Continuation Page.docx
DOCX document 89 KB Posted
- Attached to
- 7A21--PI Planning Federal contract opportunity
- Solicitation number
- 36C10B24Q0418
About this file
This document is a Continuation Page that revises the license count and Section B.3 Price Schedule for a federal contract opportunity related to the purchase of Scaled Agile, Inc.'s piplanning.io or equivalent Planning Interval (PI) planning application and associated support services.
The contract requires the purchase of 100 licenses for the piplanning.io or equivalent application, as well as installation, configuration, technical support, and documentation services. The base period and option period pricing are provided in the revised Section B.3 Price Schedule. The requirement includes security assessment and accreditation, transition support, and additional licensing as optional tasks. The Performance Work Statement describes the background, objectives, and specific tasks for the application support services. Key deliverables include Project Management Plan, Product Status Reports, technical documentation, and security authorization artifacts. The solicitation is a small business set-aside with a response due date of July 2, 2024.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Continuation Page 2.docx | DOCX document | |
| 36C10B24Q0418_4.docx | DOCX document | |
| 36C10B24Q0418_3.docx | DOCX document | |
| 36C10B24Q0418_1.docx | DOCX document | |
| FINAL RFQ 36C10B24Q0418.docx | DOCX document | |
| Redacted JA.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CONTINUATION PAGE
1. The purpose of this Amendment is to revise the license count in the base and all option years to 100, as well as revise Section B.3 Price Schedule to correct the Optional Tasks in Section B.3 Price Schedule.
2. Please find the below Section B.3 Price Schedule and Section B.4 Performance Work Statement changes are highlighted in yellow.
B.3 PRICE SCHEDULE
Base Period Period of Performance shall be for 12 months from TBD
CLIN
Description Quantity
Unit
Unit Price
Total Price
| 0001 |
| Project Management- Contractor Project Management Plan, Reporting Requirements, Technical Kickoff Meeting, and Change Enablement, Release, Management |
In accordance with (IAW) 5.1, 5.1.1, 5.1.2, 5.1.3, 5.1.4 of Performance Work Statement)
| 12 |
| MO |
| NSP |
| NSP |
| 0001AA |
| Contractor Project Management Plan IAW PWS Section 5.1.1 |
Due 30 days after contract and updated monthly thereafter.
| 12 |
| MO |
| NSP |
| NSP |
| 0001AB |
| Product Status Report IAW PWS Section 5.1.2 |
Due via dashboard, accessible real-time
| 12 |
| MO |
| NSP |
| NSP |
| 0001AC |
| Change Enablement, Release, Management IAW PWS Section 5.1.4 |
System Configuration Management Plan
Due 30 days after receipt of contract and updated monthly thereafter
| 12 |
| MO |
| NSP |
| NSP |
| 0002 |
| Application Support- installation, configuration, communications, application, and technical support for PI Planning application IAW PWS Section 5.2 |
| 12 |
| MO |
| $ |
| $ |
| 0002AA |
| Root Cause Analysis Report IAW PWS Section 5.2 |
Due within 5 business days following a reported issue
| 12 |
| MO |
| NSP |
| NSP |
| 0003 |
| Licenses-100 Scaled Agile, Inc’s ® piplanning.io IAW PWS Section 5.2.1, 5.2.1.1 |
Due at contract award
| 1 |
| EA |
| $ |
| $ |
| 0004 |
| Technical Documentation IAW PWS Section 5.3 |
The cost of this CLIN shall be included and allocated in CLIN 0002
| 12 |
| MO |
| NSP |
| NSP |
| 0004AA |
| Physical/logical diagrams IAW PWS 5.3 |
Diagrams shall be delivered thirty (30) days after receipt of contract and updated as per environment changes, thereafter
| 1 |
| LO |
| NSP |
| NSP |
| 0004AB |
| Administrative Account Records IAW PWS Section 5.3 |
Due 30 days within a change to the system
| 1 |
| LO |
| NSP |
| NSP |
| 0004AC |
| Deployment and Installation, Back-out, and Rollback Plan IAW PWS Section 5.3 |
Due every 180 days after receipt of contract or within 30 days of a change
| 1 |
| LO |
| NSP |
| NSP |
| 0004AD |
| Test Plan IAW PWS Section 5.3 |
Due 14 days after a change to Production which requires an update to the Test Plan
| 1 |
| LO |
| NSP |
| NSP |
| 0004AE |
| Test Scripts IAW PWS Section 5.3 |
Due one week prior to Production release
| 1 |
| LO |
| NSP |
| NSP |
| 0004AF |
| Test Reports IAW PWS Section 5.3 |
Due the day of release to Production
| 1 |
| LO |
| NSP |
| NSP |
BASE PERIOD TOTAL:
Option Period One This option may be exercised in accordance with FAR 52.217-9, Option to Extend the Term of the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence immediately after expiration of the base year.
CLIN
Quantity
| 1001 |
| Project Management- Contractor Project Management Plan, Reporting Requirements, Technical Kickoff Meeting, and Change Enablement, Release, Management |
In accordance with (IAW) 5.1, 5.1.1, 5.1.2, 5.1.3, 5.1.4 of Performance Work Statement)
| 12 |
| MO |
| NSP |
| NSP |
| 1001AA |
| Contractor Project Management Plan IAW PWS Section 5.1.1 |
Due 30 days after contract and updated monthly thereafter.
| 12 |
| MO |
| NSP |
| NSP |
| 1001AB |
| Product Status Report IAW PWS Section 5.1.2 |
Due via dashboard, accessible real-time
| 12 |
| MO |
| NSP |
| NSP |
| 1001AC |
| Change Enablement, Release, Management IAW PWS Section 5.1.4 |
System Configuration Management Plan
Due 30 days after receipt of contract and updated monthly thereafter
| 12 |
| MO |
| NSP |
| NSP |
| 1002 |
| Application Support- installation, configuration, communications, application, and technical support for PI Planning application IAW PWS Section 5.2 |
| 12 |
| MO |
| $ |
| $ |
| 1002AA |
| Root Cause Analysis Report IAW PWS Section 5.2 |
Due within 5 business days following a reported issue
| 12 |
| MO |
| NSP |
| NSP |
| 1003 |
| Licenses-100 Scaled Agile, Inc’s ® piplanning.io IAW PWS Section 5.2.1, 5.2.1.1 |
Due at contract award
| 1 |
| EA |
| $ |
| $ |
| 1004 |
| Technical Documentation IAW PWS Section 5.3 |
The cost of this CLIN shall be included and allocated in CLIN 0002
| 12 |
| MO |
| NSP |
| NSP |
| 1004AA |
| Physical/logical diagrams IAW PWS 5.3 |
Diagrams shall be delivered thirty (30) days after receipt of contract and updated as per environment changes, thereafter
| 1 |
| LO |
| NSP |
| NSP |
| 1004AB |
| Administrative Account Records IAW PWS Section 5.3 |
Due 30 days within a change to the system
| 1 |
| LO |
| NSP |
| NSP |
| 1004AC |
| Deployment and Installation, Back-out, and Rollback Plan IAW PWS Section 5.3 |
Due every 180 days after receipt of contract or within 30 days of a change
| 1 |
| LO |
| NSP |
| NSP |
| 1004AD |
| Test Plan IAW PWS Section 5.3 |
Due 14 days after a change to Production which requires an update to the Test Plan
| 1 |
| LO |
| NSP |
| NSP |
| 1004AE |
| Test Scripts IAW PWS Section 5.3 |
Due one week prior to Production release
| 1 |
| LO |
| NSP |
| NSP |
| 1004AF |
| Test Reports IAW PWS Section 5.3 |
Due the day of release to Production
| 1 |
| LO |
| NSP |
| NSP |
OPTION PERIOD ONE TOTAL:
Optional Tasks This option may be exercised in accordance with FAR 52.217-7, Option for increased quantity, separately priced line item any time during the period of performance. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.
CLIN
Quantity
| 0005 |
| Transition Support (Optional Task One)- If exercised, the Contractor shall provide a Transition Plan for 60 days of outgoing transition support for transitioning work from the current order to a follow-on order or Government entity IAW PWS Section 5.4 |
| 1 |
| LO |
| $ |
| $ |
| 0006 |
| Cyber Security (Optional Task Two)-Security Assessment and Accreditation IAW PWS Section 5.5, 5.5.1 |
| 12 |
| MO |
| $ |
| $ |
| 0007 |
| Licensing (Optional Task Three)- Licensing Block One, IAW PWS Section 5.6.1 -100 Licenses. |
| 1 |
| LO |
| $ |
| $ |
| 0008 |
| Licensing (Optional Task Three)- Licensing Licensing Block Two IAW PWS Section 5.6.2 100-Licenses |
| 1 |
| LO |
| $ |
| $ |
| Base Period Total |
| $ |
| Option Period One Total |
| $ |
| Optional Task Total |
| $ |
| TOTAL VALUE |
| $ |
B.4 PERFORMANCE WORK STATEMENT
Page 1 of
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Office of Information and Technology (OIT) Compliance, Risk and Remediation (CRR)
Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning Software and Support Date: June 16, 2024
VA-24-00073347
Task Order PWS Version Number: 1.0
1.0 BACKGROUND
The Department of Veterans Affairs (VA), Office of Information & Technology (OIT), Technical Solutions strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.
The VA Office of Compliance, Risk and Remediation (CRR), has a requirement for Scaled Agile, Inc’s ® piplanning.io or equivalent Planning Interval (PI) planning application for use in Scaled Agile Framework (SAFe). PI Planning is a cadence-based event that aligns all the teams on the Agile Release Train (ART) to a shared mission and vision. PI Planning has a standard agenda that includes a presentation of business context and vision, followed by team planning breakouts – where the teams create their Iteration plans and objectives for the upcoming PI. A successful PI Planning event delivers two primary outputs – committed PI objectives and a program board.
2.0 APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”
4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004
5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013
7. 10 U.S.C. § 2224, "Defense Information Assurance Program"
8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
9. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters
10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm
12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm
13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5, 2019
14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017
15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
17. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008
18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017
19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021
21. VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021
22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019
23. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010
24. VA Handbook 6500.6, “Contract Security,” March 12, 2010
25. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011
26. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018
27. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017
28. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
29. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
30. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014
31. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
32. VA Handbook 6510, “VA Identity and Access Management,” January 15, 2016
33. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017
34. VA Directive 6300, “Records and Information Management,” September 21, 2018
35. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010
36. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018
37. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)
38. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015
39. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014
40. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005
41. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019
42. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008
43. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)
44. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018
45. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020
46. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014
47. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile Devices (Draft),” October 2012
48. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981, “Mobile, PIV, and Authentication,” March 2014
49. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
50. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
51. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896
52. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents
53. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019
54. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008
55. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
56. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
57. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018
58. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
59. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013
60. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013
61. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
62. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
63. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
64. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
65. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946
66. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020
67. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),” November 19, 2020
68. Social Security Number (SSN) Fraud Prevention Act of 2017
69. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018
3.0 SCOPE OF WORK
The Contractor shall provide technical application support services, installation, configuration, troubleshooting, and user administration to the OIT Technical Solutions team. The Contractor shall provide virtual system/server support for containerized applications and their virtual environments in test, development, sandbox, and production platform environments. The Contractor shall provide vulnerability remediation in the virtual environment, and all other support services provided in this PWS within the PoP.
The solution within this TO is hosted in the VA Enterprise Cloud (VAEC) VA Platform One (VAPO) environment and shall be maintained in the current state of operations.
All documentation created by the Contractor shall use OIT approved templates.
3.1 ORDER TYPE
The effort shall be proposed on a Firm Fixed Price (FFP) basis.
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
The PoP shall be 12 months from date of award, with one 12-month option period. The overall Period of Performance shall not exceed 24 months.
4.2 PLACE OF PERFORMANCE
Efforts under this contract shall be performed at Contractor facilities. The Contractor shall identify the Contractor’s place of performance, including all remote employees, in their Task Execution Plan submission.
4.3 TRAVEL OR SPECIAL REQUIREMENTS
There is no expected travel with this effort.
4.4 GOVERNMENT FURNISHED PROPERTY
The Government shall furnish the below GFE:
· Personal Identification Verification (PIV) cards
· Cloud capacity in and connectivity to the VA Enterprise Cloud (VAEC) environments.
· VA Enterprise Cloud Operational Tools (VAECOT) comprised of a suite of COTS cloud management tools as identified in the VAEC Technical Reference Guide.
· Enterprise Development Environment (EDE) and Tools as identified in the VAEC Technical Reference Guide.
4.5 SECURITY AND PRIVACY
Specific contract requirements are as follows,
j. The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system). Such issues shall be remediated as quickly as is practical, but in no event longer than ___2__days from the date the exploitation is discovered. The vendor shall prioritize the remediation based on the severity of the exploitation.
k. When the Security Fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the vendor shall provide written notice to VA that the patch has been validated as not affecting the Systems within 10 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within __5___ days or the next available planned outage.
4.5.1 POSITION/TASK RISK DESIGNATION LEVEL(S)
The PDT Tool is located at the following US Office of Personnel Management Website: https://www.opm.gov/investigations/suitability-executive-agent/position-designation-tool/) In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity, and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:
Position Sensitivity and Background Investigation Requirements by Task
| Task Number |
| Tier1 / Low Risk |
| Tier 2 / Moderate Risk |
| Tier 4 / High Risk |
| 5.1 |
| |X| |
| |_| |
| |_| |
| 5.2 |
| |_| |
| |X| |
| |_| |
| 5.3 |
| |X| |
| |_| |
| |_| |
| 5.4 |
| |X| |
| |_| |
| |_| |
| 5.5 |
| |X| |
| |_| |
| |_| |
The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.
5.0 SPECIFIC TASKS AND DELIVERABLES
VA requires the purchase of Scaled Agile Inc.’s (SAI) piplanning.io or equivalent. This application includes 100 licenses, premium level on-premises support, installation services and end user support services. Installation services include configuration and installation of Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application to a production level. To a production level refers to the best practice of test, development, sandbox, and production environments located in the VAEC. These services also include integration with an Application Lifecycle Management (ALM) tool (e.g., Jira®). End user support services consists of live support available during business hours to all users of the product. The Contractor shall provide dedicated premium level on-premises support with coverage available between 6:00am – 7:00pm Eastern Time.
5.1 PROJECT MANAGEMENT
5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline, and tools to be used in execution of this TO effort. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks, and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA Program Manager (PM) approved CPMP throughout the PoP.
Deliverable:
A. Contractor Project Management Plan
5.1.2 REPORTING REQUIREMENTS
The Contractor shall produce an electronic Product Status Reports available real-time. These reports will be auto generated to a dashboard from existing data sources, including:
· From the VA customer service request system (e.g., ServiceNow®)
· Server monitoring tools (e.g., Dynatrace®).
The Product Status Report shall, at a minimum, include the following data elements, which shall be retrieved from multiple different data sources and aggregated to produce the reports:
a. Status of all customer service, problem, user support and incident reporting (ServiceNow data).
b. Status of all user accounts requests (ServiceNow data).
c. Status of all approved change orders to the hardware and application platform (ServiceNow change management data).
d. Status of all issues and risks (Product risk registry).
The Contractor shall use the VA-authorized tools (e.g., Jira, GitHub, or similar) and products in scope of this contract and server reports to collect and report the data to be reported in this PWS. This report will not be the only means of communication between the Contractor, COR, and the VA PM. The Contractor shall continuously monitor performance and report any deviation from the CPMP or previous Product Status Reports to the COR and VA PM during routine, regular communications.
Deliverable:
A. Product Status Report
5.1.3 TECHNICAL KICKOFF MEETING
A technical kickoff meeting shall be held within 10 days after contract award. The Contractor shall coordinate the date, time, and location (can be virtual) with the Contracting Officer (CO), as the Post-Award Conference Chairperson, the VA PM, as the Co-Chairperson, the Contract Specialist (CS), and the COR. The Contractor shall provide a draft agenda to the CO and VA PM at least five (5) calendar days prior to the meeting. Upon Government approval of a final agenda, the Contractor shall distribute to all meeting attendees.
During the kickoff-meeting, the Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, and project schedule for each effort via a Microsoft Office PowerPoint presentation. At the conclusion of the meeting, the Contractor shall update the presentation with a final slide entitled “Summary Report” which shall include notes on any major issues, agreements, or disagreements discussed during the kickoff meeting and the following statement “As the Post-Award Conference Chairperson, I have reviewed the entirety of this presentation and assert that it is an accurate representation and summary of the discussions held during the Technical Kickoff Meeting for Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application support contract.
The Contractor shall submit the final updated presentation to the CO for review and signature within three (3) calendar days after the meeting. The Contractor shall also work with the CS, the Government’s designated note taker, to prepare and distribute the meeting minutes of the kickoff meeting to the CO, COR, and all attendees within three (3) calendar days after the meeting. The Contractor shall obtain concurrence from the CS on the content of the meeting minutes prior to distribution of the document.
5.1.4 CHANGE ENABLEMENT, RELEASE AND MANAGEMENT
The Contractor shall be responsible for compliance with VA Directive 6004, Configuration, Change, and Release Management Programs, which provides department-wide standards established in accordance with Federal Information Security Management Act (FISMA) (P.L. 107-347, Title III of the E-Government Act), December 2002, related VA Directive and Handbook 6500, Information Security Program, and Office of Information Technology (OIT) Authorization Requirements Standard Operating Procedures (SOP).
The Contractor shall work with Information System Owner (ISO) to meet ATO requirements which includes completion of a System Configuration Management Plan (SCMP). In addition to complying with VA Directive 6004, the Contractor shall comply with Configuration Management System (CMS) Discovery and Service Mapping requirements, which includes, but is not limited to; providing associated system design documents or appropriate contacts for system design and technical information necessary to conduct discovery and mapping activities. Provisions must be made between the responsible vendor and VA Product team on coordination of all system changes. Release Change Requests are required to be submitted in the VA authorized Change Control system, ServiceNow.
References:
VA Directive 6004, Configuration, Change and Release Management Programs VA Directive and Handbook 6500, Information Security Program
Deliverables:
A. System Configuration Management Plan
5.2 APPLICATION SUPPORT
The Contractor shall provide installation, configuration, communications, application, and technical support for Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application. A dedicated contractor Account Manager shall respond to urgent inquiries within four hours from the time of notification. All other inquiries shall be addressed the next business day. The methods of communication shall include Slack®, phone, and Teams®.
The Contractor shall provide technical product support and if unable to resolve the contractor is responsible for escalation to the vendor for remediation. During PI events issues must be resolved within two hours; issues that cannot be resolved by the contractor within this timeframe shall be escalated to the vendor. Upon successful resolution the contractor shall provide root cause analysis of issues escalated to the vendor within three business days of event.
The Contractor shall provide the equivalent to senior level DevSecOps Engineer, with a minimum of nine years’ experience, to meet the required level of effort in support of version upgrades, integrations, and deployments within the VA ecosystem.
The Contractor shall provide full application lifecycle support, including continuous sustainment (patching) and technical support (patching, upgrades) for VA’s implementation of Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application.
The Contractor shall provide project updates in VA approved tools (e.g., ServiceNow, Jira). The resources shall provide support including, but not limited to remediation of scan results, custom script deployments, and/or any technical change within the vendor’s control that will enable successful Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application implementation.
The Contractor shall perform product integration and testing for the application. Testing shall include 508-compliance, connectivity, load, functional, and integration following industry best practices. The Contractor shall create test plans, test scripts, and test reports.
The Contractor shall perform data migration as required.
Deliverables:
A. Root Cause Analysis Report
5.2.1 LICENSES
The Contractor shall provide 100 Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning software application licenses.
SALIENT CHARACTERISTICS
• whiteboard capability with colored sticky notes for different teams.
• Graphical User Interface (GUI) must be intuitive.
• able to handle up to 600 concurrent users either onsite or in distributed teams.
• must support a “big picture” Kanban board to virtually “walk the walls.”
• must have backup/recovery features.
• must have an enterprise licensing model.
• must support several iterations of varying durations.
• must be able to support identification of the team to attend the event.
• must have the ability to create breakout room sessions.
• must have the ability to read other team boards without additional permissions.
• must allow for role-based permissions.
• must offer an integrated program risk board.
• must provide visual representation of tasks to meet feature delivery.
• must allow for creation of milestones.
• must be able to map out dependencies between teams.
• must be able to synchronize in real-time.
• must be able to be agnostic when connecting to Application Lifecycle Management (ALM)/Software-as-a-Service (SaaS) tools.
• must offer bi-directional communication with ALM and desktop applications.
• must have the ability to schedule timed breakout sessions and breaks.
• must offer both anonymous and name capture for voting/polling features.
• must allow touch screen functionality.
• must allow mobile app functionality.
• must support online availability of all documents and material for PI planning events.
• must take into consideration user bandwidth required to run the application.
Deliverable:
A. Licenses
5.3 TECHNICAL DOCUMENTATION
The Contractor shall coordinate with VA to identify needs for creation, editing, review, and promulgation of Physical/Logical Diagrams, Administrative Account Records, Deployment, and Installation, Back-out, and Rollback Plan, Test Plan, Test Scripts, Test Reports, end user communications and technical documentation, as needed. All new versions of products may require the Contractor to create/update documentation.
Deliverables:
A. Physical/logical diagrams B. Administrative account records C. Deployment and Installation, Back-out, and Rollback Plan D. Test Plan E. Test Scripts F. Test Reports
5.4 TRANSITION SUPPORT (OPTIONAL TASK ONE)
If exercised, the Contractor shall provide a Transition Plan for 60 days of outgoing transition support for transitioning work from the current contract to a follow-on contract or Government entity. This transition may be to a Government entity or to another Contractor. In accordance with the Government-approved Transition Plan, the Contractor shall execute the Transition Plan and assist the Government in implementing a complete transition from this contract to a new support provider. This shall include formal coordination with Government staff and successor staff and management. It shall also include delivery of copies of all artifacts delivered under this contract, as well as existing policies and procedures, and delivery of baseline metrics and statistics. This Transition Plan shall, at a minimum, include the following:
1. Coordination with Government representatives.
2. Review, evaluation, and transition of current support services.
3. Transition of historic data to new Contractor system.
4. Transition of application accounts.
5. Transfer of hardware and software warranties, maintenance agreements and licenses.
6. Update and transfer of all necessary business and/or technical documentation.
7. Orientation phase and program to introduce Government and Contractor personnel, programs, and users to the Contractor's team, tools, methodologies, and business processes.
8. Disposition of Contractor purchased Government owned assets,
9. Transfer of Government Furnished Equipment (GFE) and Government Furnished Information, and GFE inventory management assistance.
10. Turn-in of all Government keys, ID/access cards, and security codes.
If exercised, the PoP for the optional task may extend 60 days beyond the PoP in which it is exercised. During this period, the Contractor shall provide for continuity of services to include technical resources required to provide continued help desk functionality, database management and virtual system/server support for the series of application servers, database servers, web servers, virtual environments in the testing, training, staging and production platform environments. The Contractor shall work collaboratively with the incoming Contractor staff or Government personnel to minimize interruption to on-going program operations.
Deliverable:
A. Transition Plan
5.5 CYBER SECURITY (OPTIONAL TASK TWO)
5.5.1 SECURITY ASSESSMENT AND ACCREDITATION
All systems and applications supporting Federal government agencies shall follow National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) Special Publication (SP) 800-37 as the standard for Assessment and Authorization (A&A) process before being put into production, and every five (5) years thereafter. Risk assessments must be performed in accordance with NIST SP 800-30, NIST SP 800-53 and as described in the VA Information Security Knowledge Service. The risk factors described in NIST SP 800-30 and NIST SP 800-53 will be used across VA Administrations and Staff Offices to ensure ease of sharing risk information.
If exercised in Option period one, the Contractor shall maintain VA ATO authorization for the Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application. This includes supporting any of the associated environments prior to the expiration of any current ATO periods in effect for these products. Specific activities are to include, at a minimum, security certifications, or comprehensive assessments of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly. This effort includes all activities associated with obtaining a new ATO period for these applications and environments.
The Contractor shall develop and maintain all A&A documentation and requirements for upload, registration, and execution within the VA-approved Governance Risk and Compliance (GRC) tool for Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application.
Custom developed and Government Off the Shelf (GOTS)/Commercial Off the Shelf (COTS) VA applications are required to obtain an ATO. For any ATO effort, the Contractor shall follow the Risk Management Framework (RMF) Lifecycle. The Contractor shall initiate the ATO process within 30 calendar days of the exercising of this TO. Products in the VAEC require a continuous ATO process.
The Contractor shall provide applicable documentation and coordinate with data center partners to ensure consistency with ATO requirements for certification authorization to ensure the supported applications/systems meet VA information security policies and standards to facilitate the successful completion of the A&A process and maintain its ATO.
The Contractor shall:
1. Support VA Information Security Officers and the Office of Cyber Security Control Assessment team as detailed in VA Directive and Handbook 6500 Information Security Program, VA Handbook 6500.3 Certification and Accreditation of VA Information Systems.
2. Conduct cybersecurity software code quality testing and validation of all software code and provide certified scan reports validating the required code quality.
3. Conduct and participate in vulnerability scans and tests as detailed in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev 5 or the latest published version. Recommend Security Controls for Federal Information Systems.
4. Security scanning shall be performed by multiple methods and is done multiple times throughout the course of a project with methods such as infiltration testing, code analysis tools (Fortify), etc.
5. Remediate critical and high vulnerabilities identified in government scans or quality checks or reviews (Secure Code Review/Quality Code Review require remediation of all findings.) for approval by appropriate VA governing group.
Critical vulnerabilities shall be remediated within 30 calendar days after receiving findings report.
High vulnerabilities shall be remediated within 60 calendar days after receiving findings report.
Medium vulnerabilities shall be remediated within 90 calendar days after receiving findings report.
6. Provide vulnerability scanning reports and assessments as detailed in NIST SP 800-30 Rev 1 Guide for Conducting Risk Assessments.
7. Support each product by identifying, documenting, reviewing, and maintaining the A&A Artifacts as needed to support an ATO request in accordance with VA policy and Federal Law and guidelines, as detailed in NIST SP 800-37 Rev 2 Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach. Additionally, the Contractor shall update any aspect (e.g., documentation, code, etc.) of the effort based on comments from the A&A review process conducted.
The A&A Package may consist of the following documents:
a. System Security Plan
1. Guidance is found in NIST SP 800-18
2. SSP is authored locally, but may contain inserts that are National or Common in nature
b. Risk Assessment (coordinate with Office of Risk Management and Incident Reporting)
1. Guidance is found in NIST SP 800-30 and by using the
2. VA Risk Assessment Review Checklist
c. Signatory Authority
1. Guidance is found in NIST SP 800-18 and the
2. Signatory Authority Template available on the Security Website 36C10B21D1035
3. All package submissions shall include this document signed and dated by the appropriate parties
d. Privacy Impact Assessment (coordinate with Office of Privacy)
1. Authority is found in OMB Circular 03-22
2. Authored locally, but may contain inserts that are National or Common in nature
e. Information System Contingency Plan (coordinate with Office of Business Continuity)
1. Guidance is found in NIST SP 800-34 and VA Handbook 6500
2. Authored locally, but may contain inserts that are National or Common in nature
f. Incident Response Plan
1. Guidance is found in NIST SP 800-61 and VA Handbook 6500
2. CSOC is responsible for National level tasks associated with incident response. Each site is responsible for developing local level procedures incorporating Cyber Security Operations Center (CSOC) areas or responsibility
3. See VA Handbook 6500.04
g. Security Configuration Checklists
1. Guidance is found in NIST SP 800-70
2. Contact Technical Security for Specific Operating System (OS) Hardening Guidelines
h. System Interconnection Agreements (Memorandum of Understanding [MOU] and Interconnection)
1. Guidance is found in NIST SP 800-47 and VA Handbook 6500
2. Templates are available on the Security Website
i. Security Configuration Plan (SCP)
j. Interconnection Security Agreement (ISA) as necessary
k. Disaster Recovery Plan (DRP) The Contractor shall also provide continued security Plan of Action and Milestones (POAM) support. Any VA directed vulnerability scans, remediation and reports shall be completed prior to the conduct of the VA acceptance testing.
Deliverable:
A. Assessment and Authorization Package
5.6 Licensing (Optional Task Three)
5.6.1 100 Licenses
5.6.2 100 Licenses
6.0 GENERAL REQUIREMENTS
6.1 PERFORMANCE METRICS
The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.
| Performance Objective |
| Performance Standard |
| Acceptable Levels of Performance |
| A. Technical / Quality of Product or Service |
| 1. Shows understanding of requirements |
2. Efficient and effective in meeting requirements
3. Meets technical needs and mission requirements
4. Provides quality services/products
5. Incorporates “ease of use” Human Centered Design principles in any software developed.
Satisfactory or higher
| B. Project Milestones and Schedule |
| 1. Quick response capability |
2. Products completed, reviewed, delivered in accordance with the established schedule
3. Notifies customer in advance of potential problems Satisfactory or higher
| C. Cost & Staffing |
| 1. Currency of expertise and staffing levels appropriate |
2. Personnel possess necessary knowledge, skills and abilities to perform tasks
Satisfactory or higher
| D. Management |
| 1. Integration and coordination of all activities to execute effort |
| Satisfactory or higher |
The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the QASP at its own discretion. A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.
6.1.1 VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.
6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19-17 can be found at: https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-24.pdf, and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)
The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.
6.1.4 TRUSTED INTERNET CONNECTION (TIC)
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.
6.1.5 STANDARD COMPUTER CONFIGURATION
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.
6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT (PLM) The Contractor shall support VA efforts IAW the updated Veteran Focused Integration Process (VIP) and Product Line Management (PLM). The major focus of the new VIP is on Governance and Reporting and is less prescriptive, with a focus on outcomes and continuous delivery of value. Product Line Management (PLM) is a framework that focuses on delivering functional products that provide the highest priority work to customers while delivering simplified, reliable, and practical solutions to the business, medical staff, and our Veterans. The VIP Guide is a companion guide to the PLM Playbook and can be found at: https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 and the PLM Playbook can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946. The PLM Playbook pivots from project-centric to product-centric delivery and contains descriptive practices that focuses on outcomes. The PLM Playbook contains a set of “plays” that implement Development, Security, and Operations (DevSecOps) principles and processes such as automated development, continuous integration/continuous delivery, and release on demand. The PLM Playbook details how product lines implement Lean-Agile principles, methods, practices, and techniques through levels of maturity. VIP and PLM are the authoritative processes that IT projects must follow to ensure development and delivery of IT products.
6.1.7 PROCESS ASSET LIBRARY (PAL)
The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .