36C10B18R2935-003.pdf
PDF 771 KB Posted
- Attached to
- TAC-18-50881 App Tester Federal contract opportunity
- Solicitation number
- 36C10B18R2935
About this file
36C10B18R2935 36C10B18R2935.pdf
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10B18C2752-000.docx | DOCX document | |
| 36C10B18R2935-002.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 1. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. DUNS: DUNS+4:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. 2/2012)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS 61
36C10B18R2935 8-15-2018
Jessica Adamitis – Contract Specialist 732-440-9704 8-23-2018
12:00PM EST
Department of Veterans Affairs
Technology Acquisition Center
23 Christopher Way
Eatontown NJ 07724
541512
$27.5 Million
X
N/A
X
See Delivery Schedule
Financial Services Center
PO Box 149971
Austin TX 78714-8971
See CONTINUATION Page
Mental Health Mobile Applications Clinical Testing and Content
Writing Support
See Section B.3 Price Schedule and B.4 Performance Work Statement
This Request for Proposal (RFP) will result in a Labor-Hour
Contract.
This is a small business set-aside in accordance with FAR
52.219-6 Notice of Total Small Business Set-Aside
Offerors will be evaluated in accordance with Section E.
See CONTINUATION Page
X X
36C10B18R2935
Table of Contents
SECTION A
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
B.2 GOVERNING LAW
B.3 PRICE SCHEDULE
B.3 PERFORMANCE WORK STATEMENT
SECTION C - CONTRACT CLAUSES
C.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT
STATUTES OR EXECUTIVE ORDERS—COMMERCIAL ITEMS (JAN 2018)
C.3 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)
C.4 VAAR 852.203-70 COMMERCIAL ADVERTISING (MAY 2018)
C.5 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV
2012)
C.7 VAAR 852.270-1 REPRESENTATIVES OF CONTRACTING OFFICERS (JAN 2008) . 42
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS
SECTION E - SOLICITATION PROVISIONS
E.1 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB
1998)
E.2 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL
ITEMS (NOV 2017)
E.3 52.216-1 TYPE OF CONTRACT (APR 1984)
E.4 52.233-2 SERVICE OF PROTEST (SEP 2006)
E.5 VAAR 852.233-70 PROTEST CONTENT/ALTERNATIVE DISPUTE RESOLUTION
(JAN 2008)
E.6 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (MAY 2010)
E.7 BASIS FOR AWARD
E.8 QUOTE SUBMISSION INSTRUCTIONS
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
(continuation from Standard Form 1449, block 18A.)
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR: TBD
b. GOVERNMENT: Contracting Officer 36C10B Juan Quinones
Technology Acquisition Center
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer - System for Award
Management
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly []
b. Semi-Annually []
c. Other [X] Upon Government Acceptance of Deliverables in Section B.3
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of
Payment Requests.
ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
AMENDMENT NO DATE
B.2 GOVERNING LAW
Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the
Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41
U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data
Processing or Maintenance (38 U.S.C. § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this Clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this Clause shall prevail. Claims of patent or copyright infringement brought against the
Government as a party shall be defended by the U.S. Department of Justice (DOJ). 28 U.S.C. §
516. At the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be effected by a warranted
Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.
B.3 PRICE SCHEDULE
Inspection/Acceptance//F.O.B: Destination.
All deliverables must be submitted electronically to the VA Program Manager (PM), Contracting
Officer’s Representative (COR), and Contracting Officer unless otherwise specified in the line item. Please be advised that in accordance with Federal Acquisition Regulation (FAR) Part
2.101, a “day” means, unless otherwise specified, a CALENDER day. Additionally, deliverables with due dates falling on a weekend or holiday shall be submitted the following Government work day after the weekend or holiday.
The Price Schedule contains contract line items identified as not separately priced (NSP). This means the price for the line item is included in the price of another, related line item. The
Contractor shall not invoice the Government for any portion of the contract line item which contains an NSP until the Contractor has delivered the total quantity of all related contract line items and the Government has accepted them.
NOTE: Vendors are instructed to complete Section B.4 Contract Line Item Numbers (CLIN) and Subcontract Line Item Numbers (SLIN) and submit with their quote. Vendors are instructed to see solicitation Section E.8 for quote submission instructions. Vendors are cautioned that alterations to the line items as specified below may render quotes unacceptable. All questions shall be directed to the Contract Specialist, Jessica Adamitis, Jessica.Adamitis@va.gov and
Contracting Officer, Juan Quinones, Juan.Quinones@va.gov prior to the closing date and time specified in the Request for Quote (RFQ).
BASE PERIOD
The period of performance shall be 12 months from date of award.
Contract
Line Item
Number
(CLIN)
Description Qty Unit Unit Price Extended Price
0001 Project Management in accordance with
(IAW) Performance Work Statement (PWS)
5.1 Firm-Fixed-Price.
Period of Performance shall be 12 months from date of award.
This CLIN includes all tasks, labor, and travel required for the successful compilation of the services detailed in PWS Section 5.1 and its subtasks.
12 MO $ $
0001AA Monthly Progress Report IAW PWS 5.1.1.
Due 30 days from contract award and updated monthly thereafter.
12 MO NSP NSP
0002 Mobile App Testing IAW PWS 5.2 Labor-
Hour.
This is a Labor-Hour CLIN and includes all labor
1 LO $ NTE
mailto:Jessica.Adamitis@va.gov mailto:Juan.Quinones@va.gov required for the successful completion of the tasks associated with PWS 5.2.
The Contractor shall not execute performance on this task without approval from the Contracting
Officer.
Instructions to Offerors
Offerors shall provide their proposed Loaded
Labor Rate and complete the table below. The
Unit Price shall be the Loaded Labor Rate. The
Extended price is Not to Exceed (NTE) the total
Loaded Labor Rate multiplied by total Labor
Hours.
Labor
Category
Labor
Hours
Loaded
Labor
Rate
Amount
Tester 600 $ $
Total $
Before any work begins on a maintenance project, the Contractor shall produce time estimates of the number of hours that will be needed for the work to be performed, and shall obtain the approval of NCPTSD for the expenditure of hours.
This Labor-Hour CLIN is IAW FAR 52.232-7 for invoicing or billing purposes.
0002AA Testing Documentation and Reports IAW PWS
5.2.
Due upon completion of each testing project.
1 LO NSP NSP
0002AB Weekly Testing Report IAW PWS 5.2.
Due weekly throughout the period of performance.
1 LO NSP NSP
0003 Content for Mobile Apps IAW PWS 5.3
Labor-Hour.
Instructions to Offerors
Offerors shall provide their proposed Loaded
Labor Rate and complete the table below. The
Unit Price shall be the Loaded Labor Rate. The
Extended price is Not to Exceed (NTE) the total
Labor
Hours
Loaded
Labor
Rate
Amount
Technical
Writer
400 $ $ estimates of the number of hours that will be needed for the work to be performed, and shall
This Labor-Hour CLIN is IAW FAR 52.232-72
0003AA Weekly Content Report IAW PWS 5.3
1 LO NSP NSP
TOTAL BASE PERIOD $
OPTION PERIOD 1
This option may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR
2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting
Officer. If exercised, this option shall commence immediately after expiration of the base period.
Period of Performance shall be 12 months.
CLIN Description Qty Unit Unit Price Extended Price
1001 Project Management in accordance with
5.1.
services detailed in PWS Section 5.1 and its subtasks.
1001AA Monthly Progress Report IAW PWS 5.1.1.
12 MO NSP NSP
Due 30 days from contract award and updated monthly thereafter.
1002 Mobile App Testing IAW PWS 5.2 Labor-
Labor Rate and complete the table below. The
Unit Price shall be the Loaded Labor Rate. The
Extended price is Not to Exceed (NTE) the total
Labor
Hours
Loaded
Labor
Rate
Amount estimates of the number of hours that will be needed for the work to be performed, and shall
1 LO $ NTE
1002AA Testing Documentation and Reports IAW PWS
1002AB Weekly Testing Report IAW PWS 5.2.
1 LO NSP NSP
1003 Content for Mobile Apps IAW PWS 5.3
Labor Rate and complete the table below. The
Unit Price shall be the Loaded Labor Rate. The
Extended price is Not to Exceed (NTE) the total
Labor
Hours
Loaded
Labor
Rate
Amount
Technical
Writer estimates of the number of hours that will be needed for the work to be performed, and shall
1003AA Weekly Content Report IAW PWS 5.3
TOTAL OPTION PERIOD 1 $
OPTION PERIOD 2
This option may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR
2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting
Officer. If exercised, this option shall commence immediately after expiration of the base period.
CLIN Description Qty Unit Unit Price Extended Price
2001 Project Management in accordance with
5.1.
services detailed in PWS Section 5.1 and its subtasks.
1001AA Monthly Progress Report IAW PWS 5.1.1.
Due 30 days from contract award and updated monthly thereafter.
12 MO NSP NSP
2002 Mobile App Testing IAW PWS 5.2 Labor-
Labor Rate and complete the table below. The
Unit Price shall be the Loaded Labor Rate. The
Extended price is Not to Exceed (NTE) the total
Labor
Hours
Loaded
Labor
Rate
Amount estimates of the number of hours that will be needed for the work to be performed, and shall
1 LO $ NTE
2002AA Testing Documentation and Reports IAW PWS
2002AB Weekly Testing Report IAW PWS 5.2.
Due weekly throughout the period of performance.
2003 Content for Mobile Apps IAW PWS 5.3
Labor Rate and complete the table below. The
Unit Price shall be the Loaded Labor Rate. The
Extended price is Not to Exceed (NTE) the total
Labor
Hours
Loaded
Labor
Rate
Amount
Technical
Writer estimates of the number of hours that will be needed for the work to be performed, and shall
1 LO $ NTE
2003AA Weekly Content Report IAW PWS 5.3
1 LO NSP NSP
TOTAL OPTION PERIOD 2 $
TOTAL CONTRACT $
B.3 PERFORMANCE WORK STATEMENT
DEPARTMENT OF VETERANS AFFAIRS
Veterans Health Administration
National Center for Post-Traumatic Stress Disorder
Mental Health Mobile Applications Clinical Testing and Content Writing Support
Date: July 9, 2018
TAC-18-50881
PWS Version Number: 1.0
1.0 BACKGROUND
The Department of Veterans Affairs (VA), National Center for Post-Traumatic Stress Disorder
(NCPTSD), Dissemination and Training Division is responsible for creating training and educational products to support evidence-based care of Veterans with Post-Traumatic Stress
Disorder (PTSD) and related problems. PTSD is very common among Veterans and has a significant impact on Veterans’ quality of life. Most Veterans with PTSD do not access evidence-based treatments for PTSD, and many Veterans are either unable or choose not to access available mental health services of any kind. Lack of available services, distance from clinics, and stigma associated with mental health care are just a few of the barriers to providing care for Veterans and those living with a Veteran with PTSD. NCPTSD has developed mobile applications (apps) to overcome these and other barriers to care. The apps are designed to assist
Veterans and their family members with understanding PTSD and related problems, tracking their improvement over time, obtaining support and resources, and managing symptoms using a variety of brief tools.
NCPTSD has developed a variety of mobile applications in the past seven years, including, most notably, the multi-award winning PTSD Coach (Winner of the Advancements in Accessibility
Award from the Federal Communications Commission 2011 and Winner of the President’s
Innovation Award from the American Telemedicine Association 2012). NCPTSD currently maintains a portfolio of 25 native, publicly-available apps (e.g., PTSD Coach, CBT-i Coach, Mindfulness Coach, PE Coach, Stay Quit Coach), that have been downloaded from the App
Store and Play Store by over 640,000 Veterans and others. The portfolio currently consists of 16 native (i.e. Objective-C) iOS apps and 9 native (i.e. Java) Android apps. Each mobile app aims to address specific implementation challenges faced by Veterans and their family members in receiving education, training, and treatment.
The NCPTSD Dissemination and Training Division has also been charged with ensuring that
NCPTSD mobile apps are 1) capable of supporting scientific research, 2) capable of responding to the needs of Veterans, VA providers, and other stakeholders, and 3) reflect the most up-to-date and evidence-based guidelines for addressing PTSD and PTSD-related concerns in Veterans. To meet this charge, NCPTSD has a multi-phase coordinated research program to study the usability, efficacy, and implementation of these applications and works directly with Mental
Health Services in VA Central Office to ensure that products are aligned with the mission to enhance and optimize mental health care for Veterans. NCPTSD has also made strides to ensure that its suite of mobile applications are as easy-to-use as possible, are designed to reflect the needs of Veteran users, and integrate the best-available clinical recommendations to support
Veterans’ recovery from PTSD.
This contract action is part of a set of activities designed to maintain, redesign, and upgrade existing mobile apps previously built for NCPTSD, in order to provide reliable, high-quality mental health service to Veterans, their families, health care providers, and others. The specific work assignments will be determined throughout the period of performance, as Apple’s successive updates to iOS and Google’s successive updates to Android introduce new bugs and performance problems to the apps over the year, and as NCPTSD staff consider and develop possible new features. NCPTSD has a need to more rapidly provide feedback to the VA mobile app developers, to more rapidly generate content for new apps, to be more responsive to requests for updates to existing apps in the portfolio, and to have an additional layer of clinical review to ensure appropriateness and utility for Veterans with PTSD. NCPTSD requires support with clinical content writing (including development of clinically-supported, evidence-based, user-friendly patient education materials), clinical review of existing content to ensure appropriateness to the Veteran population and consistency with the latest clinical evidence on
PTSD treatment and recovery, Veteran-focused user experience testing to evaluate apps to ensure that they are easy to use, relatable, and inviting to Veterans with PTSD (e.g., making sure the user experience is not frustrating for Veterans and suggesting alternative approaches that could improve the user interface to better meet the needs of those with PTSD), and mobile app testing to ensure that app functionality and user interfaces are consistent with iOS and Android user interface guidelines, and expectancies of adult Veterans. This contract will assist NCPTSD in more quickly turning around builds to the mobile app developers to speed mobile app design, development, and maintenance.
2.0 APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of
2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security
Requirements For Cryptographic Modules”
4. FIPS Pub 199. Standards for Security Categorization of Federal Information and
Information Systems, February 2004
5. FIPS Pub 200, Minimum Security Requirements for Federal Information and
Information Systems, March 2016
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and
Contractors,” August 2013
7. 10 U.S.C. § 2224, "Defense Information Assurance Program"
8. Carnegie Mellon Software Engineering Institute, Capability Maturity Model®
Integration for Development (CMMI-DEV), Version 1.3 November 2010; and
Carnegie Mellon Software Engineering Institute, Capability Maturity Model®
Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010
9. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
10. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology
Act of 2006, Title IX, Information Security Matters
11. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
12. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/
13. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs
14. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility
Standards,” July 1, 2003
16. Office of Management and Budget (OMB) Circular A-130, “Managing Federal
Information as a Strategic Resource,” July 28, 2016
17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed
Services (CHAMPUS)”
18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998 http://www.va.gov/vapubs/ http://www.va.gov/vapubs http://www.va.gov/vapubs
20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
21. VA Directive 6500, “Managing Information Security Risk: VA Information Security
Program,” September 20, 2012
22. VA Handbook 6500, “Risk Management Framework for VA Information Systems –
Tier 3: VA Information Security Program,” March 10, 2015
23. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
24. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal
Information (SPI)”, July 28, 2016
25. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of
VA Information Systems,” February 3, 2014
26. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development
Lifecycle”, March 22, 2010
27. VA Handbook 6500.6, “Contract Security,” March 12, 2010
28. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011
29. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process
Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
30. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
31. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy
Impact Assessment,” October 15, 2014
32. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy
Impact Assessment,” July 30, 2015
33. VA Handbook 6510, “VA Identity and Access Management”, January 15, 2016
34. VA Directive 6300, Records and Information Management, February 26, 2009
35. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
36. NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal
Information Systems: a Security Life Cycle Approach, June 10, 2014
37. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information
Systems and Organizations, January 22, 2015
38. OMB Memorandum, “Transition to IPv6”, September 28, 2010
39. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12)
Program, October 26, 2015
40. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12)
Program, March 24, 2014
41. OMB Memorandum M-06-18, Acquisition of Products and Services for
Implementation of HSPD-12, June 30, 2006
42. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003
43. OMB Memorandum 05-24, Implementation of Homeland Security Presidential
Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal
Employees and Contractors, August 5, 2005
44. OMB memorandum M-11-11, “Continued Implementation of Homeland Security
Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for
Federal Employees and Contractors, February 3, 2011
45. OMB Memorandum, Guidance for Homeland Security Presidential Directive
(HSPD) 12 Implementation, May 23, 2008
46. Federal Identity, Credential, and Access Management (FICAM) Roadmap and
Implementation Guidance, December 2, 2011 https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx
47. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification
(PIV) Credentials in Physical Access Control Systems, November 20, 2008
48. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
49. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June
50. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014
51. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices
(Draft), October 2012
52. Draft National Institute of Standards and Technology Interagency Report (NISTIR)
7981 Mobile, PIV, and Authentication, March 2014
53. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland
Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
54. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
55. VA Memorandum “Mandate to meet PIV Requirements for New and Existing
Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
56. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland
Security, October 1, 2013, https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf
57. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections
(TIC), November 20, 2007
58. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name
System Infrastructure, August 22, 2008
59. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product
Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)
60. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public
Law 110–140), December 19, 2007
61. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
62. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015
63. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
64. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013
65. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013
66. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote
Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
67. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
68. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV)
Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ#
7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
69. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA
Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
70. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015;
https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
71. “Veteran Focused Integration Process (VIP) Guide 2.0”, May 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
72. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411
73. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
74. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
75. VA Memorandum “Updated VA Information Security Rules of Behavior (VAIQ
#7823189)”, September, 15, 2017,
3.0 SCOPE OF WORK
The Contractor shall provide mobile app testing to include functional testing, user experience testing, and ensuring the apps are clinically sound and current. The Contractor shall also generate clinical content for the mobile apps.
Contractor personnel directly involved with application testing and clinical content services shall have completed a doctoral degree in clinical psychology from an APA-accredited program, have clinical experience in working with Veterans with PTSD, conducting behavioral research, have expertise in science and evidence-based recommendations for the treatment of PTSD, and clinical experience in delivering mobile interventions to Veterans with PTSD.
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
The period of performance shall be 12 months from date of award, with two options for 12 months each.
4.2 PLACE OF PERFORMANCE
All other tasks under this PWS shall be performed at Contractor facilities.
4.3 TRAVEL
The Government anticipates travel under this effort to perform the tasks associated with the effort, as well as to attend program-related meetings or conferences throughout the period of performance. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.
The Contractor shall be required to attend meetings in-person monthly, at a minimum, at VA facility located at 795 Willow Road, Menlo Park, CA. The total estimated number of trips in support of the program related meetings for this effort is one per month. Anticipated location is
Menlo Park, CA, estimated at one day in duration for one person.
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
5.0 SPECIFIC TASKS AND DELIVERABLES
5.1 PROJECT MANAGEMENT (FFP)
5.1.1 REPORTING REQUIREMENTS
The Contractor shall provide the COR with Monthly Progress Reports in electronic form in
Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding month.
The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Electronic and Information Technology (EIT) deliverables and their current Section 508 conformance status. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.
The Contractor shall attend weekly meetings to brief VA on the status of each task and deliverable defined within this PWS and to review ongoing needs across the mobile apps portfolio. In-person attendance to the weekly meetings is required monthly at a minimum. The
Contractor briefing shall include a detailed review of the projected schedule, risk mitigation status, and the Contractor’s planned actions for recovering from any schedule slippage.
Deliverable:
A. Monthly Progress Report
5.1.2 TECHNICAL KICKOFF MEETING
The Contractor shall hold a technical kickoff meeting at VA facilities in Menlo Park, CA within
10 days after contract award. The Contractor shall present, for review and approval by the
Government, the details of the intended approach, work plan, and overall project management approach. The Contractor shall specify dates, agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and meeting minutes (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the Contracting Officer
(CO), Contract Specialist (CS), Contracting Officer’s Representative (COR), and VA PM.
5.2 MOBILE APP TESTING
The Contractor shall provide testing of NCPTSD mobile apps for PTSD to improve user experience and provide clinical judgement to ensure safety, suggest additional content to improve the apps and keep the content up-to-date. The amount and type of testing will vary widely on a per-project basis at NCPTSD’s discretion, with testing ranging from focused testing of a specific app section or feature to comprehensive user experience testing or complete testing of a mobile app. NCPTSD anticipates the Contractor shall test one mobile app at a given time, but may be required to test two apps concurrently.
The Contractor shall coordinate with NCPTSD for testing timelines for the apps. The Contractor shall report on all active and planned mobile app testing projects in the Monthly Progress Report and during weekly mobile app briefings.
Quality control of delivered mobile app testing shall be led and performed by the Contractor. All readily available specifications and documentation will be provided to the Contractor for use in testing, but the Contractor should be able to implement these tasks without any further documentation. The Contractor shall download required mobile apps to be tested from VA’s repository, currently Vertical. An issue tracking system administered by NCPTSD, currently
GitHub, shall be used to track quality control issues and monitor progress.
The Contractor shall test NCPTSD native mobile apps for PTSD. Testing shall include:
1. Testing of mobile apps on multiple Android and iOS devices to ensure the app works as intended and displays correctly on the device screen. For device testing, the Contractor shall test the mobile apps using actual devices (i.e., not simulators), particularly devices that are most widely used in the general population, that include multiple Android screen sizes (both phones and tablets) and multiple iOS screen sizes (both phones and tablets).
At a minimum, the Contractor shall test using two Android phone devices that have different screen sizes and one Android tablet device and two iOS phone devices that have different screen sizes and one iOS tablet device.
2. Ensuring mobile app content and features match NCPTSD technical specifications. The
Contractor shall be responsible for comparing technical specifications against their implementation in a mobile app, ensuring that a) all content matches between the specifications and the app and b) the app is resilient to complex user interactions without crashing, stalling, or losing data.
3. Reviewing material for consistency with current PTSD treatment guidelines (i.e., https://www.healthquality.va.gov/guidelines/MH/ptsd/) and the most up-to-date scientific literature on PTSD education, treatment, and clinical care.
4. Ensuring clinical safety (i.e., appropriateness to the clinical care of Veterans with PTSD) and confidentiality.
5. Ensuring consistency with Apple iOS human interface guidelines, Android design guidelines, and recently-released NCPTSD mobile apps.
6. Optimizing user experience, which at a minimum shall include reviewing wireframes and app sequences to identify potential dead-ends (i.e., views that cannot be easily navigated out of, user-entered information that cannot be changed or edited, etc.) or ways of interacting with the apps that are likely to be confusing for different types of Veterans using the app; offering suggestions for simplifying user interaction elements and alternative flows; identifying additional clinical content that could assist Veterans in making better use of the apps.
7. Testing for Section 508 accessibility compliance.
8. Conducting comprehensive testing of research versions of apps by visiting and recording all screens within the app and checking that data transmitted from research versions of apps (i.e., timestamps, buttons tapped, user-entered data) match testing records (i.e., data transmitted in JavaScript Object Notation (JSON) format should match testing records of which app screens were visited, dates and times for when each screen was visited, and any data entered by the tester while testing the app).
9. Veteran-focused user experience testing. Testing shall include focused (i.e., testing one section or feature of an app) and general (i.e., testing every feature and section of the app) testing of mobile apps using specific user personas (e.g., repeat survey-taker, skeptical user, long-term user, etc.). The Contractor shall also conduct user experience interviews with target users, employing established user experience (UX) research principles. The
Contractor shall incorporate results of user experience interviews into recommendations for cost-effective design changes that could improve users’ experiences with the app.
https://www.healthquality.va.gov/guidelines/MH/ptsd/
The Contractor shall provide a Weekly Testing Report that summarizes the testing performed during the week and the progress made on the issues reported in the issue tracking system. In addition, any recommended user experience improvements and suggested clinical content shall be included in the Weekly Testing Report.
Final deliverables of each testing project shall include the delivery of all testing documentation and reports as described above. Before any work begins on a testing project, the Contractor shall produce time estimates of the number of hours that will be needed for the work to be performed, and shall obtain the approval of NCPTSD for the expenditure of hours.
A. Testing Documentation and Reports
B. Weekly Testing Report
5.3 CONTENT FOR MOBILE APPS
The Contractor shall provide content writing support services for mobile apps and public health education materials to support NCPTSD mobile apps for PTSD, based on the best available scientific evidence, current VA norms and standards for the clinical care of Veterans with PTSD, expert knowledge of VA care for PTSD, current clinical guidelines for the treatment of PTSD, and familiarity with common terms and expressions used by Veterans. NCPTSD mobile apps for PTSD need to be kept up-to-date with, for example, the newest treatment, educational materials, and available clinical science. The Contractor shall be responsible for writing up-to-date content to be used in publicly-released mobile apps for mental health and supporting handouts and patient education materials.
The Contractor shall write public health education materials capable of being included in
NCPTSD mobile apps, such as brief psychoeducational topics specific to PTSD treatment and recovery (see PTSD Coach, PTSD Family Coach, and other publicly-available NCPTSD apps for examples). The Contractor shall provide written outlines and wireframes for detailed tools and other app features requested by NCPTSD. The Contractor shall create flyers and other web-based promotional materials to support appropriate implementation of VA mobile apps across
VA treatment settings. The Contractor shall use the best available scientific evidence for treatment of PTSD to write the content while also writing content that can be quickly and easily read and is optimized for delivery on a mobile device or tablet. The Contractor shall write content that is accessible to the widest possible range of reading levels, with brief content that is accessible to reading levels of sixth grade and below and more detailed content accessible to those with slightly higher reading levels. The Contractor shall provide a Weekly Content Report that contains all content written during the week, to include content for mobile apps, promotional materials, and outlines and wireframes for tools and app features.
A. Weekly Content Report
6.0 GENERAL REQUIREMENTS
6.1 ENTERPRISE AND IT FRAMEWORK
6.1.1 ONE-VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (One-VA TRM).
One-VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. One-VA TRM includes the Standards Profile and
Product List that collectively serves as a VA technology roadmap. Architecture, Strategy, and
Design (ASD) has overall responsibility for the One-VA TRM.
6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT
(FICAM)
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture
(ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all
Contractor delivered applications and systems comply with the VA Identity, Credential, and
Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation
Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology
(NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System
Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of
Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal
Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-
11-11 can be found at:
https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-
04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m0
5-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved
Product List (APL). If the Contractor delivered application and system is not on the APL, the
Contractor shall be responsible for taking the application and system through the FIPS 201
Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support:
1. Automated provisioning and are able to use enterprise provisioning service.
http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp http://www.techstrategies.oit.va.gov/enterprise_dp.asp https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf
2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number
[ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator
Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA
Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required
SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems. https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)
The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005
(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m
05-22.pdf) and September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267
(https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet), the
Technical Infrastructure for USGv6 Adoption (http://www-x.antd.nist.gov/usgv6/index.html), and the NIST SP 800 series applicable compliance
(http://csrc.nist.gov/publications/PubsSPs.html) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations.
Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at: https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet http://www-x.antd.nist.gov/usgv6/index.html http://csrc.nist.gov/publications/PubsSPs.html https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282
6.1.4 TRUSTED INTERNET CONNECTION (TIC)
The Contractor solution shall meet the requirements outlined in Office of Management and
Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC)
(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m
08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC)
(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m
08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference
Architecture Document, Version 2.0 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.
6.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.