Attachment_A_-_PWS_Information_Redacted.docx
DOCX document 288 KB Posted
- Attached to
- FALCON Operations and Maintenance Support Services and Optional Enhancements Federal contract opportunity
- Solicitation number
- 70CTD019Q00000001
- Issued by
- Immigration and Customs Enforcement
About this file
Performance Work Statement (PWS) Redacted
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 70CTD019C00000001_SF1449.PDF | ||
| JOFOC_Redacted.pdf | ||
| Attachment_F_-_Palantir_LSA_Redacted.pdf | ||
| Attachment_B_-_Addendum_to_Provision_52.212-1.docx | DOCX document | |
| Attachment_D_-_Contract_Clauses_Addendum_to_Clause_52.212-4.rtf | RTF text file | |
| Attachment_C_-_IGP_Requirements_Clause.docx | DOCX document | |
| Attachment_E_-_Palantir_O&M_Support_Services_Terms_and_Conditions.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For Official Use Only Attachment A:
FALCON OPERATIONS & MAINTENANCE (O&M) SUPPORT AND OPTIONAL ENHANCEMENTS
Performance Work Statement
November 9, 2018
Homeland Security Investigations (HSI) Mission Support
FALCON System Operations & Maintenance, Support and Optional Enhancements
1.0 PROJECT TITLE
Performance Work Statement (PWS) for FALCON System Operations & Maintenance, Support and Optional Enhancements
2.0 BACKGROUND
United States Immigration and Customs Enforcement (ICE) is the largest investigative branch of the Department of Homeland Security (DHS). As part of ICE, Homeland Security Investigations (HSI) is a critical asset in accomplishing the ICE mission and is responsible for investigating a wide range of domestic and international activities arising from the illegal movement of people and goods into, within and out of the United States. There is need for training and employee support services for Special Agents, Intelligence Research Specialists (IRSs), and Task Force Officers assigned to HSI supervision, regarding their utilization of HSI Operational Systems Development and Management (OSDM) unit’s analytical and operations support software platforms, referred to as FALCON.
FALCON provides HSI’s Agents, IRSs, and Task Force Officers with a key investigative resource: a wholly integrated, consolidated platform performing federated search, analytics, geospatial referencing, reporting and situational awareness capabilities across a broadly diverse universe of structured and unstructured law enforcement data residing in numerous, disparate source environments.
FALCON is a configuration of commercial software sold by Palantir Technologies Inc., called the Palantir Gotham Platform.
3.0 SCOPE
FALCON uses commercial software sold by Palantir Technologies, Inc., called Palantir Gotham, configured for ICE. Current and future releases of FALCON are required to have System Maintenance and Services support for the purpose of applying adaptive, perfective and corrective maintenance to the application as well as operating and maintaining the FALCON infrastructure, and delivering enhancements, as necessary and procured under this PWS, to the existing application.
In the interest of maximizing commercial competition during the period covered by this proposed contract, HSI will be splitting tasks that were previously sole-sourced to Palantir Technologies within a single FALCON Operations and Maintenance Services contract (from 2012 to 2018) between two new contracts, one of which is the proposed contract described in this PWS. The second new contract, the FALCON Training and Support Services contract, will encompass the provision of two (2) Field Support Representatives (FSRs); the provision of FALCON Help Desk services; and the provision of Minor and Moderate FALCON system updates and changes within the scope of the FALCON system and in support of HSI's mission. The vendor selected for this second contract will be Palantir or an active Palantir Authorized Service Provider vendor partner. Under the terms of the proposed contract described in this PWS, Palantir will work in close cooperation with the employees of this second vendor so that the seven FSRs have up-to-date information regarding the status of Palantir’s Gotham software and its implementation as FALCON; that Palantir’s engineers work cooperatively with the FSRs, as necessary; that the other vendor’s FALCON Help Desk staff and Palantir engineers work smoothly as a combined team to solve end users’ problems and answer questions; and so that the other vendor is granted adequate access to Palantir resources and internal tools to allow for efficient and effective completion of minor FALCON system updates and changes, as described in the Statement of Objectives for the FALCON Training and Support Services contract and referred to in a later section of this PWS.
4.0 APPLICABLE DOCUMENTS
All ICE systems shall comply with the following guidelines and regulations:
| • | DHS Acquisition Management Directive 102-01 Handbook |
| • | ICE Enterprise Systems Assurance Plan |
| • | ICE System Lifecycle Management (SLM) Handbook, Version 1.4, January, 2012 |
| • | ICE Technical Architecture Guidebook |
| • | ICE Technical Reference Model (TRM) (Standards Profile) |
| • | The Offeror shall identify any hardware, software, and/or licenses required for its proposed solution. The Government is prepared to provide any hardware and software items that are included within the ICE TRM that would reasonably be utilized by Offerors for the system development. Test and evaluation tools listed within the TRM are not provided as Government Furnished Equipment (GFE). |
| • | 4300A DHS Information Security Policy |
| • | 4300A Sensitive Systems Handbook |
The following documents are applicable to understanding the target ICE/HSI systems:
| • | International Information Systems Security Certification Consortium (ISC2) Standards |
| • | National Industrial Security Program Operating Manual (NISPOM), February 28, 2006 |
| • | National Institute of Standards and Technology (NIST) Computer Security Resource |
Center (CSRC) o Guidelines o Special Publications o Standards
• NIST Special Publication 800-37, Guide for the Certification and Accreditation of Federal Information Systems
| • | Federal Information Processing Standard (FIPS) 199 |
| • | Federal Information Security Management Act (FISMA), November 22, 2002 |
| • | Federal Information Technology Security Assessment Framework (FITSAF), November |
28, 2000
| • | Federal OMB Circular A-130, Management of Federal Information Resources |
| • | Federal Privacy Act of 1974 (As Amended) |
| • | Federal Records Act |
| • | DHS 4300A, Sensitive Systems Policy Directive, Version 6.1.1, October 31, 2008 |
| • | DHS Management Directive (MD) 4300.1, Information Technology Systems Security, November 03, 2008 |
| • | DHS MD Volume 11000 – Security |
| • | DHS Office of Chief Information Officer (OCIO) E-Government Act Report 2008 |
Please note that if newer versions of these documents are officially released, the Contractor shall comply with the updated versions within the timeframe established by the Government.
The Contractor must understand federal cyber security requirements to include, but not limited to the DHS 4300A Sensitive System Policy, applicable National Institute of Technology (NIST) 800 series documentation, and the Federal Information Security Management Act (FISMA) of 2014 and integrate the security controls in all technology proposed or developed for use in support of the ICE mission.
5.0 TASKS
The Contractor shall provide qualified, experienced personnel to deliver support for the continued System Maintenance and Services tasks associated with FALCON in accordance with Palantir’s standard O&M/Support Services Terms and Conditions. This requirement includes the tasks described in the following sections:
5.1 Tier 2 System Maintenance and Support
In consultation with the Contractor, items that cannot be resolved at the Tier 1 Support level shall be turned over to Tier 2 System Maintenance and Support.
· The Contractor shall report the status of the ticket using Atlassian Jira tracking software;
· Typical Tier 2 activities would include patching systems and effecting minor fixes, etc. in accordance with Palantir’s O&M/Support Services Terms and Conditions;
· Tier 2 System Maintenance and Support shall be operational in accordance with the performance levels identified in Section 6.0;
· The Contractor shall respond to all Tier 2 System Maintenance tickets in accordance with the contract;
· The Contractor shall implement an application feedback loop, whereas systemic issues identified during common Tier 1, 2, and 3 escalation procedures are routinely evaluated and reviewed with the appropriate Project Manager to assess the need for a SCR for a future release.
· If Tier 2 System Maintenance Support cannot resolve the assigned ticket or perform the required tasks then the ticket shall be referred to the Tier 3 - System Maintenance and Support.
Tier 3 - System Maintenance and Support
The Contractor staff and the COR will come to mutual agreement regarding issues that cannot be resolved in Tier 1 or Tier 2 (bug fixes, security patches, or upgrades) to determine whether such issues constitute SCRs (Minor, Moderate, or Major Changes requiring the use of a vendor off the FALCON Training and Support Services Contract or the procurement of the optional CLIN under Section 5.6), as opposed to every day System Tuning (Section 5.2.3) and System Administration (Section 5.2.4) actions not requiring the SCR process.
· All maintenance activities that reach this level shall have an SCR opened and be reported using Atlassian Jira;
· SCRs will be prioritized and agreed to by the authorized government personnel and entered into the ICE approved management tracking tool. SCRs will be approved in writing by the government;
· The Contractor shall implement an application feedback loop, whereas systemic issues identified during common Tier 1, 2, and 3 escalation procedures are routinely evaluated and reviewed with the Government IT Project Manager to assess the need for a SCR in future release.
· The Contractor shall respond to all Tier 3 System Maintenance Support tickets in accordance with the contract;
The Contractor shall provide Software Maintenance Tier 2 and Tier 3 Support. Software Maintenance Tier 2 and Tier 3 Support hours of operation shall be Monday through Friday 9am-5pm, ET, excluding holidays and weekends.
For emergency situations both during and outside of the normal support business hours that involve a system outage or a widespread interruption in user access to FALCON, the Contractor shall notify the FALCON Program Manager or designate within 30 minutes of occurrence. Emergencies will be further defined as part of the Software Tier 3 Support procedures, but in general an emergency is when the system is down or when multiple users are unable to access FALCON. The Contractor shall document all user problem notifications and solutions.
Operations and Maintenance Services consist of bug fixes, security patches, and upgrades in accordance with Palantir’s standard O&M/Support Services Terms and Conditions attached hereto.
5.2 Operational Support
The Contractor shall provide Operational Support for the FALCON system. Table 2 and Table 3 detail the hardware, cloud infrastructure, and software infrastructure currently in place for FALCON, and/or scheduled to be operationalized under this contract. The hardware, cloud infrastructure and software listed below is subject to change based on future expansion requirements and datacenter moves as requested by FALCON PMO.
Table 3. FALCON Cloud Infrastructure
| Environment |
| Purpose |
| FALCON Hosting Location |
| Training (TRN) |
| User training and related documentation (ongoing) |
| Amazon Gov Cloud |
| Staging (STG) |
| Performance testing (load, capacity, response time) |
Validation of deployment configuration prior to transition to production Amazon Gov Cloud
| Production (PROD) |
| Production environment |
| Amazon Gov Cloud |
Table 4.
Vacating all remaining FALCON servers from the PCN server room is of the highest priority to HSI and OCIO and is required under DHS mandates, which require that all DHS systems be housed in DHS-approved data centers or Cloud environments. Contractor shall prioritize this task instead of Operations and Maintenance services, with the exception of carrying out emergency bug fixes or security patches or other emergency work necessary to keep FALCON from failing. Palantir engineers will migrate all remaining system components currently residing on all remaining physical servers in the PCN server room to a DHS-approved environment agreeable to HSI management and the FALCON PMO at the earliest technically feasible time. Any new environment shall meet certain security and technical preconditions. Additionally, the Government accepts that after any migration and based on the new environment, Palantir may not be able to guarantee contractual SLAs regarding response times to incidents or user requests.
Additional operational support shall include the activities below:
5.2.1 Operational Support - Interfaces and Data Sources
The Contractor shall support interfaces that feed into and out of the FALCON System. The Contractor shall ensure the continuation of and proper operation of all data pipelines to external data sources currently accessed by FALCON, conditional on those source systems providing data in a format and structure and via a method that is consistent with preexisting FALCON data integrations. The Government recognizes that the Contractor is not able to guarantee continued access to data sources that reside outside the FALCON environment, nor can it guarantee SLAs around the type/quality/quantity of the data such source systems provide to FALCON/HSI. Source systems may introduce breaking changes that disrupt the flow of data in to FALCON via existing FALCON data integrations. Breaking changes include changes to the content, format, or structure of the data provided by source systems, or the infrastructure or interface through which the source system makes data available to FALCON. The Government recognizes breaking changes shall necessitate Minor, Moderate, or Major System Changes to FALCON. Whether a breaking change requires a Major System Change to FALCON in order to be remediated will be jointly agreed to by the Contractor and the Government.
The contractor must understand federal cyber security requirements to include, but not limited to the DHS 4300A Sensitive System Policy, applicable National Institute of Technology (NIST) 800 series documentation, and the Federal Information Security Management Act (FISMA) of 2014 and integrate the security controls in all technology proposed or developed for use in support of the ICE mission. (This clause applies to all sub-sections of Operational Support and Configuration Management.)
5.2.2 Operational Support - Database
The Contractor shall support all management and updates to the FALCON data stores and indices. This includes all database structural changes and ontology updates to support bug fixes, security patches, and upgrades. In addition to Operations and Maintenance services, the Contractor shall provide or enable the Government to obtain statistical data regarding FALCON utilization across HSI and HSI offices and functions.
5.2.3 Operational Support – System Tuning
The Contractor shall conduct performance tuning of the FALCON system as a result of findings during regular system monitoring and/or as operational needs arise. The Contractor shall provide the FALCON PMO with recommendations regarding system performance improvements to foster a more stable and robust operational system. The Contractor shall integrate federal cyber security requirements, such as applicable ICE / DHS baseline settings, into network devices during the course of design and development.
5.2.3.1 Operational Support – System Administration
The Contractor shall provide system administration activities to include regular monitoring of system resource utilization, disk storage utilization, identification of corrupt files or processes, system archiving, data archiving, installing operating system/software updates/versions and performing application backups; correcting flaws in software applications that escaped detection during testing of the system, or that have been introduced during previous maintenance activities; and improving software attributes such as performance, memory usage, and documentation. The Contractor shall coordinate security monitoring activities and scans with the ICE Network Operations Center (NOC) and the Security Operations Center (SOC). If the FALCON PMO determines a need to integrate additional monitoring or security capabilities, the Contractor will work with the PMO to prioritize such work against all other ongoing efforts. The Contractor shall maintain awareness of and comply with NOC and SOC procedures, to include notification of security incidents and outages, as well as adhere to the ICE Change Control Board (CCB) policies and procedures.
5.2.3.2 Operational Support – System Decommissioning
Should any components or modules of the exiting FALCON system be replaced by a follow-on component or module during the POP of this contract, or should the Government decide to halt use of a particular component or module, the Contractor shall facilitate decommissioning of that component or module, per software decommissioning standards and guidelines provided in guiding regulations as listing in Section 4.0, Applicable Documents.
5.2.4 Cloud Hosting and Cloud Management Services
The Contractor will provide cloud infrastructure including Combined GovCloud Instances, AWS support package, and SaaS Palantir Cloud.
5.2.4.1 The Contractor will provide AWS GovCloud as the underlying infrastructure for the FALCON system’s Training, Staging and Production environments. Palantir Cloud (PCloud), Palantir’s managed Software-as-a-Service (SaaS) offering, is the configured environment that will host all applicable components of the FALCON system. PCloud uses AWS GovCloud for its underlying infrastructure. PCloud will provide a variety of virtual cloud services that can be deployed or removed on demand to support the scale and high availability required by the FALCON system. Additionally, Palantir will manage and administer the FALCON environment in PCloud to ensure timely assessment and triage of issues related to the application when deployed. Palantir will have direct lines of communication to Amazon GovCloud. In summary, Palantir will be responsible for administration and maintenance of their FALCON hosting solution in PCloud, respecting change management, system availability, system performance, security, and audit requirements as set forth in Sections 3 through 13 of the FALCON-Palantir Operations and Maintenance and System Enhancements contract.
5.2.4.2 PCloud operates with strict security procedures and has undergone extensive auditing and review to ensure compliance with a broad landscape of regulatory requirements and standards. Palantir Cloud is SSAE 16 SOC 2 compliant. The Palantir team will work with the ICE security components including ISSO and IAD to facilitate testing and documentation as needed to validate the existing FISMA ATO.
5.2.4.3 To mitigate the risk of data breach or loss, Palantir-managed hardware security modules (HSMs) will be maintained in PCloud. These cloud-based HSMs enable secure data encryption, and will be dispersed across separate AWS regions to provide redundancy and multi-region support.
5.2.4.4 The Palantir Cloud (PCloud) team will provide monthly Nessus scans of the FALCON AWS environment. (Nessus scans systems, networks, and applications for weaknesses and vulnerabilities including malware detection and web application scanning. Nessus also provides the capability to complete external network scans to scan Internet-facing IP addresses for network and web application vulnerabilities. The DB and any running applications are included in these scans and vulnerabilities that would be visible over open ports are reported.) These scans shall encompass the full range of ports and perform an authenticated scan which checks local libraries, RPMs, etc. against known vulnerabilities or associated exploits; these scans will additionally cover all of the running applications and include network scanning.
5.2.4.5 The PCloud team will be responsible for providing ongoing system and operating system (OS)-level patches and updates as necessary to ensure the security of the FALCON system and the data it contains. These configuration changes will not be subject to ICE/OCIO approvals prior to implementation in PCloud and any changes applied will not impact uptime or functional/performance requirements. However, these (and any other) system-level changes will be logged and provided to the ICE ISSO on a regular basis. These logs will include information on day-to-day maintenance activities conducted by the PCloud team and FALCON support staff managing the application. Any changes that impact uptime, functional, or performance requirements will be discussed and coordinated with ICE/OCIO and the ICE ISSO for mitigation. Note that all application level SCRs (Tier 3) will follow appropriate approval routes through the FALCON PMO before any change is implemented.
5.2.4.6 A dedicated network link will be required to establish connectivity between Amazon GovCloud and a DHS-designated data center with appropriate bandwidth to meet performance requirements. This network link piece will be handled separately by ICE. Palantir will be responsible for ensuring appropriate implementation of necessary changes within PCloud to support communication with components should there be a disaster recovery/failover between data centers within ICE.
5.2.4.7 Palantir will acquire an Amazon AWS support package sufficient to support the GovCloud hosting infrastructure stipulated above.
5.3 Configuration Management
The Contractor shall conduct application-level configuration management for all Major System Changes made to the system. The Contractor shall handle all requests for changes to established baselines and configuration management thereof via the ICE approved SCR process. The Contractor shall assign proper identification of all configuration items in accordance with agreed upon naming and numbering conventions.
5.4 Maintenance of Training Support Materials and Provision of a Teaming Coordinator
The Contractor shall maintain and update training materials to include User Guides, Training Plans, and System Administration and Operations Manuals when an enhancement, or other significant software O&M release, occurs. The Contractor shall provide an electronic copy of all training material. The Contractor shall also coordinate with the FALCON PMO to insure that all members are familiar with the updates to the application.
The Contractor shall assign a “Teaming Coordinator” to assist the COR in overseeing any third party Palantir Authorized Service Provider Contractors (ASP Contractor) and the ASP Contractor’s staff of Certified Field Service Representatives (FSRs) selected by the Government to deliver engineering support and training to HSI. Additionally, the Teaming Coordinator shall ensure that Tier 2 and Tier 3 requests for assistance referred by the ICE Enterprise Help Desk are properly routed to appropriate Palantir engineering staff for resolution in a timely fashion, per standards set forth in the QASP.
5.4.1 Teaming Coordinator Assistance with Help Desk Tasks
a. The Teaming Coordinator will report status and any issues or concerns to FALCON PMO as necessary, but no less than quarterly, and shall provide the statistical data required for the Help Desk-related aspects of the QASP reports.
b. The Teaming Coordinator shall help establish procedures for smooth and timely escalation of issues requiring Tier 2 and Tier 3 support.
5.4.2 Teaming Coordinator Assistance with Third Party Provision of Engineering Support
a. The Teaming Coordinator shall coordinate with the Government in assessing the engineering performance of the third-party ASP Contractor and its FSRs. Engineering support to be provided by a third-party ASP vendor under the purview of the FALCON Training and Support Services contract shall include Minor and Moderate System Changes that do not require access to core Palantir Gotham code and that fall within the scope of the existing FALCON system and are in support of HSI's mission; performance testing against on-going ICE network/environment changes, to ensure compatability with the FALCON platform; configuration of new data integrations; and configuration of new custom data views, displays, and reports.
b. The Teaming Coordinator, with input from the FALCON PMO and its OCIO representative, will determine which Minor or Moderate System Changes requested by the Government fall within the purview of engineering support services that can be provided under the FALCON Training and Support Services contract and fulfilled by a third-party ASP vendor, meaning those additive changes, configuration services, or testing services that are small in scope and/or do not require access to Palantir Gotham source code. All such services that can be performed by the employees of the FALCON Training and Support Services contract should be routed to that partner vendor, with Palantir Technologies reserving to itself Major System Changes under a mutually agreed Optional CLIN .
c. The Teaming Coordinator shall make technical documentation available to ASP Contractor employees.
d. The Teaming Coordinator shall triage and help escalate for COR review any issues relating to substandard ASP Contractor performance.
e. The ASP Contractor shall provide detailed weekly progress reports to the Teaming Coordinator on activities relating to all engineering efforts associated with the FALCON platform.
f. The Contractor shall coordinate with ASP FSRs to review, approve, and publish all requested configuration changes, new technology, and/or custom plugins and helpers developed by ASPs. All review, approve and publish decisions shall be made on a timeline mutually agreed upon by all parties.
5.4.3 Training Coordinator Assistance with Third-Party Provision of Training Services
a. The Teaming Coordinator shall coordinate with the Government in assessing performance of the third-party ASP Contractor and its FSRs as it relates to the provision of FALCON training and operational support to users across HSI.
b. The Teaming Coordinator shall monitor the ASP Contractor FSRs as they triage, schedule, and execute FALCON trainings. As necessary, the Teaming Coordinator will help report to FALCON PMO on the status of FALCON trainings. Third party Field Service Representatives shall operate according to the direction of assigned Government staff with the FALCON PMO based on consultation with the Contractor.
The Teaming Coordinator and designated representatives from the Contractor shall—as necessary and from time to time, but at no additional cost to the government—accompany and audit ASP Contractor FSRs as they conduct training in the field, in order to verify the quality and accuracy of FALCON trainings.
5.5 Data Export Support
Once every six months upon the Government’s request, or on a mutually agreed upon schedule, at no additional cost to the Government, Palantir will export all published object data in FALCON. All data will be provided in common, non- proprietary formats (e.g., XML, YAML, CSV). Palantir will also provide the Government with the schema for exported data, which shall portray the connections between objects and related components, the ontology that represents the FALCON data model, and a copy of integration code pertinent to mapping source data to the ontology. Palantir makes object history (identities of the users who entered the information and who modified the information) available to the Government via Palantir’s Open API. Palantir will provide documentation indicating the UUID, or other key, on which the government can associate object history obtained from the Palantir Open API with a specific object contained in the exported data. Additionally, Palantir will ensure that the object history information is available in the Palantir Open API for all objects contained in the exported data.
5.6 Optional CLINs: Provision of Major System Changes
Although HSI does not intend to routinely and annually obtain Major System Changes (previously called Outcomes in earlier O&M contracts) during the period covered by this contract, the Government recognizes that unanticipated and urgent contingencies may arise that require such significant additions to the existing FALCON system. Such contingencies may include national emergencies, significant new trends in transnational, cross-border crimes within HSI’s purview, Congressional or court-ordered mandates, or major new law enforcement or regulatory intiatives ordered by ICE or DHS leadership.
The Contractor may perform Major System Changes as directed by the Government and mutually agreed upon in an associated Scope of Work under a separate optional CLIN for Major System Changes; this CLIN shall be exercised on a firm-fixed price basis for a period of performance, with each Major System Change inclusive of all software licenses required to support the tasks listed in the Scope of Work document associated with the Government’s exercise of the optional CLIN as well as Operations and Maintenance Services for the initial period of performance. Upon exercise of the optional CLIN, the Government and Contractor will agree upon the scope of the Major System Change.
Contractor and the Government will mutually determine whether a request is a Major System Change and should be performed by Contractor or whether the request is for Minor or Moderate System Changes, meaning additive changes, configuration services, or testing services that are small in scope and/or do not require access to Palantir Gotham source code and should be routed to the Palantir Authorized Service Provider vendor partner. If there is a dispute between the Contractor and Government over what constitutes a Major System Change, the dispute will be elevated to the Contracting Officer, who will determine the resolution with input from ICE OCIO and through mutual agreement with the Contractor.
5.6.1 Project Plans and Schedules for Completion of Major System Changes
The Contractor shall submit to the FALCON Program Manager and the FALCON COR/ACOR, no later than thirty (30) calendar days after the Government has announced its intention to exercise an optional CLIN for Provision of a Major System Change, a draft Project Plan and Schedule. Such Project Plans and Schedules, mutually agreed to by HSI and the Contractor, shall identify responsible parties required for project completion employed by the Contractor, the Government, and/or a third-party vendor(s), tasks and assignments, potential risks and blockers, and timelines. Progress on the work identified in Project Plans and Schedules will be documented in weekly written reports and will be orally reported on at regularly scheduled or ad-hoc meetings. Project Plans and Schedules may be amended by mutual agreement between the Government and Contractor.
6.0 PERFORMANCE STANDARDS
The following table defines the performance standards to be adhered to for the FALCON System Maintenance and Services effort and regarding maintaining overall system performance as new features, new data sets, and additional users are added.[footnoteRef:2] For the avoidance of doubt, performance standards are contingent on the use of Palantir recommended hardware and/or cloud infrastructure. [2: Any Major System Changes or bug fixes, security patches, or upgrades to FALCON should not negatively impact system performance. Specifically, system performance will be baselined at the beginning of the contract and will be re-baselined at the completion of any Major System Changes. This baseline will serve as the minimum for acceptable system performance.]
Table 5. Performance Standards
Tasks
Metric Service Level Agreement How it will be measured
7.0 DELIVERABLES AND DELIVERY SCHEDULE
Specific deliverables related to each activity are outlined below.
7.1 System Lifecycle Management (SLM) Deliverables
The Contractor shall provide SLM deliverables as required for System Maintenance Services projects. All appropriate documentation shall be prepared in accordance with the guidelines specified by the SLM and the approved Project Tailoring Plan.
7.2 Quarterly Progress and QASP Report
The Contractor shall prepare a quarterly progress and QASP report. These reports are due within fifteen (15) calendar days after the completion of the quarter under review. The quarterly reports can be delivered via email and shall contain the following:
· Description of work accomplished (Accomplishments)
· Work planned for the following month (Planned Activities)
· QASP statistics
· Deviations from planned activities
· Open risks and issues
7.3 Certification and Accreditation (C&A) Documentation
The Contractor shall be responsible for maintaining and updating existing C&A artifacts to stay current with DHS/ICE and Federal requirements. These C&A updates will be required every three years unless a major change impacts security. The Contractor shall also be responsible for supporting the Information Systems Security Officer (ISSO) for any annual C&A activities, which may be requested (i.e. self-assessments, contingency plan tests, vulnerability scans, etc.).
7.4 Quality Assurance Surveillance Plan
The Quality Assurance Surveillance Plan (QASP) is the document used by the Government to evaluate Contractor actions while implementing the PWS. It is designed to provide an effective surveillance method of monitoring Contractor performance for each listed task in the PWS.
The QASP provides a systematic method to evaluate the services the Contractor is required to furnish. The Contractor, and not the Government, is responsible for management and quality control actions to meet the terms of this contract. The role of the Government is quality assurance monitoring to ensure that the contractual standards are achieved.
FALCON Operations & Maintenance Support & System Enhancement Performance Work Statement
The Contractor shall be required to develop a comprehensive program of inspections and monitoring actions. Once the quality control program is approved by the Government, careful application of the process and standards presented in the QASP document will ensure a robust quality assurance program. The QASP below was developed by ICE and is indicative of the type of metrics that apply to the deliverables. The offeror may propose other metrics they determine upon the uniqueness and relevance of their own technical approach in meeting the task order objectives. The QASP is subject to discussions/negotiations.
FALCON Operations and Maintenance (O&M) Support Services Contract Quality Assurance Surveillance Plan (QASP) Attachment 1
| Tasks |
| Metrics |
| Service Level Agreement |
| How it will be measured |
| Exceptional Rating |
| Very Good Rating |
| Satisfactory Rating |
| Marginal Rating |
| Unsatisfactory Rating |
· Measurements will be performed quarterly.
· Measurements will be carried out by Contractor.
· QASP measurement report will be turned in quarterly to the government Contracting Officer’s Representative (COR) within fifteen calendar days after the end of the quarter under review.
· An overall quarterly QASP Rating will be computed for the Contractor by the COR, according to the following methodology:
· For each of the QASP Tasks listed above, the Contractor will be assigned the following number of points:
· Exceptional: 4 points
· Very Good: 3.5 points
· Satisfactory: 2.75 points
· Marginal: 1.75 points
· Unsatisfactory: 0 points
· The points for the QASP Tasks will be averaged (the sum total divided by the number of Tasks). The overall quarterly QASP Rating will be assigned as follows (CPARS is the Contractor Performance Assessment Reporting System):
| QASP Rating |
| Point Level |
| Consequence |
| Exceptional |
| 3.7 – 4.0 |
| Exceptional rating for quarter entered into CPARS at end of performance period |
| Very Good |
| 3.2 – 3.69 |
| Very Good rating for quarter entered into CPARS at end of performance period |
| Satisfactory |
| 2.7 – 3.19 |
| Satisfactory rating for quarter entered into CPARS at end of performance period |
| Marginal |
| 1.7 – 2.69 |
| Marginal rating for quarter entered into CPARS at end of performance period. |
| Unsatisfactory |
| < 1.7 |
| Unsatisfactory rating for quarter entered into CPARS at end of performance period. |
7.5 Deliverables Table
The Contractor shall provide the following deliverables via email to the COR, unless noted otherwise:
Deliverable
Frequency
Recipients
SLM Deliverables (Doc) & Software (SW) (Software includes updates/new versions of the primary Gotham platform; new workflow applications and updated versions of existing workflow applications; data ingestions; and customized versions of Gotham Mobile and the Phoenix and Raptor plug-ins)
| As Required |
| Electronic copy - PM |
Software (SW): ICE source control repository (Subversion); OCIO representative on FALCON PMO
| Project Plans and Schedules for optional CLINs for Provision of a Major System Change |
| 30 calendar days following the Government’s announcement of its intention to exercise the optional CLIN |
| Electronic copy - PM, Contracting Officer, COR/ACOR |
| Quarterly Progress and QASP Reports |
| Quarterly, within 15 calendar days of the end of the quarter being reviewed |
| Electronic copy: PM, Contracting |
Officer, COR/ACOR
Certification and Accreditation Documentation As Required
Electronic copy: PM, COR/ACOR
| Training Documentation |
| As Required |
Electronic copy: PM, COR/ACOR
| Transition In Plan- Final |
| 15 calendar days |
after award Electronic copy: PM, Contracting Officer, COR/ACOR
| Transition Out Plan |
| 120 calendar days |
before the end of the
POP
Electronic copy: PM, Contracting Officer, COR/ACOR
| Contractor’s QASP Administration Plan |
| 15 calendar days |
after award Electronic copy: PM, Contracting Officer, COR/ACOR
7.6 Delivery Instructions
The Contractor shall provide electronic copies of each deliverable. Electronic copies shall be delivered via email attachment. The electronic copies shall be compatible with MS Office 2010 or other applications as appropriate and mutually agreed to by the parties. The documents shall be considered final upon receiving Government approval. All deliverables shall be delivered electronically (unless a hardcopy is requested) to the COR. If a hardcopy is requested, it will be delivered to the designated COR, not later than 4:00 PM ET on the deliverable’s due date. Once created, deliverables and work products are considered the property of the Federal Government. Any work that deviates from this task order and the approved deliverables listed herein shall not be accepted without prior approval from the COR.
7.7 Draft Deliverables
The Government will provide written acceptance, comments and/or change requests, if any, within 15 working days from receipt by the Government of each draft deliverable.
Upon receipt of the Government comments, the Contractor shall have 15 working days to incorporate the Government’s comments and/or change requests and to resubmit the deliverable in its final form.
7.8 Written Acceptance/Rejection by the Government
The Government shall provide written notification of acceptance or rejection of all final deliverables within fifteen (15) calendar days. All notifications of rejection will be accompanied with an explanation of the specific deficiencies causing the rejection.
Items must be approved by the COR and/or the appropriate Government authority to be considered “accepted.” The Government will provide written acceptance, comments, or change requests within fifteen (15) calendar days from receipt by the Government, of all required deliverables.
7.9 Non-Conforming Products or Services
Non-conforming products or services will be rejected. The Government will provide written notification of non-conforming products or services within fifteen (15) calendar days. Deficiencies shall be corrected within 30 days of the rejection notice. If the deficiencies cannot be corrected within 30 calendar days, the Contractor shall immediately notify the COR of the reason for the delay and provide a proposed corrective action plan within ten (10) calendar days.
7.10 Notice Regarding Late Delivery
The Contractor shall notify the COR as soon as it becomes apparent to the Contractor that a scheduled delivery will be late. The Contractor shall include in the notification the rationale for late delivery, the expected date for the delivery, and the impact of the late delivery on the project. The COR will review the new schedule with the PM and provide guidance to the Contractor.
8.0 CONSTRAINTS
8.1 General Constraints
The following project constraints are applicable to the FALCON System Maintenance and Services task order:
· Existing FALCON system is a version of a Commercial, Off the Shelf (COTS) product sold by Palantir Technologies, Inc., called Palantir Gotham, that has been specifically configure to meet HSI’s needs;
· FALCON will be primarily accessed from the existing ICE standard desktop;
· ICE-OCIO must approve in writing any exceptions to the established ICE-OCIO System Lifecycle Management (SLM) processes;
· The Contractor will support and coordinate with ICE HSI’s move from PCN to ICE-OCIO approved alternate data centers ;
· The Contractor shall comply with all DHS information security regulations for all Law Enforcement sensitive data;
· The Contractor shall comply with all applicable technology standards and architecture policies, processes, and procedures defined in ICE OCIO Architecture Division publications;
· The Contractor shall comply with the FALCON specific configuration management plan for all design and development artifacts in accordance with guidelines set forth in the Plan;
· ICE will provide Government Furnished Equipment as necessary to support all FALCON System Maintenance and Services activities.
8.2 DHS Enterprise Architecture Compliance
All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the contractor shall comply with the following HLS EA, NIST & FISMA requirements:
• All developed solutions and requirements shall be compliant with the HLS EA.
• All IT hardware and software shall be compliant with the HLS EA Technical Reference Model (TRM) Standards and Products Profile.
• Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.
• Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.
• Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile National Institute of Standards and Technology (NIST) Special 8 ITAR Quick Essentials Guide 2011 v2.0 Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.
• Integrate federal cyber security requirements to include, but not limited to the DHS 4300A Sensitive System Policy, applicable National Institute of Technology (NIST) 800 series documentation, and the Federal Information Security Management Act (FISMA) of 2014 into technical solutions and provide strategies to meet on-going operational security controls in areas such as security patching, configuration management, authentication, and security monitoring.
8.3 Project Governance
The Government and Contractor shall on a quarterly basis meet to review the state of the work performed under the PWS and discuss any issues regarding how the project is being conducted and mutually agree upon resolving any concerns. Such quarterly meeting shall include HSI management from the Government and executive leadership from the Contractor.
9.0 GOVERNMENT FURNISHED EQUIPMENT AND INFORMATION
The Contractor shall keep an inventory of Government-furnished equipment (GFE), which shall be made available to the COR, Assistant COR, and Government Call Monitor upon request. The Government will provide basic equipment (e.g., laptops, desktops, VPN tokens, and aircards) in accordance with the contract. All GFE shall be entered into ICE’s Property Inventory System (Sunflower) within 48 hours of receipt. The Contractor shall provide their own network connectivity capability with a minimum connection speed of 10Mbps.
Items of GFE which are inventoried and tracked in Sunflower include laptops and i-Phone handheld devices that will be listed on an inventory master list to be jointly maintained by the Government COR and the Contractor PM; all G570 documentation will be kept current.
9.1 Remote Access
Contractor shall be provided with remote access to the DHS network for mutual convenience while the contractor performs business for the DHS Component.
10.0 OTHER DIRECT COSTS (ODCs)
Travel outside the local metropolitan Washington, DC area may be expected during performance of the resulting task order. Therefore, travel will be undertaken following the General Services Administration Field Travel Regulation. Reimbursement for allowable costs will be made. Any travel and training expenditures shall be pre-approved by the COR. Costs for transportation, lodging, meals and incidental expenses incurred by Contractor personnel on official company business are allowable subject to FAR 31.205-46, Travel Costs. These costs will be considered to be reasonable and allowable only to the extent that they do not exceed on a daily basis the maximum per diem rates in effect at the time of travel as set forth in the Federal Travel Regulations. The Contractor will not be reimbursed for travel and per diem within a 50-mile radius of the worksite where a Contractor has an office. Local travel expenses within the Washington Metropolitan area will not be reimbursed (this includes parking). All travel outside the Washington Metropolitan area must be approved by the COR in advance. No travel will be reimbursed without prior approval from the COR. All travel in connection with this PWS by Contractor personnel to HSI facilities, outside of regularly scheduled meetings with FALCON PMO staff, shall require prior notification to and approval by the FALCON PMO or Government COR. Contractor will not seek reimbursement for travel expenses.
11.0 PLACE OF PERFORMANCE
Work, meetings, and briefings will be performed primarily at Contractor facilities. Frequent travel to ICE offices located at 2450 Crystal Drive, Arlington, Virginia or 500 12th St SW, Washington, D.C., or to the Tech Ops facility in Lorton, Virginia will be required. Additionally, travel to the Law Enforcement Support Center (LESC) facility located in Williston, VT may be required. Due to regular interaction with a multitude of program stakeholders, the Contractor’s staff shall be located in the Greater Washington Area (GWA).
12.0 PERIOD OF PERFORMANCE
The period of performance of the FALCON System Maintenance and Services contract will consist of a base period of twelve (12) months plus two (2) twelve (12) month option periods.
13.0 SECURITY
Contractor personnel performing work under this PWS may require access to Sensitive but Unclassified, (SBU), For Official Use Only (FOUO) data. The contractor will require access to JWICS only at government facilities. The contractor shall not employ any foreign subcontractor participation.
13.1 Section 508 Compliance
Section 508 Requirements Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) (codified at 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.
1. All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT or that contain ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps. A, C & D, and available at https://www.gpo.gov/fdsys/pkg/CFR-2017-title36-vol3/pdf/CFR-2017-title36-vol3-part1194.pdf. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards.
Item that contains Information and Communications Technology (ICT): Operations and Maintenance Applicable Exception: National Security Authorization #: ICE20120201-001 Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated January 29, 2016 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated January 11, 2017.
13.2 General Clause
To ensure the security of the DHS/ICE information in their charge, ICE Contractors and Sub-contractors shall adhere to the same computer security rules and regulations as Federal Government employees unless an exception to policy is agreed to by the prime Contractors, ICE Information Systems Security Manager (ISSM) and Contracting Officer and detailed in the contract. Non-DHS Federal employees or Contractors who fail to comply with DHS/ICE security policies are subject to having their access to DHS/ICE IT systems and facilities terminated, whether or not the failure results in criminal prosecution. The DHS Rules of Behavior document applies to DHS/ICE support Contractors and Sub-contractors.
13.3 Security Policy References Clause
The following primary DHS/ICE IT Security documents are applicable to Contractor/Sub-contractor operations supporting Sensitive But Unclassified (SBU) based contracts. Additionally, ICE and its Contractors shall conform to other DHS Management Directives (MD) (Note: these additional MD documents appear on DHS-Online in the Management Directives Section. Volume 11000 “Security and Volume 4000 “IT Systems” are of particular importance in the support of computer security practices), NIST and FISMA requirements:
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.