20-FDA-SOL-1221384 Attachment D TO2 FDA Cybersecurity Support Services SOW.pdf
PDF 483 KB Posted
- Attached to
- FDA Cybersecurity Capabilities Projects IDIQ Federal contract opportunity
- Solicitation number
- 20-FDA-SOL-1211384
About this file
This is a statement of work for a task order under an indefinite delivery indefinite quantity contract to provide cybersecurity support services to the U.S. Food and Drug Administration. The task order requires the contractor to provide strategic leadership and technical capabilities to advance FDA's cybersecurity posture in alignment with federal frameworks. Specific requirements include administration of the FDA cybersecurity platform, support for cybersecurity tools and capabilities, development of a cybersecurity framework modernization plan, and strategic communications to leadership. The performance period is three months with two six-month option periods. Work will be performed onsite at FDA facilities in Maryland. The contractor must have staff that can obtain a public trust moderate risk background investigation and comply with all FDA site security and privacy requirements.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 20-FDA-SOL-1211384 Questions and Responses.pdf | ||
| 20-FDA-SOL-1211384 Attachment B - Base IDIQ SOW Amend1.pdf | ||
| 20-FDA-SOL-1221384 Attachment C TO1 FDA OIMT-OIS Risk and Vulnerability Assessment SOW.pdf | ||
| 20-FDA-SOL-1211384 SF1449 Cybersecurity Capabilities Projects IDIQ.pdf | ||
| 20-FDA-SOL-1221384 Attachment E Evaluation Instructions and Criteria.pdf | ||
| 20-FDA-SOL-1211384 Attachment F Past Performance Questionnaire.pdf | ||
| 20-FDA-SOL-1221384 Attachment A Pricing Workbook and Labor Categories.xlsx | XLSX spreadsheet | |
| 20-FDA-SOL-1211384 Attachment B - Base IDIQ SOW.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP # 20-FDA-SOL-1211384 Cybersecurity IDIQ
Attachment D
Task Order #2 FDA Cybersecurity Support Services
1 | P a g e
TASK ORDER #2
STATEMENT OF WORK
Food and Drug Administration (FDA)
Office of Information Management and Technology (OIMT) Office of Information Security (OIS)
FDA Cybersecurity Support Services
1.0 Background
The FDA is required to protect vast quantities of sensitive information including intellectual property, proprietary, company confidential, personally identifiable, protected healthcare, classified, and acquisition information from internal and external threats to the FDA IT infrastructure.
The FDA Cybersecurity Counterintelligence and Insider Threat Program (CCIT) is directed to protect the nation public health and safety and implement a cybersecurity program as defined by the following federal laws and Chief Information Security Officers (CISO) Strategic Plan:
Table 1: Federal Cybersecurity Laws and the FDA CISO’s Priorities
The FDA Cybersecurity Counterintelligence and Insider Threat Program provides governance and oversight of the FDA Information Technologies and provides assessments of risk to the FDA Information Technology program. The program provides a best-in-class, intelligence-driven cybersecurity program that directly supports the FDA’s mission to protect and promote U.S. public health.
The FDA has implemented a mature, successful cybersecurity program aligned with the federal Cybersecurity Framework and a focus on cyber capabilities, compliance and workforce development.
Success is defined by a commitment to excellence and the ability to provide strategic communications that support the FDA’s public health mission. Since 2016, the FDA program has received many awards and accolades from various government and public organizations (see Table 1).
Table 2: FDA Cybersecurity Counterintelligence and Insider Threat Program Recognitions
CSO50 Award for the FDA Systems Management Center
House of Representatives’ Energy and Commerce Committee recognition for program’s collaboration
Whitehouse recognition of the FDA’s High Value Asset Program FDA Commissioner Special Citation
Federal Executive Order #13870 – America’s Cybersecurity Workforce
Federal Executive Order #13800 – Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure
Federal Executive Order #13636 – Improving Critical Infrastructure Cybersecurity and Presidential Policy directive
Federal Information Security Modernization Act (FISMA) of 2014
NIST Federal Cybersecurity Framework
FDA Cybersecurity Counterintelligence and Insider Threat Program Strategic Plan
2 | P a g e
The following table indicates a subset of the FDA cybersecurity capabilities of the FDA Cybersecurity, Counterintelligence and Insider Threat Program.
Table 3: FDA Cybersecurity Environment/Capabilities
Cybersecurity Platform
Hardware Components
Two racks (half filled) per data Center
Two Data Centers
PureStorage (approximately 3 PB split between 2 data centers – solid state drives)
CISCO (Physical Servers)
Other components for network connectivity
Software Components
VMWare (Virtual Servers)
Windows Server
Linux Server
Microsoft SQL Servers
Splunk
Cybersecurity Platform – RESTRICTED ACCESS
Hardware Components
One racks (half filled) per data Center
One Data Center
PureStorage (solid state drives)
CISCO (Physical Servers)
Other components for network connectivity
Software Components
VMWare (Virtual Servers)
Windows Server
Linux Server
Microsoft SQL Servers
Cybersecurity Capabilties
CDM Splunk
CDM WebInspect
CDM DbProtect
CDM SailPoint
CDM BigFix
CDM ForeScout
CDM Tenable
CDM Whitelisting (McAfee)
CDM RSA Archer
McAfee Antivirus
McAfee Data Loss Prevention
FireEye
CheckPoint
Centrify
PaloAlto
EnCase
WebProxy Server
Kryptowire
3 | P a g e
1.1 Objective
The objective is to provide strategic leadership and technical cybersecurity capabilities to advance the FDA’s Cybersecurity posture via:
▪ Alignment to the Federal Cybersecurity Framework.
▪ Implementing Federally-mandated Department of Homeland Security’s (DHS) Continuous
Diagnostics and Mitigation Program.
▪ Implementing and collaborating with the Department of Health and Human Services (DHHS)
Cybersecurity toolset provided to the operating divisions (OPDIV)s.
▪ Engineering, operation and maintenance of an enterprise Cybersecurity Incident and Event
Management (CIEM) also known as the Cybersecurity Platform.
▪ Deployment and management of a suite of cybersecurity tools that provide detection of anomalous activity, identifying threat indicators.
▪ Strategic leadership and communications of work products that are aligned with the program’s cybersecurity priorities and federal laws and mandates.
1.2 Scope
The contractor shall provide:
1. Contract and Project Administration Services
2. FDA Cybersecurity Platform Support Services
3. FDA Cybersecurity Capabilities Support Services Framework Modernization Plan
4. Strategic Communications and Leadership - Advance the FDA Cybersecurity Posture
2.0 Requirements
2.1 Contract and Project Administration Services
The contractor shall:
▪ Provide project management for all phases of the requirements, in accordance with Project
Management Body of Knowledge (PMBOK) standards.
▪ Ensure meeting notes are taken and formally documented for all contractor attended meetings both formal and informal.
▪ Provide responsibility assignment matrix, commonly called RACI, documentation for all phases of the requirements.
▪ Create and update EPLC documents to support all task sections and operate all provided solutions throughout all phases. [Quarterly EPLC Documents]
▪ Provide the Government Technical Lead proof of completion for acceptance after each phase is completed. [Quarterly EPLC Documents]
4 | P a g e
▪ Assign manufacturer’s technical support services to authorized FDA IT Specialists. FDA may designate up to five (5) concurrent authorized users.
▪ Provide at a minimum (quarterly) knowledge transfer to FDA staff throughout all phases for all solutions.
▪ Coordinate project plans and status with FDA engineering and management stakeholders.
▪ Prepare a Contract Binder File that includes reports (i.e. weekly status, monthly status monthly, system utilization, trouble call, burn rates, project schedules, risk, analysis After Action Reports
(AAR) and adhoc reports). [Contract Binder File]
▪ Perform as the primary contact for all issues, escalation and standard communications with FDA engineering and management.
▪ Manage/supervise all contractor staff.
▪ Ensure quality management of all contract deliverables.
▪ Develop and maintain action items, issues, risks, and mitigation recommendations.
2.2 FDA Cybersecurity Platform and Capabilities Support Services
▪ Provide Splunk (Cybersecurity Platform) administration support.
▪ Implement, document and manage data ingestion schedule and priorities.
▪ Capture (ingest) log and report data from cybersecurity tools into the Cybersecurity Platform.
▪ Tune the Cybersecurity Platform environment and optimize the ingestion of log event data to increase storage efficiencies.
▪ Ensure the availability of storage space.
▪ Recommend, create, implement, update and maintain SIEM dashboards to address FDA threat activities or cyber business requests.
▪ Support the network connectivity of the Cybersecurity Platform environment between the FDA
Ashburn and White Oak Data Centers.
▪ Detect and respond to Cybersecurity Platform outages within one (1) hour.
▪ Support engineering requests from FDA to integrate new or enhance existing DHS CDM and HHS cybersecurity capabilities.
▪ Develop, update and provide a Cost Model as a chargeback to Center customers. [Splunk Cost
Model]
▪ Support, develop and submit documentation for FDA IT Change Control Board (CCB) – Request for Change (RFC) and
▪ Support the update EPLC documentation such as procedure guides.
▪ Provide After Action Reports (AAR) for all planned and unplanned outages.
▪ Update diagrams and procedure documents necessary for the operations.
▪ Implement data exchange and integration between FDA RSA Archer, ServiceNow, McAfee ePolicy, McAfee Cloud Access Security Broker (CASB) solution and Tenable environments.
▪ Upon request, provide technical expertise to the Advanced Forensic and Insider Threat Team’s restricted area of the Cybersecurity Platform.
5 | P a g e
▪ Upon request, provide operating system level support for network administration and scripting
(e.g. LINUX Commands, UNIX Scripts, APIs, ) (Linux commands) for FDA Cybersecurity
Capabilities (Table 3).
2.3 FDA Cybersecurity Capabilities Support Services Framework Modernization Plan
▪ Identify emerging cybersecurity roles, responsibilities and potential technical solutions.
▪ Review mission objectives and priorities and recommend improvements to tailor processes to
FDA Cybersecurity Program.
▪ Update the Recruitment and Retention Strategy that aligns with the Cybersecurity Framework.
▪ Review and recommend employee engagement and training programs that improve key technologies of Splunk, RSA Archer and core engineering skills as well as leadership and communications skills.
▪ Review current FDA Cybersecurity Workforce documents and identify efficiencies for
Cybersecurity Framework.
▪ Develop and implement executive reports and dashboard tailored to FDA executive leadership.
[Advance the FDA Cybersecurity Posture Success Journal and Monthly Executive
Dashboards/Slides]
▪ Support the code upgrades necessary to operate the digitized personas on the FDA approved
SharePoint environment.
▪ Provide surge support for critical outages for the digitized personas on the FDA SharePoint environment.
2.4 Strategic Communications and Leadership - Advance the FDA Cybersecurity Posture
To “Advance the FDA’s Cybersecurity Posture”, the contractor shall:
▪ Provide strategic communications aligned to federal laws and priorities (Table 1) via dashboards, PowerPoint slides, Adobe PDF and Word documents that illustrates how the contract work products positively impacts the protection of FDA data and information. The communications must be impactful to the FDA’s public health mission and at a level consumable by the program’s key senior executive stakeholders (Table 4). [Advance the FDA Cybersecurity
Posture Success Journal and Monthly Executive Dashboards/Slides]
Table 4: FDA Cybersecurity Counterintelligence and Insider Threat Program Senior Executive Stakeholders
FDA Chief Information Security Officer (CISO) FDA Chief Information Officer (CIO)
FDA Chief Operating Officer (COO)
FDA Chief Technology Officer (CTO)
FDA Chief Financial Officer (CFO)
FDA Center-based Associate Director CIO (ADCIO) FDA Commissioner
HHS Secretary
6 | P a g e
HHS CIO, CISO and Officer of Inspector General
Department of Homeland Security
Congress
2.5 Transition In
The contractor shall [Transition In Documentation]:
▪ Provide transition services that involve the identification and collection of available documentation within 15 calendar days after first contractor staff receives the FDA Badge.
Written documentation for the Cybersecurity Platform environment and related projects resides within a SharePoint site. Additional strategic documentation may be available from the OIS executive staff.
▪ Within the calendar days listed, implement transition staffing plan on the following schedule:
o 30 calendar days: At least 70% of the staff, including 100% of the Key Personnel, are in the
FDA onboarding process or possess their FDA badges.
o 50 calendar days: At least 90% of the staff are in FDA onboarding process or possess their
FDA badges.
▪ Within 30 calendar days, identify and document:
o the log event data being ingested by the Splunk environment.
o the existing Splunk dashboards o a roadmap of all the cybersecurity capabilities that exist within the Cybersecurity Platform o the cybersecurity platform storage weekly statistics report
▪ Within 50 calendar days, fully operate the Splunk environment within the FDA Cybersecurity platform:
3.0 Contract Deliverables
The contractor shall provide the following deliverables:
Deliverable Section Description Format Frequency Deliver
To Delivery Method
Project Kickoff Meeting
2.1 Initial project meeting In person
or WebEx
Once, within two day of award
COR and 6design ated
SME
Meeting
Quarterly
EPLC
Documents
2.1 and 2.2
Maintain a document library of FDA Cybersecurity capabilities and update the documentation as needed.
At minimum, documentation should include:
RACI documents
Standard Operating Procedure
(SOP)
Microsoft Word, Excel or Adobe
Quarterly at the end of each Fiscal Year Quarter or upon a major change to the environme nt.
COR and designat ed SME
Email as attachme nt, SharePoi nt
7 | P a g e
Capabilities matrix, Storage Capacity
Ingestion Priority Schedule
Dashboards List
Environment Inventory
Quarterly Knowledge Transfer
Provide a one-hour session of knowledge transfer of the contract activities.
Oral Presentati on
Quarterly OIS Staff Oral Presentat ion
Transition In Documentatio n
2.5 Provide documentation for:
▪ Log event ingestion list
▪ Cybersecurity storage statistics report
▪ Splunk dashboard list
▪ Cybersecurity platform roadmap
Microsoft Word, Excel or Adobe
40 days after award date.
COR and designat ed SME
Email as attachme nt, SharePoi nt
Splunk Cost Model
2.2 Develop and maintain a cost model
for the compute and storage of Splunk ingestion and dashboards
Microsoft Excel
Quarterly at the end of each Fiscal Year Quarter
COR and designat ed SME
Email as attachme nt, SharePoi nt
Advance the
FDA
Cybersecurity Posture Success Journal
2.4 Maintain a success journal
document for future Strategic Communications
Microsoft Word
Weekly COR and designat ed SME
Meeting
Monthly Executive Dashboard/Sli des
2.2 and 2.3
Provide the following monthly reports:
Executive Status Report Dashboard
Microsoft Word/Po werPoint or Adobe
PDF.
Monthly by the 15th day of the month.
COR,
CISO
and SME
Email as attachme nt, SharePoi nt
Weekly Status Report
2.1 Week’s work effort on improving
the FDA’s Cybersecurity Posture.
The Weekly Status Report will server as the meeting minutes.
Microsoft Word/Po werPoint or Adobe
PDF.
Weekly - First business day of the week is preferred.
COR,
CISO
and SME
Email as attachme nt, SharePoi nt
Contract File Binder
2.1 Maintain and update the contract
file binder that includes:
1. Award
2. SOW
3. Invoices
4. Burn Rate report
5. EPLC documents
6. Project Schedules
7. Success Journal
8. Executive Dashboards/slides
9. Ad Hoc reports
10. Change Control Board (CCB)
– Request for Change (RFC)
11. Project PlanGFE Report
12. Closeout Letter
Hard Copy Monthly
Final version Due 5 days prior to the Period of Performanc e (PoP) end date.
COR In Person, stored at the COR Office
8 | P a g e
4.0 Performance Requirements Summary
Adhoc Reports
2.1 Adhoc reports and analysis per
email request by COR
MS
Product or Adobe
Single Instance;
Within two (2) business days
COR Email as attachme nt
Statements Standards/Acceptable Quality Levels (AQLs)
4.1 Maintain the
Cybersecurity Platform availability
The FDA Cybersecurity Platform must be maintained operationally to ensure no disruption to the Splunk environment’s ingestions.
The FDA Cybersecurity Platform must maintain no disruptions to the hardware that cause an outage.
Maintain the security software updates to the operating systems and VMWare environment
4.2 Provide Strategic
Leadership
The FDA Cybersecurity Program is best-in-class in the federal civilian government and has received many praise in government and private industry.
The Contract Program Manager must maintain an active engagement to promoting and advancing the FDA Cybersecurity Program.
Contract program activities will be reviewed monthly to ensure advancement of the FDA Cybersecurity Program.
4.3 GFE Report Provide a detailed inventory list of items issued to the contractor.
Equipment inventory shall identify the contractor staff member. Report will be due quarterly based on the government’s fiscal year calendar of October 1 through September 30; the report is due by the close of business on the final business day of the government fiscal year quarter.
4.3 Provide Executive-level
Reports
Writing, presentations, and graphics must be prepared for executive-level personnel such as the FDA Commissioner, FDA Center Directors, FDA Chief Information Officer, and the FDA Chief Information Security Officer.
(See Table 3.
Content must provide accurate data that reflect FDA’s Cybersecurity Posture.
4.4 Transition In Meet the staffing plan, documentation and operations within the timelines provided.
9 | P a g e
5.0 Key Personnel
See Attachment A for labor category minimum qualifications. The following labor categories are Key Personnel for this task order:
Project Manager Senior Splunk Architect Technical Writer 2
6.0 Period of Performance
The period of performance is a base period of three (3) months with two (2) option periods of six months each in duration.
7.0 Place of Performance
The contractor shall perform the primary work onsite at the following locations:
Food and Drug Administration (FDA) 3 White Flint North (3WFN) Building 11601 Landsdown Street North Bethesda, MD 20852
FDA White Oak Campus 10903 New Hampshire Avenue Silver Spring, MD 20903
Travel to other Washington DC Metro Offices and Centers may be required.
All meetings with Agency staff will be held at various FDA offices in the Washington, D.C. metropolitan area unless otherwise specified.
All meetings will be held in person, onsite unless a meeting is identified as teleconference (via MS Outlook) only or excused by the Contracting Officer Representative (COR).
All locations within 50 miles of the 3 White Flint North Building is considered local travel; the contractor will not be reimbursed for local travel, parking fees and tolls.
The contractor may work at alternate work sites at the discretion of the COR.
FDA Site Requirements
All contractors are required to wear personal protection equipment (PPE) in FDA facilities until otherwise directed. At a minimum, the contractor shall wear a face covering at all times. Guidance may change at any time during the performance of this task order.
8.0 Security and Privacy
See Attachment 1.
9.0 Section 508 Standards
10 | P a g e
Section 508 standards are applicable to this contract. See clause HHSAR 352.239-74 Electronic and Information Technology Accessibility (December 18, 2015) in the Applicable Clauses and Conditions section.
10.0 Government Furnished Equipment (GFE)/Government Furnished Information (GFI)
The Government will furnish the contract staff with:
a) FDA identification badges that meet HSPD-12 requirement. Identification badges are used for physical and logical access.
b) FDA laptop computers with FDA images for staff performing work which requires access to FDA systems (e.g., administrators and those needing access to FDA e-mail accounts etc.). Laptops used to access FDA resources shall be imaged with the FDA workstation image, joined to the FDA domain, and managed as FDA desktops/laptops. As required, laptop/desktop configurations may include additional monitors, computer keyboards and mouse.
c) Office space and furniture will be provided only to staff whose primary office is at the Government facility in order to complete these tasks.
d) Other equipment such as mobile devices (tablets, Blackberries, etc.) will be provided only if such equipment is required to complete contract activities.
I. ** Use of non-FDA authorized external storage is prohibited i.e. USB, Hard Drives, etc..
e) FIPS 199 Security Categorization and System Security Plans for each system.
f) The Government will work directly with the Contractor to provide information required during the performance period including, but not limited to, access of any forms, publications, and documents.
The COR will be responsible to determine the adequate number of workstations and equipment post award. The contractor will not be responsible for providing equipment for work performed on the FDA network. The COR will ensure that adequate resources are provided to the contractor. FDA may provide computers or network access to contractor employees working at the contractor’s facility.
The furnished equipment is only authorized for transaction of official Government business and shall not be used for personal business. Personal long-distance calls are not authorized and the cost of all personal long-distance calls made shall be deducted from the contractor's invoice. Telephones, facsimile machines and computer equipment are subject to communications security monitoring at all times. The cost of replacement Government furnished equipment (GFE) as a result of contractor negligence may be deducted from the contractor’s invoice. The contractor may be issued keys (physical and/or electronic). The contractor shall safeguard the keys from loss, theft or destruction, and must display all keys signed for at scheduled or unscheduled key control inspections. The contractor shall be required to reimburse the Government for lost keys, or lockset (if locksets are required to be replaced) as a result of lost keys. The cost of replacement of keys/locksets may be deducted from payments to the contractor.
Contractor Negligence
Any loss, damage, or mishandling of FDA IT equipment or assets that is directly attributed to contractor negligence shall be the responsibility of the contractor. The contractor shall be required to reimburse
11 | P a g e the Government at the full retail cost of the asset(s). This reimbursement shall be deducted against the contractor’s monthly payment.
11.0 Order Type
This is a labor hour task order.
Government Points of Contact Contract Specialist Contracting Officer Michelle Dacanay Phillip Frame 4041 Powder Mill Road 4041 Powder Mill Road Room 41025B Room 42053 Beltsville, MD 20705 Beltsville, MD 20705 Phone: 301-796-0447 Phone: 240-402-7578 Email: Michelle.Dacanay@fda.hhs.gov Email: Phillip.Frame@fda.hhs.gov
Contracting Officer’s Representative Provided at award
12.0 Contractor Personnel Security Clearance Standards and Residency Requirements (October 2017)
This is applicable for this task order. Reference base contract terms and conditions for complete requirements.
The contractor shall provide staff who can obtain an active Public Trust, Moderate Level Tier 2S (previously Level 5) background investigation.
13.0 Clauses
352.239-74 Electronic and Information Technology Accessibility (Dec 2015)
(a) Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, all electronic and information technology (EIT) supplies and services developed, acquired, or maintained under this contract or order must comply with the “Architectural and Transportation Barriers Compliance Board Electronic and Information Technology (EIT) Accessibility Standards” set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in 36 CFR part 1194. Information about Section 508 is available at http://www.hhs.gov/web/508. The complete text of Section 508 Final Provisions can be accessed at http://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards.
(b) The Section 508 accessibility standards applicable to this contract or order are identified in the Statement of Work or Specification or Performance Work Statement. The contractor must provide any necessary updates to the submitted HHS Product Assessment Template(s) at the end of each contract or order exceeding the simplified acquisition threshold (see FAR 2.101) when the contract or order duration is one year or less. If it is determined by the Government that EIT supplies and services mailto:Michelle.Dacanay@fda.hhs.gov mailto:Michelle.Dacanay@fda.hhs.gov mailto:Phillip.Frame@fda.hhs.gov mailto:Phillip.Frame@fda.hhs.gov
12 | P a g e provided by the contractor do not conform to the described accessibility standards in the contract, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the contractor at its own expense.
(c) The Section 508 accessibility standards applicable to this contract are:
• Must meet WCAG 2.0 A and AA
• E101.2 Equivalent Facilitation (Appendix A, Application and Scoping Requirements)
• E203 Access to Functionality (Appendix A, Application and Scoping Requirements)
• E204 Functional Performance Criteria (Appendix A, Application and Scoping Requirements)
• E205 Electronic Content (Appendix A, Application and Scoping Requirements)
• 302 Functional Performance Criteria (Appendix C, Functional Performance Criteria and Technical Requirements)
• Electronic content must be accessible to HHS acceptance criteria. Checklist for various formats are available at http://508.hhs.gov/, or from the Section 508 Coordinator listed at https://www.hhs.gov/web/section-508/additional-resources/section-508-contacts/index.html. Materials that are final items for delivery should be accompanied by the appropriate checklist, except upon approval of the Contracting Officer or Representative.
• E207 Software (Appendix A, Application and Scoping Requirements)
• E208 Support Documentation and Services (Appendix A, Application and Scoping Requirements)
• Chapter 5 Software (Appendix C, Functional Performance Criteria and Technical Requirements)
• Chapter 6 Support Documentation and Services (Appendix C, Functional Performance Criteria and Technical Requirements)
(d) In the event of a modification(s) to this contract or order, which adds new EIT supplies or services or revises the type of, or specifications for, supplies or services, the Contracting Officer may require that the contractor submit a completed HHS Section 508 Product Assessment Template and any other additional information necessary to assist the Government in determining that the EIT supplies or services conform to Section 508 accessibility standards. Instructions for documenting accessibility via the HHS Section 508 Product Assessment Template may be found under Section 508 policy on the HHS website: (http://www.hhs.gov/web/508). If it is determined by the Government that EIT supplies and services provided by the contractor do not conform to the described accessibility standards in the contract, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the contractor at its own expense.
(e) If this is an Indefinite Delivery contract, a Blanket Purchase Agreement or a Basic Ordering Agreement, the task/delivery order requests that include EIT supplies or services will define the specifications and accessibility standards for the order. In those cases, the contractor may be required to provide a completed HHS Section 508 Product Assessment Template and any other additional information necessary to assist the Government in determining that the EIT supplies or services conform to Section 508 accessibility standards. Instructions for documenting accessibility via the HHS Section 508 Product Assessment Template may be found at http://www.hhs.gov/web/508. If it is determined by the Government that EIT supplies and services provided by the contractor do not conform to the described accessibility standards in the provided documentation, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the contractor at its own expense.
(End of clause)
File details come from the government source that posted it. Updated .