Language (HTML), Computer Generated Imagery

(CGI) applications, Perl or JavaScript, and Java.

• Application Developer - software development experience with web-based technologies. Education/Experience/Qualifications: B.A. or B.S. degree or three

(3) years of equivalent experience in a related field. Basic Experience: Shall have two (2) years of experience at least two (2) of the following disciplines: system analysis, system programming, and trouble shooting and debugging code.

Specialized Experience: at least one (1) year of experience developing applications using advanced technologies, such as internet protocols, web-based technology, and .NET technologies include HTML, CGI applications, Perl, or DRAFT

JavaScript, and Java.

• Senior Business Analyst/Functional Expert - extensive development experience with functional requirements, specifications, and system design.

Education/Experience Qualifications: B.A. or B.S. degree and a minimum of 10 years of experience working in a related field. Specialized Experience: This position requires five (5) years of specialized experience in the functional area of law enforcement training with an understanding of processes, workflow, tracking, and reporting on training activities.

• Quality Assurance Specialists - Experience in planning and managing quality assurance processes and software testing. Education/Experience Qualifications:

B.A. or B.S. degree with five (5) years of experience working with IT quality control methods and tools.

• Information Systems Security Officer (ISSO) - The Information Systems Security

Officer (ISSO) will be responsible for all Contractor systems security work performed under this SOW. The ISSO shall be a single point of contact for systems security related issues. The name of the ISSO, and the name(s) of any alternate(s) who shall act for the Contractor in the absence of the ISSO, shall be provided to the Government as part of the Contractor's proposal. The ISSO is further designated as Key by the Government. During any absence of the ISSO, only one alternate shall have full authority to act for the Contractor on all matters relating to systems security work performed under this contract. The ISSO and all designated alternates shall be able to read, write, speak and understand English.

Additionally, the Contractor shall not replace the ISSO without prior approval from the Contracting Officer.

The ISSO shall be available to available to the COR via telephone between the hours of 8:00AM and 5:00PM EST, Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 4 hours of notification.

9. Deliverables

All written contract deliverables require COR approval and formal acceptance by the COR. The

Government will have up to ten (10) business days after receipt of a deliverable to accept or reject any product. If the COR rejects a deliverable, the Contractor will be provided specific written comments detailing the basis for the rejection and recommended corrective action. The

Contractor shall have up to ten (10) calendar days to address each specific written comment by either incorporating the requested Government change or providing an explanation of why the

Government change is not being incorporated. The Government will have an additional five (5) DRAFT calendar days to review and provide a final decision regarding acceptance or rejection of the deliverable.

9.1. General Deliverables

Deliverables Deadline

Kick-Off Meeting Day of award

Data retention plan 10 Days after award

IT security plan 10 Days after award

Project management plan 14 Days after award

Project schedule - In the ITAR Clauses Appendix 10 Days after award

Any issues identified by the Contractor that affect the critical path shall be communicated to the COR in writing.

Within 4 hours of discovery

Proof IT security accreditation to include:

• Final IT security plan

• Risk assessment

• Security test and evaluation

• Disaster recovery plan

• Continuity of operations (COOP) plan

20 Days after award

Continuous monitoring data report (Security Authorization

Process Guide.pdf)

Monthly by the 10th

Monthly status reports Monthly by the 10th

Program status meetings Weekly

Updated project schedule Weekly

Single sign-on 30 days after award

Financial reports (invoices, incurred costs and funds status)

Monthly by the 10th

Presentations, demonstrations, mockups, project support materials

As required

Release notes With each software release

Training materials Within 20 days of award, and as required

Perform tasks and provide documentation to support the

Security Authorization process

3 months after award and as required

Complete any customizations required by CBP As required prior to due date

Help desk Implementation 14 days prior to the enterprise rollout

Transition-in plan 14 days after ward

Transition-out plan 60 days prior to the end of the contract

Extract Data 90 days before shutdown

Sanitize equipment and media 60 days before shutdown DRAFT https://www.dhs.gov/sites/default/files/publications/Security%20Authorization%20Process%20Guide_1.pdf https://www.dhs.gov/sites/default/files/publications/Security%20Authorization%20Process%20Guide_1.pdf

Attest and evidence of sanitization 30 days before shutdown

10. Government-Furnished Equipment and Information

The Government anticipates a limited need for CBP-issued laptops in order to assist with integration efforts. The Government will provide information for SSO, Integration with CBP systems, and data migration as required.

11. Travel

All travel shall be preapproved in writing by the COR and shall be in accordance with the

Federal Travel Regulation (FTR). Email from the COR is acceptable for written authorization.

12. Other Direct Costs (ODC)

No ODCs are anticipated under this contract.

13. Place of Performance

The work for this contract will be performed at the Contractor’s location.

14. Contracting Officer Representative

The COR for this effort is:

Ms. Jennifer Poole

(P): 304.535.5119

(E): Jennifer.A.Poole@cbp.dhs.gov.

mailto:%20Jennifer.A.Poole@cbp.dhs.gov

File details come from the government source that posted it. Updated .