36C10A19Q0204-002.pdf
PDF 340 KB Posted
- Attached to
- AITC PACS Physical Access Control System Federal contract opportunity
- Solicitation number
- 36C10A19Q0204
About this file
36C10A19Q0204 S02 - Attachment 01 - PWS at RFQ.pdf
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10A19Q0204-001.docx | DOCX document | |
| 36C10A19Q0204-003.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Office of Information & Technology Austin Information Technology Center
AITC Physical Access Control System (PACS)
Maintenance Contract
Date: August 19, 2019
TAC-19-55401
PWS Version Number: 2.0
AITC PACS Maintenance Contract
Contents
1.0 BACKGROUND
2.0 APPLICABLE DOCUMENTS
3.0 SCOPE OF WORK
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
4.2 PLACE OF PERFORMANCE
4.3 TRAVEL
5.0 SPECIFIC TASKS AND DELIVERABLES
EQUIPMENT LIST
5.1 PROJECT MANAGEMENT
5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN
5.1.2 REPORTING REQUIREMENTS
5.1.3 CONTRACTOR REQUIREMENTS
6.0 GENERAL REQUIREMENTS
6.1 ENTERPRISE AND IT FRAMEWORK
6.1.1 VA TECHNICAL REFERENCE MODEL
6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT
(FICAM)
6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)
6.1.4 TRUSTED INTERNET CONNECTION (TIC)
6.1.5 STANDARD COMPUTER CONFIGURATION
6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP)
6.1.7 PROCESS ASSETT LIBRARY (PAL)
6.1.8 AUTHORITATIVE DATA SOURCES
6.2 SECURITY AND PRIVACY REQUIREMENTS
6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S)
6.2.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
6.3 METHOD AND DISTRIBUTION OF DELIVERABLES
6.4 PERFORMANCE METRICS
6.5 SHIPMENT OF HARDWARE OR EQUIPMENT
ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM
SECURITY/PRIVACY LANGUAGE
1.0 BACKGROUND
The mission of the Department of Veterans Affairs (VA), Office of Information & Technology (OI&T), Austin Information Technology Center (VA-AITC) is to provide benefits and services to Veterans of the United States. In meeting these goals, OI&T strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.
This contract is for VA-AITC PACS 24/7 maintenance contract to respond to Security Devices maintenance and repairs.
2.0 APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”
4. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information Systems, February 2004
5. FIPS Pub 200, Minimum Security Requirements for Federal Information and
Information Systems, March 2016
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and
Contractors,” August 2013
7. 10 U.S.C. § 2224, "Defense Information Assurance Program"
8. Carnegie Mellon Software Engineering Institute, Capability Maturity Model®
Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010
9. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
10. Public Law 109-461, Veterans Benefits, Health Care, and Information
Technology Act of 2006, Title IX, Information Security Matters
11. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
12. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/
13. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs
14. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility
Standards,” July 1, 2003 http://www.va.gov/vapubs/ http://www.va.gov/vapubs http://www.va.gov/vapubs
16. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017
20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
21. VA Directive 6500, “Managing Information Security Risk: VA Information
Security Program,” September 20, 2012
22. VA Handbook 6500, “Risk Management Framework for VA Information
Systems – Tier 3: VA Information Security Program,” March 10, 2015
23. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
24. VA Handbook 6500.2, “Management of Breaches Involving Sensitive
Personal Information (SPI)”, July 28, 2016
25. VA Handbook 6500.3, “Assessment, Authorization, And Continuous
Monitoring Of VA Information Systems,” February 3, 2014
26. VA Handbook 6500.5, “Incorporating Security and Privacy in System
Development Lifecycle”, March 22, 2010
27. VA Handbook 6500.6, “Contract Security,” March 12, 2010
28. VA Handbook 6500.8, “Information System Contingency Planning”, April 6,
29. OI&T Process Asset Library (PAL), https://www.va.gov/process/ . Reference
Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
30. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
31. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014
32. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
33. VA Handbook 6510, “VA Identity and Access Management”, January 15,
34. VA Directive 6300, Records and Information Management, February 26,
35. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
36. NIST SP 800-37 Rev 1, Guide for Applying the Risk Management
Framework to Federal Information Systems: a Security Life Cycle Approach, June 5, 2014
37. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015
38. OMB Memorandum, “Transition to IPv6”, September 28, 2010
39. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12)
Program, October 26, 2015 https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx
40. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 24, 2014
41. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006
42. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003
43. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005
44. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3,
45. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008
46. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011
47. NIST SP 800-116 Rev 1, Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access, June 2018
48. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
49. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017
50. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014
51. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile
Devices (Draft), October 2012
52. Draft National Institute of Standards and Technology Interagency Report
(NISTIR) 7981 Mobile, PIV, and Authentication, March 2014
53. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland
Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
54. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
55. VA Memorandum “Mandate to meet PIV Requirements for New and Existing Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
56. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.2, Federal Interagency Technical Reference Architectures, Department of Homeland Security, June 19, 2017, https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017 .pdf
57. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007
58. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf
59. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)
60. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
61. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
62. Executive Order 13834, “Efficient Federal Operations”, dated May 17, 2018
63. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August
2, 2001
64. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013
65. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013
66. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote
Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
67. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
68. VA Memorandum, “Implementation of Federal Personal Identity Verification
(PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
69. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
70. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015;
https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
71. “Veteran Focused Integration Process (VIP) Guide 3.2”, December 2018, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
72. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411
73. “POLARIS User Guide”, Version 1.9, March 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
74. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
3.0 SCOPE OF WORK
The Contractor shall provide 24/7 support and maintain the existing Physical Access Control Systems (PACS) and Closed-Circuit Television Video (CCTV) systems installed at the AITC, to include providing C-Cure 9000 and EverRun Software support agreements through Software House. The contractor shall manage a service request response system for PACS and CCTV maintenance requests. The contractor shall employ maintenance personnel which are trained and certified in the use and operation of all PACS and CCTV equipment located within the facility and listed in paragraph 5 herein, prior to conducting any work at the AITC.
The contractor shall provide maintenance repairs and support for the AITC PACS and CCTV located at 1615 Woodward Street, Austin, Texas. The contractor shall provide all resources necessary to maintain and repair the existing PACS and CCTV systems, furnish all labor, supervision, equipment, tools, materials, supplies, travel and transportation necessary to provide PACS and CCTV systems maintenance and repairs.
Repair and replacement parts shall be included at no additional cost to the Government.
Systems functionality shall be achieved upon completion of the first service call.
Functionality is defined as a working system as designed but may be accomplished with any part available to the Technician at the time of service. Only in an event where repair is not possible during service, a loaner (or equal) part may be used to regain system functionality.
The contractor must be Enterprise Software House Dealer/Distributor and Master Technician certified, as well as Avigilon Camera/Computer Server certified.
Documentation of each must be provided. Due to requirement of 24/7 support, contractor must have local representatives that can satisfy the required response time for repairs, as defined in paragraph 5 below.
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
The period of performance shall be from October 23, 2019, through October 22, 2020, with four 12-month optional periods of performance as follows:
Option Year 1: October 23, 2020 – October 22, 2021
Option Year 2: October 23, 2021 – October 22, 2022
Option Year 3: October 23, 2022 – October 22, 2023
Option Year 4: October 23, 2023 – October 22, 2024
There are ten (10) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
New Year's Day January 1 Independence Day July 4 Veterans Day November 11 Christmas Day December 25
If any of the above falls on a Saturday, then Friday shall be observed as a holiday.
Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November
4.2 PLACE OF PERFORMANCE
Tasks under this PWS shall be performed at 1615 Woodward Street, Austin, TX 78772.
4.3 TRAVEL
The Government anticipates local travel under this effort to perform the tasks associated with the effort, as well as to attend program-related meetings or conferences throughout the PoP. Include all estimated travel costs in your firm-fixed price line items.
These costs will not be directly reimbursed by the Government.
5.0 SPECIFIC TASKS AND DELIVERABLES
1) The contractor shall obtain all necessary equipment, parts, manufacturer's specifications, and drawings to manage the PACS and CCTV maintenance and repair as required by this PWS; See equipment list below. The Contractor shall maintain an on-site inventory mix of appropriate replacement parts necessary for the security equipment. Replacement parts are included at no additional cost to the Government. The contractor shall provide non-repairable items to the Contracting Officer’s Representative (COR) for turn in and accountability. All replaced equipment is property of the VA.
2) Contractor shall provide the Government COR with the Contractor’s technical support number and one Point of Contact (POC) for service and account representation. POC shall provide customer service to VA for all questions or concerns related to this requirement.
3) The Contractor shall provide a maintenance “return to service” level of response with a technician on-site to resolve all failures within eight (8) hours after the VA representative calls the Contractor’s technical support number. The contractor shall provide technical support Monday through Friday, from 8:00 A.M. through 5:00 P.M.
Central Standard Time (CST). PACS and/or CCTV operating systems must be fully functional upon completion of service call.
4) The contractor shall perform maintenance services Monday through Friday during normal business hours, 8:00 A.M. through 5:00 P.M. CST, and the contractor shall start no later than 1:00 P.M. CST. For outdoor surveillance camera repair and/or replacement, a boom lift will be required to access the cameras after business hours.
Outdoor surveillance cameras are an estimated 20-25 feet high on light poles in the parking lot.
5) After business hours repair or services may be required by the Government.
a) This shall be effective during non-business hours.
b) Response time is four (4) hours.
c) Service will generally be requested by a service ticket signed by the COR;
however, the CO or COR may designate in writing other Government employees and/or contractors authorized to request services and sign service tickets. The CO, COR, or other designated Government representative may direct the contractor to perform the work during Holidays and outside of normal, 8:00 A.M.
through 5:00 P.M. CST, business hours.
6) The Contractor shall advise the COR of potential delays in completion of any aspects of the repair and provide recommendations on actions necessary for keeping the task on schedule.
7) The Contractor shall perform semiannual preventive maintenance on the PACS and CCTV systems during the contract maintenance period. This shall include the manual inspecting and testing of all PACS and CCTV components with inspection/testing reports on a regular basis in accordance with manufacturer recommendations. Also, the maintenance shall include site visits required to modify or replace any component of the PACS and CCTV system. The contractor shall provide to the VA Security Officer or COR, a site visit report listing all updates and corrective actions. The contractor shall verify the operation of the systems with VA Security or COR upon completion of work.
8) The contractor shall repair or replace any PACS and CCTV equipment, see equipment list below, as necessary to keep equipment fully functional and operating in accordance with manufacturer’s specifications. The contractor shall ensure that all PACS and CCTV equipment is properly configured and setup to achieve internet connectivity for all AITC servers connected to the PACS and CCTV system.
EQUIPMENT LIST
Complete access control, alarm monitoring, and photo imaging system located at the AITC includes the following:
(QTY) Product / Description
• (2) Main (head end’) / server computers and all connected accessories (such as a UPS, printer & etc.). Server located in computer room 134.
• (13) Operator interface computers and all connected accessories (such as a UPS, printer & etc.)
• (1) Badge issuing station equipment (Nisca PR5100 card printer).
• Network components (hubs, boosters, cabling & etc.)
• All access control software (C-Cure 9000) and related modules or applications for eight C-Cure workstations and PIV computers
• (50) All Software House iStars panels
• (30) All Power Distribution Units (PDU’s)
• (158) custom-built keypad readers.
• (110) HID Badge Readers.
• (35) HID Badge Readers with keypad.
• (165) Electric Door Strikes.
• (110) Magnetic Door Locks.
Complete surveillance camera control system includes the following:
• (5) Avigilon Video Edge NVR with storage system and (5) station operator computers.
• Cisco switchers.
• AD Camera Controllers.
• (150) Avigilon HD Cameras
• (2) Dell Computer Servers
• (10) Cisco switches
Note: Contractor shall field verify all equipment count.
5.1 PROJECT MANAGEMENT
5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline and tools to be used in execution of the contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA PM approved CPMP throughout the PoP.
Deliverable:
A. Contractor Project Management Plan
5.1.2 REPORTING REQUIREMENTS
The Contractor shall provide the COR with Monthly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Week.
The contractor shall keep detailed comprehensive records of all maintenance and repair.
Records shall include all equipment that has been replaced. The contractor shall submit records monthly to the COR.
The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Information and Communication Technology (ICT) deliverables and their current Section 508 conformance status. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.
A. Weekly service log - The service log data shall include the following:
i. What type of work (Inspection, Service, Repair)
ii. What was serviced (Door number or Camera Number, serial number of part)
iii. When the work was started
iv. When the work was completed
v. Status of the work (completed, still in progress, waiting on parts)
vi. What technician performed the work.
B. Monthly Progress Report - The monthly report shall include the following:
i. Description of services calls completed
ii. Open issues or concerns
iii. Record of equipment that has been replaced
iv. Summation of weekly reports
5.1.3 CONTRACTOR REQUIREMENTS
• The contractor shall maintain a current license and/or license agreement with Software House.
• The contractor shall be C-Cure 9000 and Avigilon Camera/computer server certified.
• Contractor must be Enterprise Software House Dealer/Distributor
• Must have a Software House trained, Master Enterprise Technician on staff for this contract at all times.
• The contractor’s technicians shall have at a minimum of five years relevant experience working with integrated electronic access control and CCTV systems of similar complexity.
• The contractor’s employees shall be able to pass a criminal history background investigation by the AITC Security staff and VA Security and Investigation Center.
• The contractor’s employees shall be legally able to work in the United States.
6.0 GENERAL REQUIREMENTS
6.1 ENTERPRISE AND IT FRAMEWORK
6.1.1 VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OI&T. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.
6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion-based authentication, and/or trust-based authentication, as determined by the https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp http://www.techstrategies.oit.va.gov/enterprise_dp.asp design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M- 05-24, and M-11-11 can be found at:
https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11- 11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems.
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)
The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2005/m05-22.pdf) and September 28, 2010 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transiti on-to-ipv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf), the Technical Infrastructure for USGv6 Adoption (https://www.nist.gov/programs-projects/usgv6-program), and the NIST SP 800 series applicable compliance (https://csrc.nist.gov/publications/sp) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at:
https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.
6.1.4 TRUSTED INTERNET CONNECTION (TIC)
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf.
6.1.5 STANDARD COMPUTER CONFIGURATION
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Office 365 ProPlus. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Windows 10. However, Windows 10 is not the VA standard yet https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf https://www.nist.gov/programs-projects/usgv6-program https://www.nist.gov/programs-projects/usgv6-program https://csrc.nist.gov/publications/sp https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf and is currently approved for limited use during its rollout. We are in-process of this rollout and making Windows 10 the standard for OI&T. Upon the release approval of Windows 10 as the VA standard, Windows 10 will supersede Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.
6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP)
The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products.
6.1.7 PROCESS ASSETT LIBRARY (PAL)
The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section
6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf. The main PAL can be accessed at www.va.gov/process.
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf http://www.va.gov/process
6.1.8 AUTHORITATIVE DATA SOURCES
The VA Enterprise Architecture Repository (VEAR) is one component within the overall Enterprise Architecture (EA) that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:
1. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.
2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.
3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.
4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.
5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.
6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for Qualifying Active Duty military service in the VA.
6.2 SECURITY AND PRIVACY REQUIREMENTS
6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S)
In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:
Position Sensitivity and Background Investigation Requirements by Task Task Number Tier1 / Low Risk Tier 2 / Moderate
Risk Tier 4 / High Risk
5.1.1
5.1.2
5.1.3
The Tasks identified above and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.
6.2.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
Contractor Responsibilities:
a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak and understand the English language.
b. Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.
c. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.
d. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:
1) Optional Form 306
2) Self-Certification of Continuous Service
3) VA Form 0710
4) Completed SIC Fingerprint Request Form
e. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).
f. The Contractor employee shall certify and release the e-QIP document, print and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note:
OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 business days that documents were signed via e-QIP).
g. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.
h. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of
OPM.
i. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.
j. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.
k. Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with
VA.
A. Contractor Staff Roster
6.3 METHOD AND DISTRIBUTION OF DELIVERABLES
The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include:
MS Word 2000/2003/2007/2010, MS Excel 2000/2003/2007/2010, MS PowerPoint 2000/2003/2007/2010, MS Project 2000/2003/2007/2010, MS Access
2000/2003/2007/2010, MS Visio 2000/2002/2003/2007/2010, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data Format (PDF).
6.4 PERFORMANCE METRICS
The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.
Performance Objective
Performance Standard Acceptable Levels of Performance
A. Technical / Quality of Product or Service
1. Demonstrates understanding of requirements
2. Efficient and effective in meeting requirements
3. Meets technical needs and mission requirements
4. Provides quality services/products
Satisfactory or higher
B. Project Milestones and Schedule
1. Established milestones and project dates are met
2. Products completed, reviewed, delivered in accordance with the established schedule
3. Notifies customer in advance of potential problems
Satisfactory or higher
C. Cost & Staffing
1. Currency of expertise and staffing levels appropriate
2. Personnel possess necessary knowledge, skills and abilities to perform tasks
Satisfactory or higher
D. Management
1. Integration and coordination of all activities to execute effort Satisfactory or higher
6.5 SHIPMENT OF HARDWARE OR EQUIPMENT
Inspection: Destination Acceptance: Destination Free on Board (FOB): Destination
Ship To and Mark For:
Primary POC to be provided at award 1615 Woodward Street Austin, TX. 78748
Special Shipping Instructions:
Prior to shipping, Contractor shall notify Site POCs, by phone followed by email, of all incoming deliveries including line-by-line details for review of requirements. Contractor shall not make any changes to the delivery schedule at the request of Site POC.
Contractors shall coordinate deliveries with Site POCs before shipment of hardware to ensure sites have adequate storage space.
All shipments, either single or multiple container deliveries, shall bear the VA IFCAP Purchase Order number on external shipping labels and associated manifests or packing lists. In the case of multiple container deliveries, a statement readable near the VA IFCAP PO number shall indicate total number of containers for the complete shipment (e.g. “Package 1 of 2”), clearly readable on manifests and external shipping labels.
Packing Slips/Labels and Lists shall also include the following:
IFCAP PO #: ____________ (e.g., 166-E11234 (the IFCAP PO number is located in block #20 of the SF 1449)) Project Description: (e.g. Tier I Lifecycle Refresh)
Total number of Containers: Package ___ of ___. (e.g., Package 1 of 3)
ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED
A1.0 Cyber and Information Security Requirements for VA IT Services
The Contractor shall ensure adequate LAN/Internet, data, information, and system security in accordance with VA standard operating procedures and standard PWS language, conditions, laws, and regulations. The Contractor’s firewall and web server shall meet or exceed VA minimum requirements for security. All VA data shall be protected behind an approved firewall. Any security violations or attempted violations shall be reported to the VA Program Manager and VA Information Security Officer as soon as possible. The Contractor shall follow all applicable VA policies and procedures governing information security, especially those that pertain to certification and accreditation.
Contractor supplied equipment, PCs of all types, equipment with hard drives, etc. for contract services must meet all security requirements that apply to Government Furnished Equipment (GFE) and Government Owned Equipment (GOE). Security Requirements include: a) VA Approved Encryption Software must be installed on all laptops or mobile devices before placed into operation, b) Bluetooth equipped devices are prohibited within VA; Bluetooth must be permanently disabled or removed from the device, unless the connection uses FIPS 140-2 (or its successor) validated encryption,
c) VA approved anti-virus and firewall software, d) Equipment must meet all VA sanitization requirements and procedures before disposal. The COR, CO, the PM, and the Information Security Officer (ISO) must be notified and verify all security requirements have been adhered to.
Each documented initiative under this contract incorporates VA Handbook 6500.6, “Contract Security,” March 12, 2010 by reference as though fully set forth therein. The VA Handbook 6500.6, “Contract Security” shall also be included in every related agreement, contract or order. The VA Handbook 6500.6, Appendix C, is included in this document as Addendum B.
Training requirements: The Contractor shall complete all mandatory training courses on the current VA training site, the VA Talent Management System (TMS) 2.0, and will be tracked therein. The TMS 2.0 may be accessed at https://www.tms.va.gov/SecureAuth35/ . If you do not have a TMS 2.0 profile, go to https://www.tms.va.gov/SecureAuth35/ and click on the “Create New User” link on the TMS 2.0 to gain access.
Contractor employees shall complete a VA Systems Access Agreement if they are provided access privileges as an authorized user of the computer system of VA.
A2.0 VA Enterprise Architecture Compliance
The applications, supplies, and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.