36C10B18R2935-001.docx

DOCX document 112 KB Posted

Attached to
App Tester TAC-18-50881 Federal contract opportunity
Solicitation number
36C10B18R2935
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

36C10B18R2935 RFI PWS Mobile App Testing.docx

View the file

Other files for this federal contract opportunity

Other files attached to App Tester TAC-18-50881, newest first.
File Type Posted
36C10B18R2935-000.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Mental Health Mobile Applications Test Support TAC Number: TAC-18-50881

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Veterans Health Administration National Center for Post-Traumatic Stress Disorder

Mental Health Mobile Applications Test Support

Date: July 9, 2018

TAC-18-50881

PWS Version Number: 0.6

Contents

1.0BACKGROUND3
2.0APPLICABLE DOCUMENTS4
3.0SCOPE OF WORK7
4.0PERFORMANCE DETAILS7
4.1PERFORMANCE PERIOD8
4.2PLACE OF PERFORMANCE8
4.3TRAVEL8
5.0SPECIFIC TASKS AND DELIVERABLES8
5.1PROJECT MANAGEMENT8
5.1.1REPORTING REQUIREMENTS8
5.1.2TECHNICAL KICKOFF MEETING9
5.2MOBILE APP TESTING9
5.3CONTENT FOR MOBILE APPS10
6.0GENERAL REQUIREMENTS11
6.1ENTERPRISE AND IT FRAMEWORK11
6.1.1ONE-VA TECHNICAL REFERENCE MODEL11
6.1.2FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)11
6.1.3INTERNET PROTOCOL VERSION 6 (IPV6)13
6.1.4TRUSTED INTERNET CONNECTION (TIC)13
6.1.5STANDARD COMPUTER CONFIGURATION14
6.1.6VETERAN FOCUSED INTEGRATION PROCESS (VIP)14
6.1.7PROCESS ASSETT LIBRARY (PAL)14
6.2SECURITY AND PRIVACY REQUIREMENTS14
6.2.1POSITION/TASK RISK DESIGNATION LEVEL(S)16
6.2.2CONTRACTOR PERSONNEL SECURITY REQUIREMENTS16
6.3METHOD AND DISTRIBUTION OF DELIVERABLES18
6.4PERFORMANCE METRICS18
6.5FACILITY/RESOURCE PROVISIONS19
6.6GOVERNMENT FURNISHED PROPERTY20
ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED21

BACKGROUND

The Department of Veterans Affairs (VA), National Center for Post-Traumatic Stress Disorder (NCPTSD), Dissemination and Training Division is responsible for creating training and educational products to support evidence-based care of Veterans with Post-Traumatic Stress Disorder (PTSD) and related problems. PTSD is very common among Veterans and has a significant impact on Veterans’ quality of life. Most Veterans with PTSD do not access evidence-based treatments for PTSD, and many Veterans are either unable or choose not to access available mental health services of any kind. Lack of available services, distance from clinics, and stigma associated with mental health care are just a few of the barriers to providing care for Veterans and those living with a Veteran with PTSD. NCPTSD has developed mobile applications (apps) to overcome these and other barriers to care. The apps are designed to assist Veterans and their family members with understanding PTSD and related problems, tracking their improvement over time, obtaining support and resources, and managing symptoms using a variety of brief tools.

NCPTSD has developed a variety of mobile applications in the past seven years, including, most notably, the multi-award winning PTSD Coach (Winner of the Advancements in Accessibility Award from the Federal Communications Commission 2011 and Winner of the President’s Innovation Award from the American Telemedicine Association 2012). NCPTSD currently maintains a portfolio of 25 native, publicly-available apps (e.g., PTSD Coach, CBT-i Coach, Mindfulness Coach, PE Coach, Stay Quit Coach), that have been downloaded from the App Store and Play Store by over 640,000 Veterans and others. The portfolio currently consists of 16 native (i.e. Objective-C) iOS apps and 9 native (i.e. Java) Android apps. Each mobile app aims to address specific implementation challenges faced by Veterans and their family members in receiving education, training, and treatment.

The NCPTSD Dissemination and Training Division has also been charged with ensuring that NCPTSD mobile apps are 1) capable of supporting scientific research, 2) capable of responding to the needs of Veterans, VA providers, and other stakeholders, and 3) reflect the most up-to-date and evidence-based guidelines for addressing PTSD and PTSD-related concerns in Veterans. To meet this charge, NCPTSD has a multi-phase coordinated research program to study the usability, efficacy, and implementation of these applications and works directly with Mental Health Services in VA Central Office to ensure that products are aligned with the mission to enhance and optimize mental health care for Veterans. NCPTSD has also made strides to ensure that its suite of mobile applications are as easy-to-use as possible, are designed to reflect the needs of Veteran users, and integrate the best-available clinical recommendations to support Veterans’ recovery from PTSD.

This contract action is part of a set of activities designed to maintain, redesign, and upgrade existing mobile apps previously built for NCPTSD, in order to provide reliable, high-quality mental health service to Veterans, their families, health care providers, and others. The specific work assignments will be determined throughout the period of performance, as Apple’s successive updates to iOS and Google’s successive updates to Android introduce new bugs and performance problems to the apps over the year, and as NCPTSD staff consider and develop possible new features. NCPTSD has a need to more rapidly provide feedback to the VA mobile app developers, to more rapidly generate content for new apps, to be more responsive to requests for updates to existing apps in the portfolio, and to have an additional layer of clinical review to ensure appropriateness and utility for Veterans with PTSD. NCPTSD requires support with clinical content writing (including development of clinically-supported, evidence-based, user-friendly patient education materials), clinical review of existing content to ensure appropriateness to the Veteran population and consistency with the latest clinical evidence on PTSD treatment and recovery, Veteran-focused user experience testing to evaluate apps to ensure that they are easy to use, relatable, and inviting to Veterans with PTSD (e.g., making sure the user experience is not frustrating for Veterans and suggesting alternative approaches that could improve the user interface to better meet the needs of those with PTSD), and mobile app testing to ensure that app functionality and user interfaces are consistent with iOS and Android user interface guidelines, and expectancies of adult Veterans. This contract will assist NCPTSD in more quickly turning around builds to the mobile app developers to speed mobile app design, development, and maintenance.

APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”

4. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information Systems, February 2004

5. FIPS Pub 200, Minimum Security Requirements for Federal Information and Information Systems, March 2016

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010

9. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

10. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters

11. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

12. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/

13. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs

14. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008

15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003

16. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”

18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008

19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998

20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

21. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012

22. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015

23. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008

24. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI)”, July 28, 2016

25. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA Information Systems,” February 3, 2014

26. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle”, March 22, 2010

27. VA Handbook 6500.6, “Contract Security,” March 12, 2010

28. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011

29. OI&T Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

30. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

31. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

32. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

33. VA Handbook 6510, “VA Identity and Access Management”, January 15, 2016

34. VA Directive 6300, Records and Information Management, February 26, 2009

35. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

36. NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach, June 10, 2014

37. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015

38. OMB Memorandum, “Transition to IPv6”, September 28, 2010

39. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, October 26, 2015

40. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 24, 2014

41. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006

42. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003

43. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005

44. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011

45. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008

46. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011

47. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008

48. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

49. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017

50. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014

51. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012

52. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014

53. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

54. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

55. VA Memorandum “Mandate to meet PIV Requirements for New and Existing Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

56. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf

57. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007

58. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008

59. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)

60. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

61. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

62. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015

63. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

64. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013

65. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013

66. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

67. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

68. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

69. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

70. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

71. “Veteran Focused Integration Process (VIP) Guide 2.0”, May 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

72. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

73. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

74. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

75. VA Memorandum “Updated VA Information Security Rules of Behavior (VAIQ #7823189)”, September, 15, 2017, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

SCOPE OF WORK

The Contractor shall provide mobile app testing to include functional testing, user experience testing, and ensuring the apps are clinically sound and current. The Contractor shall also generate clinical content for the mobile apps.

The Contractor shall have completed a doctoral degree in clinical psychology from an APA-accredited program, have clinical experience in working with Veterans with PTSD, conducting behavioral research, have expertise in science and evidence-based recommendations for the treatment of PTSD, and clinical experience in delivering mobile interventions to Veterans with PTSD.

PERFORMANCE DETAILS

PERFORMANCE PERIOD

The period of performance shall be 12 months from date of award, with two options for 12 months each.

PLACE OF PERFORMANCE

The Contractor shall be required to attend meetings in-person monthly, at a minimum, at VA facility located at 795 Willow Road, Menlo Park, CA. All other tasks under this PWS shall be performed at Contractor facilities. The Contractor shall identify the Contractor’s place of performance in their Task Execution Plan submission.

TRAVEL

The Government anticipates travel under this effort to perform the tasks associated with the effort, as well as to attend program-related meetings or conferences throughout the period of performance. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.

The total estimated number of trips in support of the program related meetings for this effort is one per month. Anticipated location is Menlo Park, CA, estimated at one day in duration for one person.

SPECIFIC TASKS AND DELIVERABLES

PROJECT MANAGEMENT

REPORTING REQUIREMENTS

The Contractor shall provide the COR with Monthly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding month.

The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Electronic and Information Technology (EIT) deliverables and their current Section 508 conformance status. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.

The Contractor shall attend weekly meetings to brief VA on the status of each task and deliverable defined within this PWS and to review ongoing needs across the mobile apps portfolio. In-person attendance to the weekly meetings is required monthly at a minimum. The Contractor briefing shall include a detailed review of the projected schedule, risk mitigation status, and the Contractor’s planned actions for recovering from any schedule slippage.

Deliverable:

A. Monthly Progress Report

TECHNICAL KICKOFF MEETING

The Contractor shall hold a technical kickoff meeting at VA facilities in Menlo Park, CA within 10 days after contract award. The Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, and overall project management approach. The Contractor shall specify dates, agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and meeting minutes (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the Contracting Officer (CO), Contract Specialist (CS), Contracting Officer’s Representative (COR), and VA PM.

MOBILE APP TESTING

The Contractor shall provide testing of NCPTSD mobile apps for PTSD to improve user experience and provide clinical judgement to ensure safety, suggest additional content to improve the apps and keep the content up-to-date. The amount and type of testing will vary widely on a per-project basis at NCPTSD’s discretion, with testing ranging from focused testing of a specific app section or feature to comprehensive user experience testing or complete testing of a mobile app. NCPTSD anticipates the Contractor shall test one mobile app at a given time, but may be required to test two apps concurrently.

The Contractor shall coordinate with NCPTSD for testing timelines for the apps. The Contractor shall report on all active and planned mobile app testing projects in the Monthly Progress Report and during weekly mobile app briefings.

Quality control of delivered mobile app testing shall be led and performed by the Contractor. All readily available specifications and documentation will be provided to the Contractor for use in testing, but the Contractor should be able to implement these tasks without any further documentation. The Contractor shall download required mobile apps to be tested from VA’s repository, currently Vertical. An issue tracking system administered by NCPTSD, currently GitHub, shall be used to track quality control issues and monitor progress.

The Contractor shall test NCPTSD native mobile apps for PTSD. Testing shall include:

1. Testing of mobile apps on multiple Android and iOS devices to ensure the app works as intended and displays correctly on the device screen. For device testing, the Contractor shall test the mobile apps using actual devices (i.e., not simulators), particularly devices that are most widely used in the general population, that include multiple Android screen sizes (both phones and tablets) and multiple iOS screen sizes (both phones and tablets). At a minimum, the Contractor shall test using two Android phone devices that have different screen sizes and one Android tablet device and two iOS phone devices that have different screen sizes and one iOS tablet device.

2. Ensuring mobile app content and features match NCPTSD technical specifications. The Contractor shall be responsible for comparing technical specifications against their implementation in a mobile app, ensuring that a) all content matches between the specifications and the app and b) the app is resilient to complex user interactions without crashing, stalling, or losing data.

3. Reviewing material for consistency with current PTSD treatment guidelines (i.e., https://www.healthquality.va.gov/guidelines/MH/ptsd/) and the most up-to-date scientific literature on PTSD education, treatment, and clinical care.

4. Ensuring clinical safety (i.e., appropriateness to the clinical care of Veterans with PTSD) and confidentiality.

5. Ensuring consistency with Apple iOS human interface guidelines, Android design guidelines, and recently-released NCPTSD mobile apps.

6. Optimizing user experience, which at a minimum shall include reviewing wireframes and app sequences to identify potential dead-ends (i.e., views that cannot be easily navigated out of, user-entered information that cannot be changed or edited, etc.) or ways of interacting with the apps that are likely to be confusing for different types of Veterans using the app; offering suggestions for simplifying user interaction elements and alternative flows; identifying additional clinical content that could assist Veterans in making better use of the apps.

7. Testing for Section 508 accessibility compliance.

8. Conducting comprehensive testing of research versions of apps by visiting and recording all screens within the app and checking that data transmitted from research versions of apps (i.e., timestamps, buttons tapped, user-entered data) match testing records (i.e., data transmitted in JavaScript Object Notation (JSON) format should match testing records of which app screens were visited, dates and times for when each screen was visited, and any data entered by the tester while testing the app).

9. Veteran-focused user experience testing. Testing shall include focused (i.e., testing one section or feature of an app) and general (i.e., testing every feature and section of the app) testing of mobile apps using specific user personas (e.g., repeat survey-taker, skeptical user, long-term user, etc.). The Contractor shall also conduct user experience interviews with target users, employing established user experience (UX) research principles. The Contractor shall incorporate results of user experience interviews into recommendations for cost-effective design changes that could improve users’ experiences with the app.

The Contractor shall provide a Weekly Testing Report that summarizes the testing performed during the week and the progress made on the issues reported in the issue tracking system. In addition, any recommended user experience improvements and suggested clinical content shall be included in the Weekly Testing Report.

Final deliverables of each testing project shall include the delivery of all testing documentation and reports as described above. Before any work begins on a testing project, the Contractor shall produce time estimates of the number of hours that will be needed for the work to be performed, and shall obtain the approval of NCPTSD for the expenditure of hours.

Deliverable:

A. Testing Documentation and Reports B. Weekly Testing Report

CONTENT FOR MOBILE APPS

The Contractor shall provide content writing support services for mobile apps and public health education materials to support NCPTSD mobile apps for PTSD, based on the best available scientific evidence, current VA norms and standards for the clinical care of Veterans with PTSD, expert knowledge of VA care for PTSD, current clinical guidelines for the treatment of PTSD, and familiarity with common terms and expressions used by Veterans. NCPTSD mobile apps for PTSD need to be kept up-to-date with, for example, the newest treatment, educational materials, and available clinical science. The Contractor shall be responsible for writing up-to-date content to be used in publicly-released mobile apps for mental health and supporting handouts and patient education materials.

The Contractor shall write public health education materials capable of being included in NCPTSD mobile apps, such as brief psychoeducational topics specific to PTSD treatment and recovery (see PTSD Coach, PTSD Family Coach, and other publicly-available NCPTSD apps for examples). The Contractor shall provide written outlines and wireframes for detailed tools and other app features requested by NCPTSD. The Contractor shall create flyers and other web-based promotional materials to support appropriate implementation of VA mobile apps across VA treatment settings. The Contractor shall use the best available scientific evidence for treatment of PTSD to write the content while also writing content that can be quickly and easily read and is optimized for delivery on a mobile device or tablet. The Contractor shall write content that is accessible to the widest possible range of reading levels, with brief content that is accessible to reading levels of sixth grade and below and more detailed content accessible to those with slightly higher reading levels. The Contractor shall provide a Weekly Content Report that contains all content written during the week, to include content for mobile apps, promotional materials, and outlines and wireframes for tools and app features.

Deliverable:

A. Weekly Content Report

GENERAL REQUIREMENTS

ENTERPRISE AND IT FRAMEWORK

ONE-VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (One-VA TRM). One-VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. One-VA TRM includes the Standards Profile and Product List that collectively serves as a VA technology roadmap. Architecture, Strategy, and Design (ASD) has overall responsibility for the One-VA TRM.

FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-11-11 can be found at: https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems. https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf) and September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet), the Technical Infrastructure for USGv6 Adoption (http://www-x.antd.nist.gov/usgv6/index.html), and the NIST SP 800 series applicable compliance (http://csrc.nist.gov/publications/PubsSPs.html) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at: https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.

STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Microsoft Office 2010. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Office 365 ProPlus and Windows 10. However, Office 365 ProPlus and Windows 10 are not the VA standard yet and are currently approved for limited use during their rollout, we are in-process of this rollout and making them the standard by OI&T. Upon the release approval of Office 365 ProPlus and Windows 10 individually as the VA standard, Office 365 ProPlus and Windows 10 will supersede Office 2010 and Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

VETERAN FOCUSED INTEGRATION PROCESS (VIP)

The Contractor shall support VA efforts in accordance with the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products

PROCESS ASSETT LIBRARY (PAL)

The Contractor shall utilize PAL, the OI&T-wide process management tool that assists in the execution of an IT project (including adherence to VIP standards). PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards or guides to assist project teams in facilitating their VIP compliant work.

SECURITY AND PRIVACY REQUIREMENTS

The Assessment and Authorization (A&A) requirements do not apply and a Security Accreditation Package is not required.

All VA sensitive information shall be protected at all times in accordance with local security field office System Security Plans (SSP's) and Authority to Operate (ATO)'s for all systems/LAN's accessed while performing the tasks detailed in this PWS.

a. A prohibition on unauthorized disclosure: "Information made available to the Contractor or subcontractor by VA for the performance or administration of this contract or information developed by the Contractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA." See VA handbook 6500.6, Appendix C, paragraph 3.a.

b. A requirement for data breach notification: Upon discovery of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the Contractor/subcontractor has access, the Contractor/subcontractor shall immediately and simultaneously notify the COR, the designated ISO, and Privacy Officer for the contract. The term "security incident" means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. See VA Handbook 6500.6, Appendix C, paragraph 6.a.

c. A requirement to pay liquidated damages in the event of a data breach: "In the event of a data breach or privacy incident involving SPI the Contractor processes or maintains under this contract, the Contractor shall be liable to VA for liquidated damages for a specified amount per affected individual to cover the cost of providing credit protection services to those individuals." See VA handbook 6500.6, Appendix C, paragraph 7.a., 7.d.

d. A requirement for annual security/privacy awareness training: "Before being granted access to VA information or information systems, all Contractor employees and subcontractor employees requiring such access shall complete on an annual basis either: (i) the VA security/privacy awareness training (contains VA security/privacy requirements) within 1 week of the initiation of the contract, or (ii) security awareness training provided or arranged by the Contractor that conforms to VA's security/privacy requirements as delineated in the hard copy of the VA security awareness training provided to the Contractor. If the Contractor provides their own training that conforms to VA's requirements, they will provide the COR or CO, a yearly report (due annually on the date of the contract initiation) stating that all applicable employees involved in the VA's contract have received their annual security/privacy training that meets VA's requirements and the total number of employees trained. See VA Handbook 6500.6, Appendix C, paragraph 9.

e. A requirement to sign VA's Rules of Behavior: "Before being granted access to VA information or information systems, all Contractor employees and subcontractor employees requiring such access shall sign on annual basis an acknowledgement that they have read, understand, and agree to abide by VA's Contractor Rules of Behavior which is attached to this contract." See VA Handbook 6500.6, Appendix C, paragraph 9, Appendix D. Note: If a medical device vendor anticipates that the services under the contract will be performed by 10 or more individuals, the Contractor Rules of Behavior may be signed by the vendor's designated representative. The contract must reflect by signing the Rules of Behavior on behalf of the vendor that the designated representative agrees to ensure that all such individuals review and understand the Contractor Rules of Behavior when accessing VA's information and information systems.

POSITION/TASK RISK DESIGNATION LEVEL(S)

In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:

Position Sensitivity and Background Investigation Requirements by Task

Task Number
Tier1 / Low Risk
Tier 2 / Moderate Risk
Tier 4 / High Risk
5.1
|X|
|_|
|_|
5.2
|X|
|_|
|_|
5.3
|X|
|_|
|_|

The Tasks identified above and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Contractor Responsibilities:

1. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak and understand the English language.

Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

1. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

b. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).

The Contractor employee shall certify and release the e-QIP document, print and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 business days that documents were signed via e-QIP).

1. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.

1. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of OPM.

1. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.

Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.

Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with VA.

Deliverable:

A. Contractor Staff Roster

METHOD AND DISTRIBUTION OF DELIVERABLES

The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include: MS Word 2000/2003/2007/2010, MS Excel 2000/2003/2007/2010, MS PowerPoint 2000/2003/2007/2010, MS Project 2000/2003/2007/2010, MS Access 2000/2003/2007/2010, MS Visio 2000/2002/2003/2007/2010, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data Format (PDF).

PERFORMANCE METRICS

The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.

Performance Objective
Performance Standard
Acceptable Levels of Performance
A. Technical / Quality of Product or Service
1. Demonstrates understanding of requirements

2. Efficient and effective in meeting requirements

3. Meets technical needs and mission requirements

4. Provides quality services/products Satisfactory or higher

B. Project Milestones and Schedule
1. Established milestones and project dates are met

2. Products completed, reviewed, delivered in accordance with the established schedule

3. Notifies customer in advance of potential problems Satisfactory or higher

C. Cost & Staffing
1. Currency of expertise and staffing levels appropriate

2. Personnel possess necessary knowledge, skills and abilities to perform tasks Satisfactory or higher

D. Management
1. Integration and coordination of all activities to execute effort
Satisfactory or higher

The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the surveillance methods in the QASP at its own discretion. A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.

FACILITY/RESOURCE PROVISIONS

The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.

The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact. The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.

VA may provide…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.