36C10B18R2935-003.pdf

PDF 771 KB Posted

Attached to
TAC-18-50881 App Tester Federal contract opportunity
Solicitation number
36C10B18R2935
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

36C10B18R2935 36C10B18R2935.pdf

View the file

Other files for this federal contract opportunity

Other files attached to TAC-18-50881 App Tester, newest first.
File Type Posted
36C10B18C2752-000.docx DOCX document
36C10B18R2935-002.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. DUNS: DUNS+4:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. 2/2012)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS 61

36C10B18R2935 8-15-2018

Jessica Adamitis – Contract Specialist 732-440-9704 8-23-2018

12:00PM EST

Department of Veterans Affairs

Technology Acquisition Center

23 Christopher Way

Eatontown NJ 07724

541512

$27.5 Million

X

N/A

X

See Delivery Schedule

Financial Services Center

PO Box 149971

Austin TX 78714-8971

See CONTINUATION Page

Mental Health Mobile Applications Clinical Testing and Content

Writing Support

See Section B.3 Price Schedule and B.4 Performance Work Statement

This Request for Proposal (RFP) will result in a Labor-Hour

Contract.

This is a small business set-aside in accordance with FAR

52.219-6 Notice of Total Small Business Set-Aside

Offerors will be evaluated in accordance with Section E.

See CONTINUATION Page

X X

36C10B18R2935

Table of Contents

SECTION A

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 GOVERNING LAW

B.3 PRICE SCHEDULE

B.3 PERFORMANCE WORK STATEMENT

SECTION C - CONTRACT CLAUSES

C.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT

STATUTES OR EXECUTIVE ORDERS—COMMERCIAL ITEMS (JAN 2018)

C.3 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)

C.4 VAAR 852.203-70 COMMERCIAL ADVERTISING (MAY 2018)

C.5 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV

2012)

C.7 VAAR 852.270-1 REPRESENTATIVES OF CONTRACTING OFFICERS (JAN 2008) . 42

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

SECTION E - SOLICITATION PROVISIONS

E.1 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB

1998)

E.2 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL

ITEMS (NOV 2017)

E.3 52.216-1 TYPE OF CONTRACT (APR 1984)

E.4 52.233-2 SERVICE OF PROTEST (SEP 2006)

E.5 VAAR 852.233-70 PROTEST CONTENT/ALTERNATIVE DISPUTE RESOLUTION

(JAN 2008)

E.6 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (MAY 2010)

E.7 BASIS FOR AWARD

E.8 QUOTE SUBMISSION INSTRUCTIONS

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

(continuation from Standard Form 1449, block 18A.)

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR: TBD

b. GOVERNMENT: Contracting Officer 36C10B Juan Quinones

Technology Acquisition Center

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer - System for Award

Management

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [X] Upon Government Acceptance of Deliverables in Section B.3

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of

Payment Requests.

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO DATE

B.2 GOVERNING LAW

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the

Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41

U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data

Processing or Maintenance (38 U.S.C. § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this Clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this Clause shall prevail. Claims of patent or copyright infringement brought against the

Government as a party shall be defended by the U.S. Department of Justice (DOJ). 28 U.S.C. §

516. At the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be effected by a warranted

Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.3 PRICE SCHEDULE

Inspection/Acceptance//F.O.B: Destination.

All deliverables must be submitted electronically to the VA Program Manager (PM), Contracting

Officer’s Representative (COR), and Contracting Officer unless otherwise specified in the line item. Please be advised that in accordance with Federal Acquisition Regulation (FAR) Part

2.101, a “day” means, unless otherwise specified, a CALENDER day. Additionally, deliverables with due dates falling on a weekend or holiday shall be submitted the following Government work day after the weekend or holiday.

The Price Schedule contains contract line items identified as not separately priced (NSP). This means the price for the line item is included in the price of another, related line item. The

Contractor shall not invoice the Government for any portion of the contract line item which contains an NSP until the Contractor has delivered the total quantity of all related contract line items and the Government has accepted them.

NOTE: Vendors are instructed to complete Section B.4 Contract Line Item Numbers (CLIN) and Subcontract Line Item Numbers (SLIN) and submit with their quote. Vendors are instructed to see solicitation Section E.8 for quote submission instructions. Vendors are cautioned that alterations to the line items as specified below may render quotes unacceptable. All questions shall be directed to the Contract Specialist, Jessica Adamitis, Jessica.Adamitis@va.gov and

Contracting Officer, Juan Quinones, Juan.Quinones@va.gov prior to the closing date and time specified in the Request for Quote (RFQ).

BASE PERIOD

The period of performance shall be 12 months from date of award.

Contract

Line Item

Number

(CLIN)

Description Qty Unit Unit Price Extended Price

0001 Project Management in accordance with

(IAW) Performance Work Statement (PWS)

5.1 Firm-Fixed-Price.

Period of Performance shall be 12 months from date of award.

This CLIN includes all tasks, labor, and travel required for the successful compilation of the services detailed in PWS Section 5.1 and its subtasks.

12 MO $ $

0001AA Monthly Progress Report IAW PWS 5.1.1.

Due 30 days from contract award and updated monthly thereafter.

12 MO NSP NSP

0002 Mobile App Testing IAW PWS 5.2 Labor-

Hour.

This is a Labor-Hour CLIN and includes all labor

1 LO $ NTE

mailto:Jessica.Adamitis@va.gov mailto:Juan.Quinones@va.gov required for the successful completion of the tasks associated with PWS 5.2.

The Contractor shall not execute performance on this task without approval from the Contracting

Officer.

Instructions to Offerors

Offerors shall provide their proposed Loaded

Labor Rate and complete the table below. The

Unit Price shall be the Loaded Labor Rate. The

Extended price is Not to Exceed (NTE) the total

Loaded Labor Rate multiplied by total Labor

Hours.

Labor

Category

Labor

Hours

Loaded

Labor

Rate

Amount

Tester 600 $ $

Total $

Before any work begins on a maintenance project, the Contractor shall produce time estimates of the number of hours that will be needed for the work to be performed, and shall obtain the approval of NCPTSD for the expenditure of hours.

This Labor-Hour CLIN is IAW FAR 52.232-7 for invoicing or billing purposes.

0002AA Testing Documentation and Reports IAW PWS

5.2.

Due upon completion of each testing project.

1 LO NSP NSP

0002AB Weekly Testing Report IAW PWS 5.2.

Due weekly throughout the period of performance.

1 LO NSP NSP

0003 Content for Mobile Apps IAW PWS 5.3

Labor-Hour.

Instructions to Offerors

Offerors shall provide their proposed Loaded

Labor Rate and complete the table below. The

Unit Price shall be the Loaded Labor Rate. The

Extended price is Not to Exceed (NTE) the total

Labor

Hours

Loaded

Labor

Rate

Amount

Technical

Writer

400 $ $ estimates of the number of hours that will be needed for the work to be performed, and shall

This Labor-Hour CLIN is IAW FAR 52.232-72

0003AA Weekly Content Report IAW PWS 5.3

1 LO NSP NSP

TOTAL BASE PERIOD $

OPTION PERIOD 1

This option may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR

2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting

Officer. If exercised, this option shall commence immediately after expiration of the base period.

Period of Performance shall be 12 months.

CLIN Description Qty Unit Unit Price Extended Price

1001 Project Management in accordance with

5.1.

services detailed in PWS Section 5.1 and its subtasks.

1001AA Monthly Progress Report IAW PWS 5.1.1.

12 MO NSP NSP

Due 30 days from contract award and updated monthly thereafter.

1002 Mobile App Testing IAW PWS 5.2 Labor-

Labor Rate and complete the table below. The

Unit Price shall be the Loaded Labor Rate. The

Extended price is Not to Exceed (NTE) the total

Labor

Hours

Loaded

Labor

Rate

Amount estimates of the number of hours that will be needed for the work to be performed, and shall

1 LO $ NTE

1002AA Testing Documentation and Reports IAW PWS

1002AB Weekly Testing Report IAW PWS 5.2.

1 LO NSP NSP

1003 Content for Mobile Apps IAW PWS 5.3

Labor Rate and complete the table below. The

Unit Price shall be the Loaded Labor Rate. The

Extended price is Not to Exceed (NTE) the total

Labor

Hours

Loaded

Labor

Rate

Amount

Technical

Writer estimates of the number of hours that will be needed for the work to be performed, and shall

1003AA Weekly Content Report IAW PWS 5.3

TOTAL OPTION PERIOD 1 $

OPTION PERIOD 2

This option may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR

2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting

Officer. If exercised, this option shall commence immediately after expiration of the base period.

CLIN Description Qty Unit Unit Price Extended Price

2001 Project Management in accordance with

5.1.

services detailed in PWS Section 5.1 and its subtasks.

1001AA Monthly Progress Report IAW PWS 5.1.1.

Due 30 days from contract award and updated monthly thereafter.

12 MO NSP NSP

2002 Mobile App Testing IAW PWS 5.2 Labor-

Labor Rate and complete the table below. The

Unit Price shall be the Loaded Labor Rate. The

Extended price is Not to Exceed (NTE) the total

Labor

Hours

Loaded

Labor

Rate

Amount estimates of the number of hours that will be needed for the work to be performed, and shall

1 LO $ NTE

2002AA Testing Documentation and Reports IAW PWS

2002AB Weekly Testing Report IAW PWS 5.2.

Due weekly throughout the period of performance.

2003 Content for Mobile Apps IAW PWS 5.3

Labor Rate and complete the table below. The

Unit Price shall be the Loaded Labor Rate. The

Extended price is Not to Exceed (NTE) the total

Labor

Hours

Loaded

Labor

Rate

Amount

Technical

Writer estimates of the number of hours that will be needed for the work to be performed, and shall

1 LO $ NTE

2003AA Weekly Content Report IAW PWS 5.3

1 LO NSP NSP

TOTAL OPTION PERIOD 2 $

TOTAL CONTRACT $

B.3 PERFORMANCE WORK STATEMENT

DEPARTMENT OF VETERANS AFFAIRS

Veterans Health Administration

National Center for Post-Traumatic Stress Disorder

Mental Health Mobile Applications Clinical Testing and Content Writing Support

Date: July 9, 2018

TAC-18-50881

PWS Version Number: 1.0

1.0 BACKGROUND

The Department of Veterans Affairs (VA), National Center for Post-Traumatic Stress Disorder

(NCPTSD), Dissemination and Training Division is responsible for creating training and educational products to support evidence-based care of Veterans with Post-Traumatic Stress

Disorder (PTSD) and related problems. PTSD is very common among Veterans and has a significant impact on Veterans’ quality of life. Most Veterans with PTSD do not access evidence-based treatments for PTSD, and many Veterans are either unable or choose not to access available mental health services of any kind. Lack of available services, distance from clinics, and stigma associated with mental health care are just a few of the barriers to providing care for Veterans and those living with a Veteran with PTSD. NCPTSD has developed mobile applications (apps) to overcome these and other barriers to care. The apps are designed to assist

Veterans and their family members with understanding PTSD and related problems, tracking their improvement over time, obtaining support and resources, and managing symptoms using a variety of brief tools.

NCPTSD has developed a variety of mobile applications in the past seven years, including, most notably, the multi-award winning PTSD Coach (Winner of the Advancements in Accessibility

Award from the Federal Communications Commission 2011 and Winner of the President’s

Innovation Award from the American Telemedicine Association 2012). NCPTSD currently maintains a portfolio of 25 native, publicly-available apps (e.g., PTSD Coach, CBT-i Coach, Mindfulness Coach, PE Coach, Stay Quit Coach), that have been downloaded from the App

Store and Play Store by over 640,000 Veterans and others. The portfolio currently consists of 16 native (i.e. Objective-C) iOS apps and 9 native (i.e. Java) Android apps. Each mobile app aims to address specific implementation challenges faced by Veterans and their family members in receiving education, training, and treatment.

The NCPTSD Dissemination and Training Division has also been charged with ensuring that

NCPTSD mobile apps are 1) capable of supporting scientific research, 2) capable of responding to the needs of Veterans, VA providers, and other stakeholders, and 3) reflect the most up-to-date and evidence-based guidelines for addressing PTSD and PTSD-related concerns in Veterans. To meet this charge, NCPTSD has a multi-phase coordinated research program to study the usability, efficacy, and implementation of these applications and works directly with Mental

Health Services in VA Central Office to ensure that products are aligned with the mission to enhance and optimize mental health care for Veterans. NCPTSD has also made strides to ensure that its suite of mobile applications are as easy-to-use as possible, are designed to reflect the needs of Veteran users, and integrate the best-available clinical recommendations to support

Veterans’ recovery from PTSD.

This contract action is part of a set of activities designed to maintain, redesign, and upgrade existing mobile apps previously built for NCPTSD, in order to provide reliable, high-quality mental health service to Veterans, their families, health care providers, and others. The specific work assignments will be determined throughout the period of performance, as Apple’s successive updates to iOS and Google’s successive updates to Android introduce new bugs and performance problems to the apps over the year, and as NCPTSD staff consider and develop possible new features. NCPTSD has a need to more rapidly provide feedback to the VA mobile app developers, to more rapidly generate content for new apps, to be more responsive to requests for updates to existing apps in the portfolio, and to have an additional layer of clinical review to ensure appropriateness and utility for Veterans with PTSD. NCPTSD requires support with clinical content writing (including development of clinically-supported, evidence-based, user-friendly patient education materials), clinical review of existing content to ensure appropriateness to the Veteran population and consistency with the latest clinical evidence on

PTSD treatment and recovery, Veteran-focused user experience testing to evaluate apps to ensure that they are easy to use, relatable, and inviting to Veterans with PTSD (e.g., making sure the user experience is not frustrating for Veterans and suggesting alternative approaches that could improve the user interface to better meet the needs of those with PTSD), and mobile app testing to ensure that app functionality and user interfaces are consistent with iOS and Android user interface guidelines, and expectancies of adult Veterans. This contract will assist NCPTSD in more quickly turning around builds to the mobile app developers to speed mobile app design, development, and maintenance.

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of

2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security

Requirements For Cryptographic Modules”

4. FIPS Pub 199. Standards for Security Categorization of Federal Information and

Information Systems, February 2004

5. FIPS Pub 200, Minimum Security Requirements for Federal Information and

Information Systems, March 2016

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and

Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. Carnegie Mellon Software Engineering Institute, Capability Maturity Model®

Integration for Development (CMMI-DEV), Version 1.3 November 2010; and

Carnegie Mellon Software Engineering Institute, Capability Maturity Model®

Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010

9. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

10. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology

Act of 2006, Title IX, Information Security Matters

11. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

12. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/

13. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs

14. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008

15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility

Standards,” July 1, 2003

16. Office of Management and Budget (OMB) Circular A-130, “Managing Federal

Information as a Strategic Resource,” July 28, 2016

17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed

Services (CHAMPUS)”

18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008

19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998 http://www.va.gov/vapubs/ http://www.va.gov/vapubs http://www.va.gov/vapubs

20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

21. VA Directive 6500, “Managing Information Security Risk: VA Information Security

Program,” September 20, 2012

22. VA Handbook 6500, “Risk Management Framework for VA Information Systems –

Tier 3: VA Information Security Program,” March 10, 2015

23. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008

24. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal

Information (SPI)”, July 28, 2016

25. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of

VA Information Systems,” February 3, 2014

26. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development

Lifecycle”, March 22, 2010

27. VA Handbook 6500.6, “Contract Security,” March 12, 2010

28. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011

29. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process

Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

30. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

31. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy

Impact Assessment,” October 15, 2014

32. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy

Impact Assessment,” July 30, 2015

33. VA Handbook 6510, “VA Identity and Access Management”, January 15, 2016

34. VA Directive 6300, Records and Information Management, February 26, 2009

35. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

36. NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal

Information Systems: a Security Life Cycle Approach, June 10, 2014

37. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information

Systems and Organizations, January 22, 2015

38. OMB Memorandum, “Transition to IPv6”, September 28, 2010

39. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12)

Program, October 26, 2015

40. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12)

Program, March 24, 2014

41. OMB Memorandum M-06-18, Acquisition of Products and Services for

Implementation of HSPD-12, June 30, 2006

42. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003

43. OMB Memorandum 05-24, Implementation of Homeland Security Presidential

Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal

Employees and Contractors, August 5, 2005

44. OMB memorandum M-11-11, “Continued Implementation of Homeland Security

Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for

Federal Employees and Contractors, February 3, 2011

45. OMB Memorandum, Guidance for Homeland Security Presidential Directive

(HSPD) 12 Implementation, May 23, 2008

46. Federal Identity, Credential, and Access Management (FICAM) Roadmap and

Implementation Guidance, December 2, 2011 https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx

47. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification

(PIV) Credentials in Physical Access Control Systems, November 20, 2008

48. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

49. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June

50. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014

51. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices

(Draft), October 2012

52. Draft National Institute of Standards and Technology Interagency Report (NISTIR)

7981 Mobile, PIV, and Authentication, March 2014

53. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland

Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

54. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

55. VA Memorandum “Mandate to meet PIV Requirements for New and Existing

Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

56. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland

Security, October 1, 2013, https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf

57. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections

(TIC), November 20, 2007

58. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name

System Infrastructure, August 22, 2008

59. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product

Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)

60. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public

Law 110–140), December 19, 2007

61. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

62. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015

63. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

64. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013

65. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013

66. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote

Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

67. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

68. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV)

Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ#

7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

69. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA

Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

70. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015;

https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

71. “Veteran Focused Integration Process (VIP) Guide 2.0”, May 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

72. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

73. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

74. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

75. VA Memorandum “Updated VA Information Security Rules of Behavior (VAIQ

#7823189)”, September, 15, 2017,

3.0 SCOPE OF WORK

The Contractor shall provide mobile app testing to include functional testing, user experience testing, and ensuring the apps are clinically sound and current. The Contractor shall also generate clinical content for the mobile apps.

Contractor personnel directly involved with application testing and clinical content services shall have completed a doctoral degree in clinical psychology from an APA-accredited program, have clinical experience in working with Veterans with PTSD, conducting behavioral research, have expertise in science and evidence-based recommendations for the treatment of PTSD, and clinical experience in delivering mobile interventions to Veterans with PTSD.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The period of performance shall be 12 months from date of award, with two options for 12 months each.

4.2 PLACE OF PERFORMANCE

All other tasks under this PWS shall be performed at Contractor facilities.

4.3 TRAVEL

The Government anticipates travel under this effort to perform the tasks associated with the effort, as well as to attend program-related meetings or conferences throughout the period of performance. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.

The Contractor shall be required to attend meetings in-person monthly, at a minimum, at VA facility located at 795 Willow Road, Menlo Park, CA. The total estimated number of trips in support of the program related meetings for this effort is one per month. Anticipated location is

Menlo Park, CA, estimated at one day in duration for one person.

https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

5.0 SPECIFIC TASKS AND DELIVERABLES

5.1 PROJECT MANAGEMENT (FFP)

5.1.1 REPORTING REQUIREMENTS

The Contractor shall provide the COR with Monthly Progress Reports in electronic form in

Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding month.

The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Electronic and Information Technology (EIT) deliverables and their current Section 508 conformance status. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.

The Contractor shall attend weekly meetings to brief VA on the status of each task and deliverable defined within this PWS and to review ongoing needs across the mobile apps portfolio. In-person attendance to the weekly meetings is required monthly at a minimum. The

Contractor briefing shall include a detailed review of the projected schedule, risk mitigation status, and the Contractor’s planned actions for recovering from any schedule slippage.

Deliverable:

A. Monthly Progress Report

5.1.2 TECHNICAL KICKOFF MEETING

The Contractor shall hold a technical kickoff meeting at VA facilities in Menlo Park, CA within

10 days after contract award. The Contractor shall present, for review and approval by the

Government, the details of the intended approach, work plan, and overall project management approach. The Contractor shall specify dates, agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and meeting minutes (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the Contracting Officer

(CO), Contract Specialist (CS), Contracting Officer’s Representative (COR), and VA PM.

5.2 MOBILE APP TESTING

The Contractor shall provide testing of NCPTSD mobile apps for PTSD to improve user experience and provide clinical judgement to ensure safety, suggest additional content to improve the apps and keep the content up-to-date. The amount and type of testing will vary widely on a per-project basis at NCPTSD’s discretion, with testing ranging from focused testing of a specific app section or feature to comprehensive user experience testing or complete testing of a mobile app. NCPTSD anticipates the Contractor shall test one mobile app at a given time, but may be required to test two apps concurrently.

The Contractor shall coordinate with NCPTSD for testing timelines for the apps. The Contractor shall report on all active and planned mobile app testing projects in the Monthly Progress Report and during weekly mobile app briefings.

Quality control of delivered mobile app testing shall be led and performed by the Contractor. All readily available specifications and documentation will be provided to the Contractor for use in testing, but the Contractor should be able to implement these tasks without any further documentation. The Contractor shall download required mobile apps to be tested from VA’s repository, currently Vertical. An issue tracking system administered by NCPTSD, currently

GitHub, shall be used to track quality control issues and monitor progress.

The Contractor shall test NCPTSD native mobile apps for PTSD. Testing shall include:

1. Testing of mobile apps on multiple Android and iOS devices to ensure the app works as intended and displays correctly on the device screen. For device testing, the Contractor shall test the mobile apps using actual devices (i.e., not simulators), particularly devices that are most widely used in the general population, that include multiple Android screen sizes (both phones and tablets) and multiple iOS screen sizes (both phones and tablets).

At a minimum, the Contractor shall test using two Android phone devices that have different screen sizes and one Android tablet device and two iOS phone devices that have different screen sizes and one iOS tablet device.

2. Ensuring mobile app content and features match NCPTSD technical specifications. The

Contractor shall be responsible for comparing technical specifications against their implementation in a mobile app, ensuring that a) all content matches between the specifications and the app and b) the app is resilient to complex user interactions without crashing, stalling, or losing data.

3. Reviewing material for consistency with current PTSD treatment guidelines (i.e., https://www.healthquality.va.gov/guidelines/MH/ptsd/) and the most up-to-date scientific literature on PTSD education, treatment, and clinical care.

4. Ensuring clinical safety (i.e., appropriateness to the clinical care of Veterans with PTSD) and confidentiality.

5. Ensuring consistency with Apple iOS human interface guidelines, Android design guidelines, and recently-released NCPTSD mobile apps.

6. Optimizing user experience, which at a minimum shall include reviewing wireframes and app sequences to identify potential dead-ends (i.e., views that cannot be easily navigated out of, user-entered information that cannot be changed or edited, etc.) or ways of interacting with the apps that are likely to be confusing for different types of Veterans using the app; offering suggestions for simplifying user interaction elements and alternative flows; identifying additional clinical content that could assist Veterans in making better use of the apps.

7. Testing for Section 508 accessibility compliance.

8. Conducting comprehensive testing of research versions of apps by visiting and recording all screens within the app and checking that data transmitted from research versions of apps (i.e., timestamps, buttons tapped, user-entered data) match testing records (i.e., data transmitted in JavaScript Object Notation (JSON) format should match testing records of which app screens were visited, dates and times for when each screen was visited, and any data entered by the tester while testing the app).

9. Veteran-focused user experience testing. Testing shall include focused (i.e., testing one section or feature of an app) and general (i.e., testing every feature and section of the app) testing of mobile apps using specific user personas (e.g., repeat survey-taker, skeptical user, long-term user, etc.). The Contractor shall also conduct user experience interviews with target users, employing established user experience (UX) research principles. The

Contractor shall incorporate results of user experience interviews into recommendations for cost-effective design changes that could improve users’ experiences with the app.

https://www.healthquality.va.gov/guidelines/MH/ptsd/

The Contractor shall provide a Weekly Testing Report that summarizes the testing performed during the week and the progress made on the issues reported in the issue tracking system. In addition, any recommended user experience improvements and suggested clinical content shall be included in the Weekly Testing Report.

Final deliverables of each testing project shall include the delivery of all testing documentation and reports as described above. Before any work begins on a testing project, the Contractor shall produce time estimates of the number of hours that will be needed for the work to be performed, and shall obtain the approval of NCPTSD for the expenditure of hours.

A. Testing Documentation and Reports

B. Weekly Testing Report

5.3 CONTENT FOR MOBILE APPS

The Contractor shall provide content writing support services for mobile apps and public health education materials to support NCPTSD mobile apps for PTSD, based on the best available scientific evidence, current VA norms and standards for the clinical care of Veterans with PTSD, expert knowledge of VA care for PTSD, current clinical guidelines for the treatment of PTSD, and familiarity with common terms and expressions used by Veterans. NCPTSD mobile apps for PTSD need to be kept up-to-date with, for example, the newest treatment, educational materials, and available clinical science. The Contractor shall be responsible for writing up-to-date content to be used in publicly-released mobile apps for mental health and supporting handouts and patient education materials.

The Contractor shall write public health education materials capable of being included in

NCPTSD mobile apps, such as brief psychoeducational topics specific to PTSD treatment and recovery (see PTSD Coach, PTSD Family Coach, and other publicly-available NCPTSD apps for examples). The Contractor shall provide written outlines and wireframes for detailed tools and other app features requested by NCPTSD. The Contractor shall create flyers and other web-based promotional materials to support appropriate implementation of VA mobile apps across

VA treatment settings. The Contractor shall use the best available scientific evidence for treatment of PTSD to write the content while also writing content that can be quickly and easily read and is optimized for delivery on a mobile device or tablet. The Contractor shall write content that is accessible to the widest possible range of reading levels, with brief content that is accessible to reading levels of sixth grade and below and more detailed content accessible to those with slightly higher reading levels. The Contractor shall provide a Weekly Content Report that contains all content written during the week, to include content for mobile apps, promotional materials, and outlines and wireframes for tools and app features.

A. Weekly Content Report

6.0 GENERAL REQUIREMENTS

6.1 ENTERPRISE AND IT FRAMEWORK

6.1.1 ONE-VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (One-VA TRM).

One-VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. One-VA TRM includes the Standards Profile and

Product List that collectively serves as a VA technology roadmap. Architecture, Strategy, and

Design (ASD) has overall responsibility for the One-VA TRM.

6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT

(FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture

(ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all

Contractor delivered applications and systems comply with the VA Identity, Credential, and

Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation

Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology

(NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System

Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of

Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal

Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-

11-11 can be found at:

https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-

04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m0

5-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved

Product List (APL). If the Contractor delivered application and system is not on the APL, the

Contractor shall be responsible for taking the application and system through the FIPS 201

Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp http://www.techstrategies.oit.va.gov/enterprise_dp.asp https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number

[ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator

Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA

Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required

SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems. https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m

05-22.pdf) and September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267

(https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet), the

Technical Infrastructure for USGv6 Adoption (http://www-x.antd.nist.gov/usgv6/index.html), and the NIST SP 800 series applicable compliance

(http://csrc.nist.gov/publications/PubsSPs.html) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations.

Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at: https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet http://www-x.antd.nist.gov/usgv6/index.html http://csrc.nist.gov/publications/PubsSPs.html https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282

6.1.4 TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and

Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC)

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m

08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC)

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m

08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference

Architecture Document, Version 2.0 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.

6.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.