36C10A19Q0091-001.docx
DOCX document 107 KB Posted
- Attached to
- EMC Centera Storage Drives Federal contract opportunity
- Solicitation number
- 36C10A19Q0091
About this file
36C10A19Q0091 P01 Performance Work Statement Centera Break-Fix v3.docx
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10A19Q0091-000.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment #1 Region 1 VISN 22 EMC Centera Break-Fix PWS
36C10A19?XXXX
Attachment #1
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Office of Information & Technology Back Office System Management
Region 1 VISN 22 EMC Centera Break-Fix
Date: February 22, 2019
PWS Version Number: 1.0
Contents
| 1.0 | BACKGROUND | 20 |
| 2.0 | APPLICABLE DOCUMENTS | 20 |
| 3.0 | SCOPE OF WORK | 23 |
| 4.0 | PERFORMANCE DETAILS | 24 |
| 4.1 | PERFORMANCE PERIOD | 24 |
| 4.2 | PLACE OF PERFORMANCE | 24 |
| 4.3 | TRAVEL | 25 |
| 5.0 | SPECIFIC TASKS AND DELIVERABLES | 25 |
| 5.1 | PROJECT MANAGEMENT | 26 |
| 5.1.1 | CONTRACTOR PROJECT MANAGEMENT PLAN | 26 |
| 5.1.2 | REPORTING REQUIREMENTS | 26 |
| 5.2 | <ADDITIONAL TASK(S)> | 27 |
| 6.0 | GENERAL REQUIREMENTS | 27 |
| 6.1 | ENTERPRISE AND IT FRAMEWORK | 27 |
| 6.1.1 | VA TECHNICAL REFERENCE MODEL | 27 |
| 6.1.2 | FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM) | 27 |
| 6.1.3 | INTERNET PROTOCOL VERSION 6 (IPV6) | 29 |
| 6.1.4 | TRUSTED INTERNET CONNECTION (TIC) | 30 |
| 6.1.5 | STANDARD COMPUTER CONFIGURATION | 30 |
| 6.1.6 | VETERAN FOCUSED INTEGRATION PROCESS (VIP) | 31 |
| 6.1.7 | PROCESS ASSETT LIBRARY (PAL) | 31 |
| 6.1.8 | AUTHORITATIVE DATA SOURCES | 32 |
| 6.2 | SECURITY AND PRIVACY REQUIREMENTS | 32 |
| 6.2.1 | POSITION/TASK RISK DESIGNATION LEVEL(S) | 33 |
| 6.2.2 | CONTRACTOR PERSONNEL SECURITY REQUIREMENTS | 34 |
| 6.3 | METHOD AND DISTRIBUTION OF DELIVERABLES | 35 |
| 6.4 | PERFORMANCE METRICS | 36 |
| 6.5 | FACILITY/RESOURCE PROVISIONS | 37 |
| 6.6 | GOVERNMENT FURNISHED PROPERTY | 38 |
| 6.7 | SHIPMENT OF HARDWARE OR EQUIPMENT | 40 |
| ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED | 43 | |
| ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE | 50 |
BACKGROUND
The mission of the Department of Veterans Affairs (VA), Office of Information & Technology (OI&T), Back Office System Management is to provide benefits and services to Veterans of the United States. In meeting these goals, OI&T strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.
The VA has archived emails in Region 1 Veteran Integrated Services Networks (VISN) 22 stored on two Centera storage devices. The Centera storage devices are both past End-Of-Service-Life, as of February 28, 2014. The storage devices are not under a hardware maintenance contract. The Centera storage devices are located in North Hills, California (CA), and Las Vegas, Nevada (NV).
The Centera storage device in North Hills, CA, has experienced multiple hardware failures. A number of hard drives are offline (likely failed) and two internal nodes are offline. Some system data is currently unavailable. VA requires a system health check needs to be performed; the system, to the extent practicable, returned to a normal, healthy state of operation; and VA data from any failed drives retained, to the extent practicable.
The Centera storage device in Las Vegas, NV, has not been on the VA network since approximately 2014 following a data center move. The VA needs assistance reconnecting the system to the VA local area network. VA requires a system health check assessment performed; the system returned to a normal, healthy state of operation, to the extent practicable; and VA data from any failed drives retained, to the extent practicable.
After both Centera devices have been returned to a healthy state of operation, VA requires the systems be configured to replicate data between the two devices.
APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”
4. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information Systems, February 2004
5. FIPS Pub 200, Minimum Security Requirements for Federal Information and Information Systems, March 2016
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013
7. 10 U.S.C. § 2224, "Defense Information Assurance Program"
8. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010
9. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
10. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters
11. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
12. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/
13. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs
14. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003
16. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017
20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
21. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012
22. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015
23. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
24. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI)”, July 28, 2016
25. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA Information Systems,” February 3, 2014
26. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle”, March 22, 2010
27. VA Handbook 6500.6, “Contract Security,” March 12, 2010
28. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011
29. OI&T Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
30. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
31. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014
32. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
33. VA Handbook 6510, “VA Identity and Access Management”, January 15, 2016
34. VA Directive 6300, Records and Information Management, February 26, 2009
35. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
36. NIST SP 800-37 Rev 1, Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach, June 5, 2014
37. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015
38. OMB Memorandum, “Transition to IPv6”, September 28, 2010
39. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, October 26, 2015
40. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 24, 2014
41. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006
42. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003
43. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005
44. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011
45. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008
46. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011
47. NIST SP 800-116 Rev 1, Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access, June 2018
48. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
49. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017
50. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014
51. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012
52. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014
53. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
54. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
55. VA Memorandum “Mandate to meet PIV Requirements for New and Existing Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
56. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.2, Federal Interagency Technical Reference Architectures, Department of Homeland Security, June 19, 2017, https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf
57. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007
58. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008
59. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)
60. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
61. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
62. Executive Order 13834, “Efficient Federal Operations”, dated May 17, 2018
63. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
64. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013
65. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013
66. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
67. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
68. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
69. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
70. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
71. “Veteran Focused Integration Process (VIP) Guide 3.1”, April 2018, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
72. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411
73. “POLARIS User Guide”, Version 1.9, March 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
74. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
SCOPE OF WORK
The Contractor shall perform system health checks and repairs on two Centera storage devices (to the extent practicable ). After repairs are completed on both systems, the contractor shall establish bidirectional replication between both systems. Lastly, the Contractor shall examine the Centera devices for any missing data that is referenced in the Enterprise Archive Solution database.
PERFORMANCE DETAILS
PERFORMANCE PERIOD
The PoP shall be 45 days from date of award.
Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).
Any billable work performed by Contractor shall be performed Monday-Friday 8:30 am to 5 pm local time unless approved by the Contracting Officer (CO).
There are ten (10) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
| New Year's Day | January 1 |
| Independence Day | July 4 |
| Veterans Day | November 11 |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January |
| Washington's Birthday | Third Monday in February |
| Memorial Day | Last Monday in May |
| Labor Day | First Monday in September |
| Columbus Day | Second Monday in October |
| Thanksgiving | Fourth Thursday in November |
PLACE OF PERFORMANCE
Onsite repair tasks under this PWS shall be performed in VA facilities located in North Hills, CA and Las Vegas, NV. Work on system diagnostics or troubleshooting may be performed at remote locations.
Location 1:
Sepulveda – Greater Las Angeles - Centera 16111 Plummer St.
Bldg. 201 RM 115 North Hills, CA 91343
Location 2:
Las Vegas - Centera 6900 North Pecos Road Bldg. 133 RM# Las Vegas, NV 89086
The VA will provide the names of local site contacts at both locations.
Contractor staff may work temporarily at the VA facility, but will not have dedicated work space, desks or other services provided by the VA.
TRAVEL
The Government anticipates that travel in the local commuting area will be required to perform the tasks associated with this effort. The Government does not anticipate directly reimbursing any travel costs.
Travel shall be in accordance with the Federal Travel Regulations (FTR) and requires advanced concurrence by the COR. Contractor travel within the local commuting area will not be reimbursed.
SPECIFIC TASKS AND DELIVERABLES
PROJECT MANAGEMENT
The Contractor shall provide the Contracting Officer’s Representative (COR) with Weekly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Week
The Weekly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.
The Contractor shall provide a weekly teleconference meeting with the VA COR and Program Manager.
Deliverable:
A. Weekly Progress Report
Repair of Centera APM00053305066, North Hills, CA When possible, VA owned replacement parts will be used. The VA may repurpose available hardware for repair purposes. Before installing billable repair parts, the contractor shall confirm with the Contracting Officer’s Representative (COR), that VA does not have a compatible part available that could be used instead.
The VA must retain all storage devices, disk drives and random-access memory (RAM) from the storage systems. The VA may choose to keep unusable parts. The VA accepts that a higher cost will apply to replacement parts where the VA is not returning the bad parts to the vendor.
The contractor shall perform the following on the existing storage device:
a. System Health Check and provide written recommendations for repairs to the VA.
b. Restore System to full normal operating condition ( to the extent practicable). Provide a written report documenting all repairs that were completed, and any needed repairs that could not be completed.
c. Replace all failed disk drives, preserving as much VA data from each failed drive as possible using contractor provided Dell EMC vendor tools. For each disk drive replacement, provide a written report regarding how much data was recovered from the drive, and estimate how much data could not be recovered.
d. Re-establish bidirectional data synchronization with Centera 3774 in Las Vegas, NV, ensuring that no data is deleted from either Centera device. Provide written “before” and “after” reports on both devices, which verify that no data was deleted from either Centera.
e. Provide written recommendations regarding any additional proactive system maintenance that is recommended (i.e. system software or firmware upgrades).
f. If approved by a VA Contracting Officer, implement additional proactive system maintenance. Provide a written report of any additional system maintenance performed.
Deliverables:
A. Written recommendations for repairs following System Health Check B. Written report of all repairs that were completed, and any needed repairs that could not be completed.
C. Written report for each hard drive replacement, how much data was recovered from the drive, and estimate how much data could not be recovered. 1 report for each hard drive replaced.
D. Before and After reports for data synchronization, verifying that no data was deleted from either Centera (1 Before Report, 1 After Report).
E. Written recommendations to the VA regarding any additional proactive system maintenance that is recommended by Dell EMC.
F. Written report of any additional system maintenance that was performed.
REPAIR OF Centera APM00054203774, Las Vegas, NV When possible, VA owned replacement parts will be used. The VA may repurpose available hardware for repair purposes. Before installing billable repair parts, the contractor shall confirm with the Contracting Officer’s Representative (COR), that VA does not have a compatible part available that could be used instead.
The VA must retain all storage devices, disk drives and random-access memory (RAM) from the storage systems. The VA may choose to keep unusable parts. The VA accepts that a higher cost will apply to replacement parts where the VA is not returning the bad parts to the vendor.
The contractor shall perform the following on the existing storage device:
a. Provide technical guidance and support to VA staff to reconnect the System to the VA local area network.
b. System Health Check and provide written recommendations for repairs to the VA.
c. Restore System to full normal operating condition (as much as possible). Provide a written report documenting all repairs that were completed, and any needed repairs that could not be completed.
d. Replace all failed disk drives, preserving as much VA data from each failed drive as possible using contractor provided Dell EMC vendor tools. For each disk drive replacement, provide a written report regarding how much data was recovered from the drive, and estimate how much data could not be recovered.
e. Re-establish bidirectional data synchronization with Centera 5066 in North Hills, CA ensuring that no data is deleted from either Centera device. Provide written “before” and “after” reports on both devices, which verify that no data was deleted from either Centera.
f. Provide written recommendations regarding any additional proactive system maintenance that is recommended by Dell EMC (such as system software or firmware upgrades).
g. If approved by a VA Contracting Officer, implement additional proactive system maintenance. Provide a written report of any additional system maintenance performed.
Deliverables:
A. Written recommendations for repairs following System Health Check B. Written report of all repairs that were completed, and any needed repairs that could not be completed.
C. Written report for each hard drive replacement, how much data was recovered from the drive, and estimate how much data could not be recovered. 1 report for each hard drive replaced.
D. Before and After reports for data synchronization, verifying that no data was deleted from either Centera (1 Before Report, 1 After Report).
E. Written recommendations to the VA regarding any additional proactive system maintenance that is recommended by Dell EMC.
F. Written report of any additional system maintenance that was performed.
Data Integrity Review
After Tasks 5.2 and 5.3 are complete, the Contractor shall work with VA staff to identify if all expected data is available on the system, and identify any VA data that is missing and was unable to be recovered.
Deliverable:
A. Written report identifying any email archive data identifiers (Centera Clip-IDs) that are contained in the Enterprise Archive Solution database, but are not located on either Centera device.
GENERAL REQUIREMENTS
ENTERPRISE AND IT FRAMEWORK
VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OI&T. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.
POSITION/TASK RISK DESIGNATION LEVEL(S)
METHOD AND DISTRIBUTION OF DELIVERABLES
The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include: MS Word 2000/2003/2007/2010, MS Excel 2000/2003/2007/2010, MS PowerPoint 2000/2003/2007/2010, MS Project 2000/2003/2007/2010, MS Access 2000/2003/2007/2010, MS Visio 2000/2002/2003/2007/2010, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data Format (PDF).
PERFORMANCE METRICS
The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.
| Performance Objective |
| Performance Standard |
| Acceptable Levels of Performance |
| A. Technical / Quality of Product or Service |
| 1. Demonstrates understanding of requirements |
2. Efficient and effective in meeting requirements
3. Meets technical needs and mission requirements
4. Provides quality services/products Satisfactory or higher
| B. Project Milestones and Schedule |
| 1. Established milestones and project dates are met |
2. Products completed, reviewed, delivered in accordance with the established schedule
3. Notifies customer in advance of potential problems Satisfactory or higher
| C. Cost & Staffing |
| 1. Currency of expertise and staffing levels appropriate |
2. Personnel possess necessary knowledge, skills and abilities to perform tasks Satisfactory or higher
| D. Management |
| 1. Integration and coordination of all activities to execute effort |
| Satisfactory or higher |
The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the surveillance methods in the QASP at its own discretion. A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.
FACILITY/RESOURCE PROVISIONS
The Government will not provide any office space or telephone service for contract staff. For onsite break-fix repair work, the Government anticipates that the work will be performed primarily in the appropriate VA data center. Contractor resources will have escorted access to the facility.
The VA will not provide remote access to VA specific systems/network.
SHIPMENT OF HARDWARE OR EQUIPMENT
If any hardware replacement parts are provided by the Contractor, the Contractor shall physically bring parts on-site to the VA data center for installation.
ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED
Cyber and Information Security Requirements for VA IT Services The Contractor shall ensure adequate LAN/Internet, data, information, and system security in accordance with VA standard operating procedures and standard PWS language, conditions, laws, and regulations. The Contractor’s firewall and web server shall meet or exceed VA minimum requirements for security. All VA data shall be protected behind an approved firewall. Any security violations or attempted violations shall be reported to the VA Program Manager and VA Information Security Officer as soon as possible. The Contractor shall follow all applicable VA policies and procedures governing information security, especially those that pertain to certification and accreditation.
Contractor supplied equipment, PCs of all types, equipment with hard drives, etc. for contract services must meet all security requirements that apply to Government Furnished Equipment (GFE) and Government Owned Equipment (GOE). Security Requirements include: a) VA Approved Encryption Software must be installed on all laptops or mobile devices before placed into operation, b) Bluetooth equipped devices are prohibited within VA; Bluetooth must be permanently disabled or removed from the device, unless the connection uses FIPS 140-2 (or its successor) validated encryption, c) VA approved anti-virus and firewall software, d) Equipment must meet all VA sanitization requirements and procedures before disposal. The COR, CO, the PM, and the Information Security Officer (ISO) must be notified and verify all security requirements have been adhered to.
Each documented initiative under this contract incorporates VA Handbook 6500.6, “Contract Security,” March 12, 2010 by reference as though fully set forth therein. The VA Handbook 6500.6, “Contract Security” shall also be included in every related agreement, contract or order. The VA Handbook 6500.6, Appendix C, is included in this document as Addendum B.
Training requirements: The Contractor shall complete all mandatory training courses on the current VA training site, the VA Talent Management System (TMS) 2.0, and will be tracked therein. The TMS 2.0 may be accessed at https://www.tms.va.gov/SecureAuth35/ . If you do not have a TMS 2.0 profile, go to https://www.tms.va.gov/SecureAuth35/ and click on the “Create New User” link on the TMS 2.0 to gain access.
Contractor employees shall complete a VA Systems Access Agreement if they are provided access privileges as an authorized user of the computer system of VA.
VA Enterprise Architecture Compliance The applications, supplies, and services furnished under this contract must comply with VA Enterprise Architecture (EA), available at http://www.ea.oit.va.gov/index.asp in force at the time of issuance of this contract, including the Program Management Plan and VA's rules, standards, and guidelines in the Technical Reference Model/Standards Profile (TRMSP). VA reserves the right to assess contract deliverables for EA compliance prior to acceptance.
VA Internet and Intranet Standards
The Contractor shall adhere to and comply with VA Directive 6102 and VA Handbook 6102, Internet/Intranet Services, including applicable amendments and changes, if the Contractor’s work includes managing, maintaining, establishing and presenting information on VA’s Internet/Intranet Service Sites. This pertains, but is not limited to: creating announcements; collecting information; databases to be accessed, graphics and links to external sites.
Internet/Intranet Services Directive 6102 is posted at (copy and paste the following URL to browser): https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=409&FType=2
Internet/Intranet Services Handbook 6102 is posted at (copy and paste following URL to browser): https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=410&FType=2
Notice of the Federal Accessibility Law Affecting All Information and Communication Technology (ICT) Procurements (Section 508)
On January 18, 2017, the Architectural and Transportation Barriers Compliance Board (Access Board) revised and updated, in a single rulemaking, standards for electronic and information technology developed, procured, maintained, or used by Federal agencies covered by Section 508 of the Rehabilitation Act of 1973, as well as our guidelines for telecommunications equipment and customer premises equipment covered by Section 255 of the Communications Act of 1934. The revisions and updates to the Section 508-based standards and Section 255-based guidelines are intended to ensure that information and communication technology (ICT) covered by the respective statutes is accessible to and usable by individuals with disabilities.
Section 508 – Information and Communication Technology (ICT) Standards
The Section 508 standards established by the Access Board are incorporated into, and made part of all VA orders, solicitations and purchase orders developed to procure ICT. These standards are found in their entirety at: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines. A printed copy of the standards will be supplied upon request.
Federal agencies must comply with the updated Section 508 Standards beginning on January 18, 2018. The Final Rule as published in the Federal Register is available from the Access Board: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule.
The Contractor shall comply with “508 Chapter 2: Scoping Requirements” for all electronic ICT and content delivered under this contract. Specifically, as appropriate for the technology and its functionality, the Contractor shall comply with the technical standards marked here:
| |X| | E205 Electronic Content – (Accessibility Standard -WCAG 2.0 Level A and AA Guidelines) |
| |X| | E204 Functional Performance Criteria |
| |X| | E206 Hardware Requirements |
| |X| | E207 Software Requirements |
| |X| | E208 Support Documentation and Services Requirements |
Compatibility with Assistive Technology
The standards do not require installation of specific accessibility-related software or attachment of an assistive technology device. Section 508 requires that ICT be compatible with such software and devices so that ICT can be accessible to and usable by individuals using assistive technology, including but not limited to screen readers, screen magnifiers, and speech recognition software.
Acceptance and Acceptance Testing
Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.
The Government reserves the right to test for Section 508 Compliance before delivery. The Contractor shall be able to demonstrate Section 508 Compliance upon delivery.
Physical Security & Safety Requirements:
The Contractor and their personnel shall follow all VA policies, standard operating procedures, applicable laws and regulations while on VA property. Violations of VA regulations and policies may result in citation and disciplinary measures for persons violating the law.
1. The Contractor and their personnel shall wear visible identification at all times while they are on the premises.
2. VA does not provide parking spaces at the work site; the Contractor must obtain parking at the work site if needed. It is the responsibility of the Contractor to park in the appropriate designated parking areas. VA will not invalidate or make reimbursement for parking violations of the Contractor under any conditions.
3. Smoking is prohibited inside/outside any building other than the designated smoking areas.
4. Possession of weapons is prohibited.
5. The Contractor shall obtain all necessary licenses and/or permits required to perform the work, with the exception of software licenses that need to be procured from a Contractor or vendor in accordance with the requirements document. The Contractor shall take all reasonable precautions necessary to protect persons and property from injury or damage during the performance of this contract.
Confidentiality and Non-Disclosure The Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations.
The Contractor may have access to Protected Health Information (PHI) and Electronic Protected Health Information (EPHI) that is subject to protection under the regulations issued by the Department of Health and Human Services, as mandated by the Health Insurance Portability and Accountability Act of 1996 (HIPAA); 45 CFR Parts 160 and 164, Subparts A and E, the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”); and 45 CFR Parts 160 and 164, Subparts A and C, the Security Standard (“Security Rule”). Pursuant to the Privacy and Security Rules, the Contractor must agree in writing to certain mandatory provisions regarding the use and disclosure of PHI and EPHI.
1. The Contractor will have access to some privileged and confidential materials of VA. These printed and electronic documents are for internal use only, are not to be copied or released without permission, and remain the sole property of VA. Some of these materials are protected by the Privacy Act of 1974 (revised by PL 93-5791) and Title 38. Unauthorized disclosure of Privacy Act or Title 38 covered materials is a criminal offense.
2. The VA CO will be the sole authorized official to release in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this contract. The Contractor shall release no information. Any request for information relating to this contract presented to the Contractor shall be submitted to the VA CO for response.
3. Contractor personnel recognize that in the performance of this effort, Contractor personnel may receive or have access to sensitive information, including information provided on a proprietary basis by carriers, equipment manufacturers and other private or public entities. Contractor personnel agree to safeguard such information and use the information exclusively in the performance of this contract. Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations as enumerated in this section and elsewhere in this Contract and its subparts and appendices.
4. Contractor shall limit access to the minimum number of personnel necessary for contract performance for all information considered sensitive or proprietary in nature. If the Contractor is uncertain of the sensitivity of any information obtained during the performance this contract, the Contractor has a responsibility to ask the VA CO.
5. Contractor shall train all of their employees involved in the performance of this contract on their roles and responsibilities for proper handling and nondisclosure of sensitive VA or proprietary information. Contractor personnel shall not engage in any other action, venture or employment wherein sensitive information shall be used for the profit of any party other than those furnishing the information. The sensitive information transferred, generated, transmitted, or stored herein is for VA benefit and ownership alone.
6. Contractor shall maintain physical security at all facilities housing the activities performed under this contract, including any Contractor facilities according to VA-approved guidelines and directives. The Contractor shall ensure that security procedures are defined and enforced to ensure all personnel who are provided access to patient data must comply with published procedures to protect the privacy and confidentiality of such information as required by VA.
7. Contractor must adhere to the following:
a. The use of “thumb drives” or any other medium for transport of information is expressly prohibited.
b. Controlled access to system and security software and documentation.
c. Recording, monitoring, and control of passwords and privileges.
d. All terminated personnel are denied physical and electronic access to all data, program listings, data processing equipment and systems.
e. VA, as well as any Contractor (or Subcontractor) systems used to support development, provide the capability to cancel immediately all access privileges and authorizations upon employee termination.
f. Contractor PM and VA PM are informed within twenty-four (24) hours of any employee termination.
g. Acquisition sensitive information shall be marked "Acquisition Sensitive" and shall be handled as "For Official Use Only (FOUO)".
h. Contractor does not require access to classified data.
8. Regulatory standard of conduct governs all personnel directly and indirectly involved in procurements. All personnel engaged in procurement and related activities shall conduct business in a manner above reproach and, except as authorized by statute or regulation, with complete impartiality and with preferential treatment for none. The general rule is to strictly avoid any conflict of interest or even the appearance of a conflict of interest in VA/Contractor relationships.
9. VA Form 0752 shall be completed by all Contractor employees working on this contract, and shall be provided to the CO before any work is performed. In the case that Contractor personnel are replaced in the future, their replacements shall complete VA Form 0752 prior to beginning work.
INFORMATION TECHNOLOGY USING ENERGY-EFFICIENT PRODUCTS
The Contractor shall comply with Sections 524 and Sections 525 of the Energy Independence and Security Act of 2007; Section 104 of the Energy Policy Act of 2005; Executive Order 13834, “Efficient Federal Operations”, dated May 17, 2018; Executive Order 13221, “Energy-Efficient Standby Power Devices,” dated August 2, 2001; and the Federal Acquisition Regulation (FAR) to provide ENERGY STAR®, Federal Energy Management Program (FEMP) designated, low standby power, and Electronic Product Environmental Assessment Tool (EPEAT) registered products in providing information technology products and/or services.
The Contractor shall ensure that information technology products are procured and/or services are performed with products that meet and/or exceed ENERGY STAR, FEMP designated, low standby power, and EPEAT guidelines. The Contractor shall provide/use products that earn the ENERGY STAR label and meet the ENERGY STAR specifications for energy efficiency. Specifically, the Contractor shall:
1. Provide/use ENERGY STAR products, as specified at www.energystar.gov/products (contains complete product specifications and updated lists of qualifying products).
2. Provide/use the purchasing specifications listed for FEMP designated products at https://www4.eere.energy.gov/femp/requirements/laws_and_requirements/energy_star_and_femp_designated_products_procurement_requirements . The Contractor shall use the low standby power products specified at http://energy.gov/eere/femp/low-standby-power-products.
3. Provide/use EPEAT registered products as specified at www.epeat.net. At a minimum, the Contractor shall acquire EPEAT® Bronze registered products. EPEAT registered products are required to meet the technical specifications of ENERGY STAR, but are not automatically on the ENERGY STAR qualified product lists. The Contractor shall ensure that applicable products are on both the EPEAT Registry and ENERGY STAR Qualified Product Lists.
If the acquisition is NOT Lowest Price Technically Acceptable (LPTA) please insert the following language into paragraph 3 above (in black text): “The acquisition of Silver or Gold EPEAT registered products is encouraged over Bronze EPEAT registered products”.
4. The Contractor shall use these products to the maximum extent possible without jeopardizing the intended end use or detracting from the overall quality delivered to the end user.
The following is a list of information technology products for which ENERGY STAR, FEMP designated, low standby power, and EPEAT registered products are available:
1. Computer Desktops, Laptops, Notebooks, Displays, Monitors, Integrated Desktop Computers, Workstation Desktops, Thin Clients, Disk Drives
2. Imaging Equipment (Printers, Copiers, Multi-Function Devices, Scanners, Fax Machines, Digital Duplicators, Mailing Machines)
3. Televisions, Multimedia Projectors
This list is continually evolving, and as a result is not all-inclusive.
OEM HARDWARE REQUIREMENTS
The Contractor shall ensure that information technology products are procured and/or services are performed with products that are new equipment and new parts for the required services described herein; no used, refurbished, or remanufactured equipment or parts shall be provided unless otherwise authorized by the Contracting Officer Representative. Absolutely no “Gray Market Goods” or “Counterfeit Electronic Parts” shall be provided. Gray market goods are defined as genuine branded goods intentionally or unintentionally sold outside of an authorized sales-territory or by non-authorized dealers in an authorized territory. All equipment shall be accompanied by a warranty. Counterfeit electronic parts are defined as unlawful or unauthorized reproduction, substitution, or alteration that has been knowingly mismarked, misidentified, or otherwise misrepresented to be an authentic, unmodified electronic part from the original manufacturer, or a source with the express written authority of the original manufacturer or current design activity, including an authorized aftermarket manufacturer. Unlawful or unauthorized substitution includes used electronic parts represented as new, or the false identification of grade, serial number, lot number, date code, or performance characteristics.
ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE
APPLICABLE PARAGRAPHS TAILORED FROM: THE VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE, VA HANDBOOK 6500.6, APPENDIX C, MARCH 12, 2010
GENERAL
Contractors, Contractor personnel, Subcontractors, and Subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A Contractor/Subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, Subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
b. All Contractors, Subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for Contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates (e.g. Business Associate Agreement, Section 3G), the Contractor/Subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
e. The Contractor or Subcontractor must notify the CO immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the Contractor or Subcontractor’s employ. The CO must also be notified immediately by the Contractor or Subcontractor prior to an unfriendly termination.
VA INFORMATION CUSTODIAL LANGUAGE
1. Information made available to the Contractor or Subcontractor by VA for the performance or administration of this contract or information developed by the Contractor/Subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of VA. This clause expressly limits the Contractor/Subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
2. VA information should not be co-mingled, if possible, with any other data on the Contractors/Subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the Contractor must ensure that VA information is returned to VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on site inspections of Contractor and Subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
3. Prior to termination or completion of this contract, Contractor/Subcontractor must not destroy information received from VA, or gathered/created by the Contractor in the course of performing this contract without prior written approval by VA. Any data destruction done on behalf of VA by a Contractor/Subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the Contractor that the data destruction requirements above have been met must be sent to the VA CO within 30 days of termination of the contract.
4. The Contractor/Subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
5. The Contractor/Subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on Contractor/Subcontractor electronic storage media for restoration in case any electronic equipment or data used by the Contractor/Subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
6. If VA determines that the Contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the Contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
7. If a VHA contract is terminated for cause, the associated Business Associate Agreement (BAA) must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.05, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
8. The Contractor/Subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.