P09_-_Final_PWS.pdf

PDF 315 KB Posted

Attached to
Pharmacy Control Software Federal contract opportunity
Solicitation number
36C10A19R0007
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

P09 - Final PWS

View the file

Other files for this federal contract opportunity

Other files attached to Pharmacy Control Software, newest first.
File Type Posted
S02_-_36C10A19R0007_Exhibit_1_Pricing_Table.xlsx XLSX spreadsheet
36C10A19R0007-001.docx DOCX document
36C10A19R0007-002.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Veterans Health Administration Consolidated Mail Outpatient Pharmacy

Pharmacy Control Software

Date: March 4, 2019 PWS Version Number: 0.1

36C10A19Q0079 Attachment #1 PWS

Contents

1.0 BACKGROUND

2.0 APPLICABLE DOCUMENTS

3.0 SCOPE OF WORK

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

4.2 PLACE OF PERFORMANCE

4.3 TRAVEL

5.0 SPECIFIC TASKS AND DELIVERABLES

5.1 PROJECT MANAGEMENT

5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN

5.1.2 REPORTING REQUIREMENTS

5.2 Software Requirements

5.3 Hardware Requirements

5.4 IMPLEMENTATION AND TESTING REQUIREMENTS

5.5 MAINTENANCE

6.0 GENERAL REQUIREMENTS

6.1 ENTERPRISE AND IT FRAMEWORK

6.1.1 VA TECHNICAL REFERENCE MODEL

6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT

(FICAM)

6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)

6.1.4 TRUSTED INTERNET CONNECTION (TIC)

6.1.5 STANDARD COMPUTER CONFIGURATION

6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP)

6.1.7 PROCESS ASSETT LIBRARY (PAL)

6.1.8 AUTHORITATIVE DATA SOURCES

6.2 SECURITY AND PRIVACY REQUIREMENTS

6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S)

6.2.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

6.3 METHOD AND DISTRIBUTION OF DELIVERABLES

6.4 PERFORMANCE METRICS

6.5 FACILITY/RESOURCE PROVISIONS

ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED

ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM

SECURITY/PRIVACY LANGUAGE

SCHEDULE FOR DELIVERABLES ................................ Error! Bookmark not defined.

1.0 BACKGROUND

The mission of the Department of Veterans Affairs (VA), Veterans Health Administration (VHA) is to provide health services to Veterans of the United States. In meeting these goals, VHA strives to provide high quality, effective, and efficient health services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on the Consolidated Mail Outpatient Pharmacy (CMOP) to provide outpatient pharmacy services to Veterans. The Dallas VA CMOP executes 50,000 - 70,000 prescriptions daily. The Dallas VA CMOP currently uses Think-N-Do operating software for an automated operating system, that includes hardware control, system health status, and troubleshooting. This existing pharmacy control system interfaces with several existing CMOP patient information and robotic systems, as well as a radio frequency identifier (RFID). VHA Dallas CMOP requires a replacement of the current production operating software.

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”

4. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information Systems, February 2004

5. FIPS Pub 200, Minimum Security Requirements for Federal Information and

Information Systems, March 2016

6. 10 U.S.C. § 2224, "Defense Information Assurance Program"

7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

8. Public Law 109-461, Veterans Benefits, Health Care, and Information

Technology Act of 2006, Title IX, Information Security Matters

9. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

10. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/

11. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs

12. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008

13. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility

Standards,” July 1, 2003

14. Office of Management and Budget (OMB) Circular A-130, “Managing Federal

Information as a Strategic Resource,” July 28, 2016

15. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed

Services (CHAMPUS)” http://www.va.gov/vapubs/ http://www.va.gov/vapubs http://www.va.gov/vapubs

16. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008

17. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017

18. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

19. VA Directive 6500, “Managing Information Security Risk: VA Information

Security Program,” September 20, 2012

20. VA Handbook 6500, “Risk Management Framework for VA Information

Systems – Tier 3: VA Information Security Program,” March 10, 2015

21. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008

22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive

Personal Information (SPI)”, July 28, 2016

23. VA Handbook 6500.3, “Assessment, Authorization, And Continuous

Monitoring Of VA Information Systems,” February 3, 2014

24. VA Handbook 6500.5, “Incorporating Security and Privacy in System

Development Lifecycle”, March 22, 2010

25. VA Handbook 6500.6, “Contract Security,” March 12, 2010

26. VA Handbook 6500.8, “Information System Contingency Planning”, April 6,

27. OI&T Process Asset Library (PAL), https://www.va.gov/process/ . Reference

Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

28. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

29. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

30. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

31. VA Handbook 6510, “VA Identity and Access Management”, January 15,

32. VA Directive 6300, Records and Information Management, February 26,

33. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

34. NIST SP 800-37 Rev 1, Guide for Applying the Risk Management

Framework to Federal Information Systems: a Security Life Cycle Approach, June 5, 2014

35. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015

36. OMB Memorandum, “Transition to IPv6”, September 28, 2010

37. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12)

Program, October 26, 2015

38. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12)

Program, March 24, 2014 https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx

39. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006

40. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003

41. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005

42. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3,

43. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008

44. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011

45. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

46. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017

47. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012

48. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

49. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.2, Federal Interagency Technical Reference Architectures, Department of Homeland Security, June 19, 2017, https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017 .pdf

50. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007

51. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008

52. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)

53. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

54. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

55. Executive Order 13834, “Efficient Federal Operations”, dated May 17, 2018

56. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August

2, 2001 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552

57. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013

58. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013

59. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote

Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

60. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

61. VA Memorandum, “Implementation of Federal Personal Identity Verification

(PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

62. “Veteran Focused Integration Process (VIP) Guide 3.1”, April 2018, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

63. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

64. “POLARIS User Guide”, Version 1.9, March 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

65. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

3.0 SCOPE OF WORK

The Contractor shall deliver a turn-key production operating system. The operating system shall include delivery of software, hardware, and ancillary items at the Dallas VA CMOP. The objective of the operating system is to interface with all CMOP control applications, including patient information and robotic systems, as well as a radio frequency identifier (RFID) in order to automatically fulfill prescriptions at the Dallas VA

CMOP.

The contractor shall provide development, testing, projected timelines, troubleshooting system, and transition support during the turnover from the current production software to the Contractors solution, with no downtime. The contractor shall ensure the production software is developed on an open platform in order to ensure VA can incorporate new equipment into the system in the future. The system shall be a robust expandable production control and system information system that will be viable for a minimum of 10 years.

The contractor shall provide their proposed methodology, equipment, and any past performance related to the execution of this request.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The PoP shall be 12 months after award of the contract.

https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

Any work at the Government site shall not take place on Federal holidays unless directed by the Contracting Officer (CO). Some work shall be performed during weekend and outside business hours to minimize impact to CMOP operations. Any power outages, cut overs, breaker moves shall be done after production hours or on a Saturday morning if the production line is not operational.

There are ten (10) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's Day January 1 Independence Day July 4 Veterans Day November 11 Christmas Day December 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday.

Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November

4.2 PLACE OF PERFORMANCE

Tasks under this PWS shall be performed at the contractor’s site as well as VA facilities located in Dallas VA CMOP, 2962 S. Longhorn Drive Lancaster, Texas. Work may be performed at remote locations with prior concurrence from the Contracting Officer’s Representative (COR).

4.3 TRAVEL

Any travel required by the contractor to execute at the VA facility will not be directly reimbursed by the Government.

5.0 SPECIFIC TASKS AND DELIVERABLES

The Contractor shall perform the following:

5.1 PROJECT MANAGEMENT

5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN

The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline, development plan, and tools to be used in execution of the contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks, and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA PM approved CPMP throughout the PoP.

Deliverable:

A. Contractor Project Management Plan

5.1.2 REPORTING REQUIREMENTS

The Contractor shall provide the COR with Weekly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding week.

The weekly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Information and Communication Technology (ICT) deliverables and their current Section 508 conformance status. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.

The contractor shall deliver a Contractor Staff Roster in accordance with section 6.2 of the PWS

Deliverable:

A. Weekly Progress Report B. Contractor Staff Roster

5.2 SOFTWARE REQUIREMENTS

The contractor shall provide a turn-key pharmacy control software for Supervisory Control and Data Acquisition (SCADA) solution. The contractor shall ensure the pharmacy control software is developed based on an open interface architecture that enables integration and communication with the existing VA Pharmacy Management Software. The software shall migrate from the current Microsoft COM/DCOM based communication to an open and flexible bi-directional Restful Service architecture.

Integration software shall be a viable product for a minimum of 10 years with updates and support packages available during or exceeding the time line. The contractor shall coordinate with VA for handshake protocols between the VA System and the new production software.

The pharmacy control software shall include an integration component that provides detailed logging of normal and exceptional system processes and events as well as gathering metrics displayed via a dashboard with analytics, diagnostics, and search capability for system support, tuning, and optimization.

The pharmacy control software shall include a replacement control component developed using Siemens Totally Integrated Automation Portal (TIA Portal) Version 14 or later and be deployed on redundant Siemens S7-1500 PLCs for overall plant control or equivalent. The pharmacy control software shall also be developed in TIA Portal with Siemens WinCC (or equivalent) for control and monitoring of all plant operations including:

i. High-level overview dashboards

ii. System-wide drill downs

iii. Detailed metrics and diagnostics to identify specific issues at a sensor and component level.

iv. Display panels co-located with each respective subsystem and strategically positioned at overall system control locations.

All non-Programable Logic Controller (PLC) integration software components that is part of the replacement control software system shall be deployed as lightweight containerized Docker® images that include everything required for execution including the Code, Runtime, System Tools, System Libraries, and Settings. Deployment on Microsoft Windows Server® 2016 x64 based servers (or equal) is required. The software must rely on open standards and be both scalable and highly-available (i.e.

99.9 percent availability) supporting a clustered deployment with load balancing and auto-scaling across multiple servers.

The contractor shall provide back-up disks for all programs with all codes.

Deliverables:

A. Software

B. Back-up Disks

5.3 HARDWARE REQUIREMENTS

The contractor shall deliver a parts list of all equipment and supplies. The contractor shall deliver the following minimum hardware and equipment requirements as listed below, all items identified are brand name or equal:

Item Qty

Hewlett Packard ProLiant DL 380 Gen 10 Server, 16 GB Dual Rank Memory 1TB

TC3 OPC UA, platform 94 1

TC3 PROFINET IO Device, platform 94 3

Proximity Sensor Replacement 2000

26MS Descrambler 1 1

8MS Inspection 1 and 2, Descrambler 2 and 3 4

32MS IPD 1 1

32MS IPD 2 1

32MS IPD 3-22 20

16MS Slave 1 23

6MS Slave 2 1

32MS IPD 23 1

6MS Depucker 11

24MS Depucker 2 1

14MS Depucker 3 1

26MS Depucker 4 1

KVI-CP-3-GS-GD-2 Connecting Cables 24

WP Air Prep/ Service Unit Combination 52

Auxiliary interfaces, number=16x IO-Link, Inputs, number=32, Housing material primary=Zinc

Active splitter, IO-Link, BNI IOL-104-S01-Z012-C02 IO-Link function=Device, IOLink version=1.0, Inputs, number=16, Housing material primary=Zinc

BNI IOL-752-V13-K007 Active splitter, IO-Link, IO-Link version=1.1, Outputs, number=22, Housing material primary=PA

Processor unit, Interface, protocol version 1=1.1, Interface 01=IO-Link, Antenna type=round, Length=84.50 mm, Width=80.00 mm, Height=40.00 mm, Housing material primary=PBT,Installation=with clear zone, IP rating per IEC

60529=IP67

BIS M-132-03/L Data carrier, Antenna type=round, Diameter=24.90 mm, Height=4.80 mm, Housing material

Item Qty primary=ABS, Installation=with clear zone, Memory size, read=8 Byte, Memory size max., write=112 Byte, IP rating per IEC

60529=IP68

BNI PNT-508-105-Z015 Active splitter, Profaned, IO-Link function=Master, IO-Link version=1.1,Auxiliary interfaces, number=8x IO-Link, Inputs, number=16, Housing material primary=Zinc

BCC M415-M423- 3A-300-VX43T2-020 Connector with Cable 124

BCC S415-S424-3A- 304-VX44T2-050 Connector with cable 248

BCC M415-M424- 3A-304-VX44T2-100 Connector with cable 124

BCC A325-0000-20- 063-PX05A5-100 Single-Ended Cordsets, Connector 01, style=7/8", Cable jacket, material=PUR, Cable length=10.00 m

BCC M414-E834- 8G-668-PS54N2-200 Connector with cable 5

BCC M414-E834- 8G-668-PS54N2-450 Connector with cable 5

BCC M424-M424- 6D-331-PS54N2-010 Connector with cable 10

SC 6ES75163AN010AB0 Sematic S7-1500, CPU 1516-3 PN/DP 2

SC 6ES79548LF020AA0 ASM Memory 6ES- Memory Card for

S7-1200 CPU

SC 6EP13334BA00 Sematic PM 1507 24v/8 A Stabilized Power Supply

BAE PS-XA-1S-24- 200-104 24V 20amp Heart Beat IO Link Power Supply

BCC A325-A325-30- 335-PX05A5-050 Double-Ended Corsets, Connector 01, style=7/8", Connector 02, style=7/8", Cable jacket, material=PUR

BCC M424-M424- 6D-331-PS54N2-100 Connector with cable 69

852-1106 12 Port Ethernet Switch 1

HP 875759-S01 HPE ProLiant DL 380 Gen 10 Server, 16 GB Dual Rank Memory 1 TB

The contractor shall provide a detailed equipment list, and performance information prior to identifying the parts list and performing installation. The contractor shall provide equipment information booklets, manuals, and warranty information to Dallas CMOP Engineering office. All equipment and supplies shall be come property of the Federal Government. All codes and encrypted information shall become the property of the Dallas VA CMOP.

Deliverables:

A. Parts List B. Equipment (as identified in the parts list)

C. Manuals, booklets, and warranty information

5.4 IMPLEMENTATION AND TESTING REQUIREMENTS

The contractor shall Implement one production section at a time, starting with Tote Tracking, then Labelers, Pharmacy Control Software, Sorting Lanes, Depucker, Puck Sorter, Puck Controller, Marry Depucker Orders etc. The contractor shall provide a critical path for the development, testing, and acceptance of each integration with milestone review segments. Each integration shall be fully accepted prior to roll out testing on live system. The contractor shall ensure a redundant system is available and accessible, if the new software shows failures until it can be retested and approved.

The contractor shall perform Alpha and Beta testing; and receive approval prior to cutting new system into live production system.

The contractor shall deliver a one line of the system with a mapping of the servers and equipment.

Deliverables :

A. Alpha Testing Plan and Results B. Beta Testing Plan and Results C. One Line System Acceptance

5.5 MAINTENANCE

The contractor shall provide help desk support via phone and internet 24 hours a day 7 days a week for hardware and software related problems. The contractor shall repair or replace any system components that are not operational during the period of performance.

6.0 GENERAL REQUIREMENTS

6.1 ENTERPRISE AND IT FRAMEWORK

6.1.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OI&T. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M- 05-24, and M-11-11 can be found at:

https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11- 11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp http://www.techstrategies.oit.va.gov/enterprise_dp.asp https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems.

https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2005/m05-22.pdf) and September 28, 2010 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transiti on-to-ipv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf), the Technical Infrastructure for USGv6 Adoption (https://www.nist.gov/programs-projects/usgv6-program), and the NIST SP 800 series applicable compliance https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf https://www.nist.gov/programs-projects/usgv6-program https://www.nist.gov/programs-projects/usgv6-program

(https://csrc.nist.gov/publications/sp) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at:

https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

6.1.4 TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf.

6.1.5 STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Office 365 ProPlus. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Windows 10. However, Windows 10 is not the VA standard yet and is currently approved for limited use during its rollout. We are in-process of this rollout and making Windows 10 the standard for OI&T. Upon the release approval of Windows 10 as the VA standard, Windows 10 will supersede Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the https://csrc.nist.gov/publications/sp https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf

United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP)

The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products

6.1.7 PROCESS ASSETT LIBRARY (PAL)

The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section

6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf. The main PAL can be accessed at www.va.gov/process.

6.1.8 AUTHORITATIVE DATA SOURCES

The VA Enterprise Architecture Repository (VEAR) is one component within the overall Enterprise Architecture (EA) that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf http://www.va.gov/process the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:

1. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.

3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.

4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.

5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.

6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for Qualifying Active Duty military service in the VA.

6.2 SECURITY AND PRIVACY REQUIREMENTS

It has been determined that protected health information may be disclosed or accessed and a signed Business Associate Agreement (BAA) shall be required. The Contractor shall adhere to the requirements set forth within the BAA, referenced in Section D of the contract, and shall comply with VA Directive 6066.

6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S)

The PDT Tool is located at the following US Office of Personnel Management Website: https://www.opm.gov/investigations/suitability-executive-agent/position-designation-tool/)

In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:

https://www.opm.gov/investigations/suitability-executive-agent/position-designation-tool/ https://www.opm.gov/investigations/suitability-executive-agent/position-designation-tool/

Position Sensitivity and Background Investigation Requirements by Task

Task Number Tier1 / Low Risk Tier 2 / Moderate Risk

Tier 4 / High Risk

5.1

5.2

5.3

5.4

5.5

The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

6.2.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Contractor Responsibilities:

a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak and understand the English language.

b. Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

c. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

d. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form

e. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).

f. The Contractor employee shall certify and release the e-QIP document, print and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note:

OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 business days that documents were signed via e-QIP).

g. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.

h. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of

OPM.

i. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.

j. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.

k. Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with

VA.

6.3 METHOD AND DISTRIBUTION OF DELIVERABLES

The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include:

MS Word 2000/2003/2007/2010, MS Excel 2000/2003/2007/2010, MS PowerPoint 2000/2003/2007/2010, MS Project 2000/2003/2007/2010, MS Access 2000/2003/2007/2010, MS Visio 2000/2002/2003/2007/2010, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data Format (PDF).

6.4 PERFORMANCE METRICS

The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.

Performance Objective

Performance Standard Acceptable Levels of Performance

A. Technical / Quality of Product or Service

1. Demonstrates understanding of requirements

2. Efficient and effective in meeting requirements

3. Meets technical needs and mission requirements

4. Provides quality services/products

Satisfactory or higher

B. Project Milestones and Schedule

1. Established milestones and project dates are met

2. Products completed, reviewed, delivered in accordance with the established schedule

3. Notifies customer in advance of potential problems

Satisfactory or higher

C. Cost & Staffing

1. Currency of expertise and staffing levels appropriate

2. Personnel possess necessary knowledge, skills and abilities to perform tasks

Satisfactory or higher

D. Management

1. Integration and coordination of all activities to execute effort

Satisfactory or higher

The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the surveillance methods in the QASP at its own discretion. A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.

6.5 FACILITY/RESOURCE PROVISIONS

The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.

The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact. The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.

VA may provide remote access to VA specific systems/network in accordance with VA Handbook 6500, which requires the use of a VA approved method to connect external equipment/systems to VA’s network. Citrix Access Gateway (CAG) is the current and only VA approved method for remote access users when using or manipulating VA information for official VA Business. VA permits CAG remote access through approved Personally Owned Equipment (POE) and Other Equipment (OE) provided the equipment meets all applicable 6500 Handbook requirements for POE/OE. All of the security controls required for Government furnished equipment (GFE) must be utilized in approved POE or OE. The Contractor shall provide proof to the COR for review and approval that their POE or OE meets the VA Handbook 6500 requirements and VA Handbook 6500.6 Appendix C, herein incorporated as Addendum B, before use. CAG authorized users shall not be permitted to copy, print or save any VA information accessed via CAG at any time. VA prohibits remote access to VA’s network from non- North Atlantic Treaty Organization (NATO) countries. The exception to this are countries where VA has approved operations established (e.g. Philippines and South Korea). Exceptions are determined by the COR in coordination with the Information Security Officer (ISO) and Privacy Officer (PO).

This remote access may provide access to VA specific software such as Veterans Health Information System and Technology Architecture (VistA), ClearQuest, PAL, Primavera, and Remedy, including appropriate seat management and user licenses, depending upon the level of access granted. The Contractor shall utilize government-provided software development and test accounts, document and requirements repositories, etc. as required for the development, storage, maintenance and delivery of products within the scope of this effort. The Contractor shall not transmit, store or otherwise maintain sensitive data or products in Contractor systems (or media) within the VA firewall IAW VA Handbook 6500.6 dated March 12, 2010. All VA sensitive information shall be protected at all times in accordance with VA Handbook 6500, local security field office System Security Plans (SSP’s) and Authority to Operate (ATO)’s for all systems/LAN’s accessed while performing the tasks detailed in this PWS. The Contractor shall ensure all work is performed in countries deemed not to pose a significant security risk. For detailed Security and Privacy Requirements (additional requirements of the contract consolidated into an addendum for easy reference) refer to

ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED

A1.0 Cyber and Information Security Requirements for VA IT Services

The Contractor shall ensure adequate LAN/Internet, data, information, and system security in…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.