36C24826Q0125.docx

DOCX document 138 KB Posted

Attached to
J063--Lenel System License and Support Federal contract opportunity
Solicitation number
36C24826Q0125
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 8

About this file

This is a Department of Veterans Affairs (VA) solicitation for a Lenel System License and Support contract for the Bay Pines VA Medical Center. The solicitation (Number 36C24826Q0125) is a total set-aside for Service-Disabled Veteran-Owned Small Businesses (SDVOSB) seeking a base period plus four option years for security system licensing and support services.

The contract covers licensing, software support, and maintenance for two stand-alone Lenel security system computer systems at the Lee County VA Healthcare Center, including intrusion detection, access control, and video management system upgrades. The period of performance is from 12/01/2025 to 11/30/2030, with specific requirements including configuring 14 tamper switches, integrating access control keypads, providing a new video management system, and implementing a PIV enrollment station. The systems will support unlimited cameras, provide smart search capabilities, and require comprehensive configuration and 8 hours of on-site training. Vendors must submit quotes by November 10, 2025, at 4:30 PM EST, with questions due by November 4, 2025, at 12:30 PM EST.

View the file

Other files for this federal contract opportunity

Other files attached to J063--Lenel System License and Support, newest first.
File Type Posted
36C24826Q0125 Corrections.docx DOCX document
Records Management Contract Language.docx DOCX document
2024-Police Service- Lenel Security System- App A PO Comments-Contractor Install-Maint.doc DOC document
36C24826Q0125_2.docx DOCX document
36C24826Q0125_1.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C24826Q0125

PAGE 1 OF

1. REQUISITION NO.

2. CONTRACT NO.

3. AWARD/EFFECTIVE DATE

4. ORDER NO.

5. SOLICITATION NUMBER

6. SOLICITATION ISSUE DATE

a. NAME

b. TELEPHONE NO. (No Collect Calls)

8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY

CODE

10. THIS ACQUISITION IS

UNRESTRICTED OR

SET ASIDE:

% FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ

IFB

RFP

15. DELIVER TO

CODE

16. ADMINISTERED BY

CODE

17a. CONTRACTOR/OFFEROR

CODE

FACILITY CODE

18a. PAYMENT WILL BE MADE BY

CODE

TELEPHONE NO.

UEI:

EFT:

PHONE:

FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19.

20.

21.

22.

23.

24.

ITEM NO.

SCHEDULE OF SUPPLIES/SERVICES

QUANTITY

UNIT

UNIT PRICE

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________

29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

(REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

516-26-1-4059-0016 36C24826Q0125 11-24-2025 David Wesley Hess 727-295-6041 11-28-2025 16:00

EST

36C248 Department of Veterans Affairs Network Contracting Office 8 (

NCO 8)

10,000 Bay Pines Blvd Bay Pines FL 33744 X X 561621 $25 Million Net 30 N/A X

MCC: 90D

Department Of Veteran Affairs C.W. Bill Young VA Medical Center Bldg 100 Warehouse 10,000 Bay Pines Blvd.

Bay Pines FL 33744 36C248 Department of Veterans Affairs Network Contracting Office 8 (NCO 8) C.W. Bill Young VA Medical Center 10000 Bay Pines Blvd.

Bay Pines FL 33744

Department of Veterans Affairs

FMS-VA-2(101)

Financial Services Center PO Box 149971 Austin TX 78714-9971 See CONTINUATION Page See Schedule and Statement of Work" ***Please ensure that FAR 52.212-2 Evaluation—Commercial Products and Commercial Services and ADDENDUM FAR 52.212-1 to Instructions to Offerors—Commercial Products and Commercial Services and respond accordingly*** See CONTINUATION Page X X David Wesley Hess Contracting Officer Table of Contents

SECTION A1
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES1
SECTION B - CONTINUATION OF SF 1449 BLOCKS3
B.1 CONTRACT ADMINISTRATION DATA3
B.2 PRICE/COST SCHEDULE4
ITEM INFORMATION4
B.3 DELIVERY SCHEDULE10
SECTION C - CONTRACT CLAUSES44
C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2023)44
C.2 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)49
C.3 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)50
C.4 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025) (DEVIATION)50
C.5 VAAR 852.219-73 VA NOTICE OF TOTAL SET-ASIDE FOR CERTIFIED SERVICE-DISABLED VETERAN-OWNED SMALL BUSINESSES (JAN 2023) (DEVIATION)60
C.6 VAAR 852.219-75 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING—CERTIFICATE OF COMPLIANCE FOR SERVICES AND CONSTRUCTION (JAN 2023) (DEVIATION)63
C.7 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020)64
C.8 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)65
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS66
SECTION E - SOLICITATION PROVISIONS67
E.1 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (SEP 2023)67
E.2 52.240-90 SECURITY PROHIBITIONS AND EXCLUSIONS REPRESENTATIONS AND CERTIFICATIONS (NOV 2025) (DEVIATION)72
E.3 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)76
E.4 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)76

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C248 David Wesley Hess david.hess2@va.gov Department of Veterans Affairs Network Contracting Office 8 (NCO 8)

10,000 Bay Pines Blvd Bay Pines FL 33744

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X]
52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[X]
52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly[]
b. Semi-Annually[]
c. Other[X] Annually

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE

B.2 PRICE/COST SCHEDULE

ITEM INFORMATION

ITEM NUMBER
DESCRIPTION OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
1.00
YR
__________________
__________________

ALARM RENEWAL: 1 Pro Susp Plan-Tier 1 Software License with 128-256 Readers Contract Contract Period: POP Begin: 12-01-2025 POP End: 11-30-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems Contract Period: Base POP Begin: 12-01-2025 POP End: 11-30-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

24.00
UN
__________________
__________________

DV Channel SUSP PLAN Contract Period: POP Begin: 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2025 POP End: 11-30-2026

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

91.00
UN
__________________
__________________

Salient CV Pro one-year upgrade plan Contract Period: POP Begin: 12-01-2025 POP End: 11-30-6 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2025 POP End: 11-30-2026

4.00
DY
__________________
__________________

Onsite Tech 4 Annual Onsite Days Performing Upgrade Contract Period: Begin:Performing Upgrade Contract Period: Begin: POP 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2025 POP End: 11-30-2026

1.00
YR
__________________
__________________

ALARM RENEWAL: 1 Pro Susp Plan-Tier 1 Software License with 128-256 Readers Contract Contract Period: POP Begin: 12-01-2025 POP End: 11-30-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems Contract Period: Option 1 POP Begin: 12-01-2026 POP End: 11-30-2027

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

24.00
UN
__________________
__________________

DV Channel SUSP PLAN Contract Period: POP Begin: 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2026 POP End: 11-30-2027

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

91.00
UN
__________________
__________________

Salient CV Pro one-year upgrade plan Contract Period: POP Begin: 12-01-2025 POP End: 11-30-6 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2026 POP End: 11-30-2027

4.00
DY
__________________
__________________

Onsite Tech 4 Annual Onsite Days Performing Upgrade Contract Period: Begin:Performing Upgrade Contract Period: Begin: POP 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2026 POP End: 11-30-2027

1.00
YR
__________________
__________________

ALARM RENEWAL: 1 Pro Susp Plan-Tier 1 Software License with 128-256 Readers Contract Contract Period: POP Begin: 12-01-2025 POP End: 11-30-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems Contract Period: Option 2 POP Begin: 12-01-2027 POP End: 11-30-2028

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

24.00
UN
__________________
__________________

DV Channel SUSP PLAN Contract Period: POP Begin: 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2027 POP End: 11-30-2028

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

91.00
UN
__________________
__________________

Salient CV Pro one-year upgrade plan Contract Period: POP Begin: 12-01-2025 POP End: 11-30-6 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2027 POP End: 11-30-2028

4.00
DY
__________________
__________________

Onsite Tech 4 Annual Onsite Days Performing Upgrade Contract Period: Begin:Performing Upgrade Contract Period: Begin: POP 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2027 POP End: 11-30-2028

1.00
YR
__________________
__________________

ALARM RENEWAL: 1 Pro Susp Plan-Tier 1 Software License with 128-256 Readers Contract Contract Period: POP Begin: 12-01-2025 POP End: 11-30-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems Contract Period: Option 3 POP Begin: 12-01-2028 POP End: 11-30-2029

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

24.00
UN
__________________
__________________

DV Channel SUSP PLAN Contract Period: POP Begin: 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2028 POP End: 11-30-2029

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

91.00
UN
__________________
__________________

Salient CV Pro one-year upgrade plan Contract Period: POP Begin: 12-01-2025 POP End: 11-30-6 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2028 POP End: 11-30-2029

4.00
DY
__________________
__________________

Onsite Tech 4 Annual Onsite Days Performing Upgrade Contract Period: Begin:Performing Upgrade Contract Period: Begin: POP 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2028 POP End: 11-30-2029

1.00
YR
__________________
__________________

ALARM RENEWAL: 1 Pro Susp Plan-Tier 1 Software License with 128-256 Readers Contract Contract Period: POP Begin: 12-01-2025 POP End: 11-30-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems Contract Period: Option 4 POP Begin: 12-01-2029 POP End: 11-30-2030

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

24.00
UN
__________________
__________________

DV Channel SUSP PLAN Contract Period: POP Begin: 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2029 POP End: 11-30-2030

PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

91.00
UN
__________________
__________________

Salient CV Pro one-year upgrade plan Contract Period: POP Begin: 12-01-2025 POP End: 11-30-6 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2029 POP End: 11-30-2030

4.00
DY
__________________
__________________

Onsite Tech 4 Annual Onsite Days Performing Upgrade Contract Period: Begin:Performing Upgrade Contract Period: Begin: POP 12-01-2025 POP End: 11-30-26 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

POP Begin: 12-01-2029 POP End: 11-30-2030

GRAND TOTAL
__________________

B.3 DELIVERY SCHEDULE

ITEM NUMBER
SHIPPING INFORMATION
QUANTITY
DELIVERY DATE
0001
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

1.00
11-30-2026
MARK FOR:
Hiram Perez

(727) 398-6661, EXT. 10314

hiram.perez@va.gov

FOB:
DESTINATION
0002
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

24.00
11-30-2026
MARK FOR:
Hiram Perez
FOB:
DESTINATION
0003
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

91.00
11-30-2026
MARK FOR:
Hiram Perez
FOB:
DESTINATION
0004
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

4.00
11-30-2026
MARK FOR:
Hiram Perez
FOB:
DESTINATION
1001
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

1.00
11-30-2027
MARK FOR:
Hiram Perez
FOB:
DESTINATION
1002
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

24.00
11-30-2027
MARK FOR:
Hiram Perez
FOB:
DESTINATION
1003
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

91.00
11-30-2027
MARK FOR:
Hiram Perez
FOB:
DESTINATION
1004
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

4.00
11-30-2027
MARK FOR:
Hiram Perez
FOB:
DESTINATION
2001
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

1.00
11-30-2028
MARK FOR:
Hiram Perez
FOB:
DESTINATION
2002
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

24.00
11-30-2028
MARK FOR:
Hiram Perez
FOB:
DESTINATION
2003
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

91.00
11-30-2028
MARK FOR:
Hiram Perez
FOB:
DESTINATION
2004
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

4.00
11-30-2028
MARK FOR:
Hiram Perez
FOB:
DESTINATION
3001
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

1.00
11-30-2029
MARK FOR:
Hiram Perez
FOB:
DESTINATION
3002
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

24.00
11-30-2029
MARK FOR:
Hiram Perez
FOB:
DESTINATION
3003
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

91.00
11-30-2029
MARK FOR:
Hiram Perez
FOB:
DESTINATION
3004
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

4.00
11-30-2029
MARK FOR:
Hiram Perez
FOB:
DESTINATION
4001
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

1.00
11-30-2030
MARK FOR:
Hiram Perez
FOB:
DESTINATION
4002
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

24.00
11-30-2030
MARK FOR:
Hiram Perez
FOB:
DESTINATION
4003
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

91.00
11-30-2030
MARK FOR:
Hiram Perez
FOB:
DESTINATION
4004
SHIP TO:
Lee County VAHC

2489 Diplomat Parkway East Cape Coral, FL 33909 5422 United States

4.00
11-30-2030
MARK FOR:
Hiram Perez
FOB:
DESTINATION

Statement of Work Licensing Software and Support Services for Lenel System

Background:

Police Service requires license renewal and support services of current Lenel Security System located at Lee County VA Healthcare Center. Licensing is to ensure safe and reliable physical security, intrusion detection and access control of the facility. This shall be completed to ensure maximum uptime with minimal impact on facility operations. Two stand-alone computer systems are currently in place at the Lee County VA Healthcare Center and require licensing renewal and support services.

Period of Performance:

12/01/2025 – 11/30/2030 (Base w/ 4 option years)

Scope of Work:

Contractor shall provide all services, licensing software and support required to maintain uninterrupted or impeded operations of the surveillance, intrusion detection and access control systems for the Lenel System at Lee County Healthcare Center located at 2489 Diplomat Parkway East, Cape Coral Florida 33909. The license software is essential for maintenance and repairs of the LENEL security suite and equipment is operating within manufacturer’s specifications and functioning at maximum efficiency.

Intrusion Detection System:

· Provide and install the necessary equipment to make all existing I.D.S. network capable within existing enclosure and using existing wiring and components.

· Status of all I.D.S. alarm zones will be configurable and viewable by customers in the police operations/security room 1B-192.

· Configure and test 14 tamper switches that are currently not configured to detect tamper. Should also include correcting Lenel programming for up to 5 mis-programmed IDPS intrusion reporting. MP4, MJPEG, or AVI video capture of one sample for each configuration action is performed via a PC.

Video Management System:

· Bring current controllers up to the same level as the software.

· Place maps of the building floor plans in alarm monitoring that shall pop up to indicate an alarm event with location on the monitoring screen.

· Identify all access control keypads that are currently not integrated into the system and program them to make them fully functional.

· Provide and install new video management system equal to or exceeding the specifications of Salient Systems Complete view Pro:

· Supports unlimited cameras

· Simultaneous record, playback, live view, and export

· Single seat administration

· Multi server configuration

· Remote software update

· Video client

· Alarm client

· Mapping client

· Web client

· CV Spotlight

· Smart Search – based on motion in a defined area

· Support camera resolutions up to 11 Megapixel

· Automated Attendant

· Multiple monitor support

· Stable recording architecture

· Dynamic resolution scaling

· Flexible view configuration

· Email alerts

· Flexible motion detection

· Independent frame rate control

· Joystick control – software or USB

· Supported CODEC – MJPEG, Microsoft’s MPEG4, ISO MPEG4, or H.264

· Open Architecture – Standards based

· Royalty free API

· Reuse all existing Pelco cameras.

· Reuse all existing workstations, network electronics, wire, cables, and monitors.

· Complete all programming, configuration and 8 hours of end user one site training. MP4. MJPEG, or AVI video capture of one sample for each configuration action type on the system will be provided.

· Provide a min of 16 TB storage, or enough for 24/7 motion recording detection at 7 frames per second for all existing cameras and resolution for a minimum of 30 days storage.

· A complete disk image of the fully configured system hard drive will be provided. The image must be demonstrated as fully functional when restored to a new hard drive. Alternatively, RAID configuration, with disk imaging may be used. Mirrored disk must be hot swappable and self-recovering in event the other drive fails.

Lenel PIV Enrollment Station:

· Provide one Lenel PIV enrollment reader and workstation, UPS, and programming.

· CPU specs shall be equal to or greater than Dell Optiplex 3010 Small Form Factor – Intel Core i3-2120 Processor – 3.3 GHz – 3MB – 4MB -Non-ECC – 1600 MHz – DDR3 [1 DIMM]; 8X Slim Line DVD+/-RW; 250GB SATA II 3.0Gb/s; 7200 rpm hard drive; 1 GB AMD RADEON HD 7570- Dual MON (1 DP & 1 DVI); Windows 7 Professional 64-bit.

Facial Recognition System:

· Provide a facial recognition system/server equal to or greater than 3 yr facial video analytic specs and at a minimum 1 camera running this video analytic against an internal database.

All work shall be coordinated with the V.A. Engineering staff so that all work and shutdowns of the security systems will not affect patient care or normal operation of the facility. All work shall be installed in accordance with all applicable IEEE, NIST, and VA installation standards and preferred practices. In the event of a conflict between standards or recommendations the more rigorous standard shall apply, to the extent that the standard is appropriate for the particular type and model of equipment.

RECORDS MANAGEMENT OBLIGATIONS

A. Applicability This clause applies to all Contractors whose employees create, work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.

B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

The term Federal record:

1. includes Bay Pines VA Healthcare System records.

2. does not include personal materials.

3. applies to records created, received, or maintained by Contractors pursuant to their Bay Pines VA Healthcare System contract.

4. may include deliverables and documentation associated with deliverables.

C. Requirements

1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

4. Bay Pines VA Healthcare System and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of Bay Pines VA Healthcare System or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to Bay Pines VA Healthcare System. The agency must report promptly to NARA in accordance with 36 CFR 1230.

5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the contract. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to Bay Pines VA Healthcare System control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the contract. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).

6. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and Bay Pines VA Healthcare System guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with Bay Pines VA Healthcare System policy.

8. The Contractor shall not create or maintain any records containing any non-public Bay Pines VA Healthcare System information that are not specifically tied to or authorized by the contract.

9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.

10. The Bay Pines VA Healthcare System owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which Bay Pines VA Healthcare System shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.

11. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take [Agency]-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.

[Note: To the extent an agency requires contractors to complete records management training, the agency must provide the training to the contractor.] D. Flowdown of requirements to subcontractors

1. The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph, in all subcontracts under this [contract vehicle], and require written subcontractor acknowledgment of same.

2. Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.

PO Comments:

Contractor will be required to comply with physical security guidelines by either checking in with the VA Police each time they come on-site to perform contracted services or by obtaining a VA Contractor ID badge from the VA Police.

Contractor staff must be escorted at all times when performing work in sensitive areas such as data closets.

The following language from VA Handbook 6500.6 is required in this contract:

· Appendix C:

2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language.

b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.

3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract.

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.

b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.

c. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

e. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following: (1) Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.

(2) Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.

(3) Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.

(4) Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.

(5) Contractor/subcontractor personnel have their authorization to work in the United States revoked.

(6) Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.

f. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

g. Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors

4. TRAINING. This entire section applies to all acquisitions which include section 3. a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems: (1) VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter.

(2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and

(3) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role-based information security training].

b. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.

5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any Information Security and Privacy language. a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.

b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following: (1) The date and time (or approximation of) the Security Incident occurred.

(2) The names of individuals involved (when applicable).

(3) The physical and logical (if applicable) location of the incident.

(4) Why the Security Incident took place (i.e., catalyst for the failure).

(5) The amount of data belonging to VA believed to have been compromised.

(6) The remediation measures the contractor is taking to ensure no future incidents of a similar nature.

c. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.

d. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.

e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

f. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.

g. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.

h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages—Reimbursement for Data Breach Costs.

shall notify the appropriate VA COR/CO.

6. INFORMATION SYSTEM DESIGN AND DEVELOPMENT. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (to include the subcomponents of each) designed or developed for or on behalf of VA by any non-VA entity.

a. Information systems designed or developed on behalf of VA at non-VA facilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards for the protection of electronic Protected Health Information (PHI), outlined in 45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems and FIPS 200, Minimum Security Requirements for Federal Information Systems. Baseline security controls shall be implemented commensurate with the FIPS 199 system security categorization (reference VA Handbook 6500 and VA Trusted Internet Connections (TIC) Architecture).

b. Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA Assessment and Authorization (A&A) processes in VA Handbook 6500 and VA Information Security Knowledge Service to obtain an Authority to Operate (ATO). VA Directive 6517, Risk Management Framework for Cloud Computing Services, provides the security and privacy requirements for cloud environments.

c. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500, VA Handbook 6517, Risk Management Framework for Cloud Computing Services and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution. Contractors shall comply with FAR 39.1, specifically the prohibitions referenced.

d. The contractor (including producers and resellers) shall comply with Office of Management and Budget (OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M-22-18 (September 14, 2022). The term “software” includes firmware, operating systems, applications and application services (e.g., cloud-based software), as well as products containing software. The contractor shall provide a self-attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program (FedRAMP) Third Party Assessor Organization (3PAO) or one approved by the agency will be acceptable in lieu of a software producer's self-attestation.

e. The contractor shall ensure all delivered applications, systems and information systems are compliant with Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity management requirements as set forth in OMB M-19-17, M-05-24, FIPS 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors (or its successor), M-21-31 and supporting NIST guidance. This applies to Commercial Off-The-Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations.

f. The contractor shall ensure all contractor delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity Guidelines, for direct, assertion-based authentication and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common Access Card (CAC), as determined by the business need and compliance with VA Information Security Knowledge Service specifications.

g. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operate correctly as intended on systems in compliance with VA baselines prior to acceptance or connection into an authorized VA computing environment. If the Defense Information Systems Agency (DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requires the population of operating systems and applications includes all listed on the NIST National Checklist Program Checklist Repository.

h. The standard installation, operation, maintenance, updating and patching of software shall not alter the configuration settings from VA approved baseline configuration. Software developed for VA must be compatible with VA enterprise installer services and install to the default “program files” directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on VA systems.

i. Applications designed for normal end users will run in the standard user context without elevated system administration privileges.

j. The contractor-delivered solutions shall reside on VA approved operating systems. Exceptions to this will only be granted with the written approval of the COR/CO.

k. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development life cycle outlined in NIST 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, VA Directive and Handbook 6500, and VA Handbook 6517.

l. The Contractor shall comply with the Privacy Act of1974 (the Act), FAR 52.224-2 Privacy Act, and VA rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish a VA function.

m. The contractor shall ensure the security of all procured or developed information systems, systems, major applications, minor applications, enclaves and platform information technologies, including their subcomponents (hereinafter referred to as “Information Systems”) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems.

n. When the contractor is responsible for operations or maintenance of the systems, the contractor shall apply the security fixes within the timeframe specified by the associated controls on the VA Information Security Knowledge Service.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .