CTaRRS_--_63000-16-0324_--_RFQ.pdf

PDF 897 KB Posted

Attached to
Case Tracking and Records Retention System (CTaRRS) Software Federal contract opportunity
Solicitation number
63000-16-0324
Issued by
Securities and Exchange Commission

View the file

Other files for this federal contract opportunity

Other files attached to Case Tracking and Records Retention System (CTaRRS) Software, newest first.
File Type Posted
CTaRRS_--_Questions_and_Answers.pdf PDF
Attachment_6_-_NDA_-_Contractor_Personnel.docx DOCX document
Attachment_3_-_Credit_Release_Authorization.pdf PDF
Attachment_2_-_Contractor_Data_Form.pdf PDF
Attachment_4_-_Declaration_of_Federal_Employment__OF-0306.pdf PDF
Attachment_5_-_NDA_-_Contractor.docx DOCX document
Attachment_1_-_GPAT.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION (SEC)

Office of Acquisitions 100 F. Street NE

Washington, D.C. 20549

Section A This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6, as supplemented with additional information included in this notice. This Request for Quotations (RFQ) under FAR Parts 12 and 13 constitutes the only solicitation and a written solicitation will not be issued.

Date of publication: Thursday, July 14, 2016

RFQ #: 63000-16-0324 is being issued for Case Tracking and Records Retention System (CTaRRS) software.

The RFQ document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular (FAC) 2005-88.

Points of Contact (POC):

Ricky Mills (CO) 100 F. Street NE Washington, D.C. 20549

(202) 551-6636 millsr@sec.gov

Nick Chung (CO) 100 F. Street NE Washington, D.C. 20549

(202) 551-4057 chungnic@sec.gov

All contacts after the RFQ publication (i.e. pre-award), MUST be with contracting officer (CO) Ricky Mills or contracting officer (CO) Nick Chung only. Any contact with other SEC employees in regards to this specific RFQ is improper and may result in exclusion of the vendor from consideration of an award. The designated COR will be the primary day-to-day point of contact (POC) after award. The CO will be the POC for contract administration questions.

Place of Performance (services) or Delivery Location (supplies):

Securities and Exchange Commission 100 F. Street NE Washington, D.C. 20549

Period of Performance (PoP) estimate: 1 year base (Licenses Purchase; Installation/Implementation/Deployment) and up to 4 one-year Option periods (Licenses Maintenance , Additional Software Licenses, and Enhancement/Professional Services).

NAICS Code: 511210 -- Software Publishers -- $38.5 million

Product Service Code (PSC)/Federal Supply Code (FSC): 7030 -- ADP Software.

Anticipated Contract Type: The Purchase Order (PO) is anticipated to be a hybrid Firm Fixed Price and Labor Hour. Please see anticipated CLIN structure in Section B.

System for Award Management (SAM) Registration: All interested parties MUST be registered in the SAM at the time of award. Not being registered in SAM at the time of award will be cause for the vendor to be considered ineligible for award, and no further consideration will be given. If you are not registered with SAM, you may register online at http://www.sam.gov.

Please verify that your SAM account is “active” before quote submittal.

Section B Anticipated CLIN Structure:

CLIN # Description Anticipated CLIN Type

00001 Requirements Validation and Planning.* Labor Hour

00002 Initial Commercially available off-the-shelf (COTS) Software License Purchase (i.e. Licenses needed to complete the SDLC process) **

Firm Fixed Price

00003 Installation/Implementation Support (i.e. SDLC process, configuration, customization (if applicable), etc.) ***

Labor Hour

00004 Option - Deployed COTS Software License Purchase (Production) ** Firm Fixed Price 00005 Option - Training Labor Hour

Option Year 1 00006 Maintenance and Support for Existing Licenses Firm Fixed Price 00007 Additional Software Licenses Firm Fixed Price 00008 Enhancements/Professional Services Labor Hour

Option Year 2 00009 Maintenance and Support for Existing Licenses Firm Fixed Price 00010 Additional Software Licenses Firm Fixed Price 00011 Enhancements/Professional Services Labor Hour

Option Year 3 00012 Maintenance and Support for Existing Licenses Firm Fixed Price 00013 Additional Software Licenses Firm Fixed Price 00014 Enhancements/Professional Services Labor Hour

Option Year 4 00015 Maintenance and Support for Existing Licenses Firm Fixed Price 00016 Additional Software Licenses Firm Fixed Price 00017 Enhancements/Professional Services Labor Hour

* Requirements Validation and Planning. This task is part of the SEC SDLC process; however, it’s included as a separate CLIN in order to comply with SEC accounting requirements.

** Licenses. A limited number of licenses (approximately 1-5) will be needed to go through the SEC System Development Life Cycle (SDLC) process. CLIN 00002, the initial licenses, may be invoiced for SDLC purposes when the SDLC process begins.

If the software is successfully installed and deployed at the conclusion of the SDLC process, then CLIN 00004 will be exercised and production licenses will be deployed, and may be invoiced once the term of those licenses begins (see CLIN 00004).

*** Installation/Implementation Support. Award funding amounts for the Installation/Implementation support

(i.e. SDLC process) of the software are estimates and funding may be incrementally increased (if necessary) until the software is fully deployed and the SDLC process is completed. Other labor categories may also be added post award (if necessary) to complete the SDLC process.

http://www.sam.gov/

Section C

U.S. Securities & Exchange Commission Office of the General Counsel

Case Tracking and Records Retention System (CTaRRS)

Statement of Work (SOW)

Table of Contents

C.1 OBJECTIVE

C.2 SCOPE

C.2.1 Background General Litigation Appellate Adjudication Legal Policy

C.2.2 System Capabilities and Objectives Business Objectives Non-Functional Objectives

C.3 SEC ENVIRONMENTS AND INFRASTRUCTURE

C.3.1 SEC Technical Environments C.3.2 SEC End-User Technical Resources

C.4 APPLICABLE DOCUMENTS

C.4.1 Federal Requirements and Industry Standards C.4.2 SEC Administrative Regulations C.4.3 OIT Information Security Policies C.4.4 Office of Information Technology (OIT) Policies and Procedures C.4.5 SEC System Development Life Cycle (SDLC) Process

C.5 SDLC REQUIREMENTS

C.5.1 Requirements Development

C.5.1.1 Requirement Elicitation and Documentation C.5.1.2 Requirement Traceability Matrix C.5.1.3 Requirement Acceptance (Validation and Verification) C.5.1.4 Compliance Requirements C.5.1.5 Technical Requirements C.5.1.6 Implementation Requirements C.5.1.7 Security Requirements C.5.1.8 Reporting Requirements

C.5.2 Project Management C.5.2.1 Resources C.5.2.2 Project Plans C.5.2.3 Status Reports C.5.2.4 Project Meetings C.5.2.5 Risk Management C.5.2.6 Key Personnel

C.5.3 System Design C.5.3.1 Technical Architecture Design C.5.3.2 Database Design C.5.3.3 Common Components and External Interfaces

C.5.4 Systems Integration, Configuration, and Development C.5.4.1 Integration C.5.4.2 Interface Specifications C.5.4.3 Physical and Logical Database Specification C.5.4.4 Product Customization C.5.4.5 Data Migration and Application Transition

C.5.5 Environment Support C.5.5.1 Development Environment Support C.5.5.2 QCTC Environment Support C.5.5.3 Staging Environment Support C.5.5.4 Production Environment Support C.5.5.5 Disaster Recovery (DR) Environment Support C.5.5.6 Promotion to QCTC and Staging Environments

C.5.6 Testing Support

C.5.6.1 General Testing Requirements C.5.6.2 Testing Plan and Schedule C.5.6.3 Security Issue Review C.5.6.4 Functional and Regression Testing C.5.6.5 Pre Production Environment (PPE) Testing C.5.6.6 Quality Control Test Center (QCTC Testing) C.5.6.8 User Acceptance Testing (UAT) C.5.6.9 Section 508 Acceptance Criteria C.5.6.10 Test Results and Analysis Reports

C.5.7 Training C.5.7.1 General User Training C.5.7.2 Online/Web Based Training C.5.7.3 Administrator Training

C.5.8 Deployment Support C.5.8.1 Implementation Plan C.5.8.2 Production Readiness Review C.5.8.3 Pre-deployment Implementation Plan Review C.5.8.4 Deployment Approval C.5.8.5 Go-Live Implementation

C.5.9 System Operations and Maintenance Support C.5.9.1 Annual Maintenance and Technical Support C.5.9.2 Software Service Maintenance and Support C.5.9.3 Application Updates

C.5.10 Communications and Change Management Plan

C.6 DELIVERABLES AND SCHEDULE

APPENDIX A: BUSINESS/FUNCTIONAL OBJECTIVES

APPENDIX B: NON-FUNCTIONAL OBJECTIVES

APPENDIX C: APPLICABLE STANDARDS, REGULATIONS, AND POLICIES

1. Federal Requirements and Industry Standards

2. SEC Administrative Regulations

3. SEC OIT Information Security

4. Office of Information Technology (OIT) Policies and Procedures

APPENDIX D: SEC TECHNOLOGY BRICKS

APPENDIX E: SEC SYSTEM DEVELOPMENT LIFE CYCLE (SDLC) PROCESS

1. Planning Phase

2. Design Phase

3. Development Phase

4. Testing Phase

5. Deployment Phase

6. Operations and Maintenance (O&M) Phase

TERMS AND ACRONYMS

C.1 Objective.

The SEC’s Office of the General Counsel (OGC) seeks to procure and implement a user friendly, scalable, off-the-shelf Legal Case Tracking and Record Retention System (CTaRRS) to electronically manage each OGC case through its lifecycle in a centralized location.1 This system will serve primarily as a case tracking system, but will also include basic document repository and records management functionality for files and records2 related to cases in the system. The SEC seeks an SEC-hosted solution, and will not consider solutions that are externally hosted, cloud based, or use a Software-as-a-Service (SaaS) model. The system is expected to provide the following benefits:

• Improved case creation and tracking.

• Improved visibility of cases and workloads across all OGC functions/groups via a single system.

• Improved ability to store and manage OGC case documents, files, and records in electronic format.

• Improved ability to identify, track, preserve, and dispose of OGC electronic records in accordance with applicable records retention schedules.

• Improved efficiency in information retrieval and sharing with internal and external requesters.

C.2 Scope.

The SEC is seeking an off-the-shelf solution for a Legal Case Tracking and Record Retention System (CTaRRS) that will support the business requirements of the OGC’s litigation groups (General Litigation, Appellate, and Adjudication). It is the agency’s desire to obtain needed functionality with “out-of-the-box” capabilities and configuration to the maximum extent possible, with minimum customization, if any, being a last resort. While the initial phase of this effort will be focused on the needs of OGC’s litigation groups, the acquired system must be flexible and scalable to accommodate other OGC groups and other SEC Offices and Divisions, should the SEC decide to expand the use of the system in future phases.

The desired CTaRRS solution is primarily intended for case management to organize, track, and provide search and reporting capabilities for cases handled by OGC. Each case will be categorized by case type, and the types of cases will be associated with applicable records retention schedules. The system will also serve as a file repository for each case, and the system should be able to organize all of the information in a given case by type, date, and other applicable fields. Each case must contain various other identifiers in addition to case type by which the case can be searched and organized, and which will serve as the means by which to run reports.

C.2.1 Background.

The General Counsel is the chief legal officer of the SEC and heads OGC. OGC provides a variety of legal services to the SEC and staff, and is divided into four groups: General Litigation, Appellate, Adjudication, and Legal Policy. OGC prepares all of the SEC’s appellate and amicus briefs; litigates all non-enforcement matters on behalf of the agency; assists in preparing the SEC’s opinions on appeal from administrative law judges, stock exchanges, the National Association of Securities Dealers (NASD), and the Public Company Accounting Oversight Board; and provides legal advice and counseling concerning the federal securities laws, administrative laws, and other laws that affect independent agencies. In terms of functional practice, OGC is split into two main functions: litigation and advice.

1 For purposes of this Statement of Work, the term “case” includes all litigation and non-litigation matters, projects, and assignments handled by staff.

2 For purposes of this Statement of Work, the term “file” includes documents, emails, work products, images, artifacts, and other items associated with a case in CTaRRS. A “record” is any type of file to which a record retention schedule has been applied, either automatically or manually.

OGC does not currently use a case tracking system. Each group within OGC uses a combination of MS Outlook, MS Word, MS Excel, MS Access, SharePoint, and other tools to organize and track its cases.

The information tracked by each group varies depending on the legal area of expertise. A summarized profile of each of the groups is provided below.

General Litigation The OGC General Litigation Group represents the SEC, its members, and its employees at the trial and appellate levels. Along with the federal securities law questions, these cases often involve issues arising under a variety of federal administrative statutes, such as the Administrative Procedure Act, Freedom of Information Act, and the Right to Financial Privacy Act, or the performance of the SEC’s official functions. In addition, the General Litigation Group litigates administrative disciplinary proceedings against attorneys under Rule 102(e) of the SEC’s Rules of Practice. These cases involve allegations that an attorney has violated the federal securities laws or breached his or her professional responsibilities in practicing before the SEC. The General Litigation group provides legal advice and guidance to SEC offices and divisions on operational and general law issues that arise in the performance of their work.

Appellate The OGC Appellate Group represents the SEC in litigation to which it is a party in the Federal Court of Appeals and (in conjunction with the Solicitor General) in the U.S. Supreme Court. For the most part, these cases involve appeals from the SEC, injunctive actions, and petitions seeking review of the SEC’s administrative orders. In addition, the group represents the SEC as amicus curiae in private litigation raising important issues under federal securities laws. The Appellate Group is also responsible for representing the SEC in proceedings under Chapter 11 of the Bankruptcy Code, in cases involving companies with a significant number of public security holders and raising issues of significance.

Adjudication The OGC Adjudication Group advises and assists the SEC when it publishes opinions during contested appeals. The SEC's opinions guide the securities industry on questions of law. Adjudication attorneys advise the SEC on complex factual and legal issues, study the evidentiary records on appeals, and research the relevant substantive and procedural requirements. Appeals challenge decisions made by administrative law judges, stock exchanges, the NASD, and the Public Company Accounting Oversight Board. Many cases involve disciplinary actions against brokerage firms and other securities professionals.

Legal Policy3 The OGC Legal Policy Group provides legal analysis, policy analysis, and advice to the SEC, individual Commissioners, and the SEC’s divisions and offices. This analysis and advice is specifically concerned with federal securities laws, administrative laws, and other applicable laws. The Legal Policy Group analyzes all enforcement and regulatory recommendations to the SEC from operating divisions and offices. In addition, the Legal Policy Group provides legal and policy assistance on legislative matters, prepares testimony, participates in briefings of Congressional staff, and responds to Congressional correspondence.

C.2.2 System Capabilities and Objectives.

The CTaRRS system shall be internally hosted, operated and maintained onsite at the SEC and its data centers.

The solution shall be compatible with the current SEC Enterprise environment. The system shall have sufficient

3 Information on the Legal Policy Group is provided for background purposes only, as the CTaRRS solution is not anticipated to be implemented for this group in the initial Phase I implementation.

capacity to meet at a minimum all business, functional and performance requirements specified in this statement of work.

The SEC Office of Information Technology (OIT) requires professional Information Technology (IT) services to plan, design, develop, implement, and maintain the provided solution. The contractor shall also provide OIT with full solution implementation and support services during the Software Development Life-Cycle (SDLC). This support includes but is not limited to: requirements analysis, verification and finalization; system design (if applicable); product customization (if any), installation and configuration; system integration; upgrade/bug fix;

data migration; data integration; compliance documentation support; report development; user training; test planning and execution; test metrics; system deployment and validation in the staging, testing and production environments; documentation and knowledge transfer, as needed; and ongoing software maintenance and technical support for the implemented system.

The Contractor will be responsible for ensuring the provided solution is implemented in accordance with SEC enterprise environment guidelines for: design and coding standards (if applicable), testing methodology, documentation, maintainability, scalability, performance, reliability, and security. The Contractor will also conduct modeling and prototyping sessions to verify the content and the successful implementation of each release or development iteration.

Each task shall be completed in accordance with the prioritization schedule. The prioritization schedule shall be determined and agreed upon by the business stakeholders and the OIT.

The solution must include the following features:

1. Case Management: The primary purpose of this system is to help OGC track and provide reporting on its cases. The proposed system must contain flexible and easily configurable functionality associated with this purpose. Users must have the ability to open, modify, assign, and close a case. Approximately 30 case types are anticipated to be used in CTaRRS by the litigation groups of OGC.

2. Document Management: The proposed system must include core document management capabilities (such as batch file upload,4 document storage, document tracking, document security, indexing for search, metadata, and document retrieval).

3. Search Capabilities: The proposed system must allow users to easily search and retrieve files, cases, and other relevant information contained in the system using all available field identifiers (such as case type, employee assigned, date, case number, and case name), metadata, and other attributes. In addition, the system must be able to perform full text search on case, folder, and file content.

4. Records Management and Retention: The proposed system must include the ability to designate files and cases as federal records subject to a particular records retention schedule. The system must also support the SEC in meeting obligations for managing, retaining, and disposing of federal records contained in the system.

5. Reporting Capability: The proposed system must be able to generate reports based on user-specific requirements, from a variety of sources internal to the system. Reports must be standardized for general use (e.g., all cases for the fiscal year, by case type, etc.). The system must also enable users to create and save custom/ad hoc reports.

4 As used in this solicitation, the term “upload” means adding or associating files to a case within CTaRRS, and includes mechanisms such as linking or pointing to such files by the system.

6. Compatibility: The proposed system must be compatible with and/or leverage relevant SEC-supported technology platform components as provided in this SOW, including Microsoft Office, Windows OS, remote access technologies, web browsers, and Active Directory.

7. User Capacity: The estimated number of total users for Phase I (General Litigation, Appellate, and Adjudication groups within OGC) for the CTaRRS solution is approximately 130. The number of concurrent users is expected to be approximately 115, where “concurrent users” means users accessing the application at the same time, but not necessarily performing the same function concurrently. Any implementation of the CTaRRS solution for additional groups beyond Phase I would further increase the number of total and concurrent users. The total number of users and concurrent users within each user group may increase by approximately 5% per year.

Please refer to the additional, detailed objectives provided in Appendices A and B. The requirements in Section C.2.2 and in Appendices A and B will be validated and decomposed during the design and configuration of the new system.

Business Objectives

For detailed business (functional) objectives, please see Appendix A.

Non-Functional Objectives

For detailed non-functional objectives, please see Appendix B.

C.3 SEC Environments and Infrastructure

The SEC operates IT in four different environments: Development, Quality Control Testing Center (QCTC), Staging (or pre‐production), and Production. SEC’s Integrated Support Services (ISS) configures and controls the Development, Staging and Production environments. The OIT Configuration Management and Quality Assurance Branch (CMQA) operates the QCTC environment for application functional testing, accessibility testing, usability testing, load and stress testing, hosting of security testing and hosting of user acceptance testing. The SEC uses the Staging environment for testing compatibility with the SEC infrastructure.

C.3.1 SEC Technical Environments

The SEC Enterprise Architecture (EA) provides a common basis for understanding and communicating how the target technology is structured to meet SEC strategic objectives. It contains a comprehensive set of architecture documentation providing Information Technology (IT) strategic direction, technology roadmaps, standards, and platform guidance. As part of the SEC planning, requirements, and system development life cycles, the Contractor shall collaborate with EA analysis efforts related to the proposed CTaRRS solution, provide project level architecture documentation, align with a balanced approach to the selection, design, development, deployment, and support of solutions for the enterprise, and comply with the latest published EA standards and policies.

The proposed CTaRRS solution must be compatible with and capable of integration into the SEC’s OIT Enterprise Architecture (EA) using industry standards and SEC approved products. For details please refer to SEC Technology Bricks on Appendix D. The SEC data center infrastructure is comprised of Microsoft Windows 2012 and Red Hat Linux servers. These servers are hosted on dedicated server hardware (Intel) or Virtual Servers (VMware ESX) at two major data centers. These data centers have high bandwidth network connectivity for data storage replication and redundancy. The business applications used by SEC require high availability with fault tolerance and disaster recovery capability to meet the Recover Time Objective (RTO) of four hours or less.

C.3.2 SEC End-User Technical Resources.

All OGC end users have laptop or desktop computers with the following configuration:

• Applications:

o Microsoft Office 2010 (an upgrade to 2013 is planned).

o Adobe Acrobat XI Professional.

• Operating System:

o Microsoft Windows 7.

• Web Browser:

o Internet Explorer 11.

o Chrome.

The proposed CTaRRS solution shall support deployment in both virtual and traditional desktop environments.

The system shall support a non-persistent environment and shall work with non-local administrative permissions settings with User Access Controls (UAC) enabled.

C.4 Applicable Documents.

The Contractor shall adhere to and comply with all applicable standards, regulations, and policies and any updates, changes, or amendments thereto.

C.4.1 Federal Requirements and Industry Standards.

Please see Appendix C for Federal Requirements and Industry Standards.

C.4.2 SEC Administrative Regulations.

Please see Appendix C for SEC Administrative Regulations.

C.4.3 OIT Information Security Policies.

Please see Appendix C for SEC OIT Information Security Guidelines.

C.4.4 Office of Information Technology (OIT) Policies and Procedures.

Please see Appendix C for SEC OIT Project Controls.

C.4.5 SEC System Development Life Cycle (SDLC) Process

Please see Appendix E for SEC System Development Life Cycle (SDLC) Process

C.5 SDLC Requirements.

C.5.1 Requirements Development.

The SEC has provided system requirements and functional and non-functional objectives in Section C.2.2 and Appendix A and Appendix B. The Contractor shall validate and decompose the requirements, as needed, to identify and detail the specifics required for design/configuration of the modules, components, interfaces, reports, user interface flows and mockups. Extensions that need to be developed shall be analyzed in order to define all information required for system design (if applicable).

C.5.1.1 Requirement Elicitation and Documentation.

The Contractor shall use knowledge of industry standards and best practices to develop and deliver a Functional Requirements Document for the CTaRRS, consistent with the requirements in this statement of work. The Functional Requirements Document shall be provided to the COR for review and comments. The Contractor shall incorporate feedback from the COR and deliver a final version to the COR for review and approval.

C.5.1.2 Requirement Traceability Matrix.

The Contractor shall develop and maintain the RTM in a manageable format, such as MS Excel, or a requirements management tool, that identifies all baseline requirements and artifacts captured during requirements gathering. The purpose of the RTM is to provide visibility into the current set of working requirements and any interdependencies among requirements and artifacts. The RTM shall include, minimally, the requirement ID, the requirement category, requirement type, and review status. The RTM shall reflect relationships among the requirements, comments gathered for the requirement during interviews, and the project phase in which the requirement is planned to be implemented (if applicable).

The RTM shall be maintained as the repository of up‐to‐date requirements information. The Contractor shall incorporate feedback from the COR into the RTM. The requirements shall be tracked and managed beyond deployment into production, through User Acceptance of the system to verify that all operational and functional requirements have been successfully captured and implemented.

C.5.1.3 Requirement Acceptance (Validation and Verification)

The Contractor shall utilize an iterative methodology to maintain agreement with all stakeholders as requirements are elicited and modeled. The Contractor must have the ability to explicitly describe and communicate requirements as a necessary precondition for validating requirements and resolving conflicts (such as divergent goals among stakeholders). The Contractor shall prepare User Acceptance Test (UAT) scripts in support of each system requirement. Test scripts shall be maintained in a tracking system/commercially available requirement gathering tool for review and approval by the

COR.

C.5.1.4 Compliance Requirements.

C.5.1.4.1 OIT Policies and Procedures.

The Contractor shall conform to SEC administrative regulations, policies, and procedures. See Appendix C section 4. The Contractor shall work with SEC internal organizations as needed to ensure that policies, procedures, configuration control, and product life-cycle requirements are fulfilled to the satisfaction of the SEC Office of Information Technology (OIT).

C.5.1.4.2 Section 508 Accessibility.

The Contractor’s products and services must comply with all applicable provisions of the standards issued by the Architectural and Transportation Barriers Compliance Board (Access Board) (https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards) to ensure the accessible use of Federal information and communications technology.

Contractor staff identified to provide accessible document creation support must have experience with accessible document procedural formatting techniques and be able to produce accessible documents, e.g. Word, PDF, PowerPoint, Excel.

All contract e-deliverables must be accessible under the specified applicable Section 508 technical requirements (1194.22, 1194.24, 1194.31, 1194.41). Documentation (e.g. user manuals, reports, training guides, outreach materials, online tutorials) must be readable utilizing assistive technologies (e.g. zoom text, screen reader or voice recognition software.)

COTs products that are web-based or present web content must follow either Section 508 technical standards requirements found in 1194.22 (https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards/web-based-intranet-and-internet-information-and-applications-1194-22) or the Web Content Accessibility Guidelines (WCAG) 2.0 standards Level AA (http://www.w3.org/WAI/intro/wcag), and be compatible with assistive technologies (e.g. zoom text, screen reader or voice recognition software).

See Appendix C sections 1.4, 2.11, and 4.2.

C.5.1.4.3 Privacy Act and Personally Identifiable Information (PII) Notification.

The contractor shall notify the SEC of all entities (that is, systems, companies, individuals) that will retain personally identifiable information (PII) under this contract, as such entities are all subject to the federally-mandated Security Assessment and Authorization (SA&A) testing for moderate-rated impact systems as defined in FIPS 199. See Appendix C section 1.3.

C.5.1.5 Technical Requirements.

C.5.1.5.1 Scalability.

The system shall be scalable to support increased number of users and/or additional Offices and Divisions within the SEC. The system should be scalable to incorporate additional features and modules available from the vendor.

C.5.1.6 Implementation Requirements.

The Contractor shall provide at a minimum the following system implementation services:

1. Implementation planning and base-system configuration;

2. Security configuration and user access permissions;

3. System configuration and reporting;

4. Testing requirements;

https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards/web-based-intranet-and-internet-information-and-applications-1194-22 https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards/web-based-intranet-and-internet-information-and-applications-1194-22 https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/guide-to-the-section-508-standards/web-based-intranet-and-internet-information-and-applications-1194-22 http://www.w3.org/WAI/intro/wcag

5. Training;

6. Configuration and change management plan;

7. Implementation plan;

8. Deployment; and

9. System maintenance and technical support.

C.5.1.7 Security Requirements.

The Contractor shall be compliant with applicable federal information protection and privacy laws, Executive Orders, Policies, Standards and Guidance. At a minimum, the Contractor shall comply with The Privacy Act of 1974 (as amended), the E-Government Act of 2002 (Public Law 107-347), and the Federal Information Security Management Act (FISMA) of 2014.

OIT Security will determine the type of assessment required for the CTaRRS to meet Security Assessment and Authorization (SA&A) requirements. The Contractor shall participate in SEC’s SA&A process, which adheres to the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach.

The SEC expects that the system(s) will be designated as a low or moderate impact system according to Federal Information Processing Standard (FIPS) 199 and the Security Assessment will utilize the controls from the NIST SP 800-53 baselines for testing. The SEC may change the system’s FIPS 199 categorization based on SEC’s security evaluation of the solution. Leveraging results from other Federal agency SA&As can be important inputs to the SEC SA&A review, but may not be sufficient to serve as the equivalent of the SEC’s SA&A. The SA&A covers both technical and non-technical controls. Prior to the assessment, the Contractor will have to complete a System Security Plan (SSP), based on NIST SP 800-18 Revision 1, Guide for Developing Security Plans for Federal Information Systems, which will be verified by the SEC. Following the assessment, the Contractor will be subject to periodic security assessments of certain management, operational and technical security controls, based on NIST SP 800- 53, Revision 4, Security and Privacy Controls for Federal information Systems and Organizations.

SA&A activities include:

• Enumeration: Activity aimed at identifying devices and components and cross-referencing with provided inventory lists

• Vulnerability Scanning: Network-based vulnerability assessment of customer’s servers, workstations, and any other network device or appliance in scope. The assessment will identify vulnerabilities associated with network services, operating systems, and devices that are un-patched or have out-of-date software security patches

• Penetration Testing: Attempts to exploit weaknesses identified from vulnerability scanning to verify legitimate findings, eliminate false-positives, and determine the extent of the vulnerability and potential remediation steps that may be taken. All systems containing SEC data will be subject to a penetration test and/or vulnerability assessment to ensure SEC data are not at adverse risk.

• Functional Testing: Specific tests, examinations, and inspections against NIST 800-53 controls not tested by the other activities.

During the Assessment, the Contractor shall provide the Security Team support including but not limited to: (1) a system demonstration; (2) test user accounts and IDs; (3) access to the system; and (4) system documentation, including the SSP. The OIT Security Team provides the test reports.

Results of the SA&A will be documented in a Security Assessment Report (SAR) by the SEC’s independent security assessment team, and Plans of Action and Milestones (POA&Ms) will be developed based on the requirements of Office of Management and Budget (OMB) Memorandum 02-01, Guidance for Preparing and Submitting Security Plans of Action and Milestones. The Contractor shall make arrangements to remediate deficiencies identified by SEC that are related to the developed solutions; the timeframe for remediation will vary based on the security risk of the deficiency. Systems may neither contain SEC data nor connect/interface with SEC systems without obtaining an Authorization to Operate (ATO) from the SEC’s Authorizing Official (AO). ATO requires the AO’s review of the SA&A documentation, an assessment of the risks associated with the system, and either acceptance of risks or POA&Ms for remediation of unacceptable risks.

The SEC SA&A is part of an overall OIT SDLC process to ensure compatibility with the SEC technology infrastructure, as well as adequate protection of SEC data, including Personally Identifiable Information (PII), adherence to the FISMA requirements, NIST Standards, NIST Special Publications and Section 508 compliance. The entire life-cycle may take 4 to 6 months, and will require the Contractor to assist with and/or develop elements of the SDLC documentation, including but not limited to: Standard Operating Procedures; System Security Plan; Disaster Recovery Plan; Privacy Awareness Worksheet; and a Privacy Impact Assessment.

Systems and personnel must comply with specific SEC policies relating to security requirements, including but not limited to: password complexity; password history; password longevity; background investigations; database hardening; approved system configuration baselines; and system disposition.

SEC requires that its data remain locally within the United States and not be off-shored to a foreign nation state. SEC prohibits access to its data from by any individual who has not been cleared.

C.5.1.8 Reporting Requirements.

The Contractor shall meet with the SEC business stakeholders to collect the requirements for the standard and ad hoc reports. The Contractor shall review all standard reports provided by the system with business stakeholders and the COR. The Contractor shall recommend the reports that are most applicable to the SEC and those that are most useful or popular with other clients. The Contractor shall propose and recommend any configuration or customization of reports as required to best meet the SEC requirements.

The Contractor shall document the reporting requirements including the ad hoc reporting capabilities. The Contractor shall provide the draft copy of the reporting requirements document to the COR for review and comments. The contractor shall incorporate feedback from the COR and deliver a final reporting requirements document to the COR for review and approval.

Reporting is currently performed on a manual ad hoc basis in OGC, and there are no standard reports or electronic forms that can be shared with the contractor.

C.5.2 Project Management.

C.5.2.1 Resources.

The Contractor shall provide all necessary personnel, administrative, financial, and managerial resources necessary to support this contract. The Contractor shall provide project management support that will maximize the successful and timely accomplishment of all contract requirements.

The Contractor should anticipate a mix of on-site and off-site performance. The Contractor should be prepared to perform key activities on-site, such as attending critical meetings, attending Phase Gate approvals, and performing certain requirements validation activities. The Contractor shall work closely with the SEC to coordinate the need for, and timing of, on-site performance based on scheduled activities and deliverables. The SEC can accommodate a limited number of contractor resources on-site, and is supportive of contractor telework.

C.5.2.2 Project Plans.

The Contractor will provide the following plans:

C.5.2.2.1 Project Plan, Schedule and SDLC Management.

The Contractor shall coordinate and assist the COR and/or existing Program/Project Managers to prepare, review, and maintain an individual Project Plan and Schedule to ensure the following:

timelines are appropriate for the size and scope of the project; resources are adequately assigned;

and all appropriate milestones and checkpoints are included. The Contractor shall provide comments and recommendations regarding the Project Plan and Schedule to the SEC. Once approved, the project plan will become the baseline for the project.

The Contractor shall review the Project Plan and Schedule at least weekly and immediately notify the COR of any deviations from the Project Plan and Schedule that may impact major milestone delivery dates. The Contractor shall immediately notify the COR of any deviations from the project schedule.

The Contractor shall immediately notify the COR of any deviations from the SDLC that may impact the major milestones and/or checkpoint delivery dates.

The Contractor shall provide recommendations to the SEC at each milestone and checkpoint to determine if the project should enter the next appropriate phase of the SDLC.

C.5.2.2.2 Configuration Management (CM) Plan

The Contractor shall perform each task in full compliance with the SEC’s Configuration Management processes and procedures. The Contractor shall ensure that work products created in each task are controlled in accordance with all applicable SEC standards. The Contractor shall identify and manage the software product baseline, including project plans throughout the project life cycle. The Contractor shall coordinate with the COR to identify the configuration items and other project materials to be controlled. The Contractor shall establish and maintain CM libraries, including the tracking of baseline versions of all deliverables. The Contractor shall use established SEC tools and processes as a means for tracking problems, changes and other CM information. The Contractor shall support Functional Configuration Audits (FCA) and Physical Configuration Audits (PCA) performed by SEC OIT.

C.5.2.2.3 Quality Assurance and Control

The Contractor shall perform each task with full compliance with the SEC’s Quality Assurance processes and procedures. The Contractor shall participate in formal product reviews, peer reviews, walk-throughs, and inspections in accordance with the Project Plan and Schedule. The Contractor shall participate in the preparation and review of the project by the SEC’s Application

Configuration Control Board (A-CCB), Technology Review Board (TRB), Lifecycle Configuration Control Board (L-CCB) and Operational Configuration Control Board (O-CCB).

C.5.2.3 Status Reports.

The Contractor shall provide the COR with monthly written status reports. Whenever variances with the project schedule occur, the Contractor shall include schedule and cost variance reports (i.e. Gantt or equivalent charts comparing the baseline schedule and costs to the current schedule and costs). The Contractor shall document any issues that have arisen during the reporting period and any issue resolutions.

C.5.2.4 Project Meetings.

C.5.2.4.1 Kick-Off Meeting.

Within one (1) week of contract award, the Contractor shall participate in a kick-off meeting attended by key Contractor personnel, the SEC Contracting Officer (CO), the COR, and other key SEC personnel to introduce project members and their roles and responsibilities, introduce the SEC “rules of the road”, and discuss the requirements of the system, the project schedule, testing expectations, testing environments, security requirements, connections, and restrictions, at a minimum.

C.5.2.4.2 Status Meetings.

The Contractor shall participate in periodic project status meetings attended by key Contractor personnel, the COR, and other key SEC personnel.

C.5.2.4.3 Meeting Minutes.

The Contractor shall provide minutes of all meetings to the COR for review and comment. The COR will provide feedback and comments and the Contractor shall COR incorporate them and provide the final meeting minutes for review and approval.

C.5.2.4.4 Briefings.

The Contractor shall prepare and deliver quarterly briefings that cover key project accomplishments, milestones met, and deliverables. The briefing shall address matters that are essential to ensure overall success of the task, such as funding status, project schedule, and an analysis of project risks that may affect successful task completion. The Contractor shall provide the COR with briefing materials for review prior to the presentation. The Contractor will incorporate feedback from the COR and provide the COR with final briefing materials for review and approval.

C.5.2.5 Risk Management.

The Contractor shall coordinate and assist the COR and/or existing Program/Project Managers to develop a Risk Management Plan and maintain a Risk Registry throughout the lifecycle of the project. The Contractor shall immediately notify the COR of any major risk to the project and provide recommendation on the mitigation of the risk.

C.5.2.6 Key Personnel.

The Contractor shall provide all necessary personnel, administrative, development, financial, and managerial resources necessary to successfully perform all required contract effort. Personnel provided under this agreement shall maintain a level of engagement and availability to allow for efficient and effective delivery of the requirements/objectives established herein. The following personnel are determined to be key personnel for this contract.

C.5.2.6.1 Project Manager.

The Contractor shall manage and execute the project in cooperation with the SEC Office of Information Technology (OIT). The Contractor shall designate a Project Manager (PM) with whom the Contracting Officer’s Representative (COR) can discuss problems, issues, concerns, resolutions, or plans. The PM shall interact directly throughout each day with the COR. The PM shall be proactive in alerting the COR to potential contractual and performance concerns or issues. Management and other status reports shall not be used as a means of notifying the SEC of a problem, concern, issue, or plan that has not already been bought to the attention of the COR.

The PM shall have the skills, education/certifications, experience, knowledge, responsibility, and authority to successfully manage the project and respond to and resolve issues directly with the COR. In particular, the PM shall have at a minimum:

• Demonstrated management experience and skill in deploying a solution similar to the proposed solution.

• Experience as a PM or similar management position on Federal government system management, maintenance and/or development contracts.

C.5.2.6.2 Subject Matter Expert.

The implementation, configuration, and customization (if any) of the solution requires in-depth knowledge and experience of both the proposed software and Government-specific environments and standards. The SME will oversee the implementation and execution of OGC’s Case Tracking and Records Retention functional and non-functional requirements and objectives. Such oversight may include ensuring that the functionality of the proposed software is traceable to the intended requirements and objectives.

The SME shall have appropriate skills, education/certifications, experience, knowledge, responsibility, and authority to support successful contract performance. In particular, the SME should have at least five years of relevant experience implementing and configuring the proposed software (and preferably have meaningful experience implementing the proposed software or similar legal case tracking system in a Federal Government agency environment).

C.5.3 System Design.

The Contractor shall perform system engineering and software engineering tasks. If product customization is needed then the Contractor shall design the system and/or make enhancements to the system to conform to the

SEC enterprise architecture. The Contractor shall present the design to the SEC Technology Review Board (TRB) and Configuration Control Boards (CCB). The Contractor shall deliver a draft System Design Document (SDD) to the COR for review. The design shall include tracing all requirements, including security requirements, to elements in the design. The Contractor shall incorporate feedback from the COR and shall prepare and deliver the final SDD. This process may require multiple submittals, reviews and resubmittals.

C.5.3.1 Technical Architecture Design

The Contractor shall consult with the SEC Enterprise Architecture Office in the design and development of the overall design solution document for application-specific architectural components. This architecture design solution must be compliant and consistent with the SEC Enterprise Architecture. The architecture design document must be submitted and approved by the OIT Enterprise Architecture Office via the COR as a baseline architecture for the new and enhanced system. Major changes in this application-specific architecture will require resubmitting of the changes to obtain review and approval from the SEC Enterprise Architecture Office.

C.5.3.2 Database Design

If designing a database as part of the CTaRRS solution, the Contractor shall configure the database to be compatible with database platforms identified in Appendix D and in accordance with applicable SEC security guidelines. The Contractor shall configure the underlying database to make all appropriate access available to authorized users and OIT Administrators.

C.5.3.3 Common Components and External Interfaces

The SEC has a set of common components built on a Service Oriented Architecture. The Contractor shall use existing common components when possible. When approved by the COR and Technical Review Board (TRB), the Contractor shall modify and enhance common components and update the documentation associated with them. The Contractor shall design and document new common components that will become part of the SEC’s Service Oriented Architecture. The Contractor shall trace requirements to all elements in the interface design. The Contractor shall document all external interfaces in the SDD and Standard Operating Procedures

(SOP).

C.5.4 Systems Integration, Configuration, and Development.

C.5.4.1 Integration

The Contractor shall integrate the CTaRRS solution into the SEC application infrastructure.

The Contractor shall analyze and document existing common components, applications and databases for the purpose of designing and developing integrated enterprise applications and databases. The Contractor’s integration design may require setting parameters and configuration options of the software, but shall not modify the software source code without express notification to and agreement of the SEC. The Contractor shall document the integration of the software in the SDD, and the SOP that shall be created as part of the Implementation Plan.

C.5.4.2 Interface Specifications

The Contractor shall develop and document internal and external interfaces, including user interfaces and interfaces with other systems as identified in Section C.2.2, for components and the system in accordance with the approved design. The Contractor shall deliver a draft Interface Requirements Specification (if applicable) to the COR for review. The Contractor shall incorporate feedback from the COR and shall prepare and deliver the final Interface Specification (if applicable) to the COR for review and approval.

C.5.4.3 Physical and Logical…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .