Attachment_2-Statement_of_Work_Cloud_eDiscovery.docx
DOCX document 6 MB Posted
- Attached to
- Ediscovery Cloud Pilot Federal contract opportunity
- Solicitation number
- 50310219R0009
- Issued by
- Securities and Exchange Commission
About this file
Attachment 2-SOW
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 50310219R0009-0001.pdf | ||
| eD3_cloud_pilot_Labor_Category_Descriptions.xlsx | XLSX spreadsheet | |
| SEC_eDiscovery_Pilot_-_RFP_answers.xlsx | XLSX spreadsheet | |
| Cloud_eDiscovery_RFP_Attachment_1_Requirements_amend1.xlsx | XLSX spreadsheet | |
| Attachment_1-eD3_cloud_pilot_Section_B_amend1.xlsx | XLSX spreadsheet | |
| E-Production_Standards.pdf | ||
| 50310219R0009_-_Ediscovery_Cloud_Pilot.pdf | ||
| Attachment_5_-_Non-Disclosure_Agreement_Contractor_Personnel.pdf | ||
| Attachment_1-eD3_cloud_pilot_Section_B.xlsx | XLSX spreadsheet | |
| Attachment_4_-_Non-Disclosure_Agreement_Contractor_Entity.pdf | ||
| Attachment_3-Requirements.xlsx | XLSX spreadsheet | |
| Attachment_6_-_OF-306_Form_Declaration_for_Federal_Employment.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Cloud-based Electronic Discovery Statement of Work (SOW)
Project Manager Name Here mm/dd/yyyy
Statement of Work Template v8.1 Cloud-based Electronic Discovery iii
Contents
| 1. | Overview | 1 |
| 1.1. | Introduction | 1 |
| 1.1.1. | Overarching Business Needs Statement | 1 |
| 1.1.2. | Project Goals & Objectives | 1 |
| 1.2. | Background | 1 |
| 1.2.1. | Current On-premise IT Environment | 6 |
| 1.2.2. | Cloud-based IT Environment Concept | 6 |
| 1.3. | Scope | 7 |
| 1.4. | Service Delivery Framework (SDF) | 7 |
| 1.4.1. | Initiation Phase | 8 |
| 1.4.1.1. | SEC Technical Environment | 8 |
| 1.4.2. | Planning Phase | 8 |
| 1.4.3. | Requirements Analysis Phase | 9 |
| 1.4.4. | Design Phase | 9 |
| 1.4.5. | Development Phase | 9 |
| 1.4.6. | Test Phase | 9 |
| 1.4.7. | Implementation Phase | 9 |
| 2. | Task Areas | 9 |
| 2.1. | Task Area 1: Project Management and Planning Requirements | 9 |
| 2.1.1. | Project Status Reporting | 9 |
| 2.1.2. | Project Management Plan | 10 |
| 2.1.3. | Project Schedule | 11 |
| 2.1.4. | Productivity and Performance Reports | 12 |
| 2.1.5. | Quality Assurance and Control Plans | 12 |
| 2.1.6. | Risk Management | 12 |
| 2.1.7. | Kick-Off Meeting | 13 |
| 2.1.8. | Meeting Minutes | 13 |
| 2.1.9. | General Responsibilities | 13 |
| 2.2. | Task Area 2: Requirements Analysis | 13 |
| 2.3. | Task Area 3: System Configuration | 13 |
| 2.3.1. | Proposed Infrastructure | 14 |
| 2.3.2. | Network Architecture | 14 |
| 2.3.3. | Security Architecture | 14 |
| 2.3.4. | Measuring Tools and Procedures | 15 |
| 2.3.5. | Test Planning | 15 |
| 2.3.6. | Requirements Traceability Matrix | 15 |
| 2.4. | Task Area 4: System Administration | 15 |
| 2.4.1. | Standard Operating Procedures | 15 |
| 2.4.1.1. | System Description | 16 |
| 2.4.1.2. | Operations and Maintenance | 16 |
| 2.4.2. | Section 508 Compliance | 16 |
| 2.4.3. | Section 508 Acceptance Criteria | 17 |
| 2.4.4. | System Security Plan | 17 |
| 2.4.4.1. | System Environments | 17 |
| 2.4.4.2. | System Interconnection/Information Sharing | 17 |
| 2.4.4.3. | Minimum Security Controls | 17 |
| 2.4.4.4. | Auditing procedures | 18 |
| 2.4.4.5. | Logging and reporting procedures | 18 |
| 2.4.5. | User Acceptance Testing | 18 |
| 2.4.5.1. | User Acceptance Testing Plan and Schedule | 18 |
| 2.4.5.2. | User Acceptance Testing Results | 19 |
| 2.5. | Task Area 5: Environment Support, Data Loading and e-Production | 19 |
| 2.5.1. | Staging and QCTC (Testing) Environment Support | 19 |
| 2.5.2. | Production Environment Support | 19 |
| 2.5.3. | Receiving Data | 19 |
| 2.5.4. | Loading Data | 20 |
| 2.5.5. | Processing Data | 22 |
| 2.5.6. | Hosting the eD3 System | 23 |
| 2.5.7. | Electronically Producing Data | 24 |
| 2.5.8. | Disposing of Data | 25 |
| 2.6. | Task Area 6: Testing Support | 26 |
| 2.6.1. | General Independent Testing Support Requirements | 26 |
| 2.6.2. | Testing Plan and Schedule | 26 |
| 2.6.3. | Security Issue Review | 26 |
| 2.6.4. | Integration and Regression Testing | 26 |
| 2.6.5. | Quality Control Test Center (QCTC Testing) | 27 |
| 2.6.6. | Security Testing and Authorization | 27 |
| 2.6.7. | Test Analysis Reports | 29 |
| 2.7. | Task Area 7: Training | 29 |
| 2.7.1. | Training Plan | 29 |
| 2.7.2. | Training Classes | 29 |
| 2.7.3. | Training Material | 29 |
| 2.7.4. | Communications Plan | 30 |
| 2.7.5. | Organizational Change Management Plan | 30 |
| 2.8. | Task Area 8: Implementation Support | 30 |
| 2.8.1. | Production Readiness Review | 30 |
| 2.8.2. | Deployment Approval | 30 |
| 2.8.3. | Go-Live Implementation | 30 |
| 2.9. | Task Area 9: System Operations and Disposition | 31 |
| 2.9.1. | Software Updates | 31 |
| 2.9.2. | Technical Support | 31 |
| 2.9.3. | Problem Escalation | 31 |
| 2.9.4. | Software Service Maintenance and Support | 31 |
| 2.9.5. | Application Updates | 31 |
| 2.9.6. | Other Ongoing Activities | 32 |
| 3. | Deliverables | 32 |
| 3.1. | Schedule of Deliverables | 34 |
| 4. | Place and Period of Performance | 39 |
| 4.1. | Place of Performance | 39 |
| 4.2. | Period of Performance | 39 |
| 5. | SEC Policy | 39 |
| 5.1. | SEC Applicable Laws, Regulations, Standards, and Guidelines | 39 |
ii
Tables
Table 1: Schedule of Deliverables 38
1. Overview Introduction The SEC seeks a Cloud-based electronic Discovery pilot system with options to transform it into an Enterprise system. The scope of work is to perform: design, configuration, testing, electronic document discovery (EDD) processing, data and document loading, system administration, creation of electronic productions, pilot system deployment, training, and operational support of the SEC electronic Discovery 3 (eD3) application. The Contractor shall perform the work in accordance with SEC OIT Life Cycle policy, procedures, and documentation requirements, current and future, for the duration of this contract. The eD3 application must be based on a current commercially released software product. The SEC has defined “must have” and “desirable” requirements that have value for the SEC. The eD3 application requirements are contained in Attachment 1 - Requirements Matrix. The scope of work also includes integrating analytical and review functions of the eD3 application with and developing the workflows to enable the SEC to efficiently and effectively gain the most benefit from the eD3 application. If the pilot deployment is successful, the SEC may choose to expand the project to become an SEC enterprise system. All data in the eD3 application will be deleted or returned to the SEC at the end of the contract.
Overarching Business Needs Statement The purpose of this project is for the Division of Enforcement (ENF) to evaluate the cost efficiency, capabilities and performance of electronic discovery software in a cloud-based environment.
· Evaluate how well a cloud-based solution works in comparison with the on-premises system.
· Evaluate processing, loading, e-production and archiving capabilities and workflow.
· Evaluate data transfer to and from a cloud-based solution on incoming and outgoing productions.
· Determine if a cloud-based solution allows movement of investigations between platforms.
Project Goals & Objectives The eD3 cloud-based pilot goals and objectives are:
· Reduced costs of managing and maintaining electronic discovery software and data.
· Improved access to analytic tools for use in the eDiscovery process.
Background The SEC developed and executed an acquisition effort in FY2018 for an eDiscovery cloud-based pilot system. Although there were reasonable and technically acceptable FedRAMP authorized solutions, the SEC determined those solutions proposed did not meet our short and long term business goals to justify the risks and cost. As the market has, and continues to evolve, the SEC believes it is better positioned to make an award in FY2019 and to conduct a successful pilot.
The SEC is an independent Federal agency established pursuant to the Securities Exchange Act of 1934. It is headed by a bipartisan five-member commission consisting of the chairman and four commissioners who are appointed by the President and confirmed by the Senate. The SEC is organized into five main divisions: Corporation Finance; Trading and Markets; Investment Management; Economic and Risk Analysis; and Enforcement. The SEC’s Divisions of Trading and Markets, Investment Management, and Corporation Finance, and the Office of Compliance Investigations and Examinations regulate the securities industry. These organizations collect information during inspections and examinations, and receive filings and other information from regulated entities. Some of the information comes in paper format, which must be imaged and loaded into SEC systems. Most information arrives through electronic media, and may need to be converted or processed before it is loaded into repositories. In some instances documents may be shared with other law enforcement agencies or other external organizations.
The ENF investigation and litigation support work flow process is depicted in the diagram below. In response to subpoenas, ENF receives paper materials and electronic submissions in various forms, including CD's, hard drives, emails and attachments. ENF expects that this work flow will change significantly for the implementation of an eD3 pilot system.
I. Intake Most productions to the Enforcement Division (ENF) are delivered to the Centralized Production Unit (CPU). The SEC receives approximately 3,500 new productions each month totaling 6-7 TB of compressed files. After processing this expands to approximately 10 TB of storage consumed each month. However, 95% of these productions are less than 3 GB in compressed size. Frequently, these are small, rolling productions. About half of the ENF productions are native ESI files, and about half are delivered in delimited text file formats (such as, DAT file with an Opticon cross reference file and page level text files).
Based on the SEC’s email rules, productions up to 10 MB can be sent as attachments to email. Larger productions can be delivered through secure file transfer, or downloaded through secure file transfer from a producing party’s hosted site. Regardless of size, productions can be delivered on external media, including CD, DVD, hard drives, and USB drives. The SEC also receives up to 4 million pages of paper productions each year.
The most common documents the SEC receives are email. Text messages from Bloomberg, instant messaging and other apps are an increasing proportion of documents, and can be received in text file, XML file, and other formats. Documents also are produced to the SEC in PDF format. These PDF files may or may not contain embedded text, and may or may not have endorsed Bates numbers on them. As noted above, roughly half of productions are processed by the producing party before they are sent to ENF, so many image files are loaded into eD2.0 Recommind. Image files, extracted text, Optical Character Recognition (OCR) text, links to native files, and metadata / fielded data are loaded into eD2.0 Recommind.
II. Log Productions and Manage service providers Productions are logged when they are received to establish chain of custody. The SEC is required to produce all documents received when administrative proceedings are litigated, so the production log is a necessary tracking mechanism. By reading the cover letter and examining the format of a production, technicians determine how it should be processed and create requests in the SEC’s Evidence Tracking System (ETS). Workflows in ETS route the requests to the appropriate groups for processing and loading into the eD2.0 system. ETS provides notifications to staff attorneys when productions are received and when productions are available for review and analysis in eD2.0 Recommind. ETS will be used to log and track productions loaded into the eD3 system.
Most native ESI productions can be processed for electronic document discovery (EDD) within eD2.0 Recommind. File types not supported by Recommind are processed using LAW or Nuix software, or may be sent to an outside vendor for processing.
III. Early Case Analysis / Data Analysis The SEC seeks data analysis and visualization features in an eD3 solution. Features that show connections between people and relationships among documents will enable investigative attorneys and examiners to use their time more efficiently. Visualizations should allow staff to look at a broad view of an entire matter, and then focus on areas of interest. Areas of interest may be defined by the people involved, time periods, subject matter, and other criteria either individually or in combination. Dynamic displays in different formats depending on the type of issue being examined would add value. The ability to group/search by concept is necessary, as well as predictive coding/technology assisted review (TAR) functionality, which may include Continuous Active Learning (CAL). The data analysis features should incorporate all types of documents, regardless of whether they were received in a native ESI or a delimited text file production.
IV. Investigative review and producing out There are approximately 600 Recommind users at the SEC Headquarters. Additionally, there are approximately 1,200 Recommind users in eleven SEC Regional Offices nationwide. Approximately 1 petabyte (PB) of electronic documents were stored in eD2.0 Recommind at the end of FY2018. Regional Office staff access eD2.0 Recommind over the SEC wide-area network and through the SEC remote access tools. The current eD2.0 Recommind environment contains over 7,300 cases. Of these matters, about 310 contain over 500,000 documents, and the remainder is smaller. ENF also needs the capability to selectively share, move or copy documents among related matters.
In addition to needing to handle a wide variety of incoming productions, ENF has several exceptions to standard processing and loading. Due to errors, omissions, or other reasons, the SEC receives replacement productions. As the name implies, loading a replacement production must include overwriting or deleting the original production. After loading, the SEC runs independent quality assurance checks. Errors found during the quality assurance process must be corrected, which may include deleting records, reloading documents, loading missed documents, and correcting metadata and fielded data values. Errors or incomplete data can occur in the productions the SEC receives. A common occurrence is for images to be Bates numbered by the producing party, but the Bates numbers are not included in a DAT file or cross reference file. The SEC sends productions to outside vendors to capture the Bates numbers, which are then loaded into Recommind. Similarly, native files can be named by a document level Bates number, which the SEC will have captured and loaded into eD2.0 Recommind. PDF files can be produced as one file for a set of documents. The SEC sends native ESI productions like this to outside vendors to perform logical unitization (logical document determination) to separate bulk files into individual documents and records.
The SEC sends out up to 100 productions per month. The majority of these productions go to other Government law enforcement agencies, and the rest to outside parties. The size of productions varies widely, but averages 2 – 3 TB total per month. Documents received through the Office of International Affairs from foreign regulators usually are excluded from productions. Documents subject to the Bank Secrecy Act must be excluded from productions. Personally identifiable information (PII) may be redacted from productions, or the documents may be produced under a Protective Order from a court. Productions from the SEC are made in native format, imaged format, or a combination of the two, depending on the circumstances. Productions in litigation usually require all documents to be converted to TIFF images and Bates endorsed.
V. Exhibits and Transcripts Exhibits are often created from documents loaded into eD2.0 Recommind. After they have been used in testimony or for depositions, exhibits may be loaded back into eD2.0 Recommind as new records indexed with the exhibit number. Unlike outside productions loaded into eD2.0 Recommind, exhibits become Federal records and records management procedures are applied to them. Exhibits also can be managed as Federal records as loose files outside of eD2.0 Recommind.
Transcripts are loaded into TextMap. A tracking system notifies affected groups when the SEC’s vendor delivers transcripts. They are manually loaded into TextMap.
VI. IT Forensics A small proportion of data is received in Forensic container formats. Some is provided by outside parties, and some from the SEC’s IT Forensics laboratory. An increasing percentage of Forensics collections are from smart phones and mobile devices, compared to the more traditional desktop and laptop computers. The SEC’s IT Forensics laboratory uses CelleBrite as a standard tool for processing cell phone data.
VII. Specialized data processing Staff attorneys and examiners ask for publicly available websites and online videos to be captured and preserved. The SEC currently does this outside of the eD2.0 system. When civil procedures for collecting and preserving social media sites are established, and when commercial tools become available for collecting and preserving information from social media sites, then the SEC would like to be able to include this information in an electronic discovery repository with the capability to produce it out during litigation. The volume and variety of information captured and preserved from websites is expected to increase during the life of the eD3 system. The SEC processed over 3,200 website and video capture requests in the first half of FY2017.
The SEC receives digital audio and video recorded data as part of productions. The SEC defines “documents” broadly to include audio and video recordings. Staff attorneys and examiners would benefit by being able to search, tag, and organize audio and video documents in the same application where they search, tag, and organize email and other text based documents. Audio or video recordings of testimony and depositions also may be received, but are uncommon. The SEC uses Nexidia software for searching audio and video. The SEC processed 36 requests for over 800 hours of audio recordings in the first half of FY2017.
The SEC requests brokerage statements, phone records, and other types of formatted documents for some investigations. PenLink (PLX) and Comprehensive Financial Investigative Solution (CFIS) are used to convert the statements into more usable spreadsheet or database formats. The statements can be provided to the SEC on paper or electronically. The SEC considers the spreadsheets and databases to be work product, and generally will not produce them in litigation, so the spreadsheets and databases need to be easily segregated from the documents they originated from. Staff attorneys and examiners would benefit if the information contained within brokerage statements, phone records, and similar formatted documents could be fed into the same data analysis and visualization tools the SEC hopes to make part of the eD3 solution. The SEC processed over 20,000 statements through CFIS, and 42 requests consisting of over 300,000 pages through PenLink in the first half of FY2017.
The different types of requests shown on the e-Discovery diagram are entered and tracked in the Evidence Tracking System with varying workflows depending on the type of request.
VIII. Backups and Databases The SEC receives copies of databases and installs the databases on segregated SEC servers for some cases. Database evidence is uncommon. Due to the structure of the databases, they are not suitable for processing within a commercial litigation support product. The SEC does not intend to include handling or managing database evidence within the scope of the eD3 solution.
The SEC receives backup tapes on rare occasions. The SEC does not intend to include extracting, searching or restoring documents from backup tapes within the scope of the eD3 solution. Databases and backup tapes are shown on the diagram to give a more complete view of the overall ENF environment, but not to imply these functions should be part of an eD3 solution.
Current On-premise IT Environment The SEC has primary and alternate data centers. The servers and storage in the primary data center are replicated at the alternate site. Recommind Axcelerate runs on virtual servers under VMWare. Recommind Axcelerate software, installed in separate environments for five Divisions and Offices, is used as the standard litigation support software repository, review platform and Early Case Assessment application. Image files, OCR text, links to native files, and metadata / fielded data are loaded into Axcelerate.
The SEC recommends that outside parties deliver encrypted data and provide passwords or keys separately. Data is currently delivered through secure file transfer, attachments to email, and on physical media. The SEC desires to maintain information security and to reduce the need for physical media. In addition to receiving documents, the SEC has produced out 45 TB over the last 15 months. Note that productions for Administrative Proceedings must be delivered within seven days of the date filed. Thus, the SEC must meet tight deadlines for producing out documents, which may include creating and endorsing TIFF images, if they do not already exist.
ENF uses an Evidence Tracking System (ETS) for making requests for paper document imaging, electronic media processing, and data loading services. ETS is used nationwide by ENF and includes management reporting capabilities.
Cloud-based IT Environment Concept The SEC has an Amazon Web Services (AWS) cloud-based operating environment. The SEC refers to this AWS environment as C3. The SEC prefers a solution hosted by AWS to facilitate more rapid and secure data transfer. A conceptual diagram of the future cloud-based eDiscovery environment is:
Scope The Scope of this contract encompasses the following main task areas:
· Task Area 1: Project Management and Planning Requirements
· Task Area 2: Requirements Analysis
· Task Area 3: System Configuration
· Task Area 4: System Administration
· Task Area 5: Data Loading and Electronic Productions
· Task Area 6: Testing Support
· Task Area 7: Training
· Task Area 8: Implementation Support
· Task Area 9: System Operations and Disposition
· Optional Task Area 10: Enterprise Deployment and Training
· Optional Task Area 11: Case Migration
· Optional Task Area 12: Revise System Configurations and Workflow
· Optional Task Area 13: Continuous Monitoring for Cybersecurity Service Delivery Framework (SDF) The SEC Office of Information Technology (OIT) has established the Service Delivery Framework (SDF) to govern the development of new software, installation of Commercial off the Shelf (COTS) software, and Externally Hosted Applications. The SDF employs a risk-based approach to ensuring on-time delivery of IT capabilities to customers. The process focuses on streamlined oversight where project life cycles are tailored based on project scope and complexity. The SEC SDF phases are: Initiation, Planning, Requirements Analysis, Design, Development, Test and Implementation. Progressing from one phase to another is dependent upon SDF Phase Gate reviews and approvals by the relevant approval authority (Technical Review Board [TRB] Chair, Chief Information Officer (CIO) Governance Staff, Enterprise Architecture, etc.).
SEC Service Delivery Framework (SDF) general contractor responsibilities include management and execution of OIT processes needed to deliver the system and related documentation, and make it available through the SEC network.
Initiation Phase The purpose of the Initiation Phase is to start the systems engineering necessary to determine and recommend a solution to solve the problem or capability/gap defined in the business requirements. High-level requirements are needed to understand what the solution is intended to do and how it will support the business needs. An architectural review examines whether the proposed solution potentially duplicates, interferes, contradicts or can leverage another product/project that already exists, or is proposed, under development, or planned for near-term disposition.
1.1.1.1. SEC Technical Environment
The SEC Enterprise Architecture (EA) provides a common basis for understanding and communicating how the target technology will meet SEC strategic objectives. It contains a comprehensive set of architecture documentation providing Information technology (IT) strategic direction, technology roadmaps, standards, and platform guidance. As part of the SEC Initiation, Planning, Requirements Analysis, Design, and Development Phase Gates the Contractor shall collaborate with EA analysis efforts, provide project level architecture documentation, align with a balanced approach to the selection, design, development, deployment, and support of solutions for the enterprise, and comply with the latest published EA standards and policies.
The SEC maintains two major data centers where the infrastructure is comprised of Microsoft Windows 2012 and 2016, Red Hat Linux, and Sun Solaris 10 servers. These data centers have high bandwidth network connectivity for data storage replication and redundancy.
The SEC is developing a FedRAMP-authorized cloud environment using Amazon Web Services (AWS) as the cloud provider. The SEC will develop custom solutions in this C3 cloud environment.
Planning Phase The purpose of the Planning Phase is to plan all processes and activities required to ensure success and to create a comprehensive set of plans to manage the project from this phase until deployment. All facets of the project are analyzed to ensure that the project scope, release milestones and deliverables are feasible and acceptable to stakeholders.
Requirements Analysis Phase The purpose of the Requirements Analysis Phase is to gather, analyze and document use cases and requirements including functional, non-functional, and, if needed, transition.
Design Phase The purpose of the Design Phase is to transform the baselined requirements into comprehensive, logical and detailed designs to efficiently and effectively guide or contract for assembly and coding.
Development Phase The purpose of the Development Phase is to build or configure an acquired solution; create and test databases; prepare test cases and test files; perform unit, system and integration testing; and gain user concurrence of the solution functionality.
Test Phase The purpose of the Independent Test Phase is to demonstrate that the developed solution satisfies infrastructure, functional, performance, Section 508 compliance, and security requirements. Independent testing is performed by user representatives, QCTC staff, and OIT Security. The Contractor is responsible for testing all changes to production adequately. Independent testing is not a substitute for testing performed during software development by the Contractor.
Implementation Phase The purpose of the Implementation Phase is to prepare the production environment, organization, and users for the intended use of the new solution or an upgrade to an existing solution and evaluate whether the solution meets mission need and operational requirements.
2. Task Areas Task Area 1: Project Management and Planning Requirements The Contractor shall utilize best practices in project management to plan all tasks, activities and deliverables. The project management tasks for this project are specified in the sections below.
Project Status Reporting The Contractor shall prepare and deliver written Project Status Reports to the Contracting Officer Representative (COR). The Project Status Report shall include the following: Contractor resource allocation across tasks, work accomplished, project risks, issues that require resolution with expected/needed resolution dates, upcoming activities and milestones, action items with assignees and due dates, and summary of meetings attended. The Contractor shall participate in periodic project status meetings attended by key Contractor personnel, the COR, and other SEC personnel.
The Contractor shall at a minimum meet weekly with the COR to discuss activities, issues, system usage, deliverables, and differences between planned and actual costs. The Contractor shall update the baselined schedule in Microsoft Project in preparation for the weekly meetings. The contractor shall prepare and deliver weekly reports that answer the following questions:
· What is in the pipeline to be processed?
· What was completed since the last report?
· What is delayed, and why is it delayed?
· Which requests are in a follow-up status, and what are the reasons for follow-up?
· What is the actual completion time compared to the service level agreements (by task size and priority)?
The Contractor shall:
· Provide and maintain a roster of all contractor personnel and SEC materials under Contractor control and notify the COR of any additions, deletions or changes within two business days after the change(s).
· Provide the COR with advance notice of any contractor personnel changes at least five business days before the change.
· Assist in developing management reports and analysis, as directed by the COR, for work performed and deliverables under this contract.
The Contractor shall prepare and deliver monthly status reports in accordance with OIT standards. The Contractor shall include the labor category and hours worked by name for all individuals charging work to the project in the monthly status report. The Contractor shall include the actual start date, actual finish date, and actual duration for all active tasks from the project schedule baseline in the monthly status report. The monthly status report also shall address:
· Funding Status
· Cumulative Costs to date (inclusive of labor, materials, travel, and other direct costs)
· Remaining Funds
· Cost Variance (% difference between planned and actuals)
· Actual and Projected Monthly Burn Rate
· Risk Analysis and Mitigation Planning
· Issue Management and Resolution
· Accomplishments
· Upcoming Activities and Milestones
· Other Items as Identified Project Management Plan The Contractor shall develop and deliver a Project Management Plan (PMP). The PMP shall document details on how the project will be managed. The PMP shall address the following topics: cost control, staffing, integrated project team (SEC and Contractor names and roles & responsibilities), communications plan, test plan, risk management, issue management plan (and maintain an issues log – issue, description, recommended resolution, owner, due date), project schedule with activity descriptions, and software release schedule and roadmap. The Contractor shall use the PMP outline and specifications in Attachment 2.
The Contractor shall maintain a Project Notebook (physical and electronic) that stores a copy of the contract, the PMP, monthly status reports, meeting agendas and minutes, project schedule, change request forms, and appropriate project correspondence (e-mails) to efficiently manage the project. Electronic version of the Project Notebook may be maintained on an SEC SharePoint site or a designated file directory. The project notebook must be in a location that is accessible by SEC stakeholders for this project. Contractor shall deliver updates to the issue log each week. The Contractor shall update the Project Notebook with the most recent monthly status report. Contractor shall deliver updates to event-based Project Notebook deliverables (e.g., meeting minutes) within 2 business days of the event.
Project Schedule The Contractor shall develop and deliver a resource-loaded project schedule for the implementation of an eD3 system to meet the requirements stated in Attachment 1 - Requirements Matrix. The SEC will provide a project schedule covering SEC required activities for the Contractor to incorporate into their plan. The Contractor shall estimate the necessary work packages (not more than 80-hour increments of work) with the appropriate Integrated Project Team (IPT) members. The IPT is comprised of members of the contractor staff, ENF Office of Technical Services, Litigation Support branch, OIT Quality Assurance, OIT Cloud working group, OIT Enterprise Architecture, OIT Security, Network Engineering, SEC business sponsor representatives and users as required. The project schedule must incorporate obtaining signoff by the SEC project manager on all life cycle phase reviews. The Contractor shall deliver the project schedule in Microsoft Project format for review and approval by the COR.
The project schedule baseline must include the following information:
· Deliverables and milestones, including software release schedule
· Planned duration for each task
· Project Start and End date
· Description of the task
· Resource loaded tasks
· Task Names
· Predecessors
· Planned Start Date
· Planned Finish Date
· Actual Start
· Actual Finish
· Actual Duration
The Contractor shall review and update the Project Schedule at least weekly and immediately notify the COR of any deviations that may impact milestones and/or delivery dates. The Contractor must comply with OIT PMO templates and standards as well as other direction provided by OIT.
Productivity and Performance Reports Once the eD3 system is in use, the Contractor shall prepare and deliver weekly productivity and performance reports to the Contracting Officer Representative (COR). The productivity reports shall include the following: number of productions loaded, size of productions loaded, timeliness of loading productions, independent quality assurance errors found and their resolution, number of outgoing productions created, size of productions created, and timeliness of outgoing production delivery. Productivity reports shall be detailed by case number down to individual productions. The Contractor shall use ETS and eD3 as sources of data for the productivity reports. Weekly performance reports shall include: number of unique users accessing the system; number of cases hosted, their status and size; maximum number of concurrent users; average and maximum times to retrieve and display documents; average and maximum times to perform searches; and throughput for uploading and downloading productions. Performance reports shall be detailed by case number.
Quality Assurance and Control Plans The Contractor shall develop, implement, and maintain a Quality Assurance Plan that documents specific processes and procedures used to ensure the final products are of the utmost quality and perform each task in full compliance with the SEC’s Quality Assurance processes and procedures. The Contractor shall participate in the preparation and review of the project during the relevant SDF Phase Gate reviews (i.e. Technical Design and Architecture Review, Test Readiness Review, Production Readiness Review).
The Contractor shall develop, implement, and maintain effective Quality Control to ensure they perform services in accordance with this Statement of Work, commonly accepted commercial practices, and the SEC’s high standards of quality. The SEC reserves the right to perform inspections on services provided to the extent deemed necessary to protect the SEC’s interests. The Contractor must control the quality of the services and deliverables and maintain substantiating evidence that services conform to contract quality requirements and furnish such information if requested. The Contractor shall formalize their Quality Control through delivery of a Quality Control Plan that addresses how they will identify, prevent, and ensure non-recurrence of defective services. The Quality Control Plan shall include metrics and thresholds for ensuring the Contractor meets the established quality requirements.
Risk Management The Contractor shall develop and update a Risk and Issue Log that conforms to the OIT PMO SharePoint site standards throughout the lifecycle of the project. The Risk and Issue Log will be located on an ENF SharePoint site. The Contractor shall immediately notify the COR of any major risk/issue to the project and provide recommendation on the mitigation of the risk.
Kick-Off Meeting The Contractor shall provide a kick-off meeting presentation to the COR for review and approval. The Contractor shall facilitate a kick-off meeting with key personnel, the SEC Contracting Officer (CO), the COR, and other identified SEC personnel to introduce project members and their roles and responsibilities, review the SEC “Rules of the Road”, and discuss the project.
Meeting Minutes The Contractor shall provide minutes of meetings to the COR for review and comment, when requested by the COR. Minutes must include information regarding the discussion, decisions made, action items, and next steps. The meeting minutes must be routed to all attendees for review within two days after the meeting. The COR will provide feedback and comments and the Contractor shall incorporate them and provide the final meeting minutes for review and approval.
General Responsibilities The Contractor Project Manager will interact directly with the SEC PM and COR, business and Office of Information Technology teams on a day-to-day basis regarding project activities. The Contractor Project Manager has accountability and ownership for delivery of the project and interfacing directly with SEC personnel including the immediate project team, OIT infrastructure personnel, management, business, etc.
The Contractor Technical Lead will interact directly with the SEC PM and COR, business and information technology teams and contractors on a day-to-day basis regarding project activities. In addition, the technical lead has ownership for leading the technical activities on a daily basis and will directly interface with all SEC individuals needed (not just the SEC COR and/or SEC Project Manager). Moreover, the technical lead is accountable for leading the work associated with the SDF technical forums and activities including communicating, providing input, presenting and any relevant activities that are needed.
The Contractor is responsible for overall accountability and ownership of project delivery.
Task Area 2: Requirements Analysis The Contractor shall ensure that requirements analysis is completed with a clear understanding of the functional and non-functional requirements. The Project Manager and COR must approve a baselined Business Requirements Document (BRD) based on Attachment 1, Requirements Matrix. The purpose of the BRD is to confirm a mutual understanding of the requirements between the Contractor and the SEC.
Task Area 3: System Configuration The Contractor shall design the system to conform to the SEC Enterprise Architecture and OIT Cloud strategy. The Contractor shall deliver a draft Detailed Architecture Design (DAD) to the COR for review. All human and network interfaces between the SEC and the Contractor’s cloud-based eD3 system will be described in the DAD. The Contractor shall incorporate feedback from the TRB Technical Design Review and shall prepare and deliver the final DAD to the COR for review and approval. This process may require multiple submittals, reviews and resubmittals. The Contractor shall present the design to the SEC TRB, CIO Governance Staff (CGS) and SEC Enterprise Architecture. The Contractor shall submit the DAD and TRB presentation to the TRB in advance of the scheduled TRB, complete TRB meeting action items, and obtain approval by the TRB Design Review as baseline architecture for the solution prior. As a means to completing the initial DAD, and ensuring it is comprehensive, the Contractor shall accomplish the tasks specified in the sub-sections below.
Proposed Infrastructure and Cloud Architecture The Contractor shall develop a proposed infrastructure that describes the technology to be used, including third party tools. The Contractor shall propose any infrastructure the SEC needs to have in order to connect to and use the Contractor’s cloud-based eD3 solution. The SEC uses the NIST Special Publication 800-145 definition of cloud computing. The Contractor shall propose an eD3 solution that meets the essential characteristics of: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service.
The SEC will use the pilot to evaluate multiple approaches to storing and transferring data for electronic discovery. The Contractor shall develop solutions that can use: the Contractor’s cloud-based storage; a third party cloud-based data transfer utility, like Accellion or BOX.com; or the SEC C3 AWS storage. All cloud-based components must be FedRAMP authorized or covered by an SEC issued Authority to Operate (ATO). The SEC will test whether cloud peer data storage and transfer is feasible and cost effective.
The Contractor shall include in the proposed solution only components that are FedRAMP authorized, or have a completed third party assessment (3PAO) and Readiness Assessment Report (RAR). The Readiness Assessment Report is also known as a Security Assessment Report (SAR).
The Contractor shall achieve FedRAMP authorization for a moderate risk system handling moderate sensitivity data for its cloud-based solution. The SEC strongly prefers a solution that has already received FedRAMP authorization in order to meet the schedule requirement of gaining an Authority To Operate (ATO) from the SEC within six months of contract award.
Network Architecture The Contractor shall provide a detailed description of the network architecture. The description shall include potential impacts to the Enterprise-wide network infrastructure and architecture and operational management. The network architecture portion of the DAD shall contain an outline of how the cloud-based solution interfaces with the network infrastructure and/or systems. The Contractor shall ensure the proposed solution integrates with existing solutions in the SEC Current Technical Architecture.
If approved by the COR, as an option the Contractor shall provide the SEC with the capability to use virtual workstations within the Contractor’s cloud environment. The SEC staff will use the virtual workstations to connect to the eD3 review system.
Security Architecture The Contractor shall support the process to determine the security classification and ensure it is properly documented in the Detailed Architecture Design (DAD) according to the levels for Confidentiality, Integrity and Availability. The Contractor shall ensure the Threat Mitigation Plan, located in section 9.2 of the DAD template, describes the controls in the application that address vulnerabilities such as those identified in the “Open Web Application Security Project (OWASP) Top Ten Vulnerabilities” (OWASP Top Ten Project) and those described in the attached DAD template. The Contractor shall provide its FedRAMP System Security Plan, Third Party Assessment (3PAO), Readiness Assessment Report (RAR), and Plan of Actions and Milestones (POA&M) along with an Infrastructure and Network Security summary.
The SEC will use the pilot to evaluate multiple approaches to identity and access management. The Contractor shall develop solutions that can use: the Contractor’s cloud-based access control system; a third party cloud-based identity management utility, like OKTA.com; or the SEC Active Directory system. All cloud-based components must be FedRAMP authorized or covered by an SEC issued Authority to Operate (ATO). The SEC will test to determine which solution is most feasible and cost effective.
There are multiple paths to obtaining an ATO that is sufficient to allow use of a cloud solution by the SEC. However, the LOE, cost, and time to achieve an ATO will vary dramatically depending on what currently exists. The cost to achieving an ATO can be incurred by the CSP, the Agency, or both. In addition to obtaining an ATO, the Contractor shall maintain the ATO.
Measuring Tools and Procedures The Contractor shall propose the processes, services, applications, and servers to be monitored. The Contractor shall propose how cloud-based resource consumption will be measured and reported on. The Contractor shall propose how service level delivery will be measured and reported on. The COR will review the Contractor’s measuring and monitoring proposals and provide feedback.
Test Planning The Contractor shall develop and deliver a Testing Plan and Schedule for the solution prior to scheduled TRB Design and Architecture Review.
Requirements Traceability Matrix The Contractor shall provide an updated RTM based on comments from the COR.
Task Area 4: System Administration The Contractor shall configure the solution based upon the approved design. The Contractor shall draft Standard Operating Procedures (SOP) and System Security Plan (SSP) prior to the SDF Test Readiness Review. Should the pilot cloud-based system differ from the approved design the SEC PM and COR shall be notified immediately with justification of the reason(s) for the deviation. Deviation from the approved design may require additional approvals from the TRB. The administration tasks for this project are specified in the sections below.
The Contractor shall provide the SEC technical staff with the ability to remotely manage processing and system administration functions in the eD3 system, as well as the option to utilize Contractor personnel to do so at the SEC’s discretion.
Standard Operating Procedures Following the approval of the Design, the Contractor shall work with the Project Manager and COR to determine if there is an appropriate SOP template available in the Service Delivery Framework Process Asset Library. If not, the Contractor shall propose a template based on its experience hosting electronic discovery and review systems. The Contractor shall build upon the DAD to deliver a draft SOP to the COR for review.
The Contractor shall incorporate feedback following User Acceptance Testing (UAT). The Contractor shall prepare and deliver the final SOP to the Project Manager and COR for review and approval. The Contractor shall ensure the SOP contains Stage and Production Environment information. This process may require multiple submittals, reviews and resubmittals. As a means to completing the initial SOP, and ensuring it is comprehensive, the Contractor shall accomplish the subtasks below.
2.1.1.1. System Description
The Contractor shall complete relevant sub-sections of the SOP System Description that conform to the designed solution. This could include Desktop Requirements, Network Requirements, System Configuration, System Monitoring, Data Uploading, Data Production, Case Archiving, and Deployment Strategy.
2.1.1.2. Operations and Maintenance
The Contractor shall complete relevant sub-sections of the SOP Operation and Maintenance that conform to the designed solution. This could include OIT Service Desk Requirements, Product System Interfaces, Software Maintenance Requirements/Procedures, Directory Structure, and Storage Requirements.
Section 508 Compliance Software Development deliverables must meet applicable accessibility requirements and shall not adversely affect features of existing OIT technologies. Software Development deliverables will be tested by the SEC’s QCTC testers using both manual and automated testing processes, and will not be approved to deploy to production if they do not meet the required technical standards. All accessibility issues shall be resolved by the Contractor prior to deployment to the production environment, if possible. Should 508 compliance issues remain that cannot be resolved prior to deployment, the Contractor shall coordinate with the SEC PM or COR to request a waiver with a thorough justification of why 508 compliance issues cannot be resolved and provide a detailed remediation plan with commitments that the issues will be resolved including the timeframe expected.
Contractor staff identified to provide electronic document support services must be experienced with accessible document procedural formatting techniques and be able to produce accessible documents including but not limited to the following formats: Word; PDF; PowerPoint; and/or Excel. Instructions for accessibility practices are found at the following link: Accessibility.
All Contractor’s products and/or services shall comply with all applicable provisions of the standards issued by the Architectural and Transportation Barriers Compliance Board (Access Board): (Link); the Web Content Accessibility Guidelines (WCAG) 2.0 Level AA standards (Standards); and be compatible with assistive technologies (e.g. zoom text, screen reader or voice recognition software) to ensure the accessible use of Federal Information and Communication Technology (ICT) for all individuals with disabilities.
All contract e-deliverables must be accessible under the specified applicable Section 508 technical requirements (1194.22, 1194.31, 1194.41). Documentation (e.g., user manuals, reports, training guides, outreach materials, online tutorials) shall be readable using assistive technologies (e.g., zoom text, screen reader or voice recognition software). All embedded charts, graphs, tables, pictures, etc.; within the supporting documents shall be accessible and understandable using tools such as a screen reader or voice recognition software.
To view the entire text and for more information on 36 CFR Part 1194, go to: 1194, and for 48 CFR Subpart 39.2, go to: 39.2.
Section 508 Acceptance Criteria Software Development or COTS deliverables resulting from this contract will be accepted based on satisfaction of Section 508 requirements for accessibility. All software deliverables must include a completed Government Product/Service Accessibility Template (GPAT) obtained via http://www.buyaccessible.gov/ (an example is provided as an attachment).
System Security Plan Following the approval of the Design, the Contractor shall work with the Project Manager and COR to augment the Contractor’s FedRAMP SSP with controls required to have a complete set of controls for the Contractor’s eD3 solution connected to the SEC environment. The Contractor shall build upon the DAD to deliver a draft SSP to the COR for review. The Contractor shall prepare the SSP in accordance with the NIST SP 800-171 standard. This will be determined by the level of risk to the SEC Enterprise for a moderate sensitivity and moderate impact system.
The Contractor shall incorporate feedback following UAT. The Contractor shall prepare and deliver the final SSP to the Project Manager and COR for review and approval. This process may require multiple submittals, reviews and resubmittals. As a means to completing the initial SSP, and ensuring it is comprehensive, the Contractor shall accomplish the subtasks below.
2.1.1.3. System Environments
The Contractor shall complete relevant sub-sections of the SSP Environments that conform to the designed solution. This could include Hardware, Software, System Boundary, Description, Ports/Protocols/Services, and System Diagram.
2.1.1.4. System Interconnection/Information Sharing
The Contractor shall complete relevant sub-sections of the SSP System Interconnections/Information Sharing that conform to the designed solution. As needed, the Contractor shall indicate to which information systems the developed solution connects.
2.1.1.5. Minimum Security Controls
The Contractor shall complete the SSP Minimum Security Controls that conform to the designed solution. The Contractor shall indicate if any controls are inherited from another system. The Contractor shall indicate if any controls are not implemented.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.