22Q0003_PWS_DRFT_012022.pdf
PDF 541 KB Posted
- Attached to
- IDAMS Federal contract opportunity
- Solicitation number
- HE125422Q0003
- Issued by
- Department of Defense Education Activity
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
Department of Defense Education Activity 4800 Mark Center Drive
Alexandria, VA 22350
PERFORMANCE WORK STATEMENT
Digital Asset Manager / Repository
1. General Information and Scope of Work
1.1 Agency
For school year (SY) 2021-22, the Department of Defense Education Activity (DoDEA) will provide PK- 12 instruction to over 69,000 dependents of military and civilian employees. Student enrollment is based primarily on deployment of military troops worldwide. In the Americas, DoDEA operates 50 schools located in seven states, Puerto Rico, and Cuba. In Europe and the Middle East, DoDEA operates 64 schools located in Germany, England, Netherlands, Belgium, Spain, Turkey, Bahrain, and Italy. In the Pacific, DoDEA operates 45 schools located in Korea, Japan (mainland and Okinawa), and Guam.
DoDEA's curriculum, resources and student achievement scores on standardized assessments compare favorably to those of high-performing US public school systems. DoDEA also operates a full time K-12 virtual school option with teaching hubs in each DoDEA region: Americas, Europe, and Pacific.
Within that context, the virtual high school is fully accredited.
1.2 Background
DoDEA’s Instructional Design Program provides just-in-time digital coursework for students and professional learning courses and resources for educators. This work represents a substantial investment and is critical in meeting the Virtual School’s vision and curriculum requirements, which are described at http://www.dodea.edu/virtualhs/DV/HS/dvhs/index.cfm. DoDEA currently does not have a contract for this requirement and stores the images, audio, and visual files on a SharePoint drive.
1.3 Scope of Work
For the aforementioned coursework and professional learning, DoDEA requires images, audio, and video, which are professional quality and conform to copyright laws. DoDEA requires a vendor-hosted digital asset manager / repository to store metadata tagged images, audio, and video in a searchable database accessible to multiple instructional designers/staff members. DoDEA expects to award one contract for a base year and four option years. Note: No migration of data will be required.
2 Requirement
2.1 Digital Asset Manager / Repository: DoDEA requires a vendor-hosted digital asset manager/repository to store metadata tagged images, audio, and video in a in a searchable database accessible to multiple instructional designers/staff members and related professional learning.
The tasks listed below are provided to help the contractor in gaining a better understanding of the requirements in order to successfully meet the objective. The tasks are not all inclusive as the contractor is expected to develop the total solution for meeting all the requirements of the objective in accordance with a performance-based approach.
Supporting Tasks (Objective 1)
Task 1, Solution—The Contractor shall provide a solution that:
1) Hosts up to 100,000 digital assets—approximately two terabytes— in a secure US site.
2) Allows content to be searched and downloaded via the vendor-provided search engine.
3) Allows DoDEA to add and retain metadata to our assets. For each digital asset, the solution shall accommodate up to 150 keywords, a description of the data, and the identification of the author, title, and copyright information. When files are uploaded, the added metadata shall be retained.
4) Permits up to 125 users to access content from any DoDEA workstation with Internet access.
5) Enables users to have different roles, for example, 20 administrator roles with the ability to manage and upload files while the basic user role will be limited to search, view, and bookmark assets.
6) Possesses a variety of reporting capabilities to include the ability to track usage, number of assets, assets by project, assets by user, and storage space utilized.
7) Enables single-file upload and download of files (3MB or greater).
8) Accommodates batch uploads and downloads.
9) Permits export of assets in various image sizes (thumbnail, small, medium, large, original, watermarked)
10) Allows the system administrator to define each user’s role/access.
Task 2, Professional Learning: The Contractor shall (1) provide three hours of virtual administrative and instructional designer training to include online demonstrations and (2) record each session to be posted on DoDEA’s learning management system, currently Schoology.
Task 3, Technical Support—The Contractor shall provide industry-standard technical support for its digital resources for the life of the contract via telephone or by email within one business day or less from the initial contact to include but not limited to assisting with service problems, product setup, and troubleshooting. See PWS 3.10, Upgrades.
Task 4, Meetings—The Contractor shall:
1) Medium and Minutes: Provide the medium through which each meeting occurs, record each meeting’s minutes, and submit them to the COR within two business days of the event.
2) Post-Award Conference: Participate in a video- or teleconference with the COR five business days after award IAW FAR Subpart 42.5.
3) IT Meeting: Convene a video- or teleconference with DoDEA Information Technology staff ten business days after award, per Technical Exhibit #1.
4) Other Post-Award Meetings: Meet with the Contracting Officer (KO), COR, and/or other Agency personnel, as appropriate, to review Contractor performance, as required by DoDEA. The KO may discuss the Agency’s view of Contractor performance, and the Contractor shall apprise the Agency of any problems being experienced. The Contractor shall take appropriate action to resolve any outstanding issues the Agency raises.
5) Attendance: Attend virtual meetings at no additional cost to the Government. Note: Costs associated with attendance at face-to-face meetings, if any, shall be handled/paid for as stated in the contract.
2.2 Performance Standards and Acceptable Quality Levels
2.2.1 Performance Standard: Tasks shall be completed by the required completion date.
2.2.2 Acceptable Quality Level: Ninety-five percent of tasks will be completed by the required completion date. The remaining five percent shall be completed no later than ten business days after their due date.
3 Constraints
3.1 Place of Performance: Work shall be performed at the Contractor’s facilities.
3.2 Liaison and Alternate Liaison—The Contractor shall:
1) Provide a liaison and alternate liaison to be responsible for the performance of work. Their names shall be designated in writing to the Contracting Officer. They shall have full authority to act for the
Contractor on all contract matters relating to the daily operation of this contract. They shall each have at least one year of experience working in a similar role.
2) Notify the COR in writing regarding any change in the liaison or alternate liaison’s role ten business days in advance of the change If the liaison is changed post-award, the replacement shall meet or exceed the qualifications and experience of the person assigned upon contract award.
3.3 Holidays and Hours of Operation
1) The liaison and alternate liaison shall be available during the hours of 9AM to 3PM Eastern Standard Time (EST), except for Federal holidays and Federal government closures/shutdowns. The following list shows recognized Federal holidays: New Year’s Day, Martin Luther King Jr.’s Birthday, Presidents Day, Memorial Day, Juneteenth National Independence Day, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, and Christmas Day.
2) Although there are different time zones within Europe and the Pacific and different hours for specific schools throughout DoDEA, the normal business hours for the regions roughly correspond to the following: Americas, 0700-1500 EST; Europe, 1300-2100 EST; and Pacific, 2000-0400 EST.
3.4 Availability: The Contractor shall make all resources available for the life of the contract.
3.5 Anti-Bias, Diversity, and Inclusion—The Contractor shall provide resources free of age, racial, color, national origin, disabling conditions, sexual, gender, religious, and ethnic bias and present balanced coverage of multi-cultural contributions and representation, where appropriate.
3.6 Privacy—The Contractor shall:
1) User Accounts: Ensure, if feasible, that individual accounts possess unique login credentials that do not require the use of personally identifiable information (PII), i.e., first & last name and any other unique personal identifiers, to access online content.
2) Contractor Personnel: Ensure personnel assigned to this contract take proper precautions to protect information from disclosure. Collect and/or store all agency-owned or agency-controlled PII in accordance with the relevant requirements of the Privacy Act, 5 U.S.C, which may be found at the following URL: http://www.archives.gov/about/laws/privacy-act-1974.html.
3) Privacy Training: Ensure Contractor staff who have access to DoDEA’s student, teacher and/or staff personally identifiable information take the DoD Privacy Act/Personally Identifiable Information (PA/PII) training before gaining access to the data and yearly thereafter. Provide copies of the certificates of completion to the COR which can be audited at any time by the Chief Information Security Officer (CISO) or his/her designee.
3.7 Section 508 Compliance—Ensure Contractor resources, wherever applicable, meet the following requirements:
1) IT Requirement: Ensure that all electronic hardware and software that is procured under this contract/purchase order comply with Section 508 of the Rehabilitation Act of 1973, as amended, (29 U.S.C. 794d) and the Architectural & Transportation Barriers Compliance Board Electronic Information Technology (EIT) Accessibility Standards (36 CFR part 1194). More information may be found at http://www.section508.gov.
2) Deliverable Requirement: Ensure the following occur:
Outputs/deliverables do not adversely affect accessibility features of existing EIT technologies.
EIT related to the requirements of the contract are accessible to people with disabilities, per 29
U.S.C 794(d).
Outputs/deliverables including functional performance, information, documentation, and support requirements are considered. Standards from 36 CFR Part 1194 Subpart B, C and D apply to this acquisition.
3.8 Upgrades: The Contractor shall (1) submit detailed information of system requirements for subsequent upgrades for each option year to DoDEA HQ and (2) provide DoDEA HQ with complete copies of any upgrades for testing prior to dissemination to schools.
3.9 Organizational Conflict of Interest (OCI): The Contractor (including any subcontractor) personnel performing work under this contract may receive, have access to, or participate in the development of, proprietary or Privacy Act information (e.g., personal information, education, etc.) may create a current or subsequent OCI as defined in FAR Subpart 9.5. Whenever the Contractor becomes aware that such access or participation may result in actual or potential OCI, the Contractor shall (1) immediately notify the Contracting Officer (KO) in writing and (2) promptly submit a plan to the KO to avoid or mitigate any such OCI. Note: The KO will unilaterally determine if the Contractor’s plan is acceptable. If the KO determines the plan cannot satisfactorily avoid or mitigate an OCI, s/he may implement other remedies to include prohibiting the Contractor’s further participation in contracted requirements.
4 Government-Furnished Resources
None
5 Contract Deliverables
Milestone/Deliverable Word / Excel
Digital Copies
Task /
PWS
Planned Frequency
Solution -- -- Task 1 Ongoing after receipt of initial delivery order
Professional Learning -- -- Task 2 As scheduled post-award
Technical Support -- -- Task 3 As required after the post-award conference
Meetings Yes Yes Task 4
Post-Award Conference: Five business days after award IT Meeting: Ten business days after award Other Meetings: As scheduled post-award
Upgrades Yes Yes PWS 3.10 As required, post-award
6 Acronyms and Definitions
DoD/DOD Department of Defense DFARS Defense Federal Acquisition Regulation Supplement EIT Electronic Information Technology
FAR Federal Acquisition Regulations IAW In Accordance With PA/PII Privacy Act/Personally Identifiable Information QASP Quality Assessment Surveillance Plan
Contract Line-Item Number (CLIN) – Basic structural element in a procurement instrument describing and organizing the required product or service for pricing, delivery, inspection, acceptance, invoicing, and payment.
The use of the term “line item” includes “subcontract line number”, (SLIN), as applicable.
Contracting Officer (KO) – The only individual with expressed authority to obligate (bind) the Government by means of entering, administering, and terminating contracts within the limits of the authority delegated via a Contracting Officer’s warrant.
Contracting Officer’s Representative (COR) – Qualified and trained Government employee, nominated by the requiring activity (RA) and appointed in writing by a KO primarily to perform specific technical or administrative functions on a specific contract(s); serves as the ‘eyes and ears’ of a KO to assure the Government’s best interests are protected via the terms and conditions of the contract(s) appointed. COR’s do not have authority to obligate (i.e., bind) the Government.
Contractor - Supplier or vendor having a contract to provide specific supplies or service to the Government. The term used in this contract refers to the prime.
Deliverable – Usually physically delivered items but may include such items as digital documents/reports.
Performance Requirements Summary (PRS) – Tabular listing of performance objectives and standards that provides the basis for a meaningful QASP.
Performance Work Statement (PWS) - A statement of work for performance-based acquisitions describing the required results in clear, specific, and objective terms with measurable outcomes.
7 Performance Requirement Summary (PRS) and Quality Assurance Surveillance Plan (QASP)
7.1 Performance Requirement Summary (PRS)
Performance Objective
Performance Standard
AQL
Inspection
Method
Solution, Task 1 Available except for schedule downtimes.
100% compliance with PWS COR inspection
Professional Learning, Task 2
Tasks completed within required timeline
No more than one session rescheduled due to Contractor issues
COR inspection
Technical Support, Task 3
Issues resolved in the required timeframe
90% of issues resolved within one business day. The remaining 10% resolved within three business days.
COR review and stakeholder feedback
Meetings, Task 4 Participate in all scheduled meetings
No more than one session per year rescheduled due to Contractor issues
COR inspection
Upgrades, PWS 3.10 Provided to DoDEA when released to other customers
100% compliance with PWS COR inspection
7.2 Quality Assurance Surveillance Plan (QASP): The Government will utilize a QASP to monitor the contractor’s performance on the contract. The QASP is a living document and can change at any time during the life of the contract. As such, the Government reserves the right to unilaterally edit the QASP at the Government’s discretion.
Technical Exhibit #1 - TECHNICAL REQUIREMENTS
The Contractor shall comply with the applicable technical requirements detailed below.
1.1 Software and Cloud Security Requirements—The Contractor shall:
1.1.1 Ensure all online resources, cloud-based services and instructional software meet the Department of Defense (DoD) and DoDEA Cybersecurity requirements as defined below. Note: Software, cloud services and associated websites will be rigorously tested to ensure no security risks are posed to DoDEA infrastructure and its users.
1.1.2 Complete the Cloud Services questionnaire that was submitted as part of the proposal submission and provide copies of and/or access to any software in the proposed solution.
1.1.3 Ensure on-premises software support post-installation integration of the necessary Security Technical Implementation Guides (STIG) for applicable systems and applications, including Microsoft Windows 10, Microsoft Windows Server 2016, Windows Server 2019, Microsoft Windows IIS, Apache, Oracle databases, and Microsoft SQL Server databases. Note: The STIGs may be downloaded from this URL:
https://public.cyber.mil/stigs/downloads/. The application that enables viewing all of the STIGs is found at the following URL: https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_STIGViewer_2-11.zip.
1.1.4 Ensure vendor content accessible from the web is compatible with the following browser platforms:
Internet Explorer 11, Google Chrome, and Edge. Ensure that any applicable STIGs are implemented.
1.1.5 Ensure on-premises software, which is subject to static and dynamic analysis testing, imposes no risk to DoDEA systems, users and/or data.
1.1.6 Provide a plan of actions and milestones (POA&M) to mitigate any cybersecurity findings resulting from non-compliant and/or vulnerable components within 30 calendar days of notification from DoDEA. Note: DoDEA will assess software products to ensure compatibility with existing system configurations and software, testing may also include reverse engineering analysis.
1.1.7 Participate, as needed, in interviews and deep system architecture inspections. Note: Per DoD policy for cloud-based services, DoDEA conducts a supplemental series of validations, which closely mirror the Federal Risk and Authorization Management Program (FedRAMP) Internet Cloud vetting processes.
Contractor participation/cooperation is normally required to complete this process.
1.2 System Requirements—The Contractor shall:
1.2.1 Ensure, per Section 1.1 (above), any software installed and/or accessed in or by a DoDEA system, network whether stand-alone or web-based, is compatible with standards cited herein.
1.2.2 Provide minimum desktop/server system technical specifications, available reference architectures, networking specifications and diagrams, and applicable systems configuration documentation for the proposed product solution.
1.2.3 Ensure all software is compatible with the following minimum baseline:
Specifications Minimum
Memory 4 GB Hard Drive 100 GB
Processor Intel® Core™ i5-8365U Processor 8th Generation (up to 4.1GHz, 6MB cache) equivalent or better (Must show benchmark/pass mark scores)
Video Graphics Integrated Intel HD Graphics 620 (1920x1080) equivalent or better Operating System Windows 10
Browser Environment Chrome; Edge; IE 11 or higher
1.2.4 Ensure software is completely functional on a standard DoDEA desktop without the need/ requirement for administrative-level user rights and/or permissions or the requirement to use or insert external media to execute the software.
1.2.5 Provide software that does not require modifications to folder permissions while executing.
1.2.6 Ensure, if applicable, that software packages support unattended installation methods used by enterprise software packaging and deployment systems. Notes: DoDEA currently distributes software packages via Microsoft System Center Configuration Manager (SCCM). Older 16-bit software are automatically denied.
1.3 Data Management Requirements—The Contractor shall:
1.3.1 Provide a mechanism for batch administration and automation of routine data management tasks via flat file import, or representational state transfer (REST) based web service application programming interfaces (APIs). The mechanism shall provision and manage data objects within the Contractor’s system, including but not limited to organizational structures, student accounts, staff accounts, courses, and class rosters.
1.3.2 Provide all necessary documentation and assets to facilitate batch administration and automation of routine data management tasks, including but not limited to roster template files (i.e., comma separated value templates); data element/field definitions documentation; data interchange formats and schemas (XML/JSON); and/or data dictionaries for the purpose of mapping organizational student information system (SIS) data to the Contractor’s required input formats.
1.3.3 Provide a single point of contact to support DoDEA in performing the required data integration activities within the Contractor’s system.
1.3.4 Configure DoDEA enterprise within its system and/or databases as the appropriate organizational entity (i.e., region, district, school) upon a request in writing from the contracting officer’s representative (COR).
Note: DoDEA’s organization hierarchy consists of the following: one system, three regions, eight districts, 62 communities, and 160 schools, including the K-12 virtual school programs.
1.3.5 Participate in a technical meeting with DoDEA within ten business days after award for the purposes of preparing for onboarding of new services and initial configuration of administrator-level accounts.
1.3.6 Ensure the transfer of any Sensitive, Confidential data including but not limited to PII data be transferred in a secure means meeting any requirements set by DoDEA’s Chief Information Security Officer (CISO).
1.4 DoDEA Software License Keys: The Contractor shall provide (1) license keys and electronic downloads for software required under this Contract to the COR and (2) software directly to DoDEA schools, districts, or regions only if explicitly required to do so in the contract or in writing by the COR.
1.5 Cybersecurity Supporting Elements/Requirements and Scalability—The Contractor shall:
1.5.1 Comply with the same Federal law and DoD policies and guidance to which DoDEA is subject. These requirements include but are not limited to the cybersecurity requirements defined in the following documentation:
DoD Directive (DoDD) 8500.01E, Information Assurance which may be found at https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.esd.whs.mil%2FPor tals%2F54%2FDocuments%2FDD%2Fissuances%2Fdodi%2F850001_2014.pdf&data=04% 7C01%7C%7Cdb0c3f644c0f4179831408d88b11f0ca%7Cce0f7be2a75548938d702b153371922c %7C0%7C0%7C637412256450259521%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAw MDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=smExY rJwgwDyT7%2BwOsw4vfySY6caUbS9zBSssTC5834%3D&reserved=0
DoD Security Technical Implementation Guidance (STIG), which may be found at the following URL: http://iase.disa.mil/stigs/Pages/index.aspx
DoD Risk Management Framework (DODRMF) per DoD Instruction 8510.01which may be found at https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.esd.whs.mil%2FPor tals%2F54%2FDocuments%2FDD%2Fissuances%2Fdodi%2F851001p.pdf%3Fver%3D2019-02- 26-101520- 3004.5.2&data=04%7C01%7C%7Cdb0c3f644c0f4179831408d88b11f0ca%7Cce0f7be2a755 48938d702b153371922c%7C0%7C0%7C637412256450269516%7CUnknown%7CTWFpbGZsb 3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C 1000&sdata=109TF%2B8w5flZCrmeixsqknTrSfL4ABvxKKCAxn57sM8%3D&reserved=0
1.5.2 Provide security patches/upgrades to include third-party applications in response to public-released security vulnerabilities associated with its software solution. Provide a POA&M for any security vulnerabilities within five business days of discovery. Software upgrades/patches shall be included in the licensing cost and be performed at the least disruptive times as determined by DoDEA in writing. Note: Any exception to this requirement must be approved in advance and in writing by DoDEA’s Chief Information Officer
(CIO).
1.5.3 Ensure that any portion of its solution that involves Internet access by DoDEA students complies with the relevant requirements of the Children's Internet Protection Act, Pub.L. 106-554, § 1(a)(4) [Div. B, Title XVII, § 1701], Dec. 21, 2000, 114 Stat. 2763, 2763A-335.
1.5.4 Ensure its solution is robust enough to serve the needs of a large community of learners dispersed across the world using a variety of bandwidths and scalable to meet future growth, both in terms of instruction and the number of users.
1.5.5 Ensure Contractor staff who have access to DoDEA’s student, teacher and/or staff personally identifiable information take the DoD Privacy Act/ Personally Identifiable Information (PA and PPI/PII) training before gaining access to the data and yearly thereafter. Provide copies of the certificates of completion to the COR which can be audited at any time by the CISO or his/her designee.
File details come from the government source that posted it. Updated .