J6_RFTOP_0001_-_Performance_Work_Statement_(PWS)_entitled_Domain_1_-_Information_and_Communication_Technology.docx

DOCX document 85 KB Posted

Attached to
National Prevention Information Network (NPIN) Federal contract opportunity
Solicitation number
2014-N-15803
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

Attachment J6 as amended

View the file

Other files for this federal contract opportunity

Other files attached to National Prevention Information Network (NPIN), newest first.
File Type Posted
RFP_2014-N-15803_AMENDMENT_00003.pdf PDF
QA_2_-_Business_Questions.docx DOCX document
SF-30_2014-N-15803_00002.pdf PDF
J8_Technical_Specifications_for_NPIN_Products_and_Services_-_Nov_2013_to_CDC.docx DOCX document
QA_3_-_RFTOP_00001_Questions.docx DOCX document
RFP_2014-N-15803_as_amended_00002.pdf PDF
J3_PUBLIC_VOUCHER_FOR_PURCHASES_AND_SERVICES_OTHER_THAN_PERSONAL.pdf PDF
QA_1_-_General_Questions.docx DOCX document
QA_4_-_RFTOP_00002_Questions.docx DOCX document
J9_NPIN_Software_and_technical_information.xlsx XLSX spreadsheet
J7_RFTOP_0002_-_Performance_Work_Statement_(PWS)_entitled _Domain_2_-_Communication_and_Education.docx DOCX document
RFP_2014-N-15803_Amendment_00001.pdf PDF
Attachment_J1_-_ACH_Vendor-Miscellaneous_Payment_Enrollment_Form.pdf PDF
Attachment_J7_-_RFTOP_NPIN__-_Task_Order__2-_2014-N-15803.pdf PDF
Attachment_J2_-_Past_Performance_Questionnaire_Survey.pdf PDF
Attachment_J3_-_Public_Voucher_for_Purchases_and_Services_Other_Than_Personal.pdf PDF
Attachment_J5_-_Quality_Assurance_Surveillance_Plan_(QASP).pdf PDF
Attachment_J6_-_RFTOP_NPIN__-_Task_Order__1_2014-N-15803_.pdf PDF
NPIN_Solicitation_2014-N-15803.pdf PDF
Attachment_J4_-_Government_Owned-Furnished_Equipment_Inventory_List.pdf PDF
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT J.6

National Prevention Information Network (NPIN) Solicitation #2014-N-15803 Request for Task Order Proposal #0001 – Performance Work Statement (PWS) Title: “Domain 1: Information and Communication Technology”

C.1. BACKGROUND AND NEED

The National Center for HIV/AIDS, Viral Hepatitis, STD, and TB Prevention (NCHHSTP) is part of the Centers for Disease Control and Prevention (CDC), an agency of the U.S. Department of Health and Human Services (HHS). It is one of three national Centers housed within CDC’s Office of Infectious Diseases (OID).

The National Center for HIV/AIDS, STD, and TB Prevention (NCHSTP) was established in 1994 to bring together most of CDC’s HIV prevention activities under a single organizational home with sexually transmitted disease (STD) prevention and tuberculosis (TB) elimination programs. In 2006, CDC’s Division of Viral Hepatitis (DVH) was added, and the Center was renamed the National Center for HIV/AIDS, Viral Hepatitis, STD, and TB Prevention.

The diseases addressed by NCHHSTP share a number of commonalities. They have similar or overlapping at-risk populations—including racial and ethnic minorities, men who have sex with men (MSM), and injection drug users (IDUs). These diseases also have important interactions. Those who are infected with certain STDs, such as syphilis or gonorrhea, are at greater risk for HIV infection. Likewise, those who are infected with HIV are far more susceptible to TB disease because their immune systems are weakened.

These diseases also share similar social determinants, including poor access to health care, stigma, discrimination, homophobia, and poverty. In the area of prevention and control, effective, science-based interventions exist to reduce the burden of TB, viral hepatitis, most STDs, and HIV.

A. Partnerships

NCHHSTP works in collaboration with governmental and nongovernmental partners at community, state, national, and international levels with a goal of creating and strengthening mutually beneficial strategic relationships with other individuals, organizations, and networks that strengthen HIV/AIDS, viral hepatitis, STD, and TB prevention and control by producing solutions that no individual entity working independently can accomplish.

NCHHSTP provides leadership and strengthens related efforts of other Federal agencies without duplicating efforts. NCHHSTP coordinates its efforts with several other agencies within HHS. For example, the Health Resources and Services Administration (HRSA) is authorized under the Ryan White HIV/AIDS Treatment Modernization Act to support treatment programs for people living with HIV and AIDS, and HRSA uses data from NCHHSTP’s surveillance systems to guide funding for these programs. NCHHSTP HIV/AIDS surveillance data are also used to guide funding for the U.S. Department of Housing and Urban Development’s (HUD’s) Housing Opportunities for People with AIDS program.

NCHHSTP funds prevention efforts, demonstration projects, capacity-building efforts, and surveillance activities in state, local, and territorial health departments, as well as community-based organizations (CBOs) and national organizations. In addition to funding traditional public health activities, NCHHSTP works with stakeholders in network partnerships and collaborative partnerships. As defined by NCHHSTP, network partnerships include individuals, groups, and organizations that routinely exchange ideas and information for mutual benefit about HIV, viral hepatitis, STDs, and tuberculosis. Collaborative partnerships are mutually beneficial collaborations to prevent, care for, and/or treat HIV, viral hepatitis, STDs, and tuberculosis, with a particular focus on reducing health disparities. These collaborations can be formal agreements or informal arrangements and are generally characterized by goal sharing, agreeing to explicit commitments, and promoting horizontal communication.

B. NPIN Program

NCHHSTP’s primary mechanism for supporting network partnerships is the National Prevention Information Network (NPIN).

NPIN, at its inception as the CDC National AIDS Clearinghouse, was designed to facilitate the sharing of information and resources among individuals, organizations, and networks working in HIV prevention, treatment, and support services. Today, NPIN remains an important source of CDC and partner evidence-based information and resources, serving professionals dedicated to the prevention of HIV, viral hepatitis, STDs, and TB, through digital media channels, with most NPIN products services are accessible to the general public.

NPIN has the following objectives:

1. To support CDC and NCHHSTP efforts to provide timely information and resources to prevention partners through innovative approaches to knowledge/information transfer.

1. To connect partners in public health through collaborative communication, innovative technology solutions, and customer service.

1. To provide Web-based online databases, information resources, and technical assistance via online support.

1. To support and apply innovation using digital channels to enhancing connection among and engagement with prevention partners and stakeholders to maximize health impact of NCHHSTP’s programs.

Early efforts were clearly “demand-driven” as NPIN and its predecessor, the CDC National AIDS Clearinghouse, was responsive to all legitimate information needs and the resulting pressures of increasing demand during the height of the AIDS epidemic. In recent years, the growth of digital channels, including Web, social media, and mobile media, which offer new ways to disseminate information and additional sources of information expanded the services and products of NPIN, accelerating the need to be responsive to current and emerging user needs, and to take advantage of evolving technology. In addition, the importance of curating the best resources to and among partner organizations has been heightened, requiring increased sophistication in selecting and promoting health information relevant to NCHHSTP program efforts.

C.2. PROJECT OBJECTIVE

The purpose of this contract is to provide information technology database services for the NPIN Program.

C.3. SCOPE OF WORK

The contractor shall provide services to implement the CDC NPIN program by executing work in many of the following domain and focus areas, as defined in the NPIN contract:

Domain
Focus Area
1. Information and Communication Technology
1.1 - Digital Media Channel Development, Web Content Management System (WCMS), Digital Media Metrics (web analytics) and Enhancement

1.2 - Database Development, Analysis, and Management

1.3 - Special Data Products

C.4. TECHNICAL REQUIREMENTS –

As an independent organization and not as an agent of the Government, the contractor shall furnish all necessary personnel, facilities, supplies, and equipment, as appropriate, to provide CDC with required scientific, technical, and operational services, within the general work when necessary the government shall provide government furnished equipment to ensure the contractor has the ability to achieve the parameters set forth in this Statement of Work. Contractor performance and all resulting deliverables must adhere to all federal, HHS, and/or CDC IT security policies and procedures. All resource materials produced or maintained under this contract, including databases, all information products, all data, mailing lists, websites, telephone protocols (Intellectual Property), etc., are the property of the Government.

Domain 1. Information and Communication Technology

Task 1.1 Digital Media Channel Development, Web Content Management System (WCMS), Digital Media Metrics (web analytics) and Enhancement

0. The CDC NPIN Websites The contractor shall operate and maintain an existing Internet presence offering HIV, Viral Hepatitis, STD, and TB information services and products offered by NCHHSTP and/or deemed important to prevention efforts. It shall also serve to connect NCHHSTP stakeholders and partners with interactive features, such as web communities, discussion boards, blogs, etc. The domain sites shall serve as the primary access point to CDC and CDC NPIN resources and services—those websites are as follows: http://www.cdcnpin.org, http://hivtest.cdc.gov, and www.findtbresources.org. All domains (hence force referred to as CDC NPIN Web sites—all CDC websites URL are transitioning from .org to .gov) will be made available to the contractor, including the password-protected extranet for CDC NPIN project management and reporting. Technical infrastructure/ specifications for the four associated Web sites to include web content management systems (CMS) (e.g., Percussion, Drupal), content delivery networks, technology stacks, etc. are included in Attachment: Technical Specifications for Current NPIN Products and Services.

The contractor shall maintain these specified websites and the integrity of the information contained therein on these domains or other domains as agreed upon by the government. The CDC NPIN website has been designed and managed with the purpose of providing partners full access to NPIN’s products and services via a fully interactive, dynamic web-based platform, which addresses the best practices in site architecture, quality assurance, web posting, web maintenance, web evaluation, reporting, web content management and usability/user experience.

The domain http://www.cdcnpin.org includes access to databases that provide information about prevention services, resources, and materials (See Section Database Development, Analysis, and Maintenance). The website also allows for downloading materials/publications. The contractor shall be responsible for identifying, collecting, or locating appropriate new materials, obtaining clearances or approval for their use, and organizing the information for users (See Section Web-based Information Development and Management).

Current website features include digital web, mobile, social, and marketing capabilities, but are not limited to the following:

Digital Web and Mobile

· Optimized user experience that render content in: 1) mobile-responsive format for multiple device types and platforms (mobile web, mobile apps(to include possibility porting over SMS KNOWIT code to a mobile app), 2) utilize adaptive content strategy for multiple users and technologies, 3) is user-friendly, useful and informed by user needs, and 4), use searchable databases and the latest database technology;

· Topical content with links to priority to CDC and other approved materials and resources or utilize content syndication from CDC or third party sources when necessary;

· Topic specific “microsites” (for testing campaign pages such as “Testing Makes Us Stronger,” ”Take Charge. Take the Test,” “Reasons,” STD Awareness Month, and possible other testing campaigns);

· Special “splash pages” to highlight events and/or special resources;

· Technologies to include online video, images, multimedia, webcasting, and live streaming capabilities for mobile and web applications.

Social

· Integrated social experience into NPIN websites, including social features such as commenting, microblogging, document/photo/video sharing, discussion boards, and blogs.

Marketing

· Include subscriptions to electronic mailing lists (listservs) and third-party social media sites, such as Twitter and Facebook;

· RSS feeds as a part of content syndication strategy

Please see technical specifications for the current website are included in Attachment: J.5 Government Property List. The CDC NPIN websites and e-mail addresses shall be prominently placed on all marketing materials. Inquiries received by e-mails shall be responded to by e-mail within 1 business day of receipt. Assuming that the websites and the e-mail system will provide the primary information channels, the contractor shall also shall answer requests for information that are received through the mail. The CDC NPIN post office box number shall be included in all marketing materials. Requests received by mail should be answered within 2 business days. If locating the information will take longer, requestors shall receive a communication (form letter mail or e-mail) stating that there will be a delay and forecasting when the request will be filled.

The contractor shall recommend appropriate and incremental enhancements, redesigns in conjunction with refreshed content for all the three web domains throughout the life of the contract. The government must approve these updates/changes. The domains are http://www.cdcnpin.org, http://hivtest.cdc.gov, and www.findtbresources.org. The contractor shall provide recommendations to enhance interactivity, capitalize on Web 3.0 technologies and applications, and utilize tactics, search optimization, user testing, and user-generated content.

The contractor shall be responsible for monitoring and reporting on the metrics for all existing CDC NPIN websites and tools. These statistics will be reported to the government, and based on these statistics and other evaluative methodologies the website and content strategy should be refined and improved. On a regular basis, the contractor shall review and update appropriate sections to ensure that data and links are accurate and shall recommend removal of outdated items.

The Contractor’s support for the CDC NPIN websites shall include the following:

· Maintenance and enhancement for websites redesigns, when needed. Maintenance and enhancements should include and following user-centered design principles and incorporating appropriate usability testing, when needed, this action should include best practices for the usability and effectiveness of the website’s search function.

· Conversion of documents and materials into web-appropriate formats and best practices for a multi-browser, multi-platform environment.

· Conversion of images, audio, or video into web-appropriate formats, including streaming video.

· Use of cross-platform (Mac and Windows) hardware and software for preparing and testing web-based products, including the top five browsers that access the site.

· Use of appropriate web-based products, programming languages, and applications such as responsive design, Drupal, and other new technologies that are deemed appropriate by the government.

· Achievement and maintenance of high visibility for the CDC NPIN websites utilizing Internet search engines to include meta tagging using keywords and descriptors and their requirements to catalog and maintain a current index of website content and links.

· Ascription of appropriate metadata to content as well as establishing and maintaining a CMS using the CDC standard terminology to ensure the accurate presentation and search retrieval of the content.

· Assurance that all newly added content is appropriately cleared by the CDC Contract Officer Representative (COR) , website content manager, or designated contact prior to posting.

· Assurance that all webpages and materials available on websites are compliant with CDC Section 508 Policies (See Section SECURITY COMPLIANCE, PROJECT MANAGMENT, AND SECTION 508 GUIDANCE).

· Provision of web analytics for all web domains using systems such as Google Analytics, Omniture, SiteCatalyst and other web analytics programs approved by the government.

· Maintenance of NPIN servers, storage area networks (SAN), and backup infrastructures at the non-Atlanta locations.

· Assurance that all third party software components within NPIN systems have not reached an end-of-life determination as indicated by the software providers.

· Management of virtualized hosting environments.

· Maintenance of outstanding customer support and application management.

· Resolution of problems quickly, with less risk, and at a very competitive cost.

· Evaluation and recommendations on cost-effective infrastructure changes taking into account forecasted service levels due to increased workload and recommended timing of hardware and software upgrades needed to maintain agreed upon service levels.

· Provision of a staff member with Certified Information Systems Security Professional (CISSP) certification and expert knowledge of National Institutes of Standards and Technology (NIST), Federal Information Security Management Act (FISMA), and Federal Information System Controls Audit Manual (FISCAM) statutes and regulations. The security manager shall manage NPIN’s Certification and Accreditation process. In addition, the security manager shall develop, implement, and validate security controls in NPIN, including least privilege access to systems and adherence to password policies, in concert with the NCHHSTP Information System Security Officer (ISSO) in compliance the agency’s Chief Information Security Officer.

· Emphasis on least privilege access to infrastructure and hosted systems, and limitations of access to approved personnel for administrative rights to servers, operating systems, database systems, storage systems, and other components of NPIN.

· Maintenance of a list of problems and action items, including those from NPIN and the NCHHSTP Health Communication Science Office (HCSO) management, and tracking of each item through the duration of this contract. Provision of an Enterprise/Systems Architect with knowledge and experience in data center operations and systems hosting.

· Benchmark web hosting, security, and software development against key performance indicators and best practices within the industry.

· Incorporation of appropriate webpage date-stamping in accordance to federal web policy, per CDC Contract Officer Representative (COR).

The contractor shall review the website with appropriate content and resources, and functionality is mirrored in English and Spanish on the: www.cdcnpin.org, hivtest.cdc.gov, www.findtbresources.org and websites.

Support for www.findtbresources.org shall include maintenance of a database application, which supports the website and the monthly design and distribution of an electronic newsletter. The Division of Tuberculosis Elimination shall be responsible for the content of the newsletter and website.

For content translated in alternative languages and multiple formats, the contractor shall design and develop the appropriate content management process to ensure all revisions of the content are updated when the original is changed.

Integration with Other Contractor Efforts: Interaction will occur with other contractor computer programmers/web developers and health communication staff. The contractor will interact with IT contractors supporting CDC activities for the cdc.gov domains. Key governing requirements affecting the work include the Office of Associate Director for Communication (OADC) for ensuring the accuracy and integrity of information disseminated by the federal government; federal regulations and web policies ensuring the accessibility of all electronic information to persons with disabilities (i.e., Section 508 compliance standards); and CDC policy regarding assurance of information integrity and program clearance.

The contractor shall ensure that all content and resources posted meet Section 508 compliance requirements (http://www.hhs.gov/web/508/index.html). Additionally, each year, the contractor should plan to make approximately 25 PDF documents (5 pages on average per document) of partner materials and up to 5 videos or podcasts (under 10 minutes each on average) Section 508 compliant. These resources will be provided by partners for posting and/or distribution through CDC NPIN channels.

The contractor shall report all problems encountered in a timely manner and in accordance with the contractor’s CDC-approved Standard Operating Procedures (SOP). Upon contract award, CDC will provide the contractor with the organization’s current SOP. Throughout the term of this task order contract, the contractor will review CDC’s SOP least once per year.

Task 1.1.2 Electronic Mailing Lists (listservs) and Other Customized Information Dissemination Features Information users and seekers need and prefer customized communication whenever possible. Specific information, tailored to the user’s unique situation or profile, provides easy access and relevant information to prevention partners.

The electronic mailing list feature is a popular service of CDC NPIN. Current electronic mailing lists include Connections–a bi-monthly e-Newsletter, TB Educate, TB Behavioral and Social Science, and Stop TB in the African-American Community.

The contractor shall support all existing electronic mailing lists (approximately 20 electronic mailing lists) as needed, which may include supporting moderated discussion lists. The contractor shall examine existing lists and use current technology to maintain the existing lists. It is important that the contractor create a key performance indicator (KPI) system to optimize these lists, and demonstrate how these lists will be curated and maintained to promote new NPIN products and services.

Task 1.1.3 Webcasts and Similar Technology The contractor shall provide webcasting capabilities (e.g., technical assistance seminars, meetings with grantees, etc.) for access by CDC target audiences

Task 1.2 Database Development, Analysis, and Maintenance

NCHHSTP Database Development Operations

CDC NPIN maintains databases that link users to HIV/AIDS, viral hepatitis, STD, and TB information and services. Users can search these databases through the NPIN website. The contractor shall provide database administrators to manage functional database needs and provide consolidated database servers where customers do not have system administrator privileges. Currently, NPIN manages more than 16,000 records, almost all of which are on Microsoft SQL Servers 2008. System and application-specific database servers will be managed by the contractor. These include databases that are part of mission critical systems requiring 8x5 break/fix and second site disaster recovery capabilities that CDC will provide.

The current CDC NPIN services include public access to the following databases:

· Resources and Services Database

· CDC NPIN Downloadable Materials Database

· Funding Database

· The Campaign Resource Database

CDC NPIN databases shall be reviewed for their usefulness and each shall be reconstructed to be relevant to current customer needs. These databases should take advantage of the latest technology and methodology for website design and search strategy/information retrieval. Continuous evaluation, assessment of customer needs, and validation of information will be required to ensure their relevancy. Each database has specific purposes, record formats, and search strategies. The CDC NPIN website should reflect use of emerging technology and best practices, including search functionality, to provide user access to CDC NPIN databases. The contractor shall:

· Upgrade database and associated products as required.

· Monitor and optimize database performance, security, and access to databases.

· Assume responsibility for any performance and production problems.

· Coordinate the allocation of system storage and planning for and forecasting future space requirements.

· Create primary database storage structures, database objects, and migration scripts to modify structures and objects.

· Modify database structures as needed.

· Develop backup and recovery procedures and techniques.

· Perform and validate backup procedures ensuring that data can actually be recovered in the event of a catastrophic incident. Periodically provide tests results of recovery assurance.

· Develop data archive procedures and methods.

· Establish security roles and database access rights and controls.

· Estimate storage requirements for application.

· Specify modifications of the database structure for an application.

· Troubleshoot database software and perform migrations to new platforms and/or new software versions. Migrations to new platforms must limit customer downtime.

· Design and implement database backup and restore strategies. Failed nightly backups are identified and resolved by 9:00 am the following morning. Failed backups during the course of the business day are identified and resolved within 2 hours.

· Schedule, automate, execute, and monitor job and system performance as related to SQL Server

· Resolve any connectivity issues.

· Provide database support after hours as needed for systems with after-hours support requirements.

· Information consistency.

· Improved end-user access to a wide variety of data.

· Increased data consistency.

· Providing a place to combine related data from separate sources.

· Empowering end-users to perform any level of ad-hoc queries or reports without impacting the performance of the operational systems.

· Potentially lower computing costs (by reducing the need to maintain separate databases) and increased productivity.

· Creation of a computing infrastructure that can support changes in computer systems and business structures.

· Supports application goals—decision support, predictive modeling, and planning.

· Supports metadata goals—business term definition, business rule definition, and enforcement of information consistency.

· Supports information goals—accessibility, consistency, security, and adaptability.

· Mine databases to understand who is using the data and how the data is being used.

· Data dictionaries to describe in detail the information within the NPIN databases.

· Machine-readable data formates such as CSV, XML, RDF (as RDF/XML or N3), and JSON.

Incorporate mobile technology—establish interfaces with current databases and push data real-time through social and mobile channels. This provides real-time dissemination of information and can support real-time collection of data for analysis.

The databases are core offerings on the CDC NPIN website. For monitoring purposes, the contractor shall propose a monitoring plan of database usage that reflects current methods and best practices.

The “Database Management Plan” should address currency and completeness of the information contained in each database and relevancy of the information to customer needs.

The Plan, due within 90 days of award, shall be comprehensive and shall assure the currency, completeness, and relevancy to customer needs of the information contained in each of the four databases listed above. The plan should also address the preparation of an Office of Management and Budget (OMB) package with a data entry form that would serve the purposes of the database. The current OMB package for the Resources and Services database expires 3/31/2017 (OMB control #0920-0255).

All databases shall be available on the CDC NPIN website. The contractor shall routinely assess the need for and propose how to provide the widest possible access for CDC NPIN audiences.

The contractor shall provide with the database management plan report on the “Status of NPIN Databases,” including when and how databases were updated and maintained, metrics on their use, and recommendations for alterations in their record formats, content collection procedures, and search engine optimization. This report is due monthly.

The contractor shall ensure that the computer system and support for the databases, approved by the government, is current, complete, and efficient (in cost, appearance, and search functionality) in supporting the various computer-based activities required hereunder, including data entry, management, search, and retrieval (including downloading) and reporting (including providing website statistics on the access of the databases by CDC NPIN website users).

The contractor shall follow a records management policy and plan for the management of records and program documentation that ensures compliance with applicable federal records policies. All federal records must be maintained in accordance with the retention periods and disposition instructions outlined by CDC Records Control Schedules and NARA General Records Schedule (GRS). Applicable Records Management required at CDC includes GRS 20 Electronic Records and GRS 24 Information Technology Operations and Management Records.

The contractor shall ensure that adequate capacity is provided to accommodate these records and to provide access and allow for their delivery in electronic and hardcopy versions to the government at the end of the contract. Current technical specifications for support of the existing databases are included in Attachment J.5: Technical Specifications for Current NPIN Products and Services.

1) Resources and Services Database

This database provides descriptions of more than 16,000 organizations providing services related to HIV/AIDS, viral hepatitis, STDs, and TB. It is estimated that approximately 400 records per year are added to the database. Services include case management, counseling and testing, prevention, education and outreach, health care, support services, housing assistance, and legal counseling.

Current fields of data are:

1. Name, address, and phone number

1. Geographical service area

1. Hours of service

1. Access procedures

1. Types of services and audiences served

1. Information resources produced

Additions to these fields should include at least the following:

1. E-mail addresses

1. Website address

1. Field(s) related to cultural/ethnic characteristics of audiences and operating parameters of the organizations.

1. Languages available

Once a year, this database shall be thoroughly updated, crosschecked, and all data shall be verified. The contractor shall recommend strategies to increase the effectiveness and efficiency of database update and maintenance, including appropriate enhancements/changes to the current automated processes.

2) CDC NPIN Downloadable Materials Database

This database supports tracking and electronic distribution of CDC NPIN materials and third party materials that include grantee materials, partner materials, stakeholder materials or other materials that the government deems appropriate for the materials database. These are available for download from the CDC NPIN website. These materials are additions to the materials database and are not to be confused with the materials or links in the campaign resource database but could be combined. In an effort to move beyond the PDF style cataloging, the material database should all so include categories such as online lesson modules, e-books, quick-tips and video, podcast, infographics, and other multimedia materials.

The contractor shall assure that linkages exist between the CDC NPIN Downloadable Materials Database and the Resources and Services Database so daily changes (additions, corrections, and deletions) are incorporated into both databases.

3) Funding Opportunities Database

The purpose of the funding opportunities database is to provide HIV/AIDS, viral hepatitis, STD, and TB community-based and service organizations with information about private and government funding opportunities. Included are details about eligibility requirements, application processes, and deadlines.

This database is meant to be a starting point for people seeking financial support for HIV/AIDS, viral hepatitis, STD, and TB education, prevention, social/support services, and information dissemination. Users are encouraged to contact funding organizations directly for additional information.

Specific requirements include a system that will provide daily monitoring of Grants.gov, the Catalog of Federal Domestic Assistance, and Commerce Business Daily as well as other standard sources of information regarding federal funding opportunities. Indexes and other sources of private funding shall also be monitored.

Information for the Funding Opportunities Database shall be entered on a daily basis. Data on funding opportunities shall be entered into the database not less than two working days after publication. The contractor shall establish and maintain relationships with major private-sector organizations that provide funding for HIV/AIDS, viral hepatitis, STD, and TB programs and services to ensure that information about their funding opportunities is obtained and is made available in a timely manner. Records shall be purged so that out-of-date material is not present in the database.

The contractor shall also establish and maintain relationships with state and local health agencies that provide HIV/AIDS, viral hepatitis, STD, and TB funding to private agencies to ensure that this information is collected and made available expediently.

The information about each funding opportunity shall include at a minimum:

A. Fund description B. Inclusive target audiences(s) C. Fund subject D. Inclusive target organizations for funding E. Fund location (eligibility) F. Geographic location (eligibility for funding) G. Other eligibility H. Type of funding support I. Funded products J. Procedure contact person K. Fund duration L. Letter of Intent date M. Application deadline N. Intended award date(s) O. Project start date(s) P. Maximum amount, and Q. Fund Identification Number

4) Campaign Resource Database

As stated in the National HIV/AIDS Strategy (NHAS): “The CDC will initiate a CDC-wide review of social marketing and educational campaigns related to HIV, STI, substance abuse and risk behaviors that increase risk of HIV transmission and will work to expand evidence based efforts to achieve maximum impact.” National HIV/AIDS Strategy (NHAS) (Page 16: Step 3.1). By supporting CDC NCHHSTP in executing this step for the NHAS, CDC NPIN will collect, organize, and format the results into a web-based campaign clearinghouse.

NPIN staff will collect examples of successful campaign initiatives, inventories and clearinghouses to gain insight on structure and format for web and print. NPIN will collect federal, state, and local campaign materials on HIV, STI, substance abuse, and risk behavior prevention/care campaigns and assemble them into an intuitive database and format the results into a searchable web-based clearinghouse.

The searchable database will house an inventory of local, state, and national campaigns that offers models and resources for health departments, community-based organizations, and other prevention partners that are planning HIV, Viral Hepatitis, STD, and TB health communication campaigns. It will feature resources geared to reach a variety of audiences.

Listing of search parameters included in the data collection tool:

· Campaign name

· Office name

· Description

· Campaign URL

· Month created

· Year created

· Partner organizations

· Active status

· Date ended

· Campaign medium

· Geographic target area

· Target demographics

· Evaluation information

· Similar campaigns

· Media coverage

· Previously collected evaluation data

· Campaign recommendations

· Reach

· Other information

· Recommendations

· Contact person

· Contact address

· Contact phone #

· Contact Org URL

· Image of campaign logo for website

Task 1.3 Special Data Products

1.3.1 Creation of Special Data Products Using CDC NPIN Databases

The contractor shall recommend appropriate fields and provide access to all Resources and Services Database records and all HIV testing/campaign widgets location records via the NPIN website. Contractor shall leverage and optimize the use of the existing and future NPIN partner database and related data assets to support the priorities and activities of NCHHSTP and prevention partners. Additionally, the contractor will be required to create No More than 30 special subsets of the Resources and Services Database to meet NCHHSTP programmatic needs to include: maintenance, developments and enhancements to existing and new RESTFUL APIs (that provides machine-readable responses), campaign widgets, and special data feeds. The contractor will also develop, test and deploy new data products suited to meet current and emerging needs of NCHHSTP and its partners. The contractor will work with the Contract Officer Representative (COR) to determine specifications and recommendations for delivery.

1.3.2 SHORT MESSAGING SERVICE (SMS) – “KNOWIT code (566948)”: Contractor will provide a mechanism to access SMS texting services to help CDC reach audiences with important health information or emergency notifications using the KNOWIT (566948) short code via wireless carriers (See Section The CDC NPIN Websites). The KNOWIT code will be supported for up to 10,000 texts per month. The code will be utilized to provide a service for consumers looking for HIV testing locations from the NPIN Organizations Database. Consumers will text their zip code to KNOWIT and up to three HIV testing locations (one at a time, with an option to text ‘More’ for additional sites) will be returned to them on their mobile device.

0. Specific tasks include:

1. Supporting 10,000 messages per month

1. Providing texting health campaign support for campaigns based in the Division of HIV/AIDS Prevention (DHAP) and already using KNOWIT (such as Razones)

1. Providing emergency texting service that uses the KNOWIT code and can be implemented within the 10,000 messages per month limit

0. Specific texting requirements:

1. Any potential subcontractors must complete all CDC security requirements and IT requirements as indicated in the clauses of this contract.

Contractor will support the eventual migration of the KNOWIT code if/when a new vendor successfully completes the CDC Certification and Accreditation (C&A) process. Contractor staff will work closely with a potential new vendor to gather the required documentation for a C&A package. Contractor staff will coordinate with the NCHHSTP Security Steward to ensure that all required paperwork/documentation for Office of the Chief Information Security Officer (OCISO) is submitted.

C.5 Quality Control Plan (QCP)

The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s quality control program is the means by which he assures himself that his work complies with the requirement of the contract. The contractor shall develop the QCP in identifying, preventing, and ensuring non-recurrence of defective services. The contractor shall develop submit Quality Control Plan (QCP) to the Contracting Officer (CO) for acceptance within thirty (30) calendar days after award.

C.6 Transition Plan

The Offeror shall provide a Transition Plan for the transition or phase-in of this project as well as phase -out. The plan shall include a technical and management transition approach that is clear and complete including the timeline and resources required for the transition. The Transition Plan shall detail the planned transition methodology in logical sequence to ensure a smooth transition of all projects/tasks/subtasks of the PWS without interruption or degradation of service levels. The plan shall include an approach that ensures the successful achievement while limiting impact to existing programs/projects. The plan shall also include a complete description of risks (cost, technical and performance to both the Offeror and the Government), issues and risk mitigation strategies. Contractors shall also include all transition costs within their task order cost proposal. Please note that the continuity of services clause 52.237-3 is applicable and should be considered in developing your transition plan.

TRANSITION

During the startup period, the Contractor management shall work closely with assigned Government personnel to review facilities, policies and procedures and to develop an implementation plan to provide services outlined in the PWS to CDC.

The contractor shall ensure there will be no service degradation during and after transition. The contractor shall propose a draft Transition Plan and present a finalized Transition Plan for the current requirement at the post award conference.

The contractor shall identify how it will coordinate with the incumbent contractor and/or Government personnel to obtain the knowledge regarding the following:

1. Project management processes

1. Points of contact

1. Location of technical and project management documentation

1. Status of ongoing technical initiatives

1. Appropriate contractor to contractor coordination to ensure a seamless transition

1. Transition of key personnel

1. Identify schedules and milestones

1. Identify actions required of the Government,

1. Establish and maintain effective communication with the incoming contractor/ Government personnel for the period of the transition via weekly status meetings.

Transition Out

The Transition-Out Plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor /government personnel at the expiration of the Task Order. The contractor shall provide a Transition-Out Plan NLT ninety (90) days prior to expiration of the Task Order.

The contractor shall identify how it will coordinate with the incoming contractor and/or Government personnel to transfer knowledge regarding the following:

1. Project management processes

1. Points of contact

1. Location of technical and project management documentation

1. Status of ongoing technical initiatives

1. Appropriate contractor to contractor coordination to ensure a seamless transition

1. Transition of key personnel

1. Identify schedules and milestones

1. Identify actions required of the Government,

1. Establish and maintain effective communication with the incoming contractor/ Government personnel for the period of the transition via weekly status meetings.

C.7 Period of Performance:

The period of performance of this task order will be 12-month base period with four (4) 12-month option years

SECURITY COMPLIANCE, PROJECT MANAGMENT, AND SECTION 508 GUIDANCE

Security Compliance This Statement of Objectives (SOO) requires the successful Offeror to have the ability to host and maintain a system for data collection, management, use, and reporting to support activities funded by the federal government.

IMPORTANT NOTE TO OFFERORS: The following information shall be addressed in a separate section of the Technical Proposal entitled, “Information Security.” Information Security is applicable to this solicitation because all information systems developed, operated, or used by or on behalf of the Federal government must comply with Federal Information Security laws, policies and standards. We provide the following information to assist in the preparation of proposals in order to assure that the existing data system, which would be licensed for use by CDC grantees and CDC employees, meet the security standards described below.

The E-government Act of 2002, (Federal Information Management Act) and the below federal policies dictate the framework for assuring information security for data systems operated by or on behalf of the Federal government. These are summarized below.

OMB Circular A-130 (http://www.whitehouse.gov/omb/Circulars_a130_a130trans4/) establishes policy for the management of Federal information resources, pursuant to a number of laws and regulations, including the Paperwork Reduction Act of 1980 (amended in 1995), the Computer Security Act of 1987, and other laws. Circular A-130 requires all federal information systems to have security plans, emergency response capabilities, designated individuals who are responsible for security, security awareness training, and regular review of the system. Appendix III of Circular A-130, entitled “Security of Federal Automated Information Resources,” establishes a minimum set of controls to be included in Federal automated information security programs; assigns Federal agency responsibilities for the security of automated information; and links agency automated information security programs (such as the DHHS AISSP) with OMB Circular No. A-123

The Federal Information Security Management Act of 2002 (P.L. 107-347) (FISMA) (http://csrc.nist.gov/policies/FISMA-final.pdf) requires each agency to develop, document, and implement an agency-wide information security program to safeguard information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, Offeror (including sub-Offeror), or other source. The National Institute of Standards and Technology (NIST) has issued a number of publications that provide guidance in the establishment of minimum security controls for management, operational, and technical safeguards needed to protect the confidentiality, integrity, and availability of a Federal information system and its information.

Pursuant to Federal and HHS Information Security Program Policies the following standards and guidelines apply:

1. FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf),

1. FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf)

1. NIST Special Publication 800-18, Guide to Developing Security Plans for Federal Information Systems (http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf)

1. NIST Special Publication 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories Vol. 1 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf) and Vol. 2 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf).

1. NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations (http://csrc.nist.gov/publications/PubsSPs.html)

1. NIST Special Publication 800-63, Electronic Authentication Guideline (http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf) The Offeror should demonstrate understanding of security requirements by attaching a Draft Data System Security Plan or information system security plan (SSP). The SSP should be a brief and general narrative description of the system and its integration with the CDC Network Infrastructure.

The initial draft and all subsequent versions of the SSP must be prepared and submitted by the Offeror to the CDC contracting officer and to the CDC Contract Officer Representative (COR), in Microsoft Word compatible format. The successful Offeror shall be responsible for ensuring that the security plan is acceptable to the CDC Contract Officer Representative (COR) and the NCHHSTP Center ISSO as well as any subsequent federal reviewers (e.g., Center and/or HHS officials, OMB officials, etc.). Comments shall be conveyed to the Offeror by the Contract Officer Representative (COR) and/or the contracting officer.

Once an award is made, the Contract Officer Representative (COR)and the contracting officer will review the draft SSP and any subsequent versions and submit recommendations/comments to the Offeror within 14 working days after receipt. The Offeror shall incorporate the Contract Officer Representative (COR) recommendations and submit paper and electronic copies of the security plan to the contracting officer and to the Contract Officer Representative (COR) within five working days after receipt of the Contract Officer Representative (COR) comments. The resultant contract will require the draft SSP to be finalized in coordination with the Contract Officer Representative (COR) later than 90 calendar days after contract award. Also, the successful Offeror, in conjunction with the CDC NCHHSTP ISSO, is required to update and resubmit its SSP to CDC every three years following award or when a modification has been made to its internal system. In addition to developing and maintaining an SSP, the successful Offer or shall be responsible for continuously assessing and assuring information security for the project and for updating the security plan as needed throughout the duration of the agreement.

The SSP is part of the Certification and Accreditation (C&A) process required by the Egovernment Act of 2002 and NIST Special Publication 800-18 and will include selected mandatory controls required by NIST Special Publication 800-53, Volume I & II. The successful Offeror in conjunction with the NCHHSTP ISSO will submit C&A documentation to the CDC Chief Information System Officer (CISO). The successful completion of the C&A documents will result in an award of an Authority To Operate. Based on guidance in FIPS 199 and NIST SP 800-60 the system will be assigned an overall security category (SC) of Low or moderate based on (confidentiality, LOW/MODERATE), (integrity, LOW/MODERATE), and (availability, LOW/MODERATE) impact levels. These impact levels will be initially determined by the Center ISSO and confirmed by the CDC OCISO Certifying Authority as part of the Certification and Accreditation process.

The successful Offeror is responsible for providing pertinent security information to the NCHHSTP ISSO and Security Staff and assisting in completing the below CDC Certification and Accreditation documents. Appropriate security templates will be provided to the successful Offeror by the NCHHSTP Security Staff. Completed documents will be sent to the CDC Chief Information Security Office (CISO) for review, approval and subsequent issuance of an Authority To Operate (ATO)

1. Baseline System Information (BSI)

1. Privacy Impact Assessment (PIA)

1. Host Characterization Worksheet (HCW)

1. System Security Plan (SSP)

1. Security Baseline Worksheet (SBW)

1. Business Continuity Plan (BCP)

1. Risk Assessment Report (RAR)

The Offeror shall respond to the following seven security–associated requirements in the application:

0. Position Sensitivity Designations The following position sensitivity designations and associated clearance and investigation requirements apply under this licensing contract:

Level 5: Public Trust—Moderate Risk (Requires Suitability Determination with NACIC, MBI or LBI). Licensor employees assigned to a Level 5 position with no previous investigation and approval shall undergo a National Agency Check and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .