2.2.1 Amendment 1_Attachment B_PWS 3172021.pdf

PDF 592 KB Posted

Attached to
Break-Fix and Operations & Maintenance (O&M) Support for the SEVP External Training Application (SETA) Federal contract opportunity
Solicitation number
70CTD021Q00000052
Issued by
Immigration and Customs Enforcement

About this file

This is a solicitation for Break-Fix and Operations & Maintenance (O&M) support services for the SEVP External Training Application (SETA). The solicitation is issued by Immigration and Customs Enforcement (ICE) as a total small business set-aside with a NAICS code of 518210 and size standard of $35.0M. The services include break-fixes, patching, defects, security work, and O&M support outlined in ICE's Systems Lifecycle Management and Agile processes. The period of performance consists of one 3-month base period from March 30, 2021 to June 29, 2021, and three 1-month option periods ending September 29, 2021. The place of performance is the contractor's facility with some meetings held at ICE locations. ICE intends to award a firm-fixed-price purchase order to GEO4S Technologies LLC if its price is determined fair and reasonable. Quotes are due by March 22, 2021.

View the file

Other files for this federal contract opportunity

Other files attached to Break-Fix and Operations & Maintenance (O&M) Support for the SEVP External Training Application (SETA), newest first.
File Type Posted
2.2.1 Amendment 2_Attachment D_Pricing Template_3182021.xlsx XLSX spreadsheet
2.2.1 Attachment C_Terms and Conditions_Final.pdf PDF
2.2.1 Attachment A_Standard Form 18_70CTD021Q00000052_Final.pdf PDF
2.2.1 Attachment B_PWS_Final.pdf PDF
2.2.1 Attachment D_Pricing Template.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Procurement Sensitive

Performance Work Statement Student Exchange Visitor Program (SEVP)

External Training Application (SETA)

U.S. Immigration and Customs Enforcement (ICE) The Student and Exchange Visitor Program (SEVP)

March 17, 2021

ICE SEVP SEVP External Training Application (SETA) PWS

PROCUREMENT SENSITIVE INFORMATION

Table of Contents Performance Work Statement

1.0 Project Title

2.0 Background

3.0 Scope of Work

4.0 Roles and Responsibilities

5.0 Technical Overview

5.1 System Description

5.2 Internal Interfaces

6.0 DHS Enterprise Architecture Compliance

7.0 SETA Environments Overview

8.0 Applicable Publications

9.0 Tasks

9.1 O&M Support

9.2 Project Management

9.3 Maintain Data / Software Administration

9.4 Identify Problem and Modification Process

9.5 Requirements Analysis Management

9.6 User Management

9.7 Maintain System / Software

9.8 Break-fixes and Security Management

9.8.1 Emergency Break-fixes Implementation

9.8.2 Cybersecurity Management

9.9 Software Development Processes and Tools

9.10 Disposition

10.0 Deliverables

10.1 Project Management Plan and High-Level Project Roadmap

10.2 Product Roadmap

10.3 System Lifecycle Management (SLM) Deliverables

10.4 Enterprise Systems Assurance Plan (ESAP)

10.5 Configuration Management

10.6 Transition-out Plans

10.7 Kick-Off briefing

11.0 Key Personnel

11.1 IT Project Manager (PM) - Level III

11.2 Sr Technical Application Developer

12.0 General Requirements

12.1 Period of Performance

12.3 Hours of Operations

12.4 Non-Personal Services

12.5 Business Relations

12.6 Contract Management

12.7 Contract Administration

12.8 Subcontract Management

12.9 Organizational Conflict of Interest (OCI)

12.10 Invoicing

12.11 Government Furnished Equipment (GFE)/Government Furnished Property (GFP)

12.12 Government Furnished Information (GFI)

12.13 Security and Privacy

12.14 Cybersecurity Language for High Risk Contracts

Attachment A: List of Acronyms Attachment B: Performance Requirements Summary

PROCUREMENT SENSITIVE INFORMATION

Performance Work Statement

1.0 Project Title

Student and Exchange Visitor Program (SEVP) External Training Application (SETA)

2.0 Background

The Illegal Immigrant Reform and Responsibility Act (IIRIRA) of 1996 (Public Law 104-208) contains a provision requiring the monitoring and reporting of the activities of foreign students and exchange visitors while they reside in the United States (US). Section 64l(c) mandates that an electronic data collection system be developed, for US approved institutions of higher education and designated exchange visitor programs, to monitor non-immigrants possessing or applying for F, M, and J class visas with a Certificate of Eligibility.

The Student and Exchange Visitor Information System (SEVIS) also allows the Department of Homeland Security (DHS) to meet the requirements of the Enhanced Border Security and Visa Entry Reform Act, (H.R. 3525) which was signed into public law (Public Law 1 07-173) on May 14, 2002.

The foreign student related provisions amend section 641 of IIRIRA (the law that requires SEVIS) and applies to F, M, and J visa holders. These provisions include establishing an electronic means to monitor and verify acceptance of a foreign student, or exchange visitor, by an institution (Form I- 20, Certificate of Eligibility for Nonimmigrant Student Status or DS-2019, Certificate of Eligibility for Exchange Visitor Status); reporting within 30 days after the enrollment period the students who fail to enroll; and the requirement for schools and exchange visitor programs to report additional information on non-immigrants such as date of enrollment.

The Student and Exchange Visitor Program (SEVP) has been established as part of the Homeland Security Investigations (HSI) National Security Investigations Division within U.S. Immigration and Customs Enforcement (ICE). SEVP is responsible for delivering SEVIS, which is an Internet-based application that facilitates timely electronic reporting and monitoring of international students, exchange visitors (EVs), and their dependents in the United States. SEVIS enables schools and program sponsors to transmit electronic information to DHS and the Department of State (DoS) throughout a student's or EV's program in the United States. SEVIS is intended to improve customer service by streamlining the application and adjudication processes. It also addresses deficiencies in the current student and school’s system process by providing information technology solutions and modifying business processes.

SEVIS allows schools to submit school certification applications, update certification information, submit updates to the DHS that require adjudication, and create and update F1 (academic) as well as M1 (vocational) student and dependent records. DHS Managers and Adjudicators have the capability to adjudicate updates made to school records using SEVIS, and Principal Designated School Officials and Designated School Officials (P/DSO) are notified through SEVIS of the adjudication results. SEVIS also allows program sponsors to submit certifications forms for J1 visa program, creating program designations, and updating program designation information. DoS personnel have the capability to adjudicate information submitted by Responsible Officers and Alternate Responsible Officers (R/AROs). R/AROs are notified through SEVIS of any adjudication results.

SEVIS shares information with other systems to better monitor the status of a student or EV throughout their stay in the United States. This allows SEVIS to meet requirements of the Unifying and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct

PROCUREMENT SENSITIVE INFORMATION

Terrorism (USA PATRIOT) Act (Public Law 107-56 passed on October 26, 2001).

Among other things, the USA PATRIOT Act stated that for each non-immigrant for whom information is collected under the IIRIRA Section 641, the Attorney General, in consultation with the Secretary of State, will include information on the date of entry and Port of Entry (POE).

The Student Exchange and Visitor Program (SEVP) External Training Application (SETA) was established as the training component of the Student Exchange and Visitor Information System (SEVIS). The SETA project maintains Moodle and any other, OCIO directed, COTS/open-source products as the learning management system, and designing, developing and implementing a training curriculum for the SEVP program. Moodle is the learning management system that allows SETA users to access course material for their training.

3.0 Scope of Work

The Contractor shall provide Break-Fix and Operations & Maintenance (O&M) support for the SEVP External Training Application (SETA).

The Contractor shall implement support to include but are not limited to break-fixes, patching, defects and security related work of the current O&M system as outlined in the OCIO Systems Lifecycle Management (SLM) and Agile. All work will need to be approved by the Product Owner (PO) and the Contracting Officer Representative (COR). It is the Government’s intention to continually pursue improvements to processes and practices, which will result in meeting mission requirements at the lowest possible cost. The Contractor shall partner with the Government to pursue process improvements by evaluating existing processes and recommending improvements.

Regarding all support of this contract/order, the Contractor shall be aware that the Government and other contractors are engaged in similar and supporting work in support of SEVP, which will require close cooperation. Contractors are expected to form a cohesive team with all OCIO and SEVP team members to include the Government and other contractors by fostering transparency and information sharing for successful task execution.

4.0 Roles and Responsibilities

This list briefly outlines some of the roles and responsibilities for key federal personnel that the project team will work with on a regular basis:

• Project Sponsor/ Product Owner: Represents the operational needs of the business unit and the system users; participates throughout the SLM process to ensure that the system meets operational, security, and user requirements; and answers to the System Owner.

• IT Project Manager: Serves as the central point of responsibility for project decisions and activities;

coordinates the technical aspects of the project; manages the project to achieve cost, schedule, and performance goals; answers to OCIO.

• Requirements Owners: Internal system users; draft requirements; participate in the user acceptance testing; and answer to their respective Unit or Section Chiefs.

• Information Systems Security Officer (ISSO): Performs security actions for an information system - Ensures the implementation and maintenance of security controls in accordance with the Security Plan and DHS policies; participates in planning and executing the SLM process by providing information security expertise; ensuring that appropriate steps are taken to implement information security requirements throughout the SLM process; reviewing and commenting on all SLM security documents; and answers to

PROCUREMENT SENSITIVE INFORMATION

the Security Area Manager, IAD.

• Information System Owner (ISO): Ensures required security documents and reviews are prepared and included in the SLM; ensures adequate funding is available for implementation of security requirements;

answers to the Director of SEVP to the ICE CIO (the ICE CIO is the Authorizing Official (AO)).

Determines the degree of acceptable residual risk based on mission requirements, reviews the Security Authorization (SA) package, and grants or denies Authority to Operate (ATO).

• Section 508 Coordinator: Coordinates efforts with project teams for Section 508 Assistive Technology Interoperability compliance.

• ICE Privacy Officer: Ensures that technology implementations across ICE sustain privacy protections as mandated by Section 208 of the E-Government Act of 2002 and Section 222 of the Homeland Security Act. Answers to the Office of Information Governance and Privacy, Privacy Division

• Contracting Officer’s Representative (COR): Ensures that contractors meet the commitment of their contracts/orders; facilitate proper development of requirements; and assist Contracting Officers in developing and managing their contracts/orders to stay within the cost, schedule and scope of the contract/orders. Here at SEVP the COR answers to the CO and the Director of SEVP.

5.0 Technical Overview

The Government will store/house SETA on the Amazon Web Services (AWS) Cloud. The Contractor shall ensure that the AWS instance for the hands-on SMU system training faithfully replicates the functions and performs like the production system.

The Contractor shall replicate security, authentication, user account data and overall system operations access. System users shall provide and maintain the hardware on the client tier. The technical staff at ICE manages all other tiers. These three tiers are isolated from the client tier by a perimeter network called the Demilitarized Zone (DMZ) provided by the AWS infrastructure. The AWS configuration permits only Internet traffic to pass through predefined ports for HTTP connection and secure sockets layer (SSL) connection to reach the SMU system training environment. The internal firewall of the DMZ is also configured to allow Intranet traffic to pass through predefined ports for virtual private network (VPN) connection to reach the SMU system.

The Resin application servers in the application tier are grouped into an application server cluster where requests from the Web tier are distributed to the application servers.

The Contractor shall implement Kanban, the chosen Agile methodology for O&M to manage and optimize the flow of work. The Contractor shall track work items from the time they enter the system to the time they leave, providing continuous indicators of the amount of Work in Process and the current lead time. In other words, how long, on average, it takes an item to get through the system.

The Scrum framework (work items will be managed using Kanban unless the PO and the ITPM deicide that some work items are better managed in Sprints. For both methods, Confluence and SharePoint will be utilized for project documentation.

Note: Any exception must be approved by the Technology Transformation Committee (TSSC), and, in certain cases, the adoption of some agile practices may be required.

5.1 System Description

PROCUREMENT SENSITIVE INFORMATION

• LAMP Stack on Amazon Web Services (AWS). Php 7.0.16, MySQL 5.6.36, Apache 2.4.25, Amazon Linux version 4.4.44-39.55.amzn1.x86_64 used by Moodle

• Moodle learning management system (LMS) deployed as “LAMP stack” application in SEVP AWS cloud

• Sharable Content Object Reference Model (SCORM) initial content development platform;

moved to eXperience API (xAPI/Tincan) for improved user interaction tracking capability

• Articulate StoryLine 3 used for content object packaging and export

• LearningLocker open source learning record store (LRS) is being used to collect and expose extended user interaction dataset

• Network filesystem: Amazon Elastic File System (Amazon EFS)

5.2 Internal Interfaces

This section provides an example of one the systems that, in the future, may interface with another SMU system. Additionally, this section is an example of the format and frequency of data exchanges.

Table 1 describes the ICE systems that the SMU system interfaces with in relation to SETA.

Table 1. Internal System Interfaces

System Description Interface Type

Format/ Protocol/

Transport Frequency

ICE – SEVIS SEVIS provides data on SEVIS USERS Outgoing Incoming

JSON

RESTful

On Demand

6.0 DHS Enterprise Architecture Compliance

All solutions and services shall meet DHS and ICE Enterprise Architecture (EA) policies, standards, and procedures. Specifically, the contractor shall comply with all of the following DHS EA requirements:

• All developed solutions and requirements shall be compliant with the DHS EA;

• All IT hardware and software shall be compliant with the ICE EA Technical Reference Model

(TRM) Standards and Products Profile;

• Description information for all data assets, information exchanges, and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval, and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository;

• Development of data assets, information exchanges and data standards will comply with the DHS Data Management SEVP Guidance MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines; and

• Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related

PROCUREMENT SENSITIVE INFORMATION

component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

7.0 SETA Environments Overview

The cloud infrastructure, AWS, will host the SETA application. The Government will provide the following environments:

• Virtual Development Workstations;

• Development Integration (DEV-INT);

• Functional Qualification Testing (FQT);

• Performance Testing (PERF);

• Staging (Pre-PROD); and

• Production (PROD).

The Government will provide support for these environments.

8.0 Applicable Publications

The Contractor shall abide by all applicable Federal, DHS, and ICE laws, regulations, policies, standards, publications, manuals, and procedures.

Not all laws and regulations are listed below. The guidance listed provides ICE and/or DHS implementation policies and/or procedures for higher level guidance. If newer versions of these documents are officially released, the Contractor shall comply with these updated versions within a timeframe established by the Government.

• ICE Technical Architecture Guidebook;

• ICE Technical Reference Model (TRM) (Standards Profile);

• ICE Enterprise Systems Assurance Plan;

• ICE Agile Development Framework;

• DHS Management Directive (MD) 4300.1, Information Technology Systems Security;

• DHS 4300A Sensitive Systems SEVP Guidance, Version 9.1, July 17, 2012;

• DHS 4300B National Security Systems SEVP Guidance, Version 8.0, December 27, 2010;

• DHS Management Directive (MD) 11042.1, Safeguarding Sensitive But Unclassified (For

Official Use Only) Information, January 6, 2005;

• ICE Management Directive (MD) 4003.1, Safeguarding Law Enforcement Sensitive

Information, March 23, 2007;

• ICE Management Directive (MD) 4001.1, Electronic and Information Technology and

Accessibility, March 12 2009;

• DHS Directive 047-01, Privacy SEVP Guidance and Compliance, July 7, 2011;

• The Government recommends that the Contractor use the Information Technology

Infrastructure Library (ITIL) framework in the performance of this task;

• DHS Memorandum: Class Deviation 15-01 from the Homeland of Security Acquisition

Regulation: Safeguarding of Sensitive Information, March 9, 2015 http://dhsconnect.dhs.gov/org/comp/mgmt/dhshr/emp/Documents/StandardsandSpecsGuide_ LTI.pdf.

9.0 Tasks

http://dhsconnect.dhs.gov/org/comp/mgmt/dhshr/emp/Documents/StandardsandSpecsGuide_LTI.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/dhshr/emp/Documents/StandardsandSpecsGuide_LTI.pdf

PROCUREMENT SENSITIVE INFORMATION

9.1 O&M Support

The Contractor shall provide SETA O&M support for both SEVP and DoS. The Contractor shall plan, design, develop, and provide full O&M support as defined in the OCIO System Lifecycle Management. The emphasis of this task will be to ensure that all stakeholder and system user needs are met and the system continues to perform as specified in the operational environment.

Additionally, as O&M personnel monitor the current system, process improvement recommendations should be provided. Changes will be required to fix problems, possibly add features, and to make improvements to the system. This task will continue as long as the system is in use.

The Contractor shall, as required, provide support to modify SETA or courses after delivery to correct faults; improve performance or other attributes; adapt to a changed environment or maintenance activities focused on anticipated problems; and perform preventative maintenance to support a continuously operating and reliable, stable, and secure application.

In order to support creating effective content that is interesting and relevant in facilitating a solid understanding of SEVP’s governing regulations and Final Guidance, the Contractor shall use proven behavior science and cognitive learning principles. SETA shall provide cutting-edge technology, strong writing, purposeful humor, and original animation. SETA shall be available in courses for all user roles in production including F and M certified schools, P/DSOs, and R/AROs. SETA shall also track and measure the training, progress, and results for individuals with an interface to an SMU system.

Note: Work on all course(s) or module(s) are dependent on the availability of program funds/funding.

O&M support should follow the latest version of the ICE System Lifecycle Management (SLM) process for details. This document defines tasks, activities, and responsible parties. The ITPM and Product Owner (PO) will update the product teams as changes occur. Systems operations activities and tasks need to be scheduled, on a recurring basis, to ensure that the production environment is fully functional and is performing as specified. The following is a checklist of systems operations key tasks and activities:

• Ensure that systems and networks are running and available during the defined hours of

Operations;

• Implement non-emergency requests during scheduled Outages, as prescribed in the SLM and

Security;

• Ensure all processes, are documented in the operating procedures. These processes should comply with the system documentation;

• Perform backups (day-to-day protection, contingency), as directed by the ITPM;

• Perform the physical security functions including ensuring adequate controls, Personnel have proper security clearances and proper access privileges etc;

• Ensure contingency planning for disaster recovery is current and tested as required by OCIO and the System Owner;

• Maintain performance measurements, statistics, and system logs. Examples of performance measures include volume and frequency of data to be processed in each mode, order and type of operations;

• Monitor the performance statistics, report the results and escalate problems when they occur; and

• The development of new baseline core requirements may be generated by other sources of regulatory guidance or oversight, as needed.

9.2 Project Management

The Contractor shall provide project management support throughout the life of the contract to include reporting, troubleshooting, presentations, creating, and maintaining project-related documentation. The contractor shall provide support for meetings with stakeholders to include organizing meetings and taking notes.

The Contractor shall support subsequent reviews and retrospectives until final production-ready training applications are resident in the target architecture for SETA, and said applications are approved and accepted by the government authority.

The Contractor shall communicate in writing the basis of estimate/burn down chart for each sprint session and the specific impact information such as sprint blockers, proposed function point changes, and production estimates that impact project milestones and completion times.

The Contractor shall not accept additional function point introductions as a result of follow-on technical exchanges once the sprint bloc is closed and approved. Only the government Product Owner(s) is authorized to revisit the work accepted for a sprint once approval is provided by the government.

If OCIO requires that this application move from the commercial cloud to the ICE cloud environment, the Contractor shall develop a migration plan and prepare the SETA team for the migration following SLM process.

9.3 Maintain Data / Software Administration

The Contractor shall provide Data/Software Administration support to ensure that input data and output data and data bases are correct and continually checked for accuracy and completeness. This includes insuring that any regularly scheduled jobs are submitted and completed correctly. Software and data bases should be maintained at (or near) the current maintenance level. The backup and recovery processes for data bases are normally different than the day-to-day volume backups. The backup and recovery process of the data bases should be done as a Data / Software Administration task by a data administrator while communicating with the ITPM and PO. A checklist of Data / Software Administration tasks and activities are:

• Performing a quarterly Verification / Validation of data, correct data-related problems;

• Performing production control and quality control functions (Job submission, checking and corrections);

• Interfacing with other functional areas for day-to-day checking / corrections;

• Installing, configuring, upgrading, and maintaining data base(s). This includes updating processes, data flows, and objects (usually shown in diagrams);

• Developing and performing data / data base backup and recovery routines for data integrity and recoverability. Ensure documented properly in the Operations Manual; and

• Performing quarterly configuration/design audits to ensure software, system, and parameter configurations are correct.

Following the successful deployment of each Course and final application, the Contractor shall provide O&M support for all tiers for technical request. During this support period, the Contractor shall identify and correct software, performance, and implementation failures. Corrective work

PROCUREMENT SENSITIVE INFORMATION

includes performing changes that reflect a change to requirements or technical specifications, as well as updating and maintaining the required System Lifecycle Management (SLM) documentation, including establishing and maintaining Interface Control Agreements (ICAs) with all interface partners.

As a part of O&M support, the Contractor shall provide Tier 3 Support for all of the SETA Courses once they are in production. Tier 3 Support includes but is not limited to, the following responsibilities:

• Production support of the courses and insuring availability 24/7/365 in the event of production issues;

• All maintenance activities that reach this level shall have a ticket opened and be reported using the ICE approved tracking tool;

• Tickets will be prioritized and agreed to by the authorized government personnel and entered into the ICE approved management-tracking tool;

• Known issues that cannot be addressed through a ticket shall be documented and coordinated with the OCIO ITPM for guidance;

• Responding to all Maintenance Tier 3 trouble tickets within three (3) business days or agreed upon in advance by the government;

• Implementing automated monitoring and alerting in order to proactively detect issues; and

• Supporting on-going training operations including but not limited to troubleshooting issues, code fixes, and updating the system to meet new requirements.

Note: ICE oversees other contractors and federal personnel who will provide input for product planning, solution architecture, and engineering.

The baseline core requirements supporting SETA are managed and updated, as needed, from the Governing regulations and SEVPs Final Guidance below:

• SEVP’s governing regulations for students and schools - https://www.ice.gov/sevis/schools/reg o INA § 101(a)(15)(F)(i) F-1.

o INA § 101(a)(15)(F)(ii) F-2.

o INA § 101(a)(15)(M)(i) M-1.

o INA § 101(a)(15)(M)(ii) M-2.

• e-CFR: Exchange Visitor Program – http://www.ecfr.gov/cgi-bin/retrieveECFR?gp=&SID=1bc531bf257789e45b3049bff8b50d64&r=PART&n=22y1. 0.1.7.35 o INA § 101(a)(15)(J)(i) J-1.

o INA § 101(a)(15)(J)(ii) J-2.

• SEVP Final Guidance1 - https://studyinthestates.dhs.gov/sevp-guidance-for-comment

9.4 Identify Problem and Modification Process

One fact of any system is that change is inevitable. Stakeholders and users need an avenue to suggest change and identify problems. A User Satisfaction Review, which can include a Customer

1 “Final guidance” is official SEVP guidance that establishes standards or requirements and is used in SEVP adjudications. Final guidance is not open for public comment. It is intended to clarify law or regulation related to SEVP adjudications and does not replace or supersede those laws or regulations.

https://www.ice.gov/sevis/schools/reg http://www.ecfr.gov/cgi-bin/retrieveECFR?gp&SID=1bc531bf257789e45b3049bff8b50d64&r=PART&n=22y1.0.1.7.35 http://www.ecfr.gov/cgi-bin/retrieveECFR?gp&SID=1bc531bf257789e45b3049bff8b50d64&r=PART&n=22y1.0.1.7.35 https://studyinthestates.dhs.gov/sevp-guidance-for-comment https://studyinthestates.dhs.gov/sevp-guidance-for-comment

PROCUREMENT SENSITIVE INFORMATION

Satisfaction Survey, can be designed and distributed to obtain feedback on operational systems to help determine if the systems are accurate and reliable. Systems administrators, stakeholders, and users need to be able to make recommendations for upgrade of hardware, architecture, and streamlining processes. For the small in-house system, modification requests will be handled through the in-house SETA inbox. For larger integrated systems, modification requests must be addressed in Jira and may take the form a formal Change request and may require justification and cost benefits analysis for approval by a requirement review board. A request for modifications to a system may also generate an interface that will require additional approval documentation and SLM documentation.

9.5 Requirements Analysis Management

The Contractor shall use SEVP’s Agile processes during requirements analysis, documentation, and implementation for all training products. User stories will be created and written by the Government to deliver the functionality for each Course/iteration of the training, which are based on the regulations and Final Guidance.

The Contractor shall conduct requirements gathering that includes defining and recording requirement(s) with the Requirements Owner(s) and the Product Manager(s)/Product Owner(s).

The Contractor shall deliver, manage, and update, as needed, a Product Roadmap that will communicate upcoming release dates to ensure users will comply with SEVP’s training requirements on the governing regulations and SEVP Guidance to meet their obligations as government-approved users of the system.

The Contractor shall support SEVP's Agile process to collect and validate requirements by supporting or facilitating Requirement Owner(s) and Product Manager(s)/Product Owner(s) sessions, sprint planning, daily scrum sessions, scrum of scrums, sprint backlog reviews, and subsequent reviews and retrospectives until final requirements validation is approved by the SEVP/DoS Product Managers. Technical aspects of planning are subject to review and approval by the SEVP Training Product Owner(s). The SEVP/DoS Program Managers will prioritize stories for development and determine if the completed development is acceptable in accordance with Agile processes.

The Contractor will use Agile processes to manage the project. The Contractor shall use Agile development methodologies, such as Scrum or Kanban. Agile process is to be approved by the Product Owner.

The Contractor shall be primarily concerned with the implementation cycle, which in the case of Scrum includes Sprint planning, application design, development and testing, deployment, Sprint review, Sprint retrospective, and ongoing operations and maintenance to include SETA Help. The Government will dictate how long the sprints will be. The Government will provide a Scrum Master to facilitate the Agile development process and perform the traditional duties of the Scrum Master role.

The Contractor shall not put any content in production without the sign-off of Requirements Owner(s) and Product Manager(s)/Product Owner(s). User stories will be drafted by the Requirements Owners, finalized by the Product Manager(s)/Product Owner(s), and the Contractor for implementation in the form of a product backlog. The Government Product Owner(s) will provide

PROCUREMENT SENSITIVE INFORMATION

prioritization of user stories.

The Contractor shall:

• Work with the requirements owners/working group to elicit requirements and assist in developing user stories per requirements owner’s direction. Once the user story is approved by the Product Owner, the contractor will develop any chores that define the software, hardware, and application development requirements to achieve a functional requirement.

• Support the iterative, collaborative development tasks of defining what functions and user stories will deliver a modular, scenario-driven training application that enhances user training for systems administrators, users, and instructors.

• Provide the baseline function points and user stories that deliver compliance with ICE and DoS policies, regulations, and guidance throughout the life cycle of the SEVP External Training Applications/Courses.

Note: Work on all course(s) or module(s) are dependent on the availability of program funds/funding.

9.6 User Management

The Contractor shall manage user access to the SEVP External Training Application. Account management tasks shall configure access for government personnel roles only. Account management tasks shall include, but are not limited to:

• Add/remove roles in the training environment;

• Leverage production user accounts and roles from an SMU system;

• Reserve certain roles and training solely for government personnel (PIV enabled), such as law enforcement training;

• Ensure school and program roles are available to trainees who do not yet have access to the SMU system;

• Maintain the SETA Help Inbox:

o Response time window of four (4) hours during working hours;

o Track Help Tickets on SETAHELP Kanban board; and

• Route content issues to the SEVP Communications and Training Team (SCT).

9.7 Maintain System / Software

Daily operations of the system /software may necessitate that maintenance personnel identify potential modifications needed to ensure that the system continues to operate as intended and produces quality data. Daily maintenance activities for the system takes place to ensure that any previously undetected errors are fixed. Maintenance personnel may determine that modifications to the system and databases are needed to resolve errors or performance problems. Also, modifications may be needed to provide new capabilities or to take advantage of hardware upgrades or new releases of system software and application software used to operate the system. New capabilities may take the form of routine maintenance or may constitute enhancements to the system or database as a response to user requests for new/improved capabilities. Thus, new capabilities may require a new problem resolution process.

The Contractor shall maintain and update SETA in accordance with government regulations and SEVP’s Final Guidance.

Examples of the courses are as follows (but are not limited to):

PROCUREMENT SENSITIVE INFORMATION

• SEVP Basics: Provides an overview of SEVP, SEVIS, and the management of nonimmigrant students (Existing course);

• SEVP 101: History and roles of SEVP and SEVIS in monitoring nonimmigrant students, exchange visitors, and certified/designated institutions (Existing course);

• EVP 101: Overview of the EVP, the categories, and the responsibilities of the Private Sector Exchange offices (Existing course);

• Intro to Initial SEVP Certification: Overview of federal regulation 8 CFR 214.3, which governs SEVP school certification requirements. Outlines ongoing duties for certified schools. (Existing course);

• Managing a Designation: Best practices for managing an exchange visitor program including using SEVIS, reporting, process summary, and using Pay.gov (Existing course);

• SEVP 3: Maintaining School Records (Existing course);

• SEVP 4: Becoming a Nonimmigrant Student (anticipated future course);

• SEVP 5: Maintaining Student Records (anticipated future course);

• SEVP 6: Managing Exchange Visitor Records (EVP3) (anticipated future course).

This training application helps mitigate vulnerabilities within SEVPs main system, SEVIS, that emphasizes critical information that our external users need to manage and/or stay compliant with the regulations around F, M, and J visa categories. Emphasis shall be placed on the use of behavioral science training techniques to mitigate known training deficiencies, which were borne from using a business system as a training substitute for actual interactive coaching systems that are necessary to raise training efficiency and trainee engagement.

The Contractor shall work extensively with users, Requirement Owner(s) (Requirements Working Group), Product Manager(s)/Product Owner(s), Scrum Master, IT Project Manager(s). and the ICE Engineers and Architects to ensure that the SETA continually delivers solution(s) and value to the business unit and users.

The Contractor shall follow ICE SLM, using OCIO’s technical documents repository to include but are not limited to:

• Code Development - Define, author, and deliver custom application code that conforms to the requirements and application architecture provided by the government;

• Integration Support - Integrate solutions into a custom built, modernized system, provide configuration, customization, and implementation services;

• Deployment Activities - Plan, create, and validate the implementation and deployment instructions (version description document [VDD], deployment plan) for use during application deployment;

• DevOps – As per the direction of the ITPM, work collaboratively and cross functionally with other SEVP/OCIO contractors to implement Continuous Integration and Continuous Delivery; and

• Participate in integrated program/project teams and/or Scrum teams to enhance communication, discuss lessons learned, and facilitate rapid identification and mitigation of dependencies

PROCUREMENT SENSITIVE INFORMATION

between various functional entities.

The Contractor shall manage and update, as needed, a Plan of Actions and Milestones (POA&M) and assist the Government in resolving any security issues that arise throughout the development, testing, and/or deployment phases. The training application shall possess the ICE security configurations and constraints to ensure policies regarding government restricted site access are implemented and adhered to throughout the SEVP System Training application The Baseline Functional Model will deliver full user-driven architecture functionality for every profile with the ability to track and audit all actions by profile.

Based on mission need, SETA needs will be able to communicate training data to another SMU system as requested.

The system shall keep records that track the user’s activities and accomplishments. The trainee shall have the ability to return to the "Saved State" of the training application at the point of interruption and resume training. The system must be able to create and maintain training certificates.

SETA shall audit the following systems and user activities:

• User access;

• Query strings submitted;

• Records viewed (e.g., selected from results list);

• Records created, modified, and deleted;

• Records or reports extracted or downloaded;

• Records or reports printed;

• Help Ticket management and reporting;

• Training courses viewed (e.g., selected from results list);

• Training courses; In Progress, Completed and Delayed;

• Training Test; In Progress, completed: passed or Failed and Delayed and/or graded;

• Training Records or reports extracted or downloaded for the government and for the user; and

• Training Records or reports printed.

Currently, SETA uses tableau and Learning Locker LRS as reporting tools. Tableau is connected to a real time replicated RDS instance of SETA Database. Tableau runs a query against this replicated server. Tableau is running extracts from this database for the dashboard also. The tableau dashboard is not integrated with Moodle to show any reporting on any of its pages.

The SETA application shall have an overall availability of 99.995%.

The Contractor shall replicate the government provided development, testing and Pre-Production and production environments and adhere to a test-driven development (TDD) methodology including the development and running of automated unit, integration, and functional testing.

Additionally, upon any release into production the production version of the SEVP External Training Application shall integrate into and be supported by the ICE's Product Backlog Repository (currently JIRA) to track story and task progress, ICE's Defect Management tool (currently Serena Tracker) to track SCRs, and shall use ICE's Source Code Version Management tool (currently Subversion) for version control of the system’s application code base.

The "Definition of Done" is the establishment and approval of a base line of function points aggregated into User Stories that will culminate in a functionally compliant environment within

PROCUREMENT SENSITIVE INFORMATION

which scenario-based training may be developed to replicate actual system functions and business workflows with either sanitized SMU systems data or sample data that meets the SMU system’s data quality standards.

The Contractor shall follow the ICE OCIO process prior to releasing into a production environment.

The Contractor shall manage and/or implement and require interfaces with existing SMU applications.

For the development process, the Contractor shall use Agile development methodologies, such as Scrum or Kanban. The Contractor shall be primarily concerned with the implementation cycle, which in the case of Scrum includes Sprint planning, application design, development and testing, deployment, Sprint review, and Sprint retrospective. SEVP currently implements Sprint. The Government will provide a Scrum Master to facilitate the Agile development process and perform the traditional duties of the Scrum Master role.

User stories will be written by the requirement owners and issued to the Product Manager(s)/Product Owner(s) and the Contractor for implementation in the form of a product backlog. The Government Product Owner(s) will provide prioritization of user stories.

The Contractor shall use the Government-provided Product Backlog Repository and defect management tool, currently JIRA, to track user story and task progress.

The Contractor shall use the Government-provided Source Code Version Management tool, currently GitHub, for version control of the code base.

The Contractor shall use the Government-provided Continuous Integration (CI) toolset, currently Jenkins, for automated builds and deployments to all environments.

The Contractor shall use an industry standard unit testing library, such as JUnit, to execute all unit tests. The Contractor shall use the Government-provided code coverage toolset to report on unit testing code coverage. The unit testing and code coverage toolset is integrated with the CI toolset to provide reports on unit testing. The Contractor shall ensure that required integration points with the developed code base shall be supported in order to enable the reports in the CI toolset.

The Contractor shall use the Government-provided static code analysis tools, planned to be SonarQube, and integrate the execution of the analysis with the CI toolset for automated execution and reporting of results.

The Contractor shall perform code peer reviews and document the results via an electronic medium, such as a wiki or JIRA, or using a Government-provided tool if available. The Contractor shall develop automated test cases using an industry standard automated functional testing toolset, such as Selenium. An automated test case suite shall be maintained and executed on a regular basis, at least weekly. The automated testing toolset shall be integrated with the CI toolset to allow for automated scheduled execution and results reporting.

The Contractor shall support the full lifecycle of integration testing with interface partners, including test planning, test script creation, data staging, test execution, troubleshooting, and test result reporting.

PROCUREMENT SENSITIVE INFORMATION

The Contractor shall support performance testing of the application. The Government is responsible for performance test creation and execution.

The Contractor shall work to resolve defects and/or performance issues that are identified during performance test execution. If non-standard technology components are used by the application, the Contractor shall support the Government during the ICE Technology Reference Model (TRM) and Information Technology Change Request (ITCR) process. This support shall include documentation and justification for the need for the specific technology components being used.

9.8 Break-fixes and Security Management

An emergency break-fix action changes the status of a configuration item so as to restore its operational status. This process permits actions to be taken to restore a configuration item to operational service. These actions still must follow a change management process, but one that accommodates their high impact and high urgency. Actions that change the logical or physical characteristics of a configuration item are not permitted under this process.

9.8.1 Emergency Break-fixes Implementation

• Rebooting a device (e.g., server, appliance, network equipment)

• Restarting one or more services on a device

• Stopping an application on a redundant server (provided that the application is running on another server)

• Clearing or deleting log files to resolve a memory- or disk-full condition not symptomatic of a malware or denial-of-service attack (does not include adding physical memory or allocating additional storage space)

• Restoring data from a backup

• Replacing a defective hardware part or device with a part/device of the same make, model, and configuration (includes replacing defective memory and replacement of like-for-like network devices/parts/components with no configuration modifications)

• Reinstalling/restoring corrupted software to its previously approved configuration

• Restoring the agreed-upon interconnection security agreement (ISA) configuration for AppAuth trust must provide change request number(s) that reflect agreed-upon trust configuration

• Support firewall configuration as needed

• Removing any blocker that is preventing a backup from loading

• Allocating additional storage space or reallocating storage space within a system

• Adding memory to a server (physical or virtual) at an approved time and date; Product Owner, System

Owner and OCIO POC

• Renewing server certificates

9.8.2 Cybersecurity Management

Federal law requires that all government information systems be protected against unauthorized access or use. The Federal Information Security Management Act (FISMA) is the key cybersecurity statute and requires Federal agencies to implement organization-wide cybersecurity programs. The U.S. Department of Homeland Security (DHS) has instantiated FISMA in several organizational publications.

FISMA and related DHS cybersecurity policies and requirements apply to all information technology (IT) solutions deployed across DHS. They apply to all IT solutions operated by or on behalf of DHS.

As many Immigration and Customs Enforcement (ICE) information systems are developed or maintained by contract resources, incorporating cybersecurity requirements into all ICE contracts is

PROCUREMENT SENSITIVE INFORMATION

a critical component of the overall DHS cybersecurity program.

The Contractor shall work with the System Owner and ITPM to support the new NIST 800-53 r5 controls. At this time, DHS is evaluating the impact of the new controls on the department as a whole and will formulate a plan for implementation and rollout to the components.

9.9 Software Development Processes and Tools

The Contractor shall use the Government-provided virtual environment including development workstations, development integration, testing and production. The Government will provide and support these environments, which are hosted in cloud service provider infrastructure, currently AWS. The Government will provide and support the infrastructure.

The Contractor shall support the Government in the stand-up of the environments including application specific software components, as well as application specific infrastructure implementations, such as load balancing. The Contractor shall be responsible for shake-out and validation of each environment.

The Contractor shall use the Government-provided Product Backlog Repository and defect management tool, currently JIRA, to track user story and task progress.

The Contractor shall use the Government-provided Source Code Version Management tool, currently GitHub, for version control of the code base.

The Contractor shall use the Government-provided Continuous Integration (CI) toolset, currently Jenkins, for automated builds and deployments to all environments.

The Contractor shall use an industry standard unit testing library, such as JUnit, to execute all unit tests. The Contractor shall use the Government-provided code coverage toolset to report on unit testing code coverage. The unit testing and code coverage toolset is integrated with the CI toolset to provide reports on unit testing. The Contractor shall ensure that required integration points with the developed code base shall be supported in order to enable the reports in the CI toolset.

The Contractor shall use the Government-provided static code analysis tools, planned to be SonarQube, and integrate the execution of the analysis with the CI toolset for automated execution and reporting of results.

The Contractor shall perform code peer reviews and document the results via an electronic medium, such as a wiki, JIRA, or using a Government-provided tool if available.

The Contractor shall develop automated test cases using an industry standard automated functional testing toolset, such as Selenium. The contractor shall maintain and execute an automated test case suite on a regular basis, at least weekly. The automated testing toolset shall be integrated with the CI toolset to allow for automated scheduled execution and results reporting.

The Contractor shall support the full lifecycle of integration testing with interface partners, including test planning, test script creation, data staging, test execution, troubleshooting, and test result

The Contractor shall support performance testing of the application. The Government is responsible

PROCUREMENT SENSITIVE INFORMATION

for performance test creation and execution. The Contractor shall work to resolve defects and/or performance issues that are identified during performance test execution.

The Contractor shall provide SLM deliverables identified and required by the appropriate SLM phase to the Project Manager (PM) and ELMS. The contractor shall prepare documentation in accordance with the guidelines specified by the SLM and the approved Tailoring Plan. During this period of performance of the system lifecycle, all security activities need to be completed as directed. The contractor must update the System Security plan, as well as update and test the contingency plan.

Continuous vigilance shall be given to virus and intruder detection. The project team and the IT Project Manager must be sure that security operating procedures are kept updated accordingly. The contractor shall review and update documentation from the previous releases.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .