36C10B19R0046-006.pdf

PDF 2 MB Posted

Attached to
T4NG On-Ramp Federal contract opportunity
Solicitation number
36C10B19R0046
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This notice provides information on the Transformation Twenty-One Total Technology Next Generation (T4NG) On-Ramp opportunity being administered by the Department of Veterans Affairs Technology Acquisition Center. The T4NG On-Ramp effort intends to add additional Service Disabled Veteran Owned Small Businesses certified through the Center for Verification and Evaluation onto the existing T4NG indefinite delivery/indefinite quantity multiple award task order contract. Awarded contracts through the On-Ramp will share in the $22.3 billion ceiling and five year base ordering period established for the T4NG program and shall include the same terms and conditions as the existing T4NG contracts. The notice directs any questions to the provided email address.

36C10B19R0046 T4NG On-ramp RFP.pdf

View the file

Other files for this federal contract opportunity

Other files attached to T4NG On-Ramp, newest first.
File Type Posted
36C10B19R0046-013.docx DOCX document
36C10B19R0046-014.pdf PDF
36C10B19R0046-008.docx DOCX document
36C10B19R0046-009.docx DOCX document
36C10B19R0046-010.pdf PDF
36C10B19R0046-005.docx DOCX document
36C10B19R0046-007.docx DOCX document
36C10B19R0046-004.docx DOCX document
36C10B19R0046-003.docx DOCX document
36C10B19R0046-000.docx DOCX document
36C10B19R0046-002.docx DOCX document
36C10B19R0046-001.pptx PPTX presentation
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C10B19R0046

CONTENTS

PART I - THE SCHEDULE

SECTION A - SOLICITATION/CONTRACT FORM

SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS

SECTION C - DESCRIPTION/SPECIFICATIONS/PERFORMANCE WORK STATEMENT

SECTION D - PACKAGING AND MARKING

SECTION E - INSPECTION AND ACCEPTANCE

SECTION F - DELIVERIES OR PERFORMANCE

SECTION G - CONTRACT ADMINISTRATION DATA

SECTION H - SPECIAL CONTRACT REQUIREMENTS

PART II - CONTRACT CLAUSES

SECTION I - CONTRACT CLAUSES

PART III - LIST O DOCUMENTS, EXH BITS AND OTH R ATTACHMENTS

SECTION J - LIST OF ATT CHME TS

PART IV - REPRE ENTATION AND INSTRUCTIONS

SECTION K - REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF

OFFERORS

SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS

SECTION M - EVALUATION FACTORS FOR AWARD

DRAFT

SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS

B.1 GOVERNING LAW

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act 31 U.S C. § 1 41 et se ), the C mpetition n Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Pa ment Ac (31 .S.C. § 3 01 et eq.) Contr cts for Data Pro essing or Maintenance (38 USC § 5725), an FAR cla ses 2.21 -4, 52.22 -14 2.227 9 shall superse e, control, and render ineffective any incon istent, c nflic ng, or uplic ive prov sion n any commerc al license agreement. In the event of conflict between this Clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this Clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ). 28 U.S.C. § 516. At the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be effected by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.2 HYBRID CONTRACT TYPE

The contract type is a hybrid containing: Firm-fixed-Price (FFP), Time-and-Materials (T&M)/Labor-hour (LH), Cost reimbursement (CR) line items.

B.3 PRICE SCHEDULE:

NOTE: FOR PROPOSAL PURPOSES ONLY, CLIN PRICING IS NOT REQUIRED IN

SECTION B OF THIS SOLICITATION.

All price proposals must be submitted in the format provided at Section J, Attachment 001. The deliverables associated with Contract Line Item Numbers (CLIN) 1004 through 1010 shall be submitted for each task order and included in the price/cost of each task order. The specific deliverables under CLINs 1004 through1010 will not be set forth under individual Task Orders.

PRICE SCHEDULE

BASE PERIOD

CLIN DESCRIPTION QUANTITY UNIT UNIT

COSTS

TOTAL

COST

1001 Firm-Fixed-Price Line Item

SECURITY CLASS: Determined at Task Order Level

Th s CLIN i to rovide Informa ion Te hnology IT) servi es and inc dental suppl s on a FP basis for a period of 60 months from date of award in accordance with (IAW) the Transformation Twenty-One Total Technology Next Generation (T4NG) Performance Work Statement (PWS) set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and Free on Board (FOB) Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

The delivery or performance schedule shall be determined on each individual Task Order.

1002 Time-and-Materials/Labor-Hour Line Item

This CLIN is to provide IT services and incidental supplies on a T&M/LH basis for a period of 60 months from date of award IAW the T4NG PWS set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

Th deliver or erforma ce sch dule sha l b d t mined on ea h individual ask Order.

1003 Cost Reimbursement Line Item

This CLIN is to provide IT services and incidental supplies on a CR basis for a period of 60 months from date of award IAW the T4NG PWS set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

The delivery or performance schedule shall be determined on each individual Task Order.

1004 Contractor’s Progress, Status, and Management Report

Monthly Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.1(A) and (B)(C)(D) and (E), and Section J Attachment 003 when applicable to Task Order contract type.

FOB Point: Destination Inspection/Acceptance: Destination

NSP NSP

1005 Contract Performance Report

Contract Performance Report shall be provided IAW Section C, PWS, Paragraph 8.1.2 (A) and (B), and Se tion J Attachments 004 (T&M an 005 (CR) w en appli able to Ta k Order ont ype. Repo t not ap licable f r FFP Task Order .

FOB Point: Destination Inspection/Acceptance: Destination

NSP NSP

1006 Government Furnished Equipment Status Report

Government Furnished Equipment Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.3 (A-K) and Section J, Attachment 006.

FOB Point: Destination Inspection/Acceptance: Destination

NSP NSP

1007 Personnel Contractor Manpower Report

Personnel Contractor Manpower Report shall be provided IAW Section C, PWS, Paragraph 8.1.4 (A-S) and Section J, Attachments 007 and 008.

1008 Contractor Staff Roster

Contractor Staff Roster shall be provided IAW Section C, PWS, Paragraph 8.1.5 and Section J, Attachment 009.

FOB Point: Destination Inspection/Acceptance: Destination

NSP NSP

1009 Small Business Participation Report

Small Business Participation Report shall be provided IAW Section H, clause H-4 Small Business Participation Requirements, and Section J, Attachment 010.

FOB Point: Des nation Inspection/A ce tance Destin ion

NSP NSP

1010 Ve erans Empl yment Certification Report

Veterans Employment Certification Report IAW Section H, clause H-5 and Section J, Attachment 011.

Contract Maximum/Minimum Ceiling:

IAW Section I, clause 52.216-22 entitled, “Indefinite Quantity” the Maximum value of the T4NG contract is $22.3 Billion. The maximum overall value of the T4NG On-ramp award is $11.9B. IAW Section I, clause 52.216-22 entitled, “Indefinite Quantity” the Minimum guaranteed value under the T4NG On-ramp contract is $250,000. The Government intends to compete initial orders to the maximum extent possible; however, the Government reserves the right to award initial orders on a sole source basis pursuant to FAR 16.505(b)(2)(i)(D) at amounts which may exceed the minimum guaranteed value.

The ceiling price as set forth in Section I, clause 52.232-7 entitled, “Payments under Time-and- Materials and Labor-Hour contracts” will be established for each individual Time-and Materials Task Order.

SECTION C - DESCRIPTION/SPECIFICATIONS/STATEMENT OF

WORK

Performance Work Statement (PWS) for the

Transformation Twenty-One Total Technology

Next Generation (T4NG)

Program

DATE: JANUARY 25, 2019

Department of Veterans Affairs

Office of Procurement, Acquisition and Logistics Technology Acquisition Center (TAC)

Contents

1.0 SCOPE

2.0 APPLICABLE DOCUMENTS

3.0 GENERAL REQUIREMENTS

3.1 Contract Type

3.2 Ordering Period

3.3 Hours of Work

3.4 Place of Performance

3.5 Travel

3.6 Materials, Equipment and Locations

Government-Furnished Contractor-Acquired Non-Developmental Items and Commercial Processes Connectivity Facilities

3.6.5.1 Government Facilities

3.6.5.2 Non-Government Fac lities

Warranty Marking, Han ling, S orage Preser atio Packaging, T acking & Shipping 19

Contro

3.7 Safety and Environmental

3.8 Enterprise and IT Framework

VA Technical Reference Model Federal Identity, Credential, And Access Management (FICAM) Internet Protocol Version 6 (Ipv6) Trusted Internet Connection (TIC) Standard Computer Configuration Enterprise Management Framework Authoritative Data Sources

3.9 Development Methodologies

3.10 Integrated Product Teams

3.11 Quality Assurance

3.12 Transition and Orientation Support

3.13 Government Inspection and Oversight

4.0 TECHNICAL FUNCTIONAL AREAS

4.1 Program Management, Strategy, Enterprise Architecture and Planning Support .. 26 Strategy and Planning

Standards, Policy, Procedure and Process Development, and Implementation Support

Requirements Development and Analysis Support

4.1.3.1 Requirements Packages

Technology Refresh and Configuration Reviews Studies and Analyses Program Management Support Product Data IT Services Management Support Development Toolkits

4.2 Systems/Software Engineering

Design and Development Architecture Development IT Service Management Implementation Enterprise Application/Services Cloud Computing Web Application Design and Development Mobile Application Design and Development H Comp I raction ystem/S ftw re Integ ation Modeling and Sim lation nforma cs S rvices

Engineering and Technical Documentation Current System and Data Migration Development Toolkit Support

4.3 Software Technology Demonstration and Transition

4.4 Test & Evaluation (T&E)

4.5 Independent Verification and Validation (IV&V)

4.6 Enterprise Network

Systems/Network Administration Network and Telecommunications Infrastructures

4.7 Enterprise Management Framework

4.8 Operations and Maintenance (O&M)

Systems/Network Administration Application Support Hardware Support Security Management Disaster Recovery (DR) and Continuity of Operations (COOP) Capacity/Availability Planning and Management Service/Help Desk/Call Center Support

Asset Management License Maintenance Database and Data Warehouse Administration Data Center Administration

4.9 Cyber Security

Information Assurance (IA) Logical Security Assessment and Authorization Security Operating Support

4.10 Training

4.11 Information Technology Facilities

Incidental Facility Design and Modification Services Site Surveys Facility Connectivity Installation Physical Security Systems

5.0 DELIVERABLES

5.1 Products

5.2 Data

6.0 SECURIT AND PRIVACY

6.1 Infor ti Securi y and Pr va y Security Requirements

6.2 Personnel Security Requirements

6.3 Facility/Resource Provisions

6.4 Badges

6.5 Classified Work

6.6 Incident Reporting and Management

6.7 Security and Privacy Awareness Training

6.8 Security Role BaseD Training

7.0 CONTRACT MANAGEMENT

7.1 Government Support

Task Order COR

7.2 Contractor Program Management

Work Control

7.3 Pre-Award Procedures

Request for Task Execution Plan (RTEP) Process

7.3.1.1 Yes/No Bids

Task Execution Plan (TEP) TEP Evaluation

7.4 Issuance of Task Orders

7.5 Logical Follow-Ons

8.0 REPORTING AND MEETING REQUIREMENTS

8.1 Reporting Requirements

Contractor’s Progress, Status and Management Report Contract Performance Report (CPR) Status of Government Furnished Equipment (GFE) Report Personnel Contractor Manpower Report Contractor Staff Roster Small Business Participation Report Veterans Employment Certification Report

8.2 Meetings and Reviews

Project Office Initial Program Review (IPR) Post-Award Conferences Program Reviews Quarterly Collective Prime Program Reviews

ADDENDUM A– ADDITIONAL VA REQUIREMENTS, CONSOLIDATED .............. Error!

Bookmark not defin d.

ADDENDUM B- A INFORMATION AND NFORMATION SYSTEM SECURITY /

PRIVACY LANGUAGE

1.0 SCOPE

This PWS establishes the requirements for Contractor-provided solutions in support of IT. Contractor-provided solutions may support the Department of Veterans Affairs (VA) and other Federal Agencies.

The Contractor shall provide total IT services solutions including the following functional areas: program management, strategy, enterprise architecture and planning; systems/software engineering; software technology demonstration and transition; test and evaluation; independent verification and validation;

enterprise network; enterprise management framework; operations and maintenance; cybersecurity;

training; IT facilities; and other solutions encompassing the entire range of IT and Health IT requirements, to include software and hardware incidental to the solution. Accordingly, Task Orders may include acquisitions of software and IT products. T4NG is not intended as a mechanism to solely purchase IT products. Such products may be purchased to the extent that those products are necessary to deliver the solution required. These services, as well as related IT products, may encompass the entire life-cycle of a system. Moreover, services and related products covered under this contract shall be global in reach and the Contractors must be prepared to provide services and deliverables worldwide.

This PWS provides general requirements. Specific requirements shall be defined in individual Task Orders. Functional area requirements are described in Section 4.0 and are not mutually exclusive for Task Order requirements. Requirements may fall within one specific functional area but in many cases, the requirements will encompass and apply across and within multiple functional areas to provide the total life cycle solution.

2.0 APPLICABLE DOCUMENTS

The Contractor shall omply w th t e docum nts list d be ow. Additional docum nts may be listed in individual Task Ord rs.

1. 44 U.S.C. § 3541 3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For

Cryptographic Modules”

4. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information

Systems, February 2004

5. FIPS Pub 200, Minimum Security Requirements for Federal Information and Information

Systems, March 2016

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August

7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

8. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, title IX Information Security Matters

9. 10 U.S.C. § 2224, "Defense Information Assurance Program"

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, (http://www1.va.gov/vapubs/)

12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016

(http://www1.va.gov/vapubs/)

13. VA Directive 6102 (Internet/Intranet Services), July 15, 2008 (http://www1.va.gov/vapubs/)

14. VA Handbook 6102 (Internet/Intranet Services), July 15, 2008 (http://www1.va.gov/vapubs/)

15. Health Insurance Portability and Accountability Act (HIPAA); 45 CFR Part 160, 162, and 164;

Health Insurance Reform: Security Standards; Final Rule dated February 20, 2003

16. VHA Handbook 1605.05, Business Associate Agreements, July 22, 2014(http://www.va.gov/vhapublications/)

17. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1,

18. Office of Management and Budget Circular A-130, “Managing Federal Information as a Strategic

Resource”, July 28, 2016

19. U.S.C. Section 552a, as amended

20. Title 32 CFR 199, “Civilian Health and Medical Program of the Uniformed Services

(CHAMPUS)”

21. An Introductory Resource Guide for Implementing the Health Insurance Portability and

Accountability Act (HIPAA) Security Rule, October 2008

22. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. Section § 794d), as amended, January

18, 2017

23. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

24. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,”

September 20, 2012 (http://www1.va.gov/vapubs/)

25. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA

Information ecurity Progr m, Ma h 10, 20 5 (http://www1.va.gov/va ubs/)

26. VA Handbo k 6500.1 “El tronic Media S nitiz tion,” November 3, 20 8

(http://www va.gov/v pub /)

27. VA Handbo k 6500 2 “M nagemen of B eaches I vol ng Sensitive Pe sonal Information

(SPI)”, July 28, 2016 (http://www1.va.gov/vapubs/)

28. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA

Information Systems,” February 3, 2014

29. VA Handbook, 6500.5, Incorporating Security and Privacy in System Development Lifecycle,”

March 22, 2010 (http://www1.va.gov/vapubs/)

30. VA Handbook 6500.6, “Contract Security,” March 12, 2010 (http://www1.va.gov/vapubs/)

31. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011

(http://www1.va.gov/vapubs/)

32. Office of Information and Technology (OI&T) Process Asset Library (PAL) https://www.va.gov/process/. Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

33. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015 (http://csrc.nist.gov/publications/PubsSPs.html)

34. Federal Travel Regulation (FTR) (www.gsa.gov/federaltravelregulation)

35. One-VA Technical Reference Model (TRM) (https://www.va.gov/trm/TRMHomePage.aspx)

36. Federal Segment Architecture Methodology (FSAM) v1.0, December 2008

37. VA Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact

Assessment, October 15, 2014 (http://www1.va.gov/vapubs/)

38. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

39. VA Handbook 6510, “VA Identity and Access Management”, January 15, 2016

40. VA Directive 6300, Records and Information Management, February 26, 2009

(http://www1.va.gov/vapubs/)

41. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

(http://www1.va.gov/vapubs/)

42. NIST SP 800-37 Rev 1, Guide for Applying the Risk Management Framework to Federal

Information Systems: a Security Life Cycle Approach, June 5, 2014

43. OMB Memorandum, “Transition to IPv6”, September 28, 2010

44. OMB Memorandum “Security Authorization of Information Systems in Cloud Computing

Environments” December 8, 2011 (FedRAMP Policy Memorandum)

45. VA Directive 6609, “Mailing of Sensitive Personal Information”, May 20, 2011

(http://www1.va.gov/vapubs/)

46. VA Enterprise Technology Strategic Plan, February 28, 2014

47. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, October

26, 2015 (http://www1.va.gov/vapubs/)

48. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March

24, 2014 (http://www1.va.gov/vapubs/)

49. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of

HSPD-12, J ne 30, 2006

50. OMB Memo andum 0 -04 E-Authe ticatio Gu dance or Federal Agen ies, December 16, 2003

51. OMB Memo andum 0 24 mplementatio of Homelan Security Presid ntial Directive (HSPD)

12 – Policy or a Common dentific ion Standard f r Fe eral Employee and Contractors, August 5, 2005

52. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011

53. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008

54. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011

55. NIST SP 800-116 Rev 1, Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access, June 2018

56. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

57. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017

58. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014

59. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October

60. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014

61. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

62. IAM Identity Management Business Requirements Guidance document, May 2013, (https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

63. VA Memorandum “Mandate to meet PIV Requirements for New and Existing Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

64. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.2, Federal Interagency Technical Reference Architectures, Department of Homeland Security, June 19, 2017, https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf

65. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007

66. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008

67. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)

68. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110– 140), Decem er 19, 2007

69. Section 104 f the Ene gy olicy Ac of 2005, (P blic L w 109–58), Au ust 8, 2005

70. Executive O der 1383 “E ficien Federal p ns”, ated May 17, 2 18

71. Executive O der 132 1, “E ergy-Eff cien Standby Pow r Devices,” Au ust 2, 2001

72. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013

(http://www1.va.gov/vapubs/)

73. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013

(http://www1.va.gov/vapubs/)

74. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January

15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

75. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

76. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

77. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ#7613595), June30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

78. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ#7613597), June30, 2015;

https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

79. “Veteran Focused Integration Process (VIP) Guide 3.1”, April 2018, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

80. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

81. “POLARIS User Guide”, Version 1.9, March 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

82. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

3.0 GENERAL REQUIREMENTS

The Contractor shall provide and/or acquire the services, hardware, and software required by individual Task Orders pursuant to the general requirements specified below.

3.1 Contract Type

This is an Indefinite Delivery/Indefinite Quantity (IDIQ) Multiple Award Task Order (MATO) contract.

Individual Task Orders shall be issued on a performance-based T&M, CR, and/or FFP basis.

3.2 Ordering Period

The ordering period or the bas c T NG On-Ramp c ntra t shall e five (5) years

3.3 Hours of Work

Work at a Government site shall not take place on Federal holidays or weekends unless directed by the CO. The Contractor may also be required to support 24/7 operations 365 days per year as identified in individual Task Orders.

There are ten (10) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's Day January 1 Independence Day July 4 Veterans Day November 11 Christmas Day December 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September

Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November

3.4 Place of Performance

The place of performance shall be identified in individual Task Orders. Locations will be Government or non-Government sites within the continental United States (CONUS) and/or outside the continental United States (OCONUS). Locations may include but are not limited to Federal, State, VA, or military data centers, facilities, regional offices, benefits delivery centers, medical treatment facilities, health clinics and Tricare facilities as defined in individual Task Orders.

3.5 Travel

Travel shall be IAW individual Task Order requirements. Travel details must be provided to and approved by the CO’s Representative (COR) or the Government designee prior to the commencement of travel. All travel shall be IAW the Federal Travel Regulations (FTR). OCONUS travel may require additional authorization and approvals as specified in the individual Task Order.

3.6 Materials, Equipment and Locations

Gov rnment Fur ished Government Furnish d Proper y (G P) whic includ s G vernm nt Furnished M terial (GFM), Government Furnish d Inform ion GFI) and Gov rnme t Fur shed Equipmen (GFE) may be provided and shall b identifie in t e indiv dual Task Orde T Contractor sha l be responsible for conducting all neces minati ns, inspe io , mainten nce and tests upon eceipt. The Contractor shall be responsible for reporting all inspection results, maintenance actions, losses, and damage to the Government through the VA Technology Acquisition Center (TAC) website.

VA may provide VA specific software as appropriate and required in individual Task Orders. The Contractor may utilize VA provided software development and test accounts, document and requirements repositories and others as required for the development, storage, maintenance and delivery of products.

Contractors shall comply with VA security policies and procedures with respect to protecting sensitive data. See Section 6.0 for detailed security requirements.

Contractor-Acquired The Contractor shall acquire and/or provide any hardware and/or software required to accomplish each Task Order that is not provided as GFP. Software integrity shall be maintained by the Contractor within the licensing agreement of the producer until such software is delivered to the Government, or otherwise disposed of IAW Government direction. Items delivered to the Government shall be approved by the Government in advance of purchase and shall be in compliance with PWS paragraphs 3.8 and A3.0. See Section 6.0 for detailed security requirements.

Non-Developmental Items and Commercial Processes Non-Developmental Items (NDI), Commercial-Off-The-Shelf (COTS) and Government-Off-The-Shelf (GOTS) products shall be used to the maximum extent. The Contractor shall apply commercially available and industry best processes, standards and technologies to the maximum extent.

Connectivity VA will provide connectivity to VA specific systems/network as required for execution of the task via VA approved remote access technology. Currently this may include but is not limited to Citrix Access Gateway (CAG), site-to-site VPN, or VA Remote Access Security Compliance Update Environment (RESCUE). This remote access will provide connectivity to VA specific software such as Veterans Health Information System and Technology Architecture (VistA), ClearQuest, PAL, Primavera, and Remedy, including appropriate seat management and user licenses. VA may install equipment at the Contractor’s site to ensure security requirements are in place. The Contractor must meet the requirements of VA Handbook 6500 and will bear the cost to provide connectivity to VA. Other connectivity to VA systems may be authorized as appropriate in individual Task Orders.

Facilities Work may be performed at either a Government or non-Government facility. Each Task Order shall delineate the location requirements.

3.6.5.1 Government Facilities

Certain Government office or laboratory space may be made available for performance of individual Task Orders. Contractors may be required to establish operations and support Government locations and shall comply with VA and/or Federal assessment and authorization (A&A) requirements Such facilities shall be specified in the in ividual Task rder.

3.6.5.2 Non-Gov rnment Fac ities

Personnel may perfo ontract r or remo f cilities if speci ed in the indivi ual task order.

Contractors may be required to establish operations and support Contractor facilities and shall comply with VA and/or Federal A&A requirements. Such facilities shall be specified in the individual Task Order. The Contractor shall disclose specific facility information during the Request for Task Execution Plan (RTEP) process. All facilities shall be approved by VA and in compliance with PWS paragraph 6.0, Security and Privacy.

Warranty Items acquired under this contract may require warranty protection. Commercial warranties shall be transferred to the Government. The type of warranty and extent of coverage shall be determined on an individual Task Order basis.

Marking, Handling, Storage, Preservation, Packaging, Tracking & Shipping The Contractor shall establish/maintain procedures IAW VA Handbook 6500 and VA Directive 6609 for handling, storage, preservation, packaging, marking, tracking and shipping to protect the quality of products and prevent damage, loss, deterioration, degradation or substitution of products.

Export Control The Contractor shall comply with all applicable laws and regulations regarding export-controlled information and technology and shall not use, distribute, transfer or transmit technology (even if incorporated into products, software or other information) except in compliance with such laws and regulations. In addition, the Contractor shall plan for, obtain, and maintain any and all export licensing required to satisfy individual Task Order requirements.

3.7 Safety and Environmental

Safety and environmental procedures shall be identified in individual Task Order requirements.

The Contractor shall comply with the Office of Federal Sustainability Acquisition and Electronics Stewardship initiatives as identified in individual Task Orders IAW the policies referenced at https://www.sustainability.gov/resources-eo-efo.html

3.8 Enterprise and IT Framework

VA Technical Reference Model

For VA specific task orders, the Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (VA TRM) and consider the VA Enterprise Technology Strategic Plan. The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the IT used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OI&T.

Fede al Ident ty, C d ntial, And Ac ess M g ment (FICAM)

The Contractor shall nsur omm cial Off The Shelf (COTS) roduct(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls,” and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard

(FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-11-11 can be found at:

https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation f r each Federa on Ass ance Leve (FAL) a propriate for th solution, if applicable.

7. Two-factor uthenticat on ( FA) th ough an appli able d i attern as utlined in VA Enterprise D sign Pat rns

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers is the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems. https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

Internet Protocol Version 6 (Ipv6) The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05- 22.pdf) and September 28, 2010

(https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov docs/transition-to-ipv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500- 267 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf), the Technical Infrastructure for USGv6 Adoption (https://www.nist.gov/programs-projects/usgv6-program), and the NIST SP 800 series applicable compliance (https://csrc.nist.gov/publications/sp) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at:

https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

Trusted Internet Connection (TIC) The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse archives gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08- 05.pdf), M08-23 ma dating D mai Name S stem Secu ity (NS EC) (https://obamawhite ouse.arch ves ov/sites default iles mb/as ets/omb/memo nda/fy2008/m08- 23.pdf), and shall comply with he rusted Internet ions TIC) Reference Architecture Document, Version 2.0 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf.

Standard Computer Configuration The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Office 365 ProPlus. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Windows 10. However, Windows 10 is not the VA standard yet and is currently approved for limited use during its rollout. We are in-process of this rollout and making Windows 10 the standard for OI&T. Upon the release approval of Windows 10 as the VA standard, Windows 10 will supersede Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

Enterprise Management Framework The Enterprise Management Framework (EMF) provides an enterprise-wide view of VA IT systems comprised of tools, reports, databases, dashboards, and analytics. EMF enables OI&T to view the health and performance of systems and provides intelligent analysis and trending that enables proactive enterprise system management. Performance, availability, user experience and reliability of IT service delivery is improved as OI&T is able to make strategic, operational and investment decisions based on real-time information.

EMF supports a unified enterprise service management model including release management, configuration management, change management, and incident management aligned with industry standard IT Infrastructure Library (ITIL) service management best practices. The EMF Federated Data Repository (FDR) includes the implementation of a foundational component. The EMF FDR is a national repository that collects enterprise IT management data from VA Managed Data Repositories (MDRs) and integrates with existing VA monitoring and performance systems.

Additional frameworks may be specified in individual task orders.

Authoritative Data Sources The VA Enterprise Architecture Repository (VEAR) is one component within the overall Enterprise Architecture (EA) that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughou the ent prise hall acc s VA d t solely t rough official A ADSs where applicable, see below The Inf rma ion Clas es whi h compose ach ADS are lo ated in the VEAR, in the Data & Informat on domai T e Contractor sh ll re th all delivered a plications and system solutions support:

1. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.

3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.

4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.

5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.

6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for Qualifying Active Duty military service in the VA.

3.9 Development Methodologies

The Contractor may support a Service-Oriented Architecture (SOA) that is a flexible set of design principles used during the phases of systems development and integration which will be specified at the task order level. The deployed SOA-based architecture will be deployed on a secure, scalable, interoperable and dynamic platform that has the end to end visibility and manageability from application services to the networking components level and that can be used within multiple domains.

For VA specific task orders, the Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products

For VA specific task orders, t e Co tractor s all perf rm their d ties consistent w th the processes defined in the OIT P ocess Ass t L rary (P L). Th PAL scop includes the fu spectrum of OIT functions and activit s, such a VI project manag ment pera ons, service del very, communications, acquisition, and res urce managem nt. PAL serv as an a thor ative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. For VA specific Task Orders, the Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section 6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process CONB ext.pdf. The main PAL can be accessed at www.va.gov/process.

The Contractor shall use an incremental development methodology such as Agile unless otherwise specified at the task order level.

3.10 Integrated Product Teams

The Contractor may be required to serve as a member of, or provide Subject Matter Expertise to Integrated Product Teams (IPTs) or Integrated Business Teams (IBTs) within VA. Their role(s) will be identified in individual Task Orders. IPTs and IBTs are cross-functional teams that work collaboratively to develop strategies and approaches to meet particular objectives. IPTs and IBTs bring together the principal stakeholders and focus efforts on establishing critical elements of all phases of the acquisition lifecycle.

3.11 Quality Assurance

If a Contractor is required to develop a significant portion of any mission critical systems/software product under this contract, the Contractor may be required to demonstrate they, or the Subcontractor performing the task, are operating at a specified Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration (CMMI) for Development (CMMI-DEV) level; CMMI for Acquisition (CMMI-ACQ) level; CMMI for Services (CMMI-SVC) level; and/or International Organization for Standardization and International Electrotechnical Commission (ISO/IEC) 20000, Institute of Electrical and Electronics Engineers (IEEE) 1012, or ISO 9001:2008, ITIL 2011).

If required at the Task Order level, the rating of CMMI Level III or below shall be stated as well as the date of the rating, the identification of the rating organization, the projects/divisions that were evaluated as part of the evaluation and the rating achieved by the specific business unit the Contractor is proposing on systems/software efforts. The Government reserves the right to validate the systems/software developers' process assertions and representations by conducting an evaluation by VA or a third party or appraisals of the Contractor's organization and Subcontractors using commonly accepted Industry/Government validation practices.

3.12 Transition and Orientation Support

The Contractor shall perform transition and orientation services (e.g. develop Phase-In/Phase-Out Transition Plan) to insure continuity of services as specified in the individual Task Order. Transition and orientation support may include transitioning support services to Government or Contractor personnel.

3.13 Government Inspection and Oversight

The Contractor shall p te with h i ed Gover ment offi i h a f f ilities access, audits, security incid nt notific tion and hos ng loca ion Specifically, the Con ractor (an an Subc ntractor shal :

a. Provide the O, desig ated repres ntative O, an representatives of authorized Governmen offices ull an free physica and remo e/lo ical access to t e Contractor's (and Subcontractors') facilities, installations, operations documentation, databases, and personnel used for contract hosting services. This access shall be provided to the extent required to carry out audits, inspections, device scanning utilizing Government prescribed tools, investigations, or other reviews to ensure compliance with contractual requirements for IT and information security, and to safeguard against threats and hazards to the integrity, availability, and confidentiality of agency information in the possession or…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .