DODEA SIS RFP HE125420R3001 Amendment 1.pdf
PDF 1 MB Posted
- Attached to
- DoDEA Student Information System (SIS) AMENDMENT 1 Federal contract opportunity
- Solicitation number
- 203001R
- Issued by
- Department of Defense Education Activity
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 1 SIS HE125420R3001.pdf | ||
| TECHNICAL EXHIBIT 1 Current Integrations.pdf | ||
| FINAL SIS Questions from Industry_13Feb2020_V4.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
1. REQUISITION NUMBER PAGE 1 OF 125
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
HE125420R3001 31-Jan-2020
7. FOR SOLICITATION a. NAME b. TELEPHONE NUMBER (No Collect Calls) 8. OFFER DUE DATE/LOCAL TIME
INFORMATION CALL: GEORGETTE HENDRICKSEN 571-372-1452 01:00 PM 02 Mar 2020
9. ISSUED BY CODE HE1254 10. THIS ACQUISITION IS X UNRESTRICTED OR SET ASIDE: % FOR:
DOD EDUCATION ACTIVITY
ATTN: PROCUREMENT DIVISION
4800 MARK CENTER DRIVE
SMALL BUSINESS
HUBZONE SMALL
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
NAICS:
SUITE 05F09-02
ALEXANDRIA VA 22350-1400
TEL:
FAX:
11. DELIVERY FOR FOB DESTINA-
12. DISCOUNT TERMS
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
EDWOSB
8(A)
13b. RATING
511210
SIZE STANDARD:
$41,500,000
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
15. DELIVER TO
CODE
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
16. ADMINISTERED BY
14. METHOD OF SOLICITATION
RFQ IFB
X RFP
17a.CONTRACTOR/ CODE
OFFEROR
FACILITY
18a. PAY MENT WILL BE MADE BY CODE
TELEPHONE NO.
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
SUCH ADDRESS IN OFFER BELOW IS CHECKED SEE ADDENDUM
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
X 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
ADDENDA X ARE
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
ARE
ARE NOT ATTACHED
X 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN 1 29. AWARD OF CONTRACT: REF.
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND OFFER DATED . Y OUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER
(TYPE OR PRINT)
30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
TEL:
EMAIL:
(TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
36. PAYMENT
COMPLETE PARTIAL FINAL
37. CHECK NUMBER
PARTIAL FINAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
Section SF 1449 - CONTINUATION SHEET
CONTRACT LINE ITEM NUMBERS
Offerors shall review Attachment 2 the Price Template to address this section.
PWS
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF DEFENSE EDUCATION
ACTIVITY (DoDEA) School Information System (SIS)
1 General Information
1.1 Agency
1.1.1 The Department of Defense Education Activity (DoDEA) serves the dependents of United States of America military and civilian employees by providing PK-12 instruction to approximately 70,000 students in 162 brick-and-mortar schools and one virtual high school. DoDEA schools are located in 11 countries, seven states, and two territories.
DoDEA operates across ten time zones resulting in schools that are in session every day of the week. Student enrollment is based primarily on deployment of military troops worldwide. In the Americas, DoDEA operates 51 schools located in seven states, Commonwealth of Puerto Rico, and Guantanamo Bay, Cuba. In Europe and the Middle East, DoDEA operates 64 schools located in: Germany, Italy, England, Netherlands, Belgium, Spain, Turkey and Bahrain. In the Pacific, DoDEA operates 45 schools located in South Korea, Japan (mainland and Okinawa), and territorial Guam.
DoDEA's curriculum, resources, and student achievement scores on standardized assessments compare favorably to those of high-performing United States (U.S.) public school systems.
DoDEA Virtual High School (DVHS) is a fully accredited program with teaching hubs in each DoDEA region:
Americas, Europe, and Pacific.
1.1.2 DoDEA schools have various grade configurations, with the most common being K-5, 6-8, 9-12, and K-12. Of DoDEA’s 162 brick-and-mortar schools, 102 schools have students in at least three of the grades K-5; 62 schools with at least one grade 6-8;
and 40 schools with grades 9-12. Of the 6-8 schools, ten are part of an elementary school and five have only grades 7-8.
Table 1: Student Enrollment – SY 2019-20 (rounded to nearest 50 students)
Grade Students Grade Students Grade Students Grade Students
PK 3,800 3 6,550 7 5,100 11 3,050
K 7,000 4 5,950 8 4,500 12 2,800
1 6,900 5 5,800 9 3,700 K-12 70,400
2 6,550 6 5,400 10 3,300 Total
1.1.3 Military-connected students experience high mobility rates in and out of school systems across the nation and the world; thus, DoDEA makes a concerted effort to mitigate transitional barriers to military-connected students’ success, working toward a world-wide systemic education network.
1.2 Background
1.2.1 DoDEA implemented a current Student Information System (SIS) over ten years ago and has become an integral part of DoDEA’s technology and culture. To meet sometimes unforeseen requirements, the current system has been customized many times. Features include, but are not limited to: class attendance, student grades, demographic information, addresses, graduation credits, school reports, student services, and standardized test scores.
1.2.2 DoDEA has implemented a continual service improvement program to align our current business processes with industry best practices and standards to ensure consistent, repeatable, documented business processes.
1.3 Scope of Work
1.3.1 DoDEA’s procurement intent is a Software as a Service (SaaS) SIS to maintain, support, and enable intuitive use and comprehensive privacy security of students’ educational past, current, and future records. A system that will enable school faculty and staff the ability to perform operational and administrative functions throughout DoDEA organizational hierarchy business operations from the classroom to the Director. In supporting all aspects of each student’s education and school operations, the SIS must:
Allow parents/sponsors and student access to user interface portals for educational, health, attendance, student performance, communications, and classroom to school to district information links/portals.
A SIS must provide intuitive, user-friendly, applications to administer and perform learning and administration activities and tasks.
Provides interface with data repositories and third-party applications/systems to enhance and provide the latest in modern student information system capabilities.
Provide transparent, efficient, personalized, and secure accessibility for operational and functional capabilities to the six different levels of functional users: school, complex/installation, community, district, region, and headquarters. Reference graphic of organizational structure below.
DoDEA Organizational Hierarchy Chart
1.3.2 DoDEA requires data migration services to associate current system to a new solution. Provide migration of, at a minimum, 500 gigabytes of data and associated tables. Provide a data dictionary to map interfaces and plan to support validation of data migration accuracy of 99.7% to a new system.
1.3.3 DoDEA requires the Contractor to provide and execute an Implementation Plan of events, activities, and processes from current to new system. To include, but not limited to: migration, training, data validation, system updates, configuration approach for approval by government contracting authority or designee. See Section 2.4, “Government Implementation Timeline”
1.3.4 DoDEA requires a Service Level Agreement (SLA) from the vendor to include specifics of services provided in order to ensure continuity of services and conditions of service availability. The SLA shall provide description of services such as, but not limited to: timeliness of services, roles and responsibilities of each supporting capability, explanation of procedural escalation processes, cost of service tradeoffs, and management elements for reporting, dispute resolution (e.g., risk mitigation), service level breach notifications, and upkeep of SLA relevancy throughout contract period of performance. Additional discussions are expected to ensure accommodations and capabilities are manageable and consistent with industry capabilities. This system is essential for DoDEA operations so functionality of the system is of high importance. Minimum functional performance of services are:
Global system availability 99.5%.
System problem response times for unavailability (regardless of global origination) must be acknowledged within 15 minutes and resolved within one hour. System degradation must be acknowledged within 30 minutes, resolved within two hours. System issues may be reported from any region by DoDEA SIS personnel 24 hours a day – 6 days a week (Sun – Friday).
Change response must be acknowledge within 24 hours and solution provided within three business days. Implementation of solution must be based upon agreed upon timeframe.
The contractor shall provide industry-standard technical support via telephone, ticketing system or email within one business day or less from the initial contact to include, but not limited to: providing assistance with service problems, product setup, upgrades, and troubleshooting throughout the life of the contract.
1.3.5 DoDEA expects to make one award for a 12-month base year with nine, 12-month option years to follow.
2 SERVICE REQUIREMENTS
Requirements have been developed utilizing DoDEA Subject Matter Experts (SME) from all functional areas.
2.1 Objective 1: Project Management and SIS
Provide project management to include a dedicated liaison to DoDEA and a defined project plan that covers all aspects of the SIS.
2.1.1 Task #1, Management—The Contractor shall:
2.1.1.1 Provide a dedicated project manager and alternate who will have full authority to act for the Contractor on all contract matters relating to the daily operation of this contract.
2.1.1.2 Provide an organizational chart with names, titles, and qualifications of the people leading this project.
2.1.1.3 Notify the Contracting Officer’s Representative (COR) in writing of changes in the organizational chart five business days in advance of the change. Verify in writing to the COR that the replacement’s qualifications meet or exceed those of his/her predecessor.
2.1.2 Task #2, Project Plan and Implementation— The Contractorshall:
2.1.2.1 Provide a final project plan based on written feedback from COR. The final project plan shall include an executive summary addressing all of the key requirements.
2.1.2.2 Implement the project plan, providing DoDEA with an SIS that meets the requirements set forth in this performance work statement (PWS).
2.1.3 Task #3, Post-Award Conferences— The Contractor shall:
2.1.3.1 Participate in a video- or teleconference with the COR five business days after award in accordance with FAR Subpart 42.5. Convene a video- or teleconference with DoDEA Information Technology staff ten business days after award. Provide the medium through which each conference occurs, record each meeting’s minutes, and submit them to the COR within two business days of the event.
2.1.3.2 Meet with Contracting Officer, COR, and/or other Agency personnel, as appropriate to review Contractor performance, as required by DoDEA. At these meetings the Contracting Officer may discuss the Government’s view of Contractor performance, and apprise the Government of problems, if any, being experienced. Take appropriate action to resolve any outstanding issues raised by the Government.
2.1.3.3 Attend virtual meetings at no additional cost to the Government. Note:
Costs associated with attendance at face-to-face meetings, if any, shall be handled/ paid for as stated in the contract.
Performance Standards and Acceptable Quality Levels (AQL) Objective 1, Project Management
Performance Standard and Related Task
AQL Inspection Method Incentives*
* Unless specified otherwise, possible ratings are as follows: exceptional, very good, satisfactory, marginal, or unsatisfactory, per FAR 42.1503, Table 42-1, and “Evaluation Ratings Definitions”.
Task 1, Management, PWS 2.1.1 –
PWS 2.1.1.3
From post-award conference until contract expiration.
Manager or alternate shall be able to act on behalf of the Contractor on all contract matters relating to the daily operation of this contract.
COR inspection
N/A
Task 2, Project Plan and Implementation, PWS 2.1.2. - 2.1.2.2
Draft: 80% correct.
Draft: Ten business days after post-award conference Final: Five business days after receipt of written feedback from the COR
Final: 100% correct, except for possible errors in grammar/formatting.
COR inspection N/A
Task 3, Post-Award Conferences, PWS 2.1.3 – 2.1.3.3*
Ten (10) business days after award notification.
COR inspection N/A
* Exact dates and times will be determined by the Government post-award with Contractor input.
2.2 Objective 2, Training and Help Documentation
Due to having a global school system, DoDEA opts for virtual training, whenever possible, that is synchronous webinars. Each webinar shall be conducted three or eighttimes—once during school hours for each region, Americas, Europe, and the Pacific or for each district, respectively. Webinars are recorded by the Contractor and placed on DoDEA’s LMS (currently Schoology). Digital modules are either accessed from the vendor’s website or placed on DoDEA’s LMS. This objective has three tasks: Virtual Training, Face-to-Face Training, and Help Documentation.
2.2.1 Task # 1, Virtual Training
Ref. The Contractor shall
2.2.1.1
Co-develop with DoDEA subject-matter experts (SME) an arc of learning for professional learning and product training as part of the Project Plan, to include dates, times, and locations of each training listed below:
2.2.1.2
Provide virtual training for multiple specialist/user subgroups, including but not limited to Registrars, Nurses, Counsellors/School Psychologists, Special Education, Special Programs (e.g. ESOL, Gifted), and School Administrators/Office Staff.
2.2.1.3
Conduct synchronous development/practice session webinars for each specialist/ user subgroup—at a minimum, for teachers, administrators, SMEs, registrars, families. Professional learning shall be co-delivered by DoDEA and Contractor SMEs. Each webinar shall be three to six hours long and presented three times during work hours for the users, that is, once per region: Americas, Europe, and the Pacific.
2.2.1.4
Conduct synchronous webinars of up to six hours each, delivered in half or full day sessions, for each specialist/user subgroup. Each webinar shall be presented eight times during work hours for the users, that is, once per district: Americas Mid- Atlantic, Americas Southeast, Europe West, Europe East, Europe South, Pacific West, Pacific East and Pacific South...
2.2.1.5
Conduct three synchronous development/practice session webinars on teacher functions (e.g., gradebook and attendance) in order to prepare DoDEA SMEs to present professional development to teachers. Each webinar shall be 3-6 hours long and presented three times during work hours for the users, that is, once per region:
Americas, Europe, and Pacific.
2.2.1.6
Conduct up to three additional 3-6 hour trainings per district based on needs identified post-implementation—up to 24 trainings. Note: Some, if not, all of the trainings are likely to be repeated in different districts
2.2.1.7
Conduct scheduling training (e.g., course catalog, course requests, master schedule, walk-in scheduling). Conduct three synchronous development/practice session webinars and eight synchronous webinars of up to six hours each during the spring semester. Each webinar shall be presented during work hours for the users, that is, once per region and once per district—11 times.
2.2.1.8
Provide video- or teleconference opportunities for school users to ask questions and receive real-time answers about scheduling 1-2 hours per week during the spring semester.
2.2.1.9
Conduct a total of 60 one-hour virtual trainings—approximately two per month per region during the school year—for DoDEA SIS support staff at a time appropriate for each region. Note: Topics will be determined post-award. Trainings will not be recorded. Note: Twenty trainings provided per region.
2.2.1.10 Conduct up to ten 3-6 hour trainings for system administrators.
2.2.1.11
Provide a video playlist and written documentation for at least the following topics:
system navigation, data analytics and reporting, attendance, registration, student health, special education, scheduling, gradebook, report cards, transcripts, discipline, early warning/at-risk, and special programs (e.g., 504, gifted, ESOL).
2.2.1.12 Record and post all webinars, unless otherwise specified, in DoDEA's learning management system.
2.2.1.13 Provide self-paced interactive user guides or user walkthroughs for commonly used SIS functions.
2.2.1.14 Provide industry-standard online training or documentation for non-staff users (e.g.
parents, students). Update documentation as required.
2.2.2 Task #2, Face-to-Face Training
Ref. The Contractor shall
2.2.2.1 Co-develop with DoDEA SME an arc of learning for training as part of the Project Plan, to include dates, times, and locations of the training listed below:
2.2.2.2 Conduct 4.5 day—32-hour—face-to-face training for 25 to 30 DoDEA SIS support staff at a DoDEA-provided facility in the United States prior to SIS implementation.
2.2.2.3 Ensure Contractor’s project manager and/or alternate are on site during the training.
2.2.3 Task #3, Help Documentation/Support
2.2.3.1
Co-develop with DoDEA subject-matter experts (SME) an arc of learning for training as part of the Project Plan, to include timeline for availability of each item listed below:
2.2.3.2
Provide a video playlist and written documentation of product training for at least the following topics: system navigation, data analytics and reporting, attendance, registration, student health, special education, scheduling, gradebook, report cards, transcripts, discipline, early warning/at-risk, and special programs (e.g. 504, gifted, ESOL).
2.2.3.3 Provide additional videos and written documentation based on needs identified during implementation.
2.2.3.4 Provide online, indexed documentation identifying end-user step-by-step procedures for completing tasks and activities aligned to specific screens or fields.
2.2.3.5 Provide quick guides and Frequently Asked Questions for the most common SIS tasks and functions.
2.2.3.6 Provide update videos/training documentation for each upgrade to match the current SIS version.
Objective 2, Training and Help Documentation
Performance Standard and Related Task
AQL Inspection Method Incentives*
* Unless specified otherwise, possible ratings are as follows: exceptional, very good, satisfactory, marginal, or unsatisfactory, per FAR 42.1503, Table 42-1, and “Evaluation Ratings Definitions”.
Task 1, Virtual Training, PWS 2.2.1 – 2.2.1.14
Draft within 30 calendar days of contract award;
Final within 80 calendar days of contract award.*
No more than 4% of all activities shall not perform as established.
Random Sample
Task 2, Face-to-Face Training, PWS
2.2.2 – 2.2.2.3
Within 60 calendar days of contract award, predicated upon government availability and approval *
No more than 4% of all
Initial review upon deliverable; then monthly
Task 3, Help Documentation / Support, PWS 2.2.3 – 2.2.3.6
Within 60 calendar days of contract award *
No more than 2% of all
Initial review upon deliverable; then quarterly
* Exact dates and times will be determined by the Government post-award with Contractor input.
2.3 Objective 3, SIS Function and Implementation
2.3.1 Task #1, Hierarchy levels – The Contractor shall provide an SIS reflective of the 6 DoDEA organizational layers for: reporting, data access, user security, communications, and data management.
2.3.1.1 Data shall be associated with each of the 6 levels with secure permissions. (School belongs to a complex/installation;
complex/installation belongs to a community; community belongs to a district; district belongs to region; region(s) belong to headquarters).
2.3.2 Task #2, Functional Categories – The Contractor shall provide: student registration, demographics, virtual high school, attendance, grading/ gradebook, reporting, student/master scheduling, graduation planning/transcript management, conduct/discipline, student health, special education, special program, student support services, communication, documents/records management, student/family portals, and all the subsequent tasks as indicated within PWS section 3, “Technical Requirements and Specifications”.
2.3.3 Task #3, Data Migration – The Contractor shall provide data migration services to associate current system to a new solution. Provide migration of, at a minimum, 500 gigabytes of data and associated tables. Provide a data dictionary to map interfaces and plan to support validation of data migration accuracy of 99.7% to a new system.
2.3.3.1 Provide crosswalk of tables from source to new system that need to be migrated. Provide data migration instruction recommendation of best practices to associate current system data to a new system.
2.3.3.2 Provide analysis of the amount of data contained within these tables.
2.3.3.3 Provide method for moving data from on-premises to the provider solution.
2.3.3.4 Determine list of reports and dashboards that need to be updated.
2.3.3.5 Provide plan for reporting & analytics tools with multiple environments
(e.g. Development, Test, Production).
2.3.3.6 Develop remediation plan for reporting & analytics tools issues.
2.3.3.7 Develop remediation plan for reports and dashboards performance issues.
2.3.3.8 Provide estimated reporting & analytics tools level of effort and estimated timeline for migration plan.
2.3.3.9 Provide data validation expectations to include, but not limited to:
Row count Row hash Summary of data
2.3.3.10 Provide plan for:
Data migration to multiple environments (e.g. Test and Evaluation, Training).
Data migration from multiple application/systems (e.g.
Transportation, Tuition, etc.).
Establish estimated data migration level of effort and estimated timeline for migration plan.
Provide analysis with the objectives of understanding and specifying the requirements at a level sufficient to complete the implementation, customization, testing, and deployment of the proposed solution.
Testing of migration steps for review and schedule adherence.
2.3.3.11 Provide final presentation of engagement results and recommended next steps.
2.3.3.12 Provide schedule and lead pre-kickoff planning meeting associated to DoDEA planning schedule.
2.3.3.13 Develop schedule workshop delivery plan.
2.3.4 Task #4, Implementation – The Contractor shall provide and execute an implementation plan of events, activities, and processes from current to new system. See Section 2.4, “Government Implementation Timeline”
2.3.4.1 Develop Implementation Plan of transition from the legacy systems to the new SIS to include, but not limited to:
2.3.4.1.1 Data migration, user training, data validation, system configuration, and system updates
2.3.4.1.2 User friendly data migration tools.
2.3.4.1.3 Identify and report size of database, number of records, and tables.
2.3.4.1.4 “Configuration Guide” of proposed architecture.
2.3.4.2 Execute Implementation Plan
Objective 3, SIS Function and Implementation
Performance Standard and Related Task
AQL Inspection Method Incentives*
* Unless specified otherwise, possible ratings are as follows: exceptional, very good, satisfactory, marginal, or unsatisfactory, per FAR 42.1503, Table 42-1, and “Evaluation Ratings Definitions”.
Task 1, Hierarchy levels , PWS 2.3.1
No deviation from PWS.
COR inspection
Task 2, Functional Categories, PWS 2.3.2
No more than 4% of all activities shall not perform as established.
COR inspection and feedback from SIS users system wide
Task 3, Data Migration, PWS 2.3.3
No more than 1% of all activities shall not perform as established.
COR inspection at each step
Task 4, Implementation, PWS 2.3.4
No more than 5% of all activities shall not perform as established.
COR inspection and feedback from SIS users system wide
2.4 Government Implementation Timeline
DoDEA deadline indicates project steps with specific deadlines. Critical key activity milestones:
PWS Activity Timeline
2.1.3 Post-award conference; technical
conference May/June 2020
2.1.2 Project plan June 2020
2.2.1 System administrator training/overview June 2020
2.2.2 Face-to-face training for SIS support staff Oct 2020
2.3.3 Data conversion/migration validation Dec 2020
2.3.2 SIS configuration/workflows complete 15 Jan 2021
2.2 Training materials complete 15 March 2021
2.2.1 Virtual Training Apr-May 2021
2.3.3 Final data migration and validation June 2021
2.3.4 Go live 5 July 2021
3 TECHNICAL REQUIREMENTS AND SPECIFICATIONS
3.1 Software and Cloud Security Requirements – The Contractor shall:
3.1.1 Ensure all online resources, cloud-based services and instructional software meet the Department of Defense (DoD) and DoDEA Information Assurance requirements as defined below.
3.1.2 Comply with the Cloud Services questionnaire (Attachment 1) that was submitted as part of proposal submission and provide copies of or access to any software in the proposed solution.
3.1.3 Ensure on-premises software resources support post-installation integration of the DoD Application, System and Database Security Technical Implementation Guides (STIGs) for applicable systems and applications.
3.1.4 Ensure that the on-premises software—which will be subject to static and dynamic analysis testing—pose no risk to DoDEA systems and users. Note: This testing may include reverse engineering analysis.
3.1.5 Submit a completed copy of the “Cloud Services Questionnaire”, (Attachment 1) which includes details of the proposed cloud service environment and addresses how the following seven areas provide performance functionality:
1. Vendor Data Collection and Distribution Controls
2. Vendor System Management and Security Controls
3. Vendor Data Storage and Data Access Controls
4. Vendor Data and Metadata Retention Controls
5. Vendor Development and Change Management Processes
6. Vendor Test and Development Environment Security Controls
7. Vendor Data Breach, Incident Investigation and Response Mechanisms
3.2 System Requirements: – The Contractor shall:
Ensure software installed and/or accessed in a DoDEA system—network, stand-alone or web-based—is compatible with the standards cited herein.
3.2.1 Software shall be completely functional on a standard DoDEA IT device without the need/requirement for administrative-level user rights or a requirement to insert media (CD/DVD) to execute the software. Software shall not require modifications to folder permissions while executing.
3.2.2 Ensure all software is compatible with the following hardware baseline:
Specifications Minimum Memory 4 GB
Hard Drive 100 GB Processor Intel-based 2.4 GHz
Operating System Windows 7 Enterprise; Windows 10 Browser Environment Chrome; Edge; IE 10 or higher
3.2.3 Provide the minimum desktop/server system technical specifications, available reference architectures, networking specifications and diagrams, and systems configuration documentation for the proposed product solution.
3.2.4 Ensure all software is completely functional without requiringadministrative-level user permissions or external media to execute the software.
3.2.5 Ensure all software packages support unattended installation methods used by enterprise software packaging and deployment systems. Note: Older 16-bit software will be automatically denied, per this requirement.
3.3 Data Management Requirements—The Contractor shall:
3.3.1 Provide a mechanism for batch administration and automation of routine data management tasks via flat file import, or representational state transfer (REST) based web service application programming interfaces (APIs). The mechanism shall provision and manage data objects within the Contractor’s system, including but not limited to organizational structures, student accounts, staff accounts, courses, and class rosters.
3.3.2 Provide all necessary documentation and assets to facilitate batch administration and automation of routine data management tasks, including but not limited to roster template files (i.e., comma separated value templates); data element/field definitions documentation; data interchange formats and schemas (XML/JSON);
and/or data dictionaries for the purpose of mapping organizational Student Information System (SIS) data to the Contractor’s required input formats.
3.3.3 Provide a single point of contact to support DoDEA in performing the required data integration activities within the Contractor’s system.
3.3.4 Configure DoDEA enterprise within its system and/or databases as the appropriate organizational entity (i.e., state, district, school) upon a request in writing fromthe Contracting Officer’s Representative (COR). Note: DoDEA’s organization hierarchy consists of the following: one system, three regions, eight districts, 62 communities, and 164 schools, which includes the Virtual High School.
3.3.5 Participate in a technical meeting with DoDEA within ten business days after award for the purposes of preparing for onboarding of new services and initial configuration of administrator-level accounts.
3.3.6 Provide mechanism for database connections for the purpose of moving large datasets into an enterprise warehouse/lake (on Azure platform).
3.3.6.1 Provide developer documentation for DB connection mechanism for accessing full dataset of SIS.
3.3.7 Provide, at a minimum, daily database sync with DoDEA cloud instance. In addition, capture and sync event data for analytic use.
3.3.8 Provide a query and reporting platform within the SIS:
3.3.8.1 End-user ad hoc reporting and querying.
3.3.8.2 Security layer management to ensure data security per user.
3.3.8.3 Developer layer that allows for publishing public reports.
3.4 DoDEA Software License Keys—The Contractor shall:
3.4.1 Provide license keys and electronic downloads for software required under this
Contract to the COR.
3.4.2 Provide software directly to DoDEA schools, districts, or regions only if explicitly required to do so in the contract or in writing by the COR.
3.5 DoDEA Information Assurance Supporting Elements / Requirements—The Contractor shall:
3.5.1 Comply with the same Federal law and DoD policy and guidance to which DoDEA is subject. These requirements include but are not limited to the information assurance requirements defined in:
DEPARTMENT OF DEFENSE CLOUD COMPUTING SECURITY
REQUIREMENTS GUIDE; Version 1, Release 3; 6 March, 2017
DoD Directive (DoDD) 8500.01E, Information Assurance, which may be found at http://dodcio.defense.gov/Portals/0/Documents/DIEA/850001p.pdf
DoD Security Technical Implementation Guidance (STIG), which may be found at http://iase.disa.mil/stigs/Pages/index.aspx
DoD Risk Management Framework (DODRMF) per DoD Instruction 8510.01 at http://www.dtic.mil/whs/directives/corres/pdf/851001_2014.pdf
3.5.2 Provide security patches/upgrades to include third-party applications in response to public-released security vulnerabilities associated with its software solution.
Software upgrades/patches shall be included in the licensing cost and be performed at the least disruptive times as determined by DoDEA. Note: Any exception to this requirement must be approved in advance and in writing by DoDEA’s Chief Technology Officer.
3.5.3 Ensure software packages support unattended installation methods used by enterprise software packaging and deployment systems. Note: DoDEA currently distributes software packages via Microsoft System Center Configuration Manager (SCCM). Also, older 16-bit software will be automatically denied per this requirement.
3.5.4 Ensure any portion of the Contractor's solution that involves Internet access by DoDEA students complies with the relevant requirements of the Children's Internet Protection Act, Pub.L. 106-554, § 1(a) (4) [Div. B, Title XVII, § 1701], Dec. 21, 2000, 114 Stat. 2763, 2763A-335.
3.5.5 Ensure that its solution shall be robust enough to serve the needs of a large community of learners dispersed across the world using a variety of bandwidths and scalable to meet future growth, both in terms of instruction and the number of users.
3.5.6 Ensure Contractor staff who have access to DoDEA student and/or teacher personally identifiable information take the DoD Privacy Act/ Personally Identifiable Information (PA and PPI/PII) training before gaining access to the data and yearly thereafter.
3.6 Scalability: The Contractor’s solution shall be scalable to meet future growth requirements;
in terms of instruction, number of users, organizational structure, data reporting and analysis, mobile communications, workflows, processes, and procedures.
3.7 System Security and Protection – The Contractor shall provide the following:
General security controls, SIS authentication, incident response, media protection, maintenance, physical & environmental protection, security planning policy, personal security, risk assessment, system & communication protection, system & information integrity. All policies shall be presented to DoDEA in writing and finalized within ten business days after receipt of written responses from the COR.
3.7.1 General Security Controls—The Contractor’s SIS shall:
3.7.1.1 Support personal identification number (PIN) and password authentication capability.
3.7.1.2 Include a web management portal.
3.7.1.3 Offer or support multi-factor authentication such as a “Shared Secret”;
something the user knows, (i.e., PIN and/or password) with forgotten username and password support capability and notification capability through Short Message Service (SMS) and/or email.
3.7.1.4 Provide use of a temporary password for system logons with an immediate change to a permanent password.
3.7.1.5 Enable users to reset(s) the password for a temporary password so as to unlock the account making password use available upon next log in.
3.7.1.6 Enforce minimum password complexity of: case sensitive, minimum of twelve characters, and at least one each of upper-case letters, lower-case letters, numbers, and special characters. Employ automated tool(s) to determine password authenticators are sufficiently strong to satisfy DoDEA password complexity requirements. Provide enforcement of at least one of the following number of changed characters when new passwords are created—either stores and transmits only encrypted representations of passwords or enforces password minimum and maximum lifetime restrictions of a 3-day minimum and 90-day maximum.
3.7.1.7 Prohibit password reuse for eight past used passwords.
3.7.1.8 Report results of database audits to include but not limited to the following:
database schema and object changes, failed and successful logon and logoff attempts, data type changes, field changes, permissions changes and changes to jobs/functionality in order to ensure suspicious activity is traceable and reported.
3.7.1.9 Support single sign-on compatibility with authentication in accordance with the OAuth 2.0 and SAML 2.0 protocols.
3.7.2 SIS Authentication—The Contractor’s SIS shall:
3.7.2.1 Verify—as part of the initial authenticator distribution—the identity of the individual, group, role, or device receiving the authenticator.
3.7.2.2 Define and establish initial authenticator content to perform the following:
1) Ensure authenticators have sufficient strength of mechanism for each intended use.
2) Establish/implement administrative procedures for initial authenticator distribution, lost/compromised or damaged authenticators, and revoking authenticators.
3) Change default content of authenticators prior to SIS installation.
4) Establish (1) minimum and maximum lifetime restrictions and (2) reuse conditions for authenticators.
5) Change/refresh authenticators to include ninety calendar days for passwords.
6) Protect authenticator content from unauthorized disclosure and modification.
7) Provide specific security safeguards to protect authenticators.
8) Change authenticators for group/role accounts when membership to those accounts changes.
3.7.3 Incident Reporting—The Contractor’s SIS shall:
3.7.3.1 Provide an incident response plan with the following reporting criteria:
1) Roadmap for implementing its incident response capability.
2) Structure and organization of the incident response capability.
3) High-level approach to fit the incident response capability into the overall organization.
4) Meeting the unique requirements of the Government.
5) Defining reportable incidents.
6) Metrics for measuring the incident response capability.
7) Defining the resources and management support needed to effectively maintain and mature an incident response capability.
8) Reviewing/updating the incident response plan at least annually to address system/organizational changes or problems encountered during plan implementation, execution, or testing.
9) Protecting the incident response plan from unauthorized disclosure and modification.
3.7.3.2 Develop, document, disseminate, and institute (1) an incident response policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the incident response policy and associated incident response controls. Review/update the current policy annually and the procedures upon changes initiated.
3.7.3.3 Develop/institute incident response capability within United States Computer Emergency Readiness Team (US-CERT) incident reporting timelines as specified in the National Institute of Standards and Technology (NIST) Special Publication 800-61 (as amended); and reports security incident information to US-CERT and law enforcement as necessary.
3.7.3.4 Provide two hours of virtual incident response training to SIS users consistent with assigned roles and responsibilities, as required by SIS changes, and not less than once per year.
Webinar Option: Deliver live, synchronous webinars during school hours that are based on the time zone of the DoDEA Regions—Americas, Europe, and Pacific. Provide recordings of the presentations for placement on DoDEA’s learning management system (LMS currently Schoology).
Module Option: Provide one digital modules, which shall include video clips of the incident reporting functionality.
o Each online module’s contact time shall be equivalent to the Webinar
Option described above—six hours.
o All digital content must be packaged and delivered for publishing and reusability in Sharable Content Object Reference Model® (SCORM®) packaging, and made available for placement and use on DoDEA’s LMS (currently Schoology) for the life of the contract. The Department of Defense Instruction (DoDI) 1322.26 mandates that electronic courseware be developed in compliance with the latest possible version.
3.7.3.5 Report suspected security incidents to the Contractor’s program manager and DoDEA’s Contracting Officer. Incident response shall not exceed one hour after discovery/detection for incidents involving PII/PHI. Non-PII/PHI incident responses shall not exceed two hours after discovery/ detection. Report security incident information to the Contract Officer and/or designee, Program Manager, and COR and appropriate incident response center, e.g., US-CERT if the incident involves personally identifying information and protected health information
(PII/PHI).
3.7.3.6 Test incident response capability at least every six months for high availability and at least every 12 months for low/medium availability. Provide the COR with a written summary of each test’s results.
3.7.4 Media Protection (Policy)—The Contractor shall develop, document, disseminate, and institute a media protection policy and procedures that includes a PII/PHI policy for all personnel, including contractors with potential access to that sensitive information. Ensure the policy and procedures address (1) the purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and
(2) procedures to facilitate policy implementation. Review/update the current policy once every two years and procedures every six months.
3.7.5 Media Protection (Access)—The Contractor’s SIS shall:
3.7.5.1 Restrict access to any digital or non-digital media containing PII/PHI to authorized individuals as prescribed by DoDEA.
3.7.5.2 Identify SIS media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information.
3.7.5.3 Protect SIS media until they are destroyed or sanitized using Government-approved equipment, techniques, and procedures.
3.7.5.4 Physically control and store removable media that contain PII/PHI within any securable area or in a locked container.
3.7.5.5 Protect and control all media with sensitive information during transport outsideof controlled areas and prior to leaving secure/controlled environments. Note: This requirement applies to digital media, encryption using a Federal Information Processing Standard (FIPS) 140-2 validated encryption module, and non-digital media, secured in locked container.
3.7.5.6 Maintain accountability for all SIS media during transport outside of controlled areas. Document activities associated with the transport of SIS media. Restrict the activities associated with transport of SIS media to authorized personnel for review and approval by the COR.
3.7.6 Media Protection (Sanitization)—The Contractor’s shall:
3.7.6.1 Notify the Contracting Officer and COR within two business days of any intent to conduct sanitization operations. Provide a plan of operations in writing before conducting sanitization operations. Implement the plan only upon written approval from the COR.
3.7.6.2 Sanitize digital media that contains PII/PHI prior to disposal, release out of organizational control, or release for reuse using FIPS-validated media sanitization techniques or procedures in accordance with applicable federal and organizational standards and policies. Employ a sanitization mechanisms with the strength and integrity commensurate with the security category or classification of the information.
3.7.6.3 Restrict the use of portable storage and mobile devices on information systems and networks containing PII/PHI using device ownership, media sanitization, and encryption controls.
3.7.6.4 Test sanitization equipment and procedures at least annually to verify that the intended sanitization are achieved. Provide the COR a written summary of the test results.
3.7.7 Maintenance—The Contractor shall develop, document, disseminate, and institute a system maintenance policy and procedures addressing (1) the purpose, scope, roles, responsibilities, management commitment, and coordination among organizational entities, (2) compliance and (3) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the current policy once every two years and procedures every six months.
3.7.8 Physical & Environmental Protection (Policy)—The Contractor shall develop, document, disseminate, and institute a physical and environmental policy that addresses
(1) the purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the current policy annually and the procedures upon changes initiated.
3.7.9 Physical & Environmental Protection (Practices) — The Contractor shall:
3.7.9.1 Maintain temperature and humidity levels within the facility where the SIS resides consistent with American Society of Heating, Refrigerating and Air-conditioning Engineers (ASHRAE) document entitled Thermal Guidelines for Data Processing Environments.
3.7.9.2 Monitor temperature and humidity levels continuously.
3.7.9.3 Authorize, monitor, and control all SIS components entering and exiting the facility and maintains records of those items.
3.7.9.4 Provide/maintain a list of individuals with authorized access to the facility where the SIS resides.
3.7.9.5 Issue authorization credentials for facility access.
3.7.9.6 Review authorization credentials at least annually. Remove individuals from the facility access list within eight business hours from the time access is terminated or is no longer required. Notify the Contracting Officer and COR in writing on the same business day that an individual’s access is terminated or is no longer required.
3.7.9.7 Enforce physical access authorizations by the following procedures:
1) Verify individual access authorizations before granting access to the facility.
2) Control ingress/egress to the facility using electronic locks.
3) Monitor physical access to the facility where the SIS resides to detect and respond to physical security incidents.
4) Maintain physical access audit logs for entry/exit points.
5) Document physical access logs at least monthly and upon suspicion of unauthorized entry or attempt of entry.
6) Maintain visitor access records to the facility where the SIS resides for a minimum of one year. Review visitor access records at least weekly reporting any foreign national visitors
7) Provide physical and administrative safeguards to control access to areas within the facility officially designated as publicly accessible.
8) Escort visitors and monitor visitor activity in all circumstances within restricted access areas where the SIS resides.
9) Secure keys, combinations, and other physical access devices. Change combinations and keys at least annually and/or when keys are: lost, combinations are compromised, orindividuals are transferred or terminated.
10) Inventory physical access devices at least annually.
3.7.9.8 Coordinate/document results of reviews and investigations involving physical and environmental protection (practices) with the Contracting Officer and COR.
3.7.10 Security Policy— The Contractor shall:
3.7.10.1 Develop, document, disseminate, and institute a security policy and procedures addressing (1) the purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the current policy once every three years and procedures every six months. Update more frequently, if necessary, to address changes to the SIS environment of operation or to address either problems identified during plan implementation or security control assessments.
3.7.10.2 Provide a security policy that is consistent with the enterprise architecture, defines the authorization boundaries for the system, and includes the following descriptions/information:
1) SIS’s operational context in terms of mission and business processes.
2) Overview of the SIS’s security requirements to include the (1) security categorization and supporting rationale for each entry and (2) security controls in place or planned for meeting those requirements including a rationale for the tailoring and supplementation decisions.
3) SIS’s operational environment and relationships with or connections to other information systems.
4) List of relevant overlays, if applicable, for the COR review and approval.
3.7.10.3 Protect the security plan from unauthorized disclosure and modification.
3.7.10.4 Ensure individuals requiring access to the SIS have access to the rules that describe their responsibilities and expected behavior vis-à-vis information and SIS use. Ensure these individuals sign a document testifying that they understand the rules cited above. Provide the documentation to the COR, upon request only.
3.7.10.5 Require individuals who have signed the rules of behavior to re-sign any revisions of the rules within ten business days of receiving the revisions. Provide the documentation to the COR, upon request only.
3.7.10.6 Review/update the rules of behavior at least once every three years.
3.7.11 Personal Security—The Contractor shall:
3.7.11.1 Develop, document, disseminate, and institute a personal security policy for all individuals accessing the SIS—DoDEA, Contractor, and subcontracted/ third-party personnel—that addresses (1) the purpose, scope, responsibilities, roles, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the current policy once every three years and procedures every six months.
3.7.11.2 Assign a risk designation to all organizational positions. Provide screening criteria for individuals filling those positions.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .