36C10B19Q0193-A0001001.pdf

PDF 720 KB Posted

Attached to
TAC-19-54546 Integrated Master Schedule (IMS) Support Federal contract opportunity
Solicitation number
36C10B19Q0193
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

36C10B19Q0193 A0001 36C10B19Q0193 A0001.pdf

View the file

Other files for this federal contract opportunity

Other files attached to TAC-19-54546 Integrated Master Schedule (IMS) Support, newest first.
File Type Posted
36C10B19Q0193-A0001000.docx DOCX document
36C10B19Q0193-A0001002.pdf PDF
36C10B19Q0193-001.pdf PDF
36C10B19Q0193-000.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

5. PROJECT NUMBER (if applicable)

CODE 7. ADMINISTERED BY

2. AMENDMENT/MODIFICATION NUMBER

CODE

6. ISSUED BY

8. NAME AND ADDRESS OF CONTRACTOR

4. REQUISITION/PURCHASE REQ. NUMBER 3. EFFECTIVE DATE

9A. AMENDMENT OF SOLICITATION NUMBER

9B. DATED

PAGE OF PAGES

10A. MODIFICATION OF CONTRACT/ORDER NUMBER

10B. DATED

BPA NO. 1. CONTRACT ID CODE

FACILITY CODE CODE

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

E. IMPORTANT:

is extended,

(a) By completing Items 8 and 15, and returning __________ copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR

ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY is not extended.

12. ACCOUNTING AND APPROPRIATION DATA

(REV. 11/2016)

is required to sign this document and return ___________ copies to the issuing office. is not, A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN ITEM 10A.

15C. DATE SIGNED

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES

SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER

Contractor

16C. DATE SIGNED

14. DESCRIPTION OF AMENDMENT/MODIFICATION

16B. UNITED STATES OF AMERICA

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER 16A. NAME AND TITLE OF CONTRACTING OFFICER

15B. CONTRACTOR/OFFEROR

STANDARD FORM 30 PREVIOUS EDITION NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.243

(Type or print) (Type or print)

(Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

(Number, street, county, State and ZIP Code)

(If other than Item 6)

(Specify type of modification and authority)

(such as changes in paying office, appropriation date, etc.)

(If required)

(SEE ITEM 11)

(SEE ITEM 13)

(X)

CHECK

ONE

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

(Signature of person authorized to sign) (Signature of Contracting Officer)

1 37

A0001

TAC-19-54546

Department of Veterans Affairs

Technology Acquisition Center

23 Christopher Way

Eatontown NJ 07724

Technology Acquisition Center

23 Christopher Way

Eatontown NJ 07724

To all Offerors/Bidders

36C10B19Q0193

X

X

2-22-2019 10:00AM EST

SEE CONTINUATION PAGE

36C10B19Q0193 A0001

CONTINUATION PAGE

The purpose of this Amendment A0001 to Request for Quote (RFQ) 36C10B19Q0193 titled

“Integrated Master Schedule (IMS) Support” is as detailed below. All changes to the RFQ

36C10B19Q0193 has been captured in track changes.

1. Section B.5 Performance Work Statement (PWS), Paragraph 1.0 Background is hereby revised as follows:

a. “There is a need for an Integrated Master Schedule (IMS) to be developed and maintained for all ongoing and planned OIT specified programs,” is hereby revised to “There is a need for a consolidated Integrated Master Schedule (IMS) to be developed and maintained for all ongoing and planned OIT specified programs. The IMS shall be a consolidation of existing schedules from varying

VA OIT subprojects supporting programs,” is hereby incorporated.

b. “Provide a day-to-day tool for executing the OIT Program with proper sequencing,” is hereby revised to “Provide a day-to-day tool for executing the

OTI Program with proper sequencing.”

2. Section B.5 PWS, Paragraph 3.0, Scope of Work, is hereby revised to state, “The

Contractor shall provide technical, management, analysis, and support services to OIT

OTI, to develop and maintain a consolidated IMS for all ongoing and planned OIT specified programs. The Contractor shall also provide, configure and maintain a consolidated IMS reporting/dashboard system.”

3. Section E.8 Basis for Award, Quote Submission Instructions, Paragraph 3 is hereby revised to state, “Tables may use a reduced font size not less than 10-point font.”

4. The solicitation is hereby extended to close on February 22, 2019 at 10:00AM EST.

5. Except as provided herein, all other terms and conditions of RFQ 36C10B19Q0193 remain unchanged and in full force and effect.

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.5 PERFORMANCE WORK STATEMENT

Office of Information & Technology

Office of Technology Integration (OTI)

Integrated Master Schedule (IMS) Support

Date: February 19, 2019

TAC-19-54546

PWS Version Number: 2.0

1.0 BACKGROUND

The mission of the Department of Veterans Affairs (VA), Office of Information & Technology

(OIT), Office of Technology Integration (OTI) is to provide benefits and services to Veterans of the United States. In meeting these goals, OIT and OTI strive to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the

Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on Information

Management/Information Technology (IM/IT) systems to meet mission goals.

There is a need for an consolidated Integrated Master Schedule (IMS) to be developed and maintained for all ongoing and planned OIT specified programs. The IMS shall be a consolidation of existing schedules from varying VA OIT subprojects supporting programs. The primary purpose of the IMS is for use by the Government to:

• Provide a day-to-day tool for executing the OIT OTI Program with proper sequencing

• Identify and manage dependencies and predecessor tasks

• Track individual project work request and sprint/release schedules

• Analyze schedule status sufficiently to depict any significant risks and priority trade-offs, especially as these risks might relate to cross-system dependencies

• Strengthen effectiveness of Government communications across programs, to VA senior executive leadership, and oversight entities

• Provide early warning signs of issues and concerns regarding critical projects, sequencing and dependencies

• Share OIT IMS components with other major initiative IMS teams such as the new Office of Electronic Health Record Modernization that may have an impact on OIT project milestones and completion dates

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. Carnegie Mellon Software Engineering Institute, Capability Maturity Model®

Integration for Development (CMMI-DEV), Version 1.3 November 2010; and

Carnegie Mellon Software Engineering Institute, Capability Maturity Model®

Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010

2. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility

Standards,” July 1, 2003

3. Office of Management and Budget (OMB) Circular A-130, “Managing Federal

Information as a Strategic Resource,” July 28, 2016

4. OI&T ProPath Process Methodology (Transitioning to Process Asset Library (PAL)

(reference process maps at http://www.va.gov/PROPATH/Maps.asp and templates at http://www.va.gov/PROPATH/Templates.asp

5. One-VA Technical Reference Model (TRM) (reference at http://www.va.gov/trm/TRMHomePage.aspx)

6. “Veteran Focused Integration Process (VIP) Guide 1.0”, December 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

7. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

8. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412 http://www.va.gov/PROPATH/Maps.asp http://www.va.gov/PROPATH/Templates.asp http://www.va.gov/trm/TRMHomePage.aspx https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

3.0 SCOPE OF WORK

The Contractor shall provide technical, management, analysis, and support services to OIT OTI, to develop and maintain a consolidated n IMS for all ongoing and planned OIT specified programs. The Contractor shall also provide, configure and maintain a consolidatedn IMS reporting/dashboard system.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The Period of Performance (PoP) shall be one, 12-month base period with two, 12-month option periods, which may be exercised at the Government’s discretion. Optional Task 1, Transition

Support may be exercised once for a PoP of 30 days from option exercise.

Business hours are 8:00AM – 5:00PM (EST). Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO). There are 10 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's Day January 1

Independence Day July 4

Veterans Day November 11

Christmas Day December 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's Birthday Third Monday in January

Washington's Birthday Third Monday in February

Memorial Day Last Monday in May

Labor Day First Monday in September

Columbus Day Second Monday in October

Thanksgiving Fourth Thursday in November

4.2 PLACE OF PERFORMANCE

Tasks under this PWS shall be performed at Contractor facilities. Contractors may be required to work in VACO (810/811 Vermont Ave, Washington, D.C 2001) on an as-needed basis and will be provided hoteling space as required.

4.3 TRAVEL

No travel is anticipated for this effort; however, in performance of PWS Task 5.2 and 5.4 the

Contractor shall be capable of meeting onsite with VA personnel within 8-hours of request.

5.0 SPECIFIC TASKS AND DELIVERABLES

The Contractor shall perform the following:

5.1 PROJECT MANAGEMENT

5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN

The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the

Contractor’s approach and timeline in execution of the contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA PM approved

CPMP throughout the PoP.

Deliverable:

A. Contractor Project Management Plan

5.1.2 REPORTING REQUIREMENTS

The Contractor shall provide the COR with Monthly Progress Reports in electronic form in

Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Month.

The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all deliverables and their current status. The Contractor shall monitor performance against the

CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.

A. Monthly Progress Report

5.1.3 PRIVACY TRAINING

The Contractor shall submit TMS training certificates of completion for VA Privacy and

Information Security Awareness and Rules of Behavior and Health Insurance Portability and

Accountability Act (HIPAA) training, and provide signed copies of the Contractor Rules of

Behavior in accordance with Section 9, Training, from Appendix C of the VA Handbook 6500.6, “Contract Security”.

Deliverables:

A. VA Privacy and Information Security Awareness and Rules of Behavior Training

Certificate

B. Signed Contractor Rules of Behavior

C. VA HIPAA certificate of completion

5.1.4 TECHNICAL KICK-OFF MEETING

The Contractor shall conduct a technical kickoff meeting within 10 days after contract award.

The Contractor shall present, for review and approval by the Government, the details of the intended approach to execute this contract. The Contractor shall discuss their project management processes for Schedule Management. The Contractor shall specify dates, locations

(can be virtual), agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and a copy of the presentation. The Contractor shall invite the CO, Contract Specialist

(CS), COR, and the VA PM.

5.2 INTEGRATED MASTER SCHEDULE ANALYSIS

The Contractor shall perform overall general IMS analysis of standard VA IMS monitoring parameters to include but not limited to cost, schedule, performance, risk, and VA critical path parameters identify issues and items on the critical path and overall IMS that are at risk or have trigger dates, 30-60-90 days out. This analysis is anticipated to be required for approximately 25 projects in the base period.

Based on the analysis the Contractor shall develop an IMS strategy to conduct progress assessments, identification of problems, and a discussion of critical path activities and urgent priorities. The Contractor shall document the strategy in a Schedule Process Governance

Document detailing the mechanism to provide individual project data including milestones, dependencies, and risks to the IMS. The Contractor shall provide an initial IMS briefing of its strategy to OIT staff.

A. Schedule Process Governance Document

B. IMS Strategy Briefing

5.3 INTEGRATED MASTER SCHEDULE DASHBOARD

The Contractor shall provide, configure and maintain an IMS reporting/dashboard system with connectivity to source systems (primarily MS Project/Primavera) used by VA project and program managers. The dashboard system shall utilize approved VA software packages in accordance with VA Technical Reference Model including, but not restricted to MS SharePoint and MS Project. The dashboard shall also provide visual artifacts, pictorial views, and drill down/hyperlink capability to show schedule/milestones alignment, and dependencies for individual project activities within the portfolio and against other existing IMS.

The schedule system shall include capabilities such as resource loading and identification of project/work request/sprint/release dependencies to facilitate accuracy in reprioritization scenarios.

The system shall enable alternate categorization views that group projects/work requests/sprints/releases by:

• strategic portfolio

• department

• resources

• OIT IT portfolio structure

• OIT service structure

• OIT financial reporting structure (such as Technology Business Management)

• other structures, operational and IT management frameworks, functions, processes, and lifecycles

The Contractor shall provide dashboard maintenance by coordinating with other major initiative

IMS teams and/or Government teams for dashboard inputs to include adding projects to the dashboard and changing details within projects, and will be responsible for adjusting/updating the dashboard with limited user interface features that provide further data points and project details to manage the overall program more effectively and efficiently.

Deliverables:

A. IMS Dashboard and Updates

5.4 INTEGRATED MASTER SCHEDULE SUPPORT

The Contractor shall develop, and maintain the IMS for those projects/work requests/sprints/releases specified by the COR. The Contractor shall create and maintain the

IMS using a scheduling system that develops the IMS by extraction of schedule data from project level scheduling systems used by program and project managers, such as MS Project.

The Contractor shall perform overall general IMS review of standard VA IMS monitoring parameters to include but not limited to cost, schedule, performance, risk, and VA critical path parameters on a weekly basis to identify issues and items on the critical path and overall IMS that are at risk or have trigger dates, 30-60-90 days out.

The Contractor shall assist OIT program/project managers to identify and maintain status of dependencies across projects. The Contractor shall work closely with other major initiative IMS teams and/or other VA organizations who have OIT project dependencies related to the overall success of VA initiatives.

The Contractor shall provide continuous IMS briefings to OIT staff, including progress assessments, identification of problems, and a discussion of critical path activities and urgent priorities.

The Contractor shall update, manage, and analyze proposed schedule changes providing OIT leadership with an assessment of impacts to the IMS. The Contractor shall meet regularly with

OIT program/project managers to provide guidance and feedback on products necessary to maintain the OIT IMS including secure web access to the IMS for authorized users. The

Contractor shall advise the Government of suspense dates that need to be met by the Government and/or Government Contractors to ensure on-time execution such as, but not limited to, delivery dates for items purchased by the Government, and information that the Contractor needs from the Government to complete the requirements of this PWS. The Contractor is responsible for tracking these dates and keeping the parties informed.

5.5 TRANSITION OUT PLANNING

The Contractor shall provide a Transition Plan for 30 days of outgoing transition support for transitioning work from the current contract to a follow-on contract/order or Government entity.

This transition may be to a Government entity or to another Contractor or to the incumbent

Contractor under a new contract/order.

This Transition Plan shall include, but is not limited to:

1. Coordination with Government representatives.

2. Review, evaluation, and transition of current support services.

3. Transition of historic data in VA repository accounts.

4. Transition of system accounts.

5. Transfer of hardware and software warranties, maintenance agreements, and licenses.

6. Transfer of all necessary business and/or technical documentation.

7. Orientation phase and program to introduce Government and Contractor personnel, programs, and users to the Contractor's team, tools, methodologies, and business processes.

8. Disposition of Contractor purchased Government owned assets.

9. Transfer of Government Furnished Equipment (GFE) and Government Furnished

Information, and GFE inventory management assistance.

10. Turn-in of all Government keys, ID/access cards, and security codes.

The Contractor shall also produce a list of all assets associated with the project. This includes all software assets, specification of support environments, tools; hardware and software licenses, warranties, and maintenance agreements; documentation, and any other assets that must be maintained throughout the asset lifecycle.

A. Transition Plan

B. Asset List

5.6 OPTION PERIOD ONE

If Option Period One is exercised by VA, PWS Tasks 5.1 through 5.5 shall apply. Work is anticipated to increase of up to 35 projects for this option period. It is anticipated that on average two additional views may be needed for the IMS Dashboard.

5.7 OPTION PERIOD TWO

If Option Period Two is exercised by VA, PWS Tasks 5.1 through 5.5 shall apply. Work is anticipated to increase of up to 50 projects for this option period. It is anticipated that on average two additional views may be needed for the IMS Dashboard.

5.8 OPTIONAL TASK – TRANSITION SERVICES

The Contractor shall execute the transition of essential knowledge and work products to and from other contractors as directed by VA to ensure the continuity of operations, its related components, and work flows.

In accordance with the Government-approved Transition plan, the Contractor shall assist the

Government in implementing a complete transition from this contract to a new support provider or the Government. This shall include formal coordination with Government staff and successor staff and management. It shall also include delivery of copies of all artifacts delivered under this contract, as well as existing policies and procedures, and delivery of baseline metrics and statistics.

Successful transition is defined as 100 percent completion of all work defined in the

Government-approved Transition Plan.

Upon the completion of the transition period, the Contractor shall provide closeout certifications that include a statement that the contract is complete, all deliverables have been provided, all services are complete, and there are no outstanding contractual issues.

A. Closeout Certifications

6.0 GENERAL REQUIREMENTS

6.1 ENTERPRISE AND IT FRAMEWORK

6.1.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (VA TRM).

The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the

Standards Profile and Product List, serves as a technology roadmap and tool for supporting

OI&T. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT

(FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture

(ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and

VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all

Contractor delivered applications and systems comply with the VA Identity, Credential, and

Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation

Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology

(NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System

Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of

Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal

Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-

11-11 can be found at:

https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-

04.pdf, https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp http://www.techstrategies.oit.va.gov/enterprise_dp.asp https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m0

5-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved

Product List (APL). If the Contractor delivered application and system is not on the APL, the

Contractor shall be responsible for taking the application and system through the FIPS 201

Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number

[ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator

Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA

Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required

SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems. https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m

05-22.pdf) and September 28, 2010

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication

(SP) 500-267 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf), the Technical Infrastructure for USGv6 Adoption (https://www.nist.gov/programs-projects/usgv6-program), and the NIST SP 800 series applicable compliance

(https://csrc.nist.gov/publications/sp) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf https://www.nist.gov/programs-projects/usgv6-program https://www.nist.gov/programs-projects/usgv6-program https://csrc.nist.gov/publications/sp

IPv4) connectivity without additional memory or other resources being provided by the

Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at:

https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

6.1.4 TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and

Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC)

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m

08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC)

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m

08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference

Architecture Document, Version 2.0 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf.

6.1.5 STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7

(64bit), Internet Explorer 11 and Office 365 ProPlus. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Windows 10. However, Windows 10 is not the VA standard yet and is currently approved for limited use during its rollout. We are in-process of this rollout and making Windows 10 the standard for OI&T. Upon the release approval of Windows 10 as the VA standard, Windows 10 will supersede Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using

System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or

Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and

Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP)

The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP).

VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 authoritative process that IT projects must follow to ensure development and delivery of IT products

6.1.7 PROCESS ASSETT LIBRARY (PAL)

The Contractor shall perform their duties consistent with the processes defined in the OIT

Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section

6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf.

The main PAL can be accessed at www.va.gov/process.

6.1.8 AUTHORITATIVE DATA SOURCES

The VA Enterprise Architecture Repository (VEAR) is one component within the overall

Enterprise Architecture (EA) that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications.

The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The

Contractor shall ensure that all delivered applications and system solutions support:

1. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.

3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.

4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.

5. Interfacing with Vet360 to access personal contact information, if the solution relies on

VA Veteran personal contact information data. Vet360 is the authoritative source for VA

Veteran Personal Contact Data.

6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for Qualifying

Active Duty military service in the VA.

6.2 SECURITY AND PRIVACY REQUIREMENTS

https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf http://www.va.gov/process

6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S)

In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:

Position Sensitivity and Background Investigation Requirements by Task

Task Number Tier1 / Low Risk Tier 2 / Moderate

Risk

Tier 4 / High Risk

5.1

5.2

5.3

5.4

5.5

5.6

5.7

5.8

The Tasks identified above and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

6.2.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Contractor Responsibilities:

a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak and understand the English language.

b. Within three business days after award, the Contractor shall provide a roster of

Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff

Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2

Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff

Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The

Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff

Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

c. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

d. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form

e. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic

Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).

f. The Contractor employee shall certify and release the e-QIP document, print and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the

COR within 3 business days that documents were signed via e-QIP).

g. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by

Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.

h. A Contractor may be granted unescorted access to VA facilities and/or access to VA

Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA

Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM.

However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for

Contractor personnel working under this contract must be maintained in the database of OPM.

i. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.

j. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by

Contractor and Subcontractor employees and/or termination of the contract for default.

k. Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with VA.

A. Contractor Staff Roster

6.3 METHOD AND DISTRIBUTION OF DELIVERABLES

The Contractor shall deliver documentation in electronic format, unless otherwise directed in

Section B of the solicitation/contract. Acceptable electronic media include: MS Word

2000/2003/2007/2010, MS Excel 2000/2003/2007/2010, MS PowerPoint 2000/2003/2007/2010, MS Project 2000/2003/2007/2010, MS Access 2000/2003/2007/2010, MS Visio

2000/2002/2003/2007/2010, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data

Format (PDF).

6.4 PERFORMANCE METRICS

The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.

Performance Objective Performance Standard Acceptable Levels of

Performance

A. Technical /

Quality of

Product or

Service

1. Demonstrates understanding of requirements

2. Efficient and effective in meeting requirements

3. Meets technical needs and mission requirements

4. Provides quality services/products

5. Satisfaction of executive leadership with dashboard

Satisfactory or higher

85% executives satisfied or very satisfied

B. Project

Milestones and

Schedule

1. Established milestones and project dates are met

2. Products completed, reviewed, delivered in accordance with the established schedule

3. Notifies customer in advance of potential problems

Satisfactory or higher

C. Cost & Staffing 1. Currency of expertise and staffing levels appropriate

2. Personnel possess necessary knowledge, skills and abilities to perform tasks

Satisfactory or higher

D. Management 1. Integration and coordination of all activities to execute effort

Satisfactory or higher

The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the surveillance methods in the QASP at its own discretion. A Performance Based Service

Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.

6.5 FACILITY/RESOURCE PROVISIONS

The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.

The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact.

The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The

Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.

VA may provide remote access to VA specific systems/network in accordance with VA

Handbook 6500, which requires the use of a VA approved method to connect external equipment/systems to VA’s network. Citrix Access Gateway (CAG) is the current and only VA approved method for remote access users when using or manipulating VA information for official VA Business. VA permits CAG remote access through approved Personally Owned

Equipment (POE) and Other Equipment (OE) provided the equipment meets all applicable 6500

Handbook requirements for POE/OE. All of the security controls required for Government furnished equipment (GFE) must be utilized in approved POE or OE. The Contractor shall provide proof to the COR for review and approval that their POE or OE meets the VA Handbook

6500 requirements and VA Handbook 6500.6 Appendix C, herein incorporated as Addendum B, before use. CAG authorized users shall not be permitted to copy, print or save any VA information accessed via CAG at any time. VA prohibits remote access to VA’s network from non-North Atlantic Treaty Organization (NATO) countries. The exception to this are countries where VA has approved operations established (e.g. Philippines and South Korea). Exceptions are determined by the COR in coordination with the Information Security Officer (ISO) and

Privacy Officer (PO).

This remote access may provide access to VA specific software such as Veterans Health

Information System and Technology Architecture (VistA), ClearQuest, ProPath (PAL), Primavera, and Remedy, including appropriate seat management and user licenses, depending upon the level of access granted. The Contractor shall utilize government-provided software development and test accounts, document and requirements repositories, etc. as required for the development, storage, maintenance and delivery of products within the scope of this effort. The

Contractor shall not transmit, store or otherwise maintain sensitive data or products in Contractor systems (or media) within the VA firewall IAW VA Handbook 6500.6 dated March 12, 2010.

All VA sensitive information shall be protected at all times in accordance with VA Handbook

6500, local security field office System Security Plans (SSP’s) and Authority to Operate (ATO)’s for all systems/LAN’s accessed while performing the tasks detailed in this PWS. The Contractor shall ensure all work is performed in countries deemed not to pose a significant security risk.

For detailed Security and Privacy Requirements (additional requirements of the contract consolidated into an addendum for easy reference) refer to ADDENDUM A – ADDITIONAL

VA REQUIREMENTS, CONSOLIDATED and ADDENDUM B - VA INFORMATION AND

INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE.

6.6 GOVERNMENT FURNISHED PROPERTY

The Government has determined that remote access solutions involving Citrix Access Gateway

(CAG) have proven to be an unsatisfactory access method to complete the tasks on this specific contract The Government also understands that GFE is limited to Contractors requiring direct access to the network to: access development environments; install, configure and run TRM-approved software and tools (e.g., Oracle, Fortify, Eclipse, SoapUI, WebLogic, LoadRunner, etc.); upload/download/ manipulate code, run scripts, apply patches, etc.; configure and change system settings; check logs, troubleshoot/debug, and test/QA.

Based on the Government assessment of remote access solutions and the requirements of this contract, the Government estimates that the following GFE will be required by this contract:

1. 1 standard laptop per contractor performing direct IMS labor

The Government will not provide IT accessories including but not limited to Mobile Wi-Fi hotspots/wireless access points, additional or specialized keyboards or mice, laptop bags, extra charging cables, extra PIV readers, peripheral devices, additional RAM, etc. The Contractor is responsible for providing these types of IT accessories in support of the contract as necessary and any VA installation required for these IT accessories shall be coordinated with the COR.

ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED

A1.0 Cyber and Information Security Requirements for VA IT Services

The Contractor shall ensure adequate LAN/Internet, data, information, and system security in accordance with VA standard operating procedures and standard PWS language, conditions, laws, and regulations. The Contractor’s firewall and web server shall meet or exceed VA minimum requirements for security. All VA data shall be protected behind an approved firewall.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.