20-FDA-SOL-1211384 Attachment B - Base IDIQ SOW.doc

DOC document 1000 KB Posted

Attached to
FDA Cybersecurity Capabilities Projects IDIQ Federal contract opportunity
Solicitation number
20-FDA-SOL-1211384
Issued by
Department of Health and Human Services Food and Drug Administration Office of Acquisition and Grant Services

About this file

This solicitation is seeking proposals for an Indefinite Delivery Indefinite Quantity (IDIQ) contract to provide Cybersecurity Capabilities Projects to the U.S. Food and Drug Administration (FDA). The contract will have a ceiling value of $45 million over five years. The North American Industry Classification System code is 541512 for Computer Systems Design Services, and the solicitation is set aside for small businesses certified in the 8(a) program with a size standard of $30 million or less.

The FDA intends to award a single IDIQ contract from this solicitation. The evaluation and selection process will occur in two phases, with Phase I involving a Request for Qualifications and Phase II a Request for Proposal. Responsible sources may submit a proposal by the specified due date. Accompanying the solicitation are attachments outlining the pricing workbook and labor categories, an IDIQ statement of work covering cybersecurity task areas, two sample task order statements of work for risk/vulnerability assessment and cybersecurity support services, evaluation instructions and criteria, and a past performance questionnaire for Phase II.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP # 20-FDA-SOL-1211384

Attachment B

FDA Cybersecurity Capabilities Projects IDIQ

U.S. Food and Drug Administration

Statement of Work (SOW) for FDA Cybersecurity Capabilities Projects - Indefinite Delivery Indefinite Quantity (IDIQ)

INTRODUCTION

31.1 Background

31.2 Environment

41.3 Key Technologies

Objectives

Scope

Description of Task Areas

64.1 Task Area – Identify

74.2 Task Area – Protect and Detect

84.3 Task Area – Respond and Recover

84.4 Task Area – Capabilities and Integration/ Innovative Cybersecurity Business Projects

94.5 Task Area – Penetration Testing

94.6 Other Direct Costs – Hardware and Software

94.7 Task Area – Transition In and Out

104.8 Contract Level Program Management

Applicable Documents

Constraints

126.1 FDA Information Technology

146.2 Data Quality Standards

146.3 Information Technology Investment Management (ITIM)

146.4 FDA Data Centers

Deliverables

Other Requirements

148.1 Personnel

158.2 Key Personnel

Inspection and Acceptance

Intellectual Property

Government Furnished Equipment (GFE)/Government Furnished Information (GFI)

Period of Performance

Place of Performance

Contract Type

1714.1 IDIQ Ceiling

1714.2 IDIQ Management

Ordering

1715.1 Authorized Ordering Activity

1715.2 Ordering Procedures

1815.3 Ordering for Other Direct Costs (ODCs)

Contracting Officer’s Authority

1816.1 Contracting Officer’s Representative

1916.2 IDIQ Order Contracting Officer’s Representative Roles and Responsibilities

Technical Direction

Points of Contact

Travel

Section 508 Requirements

Security

2221.1 Information Security and/or Physical Access Security

3021.2 Privacy Act Records

3021.3 Government Information Processed on GOCO or COCO Systems

3521.4 Cloud Services

4021.5 Other IT Procurements

Contractor Personnel Security Standards and Residency Requirements (October 2017)

Conflict of Interest

Do Not Compete

Non-Personal Services

Contractor Advertising of Award

Order of Precedence

1 INTRODUCTION

1.1 Background

The U.S. Food and Drug Administration (FDA) is a scientific regulatory agency that employs more than 23,000 scientific, regulatory, technical, and support staff who are responsible for protecting and promoting the public health in the United States. One of the ways that FDA will advance its broad public health mission is by working to transform administrative systems and infrastructure to support FDA operations.

The FDA is responsible for protecting and promoting public health through the regulation and supervision of food safety, tobacco products, dietary supplements, prescription, and over-the-counter pharmaceutical drugs (medications), vaccines, biopharmaceuticals, blood transfusions, medical devices, electromagnetic radiation emitting devices (ERED), veterinary products, and cosmetics. This is accomplished through the regulatory review of sponsor submissions with data in standardized formats.

To protect the FDA’s business mission, the FDA Cybersecurity, Counterintelligence and Insider Threat Program implements and operate new cyber technologies to reduce the cyber threats against the FDA’s information resources while adhering to applicable public laws, federal standards, and executive regulations. The Cybersecurity, Counterintelligence and Insider Threat Program analyzes and advises OIMT on security risks against FDA Information Technology and requires that effective, risk-based security controls are employed to maintain the confidentiality, integrity, and availability of FDA data and systems throughout the entire system lifecycle. The FDA Chief Information Security Officer (CISO) is responsible for assuring enterprise-based cybersecurity solutions are implemented and has an active role in addressing identified cyber security risks.

The FDA Cybersecurity, Counterintelligence and Insider Threat Program continuously looks to improve the cybersecurity posture at FDA by ensuring the network and business applications are monitored 24 hours a day, 7 days a week by the FDA System Management Center (SMC). The SMC staff utilize cybersecurity tools such as Intrusion Detection Systems, firewalls, vulnerability scanning applications. The FDA seeks expertise to support the SMC and the supporting cybersecurity capabilities.

1.2 Environment

The FDA is comprised of nine Centers and Offices that support over 23,000 staff members across the United States and international offices worldwide. A majority of the personnel are located within the Washington DC metropolitan area. At the end of Fiscal Year 2019, the FDA information systems that support the FDA business mission included 109 FISMA reportable systems which may contain subsystems.

The FDA Cybersecurity Capabilities projects are typically centered around the defined areas within the DHS CDM program and will likely meet one of the 15 Tool Functional Areas and 11 Service Task Areas as defined by DHS in pages 4-10 of http://www.gsa.gov/portal/mediaId/189495/fileName/CDM_CMaas_BPA_Ordering_Guide_70_Sept_2015.action. The technologies that are implemented will need to integrate, support and protect with all FISMA reportable systems and the key technologies identified in the next section.

1.3 Key Technologies

The FDA employs a variety of hardware and latest and legacy software technologies and commercial industries. The table below is a subset of some of the common technologies used at the FDA.

1. Database Management Systems

a. Oracle 12c

b. Oracle 11g

c. Oracle 10g

d. SAS Share

e. Microsoft SQL Server

2. Programming Languages

a. XML Programming

b. JAVA

c. Oracle Application Server

d. SAS

3. Servers/Operating Systems (physical and virtual machines)

a. Windows Server 2003, 2008, 2012 and 2016

b. Oracle Servers (Solaris via Logical Domains (LDOMS))

c. Linux (VMs)

d. VMWare

4. Cloud Computing

a. Amazon

b. Salesforce

c. Microsoft

d. ServiceNow

e. Box

f. Emerging Cloud Environments

5. Cybersecurity tools

a. Splunk

b. Centrify

c. McAfee Antivirus and Data Loss Prevention

d. SNORT/Suricata

e. Checkpoint

f. Palo Alto

g. FireEye

h. RES

i. BigFix

j. ForeScout

k. RSA Archer

l. DBProtect

m. SailPoint

n. WebInspect

o. Radiant Logic

p. McAfee Cloud Access Security Broker

q. EnCase Forensics

5. Cybersecurity Platform

Hardware Components

a. Two racks (half filled) per data Center

b. Two Data Centers

c. PureStorage (2.5 PB split between 2 data centers – solid state drives)

d. F5 Networks

e. CISCO (Physical Servers)

Software Components

f. VMWare (Virtual Servers)

g. Windows Server 2016

h. Linux Server

i. Microsoft SQL Servers

j. Splunk

k. McAfee AV and DLP

l. McAfee Cloud Access Security Broker

2 Objectives

As a direct result of contract performance, the Chief Information Security Officer and his staff within FDA Office of Information Security (OIS) and the Office of Information Technology and Management (OIMT) expects to maintain the FDA’s Cybersecurity posture against advancing cyber threats via the following outcomes:

· Develop, implement, integrate, operate and support cybersecurity capabilities that align with the National Institutes of Standards and Technology’s (NIST) Cybersecurity Framework and the Department of Homeland Security’s (DHS) Continuous Diagnostic and Mitigation (CDM) Program

· Acquire the necessary hardware, software, services and training required to implement and operate technology solutions in support of the FDA cybersecurity mission

· Ensure that the Information Technology FDA acquires and implements meet current industry standards while aligning with emerging capabilities

· Ensure that the FDA Information Technology staff that operates the technologies receives the necessary training to understand and operate newly implemented cybersecurity technologies

· Improve efficiencies in procedures while ensuring implementation of appropriate security controls

· Integrate new technology solutions into a system development life cycle (SDLC) management framework

· Provide operations and maintenance support for FDA Cybersecurity, Counterintelligence and Insider Threat Program

· Ensure all solutions have capacity planning, RACI and technology roadmaps for future growth.

3 Scope

This statement of work (SOW) conveys the current FDA Information Technology and cybersecurity objectives, constraints, applicable scope, technical requirements, and applicable task areas. Individual task orders will be issued to obtain specific services for FDA Cybersecurity Capabilities (projects). FDA Cybersecurity Capabilities projects will include the acquisition of software, hardware, vendor-certified engineering resources necessary for implementation, operations, maintenance and training.

The scope of this contract encompasses the technical and management services necessary to permit the FDA and all its Offices and Centers to meet the objectives presented in section 1.2 above. The Contractor shall also provide all maintenance agreements, documentation, and training materials necessary to implement and maintain FDA’s access to its solution. The task areas listed below follow the federal Cybersecurity Framework.

Examples of Cybersecurity Framework capabilities include:

· Network Penetration Testing

· Web Application Firewalls

· Dark Web services (via subscription)

· Intrusion Detection and Prevention Systems (On Premise and Cloud-based)

· Cybersecurity-related health checks

· Security Incident and Event Management (SIEM)

· Data Loss Prevention

· Data Encryption

· Hunt Team

· Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM)

· Digital Forensic

· Vulnerability management

· Cloud and mobile security technologies The scope of this contract does not include performing Security Assessment, Security Authorization, and Security Awareness training. These tasks will be performed independent of this contract to ensure separation of duties. The FDA utilizes a combination of Government employees and contractor support services to meet this requirement.

4 Description of Task Areas

4.1 Task Area – Identify

As tasked, the Contractor shall provide Cybersecurity Capabilities - Identify services that include, at a minimum, to Continuous Diagnostics and Mitigation (CDM), asset inventory, unauthorized or misconfigured asset discovery, tracking and mitigation activities. Representative activities include:

· Define the scope of the Cybersecurity Capabilities - Identify solution and analyze the necessary requirements to conform to industry standard cybersecurity practices.

· Acquire Cybersecurity Capabilities - Identify solution or components necessary to integrate the solution into FDA technologies.

· Implement Cybersecurity Capabilities - Identify solutions and integrate the solution into FDA technologies.

· Develop project plans for a phased implementation plan for each capability.

· Provide manufacturer’s certified engineering solution services to support implementation, integration and lifecycle management.

· Provide manufacturer’s certified training services to support solution transition to FDA designated staff.

· Provide artifact collection and tracking, documentation preparation, customer outreach, system and business owner communications, meeting scheduling facilitation in support of FDA cybersecurity project activities.

· Provide maintenance and operations support for cybersecurity solutions.

4.2 Task Area – Protect and Detect

As tasked, the Contractor shall provide Cybersecurity Capabilities - Protect and Detect services defined to include firewall management, vulnerability scanning, network penetration tests, host and network intrusion detection or prevention, Security Incident and Event Management (SIEM), remote patching, compromise analysis, web vulnerability analysis and application vulnerability analysis, cloud security operations and analysis, data encryption, data loss prevention, malware mitigation and other Cybersecurity Capabilities Protect and Detect projects. Representative activities include:

· Define the scope of the Cybersecurity Capabilities - Protect and Detect solution and analyze the necessary requirements necessary to conform to industry standard cybersecurity practices.

· Acquire Cybersecurity Capabilities - Protect and Detect solution or components necessary to integrate the solution into FDA technologies.

· Implement Cybersecurity Capabilities - Protect and Detect solution and integrate the solution into FDA technologies.

· Develop project plan for a phased implementation plan.

· Provide manufacturer’s certified engineering solution services to support implementation and integration.

· Provide manufacturer’s certified training services to support solution transition to FDA designated staff.

· Provide artifact collection and tracking, documentation preparation, customer outreach, system and business owner communications, meeting scheduling facilitation in support of FDA cybersecurity project activities.

· Provide maintenance and operations support for cybersecurity solutions.

4.3 Task Area – Respond and Recover

As tasked, the Contractor shall provide Cybersecurity Capabilities – Respond and Recover services that include Incident Management and Response tools capabilities, and recovery tools capabilities that support the FDA Cybersecurity, Counterintelligence and Insider Threat Program. Representative activities include:

· Define the scope of the Cybersecurity Capabilities – Respond and Recover project solution and analyze the necessary requirements necessary to conform to industry standard cybersecurity practices.

· Acquire Cybersecurity Capabilities – Respond and Recover solution and integrate the solution into FDA technologies.

· Implement Cybersecurity Capabilities – Respond and Recover solution and integrate the solution into FDA technologies.

· Develop project plan for a phased implementation plan.

· Provide manufacturer’s certified engineering solution services to support implementation and integration.

· Provide manufacturer’s certified training services to support solution transition to FDA designated staff.

· Provide artifact collection and tracking, documentation preparation, customer outreach, system and business owner communications, meeting scheduling facilitation in support of FDA cybersecurity project activities.

· Provide maintenance and operations support for cybersecurity solutions.

4.4 Task Area – Capabilities and Integration/ Innovative Cybersecurity Business Projects As tasked, the Contractor shall provide project support for Cybersecurity Capabilities and Integration/Innovative Cybersecurity Business Projects is defined to include cybersecurity-related Mobility and Cloud solutions, Cloud IDS solutions, the Internet of Things, Security and Incident Event Management (SIEM), Web Application Firewalls (WAF) and other technologies that FDA must adopt and secure to maintain and improve business activities. These technologies are active emerging or disruptive technologies introduced into the FDA environment. Representative activities include:

· Define the scope of the Innovative business solution and analyze the necessary requirements to conform to requirements.

· Acquire innovative business solution and integrate the solution into FDA technologies.

· Implement innovative business solution and integrate the solution into FDA technologies.

· Develop project plan for a phased implementation plan.

· Provide manufacturer’s certified engineering solution services to design, implement and integrate a solution.

· Provide manufacturer’s certified training services to support solution transition to FDA designated staff.

· Provide artifact collection and tracking, documentation preparation, customer outreach, system and business owner communications, meeting scheduling facilitation in support of FDA cybersecurity project activities.

· Provide maintenance and operations support for cybersecurity solutions.

4.5 Task Area – Penetration Testing

As tasked, the Contractor shall provide Penetration Testing for FDA Cybersecurity, Counterintelligence and Insider Threat Program. Representative activities include:

· Obtain penetration services from an independent 3rd party penetration testing certified provider;

· Support the development of the test plans and Rules of Engagement;

· Review and integrate penetration testing results to support security authorizations. This includes penetration test results from HHS, DHS and other external sources;

· Provide planning, meeting coordination, documentation and exercise activities.

· Provide findings and remediation recommendations.

· Provide final penetration report.

4.6 Other Direct Costs – Hardware and Software

As tasked, the Contractor shall provide commercially available hardware, software, and subscription services to support the FDA Cybersecurity, Counterintelligence and Insider Threat Program.

4.7 Task Area – Transition In and Out

As tasked, the Contractor shall facilitate the transition of contracted activities and services to and from the Federal Government or another contractor.

Representative activities under this task area may include:

· Create or updated documentation to ensure currency and accuracy; documentation shall be provided to new federal staff or contractor to facilitate knowledge transfer and transitions.

· Provide FDA all licensing and renewal information, hardware and software Management records, software documentation, and training materials;

· Provide staffing for a task order to ensure projects are brought to full operations within an established time.

· Provide FDA with a current inventory of all Government-owned assets used by the Contractor along with full support in the reconciliation of this inventory;

· Provide FDA with current versions of all CONOPS, operational procedures, standard operating procedures, guidelines, performance reports, specifications for hardware and software, and other pertinent information needed to continue the services being performed by the Contractor;

· Provide “shadowing” and other knowledge transfer meetings and opportunities to facilitate the transfer of information, processes, and data needed to continue the services being performed by the Contractor and;

· Provide up-to-date-EPLC and program/project management documents.

· Provide RACI documentation to transition the operation of a technology to other staff equipment to operate the technology and to clarify roles and responsibilities to produce effective communications.

4.8 Contract Level Program Management

As tasked, the Contractor shall establish the program plans, structures, processes, schedules, reporting requirements, communication channels, and quality control functions necessary to steward the project throughout the contract’s period of performance and fully achieve contract objectives.

At a minimum, the Contractor shall:

· Provide overall coordination, management, and reporting for all the activities and tasks specified in all task orders under this contract;

· Develop and maintain an overall FDA Cybersecurity Capabilities Projects Contract Transition Plan to successfully transition existing support services from incumbent contractors per FDA-approved priorities and timelines;

· Develop, maintain and manage an overall FDA Cybersecurity Capabilities Projects Contract Management Plan that links the high-level activities of all task orders to overall contract objectives;

· Develop, maintain and communicate FDA Cybersecurity Capabilities Projects Contract Integrated Master Schedule (IMS) to ensure that all contract deliverables and products are produced per established schedules;

· Develop, maintain and manage a unified Risk Management Plan to identify, document, and communicate risks including their impact on FDA Cybersecurity Capabilities Projects Contract objectives;

· Develop, maintain and manage a FDA Cybersecurity Capabilities Projects Contract Communication Plan and associated capability that considers a broad range of modes and requirements from ad hoc, informal check-ins and progress updates to weekly status reports to formal briefings to FDA Executive Management, the SCB, and other key stakeholders;

· Establish control, monitoring and notification mechanisms to ensure that contract activities and processes stay on track and important milestones are met.

· Maintain a contract binder in the Contracting Officer Representative’s office that contains the task orders, deliverables, monthly contract burn rate, invoices and other contract documentation.

The Contractor shall provide a monthly contract level status report to the IDIQ COR, incorporating all tasks at a high level and their progress. Within the first 30 days after contract award, the Government and the Contractor will design and agree upon a standard reporting format that includes the following information at a minimum:

· Summary status and progress of tasks, by task order;

· Summary cost and schedule variances;

· Coordination activities across all tasks;

· Impact or influence of any task on other tasks;

· Impact or influence of tasks on overall FDA program;

· Significant risks to scheduled deliverables and plans to mitigate them; and,

· Recommendations for changes or additional activities to ensure that the tasks support progress on the overall FDA Information Security Program objectives.

· Inventory of assets of the Government Furnished Equipment and Information

In addition to progress reporting, the Contractor shall actively inform the designated Government Contracting Officer’s Representatives of any issues, problems and recommendations that should be addressed in order for the overall effective accomplishment of the IDIQ contract. Recommendations for actions that need to be taken by FDA staff, or other contractors, shall be clearly defined and communicated to the responsible party and the FDA, and have identified dates for completion.

5 Applicable Documents

The work to be performed under this contract will assist the FDA in meeting legislative mandates and associated implementation guidance from DHHS and Federal agencies. Statutes and Acts applicable to this contract include the following. The contractor shall also follow any new guidance issued during the period of performance that the FDA is required to meet.

· Computer Security Act of 1987, PL 100-235

· Federal Information Security Modernization Act (FISMA) of 2014 (an update to Federal Information Security Management Act (FISMA), part of the E-Government Act of 2002 (Public Law 107-347, Title III))

· OMB Circular A-130 and Appendix III, Security of Federal Automated Information Resources

· Government Performance and Results Modernization Act of 2010

· The Federal Cybersecurity Enhancement Act of 2015

· Federal Cybersecurity Workforce Assessment Act (FCWAA) (contained in the Consolidated Appropriations Act of 2016 (Public Law 114-113))

· Presidential Decision Directives

· Homeland Security Presidential Directives

· Executive Orders (e.g. 13636, 13800 and 13870)

· Department of Health and Human Services, Policy for Information Systems Security and Privacy, 7/2011

· Department of Health and Human Services, Information Sharing Environment (ISE) Privacy Policy, 5/2013

· E-Government Act of 2002

· Clinger-Cohen Act of 1996

· Computer Fraud and Abuse Act of 1986

· FDA Staff Manual Guides – primarily Information Resources Management – Information Technology Security Policies - 3250 Series.

· NIST Special Publications – 800 Series

· NIST Federal Information Processing Standards (FIPS)

· The Privacy Act of 1974

· Section 508 of the Rehabilitation Act of 1973

6 Constraints

6.1 FDA Information Technology

Current standards and guidelines that must be considered in the execution of all FDA Information Technology contracts include:

1. FDA Tailored Enterprise Performance Life Cycle (EPLC). Refer to the attachment “EPLC Overview for Contracts” for more information.

2. FDA Approved Technologies List - The FDA Master Approved Technology (MAT) List contains a list of approved and not approved technologies including applications (software), infrastructure and peripherals (hardware), and scientific software and devices.

3. Adhere to and work around current FDA patching maintenance schedule. This includes monthly patching for Unix, Linux and Microsoft for both the production and pre-production environments as well as quarterly database patching (Oracle) for the same two environments.

4. FDA Security Authorization Process - Security Authorization is the approach FDA follows to fulfill Federal Information Security Management Act (FISMA), Office of Management and Budget (OMB) and Department of Health and Human Services (HHS) requirements to ensure that information resources have adequate security to protect the Confidentiality, Integrity and Availability of information collected, processed, transmitted, stored, or disseminated by the agency. For further information see: FDA Security Authorization Toolkit (see attachment entitled Security Authorization Toolkit) SP 800-37 Rev. 1: Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach.

5. National Institute of Standards and Technology (NIST) SP800-53 - This publication was developed by the Joint Task Force Transformation Initiative Interagency Working Group with representatives from the Civil, Defense, and Intelligence Communities in an ongoing effort to produce a unified information security framework for the federal government— including a consistent process for selecting and specifying safeguards and countermeasures (i.e., security controls) for federal information systems (The latest revision applies). SP 800-53 Rev. 4: Security and Privacy Controls for Federal Information Systems and Organizations.

6. Federal Information Security Management Act (FISMA)—The E-Government Act (Public Law 107-347), passed by the 107th Congress and signed into law by the President in December 2002 and updated as the Federal Information Security Modernization Act (FISMA) of 2014, the recognizes the importance of information security to the economic and national security interests of the United States. Title III of FISMA requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. Federal Information Security Management Act (FISMA).

7. The E-Government Act [Public Law 107-347] passed by the 107th Congress and signed into law by the President in December 2002 recognized the importance of information security to the economic and national security interests of the United States. Title III of the E-Government Act, entitled the Federal Information Security Management Act of 2002 (FISMA), included duties and responsibilities for the Computer Security Division in Section 303 of the National Institute of Standards and Technology document: NIST: Computer Security Division - Computer Security Resource Center.

8. FDA 3250 series of Staff Manual Guide (SMG) policies, as well as HHS security policies. Note: SMG 3251.4 Outsourcing and Third Party Arrangements - The FDA Staff Manual Guides (SMGs) are the Agency directives that document organizations and functions; delegations of authority; and administrative and program policies, responsibilities and procedures.

9. FDA Security Program: Contractor Oversight Guide - Section 2, Defining Contractor Systems and Related Security Requirements - Information systems subject to Departmental and Federal requirements are predominantly maintained by Department personnel within HHS facilities; however, there exist a substantial number of contractor-run systems. This section clarifies security requirements for these contractor-based systems as well as defines the related roles of contractors and Departmental personnel.

10. HHS Cybersecurity Program – Security and Privacy Guide for Information Technology Acquisition, October 2017 – The HHS guide outlines necessary security and privacy requirement for any information technology contract.

11. FDA’s Project Management (PM) processes include a variety of project management methodologies which may be employed in the task orders released under this contract including, but not limited to, the Project Management Body of Knowledge (PMBOK).

12. Section 508 of the Rehabilitation Act of 1973

6.2 Data Quality Standards

The FDA has approved data standards for e-submissions and their regulatory review process. For example, the CDER data standards references and resources can be found at:

http://www.fda.gov/Drugs/DevelopmentApprovalProcess/FormsSubmissionRequirements/ElectronicSubmissions/ucm248635.htm

If applicable, specific data standards requirements will be detailed in each task order issued under this contract.

6.3 Information Technology Investment Management (ITIM)

FDA has instituted the ITIM process to track technologies across the agency. The introduction of a new technology or a different version of an already approved technology requires the submission and approval of an ITIM request. The Contractor may be responsible for supporting the ITIM process including writing and submitting ITIM requests and tracking them from inception through completion. FDA Center IT Investment Review Boards may need to be included in a coordinated review process.

6.4 FDA Data Centers

As of the start of Fiscal Year 2019, the FDA has four primary data centers. These are the White Oak Data Center (WODC), the Ashburn Data Center (ADC), the Wiley Scientific Data Center and the NCTR Data Center. WODC is used primarily for Development and Test environments. ADC is used for Pre-Production and Production environments. The Wiley Scientific Data Center (WSDC) is currently in use for hosting some scientific environments. The NCTR Data Center facilitates the FDA NCTR Center located in Arkansas.

At least one FISMA reportable system utilizes other data centers such as Rackspace. In addition, FDA utilizes cloud-based services from Sales Force, Microsoft, Amazon Cloud, ServiceNow and other cloud providers.

7 Deliverables

Deliverables will be specified in the task orders issued under this contract. Deliverable products will be reviewed, validated and tested as appropriate to ensure that they meet applicable/specified standards, policy, business requirements and quality measures.

8 Other Requirements

8.1 Personnel

The Contractor shall ensure that all Contractor support personnel are adequately trained, possess the credentials specified in the appropriate labor categories, and are otherwise fully qualified to provide the high level of support required by this SOW prior to being assigned to task orders awarded.

All Contractor personnel shall complete all required annual FDA agency training (i.e. security awareness training, records management training). The Contractor shall ensure that only FDA business activities are performed on FDA Government Furnished Equipment and FDA Government site locations.

The Contractor shall assure that their personnel are trained in the agency’s software applications necessary to complete the contract tasks.

The Contractor shall assure that their personnel complete all required annual agency training (i.e. security awareness training, records management training).

The Contractor shall assure that only FDA business activities are performed on FDA Government Furnished Equipment and FDA Government site locations.

The Contractor shall provide personnel with management authority at the government site.

The Contractor shall provide personnel that are United States citizens.

The Contractor shall provide personnel who are able to obtain a Public Trust Moderate (Tier 2S) security clearance.

The Contractor shall take immediate actions to remediate any challenges identified in performance.

8.2 Key Personnel

Key personnel will be designated at the task order level. Labor category descriptions and minimum qualifications are noted in Attachment A: Labor Categories and Pricing Worksheet.

The key personnel specified in the task order are considered to be essential to work performance. Reference clause HHSAR 352.237-75 Key Personnel (December 18, 2015).

9 Inspection and Acceptance

The FDA COR will inspect and accept the services, documents and materials provided to ensure they meet the requirements as outlined in the contract. The FDA COR will accept goods, reports and services only if they conform to all terms and conditions of the contract. Specific requirements for inspection and acceptance will be designated at the task order level.

10 Intellectual Property All material, software, configurations, data, briefings, videos, or documentation created by the contractor in support of this contract will become the property of the Government.

11 Government Furnished Equipment (GFE)/Government Furnished Information (GFI)

The Government will furnish the contract staff with the necessary facilities and equipment as needed to perform the scope of work in the orders. Specific items will be indicated at the task order level. Items that may be furnished include:

a. FDA identification badges that meet HSPD-12 requirement. Identification badges are used for physical and logical access.

b. FDA laptop computers with FDA images for staff performing work which requires access to FDA systems (e.g., administrators and those needing access to FDA e-mail accounts etc.). Laptops used to access FDA resources shall be imaged with the FDA workstation image, joined to the FDA domain, and managed as FDA desktops/laptops. As required, laptop/desktop configurations may include additional monitors, computer keyboards and mouse.

c. Access to shared network resources (i.e., printers, scanners, storage, FDA’s Intranet, etc.) as needed.

d. FDA network and e-mail accounts.

e. Office space and furniture will be provided only to staff whose primary office is at the Government facility in order to complete these tasks.

f. Other equipment such as mobile devices (tablets, Blackberries, etc.) will be provided only if such equipment is required to complete contract activities.

** Use of non-FDA authorized external storage is prohibited i.e. USB, Hard Drives, etc.

g. FDA will provide any planning and design documents developed for the contractor’s review.

The furnished equipment is only authorized for transaction of official Government business and shall not be used for personal business. Personal long-distance calls are not authorized and the cost of all personal long-distance calls made shall be deducted from the contractor's invoice. Telephones, facsimile machines and computer equipment are subject to communications security monitoring at all times. The cost of replacement Government furnished equipment (GFE) as a result of contractor negligence may be deducted from the contractor’s invoice. The contractor may be issued keys (physical and/or electronic). The contractor shall safeguard the keys from loss, theft or destruction, and must display all keys signed for at scheduled or unscheduled key control inspections. The contractor shall be required to reimburse the Government for lost keys, or lockset (if locksets are required to be replaced) as a result of lost keys. The cost of replacement of keys/locksets may be deducted from payments to the contractor.

Contractor Negligence

Any loss, damage, or mishandling of FDA IT equipment or assets that is directly attributed to contractor negligence shall be the responsibility of the contractor. The contractor shall be required to reimburse the Government at the full retail cost of the asset(s). This reimbursement shall be deducted against the contractor’s monthly payment.

12 Period of Performance

The period of performance for this IDIQ contract is five (5) years from date of award.

13 Place of Performance

The place of performance will be designated under each order and will be predominately at FDA centers and offices. Some orders may be performed at the contractor site. Most FDA Centers and Offices operate predominantly in the Washington, DC Metropolitan area with concentrations in the FDA's Maryland locations of Bethesda, College Park, Laurel, Rockville, and White Oak. The contractor maybe required to travel to FDA office outside the Washington, DC metropolitan offices. The specific place of performance will be indicated at the task order level.

Contractor Site The contractor may work at their designated alternate work site at the discretion of the COR. This can change at any time. The FDA will allow work to be performed at an alternate work site if the contractor meets the follow criteria:

1. The contractor shall have a rules of behavior for work performed at an alternate work site.

2. The contractor shall coordinate with the Contracting Officer Representative (COR) regarding the number of remote days per week per person.

3. The contractor shall maintain a presence of staff on site as agreed upon with the COR unless travel safety issues are identified (e.g. weather).

4. The contractor shall maintain all meeting obligations onsite.

14 Contract Type

This contract is an indefinite delivery indefinite quantity (IDIQ) contract. The task orders issued against this contract vehicle will be firm fixed price, labor hours, or time and material; or any combination within each task order.

14.1 IDIQ Ceiling

The total value of services procured under this IDIQ shall not exceed $45 million over the period of performance.

14.2 IDIQ Management

Notwithstanding the contractor’s responsibility for total management during the performance of this IDIQ, the administration of the IDIQ will require maximum coordination between the Government and the Contractor. The FDA has the right to inspect all services in accordance with the IDIQ requirements and as called for by the IDIQ orders. The FDA shall perform inspections and tests as specified in the order in a manner that will not unduly delay the work.

Communications pertaining to the IDIQ administration will be addressed to a FDA Contracting Officer or Contract Specialist. No changes to the IDIQ and IDIQ order statements of work or any other terms are authorized without a formal written modification to the IDIQ and/or IDIQ order executed by a warranted FDA Contracting Officer.

Contractors who reply and/or act on direction from anyone other than an FDA Contracting Officer do so at their own risk and expense. Such actions do not bind the Government contractually. Any contractual questions shall be directed to the FDA Contracting Officer or Contract Specialist.

15 Ordering

15.1 Authorized Ordering Activity

The contracting activity authorized to issue IDIQ orders under this IDIQ is: FDA Office of Acquisitions and Grants Services (OAGS).

15.2 Ordering Procedures

Orders placed under this IDIQ will be issued unilaterally. Orders will clearly describe all services to be performed or supplies to be delivered so the full cost or price for the performance of the work can be established when the order is placed. Orders will be within the base IDIQ scope and issued within the IDIQ period of performance. Orders can be issued by any FDA Contracting Officer (CO).

The Contractor shall identify a contractor personnel for issuing orders and provide their contact information.

For each order, the FDA will issue a Request for Proposal (RFP) to the Contractor via email. The Contractor shall provide a proposal to include a technical and business response to demonstrate their understanding of the task order scope. The FDA will evaluate the Contractor’s technical response regarding their technical understanding of the requirement, completeness and feasibility of their approach, and price reasonableness. If the FDA has questions or concerns, the Contracting Officer or Specialist will contact the contractor and may request a revised proposal. Once the proposal and price is determined acceptable, the Contracting Officer may issue the order. Orders will include the information described in FAR 16.505(a)(7).

Any work that the contractor undertakes prior to receiving a fully executed order signed by the Contracting Officer is undertaken at the contractor’s risk.

15.3 Ordering for Other Direct Costs (ODCs)

Since ODCs are identified and acquired at the order level, the Contracting Officer is responsible for making a fair and reasonable price determination for all ODCs. To support the price reasonableness of ODCs, the contractor shall obtain quotes for each ODC item in accordance with the FAR procedures for that value of the ODCs included in the quote. The quotes must be submitted to the Government for concurrence of the Program Office and the Contracting Officer. The quotes shall be maintained by the contractor in the contractor’s files and are subject to audit.

The contractor may apply indirect costs, as a fixed amount, such as G&A and material handling costs and shall indicate the indirect cost rates applicable to the order. Fee, profit, and overhead may not be applied. All indirect costs must be sufficiently explained. If ODC’s are required in an order in conjunction with services, the ODCs will have its own line item.

16 Contracting Officer’s Authority

The Contracting Officer (CO) is the sole person authorized to make or approve any changes in any of the requirements of this order and notwithstanding any provisions contained elsewhere in the order, the said authority remains solely with the CO. In the event the Contractor makes any changes at the direction of any person other than the CO, the change shall be considered to have been made without authority and no adjustment will be made in the delivery order terms and conditions, including price. The CO shall be the only individual authorized to accept nonconforming work, waive any requirement of the order and modify any term or condition of the order. The CO is the only individual who can legally obligate Government funds.

16.1 Contracting Officer’s Representative

The Contracting Officer may designate other Government personnel (known as the Contracting

Officer’s Representative, or COR) to act as his or her authorized representative for contract administration functions which do not involve changes to the scope, price, schedule, or terms and conditions of the IDIQ or resulting orders. The designation will be in writing, signed by the Contracting Officer, and will set forth the authorities and limitations of the representative(s) under the contract.

Such designation will not contain authority to sign contractual documents, order contract changes, modify contract terms, or create any commitment or liability on the part of the Government different from that set forth in the IDIQ.

The COR is responsible for the technical aspects of the project and serves as technical liaison with the contractor and is responsible for the final inspection and acceptance, and such other responsibilities as may be specified in the order.

The IDIQ COR is responsible for: 1) interpreting scope of task areas identified in IDIQ SOW, 2) acts as a Government escalation point for potential contractor resource conflicts across IDIQ Orders, and 3) monitors IDIQA ceiling over the life of the IDIQ.

The contractor shall immediately contact the Contracting Officer if there is any question regarding the authority of an individual to act on behalf of the Contracting Officer under this contract.

16.2 IDIQ Order Contracting Officer’s Representative Roles and Responsibilities For each IDIQ Order, a Contracting Officer’s Representative (COR) will be assigned. The Government may unilaterally change its COR designation. The COR shall serve as the contractor’s first point of contact for any technical questions and is responsible for:

1) monitoring the contractor’s technical progress, including the surveillance and assessment of performance and compliance with all substantive project objectives;

2) interpreting the statement of work and any other technical performance requirements;

3) performing technical evaluations as required;

4) performing technical inspections and acceptances required by this IDIQ;

5) assisting in the resolution of technical problems encountered during performance; and

6) providing technical direction in accordance with technical direction section of this SOW; and

7) reviewing invoices/vouchers.

Technical leads/points of contacts may assist the COR. The Technical Leads will not have the authority to provide technical direction in accordance with the technical direction section; however, they may be responsible for:

1) monitoring the Contractor’s technical progress, including the surveillance and assessment of performance and compliance with all substantive project objectives;

2) performing technical evaluation as required;

3) performing technical inspections and acceptances as required by this performance; and

4) reviewing invoices/vouchers.

17 Technical Direction

Performance of the work under orders shall be subject to the technical direction of the COR. The term “technical direction” is defined to include, without limitation, the following:

· Communication to the contractor which directs or redirects the contract performance effort, shifts work emphasis between work areas or tasks, requires pursuit of certain lines of inquiry, fills in details or otherwise serves to accomplish the contractual statement of work.

· Provision of information to the contractor which assists in the interpretation of drawings, specifications, or technical portions of the work descriptions.

· Review and, where required by the contract and/or order, approval of technical reports, drawings, specifications, and technical information to be delivered by the contractor to the Government under the contract and order.

Technical direction must be within the work stated in the contract or order. Neither the COR nor the TOCOR have the authority to, and may not issue any technical direction, which:

· Constitutes an assignment of additional work outside the work of the contract and orders.

· Constitutes a change as defined in the applicable clause entitled FAR 52.212-4(c) Contract Terms and Conditions – Commercial Items.

· In any manner causes an increase or decrease in the total estimated contract or order cost, fixed-fee, or the time required for performance.

· Change any of the expressed terms, conditions, or specifications of the contract and order.

All technical direction shall be issued in writing by the COR or shall be confirmed in writing within five (5) working days after issuance. The contractor shall proceed promptly with the performance of technical direction duly issued by the COR in the manner prescribed by this article and within his/her authority under the provisions of this article. If, in the opinion of the contractor, any instructions or direction issued by the COR is within one of the COR’s unauthorized categories described above, the contractor shall not proceed and shall notify the Contracting Officer in writing within five (5) working days after the receipt of any such instructions or direction and shall request the Contracting Officer to modify the order, accordingly. Upon receiving such notification from the contractor, the Contracting Officer shall issue an appropriate modification or advise the contractor in writing that, in the Contracting Officer’s opinion, the technical direction is within the work of this contract or order. The contractor shall proceed immediately with the instructions or directions and shall be subject to the FAR clause FAR 52.233-1 “Disputes.”

18 Points of Contact

The points of contact (POC) listed are for the base IDIQ. Each order will have designated POCs.

Contract Specialist
Contracting Officer
Michelle Dacanay
Phillip Frame

U.S. Food and Drug Administration

4041 Powder Mill Road U.S. Food and Drug Administration

4041 Powder Mill Road

Room 41025B
Room 42053
Beltsville, MD 20705
Beltsville, MD 20705
Phone: 301-796-0447
Phone: 240-402-7578
Email: Michelle.Dacanay@fda.hhs.gov
Email: Phillip.Frame@fda.hhs.gov

Contracting Officer’s Representative

Provided at award

19 Travel

Travel costs within the Washington DC metropolitan area will not be reimbursed. Travel performed for personal convenience or daily travel to and from work at the Contractor’s facility or local Government facility within the Washington DC metro region shall not be reimbursed hereunder. “Local” is defined under this term as the travel destination located within the Washington DC metro region.

Travel outside of the Washington DC metropolitan area shall be conducted in strict accordance with the Federal Travel Regulations (FTR) and FAR 31.205-46. Any travel travel by the Contractor shall be conducted by the direction of the Government and must have written approval by the COR prior to booking and conducting travel. Costs associated with approved travel shall be reimbursed at actual cost, or by established Government per diems, whichever is less. Travel costs exceeding rates and per diems established under Federal Travel Regulations (FTR) are prohibited from reimbursement without written Contracting Officer approval prior to the associated travel being conducted.

Prior to booking or conducting Government-direct travel, the Contractor shall provide a written request for travel to the COR and CO. The Contractor’s request for travel shall be in writing and contain the dates, locations and estimated costs of the travel. The Contractor shall then coordinate specific travel arrangements with the COR and must obtain advance, written COR approval for the travel to be conducted. The Contractor shall, to the maximum extent practicable, minimize overall travel costs by taking advantage of discounted airfare rates and other travel-related expenses available through advance purchase.

Prior to changing and/or cancelling any travel that will incur cancellation fees, the Contractor shall notify the COR in writing of the total amount of the fees associated with Government-directed travel changes and/or cancellations. The Contractor shall consider and purchase reimbursable tickets when it is more beneficial to the Government.

Any travel will be indicated in the Order 20 Section 508 Requirements HHSAR Clause 352.239-74 Electronic and Information Technology Accessibility is applicable to this contract. See clause section for full text. The clause will be included in all task orders issued based on 508 compliance requirements of each task order.

The following standards are…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .